A method of controlling access to a good or service distributed via a data communication network.

By using a token-based system that separates service access and authentication terminals, the method provides flexible access to online services while ensuring strong security and reducing fraudulent access.

FR3121764B1Active Publication Date: 2025-05-09HIASECURE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2021003663
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-04-09
Publication Date
2025-05-09
Estimated Expiration
2041-04-09

AI Technical Summary

Technical Problem

Existing access control methods for online platforms struggle to balance flexibility in accessing services from any terminal with strong security measures to prevent fraudulent access.

Method used

The method distinguishes between a service access terminal and an authentication terminal, using a token issued by the platform to facilitate secure authentication. This token is transmitted from the access terminal to the authentication terminal and then back to the platform with the authentication result, allowing flexible access while maintaining strong security.

Benefits of technology

This approach enables users to access services from any terminal while significantly reducing the risk of fraudulent access, as authentication must occur on a previously registered, single authentication terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000016_0000
    Figure 00000016_0000
  • Figure 00000017_0000
    Figure 00000017_0000
Patent Text Reader

Abstract

A method for controlling access to a good or service offered by a platform from an access terminal, characterized in that it comprises: a step of transmitting an access request from the access terminal to the platform; a step of transmitting, from the platform to the access terminal, a token containing information enabling the platform to identify the access request; a step of transmitting the token from the access terminal to an authentication terminal; a step of transmitting the token and a user identifier from the authentication terminal to an authentication server; a step of authenticating the user by the authentication terminal;In the event of successful authentication: a step of transmitting information enabling the platform to identify the access request and the authenticated identity of the user from the authentication server; a step of releasing access, by the platform, from the access terminal to the good or service required by the access request. [Fig. 3];
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for controlling access to a good or service distributed via a data communication network

[0001] The present invention relates to the field of the distribution of goods and services via a data communication network. More particularly, the invention relates to access control for the distributed service or good.

[0002] The distribution of goods and services via a data communication network, typically the Internet, is rapidly developing. An increasing number of goods and services are thus offered to the user. Several marketing models are available, including purchase, rental, purchase of access rights, and others.

[0003] These goods and services are typically offered by a merchant via a service platform, often called an online commerce platform, connected to the data communication network and made accessible to users via that network. The user uses a terminal also connected to the data communication network, enabling them to connect to and interact with the merchant's platform. The terminal used by the user is typically a personal computer, a tablet, a smartphone, or any other information processing device that can be connected to the data communication network.

[0004] A user wishing to access a good or service offered by an online commerce platform must typically register with the platform. This registration typically consists of opening an account linked to the user with the platform and the platform assigning authentication credits to the user to subsequently allow them to authenticate with the platform.

[0005] A first family of access control methods consists of encrypting the content offered and providing the user with a hardware device for decryption. This hardware device, typically called a decoder, is associated with a second hardware device containing the decryption keys and the user's authentication credentials. This second hardware device is typically a smart card. Access to the service requires the use of the decoder and the associated smart card. This first family offers a good level of control over the legitimacy of user access to the service. However, it limits access to the user's home where the decoder is installed. This constraint is increasingly unsuitable in a context where the user typically has several terminals allowing access to the service, these terminals being increasingly mobile.Users today expect to be able to access services more freely, regardless of their location.

[0006] A second family of access control methods allows the user to use any type of terminal connected to the data communication network. The only constraint imposed is that the user must authenticate from the terminal when they wish to access the service. This authentication typically relies on entering the password associated with the user's account. This family of access control methods offers the expected flexibility in terms of the freedom given to the user to access the service from any terminal connected to the network and from any location. However, it suffers from a lower level of control. In particular, it is not possible to verify that the authentication credentials were indeed entered by the legitimate user. Merchants using these access control methods have great difficulty limiting the sharing of credentials between users and the resulting fraudulent access. Description of the invention

[0007] The present invention aims to overcome the aforementioned drawbacks by proposing an access control method that offers flexibility in terms of the access terminal and its location while providing better control over the legitimacy of access. It is based on the distinction made between the service access terminal and the authentication terminal. It also relies on a token issued by the platform in response to a service access request. This token is made accessible from the service access terminal, is then transmitted to the authentication terminal, and returned to the platform along with the authentication result. It is thus possible to offer considerable flexibility regarding the access terminal used while benefiting from the strong security provided by the authentication terminal. The token links the two.

