EP1925113B1

Systems and methods for multi-factor remote user authentication

Abstract

This record has no abstract on file.

EP1925113B1, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Expired 15 September 2026, 0 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

14 claims: 14 independent, 0 dependent

  1. 1
    A remote user authentication device comprising:a hand-held remote user authentication card-device (12) with an interface (14) and an embedded computer logic (16), wherein the embedded computer logic (16) and the interface (14) are configured to interface the device to a network (15) for a "what you have" factor of authentication, the embedded computer logic (16) including, at least, a serial number corresponding to the card-device,the card-device (12) has a top side and a bottom side, a thumbprint sensor area (24) positioned on the top side of the card-device (12) so that when the card-device (12) is held in a hand (25) with the thumb gripping the top side and the hand's index finger gripping the bottom side, the position of the thumbprint sensor area (24) is configured to capture only a thumbprint of a holder of the card-device for a "what you are" factor of authentication,the embedded computer logic (16) in the card-device (12) transfers to the network (15) through the interface (14) an authentication record with separate "what you have" and "what you are" factors of authentication, the card-device does not store the thumbprint identity data after being transferred to the network, and the card-device (12) is configured to provide at least two-factor remote user authentication corresponding to "what you have" and "what you are" authentication factors. Dispositif d'authentification d'utilisateur à distance comprenant : un dispositif à carte d'authentification d'utilisateur à distance portatif (12) avec une interface (14) et une logique informatique intégrée (16), dans lequel la logique informatique intégrée (16) et l'interface (14) sont configurées de manière à interfacer le dispositif avec un réseau (15) pour un facteur d'authentification de type « ce que vous avez », la logique informatique intégrée (16) incluant, au moins, un numéro de série correspondant au dispositif à carte ;le dispositif à carte (12) présente une face supérieure et une face inférieure, une zone de capteur d'empreinte de pouce (24) positionnée sur la face supérieure du dispositif à carte (12) de sorte que, lorsque le dispositif à carte (12) est tenu dans une main (25) avec le pouce tenant la face supérieure et l'index de la main tenant la face inférieure, la position de la zone de capteur d'empreinte de pouce (24) est configurée de manière à capturer uniquement une empreinte de pouce du porteur du dispositif à carte pour un facteur d'authentification de type « ce que vous êtes » ;la logique informatique intégrée (16) dans le dispositif à carte (12) transfère au réseau (15), par l'intermédiaire de l'interface (14), un enregistrement d'authentification avec des facteurs d'authentification de type « ce que vous avez » et « ce que vous êtes », séparés, le dispositif à carte ne stocke pas les données d'identité d'empreinte de pouce suite au transfert au réseau, et le dispositif à carte (12) est configuré de manière à fournir au moins une authentification d'utilisateur à distance à deux facteurs correspondant aux facteurs d'authentification « ce que vous avez » et « ce que vous êtes ». Eine Fernnutzer-Authentifizierung-Vorrichtung, aufweisend: • eine Handgehalten-Fernnutzer-Authentifizierung-Kartenvorrichtung (12) mit einer Schnittstelle (14) und einer eingebetteten Computerlogik (16), wobei die eingebettete Computerlogik (16) und die Schnittstelle (14) eingerichtet sind, die Vorrichtung zu einem Netzwerk (15) zu verbinden für einen "was du hast"-Faktor der Authentifizierung, wobei die eingebettete Computerlogik (16) zumindest eine Ordnungsnummer korrespondierend zu der Kartenvorrichtung aufweist;• wobei die Kartenvorrichtung (12) eine Oberseite und eine Unterseite hat, einen auf der Oberseite der Kartenvorrichtung (12) angeordneten Daumenabdruck-Sensorbereich (24), so dass, wenn die Kartenvorrichtung (12) in einer Hand (25) mit dem Daumen die Oberseite greifend und dem Zeigefinger der Hand die Unterseite greifend gehalten wird, die Position des Daumenabdruck-Sensorbereich (24) eingerichtet ist, nur einen Daumenabdruck eines Trägers der Kartenvorrichtung für einen "Was du bist"-Faktor der Authentifizierung zu erfassen;• wobei die eingebettete Computerlogik (16) in der Kartenvorrichtung (12) eine Authentifizierungsaufzeichnung mit separaten "Was du hast" und "Was du bist"-Faktoren der Authentifizierung mittels der Schnittstelle (14) zu dem Netzwerk (15) transferiert, wobei die Kartenvorrichtung die Daumenabdruck-Identitätsdaten nicht speichert nachdem diese zu dem Netzwerk transferiert wurden, und wobei die Kartenvorrichtung (12) eingerichtet ist, eine zumindest zwei-Faktor-Fernnutzer-Authentifizierung korrespondierend zu "Was du hast" und "Was du bist" Authentifizierung-Faktoren bereitzustellen.
