Secure transaction authentication
15 claims: 7 independent, 8 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method for authenticating a secure transaction to be performed between a secure transaction host (15) and a user (9) performing the transaction, the method being performed by an authentication service provider and comprising the following steps:1. Sposób uwierzytelniania bezpiecznej transakcji do przeprowadzenia między hostem (15) bezpiecznej transakcji a użytkownikiem (9) przeprowadzającym transakcję, przy czym sposób jest wykonywany przez dostawcę usługi uwierzytelniania i obejmuje następujące etapy: odbieranie żądania uwierzytelnienia z hosta (15) bezpiecznej transakcji;receiving an authentication request from a secure transaction host (15);odebranie identyfikatora cyfrowego (13) zawierającego identyfikator sprzętowy z przenośnego urządzenia komunikacyjnego (7) powiązanego z użytkownikiem (9) przeprowadzającym transakcję, za pomocą którego przenośne urządzenie komunikacyjne może być niepowtarzalnie zidentyfikowane, przy czym identyfikator cyfrowy (13) został utworzony, bez interwencji użytkownika, przez aplikację uwierzytelniania (59) zainstalowaną w przenośnym urządzeniu komunikacyjnym, jako funkcja identyfikatora sprzętowego i co najmniej liczby losowej utworzonej przez aplikację uwierzytelniania, tak że identyfikator cyfrowy (13) nie może zostać odtworzony bez przenośnego urządzenia komunikacyjnego użytkownika (9), a zatem ustanawiając relację jeden do jednego między identyfikatorem cyfrowym a przenośnym urządzeniem komunikacyjnym (7) użytkownika (9), przy czym identyfikator cyfrowy (13) jest przechowywany w bezpiecznej lokacji przechowywania (65) w przenośnym urządzeniu komunikacyjnym, z której może być on pobrany jedynie przez autoryzowane aplikacje, w tym aplikację uwierzytelniania (59);receiving a digital identifier (13) including a hardware identifier from a portable communication device (7) associated with a user (9) carrying out a transaction, by which the portable communication device can be uniquely identified, the digital identifier (13) having been created without user intervention, by an authentication application (59) installed on a portable communication device, as a function of the hardware identifier and at least a random number formed by the authentication application, such that the digital identifier (13) cannot be reconstructed without the user portable communication device (9), thus establishing a one-to-one relationship between the digital identifier and the portable communication device (7). ) user (9), wherein the digital identifier (13) is stored in a secure storage location (65) on the portable communication device from which it can only be retrieved by authorized applications, including an authentication application (59);comparing the digital identifier (13) with a list of digital identifiers associated with portable communication devices previously stored porównywanie identyfikatora cyfrowego (13) z listą identyfikatorów cyfrowych powiązanych z przenośnymi urządzeniami komunikacyjnymi zapisanych wcześniej 59P41149PL00 59P41149PL00 EP 2 368 339 BI użytkowników, przechowywaną w bazie danych (5) powiązanej z dostawcą usługi uwierzytelniania;Users, stored in a database (5) associated with the authentication service provider;if the received digital identifier (13) corresponds to the digital identifier stored in the database (5), enabling a secure communication connection to be established between the portable communication device (7) of the user (9) performing the transaction and the authentication service provider, the secure communication connection being initiated from the application authenticating (59) at the portable communication device (7);jeżeli odebrany identyfikator cyfrowy (13) odpowiada identyfikatorowi cyfrowemu przechowywanemu w bazie danych (5), umożliwianie nawiązania bezpiecznego połączenia komunikacyjnego między przenośnym urządzeniem komunikacyjnym (7) użytkownika (9) przeprowadzającego transakcję a dostawcą usługi uwierzytelniania, przy czym bezpieczne połączenie komunikacyjne jest inicjowane z aplikacji uwierzytelniania (59) w przenośnym urządzeniu komunikacyjnym (7);transmitowanie żądania potwierdzenia transakcji do przenośnego urządzenia komunikacyjnego (7) użytkownika (9) przeprowadzającego transakcję przez bezpieczne połączenie komunikacyjne, przy czym żądanie wymaga od użytkownika (9) potwierdzenia lub odrzucenia jego zamierzonego wykonania bezpiecznej transakcji;transmitting a transaction confirmation request to the portable communication device (7) of the user (9) performing the transaction over the secure communication link, the request requiring the user (9) to confirm or deny its intended execution of a secure transaction;odbieranie wyniku potwierdzenia lub odrzucenia z przenośnego urządzenia komunikacyjnego (7);receiving an acknowledgment or rejection result from the portable communication device (7);in response to the acknowledgment result, transmitting the positive authentication result to the secure transaction host (15);and in response to the rejection result, transmitting the negative authentication result to the secure transaction host (15). w odpowiedzi na wynik potwierdzenia, transmitowanie pozytywnego wyniku uwierzytelnienia do hosta (15) bezpiecznej transakcji;oraz w odpowiedzi na wynik odrzucenia, transmitowanie negatywnego wyniku uwierzytelnienia do hosta (15) bezpiecznej transakcji.
