Strong authentication of a user of a communication device
Patent Information
- Application Number
- DE602021045955
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-03-27
- Filing Date
- 2021-03-05
- Publication Date
- 2026-01-07
- Estimated Expiration
- 2041-03-05
AI Technical Summary
Basic communication terminals lack internet access capabilities, limiting their use of high-value services requiring strong user authentication, such as banking, due to reliance on mobile phone numbers for authentication, which is inadequate for security.
Implementing a voice biometrics mechanism coupled with communication terminal identifiers, using DTMF, USSD, or SMS channels, to authenticate users by recognizing voiceprints and additional password requests, enhancing security through multiple authentication layers.
This method allows secure access to sensitive services on both smartphones and basic terminals by leveraging voice biometrics and additional authentication methods, significantly reducing fraud and ensuring reliable access.
Description
Scope of the invention
[0001] The present invention relates generally to the field of strong authentication of a user of a communication terminal.
[0002] The present invention applies more particularly to the authentication of a user who requires access to a service by means of any type of communication terminal, including communication terminals not equipped with Internet access capabilities. Previous art
[0003] Currently, despite the arrival of smartphones on the market for over a decade, basic communication terminals, also known as feature phones or basic phones, remain popular. Since these basic communication terminals lack internet access, the use of high-value services is quite limited because they require strong user authentication. A user requesting access to a service via a basic communication terminal is generally authenticated using their mobile phone number, i.e., their MSISDN (Mobile Station International Subscriber Directory Number). US documents 2013 / 080166, US 2019 / 259390, and GB 2 547 885 describe how to implement user authentication for a terminal using the user's voiceprint. Object and summary of the invention
[0004] One of the aims of the invention is to overcome the drawbacks of the aforementioned prior art by offering users of basic or advanced communication terminals access to a wider range of services, particularly those requiring strong user authentication, such as banking services, in a way that is easy to implement across all such terminals. The invention is defined in the independent claims.
[0005] To this end, an object of the present invention relates to a method for authenticating a user of a service on a communication terminal, comprising the following, at the level of the communication terminal: send a request to a server to access said server, said request including a first identifier associated with the communication terminal and a second identifier associated with a service required in said server, receive from an authentication device an authentication request asking the user to pronounce at least one word, communicate said at least one word pronounced by the user to the device, said at least one word pronounced corresponding to a voiceprint of the user previously recorded in association with the identifier of said communication terminal, access the service or receive from the device a further authentication request from the user.
[0006] The sequence of operations described above thus allows the user of a communication terminal, whether it be a smartphone or one without internet access capabilities like a basic terminal, to access a service handling sensitive user data (such as the user's banking or medical data) in a highly secure manner, thanks to: recognition of the communication terminal identifier, such as the phone number, which is coupled with a voice biometrics mechanism.
[0007] According to a particular embodiment, the additional authentication request received is a password request, to which, in response, the terminal communicates the required password in text or voice form.
[0008] Receiving such a password request further improves the security of access to the service required by the communication terminal by providing an additional layer of authentication for the user.
[0009] According to another particular embodiment, the second identifier associated with the required service belongs to the group comprising a two-tone Multi-Frequency Tone code, a ussd code (“Unstructured Supplementary Service Data”), an sms message (“Short Message Service”).
[0010] By using a communication channel such as DTMF (dual-tone multi-frequency), USSD, or SMS, which has the advantage of being widely available on most communication devices on the market, and particularly on devices without internet access capabilities, it is possible to secure this type of access by providing the user with strong, or even very strong, authentication. This significantly reduces the fraud rate associated with this type of access.
[0011] According to another particular embodiment, the at least one spoken word that is communicated to the authentication device is identified according to at least one physical characteristic of the user.
[0012] The advantage of using at least one physical characteristic of the user to identify the at least one word spoken by that user lies in the fact that this type of characteristic is impossible to reproduce by a malicious individual who might wish to fraudulently access the service requested by the user. The reliability of access to services via basic terminals is thus strengthened. According to another particular embodiment, the at least one physical characteristic belongs to the group including intonation, cadence, and accent with which the user pronounces the word.
