EP1649657A1 - Procede et dispositif d'accreditation d'un utilisateur a un fournisseur de services - Google Patents
Procede et dispositif d'accreditation d'un utilisateur a un fournisseur de servicesInfo
- Publication number
- EP1649657A1 EP1649657A1 EP03758197A EP03758197A EP1649657A1 EP 1649657 A1 EP1649657 A1 EP 1649657A1 EP 03758197 A EP03758197 A EP 03758197A EP 03758197 A EP03758197 A EP 03758197A EP 1649657 A1 EP1649657 A1 EP 1649657A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- accreditation
- user
- message
- provider
- identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 42
- 238000004891 communication Methods 0.000 claims description 27
- 238000012546 transfer Methods 0.000 claims description 15
- 238000012795 verification Methods 0.000 claims description 9
- 101001094649 Homo sapiens Popeye domain-containing protein 3 Proteins 0.000 claims description 8
- 101000608234 Homo sapiens Pyrin domain-containing protein 5 Proteins 0.000 claims description 8
- 101000578693 Homo sapiens Target of rapamycin complex subunit LST8 Proteins 0.000 claims description 8
- 102100027802 Target of rapamycin complex subunit LST8 Human genes 0.000 claims description 8
- 239000001095 magnesium carbonate Substances 0.000 claims description 7
- 238000013475 authorization Methods 0.000 claims description 6
- 239000001878 Bakers yeast glycan Substances 0.000 claims description 4
- 230000004913 activation Effects 0.000 claims description 4
- 239000000679 carrageenan Substances 0.000 claims description 4
- 235000010418 carrageenan Nutrition 0.000 claims description 4
- 239000000728 ammonium alginate Substances 0.000 claims description 3
- 235000010407 ammonium alginate Nutrition 0.000 claims description 3
- 239000000648 calcium alginate Substances 0.000 claims description 3
- 235000010410 calcium alginate Nutrition 0.000 claims description 3
- 238000012545 processing Methods 0.000 claims description 3
- 239000001099 ammonium carbonate Substances 0.000 claims description 2
- 238000004590 computer program Methods 0.000 claims description 2
- 238000012790 confirmation Methods 0.000 claims description 2
- 239000000737 potassium alginate Substances 0.000 claims description 2
- 235000010408 potassium alginate Nutrition 0.000 claims description 2
- BWHMMNNQKKPAPP-UHFFFAOYSA-L potassium carbonate Substances [K+].[K+].[O-]C([O-])=O BWHMMNNQKKPAPP-UHFFFAOYSA-L 0.000 claims description 2
- 230000008569 process Effects 0.000 description 13
- 235000014510 cooky Nutrition 0.000 description 12
- 239000000783 alginic acid Substances 0.000 description 5
- 235000010443 alginic acid Nutrition 0.000 description 5
- 230000008520 organization Effects 0.000 description 5
- 239000001904 Arabinogalactan Substances 0.000 description 3
- 230000004044 response Effects 0.000 description 3
- CDBYLPFSWZWCQE-UHFFFAOYSA-L sodium carbonate Substances [Na+].[Na+].[O-]C([O-])=O CDBYLPFSWZWCQE-UHFFFAOYSA-L 0.000 description 3
- 239000008272 agar Substances 0.000 description 2
- 235000010419 agar Nutrition 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 210000001747 pupil Anatomy 0.000 description 2
- 238000010200 validation analysis Methods 0.000 description 2
- GHOKWGTUZJEAQD-ZETCQYMHSA-N (D)-(+)-Pantothenic acid Chemical compound OCC(C)(C)[C@@H](O)C(=O)NCCC(O)=O GHOKWGTUZJEAQD-ZETCQYMHSA-N 0.000 description 1
- 102100024412 GTPase IMAP family member 4 Human genes 0.000 description 1
- 101000833375 Homo sapiens GTPase IMAP family member 4 Proteins 0.000 description 1
- 230000000977 initiatory effect Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000035755 proliferation Effects 0.000 description 1
- 239000000770 propane-1,2-diol alginate Substances 0.000 description 1
- 235000010409 propane-1,2-diol alginate Nutrition 0.000 description 1
- 230000011664 signaling Effects 0.000 description 1
- 239000000661 sodium alginate Substances 0.000 description 1
- 235000010413 sodium alginate Nutrition 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/30—Definitions, standards or architectural aspects of layered protocol stacks
- H04L69/32—Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
- H04L69/322—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
- H04L69/329—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
Definitions
- the present invention relates to a method and a device for authenticating access to a plurality of services through a telecommunications network and a method and a device for transferring accreditation messages. More specifically, the invention is in the field of unique authentication to service providers such as electronic messaging or email in Anglo-Saxon terminology, news groups or News Group in Anglo-Saxon terminology, servers private or other information via a network such as the Internet.
