首页> 外国专利> METHOD FOR ELECTRONIC SIGNING AND AUTHENTICATON STRONGLY LINKED TO THE AUTHENTICATOR FACTORS POSSESSION AND KNOWLEDGE

METHOD FOR ELECTRONIC SIGNING AND AUTHENTICATON STRONGLY LINKED TO THE AUTHENTICATOR FACTORS POSSESSION AND KNOWLEDGE

机译:电子签名和认证的方法与认证者的拥有和知识密切相关

摘要

The invention consists of a method for a user to generate digital signatures based on a device, e.g. a smart phone, and secret knowledge of the user (Personal Identification Number or PIN) that are completely under control of the user. Characteristic of the invention is that it is based on a software application (A-APP) in the device that innovatively uses a secure part of the device (Secure Cryptographic Environment or SCE) to bind the signature to both the possession of the SCE and the secret knowledge of the user to the digital signature in such a way that the resulting digital signatures complies with regular digital signatures standards. In effect it is like the SCE has implemented a PIN that only allows access to the digital signature generation function after the user has correctly entered that whereas in reality the SCE is completely oblivious of the PIN. Part of the invention is letting a certificate issuer place the generated public keys in digital certificates together with user information. The invention also entails various applications of the method and system including the setup of a centralized authentication provider providing user authentication and the direct use of the setup of service providers to authenticate users and providing additional services including remote signing. By placing a separated, trusted environment within the authentication provider or certificate issuer the invention caters for privacy friendly authentication mechanisms.
机译:本发明包括一种用于用户基于设备(例如智能手机)生成数字签名的方法,以及完全在用户控制下的用户秘密知识(个人识别号或PIN)。本发明的特征在于,它基于设备中的软件应用(a-APP),该应用创新地使用设备的安全部分(安全加密环境或SCE)将签名绑定到SCE的拥有以及用户的秘密知识到数字签名,从而生成的数字签名符合常规数字签名签名标准。实际上,这就像SCE实现了一个PIN,只有在用户正确输入后才允许访问数字签名生成功能,而实际上SCE完全不知道PIN。本发明的一部分是让证书颁发者将生成的公钥与用户信息一起放入数字证书中。本发明还涉及该方法和系统的各种应用,包括设置提供用户认证的集中认证提供商,以及直接使用服务提供商的设置来认证用户,并提供包括远程签名的附加服务。通过在认证提供者或证书颁发者内放置分离的、可信的环境,本发明迎合了隐私友好的认证机制。

著录项

  • 公开/公告号WO2022050833A1

    专利类型

  • 公开/公告日2022-03-10

    原文格式PDF

  • 申请/专利权人 KEYCONTROLS;

    申请/专利号WO2021NL00012

  • 发明设计人 VERHEUL ERIC ROBERT;

    申请日2021-08-24

  • 分类号H04L9/32;

  • 国家 NL

  • 入库时间 2022-08-24 23:51:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号