EP2721795A1 - Procédé et dispositif d'authentification des utilisateurs d'un terminal hybride - Google Patents

Procédé et dispositif d'authentification des utilisateurs d'un terminal hybride

Info

Publication number
EP2721795A1
EP2721795A1 EP11725929.1A EP11725929A EP2721795A1 EP 2721795 A1 EP2721795 A1 EP 2721795A1 EP 11725929 A EP11725929 A EP 11725929A EP 2721795 A1 EP2721795 A1 EP 2721795A1
Authority
EP
European Patent Office
Prior art keywords
user
authentication
hybrid terminal
internet
identification number
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP11725929.1A
Other languages
German (de)
English (en)
Inventor
Matthias Wagner
Andreas KARANAS
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
TEVEO INTERACTIVE GmbH
Original Assignee
TEVEO INTERACTIVE GmbH
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by TEVEO INTERACTIVE GmbH filed Critical TEVEO INTERACTIVE GmbH
Publication of EP2721795A1 publication Critical patent/EP2721795A1/fr
Withdrawn legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/43Processing of content or additional data, e.g. demultiplexing additional data from a digital video stream; Elementary client operations, e.g. monitoring of home network or synchronising decoder's clock; Client middleware
    • H04N21/441Acquiring end-user identification, e.g. using personal code sent by the remote control or by inserting a card
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0815Network architectures or network communication protocols for network security for authentication of entities providing single-sign-on or federations
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/2866Architectures; Arrangements
    • H04L67/30Profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials

