Method for establishing the authenticity of the identity of a service user and device for carrying out the method
Abstract
The invention relates to a method and a device for establishing the authenticity of the identity of a service user in relation to a service provider, for releasing an access authorization (password) for a service, using two different data input terminals, a registration server and a message converter.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
9 claims: 9 independent, 0 dependent
- 1Claims 1. A method for determining the authenticity of the identity of a service user (6) towards a service provider (2) for releasing an access authorization (password) for a service using two different data entry terminals (1, 5), a registration server (3) and a message converter (4), wherein, a) by the service user (6) in a first step via a secure connection (7), z. B. on the Internet, the connection to the registration server (3) of the service provider (2) is made via the data entry terminal (1) with the request to transmit an access code (password;TAN);Patentansprüche 1. Verfahren zum Feststellen der Authentizität der Identität eines Dienste-Nutzers (6) gegenüber einem Dienste-Anbieter (2) zur Freigabe einer Zugangsberechtigung (Paßwort) für einen Dienst unter Verwendung von zwei verschiedenen Dateneingabeterminals (1, 5), eines Registrierungsservers (3) und eines Nachrichten-Konverters (4), wobei, a) von dem Dienste-Nutzer (6) in einem ersten Schritt über eine gesicherte Verbindung (7), z. B. im Internet, über das Dateneingabeterminal (1) die Verbindung zu dem Registrierungsserver (3) des Dienste-Anbieters (2) hergestellt wird, mit der Aufforderung, eine Zugangskennung (Paßwort;TAN) zu übermitteln;b) whereupon in a second step the registration server (3) on the same transmission path (7) as in a) an invalid password (identifier;TAN) is sent to the data input terminal (1) of the registered service user (6);c) whereupon the service user (6) enters the invalid password sent to the data entry terminal (1) into a second terminal (5) (mobile device, fixed network device) different from the data entry terminal (1), for the same service user (6) according to a) is registered in the registration server (3);b) woraufhin in einem zweiten Schritt der Registrierungsserver (3) auf demselben Übertragungsweg (7) wie unter a) ein ungültiges Paßwort (Kennung;TAN) an das Dateneingabeterminal (1) des registrierten Dienste-Nutzers (6) gesendet wird;c) woraufhin der Dienste-Nutzer (6) das an das Dateneingabeterminal (1 ) gesandte ungültige Paßwort in ein von dem Dateneingabeterminal (1 ) verschiedenes zweites Endgerät (5) (Mobilfunkgerät;Festnetzgerät) eingibt, das für den gleichen Dienste-Nutzer (6) gemäß a) in dem Registrierungsserver (3) registriert ist;d) then from this second terminal (5) this invalid password or the like via a transmission path (8) different from that mentioned under a) and b) to a message converter (4) of the service provider (2) is sent ;d) woraufhin von diesem zweiten Endgerät (5) dieses ungültige Paßwort oder dergleichen über einen von dem unter Ziffer a) und b) erwähnten Übertragungsweg verschiedenen Übertragungsweg (8) an einen Nachrichten-Konverter (4) des Dienste-Anbieters (2) gesendet wird;e) and that the message converter (4) together with the registration center (3) compares the returned invalid password or the like with the password sent to the data entry terminal (1) and identity of the authorization data of the service user (6) for the data input terminal (1) and for the different second terminal (5) the password is released as valid. e) und daß der Nachrichten-Konverter (4) zusammen mit dem Registrie- rungssenter (3) das zurückgesendete ungültige Paßwort oder dergleichen mit dem an das Dateneingabeterminal (1 ) gesendeten Paßwort vergleicht und bei Identität der Autorisierungsdaten des Dienste-Nutzers (6) für das Dateneingabeterminal (1 ) und für das davon verschiedene zweite Endgerät (5) das Paßwort als gültig freigegeben wird.
