首页> 外国专利> Secure mutual network authentication and key exchange protocol

Secure mutual network authentication and key exchange protocol

机译:安全的相互网络身份验证和密钥交换协议

摘要

Secure communication protocols are disclosed in which two parties generate a shared secret which may be used as a secure session key for communication between the parties. The protocols are based on Diffie-Hellman type key exchange in which a Diffie-Hellman value is combined with a function of at least a password using the group operation such that the Diffie-Hellman value may be extracted by the other party using the inverse group operation and knowledge of the password. In one embodiment, each of the parties explicitly authenticates the other party, while in another embodiment, the parties utilize implicit authentication relying on the generation of an appropriate secret session key to provide the implicit authentication. Typically, the parties will be a client computer and a server computer. In accordance with other embodiments of the invention, in order to protect against a security compromise at the server, the server is not in possession of the password, but instead is provided with, and stores, a so-called password verifier which is a function of the password and where the password itself cannot be determined from the value of the password verifier.
机译:公开了一种安全通信协议,其中,两个当事方生成共享秘密,该秘密可以用作当事方之间进行通信的安全会话密钥。协议基于Diffie-Hellman类型的密钥交换,其中使用组操作将Diffie-Hellman值与至少一个密码的功能组合在一起,以便另一方可以使用逆组提取Diffie-Hellman值操作和密码知识。在一个实施例中,各方中的每一个都明确地认证另一方,而在另一实施例中,各方利用隐式认证,这依赖于适当的秘密会话密钥的产生以提供隐式认证。通常,参与方将是客户端计算机和服务器计算机。根据本发明的其他实施例,为了防止服务器上的安全性受损,服务器不拥有密码,而是被提供并存储所谓的密码验证器,该功能是功能。密码的含义,以及无法根据密码验证程序的值确定密码本身的地方。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号