Definitions

  • the present invention relates to a method and a device for
  • Such methods are used for registration and authentication of a user of televisions and satellite receivers, in addition to the actual
  • the publication DE 10 2006 045 352 A1 discloses a single sign-on method for the use of a set-top box with an Internet and a broadband interface. By means of a registration provided by a provider and
  • Authentication function user authentication occurs after powering on a set-top box. If the user successfully authenticates, the
  • Authentication information is then sent to the registry for registration
  • Service providers or multiple service providers.
  • Authentication function is called after switching on the set-top box and if the authentication is successful, an authentication information to the
  • the user can access the digital television offering.
  • Communication device which is within sight of the TV, transmitted to the TV.
  • the data required for identifying the user are already present or stored on the communication device.
  • the received data is matched in the TV with stored user profiles to subsequently control the TV accordingly.
  • the method has the disadvantage that the data required for the identification and authentication of a user are stored on the wireless communication device, so that an authentication of the user can always be carried out only by means of the associated communication device. This is complicated to handle and expensive. If the wireless communication device is used by third parties, the user whose identification data is stored on the wireless communication device is not identified and authorized, but the user.
  • the object of the present invention is therefore to propose a secure method that simplifies the handling of the authentication. Furthermore, it is an object of the invention to provide a corresponding device for carrying out the
  • the inventive method has the advantage that the authentication of users , - A hybrid terminal by means of a user assigned to the unique registration code and a personal identification number.
  • a particular advantage of the method according to the invention is that the user can initiate an authentication process directly on the hybrid terminal. Would the user like to access services and / or content that was a previous one
  • the user can request and obtain a unique registration code directly via the hybrid terminal, without first having to register via an Internet-enabled computer, for example.
  • the inventive method has the advantage that the user of the hybrid terminal only a single application - hereinafter referred to as "single-sign-on" - is required to identify to one of the service providers or against several of the Divan- bictern. After successful authentication of the user, the latter can not only access the user data or contents of one of the service providers, but is in principle also legitimized for the transmission of user data or the access to contents of other service providers.
  • the generation of the unique registration code comprises the following steps: sending a request message from the hybrid terminal to the registration server of the authentication device for requesting the unique registration code, generating the requested registration code by means of the registration server of the authentication device and transmitting the unique registration code from the registration server of the
  • Authentication device to the hybrid terminal offers the advantage that the registration code is generated independently of the respective hybrid terminal in that the user at the hybrid terminal initiates the generation of the registration code, for example by pressing a key.
  • the hybrid terminal then sends a request message to the registration server of the authentication device to signal to it that a unique registration code is to be generated.
  • the respective unique registration code is generated.
  • the unique registration code is unique and unmistakable, ie the generation of two identical codes is avoided in any case.
  • the generated unique registration code is transmitted from the registration server of the authentication device to the hybrid terminal.
  • a further preferred development of the method is characterized in that the generation of the unique registration code takes place by means of the hybrid terminal. This offers the advantage that the registration code can be generated locally by means of the hybrid terminal, without the registration code first being issued by the registration server
  • Authentication device must be transmitted to the hybrid terminal.
  • An expedient embodiment of the invention is characterized in that performing the initial authentication comprises: inputting the unique registration code and the personal identification number by means of the hybrid terminal,
  • Identification number one of the users are assigned. Determining that this user is authorized to receive the payload from the service provider and / or to send the payload to the service provider. For the first time, the user accesses the user data of one of the service providers. this must first be legitimized by means of the first authentication for access to the user data of the service provider.
  • the first authentication is thus set up in the form of a two-factor authentication and thus represents a particularly secure method for the first authentication of the user.
  • a preferred development of the invention is characterized in that performing the authentication comprises: transmitting the profile file that is stored on the Hybrid terminal is stored on the authentication server of the authentication device via the Internet interface of the hybrid terminal, checking the Profi Ifile in the Authenti fication server of Authenti fiz istsvortechnisch by adjusting the Profile file containing the user identification data of the users stored on the storage medium of the authentication device, and if the checking reveals that the profile file is attributable to one of the users, determining that this user is to receive the payload from the service provider and / or to send the payload - Data is authorized to the service provider.
  • performing the authentication comprises: inputting the personal identification number by means of the hybrid terminal, transmitting the profile file stored on the hybrid terminal, and the personal identification number to the authentication server of the authentication device via the internet interface of the hybrid terminal, checking the personal Identification number and the profile file in the authentication server of the authentication device by matching the personal identification number and the profile file with the user identification data of the users stored on the storage medium of the authentication device, and if the checking reveals that the personal identification number and the profile file are assignable to one of the users , Determining that this user is to receive the payload data from the service provider and / or to send the N user data is authorized at the service provider.
  • the additional input of the personal identification number offers the advantage of increased security of authentication of the user.
