Strong authentication of a user of a communication terminal
By implementing voiceprint authentication and multi-level authentication methods on basic communication terminals, the problem of insufficient security authentication of basic communication terminals is solved, and high-security and reliable access to sensitive services is achieved.
Patent Information
- Application Number
- CN202180024957.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-27
- Filing Date
- 2021-03-05
- Publication Date
- 2026-06-23
- Estimated Expiration
- 2041-03-05
AI Technical Summary
Basic communication terminals lack internet access capabilities, making it difficult to provide secure authentication for high-value-added services. Existing technologies mainly rely on MSISDN number authentication, which is insufficient in terms of security.
By implementing voiceprint authentication on communication terminals, combined with voice biometric mechanisms, strong authentication is performed using DTMF, USSD, or SMS channels, and multi-level authentication is performed using the user's voiceprint and password.
It improves the security and reliability of basic communication terminals accessing sensitive services, reduces the risk of fraud, and ensures the accuracy of user identities.
Smart Images

Figure CN115349245B_ABST
Abstract
Description
Technical Field
[0001] This invention generally relates to the field of strong authentication for users of communication terminals.
[0002] This invention is more specifically applicable to authenticating users requesting access to services through any type of communication terminal (including communication terminals without Internet access capabilities). Background Technology
[0003] Currently, although smartphones have been on the market for a decade, basic communication terminals (also known as "feature phones" or "basic phones") remain popular. Because these basic communication terminals lack internet access, the use of high-value-added services is relatively limited, as this requires strong user authentication. Users requesting service access through basic communication terminals typically authenticate using their mobile phone number, specifically their MSISDN (Mobile International Subscriber Directory Number). Summary of the Invention
[0004] One of the objectives of this invention is to overcome the shortcomings of the prior art by providing users of communication terminals, regardless of their basic type, with access to more services, especially those that require strong authentication of the user (e.g., banking services, which are easy to implement for all such terminals).
[0005] Therefore, one aspect of the present invention relates to a method for authenticating users of a service on a communication terminal, the method comprising the following operations performed on the communication terminal:
[0006] - Send a request to the server to access the server, the request including a first identifier associated with the communication terminal and a second identifier associated with the service requested on the server.
[0007] - Receive an authentication request from the authentication device requiring the user to say at least one word.
[0008] - The device will transmit at least one word spoken by the user.
[0009] - The spoken at least one word corresponds to the user's voiceprint, which is pre-recorded and associated with the identifier of the communication terminal, to access the service or to receive an additional authentication request from the device for additional authentication of the user.
[0010] Therefore, the sequence of operations described above advantageously allows users of communication terminals (whether smartphones or basic terminals without internet access) to securely access services that process user-specific sensitive data (such as banking or medical data) by means of:
[0011] - Identification of communication terminal identifiers, such as telephone numbers associated with the communication terminal.
[0012] -Speech biometrics mechanism.
[0013] According to one particular embodiment, the received additional authentication request is a password request, and in response, the terminal transmits the requested password in text or voice form.
[0014] By providing the user with an additional level of authentication, receiving such a password request can further enhance the security of accessing services requested by the communication terminal.
[0015] According to another specific embodiment, the second identifier associated with the requested service belongs to the group that includes: dual-tone multi-frequency (DTMF) codes, USSD (“Unstructured Supplemental Service Data”) codes, and SMS (“Short Message Service”) messages.
[0016] The advantage of DTMF (Dual-Tone Multi-Frequency), USSD, or SMS communication channels is their widespread use in the vast majority of communication terminals on the market, especially in those without internet access. Therefore, by using such communication channels, this type of access can be protected by providing strong or even very strong authentication to the user. The level of fraud against this type of access is significantly reduced.
[0017] According to another specific embodiment, the at least one word spoken and transmitted to the authentication device is identified based on at least one physical characteristic of the user.
[0018] The advantage of using at least one physical characteristic of the user to identify the at least one word spoken by the user is that this type of characteristic is unreproducible to malicious individuals who wish to fraudulently access the service requested by the user. Therefore, the reliability of accessing services using a basic terminal is improved.
