首页> 外国专利> ADMINISTRATION AND UTILIZATION OF SECRET FRESH RANDOM NUMBERS IN A NETWORKED ENVIRONMENT

ADMINISTRATION AND UTILIZATION OF SECRET FRESH RANDOM NUMBERS IN A NETWORKED ENVIRONMENT

机译:网络环境中秘密新随机数的管理和利用

摘要

In a public key cryptosystem employing the El-Gamal algorithm, secret fresh random numbers are generated at a server and private keys of users, as encrypted with a symmetric algorithm by using individual user identifying keys determined by hashing the users' respective passphrases or biometric information (fingerprint, voiceprint, retina scan, or face scan) are maintained in a store accessible to the server, and the fresh random numbers and encrypted private keys are transmitted to the user equipment when needed via a network which is not secure. In order to prevent an attacker from discovering the random numbers or employing formerly used random numbers in a block replay attack, an interchange in the nature of a challenge response protocol is employed which passes at least one secret fresh random number from the server to the user equipment while also authenticating the user to the server. In this interchange, a first random number to be distributed to the user for use in signing a document and a second random number which is to be used by the user in forming a signature of a hashing together of the first and second random numbers as part of the challenge response protocol, are supplied to the user equipment in encrypted form together with a freshness value, and a signature by the server of a hashing together of the first and second random numbers and the freshness value.
机译:在采用El-Gamal算法的公钥密码系统中,在服务器和用户的私钥上会生成秘密的新鲜随机数,如使用对称算法进行加密,方法是使用散列用户各自的密码或生物特征信息确定的各个用户标识密钥,以对称算法进行加密(指纹,声纹,视网膜扫描或面部扫描)保存在服务器可访问的商店中,并且在需要时,通过不安全的网络将新的随机数和加密的私钥传输到用户设备。为了防止攻击者发现随机数或在块重播攻击中采用以前使用的随机数,采用了质询响应协议本质上的一种互换,该协议将至少一个秘密的新鲜随机数从服务器传递给用户。设备,同时还向服务器验证用户身份。在该交换中,将分发给用户以用于对文档进行签名的第一随机数和由用户在将第一随机数和第二随机数一起形成散列的签名时由用户使用的第二随机数挑战响应协议的“加密”与新鲜度值一起以加密形式提供给用户设备,并且由服务器将第一和第二随机数以及新鲜度值进行哈希处理的签名提供给用户设备。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号