- service providers such as electronic messaging or email in Anglo-Saxon terminology, news groups or News Group in Anglo-Saxon terminology, servers private or other information via a network such as the Internet.
- User authentication allows access to a service or resources to be limited to only authorized persons for reasons of confidentiality or because the service is chargeable.
- the authentication of a user to a service also makes it possible to personalize the service rendered to the identified user.
- User authentication is a process that allows a user to prove their identity to a verification entity.
- the proof is provided by the user by providing the verification entity with a password that he previously obtained during registration.
- An identity provider is an entity capable of creating, managing identities associated with users of services, managing rights of use of a service and providing, as a verification entity, an authentication service for these services. .
- the password is either assigned by the identity provider or chosen by the user.
- Other types of evidence also exist. These are, for example, authentication from magnetic or smart cards or from a specificity of the user such as his fingerprint, his voice, the features of his face or the iris of one of his eyes. . Today, it is common for the same user to subscribe to a large number of services.
- the identity provider or Identity Provider in English created, manages identities associated with service users, manages rights to use a service and provides an authentication service for these services.
- the service provider provides services over the Internet. It is for example a service provider such as a server of a banking establishment or a server capable of making flight reservations for an airline, vehicle reservations for a vehicle rental company.
- a circle of trust or Circle of Trust in English is a set of identity providers and service providers sharing the identity provider between them and with which the users can carry out secure transactions.
- a user of a service provider of a trust circle can use his identification with the other service providers of the same trust circle. The user accesses this system through their HTTP browser.
- the communication protocol used between the HTTP browser and the identity and / or service provider is the HTTP protocol.
- HTTP is the acronym for Hypertext Transfer Protocol or hyper text transfer protocol.
- the user connects via his HTTP browser and the Internet to a service provider and the service provider redirects the latter to an identity provider.
- the identity provider authenticates the user according to a standard registration by password and delivers in return an accreditation while redirecting the HTTP browser to the access provider to which the user had previously connected.
- the accreditation is thus transmitted to the service provider in a transparent manner for the user to the provider.
- the accreditation includes, among other things, the identity of the user and proves that the user has been authenticated by the identity provider. This accreditation thus allows the service provider to authenticate the user and authorize user access to the services he offers or to transfer to the user a personalized WEB page.
- the accreditation is transferred from the identity provider to the HTTP browser in the form of a set of information, more precisely information of reduced size. This reduced-size information is known by the name
- Cookies are stored on the hard drive of the user's computer by the HTTP browser. The information stored in the cookie is then transmitted by the user's HTTP browser to the service provider. It is accreditation.
- the system as proposed by the Liberty Alliance project is a system based on the use of the HTTP communication protocol and Cookies.
- the identity provider must in this case be able to process the various commands of these HTTP browsers, which makes the creation of such a browser more complex.
- the user when the user wishes to connect to an electronic mail server or a news server, the latter must nevertheless authenticate in a conventional manner to these servers.
- the invention aims to solve the drawbacks of the prior art by proposing a method of transferring information by client software of a telecommunications terminal for the accreditation of a user of the telecommunications terminal to a supplier of services, the client software being connected to the service provider via a telecommunication network, an identity provider being accessible by software accessing inter alia the identity provider of the telecommunication terminal via a telecommunication network, characterized in that that the method comprises the steps of generation by the client software of a message intended for the software accessing inter alia the identity provider of the telecommunication terminal to obtain an accreditation of the identity provider, of obtaining by the client software d '' an accreditation of the identity provider of the software accessing inter alia the identity provider of the telecommunications terminal, and of generation by the client software of at least one message intended for the service provider, the message comprising at least information of the accreditation obtained.
- the invention provides a device for transferring information by client software of a telecommunication terminal for the accreditation of a user of the telecommunication terminal to a service provider, the client software being linked to the service provider.
