EP4107905A1 - Procede et dispositif de controle d'acces a une fonction d'une application inscrite dans une chaine de blocs - Google Patents
Procede et dispositif de controle d'acces a une fonction d'une application inscrite dans une chaine de blocsInfo
- Publication number
- EP4107905A1 EP4107905A1 EP21710027.0A EP21710027A EP4107905A1 EP 4107905 A1 EP4107905 A1 EP 4107905A1 EP 21710027 A EP21710027 A EP 21710027A EP 4107905 A1 EP4107905 A1 EP 4107905A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- function
- terminal
- identifier
- request
- execution
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/629—Protecting access to data via a platform, e.g. using keys or access control rules to features or functions of an application
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3239—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/50—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/56—Financial cryptography, e.g. electronic payment or e-cash
Definitions
- Title Method and device for controlling access to a function of an application registered in a blockchain.
- the invention relates to the general field of telecommunications networks, and more specifically to blockchain technology.
- each decentralized application present within the blockchain is composed of a binary code and an interface exposing methods that can be called, for example by a third party or by other applications.
- a DApps also has a private data area that it will be able to modify depending on the processing carried out.
- the business model of such a blockchain is essentially focused on the act of deploying the application. You have to "pay" to deploy the application, that is, pay the people who validate the application and create the block associated with validation at the blockchain level. In addition, people who want to use the application, for example by sending a request to complete a particular task, must also pay for each use according to a predetermined algorithm.
- the invention improves on the state of the art and proposes a method for controlling access to a function of an application implemented by a device for controlling access to a function of an application, this control device. being registered in a chain of blocks, the method being characterized in that it comprises:
- a step of sending a response to the access request comprising at least one parameter for accessing said at least one first function and at least one second identifier of at least one second function registered in said chain of blocks , said at least one second identifier being associated with said at least one parameter.
- the invention proposes to use a blockchain to manage access to an application registered in a blockchain and more specifically to its function (s).
- the present request is presented in the context of a "blockchain” in English “blockchain” but the expression “block chain” is to be understood as covering any type of DLT (in English Distributed Ledger Technology) capable of hosting decentralized applications known under the name of DApp (Decentralized Applications in English) of which the blockchains themselves constitute a particular element.
- blockchain technology is a technology for storing and transmitting information without a control organ.
- it is a distributed database whose information sent by users and internal links to the base are verified and grouped at regular time intervals in blocks, the whole being secured by cryptography, and thus forming chain.
- a blockchain is a distributed database that maintains a list of records protected against tampering or modification by storage nodes; it is therefore a distributed and secure register of all transactions carried out since the start of the system.
- Blockchains are characterized in particular in that their content cannot be modified or deleted: information that is published (that is, recorded or saved) in a blockchain remains forever.
- the invention offers a new mechanism in which, when a request for access to a function of an application registered in a blockchain is sent by a user terminal, the device executing the method access control system then sends back a response with an access parameter associated with the function, such as for example a tariff option and an identifier of a second function, such as a payment function associated with the option.
- an access parameter associated with the function such as for example a tariff option and an identifier of a second function, such as a payment function associated with the option.
- this embodiment makes it possible to specify to a user the conditions of access and use of a function registered in a chain of blocks.
- function is meant a portion of computer code representing a computer subroutine, which performs a particular task or calculation.
- the function identifier is for example the name given by the programmer when creating it or the signature of the function including parameters.
- a terminal identifier is understood to mean a sequence of characters that uniquely identifies the terminal such as a MAC address, an IP address, a serial number (eg an IMEI) or a cryptographic key.
- the identifier of the terminal can also be an identifier of the user entered by the latter via a user interface of the terminal such as a graphical or voice interface, and making it possible to uniquely identify the user of the terminal.
- the identifier can for example be an e-mail address, an identity card number, a subscriber number, etc.
- a method as described above is characterized in that the sending step is followed by a first step of publishing in said chain of blocks, said identifier of said first terminal , at least one datum associated with the receiving step and at least one datum associated with the sending step.
