EP1150197A2

Authentication and authorization system using smart card

Abstract

Authentication and authorization system through intelligent card and only key, consisting of a system having intelligent card readers, located at different peripheral units, all them connected with an authentication and authorization server, which, on one side, identifies the person who is the owner of the card by means of a key made available in the card, which is only accesible to the system, not even to the own user, and on the other side, starting from the profile arrogated to the user, which is also recorded in the own card, the server authorizes it and gains access to certain computerized applications, with no need for the user to know the method of access to them, without entering new access keys, although so required by the applications, the own system doing it instead of the user.

EP1150197A2, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 25 April 2021, 5.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 4 independent, 6 dependent

  1. 1
    An authentication and authorization system, thru intelligent card and only key, of those constituted by an architecture based on a unit acting as an identification, authentication and authorization server, connected, through a communication network, on one side, to peripheral units used by multiusers, such as, for example, the access to buildings, and to others units used by only one user, each of which has a corresponding reading element and the corresponding method for performing said read for an intelligent card, such as a chip card, and on the other side, the identification and authorization server is connected with public key infrastructures and different computerized application servers to which a user wishes to accede, characterized in that it combines, on a same intelligent card support, keys of physical access to installations, and logic access to computerized systems of the organization, using for this purpose two applications recorded in said support managing the use of these keys, also recorded in protected portions of the support.
  2. 8
    An authentication and authorization system thru intelligent card and only key, according to any of the preceding claims, characterized in that by configuring in an adequate way the modifiable computerized applications, said applications can be entered without intervening the user, by means of the automatic write of the entry keys to said applications.
  3. 9
    An authentication and authorization system thru intelligent card and only key, according to any of the preceding claims, characterized in that the identification made of the user is configured so that it is accepted as certification and electronic signature in systems with applications in a native mode of challenge/answer.
  4. 10
    An authentication and authorization system thru intelligent card and only key, according to claims 7, 8 and 9, characterized in that, independently of the strategy to carry out as a function of the applications to be acceded, the interface is unique and diaphanous to the user.