- 2Verfahren nach Anspruch 1 , dadurch gekennzeichnet, daß die Kennung (Paßwort;TAN) nur für eine vorbestimmte Zeitspanne zur Feststellung der Authentizität verwendet wird. Second Method according to Claim 1, characterized in that the identifier (password, TAN) is used only for a predetermined period of time to determine the authenticity.
- 3Verfahren nach Anspruch 1 oder 2, dadurch gekennzeichnet, daß die Kennung (Paßwort;TAN) von dem Dienste-Nutzer (6) nach Freigabe des Paßwortes jederzeit zu ändern ist. Third Method according to Claim 1 or 2, characterized in that the identifier (password, TAN) is to be changed at any time by the service user (6) after the password has been released.
- 4Verfahren nach Anspruch 1 oder einem der darauffolgenden Ansprüche, dadurch gekennzeichnet, daß die Kennung nach einer vorbestimmten Anzahl von Nutzungen durch den Dienste-Anbieter (2) ungültig gemacht wird. 4th Method according to Claim 1 or one of the subsequent claims, characterized in that the identifier is invalidated after a predetermined number of uses by the service provider (2).
- 5Verfahren nach Anspruch 1 oder einem der darauffolgenden Ansprüche, dadurch gekennzeichnet, daß die vom Dateneingabeterminal (1) an den Registrierungsserver (3) übermittelten Daten verschlüsselt werden. 5th Method according to Claim 1 or one of the subsequent claims, characterized in that the data transmitted by the data input terminal (1) to the registration server (3) are encrypted.
- 6Verfahren nach Anspruch 1 oder einem der darauffolgenden Ansprüche, dadurch gekennzeichnet, daß die vom Registrierungsserver (3) an das Dateneingabeterminal (1 ) zurückgesandten Daten verschlüsselt werden. 6th Method according to Claim 1 or one of the subsequent claims, characterized in that the data returned by the registration server (3) to the data input terminal (1) is encrypted.
- 7Verfahren nach Anspruch 1 oder einem der darauffolgenden Ansprüche, dadurch gekennzeichnet, daß die von dem zweiten Endgerät (5) an den Nachrichten-Konverter (4) übermittelten Daten nach GSM-/SMS-Standard an den Nachrichten-Konverter (4) übermittelt werden. 7th Method according to Claim 1 or one of the subsequent claims, characterized in that the data transmitted by the second terminal (5) to the message converter (4) is transmitted to the message converter (4) in accordance with the GSM / SMS standard.
- 8Verfahren nach Anspruch 1 oder einem der darauffolgenden Ansprüche, dadurch gekennzeichnet, daß die von dem zweiten Endgerät (5) an den Nachrichten-Konverter (4) übermittelten Daten über ISDN übermittelt werden. 8th. Method according to Claim 1 or one of the subsequent claims, characterized in that the data transmitted by the second terminal (5) to the message converter (4) are transmitted via ISDN.
- 9Vorrichtung zum Durchführen des Verfahrens nach Anspruch 1 oder einem der darauffolgenden Ansprüche, mit einem Dateneingabeterminal (1), einem Registrierungsseπ/er (3) und einem Nachrichten-Konverter (4), dadurch gekennzeichnet, daß das Dateneingabeterminal (1 ) ein PC, das zweite Endgerät (5) ein Mobilfunkgerät, die Verbindung (7) zwischen dem PC (1) und dem Registrierungsserver (3) eine gesicherte Internet- Verbindung über Secure Socket Layer oder dergleichen und die Verbindung zwischen dem Mobilfunkgerät (5) und dem Nachrichten-Konverter (4) eine Mobilfunkverbindung im GSM-Netz oder dergleichen ist. 9th Apparatus for carrying out the method according to claim 1 or one of the subsequent claims, with a data entry terminal (1), a registration server (3) and a message converter (4), characterized, that the data input terminal (1) is a PC, the second terminal (5) a mobile device, the connection (7) between the PC (1) and the registration server (3) a secure Internet connection via Secure Socket Layer or the like and the connection between the mobile device (5) and the message converter (4) a mobile radio connection in the GSM Network or the like.
