METHOD FOR AUTHENTICATING A USER FOR ACCESS TO A TERMINAL DEVICE MANAGEMENT SERVICE AND CORRESPONDING ACCESS AUTHORIZATION SYSTEM.
The method addresses the vulnerability of existing user authentication systems by enabling vocal authentication using a communication device and terminal device, ensuring secure access to terminal device management services without requiring functional peripheral equipment.
Patent Information
- Application Number
- FR2023014872
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-27
AI Technical Summary
Existing methods for authenticating users to access management services for terminal devices in local telecommunications networks are vulnerable to trial and error attacks and require peripheral equipment, which can be non-existent or inoperative, preventing user authentication.
A method that uses a communication device to display an authentication token, which the user pronounces aloud, and is recorded by the terminal device, allowing the authentication system to verify the user's identity through voice transcription and comparison with the token, without relying on peripheral equipment.
This solution enables secure user authentication and access to terminal device management services even when peripheral equipment is unavailable, enhancing security and usability by allowing vocal authentication.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: METHOD FOR AUTHENTICATING A USER FOR ACCESSING A MANAGEMENT SERVICE OF A TERMINAL DEVICE AND SYSTEM CORRESPONDING ACCESS AUTHORIZATION. Technical field
[0001] The field of the invention is that of local telecommunications networks integrating a plurality of terminal devices, such as a television (for example a connected television of the “Smart TV” type), a TV decoder (“Set Top Box” in English), a gateway for access to a wide area network (“Wide Area Network” in English), etc. In particular, the invention relates to a method for authenticating a user to authorize access to a management service managing a terminal device (eg, the TV decoder) and a system for authorizing access to this management service. STATE OF THE PRIOR ART
[0002] Access to remote services generally requires authentication of a user wishing to access them. Such remote services are, for example, management services for remotely managing different terminal devices within a local area network (Local Area Network). In one example, such a management service is a maintenance service for performing diagnostics of malfunctions of such terminal devices and proposing solutions to remedy these malfunctions.
[0003] User authentication for access to such terminal device management services can be performed via the use of different types of authentication protocols. Among these authentication protocols, the Password Authentication Protocol (PAP) is known. This authentication protocol requires a user device to send a user identifier and an associated password to an authentication system. Depending on the accuracy of this pair of information, the authentication system authorizes, or denies, the user access to the desired remote service. However, this authentication protocol remains vulnerable, particularly against trial and error attacks.To enhance the security of user authentication, other authentication protocols can be used instead of PAP, or in combination. For example, the Challenge-Response Authentication Protocol uses a challenge-response system for authentication. authenticate the user. One party (e.g., the authentication server) presents a question (i.e., the challenge) and another party (e.g., the user) must provide a valid answer (i.e., the response) to be authenticated.
[0004] In the context of accessing a management service of a terminal device (e.g., TV decoder) in a local network, the user can authenticate himself by interacting with peripheral equipment associated with these terminal devices (e.g., remote control, keyboard, etc.). The user can, for example, use a remote control to enter his identifier and password on a television screen connected to a TV decoder for access to a maintenance service of the TV decoder. In the same way, when the authentication protocol is a challenge / response type protocol, the challenge (e.g., word, image, etc.) can be displayed on a television screen and the user can respond to this challenge by using the remote control to enter the response, which is displayed on the television screen.
[0005] However, when these peripheral devices are non-existent or inoperative, the user is no longer able to authenticate and access the requested management service.
[0006] It is then desirable to overcome these drawbacks of the state of the art. It is particularly desirable to provide a solution that allows the user to be authenticated and to authorize him to access terminal device management services without using the associated peripheral equipment (e.g., television, remote control, keyboard, etc.) and without risking compromising the security of the management service. Presentation of the invention
[0007] A method for authenticating a user to authorize access to a management service of a terminal device is proposed here, the terminal device being connected to a local network. The local network is managed by a gateway for access to a wide area network, a communication device and the terminal device having access to an authentication system and a management system. The method comprising: - perform a user authentication phase including: (i) receive, by the communication device, from the authentication system, a message comprising an authentication token, (ii) display, by the communication device, the authentication token, (iii) generate, by the terminal device, a voice recording corresponding to a pronunciation by the user of the authentication token displayed by the communication device, (iv) authenticate the user, by the authentication system, when a level of similarity between a text transcription of the authentication token from the voice recording, and said authentication token is greater than or equal to a threshold predefined, - and, when the user is authenticated, execute a phase of authorization of access to the management service comprising: establishing, by the management system, a secure communication channel between the management system and the communication device and / or the terminal device.
[0008] Thus, the present disclosure proposes an approach for authenticating a user and authorizing access to a management service of a terminal device (e.g., maintenance service for diagnosing and repairing the terminal device) in which the communication device plays an interface role between the user and an authentication system. The communication device displays an authentication token provided by the authentication system and the terminal device records the user speaking aloud the authentication token displayed by the communication device, and obtains a text transcription thereof. The user is authenticated if this text transcription and the authentication token have a similarity level greater than or equal to the predefined threshold.
[0009] Thus, the display of the authentication token on the user's communication device makes it possible to resolve a challenge-response type authentication vocally, without having to use any peripheral equipment of the terminal device.
[0010] Furthermore, the vocal resolution of the challenge allows the user to verbally consent to the management system accessing the user's personal data contained on the terminal device. Indeed, by pronouncing the authentication token aloud, the user implicitly accepts that the management system connects (directly or indirectly via the communication device) to the terminal device, for example to carry out maintenance operations.