- an identity supplier being accessible by software accessing, inter alia, the identity supplier of the telecommunications terminal by means of a telecommunications network
- the device includes means by the client software for generating a message intended for the software accessing, inter alia, the identity provider of the telecommunications terminal in order to obtain accreditation from the identity provider, means for obtaining, by the client software, accreditation from the software identity provider accessing, among other things, the identities of the telecommunication terminal, and means of generation by the client software of at least one message intended for the service provider, the message comprising at least information of the accreditation obtained.
- the user of a telecommunications terminal comprising the present invention no longer has to communicate his username and password to each service provider and to each access to the service providers, this is done automatically, and without any user intervention.
- the tasks of the user are thus simplified, the user only has to register once with the identity provider by communicating his username and password.
- a telecommunication terminal comprises a plurality of software capable of accessing an identity provider, only one of these software has access to the service provider. This improves the performance of the accreditation system and also allows access to the identity provider with the most suitable software.
- the information exchanged between the client software of the telecommunication terminal and the service provider conforms to a first communication protocol and the information exchanged between the software accessing inter alia the identity provider of the telecommunication terminal and the provider of identities conform to a second communication protocol different from the first protocol.
- the client software activates the software accessing inter alia the identity provider of the telecommunication terminal.
- the tasks of the user are simplified, all these operations are carried out automatically and without intervention of the latter.
- the information on the accreditation obtained is an accreditation code.
- the message generated by the client software intended for the software accessing, inter alia, the identity provider of the telecommunications terminal comprises an identifier of the user of the telecommunications terminal, an identifier of the service provider and an identifier of the provider d 'identities.
- the software accessing, inter alia, the identity provider has all the information necessary for accreditation by the identity provider of the telecommunications terminal user. More particularly, the software accessing inter alia the identity provider generates at least one message intended for the identity provider comprising at least the identifier of the user of the telecommunications terminal and the identifier of the service provider, obtains a accreditation of the identity provider, the accreditation being in the form of a cookie comprising the identity of the user, the identity of the identity provider, the identity of the service provider and an accreditation code and transfers at least the client software accreditation code.
- the transfer of information between the software accessing inter alia the identity provider and the identity provider remains in accordance with single authentication systems such as the system proposed by the Liberty Alliance project.
- the information exchanged between the software accessing inter alia the identity provider of the telecommunication terminal and the identity provider conforms to the HTTP protocol and in that the software accessing inter alia the identity provider of the telecommunication terminal is Browser
- the information exchanged between the client software of the telecommunications terminal and the service provider conforms to an SMTP protocol or to an NNTP protocol or to a POP3 protocol or to an IMAP protocol or to an XMPP protocol, or to a protocol SIP or H323 protocol.
- the service provider determines in the received message the presence of an accreditation code issued by an identity provider, if an accreditation code is present in the received message, the service provider checks the conformity of the accreditation code and authorizes the user of the telecommunications terminal to access at least one service of the service provider and if an accreditation code is not present in the message, the service provider checks the conformity of a password associated with the user and authorizes the user of the telecommunications terminal to access at least one service of the service provider.
- the invention also relates to a method for processing an accreditation message of a user of a telecommunications terminal by a service provider, the accreditation message being transferred by client software of the telecommunications terminal via a telecommunications network in accordance with a communication protocol, characterized in that the method comprises the steps of determining in the message received the presence of an accreditation code issued by a supplier 'identities, if an accreditation code is present in the message received, of verification of the conformity of the accreditation code and authorization of the user of the telecommunications terminal to access at least one service of the service provider and if a accreditation code is not present in the message, verification of the conformity of a password associated with the user and authorization of the user of the telecommunications terminal to access at least one service of the service provider .
- the invention provides a device for transferring information by client software of a telecommunication terminal for the accreditation of a user of the telecommunication terminal to a service provider, the client software being linked to the service provider. via a telecommunication network, the information exchanged between client software of the telecommunication terminal and the service provider conforming to a first communication protocol, an identity provider being accessible by software accessing inter alia the identity provider of the telecommunication terminal via a telecommunication network, characterized in that the information exchanged between the software accessing inter alia the identity provider of the telecommunication terminal and the identity provider conforms to a second different communication protocol of the first protocol and in that the device comprises means for generating a message intended for the software accessing inter alia the identity provider of the telecommunication terminal to obtain accreditation from the identity provider, means for obtaining '' an accreditation of the identity provider of the software accessing inter alia the identity provider of the telecommunications terminal and means for generating at least one message intended for the service provider, the message comprising at least information from the accreditation
- the service provider is able to process accreditations in accordance with the present invention while remaining compatible with authentications by communication of identifier and password.