[0019] According to another specific embodiment, the at least one physical characteristic belongs to the group including the tone, speed, and accent of the user when speaking the word.
[0020] The various embodiments or implementation features described above can be added individually or in combination to the authentication methods defined above.
[0021] The present invention also relates to a communication terminal for implementing user authentication access to a service, the terminal including a processor configured to perform the following operations:
[0022] - Send a request to the server to access the server, the request including a first identifier associated with the communication terminal and a second identifier associated with the service requested on the server.
[0023] - Receive an authentication request from the authentication device requiring the user to say at least one word.
[0024] - The device will transmit at least one word spoken by the user.
[0025] - The spoken at least one word corresponds to the user's voiceprint, which is pre-recorded and associated with the identifier of the communication terminal, to access the service or to receive an additional authentication request from the device for additional authentication of the user.
[0026] The present invention also relates to an apparatus for authenticating users accessing services via a communication terminal, the apparatus including a processor configured to perform the following operations:
[0027] - Receive a first identifier associated with the communication terminal and a second identifier associated with the requested service from the server that has received the server access request sent by the communication terminal.
[0028] - Send an authentication request to the communication terminal associated with the first identifier, requiring the user to say at least one word.
[0029] - Receive spoken words from the terminal.
[0030] - The spoken at least one word corresponds to the user's voiceprint pre-recorded in association with the first identifier, authorizing the terminal to access the service or sending an additional authentication request to the terminal for additional authentication of the user.
[0031] The present invention also relates to an authentication system, which includes the aforementioned terminal and authentication device.
[0032] The present invention also relates to a computer program comprising instructions which, when executed by a processor, are used to implement the authentication method according to any of the specific embodiments described above.
[0033] Such instructions can be persistently stored in the non-transitory memory medium of the communication terminal implementing the above authentication method.
[0034] This program can be used in any programming language and can be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form or in any other desired form.
[0035] The present invention also relates to a computer-readable recording medium or information medium comprising instructions of a computer program as mentioned above.
[0036] The recording medium can be any entity or device capable of storing programs. For example, the medium may include a storage device such as a ROM (e.g., a CD-ROM or a microelectronic circuit ROM) or a magnetic recording device (e.g., a USB key or a hard disk).
[0037] Furthermore, the recording medium can be a transmissible medium (such as an electrical or optical signal) that can be transmitted via cable or optical fiber, radio, or other means. The program according to the invention can be downloaded, in particular, from a network such as the Internet.
[0038] Alternatively, the recording medium may be an integrated circuit in which the program is incorporated, the circuit being designed to execute or be used to execute the authentication methods mentioned above. Attached Figure Description
[0039] Other advantages and features will become apparent from the specific embodiments of the invention given by way of illustrative and non-limiting example, and from the accompanying drawings, in which:
[0040] [ Figure 1 ] Figure 1 An authentication system according to an embodiment of the present invention is shown.
[0041] [ Figure 2 ] Figure 2 A service providing server according to a specific embodiment of the present invention is shown.
[0042] [ Figure 3 ] Figure 3 An authentication device according to a specific embodiment of the present invention is shown.
[0043] [ Figure 4 ] Figure 4 A communication terminal according to a specific embodiment of the present invention is shown.
[0044] [ Figure 5A ] Figure 5A The main actions implemented in a voiceprint creation method performed prior to authentication, according to a specific embodiment of the present invention, are illustrated.
[0045] [ Figure 5B ] Figure 5B The main actions implemented in the authentication method according to a specific embodiment of the present invention are shown. Detailed Implementation
[0046] Architecture environment
[0047] Figure 1 An environment in which the authentication method according to the present invention is implemented is shown.
[0048] Figure 1 An authentication system is shown, which includes:
[0049] - Smartphone type, or even basic or "feature phone" type (i.e., without internet access capability) communication terminals TER
[0050] -Service provider: Server SER
[0051] - Authentication device AUT, which is used to authenticate the user UT of terminal TER when accessing services provided by server SER.
[0052] Despite Figure 1 The authentication device (AUT) is different from the server (SER), but the authentication device (AUT) can be integrated into the server (SER) to form a single entity.
