WO2002065253A3 - Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers - Google Patents

Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers Download PDF

Info

Publication number
WO2002065253A3
WO2002065253A3 PCT/CH2002/000072 CH0200072W WO02065253A3 WO 2002065253 A3 WO2002065253 A3 WO 2002065253A3 CH 0200072 W CH0200072 W CH 0200072W WO 02065253 A3 WO02065253 A3 WO 02065253A3
Authority
WO
WIPO (PCT)
Prior art keywords
access
user
data bank
chipcard
data
Prior art date
Application number
PCT/CH2002/000072
Other languages
English (en)
French (fr)
Other versions
WO2002065253A2 (de
Inventor
Friedrich Kisters
Original Assignee
Human Bios Gmbh
Friedrich Kisters
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Human Bios Gmbh, Friedrich Kisters filed Critical Human Bios Gmbh
Priority to DE50201014T priority Critical patent/DE50201014D1/de
Priority to US10/467,508 priority patent/US7447910B2/en
Priority to AT02716033T priority patent/ATE276541T1/de
Priority to EP02716033A priority patent/EP1358533B1/de
Publication of WO2002065253A2 publication Critical patent/WO2002065253A2/de
Publication of WO2002065253A3 publication Critical patent/WO2002065253A3/de

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
    • G07F7/1008Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2153Using hardware token as a secondary aspect

Abstract

Bein Zugriff auf vertrauliche Daten bzw. Bereiche eines EDV-Systems (2) durch einen Benutzer (9), wird diesem der Zugriff nur gewährt, wenner sich mit Benutzernamen und Passwort kkorrekt beim EDV-System anmeldet (16) und sich darüber hinaus mit einem nur ihm zugänglichen Zugangscode (21) aus einer Datenbank (5.2) als zugangsberechtigt ausweisen kann. Die Datenbank ist auf einer Chipkarte (5) abgespeichert und der Zugriff auf die Daten bank ist doppelt abgesichert. Zugriff auf die Zugangscodes in der Datenbank erhält nur derjenige Benutzer, der sich korrekt, beispielsweise mittels biometrischer Daten, gegenüber der Chipkarte authentifizieren kann (12). Zudem kann der Zugriff auf die Zugangscodes in der Katenbank nur durch ein auf der Chipkarte abgespeichertes Programm (5.1) erfolgen, das sich erst nach einer korrekten Authentifizierung durch den Benutzer gegenüber der Chipkarte aktivieren lässt und das sich direkt auf der Datenbank mittels einer im Programmcode eingebauten ID korrekt authentifiziert haben muss (20).
PCT/CH2002/000072 2001-02-09 2002-02-07 Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers WO2002065253A2 (de)

Priority Applications (4)

Application Number Priority Date Filing Date Title
DE50201014T DE50201014D1 (de) 2001-02-09 2002-02-07 Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers
US10/467,508 US7447910B2 (en) 2001-02-09 2002-02-07 Method, arrangement and secure medium for authentication of a user
AT02716033T ATE276541T1 (de) 2001-02-09 2002-02-07 Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers
EP02716033A EP1358533B1 (de) 2001-02-09 2002-02-07 Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
EP01810138A EP1231531A1 (de) 2001-02-09 2001-02-09 Verfahren, Anordnung und Sicherheitsmedium zur Benutzer-Authentifikation beim Zugriff auf vertrauliche Daten
EP01810138.6 2001-02-09

Publications (2)

Publication Number Publication Date
WO2002065253A2 WO2002065253A2 (de) 2002-08-22
WO2002065253A3 true WO2002065253A3 (de) 2003-01-09

Family

ID=8183724

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CH2002/000072 WO2002065253A2 (de) 2001-02-09 2002-02-07 Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers

Country Status (5)

Country Link
US (1) US7447910B2 (de)
EP (2) EP1231531A1 (de)
AT (1) ATE276541T1 (de)
DE (1) DE50201014D1 (de)
WO (1) WO2002065253A2 (de)

