Authenticator, authenticatee and authentication method
    21.
    发明授权
    Authenticator, authenticatee and authentication method 有权
    认证者,认证方和认证方式

    公开(公告)号:US09544138B2

    公开(公告)日:2017-01-10

    申请号:US13985431

    申请日:2012-02-17

    IPC分类号: H04L9/32 H04L9/08 H04L9/00

    摘要: According to one embodiment, an authentication method between an authenticatee which stores key information having a data structure composed of a key transition record, secret information XY of a matrix form, and secret information XYE which is created by encrypting the secret information XY, and an authenticator which authenticates the authenticatee, includes selecting, by the authenticator, a record corresponding to a device index of the authenticator from the key information which is received from the authenticatee, and decrypting the record by a device key, thereby taking out a key transition, and executing, by the authenticator, a decryption process on the secret information XYE, which is received from the authenticatee, by using the corresponding key transition, and sharing the secret information XY.

    摘要翻译: 根据一个实施例,存储具有由密钥转换记录,矩阵形式的秘密信息XY和通过加密秘密信息XY创建的秘密信息XYE组成的密钥信息的认证方的认证方法,以及 验证认证者的认证方包括由认证者从从认证者接收到的密钥信息中选择与认证者的设备索引对应的记录,并通过设备密钥解密记录,从而进行密钥转换, 并且由认证器执行对从认证者接收的秘密信息XYE的解密处理,通过使用相应的密钥转换并共享秘密信息XY。

    Device and method for certifying one's own authenticity
    22.
    发明授权
    Device and method for certifying one's own authenticity 有权
    验证自己的真实性的设备和方法

    公开(公告)号:US08995657B2

    公开(公告)日:2015-03-31

    申请号:US13523290

    申请日:2012-06-14

    IPC分类号: H04L9/00

    摘要: According to one embodiment, a device includes a memory area being used to store a first key (NKey), unique secret identification information (SecretID), and encrypted secret identification information (E-SecretID), the encrypted secret identification information (E-SecretID) being generated by encrypting the secret identification information (SecretID), the first key (NKey) and the secret identification information (SecretID) being prohibited from being read from outside, the encrypted secret identification information (E-SecretID) being readable from outside; a data generator configured to generate a session key (SKey) by using a second key (HKey), the second key (HKey) being generated based on the first key (NKey); and a one-way function processor configured to generate an authentication information by processing the secret identification information (SecretID) with the session key (SKey) in one-way function operation.

    摘要翻译: 根据一个实施例,一种设备包括用于存储第一密钥(NKey),唯一秘密识别信息(SecretID)和加密秘密识别信息(E-SecretID)的存储区域,加密的秘密识别信息(E-SecretID )秘密识别信息(SecretID)生成,第一密钥(NKey)和秘密识别信息(SecretID)被禁止从外部读取,加密的秘密识别信息(E-SecretID)可从外部读取; 数据生成器,被配置为通过使用第二密钥(HKey)生成会话密钥(SKey),所述第二密钥(HKey)基于所述第一密钥(NKey)生成; 以及单向功能处理器,被配置为通过在单向功能操作中通过会话密钥(SKey)处理秘密识别信息(SecretID)来生成认证信息。

    Device
    24.
    发明授权
    Device 失效
    设备

    公开(公告)号:US08751814B2

    公开(公告)日:2014-06-10

    申请号:US13517900

    申请日:2012-06-14

    IPC分类号: G06F21/00

    CPC分类号: H04L63/061 G06F21/10

    摘要: According to one embodiment, a device includes a second data generator configured to generate a session key (SKey) by encrypting a random number (RN) with the second key (HKey) in AES operation; a one-way function processor configured to generate an authentication information (Oneway-ID) by processing the secret identification information (SecretID) with the session key (SKey) in one-way function operation; and a data output interface configured to output the encrypted secret identification information (E-SecretID) and the authentication information (Oneway-ID) to outside of the device.