  • a further expedient embodiment of the invention is characterized in that the communication between the Internet-enabled terminal and the authentication device takes place via a secure Internet network connection by means of a secure hypertext transmission protocol. In this way, the communication between the internet terminal and the authentication device becomes unwanted
  • the unique registration code comprises only numeric characters.
  • the character set for inputting the registration code by the user is limited only to the numbers 0, 1, 2, 3, 4, 5, 6, 7, 8 and 9, so that the entry of the unique registration code is much easier due to the limited character set becomes.
  • the entry of the unique registration code and the personal identification number takes place by means of a remote control of the hybrid terminal. The unique registration code and personal identification number can therefore be conveniently entered using the number buttons on the remote control.
  • a further expedient embodiment of the invention is characterized in that the user data comprise at least substantially video data and / or audio data.
  • the payload includes further control data, namely additional data in addition to the actual audio and video data, which ensure a linkage of the transmitted audio and video data with contents of the Internet.
  • the user data comprise communication and release data, which serve, for example, for the purchase transaction. The user accesses content from service providers who use an online store to purchase items or
  • Provision of services the purchase is carried out by the transmission of appropriate communication and release data via the broadband interface.
  • Hybrid Broadcast Broadband TV (HbbTV) hybrid terminal as described in the draft technical specification TS 102 796 VI .1.1 (2009-). 12) - hereafter referred to as HbbTV standard - is defined more closely by the European Telecommunications Standards Institute 2009. According to the HbbTV standard, a platform for the signaling, transport and presentation of advanced and interactive applications for operation on hybrid terminals is defined Such hybrid terminals are preferably television sets, satellite receivers, cable television receivers, set-top boxes, or the like, so the hybrid terminal communicates both over the
  • the hybrid terminal receives, in addition to the user data in the form of audio and video data, additional information via the broadband interface, for example in the form of an embedded one
  • Hybrid terminal to communicate with the Internet and specifically access content on the Internet, which are linked to the transmitted via the broadband interface payload.
  • the transmission of the user data preferably takes place unidirectionally, for example starting from a television transmitter to the hybrid terminal.
  • DVB-S Broadband site is therefore preferred as DVB-S.
  • the broadband interface is not limited to the reception of television signals in accordance with the aforementioned DVB standards, but is basically adapted and arranged to receive television signals in accordance with other conventional television signal transmission methods.
  • FIG. 2 schematically illustrates performing an initial authentication
  • Fig. 3 schematically shows the passage of a Authenti fication
  • Fig. 4 is a schematic diagram of the device according to the invention.
  • the unique registration code 15 is uniquely designed, so that each generation generates one of the unique
  • Registration codes 15 each other unique registration code 15 is generated.
  • the professional file 19 associated with the unique registration code 15 is then stored on the hybrid terminal 10, i. on the hybrid terminal 10 or a the
  • Hybrid terminal 1 associated memory device stored. The unique
  • the registration code 15 is output via the hybrid terminal 10 so as to be displayed to the user.
  • the user notes the displayed unique registration code 15 for further use.
  • the output of the unique registration code 15 may, for example, be made via a screen connected to the hybrid terminal 10.
  • Registration code 15 directly on the hybrid terminal 10, for example via a separate display.
  • the user of the flybridge terminal 10 subsequently inputs his user identification data 14 by means of an Internet-capable terminal 11.
  • any customary Internet-capable terminal is suitable, for example a laptop, a desktop computer, a PDA, an internet-capable mobile telephone or the like.
  • the input of the user identification data 14, which is, for example, personal data such as name, address, bank details or credit card data of the user, are transmitted from the Internet-enabled terminal 11 via a first Internet connection 12 to a registration server of an authentication device 13.
  • the communication between the Internet-enabled terminal 11 and the authentication device 13 is advantageously via a secure Internet connection using a secure hypertext transmission protocol (HTTPS protocol).
  • HTTPS protocol secure hypertext transmission protocol
  • the communication between the Internet-enabled terminal 11 and the authentication device 13 can also be unsecured or else by means of other encryption methods.
  • the user is prompted to enter a personal identification number 16.
  • the personal identification number 16 is freely selectable by the user, i. the user can enter the personal identification number 16 after his
  • Entering the personal identification number 16 also takes place by means of the Internet-enabled terminal 11.
  • the user has the choice of whether he wants to dial the personal identification number 16 itself. If the user follows the request to input the personal identification number 16, the personal identification number 16 will become after entering the internet
  • Terminal 11 is transmitted to the registration server of the authentication device 13 via the first Internet connection.
  • the personal identification number 16 is transmitted to the registration server of the authentication device 13 via the first Internet connection.
  • Identification number 16 generated in a step described below.
  • the personal identification number 16 as well as the user identification data 14 from the Internet-enabled terminal 11 is sent to the registration server of the authentication device via a first Internet connection 12 13 transmitted. If the user does not enter a personal identification number 16, only the transmission of the
  • the personal identification number 16 is subsequently generated in the authentication device 13.
  • the user is prompted to enter the unique registration code 15 by the internet-prone terminal 11.
  • the entered unique registration code 15 is then followed by the - - Internet-capable terminal 1 1 to the registration server of the authentication device 13 transmitted.
  • the user identification data 14 is then validated by comparing the user identification data 14 with a given user reference record.
  • the user reference record includes information used to verify the identity of the user based on the one present on the registration server
  • User identification data 14 are suitable.
  • the user reference data record is adapted to the user identification data 14 to be checked.
  • this includes information for checking account information
  • the creditworthiness of the user or for checking the credit card data corresponding control data which are required to determine whether the present user identification data 14 a valid credit card.
  • the user reference record may also be used for age verification or simply for determining the actual identity of the user.
