首页> 外国专利> A computer implemented system and method for lightweight authentication on datagram transport for internet of things

A computer implemented system and method for lightweight authentication on datagram transport for internet of things

机译:用于物联网数据报传输的轻量级认证的计算机实现的系统和方法

摘要

#$%^&*AU2014265030B220160421.pdf#####ABSTRACT A computer implemented system and method for lightweight authentication on datagram transport for internet of things provides a robust authentication scheme based on challengeresponse type of exchanges between two endpoints sharing a pre-shared secret. A symmetric key-based security mechanism is utilized in the present disclosure where key management is integrated with authentication. It provides mutual authentication wherein the end-points in the system are provisioned with a pre-shared secret during a provisioning phase and a client database is provided at the server side for client identification. The system comprises random number generators for generation of nonces, and key generators to generate secret key and session key. The nonces and keys are valid only during the session and thus help in providing secure authentication across sessions. The system can be further adapted on transport layer security protocols like DTLS and can be integrated with application layer protocols like CoAP for constrained devices. 222/8 200 Authentication request from client with a unique id Client response encrypted with - 206 received key and nonce challenge 202 Server challenge to client with to server nonce including keying element 204 Server challenge deciphered 208 at client with shared secret Client response No satisfies the server 212 Client not authenticated Yes Client authenticated and key 210 sharing completion Server response to client 214 challenge 220 Server not No Server response Servr no Nosatisfies the authenticated c client challenge? Yes Server authenticated 218 222 N Secure channel establishment with key sharing FIGURE 2
机译:#$%^&* AU2014265030B220160421.pdf #####抽象用于数据报的轻量级认证的计算机实现的系统和方法物联网传输提供了基于质询的可靠认证方案共享预共享机密的两个端点之间的交换的响应类型。对称的在本公开中利用基于密钥的安全机制,其中密钥管理是与身份验证集成。它提供相互认证,其中端点位于系统在预配阶段预配了预共享的机密,并且客户端服务器端提供数据库用于客户端标识。系统包括随机用于生成随机数的数字生成器,以及用于生成秘密密钥和会话密钥。随机数和密钥仅在会话期间有效,因此有助于提供跨会话的安全身份验证。该系统可以进一步适应DTLS等传输层安全协议,并且可以与受限设备的应用层协议(例如CoAP)集成。222/8200认证请求来自具有唯一ID的客户客户端响应使用-206加密收到了密钥和随机数挑战202服务器对客户端与服务器的挑战随机数,包括键元素204服务器质询破译208在客户端使用共享的秘密客户端响应没有满足服务器212客户端不认证是客户端身份验证和密钥210分享完成服务器对客户端214的响应挑战220服务器不是没有服务器响应伺服器不满足认证的c客户挑战?是服务器认证218222 N使用密钥建立安全通道分享图2

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号