    摘要翻译: 根据一个实施例,一种设备包括:第二数据生成器,被配置为通过在AES操作中用第二密钥(HKey)加密随机数(RN)来生成会话密钥(SKey); 单向功能处理器,被配置为通过在单向功能操作中通过会话密钥(SKey)处理秘密识别信息(SecretID)来生成认证信息(Oneway-ID); 以及数据输出接口,被配置为将加密的秘密识别信息(E-SecretID)和认证信息(Oneway-ID)输出到设备外部。

    Data recording device, host device and method of processing data recording device
    25.
    发明授权

    公开(公告)号:US08745391B2

    公开(公告)日:2014-06-03

    申请号:US13513469

    申请日:2012-03-22

    IPC分类号: G06F21/00

    摘要: A data storage unit can store an encrypted medium device key Enc (Kcu, Kmd_i), and a medium device key certificate (Certmedia). A controller can include an information recording unit to store a controller key (Kc) and first controller identification information (IDcu). A key generation unit executes a one-way function calculation based on the controller key and the first controller identification information to generate a controller unique key (Kcu). An identification information generating unit executes a one-way function calculation based on the controller key and the first controller identification information to generate second controller identification information (IDcntr). A key encryption unit encrypts the medium device key (Kmd_i) by the controller unique key (Kcu) to generate encrypted medium device key Enc (Kcu, Kmd_i). A key exchange unit executes an authentication key exchange process with a host device using the medium device key (Kmd_i) and the medium device key certificate (Certmedia).

    摘要翻译: 数据存储单元可以存储加密的介质设备密钥Enc(Kcu,Kmd_i)和中等设备密钥证书(Certmedia)。 控制器可以包括用于存储控制器密钥(Kc)和第一控制器标识信息(IDcu)的信息记录单元。 密钥生成单元基于控制器密钥和第一控制器识别信息执行单向函数计算,以生成控制器唯一密钥(Kcu)。 识别信息生成单元基于控制器键和第一控制器识别信息执行单向函数计算,以生成第二控制器识别信息(IDcntr)。 密钥加密单元通过控制器唯一密钥(Kcu)加密介质设备密钥(Kmd_i),以产生加密的介质设备密钥Enc(Kcu,Kmd_i)。 密钥交换单元使用介质设备密钥(Kmd_i)和介质设备密钥证书(Certmedia)来执行与主机设备的认证密钥交换过程。

    Information recording device
    26.
    发明授权
    Information recording device 有权
    信息记录装置

    公开(公告)号:US08693694B2

    公开(公告)日:2014-04-08

    申请号:US13524842

    申请日:2012-06-15

    IPC分类号: H04L9/08

    摘要: A data storage unit may store an encrypted medium device key Enc (Kcu, Kmd_i), and a medium device key certificate (Certmedia). A controller further includes: an information recording unit configured to store a controller key (Kc) and first controller identification information (IDcu). A key generation unit executes a one-way function calculation based on the controller key and the first controller identification information to generate a controller unique key (Kcu). An identification information generating unit executes a one-way function calculation based on the controller key and the first controller identification information to generate second controller identification information (IDcntr). A key encryption unit encrypts the medium device key (Kmd_i) by the controller unique key (Kcu) to generate encrypted medium device key Enc (Kcu, Kmd_i). A key exchange unit executes an authentication key exchange process with a host device using the medium device key (Kmd_i) and the medium device key certificate (Certmedia).

    摘要翻译: 数据存储单元可以存储加密的介质设备密钥Enc(Kcu,Kmd_i)和介质设备密钥证书(Certmedia)。 控制器还包括:信息记录单元,被配置为存储控制器密钥(Kc)和第一控制器标识信息(IDcu)。 密钥生成单元基于控制器密钥和第一控制器识别信息执行单向函数计算,以生成控制器唯一密钥(Kcu)。 识别信息生成单元基于控制器键和第一控制器识别信息执行单向函数计算,以生成第二控制器识别信息(IDcntr)。 密钥加密单元通过控制器唯一密钥(Kcu)加密介质设备密钥(Kmd_i),以产生加密的介质设备密钥Enc(Kcu,Kmd_i)。 密钥交换单元使用介质设备密钥(Kmd_i)和介质设备密钥证书(Certmedia)来执行与主机设备的认证密钥交换过程。