  • the user's user identification data 14 is stored on a storage medium of the authentication device 13.
  • the user identification data 14 are thus permanently secured and at any time in the
  • the storage medium used are all the usual known storage technologies.
  • the professional file 19 is assigned to the respective user. In other words, a correspondence is established between the profile file 19 and the user, which allows the identification of the user via the professional file 19.
  • the personal identification number 16 is subsequently generated. Based on the unique registration code 15 and the personal identification number 16, the user is uniquely identifiable, ie the unique registration code 15 and / or the personal identification number 16 are User assigned.
  • the unique registration code 15 includes a 16-digit numeric hash value that is generated based on the user identification data 14. The generation of the hash value allows the later execution of a plausibility check. about the correctness of the - - to be able to check the unique registration codes 15.
  • the unique registration code 15 is not limited to 16-digit numerical flash values only, but may be any registration code length.
  • the personal identification number 16 is transmitted from the registration server to the user or to the internet-capable terminal 11 in a separate way.
  • the user is sent the personal identification number 16 by email or SMS. It is also possible to transmit the personal identification number 16 not by electronic means, but by post. In any case, the
  • Service providers 17, 18, the application server begins with the check whether a user file associated with the profile file 19 is present on the hybrid terminal. Thus, it is determined whether the user has previously accessed an authentication-requiring service provider 17, 1 8.
  • the profile file 19 is available as a cookie or as a client - -
  • the authorization of the user presupposes that this has been identified in the registration step and the user has been assigned a registration code 15 generated for the purpose of unambiguous identification as well as a personal identification number 16. If no profile file 19 assigned to the user is present on the hybrid terminal 10, the initial authentication is carried out to determine whether the user is authorized to receive the user data from the service provider 17, 18 and / or to send the user data to the service provider 17, 18 , If the initial authentication indicates that the user is authorized, i. for receiving the payload data from the service provider 17. 18 and / or legitimized for sending the payload data to the service provider, the profile file 19 assigned to the user is generated. The profile file 19 is transmitted from the authentication server of the authentication device 13 to the hybrid terminal 10 and stored on the hybrid terminal 10, i. permanently on the
  • the profile file 19 is also maintained via a restart of the hybrid terminal 10 and over longer periods without current. In other words, the presence or absence of the profile file 19 on the hybrid terminal 10 recognizes whether the user as an authorized user has previously accessed a service provider 17, 18 or whether it is the first access to one of the service providers 17. 18 acts.
  • a release message is transmitted to one or more service providers 17, 18.
  • the service provider 17, 18 is signaled that the user has authenticated himself as the authorized user for access to the services of the service provider 17, 18.
  • the release message is transmitted via the second Internet connection 20 from the authentication device 13 to the service providers 17, 18.
  • the user data is transmitted by the service provider 17, 18 via the broadband interface to the hybrid terminal 10.
  • the transmission of user data is not _ "Limited only to a transmission of user data from the service provider 17, 18 to the hybrid device 10.
  • the transmission also includes the transmission of data or user data from the hybrid terminal 10 to the service provider 17, 18. This is for example the case when the user via the service provider 17, 18 fee-based services claims, for example, the purchase of goods over the service provider 17, 18.
  • the generation of the unique registration code 15 takes place by means of the registration server of the authentication device 13.
  • This process is initiated by sending a request message from the hybrid terminal 10 to the registration server of the authentication device 13, for example by selecting a corresponding menu item in the menu of the hybrid terminal 10.
  • the transmission process can be triggered via a button on the hybrid terminal 10 or on the remote control.
  • the registration server uses the
  • a further preferred embodiment of the invention is characterized in that the unique registration code 15 is generated by means of the hybrid terminal 10.
  • the generation of the unique registration code 15 is not performed by the registration server as described above, but locally on the hybrid terminal 10.
  • the generation of the unique registration code 15 can be based on certain hardware features of the hybrid terminal 10 as well as independently hardware features. In the case of hardware-bound generation of the unique registration code 15, the registration code generation becomes unique
  • Characteristics of the hybrid terminal 10 for example, to a unique serial number of the hybrid device 10 or the like, bound.
  • any other hardware feature of the hybrid terminal 10 that allows the generation of the unique registration code 15 is also suitable.
  • the generation of the unique registration code 15 is also suitable.
  • Registration codes 15 independent of hardware features of the hybrid terminal 10.
  • the registration code generation for example, by means of any
  • FIG. 2 schematically illustrates the performance of the initial authentication.
  • the user is prompted to enter the unique registration code 15 and the personal identification number 16 using the hybrid terminal 10.
  • Registration code 15 and personal identification number 16 are transmitted via the Internet
  • the authentication server verifies the unique registration code 15, in conjunction with the personal identification number 16, as to whether the unique registration code 15 and the personal registration number
  • Identification number 16 can be assigned to one of the users. This happens through
  • the profile file 19 stored on the hybrid terminal 10 is sent to the authentication server of the authentication device 13 transmitted via the Internet interface of the hybrid terminal 10.
  • the profile file 19 is matched in the authentication server of the authentication device 13 by matching the profile file 19 with the user identification data 14.
  • the user identification data 14 are stored on the storage medium of the authentication device 13. If the comparison or the check shows that the profile file 19 can be assigned to one of the users, this user is recognized as the authorized user and it is determined that this user is to receive the user data from the service provider 17, 18 and / or to send the user data is entitled to the service provider. In other words, the user is due to the _.
  • Presence of the profile file 19 on the hybrid terminal 10 uniquely identified and recognized as an authorized user or authorized user.