[0053] The server (SER) and the authentication device (AUT) communicate with each other via any type of communication network (not shown). This network could be, for example, an IP (Internet Protocol) network, x-DSL, fiber optic, or even a 3G, 4G, or 5G network. If the server (SER) and the authentication device (AUT) are close to each other, they can also communicate via a wireless LAN, particularly via Wi-Fi or a PLC (Power Line Communication) network.
[0054] The communication terminal TER is configured as follows:
[0055] - To conduct voice communication with the server SER so that the user UT's voiceprint EV is associated with the identifier ID of the communication terminal TER and recorded in the server SER and / or the authentication device AUT.
[0056] - To communicate via voice or text with the following:
[0057] - Server SER, so that requests can be made to access the services provided by server SER.
[0058] - Authentication device (AUT) to authenticate the user's UT when accessing the provided services.
[0059] This communication is implemented through mobile communication networks (RCMs), which are typically mobile communication networks of operators, such as 2G, 3G, and 4G.
[0060] Server SER is configured to provide multiple services SERV1 to SERV. NFor example, the server could be a mobile operator's platform providing a range of services (e.g., services for accessing the archive of a user UT's communication bills, services for accessing payments on said user's bills, services for accessing the user's community, services for accessing balance inquiries for communication units, etc.). According to another non-limiting example, the server SER could be a bank server providing a range of services (e.g., services for inquiring about a user UT's bank account, payment suspension services, direct debit services, etc.).
[0061] Depending on the sensitivity of the data processed when accessing these services, some services can be accessed through simple authentication of the user's UT, while others can be accessed through strong authentication, and still others can be accessed through very strong authentication.
[0062] The server SER is also configured to, after learning the voice of the user UT transmitted via the communication network RCM, associate the user UT's voiceprint EV with the identifier ID of the communication terminal TER and record it in the server SER and / or the authentication device AUT.
[0063] The authentication device AUT is configured to, upon receiving a service access request from the terminal TER in the server SER via the communication network RCM, perform either Level 1 (simple) authentication AUT1, Level 2 (strong) authentication AUT2, or Level 3 (very strong) authentication AUT3, depending on the requested service. The authentication device AUT is also configured to conduct voice or text communication with the terminal TER via the mobile communication network RCM.
[0064] Description of an embodiment of server SER
[0065] Figure 2 A simplified structure of a server SER is shown, which is designed to provide services to a user UT via a mobile communication network RCM within the framework of the authentication methods described below. For example, this server is an interactive voice server.
[0066] Such servers include:
[0067] - Multiple service software blocks B_SERV1 to B_SERV N ,
[0068] - Voiceprint creation software module CEV
[0069] - Audio communication interface ICA_S, which is designed for voice communication with the user UT's terminal TER via the mobile communication network RCM.
[0070] - Communication interface IC1_S, which is designed to operate via network RCM according to certain protocols (e.g., SMS and / or DTMF and / or USSD) and communicate with the user UT's terminal TER.
[0071] - Communication interface IC2_S, which is designed to communicate with the authentication device AUT according to, for example, IP (short for "Internet Protocol"), x-DSL, fiber optic, 3G, 4G, 5G, Wi-Fi, PLC protocol, etc.
[0072] According to a specific embodiment of the invention, the actions performed by the server SER to provide services and create voiceprints are implemented by instructions from a computer program PG_S. For this purpose, the server SER has a conventional computer architecture and, in particular, includes a memory MEM_S and a processing unit UTR_S equipped with, for example, a processor PROC_S and driven by the computer program PG_S stored in the memory MEM_S. According to any of the specific embodiments of the invention, the computer program PG_S includes instructions for implementing service provisioning and voiceprint creation actions within the framework of the authentication method described below when the program is executed by the processor PROC_S.
[0073] During initialization, the code instructions of the computer program PG_S are loaded into RAM memory (not shown) before being executed by the processor PROC_S. The processor PROC_S of the processing unit UTR_S implements the actions of service provision and voiceprint creation methods in particular according to the instructions of the computer program PG_S.
