EP1680905A1 - Procede de transfert de donnees confidentielles en coeur de reseaux - Google Patents
Procede de transfert de donnees confidentielles en coeur de reseauxInfo
- Publication number
- EP1680905A1 EP1680905A1 EP04805271A EP04805271A EP1680905A1 EP 1680905 A1 EP1680905 A1 EP 1680905A1 EP 04805271 A EP04805271 A EP 04805271A EP 04805271 A EP04805271 A EP 04805271A EP 1680905 A1 EP1680905 A1 EP 1680905A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- data
- user
- communication equipment
- confidential data
- provider
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/22—Parsing or analysis of headers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/30—Definitions, standards or architectural aspects of layered protocol stacks
- H04L69/32—Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
- H04L69/322—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
- H04L69/329—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
Definitions
- the present invention relates to a method for transferring confidential data at the heart of networks. It finds application in particular in the fields of transactions using the Internet. In the technical field of computer communications, users who want to consult data content via a computer network such as the Internet, must in most cases obtain a connection resource from a provider of access to the computer network.
- this file cannot be used by another content provider and must therefore be reconstituted by the latter for its own account, which adds an entry under the responsibility of the user and the existence of a new file ("cookie") which the latter generally ignores the existence.
- a "trusted third party" to whom the user transmits his confidential data once and for all.
- the content provider contacts the trusted third party to securely obtain the user's confidential data.
- the exchange with the trusted third party is done with a means of data protection which is not at the discretion of the content provider.
- the trusted third party needs to place “cookie” type files on the user's terminal and the latter must still have registered with the trusted third party.
- the trusted third party is also in possession of a large number of confidential data, which exposes it to the lusts of hackers who can follow secure transactions by accessing the “cookie” files signed by the trusted third party at least on user machines.
- the "trusted third party" provides each user who requests it, software which makes it possible to memorize the confidential data of the user necessary for the execution of transactions with subscribed content providers for which the user has indicated his intention to be able to access it and to conduct transactions such as debit cards.
- the user must still correspond with a third party supplier of the software to establish a part of the transaction, in particular the banking part of the transaction when it puts implement a payment by bank card.
- the present invention provides a remedy to these drawbacks of the state of the art.
- Internet users who use the services of an Internet service provider, exchange confidential data. Such data could be intercepted by people who could surprise the secret that the parties expect from a data exchange. This will be the case for a file containing professional data such as manufacturing secrets.
- the sending party performs encryption of the data which is then transmitted to the receiving party to be decrypted there. Such encryption guarantees data confidentiality and data integrity.
- the present invention remedies this other drawback of the state of the art. Indeed, it relates to a method for transferring confidential data between at least one user terminal and communication equipment belonging to a supplier of content, the terminal having received attributes for connection to a data processing network owned by an access provider.
- the method of the invention consists: - on the side of the user terminal transmitting confidential data, to send, via the network, a service request for content constituted according to a predetermined protocol intended for the communication equipment of the supplier of contents; - then, on the side of a communication equipment belonging to the access provider: • to intercept the service request according to the address of the communication equipment of the content provider; • to execute an encryption service for confidential data relating to the terminal user; • modify the service request intercepted by inserting encrypted confidential data into it; • and re-route the modified service request to the communication equipment of the content provider; - then, on the communication equipment side of the content provider: • to receive the modified service request; • extract the encrypted confidential data in relation to the address of the user terminal, • and decrypt the encrypted confidential data, using a decryption key compatible with the encryption key.
- the method also includes a preparatory step which consists on the side of the communication equipment of the access provider: - to constitute, during a registration procedure, a file comprising the confidential data associated with the terminal user at the same time as his network access account data; - to constitute, during an authorization procedure, an authorization data file of the content provider, such an authorization file containing at least data relating to the identification of the authorized content supplier.
- the authorization file also contains an encryption key which is used during the step of encryption of confidential data relating to the user of the terminal by the communication equipment of the supplier d 'access.
- the present invention also relates to communication equipment belonging to a provider of access to a computer network which offers a service for transferring confidential data between at least one user terminal and communication equipment belonging to a content provider.
- the communication equipment of the access provider is remarkable in that it comprises: - an interception module for intercepting, as a function of the address of the communication equipment of the content provider, a service request d content constituted according to a predetermined protocol, such a request being sent from the user terminal to the communication equipment of the content provider; - an encryption module for encrypting confidential data relating to the user of the terminal; - a request modification module for inserting the encrypted confidential data in the intercepted service request; - And a module for re-routing the modified service request to the communication equipment of the content provider.