[0013] The various modes or embodiments mentioned above can be added independently or in combination with each other to the authentication process defined above.
[0014] The invention also relates to a communication terminal for implementing authenticated user access to a service, said terminal comprising a processor which is configured to implement the following: send a server a request to access the server, the request including a first identifier associated with the communication terminal and a second identifier associated with the service requested in the server, receive from an authentication device an authentication request asking the user to pronounce at least one word, communicate said at least one word pronounced by the user to the device, said at least one word pronounced corresponding to a voiceprint of the user previously recorded in association with the identifier of said communication terminal, access the service or receive from the device a further authentication request from the user.
[0015] The invention also relates to a device for authenticating a user of a service accessed via a communication terminal, the device comprising a processor which is configured to implement the following: receive from a server that has received an access request to said server sent by the communication terminal, a first identifier associated with the communication terminal and a second identifier associated with the service required in the server, send to the communication terminal associated with the first identifier an authentication request asking the user to pronounce at least one word, receive from the terminal the spoken word, said at least one spoken word corresponding to a voiceprint of the user previously recorded in association with the first identifier, authorize the terminal's access to the service or send to the terminal a further authentication request from the user.
[0016] The invention also relates to an authentication system comprising the aforementioned terminal and authentication device.
[0017] The invention further relates to a computer program comprising instructions for implementing the authentication method according to the invention, according to any one of the particular embodiments described above, when said program is executed by a processor.
[0018] Such instructions can be stored permanently in a non-transient memory medium of the communication terminal implementing the aforementioned authentication process.
[0019] This program can use any programming language, and be in the form of source code, object code, or code somewhere between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0020] The invention also relates to a recording medium or information medium readable by a computer, and comprising instructions for a computer program as mentioned above.
[0021] The recording medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a USB flash drive or a hard drive.
[0022] On the other hand, the recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. The program according to the invention can, in particular, be uploaded to a network such as the Internet.
[0023] Alternatively, the recording medium may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the aforementioned authentication process. Brief description of the drawings
[0024] Other features and advantages will become apparent upon reading particular embodiments of the invention, given by way of illustrative and non-limiting examples, and the accompanying drawings, among which: [ Fig. 1 ] there figure 1 represents an authentication system according to an embodiment of the invention, [ Fig. 2 ] there figure 2 represents a service delivery server in a particular embodiment of the invention, [ Fig. 3 ] there figure 3 represents an authentication device in a particular embodiment of the invention, [ Fig. 4 ] there figure 4represents a communication terminal in a particular embodiment of the invention, [ Fig. 5A ] there figure 5A represents the main actions implemented in the voiceprint creation process that precedes authentication, according to a particular embodiment of the invention, [ Fig. 5B ] there figure 5B represents the main actions implemented in the authentication process, according to a particular embodiment of the invention. Detailed description of an embodiment of the invention Architectural environment
[0025] There figure 1 represents an environment in which the authentication process according to the invention is implemented.
[0026] On the figure 1 is represented an authentication system comprising: a TER communication terminal of the smartphone type or of the basic type or of the "feature phone" type, i.e. not equipped with Internet access capabilities, a SER service provision server, an AUT authentication device of a UT user of the TER terminal when accessing a service offered by the SER server.
[0027] Although the AUT authentication device is separate from the SER server on the figure 1 The AUT authentication device could be integrated into the SER server to form a single entity.
[0028] The SER server and the AUT authentication device communicate with each other via any type of communication network (not shown). This could be, for example, an IP network (short for "Internet Protocol"), an x-DSL network, fiber optic, or even 3G, 4G, 5G, etc. If the SER server and the AUT authentication device are in close proximity to each other, they can also communicate via a wireless local area network, particularly a Wi-Fi or PLC (Power Line Communication) network.
[0029] The TER communication terminal is configured for: communicate vocally with the SER server in order to record in the SER server and / or in the AUT authentication device a voiceprint EV of the user UT in association with an ID identifier of the communication terminal TER, communicate vocally or textually: with the SER server in order to request access to a service offered in the SER server, with the AUT authentication device in order to authenticate the user UT when accessing the service offered.
[0030] Such communication is implemented using an RCM mobile communication network, typically a mobile communication network of an operator, of the 2G, 3G, 4G, etc. type.