- the accreditation code is included in a message field intended to include a password for the user of the telecommunications terminal.
- the verification of the conformity of the accreditation code is carried out by decrypting said identification code or by questioning the identity provider to obtain confirmation of said accreditation.
- the invention also relates to computer programs stored on an information medium, said programs comprising instructions making it possible to implement the methods described above, when they are loaded and executed by a computer system.
- FIG. 1 represents the telecommunications system in which the single authentication process is implemented and in which at least two service providers offer services to users according to different communication protocols;
- Fig. 2 shows the block diagram of a telecommunications terminal according to the invention;
- Fig. 3 shows a service provider according to the invention;
- Fig. 4 shows the algorithm performed by the telecommunication device according to the invention;
- Fig. 5 shows the algorithm performed by the service provider according to the invention.
- Fig. 1 shows the telecommunications system in which the single authentication process is implemented and in which at least two service providers offer services to users according to different communication protocols.
- the communication system 100 consists of at least one telecommunication terminal 10 which accesses, via client software 11, 12 and software 13 accessing inter alia the identity provider 16 via a network of telecommunications such as the Internet 120, to service providers 14, 15, 17 and 18. Access to these service providers is subject to user accreditation by an identity provider 16.
- the service provider 14 is for example a server for exchanging news or discussion forums.
- the user of the telecommunications terminal 10 communicates via his news exchange client software 11 with the news exchange server 14 in accordance with the NNTP protocol.
- the NNTP protocol acronym for Network News Transfer Protocol
- the NNTP protocol is a protocol which ensures the exchange of news between the news exchange server 14 and the news exchange client software of the telecommunications terminal 10 for both reading and for writing short stories.
- the NNTP protocol is a protocol from an IETF organization, acronym for the Internet Engineering Task Force, it complies with RFC 977, RFC being the acronym for Requests For Comments.
- the service provider 15 is for example an electronic mail server.
- the user of the telecommunications terminal 10 communicates via his electronic messaging client software 12 with the electronic messaging server in accordance with the SMTP protocol.
- the SMTP protocol acronym for Simple Mail Transfer Protocol, is a protocol which ensures the exchange of electronic messages between the electronic mail server 15 and the telecommunications terminal 10 for both reading and reading.
- the SMTP protocol is also a protocol originating from an IETF organization, it complies with RFC 821. It should be noted here that, as a variant, the user of the telecommunications terminal 10 communicates via his messaging client software 12 with the e-mail server in accordance with the POP3 or IMAP4 protocol.
- the POP protocol acronym for Post Office Protocol or post office protocol allows a user of a telecommunication terminal 10 to consult his electronic mail on the electronic mail server 15. This protocol allows users of telecommunication terminals that are not permanently connected to the telecommunication network 120 to collect the e-mails they received in their mailbox when they were not connected to the telecommunication network 120.
- the POP3 protocol also manages user authentication using a user name and password.
- the IMAP protocol acronym for Internet Mail Access Protocol or Internet Mail Access Protocol is a protocol offering many more possibilities than the POP 3 protocol.
- the IMAP protocol allows for example to manage several accesses to a mailbox simultaneously, it It also allows you to manage several mailboxes simultaneously and it also allows you to sort emails by different criteria.
- the POP3 protocol is also a protocol originating from an IETF organization, it complies with RFC 1939.
- the IMAP protocol is also a protocol originating from an IETF organization, it complies with RFC 2060 and 2061.
- the service provider 17 is by an example a server of a banking establishment. The user of the telecommunications terminal 10 communicates via the HTTP browser 13 with the service provider 17 according to the HTTP protocol.
- the service provider 18 is, for example, a server capable of making flight reservations for an airline.
- the user of the telecommunications terminal 10 communicates via the HTTP browser 13 with the service provider 18 according to the HTTP protocol.
- the HTTP protocol is also a protocol originating from an IETF organization, it complies with RFC 2816.
- the identity provider 16 creates, manages and maintains the identities associated with users and provides an authentication service.
