Certified calls
Abstract
Verfahren zur Authentifikation eines ersten Teilnehmers 1 gegenüber einem mit dem ersten Teilnehmer 1 in Kommunikationsverbindung befindlichen zweiten Teilnehmer 2, wobei sich einer der Teilnehmer unter Vorgabe der Kennung des anderen Teilnehmers mittels eines Endgerätes in ein Kommunikationsnetz einwählt und wobei über das Netz eine Verbindung zum Endgerät des anderen Teilnehmers aufgebaut wird, wobei ein im Netz befindliches Authentifikationsmittel 3,4 angewählt wird, in dem persönliche Daten des ersten Teilnehmers 1 hinterlegt sind, dass das Authentifikationsmittel 3,4 im Rahmen der Verbindung zur Identifikation geeignete Daten des ersten Teilnehmers aufnimmt und durch einen Vergleich mit den gespeicherten Daten seine Identität abgleicht und dass das Authentifikationsmittel 3,4 dem zweiten Teilnehmer 2 die Identität des ersten Teilnehmers 1 bestätigt.

Term
Term ended
Projected expiry passed 11 October 2024, 2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
13 claims: 7 independent, 6 dependent
- 1A method for authentication of a first subscriber (1) relative to one to the first subscriber (1) in communication located second subscriber (2), wherein one of the participants with specification of the identifier of the other party by means of a dialing terminal in a communication network and said over the net a connection is established to the terminal device of the other party, characterized in that a work in network Authentication means (3,4) is selected, the data in the personal the first subscriber (1) are stored, that the authentication means (3,4) during the connection to the identification data of the appropriate first subscriber receives and by comparison with stored data matches its identity and that the Authentication means (3,4) to the second subscriber (2) the identity of the first subscriber (1) confirmed.
- 4Method according to one of the preceding claims, characterized in that turning on the Authentication agent (3.4) in the pipe between two participants is done automatically.
- 5Method according to one of the preceding claims, characterized in that authentication via a switched into the line and assigned to the subscriber box (3) happens, which is accessible via an electronic address.
- 7Method according to one of the preceding claims, characterized in that authentication is performed by means of the voice of the participant, the Clean with a stored voice sample or characteristic Parameters of a voice sample occurs.
- 9Method according to one of the preceding claims, characterized in that the addressee of the Box a certification message gets that particular name, contains address and / or the identity card number of the subscriber.
- 11Method according to one of the preceding claims, characterized in that electronic News are stored in the box, where the forwarding is made, after to be authenticated subscriber dialed the box and has to identify himself to the box.
- 12System, in particular for performing the method according to one of preceding claims, comprising a communication network and to the Grid connected and selectable via an identification terminal, wherein means for authentication are present which the identity of a communicating via a terminal operator in relation to a other communicating via a terminal subscriber (1,2) certified, characterized in that the means for Authentication (3.4) is implemented on a network computer is selected and a associated with a subscriber address, being accessible via the means personal data of the subscriber, which serve to balance with appropriate to identification data of are the participants to be authenticated enterable, said Authentication means another subscriber identity of the to authenticating participant confirmed.
Independent claims7
16 paragraphs, as filed
0001The present invention relates to a method for authentication of a first Subscriber by a communication link with this in standing second party, said one of the participants with specification the identification of the other party by means of a terminal in a Communications network dials and where on the network to connect to Terminal of the other party is established. The invention relates to also a system for implementing the method.
0002Generally, both partners identify within a telephone conversation the very fact that one's voice is the other known. However, each of the two more or less easily through an imitation of Voice of the other are deceived. Mostly, however, the caller can it assume that the called party by dialing the assigned him Network identifier is sufficiently identified. If the person being called, however, the Voice of the caller is not known personally, so to must the caller legitimize. Here, the called party has the ability to query data the caller are more or less assign good and really only this should know. For example, a customer can with a call by the identify target its customer number.
0003Usually the information that a caller by giving such easy accessible data gets comparatively "ünkritisch" and contain hardly personal information. Nevertheless, it often happens that For example, the tax office employees give out personal information, after-read the caller by specifying on every business letter "Identified" control number has. A secure, yet easy to handle Authentication is obviously not by the methods known to date given.
0004For an electronic signature of documents or to authenticate Online customers are also cumbersome key method known in which to be signed and-Checking must verify from a trust center. Nevertheless, there is still the problem of the authentication of the unique Sender or of the customers. Object of the present invention is therefore to provide a method for secure to provide authentication of the two participants, the cost is with can be realized by simple means and the opportunities to complete Automation offers. Yet another object of the invention, a system for to provide implementation of the method.
0005These objects are achieved with a method according to claim 1 and a system dissolved according to claim 12th
0006The essential idea of the invention is an independent means, in the line is switched and the one subscriber over the can authenticate other participants safe since it it in some ways personally "knows". This accessible through the network authentication means, in the suitable for secure identification and "tamper-proof" personal Dates to be authenticated subscriber are stored, can already at the Dial the sender in the network or as needed when connected be selected. So the selection of the composition can be targeted by one of the two carried partners when personal in the following discussion of the exchange Data is intended. According to the invention for authentication data added the subscriber to be authenticated by the means and with the stored data synchronized. After successful adjustment, can the authentication means the identity of the person served compared to the other participants certify.
0007The advantages of the method are obvious: For each on the type of data used for authentication with the method, a ensures comparatively secure authentication of the subscriber will. Above all, the process is relatively easy with the existing implement funds. The method can be used where for accessing security-related services to authenticate the customer necessarily is required. With the invention, a legally binding certificate is created, legal transactions to do with the authorities with a voice call.