- 4A system (1) for authenticating a secure transaction between a transacting user (9) and a secure transaction host (15), the system comprising:4. System (1) do uwierzytelniania bezpiecznej transakcji przeprowadzanej między użytkownikiem (9) przeprowadzającym transakcję a hostem (15) bezpiecznej transakcji, przy czym system zawiera: an authentication application (59) of the portable communication device configured to be installed on the portable communication device (7) to create, without user intervention, a digital identifier (13) comprising a hardware identifier from the portable communications device, and wherein the digital identifier is formed as a function of the hardware identifier and at least a random number generated by the authentication application, such that the digital identifier cannot be retrieved without the user portable communication device (9), so as to establish a one-to-one association between the digital identifier and the user portable communication device (7) (9), and through which the portable communication device (7) is established. which the authentication application is installed on (59) can be uniquely identified, and to save and retrieve the digital identifier (13) from the secure storage location (65) to the portable communication device (7), wherein the digital identifier (13) can be retrieved from the secure storage location (65) only by authorized applications including application authentication (59);and an authentication service provider comprising at least one authentication server (3) and an associated authentication database (5);aplikację uwierzytelniania (59) przenośnego urządzenia komunikacyjnego skonfigurowaną do zainstalowania w przenośnym urządzeniu komunikacyjnym (7), aby utworzyć, bez interwencji użytkownika, identyfikator cyfrowy (13) zawierający identyfikator sprzętowy z przenośnego urządzenia komunikacyjnego i przy czym identyfikator cyfrowy jest tworzony jako funkcja identyfikatora sprzętowego i co najmniej liczby losowej wygenerowanej przez aplikację uwierzytelniania, tak że identyfikator cyfrowy nie może zostać odtworzony bez przenośnego urządzenia komunikacyjnego użytkownika (9), tak aby ustanowić powiązanie jeden do jednego między identyfikatorem cyfrowym a przenośnym urządzeniem komunikacyjnym (7) użytkownika (9), i przez który przenośne urządzenie komunikacyjne (7), na którym zainstalowana jest aplikacja uwierzytelniania (59), może być niepowtarzalnie zidentyfikowane, i aby zapisywać i odzyskiwać identyfikator cyfrowy (13) wiz bezpiecznej lokacji przechowywania (65) w przenośnym urządzeniu komunikacyjnym (7), przy czym identyfikator cyfrowy (13) może być odzyskany z bezpiecznej lokacji przechowywania (65) jedynie przez autoryzowane aplikacje, w tym aplikację uwierzytelniania (59);oraz dostawcę usługi uwierzytelniania zawierającego co najmniej jeden serwer uwierzytelniania (3) i powiązaną z nim bazę danych uwierzytelniania (5);przy czym serwer uwierzytelniania (3) jest skonfigurowany do zapisywania użytkowników poprzez rejestrację co najmniej identyfikatorów cyfrowych (13), utworzonych przez aplikację uwierzytelniania (59) wherein the authentication server (3) is configured to store users by registering at least digital identifiers (13) created by the authentication application (59) 59P41149PL00 59P41149PL00 ΕΡ 2 368 339 BI installed in their portable communication devices, in the authentication database (5), each digital identifier (13) being uniquely capable of identifying the portable communication device on which it has been created;for receiving an authentication request from a secure transaction host (15);for receiving the digital identifier (13) from the portable communication device (7) of the user (9) performing the transaction;for comparing the received digital identifier (13) with a list of digital identifiers associated with pre-stored portable communication devices of users stored in the database (5);for allowing, if the received digital identifier (13) corresponds to the digital identifier stored in the database (5), to establish a secure communication connection between the portable communication device (7) of the user (9) performing the transaction and the authentication server (3), the secure connection being the communication is initiated from the authentication application (59) in the portable communication device (7);for transmitting a transaction confirmation request to the portable communication device (7) of the user (9) performing the transaction over the secure communication link, requiring the user (9) to acknowledge or deny its intended execution of a secure transaction;for receiving an acknowledgment or rejection result from the portable communication device (7) of the user (9) performing the transaction;and for transmitting the positive authentication result to the secure transaction host (15) in response to the result ΕΡ 2 368 339 BI zainstalowaną w ich przenośnych urządzeniach komunikacyjnych, w bazie danych uwierzytelniania (5), przy czym każdy identyfikator cyfrowy (13) jest niepowtarzalnie zdolny do identyfikacji przenośnego urządzenia komunikacyjnego, w którym został utworzony;do odbierania żądania uwierzytelnienia z hosta (15) bezpiecznej transakcji;do odbierania identyfikatora cyfrowego (13) z przenośnego urządzenia komunikacyjnego (7) użytkownika (9) przeprowadzającego transakcję;do porównywania odebranego identyfikatora cyfrowego (13) z listą identyfikatorów cyfrowych powiązanych z przenośnymi urządzeniami komunikacyj nymi zapisanych wcześniej użytkowników, przechowywaną w bazie danych (5);do zezwalania, jeżeli odebrany identyfikator cyfrowy (13) odpowiada identyfikatorowi cyfrowemu przechowywanemu w bazie danych (5), na nawiązanie bezpiecznego połączenia komunikacyjnego między przenośnym urządzeniem komunikacyjnym (7) użytkownika (9) przeprowadzającego transakcję a serwerem uwierzytelniania (3), przy czym bezpieczne połączenie komunikacyjne jest inicjowane z aplikacji uwierzytelniania (59) w przenośnym urządzeniu komunikacyjnym (7);do transmitowania żądania potwierdzenia transakcji do przenośnego urządzenia komunikacyjnego (7) użytkownika (9) przeprowadzającego transakcję przez bezpieczne połączenie komunikacyjne, wymagającego od użytkownika (9) potwierdzenia lub odrzucenia jego zamierzonego wykonania bezpiecznej transakcji;do odbierania wyniku potwierdzenia lub odrzucenia z przenośnego urządzenia komunikacyjnego (7) użytkownika (9) przeprowadzającego transakcję;i do transmitowania pozytywnego wyniku uwierzytelnienia do hosta (15) bezpiecznej transakcji w odpowiedzi na wynik 59P41149PL00 59P41149PL00 An acknowledgment and a negative authentication result in response to the rejection result. EP 2 368 339 BI potwierdzenia i negatywnego wyniku uwierzytelnienia w odpowiedzi na wynik odrzucenia.