- the identity provider 16 is linked to a local or remote database 19. This database contains all the identifiers of the users who have been previously registered as well as information representative of the access rights of these users to the various service providers 14, 15, 17 and 18. These access rights are obtained by exchanges of information noted 130 in FIG. 1 between the different service providers 14, 15, 17 and 18 and the identity provider 16.
- the user of the telecommunications terminal 10 when the user of the telecommunications terminal 10 is authorized to access the electronic mail server 15, this information is stored in the database 19.
- the user of the telecommunications terminal 10 communicates via the HTTP browser 13 with the identity provider 16 according to the HTTP protocol.
- the exchanges between the browser 13 and the service providers 17 and 18 and the identity provider 16 are for example in accordance with those as described in the Liberty Alliance project.
- the electronic messaging client software 12 when the user of the telecommunications terminal 10 wishes to connect to the service provider 15, the electronic messaging client software 12 generates a request 101 intended for the HTTP browser 13 to obtain accreditation from the electronic messaging server. 15.
- the HTTP browser 13 transfers to the electronic mail client software 12 the accreditation 104 obtained from the identity provider 16 in the form of a Cookie. Accreditation is obtained by the HTTP 13 browser by generating a request
- HTTP 102 to the identity provider 16 which after consulting the database 19 transfers the accreditation 103 in the form of a cookie to the HTTP browser 13.
- the accreditation 103 or part of the information contained in the cookie received is then transferred to the electronic mail client software 12 which then transfers this accreditation message to the electronic mail server 15 in a form adapted to the SMNP communication protocol.
- the electronic mail server 15 on the basis of this accreditation message, authorizes the user of the telecommunication terminal 10 to access its services, without any user and password input.
- the client software 11 and 12 can also alternatively use protocols such as the SIP protocol, XMPP or the H323 protocol.
- SIP is the acronym for Session Initiation Protocol or signaling and intermediation protocol defined by LTETF.
- XMPP is the acronym for eXtented Message and Presence Protocol as proposed to 1TETF.
- H323 is a recommendation from the International Telecommunication Union for multimedia communication systems.
- Fig. 2 shows the block diagram of a telecommunications terminal according to the invention.
- the telecommunications terminal 10 is adapted to operate in a single accreditation system for service providers 14, 15, 17 and 18 able to exchange information according to different communication protocols.
- the telecommunications terminal 10 is for example a microcomputer. It can also be integrated into a personal assistant or a mobile phone.
- the telecommunications terminal 10 comprises a communication bus 201 to which a central unit 200, a read only memory 202, a random access memory are connected.
- the hard disk 208 stores the program implementing the invention which will be described later with reference to FIG. 4, as well as the data allowing the unique accreditation according to the invention. These data are, among other things, the different accreditations to service providers 14, 15, 17 and 18.
- the hard disk 208 also stores the HTTP navigation software 13, the email client software 12 and the client software for exchanging news 11
- the programs implementing the invention can also be read via the compact disc player 209 or received via the telecommunications network 120. More generally, the programs according to the present invention are stored in a storage means. .
- This storage means can be read by a computer or a microprocessor 200. This storage means is integrated or not in the device, and can be removable. It should be noted that when the telecommunications terminal is a personal assistant known under the term PDA, or a mobile telephone, the hard disk 208 is replaced by an information storage means such as for example a memory of SDRAM type.
- PDA personal assistant
- the telecommunications terminal 10 is powered up, or when one of the client software 11 or 12 is launched, the programs according to the present invention are transferred into the random access memory 203 which then contains the executable code of the invention as well as the data necessary for the implementation of the invention.
- the telecommunication terminal 10 comprises a screen 204 capable of reproducing the information received from the service providers 14, 15, 17 and 18.
- the screen 204 is also an element of the man-machine interface of the telecommunication terminal 10 for the first identification and authentication of the user of the telecommunications terminal 10.
- the telecommunications terminal 10 also includes a keyboard 205 also serving as a man-machine interface. By means of this keyboard 205, the user can enter his password during his first authentication with the identity provider 16. It should be noted here that the keyboard 205 can also be replaced by a touch screen , a mouse, or any other type of human-machine interface.
- the telecommunication terminal also comprises means for capturing fingerprints or means for obtaining characteristics of a pupil of the user of the telecommunication terminal 10. For the sake of clarity, the means for capturing fingerprints and characteristics of a pupil of the user are not shown in FIG.
- the service provider is for example the electronic mail server 15.
- the news exchange server 14 being identical to the electronic mail server 15, it will not be described.
