Information Carrier Authentication With a Physical One-Way Function
    21.
    发明申请
    Information Carrier Authentication With a Physical One-Way Function 有权
    具有物理单向功能的信息载体认证

    公开(公告)号:US20080229119A1

    公开(公告)日:2008-09-18

    申请号:US12064089

    申请日:2006-08-16

    IPC分类号: G06F21/00

    摘要: The present invention relates to a method of enabling authentication of an information carrier (105), the information carrier (105) comprising a writeable part (155) and a physical token (125) arranged to supply a response upon receiving a challenge, the method comprising the following steps; applying a first challenge (165) to the physical token (125) resulting in a first response (170), and detecting the first response (170) of the physical token (125) resulting in a detected first response data (175), the method being characterized in that it further comprises the following steps; forming a first authentication data (180) based on information derived from the detected first response data (175), signing the first authentication data (180), and writing the signed authentication data (185) in the writeable part (155) of the information carrier (105). The invention further relates to a method of authentication of an information carrier (105), as well as to devices for both enabling authentication as well as authentication of an information carrier (105).

    摘要翻译: 本发明涉及一种能够认证信息载体(105)的方法,所述信息载体(105)包括布置成在接收到挑战时提供响应的可写入部分(155)和物理令牌(125),所述方法 包括以下步骤: 将第一挑战(165)应用于所述物理令牌(125),从而产生第一响应(170),并且检测所述物理令牌(125)的第一响应(170),从而产生检测到的第一响应数据(175) 其特征在于还包括以下步骤: 基于从检测到的第一响应数据(175)导出的信息,形成第一认证数据(180),对第一认证数据(180)进行签名,并将签名认证数据(185)写入信息的可写入部分(155) 载体(105)。 本发明还涉及信息载体(105)的认证方法,以及用于启用认证以及信息载体(105)的认证的设备。

    Key generation using biometric data and secret extraction codes
    23.
    发明授权
    Key generation using biometric data and secret extraction codes 有权
    密钥生成使用生物特征数据和密码提取码

    公开(公告)号:US08583936B2

    公开(公告)日:2013-11-12

    申请号:US11722443

    申请日:2005-12-22

    摘要: A method of generating a key for encrypting communications between first and second terminals includes obtaining a measurement of characteristics of a physical identifier of a user; and extracting a key from the physical identifier using a code selected from a collection of codes. Each code in the collection defines an ordered mapping from a set of values of the characteristics to a set of keys. The collection of codes includes at least one code in which the ordered mapping is a permutation of the ordered mapping of one of the other codes in the collection.

    摘要翻译: 一种生成用于加密第一和第二终端之间的通信的密钥的方法包括获得用户的物理标识符的特性的测量; 以及使用从代码集合中选择的代码从所述物理标识符提取密钥。 集合中的每个代码定义了从一组特征值到一组键的有序映射。 代码集合包括至少一个代码,其中有序映射是集合中其他代码之一的有序映射的置换。

    CONTROLLED ACTIVATION OF FUNCTION
    25.
    发明申请
    CONTROLLED ACTIVATION OF FUNCTION 有权
    功能的控制激活

    公开(公告)号:US20100146261A1

    公开(公告)日:2010-06-10

    申请号:US12595671

    申请日:2008-04-04

    IPC分类号: H04L29/06 H04L9/32

    摘要: A method of and system (110) for controlled activation of at least one function in a product or component at a remote location, which activation requires a correct activation data item to be available in the product or component. The method comprises receiving one or more noisy outputs of an unclonable element associated with the component from the remote location, and providing helper data to the remote location, which helper data transforms the one or more noisy outputs to a single value which corresponds to the correct activation data item.

    摘要翻译: 一种用于受控激活远程位置的产品或组件中的至少一个功能的方法和系统(110),该激活需要在产品或组件中可用的正确的激活数据项。 该方法包括从远程位置接收与组件相关联的不可克隆元件的一个或多个噪声输出,以及向远程位置提供帮助数据,哪个帮助数据将一个或多个噪声输出转换成对应于正确的单个值 激活数据项。

    Enhanced content resolution method
    26.
    发明授权
    Enhanced content resolution method 有权
    增强内容分辨率方法

    公开(公告)号:US07730303B2

    公开(公告)日:2010-06-01

    申请号:US10496467

    申请日:2002-11-13

    IPC分类号: H04L29/06 G06F7/04

    摘要: A method of providing automatically verifiable trust in a content resolution process in which a PDR resolves a content reference identifier (CRID) identifying a content item using a resolution authority record (RAR) to obtain a locator identifying a location where the PDR can obtain the content item. Preferably, the measure comprises computing a digital signature over at least part of the contents of the CRID, the locator and/or the RAR. The method may also comprise encrypting at least a data portion of the CRID, RAR or locator. Digital rights needed to access the content item can be provided with the CRID, RAR or locator.

