首页> 外国专利> System and method for authentication in a crypto-system utilizing symmetric and asymmetric crypto-keys

System and method for authentication in a crypto-system utilizing symmetric and asymmetric crypto-keys

机译:在利用对称和非对称加密密钥的加密系统中进行认证的系统和方法

摘要

A system and method for authentication of a crypto-system user is provided. A user is authenticated by the use of both symmetric and asymmetric crypto-keys. A user associated with a first asymmetric crypto-key having a public portion and multiple private portions is represented by a first network station. The user transmits a first request for authentication to a second network station. The second network station is associated with a second asymmetric crypto-key having a public portion and at least one private portion. A first one of the multiple private portions of the first crypto-key is stored at the second network station. The second network station generates a shared symmetric crypto-key and encrypts the shared crypto-key with the first private portion of the first crypto-key to form a first message. The second network station signs the first message with a private portion of the second crypto-key and transmits the first message to the first network station. The second network station also encrypts the shared crypto-key with the public portion of a third crypto-key to form a second message. The second network station signs the second message and transmits it to a third network station. The third network station, associated with the third crypto-key, authenticates the second network station, further encrypts the second message with a second private portion of the first crypto-key stored at the third network station, forming a third message. The third network station transmits the third message to the first network station. The first network station authenticates the first network station, combines the first and third messages to form a fourth message, further encrypts the fourth message with another private portion of the first crypto-key, forming a fifth message. The first network station applies the public portion of the first crypto-key to the fifth message to recover the shared crypto-key. The first network station encrypts a second authentication request with the shared crypto-key to form a sixth message, and transmits the sixth message to authenticate the user.
机译:提供了一种用于认证密码系统用户的系统和方法。通过使用对称和非对称加密密钥对用户进行身份验证。与具有公共部分和多个私有部分的第一非对称加密密钥相关联的用户由第一网络站表示。用户向第二网络站发送第一认证请求。第二网络站与具有公共部分和至少一个私有部分的第二非对称加密密钥相关联。第一加密密钥的多个私有部分中的第一个被存储在第二网络站处。第二网络站产生共享的对称密码,并用第一密码的第一私有部分对共享的密码进行加密,以形成第一消息。第二网络站用第二加密密钥的私有部分对第一消息进行签名,并将第一消息发送到第一网络站。第二网络站还用第三加密密钥的公共部分加密共享加密密钥,以形成第二消息。第二网络站对第二消息进行签名并将其发送到第三网络站。与第三加密密钥相关联的第三网络站点对第二网络站点进行认证,并进一步利用存储在第三网络站点的第一加密密钥的第二私有部分来加密第二消息,从而形成第三消息。第三网络站将第三消息发送到第一网络站。第一网络站对第一网络站进行认证,将第一消息和第三消息组合以形成第四消息,并进一步用第一加密密钥的另一私有部分对第四消息进行加密,从而形成第五消息。第一网络站将第一加密密钥的公共部分应用于第五消息,以恢复共享的加密密钥。第一网络站使用共享的加密密钥加密第二认证请求以形成第六消息,并发送第六消息以认证用户。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号