- This publication in the blockchain is carried out to store and share information related to the reception and transmission stages such as the date and time of reception and transmission of requests, elements received or sent such as for example the identifier of the terminal, or the result of processing carried out by the device.
- a method as described above is characterized in that the emission step is followed:
- this embodiment allows the user to execute the second function such as for example a payment function allowing the use of the first function.
- a blockchain post is also performed to store and share the result of performing the second function.
- the information published can for example be the status of a payment, information related to the request for execution of the second function such as the identifier of the terminal and / or of the user or any other information associated with the. execution of the second function.
- a method as described above is characterized in that the second publication step is followed by a second step for sending a response to the request.
- execution comprising at least one piece of data associated with the result of the execution of said at least one second function.
- this embodiment allows the user to have information on the execution of the second function and its result.
- the second function is a payment function
- the user will thus have, for example, information on the status of the payment (accepted, refused or pending) or its transaction number.
- a method as described above is characterized in that the second publication step is followed:
- a third step of sending a response to the authorization request comprising at least one second parameter for accessing said at least one first function, said access parameter being a function of the result of the execution of said at least one second function obtained via the data of said payment publication;
- this embodiment makes it possible to verify that the user does indeed have the right to access the first function.
- the application will then verify that the second function has been executed by the user's terminal and that the result conforms to what is expected. For example, the application will check that a payment has been made by the user (execution of the second function) and that the payment has been validated (compliant result) before giving access to the first function.
- Method for controlling the execution of a function of an application implemented by a device for controlling the execution of a function of an application, this control device being registered in a chain of blocks, the method being characterized in that it comprises:
- this embodiment allows, when a first execution request to a first function of an application registered in a blockchain is sent by a user terminal, to return a response with an identifier of a second function such as for example a function which will make it possible to give additional information to the user on the first function.
- a method of controlling the execution of a function of an application as described above is characterized in that the sending step is followed by a first step of publication in the blockchain of said identifier of said terminal, at least one datum associated with the receiving step and at least one datum associated with the sending step.
- This blockchain posting is performed following the issue step of the fulfillment request response to store and share information related to the receive and issue steps such as date and time. time of reception and transmission of requests, of elements received or sent such as for example the identifier of the terminal, or the result of a processing carried out by the device
- a method of controlling the execution of a function of an application as described above is characterized in that the emission step is followed:
- this embodiment makes it possible, when a second request for execution of a first function of an application registered in a chain of blocks is sent by a user terminal, to issue a request for authorization of use. and to obtain in return an access parameter to the first function for the user terminal. The execution of the function then depends on the access parameter.
- a publication in the blockchain is also carried out to store and share information related to the stages of reception, transmission and execution such as the date and time of reception and transmission of requests, elements received or sent as for example the access parameter, or the result of a processing carried out by the device.
- a method of controlling the execution of a function of an application as described above is characterized in that the second publication step is followed by a third step sending a response to the second execution request comprising at least one piece of data associated with the result of the execution of said at least one first function.
- this embodiment allows the user to have information on the execution of the first function and its result.
- the invention also relates to a device for controlling access to a function of an application, said control device being registered in a chain of blocks and comprising:
- a module for sending a response to the access request comprising at least one parameter for accessing said at least one first function and at least one second identifier at least one second function registered in said chain of blocks, said at least one second identifier being associated with said at least one parameter;
- a device for controlling access to a function of an application as described above is characterized in that it further comprises:
- a second module for receiving an execution request, coming from at least a second terminal, of said at least one second function, said execution request comprising at least said identifier of said first terminal;
- a device for controlling access to a function of an application as described above is characterized in that it further comprises:
- a third module for receiving a request for authorization of use by said first terminal of said at least one first function, said request coming from said application and comprising at least said identifier of said first terminal and at least said first identifier of said at least one first function;
- a third module for sending a response to the authorization request comprising at least one second parameter for accessing said at least one first function, said access parameter being a function of the result of the execution of said at least one first function. at least one second function obtained in the data of said payment publication; a third module for publishing, in the blockchain, said at least one second access parameter and said identifier of said first terminal.
