Authentication system for electronic transactions
Abstract
The system includes a modem telephone link for an user access to the Internet (1) using a personal computer (2). A service provider server installation (3), an authentication server (4) and a short message service server (5) are connected to the internet. The short message service server is linked to a mobile telephone system (6,7). Authentication code details are sent to the user via a separate mobile telephone unit (8).

Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
7 claims: 1 independent, 6 dependent
- 1CONCLUSIES CONCLUSIONS 1. Authentication system, in which a local user authenticates to a system by entering an authentication code, via a local terminal (2), at that system, 1. Authenticatiesysteem, waarbij een lokale gebruiker zich tegenover een systeem authenticeert door het, via een lokale terminal (2), bij dat systeem invoeren van een authenticatiecode, die door dat systeem 5 validity is examined, characterized in that the authentication code is generated by a code generator (4), which on the one hand transfers the generated code to the system (3) requesting authentication, and on the other hand addresses and transfers it to a local code receiver (8 ) with its own receiving address, after which the 5 op geldigheid wordt onderzocht, met het kenmerk dat de authenticatiecode gegenereerd wordt door een codegenerator (4), die de gegenereerde code enerzijds overgedraagt aan het systeem (3) dat om athenticatie vraagt, en anderzijds adresseert en overdraagt aan een lokale code-ontvanger (8) met een eigen ontvangstadres, waarna de 10 user transmits the thus received authentication code to the system (3) requesting it. 10 gebruiker de aldus ontvangen authenticatiecode aan het daarom vragende systeem (3) overdraagt.
17 paragraphs in 3 sections, as filed
BACKGROUND OF THE INVENTION
The invention relates to an authentication system, in which a user of a system authenticates himself against that system by entering an authentication code into that system, which is examined for validity by the system.
Such an authentication system is generally known. Often alphanumeric passwords are used for authentication, which are entered by the user. If a fixed password is used, it has the drawback that the password can be stolen or copied and then misused. For that reason there are also one time password (OTP) systems, where a password is only used once.
SUMMARY OF THE INVENTION
The invention provides an OTP system in which the OTP generated by an OTP generator is transferred on the one hand to the system requesting authentication and on the other hand is transferred to the user, the OTP being addressed to a unique user address. Naturally, the transfer medium must be intruder proof. Preferably, a strictly personal user terminal is used, such as a (GSM) terminal that is equipped with a Security & Identification Module (SIM).
The invention will be explained in more detail below with reference to an exemplary embodiment.
IMPLEMENTATION EXAMPLE
Figure 1 shows very schematically an embodiment of the invention. A terminal 2, a server 3 and an authentication server 4 are connected to an IP-capable network 1 (internet). A Short Message Service (SMS) server 5 and a base station 7, which can be connected, are connected to a GSM-capable network 6. with a GSM terminal 8. Of course there are in reality many more terminals, servers etc.
The operation of the authentication system according to the invention, performed in the system shown in figure 1 is as follows.
0 0 7 4 0 9
A user connects to server 3 via terminal 2 and the internet 1 to use a service that requires authentication. To this end, the server 3 sends an HTML-coded message to the terminal, in which the user is requested to enter the telephone number of the mobile telephone 8. The server 3 sends a request to authentication server 4 to generate a (random) authentication code and have it transmitted to the user. The server 3 then sends the user the request to wait for an SMS message to be received on her mobile telephone with the requested authentication code. In the meantime, that code is generated by server 4 and sent to both SMS server 5 and server 3. The SMS server 5 sends the code, in the form of an SMS message, to the mobile telephone 8, which shows the received code on the screen. The user reads that and passes the code to the server 3 via her terminal. This compares the code received from the terminal 2 with the code received directly from the server 4. By agreement, the service requested by the user is released.
It is noted that the links between servers 3, 4 and 5 must be secure. It can be (other than the figure indicates) connections outside the IP network or realized via the IP network, but then secured, for example by firewalls etc. Server 4 can also be incorporated in server 3, which also increases security.