Families Citing this family (52)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6948135B1 (en) 2000-06-21 2005-09-20 Microsoft Corporation Method and systems of providing information to computer users
US7000230B1 (en) 2000-06-21 2006-02-14 Microsoft Corporation Network-based software extensions
US7155667B1 (en) * 2000-06-21 2006-12-26 Microsoft Corporation User interface for integrated spreadsheets and word processing tables
US6883168B1 (en) 2000-06-21 2005-04-19 Microsoft Corporation Methods, systems, architectures and data structures for delivering software via a network
US7624356B1 (en) 2000-06-21 2009-11-24 Microsoft Corporation Task-sensitive methods and systems for displaying command sets
US7191394B1 (en) 2000-06-21 2007-03-13 Microsoft Corporation Authoring arbitrary XML documents using DHTML and XSLT
US7346848B1 (en) 2000-06-21 2008-03-18 Microsoft Corporation Single window navigation methods and systems
US20040111625A1 (en) * 2001-02-14 2004-06-10 Duffy Dominic Gavan Data processing apparatus and method
GB0113255D0 (en) * 2001-05-31 2001-07-25 Scient Generics Ltd Number generator
NO316489B1 (no) 2001-10-01 2004-01-26 Genkey As System, b¶rbar anordning og fremgangsmåte for digital autentisering, kryptering og signering ved generering av flyktige, men konsistente ogrepeterbare kryptonökler
GB0228434D0 (en) * 2002-12-05 2003-01-08 Scient Generics Ltd Error correction
DE60309176T2 (de) * 2002-05-31 2007-09-06 Scientific Generics Ltd., Harston Biometrisches authentifizierungssystem
EP1418483A1 (de) * 2002-08-23 2004-05-12 Siemens Aktiengesellschaft Überprüfung und Einräumung von Nutzungsberechtigungen
DK200300384A (da) 2003-03-13 2004-09-14 Quard Technology I S Selvgodkendende Biometrisk anordning med Dynamisk PIN kode skabelse
US7415672B1 (en) 2003-03-24 2008-08-19 Microsoft Corporation System and method for designing electronic forms
US7370066B1 (en) 2003-03-24 2008-05-06 Microsoft Corporation System and method for offline editing of data files
US7296017B2 (en) 2003-03-28 2007-11-13 Microsoft Corporation Validation of XML data files
US7913159B2 (en) 2003-03-28 2011-03-22 Microsoft Corporation System and method for real-time validation of structured data files
JP4240293B2 (ja) * 2003-05-27 2009-03-18 株式会社ソニー・コンピュータエンタテインメント マルチメディア再生装置およびマルチメディア再生方法
US7451392B1 (en) 2003-06-30 2008-11-11 Microsoft Corporation Rendering an HTML electronic form by applying XSLT to XML using a solution
US7406660B1 (en) 2003-08-01 2008-07-29 Microsoft Corporation Mapping between structured data and a visual surface
US7334187B1 (en) 2003-08-06 2008-02-19 Microsoft Corporation Electronic form aggregation
US8819072B1 (en) 2004-02-02 2014-08-26 Microsoft Corporation Promoting data from structured data files
DE102004014416A1 (de) * 2004-03-18 2005-10-06 Deutsche Telekom Ag Verfahren und System zur Personen/Sprecherverifikation über Kommunikationssysteme