[0008] The invention relates to a method of controlling access to a good or service offered by a platform (102) from an access terminal (100), characterized in that it comprises:

[0009] a step of transmitting an access request (300) from the access terminal (100) to the platform (102);

[0010] a step of storing the access request (300) by the platform;

[0011] a transmission step (301), from the platform to the terminal access, a token containing information allowing the platform to identify the stored access request (300);

[0012] a step of transmitting the token from the access terminal to an authentication terminal (200);

[0013] a step of transmitting the token and a user identifier from the authentication terminal (200) to an authentication server;

[0014] a user authentication step by the authentication terminal;

[0015] if authentication is successful:

[0016] a step of transmitting information enabling the platform to identify the stored access request (300) and the authenticated identity of the user from the authentication server (202);

[0017] a step (307) of releasing, by the platform, access, from the access terminal (100) to the good or service required by the stored access request.

[0018] According to a particular embodiment, the token is a QR code.

[0019] According to a particular embodiment, the token is a mark concealed in a picture.

[0020] According to a particular embodiment, the token is transmitted between the access terminal and the authentication terminal by photographic capture of the token from the authentication terminal.

[0021] According to a particular embodiment, the token further includes platform identification information.

[0022] According to a particular embodiment, the token further includes information relating to the access terminal.

[0023] According to a particular embodiment, the authentication terminal is previously registered with the authentication server, only one terminal being able to be registered for a given user.

[0024] According to a particular embodiment, the authentication server also performs checks relating to the legitimacy of the stored request.

[0025] According to a particular embodiment, the user authentication step includes the verification of a biometric characteristic of that user.

[0026] According to a particular embodiment, the token is transmitted with the authenticated identity of the user from the authentication server to the platform.

[0027] The invention relates to a computer program comprising instructions adapted to the implementation of each of the steps of the process according to the invention when said program is executed on a computer.

[0028] The invention relates to a means of storing information, removable or not, partially or totally readable by a computer or a microprocessor comprising code instructions of a computer program for the execution of each of the steps of the process according to the invention.

[0029] Other features and advantages of the invention will become apparent in the following description. Brief description of the drawings

[0030] Other features, details and advantages of the invention will become apparent upon reading of the detailed description below. This is purely illustrative and should be read in conjunction with the attached drawings, on which: Fig. 1

[0031] [Fig. 1] illustrates a known system for distributing goods and / or services via a data communication network; Fig. 2

[0032] [Fig.2] illustrates a system for distributing goods and / or services according to an embodiment of the invention; Fig. 3

[0033] [Fig.3] illustrate the exchanges during access to a good or service according to an embodiment of the invention; Fig. 4

[0034] [Fig.4] is a schematic block diagram of an information processing device for the implementation of one or more embodiments of the invention. Detailed description

[0035] Fig. 1 illustrates a known system for distributing goods and / or services via a data communication network.

[0036] In this system, a client 100 is connected to a data communication network 101, typically the Internet. A platform 102, also connected to the data communication network 101, offers goods or services. A user can access a good or service offered by the platform 102 from the client 100. This access is achieved through exchanges 103 between the client 100 and the platform 102.

[0037] The client 100 is typically a service access software, such as, for example, a web browser operating on an access terminal connected to the network 101. The access terminal can be a personal computer, a digital tablet, a smart mobile phone, or any other information processing device that can connect to the network.

[0038] Platform 102 is a set of software operating on one or more computer servers. Here, we will use the term "platform" to refer to all the services offered by a merchant to users, regardless of the hardware implementation of the server(s) enabling this software to function. The platform can operate on a single server or a set of servers that may be located in different geographical locations. These servers can communicate with each other to provide the service.

[0039] Platform 102 typically includes several functions. In addition to the offer and the In addition to distributing goods and services, the platform typically also manages a database of registered users, their authentication, and the rights associated with each user. The platform may be a platform for purchasing goods online, or for distributing services such as video-on-demand, film rentals, music streaming, etc.