- 7System according to any of claims 4 to 6, wherein the storage location (65) on the portable communication device (7) is secure and accessible to an application (59) by means of the digital rights management feature of an operating system running on the portable communication device (7). 7. System według dowolnego z zastrzeżeń od 4 do 6, w którym lokacja przechowywania (65) w przenośnym urządzeniu komunikacyjnym (7) jest bezpieczna i dostępna dla aplikacji (59) za pomocą właściwości zarządzania prawami cyfrowymi systemu operacyjnego działającego w przenośnym urządzeniu komunikacyjnym (7).
- 9System according to any of claims 4 to 8, wherein the application (59) is configured to periodically create a new digital identifier using the IMEI number of the portable communication device, the IMSI number of the SIM card used in the portable communication device and the newly generated random number. 9. System według dowolnego z zastrzeżeń od 4 do 8, w którym aplikacja (59) jest skonfigurowana do okresowego tworzenia nowego identyfikatora cyfrowego z wykorzystaniem numeru IMEI przenośnego urządzenia komunikacyjnego, numeru IMSI karty SIM używanej w przenośnym urządzeniu komunikacyjnym i nowo wygenerowanej liczby losowej. 59P41149PL00 59P41149PL00 ΕΡ 2 368 339 BI ΕΡ 2 368 339 BI
- 11System according to any of claims 4 to 10, wherein a write access key is created and assigned to the user (9) when an application (59) is downloaded to his portable communication device (7), the write access key enabling the user to be stored on the server. authentication (3). 11. System według dowolnego z zastrzeżeń od 4 do 10, w którym klucz dostępu zapisu jest tworzony i przypisywany użytkownikowi (9), gdy aplikacja (59) jest pobierana do jego przenośnego urządzenia komunikacyjnego (7), przy czym klucz dostępu zapisu umożliwia użytkownikowi zapisanie na serwerze uwierzytelniania (3).
- 12The system according to any of claims 4 to 11, which comprises an authentication network server (21) via which clients or client applications can connect to the authentication server (3). 12. System według dowolnego z zastrzeżeń od 4 do 11, który zawiera serwer sieciowy uwierzytelniania (21), za pomocą którego klienci lub aplikacje klientów mogą łączyć się z serwerem uwierzytelniania (3).
- 13System according to any of claims 4 to 12, wherein the application (59) is configured to trigger a corresponding alarm and display a pop-up message that appears on the screen of the portable communication device (7) of the user (9) performing the transaction in response to an acknowledgment or rejection from the authentication server (3), wherein the pop-up message requires the user (9) to confirm or decline his intended execution of a secure transaction by pressing a button. 13. System według dowolnego z zastrzeżeń od 4 do 12, w którym aplikacja (59) jest skonfigurowana do uruchamiania odpowiedniego alarmu i wyświetlania wyskakującego komunikatu, który pojawia się na ekranie przenośnego urządzenia komunikacyjnego (7) użytkownika (9) przeprowadzającego transakcję w odpowiedzi na żądanie potwierdzenia lub odrzucenia z serwera uwierzytelniania (3), przy czym wyskakujący komunikat wymaga od użytkownika (9) potwierdzenia lub odrzucenia jego zamierzonego wykonania bezpiecznej transakcji poprzez naciśnięcie przycisku.
Independent claims7
79 paragraphs in 31 sections, as filed
FIELD OF THE INVENTION
[0001] The present invention relates to a method for authenticating secure transactions. More specifically, but not exclusively, the invention relates to a method of authenticating the identity of users who perform secure transactions, in particular, secure online transactions.
[0002] The invention includes a user authentication system and a platform for use by clients requiring user authentication.
BACKGROUND OF THE INVENTION
[0003] Passwords and access keys are commonly used to control authorized access to electronic media such as computer programs or websites such as bank websites. Often, when a user wants to be authorized access to a program / website, the user has to enter an identifying login (username) and a secret password. They are then compared with the records in the secure database by the program / website, and access is only allowed if the login and password match the record in the database. Using such an identification login and password to control authorized access is known as one factor authentication.
[0004] Password protected resources in computer networks such as the Internet range from the simplest services, for example, managing your e-mail subscription list, to services requiring high-level encryption and protection, such as trading wallets and banking services. Together with
59P41149PL00
ΕΡ 2 368 339 BI with the development of technology and the rapid growth of unscrupulous operators, especially in the Internet area, the protection of these sensitive resources solely with a username and password has become insufficient and, in fact, less and less. The main disadvantage of a simple password is that knowing this single, vital piece of information can give anyone, anywhere, anytime, unauthorized access to the sensitive data it is designed to protect.
[0005] One-factor authentication thus provides relatively weak protection as it relies on the user keeping his login ID and password secret. In addition, so-called "keyboard recording software" has been developed, which can be installed on a computer as a so-called "spy program for recording all keyboard strokes made by the user on the computer keyboard. Such spyware, which is often secretly installed by criminals on computers in public places such as internet cafes, allows third parties to secretly store the user's identification login and password and use them later to gain unauthorized access to the user's secure information. Thus, this is a relatively easy way to bypass one-factor authentication.
