Method and arrangement for reliably identifying a user in a computer system
First Claim
1. A method of reliably identifying a user in a computer system, in which method a mobile station is used for communicating with the computer system and a persona identification number is supplied into the mobile station, the method comprising the steps of:
- generating a first one-time password in the mobile station without any action by the user by utilizing a known algorithm on the basis of a personal identification number of the user, the personal identification number supplied into the mobile station enables the user to use the mobile station, subscriber-specific identifier read from a subscriber-specific identification module of the mobile station, device-specific identifier of the mobile station and time, encoding the first one-time password and the subscriber-specific identifier of the user at the mobile station, transmitting the encoded password and subscriber-specific identifier to an authentication server of the computer system, identifying the user at the authentication server on the basis of the subscriber-specific identifier, and searching a database for the personal identifier number of the user and the device-specific identifier of the mobile station associated with the user, generating a second one-time password at the authentication server by utilizing the predetermined algorithm on the basis of the personal identification number of the user, subscriber-specific identifier, device-specific identifier of the mobile station and time, comparing the first password and the second password with each other at the authentication server, and if the passwords match, enabling the telecommunication connection between the mobile station of the user and the computer system.
1 Assignment
0 Petitions
Accused Products
Abstract
The invention relates to an arrangement and a method for reliably identifying a user in a computer system. The method utilizes a mobile station for communicating with the system. The method comprises generating a first one-time password in the mobile station by utilizing a known algorithm on the basis of the identification number of the user, subscriber-specific identifier, device-specific identifier of the mobile station, and time. The password obtained and the subscriber-specific identifier of the user are encoded and transmitted to an authentication server of the computer system, comprising identifying the user on the basis of the subscriber-specific identifier, searching a database for the personal identifier number of the user and the device-specific identifier of the mobile station associated with the user, generating a second password at the authentication server by utilizing the same predetermined algorithm on the basis of the personal identification number of the user, subscriber-specific identifier, device-specific identifier of the mobile station and time, comparing the first and the second passwords with each other at the authentication server, and if the passwords match, enabling the telecommunication connection between the mobile station and the computer system.
209 Citations
19 Claims
-
1. A method of reliably identifying a user in a computer system, in which method a mobile station is used for communicating with the computer system and a persona identification number is supplied into the mobile station, the method comprising the steps of:
-
generating a first one-time password in the mobile station without any action by the user by utilizing a known algorithm on the basis of a personal identification number of the user, the personal identification number supplied into the mobile station enables the user to use the mobile station, subscriber-specific identifier read from a subscriber-specific identification module of the mobile station, device-specific identifier of the mobile station and time, encoding the first one-time password and the subscriber-specific identifier of the user at the mobile station, transmitting the encoded password and subscriber-specific identifier to an authentication server of the computer system, identifying the user at the authentication server on the basis of the subscriber-specific identifier, and searching a database for the personal identifier number of the user and the device-specific identifier of the mobile station associated with the user, generating a second one-time password at the authentication server by utilizing the predetermined algorithm on the basis of the personal identification number of the user, subscriber-specific identifier, device-specific identifier of the mobile station and time, comparing the first password and the second password with each other at the authentication server, and if the passwords match, enabling the telecommunication connection between the mobile station of the user and the computer system. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. An arrangement for reliably identifying a user in a compute system, which arrangement comprises
a mobile station used for communicating with the computer system, the mobile station comprising a subscriber-specific identification module comprising a subscriber-specific identifier, a device-specific identifier permanently encoded in the mobile station, means for reading a personal identifier number which is supplied by the user and which enables the device to be used, means for checking the correctness of the identifier number always before the device is put to use, and which arrangement comprises an authentication server comprising memory means for storing the user names of the users in the system and the corresponding personal identifiers and device-specific identifiers, the mobile station further comprising means for generating a first one-time password without any action by the user by utilizing a known algorithm on the basis of the personal identification number of the user, subscriber-specific identifier read from a subscriber-specific identification module of the mobile station, device-specific identifier of the mobile station and time, means for encoding the first one-time password and the subscriber-specific identifier of the user, means for transmitting the encoded password and subscriber-specific identifier to an authentication server of the computer system, and the authentication server is further arranged to identify the user on the basis of the subscriber-specific identifier, and search a database for the personal identifier number of the user and the device-specific identifier of the mobile station associated with the user, generate a second one-time password at the authentication server by utilizing the predetermined algorithm on the basis of the personal identification number of the user, subscriber-specific identifier, device-specific identifier of the mobile station and time, compare the first password and the second password with each other at the authentication server, and if the passwords match, enable the telecommunication connection between the mobile station of the user and the computer system.
Specification