IP Library Granted Patent US 10,693,854
Granted Patent B2
US 10,693,854 · App. 14/968,231 · Granted Jun 23, 2020

Method for authenticating a user, corresponding server, communications terminal and programs

Inventor: David Naccache (Paris, FR)
Assignee: INGENICO GROUP
H04L63/08G06Q20/401H04L63/0853H04W4/80H04W12/06H04L63/0884H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,693,854
App. No.
14/968,231
Granted
Jun 23, 2020
Kind
B2
Abstract

A method is provided for authenticating a user's communications terminal with an authentication server connected to a gateway terminal by using a communications network. The method includes: obtaining a piece of data representing an identity of the user from the gateway terminal; configuring, by the authentication server, a data transmission link between the authentication server and the terminal, using a predefined data transmission interface of the gateway terminal and as a function of the piece of data representing the identity of the user; transmitting, by the authentication server, to the terminal, a piece of encrypted data for checking authentication, using the data transmission link; receiving, by the authentication user, coming from the terminal, a piece of encrypted data for counter-checking authentication; issuing an assertion of authentication of the user when the piece of data for the counter-checking of authentication corresponds to the piece of data for checking authentication.

Claims (39)

1. A method comprising:

authenticating a communications terminal belonging to a user with an authentication server connected to a gateway terminal by using a communications network, wherein the method comprises the following acts performed by the authentication server:

obtaining a piece of data representing an identity of the user from said gateway terminal;

carrying out a checking operation, directly or through a gateway application installed on said gateway terminal, to determine whether or not said gateway terminal comprises a Bluetooth physical interface;

and in response to determining that said gateway terminal comprises a Bluetooth physical interface:

configuring, by said authentication server, a data transmission link between said authentication server and said user's communications terminal, by using said Bluetooth physical interface of said gateway terminal and as a function of said piece of data representing an identity of the user, said data transmission link being a virtual Bluetooth link set up by transmitting a Bluetooth pairing code of the authentication server to the user's communications terminal, enabling pairing the user's communications terminal directly with the authentication server;

transmitting, by the authentication server, to the user's communications terminal, a piece of encrypted data for checking authentication, by using the data transmission link;

receiving, by the authentication server, coming from the user's communications terminal, a piece of encrypted data for counter-checking of authentication; and

issuing an assertion of authentication of the user in response to the piece of encrypted data for counter-checking of authentication corresponding to said piece of encrypted data for checking authentication.

2. The method according to claim 1 , wherein, prior to the act of obtaining a piece of data representing an identity of the user, said method comprises:

receiving a request for connection from said gateway terminal or from a server connected to said authentication server; and

transmitting, to said gateway terminal, a request for identification as a function of said request for connection.

3. The method according to claim 1 , wherein the act of configuration by said authentication server of a data transmission link between said authentication server and said user's communications terminal comprises:

obtaining at least one piece of data representing at least one parameter of connection to the communications terminal by using said piece of data representing said identity of the user;

transmitting said at least one piece of data representing a parameter of connection to said gateway terminal.

4. The method according to claim 3 , wherein said at least one parameter of connection comprises at least one piece of data necessary for building the link between the communications terminal of the user and the gateway terminal.

5. The method according to claim 3 , wherein said at least one parameter of connection comprises at least one piece of data belonging to a group consisting of:

a physical address of the user's communications terminal ;

a pairing code type piece of data;

a password type piece of data.

6. A server for authenticating a communications terminal belonging to a user with an authentication server connected to a gateway terminal by using a communications network wherein the server comprises:

a data processor; and

a non-transitory computer-readable medium comprising instructions stored thereon, which when executed by the processor configure the server to:

obtain a piece of data, from said gateway terminal, representing an identity of the user;

carrying out a checking operation, directly or through a gateway application installed on said gateway terminal, to determine whether or not said gateway terminal comprises a Bluetooth physical interface;

and in response to determining that said gateway terminal comprises a Bluetooth physical interface:

configure a data transmission link between said authentication server and said user's communications terminal, by using said Bluetooth physical interface of said gateway terminal and as a function of said piece of data representing an identity of the user, said data transmission link being a virtual Bluetooth link set up by transmitting a Bluetooth pairing code of the authentication server to the user's communications terminal, enabling pairing the user's communications terminal directly with the authentication server;

transmit, to the user's communications terminal, a piece of encrypted data for checking authentication by using the data transmission link;

receive a piece of encrypted data for counter-checking of authentication from the user's communications terminal; and

issue an assertion of authentication of the user in response to the piece of encrypted data for counter-checking of authentication corresponding to said piece of encrypted data for checking authentication.

7. A non-transitory computer-readable medium comprising program code instructions stored thereon to execute an operation for authenticating when the instructions are executed by a processor of an authentication server, wherein the operation comprises:

authenticating a communications terminal belonging to a user with the authentication server connected to a gateway terminal by using a communications network, wherein the authenticating the communications terminal comprises the following acts performed by the authentication server:

obtaining a piece of data representing an identity of the user from said gateway terminal;

carrying out a checking operation, directly or through a gateway application installed on said gateway terminal, to determine whether or not said gateway terminal comprises a Bluetooth physical interface;

and in response to determining that said gateway terminal comprises a Bluetooth physical interface:

configuring, by said authentication server, a data transmission link between said authentication server and said user's communications terminal, by using said Bluetooth physical interface of said gateway terminal and as a function of said piece of data representing an identity of the user, said data transmission link being a virtual Bluetooth link set up by transmitting a Bluetooth pairing code of the authentication server to the user's communications terminal, enabling pairing the user's communications terminal directly with the authentication server;

transmitting, by the authentication server, to the user's communications terminal, a piece of encrypted data for checking authentication, by using the data transmission link;

receiving, by the authentication server, coming from the user's communications terminal, a piece of encrypted data for counter-checking of authentication; and

issuing an assertion of authentication of the user in response to the piece of encrypted data for counter-checking of authentication corresponding to said piece of encrypted data for checking authentication.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2021
From: INGENICO GROUP
To: BANKS AND ACQUIRERS INTERNATIONAL HOLDING
Reel/Frame 058173/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2016
From: NACCACHE, DAVID
To: INGENICO GROUP
Reel/Frame 038082/0160 →
Cited By (1)
US 12,425,365