[0006] To the applicant's knowledge, recent attempts to improve security have used users' mobile phones as it is assumed that there is a one-to-one relationship between the user and his mobile phone. When using this technology, it is assumed that the phone is always in the user's possession. Short text messages (SMS) are currently the preferred delivery mechanism for security messages and generally take the form of a text message sent by a service provider (on
59P41149PL00
(E.g. banking institution) to the user's mobile phone. The message usually contains a single, unique, one-time password (OTP) pin, which the user then has to manually enter in the secure environment to which he wants to access or before executing a secure transaction, along with his usual login details. Even though this technology offers an additional level of security, it is still susceptible to abuse by techniques such as SIM cloning. It also still requires the user to enter an 8-digit code from a mobile phone on a website or elsewhere in a secure transaction that he or she wishes to perform. Another disadvantage of this technology is the relatively high associated cost for the secure transaction host institution as it has to send an SMS through the GSM network provider every time user authentication is required. Authentication may take place many times during any one session and each such message will be added to the account separately by the GSM network provider.
[0007] US 2004/0097217 discloses an authorization and authentication method and system based on hardware specific information of a mobile device registered on a trusted server in association with a user-related credential.
[0008] There are also fully offline solutions where the access key is randomly generated by the digital portable device every time a user wishes to make a secure transaction. The access key is usually a meaningless hash number generated according to some fixed algorithm or private key that is stored on the device, and which the secure environment can recognize as coming from an authorized device. This solution entails an initial hardware cost for the issuing institution (in most cases for banks), a
59P41149PL00
The user is forced to carry additional equipment with him. Moreover, this technology still requires the user to enter a sometimes long and complicated access key before being allowed to execute a secure transaction. Since errors in rewriting the access key from a digital mobile device will result in the transaction being rejected, this usually causes significant delays in the transaction time as the user has to rewrite the access key very carefully. This solution is, however, also vulnerable to various security threats. The fact that it is fully offline makes it vulnerable to abuse without the user's knowledge. Also, if a key generating device (OTP) is stolen, the thief will have the device that generates the real OTP, and all the thief needs is a real username and password that can be easily obtained by spyware or other means.
[0009] Existing authentication systems known to the applicant thus use either one-factor authentication (username and password) or offline two-factor authentication (as described in the two preceding paragraphs) to protect sensitive information. Two-factor authentication (T-FA) typically refers to systems in which two different elements or factors are used to authenticate a person or information. These two factors usually include something that the person to be authenticated has in their possession (for example, the hardware device that generates the passkey or the mobile phone in the examples above) and something that is familiar to them (for example, a username and password) . Using these two factors as opposed to one provides a higher level of authentication consistency. Any type of authentication where
59P41149PL00
ΕΡ 2 368 339 BI more than one factor is used is generally called strong authentication.
[0010] In the remainder of this description, the term "secure transaction will be broadly understood and may include any case where user authentication is required prior to performing a secure operation or prior to granting access to a secure environment. Likewise, a "secure transaction host or" client should be broadly understood to include any institution that provides secure services and that may require authentication of its users in order to deliver the services.
PURPOSE OF THE INVENTION
An object of the invention is to provide a secure transaction authentication system and method that will at least partially solve the above-mentioned problems of the existing authentication systems.
SUMMARY OF THE INVENTION
[0012] In accordance with the present invention, there is provided a secure transaction authentication method for performing between a secure transaction host and a user performing the transaction as set out in claim 1.
[0013] According to a further feature of the invention, the portable communication device is a cellular telephone.
[0014] According to further features of the invention, the method comprises the steps of: requesting a digital ID from the portable communication device upon receipt of an authentication request from a host for a secure transaction;
59P41149PL00
Receiving an acknowledgment or rejection result over a secure communication link; and a step of receiving the digitized identifier from the portable communication device associated with a user performing the transaction, comprising receiving the digital identifier from a secure storage location on the portable communications device.
[0015] The invention also provides a system for authenticating a secure transaction performed between a user performing the transaction and a secure transaction host as set out in claim 4.
[0016] According to further features of the invention, the acknowledgment or rejection result is communicated over a secure communication link; the portable communication device is a cellular telephone; the mobile communication device authentication application is a software application that is downloadable by a mobile phone from a domain associated with an authentication service provider via the Internet; the digital ID is created as a function of the International Device Identification Number (IMEI) of the mobile phone on which the application is installed, the International Mobile Subscriber Identification Number (IMSI) of the SIM card used in the mobile and a random number stored in the mobile device, and the digital ID is stored at a storage location on a portable communication device; and the authentication service provider includes at least one authentication server and an associated authentication database; wherein the authentication server is configured to store users by registering at least digital identifiers, created by an application installed on their portable communication devices, in an authentication database; to receive an authentication request from a secure host
59P41149PL00
Transaction; for receiving the digital identifier from the transactional user portable communication device; for comparing the received digital identifier with a list of digital identifiers associated with pre-stored portable communication devices of users stored in a database; for sending a transaction confirmation request to the portable communication device of the user carrying out the transaction, if the received digital identifier corresponds to the digital identifier stored in the database, asking the user to confirm or reject his intended execution of a secure transaction; for receiving an acknowledgment or rejection result from the user carrying out a transaction portable communication device; and for sending the positive authentication result to the secure transaction host in response to the acknowledgment result and the negative authentication result in response to the rejection result.
[0017] According to further features of the invention, the communication link is established between the server and the transaction user's portable communication device, if the received digital identifier corresponds to a digital identifier stored in the database, the transaction confirmation request and the confirmation or rejection result are communicated over the communication link; the portable communication device is a cellular telephone; a portable communication device application is a software application that is downloadable via a mobile phone from a domain associated with an authentication service provider via the Internet; digital identifier is created as a function of the International Device Identification Number (IMEI) of the mobile phone on which the application is installed, the International Mobile Subscriber Identity Number (IMSI) of the SIM card
59P41149PL00
EP 2 368 339 B1 used in the cell phone and a random number stored in the cell phone memory; the storage location on the mobile phone is secure and accessible to the application using the digital rights management functionality of the operating system running on the mobile phone; and only authorized applications, preferably one application, have access to the unique identifier stored in the mobile phone.