[0031] The SER server is configured to provide a range of services, from SERV 1 to SERV N. For example, it could be a mobile operator's platform offering a suite of services such as access to an archive of the user's (UT) communication bills, access to bill payment, access to a subscriber community, access to checking communication unit balances, etc. As another, non-exhaustive example, the SER server could be a banking server offering a suite of services such as access to the user's (UT) bank accounts, a chargeback service, a direct debit service, etc.
[0032] Depending on the sensitivity of the data handled when accessing these services, some services can be made accessible through simple UT user authentication, while other services can be made accessible through strong UT user authentication, and still other services can be made accessible through very strong UT user authentication.
[0033] The SER server is further configured to record the EV voiceprint of the user UT in the SER server and / or in the AUT authentication device, in association with an ID identifier of the communication terminal TER, following a learning of the voice of the user UT communicated via the RCM communication network.
[0034] The AUT authentication device is configured to, upon receiving a service access request from the TER terminal via the RCM communication network, implement, depending on the service requested, either AUT 1 (first level, simple), AUT 2 (second level, strong), or AUT 3 (third level, very strong) authentication. The AUT authentication device is configured to communicate with the TER terminal via voice or text communication over the RCM mobile communication network. Description of one implementation of the SER server
[0035] There figure 2 This presents the simplified structure of the SER server, which is adapted to provide services to the UT user via the RCM mobile communication network within the authentication process described below. This is, for example, an interactive voice server.
[0036] Such a server includes: a plurality of software service blocks B_SERV 1 to B_SERV N, a CEV software module for voiceprint creation, an audio communication interface ICA_S which is adapted to communicate vocally, via the RCM mobile communication network, with the TER terminal of the user UT, a communication interface IC1_S which is adapted to operate according to certain protocols, such as SMS and / or DTMF and / or ussd, via the RCM network, and communicate with the TER terminal of the user UT, a communication interface IC2_S which is adapted to communicate with the authentication device AUT, according to, for example, the IP protocol (English abbreviation for "Internet Protocol"), x-DSL, fiber, 3G, 4G, 5G, etc., WiFi, PLC, or others.
[0037] According to a particular embodiment of the invention, the actions performed by the SER server to provide services and create voiceprints are implemented by instructions in a computer program PG_S. For this purpose, the SER server has the classic architecture of a computer and includes, in particular, a MEM_S memory, a UTR_S processing unit, equipped, for example, with a PROC_S processor, and controlled by the PG_S computer program stored in MEM_S memory. The PG_S computer program includes instructions to implement the service provision and voiceprint creation actions carried out within the framework of the authentication process described below, when the program is executed by the PROC_S processor, according to any one of the particular embodiments of the invention.
[0038] At initialization, the code instructions of the PG_S computer program are, for example, loaded into RAM (not shown) before being executed by the PROC_S processor. The PROC_S processor of the UTR_S processing unit implements, in particular, the actions of the service provision and voiceprint creation process, according to the instructions of the PG_S computer program. Description of an embodiment of the AUT authentication device
[0039] There figure 3 presents the simplified structure of the AUT authentication device which is adapted to authenticate the UT user, via the RCM mobile communication network, when the UT user wishes to access, via their TER terminal, a service offered by the SER server.
[0040] Such an AUT authentication device includes: three authentication software blocks B_AUT 1 , B_AUT 2 , B_AUT 3, an audio communication interface ICA_A which is adapted to communicate voicewise, via the RCM mobile communication network, with the TER terminal of the user UT, a communication interface IC1_A which is adapted to operate according to certain protocols, such as for example SMS and / or DTMF and / or ussd, via the RCM network, and communicate with the TER terminal of the user UT, a communication interface IC2_A which is adapted to communicate with the SER server, according to for example the IP, x-DSL, fiber, 3G, 4G, 5G, etc, WiFi, PLC, or other protocols.