[0011] According to one embodiment, the user authentication phase comprises: receiving, by the authentication system from the management system, a request for delegation of authentication of the user, so that the authentication system transmits to the communication device said message comprising the authentication token. The delegation request comprises at least one piece of authentication information associated with a profile of the user.
[0012] Delegating user authentication to the authentication system is particularly advantageous when the terminal device does not have functional peripheral equipment to allow the user to enter their authentication information. And thus, the user is authenticated via a “multi-factor” type authentication comprising on the one hand, authentication with the authentication system thanks to the authentication delegation, and on the other hand, via obtaining the response to the challenge in voice form. The security of the authentication of the user is therefore improved.
[0013] According to one embodiment, the user authentication phase comprises: receiving, by the management system from the communication device, a request for access to the management service comprising identification information for the terminal device. Thus, the management system is capable of knowing which terminal device of the user is concerned, in particular when the user has several terminal devices managed by the management system. Furthermore, the management system is capable of transmitting the user's authentication delegation request to the appropriate authentication system.
[0014] According to one embodiment, the communication device displays an indication of activation of a sound capture means of the terminal device. Thus, the terminal device is ready to record the user when he pronounces aloud the authentication token displayed by the communication device.
[0015] According to one embodiment, the user authentication phase further comprises: - obtain, through the authentication system, the text transcription of the authentication token from the voice recording, - compare said text transcription with the authentication token transmitted by the authentication system to the communication device, and - determine the level of similarity between said text transcription and said authentication token.
[0016] Thus, the resources of the authentication system are also shared to carry out the textual transcription of the authentication token.
[0017] According to one embodiment, to obtain the text transcription of the authentication token from the voice recording, the method comprises the following steps executed by a transcription system: - receive, from the terminal device, the voice recording corresponding to the user's pronunciation of the authentication token displayed by the communication device, and - transcribe said voice recording to obtain said text transcription, - transmit said text transcription to the authentication system.
[0018] Thus, the use of a system dedicated to transcription makes it possible to dedicate a quantity of resources adapted to accurately transcribing authentication tokens which can be complex.
[0019] According to one embodiment, to obtain the text transcription of the authentication token from the voice recording, the method comprises the following steps executed by the terminal device: - transcribe the voice recording corresponding to the user's pronunciation of the authentication token displayed by the communication device to obtain the text transcription of the authentication token from the voice recording, - transmit to the authentication system, said text transcription.
[0020] Thus, since the transcription is carried out by the terminal device, it is possible to limit the intermediaries and improve the security of user authentication.
[0021] According to one embodiment, the method further comprises, prior to the user authentication phase: - authenticate, by the authentication system, the terminal device.
[0022] Thus, the terminal device is considered in advance by the authentication system as a trusted terminal device.
[0023] According to one embodiment, the method further comprises, prior to the user authentication phase: - authenticate, by the terminal device, the authentication system.
[0024] Advantageously, in order to improve the security of user authentication, the authentication system and the terminal device mutually authenticate each other.
[0025] According to one embodiment, the message comprising the authentication token further comprises a validity period and / or an end date of validity of said predefined authentication token. The communication device monitors the validity period and / or the end date of validity so as to request sending of a new authentication token when the validity period and / or the end date of validity has expired.
[0026] Advantageously, it is thus possible to increase the security of the authentication token by limiting its validity over time.
[0027] According to one embodiment, the terminal device has access to the authentication system and the management system via access to the wide area network through the gateway.
[0028] Also provided herein is a method for maintaining a terminal device connected to a local area network, the local area network being managed by a wide area network access gateway, a communication device and the terminal device having access to an access authentication system and a management system, said method comprising: - authenticate the user by performing the authentication method as described above, in any of its embodiments, - perform a maintenance operation on the terminal device, when the user is authenticated and access to the management service is authorized.
[0029] Also provided herein is a system for authorizing access to a management service, comprising: a terminal device, a communication device, a terminal device management system, and an authentication system. The device terminal is connected to a local area network, the local area network being managed by a wide area network access gateway. The communication device and the terminal device have access to the authentication system and the management system. The management service access authorization system comprises electronic circuitry configured to: - execute a user authentication phase comprising: (i) receiving, by the communication device, from the authentication system, a message comprising an authentication token, (ii) displaying, by the communication device, the authentication token, (iii) generating, by the terminal device, a voice recording corresponding to a pronunciation by the user of the authentication token displayed by the communication device, (iv) authenticate the user, by the authentication system, when a level of similarity between a text transcription of the authentication token from the voice recording, and said authentication token is greater than or equal to a predefined threshold, - and, when the user is authenticated, execute a phase of authorization of access to the management service comprising: establishing, by the management system, a secure communication channel between the management system and the communication device and / or the terminal device.
[0030] According to one embodiment, the terminal device is a voice-controlled audio and video stream decoder, and the communication device is a smartphone or an electronic tablet or a laptop.