  • the user is uniquely identifiable after a single access to a service provider 17, 18 including successful authentication of the presence of the profile file 19. This offers the advantage that the user for all the service providers 17, 18 for whom the profile file the
  • Identification number 16 in order to authenticate as a legitimate user in a plurality of service providers 17, 18 without having to reenter the unique registration code 15 and the personal identification number 16 each time access to another service provider 17, 18 occurs.
  • Authentication server of the authentication device 13 transferred. If the verification of the personal identification number 16 and the profile file 19 indicates that it is assignable to one of the users, the determination is made that this user is authorized to receive the user data from the service provider 17, 18 and / or to send the user data to the service provider. The authorization of the user is checked by matching the personal identification number 16 and the profile file 19 with the corresponding user identification data 14 stored on the storage medium of the authentication device.
  • the personal identification number 16 is user-selectable and usually includes four numeric characters. In this way, the authorship is particularly convenient for the user since only four numeric characters are to be entered. Alternatively, the personal identification number has more than four characters and also includes any non-numeric characters.
  • Another embodiment is characterized in that the inputting of the unique registration code 15 and the personal identification number 16 takes place by means of a remote control 21 of the hybrid device.
  • the user can in this way very comfortable with the anyway for the operation of the hybrid terminal 10 erf orderlichen
  • Remote 21 enter the unique registration code 15 and the personal identification number 16.
  • the user data comprise at least substantially video data and / or audio data.
  • the payload includes digital television data.
  • the payload is not limited to television data, but includes any form of audio and video data.
  • the payload data includes control data which is usually transmitted for the correct transmission of the audio and video data.
  • the payload For linking the audio and video data, i. the content transmitted by the service providers 17, 18, the payload further comprises embedded Internet addresses. This is a synchronization between the user data, such as a running television program, and ordinary HTML websites instead.
  • the payload therefore includes trigger information as well as internet addresses used by the
  • Hybrid terminal 10 are evaluated. This allows the user to access corresponding content on the Internet, which are assigned to the user data in terms of time and content. In this way, the service providers can offer interactive applications and information that the user can interactively access.
  • the payload data includes communication and release data required to handle online transactions between the user and the service provider 17, 18 via the broadband interface. - -
  • Fig. 4 shows a schematic diagram of the device according to the invention.
  • the device comprises the hybrid terminal 10 with at least one Internet interface and at least one broadband interface, the authentication device 13, wherein the authentication device 13 comprises the registration server, the application server, the authentication server and at least one storage medium.
  • the authentication device 13 comprises the registration server, the application server, the authentication server and at least one storage medium.
  • the hybrid terminal 10 is connected via the intra-interface with the
  • Authentification device 13 connected and connected via the broadband interface with at least one service provider 17, 18.
  • the authentication device 13 is connected to at least one of the service providers 17, 18 via the second Internet connection and configured such that, for example, the release message can be transmitted from the authentication device 13 to the service provider 17, 18.
  • the internet-enabled terminal 11 is connected to the registration server of the authentication device 13 via the first Internet connection 12.
  • the registration server of the authentication device 13 is adapted to at least generate the unique registration code 15 and a professional file 19 associated therewith upon receipt of a request message sent by the hybrid terminal 10 and transmit the unique registration code 15 from the registration server of the authentication device 13 to the hybrid terminal 10 , or that
  • Hybrid terminal 10 is adapted to generate at least the one unique registration code 15 and the profile file 19 associated with the registration code 15.
  • either the registration server or the hybrid device 10 is adapted to generate the unique registration code 15, as previously described in connection with the inventive method.
  • the registration server is adapted to deposit the profile file 19 on the hybrid terminal 10 and to output the unique registration code 15 in order to display the unique registration code 15 to the user.
  • the registration server is also customized. User Identifkations stylist and the unique registration code 15, the Internet-enabled terminal 1 1 to the
  • Registration server over the first Internet connection 12 are transmitted by comparing user identification data 14 with a predetermined
  • the registration server is adapted to generate the personal identification number 16, wherein the personal identification number 16 is associated with the user to transmit the personal identification number 16 from the registration server via a separate connection to the user or to the internet-capable terminal 11.
  • the registration server is further configured and adapted to check if the
  • Profile file 19 on the hybrid terminal 10 is present. wherein the hybrid terminal 10 is arranged to communicate with the application server of the authentication device 13 via the Internet interface and, in the event that the professional file 19 associated with the user is present on the hybrid terminal 10, perform the authentication to determine if the user is authorized to receive payload data from the service provider 17, 18. otherwise the initial authentication
  • the hybrid terminal 10 Authentication device 13 via the Internet interface to the hybrid terminal 10 to transfer, the profile file 19 is stored on the hybrid terminal 10, and after Clearauthenti fication or authentication, if the user was authenticated as an authorized user, a release message to at least one of the service providers 17, 18 and to transmit the payload data from the service provider 17, 18, to which the transmission of the release message has been made, the hybrid terminal 10 is adapted to transmit the payload over the
  • Broadband interface to communicate with the service provider.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Multimedia (AREA)
  • Information Transfer Between Computers (AREA)
  • Storage Device Security (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
  • Telephonic Communication Services (AREA)
  • Measurement Of The Respiration, Hearing Ability, Form, And Blood Characteristics Of Living Organisms (AREA)
  • Collating Specific Patterns (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

