Digital authentication over acoustic channel
Abstract
A device and method for digital authentication and verification are disclosed. In one embodiment, the authentication includes: storing an encryption key and a look-up table (LUT); using the encryption key to generate an access code; based on the access code, generating multiple parallel BPSK symbols; using the LUT, Converting the BPSK symbol into a plurality of tones encoded with the access code; outputting the plurality of tones encoded with the access code for authentication. In another embodiment, the verification includes: receiving multiple tones encoded with an access code; generating multiple parallel BPSK symbols based on the multiple tones; converting the BPSK symbols into coded interleaved bits of the access code Stream; de-interleave the coded interleaved bit stream; recover the access code from the coded de-interleaved bit stream.

Term
Term ended
Projected expiry passed 21 July 2024, 2.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
29 claims: 11 independent, 18 dependent
- 1第 1、 用于认证的装置,包括: 存储介质,用于存储加密密钥和查找表(LUT); 与所述存储介质相连的第一处理器,用于使用所述加密密钥来生 成访问码; 与所述处理器相连的转换器,用于将所述访问码转换成用所述访 问码编码的多个音调;以及 音频输出单元,用于输出用所述访问码编码的多个音调,以进行 认证; 其中,所述转换器包括: 二进制移相键控(BPSK)模块,用于生成多个并行的BPSK 符号;以及 与所述BPSK模块和所述存储介质相连的第二处理器,用于 使用所述LUT将所述BPSK符号转换成所述多个音调。
- 22、 如权利要求1所述的装置,其中,所述第一或第二处理器中 之一还将所述BPSK符号重复选定次数;以及 其中,所述第二处理器将重复的BPSK符号转换成所述多个音 调。
- 33、 如前述任一权利要求所述的装置,还包括: 与所述第一处理器相连的时钟模块,用于生成时间元素;以及 其中,所述第一处理器使用所述加密密钥和时间元素来生成所述 访问码。
- 44、 如前述任一权利要求所述的装置,还包括: 与所述第一处理器相连的致动器,用于接收用户命令;以及 其中,当收到所述用户命令时,所述第一处理器生成所述访问码。 200480021026.9 第
- 55、 如前述任一权利要求所述的装置,还包括: 容纳部件,用于包含所述存储介质、所述第一处理器、所述转换 器和所述音频输出单元;以及 穿过所述容纳部件的孔。
- 66、 如前述任一权利要求所述的装置,还包括: 与所述第一处理器相连的显示模块,用于显示所述访问码。
- 77、 如前述任一权利要求所述的装置,还包括: 用户输入端,用于接收个人标识号(PIN); 其中,所述转换器将所述PIN转换成用所述PIN编码的多个音 调;以及 其中,所述音频输出单元还输出用所述PIN编码的多个音调,以 进行认证。
- 88、 用于认证的装置,包括: 存储介质,用于存储加密密钥和查找表(LUT); 与所述存储介质相连的处理器,用于使用所述加密密钥来生成访 问码; 与所述处理器相连的转换器,用于将所述访问码转换成用所述访 问码编码的多个音调;以及 音频输出单元,用于输出用所述访问码编码的多个音调,以进行 认证; 其中,所述转换器包括: 二进制移相键控(BPSK)模块,用于生成多个并行的BPSK 符号;以及 其中,所述处理器使用所述LUT将所述BPSK符号转换成多个 音调。
- 99、用于认证的方法,包括:200480021026.9 第 存储加密密钥和查找表(LUT); 使用所述加密密钥来生成访问码; 基于所述访问码,生成多个并行的BPSK符号; 使用所述LUT,将所述BPSK符号转换成用所述访问码编码的 多个音调;以及 输出用所述访问码编码的多个音调,以进行认证。
- 1010、 如权利要求9所述的方法,包括: 在转换所述BPSK符号之前,将所述BPSK符号重复选定次数。
- 1111、 如权利要求10所述的方法,其中,重复所述BPSK符号的 步骤包括:将一组三BPSK符号重复所述选定次数;以及 其中,转换所述BPSK符号的步骤包括:使用所述LUT,将每 组三BPSK符号转换成所述多个音调。
- 1212、 如权利要求9或其从属权利要求10-11中任意一项所述的 方法,还包括: 将具有参考相位的参考音调加上所述多个音调;以及 将所述参考音调与所述多个音调一起输出。
- 1313、 如权利要求9或其从属权利要求10-12中任意一项所述的 方法,还包括生成时间元素;以及 其中,生成所述访问码的步骤包括:使用所述加密密钥和时间元 素来生成所述访问码。
- 1414、 如权利要求9或其从属权利要求10—13中任意一项所述的 方法,还包括接收用户命令;以及 其中,生成所述访问码的步骤包括:当收到所述用户命令时,生 成所述访问码。 200480021026.9 第