  2. 2
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 1, wobei die Vorrichtung in der Form von einer flachen Karte ist, die einen linken Rand und einen rechen Rand hat, wobei die Schnittstelle (14) auf dem linken Rand ist und der Sensor (24) auf der Oberseite und nahe dem rechen Rand ist. Dispositif d'authentification d'utilisateur à distance selon la revendication 1, dans lequel le dispositif est sous la forme d'une carte plate présentant un bord gauche et un bord droit, dans lequel l'interface (14) est sur le bord gauche, et le capteur (24) est sur la face supérieure et près du bord droit. The remote user authentication device of claim 1, wherein the device is in the form of a flat card having a left edge and a right edge, wherein the interface (14) is on the left edge, and the sensor (24) is on the topside and near the right edge.
  3. 3
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 1, wobei die Logik (16) und die Schnittstelle (14) eingerichtet sind, eine Kartenidentifikation und den erfassten Daumenabdruck zu dem Netzwerk (15) zu transferieren. Dispositif d'authentification d'utilisateur à distance selon la revendication 1, dans lequel la logique (16) et l'interface (14) sont configurées de manière à transférer une identification de carte et une empreinte de pouce à capturer, au réseau (15). The remote user authentication device of claim 1, wherein the logic (16) and of the interface (14) are configured to transfer a card identification and be captured thumbprint to the network (15).
  4. 4
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 3, wobei die Logik eingerichtet ist, eine Erfassung des Daumenabdrucks zu starten, wenn und nicht bevor die Kartenvorrichtungen mit dem Netzwerk verbunden ist, und bis zu dem Transfer zu dem Netzwerk in dem temporären Speicher der Logik zu halten, wobei die Vorrichtung den Daumenabdruck nicht hält ausgenommen für einen kurzen Zeitpunkt. Dispositif d'authentification d'utilisateur à distance selon la revendication 3, dans lequel la logique est apte à commencer la capture d'empreinte de pouce lorsque les dispositifs à carte s'interfacent avec le réseau, et non pas avant, et à la conserver, dans la mémoire temporaire de la logique, jusqu'au transfert au réseau, moyennant quoi le dispositif ne conserve pas l'empreinte de pouce, hormis pendant un bref instant. The remote user authentication device of claim 3, wherein the logic is adapted to begin thumbprint capture when the card-devices interfaced with the network and not before and hold in the temporary memory of logic until the transfer to the network, whereby the device does not hold the thumbprint except for a brief moment in time.
  5. 5
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 1, wobei die Vorrichtung einen Funkuhr-Sensor aufweist und einen Mechanismus-Chip, eingerichtet, die Zeit der Vorrichtungsbenutzung zu berechnen diese Zeit als Teil der Authentifizierungsaufzeichnung mittels der Schnittstelle zu einer Netzwerk-Vorrichtung zu transferieren als ein Mittel von Sicherheitsgarantie. Dispositif d'authentification d'utilisateur à distance selon la revendication 1, dans lequel le dispositif comprend un capteur d'horloge radio et une puce de mécanisme configurés de manière à calculer le temps d'utilisation de dispositif et à transférer ce temps dans le cadre de l'enregistrement d'authentification par l'intermédiaire de l'interface, à un dispositif de réseau, en tant que moyen de garantie de sécurité. The remote user authentication device of claim 1, wherein the device comprises a radio clock sensor and a mechanism chip configured to compute the time of device use and transfer such time as part of the authentication record via the interface to a network device, as a means of security assurance.
  6. 6
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 1, wobei die Kartenvorrichtung (12) einen eingebetteten GPS-Funktion-Chip aufweist, eingerichtet zu ermöglichen, den Standort der Kartenvorrichtung (12) heraus zu transferieren aus der Kartenvorrichtung als ein zusätzlicher "Wo du bist"-Faktor der Authentifizierung in der Authentifizierungsaufzeichnung. Dispositif d'authentification d'utilisateur à distance selon la revendication 1, dans lequel le dispositif à carte (12) comprend une puce de fonction GPS intégrée configurée de manière à permettre le transfert de l'emplacement du dispositif à carte (12) hors du dispositif à carte, sous la forme d'un facteur d'authentification supplémentaire de type « où vous êtes » dans l'enregistrement d'authentification. The remote user authentication device of claim 1, wherein the card-device (12) comprises an embedded GPS function chip configured to enable the location of the card-device (12) to be transferred out of the card-device as an additional "where you are" factor of authentication in the authentication record.
