METHOD FOR AUTHENTICATING A USER AGAINST A SERVICE PROVIDER AND AUTHENTICATION SYSTEM
Patent Information
- Application Number
- DE502018016320
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-07-25
- Filing Date
- 2018-07-20
- Publication Date
- 2026-01-15
- Estimated Expiration
- 2038-07-20
Description
Technical field
[0001] The present invention relates to a method for authenticating a user to a service provider by means of an electronic identification element of the user and an authentication device. Description of the state of the art
[0002] Methods for authentication, i.e., for verifying the authenticity of a user or communication partner by means of an electronic identification element, as well as suitable authentication systems or services for carrying out such methods, are known.
[0003] A well-known example of an electronic identification element is the electronic identity card issued by the Federal Republic of Germany, which contains an RFID chip that enables various forms of electronic authentication. The user of this card can provide the same proof of identity online using an application called the "AusweisApp" (ID card app) as the physical ID card does when viewed offline. This allows the user to clearly and authentically identify themselves to third parties in electronic business and legal transactions. A service provider (private or public) that offers its customers the option of authentication using the electronic identity card requires an authorization certificate issued by the issuing authority for authorization certificates.In addition, it requires an electronic authentication service, a so-called eID server, which it can either operate itself or rent from external service providers.
[0004] DE 10 2010 028133 A1 concerns a method for reading attributes from an ID token assigned to a user.
[0005] US Regulation 2017 / 094513 A1 describes an identity management procedure in which the user can identify himself to service providers.
[0006] To use the electronic ID card function, the user typically needs a card reader connected to their desktop PC (user device). However, communication between the ID card and a suitable "smartphone" (mobile phone with extensive computer functionalities) is also possible via near-field communication (NFC). Summary of the invention
[0007] Based on this, the invention proposes a method for operating an electronic authentication service for authenticating a user to a service provider by means of an electronic identification element with the features of claim 1 and a corresponding authentication device with the features of claim 5.
[0008] The invention's key feature lies in establishing a secure connection between a stationary user device and a service provider using ID card authentication, instead of a card reader which is not always available. This allows a user to identify and authenticate themselves to a service provider within an application running on a traditional stationary device, such as a desktop PC, without needing a (compatible) card reader. Instead, the official document is read using an NFC-enabled mobile device (smartphone, tablet, etc.) that has a contact number (phone number).According to the invention, the electronic identification element does not need to be read directly by the mobile device, but the mobile device serves as a communication link for a secure connection to be established directly between the identification element or its chip and the authentication service or authentication server.
[0009] The actual (and in itself known) authentication process thus takes place between the identification element and the electronic authentication service of the service provider via a communication channel provided by the mobile device, while the subsequent authenticated transaction connection is established between the server of the service provider and the stationary device of the user.
[0010] To initiate the authentication process, the user provides the service provider with the phone number / contact number of the mobile device in question (mobile number). A secret and an identifier associated with the process are then generated on the service provider's server. These are transmitted to the provided mobile number along with a hyperlink. For example, the secret and / or the identifier can be integrated into the hyperlink.
[0011] The transmitted hyperlink is designed to establish a secure connection with an electronic authentication service, enabling the user of the receiving mobile device to establish such a secure connection between their mobile device and the authentication service using the received hyperlink. Furthermore, the user also transmits the received secret and identifier to the electronic authentication service. The latter occurs automatically if the secret and identifier are integrated into the hyperlink as described above.
[0012] To perform the familiar authentication process (e.g., two-factor authentication) with the electronic authentication service, the user simply needs to establish a connection between their mobile device and the electronic ID element, for example, via near-field communication (NFC), and confirm the secret. After successful authentication, the electronic authentication service sends an authentication confirmation along with the identifier to the service provider's server. Based on this authentication confirmation and identifier, a personalized access credential for the user can then be opened to utilize the service provider's services.
[0013] The present description also covers a computer program with program code suitable for executing a method according to the invention when the computer program runs on a server of a service provider or a server of an electronic authentication service. Both the computer program itself and the program stored on a computer-readable medium (computer program product) are claimed.
[0014] Further advantages and embodiments of the invention will become apparent from the dependent claims, the description and the accompanying drawing.