L'invention concerne un procédé et un dispositif d'authentification des utilisateurs d'un terminal hybride (10), comprenant la production d'un code d'enregistrement unique (15) et d'un fichier de profil (19), au moins une étape d'enregistrement comprenant : saisie de données d'identification d'utilisateur (14), saisie et transmission d'un numéro personnel d'identification (16) entre le terminal à fonctions internet (11) et un serveur d'enregistrement, transmission des données d'identification d'utilisateur (14) de l'utilisateur entre le terminal à fonctions internet (11) et le serveur d'enregistrement, saisie du code d'enregistrement unique (15), validation des données d'identification d'utilisateur (14) et, si les données d'identification d'utilisateur (14) correspondent à un ensemble de données de référence d'utilisateur, mise en correspondance du fichier de profil (19) et si la saisie du numéro personnel d'identification (16) par l'utilisateur n'a pas eu lieu, production et transmission du numéro personnel d'identification (16) entre le serveur d'enregistrement et l'utilisateur, et une étape d'authentification comprenant : contrôle de la présence du fichier de profil (19) sur le terminal hybride (10) et, si celui-ci est présent, exécution d'une authentification et, sinon, exécution d'une première authentification et, si la première authentification indique que l'utilisateur est autorisé, production et transmission du fichier de profil (19) entre le serveur d'authentification et le terminal hybride (10), ainsi qu'après exécution de l'authentification ou de la première authentification, transmission d'un message de validation à au moins l'un des fournisseurs de services (17, 18).
EP11725929.1A 2011-06-16 2011-06-16 Procédé et dispositif d'authentification des utilisateurs d'un terminal hybride Withdrawn EP2721795A1 (fr)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/EP2011/060044 WO2012171568A1 (fr) 2011-06-16 2011-06-16 Procédé et dispositif d'authentification des utilisateurs d'un terminal hybride