[0041] According to a particular embodiment of the invention, the actions performed by the authentication device AUT to authenticate the user UT are implemented by instructions in a computer program PG_A. For this purpose, the authentication device AUT has the classic architecture of a computer and includes, in particular, a memory MEM_A, a processing unit UTR_A, equipped, for example, with a processor PROC_A, and controlled by the computer program PG_A stored in memory MEM_A. The computer program PG_A includes instructions to implement the authentication process described below, when the program is executed by the processor PROC_A, according to any one of the particular embodiments of the invention.
[0042] At initialization, the code instructions of the computer program PG_A are, for example, loaded into RAM (not shown) before being executed by the PROC_A processor. The PROC_A processor of the UTR_A processing unit notably implements the actions of the authentication process, according to the instructions of the computer program PG_A. Description of an embodiment of the TER communication terminal
[0043] There figure 4 presents the simplified structure of the TER communication terminal adapted to access a service offered in the SER server, subject to authentication of the UT user of this terminal.
[0044] As already mentioned above, the TER communication terminal is a smartphone or a basic terminal or feature phone. In the case where the TER terminal is a basic terminal, it does not have the capacity to access an Internet or Intranet network.
[0045] The TER communication terminal includes: an EC display screen, an HP speaker, a MIC microphone, a CL keyboard, an MS security module, such as for example a CIA subscriber identification card of the SIM or USIM type which is associated with a CC PIN, an ICA_T audio communication interface which is adapted to communicate voicewise, via the RCM mobile communication network, with the SER server or the AUT authentication device, an IC1_T communication interface which is adapted to operate according to certain protocols, such as for example SMS and / or DTMF (English abbreviation for "dual-tone multi-frequency") and / or ussd, via the RCM network, and communicate with the SER server and the AUT authentication device.
[0046] According to a particular embodiment of the invention, the actions performed to access a service offered in the SER server and to enable the authentication of the user UT are implemented by instructions in a computer program PG_T. For this purpose, the TER terminal has the classic architecture of a computer and includes, in particular, a MEM_T memory, a UTR_T processing unit, equipped, for example, with a PROC_T processor, and controlled by the PG_T computer program stored in MEM_T memory. The PG_T computer program includes instructions for implementing voiceprint creation, access to the service, and authentication of the user UT, which will be described below, when the program is executed by the PROC_T processor, according to any one of the particular embodiments of the invention.
[0047] At initialization, the code instructions of the computer program PG_T are, for example, loaded into RAM (not shown) before being executed by the PROC_T processor. The PROC_T processor of the UTR_T processing unit notably implements voiceprint creation, service access, and user authentication for the UT, according to the instructions of the computer program PG_T. Description of one embodiment of the authentication process
[0048] With reference to Figures 5A And 5B We now describe the execution of an authentication process according to an embodiment of the invention, implemented in the authentication system of the figure 1 .
[0049] Such an authentication process requires the prior creation of an EV voiceprint of the UT user, which is described figure 5A .
[0050] In S10, a COM connection is established between the TER terminal and the SER server. This connection can be initiated by the SER server via its ICA_S communication interface, provided that the SER server has prior knowledge of the MSISDN number associated with the UT user's CIA subscriber identification card. The MSISDN number may have been previously stored in memory, either on the SER server, the AUT authentication device, or another device accessible by both the SER server and the AUT authentication device. Alternatively, it could be the IMSI number (International Mobile Subscriber Identity), which is the UT user's "private" identifier contained on the CIA subscriber identification card. Such a communication is voice-based. The MSISDN number or the IMSI number is an ID identifier for the TER communication terminal.
[0051] Alternatively, the S10 communication can be initiated by the TER terminal. This communication can be voice-based, with the UT user dialing a phone number assigned to the SER server on the TER terminal's CL keypad. The communication is initiated by the TER terminal's ICA_T communication interface via the RCM network. Another alternative is for the UT user to initiate communication by typing an SMS or USSD code specific to the SER server on the TER terminal's CL keypad. In this case, the communication is initiated by the TER terminal's IC1_T communication interface via the RCM network and sent to the SER server. Upon receipt of the communication from the TER terminal, and provided the SER server has prior knowledge of the MSISDN or IMSI number associated with the UT user's CIA subscriber identification card, the UT user is authenticated by the SER server.