  7. 7
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 1, wobei die Vorrichtung mit einem RFID-Mechanismus-Chip eingerichtet ist, welcher die Vorrichtung mittels der Ordnungsnummer identifiziert, wobei die Vorrichtung Standort-nachverfolgt werden kann, wenn kontrollierte Bereiche, wie einen Flughafen, betretend und verlassend. Dispositif d'authentification d'utilisateur à distance selon la revendication 1, dans lequel le dispositif est adapté avec une puce de mécanisme d'identification RFID qui identifie le dispositif par le numéro de série, dans lequel le dispositif peut être suivi à des fins de localisation lorsqu'il entre et sort de zones contrôlées, par exemple d'un aéroport. The remote user authentication device of claim 1, wherein the device is adapted with an RFID mechanism chip that identifies the device by the serial number, wherein the device may be tracked for location when entering and leaving controlled areas such as an airport.
  8. 8
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 1, wobei die Schnittstelle aus einer Gruppe aus verkabelt, optisch und kurz-Reichweite-kabellos ist. Dispositif d'authentification d'utilisateur à distance selon la revendication 1, dans lequel l'interface fait partie d'un groupe d'interfaces câblées, optiques et sans fil à courte distance. The remote user authentication device of claim 1, wherein the interface is from a group of, wired, optical, and short distance wireless.
  9. 9
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß einem vorangegangen Anspruch, wobei die Kartenvorrichtung mit einem Eingabe-und-Anzeige-Mittel eingerichtet ist, und wobei die Logik eingerichtet ist, eine Eingabe und Anzeige einer PIN in einen temporären Speicher der Logik zu ermöglichen, wobei die PIN ein "Was du weißt"-Faktor der Authentifizierung ist, wobei die eingebettete Computerlogik (16) in der Kartenvorrichtung (12) eine Authentifizierungsaufzeichnung mit separaten "Was du hast", "Was du weißt", und "Was du bist"-Faktoren der Authentifizierung zu dem Netzwerk (15) mittels der Schnittstelle (14) transferiert, wobei die Kartenvorrichtung die Daumenabdruck-Identitäts- und PIN-Daten nach dem Transfer zu dem Netzwerk nicht speichert, wobei die Kartenvorrichtung (12) eingerichtet ist, zumindest eine drei-Faktor-Fernnutzer-Authentifizierung korrespondierend zu "Was du hast", "Was du bist", und "was du weißt" Authentifizierung-Faktoren bereitzustellen. Dispositif d'authentification d'utilisateur à distance selon l'une quelconque des revendications précédentes, dans lequel le dispositif à carte est adapté avec un moyen de saisie et d'affichage, et la logique est configurée de manière à permettre la saisie et l'affichage d'un code PIN dans une mémoire temporaire de la logique, dans lequel le code PIN est un facteur d'authentification de type « ce que vous savez », la logique informatique intégrée (16) du dispositif à carte (12) transfert au réseau (15), à travers l'interface (14), un enregistrement d'authentification avec des facteurs d'authentification de type « ce que vous avez », « ce que vous savez » et « ce que vous êtes », séparés, le dispositif à carte ne stocke pas l'identité d'empreinte de pouce et les données de code PIN après le transfert au réseau, le dispositif à carte (12) est configuré de manière à fournir une authentification d'utilisateur à distance à au moins trois facteurs, correspondant aux facteurs d'authentification « ce que vous avez », « ce que vous êtes » et « ce que vous savez ». The remote user authentication device of any preceding claim wherein the card-device is adapted with an entry and display means and the logic is configured to enable entry and display of a PIN into a temporary memory of the logic, wherein the PIN is a "what you know" factor of authentication, the embedded computer logic (16) in the card device (12) transfers to the network (15) through the interface (14) an authentication record with separate "what you have", "what you know", and "what you are" factors of authentication, the card-device does not store thumbprint identity and PIN data after the transfer to the network, the card-device (12) is configured to provide at least three-factor remote user authentication corresponding to "what you have", "what you are", and "what you know" authentication factors.
  10. 10
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 9, wobei die Vorrichtung eine Mehrzahl von elektronischen Drehschaltern aufweist, welche eine alphanumerische Eingabe der PIN ohne eine Tastatur ermöglichen. Dispositif d'authentification d'utilisateur à distance selon la revendication 9, dans lequel le dispositif comprend une pluralité de commutateurs rotatifs électroniques qui permettent la saisie alphanumérique du code PIN sans clavier. The remote user authentication device of claim 9, wherein the device comprises a plurality of electronic rotary switches that enable alphanumeric entry of the PIN without a keypad.