[0015] It is understood that the features mentioned above and those to be explained below can be used not only in the combinations specified, but also in other combinations or on their own, without leaving the scope of the present invention.
[0016] The invention is schematically illustrated in the drawing using an exemplary embodiment and is described in detail below with reference to the drawing. Brief description of the drawing
[0017] Figure 1 Figure 1 shows, in a highly schematic block representation, a system according to the invention for authenticating a user to a service provider by means of an electronic identification element of the user. Figure 2 shows a highly schematic overview of the process flow of a method according to the invention. Detailed description
[0018] Identical and similar features depicted in the individual figures are designated with the same reference symbols.
[0019] Figure 1Figure 1 shows a highly schematic block diagram of an authentication device 100 according to the invention. The authentication device 100 serves to authenticate a user to a service provider by means of an electronic identification element (PA) of the user.
[0020] The authentication device 100 comprises, on the user side, an electronic identification element (PA), a stationary user terminal 120, and a mobile user terminal 122, which can be paired with the electronic identification element PA. This pairing is achieved, as in the illustrated embodiment, by means of so-called near-field communication (NFC). The electronic identification element PA is, for example, an electronic identity card with an RFID chip, such as those issued by the authorities of the Federal Republic of Germany.
[0021] For the purposes of the present invention, the term "electronic identification element" refers to any electronic identification document in which functions for electronic authentication vis-à-vis third parties, for example on the internet, are implemented. A stationary user device is, for example, a desktop computer or PC, including laptop computers, and a mobile user device is, for example, a mobile phone or a tablet.
[0022] On the provider side, the authentication device 100 according to the invention comprises a service provider server 130 and an authentication server 140.
[0023] Service providers who offer their customers (users) the option of authentication via an electronic identity card must first authenticate themselves to the identity card using an authorization certificate and prove their authorization to access specific data fields of the identity card. To communicate with the identity card, the service provider requires an electronic authentication service (also called an "eID server") that handles the communication with the identity card. The service provider can either operate this authentication server themselves or rent it from external service providers.
[0024] An "authentication server" within the meaning of the present invention is therefore a device in which an electronic authentication service is implemented for communication with an electronic identification element on the one hand and a service provider operating or renting the authentication server on the other.
[0025] The individual components of the authentication device according to the invention communicate, for example, via a communication network N such as the Internet, or via a mobile communication connection T, or via the aforementioned near field communication NFC or the like.
[0026] In the illustrated embodiment, a connection is established between the stationary user terminal device 120 and the server 130 of the service provider, e.g. via the Internet N (S10, cf. Figure 2 This could include, for example, a user visiting a shopping website, a government website, or similar.
[0027] To initiate an authentication process according to the present invention, the user transmits a contact number of his mobile user device 122 (such as in particular the mobile phone number) to the server 130 of the service provider DL (S20) via this connection N.
[0028] Subsequently, a secret S and an identifier ID (S30) are generated on server 130 of the service provider DL and transmitted to the mobile user device 122 along with a hyperlink URL (S40). This transmission preferably occurs via a mobile network connection T, for example, using SMS (Short Message Service). The secret S allows the user to later "merge" the two sessions between their stationary device 120 and server 130 on the one hand, and between their mobile device 122 and the electronic authentication service eID on the authentication server 140 on the other, for example, by comparing and / or confirming the displayed secrets, as described in more detail below.
[0029] In step S50, the user establishes a connection between their mobile device 122 and the electronic authentication service eID on the authentication server 140 using the transmitted URL. The user also transmits the secret S and the identifier ID, sent to them by the service provider, to the electronic authentication service. The secret and the identifier can, for example, be integrated into the URL as mentioned above, resulting in "automatic" transmission to the electronic authentication service. Furthermore, the user ensures that a functional connection exists between their electronic identification element PA and the mobile device 122.
[0030] The electronic authentication service eID (eID service) logs on to the mobile device at step S51 and the so-called "ID card app", i.e. the software solution on the mobile device 122 required to carry out the authentication process as already mentioned above, is started and a secure connection is established between the ID card element PA and the authentication service eID.
