IP Library › Granted Patent US 12,267,318
Granted Patent B2
US 12,267,318 · App. 17/416,114 · Granted Apr 1, 2025

Method and system for securing operations and associated user station

Inventor: Ghislain Moncomble (Châtillon, FR)
Assignee: ORANGE
H04L63/0838G06Q20/385H04L63/062H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,318
App. No.
17/416,114
Granted
Apr 1, 2025
Kind
B2
Abstract

A method for securing operations is described. In this method a user requests that a service provider device perform an operation, the service provider device transmitting to a certification device a request to validate the requested operation while indicating a key associated with the user. The certification device identifies the user associated with the key and transmits a dynamic code request to the user. A device that generates dynamic codes assigned to the user generates a first version of the dynamic code and transmits it to the certification device, which compares it with a second version of the code in order to decide whether it would or would not be appropriate to inform the service provider device that the requested operation has been validated.

Claims (52)

1. A method for securing operations, the method comprising:

formulating a request, by a user associated with a key generated by a certification body, to implement an operation with a service provider apparatus, the generated key comprising a component allowing identification of the certification body, the request including the key;

receiving, by a user station, a request for a dynamic code, the request for a dynamic code intended for the user associated with the key, the request for a dynamic code transmitted directly to the user from an apparatus of the certification body;

generating, by a dynamic code generator device associated with the key of the user, a first version of the dynamic code;

transmitting the first version of the dynamic code to the apparatus of the certification body; and

receiving, from the service provider apparatus, a message confirming the achievement of the requested operation, provided that the first version of the code corresponds to a second version of the dynamic code generated at the certification body when the apparatus of the certification body compares the first and second versions of the dynamic code.

2. The method of claim 1 , wherein the generation of the first version of the dynamic code by the dynamic code generator device is triggered by an action of the user.

3. The method of claim 2 , wherein biometric data of the user are detected during the action of the user that triggers the generation of a code, and wherein the first version of the dynamic code to the apparatus of the certification body is transmitted only upon validation of the detected biometric data.

4. The method of claim 1 , wherein the dynamic code includes a sub-code and evolution of the dynamic code includes a progressive change of each character of the sub-code according to a respective rule.

5. The method of claim 4 , wherein the characters of the sub-code are distributed among the other characters of the dynamic code.

6. A user station comprising a processor and a user interface configured to allow a user associated with a key generated by a certification body to formulate a request to implement an operation with a service provider apparatus, the generated key comprising a component allowing identification of the certification body, the request to implement an operation with a service provider apparatus including the key, the user station configured to;

receive a request for a dynamic code, the request for a dynamic code intended for the user associated with the key, the request for a dynamic code transmitted directly to the user from an apparatus of the certification body;

transmit to the certification apparatus a first version of the dynamic code generated by a dynamic code generator device associated with the key of the user; and

receive, from the service provider apparatus, a message confirming the achievement of the requested operation provided that the first version of the dynamic code corresponds to a second version of the dynamic code generated on the certification body side when the certification apparatus compares the first and second versions of the dynamic code.

7. The user station of claim 6 , further comprising a biometric data sensor, wherein the user station is further configured to:

upon activation by the user, trigger the generation of a code by the dynamic code generator device obtain biometric data of the user upon activation by the user, and

transmit the first version of the code to the certification apparatus only if the biometric data detected by the biometric data sensor during activation by the user are valid.

8. A system for securing operations, the system comprising a service provider apparatus and a certification apparatus of a certification body, wherein:

the service provider apparatus is configured to:

receive a request, from a user, to implement an operation, the request including a key associated with the user, the key generated by the certification body, the generated key comprising a component allowing identification of the certification body;

issue to the certification apparatus a request to validate the requested operation, the request indicating the key associated with the user, and

implement the requested operation following receipt of a validation signal from the certification apparatus; and

the certification apparatus is configured to:

issue a dynamic code request, intended for the user associated with the key, the dynamic code request transmitted directly to the user from the certification apparatus,

receive a first version of the dynamic code generated by a dynamic code generator device assigned to the user associated with the key,

acquire a second version of the dynamic code,

compare the first and second versions of the dynamic code, and

transmit a signal indicating the validation of the operation when the first and second versions of the dynamic code match.

9. A method for securing operations, wherein the method comprises:

sending a request, by a user associated with a key generated by a certification body, to implement an operation with a service provider apparatus, the generated key comprising a component allowing identification of the certification body, the request including the key;

issuing, by the service provider apparatus to a certification apparatus of a certification body, a request to validate the requested operation, the request indicating the key;

issuing a request for a dynamic code, intended for the user associated with the key, the request for a dynamic code transmitted directly to the user from the certification apparatus;

generating, by a dynamic code generator device assigned to the user associated with the key, a first version of the dynamic code;

transmitting the first version of the dynamic code to the certification apparatus;

acquiring a second version of the dynamic code and comparing the first and second versions of the dynamic code by the certification apparatus; and

upon confirmation that the first and second versions of the dynamic code match when the certification apparatus compares the first and second versions of the dynamic code, transmitting by the certification apparatus to the service provider apparatus, a signal indicating the validation of the operation requested from the user.

