The present invention relates to a dynamic authentication system for digital TV.
Most broadcast networks today are one-way meaning that they are designed to carry broadcast signals from the content provider to the end-user, but not to carry information from the end-user and back to the content provider or distribution operator. Exceptions include some broadband networks and two-way cable networks,
In order to facilitate two-way interactive television (iTV), the end-user needs to send requests or responses through a second network herein denoted the return path network.
Some types of iTV applications require the user to accept terms or confirm actions. Examples are TV-shopping where the user orders and pays electronically for delivery of physical or electronic goods, and money games where the user places a bet-combination and pays electronically. In such scenario, the digital TV operator needs an authentication mechanism to ensure the identity of the user and for collection of a conscious approval from the user of the action to be made. The identity may be required e.g. due to legislation (not allowed to bet unless over 18 years old) and the user approval is required e.g. for withdrawal of money directly from the user's bank account.
The aforementioned conditions are met by the authentication system according to the present invention, as defined by the features stated in the claims.
This invention defines a way of using a digital TV receiver, which could be a digital TV set top box, a PC able to receive digital TV signals or a TV with embedded digital TV reception capability, in conjunction with a return path network to achieve authentication, the return path network can be of several types, one being a GSM network and in particular the short message system (SMS).
SMS allows the end-user to input some messages/text, e.g. the response to a quiz, allows the user to be anywhere when generating the request or response, and allows the request/response to be handled fully electronically with the content provider or distribution operator. For faster penetration, ability to address all GSM users with the same concept, general handling in the system operations and to be as autonomous as possible versus a particular GSM operator e.g. with respect to not having to share revenue, it is desirable for the iTV operator to have an authentication mechanism that is GSM operator independent. In practice, this implies that the authentication data must be entered into the SMS message by the end-user.
The SMS messages will be secured by the mechanisms built into the GSM network, and thereby a reasonable confidentiality level is obtained towards monitoring of the GSM network activity. However, the SMS message is not protected versus the GSM operator himself, and the SMS message is not protected when in gateways between the GSM network and the network contributing the SMS message to the iTV operator.
A static authentication mechanism, such as a PIN code, can therefore easily be compromised or the end-user can deny having performed an action. The authentication mechanism should therefore be dynamic, i.e. the authentication data must be different per transaction. Decent dynamic authentication cannot be based on end-users remembering of codes, rather, it needs to be based on an electronic security device in the possession of the user.
In
In conjunction with iTV, the User smart card in the digital TV receiver can be used as a generator of dynamic authentication codes.
The operator has an authentication code validation system that contains the same or complementary cryptographic algorithms and keys making the authentication code validation system able to verify the authentication code in the message from the user.
The authentication code validation system resides in—or is associated with—a service application server, and depending on whether among others the authentication code validation system deems the authentication code from the user acceptable, the service application server grants or conducts a certain service for the end-user.
1. The user interacts with the digital TV receiver, via the digital TV receiver remote control, and decides to purchase service X
2. The user enters a PIN to open for the User smart card to generate a new dynamic authentication code.
3. The User smart card has generated an authentication code that is being shown on the TV.
4. The user enters the authentication code in an SMS message on his mobile telephone.
5. The SMS message is sent to the operator and the authentication code to the authentication validation system for validation.
6. Upon positive validation, the service application server grants service or not, and potentially send an SMS “receipt” back to the user.
The authentication code is made variable by involving a changing parameter, e.g. an always increasing sequence number that has a different value each time an authentication code is generated.
The authentication code can be independent of the other transaction data, or (selected) transaction data can form a part of the basis for calculation of the authentication code. Examples of transaction data for the latter case are a product reference, a payment sum, an account number, an identity number, etc.
The SMS message may contain a reference to—and/or a parameter related to the service offering the user wants to respond to. The SMS message may contain a user reference, e.g. the User smart card number.
The invention is not restricted to the above-described embodiment but can be varied in a number of ways within the scope of the invention.
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/NO02/00438 | 11/25/2002 | WO | 1/5/2006 |