- the electronic messaging server 15 is for example a microcomputer. It can also be integrated into a personal assistant or a mobile phone.
- the electronic messaging server 15 comprises a communication bus 301 to which a central unit 300, a read-only memory 302, a random access memory 303, a hard disk 308, a compact disc or CD player / recorder 309, a communication interface are connected.
- 306 with a telecommunications network such as the Internet 120.
- the hard disk 308 stores the program implementing the invention which will be described later with reference to FIG. 5.
- the program implementing the invention can also be read via the compact disc player 309 or received via the telecommunications network 120.
- the hard drive 308 also stores the emails of users of telecommunications terminals subscribed to its services as well as information to authenticate these users. This information is user identifiers with their associated passwords or, according to the invention, information enabling validation of the accreditation received according to the invention.
- the programs according to the present invention are stored in a storage means.
- This storage means can be read by a computer or a microprocessor 300. This storage means is integrated or not into the device, and can be removable.
- the input-output interface 306 is a communication interface capable of ensuring the exchange of information via the Internet network 120 with users of telecommunications terminals.
- the input-output interface 306 ensures these exchanges of information in accordance with the SMTP protocol. It should be noted that, as a variant, the input-output interface 306 ensures these exchanges of information in accordance with the POP3 protocol or the IMAP protocol.
- Fig. 4 shows the algorithm performed by the telecommunications device according to the invention.
- the processor 200 of the telecommunications terminal 10 reads, from the memory 202, the instructions of the program corresponding to steps E400 to E409 of FIG. 4 and loads them into random access memory 203 to execute them.
- step E400 for example the electronic messaging client software 12
- the processor 200 of the telecommunications terminal 10 proceeds to the next step E401.
- the processor 200 checks whether the HTTP navigation software 13 of the telecommunications terminal 10 is activated. If the HTTP browser 13 is not activated, the processor 200 generates in step E402 a command for the activation of the latter. This operation carried out or if the HTTP browser 13 is already activated, the processor 200 goes to the next step E403. At this stage, a request noted 101 in FIG.
- This request is transferred from the electronic messaging client software 12 to the HTTP browser 13.
- This request is transferred for example by means of messages from applications to applications managed by the operating system of the telecommunications terminal 10.
- This request includes the identifier of the user, for example his electronic mail address mdupont@wanadoo.fr, an identifier such as the address of the service provider 15 smtp-smtp.wanadoo.fr and an identifier such as the address of the identity provider 16 pau.wanadoo.fr.
- the address of the identity provider 16 was previously obtained by the email client software 12 during previous exchanges in accordance with the SMTP protocol with the email server 15.
- the HTTP browser 13 transfers a request denoted 102 in FIG.
- the identity provider 16 determines from the identifier of the user and more precisely from the electronic mail address of the user of the telecommunications terminal 10 whether or not the latter is authorized to access the service provider whose address is contained in request 102.
- the identity provider 16 interrogates with this information the database 19 of FIG. 1 and thus determines whether the user of the telecommunications terminal 10 is authorized or not to access the service of the electronic messaging server 15.
- the identity provider 16 enters an identification and authentication procedure with the HTTP browser 13 with the user entering his identifier and a password.
- the identity provider 16 in response to the request 102 received in step E404 transfers an HTTP message noted 103 in FIG. 1 intended for the HTTP browser 13.
- the HTTP browser 13 on receipt of the message 103 checks whether this message is an accreditation message.
- the accreditation message is, according to our example, a Cookie comprising inter alia the identity of the user of the telecommunications terminal 10, the identity of the identity provider, the identity of the service requested and an accreditation code.
- step E406 If the identity provider 16 refuses access by the user of the telecommunications terminal 10 to the electronic messaging server 16, the processor 200 goes to step E406 and generates a message intended for the screen 204 informing the user of the telecommunication terminal 10 of the rejection of the request for access to the electronic mail server 16.
- the algorithm of FIG. 4 stops and the processor 200 returns to step E400 awaiting a new activation of client software, for example the client software for exchanging news 11.
- the processor 200 passes to step E407.
- the HTTP browser 13 transfers to the electronic messaging client software 12 a message noted 104 in FIG. 1.
- This message can be the Cookie previously received from the identity provider 16 or only part of the information contained in the Cookie received, such as for example the accreditation code.
- steps E404, E405, E406 and E407 are steps performed by the HTTP browser 13.