Independent claims9
80 paragraphs in 4 sections, as filed
A method for determining the authenticity of the identity of a user Services- and apparatus for performing the method
description
genus
The invention relates to a method for determining the authenticity of the identity of a service user against a service provider to release an access authorization (password) for a service.
The invention further relates to an apparatus for performing the aforementioned method.
State of the art
From DE 197 18 103 A1 a method and apparatus for authorization are already known in data transmission systems using a transaction number (TAN) or similar password. The prior art method suggests that
the user together with a request to generate or to choose a TAN or a comparable password from a file com- puter sends in a first step via a data input device his identification and / or an identification code of the data input device to a authoriza-;
in a second step the authorization computer which TAN or comparable password generated or selects from a file;
the TAN or comparable password via a different transmission path as in step 1 sends in a third step, the authorization computer to a recipient; takes over in a fourth step, the user this TAN or the comparable password from the receiver and enters into the data input device;
in a fifth step this TAN or comparable password is transferred again to the authorization computer;
in a sixth step the authorization computer, the validity of the TAN or the comparable password checks, then
produce in a seventh step, a connection between the data input unit and a receiver unit or unlock.
Furthermore, it is proposed in the prior publication that it is a TAN or a comparable password used only once. The validity of the TAN or comparable password can be a predefined user time. Furthermore, may depend the validity of the TAN or comparable password from a predefined number of transmitted files. The validity of the TAN or comparable password is dependent on a predefined size of the transferred data. Access to the data input device and / or the recipient and / or the receiving unit is protected by the password. The data from the input device to the receiving unit or vice versa transmitted files are encrypted. The data from the input device transmitted to the authorization computer or vice versa, data are also encrypted. The receiver can be a pager. However, it is also possible that the receiver is a mobile radio device. Furthermore, it is proposed that the recipient as fax. The receiver can also be an e-mail or network address. Furthermore, it is possible that the receiver is a data output device. Finally, it is proposed that the voice output device to be used as a speaker or as a voice output device is a phone. Described is also that the receiver is a built in the data input device radio receiver, which outputs the TAN or comparable password on the display or monitor of the data input device. The radio device may have a user identification element, as it is also possible that the user identification element is a magnet or chip card. Finally, it is conceivable to design the user identification element with graphic systems for verifying fingerprint or an image identifying the user. In authorization computer and the receiver matching encryption modules are present. The receiver unit can also be a door closing mechanism. In addition, it is proposed that the authorization computer and the receiving unit are integrated in one device. The data input device, the authorization computer and the receiver unit can be configured in one appliance.
By the procedure described are those described in DE 197 18 103 A1 another prior art procedures as "telebanking" and the so-called "call-back system" are functionally safer.
Since the user sends the first step on a data input device his identification and / or an identification code of the data input device together with a request for the generation and selection of a TAN or a comparable password from a file to an authorization computer, accomplishing the third step, the fact consists in that the authorization computer which TAN or comparable password sent to the receiver via another transmission path, which takes in a fourth step, the user this TAN or comparable password from this receiver and re-introduce it into his data input device. Thus, two different transmission paths are used. The user's authenticity, which is for the service provider of high significance is not verified in the process described in DE 197 18 103 A1. The method described in DE 197 18 103 A1 leaves open the possibility that a user specifies a false identity, to operate with the aim of abuse. Following abuse possibilities here:
1. A user logs on under a false identity and can send the password to the recipient.
2. A user logs on properly. Due to technical problems, the delivery of the password to the recipient delayed. The receiver unit now in the wrong hands.
Since the method is based on that a valid password will be sent to the recipient, an unauthorized use services to the detriment of the service provider or a third party is possible immediately.
