US2013247088A1PendingUtilityA1

Method and apparatus for the authentication of users of a hybrid terminal

Assignee: TEVEO INTERACTIVE GMBHPriority: Feb 10, 2010Filed: Jan 14, 2013Published: Sep 19, 2013
Est. expiryFeb 10, 2030(~3.5 yrs left)· nominal 20-yr term from priority
H04N 21/441H04N 21/25875H04N 21/4753H04L 63/0815H04L 9/32
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The invention concerns a method for the authentication of users of a hybrid terminal with a first registration step. The first registration step comprises entry of user identification data, request to enter a personal identification number, forwarding of the personal identification number to a registration server of an authentication apparatus, forwarding of the user identification data, validation of the user identification data, generation of a registration code, and in the event that entry of the personal identification number has not taken place, generation of the personal identification number, forwarding of the registration code to the internet-capable terminal and in the event that entry of the personal identification number has not taken place, forwarding of the personal identification number via a separate connection to the user. Furthermore, the invention concerns a corresponding apparatus for carrying out the method.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for authenticating users of a hybrid terminal, wherein the hybrid terminal communicates via at least one internet interface and communicates via at least one broadband interface with at least one service provider, comprising:
 at least one first registration step comprising:
 entry of user identification data of at least one of the users by means of an internet-capable terminal, 
 requesting the user to enter a personal identification number by means of the internet-capable terminal, wherein the personal identification number is freely chosen by the user, and 
 in the event that entry of the personal identification number has been carried out by the user, forwarding of the personal identification number from the internet-capable terminal to a registration server of an authentication apparatus via a first internet connection, 
 forwarding of the user identification data of the user from the internet-capable terminal to the registration server of the authentication apparatus via the first internet connection, 
 validation of the user identification data which are present on the registration server, by comparison of the user identification data with a predetermined user reference data record, and in the event that the user identification data correspond to the predetermined user reference data record, 
 storage of the user identification data of the user on a storage medium of the authentication apparatus, 
 generation of at least one registration code, wherein the registration code is assigned to the user; and 
   an authentication step comprising:
 checking whether a profile file assigned to the user is present on the hybrid terminal, wherein the hybrid terminal communicates via the internet interface with an application server of the authentication apparatus, and 
 in the event that the profile file assigned to the user is present on the hybrid terminal,
 a) carrying out an authentication in order to establish whether the user is authorised to receive user data from the service provider and/or to send user data to the service provider, or otherwise 
 b) carrying out an initial authentication in order to establish whether the user is authorised to receive the user data from the service provider and/or to send the user data to the service provider, and 
 
 in the event that the initial authentication shows that the user is authorized, 
 generation of the profile file, wherein the profile file is assigned to the user, 
 transfer of the profile file from the authentication server of the authentication apparatus via the internet interface to the hybrid terminal, wherein the profile file is filed on the hybrid terminal, and 
 after carrying out the initial authentication or carrying out the authentication, provided that the user has been authenticated as an authorized user, 
 transmission of a clearance message to at least one of the service providers, and 
 forwarding of the user data from the service provider to which transmission of the clearance message has taken place, wherein the hybrid terminal communicates with the service provider for forwarding of the user data. 
   
     
     
         2 . The method according to  claim 1 , characterized in that carrying out the initial authentication comprises:
 entry of the registration code and the personal identification number by means of the hybrid terminal;   forwarding of the registration code and the personal identification number to an authentication server of the authentication apparatus via the internet interface of the hybrid terminal;   checking of the registration code and personal identification number in the authentication server of the authentication apparatus by comparison of the registration code and personal identification number with the user identification data of the users who are stored on the storage medium of the authentication apparatus, and in the event that checking shows that the registration code and personal identification number can be assigned to one of the users;   establishing that this user is authorized to receive the user data from the service provider and/or to send the user data to the service provider.   
     
     
         3 . A method according to  claim 1 , characterized in that carrying out the authentication comprises:
 transfer of the profile file which is filed on the hybrid terminal to the authentication server of the authentication apparatus via the internet interface of the hybrid terminal,   checking of the profile file in the authentication server of the authentication apparatus by comparison of the profile file with the user identification data of the users who are stored on the storage medium of the authentication apparatus, and in the event that checking shows that the profile file can be assigned to one of the users,   establishing that this user is authorized to receive the user data from the service provider and/or to send the user data to the service provider.   
     