- the http browser 13 can include these steps during its creation or these same steps can be added to an HTTP browser which comes connect to existing software and that improves the functionality of the program to which it connects.
- the electronic messaging client software 12 On receipt of the message 104, the electronic messaging client software 12 generates in step E408 an authentication message noted 105 in FIG. 1 conforms to the SMTP protocol intended for the electronic mail server 15. As a variant, the authentication message 105 conforms to the POP3 protocol or to the IMAP protocol.
- This authentication message includes the identity of the user of the telecommunications terminal as well as the accreditation code previously transferred by the identity provider 16.
- the accreditation code replaces for example the classic password of the user of the telecommunication terminal 10.
- the user of the terminal telecommunications 10 has access to step E409 to the services offered by the service provider 15.
- the user of the telecommunications terminal 10 accesses his electronic mail.
- the algorithm of FIG. 4 has been described according to the example of access to an electronic mail server.
- the news exchange client software 11 is activated, the steps E400 to E409 are iterated in the same manner as that previously described.
- the news exchange client software 11 generates in step E408 an authentication message conforming to the NNTP protocol intended for the news exchange server 14.
- This authentication message comprises the identity of the user of the terminal as well as an accreditation code previously transferred by the identity provider 16.
- the accreditation code replaces for example the classic password of the user of the telecommunication terminal 10.
- the client software during the activation of the client software in step E400, the client software generates a request intended for a service provider via the telecommunications network 10 which in response redirects this message to the http browser 13 of the telecommunications terminal 10.
- the service provider redirects the message, the address of the identity provider 16 is added to it who he is associated with.
- Fig. 5 shows the algorithm performed by the service provider according to the invention.
- the processor 300 of the service provider 14 or 15 reads, from the memory 302, the instructions of the program corresponding to steps E500 to E504 of FIG. 5 and loads them into RAM 303 to execute them.
- the service provider for example the electronic messaging server 15 receives a message from the electronic messaging client software 12. This message conforms to the message previously described in step E408 of FIG. 4. This message conforms to the SMTP protocol or alternatively to the POP3 or IMAP protocol.
- the processor 300 goes to the next step E501. At this stage, the processor 300 determines the type of information contained in the message received.
- the service provider is able to process conventional authentication of the identifier and password type
- the service provider is also able to process authentication comprising an accreditation code issued by a service provider. identities operating in a protocol different from the communication protocol used by the service provider.
- the accreditation code is, in the message, in place of the password of the user of the telecommunications terminal 10 wishing to access the services provided by the service provider.
- the processor 300 determines in the received message whether or not an accreditation code is included in the message. If not, the processor 300 goes to step E502 and enters into a conventional procedure for identifying and authenticating the user of telecommunication terminal 10 with information of the identifier and password type.
- step E504. If an accreditation code is included in the message, the processor 300 goes to step E503. At this stage, the processor 300 uses a decryption key and decodes the accreditation code. If the decoded accreditation code conforms to information previously exchanged between the electronic messaging server 15 and the identity provider 16, the processor goes to step E504. It should be noted that, as a variant, the processor 300 does not decrypt the accreditation code and generates a validation request message represented by the link 130 in FIG. 1 to the identity provider 16. If the identity provider validates this message, the processor 300 goes to step E504. In step E504, the electronic messaging server 15 authorizes the user of the telecommunication terminal 10 to access the memorized mailbox.
- the algorithm of FIG. 5 has been described according to the example of access to an electronic mail server.
- steps E500 to E504 are iterated in the same way by the news exchange server 14 as that previously described.
- the messages passing between the news exchange server 14 and the news exchange client software 11 are in accordance with the NNTP protocol.
- the present invention is not limited to the embodiments described here, but encompasses, quite the contrary, any variant within the reach of ordinary skill in the art.
- the client software is linked to the service providers 14 or 15 via an Internet telecommunications network 120.