[0074] Description of an embodiment of the authentication device AUT
[0075] Figure 3 A simplified structure of the authentication device AUT is shown, which is designed to authenticate the user UT via the mobile communication network RCM when the user UT wishes to access services provided by the server SER via its terminal TER.
[0076] This type of certification equipment (AUT) includes:
[0077] - Three authentication software blocks B_AUT1, B_AUT2, and B_AUT3
[0078] - Audio communication interface ICA_A, which is designed for voice communication with the user UT's terminal TER via the mobile communication network RCM.
[0079] - Communication interface IC1_A, which is designed to operate via network RCM according to certain protocols (e.g., SMS and / or DTMF and / or USSD) and communicate with the user UT's terminal TER.
[0080] - Communication interface IC2_A, which is designed to communicate with server SER according to protocols such as IP, x-DSL, fiber optic, 3G, 4G, 5G, Wi-Fi, CPL, etc.
[0081] According to a specific embodiment of the present invention, the action performed by the authentication device AUT to authenticate the user UT is implemented by instructions of a computer program PG_A. For this purpose, the authentication device AUT has a conventional computer architecture and, in particular, includes a memory MEM_A and a processing unit UTR_A, which is equipped with, for example, a processor PROC_A and driven by the computer program PG_A stored in the memory MEM_A. According to any of the specific embodiments of the present invention, the computer program PG_A includes instructions for implementing the authentication method described below when the program is executed by the processor PROC_A.
[0082] During initialization, the code instructions of the computer program PG_A are loaded into RAM memory (not shown) before execution by the processor PROC_A. The processor PROC_A of the processing unit UTR_A implements the authentication method's actions specifically according to the instructions of the computer program PG_A. Description of an embodiment of the communication terminal TER
[0083] Figure 4 A simplified structure of a communication terminal TER is shown, which is designed to access services provided in server SER by authenticating the user UT of the terminal.
[0084] As mentioned above, the communication terminal TER is a smartphone, a basic terminal, or a feature phone. If the terminal TER is a basic terminal, it does not have the ability to access the Internet or intranet.
[0085] The communication terminal TER includes:
[0086] -Display EC,
[0087] - Speaker HP,
[0088] -Microphone (MIC)
[0089] -Keyboard CL,
[0090] - Security modules associated with the confidentiality code CC, such as SIM or USIM type user identification cards (CIA).
[0091] - Audio communication interface ICA_T, which is designed for voice communication with server SER or authentication device AUT via mobile communication network RCM.
[0092] - Communication interface IC1_T, which is designed to operate via network RCM according to certain protocols (such as SMS and / or DTMF (short for "Dual Tone Multi-Frequency") and / or USSD) and communicate with server SER or authentication device AUT.
[0093] According to a specific embodiment of the invention, the actions performed to access services provided in the server SER and allow authentication of the user UT are implemented by instructions of a computer program PG_T. For this purpose, the terminal TER has a conventional computer architecture and, in particular, includes a memory MEM_T and a processing unit UTR_T, which is equipped with, for example, a processor PROC_T and driven by the computer program PG_T stored in the memory MEM_T. According to any specific embodiment of the invention, the computer program PG_T includes instructions for implementing voiceprint creation, service access, and authentication of the user UT, as described below, when the program is executed by the processor PROC_T.
[0094] During initialization, the code instructions of the computer program PG_T are loaded into RAM memory (not shown) before being executed by the processor PROC_T. The processor PROC_T of the processing unit UTR_T specifically implements the user UT's voiceprint creation, service access, and authentication according to the instructions of the computer program PG_T.
[0095] Description of an embodiment of the authentication method
[0096] refer to Figure 5A and Figure 5B Now it will be described in Figure 1 A sequence of authentication methods implemented in an authentication system according to an embodiment of the present invention.
[0097] This authentication method requires the prior creation of the user's UT's voiceprint EV, which in Figure 5A It is described in the text.
