再颁专利
- 专利标题: Method and apparatus for authentication of client server communication
- 专利标题(中): 客户端服务器通信认证方法和装置
-
申请号: US08778151申请日: 1996-09-20
-
公开(公告)号: USRE37178E1公开(公告)日: 2001-05-15
- 发明人: Kevin Kingdon
- 申请人: Kevin Kingdon
- 主分类号: H04L928
- IPC分类号: H04L928
摘要:
The present invention provides a method and apparatus for message packet authentication to prevent the forging of message packets. After a message packet is created, a secret session key is preappended to the message, and a message digesting algorithm is executed on the altered message to create a message digest. A portion of the message digest, referred to as the signature, is then appended to the actual message when it is sent over the wire. The receiving station strips the signature from the message, preappends the same secret session key and creates its own message digest. The signature of the digest created by the receiving station is compared to the signature of the digest appended by the sending station. If there is a match, an authentic message is assumed. If there is no match, the message is considered as invalid and discarded. An advantage of the present invention is that the session key is never transmitted over the wire. The receiving station (server) already has the key and uses the key along with the message data to recalculate the message digest upon receiving the packet. The shared secret key (session key) is generated during initiation of the NCP session. In addition, cumulative state information is maintained by both the sending station and the receiving station. This state information is also used to authenticate messages.
信息查询