- the communication equipment of the access provider further comprises a module for executing a preparatory step of registering users and authorizing content providers.
- the execution module of the preparatory step comprises: a web server to which, on the one hand, the user's terminal transmits confidential data, and, on the other hand, the communication equipment of the content provider transmits authorization data, - a first storage sub-module in which the confidential data are recorded, - and a second storage sub-module in which the authorization data are recorded .
- the interception module and the redirection module are contained in a proxy-cache device, while the encryption module and the module are contained in a server implementing an interface which supports an HTTP data flow transfer protocol.
- the present invention also relates to communication equipment belonging to a content provider authorized beforehand with a provider of access to a computer data network which offers a service for transferring confidential data between at least one user terminal and this communication equipment.
- the communication equipment of the content provider is remarkable in that it comprises: a module for receiving a service request for content sent by the terminal, such a request comprising confidential encrypted data relating to the terminal user; - A module for extracting encrypted confidential data in relation to the address of the user's terminal, - and a module for decrypting confidential encrypted data using a decryption key compatible with the encryption key.
- the present invention also relates to a server implementing an interface which supports a data flow transfer protocol.
- Such a server is remarkable in that it comprises: - a module for receiving, coming from a terminal, a service request for content constituted according to the aforementioned protocol, - a module for establishing a correspondence between the address allocated to the terminal and at least one confidential datum relating to the user of the terminal, the confidential datum being previously recorded in a storage sub-module, - a module for verifying the agreement of the user for the transmission of confidential data relating to the latter, the confidential data also being recorded beforehand in the storage sub-module, - an export module for extracting, in the case where the verification is positive, on the one hand, the data confidentiality of the storage sub-module, and on the other hand, an encryption key previously registered in a storage sub-module belonging to a supplier of contents for which the service request is intended, - a module for encrypting confidential data by means of the extracted encryption key, - a request modification module for inserting the encrypted confidential data in a particular field of the service request, - And a module for retransmission
- the present invention also relates to a system for transferring confidential data between at least one user terminal and communication equipment belonging to a content provider, the terminal having received connection attributes to a data processing network owned by an access provider.
- the user terminal transmitting confidential data comprises a module for transmitting, via the aforementioned network, a service request for content constituted according to a predetermined protocol intended for the equipment.
- content provider communication - the communication equipment of the content provider is that defined above, and in that it further comprises: - communication equipment belonging to the access provider, as defined above.
- FIG. 1 represents a procedure for transaction of confidential data according to a state of the art
- - Figure 2 is a flowchart showing a particular embodiment of the method of the invention
- Figure 3 is a block diagram of a system implementing the method of the invention
- Figures 4 (a) and 4 (b) are diagrams of databases used in the method of the invention
- FIG. 5 is a block diagram of a system implementing another embodiment of the method of the invention.
- the user terminal 1 which can be a desktop computer or even a mobile phone, is connected to the computer network via a provider of access to the computer network 2. Such a connection is only possible if the user 1 is registered with the access provider 2.
- the user indicates a certain number of confidential data determined by the access provider 2.
- a content provider 4 is connected to the computer network 2. During of his registration, the content provider 4 indicates the type of confidential data that users who connect to his site could be led to exchange with him.
- the computer network access provider determines the confidential data that it must request from its users when they first register with the network.
- the user 1 connects along the path 5 to the content provider 4, the latter presents him, along the path 10, requests tending to transmit confidential data held directly by the access provider 2.
- the content provider 4 transmits a request 6 to a billing third party 3.
- the billing third party 3 then sends to the network access provider 2 a data transfer request confidential data associated with both user 1 and its recipient 4.
- the network access provider 2 consults the databases and extracts confidential data relating to user 1. It transmits the confidential data requested to an invoicing third party 3 according to an encrypted procedure 8, which then sends invoicing processing to benefit of the digital content provider 4 in respect of the user and which transmits an acknowledgment of the transaction to the content provider by means of a return connection 9.
- the content provider 4 informs its user 1 of the execution of the transaction constituted by the transfer of the confidential data requested.
- FIG. 2 a flowchart has been represented. of an embodiment of the method of the invention.