[0018] According to still other features of the invention, the application is configured to periodically create a new digital identifier using the IMEI number of the mobile phone, the IMSI number of the SIM card of the mobile phone and the newly generated random number; a new digital ID is created after each successful transaction authentication, each new digital ID is stored in a secure storage location on the mobile phone and saved in the authentication database after creation.
[0019] According to still other features of the invention, additional information related to the user is stored in the authentication database when the user is stored on the authentication server, the additional information includes one or more personal information, bank account details, and credit card details; The write access key is created and assigned to the user when the application is downloaded to his mobile phone, the write access key allows the user to write to the authentication server, and the user is required to provide personal identifying information to enable the user to save with the authentication service provider.
[0020] According to further features of the invention, the system comprises an authentication network server via which clients or client applications can connect to the authentication server; the web server specifies a number of XML-RPC queries that the client's institutions can use
59P41149PL00
Perform authentication queries with the authentication server; and the network server provides the authentication server query results by means of an independent variable that can be read by client institutions, preventing direct access to the authentication server and the database by client institutions.
[0021] According to yet another feature of the invention, the communication link is a GSM or CDMA wireless communication link, preferably a GPRS link for a GSM network.
According to still other features of the invention, the application is configured to trigger a corresponding alert or pop-up message that appears on the screen of the mobile phone of the user performing the transaction in response to the confirmation or rejection of the request from the authentication server, the pop-up message prompts the user to acknowledge or deny its deliberate execution of a secure transaction with the press of a button; the authentication server is configured to send a text message to the mobile communication device of the user performing the transaction, asking the user to establish a communication connection if the communication connection has not yet been established when the authentication server tries to send an acknowledge or reject request to the mobile phone of the user performing the transaction; and the communication over the communication link is performed with SSL or TLS secured messages.
[0023] According to still other features of the invention, the authentication service provider includes a plurality of authentication servers managed by a load-sharing server that assigns servers to the mobile communication devices of users carrying out transactions according to
59P41149PL00
Individual server loads; secure transaction includes any one or more of the group that includes access to a customer's secure domain, online financial transactions, offline financial transactions, online shopping, offline shopping, database access, information access, physical access to buildings or other areas, network access computer, subscriber websites, internet portals and the like; and a successful secure transaction is only allowed to the user performing the transaction after receiving a successful authentication result from the authentication server.
SHORT DESCRIPTION OF THE DRAWING FIGURES
[0024] The invention will now be described, by way of example only, with reference to the accompanying representations in which:
Figure 1 is a schematic illustration of an authentication system according to the invention;
Figure 2 is a schematic illustration of an authentication system according to an alternative embodiment of the invention using a web server and a load sharing server; and
Figure 3 is a schematic illustration of the memory layout of a typical cell phone.
DETAILED DESCRIPTION WITH REFERENCE TO THE DRAWING FIGURES
[0025] In its simplest implementation, and as shown in Figure 1, the authentication system (1) of a secure transaction comprises an authentication server (3), an authentication database (5), and a portable communication device software application (not shown).
59P41149PL00
EP 2 368 339 B1
The application is configured to be installed on a portable communication device (7) which, in most cases, will be the user's mobile phone (9). It should be noted that the server (3), database (5), and the software application will be implemented, operated and maintained by the authentication service provider and provide an authentication platform by which authentication operations can be performed. [0026] In order to use the authentication system (1), the user (9) has to be registered with the authentication service provider. The recording is done by the user (9) downloading the software application to his mobile phone (7) through the mobile internet browser application on the phone (7), and then installing it on the phone. When downloading the application, the server (3) also generates an access key that will be needed by the user (9) when saving. The installation of the software application on the mobile phone (7) can be done manually by the user (9) or it can be done automatically with the help of a direct link to the application sent to the user's phone via an over the air (OTA) message. Communication between the application on the mobile phone (7) and the authentication server (3) takes place over the GSM network (11), preferably by means of the General Packet Radio Service (GPRS) protocol. However, it is envisioned that any other suitable bi-directional communication network and protocol may be used. [0027] The application then creates a unique digital identifier (13) (hereinafter referred to as a fingerprint) uniquely associated with a specific mobile phone (7) of the user (9). The fingerprint (13) is formed as a function of the unique International Device Identification Number (IMEI) of the mobile phone (7), the International Mobile Subscriber Identification Number
59P41149PL00
ΕΡ 2 368 339 BI (IMSI) of the SIM card assigned to the user and used in the mobile phone (7) and the random number generated by the software application. The fingerprint (13) is automatically generated without the knowledge and intervention of the user (9) and is stored in a secure storage area on the mobile phone (7) from which it can only be read by authorized software applications, preferably only by an authentication application. There is therefore a one-to-one relationship between a digital fingerprint and a mobile phone. As it is assumed that the user is always in possession of his mobile phone, this implies a one-to-one relationship between the digital fingerprint (13) and the user (9).
[0028] Once installed, the user (9) can open the software application on his mobile phone (7) and choose to subscribe to the authentication service provider. The application then sends a request to save containing the digital fingerprint (13) of the mobile phone (7) and the access key to the server (3) via GPRS.
[0029] The server (3) receives the request to save and the access key and recognizes that the new device wants to register (save). The server (3) accepts the request to save if the write access key is valid, and stores the digital fingerprint (13) of the mobile phone (7) to be enrolled in the authorization database (5). At this point, the user's mobile phone (9) is registered with the authorization service, and his mobile phone (7) is uniquely identified to the authorization server (3).
