×

Secured authentication method for providing services on a data transmisson Network

  • US 8,359,273 B2
  • Filed: 08/05/2005
  • Issued: 01/22/2013
  • Est. Priority Date: 08/10/2004
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of accessing a service, via a data transmission network, using a user terminal (30) connected to said network, comprising:

  • a step of the user connecting the user terminal (30) to an access network (AN), the access network, via a gateway (GW), being connected to the data transmission network, a management server being located on the data transmission network, wherein the access network is one of i) a local wireless network, ii) a public network, iii) a private network, iv) a public switched one network, and v) a private switched telephone network;

    a step of the user subscribing to the service, including the management server generating a secure information container (TOKEN) associated with the user, the secure information container including i) a first encrypted set of authentication data (X0, X1, X2, X3) for accessing the service, and ii) a second encrypted set of data identifying the user (SID/PN) and defining access rights of the user to said service (RBF, UBF, TBF), said information container itself being encrypted prior to secure transmission so that the secure information container is an encrypted digital value of the first encrypted set of authentication data and the second encrypted set of data,said subscribing step further includes an act of payment (a) by the user to a payment server (20), andin return (b) to the payment (a), the user obtaining an activation for the subscribed service, the activation including a one-time use password (OTP) and a secret key, the user terminal transmitting the one time password and the secret key to the management server in order to receive the information container from the management server, the secret key being used by the management server to encrypt the information container, andthe information container comprisingi) the first set authentication data for accessing the service (X0, X1, X2, X3) constituting proof that the user'"'"'s access to the service is authorized, a value and a provenance of the authentication data being authentifiable and verifiable by the management server, the authentication data comprises a field representative of the management server producing the container, and electronic coins comprising bit strings having validity that can be verified, the electronic coins being represented by hash function collisions, andii) the second set data comprising at least one of a subscriber identification number and a telephone number of the user;

    a step of the management server transmitting the secure information container, over the data transmission network, to the user terminal (d);

    a step of the user terminal receiving the transmitted secure information container and storing the secure information container in the user terminal;

    a step of accessing the subscribed service by sending a service access request from the user terminal to the management server (e), the service access request comprising the secure information container;

    a step of receiving said service access request by the management server and the management server decrypting the secure information container using the secret key, then decrypting the first and second sets of data (f);

    a step of the management server verifying validity of the decrypted first set of data (g); and

    when said validity verification step is successful, a step of the management server authorizing access by the user to the service based on said defined access rights contained in the second set of data,wherein the service refers to any exchange of information, via a digital data transmission network or via a telecommunication data transmission network, between i) the user and another user, or ii) between the user and a service provider,wherein, with the method providing a secured authentication, the method accesses services requiring a secure exchange of information including any of i) a telephony over IP service, ii) a videotelephony service, iii) a service for downloading digital files, and iv) a payment service.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×