- the invention also relates to a device for controlling the execution of a function of an application, said control device being registered in a chain of blocks and comprising:
- a device for controlling the execution of a function of an application as described above is characterized in that it further comprises:
- a second module for receiving a second execution request, coming from said terminal, of said at least one first function, said second execution request comprising at least said first identifier of said at least one first function and at least said identifier of said terminal;
- a second module for transmitting an execution authorization request, for said terminal, of said at least one first function, said authorization request comprising at least said identifier of said terminal and at least said first identifier of said terminal. said at least one first function;
- a third module for receiving a response to the authorization request comprising at least one parameter for accessing said at least one first function for said terminal;
- module can correspond both to a software component and to a hardware component or a set of hardware and software components, a software component itself corresponding to one or more computer programs or subroutines or more generally. to any element of a program capable of implementing a function or a set of functions as described for the modules concerned.
- a hardware component corresponds to any element of a hardware assembly capable of implementing a function or a set of functions for the module concerned (integrated circuit, smart card, memory card, etc. .).
- the invention also relates to a computer program comprising instructions for implementing one or other of the methods defined above according to any one of the particular embodiments described above, when said program is executed. by a processor.
- the method can be implemented in various ways, in particular in wired form or in software form.
- This program can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other. desirable shape.
- the invention also relates to a recording medium or information medium readable by a computer, and comprising instructions of a computer program as mentioned above.
- the aforementioned recording media can be any entity or device capable of storing the program.
- the medium can comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording means, for example a hard disk.
- the recording media can correspond to a transmissible medium such as an electrical or optical signal, which can be conveyed via an electrical or optical cable, by radio or by other means.
- the programs according to the invention can in particular be downloaded from an Internet type network.
- the recording media can correspond to an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question.
- Figure 1 shows the hardware architecture of an access control device to a function according to a particular embodiment
- Figure 2 shows the hardware architecture of a device for controlling the execution of a function according to a particular embodiment
- FIG. 3 represents in the form of a flowchart the main steps of a method of controlling access to a function and the main steps of a method of controlling the execution of a function in accordance with the modes of operation. realization of the invention.
- FIG. 1 represents the hardware architecture of a DCA access control device to a function in accordance with the invention.
- this device has the hardware architecture of a computer. It notably comprises a processor PROC1, a random access memory MV1, a read only memory MEM1 and a non-volatile flash memory MF1.
- the read only memory constitutes a recording medium in accordance with the invention, readable by the processor PROC1 and on which is recorded here a computer program PG1 in accordance with the invention, this program comprising instructions for implementing the steps of the process. method of controlling access to a function as described above, when the program is executed by the processor PROC1.
- the code instructions of the computer program PG1 are for example loaded into a memory before being executed by the processor PROC1.
- the processor PROC1 of the processing unit UT1 notably implements the steps of the method of controlling access to a function according to any one of the particular embodiments described in relation to FIG. 3, according to the instructions of the program d computer PG1.
- the DCA device also comprises communication modules COM 11 and COM 12 configured to establish communications with for example an IP network and / or circuit.
- the communication module COM11 is used to receive requests for access to a first function coming from a terminal and the module COM 12 to send a response comprising access parameters and an identifier of a second function associated with the first function.
- the DCA device further comprises an OBT1 module capable of publishing in the block chain data related to the reception and transmission steps of the access control method to a function.
- the modules COM11 and COM12 can be one and the same communication module (COM1).
- the module COM1 is also able to receive requests for execution of the second function and the module OBT1 is able to publish in the block chain data related to the step of receiving d 'an execution request and its execution.
- the second function can be executed by the DCA device and its processor PROC1 or via a dedicated module (not shown here).
- the module COM1 can also be used to send a response to the execution request with data concerning the result of the execution of the second function.
- the module COM1 can also receive authorization request requests concerning the use of the first function and send a response comprising a second access parameter according to a publication. obtained from the blockchain via the OBT1 module.
- the module OBT1 can also publish in the block chain data such as the second parameter, an identifier of the terminal or any other data relating to the data received and sent by the module COM1.