10. The method of claim 9 , wherein issuing the request to validate the operation comprises issuing a request including information on the requested operation, the method further comprising retrieving data of the user associated with the key, this data retrieval comprising:

retrieving verification data that indicates at least one restriction in relation to the permitted operations, and

analyzing the received information on the requested operation in order to determine whether this operation is permitted or not in relation to the verification data.

11. The method of claim 10 , wherein:

retrieving verification data comprises retrieving data defining at least one restriction chosen from the group consisting of:

the type of permitted operation,

the time period during which operations are permitted,

the geographical area where, or from which, operations are permitted,

the service provider with which operations are permitted, and

the price associated with the achievement of the operation.

12. The method of claim 11 , further comprising parameterizing,

by the user, restrictions defined by the verification data.

13. The method of claim 9 , wherein the method further comprises, if the first and second versions of the dynamic code do not correspond, implementing an iterative process comprising:

acquiring a new version of the dynamic code,

comparing the new version with the first version of the dynamic code, and repeating the steps of the iterative process as long as the result of the comparison is negative and until a number n of versions of the code have been acquired and compared with the first version of the code.

14. The method of claim 9 , wherein issuing a request for a dynamic code by the certification apparatus comprises transmitting to a station of the user a request for complementary information and the validation of the operation by the certification apparatus is conditional upon the complementary information provided by the user station.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2021
From: MONCOMBLE, GHISLAIN
To: ORANGE
Reel/Frame 058408/0051 →
Priority Claims (1)
FR 1874079 · Dec 21, 2018 · national
Continuity (1)
Related Publication 20220078183A1 · Mar 10, 2022
References Cited (39)
US 6067621A · Yu · 2000 [cited by examiner]
US 10552823B1 · Woodward · 2020 [cited by examiner]
US 10915891B1 · Winklevoss · 2021 [cited by examiner]
US 20030168509A1 · Nielsen · 2003 [cited by examiner]
US 20060020559A1 · Steinmetz · 2006 [cited by examiner]
US 20070203836A1 · Dodin · 2007 [cited by examiner]
US 20080103984A1 · Choe · 2008 [cited by examiner]
US 20090292641A1 · Weiss · 2009 [cited by examiner]
US 20090307142A1 · Mardikar · 2009 [cited by examiner]
US 20110184867A1 · Varadarajan · 2011 [cited by examiner]
US 20110219230A1 · Oberheide · 2011 [cited by examiner]
US 20130226799A1 · Raj · 2013 [cited by examiner]
US 20130273882A1 · Walsh · 2013 [cited by examiner]
US 20140229339A1 · Massiere · 2014 [cited by examiner]
US 20140245396A1 · Oberheide · 2014 [cited by examiner]
US 20140281506A1 · Redberg · 2014 [cited by examiner]
US 20140337175A1 · Katzin · 2014 [cited by examiner]
US 20140379575A1 · Rogan · 2014 [cited by examiner]
US 20150249540A1 · Khalil · 2015 [cited by examiner]
US 20150348044A1 · Smith · 2015 [cited by examiner]
US 20160300237A1 · Khan · 2016 [cited by examiner]
US 20170034141A1 · Oberheide · 2017 [cited by examiner]
US 20170085558A1 · Ibrahim · 2017 [cited by examiner]
US 20170279795A1 · Redberg · 2017 [cited by examiner]
US 20170323354A1 · Martell · 2017 [cited by examiner]
US 20170331801A1 · Mezei · 2017 [cited by examiner]
US 20180219851A1 · Woo · 2018 [cited by examiner]
US 20190034914A1 · Kumawat · 2019 [cited by examiner]
US 20190213585A1 · Patni · 2019 [cited by examiner]
US 20200084204A1 · Craswell · 2020 [cited by examiner]
US 20200202354A1 · Senn · 2020 [cited by examiner]
US 20220129903A1 · Sambhar · 2022 [cited by examiner]
EP 1295264A1 · 2003 [cited by applicant]
FR 3067499A1 · 2018 [cited by applicant]
WO WO2009032523A1 · 2009 [cited by examiner]
WO WO2012160318A1 · 2012 [cited by examiner]
WO WO2017196468A1 · 2017 [cited by applicant]
Y. Shah, V. Choyi, A. U. Schmidt and L. Subramanian, “Multi-factor Authentication as a Service,” 2015 3rd IEEE International Conference on Mobile Cloud Computing, Services, and Engineering, San Francisco, CA, USA, 2015,… [cited by examiner]
International Search Report and Written Opinion dated Apr. 8, 2020 for Application No. PCT/FR2019/052926. [cited by applicant]