- 1515、 如权利要求9或其从属权利要求10-14中任意一项所述的 方法,还包括: 接收个人标识号(PIN); 将所述PIN转换成用所述PIN编码的多个音调;以及 输出用所述PIN编码的多个音调,以进行认证。
- 1616、 用于认证的装置,包括: 存储介质,用于存储加密密钥; 与所述存储介质相连的处理器,用于使用所述加密密钥来生成访 问码; 与所述处理器相连的转换器,用于将所述访问码转换成用所述访 问码编码的多个音调;以及 与所述转换器相连的音频输出单元,用于输出用所述访问码编码 的多个音调,以进行认证; 其中,所述转换器包括: 二进制移相键控(BPSK)模块,用于基于所述访问码生成 多个并行的重复BPSK符号; 与所述BPSK模块相连的快速傅立叶反变换(IFFT)模块, 用于对重复的BPSK符号执行IFFT,以生成代码符号;以及 与所述IFFT模块相连的上变频器,用于将所述代码符号调 制成用所述访问码编码的多个音调。
- 1717、 用于认证的方法,包括: 存储加密密钥; 使用所述加密密钥来生成访问码; 基于所述访问码,生成多个并行的二进制移相键控(BPSK)符 号; 在转换所述BPSK符号之前,将所述BPSK符号重复选定次数; 对重复的BPSK符号执行快速傅立叶反变换(IFFT),以生成IFFT 符号; 200480021026.9 第 将所述IFFT符号调制成用所述访问码编码的多个音调;以及 输出用所述访问码编码的多个音调,以进行认证。
- 1818、如权利要求17所述的方法,其中,重复所述BPSK符号的 步骤包括:将一组三BPSK符号重复所述选定次数;以及 其中,转换所述BPSK符号的步骤包括:使用所述LUT,将每 组三BPSK符号转换成所述多个音调。 19>用于验证的装置,包括: 音频输入单元,用于接收用访问码编码的多个音调; 与所述音频输入单元相连的转换器,用于从用所述访问码编码的 多个音调中恢复出所述访问码;以及 其中,所述转换器包括: 下变频器,用于将所述多个音调解调成IFFT符号; 快速傅立叶变换(FFT)模块,用于根据所述IFFT符号生 成多个并行的BPSK符号; 与所述处理器相连的BPSK模块,用于将所述BPSK符号转 换成所述访问码的编码交织比特流; 与所述BPSK模块相连的解交织器,用于将所述编码交织比 特流进行解交织;以及 与所述解交织器相连的解码模块,用于从所述编码解交织比 特流中恢复出所述访问码。
- 1920、 如权利要求19所述的装置,还包括: 存储介质,用于存储加密密钥; 与所述存储介质和所述转换器相连的处理器,用于使用所述加密 密钥来验证所述访问码,并且,如果证实了所述访问码,则准予访问。
- 2021、 如权利要求20所述的装置,其中,所述音频输入单元还接 收用个人标识号(PIN)编码的多个音调; 200480021026.9 第 其中,所述转换器还从用所述PIN编码的多个音调中恢复出所述 PIN;以及 其中,如果证实了所述访问码和所述PIN,则所述处理器也准予 访问。
- 2122、 如权利要求20或其从属权利要求21所述的装置,还包括: 与所述第一处理器相连的时钟模块,用于生成时间元素;以及 其中,所述处理器使用所述加密密钥和时间元素来验证所述访问 码。
- 2223、 如权利要求19或其从属权利要求20-22中任意一项所述的 装置,其中,所述FFT模块将所述多个音调转换成多组重复BPSK 符号,并生成一组选定BPSK符号;以及 其中,所述BPSK模块转换该组选定BPSK符号。
- 2324、 一种用于验证的方法,包括: 接收用访问码编码的多个音调; 根据所述多个音调,生成多个并行的BPSK符号; 将所述BPSK符号转换成所述访问码的编码交织比特流; 将所述编码交织比特流进行解交织;以及 从所述编码解交织比特流中恢复出所述访问码。
- 2425、 如权利要求24所述的方法,其中,执行FFT的步骤包括: 生成重复的BPSK符号; 其中,所述方法还包括:根据重复的BPSK符号,生成一组选定 BPSK符号;以及 其中,执行BPSK的步骤包括:将该组选定BPSK符号转换成编 码交织比特流。
- 2526、 如权利要求25所述的方法,其中,执行FFT的步骤包括: 200480021026.9 第 将所述IFFT符号转换成多组重复的三BPSK符号;以及 其中,生成该组选定BPSK符号的步骤包括:从这些组重复的三 BPSK符号中选择三个BPSK符号,以生成该组选定BPSK符号。
- 2627、 如权利要求25所述的方法,其中,执行FFT的步骤包括: 将所述IFFT符号转换成多组重复的三BPSK符号;以及 其中,生成该组选定BPSK符号的步骤包括:选择所述多组重复 的三BPSK符号中的一组重复的三BPSK符号,以生成该组选定BPSK 符号。
- 2728、 如权利要求24或其从属权利要求25—27中任意一项所述的 方法,还包括: 存储加密密钥; 用所述加密密钥来验证所述访问码;以及 如果证实了所述访问码,则准予访问。
- 2829、 如权利要求24或其从属权利要求25-28中任意一项所述的 方法,还包括: 接收用个人标识号(PIN)编码的多个音调; 从用所述PIN编码的多个音调中恢复出所述PIN;以及 如果证实了所述访问码和所述PIN,则准予访问。
- 2930、 如权利要求24或其从属权利要求25-29中任意一项所述的 方法,还包括: 生成时间元素;以及 其中,验证所述访问码的步骤包括:使用所述加密密钥和时间元 素来验证所述访问码。 200480021026.9
Independent claims29
77 paragraphs, as filed
FIELD OF THE INVENTION The present invention generally relates to authentication, and more particularly to digital authentication of entities using voice.
