Nova Patents
EP4333554A2

Authentication method

Abstract

A method of authenticating a user to a transaction at a terminal (10), wherein a user identification is transmitted from the terminal (10) to a transaction partner (12) via a first communication channel (14), and an authentication device (18) uses a second communication channel (20) for checking an authentication function that is implemented in a mobile device (16) of the user, and, as a criterion for deciding whether the authentication to the transaction shall be granted or denied, the authentication device (18) checks whether a predetermined time relation exists between the transmission of the user identification and a response from the second communication channel, characterized in that the authentication function is normally inactive and is activated by the user only preliminarily for the transaction, said response from the second communication channel (20) includes the information that the authentication function is active, and the authentication function is automatically deactivated.

EP4333554A2, drawing sheet 1
Sheet 1 of 5

Term

Projected expiry 30 October 2032.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 15 independent, 0 dependent

  1. 1
    A method of authenticating a user to a transaction at a terminal (10), the method comprising the following steps:- receiving at an authentication device (18) from a transaction partner (12) a transmission of a user identification that was transmitted from a terminal (10) to the transaction partner (12) via a first communication channel (14), - using a second communication channel (20), in conjunction with a mobile device (16) of the user, for checking an authentication function that is implemented in an applet on the mobile device (16) and is normally inactive and is activated by the user only preliminarily for the transaction, - as a criterion for deciding whether the authentication to the transaction shall be granted or denied, the authentication device (18) checks whether a predetermined time relation exists between the transmission of the user identification and a current active state of the authentication function, and, - if said criterion for granting the authentication is fulfilled, the authentication device (18) sends an authentication signal to the transaction partner, - characterized in that the mobile device (16) of the user permits the authentication device to detect, via the second communication channel (20), whether or not the authentication function is active, and in that , based on the user identification, the authentication device (18) checks the active state of the authentication function in the mobile device (16) and, if the authentication function is active, the authentication device (18) receives a response via the second communication channel, said response including the information that the authentication function is active, and - wherein the authentication function is automatically deactivated after a predetermined time interval after its activation and/or when its active state has been checked.
  2. 2
    A method of authenticating a user to a transaction at a terminal (10), the method comprising the following steps:- receiving at an authentication device (18) from a transaction partner (12) a transmission of a user identification that was transmitted from a terminal (10) to the transaction partner (12) via a first communication channel (14) - using a second communication channel (20), in conjunction with a mobile device (16) of the user, for checking an authentication function that is implemented in an applet on the mobile device (16) and is normally inactive and is activated by the user only preliminarily for the transaction by interacting with a biometric sensor of the mobile device (16), - as a criterion for deciding whether the authentication to the transaction shall be granted or denied, the authentication device (18) checks whether a predetermined time relation exists between the transmission of the user identification and a current active state of the authentication function, and, - if said criterion for granting the authentication is fulfilled, the authentication device (18) sends an authentication signal to the transaction partner, - characterized in that the mobile device (16) of the user permits the authentication device to detect, via the second communication channel (20), whether or not the authentication function is active, and in that , based on the user identification, the authentication device (18) checks the active state of the authentication function in the mobile device (16) and, if the authentication function is active, the authentication device (18) receives a response via the second communication channel, said response including the information that the authentication function is active, and - wherein the authentication function is automatically deactivated after a predetermined time interval after its activation and/or when its active state has been checked.
  3. 3
    A method of authenticating a user to a transaction at a terminal (10), the method comprising the following steps:- a user identification is transmitted from the terminal (10) to a transaction partner (12) via a first communication channel (14), - the transaction partner (12) forwards the user identification to an authentication device (18), - using a second communication channel (20), in conjunction with a mobile device (16) of the user, for checking an authentication function that is implemented in an applet on the mobile device (16) and is normally inactive and is activated by the user only preliminarily for the transaction, - as a criterion for deciding whether the authentication to the transaction shall be granted or denied, the authentication device (18) checks whether a predetermined time relation exists between the transmission of the user identification and an active state of the authentication function, and, - if said criterion for granting the authentication is fulfilled, the authentication device (18) sends an authentication signal to the transaction partner, - wherein the mobile device (16) of the user permits the authentication device to detect, via the second communication channel (20), whether or not the authentication function is active, and , based on the user identification, the authentication device (18) checks the active state of the authentication function in the mobile device (16) and, if the authentication function is active, the authentication device (18) receives a response via the second communication channel, said response including the information that the authentication function is active, and - wherein the authentication function is automatically deactivated after a predetermined time interval after its activation and/or when its active state has been checked.
  4. 4
    The method according to any of the preceding claims, wherein the authentication function is implemented in an applet on the mobile device (16) and the authentication function can be activated and deactivated independently of the mobile device as a whole.
  5. 5
    The method according to any of the preceding claims, wherein the authentication function receives authentication data from the authentication device (18) and responds to the authentication device.
  6. 6
    The method according to any of the preceding claims, wherein the authentication device (18) determines a current location of the mobile device (16) and denies the authentication of the user when the locations of the terminal (10) and of the mobile device (16) do not fulfil a predetermined spatial relationship.
  7. 7
    The method according to any of the preceding claims, wherein the authentication device (18) is remote from the transaction partner (12) and communicates with the transaction partner via a third communication channel (22), and wherein information linking the user identification to an address of the mobile device (16) is stored only in the authentication device (18), and the authentication device notifies to the transaction partner (12) whether or not the user is authenticated.
  8. 8
    The method according to any of the preceding claims, wherein a password is transmitted to the transaction partner (12) via the authentication device (18).
  9. 9
    The method according to any of the preceding claims, wherein the mobile device (16) is interfaced to an identity token of the user to read identity data therefrom.
  10. 10
    The method according to any of the preceding claims, wherein as a criterion for deciding whether the authentication to the transaction shall be granted or denied, the authentication device (18) and/or the authentication applet checks whether a required code was entered into the mobile device (16).
  11. 11
    The method according to any of the preceding claims, wherein the authentication device (18) compares recent mobile device identifying data with prestored mobile device identifying data.
  12. 12
    The method according to any of the preceding claims, wherein the user is shown terminal (10) identifying data on the mobile device (16).
  13. 13
    The method according to any of the preceding claims, wherein encryption parameters are send from the authentication device (18) to the mobile device (16) and an identification code is returned by the mobile device (16) accordingly.
  14. 14
    The method according to any of the preceding claims, wherein the terminal (10) and the mobile device (16) are the same apparatus (30).
  15. 15
    The method according to any of the preceding claims, wherein the first communication channel (14) and the second communication channel (20) are both part of the same network, but separated by technical means.
Independent claims15