Invention Grant
US08447982B2 System and method for operating end-to-end security channel between server and IC card 有权
在服务器和IC卡之间运行端到端安全通道的系统和方法

  • Patent Title: System and method for operating end-to-end security channel between server and IC card
  • Patent Title (中): 在服务器和IC卡之间运行端到端安全通道的系统和方法
  • Application No.: US12811470
    Application Date: 2008-10-31
  • Publication No.: US08447982B2
    Publication Date: 2013-05-21
  • Inventor: Sung-man Lee
  • Applicant: Sung-man Lee
  • Agency: The H.T. Than Law Group
  • Priority: KR10-2008-0000175 20080102; KR10-2008-0000186 20080102
  • International Application: PCT/KR2008/006454 WO 20081031
  • International Announcement: WO2009/084806 WO 20090709
  • Main IPC: H04L29/06
  • IPC: H04L29/06
System and method for operating end-to-end security channel between server and IC card
Abstract:
The present invention relates to a system and method for operating an end-to-end security channel between an IC card and a server on a communication network. A method for connecting an end-to-end security channel between an IC card and a server on a communication network includes the steps of: generating, by the server, a random number Rs for transmission to the IC card, generating an E(Rs) by encrypting the random number Rs by a user public key, and transmitting the E(Rs) to the IC card through the communication network; receiving, by the IC card, the E(Rs) through the communication network and extracting the random number Rs by decrypting the E(Rs) by a user private key; generating, by the IC card, a random number Rc to be transmitted to the server, generating a session key K′ by the random number Rs and the random number Rc, and generating a first card verifier MAC by encrypting the random number Rs by the session key K′; transmitting, by the IC card, the random number Rc and the first card verifier MAC to the server through the communication network; receiving, by the server, the random number Rc and the first card verifier MAC through the communication network, generating a session key K by the random number Rs and the random number Rc, and generating a first server verifier MAC by encrypting the random number Rs by the session key K; and comparing, by the server, the first card verifier MAC and the first server verifier MAC to certify the session key K.
Information query
Patent Agency Ranking
0/0