    Manufacturing method of a memory device to be authenticated
    28.
    发明授权
    Manufacturing method of a memory device to be authenticated 失效
    要认证的存储器件的制造方法

    公开(公告)号:US08627455B1

    公开(公告)日:2014-01-07

    申请号:US13523485

    申请日:2012-06-14

    IPC分类号: G06F21/00

    摘要: According to one embodiment, a manufacturing method of a device to be authenticated, wherein the device includes a first memory area which is prohibited from data-reading and data-writing after shipping from a memory vendor; a second memory area which is allowed to data-read from outside after shipping from the memory vendor; and a third memory area which is allowed to data-read and data-write from outside after sipping from the memory vendor.

    摘要翻译: 根据一个实施例,一种要认证的设备的制造方法,其中所述设备包括在从存储器供应商运送之后禁止数据读取和数据写入的第一存储区域; 第二存储器区域,其在从存储器供应商运送之后被允许从外部进行数据读取; 以及第三存储器区域,其在从存储器供应商处理之后被允许从外部进行数据读取和数据写入。

    Host device
    29.
    发明授权
    Host device 有权
    主机设备

    公开(公告)号:US08948400B2

    公开(公告)日:2015-02-03

    申请号:US13524579

    申请日:2012-06-15

    IPC分类号: H04L9/08

    摘要: the host device being configured to receive, from a key issuer who issued the medium device key (Kmd_i) and the medium device key certificate, a host device key (Khd_i) and a host device certificate (Certhost), the host device being configured to execute authentication with the information recording device using the host device key (Khd_i) and the host device certificate (Certhost), the host device being configured to receive second controller identification information (IDcntr) from the information recording device, the second controller identification information being generated by executing a one-way function calculation based on the controller key (Kc) and the first controller identification information (IDcu), and the host device being configured to decrypt the encrypted content data stored in the information recording device, in response to reception of the second controller identification information (IDcntr) from the information recording device.

    摘要翻译: 所述主机设备被配置为从发出所述介质设备密钥(Kmd_i)和所述介质设备密钥证书的密钥发行者接收主机设备密钥(Khd_i)和主机设备证书(Certhost),所述主机设备被配置为 使用所述主机设备密钥(Khd_i)和所述主机设备证书(Certhost)与所述信息记录设备一起执行认证,所述主机设备被配置为从所述信息记录设备接收第二控制器标识信息(IDcntr),所述第二控制器标识信息 通过执行基于控制器密钥(Kc)和第一控制器标识信息(IDcu)的单向函数计算而产生的,并且主机设备被配置为响应于接收来对存储在信息记录设备中的加密内容数据进行解密 的来自信息记录装置的第二控制器识别信息(IDcntr)。

    Authentication method
    30.
    发明授权
    Authentication method 有权
    认证方式

    公开(公告)号:US08938616B2

    公开(公告)日:2015-01-20

    申请号:US13523188

    申请日:2012-06-14

    IPC分类号: H04L9/32

    摘要: According to one embodiment, a authentication method comprising: generating a second key by the first key, the first key being stored in a memory and being prohibited from being read from outside; generating a session key by the second key; generating first authentication information, the secret identification information stored in a memory and being prohibited from being read from outside; transmitting encrypted secret identification information to an external device and receiving second authentication information from the external device, the encrypted secret identification information stored in a memory and readable, the second authentication information generated based on the encrypted secret identification information; and determining whether the first authentication information and the second authentication information match.

    摘要翻译: 根据一个实施例,一种认证方法,包括:通过第一密钥生成第二密钥,第一密钥存储在存储器中并被禁止从外部读取; 通过第二个密钥生成会话密钥; 生成第一认证信息,存储在存储器中并被禁止从外部读取的秘密识别信息; 向外部设备发送加密的秘密识别信息并从外部设备接收第二认证信息,所述加密的秘密识别信息存储在存储器中并且可读,所述第二认证信息是基于所述加密的秘密识别信息生成的; 以及确定所述第一认证信息和所述第二认证信息是否匹配。