[0031] Also provided here is a terminal device intended to belong to a local network managed by a gateway, said terminal device comprising electronic circuitry configured to: - generate a voice recording corresponding to a user's pronunciation of an authentication token to authorize access to a terminal device management service; - transcribe said voice recording to obtain a text transcription of the authentication token at the end of the voice recording; and - transmit to an authentication system, said text transcription via said gateway. Brief description of the drawings
[0032] The characteristics of the invention mentioned above, as well as others, will appear more clearly on reading the following description of at least one exemplary embodiment, said description being made in relation to the attached drawings, among which:
[0033] [Fig.l] schematically illustrates an example of an environment for implementing a method for authenticating a user according to a particular embodiment;
[0034] [Fig.2] illustrates in diagram form the steps of the authentication process of the user according to an embodiment;
[0035] [Fig.3A] schematically illustrates exchanges within a system for authorizing access to a management service during the execution of the user authentication method, according to a first embodiment;
[0036] [Fig.3B] schematically illustrates exchanges within a system for authorizing access to a management service during the execution of the user authentication method, according to a second embodiment;
[0037] [Fig.4A] schematically illustrates an example of hardware architecture of a terminal device configured to execute all or part of the steps of the authentication method of Figs. 2 and 3A; and
[0038] [Fig.4B] schematically illustrates an example of hardware architecture of a terminal device configured to execute all or part of the steps of the authentication method of Figs. 2 and 3B.
[0039] DETAILED DESCRIPTION OF EMBODIMENTS
[0040] The general principle of the present disclosure concerns the authentication of a user for access to a management service (e.g., maintenance service) enabling the management of a terminal device (e.g., a TV decoder, a home gateway, etc.), even when this terminal device encounters malfunctions at the level of communication interfaces enabling it to connect to associated peripheral equipment (e.g., television screen, etc.). Indeed, in this case, the user cannot authenticate himself with the terminal device for access to the management service. In particular, the user cannot enter his authentication information (e.g., identifier and associated password), nor respond to a challenge that would be displayed on peripheral equipment, with the terminal device to access the management service.
[0041] Thus, the present disclosure proposes to use a third-party communication device (e.g., smartphone) of the user in order to allow him to authenticate himself with the management service, without the user having to use the peripheral equipment associated with the terminal device.
[0042] [Fig.l] schematically illustrates an example of an environment for implementing a method for authenticating a user according to a particular embodiment.
[0043] In this particular exemplary embodiment, a GW gateway (eg, a home gateway) is configured to be connected to a WAN (“Wide Area Network”). Network), for example the Internet. The GW is further configured to act as a router for a TER terminal device and a COM communication device of the user UT, when the TER terminal device and the COM communication device are connected to the GW. The GW is configured to establish a LAN (Local Area Network) to which the TER terminal device and the COM communication device are able to connect, for example to communicate with each other, or to access the WAN.
[0044] In the present example, the communication device COM of the user UT is connected to the gateway GW so that the gateway GW acts as a router for the communication device COM. However, the communication device COM is not necessarily configured or capable of connecting to the gateway GW. Thus, the communication device COM may be configured to access the wide area network WAN by means of a mobile radio network, for example of the 3G, 4G or 5G type or any other infrastructure allowing it to access the wide area network WAN. In this case, the communication device COM comprises a radio communication interface of the 3G, 4G or 5G type.
[0045] The TER terminal device is an audio / video (A / V) device intended to broadcast audio and / or video content on the local area network LAN. In the example of [Fig.l], the TER terminal device is an audio-visual stream decoder, or TV decoder (“Set-Top Box” in English, also known by the acronym STB), preferably a voice-controlled TV decoder (or “Voice STB”). In another example (not shown in [Fig.l]), the TER terminal device is a connected television (“Smart TV” in English) which is connected to the gateway GW, for example by WiFi.
[0046] Peripheral equipment may be associated with the TER terminal device. This peripheral equipment is, for example, connected to the TER terminal device via a dedicated input / output interface. This connection may be established by WiFi, HDMI link (“High-Definition Multimedia Interface” in English), Bluetooth, etc. Such peripheral equipment allows the user in particular to interact with the TER terminal device. In the example of [Fig.l], a television TV1 is connected to the TER terminal device, and adapted to display the decoded A / V streams. A C-TV remote control allows the user UT to remotely control the TER terminal device.
[0047] Subsequently, by way of illustration, it is considered that the management service is a maintenance service and that the TER terminal device is of the A / V device type (e.g., TV decoder). Thus, “terminal devices” (including “TER terminal device”) are understood hereinafter to mean A / V devices belonging, or intended to belong (i.e., configured to belong), to the local area network LAN. However, the method authentication of the user UT according to the embodiments described below can also be applied to the management, or maintenance, of other devices such as peripheral equipment connected to the A / V device, such as the television TV 1 (eg to modify the resolution or other display parameters) or the home gateway GW (eg, to adapt the transmission performance so as to optimize the transmission rate of the home gateway, for example depending on the A / V services which the user UT wishes to access).
[0048] As detailed below, in the context of authentication of the user UT via a challenge / response authentication protocol, the terminal device TER is configured to capture and generate an audio recording corresponding to the response to a challenge. In particular, a challenge pronounced by the user UT having received said challenge on the communication device COM.
[0049] The COM communication device is a “third party” device. In other words, “COM communication device” is understood to mean any device that is not a peripheral device associated with the TER terminal device. In particular, the COM communication device is a device allowing the UT user to authenticate himself with the management service that manages the TER terminal device, without using the peripheral equipment associated with the TER terminal device in question. In other words, the COM communication device allows the UT user to authenticate himself to access the management service that manages the TER terminal device when the peripheral equipment of the TER terminal device in question is non-existent or inoperative (e.g., in the case of a malfunction of the input / output interfaces of the TER terminal device). In the example of [Fig.l], the communication device COM is a smartphone of the user UT. In another example (not shown in [Fig.l]), the communication device COM is a tablet of the user UT.
