首页> 外国专利> ENTITY AUTHENTICATION METHOD AND DEVICE BASED ON PRE-SHARED KEY

ENTITY AUTHENTICATION METHOD AND DEVICE BASED ON PRE-SHARED KEY

机译:基于预共享密钥的实体认证方法及装置

摘要

The present invention relates to the technical field of network security. Provided are an entity authentication method and device based on a pre-shared key. The method comprises: an entity A generates and sends a random number NA to an entity B; the entity B generates random numbers NB and ZSEEDB, computes a key MKAˆ¥KEIA and first encrypted authentication data AuthEncDataB, and sends the NBˆ¥NAˆ¥AuthEncDataB to the entity A for verification; the entity A generates a random number ZSEEDA, computes second encrypted authentication data AuthEncDataA, a shared key seed Z, a master key MK and a first message authentication identifier MacTagA, and sends the NAˆ¥NBˆ¥AuthEncDataAˆ¥MacTagA to the entity B for verification; the entity B computes Z, MK and MacTagA, compares the MacTagAwith the received MacTagA, and if the two are equal, considers that the entity A is valid; the entity B computes and sends a second message authentication identifier MacTagB to the entity A; and the entity A computes MacTagB, compares the MacTagB with the received MacTagB, and if the two are equal, considers that the entity B is valid. The device of the present invention is corresponding to the entity A and the entity B in the method. The present invention can achieve bidirectional authentication between network entities and determine the identity of the other party, and greatly improves the efficiency and reduces the consumption of hardware computing resources.
机译:本发明涉及网络安全技术领域。提供了一种基于预共享密钥的实体认证方法和设备。该方法包括:实体A生成随机数NA并将其发送给实体B;实体B生成随机数NB和ZSEEDB,计算密钥MKAˆKEIA和第一加密认证数据AuthEncDataB,并将NBˆNAˆAuthEncDataB发送给实体A进行验证。实体A生成随机数ZSEEDA,计算第二加密认证数据AuthEncDataA,共享密钥种子Z,主密钥MK和第一消息认证标识符MacTagA,并将NAˆ¥NBˆ¥AuthEncDataAˆ¥MacTagA发送给实体B进行验证;实体B计算Z,MK和MacTagA,比较MacTagA和接收到的MacTagA,如果两者相等,则认为实体A有效。实体B计算并发送第二消息认证标识MacTagB至实体A;实体A计算MacTagB,将MacTagB与接收到的MacTagB进行比较,如果两者相等,则认为实体B有效。本发明的装置对应于该方法中的实体A和实体B。本发明可以实现网络实体之间的双向认证,可以确定对方的身份,大大提高了效率,减少了硬件计算资源的消耗。

著录项

  • 公开/公告号EP3208967B1

    专利类型

  • 公开/公告日2020-04-22

    原文格式PDF

  • 申请/专利权人 CHINA IWNCOMM CO. LTD.;

    申请/专利号EP20150851121

  • 申请日2015-06-23

  • 分类号H04L9/32;H04W12/04;

  • 国家 EP

  • 入库时间 2022-08-21 11:42:10

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号