[0098] In S10, a communication COM is established between the terminal TER and the server SER. If the server SER knows in advance the MSISDN number associated with the user identification card CIA of the user UT, it can proactively establish communication via its communication interface ICA_S. For example, the MSISDN number may have been pre-stored in the memory of the server SER or the authentication device AUT, or in another device accessible to both the server SER and the authentication device AUT. Alternatively, this number may be an IMSI (International Mobile Subscriber Identity) number, which is the user UT's "private" identifier contained in the user identification card CIA. This communication is voice communication. The MSISDN number or IMSI number is the identifier ID of the communicating terminal TER.
[0099] As a variant, S10 communication can be initiated proactively by the terminal TER. This communication can be voice communication, whereby the user UT dials a phone number assigned to the server SER on the terminal TER's keyboard CL, and the communication is initiated via the network RCM through the terminal TER's communication interface ICA_T. According to another variant, communication can be implemented by the user UT by typing an SMS or USSD code specific to the server SER on the terminal TER's keyboard CL, and then the communication is initiated to the server SER via the network RCM through the terminal TER's communication interface IC1_T. Upon receiving communication from the terminal TER, if the server SER knows in advance the MSISDN or IMSI number associated with the user UT's CIA card, the server SER authenticates the user UT.
[0100] In S11, the server SER then sends a voiceprint creation request REQ.EV to the user UT via the network RCM. If the communication established in S10 is a voice call, the request REQ.EV is a voice request and is sent to the terminal TER via the network RCM through the communication interface ICA_S. For example, the type of the request is: "Please record your voiceprint. First, please say your first and last name." If the communication in S10 is established using DTMF, SMS, or USSD codes, in response, the server SER initiates a telephone call to the terminal TER via the network RCM through the communication interface ICA_S. When the terminal TER is picked up, the server SER then sends the aforementioned voice request REQ.EV. Alternatively, when the terminal TER is picked up, the server SER asks the user UT in a voice: "To record your voiceprint, please press '1'." Then, the user UT presses "1" on the CL keypad of their terminal TER, and then the server SER sends the aforementioned voice request REQ.EV. According to another non-limiting embodiment, if the establishment of communication in S10 is implemented using DTMF, SMS, or USSD codes, then in response, the server SER sends a USSD or SMS message to the terminal TER via its communication interface IC1_S and via the network RCM, thereby inviting the user UT to contact the server SER by telephone to create their voiceprint, or to enter a specific code to directly access the voice-based interactive voiceprint creation service in the server SER, which will then generate the aforementioned voice request REQ.EV.
[0101] In response to request REQ.EV, user UT utters the required statement PHR, which is sent to server SER via network RCM through communication interface ICA_T in S12. Upon receiving the statement, server SER's voiceprint creation module CEV analyzes the spoken statement in S13 and creates a voiceprint EV based on at least one physical characteristic of user UT in S14. The at least one physical characteristic belongs to the group including the tone, speed, and accent of user UT when uttering statement PHR. In S15, server SER analyzes the voiceprint. If the voiceprint is not created correctly, steps S11 to S15 are iterated at least once, and server SER then asks user UT to utter another statement, such as "The duckling is swimming in the river." According to another example, server SER may also ask user UT a question, such as "What is your date of birth?". If the voiceprint EV has been created correctly, it is recorded in server SER, and / or authentication device AUT, and / or a database accessible to server SER and authentication device AUT in S16. The voiceprint EV is recorded in correspondence with the identifier ID of the terminal TER, which in the proposed embodiment is the aforementioned MSISDN or IMSI number.
[0102] At the end of step S16, the server SER can send a message to the user UT confirming the creation of the voiceprint EV. This message can be a voice message, an SMS message, or even a USSD message.
[0103] refer to Figure 5B The method for authenticating users UT who request access to services provided by server SER will now be described.
[0104] In S20, user UT sends a communication request COM to server SER to communicate with server SER using its terminal TER. This communication can be established in voice mode or by sending an SMS message or USSD message to server SER, as explained above in S10. In S21, server SER identifies user UT by requesting the MSISDN or IMSI number contained in S20. To identify user UT, server SER accesses a database containing information (surname, first name, address, etc.) identifying user UTs that match the MSISDN or IMSI number. Alternatively, server SER sends a request containing user UT's MSISDN or IMSI number to authentication device AUT via its communication interface IC2_S. Authentication device AUT activates authentication block B_AUT1, which authenticates user UT according to the first level using the received MSISDN or IMSI number and returns a message to server SER via communication interface IC2_A, indicating that user UT has been correctly authenticated.
