EP1480107A2

Method for authentication of a user with an authorizing device, and a security apparatus for carrying out the method

Abstract

The invention relates to an authentication system having a security apparatus (10, 100) which can check all three authenticating factor types for authentications (personal subject matter, secret, biometric characteristic), having an authorizing device (2, 102) and having a certifying institution (5, 105), in which case their private keys, the public keys on the subscribing authorizing devices (102) and the public keys of the connected users (10) can be stored in this certifying institution (5, 105). Furthermore, authentication means (305, 316) are provided there, by means of which an appropriately coded report can be produced, which can be passed via the authorizing device (102) to the user (10). The user (10) decodes this message (310, 311, 312) and transmits the resultant authorization code via the authorizing device (102) to the certifying institution (105). After checking the code in this certifying institution (105), a response (317) which comprises confirmation or rejection is transmitted to the authorizing device (102).

EP1480107A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 13 May 2024, 2.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

9 claims: 4 independent, 5 dependent

  1. 1
    Method for authentication of a user with an authorizing device (2, 5), with the authorizing device (2, 5) directly or indirectly (6) having at least one output appliance (3) and at least one input appliance (4), with the user having a security apparatus (10) in which personal data is stored by him and which has a receiving means (12) using which data (13) which is output via an output appliance (3) of the authorizing device can be transmitted to the security apparatus (10), with the method comprising the following steps:a.) inputting of a first information item into one of the said input appliances (4) of the authorizing device (14, 24, 34), b.) processing of the input via the authorizing device which produces first (16) and/or second (26) data items directly or indirectly, which are output via at least one output appliance (3) of the authorizing device (2), c.) identification of the user by the security apparatus (10) by means of a data input (15, 25) by the user on and to the security apparatus (10), d.) comparison of the input made in step c.) with an expected input in a checking element (17) of the security apparatus (10), e.) if the comparison of the data in step d.) is successful, recording of the first data items (16), which were output by the said output appliance (3) of the authorizing device in accordance with step b.), by the security apparatus (10), f.) conversion (27) of the data recorded by the security apparatus (10) to information which can be identified by the user, as an input request (28), g.) inputting of the input request by the user in one of the said input appliances (4) of the authorizing device (2), directly or indirectly by means of the security device (15), h.) comparison of the input made in step g.) with the input, expected with respect to the data (16) produced, in the authorizing device (2, 5), and i.) if the comparison of the data in step h.) is successful, confirmation of the authentication by the authorizing device (2, 5).
  2. 2
    Method according to Claim 1, in which the data input in step c.) comprises an input of biometric data by the user into the said security apparatus (10), and/or in that, in step d.) the user is identified by the security apparatus (10) by comparison of the said biometric input with the or a corresponding part of the stored biometric data.
  3. 3
    Method according to Claim 1 or 2, in which the biometric input comprises a fixed secret (41) or a dynamically adaptable secret (41), which comprises a sequential or parallel biometric input which can be compared with the or with a corresponding part of the stored biometric data.
  4. 4
    Method according to one of Claims 1 to 3, in which the data input in step c.) is initialized by the second data items (26), and in the process a determination is made in particular as to which input is awaited and will be checked in step d.) and/or in that the data input in steps a.) and/or c.) is made by means of RFID.
  5. 5
    Method according to one of Claims 1 to 4, in which the information which could be identified by the user according to step f.) as an input request is an alphanumeric, graphical or acoustic information item, which can be implemented by the input appliance, in particular in the form of a keyboard or graphical pointing appliance or drawing appliance.
  6. 6
    Security apparatus (10) for carrying out the method according to one of the preceding claims having a memory (11) in which personal data can be stored by a user, having a receiving means (12) for recording data (13), which has been output via an output appliance (3) of an authorizing device (2, 5), in the security appliance (10), characterized by a checking element (17) for comparison of the input made in step c.) of the method with an expected input, a converter device (27) for the data recorded by the security apparatus (10) to information which can be identified by the user, and an output unit (28) for outputting the input request..
  7. 7
    Security apparatus (10) according to Claim 6, characterized in that the memory (11) comprises data from the group of freely available identification data (11), biometric data (31) and a secret (41).
  8. 8
    Authentication system having a security apparatus (10), an authorizing device (102) and a certifying institution (105), in which case the private key for the certifying institution (105), the public key for the subscribing authorizing devices (102) and the public keys for the connected users (10) can be stored in the certifying institution (105), in that authentication means (305, 316) are provided in the certifying institution (105) and can be used to produce a report which is coded in accordance with the authorizing device (102) that is involved corresponding to the user (10) requesting authorization via the said authorizing device (102), and which report can be passed via the authorizing device (102) to the user (10), in that the user (10) requesting authorization has a decoding unit (27) in which the report containing the authorization code can be decoded by means of his secret key and the public key of the authorizing device (102) which can be stored in the security apparatus (10), and with transmission means being provided such that, after receiving and passing on the authorization code from the user (10) via the authorizing device (102) to the certifying institution (105), the latter can transmit the checked response, provided with confirmation or rejection of the authentication, to the authorizing device (102).
  9. 9
    Method for operation of an authentication system, which comprises a security apparatus (10), an authorizing device (102) and a certifying institution (105), with the private key of the certifying institution (105), with the public key of the subscribing authorizing devices (102) and the public keys of the connected users (10) being stored in the certifying institution (105), and with the secret key of the said security apparatus (10) and the public key of the authorizing device (102) being stored in the security apparatus (10), characterized by the following steps, a.) that a user (10) who is requesting authorization transmits identification information to the authorizing device (102), b.) that the authorizing device (102) transmits this or modified identification information to the certifying institution (105), c.) that the certifying institution (105) produces a report which is coded corresponding to the authorizing device (102) that is involved and the requesting user (10), d.) in that this report is passed via the authorizing device (102) to the user (10), e.) in that the user requesting authorization has a decoding unit (27) in his security apparatus (10), in which decoding unit (27) the report which contains the authorization code is decoded by means of his secret key and the public key of the authorizing device (102), which is stored in the security apparatus (10), f.) in that the authorization code is passed from the user (10) via the authorizing device (102) to the certifying institution (105), g.) in that the certifying institution (105) checks the authorization code and transmits a response, which contains a confirmation or rejection of the authentication to the authorizing device (102) which handles this appropriately for the user.