[0040] A user connecting to the platform for the first time is typically offered a registration procedure. This registration procedure consists of creating an account for the user and allocating authentication credits to enable them to authenticate themselves with the platform. This registration may be subject to a purchase or be free of charge, depending on the distribution model adopted by the platform. Once registration is complete, the platform has an account linked to the user, which stores information related to that user. This may include banking information, rights linked to their registration, authentication data, and any other information necessary for the platform to provide its service to the user.

[0041] Once registered, a user wishing to access a good or service offered by the platform must connect to it from the client running on their terminal. This client can typically be an internet browser, such as Safari (registered trademark), Chrome (registered trademark), Edge (registered trademark), or another. The client can also be an application dedicated to accessing the platform. To do so, the user must typically authenticate with the platform. Any type of authentication can then be used. The most common authentication method consists of providing a pair of identifiers composed of a user ID, often referred to by the English word "login," and an associated password.

[0042] Authentication can be requested at each connection or only occasionally. The user's identity is then saved by the client. Once authenticated, the user can access the platform and choose a product or service. A request for a product or service is then sent by the client to the platform. The platform typically verifies the legitimacy of the request, that is, it verifies that the user has the rights to access the requested product or service. This verification may include checking the client's geographical location, for example, when the product or service is legally available only in certain parts of the world. This can be the case for audiovisual services where the rights associated with a work may be geographically restricted. Depending on the type of product or service offered, any type of verification may be necessary.Payment may also be required to obtain the requested product or service.

[0043] Once these checks have been carried out and any payment made, the user can to obtain the requested good or service. For example, in the case of a video-on-demand service, the requested audiovisual program can be streamed by the platform to the user's terminal client from which the request was issued.

[0044] This access control method offers users flexible access from any terminal, both at home and away. When a user wishes to access the platform from a new terminal, they simply authenticate with the platform using the client available on that terminal. Knowing the authentication credentials—in this case, a username and password—allows access to the platform with the associated user rights.

[0045] However, access control is not always sufficient. In particular, a user may forget to log out from the client on a terminal belonging to another person, who can then access the platform using the user's identity. Another problem can arise, particularly concerning subscription-based services such as on-demand audiovisual streaming services: the sharing of authentication credits. A user subscribes to a platform and obtains the authentication credits associated with their account. They then distribute these authentication credits to a group of other people. These individuals can then benefit from the user's subscription using their authentication credits by fraudulently accessing the service offered by the platform. Authentication credits can also be stolen from the legitimate user.

[0046] It is difficult today to combat these fraudulent accesses, except by restricting the flexibility of access allowing a legitimate user to connect from any place and any terminal to the services to which he has subscribed.

[0047] The invention aims to solve this problem by proposing a method of access control to an online platform allowing the flexibility of access to the services offered from any terminal while limiting the risks of fraudulent access by a user other than the legitimate user.

[0048] Figure 2 illustrates an architecture for distributing goods or services from a platform according to one embodiment of the invention.

[0049] This figure illustrates the access terminal 100 to the platform 102 via the data communication network 101. The access terminal 100 exchanges messages 103 with the platform 102. We find here the same architecture as that illustrated by [Fig.1].

[0050] One aspect of the invention consists of distinguishing the access terminal 100 to the platform from the authentication terminal 200. This makes it possible to offer the user considerable flexibility in choosing the access terminal 100 while imposing constraints on the choice of the authentication terminal 200. Typically, according to a In this embodiment of the invention, the authentication terminal 200 is a unique terminal linked to the user. This could be, for example, their smartphone, a digital tablet, or other device.

[0051] A second aspect of the invention consists of distinguishing the platform 102 offering the goods or services from the authentication server 202 responsible for user authentication. The authentication server 202 is referred to here independently of its specific implementation, which may involve one or more connected servers, co-located or not, offering the user authentication service.

[0052] When we say that we distinguish between the access terminal and the authentication terminal, this distinction is functional and in no way precludes embodiments where the access terminal and the authentication terminal are the same terminal. Similarly, the distinction made between the service platform and the authentication server is also functional and does not preclude embodiments where these two services are implemented on the same server or the same set of servers.