US7496837B1 (en) 2004-04-29 2009-02-24 Microsoft Corporation Structural editing with schema awareness
US7281018B1 (en) 2004-05-26 2007-10-09 Microsoft Corporation Form template data source change
US7774620B1 (en) 2004-05-27 2010-08-10 Microsoft Corporation Executing applications at appropriate trust levels
GB0413034D0 (en) 2004-06-10 2004-07-14 Scient Generics Ltd Secure workflow engine
US7692636B2 (en) 2004-09-30 2010-04-06 Microsoft Corporation Systems and methods for handwriting to a screen
JP4664644B2 (ja) * 2004-10-08 2011-04-06 富士通株式会社 生体認証装置及び端末
US20060107067A1 (en) * 2004-11-15 2006-05-18 Max Safal Identification card with bio-sensor and user authentication method
US7712022B2 (en) 2004-11-15 2010-05-04 Microsoft Corporation Mutually exclusive options in electronic forms
US7584417B2 (en) * 2004-11-15 2009-09-01 Microsoft Corporation Role-dependent action for an electronic form
US7721190B2 (en) 2004-11-16 2010-05-18 Microsoft Corporation Methods and systems for server side form processing
US7904801B2 (en) 2004-12-15 2011-03-08 Microsoft Corporation Recursive sections in electronic forms
US7937651B2 (en) 2005-01-14 2011-05-03 Microsoft Corporation Structural editing operations for network forms
US7725834B2 (en) 2005-03-04 2010-05-25 Microsoft Corporation Designer-created aspect for an electronic form template
US8010515B2 (en) 2005-04-15 2011-08-30 Microsoft Corporation Query to an electronic form
US8200975B2 (en) 2005-06-29 2012-06-12 Microsoft Corporation Digital signatures for network forms
CN100405250C (zh) * 2005-10-21 2008-07-23 鸿富锦精密工业(深圳)有限公司 笔记本电脑的解密装置
US8001459B2 (en) 2005-12-05 2011-08-16 Microsoft Corporation Enabling electronic documents for limited-capability computing devices
IL178262A (en) * 2006-09-21 2013-06-27 Aser Rich Ltd Install and method of purchasing and storing digital content on a smart card
US8325989B2 (en) * 2007-09-24 2012-12-04 Accenture Global Services Limited Smart identity system
US20090260071A1 (en) * 2008-04-14 2009-10-15 Microsoft Corporation Smart module provisioning of local network devices
DE102009000408A1 (de) * 2009-01-26 2010-09-16 Bundesdruckerei Gmbh Lesegerät für eine Chipkarte und Computersystem
KR20110083889A (ko) * 2010-01-15 2011-07-21 삼성전자주식회사 데이터 저장장치에서 원격 제어에 따라 데이터를 처리하는 방법 및 그 장치
CN102404113A (zh) * 2010-09-08 2012-04-04 中国银联股份有限公司 安全性信息交互方法及系统
DE102014004347A1 (de) * 2014-03-27 2015-10-15 Friedrich Kisters Authentifikationsverfahren und Authentifikationssystem
DE102014004349A1 (de) 2014-03-27 2015-10-15 Friedrich Kisters Authentifikationssystem
DE102014007976A1 (de) 2014-06-04 2015-12-31 Friedrich Kisters Sicherheitsvorrichtung und Authentifizierungsverfahren mit dynamischen Sicherheitsmerkmalen
DE102016220618A1 (de) 2016-10-20 2018-04-26 Volkswagen Aktiengesellschaft Verfahren zur Vergabe von Zugriffsberechtigungen auf Daten einer ersten Entität
NL2019349B1 (en) * 2017-07-26 2019-02-19 Northend Systems B V Methods and systems for providing access to confidential information