  11. 11
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 9, wobei die Logik mit einem heuristischen kartenspezifischen Algorithmus eingebettet ist, welcher die temporär gespeicherte PIN in einen temporär gespeicherten Verschlüsselungsschlüssel transformiert. Dispositif d'authentification d'utilisateur à distance selon la revendication 9, dans lequel la logique est intégrée avec un algorithme heuristique spécifique à la carte qui transforme le code PIN stocké temporairement en une clé de chiffrement stockée temporairement. The remote user authentication device of claim 9 wherein the logic is embedded with a heuristic card-specific algorithm that transforms the temporary stored PIN into a temporary stored encryption key.
  12. 12
    Die Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 11, wobei die Logik den Verschlüsselungsschlüssel verwendet, um die Authentifizierungsaufzeichnung zu verschlüsseln, und die mittels der Karte-Ordnungsnummer entstandenen verschlüsselten Authentifizierungsaufzeichnung-Daten mittels des Schnittstelle-Mittels zu dem Netzwerk transferiert. Dispositif d'authentification d'utilisateur à distance selon la revendication 11, dans lequel la logique utilise la clé de chiffrement pour chiffrer l'enregistrement d'authentification, et transfère les données d'enregistrement d'authentification chiffrées occasionnées par le numéro de série de carte, par l'intermédiaire du moyen d'interface, au réseau. The remote user authentication device of claim 11, wherein the logic uses the encryption key to encrypt the authentication record and transfers the encrypted authentication record data incurred by the card serial number via the interface means to the network.
  13. 13
    A method of remote user authentication comprising the steps of:a. entering a PIN in a remote user authentication device according to claim 9;b. converting the PIN into an encryption key using a card-specific algorithm and then deleting the PIN;c. encrypting and authentication record using the key and then deleting the key;andd. transferring the encrypted record to a network device for forwarding the record by the network device to an authentication server. Procédé d'authentification d'utilisateur à distance comprenant les étapes ci-dessous consistant à : a. saisir un code PIN dans un dispositif d'authentification d'utilisateur à distance selon la revendication 9 ;b. convertir le code PIN en une clé de chiffrement à l'aide d'un algorithme spécifique à la carte, et supprimer le code PIN ;c. chiffrer un enregistrement d'authentification en utilisant la clé, et supprimer la clé ;etd. transférer l'enregistrement chiffré à un dispositif de réseau en vue d'acheminer l'enregistrement, par le biais du dispositif de réseau, à un serveur d'authentification. Verfahren einer Fernnutzer-Authentifizierung, aufweisend die Schritte von: a. Eingeben einer PIN in eine Fernnutzer-Authentifizierung-Vorrichtung gemäß Anspruch 9;b. Umwandeln der PIN in einen Verschlüsslungsschlüssel unter Verwendung eines kartenspezifischen Algorithmus und dann Löschen der PIN;c. Verschlüsseln der Authentifizierungsaufzeichnung unter Verwendung des Schlüssels und dann Löschen des Schlüssels;undd. Transferieren der verschlüsselten Aufzeichnung zu einer Netzwerk-Vorrichtung zum Weiterleiten der Aufzeichnung von der Netzwerk-Vorrichtung zu einem Authentifizierung-Server.
  14. 14
    Das Verfahren gemäß Anspruch 13, aufweisend die Schritte von:a. Empfangen der Authentifizierungsaufzeichnung;b. Wiederherstellen des Verschlüsslungsschlüssels aus der PIN und dem kartenspezifischen Algorithmus, die in einer Authentifizierung-Datenbank vorgespeichert sind;c. Entschlüsseln der Authentifizierungsaufzeichnung unter Verwendung des Schlüssels;d. Verifizieren der Authentifizierungsaufzeichnung mit den vorgespeicherten Daten. Procédé selon la revendication 13, comprenant les étapes ci-dessous consistant à : a. recevoir l'enregistrement d'authentification ;b. recréer la clé de chiffrement à partir du code PIN et de l'algorithme spécifique à la carte stockés au préalable dans une base de données d'authentification;c. déchiffrer l'enregistrement d'authentification en utilisant la clé ;etd. vérifier l'enregistrement d'authentification avec les données stockées au préalable. The method of claim 13, comprising the steps of: a. receiving the authentication record;b. re-creating the encryption key from the PIN and the card specific algorithm pre-stored in an authentication database;c. decrypting the authentication record using the key;d. verifying the authentication record with the pre-stored data.
Independent claims14