0008In an advantageous embodiment of the method of turning on is Authentication means automatically in the line between the two participants made. So the selection of the composition, for example, build the happen connection, since at this time the one hand the network identifier of the Sender and the addressee are known. In this case, the means of a the web located central computer (server) can be implemented, for the Plurality of subscribers some kind of personal data stocked Netzbox (Hereinafter also referred to ID box) manages. This box is the network identifier of the assigned each participant. It is possible, the authentication does not cleared directly over the box, but the need for authentication take actions on a trust center, in which the relevant data stored and perform trimming. The box is then used only as Nodes in the constructed by the sender and can connect in this role even more functions, for example, a telephone exchange, take.
0009Since the inventive method advantageously for authentication of Sender to the addressee will be used, could the Certification appropriate box will be automatically dialed once the caller by selecting a network identifier connects. Certainly is a preferred use of the invention in the telephonic communication are, as for example in the communication via e-mail, other methods for (de-) Coding respectively for authentication are possible.
0010When communicating over a network, in particular a telephone network or the Internet will be an advantageous medium for the personal authentication Voice of the operator in which it is necessarily in the context of must use telephonic communications, used. Here, the biological uniqueness of the voice as unique as a fingerprint Participant. In particular, each part has its own recognizable Sound. Just this sound is to be used according to the invention to the to allow verification respectively authentication. Advantageously, is to enable the verification in a training phase, a voiceprint created the subscriber that represents the specific properties. To discusses the participants Netzbox, the language the by on Server installed recognition program is analyzed. The results of the Analysis based on characteristic parameters in the ID box as Authentication means for subsequent comparison stored. As a means for Authentication is the use of other biometric data possible.
0011Under an initialization must be ensured that an ID box can be assigned to one person. Since the conventional relationship between the network operator and the customer, such a unique assignment can not ensure this happens Ident process advantageously direct personal contact and on presentation of an identification means, for example, the identity card. Will the participants now a certified call active, a certified e-mail, SMS, VMS, MMS or a certified fax Send or complete a transaction online, he chooses in his ID box and authenticated by his voice.
0012Advantageously, it selects the destination number via voice or via key input and the connection to the subscriber is out of the box built up. The called party receives from the box a certification release, the For example, the name, address, or social security number may include. The certification announcement may in any other way be delivered: It is possible that the ID box with a synthetic Voice signals to the called party prior to or during the establishment of the connection. Also a fax or other means (eg. As in a secure browser window) transmitted in parallel with the existing connection message is possible. Of the Recipient of an e-mail, a certificate to the appendix of the email.
0013In another embodiment, e-mails are stored in the ID box, respectively retained by the box. The dispatch takes place only after if the subscriber dialed the box and be identified with respect to the box Has. According to the participants signed a sense the email or the Transaction through his voiceprint.
0014Listed below are two embodiments of the invention with reference to FIGS 1 and 2 in greater detail. Show it:<dl tsize="7"><dt><b>figure 1</b></dt><dd>a scheme for the certification of calls and</dd><dt><b>figure 2</b></dt><dd>the certification of transactions, faxes or e-mails.</dd></dl>
0015Figure 1 illustrates schematically an application of the invention in which a first Participants 1 connects to a second party. 2 For example, this may be the call of the customer 1 at his bank 2 act, where the customer wishes to query by the call's account balances. In the line the Netzbox 3 is switched automatically by the customer Choosing the network identifier of the bank selects (Step A). The Netzbox 3 turns Now the next step B to the trust center 4 and amplify the voice of the OPERATOR 1 therethrough. are in the Trust Center 4 and the balance thus relevant for the authentication data, especially the voice sample, stored. The Trust Center 4 makes the adjustment and forwards in the case of successful authentication result as a certificate on a path 5 to the Participants 2 (step C). In a step D may the outcome of the successful authentication more information such as name, address and / or Account number are added. The bank gets below the entire Information, in particular that it is the caller really to give customers XY is. Thus, the transaction complete (step E) and the line 6, on to be held an exchange of confidential data, can by connected will.
0016The diagram of Figure 2 illustrates the scheme of authentication at an online order. First, the participants are 1 (customer) his order on a PC 7 (step A) and sends it via the data line 8 (step B). The program will be automatically intercepted by the Netzbox 3 and delayed until the customer 1 like in Netzbox 3 (Step C) and means his voice authenticated. As in the example of Figure 1 is here the authentication by means of a trust center 4 (step D). the Result, in this case for 3 Netzbox sent back (step E) and as attached Annex to the electronic order that on the way to the 9 Receiver goes. Thus, the transaction complete (Step F).
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0823701A2 | Cites | European Patent Office (EPO) | Search report |
| EP1009148A2 | Cites | European Patent Office (EPO) | Search report |
| US2003108160A1 | Cites | United States of America | Search report |
| US2003169857A1 | Cites | United States of America | Search report |
3 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 10352087 | Germany | – | |
| 10352087 | Germany | A |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| EP1530354A2This record | European Patent Office (EPO) | A2 | |
| DE10352087A1 | Germany | A1 | |
| EP1530354A3 | European Patent Office (EPO) | A3 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application refused18R | 18R | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN REFUSEDSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Designation fees paidAKX | AKX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1530354
- Application
- 40241762
Titles3
- German
- Zertifizierte Anrufe
- English
- Certified calls
- French
- Appels certifiés
Classification
- IPC, 2
- H04M3 38
- H04M3 42
Designated states33
- Contracting states, 28
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Poland
- Portugal
- Romania
and 4 moreShow fewer
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 5
- Albania
- Croatia
- Lithuania
- Latvia
- North Macedonia