[0052] In S11, the SER server then sends a voiceprint creation request (REQ.EV) to the user UT via the RCM network. If the communication established in S10 is a voice call, the REQ.EV request is of the voice type and is sent to the terminal TER via the ICA_S communication interface over the RCM network. For example, it might look something like this: Please record your voiceprint. To begin, please say your first and last name. In the event that the S10 communication is established via DTMF code, SMS, or USSD, the SER server responds by making a telephone call to the TER terminal via the RCM network, using the ICA_S communication interface. Upon the TER terminal's answer, the SER server then sends the aforementioned voice-type REQ.EV request. Alternatively, upon the TER terminal's answer, the SER server verbally requests the user UT: To register your voiceprint, type"1". The user UT then types "1" on the CL keypad of their terminal TER, and the SER server then sends the aforementioned voice-type REQ. EV request. According to yet another non-limiting embodiment, if the S10 communication is established using DTMF code, SMS, or USSD, the SER server sends a response to the terminal TER, via its IC1_S communication interface and the RCM network, via a USSD or SMS message inviting the user UT either to contact the SER server by telephone to create their voiceprint, or to enter a specific code to directly access an interactive voiceprint creation service on the SER server, which will then generate the aforementioned voice-type REQ. EV request.
[0053] In response to the REQ. EV request, the user UT pronounces the required phrase PHR, which is sent in S12 to the SER server via the ICA_T communication interface over the RCM network. Upon receiving this phrase, the SER server's CEV voiceprint creation module analyzes the spoken phrase in S13 and creates a voiceprint EV in S14 based on at least one physical characteristic of the user UT. This at least one physical characteristic belongs to the group including intonation, cadence, and accent with which the user UT pronounces the phrase PHR. In S15, the SER server analyzes the voiceprint. If the voiceprint was not created correctly, steps S11 to S15 are iterated at least once, with the SER server then asking the user UT to pronounce another phrase, for example: " "The little duck is swimming in the river." In another example, the SER server can also ask the UT user a question, such as: What is your date of birth?If the EV voiceprint was created correctly, it is recorded in S16 on the SER server and / or on the AUT authentication device and / or in a database accessible by the SER server and the AUT authentication device. The EV voiceprint is recorded corresponding to the TER terminal ID, which is the MSISDN or IMSI number mentioned above in the proposed embodiment.
[0054] At the end of step S16, the SER server can send a confirmation message for the creation of the EV voiceprint to the UT user. The message can be voice, SMS, or USSD.
[0055] With reference to the figure 5B We now describe a method for authenticating a UT user that requires access to a service offered by the SER server.
[0056] In S20, the user UT sends a COM communication request to the SER using their TER terminal. This communication can be established via voice or by sending an SMS or USSD message to the SER, as explained above in S10. In S21, the SER identifies the user UT using the MSISDN or IMSI number contained in the S20 request. To identify the user UT, the SER accesses a database containing the user's identification information (name, surname, address, etc.) matched with the MSISDN or IMSI number. Alternatively, the SER sends a request to the AUT authentication device via its IC2_S communication interface; this request contains the user UT's MSISDN or IMSI number.The AUT authentication device activates the B_AUT 1 authentication brick which authenticates the UT user at a first level, using the received MSISDN or IMSI number and which sends a message to the SER server, via the IC2_A communication interface, indicating that the UT user has been successfully authenticated.
[0057] In S22, the voice server SER sends a REQ.SEL.SERVICE request to the terminal TER, selecting a service offered by the SER server. Such a request is, for example, a voice message of the type: "To access the SERV 1 service, say " 1 To access SERV 2, say "2", to access SERV 3, say "3" The message is then sent via the ICA_S communication interface of the SER server, over the RCM network. As another example, such a request is a text message of the type: "To access the SERV 1 service, type " 1 To access SERV 2, type "2"; to access SERV 3, type "3" "If it's an SMS message, or something like:" "To access SERV 1, type "#001#", to access SERV 2, type "#002#", to access SERV 3, type "#003#" "if it is a ussd message."