[0030] The rest of this example of the invention will be explained with reference to the user (9) trying to perform an online (internet) secure banking transaction. Note, however, that the example applies the same to any of a number of secure transactions including, but in no way limiting, access to secure domains
59P41149PL00
Customer Service, online financial transactions, offline financial transactions, online shopping, offline shopping, database access, information access, physical access to buildings or other premises, access to computer networks, subscriber websites, web portals and the like.
[0031] To log into his online bank account, the user (9) first opens the website of the banking institution (15) where he has his account from a personal computer (17), laptop or other internet-enabled device. The user (9) then enters his account number (equivalent to the username) and password on the baku website on his computer (17). Before logging in, the user (9) starts the authentication application on his mobile phone (7). At startup, the software application sends the digital fingerprint (13) over the network (11) via GPRS to the authentication server (3), which receives it and compares it with the digital fingerprints of all stored cell phones in the database (5). If the digital fingerprint (13) matches a previously stored fingerprint in the database (5), the mobile phone (7) of the user (9) is logged on the authentication platform and a direct real-time communication connection is established between the authentication server (3) and with a mobile phone (7). The mobile phone (7) and the authentication server (3) now communicate directly with each other via messages secured by Secure Sockets Layer (SSL) or Transport Layer Security (TLS).
[0032] After the user (9) requests to login to his internet bank account, the banking institution (15) requests the authentication of the user (9) from the authentication server (3). The authentication server (3) in turn sends a transaction confirmation request to the phone
59P41149PL00
Cell (7) that is received by the software application. The software application displays a pop-up message on the screen of the mobile phone and triggers an appropriate alarm to attract the user's attention (9). The pop-up message contains information about the transaction the user (9) is trying to perform and requests the user (9) to either confirm (accept) or reject (decline) the transaction by pressing the appropriate button. If the user (9) confirms the transaction, the application forwards this confirmation result to the server (3) which, in turn, sends the positive authentication result to the banking institution's server (15). The banking institution (15) then allows the user (9) to access his online bank account.
[0033] The user (9) is now successfully logged into his online bank account and can continue to use the account as usual. During an internet banking session, any number of authentication requests may be made, depending on the type of transaction the user (9) is attempting to perform and the bank's decision on how to implement the security layer provided by the invention.
[0034] If the user (9) decides to reject the confirmation request on his mobile phone, this rejection result will also be communicated by the application to the server (3), which, in turn, sends the negative authentication result to the banking institution's server (15) (secure host). transactions). The requested login of the user will be appropriately rejected on his computer (17), and the appropriate login error message will be displayed. The example thus illustrates that a user can log into his account by explicitly acknowledging (accepting) the login request sent to his mobile phone in an interactive manner. Because the digital print
59P41149PL00
ΕΡ 2 368 339 BI finger can not be copied without the user's mobile phone, this implies that no third party can log into the user's authentication-protected domain without having the user's username, password and mobile phone.
[0035] A more complicated embodiment of the system (1) of the invention is shown in Figure 2. In the figure, similar or analogous elements to those described above with reference to Figure 1 are denoted by like numerals. The user authentication system (1) in this embodiment comprises a plurality of authentication servers (3), although only one is shown in the figure, the authentication database (5), and a software application (not shown) for the portable communication device installed on the mobile phone (7). user (9). Moreover, the system (1) includes a web server (21) used to connect to the client's web server (23). The network server (21) provides a specific interface via which any client server (23) can forward authentication requests through the network server (21) to the authentication database (5) or the authentication server (3). The web server defines the interface to the client software by providing the client with a number of predefined XML-RPC queries that can be sent to the web server (21) (XML-RPC is a remote procedure call protocol that uses XML to encode its calls and HTTP as the mechanism for transport). The web server (21) only allows queries specified by the XML-RPC interface, thus allowing the authentication platform to define the rules by which the information is made available.
[0036] The authorization network server (21) also connects to the database (5) when a query is received, and returns the result of such query using a variable that can be accessed by the client institution's web server (23). I guarantee
59P41149PL00
ΕΡ 2 368 339 BI the fact that unauthorized access to authorization data is impossible because only the own system components (1) have direct access to such data.
[0037] Figure 2 also shows how the system (1) user login process will be performed for a typical customer online banking institution. In step (27), the user (9) runs an authentication software application on his mobile phone (7) and the application sends a connection request (establishing a communication connection) to the load-sharing server (29) which forms part of the system (1). The load-sharing server (29) then selects the authentication server (3) with the lowest current load of all available authentication servers and assigns the user's mobile phone (7) to that server (3) in step (31). The user (9) then logs on to the website and his bank account from his personal computer (17) in step (33), which are operated by the respective bank's web server (23). In step (35), the bank's web server (23) then sends an authentication request to the authentication web server (21) with an XML-RPC request, and the web server (21) starts polling regarding the authentication result. The network server (21) places the request in the pending request table (37) in step (39). The authentication server (3) assigned to the cell phone (7) then retrieves the request from the table (37) in step (41) and sends an acknowledgment request over the communication link to the cell phone in step (43) in response to which the application calls the user (9 ) to confirm (accept) or reject (refuse) login by pressing the appropriate button. The user response is again passed over the communication link to the authentication server (3) in step (45), after which the server (3) places the authentication result with
59P41149PL00
Return to table (37) in step (47). The network server (21) then reads the authentication result from the table (37) and delivers it to the bank client server (23) when inquired in step (49). If the authentication was successful, the user (9) will be logged into his online bank account by the customer's bank.