Technical Background With the growth of e-commerce, the use of public communication infrastructures such as the Internet to access various secure networks, systems, and/or applications is also increasing. For example, through digital authentication, users can access banks, private networks such as intranets, secure servers or databases, and/or other virtual private networks (VPNs) via public communication networks (online or through ATMs). But Because of the adoption of a communication system where face-to-face contact is not possible, the chances of fraud or illegal access have also increased. If the stolen identity falls into the hands of criminals, it can cause damage to individuals, organizations, or other entities.
In order to prevent illegal access, various security mechanisms for verifying the identity of users or entities have been developed in the past, so that only authorized entities are permitted to access. Access code generation devices such as tokens can implement a user authentication and access control technology. Here, a unique access code is generated periodically and displayed to the user. Usually, the access code is generated according to an algorithm based on security information and the current time. Then, the user needs to enter the currently displayed access code to access it.
In some systems, a password is also required for access. This type of system is called two-factor authentication (two-fhctor authentication). Two-factor authentication is usually based on: for example, the user has a token; for example, the user knows the password. Since both pieces of information are used to authenticate users, compared with single-factor authentication, systems that perform two-factor authentication are less vulnerable to attacks.
The token described above can prevent unauthorized access, but it is troublesome because the user must manually enter each access code during each access. In addition, since the access code is manually entered, errors are more likely to occur. In some systems, the user needs to enter the access code more than once during each visit, which increases the inconvenience and error probability. In addition, since the access code can be
200480021026.9 The first is based on time and continuous display, so the token may require constant calculation, thereby reducing the battery life of the token.
Therefore, there is a need for a more efficient, more convenient and/or more secure way to use the device to implement a control access system.
SUMMARY OF THE INVENTION The embodiments disclosed herein solve the above-mentioned needs by providing a security method in a data processing system.