[0058] In S23, according to one embodiment, the user UT speaks into the microphone (MIC) of their terminal (TER) the code associated with the service they wish to access. According to another embodiment, the user UT types the code associated with the service they wish to access on the keypad (CL) of their terminal (TER), which triggers the sending of a service access request (REQ. ACC. SERVICE) to the server (SER) via the RCM network. The typed code can be of the DTMF, SMS, or USSD type. The REQ. ACC. SERVICE request contains the aforementioned MSISDN or IMSI number and the code associated with the service requested by the user UT, in the example "1", "2", or "3", or "#001#", "#002#", or "#003#".
[0059] Upon receiving the REQ. ACC. SERVICE request, in S24, the SER server forwards this request to the AUT authentication device. If the requested service requires first-level AUT authentication, the AUT authentication device, having already authenticated the user UT, sends a response to the SER server authorizing the user UT's access to the requested service. This step is standard and is therefore not described in the documentation. figure 5B In cases where the required service necessitates second-level (strong) AUT 2 authentication, in S25, the AUT authentication device sends a REQ_P authentication request to the TER terminal, consisting of the pronunciation of at least one word. This could be, for example, the name of the UT user previously communicated during the voiceprint creation phase illustrated in [reference]. figure 5Aor one of the phrases communicated by the UT user during this phase. In another embodiment, the REQ_P request can be sent directly by the SER server after being received by the latter from the AUT authentication device. Such a request is, for example, a voice message of the type: " Please say at least one word. The message is then sent by the ICA_A communication interface of the AUT authentication device, via the RCM network, to the TER terminal. In another example, such a request is a text message of the type: Please call the SER server again and say at least one word. or even The SER server will call you back in 1 minute to ask you to say at least one word.
[0060] In S26, upon receipt of the REQ_P request in the TER terminal, the user UT pronounces said at least one word M, said at least one word being transmitted to the authentication device AUT directly in response REP_P to the REQ_P request or indirectly via the SER server, if the user UT has recalled the SER server or has been recalled by the SER server to pronounce said at least one word.
[0061] In S27, the authentication device records at least one M word. In S28, the B_AUT 2 software component of the AUT authentication device checks if the spoken M word matches the previously created EV fingerprint. Specifically, the B_AUT 2 software component checks the M word against at least one of the physical characteristics of the user UT, such as intonation, cadence, or accent, with which the user UT spoke the M word. If there is no match between the M word and the EV voiceprint (branch "N" on the figure 5B ), for example, steps S25 to S28 are iterated a predefined number of times. In another example, the authentication device AUT sends a voice or text message to the user's terminal TER, instructing them to recreate a voiceprint. If, however, there is a match between the word M and the voiceprint EV (branch "O1" on the figure 5BIf third-level AUT 3 authentication is not required for the service requested by user UT, the AUT authentication device sends an AUT_OK voice or text message to the TER terminal in S29a, confirming that strong authentication was successful for the requested service. In another embodiment, the AUT_OK message can be sent directly by the SER server after being received from the AUT authentication device. In S30a, user UT then accesses the requested service via their TER terminal. Alternatively, the AUT_OK message may not be sent; in this case, user UT can access the requested service directly via their TER terminal once the match between the at least one word and the EV voiceprint has been established in S28.
[0062] In the event that there is indeed a match between the word M and the voiceprint EV and the required service requires third-level (very strong) AUT 3 authentication (branch "O2" on the figure 5BIn S29b, the authentication device AUT sends a supplementary authentication request to the terminal TER. This is a REQ_MP request for a password, for example, the aforementioned CC confidential code, typically a PIN, associated with the user UT's CIA subscriber identity card and previously registered in association with the user UT's MSISDN or IMSI number and with the latter's EV voiceprint, either in the SER server, in the authentication device AUT, or in a database accessible by the SER server and the authentication device AUT. In another embodiment, the REQ_MP request can be sent directly by the SER server after being received by it from the authentication device AUT. Such a request is, for example, a voice message of the type: " Please pronounce / Enter your PINCC”. The message is then sent by the ICA_A communication interface of the AUT authentication device, via the RCM network, to the TER terminal. In another example, such a request is a text message of the type: Please call the SER server again and state your PIN CC. or even " The SER server will call you back in 1 minute to ask you to state your PIN. or even "please type your confidential code CC.