[0050] Generally speaking, the communication device COM designates any communication device adapted to connect to the wide area network WAN, with or without the intermediary of the gateway GW.
[0051] In the example of [Fig.l], the terminal device TER (eg, TV decoder) encounters a malfunction at the level of its communication interfaces with peripheral equipment (eg, input / output interfaces of the TV decoder), such as the television TV 1 and the remote control C-TV. These peripheral equipments are therefore inoperative. Thus, when the user UT wishes to access the management service which manages the terminal device TER, the user UT cannot authenticate himself with the terminal device TER via an interaction with his peripheral equipments. In particular, the user UT can neither enter his identifier and his password via the remote control C-TV, nor respond to a challenge displayed on the television TV1.
[0052] Such a management service (eg, maintenance service) is, for example, hosted on a management system SER_APP located in the wide area network WAN and accessible via the gateway GW. In one example, when the management service is a maintenance service of the terminal device TER, then the management system SER_APP makes it possible to diagnose malfunctions of the terminal device TER and to resolve them. In this example, the management system SER_APP is a maintenance server of a service provider configured to ensure the maintenance of all or part of the terminal devices of the local area network LAN.
[0053] In the example of [Fig.l], an authentication system SER_AUTH makes it possible to authenticate the user UT from authentication information associated with a user profile of said user UT, to authorize the user UT to access services (eg, maintenance service). In one example, the authentication system SER_AUTH is an authentication server of a service provider located on the wide area network WAN and accessible via the gateway GW.
[0054] The user profile of the user UT is, for example, created when the user UT registers with the management service of the terminal device TER. This user profile includes information such as: information related to his identity (name, address, etc.), information concerning the terminal devices TER of the user UT (for example: type of terminal devices, identifier of each terminal device, etc.). The authentication information is information allowing the user UT to prove his identity to the management service, and, if necessary, to link the user UT to his user profile to check whether the user UT is authorized to benefit from the required management service. In one example, this authentication information is an identifier of the user UT associated with a password.
[0055] In a particular embodiment, the terminal device TER can communicate via the gateway GW providing access to the wide area network WAN to a transcription system SER_TRANS, such as a transcription server. This transcription system SER_TRANS makes it possible to transcribe, or convert, spoken words or audio content into written or digital text. Thus, the transcription system SER_TRANS is configured to transcribe into text an audio or voice recording made by the terminal device TER.
[0056] In the example of [Fig.l], the terminal device TER and the communication device COM can communicate with the authentication system SER_AUTH, the service management system SER_APP and, if applicable, the transcription system SER_TRANS, via access to the wide area network WAN by the gateway GW. Alternatively, the authentication system SER_AUTH, the management system SER_APP, and if applicable, the transcription system SER_TRANS, are located in the network local LAN, for example in the GW gateway or any other equipment capable of hosting such systems.
[0057] [Fig.2] illustrates in diagram form the steps of the UT user authentication method according to one embodiment. The UT user authentication method is implemented in a system SYS for authorizing access to the TER terminal management service (eg, TER terminal device maintenance service) (hereinafter referred to as the SYS authorization system).
[0058] [Fig.3A] and [Fig.3B] show exchanges occurring in different embodiments of this authorization system SYS. In [Fig.3A], the authorization system SYS comprises: the terminal device TER, the communication device COM, the management system SER_APP, the authentication system SER_AUTH and the transcription system SER_TRANS. In [Fig.3B], the authorization system SYS comprises: the terminal device TER, the communication device COM, the management system SER_APP, and the authentication system SER_AUTH.
[0059] According to one embodiment, during a step 201, denoted AUTH_TER, the terminal device TER authenticates itself with the authentication system SER_AUTH (i.e. unidirectional authentication), in order to allow the terminal device TER to be recognized as a trusted terminal device.
[0060] In order to authenticate itself with the SER_AUTH authentication system, the TER terminal device transmits a message comprising information allowing the latter to be recognized, then authenticated by the SER_AUTH authentication system. This information is, for example, a private key provided to the TER terminal device in the factory and allowing it to affix an authenticatable signature using a public key. For this, the SER_AUTH authentication system has in memory a list of TER terminal devices, authorized to access services of a service provider (e.g., maintenance service), as well as their associated public keys.
[0061] In a preferred variant, during a step 2011, denoted AUTH_SER_AUTH, the authentication system SER_AUTH is also authenticated with the terminal device TER (i.e., mutual authentication). For this, in one example, the authentication system SER_AUTH transmits, in a message, an authenticatable signature (generated using a private key) allowing recognition with the terminal device TER (using a public key associated with the private key). Thus, the terminal device TER and the authentication system SER_AUTH mutually authenticate themselves with each other.
[0062] The public keys useful to the TER terminal device and to the SER_AUTH authentication system can be stored in memory at the factory, or previously exchanged between the devices and systems involved.
[0063] When the terminal device TER has malfunctions, the user UT has the possibility of requesting access to a management service (e.g., maintenance service) which manages the terminal device TER and which is accessible via the management system SER_APP. Thus, in order to remedy the malfunctions of his terminal device TER, the user UT requests access to the management system SER_APP, for access to the management service. For this, the user UT must authenticate himself with the management service. In particular, as described below, the user UT must authenticate himself via a PAP type authentication protocol combined with a challenge / response type authentication protocol.