Instead of a telephone, other types of receivers can also be used, for example a paging receiver. However, these types of receivers are less intruder-proof today than the current GSM terminals. Nor is it necessarily necessary to use a radio receiver: any medium is suitable, provided that the link from the code generator (authentication server) to the receiver is sufficiently secure with the user. In principle, the same medium can be used as the medium with which the terminal is connected to the server (3) requesting authentication. A medium can be a secured virtual channel or a Virtual Private
Network (VPN) are used.
In the above it is proposed that the user reads the received authentication code (from the screen of her GSM device) and passes it on to the server 3 by transferring that code via her keyboard.
100 ^ 409 types. In itself it is of course nicer to send the authentication code received at the user location directly to the server 3 without having to retype it. For example, this could be done by using a local, direct data connection between the GSM receiver and data terminal 2. The data terminal can - via an appropriate application program - read in the received authentication code and pass it on to server 3. Also, the authentication code receiver 8 can be incorporated in the terminal 2. If the same medium were to be used as for the connection between the terminal 2 and the server 3, in this case the Internet 1, then such a direct transfer of the locally received authentication code is even more obvious. The process is then:
- server 3 asks terminal 2 for authentication code;
server 3 requests server 4 to generate an authentication code;
- server 4 generates an authentication code and sends it to server 3 and to a user terminal: in the above thus via GSM-SMS (server 5, network 6 and radio connection 7-8), or, alternatively, via a secure connection via the IP network 1, to the terminal 2;
- the local user accepts the received authentication code and sends it to server 3; with a direct local link, the authentication code is received locally, via GSM or via IP, and then sent by terminal 2 to server 3; in the latter case, the user therefore does not have to do anything; even the authentication process for the user may take place underwater.
Contents3
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| FR2835129A1 | Cited by | France | Search report |
| US7254390B2 | Cited by | United States of America | Applicant |
| US7283820B2 | Cited by | United States of America | Search report |
| EP1107203A3 | Cited by | European Patent Office (EPO) | Search report |
| WO2008007162A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0211082A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7177625B2 | Cited by | United States of America | Applicant |
| WO9923617A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| FR2795897A1 | Cited by | France | Search report |
| WO0159569A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US6986040B1 | Cited by | United States of America | Applicant |
| EP1361771A1 | Cited by | European Patent Office (EPO) | Search report |
| US6928420B1 | Cited by | United States of America | Search report |
| US7293176B2 | Cited by | United States of America | Applicant |
| US7702915B2 | Cited by | United States of America | Search report |
| US7203477B2 | Cited by | United States of America | Applicant |
| US6430407B1 | Cited by | United States of America | Applicant |
| WO03094560A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US6934532B2 | Cited by | United States of America | Applicant |
| EP1058872A1 | Cited by | European Patent Office (EPO) | Opposition |
| WO03063411A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0159569A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0192999A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0003316A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0078009A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7020773B1 | Cited by | United States of America | Applicant |
| US7817981B2 | Cited by | United States of America | Applicant |
| EP1104921A2 | Cited by | European Patent Office (EPO) | Search report |
| WO9923617A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0192999A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| GB2382423A | Cited by | United Kingdom | Search report |
| WO0078009A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP1104921A3 | Cited by | European Patent Office (EPO) | Search report |
| US7203485B2 | Cited by | United States of America | Applicant |
| US10567385B2 | Cited by | United States of America | Applicant |
| EP1107203A2 | Cited by | European Patent Office (EPO) | Search report |
| WO0180525A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP1058872B2 | Cited by | European Patent Office (EPO) | Opposition |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 1007409 | Netherlands (Kingdom of the) | A | |
| NL19971007409 | – | – | – |
Numbers
- Publication, DOCDB
- 1007409
- Publication, EPODOC
- NL1007409C
- Application
- 1007409
- Application, DOCDB
- 1007409
- Application, EPODOC
- NL19971007409
Titles2
- English
- Authentication system for electronic transactions
- Dutch
- Authenticatiesysteem.
Classification
- CPC, 9
- H04L63/0853
- G06Q20/04
- G06Q20/341
- G06Q20/4097
- G06Q20/425
- G07F7/1008
- H04L29/06
- H04L63/18
- H04W12/06
- IPC, 4
- G06Q20 00
- G07F7 10
- H04L29 06
- H04W12 06