     
         4 . The method according to  claim 1 , characterized in that carrying out the authentication comprises:
 entry of the personal identification number by means of the hybrid terminal,   transfer of the profile file which is filed on the hybrid terminal and of the personal identification number to the authentication server of the authentication apparatus via the internet interface of the hybrid terminal,   checking of the personal identification number and profile file in the authentication server of the authentication apparatus by comparison of the personal identification number and profile file with the user identification data of the users who are stored on the storage medium of the authentication apparatus, and in the event that checking shows that the personal identification number and profile file can be assigned to one of the users,   establishing that this user is authorized to receive the user data from the service provider and/or to send the user data to the service provider.   
     
     
         5 . The method according to  claim 1 , characterized in that the hybrid terminal communicates via the internet interface and the broadband interface according to the HbbTV standard, by the fact that the hybrid terminal is designed as an HbbTV terminal. 
     
     
         6 . The method according to  claim 1 , characterized in that communication between the internet-capable terminal and the authentication apparatus takes place via a secure internet connection by means of a secure hypertext transfer protocol. 
     
     
         7 . The method according to  claim 1 , characterized in that the registration code comprises exclusively numerical characters. 
     
     
         8 . The method according to  claim 2 , characterized in that entry of the registration code and personal identification number is effected by means of a remote control of the hybrid terminal. 
     
     
         9 . The method according to  claim 1 , characterized in that the user data comprise at least one of video data and/or audio data. 
     
     
         10 . The method according  claim 1 , characterized in that the user data comprise communications and clearance data. 
     
     
         11 . An apparatus for authenticating users of a hybrid terminal comprising:
 at least one hybrid terminal with at least one internet interface and at least one broadband interface;   an authentication apparatus, wherein the authentication apparatus comprises a registration server, an application server, an authentication server and at least one storage medium;   and wherein the hybrid terminal is connected via the internet interface to the authentication apparatus and via the broadband interface to at least one service provider;   and wherein the authentication apparatus is connected via a second internet connection to at least one of the service providers;   an internet-capable terminal which is connected via a first internet connection to the registration server of the authentication apparatus;   wherein the registration server is adapted:
 to validate user identification data which are forwarded from the internet-capable terminal to the registration server via the first internet connection, by comparison of user identification data with a predetermined user reference data record, and in the event that the user identification data correspond to the predetermined user reference data record, 
 to store the user identification data of the user on the storage medium, 
 to generate at least one registration code and at least one personal identification number, wherein the registration code and/or the personal identification number is assigned to the user, to forward the registration code from the registration server of the authentication apparatus to the internet-capable terminal via a communication path that is separate and different from the first internet connection, and 
 to forward the personal identification number from the registration server via a separate connection to the user or to the internet-capable terminal, 
 and to check whether a profile file assigned to the user is present on the hybrid terminal, wherein the hybrid terminal is designed to communicate via the internet interface with an application server of the authentication apparatus; and 
   in the event that the profile file assigned to the user is present on the hybrid terminal,
 a) to carry out an authentication in order to establish whether the user is authorized to receive user data from the service provider, or otherwise 
 b) to carry out an initial authentication in order to establish whether the user is authorized to receive the user data from the service provider and/or to send the user data to the service provider,
 to generate the profile file, wherein the profile file is assigned to the user, 
 to transfer the profile file from the authentication server of the authentication apparatus via the internet interface to the hybrid terminal, wherein the profile file is filed on the hybrid terminal, 
 
   and after the initial authentication or the authentication, provided that the user has been authenticated as an authorized user;   to transmit a clearance message to at least one of the service providers; and   to forward the user data from the service provider to which transmission of the clearance message has taken place, wherein the hybrid terminal is adapted to communicate with the service provider for forwarding of the user data.   
     
