首页> 外国专利> STRONG AUTHENTICATION TOKEN USABLE WITH A PLURALITY OF INDEPENDENT APPLICATION PROVIDERS

STRONG AUTHENTICATION TOKEN USABLE WITH A PLURALITY OF INDEPENDENT APPLICATION PROVIDERS

机译:可用于众多独立应用程序提供者的强大认证令牌

摘要

The present invention defines a strong authentication token for generating different dynamic credentials for different application providers comprising an input interface providing an output representing an application provider indicator; a secret key storage for storing one or more secret keys; a variability source for providing a dynamic variable value; a key providing agent for providing an application provider specific key as a function of said application provider indicator using one or more keys stored in said secret key storage; a cryptographic agent for cryptographically combining said application provider specific key with said dynamic variable value using symmetric cryptography; a transformation agent coupled to said cryptographic agent for transforming an output of said cryptographic agent to produce a dynamic credential; and an output interface to output said dynamic credential. The present invention defines furthermore a method to manage the secret keys of strong authentication tokens that can generate dynamic credentials for more than one supported application provider or application provider group using different secret keys for each supported application provider or application provider group comprising generating for each of a batch of strong authentication tokens a token specific master key; personalizing each token of said batch with the token specific master key associated with said token; generating for each of a plurality of supported application providers or application provider groups a set of application provider specific token keys, one application provider specific token key for each token of said batch, whereby each application provider specific token key of each of said sets is derived from that token's token specific master key and a unique identifier or indicator of that application provider or application provider group; providing to each application provider or an entity that is responsible for the verification on behalf of said application provider of the dynamic credentials that are generated for said application provider, the corresponding set of application provider specific token keys.
机译:本发明定义了一种强认证令牌,用于为不同的应用程序提供者生成不同的动态证书,包括输入接口,该接口提供代表应用程序提供者指示符的输出。秘密密钥存储器,用于存储一个或多个秘密密钥;用于提供动态变量值的可变性源;密钥提供代理,用于使用存储在所述秘密密钥存储器中的一个或多个密钥,根据所述应用提供者指示符来提供应用提供者特定的密钥;加密代理,用于使用对称加密将所述应用提供商特定密钥与所述动态变量值进行加密结合;转换代理,耦合到所述密码代理,用于转换所述密码代理的输出以产生动态证书;输出接口,用于输出所述动态证书。本发明还定义了一种管理强认证令牌的密钥的方法,该强认证令牌的密钥可以使用每个受支持的应用程序提供商或应用程序提供商组的不同密钥为多个受支持的应用程序提供商或应用程序提供商组生成动态凭证。一批强身份验证令牌,令牌特定的主密钥;用与所述令牌相关联的令牌专用主密钥来个性化所述批次的每个令牌;为多个受支持的应用程序提供者或应用程序提供者组中的每一个生成一组应用程序提供者特定的令牌密钥,为所述批次的每个令牌生成一个应用程序提供者特定的令牌密钥,从而得出每个所述集合的每个应用程序提供者特定的令牌密钥来自该令牌的令牌特定主密钥以及该应用程序提供商或应用程序提供商组的唯一标识符或指示符;向每个应用程序提供者或代表该应用程序提供者负责为该应用程序提供者生成的动态证书的验证的实体提供相应的应用程序提供者特定令牌密钥集。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号