- the requests received and sent by the DCA device are handled by the module COM1.
- the DCA device can include several communication modules allowing the reception and / or transmission of requests.
- the OBT1 module manages all the publications made at the blockchain level.
- the DCA device can include several publication modules allowing the publication and / or the obtaining of the publications at the blockchain level.
- FIG. 2 shows the hardware architecture of a DCE control device for the execution of a function according to the invention.
- this device has the hardware architecture of a computer. It comprises in particular a processor PROC2, a random access memory MV2, a read only memory MEM2 and a non-volatile flash memory MF2.
- the read only memory constitutes a recording medium in accordance with the invention, readable by the processor PROC2 and on which is recorded here a computer program PG2 in accordance with the invention, this program comprising instructions for implementing the steps of the method of controlling the execution of a function as described above, when the program is executed by the processor PROC2.
- the code instructions of the computer program PG2 are for example loaded into a memory before being executed by the processor PROC2.
- the processor PROC2 of the processing unit UT2 notably implements the steps of the method for controlling the execution of a function according to any one of the particular embodiments described in relation to FIG. 3, according to the instructions of the computer program PG2.
- the DCE device also comprises communication modules COM21 and COM22 configured to establish communications with for example an IP network and / or circuit.
- the communication module COM21 is used to receive requests for execution of a first function from a terminal and the module COM22 to send a response comprising an identifier of a second function registered in a chain of blocks. Note that the response can also include network parameters.
- the DCE device further comprises an OBT2 module capable of publishing in the block chain data related to the reception and transmission steps of the method for controlling the execution of a function.
- the modules COM21 and COM22 can be one and the same communication module (COM2).
- the module COM2 is also able to send a request for authorization to use the first function by the terminal and to receive a response comprising an access parameter to the first function.
- the OBT2 module can also be used to publish in the blockchain data related to the step of sending the request for authorization of use and to its execution according to an access parameter received in response to the request for authorization of use.
- the first function can be executed by the DCE device and its processor PROC2 or via a dedicated module (not shown here).
- the module COM2 can also send, to the terminal, a response to the execution request, the response possibly including data associated with the result of the execution of the first function.
- the OBT2 module can also publish in the blockchain data such as the result of the execution of the first function, an identifier of the terminal or any other data relating to the data received and sent by the module COM2.
- the requests received and sent by the DCE device are handled by the module COM2.
- the DCE device can include several communication modules allowing the reception and / or transmission of requests.
- the OBT2 module manages all the publications made at the blockchain level.
- the DCE device can include several publication modules allowing publication and / or obtaining of publications at the blockchain level.
- FIG. 3 consists of a TRM terminal such as for example a mobile terminal or a computer capable of sending and receiving requests to and from a block chain and DCE and DCA devices registered in a block chain and capable of executing decentralized functions or DApps in the sense of blockchain technology. These applications are in the form of executable code.
- the DCE device executes a DApps comprising a function F1
- the DCA device executes a DApps comprising the functions F2 and F3.
- the TRM terminal sends a request for execution of the function F1 of the DApps to the DCE device.
- the request comprises for example the identifier of the sending terminal and the identifier of the function F1.
- the request can also include other data such as tokens, cryptographic keys allowing for example the DCE device to authenticate the TRM terminal or a user identifier that he has previously entered at the level of the TRM terminal via for example a dedicated user interface such as a voice or graphic interface.
- a dedicated user interface such as a voice or graphic interface.
- the DCE device On receipt of the request (El 1), the DCE device will process the request and generate a response comprising an identifier of a second function F2. The DCE device will then send this response (El 2) to the TRM terminal. Concretely, the DCE device realizes a redirection to an F2 function of a DApps executed by the DCA device.
- the DCE device can also publish in the block chain information related to the reception and transmission steps such as the date and time of reception and transmission of requests, elements received or sent such as for example the identifier. of the terminal, or the result of processing carried out by the device.
- the TRM terminal will generate a request for execution of the function F2 intended for the DCA device.
- the request is sent to step E20 with for example the same data as the first request sent by the terminal TRM to step E10.