DE 197 22 424 C1 a method for secure access by a user to a separate system is previously known with stored data in a memory device, comprising the steps of:
Establishing a first connection between a first communication device and an access device and transmission of a first password from the first communication device to the access device; Comparing the first password with stored in the access device first authentication data;
Establishing a second connection between a second communication device and the access device and transmission of a second password from the second communication device to the access device;
Comparing the second password with stored in the access device second authentication data; and
Release of access to the system with one or two communication devices in the presence of a predetermined relationship between the first and second password with those stored in the access device second authentication data.
It proposes in this context, the following steps:
Transmitting the second or a third password from the access device to the first communication device; Transmitting the second or third password from the first communication device to the second communication device; and
Transmitting the second or third password from the second communication device to the access apparatus, which performs such inspection of the password before access is enabled to the data.
Furthermore, the establishment of a connection between a first communication device and an access device and transmission of a first password from the first communication device is proposed for accessing device, wherein comparing the first password is carried out with data stored in the first access device authentication data;
In the presence of a predetermined relationship between the first password with those stored in the access device authentication data, construction of a second connection between the access device and a second communication device and transmitting a second password from the access device to the second communication device;
Transmitting the second password from the second communication device to the first communication device; Transmitting the second password from the first communication device to the access device;
Comparing the second password with stored in the access device second authentication data; and
Release of access to the system with one or two communication devices, in the presence of a predetermined relationship between the second password with those stored in the access device second authentication data.
Also proposed is a method which is characterized by constructing the first and second connection through independent communication paths, whereby a data processing device is used as the first or second communication device, and the connection between the data processing device and the access device is set up processing apparatus network via a data network. For the connection between the access device and the data processing apparatus, a Internet can be used. As the first or second communication device, a phone can be used, the connection between phone and access device is set up via a telephone network. As a communication device, a cellular phone may be used. The first or second marking word can be transmitted by pressing a call request button or at least one other key of the phone. The system can be a Home Location Register a GSM network and the storage device, stored in the subscriber-related data. At least one of the passwords can be generated in the access device or elsewhere and be valid for an access session. It is further proposed to generate at least one of the passwords using a subscriber identification and the current time or date. One of the passwords may be used for data encryption and a data transmission between the first or the second communication device and the access device. After release of data access can be transferred from one of the communication devices at least another password to Zugriffsvorrich- device to release an extended access to the system or to another in the storage device stored data. As a device can be used with associated access devices, a system with a data processing apparatus, device network via a Datenverarbeitungsvorrich- to which the access device can be connected using a permanently installed telephone with a mobile phone that via a fixed network or a mobile radio network to is access device connected.
This device produces a very complicated way different passwords that are sent via separate communications devices. From WO 95/19593 a computer security system is previously known, in which the system occasionally generates a code A, which is umtransformiert and generates a code B, wherein even a third code is generated to be compared with the second code and wherein conformity of the second and third codes until the access is released.
task
The invention addresses the problem of designing a method for releasing an access authorization based on the verification of the authenticity of the identity of a service user in accordance with the assumed genre. The process should the service providers provide security to release access permissions only for service user whose authenticity has been verified.
Furthermore, the invention has for its object to provide an advantageous device for carrying out the inventive method. Solution of the problem concerning the procedure
This object is achieved by the reproduced in patent claim 1
Some advantages
In the invention, in contrast to the DE 197 18 103 A1 on only one z. B. secured connection is sent to the identification of the service provider, during these the like returns the initially still invalid password or to the user over the same connection.
The method can be applied if an access authorization for the use of a service should only be enabled by the service provider, if previously the authenticity of the identity of the service user was reviewed with high security. By checking the authenticity of the identity of the service user and the link between the release of the access code of the review, the possibility of abuse is greatly reduced by providing a false identity.
An abusive use is only possible when the terminal is already in possession of unauthorized persons at the time of registration. Other inventive embodiments
Further inventive embodiments are described in claims 2 to 8. FIG.