- a start step S 1 which can be initiated as soon as a user and / or content provider is detected.
- a loop B 1 during which a preparatory step S2 is executed.
- a step S21 of registering a new user is performed or a step S22 of enabling a new content provider is performed. If the user or the content provider is not identified as registered or authorized, we enter a registration or authorization phase.
- the registration phase makes it possible to constitute a confidential data file associated with a user at the same time as his data account for access to the computer network during a registration procedure held by the supplier of access to the computer network as the Internet.
- the authorization phase aims to constitute an authorization data file for at least one content provider.
- This content provider for example, owns a website and offers services requiring the communication of confidential user data.
- this user is registered with the network access provider
- the Internet and the confidential data requested by the content provider are recorded in the confidential data file associated with this user when he requests the services of the content provider.
- These services can be market services, purchase of multimedia documents over the Internet, or indirectly products or services, for example sold by a multimedia catalog produced by the content provider.
- these services may also not be market services and for example consist of the transmission of confidential data produced by the user so that a special treatment is carried out by the content provider.
- the confidential data consists of a data file returned by the content provider to the user.
- the exchanges of keys of two-key encryption procedures are carried out when personal data of the registration and / or authorization procedures are updated with the Internet Service Provider.
- the data file can be directly associated in an HTTP request, for example on a method called "POST Method" or in the form of a URL address or an indirect reference to a data file to be encrypted.
- the authorization file is constructed using an application owned by the Internet access provider on the database relating to the identification of the authorized content provider and, where appropriate, configuration data to prepare a transaction with at least one registered user.
- the access provider has an application that allows him to request the confidential data required speak authorization file for each content provider with which the user wishes to have contact. If one of the partners, user or content provider, is not registered, the access provider has a registration application or an authorization application to enter it into the transfer service of confidential data of the invention. If either partner refuses, the service is interrupted (not shown).
- the preparatory phase S2 is immediately ended. Note that a communication between a single user and a single content provider is described here. It will be understood that more than one user can be connected in a preparatory phase, or a federation of content providers such as an Internet portal or a ring of genre providers
- a second loop B2 is initiated and, during an end-of-loop test T1 which terminates the first loop B1, it is verified that the two partners are correctly recognized as is. described above.
- the method of the invention then comprises an operating step S3 which starts during a transaction between a user registered with the access provider and a content provider offering the service required by said user and authorized during the preparatory stage.
- the second loop initiated in B2 is terminated by an end-of-loop test T2 which terminates the confidential data transfer service according to the invention, during an end step S4.
- each loop B1 or B2 can be initiated by the detection of a request to open the preparatory phase (registration or authorization) or an operating request (detection of a transaction request requesting the transfer of confidential data) asynchronously. It is understood that the process of FIG. 2 can be executed in several replications operating in parallel with a multi-channel communications system.
- the invention therefore applies to transactions of various types.
- a transaction according to the invention is established between a user and a transfer site of the web genre, but also of other genres, such as WAP.
- Such a transaction always includes at least one encryption of confidential data executed at the heart of the network, and therefore an encryption which is not submitted either to the user, or to the transfer site, or to a third party other than the provider.
- Such a transaction may relate directly to digital content presented by the content provider or to other non-digital content or non-computer products or services such as those of a Mail Order or similar service. It can be merchant or not, implement a financial or banking transaction. In the application of the invention to the payment of goods on
- the method of the invention brings together a provider 40 for access to a network such as the Internet, at least one content provider 39 and at least one user 38 of said provider 39 content
- a provider 40 for access to a network such as the Internet, at least one content provider 39 and at least one user 38 of said provider 39 content
- the Internet Service Provider 40 are: - A User Registration Database 20 in which each user account registered with the Internet Service Provider 40 is maintained; - A database 21 for authorizing content providers in which each authorization account is maintained for content providers authorized by the Internet Service Provider 40.
- the Internet Service Provider has one or more resources which are: a resource 23 for registering or modifying a user account with the user registration database 20; a resource 24 for enabling or modifying an enabling account with the database 21 for enabling; - an encryption resource C; an HTTP request diversion resource D which allows, in an HTTP channel 33, to take a request 31, 32 formulated on the user's Internet browser to present it to the encryption resource at the Internet Service Provider 40; a resource R for re-routing the HTTP request in which a portion 32 of clear or reference X data is available to allow the encryption executed by the resource C as a function of encryption data contained in the accounts database 20 user and / or in the database 21 of authorization accounts.