[0064] For this, during a step 202, denoted ACC_SER_APP, the user UT requests access to the management system SER_APP via his communication device COM, for example via a dedicated application on his smartphone. For this, the user UT enters his authentication information, and the communication device COM transmits to the management system SER_APP a request for access to the management service which includes the authentication information entered by the user UT (eg, identifier and password which are supposed to correspond to the profile of the user UT). This request for access to the management service can be secured, for example by using a secure protocol such as the HTTPS protocol (Hyper Text Transfer Protocol Secure).
[0065] In one embodiment, during this step 202 ACC_SER_APP, the SER_APP management system executes the PAP type authentication protocol by authenticating the user UT using his authentication information.
[0066] During a step 203, denoted DEL_AUTH, upon receipt of the request for access to the management service, the management system SER_APP transmits to the authentication system SER_AUTH a delegation request which delegates the authentication of the user UT to the authentication system SER_AUTH. In particular, according to one embodiment, the management system SER_APP delegates the authentication of the user UT for the execution of the challenge / response type authentication protocol.
[0067] In another embodiment, the SER_APP management system delegates the authentication of the user for the execution of the PAP type and challenge / response type authentication protocol to the SER_AUTH authentication server.
[0068] For this, the delegation request includes the authentication information of the user UT previously transmitted from the communication device COM to the management system SER_APP, which avoids the user UT having to resubmit this authentication information to the authentication system SER_AUTH. Thus, the authentication system SER_AUTH is specifically used for verify the identity of the UT user when the UT user needs to prove his identity to the SER_APP management system. For example, this delegation of authentication is carried out in accordance with the OAuth protocol (“Open Authentication” in English).
[0069] The delegation request further comprises identification information making it possible to identify the terminal device TER for which the user UT requests access to the management service. This identification information is, for example, a serial number or a MAC address of the terminal device TER. This identification information may be: - either hosted on the SER_APP management system, for example, in the form of a list of terminal devices each associated with its identification information, this list also being associated with the UT user profile, - either transmitted in the request for access to the management service, together with the authentication information of the UT user. In one example, the identification information of the TER terminal device can be retrieved by the UT user by means of a QR-Code to be scanned on the TER terminal device by means of the COM communication device.
[0070] In the case where the identification information is hosted in the form of a list on the SER_APP management system in association with the profile of the UT user, the UT user can, for example, choose from this list of terminal devices (TER), via his communication device (COM), the terminal device (TER) concerned by the malfunction.
[0071] From this identification information of the terminal device TER, the management system SER_APP is able to transmit the delegation request to the appropriate authentication system SER_AUTH among a set of authentication systems (eg, each authentication system is responsible for a batch of terminal devices which is specific to it).
[0072] During a step 204, denoted ENV_CV, upon receipt of the delegation request from the management system SER_APP, the authentication system SER_AUTH transmits a message comprising an authentication token CV to the communication device COM. The transmission of this authentication token CV is carried out as part of the authentication of the user UT via the challenge / response type authentication protocol. This transmitted authentication token CV is, for example, a verification code consisting of letters and / or numbers, in particular so as to form one or more words, a 6-digit code, etc. This verification code is adapted to be dictated (i.e., spoken aloud) by the user UT.
[0073] According to one embodiment, this CV authentication token is valid for a predetermined duration and / or until an end of validity date, beyond which it is replaced by a new authentication token. This validity period and / or this validity end date are transmitted by the SER_AUTH authentication system to the COM communication device, in the same message as the CV authentication token. Thus, in one embodiment, the COM communication device monitors this validity period and / or this validity end date in order to determine when they have expired. In the case where the validity period and / or the validity end date have expired, then the COM communication device requests a new authentication token from the SER_AUTH authentication system, if the previous CV authentication token expires before being validated by the SER_AUTH authentication server.
[0074] During a step 205, noted AFF_CV, upon receipt of the authentication token CV, the communication device COM displays it, for example on a screen, to allow the user UT to read it and pronounce it aloud.
[0075] In the context of authentication according to the challenge / response protocol, the display of the authentication token CV (i.e., the challenge) by the communication device COM allows the user UT to resolve this challenge, without having to use any peripheral equipment of the terminal device TER, for example the television TV1.
[0076] According to a preferred embodiment, the message comprising the authentication token CV further comprises an indication, to be displayed to the user UT, to activate sound capture means of the terminal device TER. In one example, this indication asks the user UT to press a physical button preferably located on a front part of the terminal device TER. This indication makes it possible to best support the user UT given that the way of activating the sound capture means of the terminal device TER may be different from one terminal device TER to another (e.g. indication of the location of the button).
[0077] In a variant, the message does not include any particular indication; it is directly the communication device COM (e.g., via a dedicated application) which displays this indication to activate the sound capture means upon receipt of the message including the authentication token CV.
[0078] In another variant presented in connection with [Fig.3B] and [Fig.4B], in the case where the terminal device TER is equipped with a voice recognition module VOC 407, the activation of the sound capture means is carried out upon detection of a voice command from the user UT.
[0079] During a step 206, denoted ENR_VOC, when the sound capture means of the terminal device TER are activated (eg, microphones), then the user UT can read aloud the verification token CV displayed by his communication device COM. The vocalization of the authentication token CV by the user UT is captured by the sound capture means of the terminal device TER so as to obtain a digital voice recording, i.e. a dictated authentication token CD, assumed to correspond to the transmitted CV authentication token. This voice recording (i.e., dictated authentication token CD) is then stored in a memory of the TER terminal device. Thus, the resolution of the challenge is done via the vocalization of the CV authentication token displayed by the COM communication device and by using the sound capture means of the TER terminal device (e.g. microphones) to record this vocalization.
