- 相关
- 目录
- 笔记
- 书签
暂无目录
点击鼠标右键菜单,创建目录
暂无笔记
选择文本,点击鼠标右键菜单,添加笔记
暂无书签
在左侧文档中,点击鼠标右键,添加书签
188宝金博页面版: A SYSTEM AN ARRANGEMENT AND A METHOD FOR END USER AUTHENTICATION
下载积分:
3500
内容提示: EP 1 987 627 B12510152025303540455055DescriptionFIELD OF THE INVENTION[0001] The present invention relates to a system forauthentication of an end user of a user station arrange-ment requesting access to protected information, for ex-ample a protected resource or a protected service or sim-ilar, which comprises access server means and authen-tication means, wherein the mobile user station arrange-ment supports communication with the authenticationmeans over a first communication channel of a radio net-work...
文档格式:PDF |
页数:25 |
浏览次数:13 |
上传日期:2023-04-19 02:40:47
|
文档星级:
EP 1 987 627 B12510152025303540455055DescriptionFIELD OF THE INVENTION[0001] The present invention relates to a system forauthentication of an end user of a user station arrange-ment requesting access to protected information, for ex-ample a protected resource or a protected service or sim-ilar, which comprises access server means and authen-tication means, wherein the mobile user station arrange-ment supports communication with the authenticationmeans over a first communication channel of a radio net-work.[0002] The invention also relates to an authenticationmeans for authentication of an end user requesting ac-cess to protected information, a protected resource or aprotected service, from a user station arrangement com-prising an access serving means interface, at least oneinterface enabling communication with the user stationarrangement over a first communication channel of a ra-dio network.[0003] The invention also relates to a method for au-thentication of a remote end user of a user station ar-rangement requesting access to a protected service, re-source, information etc. by sending an access requestto an authentication means. Particularly it relates to au-thentication of mobile users requesting access to pro-tected resources via an IP network or other form of elec-tronic access network.STATE OF THE ART[0004] Remote access to services which are protected,or protected sensitive information in general, via publicnetworks requires strong authentication of the end userto avoid abuse of the protected information or to preventthat the protected information or services are spread un-intentionally. Traditionally authentication is provided withso-called authentication tokens provided to the end us-ers. It is then verified if the end user is in possession ofthe token before access to the protected service or infor-mation is granted. A typical example thereof is a so calledtoken card, which provides the end user with pseudo-random one-time passwords to be verified by an authen-tication server.[0005] As an alternative to the deployment of separateauthentication tokens, the identity module of a mobiledevice, for example a GSM SIM (Subscriber IdentityModule) card or an UMTS (Universal Mobile Telecom-munication System) USIM (UMTS SIM) can be utilisedas a token. The identity module may contain a privatesecret key which can be used for signing an authentica-tion challenge and to prove that the remote end user isin possession of the security token, which in such imple-mentations consists of the identity module of the mobiledevice.[0006] Today there are two main approaches for utilis-ing the identity module of mobile devices as a securitytoken. One of the approaches consists in utilising themobile network as a security channel, whereby the au-thentication server communicates with the mobile devicevia the radio network, which in the following will be de-noted network-based authentication. Network-based au-thentication provides superior ease-of-use, since the au-thentication server automatically can carry out severalsteps in the authentication dialogue with only minimuminput from the end user. It is however a disadvantagewith such network-based authentication methods that themobile device has to be within radio coverage for theauthentication to work. Another disadvantage is that thechannel simply can be blocked, thus preventing authen-tication to be performed.[0007] Another approach is based on requesting theend user to manually perform a signature operation onthe mobile device, which here is denoted authenticationwith manual input.[0008] Authentication with manual input requires con-siderable interaction with the end user, the end user e.g.has to read a challenge from the access channel, inputthis on the mobile device, and return a signed responseevery time. This becomes particularly inconvenient if themobile device simultaneously is used as an access ter-minal. Such an approach is however not dependent onradio coverage.[0009] US-A-5 668 876 describes a method and anapparatus for authentication of an end user attemptingto access an electronic service whereby a challenge codeis sent to a personal unit such as a mobile phone to beused with a standard telephone, a mobile telephone ora wired telephone. A challenge code is transmitted to thepersonal unit, the user puts in a PIN or similar, the unitgenerates a response code based on an internally storedsecret key. This code is input on e.g. a telephone, sentback for comparing the response with the original chal-lenge code or with an expected response code to allowor reject access. This document particularly solves theproblem of requiring dedicated terminals or customizedterminals restricting the use of security systems to spe-cific sites. However, this solution is disadvantageous inthat it does not follow up the outcome of the delivery ofchallenge codes, which among others means that if thereis no radio coverage, the authentication will fail.[0010] US 2005/085258 describes a wireless commu-nication system comprising both a cellular system and aWLAN. A mobile terminal requesting access to the com-munication system selects to communicate either via thecellular system or via the WLAN.[0011] WO03/055261 shows a mobile terminal thathas capability to communicate with two different mobilenetworks. The second network has priority over the firstnetwork. When the mobile station moves into the cover-age area of the second network, a connection to the sec-ond network is authorized based on an authorization al-ready made for the first network.1 2
