IP Library Patent Application 12760790
Patent Application
App. No. 12/760,790

METHOD FOR AUTHENTICATING A CLENT MOBILE TERMINAL WITH A REMOTE SERVER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/760,790
Abstract

The disclosure relates to a method and a device for authenticating a client mobile terminal on a remote server of said terminal, with said server sending a challenge to said mobile terminal in advance, said mobile terminal having to respond to the challenge, to authenticate at the same time, by transmitting a response consisting in encoding said challenge combined with a secret key known to said terminal and the same time to the server, wherein the secret key is hidden in a media file recorded in the mobile terminal using steganography.

Claims (66)

1 . A method for authenticating a client mobile terminal on a remote server of the terminal, the method comprising using the server to a challenge to the mobile terminal in advance, the mobile terminal having to respond to the challenge, to authenticate at the same time, by transmitting a response including encoding said challenge combined with a secret key known to the terminal and the same time to the server, and hiding the secret key in a media file recorded on the mobile terminal using steganography.

2 . A method according to claim 1 , further comprising:

sending an authentication request from the mobile terminal to the server;

sending a challenge from the server to the mobile terminal;

extracting the secret key from the media file by executing a reverse steganography algorithm at the mobile terminal;

generating:

a response to the challenge at the mobile terminal, as the response consists in encoding the challenge combined with the secret key using an encoding algorithm known to the server and the terminal;

a standard response to the challenge at the server, with the standard response including encoding the challenge combined with the secret key using the same encoding algorithm;

sending the response from the mobile terminal to the server;

comparing at the server, the response received with the standard response; and

authenticating the mobile terminal if the response matches the standard response.

3 . A method according to claim 1 , further comprising an initialisation phase comprising:

sending an initial request to download the resources of a computer application associated with a function from the mobile terminal to the server, as the request includes a client password known to the terminal and to the server;

authenticating the received client password, at the server and generating a secret key;

hiding the secret key in a media file at the server, by applying a steganography algorithm bootstrapped by the client password; and

transferring the resources of the computer application, including the media file containing the secret key, from the server to the mobile terminal.

4 . A method according to claim 2 , wherein the challenge comprises a random number and a time marker, in addition to the secret key, with the generation of the standard response at the mobile terminal and the standard response at the server consisting in encoding: the secret key, the random number and the time marker using an algorithm known to the server and terminal.

5 . A method according to claim 1 , in which:

multiple secret keys are associated with indexes in a table, with the latter being hidden in a media file recorded in the mobile terminal using steganography;

the challenge sent by the server includes an index from the table; and

the response sent by the mobile terminal includes the secret key associated with the index.

6 . A method according to claim 5 , further comprising:

sending an authentication request from the mobile terminal to the server;

sending a challenge comprising an index from the table from the server to the mobile terminal;

extracting, at the mobile terminal, the table from the media file by executing a reverse steganography algorithm, then extracting the secret key associated with the index from the table;

generating:

a response to the challenge at the mobile terminal, as the response includes encoding the challenge combined with the secret key associated with the index using an encoding algorithm known to the server and the terminal;

a standard response to the challenge at the server, with the standard response including encoding the challenge combined with the secret key associated with the index using the same encoding algorithm;

sending the response, from the mobile terminal to the server;

comparing at the server, the response received with the standard response; and

authenticating the mobile terminal if the response matches the standard response.

7 . A method according to claim 5 , comprising an initialisation phase comprising:

sending an initial request to download the resources of a computer application associated with a function from the mobile terminal to the server, as the request includes a client password known to the terminal and to the server;

authenticating the client password received, at the server, and generating a table associating the indexes with the secret keys;

hiding the table in a media file at the server, by executing a steganography algorithm bootstrapped by the client password; and

transferring the resources of the computer application, including the media file containing the table, from the server to the mobile terminal.

8 . A method according to claim 6 , wherein the challenge comprises a random number and a time marker, in addition to the index, with the generation of the response at the mobile terminal and the standard response at the server includes encoding: the secret key associated with the index, the random number and the time marker using an algorithm known to the server and terminal.

9 . A method according to claim 3 , wherein the media file is an image file, which is part of the resources of a computer application downloaded in the mobile terminal.

10 . A method according to claim 3 , wherein the media file is an audio file, which is part of the resources of a computer application downloaded in the mobile terminal.

11 . A method according to claim 3 , wherein the media file is a video file, which is part of the resources of a computer application downloaded in the mobile terminal.

12 . A method according to claim 1 , wherein the media file containing the secret key or the table is also recorded in the memory of the server.

13 . A method according to claim 12 wherein, before generating the standard response, the server extracts the secret key from the media file recorded in the memory thereof by executing a reverse steganography algorithm.

14 . A method according to claim 12 , wherein, before generating the standard response, the server extracts the table from the media file recorded in the memory thereof by executing a reverse steganography algorithm, then extracts the secret key associated with the index from the table.

15 . A method according to claim 1 , wherein the encoding algorithm, which makes it possible to generate the response at the mobile terminal and the standard response at the server, is a coding and encryption algorithm, which integrates a hashing function.

16 . A device for authenticating comprising a client mobile terminal with a remote server of the terminal, the server sending a challenge to the mobile terminal in advance, the mobile terminal being configured to respond to the challenge by transmitting a response including encoding the challenge combined with a secret key known to the terminal and the same time to the server, the secret key being hidden in a media file recorded in the mobile terminal using steganography.

17 . A device according to claim 16 , wherein:

the mobile terminal includes a memory area, where a media file is recorded, in which a table associating the indexes to the secret keys is hidden using steganography;

the server comprises a processor configured for sending a challenge including an index from the table; and

the mobile terminal comprises a processor configured to issue a response to the challenge, with the response including the challenge combined with the secret key associated with the index transmitted with the challenge.

18 . A device according to claim 17 , wherein:

the mobile terminal comprises a processor configured to:

send an authentication request to the server;

extract the table from the media file by applying a reverse steganography algorithm, and extract the secret key associated with an index transmitted by the server from the table;

execute an algorithm, which makes it possible to encode a challenge signal combined with the secret key associated with the index for generating a response to the challenge;

send a response to the server;

the server comprises a processor configured to:

generate and send a challenge signal comprising an index from the table to the mobile terminal;

execute an algorithm, which makes it possible to encode a challenge signal combined with the secret key associated with the index for generating a standard response to the challenge;

compare the response transmitted by the mobile terminal with the standard response; and

authenticating the mobile terminal if the response matches the standard response.

19 . A device according to claim 17 , wherein the server comprises a processor configured to:

generate the table associating the indexes with the secret keys;

execute a steganography algorithm, which makes it possible to hide the table in a media file; and

transfer this media file to the memory area of the mobile terminal.

20 . A mobile terminal intended to be used for implementing the method according to claim 1 , with the terminal comprising a memory area, where a media file is recorded, in which a secret key is hidden using steganography.

21 . A mobile terminal intended to be used for implementing the method according to claim 5 , with the terminal comprising a memory area, where a media file is recorded, in which a table associating the indexes with the secret keys is hidden using steganography.

Assignments (2)
CHANGE OF NAME AND ADDRESS Recorded Jan 7, 2013
From: MIYOWA
To: SYNCHRONOSS TECHNOLOGIES FRANCE
Reel/Frame 029576/0325 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2010
From: COLON, FRANCOIS
To: MIYOWA
Reel/Frame 024761/0845 →