     
         12 . A method for authenticating users of a hybrid terminal, wherein the hybrid terminal communicates via at least one internet interface and communicates via at least one broadband interface with at least one service provider, comprising:
 at least one first registration step comprising:
 entry of user identification data of at least one of the users by means of an internet-capable terminal, 
 forwarding of the user identification data of the user from the internet-capable terminal to a registration server of a authentication apparatus via a first internet connection, 
 validation of the user identification data which are present on the registration server, by comparison of the user identification data with a predetermined user reference data record, and in the event that the user identification data correspond to the predetermined user reference data record, 
 storage of the user identification data of the user on a storage medium of the authentication apparatus, 
 generation of at least one registration code, wherein the registration code is assigned to the user, and 
 in the event that entry of a personal identification number by the user has not taken place, generation of at least the personal identification number, wherein the personal identification number is assigned to the user, 
 forwarding of the registration code from the registration server of the authentication apparatus to the internet-capable terminal via a communication path that is separate and different from the first internet connection, and 
 in the event that entry of the personal identification number by the user has not taken place, forwarding of the personal identification number from the registration server via a separate connection to the user or to the internet-capable terminal; and 
   an authentication step comprising:
 checking whether a profile file assigned to the user is present on the hybrid terminal, wherein the hybrid terminal communicates via the internet interface with an application server of the authentication apparatus, and 
 in the event that the profile file assigned to the user is present on the hybrid terminal, 
 a) carrying out an authentication in order to establish whether the user is authorised to receive user data from the service provider and/or to send user data to the service provider, or otherwise 
 b) carrying out an initial authentication in order to establish whether the user is authorised to receive the user data from the service provider and/or to send the user data to the service provider, and 
 in the event that the initial authentication shows that the user is authorized, 
 generation of the profile file, wherein the profile file is assigned to the user, 
 transfer of the profile file from the authentication server of the authentication apparatus via the internet interface to the hybrid terminal, wherein the profile file is filed on the hybrid terminal, and 
 after carrying out the initial authentication or carrying out the authentication, provided that the user has been authenticated as an authorized user, 
 transmission of a clearance message to at least one of the service providers, and 
 forwarding of the user data from the service provider to which transmission of the clearance message has taken place, wherein the hybrid terminal communicates with the service provider for forwarding of the user data. 
   
     
     
         13 . The method according to  claim 12 , characterized in that carrying out the initial authentication comprises:
 entry of the registration code and the personal identification number by means of the hybrid terminal;   forwarding of the registration code and the personal identification number to an authentication server of the authentication apparatus via the internet interface of the hybrid terminal;   checking of the registration code and personal identification number in the authentication server of the authentication apparatus by comparison of the registration code and personal identification number with the user identification data of the users who are stored on the storage medium of the authentication apparatus, and in the event that checking shows that the registration code and personal identification number can be assigned to one of the users;   establishing that this user is authorized to receive the user data from the service provider and/or to send the user data to the service provider.   
     
     
         14 . A method according to  claim 12 , characterized in that carrying out the authentication comprises:
 transfer of the profile file which is filed on the hybrid terminal to the authentication server of the authentication apparatus via the internet interface of the hybrid terminal,   checking of the profile file in the authentication server of the authentication apparatus by comparison of the profile file with the user identification data of the users who are stored on the storage medium of the authentication apparatus, and in the event that checking shows that the profile file can be assigned to one of the users,   establishing that this user is authorized to receive the user data from the service provider and/or to send the user data to the service provider.   
     
     
         15 . The method according to  claim 12 , characterized in that carrying out the authentication comprises:
 entry of the personal identification number by means of the hybrid terminal,   transfer of the profile file which is filed on the hybrid terminal and of the personal identification number to the authentication server of the authentication apparatus via the internet interface of the hybrid terminal,   checking of the personal identification number and profile file in the authentication server of the authentication apparatus by comparison of the personal identification number and profile file with the user identification data of the users who are stored on the storage medium of the authentication apparatus, and in the event that checking shows that the personal identification number and profile file can be assigned to one of the users,   establishing that this user is authorized to receive the user data from the service provider and/or to send the user data to the service provider.   
     
     
         16 . The method according to  claim 12 , characterized in that the hybrid terminal communicates via the internet interface and the broadband interface according to the HbbTV standard, by the fact that the hybrid terminal is designed as an HbbTV terminal. 
     
     
         17 . The method according to  claim 12 , characterized in that communication between the internet-capable terminal and the authentication apparatus takes place via a secure internet connection by means of a secure hypertext transfer protocol. 
     
     
         18 . The method according to  claim 12 , characterized in that the registration code comprises exclusively numerical characters. 
     
     
         19 . The method according to  claim 13 , characterised in that entry of the registration code and personal identification number is effected by means of a remote control of the hybrid terminal. 
     
     
         20 . The method according to  claim 12 , characterized in that the user data comprise at least one of video data and/or audio data. 
     
     
         21 . The method according  claim 12 , characterized in that the user data comprise communications and clearance data.

Join the waitlist — get patent alerts

Track US2013247088A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.