首页> 外国专利> Method and means for combining and managing personal verification and message authentication encryptions for network transmission

Method and means for combining and managing personal verification and message authentication encryptions for network transmission

机译:组合和管理用于网络传输的个人验证和消息认证加密的方法和装置

摘要

The method and means of transmitting a user's transaction message to a destination node in a computer-secured network operates on the message, and a sequence number that is unique to the transaction message to form a message authentication code in combination with the user's personal identification number. The message authentication code is encrypted with a generated random number and a single session encryption key which also encrypts the user's personal identification number. An intermediate node may receive the encryptions to reproduce the personal identification number that is then used to encrypt the received message and sequence number to produce the random number and a message authentication code for comparison with a decrypted message authentication code. Upon favorable comparison, the random number and the message authentication code are encrypted with a second session encryption key to produce an output code that is transmitted to the destination node along with an encrypted personal identification number. There, the received encryptions are decrypted using the second session key to provide the personal identification number for use in encrypting the message and sequence number to produce a message authentication code for comparison with a decrypted message authentication code. Upon favorable comparison, the transaction is completed and a selected portion of the decrypted random number is returned to the originating node for comparison with the corresponding portion of the random number that was generated there. Upon unfavorable comparison at the destination node or at an intermediate node, a different portion of the decrypted random number is returned to the originating node for comparison with the corresponding portion of the random number that was generated there. The comparisons at the originating node provide an unambiguous indication of the completion or non-completion of the transaction at the destination node.
机译:将用户的交易消息发送到计算机安全网络中的目标节点的方法和装置对消息进行操作,并且该交易消息唯一的序列号与用户的个人识别码结合形成消息验证码。消息身份验证代码使用生成的随机数和单个会话加密密钥进行加密,该会话加密密钥还对用户的个人标识号进行加密。中间节点可以接收加密以再现个人标识号,然后该个人标识号用于对接收到的消息和序列号进行加密以产生随机数和消息认证码,以与解密的消息认证码进行比较。通过有利的比较,该随机数和消息验证码用第二个会话加密密钥加密,以生成输出码,该输出码与加密的个人识别码一起发送到目标节点。在那里,使用第二会话密钥对接收到的加密进行解密,以提供用于加密消息的个人识别码和序列号,以生成消息认证码,以与解密后的消息认证码进行比较。经过有利的比较,交易完成,解密后的随机数的选定部分返回到始发节点,以便与随机数的相应部分进行比较!<!-EPO ->是在那里产生的。在目的地节点或中间节点处进行不利的比较时,将解密后的随机数的不同部分返回到原始节点,以与在此处生成的随机数的相应部分进行比较。原始节点上的比较提供了目标节点上事务完成或未完成的明确指示。

著录项

  • 公开/公告号EP0678836B1

    专利类型

  • 公开/公告日1998-01-14

    原文格式PDF

  • 申请/专利权人 TANDEM COMPUTERS INC;

    申请/专利号EP19940105573

  • 发明设计人 HOPKINS W. DALE;ATALLA MARTIN M.;

    申请日1994-04-11

  • 分类号G07F7/10;

  • 国家 EP

  • 入库时间 2022-08-22 02:50:24

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号