[0038] In the event that the user tries to make a secure transaction by a client that has used the authentication system of the invention without first establishing a communication connection between the authentication server and the user's mobile phone, the authentication server may be configured to automatically send a regular SMS message to the user's mobile phone, asking the user to run an authentication software application on his mobile phone, which in turn will establish a communication connection with the authentication server. However, it is also envisaged that the authentication server may be able to remotely run a mobile phone software application if the user requires this functionality. It is also possible that the authentication service provider and the mobile phone of the user carrying out the transaction may communicate by SMS or other appropriate messages without having to establish a secure communication connection between the service provider and the mobile phone.
It is envisaged that the software application of the mobile telephone may also be additionally secured with its own password, in which case the person who illegally acquires the mobile telephone will not even be able to run the software application, let alone establish a communication connection with the server. authentication.
[0040] An important aspect of the safe operation of the invention is a secure storage location in a mobile phone,
59P41149PL00
Wherein the authentication software application stores the fingerprint of the mobile phone. The fingerprint should be able to be downloaded and interpreted by authorized software applications, preferably solely by the authentication software application itself. In this way, it will not be possible for third parties who have access to the phone to obtain a unique fingerprint of the mobile phone. The digital fingerprint will therefore never be displayed and the mobile phone user will not be aware of it. The phone's IMEI number can be copied by reprogramming the victim cell phone or by modifying the J2ME application in it. Likewise, the IMSI number of the cell phone SIM card can be copied, simulated or duplicated by modifying the phone's J2ME application. Moreover, the file containing the random number can be copied from the mobile phone or obtained by modifying the J2ME application. It is therefore essential that the fingerprint of the telephone is stored in a secure storage location. To achieve this, the invention proposes that the unique digital fingerprint of the telephone be stored at a location on the telephone where the operating system of the telephone will only allow access and modification to the authentication application (or other applications specifically authorized by it). Moreover, the fingerprint may have pseudo-random properties that are implemented by updating the fingerprint both in the mobile phone and in the authentication database with each successful user authentication. One way to achieve this is to change the random number used in fingerprint generation and recompile the fingerprint with IMEI, IMSI and a new random number each time the user is authenticated successfully. In this way, the user will be uniquely linked to the phone and breach security or leak
59P41149PL00
The digital telephone fingerprint will only be effective until the next successful user authentication.
[0041] It is further envisaged that by using the digital rights management (DRM) feature of the mobile phone operating system, access to the signature may be restricted by including a unique signature in the authentication application code. Most mobile phones support a standard called OMA DRM (ang. Open Mobile Alliance Digital Rights Management), which guarantees that when data is stored on a mobile phone, it cannot be obtained by unauthorized persons. The authentication system of the invention uses this functionality and stores a unique key inside the DRM protected area of the mobile phone. This prevents access to the secure key without the required authorization.
[0042] As shown in Figure 3, the memory of a cell phone typically includes designated storage areas (51) where data related to the phone's operating system (53) and other data files (55), respectively, are stored. Many different applications can be stored in the operating system storage area (53) including, in most mobile phones, a group of applications (57) running in the Java Virtual Machine (JVM) Runtime environment. The authentication application according to the invention may be one of the applications that run in the JVM environment. The cell phone memory file system (55) typically comprises a guard area (61) that corresponds to the DRM protected area. Most JVM applications use a portion of a protected area (61) called "JVM Recordstore (63), inside which they store sensitive information. The downside of JVM Recordstore (63), however, is that full round-trip access is possible between the JVM (57) runtime application and the JVM Recordstore
59P41149PL00
EP 2 368 339 B1 (63). Thus, an unscrupulous operator wishing to access the information stored in JVM Recorstore (63) simply has to write a separate application running in the JVM runtime environment to allow such access. However, as further illustrated in Figure 3, the authentication application of the invention (59) uses and manages a portion (65) of the secure area (61) in a manner that allows only the application (59) to access that portion (65). It should therefore be noted that by storing the digital fingerprint in this manner, possibly with additional security information, only the application (59) will have access to it.
[0043] Since uploading the authentication system application to the mobile phone is not secure, it may be necessary to store an additional signature on the mobile phone. This additional signature will be stored in the mobile phone once the unique signature of the phone is validated in the authentication database. When an authentication application is run on a mobile phone, the phone's unique signature, along with an additional signature, will be shared with the authentication server. After each successful authentication, an additional signature can be stored or updated on the mobile phone. One way to achieve this is to use a cryptographic encryption system. It uses a pair of keys: private and public, with which data can be encrypted and decrypted. Data encrypted with the private key can be decrypted with the public key and vice versa. The private key will usually be stored by the authentication server, while the public key will be shared with the mobile phone authentication application. When a mobile phone is used in the system according to the invention, it can encrypt data with a key
59P41149PL00
After a successful connection to the server. Only a real authentication server that has the private key will then be able to decrypt this data. This effectively prevents so-called "man-in-the-middle" attacks.
[0044] It should be noted that the authentication system and method described above largely eliminates the danger of the various known authentication systems. In particular, they eliminate the threat of cloning SIM cards. Since the fingerprint is unique to each mobile phone and includes both hardware and software aspects related to the actual phone and SIM card, a cloned SIM card used in another phone will produce a completely different fingerprint which will not be saved in the authentication system, making the SIM card is completely useless when attempting to use it as a means to access a domain protected by the authentication system according to the invention. If the user's phone is stolen, the user only needs to report it to the authentication service provider so that one or both of the IMEI and IMSI numbers are saved as stolen and blocked. Therefore, any further authentication attempt will be unsuccessful. Due to the nature of the protocol between the cellular telephone and the authentication server, the system of the invention can detect hostile intentions very quickly and efficiently. Since the user never has to physically enter login details (digital fingerprint), any cell phone trying to connect with an unsaved cell phone almost certainly points to a user trying to bypass the system.
