首页> 外国专利> A SYSTEM AND METHOD FOR CRYPTOGRAPHIC INTERACTIONS FOR AUTHENTICATION AND AUTHORIZATION USING OUT-OF-BAND INPUTS AND OUTPUTS

A SYSTEM AND METHOD FOR CRYPTOGRAPHIC INTERACTIONS FOR AUTHENTICATION AND AUTHORIZATION USING OUT-OF-BAND INPUTS AND OUTPUTS

机译:使用带外输入和输出进行身份验证和授权的密码交互的系统和方法

摘要

Cryptographic interactions for authentication and authorization is mediated by means of visual inputs (via camera) and outputs (graphical display) using visual channel as out-of-band (OOB) medium for cryptographic handshaking based on strong public-key protocols. The system comprising at least one out-of-band (OOB) channel which allows machine to machine and machine to user interaction using same input and output devices; and bidirectional actions which comprises at least one or both entities computing and transmitting action parameter at remote entity. The at least one out-of-band (OOB) channel is deployed for entirety of interaction sequences in different phases of the system which allows machine to machine and machine to user interaction that adopts visual codes of cryptographic parameters. The general methodology of the present invention comprising steps of initializing interaction between entities (202); computing action through ZK integration of commitment of entity credentials on challenge (204) upon obtaining password from user (206); encoding cryptographic codeword used in computing actions (208) into machine readable visual representation to be displayed (210); decoding received barcodes from other interacting entities (214) into internal representations (212); synchronizing computation on each entity (216); determining if outcome of computation is correct (218); presenting outcome as image-based visualization if computation is correct (222, 224); and transmitting said image-based visualization with equivalent computation of other entity (228) as perceptible images on visual outputs (232). Cryptographic interactions of the present invention fully utilize visual inputs and outputs capabilities without having requirement of additional hardware tokens, and without external connectivity or TTP (trusted third party) involvement provided trusted device associated with user of interest is capable of undertaking the necessary computations.
机译:用于身份验证和授权的密码交互是通过视觉输入(通过摄像机)和输出(图形显示)来实现的,这些输入使用视觉通道作为带外(OOB)介质,用于基于强公钥协议的加密握手。该系统包括至少一个带外(OOB)信道,该信道允许机器对机器和机器对用户使用相同的输入和输出设备进行交互;双向动作,其包括至少一个实体或两个实体,在远程实体处计算和发送动作参数。至少一个带外(OOB)通道被部署用于系统不同阶段中的整个交互序列,从而允许机器对机器以及机器对用户的交互采用密码参数的可视代码。本发明的一般方法包括初始化实体之间的交互的步骤(202);在从用户(206)获得密码之后,通过对挑战(204)上的实体证书的承诺的ZK集成来计算动作;将在计算动作中使用的密码码字(208)编码为机器可读的视觉表示以进行显示(210);将从其他交互实体(214)接收到的条形码解码为内部表示(212);在每个实体上同步计算(216);确定计算结果是否正确(218);如果计算正确,则将结果呈现为基于图像的可视化(222、224);以及与其他实体(228)的等效计算作为可视输出(232)上的可感知图像一起传输所述基于图像的可视化。本发明的密码交互作用充分利用视觉输入和输出能力,而不需要附加的硬件令牌,并且不需要外部连接性或TTP(可信第三方)的介入,只要与感兴趣的用户相关联的可信设备能够进行必要的计算即可。

著录项

  • 公开/公告号WO2015076657A1

    专利类型

  • 公开/公告日2015-05-28

    原文格式PDF

  • 申请/专利权人 MIMOS BERHAD;

    申请/专利号WO2014MY00110

  • 发明设计人 GOH ALWYN;SEA CHONG SEAK;NG KANG SIONG;

    申请日2014-05-23

  • 分类号H04L29/06;

  • 国家 WO

  • 入库时间 2022-08-21 15:06:24

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号