[0080] By using the communication device COM as a substitute for the peripheral equipment associated with the terminal device TER, it is possible to authenticate the user UT by performing this “multi-factor” authentication (MFA or “Multifactor Authentication” in English) (i.e., use of the PAP authentication protocol in combination with the challenge / response authentication protocol). The challenge (i.e., CV authentication token) can be displayed and then resolved vocally by the user UT, even in the event of a malfunction of the terminal device TER rendering its own peripheral equipment unusable.
[0081] According to one embodiment, when the terminal device TER is considered to be a trusted device, because previously authenticated with the authentication system SER_AUTH during step 201, an authentication "multifactor" is achieved for the TER terminal device thanks to the sound recording of the response to the challenge in voice form.
[0082] In a first embodiment presented in connection with [Fig.3A], during a step 207, noted TRANS_VOC_CV, the terminal device TER transmits, via the gateway GW, to a transcription system SER_TRANS the voice recording corresponding to the dictated authentication token CD.
[0083] Upon receipt of this voice recording, the transcription system SER_TRANS performs a text transcription of the voice recording. A text transcription, called a transcribed authentication token CT, corresponding to the dictated authentication token CD is thus obtained.
[0084] In a second embodiment, presented in connection with [Fig.3B], during step 207, denoted TRANS_VOC_CV, it is the terminal device TER which performs the transcription of the voice recording. Thus, in a variant of step 207 TRANS_VOC_CV, the terminal device TER transcribes, by means of an embedded VOC voice recognition module 407, the voice recording corresponding to the dictated authentication token CD into a transcribed authentication token CT.
[0085] During a step 208, denoted TRANS_CT, the transcribed authentication token CT is transmitted to the authentication system SER_AUTH. According to the first embodiment presented in connection with [Fig.3A], the transmission of the transcribed authentication token CT is carried out by the transcription system SER_TRANS. According to the second embodiment presented in connection with [Fig.3B], the transmission of the transcribed authentication token CT is carried out by the terminal device TER, via the gateway GW.
[0086] During a step 209, noted C0M_CV-CT, the authentication system SER_AUTH compares the transcribed authentication token CT to the authentication token CV previously transmitted to the communication device COM during step 204 ENV_CV.
[0087] If a level of similarity (eg, expressed as a percentage) between the transcribed authentication token CT and the authentication token CV is greater than or equal to a predefined threshold (eg, greater than or equal to 60%, preferably greater than or equal to 80%), then the authentication system SER_AUTH determines that the transcribed authentication token CT corresponds (step 209, result “yes”) to the transmitted authentication token CV.
[0088] On the contrary (step 209, result “no”), if the level of similarity between the transcribed authentication token CT and the authentication token CV is lower than the predefined threshold (e.g., lower than 60%, preferably lower than 80%), then the authentication system SER_AUTH determines that the transcribed authentication token CT does not correspond to the transmitted authentication token CV. In this case, during a step 211, noted AUTH_UT_Err, the authentication system SER_AUTH was unable to authenticate the user UT. The user UT is denied access to the management service of the terminal device TER. In other words, the user UT is not authorized to communicate with the management system SER_APP and consequently cannot benefit from the management service (e.g., maintenance service).
[0089] On the contrary, when the transcribed authentication token CT corresponds to the transmitted authentication token CV, then during a step 210, noted AUTH_UT_ok, the authentication system SER_AUTH validates the authentication of the user UT with the management system SER_APP. For this, the authentication system SER_AUTH sends an authentication validation message to the management system SER_APP, for example according to the OAuth protocol.
[0090] During a step 212, denoted ACC_SER, an authorized and secure communication channel (or “secure communication channel” hereinafter) is set up. It is thus possible to carry out a maintenance method for the TER terminal device. This maintenance method therefore comprises: - authentication of the user UT according to the authentication method described in connection with the different embodiments of Figs. 2, 3A, 3B, and - performing a maintenance operation on the TER terminal device, when the user is authenticated and access to the management service is authorized.
[0091] Such a maintenance operation includes, for example: a diagnosis of the malfunctions of the TER terminal device, repair operations or resolution of identified malfunctions.
[0092] In one embodiment, when the user UT has been validly authenticated, a secure communication channel is set up between the management system SER_APP and the communication device COM, in order to secure the subsequent maintenance operations towards the terminal device TER.
[0093] According to this embodiment, the maintenance operations are carried out by the user UT who communicates with the management system SER_APP via his communication device COM. In one example, the management system SER_APP sends instructions to the user UT on the communication device COM to diagnose and then repair the identified malfunctions.
[0094] In another embodiment, alternatively or additionally, a secure communication channel is also set up between the SER_APP management system and the TER terminal device. Thus, the SER_APP management system can communicate directly, in a secure manner, with the TER terminal device so as to obtain configuration information from the TER terminal device to enable the SER_APP management system to establish and / or carry out these maintenance operations. For example, it is the SER_APP management system which diagnoses malfunctions alone or in collaboration with the UT user, and proposes repair actions to be carried out by the UT user or by himself.
[0095] The vocal resolution of the challenge allowed the UT user to implicitly consent to the SER_APP management system connecting directly to the TER terminal device and accessing his personal data to send them back to the SER_APP management system, to carry out diagnostics and repair operations for the identified malfunctions.