[0105] In S22, the voice server SER sends a request REQ.SEL.SERVICE to the terminal TER to select a service provided by the server SER. For example, this request might be a voice message of the following type: "To access service SERV1, say '1'; to access service SERV2, say '2'; to access service SERV3, say '3'". This message is then sent via the network RCM through the server SER's communication interface ICA_S. According to another example, if this request is an SMS message, it would be a text message of the following type: "To access service SERV1, press '1'; to access service SERV2, press '2'; to access service SERV3, press '3'", or if this request is a USSD message, it would be a text message of the following type: "To access service SERV1, press '#001#'; to access service SERV2, press '#002#'; to access service SERV3, press '#003#'".
[0106] In S23, according to one embodiment, the user UT speaks a code associated with the service they wish to access into the microphone MIC of their terminal TER. According to another embodiment, the user UT types the code associated with the service they wish to access onto the keyboard CL of their terminal TER, thereby triggering the transmission of a service access request REQ.ACC.SERVICE to the server SER via the network RCM. The typed code can be a DTMF, SMS, or USSD code. The request REQ.ACC.SERVICE contains the aforementioned MSISDN or IMSI number and a code associated with the service requested by the user UT, which in the example is "1", "2", or "3", or "#001#", "#002#", or "#003#".
[0107] Upon receiving the request REQ.ACC.SERVICE, in S24, the server SER sends the request to the authentication device AUT. If the requested service requires Level 1 authentication (AUT1), and the authentication device AUT has already pre-authenticated the user UT, the authentication device sends a response to the server SER, authorizing the server to allow the user UT to access the requested service. This process is routine, and therefore... Figure 5B Not described in the text. If the requested service requires Level 2 (strong) authentication AUT2, then in S25, the authentication device AUT sends an authentication request REQ_P to the terminal TER, which requests authentication by uttering at least one word. For example, the word is... Figure 5A The example shows the name of the user UT pre-transmitted during the voiceprint creation phase, or one of the statements transmitted by the user UT during that phase. According to another embodiment, the request REQ_P can be sent directly by the server SER after it has been received from the authentication device AUT. For example, such a request is a voice message of the type: "Please say at least one word." This message is then sent to the terminal TER via the network RCM through the communication interface ICA_A of the authentication device AUT. According to another example, such a request is a text message of the type: "Please call back the server SER and say at least one word M," or "The server SER will call you back in 1 minute to ask you to say at least one word."
[0108] In S26, when a request REQ_P is received in the terminal TER, the user UT says the at least one word M. The at least one word is sent directly to the authentication device AUT in the response REP_P to the request REQ_P. Alternatively, if the user UT has called back the server SER or has been called back by the server SER to say the at least one word, the at least one word is sent indirectly to the authentication device via the server SER.
[0109] In S27, the authentication device records the at least one word M. In S28, software block B_AUT2 of the authentication device AUT checks whether the spoken word M corresponds to a pre-created voiceprint EV. Specifically, software block B_AUT2 checks the word M against at least one physical characteristic of the user UT (e.g., the tone, speed, or even accent of the user UT when speaking the word M). If there is no match between the word M and the voiceprint EV ( Figure 5B If the branch "No" is selected, then iteration steps S25 to S28 are performed a predetermined number of times. According to another example, the authentication device AUT sends a voice message or text message to the user UT's terminal TER, instructing them to recreate the voiceprint. On the other hand, if the word M does match the voiceprint EV (…), then… Figure 5B If the branch "is 1" in the code, and if the service requested by user UT does not require third-level authentication AUT3, then in S29a, the authentication device AUT sends a voice message or text message AUT_OK to the terminal TER to confirm to the user that strong authentication for the requested service has been successful. According to another embodiment, the message AUT_OK can be sent directly by the server SER after it has been received from the authentication device AUT. In S30a, user UT then accesses the requested service via its terminal TER. The message AUT_OK is not necessarily sent; once the match between the at least one word and the voiceprint EV is confirmed in S28, user UT then directly accesses the requested service via its terminal TER.
