首页> 外国专利> A SYSTEM AND METHOD FOR PROTECTION OF USER AUTHENTICATION AGAINST CAPTURE-AND-REPLAY ATTACKS

A SYSTEM AND METHOD FOR PROTECTION OF USER AUTHENTICATION AGAINST CAPTURE-AND-REPLAY ATTACKS

机译:一种针对捕获和重放攻击保护用户认证的系统和方法

摘要

The present invention relates to a system (100, 200) and method (300) for protection of user authentication against at least single instance of capture-and-replay attacks, by means of input and processing of user credentials on a client-side user interface (Ul), and subsequent transmission to a server undertaking credential authentication. The system (100, 200) and method (300) of the present invention utilizes credentials which are context dependent as inputs into ZK integration function which is additionally applicable as an interaction in two actions: firstly between user and trusted platform, and secondly between trusted platform and client terminal, as similarly protective of user authentication against capture-and-replay- attacks. The user submits credentials as an act of authentication based on context of interest (310) as deemed correct by user. Optional verification of the submitted context-dependent credential (320) on the client terminal or trusted platform follows. The method (300) involves ZK integration of the context-dependent credential (330) followed by verification of the authenticator (340), such that unauthorised interception of credentials as submitted does not necessarily result in capability of intercepting party to undertake fraudulent authentication. Verification of user-to-server authentication interaction as being correct is additionally dependent on independent determination by server of context of interest, which might include specification and stratification of time and/or location of the authentication interaction.
机译:本发明涉及一种系统(100、200)和方法(300),其用于通过在客户端用户上输入和处理用户凭证来保护用户认证免受至少单个实例的捕获和重放攻击。接口(UI),并随后传输到进行凭证认证的服务器。本发明的系统(100、200)和方法(300)利用依赖于上下文的凭证作为ZK集成功能的输入,该ZK集成功能还可以用作两个动作的交互:首先在用户和可信平台之间,其次在可信平台之间。平台和客户终端,以同样的方式保护用户身份免受捕获和重放攻击。用户基于用户认为正确的感兴趣的上下文(310)提交凭证作为认证动作。接下来是在客户端或可信平台上对所提交的上下文相关证书(320)的可选验证。方法(300)包括上下文相关凭证(330)的ZK集成,然后是认证器(340)的验证,使得提交的凭证的未授权拦截不一定导致拦截方进行欺诈性认证的能力。用户到服务器认证交互的验证是否正确还取决于服务器对感兴趣上下文的独立确定,这可能包括认证交互的时间和/或位置的指定和分层。

著录项

  • 公开/公告号WO2015088315A1

    专利类型

  • 公开/公告日2015-06-18

    原文格式PDF

  • 申请/专利权人 MIMOS BERHAD;

    申请/专利号WO2014MY00164

  • 发明设计人 GOH ALWYN;POH GEONG SEN;NG KANG SIONG;

    申请日2014-06-05

  • 分类号H04L9/30;H04L29/06;

  • 国家 WO

  • 入库时间 2022-08-21 15:05:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号