- the request is then received, in step E21, by the DCA device that will perform the F2 function.
- the result of the function F2 is for example a list of data pairs of which the first data of each pair is an identifier or a character string indicating a tariff option (ID PA) associated with the execution of the function F1 and the second data, an identifier of a third function (ID F3) associated with the tariff option.
- ID PA tariff option
- ID F3 a third function associated with the tariff option
- the DCA device can also publish in the block chain information related to the reception and transmission steps such as the date and time of reception and transmission of requests, elements received or sent such as for example the identifier. of the terminal, the execution information of the function F2, or the result of the function F2.
- This publication is called a "tariff publication”.
- the DCA device may not need to perform function F2. This is the case, for example, if the list is static, that is to say that the tariff options remain unchanged for a fairly long period of time (ex: 1 week, 1 month, 1 year, etc.).
- a tariff option can be associated with the execution of a function, for example Fl, or with several functions (Fil,
- a tariff option may depend on the identifier of the terminal. This is the case, for example, when a price for the execution of the function Fl is negotiated by a company for its employees.
- a tariff option may be associated with a validity period.
- the user of the TRM terminal will then choose a tariff option from the list according to his needs.
- the tariff option chosen will make it possible to specify the framework for executing the function Fl for the TRM terminal and its user.
- the pricing options can for example determine:
- a subscription that is to say unlimited use of the function F1 for a determined period.
- a price based on a data external to the block chain such as an energy cost or data sent by an Oracle.
- an Oracle is a service authorized to enter data into the blockchain at the request of a user.
- the cost of use may for example vary depending on the duration of the time slot or depending on its start time.
- the user can, for example, pay less for a time slot starting at night.
- This makes it possible to encourage users of the Fl function to request its execution for a given period to take into account the load on the server.
- it is possible to smooth the executions over time and therefore optimize the hardware architectures (memory, processors, etc.) of the servers.
- the terminal will send a request to execute the F3 function to the DCA device.
- Function F3 is for example a payment function associated with the chosen tariff option.
- the DCA device will then execute (E25) the function F3 and proceed to payment using the payment parameters (PAY PARA) received previously.
- the device can verify that the payment has indeed taken place thanks to the payment parameters (PAY PARA) received previously.
- These settings can be banking information, proof of purchase information, or blockchain user account information to make or certify a payment.
- the payment process can be done outside or inside the blockchain. In the event that payment is made outside of the blockchain, the DCA device will, for example, obtain proof of purchase from a third party to determine whether the payment has been made.
- the payment process can correspond to a sequestration of an amount in anticipation of the execution of the function F1 by the user terminal. The amount is then released at the time of execution of the function Fl with the consequence of making the payment.
- the DCA device can send a response (E26) to the TRM terminal comprising the result of the payment or its acceptance (PAY RESULT).
- the result is for example a status concerning the act of payment (payment made or refused or pending) or any other data relating to the act of payment (date, status, transaction number, financial institution, etc.).
- the DCA device can obtain from the block chain, via the data of the so-called tariff publication, the date on which the DCA device sent the tariff options of the F1 function to the TRM terminal. (E22).
- the DCA device can verify that the offer is still valid before executing the function F3. This verification is conventionally carried out by comparing the date of receipt of the request E25 with that of the request E22 to which the period of validity is added. If the date of the request E25 is earlier then the tariff option is still valid and the DCA device can execute the function F3. Otherwise, an error message is sent to the TRM terminal, for example during step E26.
- the DCA device can also publish in the blockchain information related to the reception (E25) and transmission (E26) steps such as the date and time of reception and transmission of requests, elements received or sent. such as for example the identifier of the terminal, the execution information of the function F3, or the result of the function F3.
- This publication is called a “payment publication”.
- step E30 the TRM terminal sends the request for execution of function F1 a second time to the DCE device.
- the request can be enriched with respect to that sent in step E10 with additional data such as a payment transaction number or a counter value.