[0053] User authentication is performed by the user via the authentication terminal 200. For this purpose, the user uses an authentication client running on the terminal 200. This client can be a generic client such as a web browser, or preferably a dedicated authentication application offered by the authentication server provider 202. Any authentication protocol can be used, from a simple username and password to more secure protocols that may employ verification of a biometric characteristic of the user, for example. In the embodiment shown, challenge-response authentication is used, with the user employing a secret convention specific to them to determine the response to the challenge presented by the authentication server. Such a method is described in French patent application FR3074321.Authentication involves a connection from the authentication terminal 200 to the authentication server 202 via the communication link 204. Advantageously, the authentication terminal is pre-registered with the authentication server and it is only possible for a given user to register one authentication terminal.

[0054] Because the provision of a good or service to an access terminal 100 by a platform 102 has been distinguished from the authentication of the user requesting the good or service carried out between the authentication terminal 200 and the authentication server 202, it is necessary that a link be established between the user's request and their authentication.

[0055] According to a third aspect of the invention, when the platform 102 receives a request from an access terminal, it generates a token and retransmits it to the access terminal 100. The user transfers this token to the authentication terminal 200. This transfer, referenced as 203, can take any form. It can be an electronic transmission via a wireless connection between the two terminals, for example, using the Bluetooth protocol (registered trademark) or the Wi-Fi protocol (registered trademark). It can also be information displayed on the screen of the access terminal 100, which the user copies onto the authentication terminal 200. In one embodiment of the invention, the token transmitted by the platform is displayed on the screen of the access terminal 100 and photographed from the authentication terminal 200. In this embodiment, the token can take the form of a two-dimensional code such as a QR code or a mark hidden within an image using a process known as watermarking.The token, or at least the information contained in the token, is then transmitted by the authentication terminal to the authentication server during the exchanges that perform this authentication.

[0056] Next, when authentication is successful, the authentication server 202 is able to transmit the verified user identity and the token, or the information contained in the token, to platform 102. Platform 102, having the user's identity and the token, is then able to authorize the distribution, or transmission, of the good or service requested by the user. The nature of this distribution or transmission depends on the nature of the good or service requested by the user. It may involve transmission to the access terminal, for example, in the case of an e-book or an audiovisual work purchased by the user. It may also involve the distribution without storage, or streaming, of an audiovisual work. It may even involve the shipment of a physical good, unrelated to the access terminal, which was only used for the purchase, when the user's request concerns a physical good.

[0057] The token must contain at least one piece of information enabling the platform to directly identify: the pending request received from the access terminal that triggered the token generation; or indirectly: to retrieve or calculate identifying information for the pending request from the access terminal. This could be an identifier for this request, which is typically stored by the platform pending authentication. This identifier is then typically generated by the platform when the request is stored. In an alternative embodiment, it could be an identifier for the access terminal that issued the request; the platform then searches among the stored requests for the one originating from that access terminal. Generally, it could be any data enabling the platform to identify the request, directly or indirectly.

[0058] In certain embodiments of the invention, the platform may perform additional checks upon receipt of the user's identity and the token. These checks may relate to user rights, time slots for using the good or service. They may also relate to the characteristics of the access terminal, these characteristics being technical such as screen size, processor power or others, or characteristics related to the geographical location of the access terminal, access rights to certain goods or services may be limited geographically, but also characteristics related to the context of the access terminal such as the presence of a High Fidelity acoustic system usable in the vicinity or the presence of an electronic or digital component, such as a Secure Element or digital safe, accessible and usable from the access terminal.

[0059] Some of these checks relating to the legitimacy of the pending request can be performed by the authentication server in certain embodiments of the invention. The platform can then transmit certain necessary information within the token. This information may, for example, contain details about the capabilities of the access terminal, its location, and its network environment.

[0060] Access to the good or service may be conditional upon payment by the user. This payment may be processed by the platform upon receipt of the user's authenticated identity, in collaboration with a payment platform and / or the bank associated with the user's account. The payment will then be confirmed by the user from the access terminal.

[0061] Payment processing can also be managed by the authentication server. For example, upon receiving the user's identity and token, the platform informs the authentication server that a payment is required. The server then processes the payment, which will be confirmed by the user from the authentication terminal. This payment can, for example, credit a platform account in real time and, by linking this payment to the token issued by the platform, enable the release of the service identified by the token. The information necessary for payment can be stored by the authentication server or provided by the platform for each transaction.