- resources are: a resource 23 for registering or modifying a user account with the user registration database 20; a resource 24 for enabling or modifying an enabling account with the database 21 for enabling; - an encryption resource C; an HTTP request diversion resource D which allows, in an HTTP channel 33, to take a request 31, 32 formulated on
- the HTTP request is conventionally composed with a mechanism for producing data in the HTTP request 31.
- Confidential data can be inserted as described below, on the fly by the Internet Service Provider without further intervention from the registered user.
- the encrypted part of data 35 in the request 34 as re-routed by the re-routing resource R and the encrypted part X can then be decrypted by a local resource of decryption and used by a local resource for using the X data, in particular for producing an HTTP response (not shown) on the HTTP channel 33.
- FIG. 4 (a) the structure of a registration file is shown.
- FIG. 4 (b) the structure of an authorization file 45 of a content provider authorized by the Internet access provider and which comprises: identification data 46 of the content provider has been represented. empowered; object generation data 47 which contain the object generation arguments allowing the application 25 (FIG. 3) to generate the object accessible by the user according to what has already been described; data defining the address of the site receiving the confidential data from the registration file sent when the user has performed the expected action on the dot object accessible by the user.
- FIG. 5 there is shown an Internet communication system in a particular embodiment of the method of the invention in which we will specify in particular the means of control of the Internet service provider ISP on a transaction between a content provider and a user during which confidential data must be transmitted.
- the communication system implements three parts: the user, customer of the Internet service provider, the Internet service provider ISP and at least one content provider site. The various means required are respectively:
- a terminal 50 provided with a data processing connection to the ISP access provider, a means for producing and receiving HTTP type requests, such as a browser and means for processing digital content originating from content providers via the Internet provider's network;
- resources 52 for producing digital content resources for producing and receiving HTTP requests with users connected to the Internet by the Internet service provider ISP;
- a Web server 53 to execute the preparatory step of registering users and authorizing content providers, a “proxy-cache” device implementing an iCAP 51 client, a server iCAP implementing an iCAP service 55, a database 54 of the ISP users having subscribed to the secure transfer service of confidential data of the invention, a database 56 of the authorization data of the content providers, partners of the provider of Internet access ISPs and who request to benefit from the confidential data of users registered in the database 55.
- proxy-cache and iCAP protocol techniques implemented at the level of the Internet service provider ISP, reference may be made to the content of patent application FR 2 823 044 of March 30, 2001 in the name of France Telecom. The means to produce and receive type requests
- HTTP HyperText Transfer Protocol
- WAP Wireless Application Protocol
- SMTP Simple Mail Transfer Protocol
- RTCP Real Time Transfer Protocol
- This latter protocol is based on periodic transmissions of control packets by all the participants in a session in flow control of another protocol known as the RTP protocol, making it possible to convey basic information about the participants of a session, and on the quality of service, in particular during communications between several users and / or content providers, the latter actors being considered from the point of view of the present invention.
- RTP protocol another protocol known as the RTP protocol
- the user 50 informs the confidential data on a Web server 53 by a secure connection of “HTTPs” type or non-secure. This connection can take place during the first connection to the ISP Provider for user registration, or later during an update procedure.
- the confidential data are then hosted by a writing 62, or an update if necessary, at the level of the database 54 of the users of the ISP supplier.
- the same procedure (not shown) is followed for the authorization data of the database 56 of the content providers partners of the Internet service provider ISP.
- the content provider to the website from which the user has connected through the proxy-cache of the ISP provider has transmitted a web page in which there is a proposed transaction with data transmission.
- the proxy-cache 51 installed at the ISP supplier, includes a means for intercepting online purchase requests or any other HTTP request originating from the browser of a user registered with the Internet access provider. Interception 64 takes place by means of the analysis of lists, called "ACLs", which are part of the flow management functionalities of a proxy-cache. Having detected in the "ACLs" the presence of an online purchase request, the proxy-cache routes this request to a server implementing an interface supporting an HTTP flow transfer protocol such as an iCAP server implementing the iCAP service transfer of confidential data defined in the method of the invention.