- the DCE device On receipt of the request by the DCE device (E31), the latter will check whether this request for execution of the function F1 by the terminal TRM is not the first. For this, the DCE device can consult its history of received and transmitted requests in order to determine whether the request in question is the first. The device can also be based on parameters of the request such as the payment transaction number or the value of the counter. In the case of a counter value, it is the TRM terminal which will increment it during a new transmission of the request for execution of the function F1.
- the DCE device goes to step E32 to issue a request for authorization to use the function F1 by the terminal TRM to the DCA device.
- This request comprises for example the identifier of the terminal TRM (ID TRM) and the identifier of the function F1 (ID Fl).
- the DCA device will then obtain, for example from a private memory, the status of the payment (result of execution of function F3 or proof of purchase) and deduce therefrom an access parameter to function F1 (PARAC) for the terminal TRM.
- the access parameter can also be a function of other data such as the date or time if the tariff offer chosen by the user is a function of a time slot but also of a value of a counter indicating the number of executions already carried out of function F1 if the tariff offer chosen by the user is a function of a number of executions.
- the DCA device can get the status of the payment from the blockchain. Obtaining this status can be done via the data of the so-called payment publication and the retrieval of a dedicated parameter or by retrieving the information concerning the execution of the payment function.
- the PARAC parameter can for example be a Boolean which indicates, when it is for example set to 1 that the TRM terminal has the authorization to execute the Fl function.
- the PARAC parameter can be a character string or any other set of data making it possible to provide a status on the authorization to execute the function F1 by the terminal TRM.
- the PARAC parameter can for example be a boolean / character string pair in which the boolean gives information on the authorization to execute the function F1 by the terminal TRM and the character string represents a label such as a code error in the event that the authorization is refused.
- step E34 the DCA device will return a response to the DCE device comprising the access parameter PARAC, the identifier of the TRM terminal (ID TRM) and the identifier of the function Fl (ID Fl).
- the DCA device can also publish in the blockchain information related to the reception (E33) and transmission (E34) steps such as the date and time of reception and transmission of requests, elements received or sent.
- the blockchain information related to the reception (E33) and transmission (E34) steps such as the date and time of reception and transmission of requests, elements received or sent.
- the identifier of the terminal such as for example the identifier of the terminal, the access parameter PARAC, or the result of a processing carried out by the device.
- the DCE device When the DCE device receives the response (E35), it will test (E37) the PARAC parameter. If the PARAC parameter indicates that the execution of the function F1 by the terminal TRM is not authorized, then the device DCE sends the parameter PARAC to the terminal TRM. The TRM terminal thus has the information that execution is not possible and the reason why execution cannot be carried out. Conversely, if the PARAC parameter indicates that the execution of the function F1 by the terminal TRM is authorized, then the device will execute the function F1 (E38) and send the result of the execution to the terminal TRM (E39).
- the DCE device can also publish in the blockchain information related to the reception (E31 and E35) and transmission (E32, E36, E39) steps such as the date and time of reception and transmission of requests. , elements received or sent such as for example the identifier of the terminal, the access parameter PARAC, the execution information of the function F1 or the result of the execution of the function F1.
- the function F1 can be executed outside the blockchain.
- the DCE device will send the execution request to an external server via a dedicated blockchain interface.
- the DCE and DCA devices can be one and the same computer machine executing several DApps implementing the functions F1, F2 and F3.
- a request is sent from the DCE device to the DCA device comprising a parameter indicating that the execution of the function Fi has failed, the identifier of the terminal TRM and the identifier of the function Fl.
- the DCA device can then perform by example a partial or total reimbursement of the sum previously paid in step E25.
- the user can, via his TRM terminal and before step E10, consult a directory of functions in order to choose the function F1 to be executed.
- the directory can for example be represented at the terminal level in the form of a list of functions or a table of functions with for example a description, the name of the developer and a note for each function, the note being for example the result of an average of the scores given by the users weighted by the availability rate of the function.