[0031] Optionally, in step S52, the secret S is explicitly displayed to the user on their mobile device 122 so that they can confirm it as correct and identical to the secret optionally displayed on their stationary device 120 in step S41. Confirmation of the secret can be done as a separate entry or implicitly by entering the PIN (see step S55 below). Optionally or additionally, confirmation of the secret can also be requested from the stationary device 120 (step S42).
[0032] In step S55, the familiar process of the online ID function is carried out, including authorization certificate, PIN entry, cryptography, data retrieval, and at the beginning, a display of the secret (which in this context can then be implicitly confirmed by PIN entry, for example).
[0033] After successful authentication, the eID service generates an authentication confirmation and sends it, along with the identifier, to the service provider's server 130 (S60). Upon receiving the authentication confirmation and identifier, server 130 opens personalized access for the stationary terminal device 120 (S70), meaning the user's login to the service provider's website is successfully completed. "Opening" refers to any known method of providing access to an electronic service offered via an electronic network, particularly the internet, as commonly known as "logging in." This can include, for example, assigning a unique identifier to the user. Communication between the service provider's server 130 and the authentication server 140 can, for example,via a (secure) internet connection N or via a private / proprietary network, such as a LAN (Local Area Network).
[0034] In the optional variant, which requires confirmation of the secret displayed on the stationary device (step S41), the confirmation by the user can take place before or after the transmission of the authentication confirmation in step S60 (dashed arrows S42), but it is a prerequisite for successful login at S70 in any case.
[0035] The desired transaction between user and service provider can then take place (S80).
[0036] The invention thus enables user identification from a stationary terminal / desktop PC using a mobile terminal, so that user identification is also possible on stationary terminals that do not have an ID card reading device.
Claims
1. Method for operating an electronic authentication service (eID) for authenticating a user with respect to a service provider (DL) by means of an electronic ID element (PA) of the user, having the following steps of: receiving (S50) a connection request from a mobile user terminal (122) of the user via a hyperlink (URL), wherein the hyperlink (URL) contains information regarding a secret (S) generated by a server (130) of the service provider (DL) and an identifier (ID) assigned to the authentication operation, which were generated by a service provider (DL), approving (S51) the connection request and transmitting the secret (S) to the mobile user terminal (122), carrying out (S55) the authentication operation using a secure channel between the electronic ID element and the authentication service, including receiving confirmation of the secret (S) by the user, transmitting (S60), after successful authentication, an authentication confirmation together with the identifier (ID) to the server (130) of the service provider (DL) for opening a personalized access for a stationary user terminal (120) after confirmation of the secret (S).
2. Method according to Claim 1, wherein the electronic authentication service (eID) requires a separate confirmation of the match of the secret (S) (S52).
3. Method according to Claim 1 or 2, wherein the server (130) of the service provider also transmits the secret to the stationary user terminal (S41).
4. Method according to Claim 3, wherein the user compares a display of the secrets on the stationary and mobile user terminals (120, 122) and, in the event of a match, confirms the secrets via the stationary user terminal (120) and / or the mobile user terminal (122) (steps S42 or S52).
5. Authentication device, comprising an authentication server (140) for authenticating a user with respect to a service provider (DL) by means of an electronic ID element (PA) of the user, and a server (130) of the service provider (DL), wherein the server (130) of the service provider is configured to open a personalized access for a stationary user terminal (120) after confirmation of a secret (S) generated by the server (130) of the service provider (DL), and wherein the authentication server (140) is configured as an electronic authentication service (eID) and designed to receive a connection request from a mobile user terminal (122) of the user to be authenticated via a hyperlink (URL), wherein the hyperlink (URL) contains information regarding a secret (S) and an identifier (ID) assigned to the authentication operation, which were generated by a service provider (DL), approve the connection request and transmit the secret to the mobile user terminal (122), carry out the authentication operation including receiving the confirmation of the secret (S) by the user, and after successful authentication, send an authentication confirmation together with the identifier (ID) to the server (130) of the service provider for opening a personalized access for a stationary user terminal (120) after confirmation of the secret (S).
6. Computer program having program code means for carrying out all steps of a method according to any one of Claims 1 to 4 when the computer program is executed in an authentication device according to Claim 5.
7. Computer program according to Claim 6, which is stored on a computer-readable data carrier.