[0063] In S30b, upon receipt of the REQ_MP request in the TER terminal, the user UT speaks or types the CC PIN, depending on the implemented embodiment. This CC PIN is transmitted directly to the AUT authentication device in response to the REQ_MP request, either via the TER terminal's ICA_T communication interface if the CC PIN is spoken, or via the TER terminal's IC1_T communication interface if the CC PIN is typed (SMS, USSD, or DTMF code). Alternatively, the CC PIN is transmitted indirectly via the SER server if the user UT has called the SER server or has been called back by the SER server to speak or type the CC PIN.
[0064] In S31, the B_AUT 3 software component of the AUT authentication device checks if the spoken or typed PIN matches the previously registered PIN. If there is no match between the two PINs (branch "N" on the figure 5B ), steps S29b and following are, for example, iterated with a limited number of iterations, for example, 2. In another example, the authentication device AUT sends a voice or text message to the user UT's terminal TER indicating a refusal of access to the requested service. If, on the other hand, there is a match between the two PINs (branch "O" on the figure 5BThe authentication device AUT sends a voice or text message, AUT_OK, to the terminal TER via S32, confirming that strong authentication was successful for the requested service. In another embodiment, the AUT_OK message can be sent directly by the server SER after being received from the AUT authentication device. In S33, the user UT then accesses the requested service via their terminal TER. Alternatively, the AUT_OK message is not necessarily sent via S32; the user UT can then access the requested service directly via their terminal TER once the PIN matching has been established in S31.
Claims
1. Method for authenticating a user of a service on a communication terminal (TER), comprising the following, on the communication terminal: - sending (S23), to a server, a request to access said server, said access request being vocal or textual and comprising a first identifier associated with the communication terminal and a second identifier associated with a service requested in said server, - receiving (S25), from an authentication device, an authentication request asking the user to speak at least one word, - communicating (S26) said at least one word spoken by the user to the device, said at least one spoken word corresponding to a voiceprint (EV) of the user recorded beforehand in association with the identifier of said communication terminal, - receiving (S29b), from the device, an additional authentication request for additional authentication of the user.
2. Authentication method according to Claim 1, wherein the received additional authentication request is a password request, to which the terminal communicates (S30b), in response, the requested password in text or voice form.
3. Authentication method according to Claim 1, wherein the second identifier associated with the requested service belongs to the group comprising a dual-tone multi-frequency tone code, a USSD code, and an SMS message.
4. Authentication method according to Claim 1, wherein the at least one spoken word that is communicated to the authentication device is identified according to at least one physical characteristic of the user.
5. Authentication method according to Claim 4, wherein said at least one physical characteristic belongs to the group comprising intonation, speed, and the accent with which the user speaks the word.
6. Communication terminal for implementing authenticated access of a user to a service, said terminal comprising a processor (UTR_T) that is configured to implement the following: - sending, to a server, a request to access said server, said access request being vocal or textual and comprising a first identifier associated with the communication terminal and a second identifier associated with a service requested in said server, - receiving, from an authentication device, an authentication request asking the user to speak at least one word, - communicating said at least one word spoken by the user to the device, said at least one spoken word corresponding to a voiceprint of the user recorded beforehand in association with the identifier of said communication terminal, - receiving, from the device, an additional authentication request for additional authentication of the user.
7. Device for authenticating a user of a service accessed by way of a communication terminal, the device comprising a processor (UTR_A) that is configured to implement the following: - receiving, from a server that has received a request to access said server sent by the communication terminal, said access request being vocal or textual and comprising a first identifier associated with the communication terminal and a second identifier associated with a service requested in said server, - sending, to the communication terminal associated with the first identifier, an authentication request asking the user to speak at least one word, - receiving, from the terminal, the spoken word, said one spoken word corresponding to a voiceprint of the user recorded beforehand in association with the first identifier, - sending, to the terminal, an additional authentication request for additional authentication of the user.
8. Authentication system, characterized in that it comprises: - a communication terminal according to Claim 6, - an authentication device according to Claim 7.
9. Computer program comprising program code instructions for implementing the authentication method according to any one of Claims 1 to 5 when it is executed on a computer.
10. Computer-readable information medium comprising instructions of a computer program according to Claim 9.