Publications (1)

Publication Number Publication Date
EP2721795A1 true EP2721795A1 (fr) 2014-04-23

Family

ID=44627132

Family Applications (1)

Application Number Title Priority Date Filing Date
EP11725929.1A Withdrawn EP2721795A1 (fr) 2011-06-16 2011-06-16 Procédé et dispositif d'authentification des utilisateurs d'un terminal hybride

Country Status (12)

Country Link
US (1) US20140137223A1 (fr)
EP (1) EP2721795A1 (fr)
JP (1) JP2014524072A (fr)
KR (1) KR20140053913A (fr)
CN (1) CN103765843A (fr)
AU (1) AU2011370755A1 (fr)
BR (1) BR112013032270A2 (fr)
CA (1) CA2839231A1 (fr)
DE (1) DE112011104670A5 (fr)
MX (1) MX2013014618A (fr)
RU (1) RU2013157400A (fr)
WO (1) WO2012171568A1 (fr)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9819728B2 (en) * 2012-04-30 2017-11-14 Google Inc. System and method for facilitating deduplication of operations to be performed
US9053307B1 (en) * 2012-07-23 2015-06-09 Amazon Technologies, Inc. Behavior based identity system
US9166961B1 (en) 2012-12-11 2015-10-20 Amazon Technologies, Inc. Social networking behavior-based identity system
CN104125201A (zh) * 2013-04-26 2014-10-29 达创科技股份有限公司 通信传输系统和方法
US9262470B1 (en) 2013-06-25 2016-02-16 Amazon Technologies, Inc. Application recommendations based on application and lifestyle fingerprinting
US9921827B1 (en) 2013-06-25 2018-03-20 Amazon Technologies, Inc. Developing versions of applications based on application fingerprinting
US10269029B1 (en) 2013-06-25 2019-04-23 Amazon Technologies, Inc. Application monetization based on application and lifestyle fingerprinting
KR102176399B1 (ko) * 2014-05-28 2020-11-09 삼성전자주식회사 디스플레이장치, 디스플레이장치의 제어방법 및 서버
KR102217749B1 (ko) 2014-08-29 2021-02-19 삼성전자 주식회사 전자 장치 및 이의 기능 실행 방법
CN107257444B (zh) * 2017-05-08 2018-10-09 广州美凯信息技术股份有限公司 一种主机接口自适应方法及装置
CN107483435A (zh) * 2017-08-11 2017-12-15 青岛海尔多媒体有限公司 验证码校验的方法及装置
US10956224B1 (en) * 2017-08-29 2021-03-23 Wells Fargo Bank, N.A. Creating augmented hybrid infrastructure as a service
WO2023196823A2 (fr) * 2022-04-04 2023-10-12 3Num Inc. Dispositif, système et procédé pour générer des informations discernables par l'homme comportant des métadonnées vérifiables par machine

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100459804C (zh) * 2005-12-13 2009-02-04 华为技术有限公司 终端接入第二系统网络时进行鉴权的装置、系统及方法
US20080127254A1 (en) 2006-09-22 2008-05-29 Satoshi Nakajima Subscriber based tv operation
CN101155293B (zh) * 2006-09-25 2011-11-30 华为技术有限公司 一种进行网络直播电视业务频道授权的方法、系统及装置
DE102006045352B4 (de) * 2006-09-26 2015-02-12 Nokia Solutions And Networks Gmbh & Co. Kg Verfahren für Single-Sign-On bei Verwendung einer Set-Top-Box
CN101170409B (zh) * 2006-10-24 2010-11-03 华为技术有限公司 实现设备访问控制的方法、系统、业务设备和认证服务器
KR100795157B1 (ko) 2006-12-06 2008-01-16 주식회사 조인온 임대된 디지털티브이를 이용한 무선랜 서비스 제공 방법 및그 시스템
ES2324753B1 (es) * 2007-03-20 2010-05-24 Vodafone España, S.A. Procedimiento y sistema para reconocimiento de usuarios de television sobre ip.
US20090052870A1 (en) * 2007-08-22 2009-02-26 Time Warner Cable Inc. Apparatus And Method For Remote Control Of Digital Video Recorders And The Like
US20100031290A1 (en) * 2008-07-30 2010-02-04 Lucent Technologies Inc. Method and apparatus for automatic channel switching for iptv
US8555355B2 (en) * 2010-12-07 2013-10-08 Verizon Patent And Licensing Inc. Mobile pin pad

