EP2241085A2

Method for authentication and signature of a user in an application service using a mobile telephone as a second factor in addition to and independently from a first factor

Abstract

The invention relates to a method for the two-factor authentication of a user in an application service running on an application server (5). The authentication method is characterised in that the first authentication factor is a PIN authentication code known only by the user and the application service, and in that the second authentication factor is the mobile communication terminal (3) of the user on which is installed a reliability application obtained from a reliable third party or certified by the same, said reliability application being capable of generating, using said PIN identification code and a secret key (Ks) shared only with the reliable third party, a single use authentication code (OTP) for each authentication of the user in said application service.

EP2241085A2, drawing sheet 1
Sheet 1 of 7

Term

2.3 yearsto projected expiry

Projected expiry 27 January 2029, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    Claims of equivalent WO 2009112693 A2 CLAIMS 1. A method of two-factor autheπtification of a user with an application service running on an application server (5), characterized in that the first authentication factor is a PIN authentication code known only to the user and the Application Service, and in that the second authentication factor is the Mobile Communication Terminal (3) of the user on whom a trusted application obtained from a trusted or certified third party has been installed, said trusted application being able to generate using said PIN authentication code and a secret deed (Ks) shared only with the trusted third party, a one-time Authentication Code (OTP) for each user authentication to the Application Service.
  2. 4
    Air-authentication method according to Claim 1, characterized in that the first air-identification factor, namely the PIN authentication code, is chosen by the user and communicated to the application service in a secure manner.
  3. 7
    Air-authentication method according to any one of the preceding claims, characterized in that it comprises, prior to the authentication of the user, a step dlnsαiption of the user to the server (7) of the trusted third, said registration comprising steps of:register (2, 4, 6, 8, 10, 12) the user with the server (7) of the trusted third party;- download and install (14, 16, 18, 20, 22, 26, 28, 30) the Trusted Application in the Mobile Communication Terminal (3);- Activate (32, 34, 36, 38) said Trusted Application to make it functional for subsequent authentication operations of the user to the application server (5).
  4. 8
    Authentication method according to Claim 7, characterized in that your registration phases up to the activation of a user with a trusted third party are carried out via an application service and comprise the following steps:a step (2) of declaration of its mobile number by the user to the application service;a step (6) consisting in requesting the Application Service to register the user with the trusted third party by communicating to him the Mobile Number of the user;a step (8) of assigning to the user by the trusted third party a Code of Authenticity followed by a step (10) of sending this Code of Authenticity to the Application Service;a step (12) of communication of the Code of Authenticity to the user by the Application Service;a step (14) for sending by the trusted third party an SMS message to the user, said SMS message containing the parameters for loading and installing the trusted application on the terminal of Mobile Communication;a step (26) of loading and installing the trusted application on the mobile communication terminal of the user;- A step of activatton of the Trusted Application after verification (28,30) of the Code of Authenticity, - a step of generation by the Trusted Application of a Secret Key;a step (32) for securely transmitting the secret Qé and said parameters to the trusted third party server;a step (34) of checking the elements received by the trusted third party and initializing the user's registers;a step (36) of sending by the trusted third party an activation confirmation message to the trusted application.
  5. 13
    Authentication method according to any one of the preceding claims, characterized in that the authentication of a user using the second authentication factor comprises:a step (40) consisting of the user launching on his Mobile Communication Terminal (3) the previously activated Trust Application and entering (42,44) his PIN code on said Mobile Communication Terminal (3);a step (46) of calculating the one-time authentication code (OTP) in the mobile communication terminal (3) by means of the trusted application, to display (48) the self-identification code at single use (OTP) thus calculated on the screen of the Mobile Communication Terminal;a step (50) of asking the user to enter at the application server (5) his identifier (ID) and the one-time authentication code (OTP) thus calculated;at the level of the application server (5), a step (52) of necreating the Mobile Number and HPIN from the user's stored identifier, then calculating a reduced password (OTPj) and transmitting (54) the Mobile Number and the reduced password (OTP_r) to the server (7) of the trusted third party;at the level of the server (7) of the trusted third party, a step (56) consisting of calculating an increment value and then incrementing the value of said counter (base_rank) by the calculated increment value, then a step (58) of returning to the application server an OK signal if the Increment is greater than zero, or a signal OK otherwise;at the level of the application server (5), if the signal received from the server (7) of the trusted third party is OK, a step (62) of notifying the user that his authentication with the application service (15) is successful and if not, to notify the user that his authentication failed and deny him access to the Application Service (15).
  6. 17
    A method of signing a transaction between an application server (5) and a user previously registered and authenticated with said application server (5) according to an authentrfkation method according to any one of claims 1 to 16, characterized in that it comprises the following steps:- a step (66) of preparing at the application server (5) a "Good to execute" (BAE) representative of the transaction to be signed, followed by the transmission (68) of the "Good to execute" and the Mobile Number of the user to the server (7) of the trusted third party;a step (70) of generating at the level of the server (7) of the trusted third a random challenge, then a step (76) of preparing and sending to the mobile communication terminal (3) of the user the "good to execute "and the Challenge;- after acceptance (82) of the "Order to execute" by the user and entry of his PDSI Code, a step (84) of calculating at the level of the Trusted Application a Response (R4) to the sending of " Good to execute "by the trusted third party;- after input (88) of the Response (R4) by the user on the Application Service, calculation (90) by the Application Server of a reduced Response (Resp_r);- transmission (92) by the application server (5) of the Mobile Number and the reduced Response (Resp_r) previously calculated, to the Server (7) of the trusted third party;- At the level of the server (7) of the trusted third party, calculation (94) of a result (R6) and depending on the value of said result (R6), indicate to the application service (5) whether the user has validly signed the "Good to execute" or not.
  7. 19
    Signature method according to Claim 17, characterized in that the said reduced response (Resp_r) is calculated by the application service according to a function (F5) of H (PIN), the "good to execute", of the said response (R4).