发明授权
- 专利标题: Authentication and data integrity protection of token
- 专利标题(中): 令牌的认证和数据完整性保护
-
申请号: US13504874申请日: 2010-09-28
-
公开(公告)号: US09118643B2公开(公告)日: 2015-08-25
- 发明人: Rainer Falk
- 申请人: Rainer Falk
- 申请人地址: DE Munich
- 专利权人: SIEMENS AKTIENGESELLSCHAFT
- 当前专利权人: SIEMENS AKTIENGESELLSCHAFT
- 当前专利权人地址: DE Munich
- 代理机构: Staas & Halsey LLP
- 优先权: DE102009051201 20091029
- 国际申请: PCT/EP2010/064313 WO 20100928
- 国际公布: WO2011/051064 WO 20110505
- 主分类号: H04K1/00
- IPC分类号: H04K1/00 ; H04L29/06 ; G06F21/31 ; G06F21/64 ; G06Q20/34 ; G07F7/08 ; G07F7/12 ; H04L9/32
摘要:
In deriving a cryptographic key from the response message in a challenge-response message in a challenge-response authentication, a checksum for the related response is calculated after receiving a challenge message and before the related response has been transferred. A cryptographic key is derived from the response, which is used to determine the cryptographic checksum. The cryptographic checksum is transferred in a first time period after receiving the challenge message. The response message is transferred during a later, second time period. The duration of validity of the key derived from the response message ends before the response message is transferred. A theoretical attacker who can overhear and manipulate the communication will not know the response message until a point in time when the cryptographic key which can be derived therefrom is already no longer valid.
公开/授权文献
- US20120213368A1 AUTHENTICATION AND DATA INTEGRITY PROTECTION OF A TOKEN 公开/授权日:2012-08-23
信息查询