首页> 外国专利> A STRONG AUTHENTICATION TOKEN GENERATING ONE-TIME PASSWORDS AND SIGNATURES UPON SERVER CREDENTIAL VERIFICATION

A STRONG AUTHENTICATION TOKEN GENERATING ONE-TIME PASSWORDS AND SIGNATURES UPON SERVER CREDENTIAL VERIFICATION

机译:服务器身份验证后生成一次密码和签名的强认证令牌

摘要

The invention defines a strong authentication token that remedies a vulnerability to a certain type of social engineering attacks, by authenticating the server or messages purporting to come from the server prior to generating a one-time password or transaction signature; and, in the case of the generation of a transaction signature, signing not only transaction values but also transaction context information and, prior to generating said transaction signature, presenting said transaction values and transaction context information to the user for the user to review and approve. It furthermore offers this authentication and review functionality without sacrificing user convenience or cost efficiency, by judiciously coding the transaction data to be signed, thus reducing the transmission size of information that has to be exchanged over the token's interfaces.
机译:本发明定义了一种强认证令牌,该令牌通过在生成一次性密码或交易签名之前认证服务器或声称来自服务器的消息来补救对某种类型的社会工程学攻击的脆弱性;并且,在生成交易签名的情况下,不仅对交易价值进行签名,而且还对交易上下文信息进行签名,并且在生成所述交易签名之前,将所述交易价值和交易上下文信息呈现给用户以供用户查看和批准。 。此外,它通过明智地编码要签名的交易数据,从而在不牺牲用户便利性或成本效率的情况下提供了这种身份验证和审核功能,从而减小了必须在令牌接口上交换的信息的传输大小。

著录项

  • 公开/公告号EP3156929A1

    专利类型

  • 公开/公告日2017-04-19

    原文格式PDF

  • 申请/专利权人 VASCO DATA SECURITY INTERNATIONAL GMBH;

    申请/专利号EP20160197842

  • 发明设计人 MENNES FREDERIK;HOORNAERT FRANK;

    申请日2009-03-11

  • 分类号G06F21/33;G06Q20/00;G06F21/34;H04L9/32;

  • 国家 EP

  • 入库时间 2022-08-21 14:04:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号