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO2012171568A1 *

Also Published As

Publication number Publication date
AU2011370755A1 (en) 2014-01-23
WO2012171568A1 (fr) 2012-12-20
WO2012171568A8 (fr) 2013-03-07
JP2014524072A (ja) 2014-09-18
RU2013157400A (ru) 2015-07-27
CN103765843A (zh) 2014-04-30
US20140137223A1 (en) 2014-05-15
MX2013014618A (es) 2014-04-14
DE112011104670A5 (de) 2013-10-02
CA2839231A1 (fr) 2012-12-20
KR20140053913A (ko) 2014-05-08
BR112013032270A2 (pt) 2016-12-20

Similar Documents

Publication Publication Date Title
EP2721795A1 (fr) Procédé et dispositif d'authentification des utilisateurs d'un terminal hybride
DE60318470T2 (de) Verfahren zum gewähren von zugriff auf eine einrichtung aufgrund einer verknüpfung eines ersten charakteristikums einer ersten vorrichtung und eines zweiten charakteristikums einer zweiten vorrichtung
WO2007053864A9 (fr) Dispositif de réalisation d’une signature électronique améliorée d’un document électronique
EP2632104B1 (fr) Procédé et système de télécommunication pour l'inscription d'un utilisateur à un service IPTV personnalisé sécurisé
EP2140654B1 (fr) Dispositif multimédia et procédé de transmission de données par un dispositif multimédia
EP2380330B1 (fr) Procédé et dispositif d'authentification d'utilisateurs d'un terminal hybride
DE102019100335A1 (de) Verfahren zum sicheren Bereitstellen einer personalisierten elektronischen Identität auf einem Endgerät
WO2011069492A1 (fr) Procédé et produits-programmes informatiques pour accès authentifié à des comptes en ligne
EP1964042B1 (fr) Procede de preparation d'une carte a puce pour des services de signature electronique
DE102019100334A1 (de) Verfahren zum sicheren Bereitstellen einer personalisierten elektronischen Identität auf einem Endgerät
WO2013011043A1 (fr) Système mobile pour transactions financières
DE102017127280B4 (de) Schutz vor realtime phishing und anderen attacken während eines login-prozesses an einem server
EP2783320B1 (fr) Procédé pour authentifier une personne se trouvant au niveau d'une instance de serveur
EP3271855B1 (fr) Procédé de génération d'un certificat pour un jeton de sécurité
EP2631837A1 (fr) Procédé de création d'un pseudonyme à l'aide d'un jeton d'ID
EP2879073B1 (fr) Procédé de transaction électronique et système informatique
WO2021228537A1 (fr) Procédé de couplage d'un moyen d'authentification à un véhicule
DE102014204122A1 (de) Elektronisches Transaktionsverfahren und Computersystem
WO2012056049A1 (fr) Appareil de lecture servant d'identifiant électronique
WO2015114160A1 (fr) Procédé de transmission sécurisée de caractères
AT16055U1 (de) Verfahren und System zur Erzeugung einer elektronischen Stapelsignatur
EP3289507B1 (fr) Jeton id, système et procédé de génération de signature électronique
DE102012200506A1 (de) Verfahren und Vorrichtung zum Bereitstellen von kostenpflichtigen Angeboten
DE102011110898A1 (de) Verfahren zur Authentifizierung eines Benutzers zum Gewähren eines Zugangs zu Diensten eines Computersystems, sowie zugehöriges Computersystem, Authentifizierungsserver und Kommunikationsgerät mit Authentifizierungsapplikation
DE102014206949A1 (de) Transaktionsverfahren

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20140114

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

DAX Request for extension of the european patent (deleted)
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION HAS BEEN WITHDRAWN

18W Application withdrawn

Effective date: 20170630