- the invention is also applicable in the context of a local telecommunications network, such as a corporate intranet.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/FR2003/002449 WO2005022864A1 (fr) | 2003-08-01 | 2003-08-01 | Procede et dispositif d'accreditation d'un utilisateur a un fournisseur de services |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1649657A1 true EP1649657A1 (fr) | 2006-04-26 |
Family
ID=34259337
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP03758197A Withdrawn EP1649657A1 (fr) | 2003-08-01 | 2003-08-01 | Procede et dispositif d'accreditation d'un utilisateur a un fournisseur de services |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP1649657A1 (fr) |
| AU (1) | AU2003274214A1 (fr) |
| WO (1) | WO2005022864A1 (fr) |
-
2003
- 2003-08-01 WO PCT/FR2003/002449 patent/WO2005022864A1/fr not_active Ceased
- 2003-08-01 AU AU2003274214A patent/AU2003274214A1/en not_active Abandoned
- 2003-08-01 EP EP03758197A patent/EP1649657A1/fr not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2005022864A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| AU2003274214A1 (en) | 2005-03-16 |
| WO2005022864A1 (fr) | 2005-03-10 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1327345B1 (fr) | Procede de controle d'acces a des adresses de sites internet | |
| US20090077649A1 (en) | Secure messaging system and method | |
| FR2985130A1 (fr) | Procede de partage d'un contenu multimedia entre au moins un premier utilisateur et un second utilisateur sur un reseau de telecommunications | |
| EP2001196A1 (fr) | Gestion d'identité d'usager pour accéder à des services | |
| WO2012097864A1 (fr) | Partage de contenu en ligne | |
| EP1537718B1 (fr) | Serveur de selection automatique d'authentification | |
| WO2006084960A1 (fr) | Systeme de selection automatique d’authentification | |
| EP2795870A1 (fr) | Procede d'acces par un terminal de telecommunication a une base de donnees hebergee par une plateforme de services accessible via un reseau de telecommunications | |
| WO2005006646A9 (fr) | Méthode de sécurisation d'un certificat électronique | |
| EP4241416B1 (fr) | Procede de delegation d'acces a une chaine de blocs | |
| WO2005034468A1 (fr) | Systeme d'acces a un reseau adapte pour la mise en oeuvre d'un procede a signature simplifiee, et serveur pour sa realisation | |
| WO2006010810A2 (fr) | Procede et systeme de certification de l’identite d’un utilisateur | |
| EP1649665A2 (fr) | PROCEDE ET SYSTEME DE DOUBLE AUTHENTIFICATION SECURISEE D UN UTILISATEUR LORS DE L ACCES A UN SERVICE PAR L’INTERM EDIAIRE D UN RESEAU DE TRANSMISSION DE DONNEES. | |
| EP1637989A1 (fr) | Procédé et système de séparation de comptes de données personnelles | |
| EP1649657A1 (fr) | Procede et dispositif d'accreditation d'un utilisateur a un fournisseur de services | |
| EP3206149B1 (fr) | Procede de controle d'un parametre indicatif d'un niveau de confiance associe a un compte utilisateur d'un service en ligne | |
| EP1413120A2 (fr) | Procede de communication pour echanger de maniere controlee des donnees entre un teminal client et un reseau de sites hotes et ensemble serveur de protection pour la mise en oeuvre de ce procede | |
| EP4128700A1 (fr) | Procede et dispositif d'authentification d'un utilisateur aupres d'une application | |
| EP4187409A1 (fr) | Procédé et système d'authentification d'un utilisateur sur un serveur d'identité as a service | |
| EP4362391B1 (fr) | Procédé de gestion d'accès d'un utilisateur à au moins une application, programme d'ordinateur et système associés | |
| FR2864283A1 (fr) | Procede et dispositif de controle d'acces a un document partage dans une reseau de communication poste a poste | |
| FR2827458A1 (fr) | Procede d'acces a un service specifique propose par un operateur virtuel et carte a puce d'un dispositif correspondant | |
| FR3156939A1 (fr) | Procédé pour contrôler l’accès d’un utilisateur d’une chaîne de blocs à un serveur informatique lié à ladite chaîne de blocs | |
| EP1642442A1 (fr) | Dispositif de personnalisation du traitement de communications | |
| EP1484895A1 (fr) | Procédé d'accès à un réseau ou à un service en utilisant un protocole de la famille de protocoles PPPoX, et architecture mettant en oeuvre une tel procédé |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20051205 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PT RO SE SI SK TR |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: CROM, JEAN-MICHEL Inventor name: MAINARD, LAURENT Inventor name: MERCIER, VALERIE |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: MERCIER, VALERIE Inventor name: MAINARD, LAURENT Inventor name: CROM, JEAN-MICHEL |
|
| 17Q | First examination report despatched |
Effective date: 20060328 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20101012 |