- the request arriving at the iCAP 55 server is of the following form commented in Table 1: Table 1:
- Accept-Encoding gzip
- deflate User-Agent Mozilla / 4.0 (compatible; list)
- X-Forwarded-For yyy.yyy.yyy.yyy in which request: xxx. xxx. xxx. xxx is the IP Internet address of the iCAP 55 service; - yyy.yyy.yyy.yyyy is the Internet address url of the detected user and HTTP: //www.site.domain/ is the address of the detected website of the content provider; the other fields of the request in the form of table 1 make it possible to determine the resources available for the generation of the object accessible by the user.
- the iCAP server 55 which receives the request from table 1 implements an iCAP service implementing the processing part of the operating step of the method of the invention according to the teachings presented in particular in the French patent application FR 2 823 044 registered in the name of France Telecom to which we will refer for the details of realization.
- the iCAP service then performs a step 66 to establish the correspondence between the Internet IP address of the X-Client-I P field allocated to the user for the current session and which is found in the HTTP request header and an identifier of the user contained in its database of registered users 54.
- the iCAP service then performs a step to verify the agreement of the user for the transmission of his data confidential to the partner site during a step 67.
- the iCAP server 55 exports 68 this confidential data necessary for the purchase in line from the user database 54 to the iCAP server 55.
- the iCAP service then performs a step of interrogating the database of authorized suppliers (partners) 56 to know the public key of the declared supplier and, if necessary if this data is missing, to determine the address of the destination site of confidential data, here defined in the request in the IP address field destination of confidential data (Host field - Table 1) in stream 69.
- the exchange steps flows 68 and 69 can be performed simultaneously to speed up the service.
- the step of exchanging the flow 69 is executed first and then only after those of the flows 66 and 67.
- the iCAP server 55 performs an encryption step with the appropriate public key from stream 70 and inserts them in a particular field, which could be normalized and which is entitled “Encrypted-Data”, internal to the HTTP request which returns the correct public key.
- the iCAP server 55 then performs a step of retransmission of the modified request in the stream 72 to the proxy-cache 51.
- the modified request then becomes according to Table 2: Table 2:
- X-Client-IP yy.yyy.yyy.yyy
- Encrypted-Data zzzzzzzzzzzzzzzzzzzzzzzz in which request the last two lines have been added to the initial request which are: the line "VIA" defining the iCAP resource of the proxy-cache responsible for transmitting the modified request to the site of the authorized provider partner receiving the encoded data; the “Encrypted-Data” line containing the stream of encrypted data.
- the proxy-cache then performs a transmission step 73 to the site of the host concerned by the online purchase.
- the encryption of the user data is done on the ICAP server 55 and the insertion of this encrypted data is carried out in a field of the request received in the stream 65 by the ICAP server and retransmitted by the stream 72.
- the content provider 62 hosting the online shopping site extracted from the HTTP header (“Encrypted-Data” line) during a step 74 which it decrypts using its own private key and processes the online purchase of the user, his own client.
- the content provider 62 executes: if the confidential data transmitted are bank data (credit card, direct debit account number), a user billing step is carried out by the content provider; if the confidential data transmitted is identification data for a client of the content provider, a billing step for the client is carried out and transmitted with this identifier to the ISP access provider, which can then re-charge its own client client 50.
- a response step 76 containing the confirmation of the transaction to the proxy-cache 51 is then carried out. Then, the proxy-cache 51 performs a routing step 77 of the transaction confirmation towards the user 50.
- the Internet service provider ISP can offer a service to hide the identity of its users by assigning them a unique and encrypted identifier that can be linked to this single customer. This results in this case:
- the real identity of the customer is hidden from the content provider, which preserves the anonymity of the customer during purchase; such a characteristic makes it possible in particular to reduce the involuntary dissemination of the name of the users in commercial files which in return produce unwanted commercial solicitation messages (spamming in particular);
- the bank details of the registered user no longer pass over the network, which reinforces the security of confidential data; 3.