[0110] If the word M does indeed match the voiceprint EV, and the requested service requires Level 3 (very strong) authentication (AUT3). Figure 5BIf the branch "is 2" in S29b, then in S29b, the authentication device AUT sends an additional authentication request to the terminal TER. This additional authentication request is a password request REQ_MP requesting a password (e.g., the aforementioned security code CC, typically a PIN code), which is associated with the user UT's user identification card CIA and is pre-recorded in the server SER, the authentication device AUT, or even a database accessible to both the server SER and the authentication device AUT, in association with the user UT's MSISDN or IMSI number and the user's voiceprint EV. According to another embodiment, the request REQ_MP can be sent directly by the server SER after it has been received from the authentication device AUT. For example, such a request is a voice message of the type: "Please say / type your security code CC." This message is then sent to the terminal TER via the network RCM through the authentication device AUT's communication interface ICA_A. According to another example, such a request is a text message of the type: "Please call back the server SER and say your security code CC," or "The server SER will call you back in 1 minute to ask you to say your security code CC," or "Please type your security code CC."
[0111] In S30b, when a request REQ_MP is received in the terminal TER, the user UT speaks or types a security code CC according to the implemented embodiment. The security code CC is directly transmitted to the authentication device AUT in the response REP_MP to the request REQ_MP. If the security code CC is spoken, it is transmitted to the authentication device via the terminal TER's communication interface ICA_T; or if the security code CC is typed (SMS, USSD, or DTMF code), it is transmitted to the authentication device via the terminal TER's communication interface ICI_T. Alternatively, if the user UT has already called back the server SER or has been called back by the server SER to speak or type the security code CC, the security code CC is sent indirectly via the server SER.
[0112] In S31, the software block B_AUT3 of the authentication device AUT checks whether the spoken or entered security code corresponds to the pre-recorded security code CC. If the two codes do not match ( Figure 5B If the branch "No" is selected, then for example, iterating step S29b and subsequent steps a certain number of iterations (e.g., limited to 2). According to another example, the authentication device AUT sends a voice or text message to the user UT's terminal TER, informing them that access to the requested service has been denied. On the other hand, if the two confidential codes do match ( Figure 5BIf the branch "Yes" is selected in S32, then in S32, the authentication device AUT sends a voice message or text message AUT_OK to the terminal TER to confirm that the very strong authentication for the requested service has been successful. According to another embodiment, the message AUT_OK can be sent directly by the server SER after it has been received from the authentication device AUT. In S33, the user UT then accesses the requested service via its terminal TER. The message AUT_OK may not necessarily be sent in S32; once the match between the security codes is confirmed in S31, the user UT will then directly access the requested service via its terminal TER.
Claims
1. A method for authenticating a user of a service on a communication terminal (TER), the method comprising the following operations performed on the communication terminal after establishing audio communication with a server: - A request to access the server is sent to the server via the audio communication (S23), the request being in the form of voice or text, wherein, The voice request is initiated by the user dialing a phone number assigned to the server on the keypad of the communication terminal through the communication interface of the communication terminal. The text request is initiated by the user typing an SMS or USSD code specific to the server on the keypad of the communication terminal through another communication interface of the communication terminal. The request includes a first identifier associated with the communication terminal and a second identifier associated with the service requested on the server. - In response to a request from the server that requires Level 2 authentication, an authentication request is received from the authentication device via the audio communication (S25) requesting the user to speak at least one word, wherein the authentication device is logically separate from the server and communicates with the server through a communication interface. - At least one word spoken by the user will be transmitted to the authentication device via the audio communication (S26). - In response to at least one physical characteristic, including tone, speed, or accent, of the spoken at least one word, corresponding to the user's pre-recorded voiceprint (EV) associated with the identifier of the communication terminal, and the service requested in the server requires third-level authentication, a PIN-based additional authentication request for additional authentication of the user is received from the authentication device (S29b).
2. The method as described in claim 1, wherein, The second identifier associated with the requested service belongs to the group that includes: dual-tone multi-frequency codes, USSD codes, and SMS messages.
