首页> 外国专利> SYSTEM FOR MANAGING ACCESS TO RESOURCES OF A FIRST ELECTRONIC DEVICE'S APPLICATION BY A SECOND ELECTRONIC DEVICE ON A REMOTE SERVER

SYSTEM FOR MANAGING ACCESS TO RESOURCES OF A FIRST ELECTRONIC DEVICE'S APPLICATION BY A SECOND ELECTRONIC DEVICE ON A REMOTE SERVER

机译:远程服务器上的第二电子设备管理第一电子设备的资源访问的系统

摘要

The present invention relates to a system (SYS) for managing access to resources (Re) of a first application (App1) of a first electronic device (D1) stored on a remote server (RS), said system (SYS) comprising said first electronic device (D1), a second electronic device (D2) comprising a second application (App2) and said remote server (RS) providing services (Sv), wherein: said second electronic device (D2) is adapted to: receive from said first electronic device (D1) via a secured communication link (Ls) second credentials (Cr2) comprising an identifier (Id1) for said second application (App2) and a derived key (Dk) based on a first credential (Cr1) comprising a master key (Mk1) provided by said remote server (RS) to said first electronic device (D1); and send to said remote server (RS) a first access request (Rq1) to access to said resources (Re), said first access request (Rq1) comprising said identifier (Id1); said remote server (RS) is adapted to: receive from said second electronic device (D2) said first access request (Rq1); - perform a challenge-response authentication of said second electronic device (D2), said challenge (Ch) being a random or non- predictable number and said response (Rp) comprising a signature (Sg1) computed with said derived key (Dk); if said second electronic device (D2) is authenticated, grant access for said second application (App2) of said second electronic device (D2) to said resources (Re).
机译:本发明涉及一种用于管理对存储在远程服务器(RS)上的第一电子设备(D1)的第一应用(App1)的资源(Re)的访问的系统(SYS),所述系统(SYS)包括所述第一服务器。电子设备(D1),第二电子设备(D2),包括第二应用程序(App2)和提供服务(Sv)的所述远程服务器(RS),其中:所述第二电子设备(D2)用于:从所述第一电子设备(D2)接收经由安全通信链路(Ls)的电子设备(D1),第二凭证(Cr2),包括用于所述第二应用(App2)的标识符(Id1)和基于包括主密钥的第一凭证(Cr1)的派生密钥(Dk) (Mk1)由所述远程服务器(RS)提供给所述第一电子设备(D1);并向所述远程服务器(RS)发送用于访问所述资源(Re)的第一访问请求(Rq1),所述第一访问请求(Rq1)包括所述标识符(Id1);所述远程服务器(RS)适于:从所述第二电子设备(D2)接收所述第一访问请求(Rq1); -对所述第二电子设备(D2)执行挑战-响应认证,所述挑战(Ch)是随机或不可预测的数字,并且所述响应(Rp)包括由所述导出密钥(Dk)计算出的签名(Sg1);如果所述第二电子设备(D2)被认证,则向所述资源(Re)授权所述第二电子设备(D2)的所述第二应用(App2)的访问。

著录项

  • 公开/公告号WO2016091959A1

    专利类型

  • 公开/公告日2016-06-16

    原文格式PDF

  • 申请/专利权人 GEMALTO SA;

    申请/专利号WO2015EP79140

  • 发明设计人 PHAN LY THANH;TOURNIER DIDIER;

    申请日2015-12-09

  • 分类号G06F21/60;G06F21/30;G06F21/44;G06F21/62;G06F9/46;

  • 国家 WO

  • 入库时间 2022-08-21 14:17:31

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号