[0045] According to the invention, any attempt by a user to perform a secure transaction may require the user to interactively confirm (accept) or decline (deny) the transaction in real time. System
59P41149PL00
The EP 2 368 339 B1 according to the invention thus provides a method of using a person's cell phone to uniquely identify a user for authentication purposes.
[0046] An additional advantage of the invention is that when a user approves or denies an acknowledgment request sent by the authentication server, as the case may be, access to or permission to perform a secure transaction is immediately granted, completely eliminating the need for OTP and the like. An outsider who comes into possession of the user's secure username and password will therefore still not be able to carry out transactions on behalf of the user.
[0047] The authentication system according to the invention thus provides a platform on which clients can obtain real-time online two-factor authentication for any secure transactions.
[0048] The integration of the system according to the invention with existing authentication systems is simple as a full XML-RPC interface is provided for communication with the authentication server and the database. For integration in non-networking applications, an Application Programming Interface (API) is provided allowing the developer to customize the platform to suit his application.
[0049] The foregoing description is exemplary only, and it should be noted that numerous changes and additions may be made to the invention described without departing from the scope of the invention. In particular, it is envisaged that the invention may also have an offline component which can be used when the mobile phone is unable to establish a communication connection with the authentication server due to the absence or weak GPRS signal or lack of resources when the mobile phone is operated on the basis of pre-paid contracts. Under these conditions, the authentication server can
59P41149PL00
It will automatically detect the inability to connect via GPRS and can switch the authentication mode to offline mode. In offline mode, the mobile application on the user's mobile phone can be used offline, in which it generates an OTP which the user can enter to access domains protected by the authentication system according to the invention. The user can then enter the OTP in the tool they are using to authenticate their identity.
[0050] It should also be noted that a mobile phone application may, when working offline, use a random number stored in the mobile phone (hereinafter referred to as a seed) and a digital fingerprint to generate an OTP, and the seed may be updated each time successful communication between the mobile phone application and the authentication server will take place.
[0051] It should also be noted that the authentication system of the invention overcomes the problem that exists when a GSM SIM card is cloned. In the case of SIM cloning, the SMS messages sent by the financial institution (via the GSM provider) are received either by both, or by only one active SIM card: therefore either the legitimate user or the person trying to cheat the user, or both. Knowing that this is the case, there is a real chance that the legitimate user will not even receive SMS notifications about the transactions performed on his account after the transaction has been executed. The authentication system of the invention allows each secure transaction to be confirmed or rejected by the user performing the transaction prior to finalizing the transaction. Since the request to confirm or decline the transaction is effectively sent to the fingerprint and not only to the IMSI or SIM of the user performing the transaction, the system is not sensitive to SIM cloning. Due to its interactive nature,
59P41149PL00
EP 2 368 339 B1 is therefore very well equipped to defend against brute force attempts as it recognizes and responds to them.
[0052] It is envisioned that the ability of the system to run other additional security solutions allows for many applications in the future without any changes required to the existing system. The interactive nature of the authentication process and platform leaves room for endless possibilities and innovation. For example, the user may also use the authentication system of the invention to authorize third party transactions because the final confirmation or rejection is up to him. The invention may even be used to expedite ATM transactions, conducting secure banking operations via a mobile phone, and electronic money transfers between bank account holders and non-bank account holders, with just a few examples being mentioned.
Entersekt International Limited
Proxy:
59P41149PL00
ΕΡ 2 368 339 BI
Contents31
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
20 members in 12 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 200808439 | South Africa | A | |
| 200904956 | South Africa | A | |
| 09830074 | European Patent Office (EPO) | A | |
| 2009007639 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| EP20090830074 | – | – | – |
| WO2009IB07639 | – | – | – |
| ZA20080008439 | – | – | – |
| ZA20090004956 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| CA2744971A1 | Canada | A1 | |
| WO2010064128A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2010064128A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2011086616A1 | United States of America | A1 | |
| ZA201008904B | South Africa | B | |
| EP2368339A2 | European Patent Office (EPO) | A2 | |
| AU2009323748A1 | Australia | A1 | |
| CN102301642A | China | A | |
| EP2368339A4 | European Patent Office (EPO) | A4 | |
| US8862097B2 | United States of America | B2 | |
| AU2009323748B2 | Australia | B2 | |
| CN102301642B | China | B | |
| BRPI0917067A2 | Brazil | A2 | |
| EP2368339B1 | European Patent Office (EPO) | B1 | |
| ES2645289T3 | Spain | T3 | |
| PL2368339T3This record | Poland | T3 | |
| DE202009019188U1 | Germany | U1 | |
| HUE037029T2 | Hungary | T2 | |
| CA2744971C | Canada | C | |
| EP2368339B2 | European Patent Office (EPO) | B2 |
Numbers
- Publication, DOCDB
- 2368339
- Publication, EPODOC
- PL2368339T
- Application
- 830074
- Application, DOCDB
- 09830074
- Application, EPODOC
- PL20090830074T
Titles2
- English
- SECURE TRANSACTION AUTHENTICATION
- Polish
- UWIERZYTELNIANIE BEZPIECZNYCH TRANSAKCJI
Classification
- CPC, 10
- H04L63/18
- G06Q20/10
- G06Q20/32
- G06Q20/326
- G06Q20/42
- G06Q20/425
- H04L63/0876
- H04L2463/082
- H04L2463/102
- H04W12/06
