发明授权
- 专利标题: Scalable authentication system
- 专利标题(中): 可扩展认证系统
-
申请号: US14382942申请日: 2013-02-14
-
公开(公告)号: US09369464B2公开(公告)日: 2016-06-14
- 发明人: Basil Philipsz
- 申请人: DISTRIBUTED MANAGEMENT SYSTEMS LTD.
- 申请人地址: GB Blackburn
- 专利权人: DISTRIBUTED MANAGEMENT SYSTEMS LTD.
- 当前专利权人: DISTRIBUTED MANAGEMENT SYSTEMS LTD.
- 当前专利权人地址: GB Blackburn
- 代理机构: Hoffman Warnick LLC
- 优先权: GB1204202.4 20120309
- 国际申请: PCT/GB2013/050341 WO 20130214
- 国际公布: WO2013/132224 WO 20130912
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
Disclosed is a key management method for administering a token with an administrative server and an authentication server wherein a set of keys stored therein in use differs so that at least a mutually exclusive key is stored in each of the token, the administrative server or the authentication server, the method comprising the steps of: the token transmitting an identity proxy ID 1 encrypted with an encryption key Key 1; the administrative server generating data Key 1a and Key 1b from Key 1 stored therein, whereby Key 1a and Key 1b can be used in conjunction to derive Key 1 but not separately; the administrative server generating an identity proxy ID 2 and an encryption key Key 2, whereby the administrative server records a token profile comprising an association information among ID 2, Key 1b and Key 2; the administrative server communicating ID 2, Key 1a and Key 2 to the token and the token storing ID 2, Key 1a and Key 2 wherein Key 2 is stored therein encrypted with Key 1; the administrative server communicating the token profile to the authentication server and deleting Key 1b and Key 2 from its records thereafter; the authentication server requesting ID 2 from the token and the token transmitting ID 2 thereto; the authentication server identifying Key 1b and Key 2 associated with the transmitted ID 2 and generating a new encryption key Key 3; the authentication server recording Key 3's association with ID 2 in the token profile and communicating Key 3 to the token; and the token storing Key 3 therein encrypted with Key 2, whereby the administrative server stores ID 1, ID 2 and Key 1, the authentication server stores ID 2, Key 1b, Key 2, and Key 3, and the token stores ID 1, ID 2, Key 1a, Key 2, and Key 3, wherein the token stores Key 2 encrypted with Key 1 and stores Key 3 encrypted with Key 2 therein.
公开/授权文献
- US20150046695A1 SCALABLE AUTHENTICATION SYSTEM 公开/授权日:2015-02-12
信息查询