The limitation of the period in which the first invalid password can be used to authenticate the service user, further increases the security by the service user will be forced to authenticate in said time interval. An authentication after the time interval is not possible, the service user must re-register in this case, and then receives a new invalid password - claim. 2
After the service user has been successfully authenticated and them the password has been enabled by the service provider, it should be the service user able to change the password at its own discretion - to claim. 3
To increase security, you have the option to use the valid password to restrict so that the password is valid only for a predetermined number of uses. If this number is reached, the password is automatically set to invalid. The validity will only be restored by the Service user authenticates itself again by the method described in claim 1 - claim. 4
Encryption offers the service user the advantage that their personal information such as bank account, credit card number, etc., to third parties without authorization mitgelauscht -... Claim 5.
Encryption offers the service user the advantage that the invalid password and other details of the registration server are mitgelauscht without authorization by third parties - claim. 6
The GSM standard has highly secure procedures for ensuring the authenticity of a mobile user. Therefore, the transmission of the data is well suited from the terminal to the message converter - claim 7th
To establish the identity of the ISDN called "Calling Line Identification" can be used, which is used as a mark of identity for other purposes according to the prior art - to claim. 8 Solution of the problem concerning the device
This object is achieved by the features described in patent claim. 9
Some advantages
If the method is used according to claim 9 in a mobile network, created for the service user and the network operator the following advantages:
A mobile customer (service user) has signed a contract with the mobile network operators (service providers), it admits that the applicable fees are paid by direct debit by the mobile network operators. If the mobile customer decides for the use of an Internet service, which is also offered by the mobile network operator, he must register for this service. After registration, the customer should be able to use the service using the access authorization. The use of the service is also excluded by direct debit. In conjunction with the existing direct debit authorization, it is for the protection of mobile users and the mobile network operator's important to ensure the authenticity of the identity of registrants service user in order to avoid misuse. The Use of an ISDN network instead of a mobile telephone network leads to the same advantage.
In the drawing, the invention - partly schematically - illustrates an exemplary embodiment.
Numeral 1 is a data entry terminal is called a first terminal which is embodied here as a PC, while a whole by reference numeral 2, a service provider is called, of a registration server 3 and a short message service center as a message converter 4 includes.
The reference numeral 5 denotes a second terminal, the present case is designed as a mobile radio device.
The data input terminal 1 as the first terminal and the second terminal 5 are both registered with the service provider 2 for a service user. 6 This therefore means that the service provider 2 knows the personal data of the service user. 6 Usually that does the terminal 1 and the terminal 5 in possession of the same service user. 6
The data input terminal 1 can make secure 7, for example, Secure Socket Layer, with the registration server 3 of the service provider 2 contact, while the second terminal 5 with the message converter 4 via a connection 8, for example via a GSM mobile network, or over ISDN or SUS, can contact.
The procedure is as follows:
Step 1 :
The service user 6 occurs via the first terminal 1, ie on the data input terminal 1 via the secured connection 7 with the registration server 3 in conjunction who knows the personal data of the service user. 6
Step 2:
The registration server 3 transmits to the service user 6 on its data input terminal 1 over the same connection 7 a still invalid password (code number, TAN or the like).
Step 3:
The service user 6 reads the password, the identification number, TAN or the like onto his terminal. 1 Step 4:
The service user 6 sends the read off in step 3 password, the characteristic number or the like on its second terminal 5 via the connection 8, for example via a GSM network, the message converter. 4
Step 5:
The service provider 2 checks the via connection 7 to the data input terminal 1 sent password, the identifier or the like with the one of the service user like 6 received password or via the connection. 8 At equality the password, the ID or the like is valid and the service user is 6, the services of the service provider 2, for example the internet, avail.