[0096] In one example, this configuration information and personal data are transmitted from the TER terminal device to the SER_APP management system according to the TR-069 protocol (e.g., “Technical Report” protocol or CWMP protocol for “CPE WANManagement Protocol” in English). This TR-069 protocol is commonly used to send information such as logs, incidents, from the TER terminal device to the servers (e.g., key servers, VOD servers) dedicated to the operation of the TER terminal device, and to send commands for updating, rebooting, or modifying the configuration parameters of the TER terminal device.
[0097] [Fig.4A] schematically illustrates the hardware architecture of the TER terminal device configured to execute all or part of the steps of the authentication method according to the first embodiment illustrated in [Fig.3A], and [Fig.4B] schematically illustrates the hardware architecture of the TER terminal device configured to execute all or part of the steps of the authentication method according to the second embodiment illustrated in [Fig.3B].
[0098] The terminal device TER according to [Fig.4A] or 4B comprises, connected by a communication bus 410: a processor or CPU (“Central Processing Unit” in English) 401; a RAM (“Random Access Memory” in English) 402; a ROM (“Read Only Memory” in English) 403, for example a Flash memory; a data storage device, such as a hard disk HDD (“Hard Disk Drive” in English), or a storage media reader, such as an SD (“Secure Digital” in English) card reader 404; at least one communication interface 1 / 1' 405. This communication interface I / f 405 allows the terminal device TER to interact with the other elements of the authorization system SYS, i.e.: the communication device COM, the authentication system SER_AUTH and the management system SER_APP, and where applicable, the transcription system SER_TRANS.
[0099] The terminal device TER according to [Fig.4A] or 4B further comprises, connected by the communication bus 410: a sound recording module REC 406, which comprises sound capture means (eg, microphone) configured to capture the sounds emitted in the environment of the terminal device TER (in particular the voice of the user UT) and which is configured to record the sounds captured by the sound capture means.
[0100] According to the second embodiment presented in [Fig.4B], the terminal device TER further comprises, connected by the communication bus 410: a voice recognition module VOC 407 configured to transcribe one or more words and / or numbers spoken aloud by the user UT.
[0101] In one embodiment, the terminal device TER comprises a physical button (not shown in Figs. 4A and 4B) preferably located on a front part of the terminal device TER. The button is connected to a switch to activate the sound capture means and trigger the sound recording by the recording module REC 406. In a variant, when the terminal device TER comprises a voice recognition module VOC 407 (see [Fig.4B]), the activation of the sound capture means is carried out upon detection of a voice command from the user UT.
[0102] The processor 401 is capable of executing instructions loaded into the RAM 402 from the ROM 403, from an external memory (not shown), from the data storage device 404, such as an SD card, or from a communication network (not shown). When the terminal device TER is powered on, the processor 401 is capable of reading instructions from the RAM 402 and executing them. These instructions form a computer program causing the processor 401 to implement, of a portion of the behaviors, steps and algorithms described herein, particularly in combination with a portion of the steps of Figs. 2 and 3A or 3B. Generally, the TER terminal device comprises electronic circuitry arranged and configured to implement the behaviors, steps and algorithms relating thereto described herein.
[0103] All or part of the behaviors, steps and algorithm described here can thus be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (“Digital Signal Processor” in English) or a microcontroller, or be implemented in hardware form by a machine or a dedicated component (“chip” in English) or a set of components (“chipset” in English) dedicated, such as an FPGA (“Field-Programmable Gate Array” in English) or an ASIC (“Application-Specific Integrated Circuit” in English).
[0104] It should further be noted that the term “module” can correspond to either a software component or a hardware component, or to a combination of the two.
[0105] In a particular embodiment, the terminal device TER can embed in its software layers an artificial intelligence module (not shown in Figs. 4A and 4B) intended to guide the user UT in resolving technical problems related to the use of the terminal device TER and its peripheral equipment (eg, television screen TV1). This functionality can be implemented in the form of a “chat-bot” in expert mode that can interact directly with the management system SER_APP, as soon as the secure communication channel is established in step 212 ACC_SER.
Claims
Claims
1. Method for authenticating a user (UT) to authorize access to a management service of a terminal device (TER), the terminal device (TER) being connected to a local area network (LAN), the local area network (LAN) being managed by a gateway (GW) for access to a wide area network (WAN), a communication device (COM) and the terminal device (TER) having access to an authentication system (SER_AUTH) and to a management system (SER_APP), the method comprising: - executing a phase of authentication of the user (UT) comprising (i) receiving (204), by the communication device (COM), from the authentication system (SER_AUTH), a message comprising an authentication token (CV), (ii) displaying (205), by the communication device (COM), the authentication token (CV), (iii) generating (206), by the terminal device (TER),a voice recording corresponding to a pronunciation by the user (UT) of the authentication token (CV) displayed by the communication device (COM), (iv) authenticating (210) the user (UT), by the authentication system (SER_AUTH), when a level of similarity between a text transcription of the authentication token (CT) from the voice recording, and said authentication token (CV) is greater than or equal to a predefined threshold, - and, when the user (UT) is authenticated, executing a phase of authorization of access to the management service comprising: establishing (212), by the management system (SER_APP), a secure communication channel between the management system (SER_APP) and the communication device (COM) and / or the terminal device (TER).,
2. Method according to claim 1, in which the user authentication phase (UT) comprises: receiving, by the authentication system (SER_AUTH) from the management system (SER_APP), a request for delegation of authentication of the user (UT), so that the authentication system (SER_AUTH) transmits to the communication device (COM) said message comprising the authentication token (CV), said delegation request comprising at least one piece of authentication information associated with a user profile (UT).