    摘要翻译: 一种在内容解析过程中提供自动验证的信任的方法,其中PDR使用分辨率授权记录(RAR)来解析识别内容项的内容参考标识符(CRID),以获得标识PDR可以获得内容的位置的定位符 项目。 优选地,该措施包括在CRID,定位器和/或RAR的内容的至少一部分上计算数字签名。 该方法还可以包括加密CRID,RAR或定位符的至少一个数据部分。 可以向CRID,RAR或定位器提供访问内容项目所需的数字权限。

    FUZZY BIOMETRICS BASED SIGNATURES
    27.
    发明申请
    FUZZY BIOMETRICS BASED SIGNATURES 有权
    基于FUZZY BIOMETRICS的标志

    公开(公告)号:US20100058063A1

    公开(公告)日:2010-03-04

    申请号:US12515020

    申请日:2007-11-12

    IPC分类号: H04L9/32 H04L9/08 G06K9/00

    摘要: The present invention relates to a method and a device of verifying the validity a digital signature based on biometric data. A basic idea of the invention is that a verifier attains a first biometric template of the individual to be verified, for instance by having the individual provide her fingerprint via an appropriate sensor device. Then, the verifier receives a digital signature and a second biometric template. The verifier then verifies the digital signature by means of using either the first or the second biometric template as a public key. The attained (first) biometric template of the individual is compared with the received (second) biometric template associated with the signature and if a match occurs, the verifier can be confident that the digital signature and the associated (second) biometric template have not been manipulated by an attacker for impersonation purposes.

    摘要翻译: 本发明涉及一种基于生物特征数据验证数字签名的有效性的方法和装置。 本发明的基本思想是,验证者获得要验证的个体的第一生物特征模板,例如通过使个体经由适当的传感器装置提供她的指纹。 然后,验证者接收数字签名和第二生物特征模板。 验证者然后通过使用第一或第二生物特征模板作为公钥来验证数字签名。 将获得的(第一)个体生物特征模板与与签名相关联的接收(第二)生物特征模板进行比较,并且如果匹配发生,验证者可以确信数字签名和相关联的(第二)生物测定模板尚未被 由攻击者为了冒充目的操纵。

    ATTACH DETECTION WITH COATING PUF
    28.
    发明申请
    ATTACH DETECTION WITH COATING PUF 审中-公开
    用涂层PUF连接检测

    公开(公告)号:US20090265758A1

    公开(公告)日:2009-10-22

    申请号:US12296675

    申请日:2007-04-05

    申请人: Pim Theo Tuyls

    发明人: Pim Theo Tuyls

    IPC分类号: H04L9/32

    摘要: The present invention relates to a method of authenticating a physical token (14) which provides measurable parameters, and a device (11) comprising a physical token (14) which provides measurable parameters for authentication. A basic idea of the invention is to utilize properties of a physical token (14) comprised in a device (11) to detect whether the device has been tampered with. In an enrolment phase, values of a plurality of physical parameters provided by the physical token are measured. This set of measured values is referred to as response data. Noise-correcting data, also referred to as helper data, is employed to provide noise-robustness to the response data in a secure way. Then, in an authentication phase, the parameter values are measured again, and the noise-correcting data is employed to derive verification data. The verification data is compared with the enrolment data and a determination is made whether the derived verification data corresponds to the enrolment data. If so, the physical token is considered to be authenticated.

    摘要翻译: 本发明涉及一种验证提供可测量参数的物理令牌(14)的方法,以及包括物理令牌(14)的设备(11),其提供用于认证的可测量参数。 本发明的基本思想是利用包括在设备(11)中的物理令牌(14)的属性来检测设备是否被篡改。 在注册阶段,测量由物理令牌提供的多个物理参数的值。 这组测量值被称为响应数据。 采用噪声校正数据,也称为辅助数据,以安全的方式为响应数据提供噪声鲁棒性。 然后,在验证阶段,再次测量参数值,采用噪声校正数据来导出验证数据。 将验证数据与登记数据进行比较,并确定导出的验证数据是否对应于登记数据。 如果是这样,物理令牌被认为是认证的。

    Preserving Privacy While Using Authorization Certificates
    30.
    发明申请
    Preserving Privacy While Using Authorization Certificates 审中-公开
    使用授权证书时保护隐私

    公开(公告)号:US20080052772A1

    公开(公告)日:2008-02-28

    申请号:US10596668

    申请日:2004-12-13

    IPC分类号: H04L9/32

    摘要: The invention proposes a method to provide privacy for users or a user from a group of users with respect to authorizations they are granted, where such authorizations are expressed using digital authorization certificates, and with respect to domain certificates in case of groups of users. The idea is to conceal the user identity in the certificates, while the certificate itself remains in the clear. In this way, certificates can be widely and openly available, e.g. in a public network, without a random observer being able to link a user to an authorization or to identify a user within a domain. Privacy is also provided towards the certificate verifier by means of zero-knowledge protocols, which are carried out between the user and the verifier in order for the verifier to check a user's entitlement to a certificate. Privacy is further provided towards the certificate issuer as well, by means of a mechanism that allows the anonymous (buying or) issuing of certificates from the issuer.

    摘要翻译: 本发明提出了一种方法,用于为用户或用户提供关于其授权的授权的用户或用户的隐私,其中使用数字授权证书表示授权,以及在用户组的情况下关于域证书。 这个想法是在证书中隐藏用户身份,而证书本身保持清晰。 以这种方式,证书可以广泛和公开地获得,例如。 在公共网络中,没有随机观察者能够将用户链接到授权或识别域内的用户。 还通过在用户和验证者之间执行的零知识协议向证书验证者提供隐私,以便验证者检查用户对证书的授权。 通过允许发行人匿名(购买或发行)证书的机制,还向证书颁发者提供隐私。