- the directory can for example be retrieved in response to a request sent by the TRM terminal to a DApps registered in a blockchain.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Information Transfer Between Computers (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2001661A FR3107417A1 (fr) | 2020-02-19 | 2020-02-19 | Procédé et dispositif de contrôle d’accès à une fonction d’une application inscrite dans une chaîne de blocs. |
| PCT/FR2021/050276 WO2021165612A1 (fr) | 2020-02-19 | 2021-02-17 | Procede et dispositif de controle d'acces a une fonction d'une application inscrite dans une chaine de blocs |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4107905A1 true EP4107905A1 (fr) | 2022-12-28 |
Family
ID=72470405
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP21710027.0A Pending EP4107905A1 (fr) | 2020-02-19 | 2021-02-17 | Procede et dispositif de controle d'acces a une fonction d'une application inscrite dans une chaine de blocs |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12367319B2 (fr) |
| EP (1) | EP4107905A1 (fr) |
| FR (1) | FR3107417A1 (fr) |
| WO (1) | WO2021165612A1 (fr) |
Family Cites Families (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CA3027741C (fr) * | 2016-06-17 | 2020-07-21 | Jonathan WEIMER | Systemes de chaines de blocs et procedes d'authentification d'utilisateur |
| MX2019007034A (es) * | 2016-12-14 | 2019-08-22 | Walmart Apollo Llc | Sistemas y metodos para controlar el acceso a un espacio bloqueado utilizando claves criptograficas almacenadas en una cadena de bloques. |
| US11544708B2 (en) * | 2017-12-29 | 2023-01-03 | Ebay Inc. | User controlled storage and sharing of personal user information on a blockchain |
| US11531783B2 (en) * | 2018-03-27 | 2022-12-20 | Workday, Inc. | Digital credentials for step-up authentication |
| CN108632284B (zh) * | 2018-05-10 | 2021-02-23 | 网易(杭州)网络有限公司 | 基于区块链的用户数据授权方法、介质、装置和计算设备 |
| US10693716B2 (en) * | 2018-05-29 | 2020-06-23 | At&T Mobility Ii Llc | Blockchain based device management |
| US20200020440A1 (en) * | 2018-07-12 | 2020-01-16 | Appley Health, Inc. | Computer-assist method using distributed ledger technology for operating and managing an enterprise |
| US11489816B2 (en) * | 2018-07-31 | 2022-11-01 | Ezblock Ltd. | Blockchain joining for a limited processing capability device and device access security |
| US11276056B2 (en) * | 2018-08-06 | 2022-03-15 | Inveniam Capital Partners, Inc. | Digital contracts in blockchain environments |
| WO2020055384A1 (fr) * | 2018-09-11 | 2020-03-19 | Visa International Service Association | Système, procédé, et produit de programme d'ordinateur pour la gestion des fraudes avec carte de hachage partagée |
| US11277261B2 (en) * | 2018-09-21 | 2022-03-15 | Netiq Corporation | Blockchain-based tracking of program changes |
| EP3881270A4 (fr) * | 2018-11-13 | 2022-08-17 | Banqu, Inc. | Définition et gestion de formulaires dans un réseau de confiance de registre distribué |
| US10958421B2 (en) * | 2018-11-20 | 2021-03-23 | International Business Machines Corporation | User access control in blockchain |
| ES2880455T3 (es) * | 2018-11-27 | 2021-11-24 | Advanced New Technologies Co Ltd | Plataforma de función como servicio (FAAS) en redes de cadena |
| US11263315B2 (en) * | 2018-12-03 | 2022-03-01 | Ebay Inc. | System level function based access control for smart contract execution on a blockchain |
| US10325079B1 (en) * | 2018-12-04 | 2019-06-18 | Capital One Services, Llc | Version management platform |
| US11030297B2 (en) * | 2019-01-04 | 2021-06-08 | Comcast Cable Communications, Llc | Systems and methods for device and user authorization |
| US11368441B2 (en) * | 2019-01-29 | 2022-06-21 | Mastercard International Incorporated | Method and system for general data protection compliance via blockchain |