The registration server 3, and the message converter 4 may be spatially combined. Furthermore, it is possible that the data entry terminal 1, which via the line 7 received from the registration server 3 password, the identification or the like automatically passes on the message converter 4 via a second terminal 5, and thus via the connecting eighth
The apparent in the abstract, in the claims and in the description described and in the drawing can be essential both individually and in any combination for implementing the invention.
LIST OF REFERENCE NUMBERS
1 data input terminal, terminal 1, PC
2 service provider
3 registration server
4 Short Message Service Center, message converter
5 terminal, second; Mobile device; Data entry terminal
6 service user
7 connection, secured
8 connection; GSM cellular network; ISDN; SUS TAN transaction number
bibliography
DE 197 18 103 A1
DE 197 22 424 C1
WO 95/19593 A1
Contents4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7054616B2 | Cited by | United States of America | Applicant |
| EP1408391A1 | Cited by | European Patent Office (EPO) | Search report |
| US7954137B2 | Cited by | United States of America | Applicant |
| DE10325089A1 | Cited by | Germany | Search report |
| WO2004034237A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN100347624C | Cited by | China | Search report |
| WO2004034237A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP1408391A1 | Cited by | European Patent Office (EPO) | Search report |
| WO2004034237A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| DE102014224427A1 | Cited by | Germany | Applicant |
| DE19722424C1 | Cites | Germany | International search |
| US5875394A | Cites | United States of America | International search |
16 members in 10 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 10007807 | Germany | A | |
| 10007807 | Germany | A | |
| 100078079 | – | – | – |
| DE2000107807 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| WO0162016A2This record | World Intellectual Property Organization (WIPO) | A2 | |
| WO0162016A3 | World Intellectual Property Organization (WIPO) | A3 | |
| NO20023738D0 | Norway | D0 | |
| NO20023738L | Norway | L | |
| EP1264490A2 | European Patent Office (EPO) | A2 | |
| JP2003523569A | Japan | A | |
| US2003159031A1 | United States of America | A1 | |
| JP2006318489A | Japan | A | |
| EP1264490B1 | European Patent Office (EPO) | B1 | |
| AT367060T | Austria | T | |
| DE50112712D1 | Germany | D1 | |
| PT1264490E | Portugal | E | |
| DK1264490T3 | Denmark | T3 | |
| ES2288509T3 | Spain | T3 | |
| NO326836B1 | Norway | B1 | |
| US7865719B2 | United States of America | B2 |
11 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: grant in national officeWWG | WWG | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Entry into the national phaseENP | ENP | JP | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)DFPE | DFPE | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO |
Numbers
- Publication
- 01/62016
- Publication, DOCDB
- 0162016
- Publication, EPODOC
- WO0162016
- Application
- 101469
- Application, DOCDB
- 0101469
- Application, EPODOC
- WO2001EP01469
Titles3
- German
- VERFAHREN ZUM FESTSTELLEN DER AUTHENTIZITÄT DER IDENTITÄT EINES DIENSTE-NUTZERS UND VORRICHTUNG ZUM DURCHFÜHREN DES VERFAHRENS
- English
- METHOD FOR ESTABLISHING THE AUTHENTICITY OF THE IDENTITY OF A SERVICE USER AND DEVICE FOR CARRYING OUT THE METHOD
- French
- PROCEDE PERMETTANT DE VERIFIER L'AUTHENTICITE DE L'IDENTITE D'UN UTILISATEUR DE SERVICES ET DISPOSITIF PERMETTANT DE METTRE EN OEUVRE CE PROCEDE
Classification
- CPC, 7
- H04L63/083
- G06F21/00
- G06F21/33
- G06F21/42
- H04L63/18
- H04W12/06
- H04L63/0846
- IPC, 6
- G06F21 00
- G06F21 33
- G06F21 42
- H04L9 32
- H04L29 06
- H04W12 06
Designated states24
- Regional, 20
- European Patent Office (EPO)
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye
- National, 4
- Japan
- Lithuania
- Norway
- United States of America