- the Internet service provider ISP then acts as a third party for invoicing and can set up an economic model of remuneration on commercial exchanges. Finally, the invention provides assurance to any content provider authorized by the Internet service provider ISP of the veracity of the identity of its user since the latter is authenticated by his access.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0313053A FR2862170A1 (fr) | 2003-11-06 | 2003-11-06 | Procede de transfert de donnees confidentielles en coeur de reseaux |
| PCT/FR2004/002707 WO2005048558A1 (fr) | 2003-11-06 | 2004-10-21 | Procede de transfert de donnees confidentielles en coeur de reseaux |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1680905A1 true EP1680905A1 (fr) | 2006-07-19 |
Family
ID=34508304
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04805271A Withdrawn EP1680905A1 (fr) | 2003-11-06 | 2004-10-21 | Procede de transfert de donnees confidentielles en coeur de reseaux |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP1680905A1 (fr) |
| FR (1) | FR2862170A1 (fr) |
| WO (1) | WO2005048558A1 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11488202B2 (en) * | 2014-02-28 | 2022-11-01 | Ncr Corporation | Unified channel management |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| GB2350982B (en) * | 1999-06-10 | 2003-06-25 | John Quentin Phillipps | Electronic commerce system |
| US20030191801A1 (en) * | 2002-03-19 | 2003-10-09 | Sanjoy Paul | Method and apparatus for enabling services in a cache-based network |
-
2003
- 2003-11-06 FR FR0313053A patent/FR2862170A1/fr active Pending
-
2004
- 2004-10-21 WO PCT/FR2004/002707 patent/WO2005048558A1/fr not_active Ceased
- 2004-10-21 EP EP04805271A patent/EP1680905A1/fr not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2005048558A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| FR2862170A1 (fr) | 2005-05-13 |
| WO2005048558A1 (fr) | 2005-05-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP4152051B2 (ja) | インターネット・ブラウジング・セッション中に有料の電話コールを行うための方法及びシステム | |
| US8661557B2 (en) | Method and system for granting access to system and content | |
| EP1909462B1 (fr) | Procédé de mise à disposition cloisonnée d'un service électronique | |
| EP1256911A1 (fr) | Procédé de sécurisation d'un paiement d'un client à un commerçant, centre de localisation et système correspondants | |
| EP1829280A2 (fr) | PROCEDE D'AUTHENTIFICATION SECURISEE POUR LA MISE EN ŒUVRE DE SERVICES SUR UN RESEAU DE TRANSMISSION DE DONNEES | |
| EP3391614A1 (fr) | Procede de transmission d'une information numerique | |
| WO2005034468A1 (fr) | Systeme d'acces a un reseau adapte pour la mise en oeuvre d'un procede a signature simplifiee, et serveur pour sa realisation | |
| EP1227640B1 (fr) | Procédé et système de communication d'un certificat entre un module de sécurisation et un serveur | |
| EP1983722A2 (fr) | Procédé et système de sécurisation d'accès internet de téléphone mobile, téléphone mobile et terminal correspondants | |
| WO2001001280A2 (fr) | Procede et dispositif de mise en commun d'informations temoins pendant des operations sur internet | |
| EP1680905A1 (fr) | Procede de transfert de donnees confidentielles en coeur de reseaux | |
| EP1400090B1 (fr) | Procede et dispositif de securisation des communications dans un reseau informatique | |
| CN101658004A (zh) | 用于提供rel令牌的方法和系统 | |
| Sim et al. | The Internet—past, present and future | |
| FR2844943A1 (fr) | Procede de production d'un premier identifiant isolant un utilisateur se connectant a un reseau telematique | |
| EP1535253A1 (fr) | Procede et systeme de securisation de transmission d'informations sur des reseaux de telecommunication | |
| EP2630765B1 (fr) | Procede d'optimisation du transfert de flux de donnees securises via un reseau autonomique | |
| FR2844942A1 (fr) | Procede de production, pour un fournisseur d'acces, d'un identifiant isolant multimedia | |
| KR101507958B1 (ko) | 모바일 메신저를 구동하는 모바일 웹페이지 제공 방법 | |
| EP0803087B1 (fr) | Procede de realisation de transfert securise de donnees sur un reseau a serveurs multiples | |
| Sim et al. | The Internet—past, present and future | |
| EP2254275A1 (fr) | Procédé de chiffrement de parties particulières d'un document pour les utilisateurs privilèges | |
| JP2001290773A (ja) | ネットワーク型サービス提供システム | |
| KR20020066853A (ko) | 통신망을 통한 아이템 전달 방법 | |
| De Bruin | Validity and Accuracy Issues in Electronic Commerce with Specific Reference to Vpn's |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20060505 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: BOUTROUX, VINCENT Inventor name: BOUTROUX, ANNE Inventor name: MITTIG, KAREL |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20070209 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20090605 |