[0062] The authentication server can be associated with a given platform. However, in some embodiments, the authentication server allows user authentication from multiple platforms. In this case, it is necessary that the authentication server receiving an authentication request associated with a token be able to identify the platform in question in order to transmit the authentication result and the associated token to it. To do this, the platform can include a platform identifier in the token information. This identifier can take the form of the platform's internet address, or an identifier previously agreed upon between the platform and the authentication server or any information enabling the authentication server to identify the platform.

[0063] Thus, the invention allows the user to access the platform from any access terminal and from any location. However, by requiring authentication from a single authentication terminal previously registered with the authentication server, the risk of a user other than the legitimate user being able to authenticate is greatly reduced. The authentication terminal is typically, but not exclusively, the user's smartphone. Authentication therefore requires physical access to this phone. Sharing authentication credentials with a circle of friends, for example, is no longer possible. It is therefore possible, thanks to the invention, to maintain the flexibility of the user's choice of access method to a platform while significantly limiting the possibilities of fraudulent access by an illegitimate user.

[0064] Figure 3 illustrates the exchanges taking place when accessing a good or service in an example of an embodiment of the invention.

[0065] A user wishing to access a good or service offered by a platform from an access terminal causes the emission of an access request 300 from that access terminal to the platform.

[0066] The platform receives and stores this 300 request. This request is then pending. Advantageously, information about the accessing terminal is stored within or with the received request. This information can be transmitted by the accessing terminal with the request. For example, if the request is made using the HTTP (Hyper Text Transfer Protocol), a header of the HTTP request typically contains a signature of the accessing terminal and the client issuing the request. The platform generates a token and transmits this token as a 301 response to the 300 request. As discussed above, this token contains at least one piece of information that will allow the platform to identify the pending 300 request later. The token may also contain information that identifies the platform or any additional information such as details about the accessing terminal.

[0067] Once the token 301 is received by the access terminal, this token must be transmitted, 302, by the user to their authentication terminal. This transmission can take any form. It can be a transmission using a wired or wireless transmission protocol between the access terminal and the authentication terminal. It can also be a photographic capture of an element such as a QR code or an invisible marking, the token then being displayed on the screen of the access terminal. It can also be the manual copying of information, such as a string of characters, displayed on the screen of the access terminal.

[0068] Once the token is transmitted to the authentication terminal, the user is authenticated from their authentication terminal. The specific exchanges here depend on the authentication protocol used, which can be any known authentication protocol. In the usage example, the authentication terminal transmits the token and the user's identifier in an authentication request (303) to the authentication server. The authentication server generates and transmits a challenge (304) to the authentication terminal in response. The user then uses the secret convention to generate the response to the challenge and transmit it (305) to the authentication server.

[0069] The authentication server performs authentication and, if successful, transmits the authenticated user identity and the received token to the platform in the form of message 306. In some embodiments, the authentication server may perform additional checks as described above. These checks may require the interpretation and use of additional information contained in the token. The authentication server may also need to obtain a platform identifier contained in the token to identify the platform when there are multiple platforms. In some embodiments, the information contained in the token that is only useful to the authentication server is not retransmitted to the platform. Only the information enabling the platform to identify the pending request is required in addition to the authenticated user identity.

[0070] When the platform receives the user's authenticated identity and the information identifying the pending request, it can release access to the requested good or service from the access terminal via a 307 message. In an alternative implementation, the authentication server may, based on session or context information already residing and time-stamped in the authentication terminal, not perform a new user authentication and directly transmit the previously obtained authenticated user identity to the platform.

[0071] These exchanges between the access terminal, the authentication terminal, the authentication server, and the platform can use any transmission protocol. In one embodiment, the HTTP protocol is used.

