首页> 外国专利> Method and system for key distribution comprising a step of authentication and a step of key distribution using a KEK (key encryption key)

Method and system for key distribution comprising a step of authentication and a step of key distribution using a KEK (key encryption key)

机译:用于密钥分发的方法和系统,包括认证步骤和使用KEK(密钥加密密钥)的密钥分发步骤

摘要

A method for protecting the transfer and storage of data by encryption using a private key encrypted with a first key encrypting key, which is encrypted using a second key encrypting key. This latter key is encrypted using a hashed passphrase value, obtained by hashing a passphrase known only to the authorized user. Upon receipt of a request initiated by the user by entering a passphrase, a first hashed passphrase is transferred to a first data processing system, where it is compared with a predefined hash string. If they match, the first data processing system transfers to a second data processing system the encrypted second key encrypting key. A candidate key is obtained by decrypting the encrypted second key encrypting key using a second hashed passphrase. Upon successful validation of the candidate key, the passphrase is verified and the user is authenticated. After the user has been authenticated, the first data processing system transmits to the second data processing system the encrypted private key and the encrypted data. The second processing system then decrypts the encrypted first key encrypting key using the second key encrypting key, decrypts the encrypted private key using the first key encrypting key and finally decrypts the data using the private key.
机译:一种用于通过使用由第一密钥加密密钥加密的私钥进行加密来保护数据的传输和存储的方法,该私钥使用第二密钥加密密钥加密。后一个密钥使用散列的密码短语值加密,该值是通过散列仅授权用户已知的密码短语而获得的。在接收到用户通过输入密码短语发起的请求后,第一哈希密码短语将被传输到第一数据处理系统,在此将其与预定义的哈希字符串进行比较。如果它们匹配,则第一数据处理系统将加密的第二密钥加密密钥传送到第二数据处理系统。通过使用第二散列密码短语解密加密的第二密钥加密密钥来获得候选密钥。成功验证候选密钥后,便会验证密码短语并验证用户身份。在用户已经被认证之后,第一数据处理系统将加密的私钥和加密的数据发送到第二数据处理系统。然后,第二处理系统使用第二密钥加密密钥解密加密的第一密钥加密密钥,使用第一密钥加密密钥解密加密的私钥,最后使用私钥解密数据。

著录项

  • 公开/公告号EP1501238B1

    专利类型

  • 公开/公告日2007-11-14

    原文格式PDF

  • 申请/专利权人 EISST LTD;

    申请/专利号EP20030016787

  • 发明设计人 RONCHI CORRADO;ZAKHIDOV SHUKHRAT;

    申请日2003-07-23

  • 分类号H04L9/30;H04L9/32;G06F1;

  • 国家 EP

  • 入库时间 2022-08-21 20:00:51

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号