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE3736190A1 (de) * 1986-10-24 1988-05-05 Hitachi Ltd Zugriffssteuersystem und -verfahren fuer chip-karten
EP0715242A1 (de) * 1994-12-01 1996-06-05 Nippon Telegraph And Telephone Corporation Verfahren und System zum Schutz digitaler Informationen
GB2329497A (en) * 1997-09-19 1999-03-24 Ibm Controlling access to electronically provided data or services
US5995965A (en) * 1996-11-18 1999-11-30 Humetrix, Inc. System and method for remotely accessing user data records
US6044349A (en) * 1998-06-19 2000-03-28 Intel Corporation Secure and convenient information storage and retrieval method and apparatus
EP1004992A2 (de) * 1997-03-24 2000-05-31 Visa International Service Association System und Verfahren für eine Mehranwendungschipkarte zum Vereinfachen des Fernladens einer Anwendung nach der Kartenausgabe

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE3736190A1 (de) * 1986-10-24 1988-05-05 Hitachi Ltd Zugriffssteuersystem und -verfahren fuer chip-karten
EP0715242A1 (de) * 1994-12-01 1996-06-05 Nippon Telegraph And Telephone Corporation Verfahren und System zum Schutz digitaler Informationen
US5995965A (en) * 1996-11-18 1999-11-30 Humetrix, Inc. System and method for remotely accessing user data records
EP1004992A2 (de) * 1997-03-24 2000-05-31 Visa International Service Association System und Verfahren für eine Mehranwendungschipkarte zum Vereinfachen des Fernladens einer Anwendung nach der Kartenausgabe
GB2329497A (en) * 1997-09-19 1999-03-24 Ibm Controlling access to electronically provided data or services
US6044349A (en) * 1998-06-19 2000-03-28 Intel Corporation Secure and convenient information storage and retrieval method and apparatus

Also Published As

Publication number Publication date
DE50201014D1 (de) 2004-10-21
EP1231531A1 (de) 2002-08-14
EP1358533B1 (de) 2004-09-15
US7447910B2 (en) 2008-11-04
WO2002065253A2 (de) 2002-08-22
EP1358533A2 (de) 2003-11-05
ATE276541T1 (de) 2004-10-15
US20040107367A1 (en) 2004-06-03

Similar Documents

Publication Publication Date Title
WO2002065253A3 (de) Verfahren, anordnung und sicherheitsmedium zur authentifizierung eines benutzers
US8102240B2 (en) Controller providing shared device access for access control systems
EP1910911B1 (de) Massenspeichereinrichtung mit nahfeldkommunikation
EP2153382B1 (de) Dynamisch programmierbarer rfid-transponder
JP4792405B2 (ja) 無線データ転送をするためのポータブルデータキャリア、外部装置、システムおよび方法
WO2003044721A3 (en) Transaction card system having security against unauthorized usage
WO2002011394A3 (en) Smart card security information configuration and recovery system
EP1676805A4 (de) Sicherheitssystem für aufzug
EP0924657A3 (de) Technik zur Fernüberprüfung der Identität mit einer persönlichen Identifizierungsvorrichtung
EP1402459B8 (de) Tragbare vorrichtung mit biometrisch basierter identifizierungsfaehigkeit
US7461264B2 (en) Method for automatic identification control and management
WO2001078021A3 (en) Biometric authentication card, system and method
WO2003040996A3 (en) Identity card and system for tracking the use of the card
NZ232106A (en) Secure data interchange system: verification of card, terminal and user validity
CA2418758A1 (en) Interactive and/or secure activation of a tool
WO2001072224A1 (en) An arrangement and a method for checking the identity of a person
AU2003213634A1 (en) Identification card manufacturing security
WO2001091057A3 (en) Fingerprint activated remote input device for personal id recognition and access authentication
JP2006351015A (ja) 記憶装置及びその記憶データの保護方法
AU6437800A (en) Method, data carrier and system for authentication of a user and a terminal
WO2002008974A3 (en) Improvements relating to the security of authentication systems
JP4687045B2 (ja) 認証装置およびその方法
EP1310855A3 (de) System und Verfahren zur Datenfolgenauthentisierung
WO2002069281A2 (en) Chip reader and identification method for verifying the user authorisation of a chip user
JP2010152841A (ja) 個人認証付電子決済カード及びそれを使用した電子決済方法

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ OM PH PL PT RO RU SD SE SG SI SK SL TJ TM TN TR TT TZ UA UG US UZ VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
AK Designated states

Kind code of ref document: A3

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ OM PH PL PT RO RU SD SE SG SI SK SL TJ TM TN TR TT TZ UA UG US UZ VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A3

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

WWE Wipo information: entry into national phase

Ref document number: 2002716033

Country of ref document: EP

WWP Wipo information: published in national office

Ref document number: 2002716033

Country of ref document: EP

REG Reference to national code

Ref country code: DE

Ref legal event code: 8642

WWE Wipo information: entry into national phase

Ref document number: 10467508

Country of ref document: US

WWG Wipo information: grant in national office

Ref document number: 2002716033

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: JP

WWW Wipo information: withdrawn in national office

Country of ref document: JP