[0072] Figure 4 is a schematic block diagram of an information processing device 400 for implementing one or more embodiments of the invention. The information processing device 400 may be a peripheral device such as a microcomputer, a workstation, or a mobile telecommunications terminal. The device 400 includes a communication bus connected to:

[0073] - a central processing unit 401, such as a microprocessor, denoted CPU;

[0074] - a 402 random access memory, denoted RAM, for storing the executable code of the method for carrying out the invention as well as registers adapted to record variables and parameters necessary for the implementation of the method according to embodiments of the invention; the memory capacity of the device can be supplemented by an optional RAM memory connected to an expansion port, for example;

[0075] - a read-only memory 403, denoted ROM, for storing computer programs for the implementation of the embodiments of the invention;

[0076] - a 404 network interface is normally connected to a communication network on which digital data to be processed is transmitted or received. The 404 network interface can be a single network interface, or composed of a set of different network interfaces (e.g., wired and wireless, interfaces, or different types of wired or wireless interfaces). Data packets are sent on the network interface for transmission or are read from the network interface for reception under the control of the software application running in the 401 processor;

[0077] - a 405 user interface for receiving input from a user or for display information to a user;

[0078] - a storage device 406 as described in the invention and noted HD;

[0079] - an input / output module 407 for receiving / sending data to / from external devices such as hard drives, removable storage media or others.

[0080] The executable code can be stored in read-only memory 403, on the storage device 406, or on a removable digital medium such as, for example, a disk. According to one embodiment, the executable code of the programs can be received via a communication network, through the network interface 404, in order to be stored in one of the storage means of the communication device 400, such as the storage device 406, before being executed.

[0081] The central processing unit 401 is adapted to command and direct the execution of instructions or portions of software code of the program or programs according to one of the embodiments of the invention, instructions which are stored in one of the aforementioned storage means. After power-up, the CPU 401 is capable of executing instructions from the main RAM 402, relating to a software application. Such software, when executed by the processor 401, causes the execution of the processes described.

[0082] In this embodiment, the device is a programmable device that uses software to implement the invention. However, alternatively, the present invention can be implemented in hardware (for example, in the form of a specific integrated circuit or ASIC).

[0083] Naturally, to meet specific needs, a competent person in The field of the invention may apply modifications to the preceding description.

[0084] Although the present invention has been described above with reference to specific embodiments, the present invention is not limited to specific embodiments, and modifications which fall within the scope of the present invention will be obvious to a person versed in the art.

Claims

Claims

1. Method for controlling access to a good or service offered by a platform (102) from an access terminal (100) characterized in that it comprises: • a step of transmitting an access request (300) from the access terminal (100) to the platform (102); • a step of generating and transmitting (301), by the platform to the access terminal, a token comprising information allowing identification by the platform of the access request (300); • a step of transmitting the token from the access terminal to an authentication terminal (200); • a step of transmitting the token and an identifier of the user from the authentication terminal (200) to an authentication server; • a step of authenticating the user by the authentication terminal;• in case of successful authentication: • a step of transmitting the information allowing the identification by the platform of the access request (300) and the authenticated identity of the user from the authentication server (202); • a step (307) of release, by the platform, of access, from the access terminal (100) to the good or service required by the access request.;

2. Method according to claim 1, characterized in that the token is a QR code.

3. Method according to claim 1, characterized in that the token is a mark hidden in an image.

4. Method according to claim 2, characterized in that the token is transmitted between the access terminal and the authentication terminal by photographic capture of the token from the authentication terminal.

5. Method according to claim 1, characterized in that the token further comprises information identifying the platform.

6. Method according to claim 1, characterized in that the token further includes information relating to the access terminal.

7. Method according to claim 1, characterized in that the authentication terminal is previously registered with the authentication server, only one terminal being able to be registered for a given user.

8. Method according to claim 1, characterized in that the authentication server further carries out checks relating to the legitimacy of the stored request.

9. Method according to claim 1, characterized in that the step of authenticating the user comprises the verification of a biometric characteristic of this user.

10. Method according to claim 1, characterized in that the token is transmitted with the authenticated identity of the user from the authentication server to the platform.

11. Computer program comprising instructions adapted to the implementation of each of the steps of the method according to any one of claims 1 to 10 when said program is executed on a computer.

12. Information storage means, removable or not, partially or totally readable by a computer or a microprocessor comprising code instructions of a computer program for the execution of each of the steps of the method according to any one of claims 1 to 10.