3. Method according to one of claims 1 and 2, in which the user authentication phase (UT) comprises: receiving, by the management system (SER_APP) from the communication device (COM), a request for access to the management service comprising identification information for the terminal device (TER).
4. Method according to any one of claims 1 to 3, in which the communication device (COM) displays an indication of activation of a sound capture means of the terminal device (TER).
5. Method according to any one of claims 1 to 4, in which the user authentication phase (UT) further comprises: - obtaining (208), by the authentication system (SER_AUTH), the text transcription of the authentication token (CT) from the voice recording, - comparing (209), said text transcription (CT) with the authentication token (CV) transmitted by the authentication system (SER_AUTH) to the communication device (COM), and - determining the level of similarity between said text transcription (CT) and said authentication token (CV).
6. Method according to claim 5, in which, to obtain (207) the text transcription of the authentication token (CT) from the voice recording, the method comprises the following steps executed by a transcription system (SER_TRANS): - receiving, from the terminal device (TER), the voice recording corresponding to the pronunciation by the user (UT) of the authentication token (CV) displayed by the communication device (COM), and - transcribing (207) said voice recording to obtain said text transcription (CT), - transmitting (208) to the authentication system (SER_AUTH), said text transcription (CT).
7. Method according to claim 5, in which, to obtain (208) the text transcription of the authentication token (CT) from the voice recording, the method comprises the following steps executed by the terminal device (TER): - transcribing (207) the voice recording corresponding to the pronunciation by the user (UT) of the authentication token (CV) displayed by the communication device (COM) to obtain the transcription textual transcription (CT) of the authentication token (CT) from the voice recording, - transmit (208) to the authentication system (SER_AUTH), said textual transcription (CT).
8. Method according to any one of claims 1 to 7, further comprising, prior to the user authentication phase (UT): - authenticating (201), by the authentication system (SER_AUTH), the terminal device (TER).
9. Method according to claim 8, further comprising, prior to the user authentication phase: - authenticating (2011), by the terminal device (TER), the authentication system (SER_AUTH).
10. Method according to any one of claims 1 to 9, wherein the message comprising the authentication token (CV) further comprises a validity period and / or an end date of validity of said predefined authentication token (CV), the communication device (COM) monitoring the validity period and / or the end date of validity so as to request sending of a new authentication token (CV) when the validity period and / or the end date of validity has expired.
11. Method according to any one of claims 1 to 10, wherein the terminal device (TER) has access to the authentication system (SER_AUTH) and the management system (SER_APP) via access to the wide area network (WAN) by the gateway GW.
12. Method for maintaining a terminal device (TER) connected to a local area network (LAN), the local area network (LAN) being managed by a gateway (GW) for access to a wide area network (WAN), a communication device (COM) and the terminal device (TER) having access to an access authentication system (SER_AUTH) and to a management system (SER_APP), said method comprising: - authenticating the user (UT) by executing the authentication method according to any one of claims 1 to 11, - performing a maintenance operation on the terminal device (TER), when the user is authenticated and access to the management service is authorized.
13. System (SYS) for authorizing access to a management service, comprising: a terminal device (TER), a communication device (COM), a management system (SER_APP) of the terminal device (TER) and an authentication system (SER_AUTH), the terminal device (TER) being connected to a local area network (LAN), the local area network (LAN) being managed by a gateway (GW) for access to a wide area network (WAN), the communication device (COM) and the terminal device (TER) having access to the authentication system (SER_AUTH) and to the management system (SER_APP), the system (SYS) for authorizing access to the management service comprises electronic circuitry configured to: - execute a user authentication phase (UT) including (i) receiving (204), by the communication device (COM), from the authentication system (SER_AUTH), a message comprising an authentication token (CV), (ii) displaying (205), by the communication device (COM), the authentication token (CV), (iii) generating (206), by the terminal device (TER), a voice recording corresponding to a pronunciation by the user (UT) of the authentication token (CV) displayed by the communication device (COM), (iv) authenticate (210) the user (UT), by the authentication system (SER_AUTH), when a level of similarity between a text transcription of the authentication token (CT) from the voice recording, and said authentication token (CV) is greater than or equal to a predefined threshold, - and, when the user (UT) is authenticated, execute a phase of authorization of access to the management service comprising: establishing (212), by the management system (SER_APP), a secure communication channel between the management system (SER_APP) and the communication device (COM) and / or the terminal device (TER).
14. System (SYS) according to claim 13, wherein the terminal device (TER) is a voice-controlled audio and video stream decoder, and the communication device (COM) is a smartphone or an electronic tablet or a laptop.
15. Terminal device (TER) intended to belong to a local area network (LAN) managed by a gateway (GW), said terminal device (TER) comprising electronic circuitry configured to: - generate (206) a voice recording corresponding to a pronunciation by a user (UT) of an authentication token (CV) to authorize access to a management service of the terminal device (TER); - transcribing (207) said voice recording to obtain a text transcription (CT) of the authentication token (CT) at the end of the voice recording; and - transmitting (208) to an authentication system (SER_AUTH), said text transcription (CT) via said gateway (GW).
Citation Information
Patent Citations
Authentication method, access authorisation method, terminal, server, radio-tag component, product, computer program product and corresponding storage medium
EP3062538A1
Bluetooth voice pairing apparatus and method
EP3226585A1
Voice-based verification for multi-factor authentication challenges
WO2020112322A1