Authentication method, system and apparatus of an electronic value
    81.
    发明授权
    Authentication method, system and apparatus of an electronic value 有权
    电子价值的认证方法,系统和设备

    公开(公告)号:US07325132B2

    公开(公告)日:2008-01-29

    申请号:US10647640

    申请日:2003-08-25

    IPC分类号: H04L9/00 H04K1/00

    摘要: An authentication system providing a safety authentication process of electronic values with the use of mobile terminals which do not have a tamper-resistant function. The electronic value including encrypted value authentication information (F(VPW)), wherein an authentication information (VPW) corresponding to an electronic value specified by a user is acquired by the hash calculation, is stored in user's mobile terminal. In the user authentication process; authentication apparatus generates a random number R and transmits it to mobile terminal, mobile terminal generates value authentication information (F(VPW′)) from authentication information (VPW′) corresponding to electronic value input by user, further executes a hash calculation on data wherein value authentication information (F(VPW′)) and the random number R are concatenated, generates authentication information (F(VPW′)∥R), transmits it to the authentication apparatus with the electronic value, authentication apparatus decrypts the received electronic value, extracts the value authentication information (F(VPW)) from the electronic value, executes the hash calculation on data wherein value authentication information (F(VPW)) and the random number R are concatenated, generates the authentication information (F(VPW)∥R), and collates the received authentication information (F(VPW′)∥R) with the authentication information (F(VPW)∥R), so that the user is authenticated.

    摘要翻译: 一种认证系统,其使用不具有防篡改功能的移动终端提供电子价值的安全认证处理。 包含加密值认证信息(F(VPW))的电子值存储在用户移动终端中,其中通过散列计算获取与用户指定的电子值对应的认证信息(VPW)。 在用户认证过程中; 认证装置生成随机数R并将其发送到移动终端,移动终端从与用户输入的电子值对应的认证信息(VPW')生成值认证信息(F(VPW')),进一步执行数据的哈希计算 将值验证信息(F(VPW'))和随机数R连接起来,生成认证信息(F(VPW')||R),将其发送到具有电子值的认证装置,认证装置解密接收到的电子值, 从电子值中提取值认证信息(F(VPW)),对其中值认证信息(F(VPW))和随机数R进行级联的数据执行哈希计算,生成认证信息(F(VPW) (F(VPW')||R)与认证信息(F(VPW)‖RR)对照,从而对用户进行认证。

    Secure device and mobile terminal which carry out data exchange between card applications
    83.
    发明申请
    Secure device and mobile terminal which carry out data exchange between card applications 有权
    安全设备和移动终端进行卡应用之间的数据交换

    公开(公告)号:US20050173518A1

    公开(公告)日:2005-08-11

    申请号:US11049482

    申请日:2005-02-02

    申请人: Hisashi Takayama

    发明人: Hisashi Takayama

    摘要: A secure device comprises a data exchange card application carrying out data exchange between card applications isolated by a fire wall, card application plug-in data defining authentication processing of the data exchange card application, in such a manner that authentication processing between the card application and the data exchange card application is carried out in the same manner as authentication processing between the card application and a dedicated host terminal, and authentication key data used for this authentication processing. Data exchange and tie-up processing between card applications are possible in a secure device, or under the mediation of a mobile terminal, and rapid processing can be done. The card application has only to carry out the same operation as data exchange with a related dedicated host terminal. Also, tie-up processing between card applications can be carried out by only a mobile terminal side in which a secure device is loaded.

    摘要翻译: 安全装置包括数据交换卡应用程序,该数据交换卡应用程序以防火墙隔离的卡片应用之间进行数据交换,定义数据交换卡应用的认证处理的卡应用插件数据, 数据交换卡应用程序以与卡应用程序和专用主机终端之间的认证处理相同的方式执行,以及用于该认证处理的认证密钥数据。 在安全设备或移动终端的中介之间,卡应用之间的数据交换和绑定处理是可能的,并且可以进行快速处理。 卡应用程序只能执行与相关专用主机终端的数据交换相同的操作。 此外,卡应用之间的联动处理只能由安装有安全装置的移动终端侧进行。