| JP2020528224A (ja) * | 2019-04-26 | 2020-09-17 | アリババ・グループ・ホールディング・リミテッドAlibaba Group Holding Limited | 信頼できる実行環境におけるスマート契約動作のセキュアな実行 |
| US11132460B2 (en) * | 2019-06-07 | 2021-09-28 | Mo Ac Blockchain Tech Inc. | Apparatus and method for controlling access to user information |
| US11734616B2 (en) * | 2019-07-12 | 2023-08-22 | Mastercard International Incorporated | Method and system for access control of shared spaces through blockchain |
-
2020
- 2020-02-19 FR FR2001661A patent/FR3107417A1/fr not_active Withdrawn
-
2021
- 2021-02-17 US US17/800,707 patent/US12367319B2/en active Active
- 2021-02-17 WO PCT/FR2021/050276 patent/WO2021165612A1/fr not_active Ceased
- 2021-02-17 EP EP21710027.0A patent/EP4107905A1/fr active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| WO2021165612A1 (fr) | 2021-08-26 |
| US20230177214A1 (en) | 2023-06-08 |
| US12367319B2 (en) | 2025-07-22 |
| FR3107417A1 (fr) | 2021-08-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1299838A1 (fr) | Systeme et procede de gestion de transactions de micropaiement, terminal de client et equipement de marchand correspondants | |
| EP1164529A1 (fr) | Système et procédé de couponnage électronique | |
| EP1314143A1 (fr) | Dispositif et procede de sauvegarde d'information de transaction en ligne | |
| CA2999731A1 (fr) | Procede de traitement de donnees par un terminal de paiement, terminal de paiement et programme correspondant | |
| WO2020128240A1 (fr) | Traitement d'un service de tickets electroniques | |
| EP4359986B1 (fr) | Procédé et dispositif de paiement par chaînes de blocs | |
| EP3485451B1 (fr) | Procédé de traitement d'au moins une donnée de moyen de paiement, terminal de paiement et programme d'ordinateur correspondant | |
| EP4107905A1 (fr) | Procede et dispositif de controle d'acces a une fonction d'une application inscrite dans une chaine de blocs | |
| FR3062499A1 (fr) | Procede de reduction de la taille d'une base de donnees repartie de type chaine de blocs, dispositif et programme correspondant | |
| EP4099249A1 (fr) | Procédé et dispositif de transmission d'un identifiant d'un utilisateur lors d'un paiement électronique réalisépar l utilisateur | |
| EP4032057A1 (fr) | Procede de transmission d'une information complementaire relative a une transaction financiere | |
| CA3143068A1 (fr) | Systeme d'applications de service pour terminaux de paiement | |
| EP3928501B1 (fr) | Procédé de gestion d'accès d'un utilisateur à un service vocal, dispositif, système et programmes correspondants | |
| WO2023001846A1 (fr) | Procédé de transaction entre un organisme et un établissement sur une chaîne de blocs | |
| FR2862782A1 (fr) | Procede d'acces a un contenu multimedia et plate-forme pour la mise en oeuvre du procede | |
| EP3926566A1 (fr) | Validation d'une transaction relative a une offre d'un bien ou d'un service à un utilisateur | |
| WO2008020123A1 (fr) | Procédé et système de paiement à l'aide d'un téléphone mobile | |
| WO2002005226A1 (fr) | Systeme et procede de gestion de transaction de micropaiement dispositifs client, marchand et intermediaire financier | |
| FR2962830A1 (fr) | Serveur, terminal et procede de transaction securisee | |
| FR3140184A1 (fr) | Procédé et dispositif d’attribution d’un NFT | |
| WO2024188823A1 (fr) | Procédé et dispositif de vérification d'au moins une donnée obtenue depuis un service de fourniture de données | |
| FR2881006A1 (fr) | Systeme de communication pour jeu mobile | |
| FR3163472A1 (fr) | Procédés et dispositifs d’authentification et de validation biométrique d’un utilisateur | |
| FR3143143A1 (fr) | Procédé de connexion à un compte personnel sur un service en ligne au moyen d’une chaîne de blocs | |
| WO2003098433A2 (fr) | Systemes et procedes pour commander selectivement et comptabiliser l'utilisation effective de logiciels |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20220824 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20260217 |