摘要:
A method for controlling a message from a sender (101). A referee (103) can evaluate a credential associated with a message to determine it’s desirability to the intended recipient (102), and take an action based upon the results of the determination. A sender (101) that includes a trusted component can send a credential with the message, and the message can be controlled without a referee.
摘要:
A system and method for authenticating a client application to a service. During registration, an application requesting access to a service receives a service identifier, which can be authenticated. The application can generate and send to the service an application-service key, based upon the authenticated identifier and a secret application key, a service-application identifier based upon the authenticated service identifier and an application identifier, and a registration nonce, all of which can be stored at the server. During authentication, the client sends the application-service identifier to the service, which the server can use to lookup the stored registration data. The server sends the registration nonce to the client, which can compute a proof of possession of the service-application key and send to the server. The server can compute its own version of the key, which is compared with the received key for authentication purposes.
摘要:
A Privacy enhanced identity scheme that may use public and private key cryptography to selectively distribute attributes of a token holder to a relying party. A challenge message {Rnonce, RID}, where Rnonce is a reader nonce and RID is a reader identifier (330). Methods may also include, responsive to the challenge message, sending a response message including at least an encrypted private token identifier TID and a session key k (360). In response to a challenge from a reader. The token sends a message that includes token identifier that is un-linkable to other identifier sent from the same token (370).
摘要:
A hybrid authentication device that has a keypad (103), a display(104), an electronic communications interface (105) and a processor (101) and memory (102) that can be removable, such as a Subscriber Identity Module. The device can operate in a stand-alone mode, in which a user enters a personal identification number and challenge using the keypad (103), and the device generates a response. The device can also function as a smartcard, and can be electronically coupled to an external device using the communications interface (105).