3. A communication terminal for implementing user authentication access to a service, the terminal including a processor (UTR_T) configured to perform the following operations after establishing audio communication with a server: - A request to access the server is sent to the server via the audio communication, the request being in voice or text form, wherein, The voice request is initiated by the user dialing a phone number assigned to the server on the keypad of the communication terminal through the communication terminal's communication interface. The text request is initiated by the user typing an SMS or USSD code specific to the server on the keypad of the communication terminal through another communication interface of the communication terminal. The request includes a first identifier associated with the communication terminal and a second identifier associated with the service requested on the server. - In response to a service request in the server requiring Level 2 authentication, an authentication request is received from an authentication device via the audio communication, requiring the user to speak at least one word, wherein the authentication device is logically separate from the server and communicates with the server through a communication interface. - At least one word spoken by the user will be transmitted to the device via the audio communication. - In response to at least one physical characteristic, including tone, speed, or accent, of the spoken at least one word, corresponding to the user's voiceprint pre-recorded in association with the identifier of the communication terminal, and the service requested in the server requires Level 3 authentication, the device receives an additional authentication request based on a PIN code for further authentication of the user.
4. An apparatus for authenticating users accessing services via a communication terminal, the apparatus comprising a processor (UTR_A) configured to perform the following operations: - Receives, via audio communication, a first identifier associated with the communication terminal and a second identifier associated with the requested service on the server, the request being in voice or text form, from a server that has already received a server access request sent by the communication terminal. The voice request is initiated by the user dialing a phone number assigned to the server on the keypad of the communication terminal through the communication interface of the terminal. The text request is initiated by the user typing an SMS or USSD code specific to the server on the keypad of the communication terminal through another communication interface of the terminal. The device is logically separate from the server and communicates with the server through the communication interface. - In response to the service request in the server requiring Level 2 authentication, an authentication request is sent via the audio communication to the communication terminal associated with the first identifier, requiring the user to pronounce at least one word. - Receive spoken words from the terminal via the aforementioned audio communication. - In response to at least one physical characteristic, including tone, speed, or accent, of the uttered at least one word, corresponding to the user uttering at least one first word, a pre-recorded voiceprint associated with an identifier of the communication terminal, and the service requested in the server requires Level 3 authentication, a PIN-based additional authentication request is sent to the terminal to perform additional authentication on the user.
5. An authentication system, characterized in that, The authentication system includes: - The communication terminal as described in claim 3, - The device as described in claim 4.
6. A computer program product comprising program code instructions, which, when executed on a computer, are used to implement the method as described in any one of claims 1 to 2.
7. A computer-readable information medium comprising a computer program including program code instructions that, when executed on a communication terminal (TER), implement a method for authenticating a user of a service on the communication terminal, the method comprising the following operations performed on the communication terminal after establishing audio communication with a server: - A request to access the server is sent to the server via the audio communication (S23), the request being in the form of voice or text, wherein, The voice request is initiated by the user dialing a phone number assigned to the server on the keypad of the communication terminal through the communication interface of the communication terminal. The text request is initiated by the user typing an SMS or USSD code specific to the server on the keypad of the communication terminal through another communication interface of the communication terminal. The request includes a first identifier associated with the communication terminal and a second identifier associated with the service requested on the server. - In response to a request from the server that requires Level 2 authentication, an authentication request is received from the authentication device via the audio communication (S25) requesting the user to speak at least one word, wherein the authentication device is logically separate from the server and communicates with the server through a communication interface. - At least one word spoken by the user will be transmitted to the authentication device via the audio communication (S26). - In response to at least one physical characteristic, including tone, speed, or accent, of the spoken at least one word, corresponding to the user's pre-recorded voiceprint (EV) associated with the identifier of the communication terminal, and the service requested in the server requires third-level authentication, a PIN-based additional authentication request for additional authentication of the user is received from the authentication device (S29b).
Citation Information
Patent Citations
Safe handling device and method for telephone bank system
CN102393943A
User authentication method and system
CN105991280A
Dialog-based voiceprint security for business transactions
US20030037004A1