In one aspect, an apparatus for authentication includes: a storage medium for storing an encryption key and a look-up table (LUT); a first processor connected to the storage medium for using the encryption key Key to generate an access code; a converter connected to the processor for converting the access code into multiple tones encoded with the access code; an audio output unit for outputting the access code encoded with the access code Multiple tones for authentication; wherein, the converter may include: a binary phase shift keying (BPSK) module for generating a plurality of parallel BPSK symbols; a second connected to the BPSK module and the storage medium The second processor is configured to use the LUT to convert the BPSK symbol into multiple tones. Here, one of the first or second processor may repeat the BPSK symbol for a selected number of times; then, the second processor converts the repeated BPSK symbol into the plurality of tones.
In another embodiment, an apparatus for authentication may include: a storage medium for storing an encryption key and a look-up table (LUT); a processor connected to the storage medium for using the encryption key Key to generate an access code; a converter connected to the processor for converting the access code into a plurality of tones encoded with the access code; an audio output unit for outputting the access code encoded with the access code Multiple tones for authentication; wherein, the converter includes: a binary phase shift keying (BPSK) module for generating multiple parallel BPSK symbols; wherein, the processor uses the LUT to convert the BPSK The symbol is converted into multiple tones.
In another embodiment, a method for authentication may include: storing an encryption key and a look-up table (LUT); using the encryption key to generate an access code; based on the access code, generating multiple parallel BPSK symbol; using the LUT, convert the BPSK symbol into multiple tones encoded with the access code; output the multiple encoded with the access code
200480021026.9 The first tone for certification. The method may further include: before converting the BPSK symbol, repeating the BPSK symbol a selected number of times. Here, the step of repeating the BPSK symbol may include: repeating a group of three BPSK symbols for selected times; wherein the step of converting the BPSK symbol may include: using the LUT to convert each group of three BPSK symbols into multiple Tones.
In another embodiment, an apparatus for authentication may include: a module for storing an encryption key and a look-up table (LUT); a module for using the encryption key to generate an access code; and a module for generating an access code based on The access code generates a module for multiple parallel BPSK symbols; a module for using the LUT to convert the BPSK symbols into multiple tones encoded with the access code; an output module for outputting the access code Encode multiple tones for authentication. The device may further include a module for repeating the BPSK symbol a selected number of times, wherein the module for converting the BPSK symbol converts the repeated BPSK symbol.
In another embodiment, an apparatus for authentication may include: a storage medium for storing an encryption key; a processor connected to the storage medium for generating an access code using the encryption key; A converter connected to the processor is used to convert the access code into a plurality of tones encoded with the access code; an audio output unit connected to the converter is used to output the access code encoded Wherein, the converter may include: a binary phase shift keying (BPSK) module for generating a plurality of parallel repeated BPSK symbols based on the access code; connected to the BPSK module The inverse fast Fourier transform (IFFT) module of BPSK is used to perform IFFT on repeated BPSK symbols to generate code symbols; an up-converter connected to the IFFT module is used to modulate the code symbols into the access code Encoded multiple tones.
In another embodiment, a method for authentication may include: storing an encryption key; using the encryption key to generate an access code; based on the access code, generating multiple parallel binary phase shift keying ( BPSK) symbols; before converting the BPSK symbols, repeat the BPSK symbols a selected number of times; perform inverse fast Fourier transform (IFFT) on the repeated BPSK symbols to generate IFFT symbols; modulate the IFFT symbols to be used The multiple tones encoded by the access code; and the multiple tones encoded by the access code are input for authentication.
In another embodiment, an apparatus for authentication may include: storage encryption
200480021026.9 The module of the key; the module used to generate the access code using the encryption key; the module used to generate multiple parallel binary phase shift keying (BPSK) symbols based on the access code; A module for repeating the BPSK symbol for a selected number of times before the BPSK symbol; a module for performing inverse fast Fourier transform (IFFT) on the repeated BPSK symbol to generate IFFT symbols; a module for modulating the IFFT symbols to use the A module for multiple tones encoded with an access code; a module for outputting multiple tones encoded with the access code for authentication.
In another embodiment, an apparatus for verification may include: an audio input unit for receiving a plurality of tones encoded with an access code; a converter connected to the audio input unit for using the access code The access code is recovered from the encoded multiple tones; wherein the converter includes: a down-converter, used to demodulate the multiple tones into IFFT symbols; a fast Fourier transform (FFT) module, used according to The IFFT symbol generates multiple parallel BPSK symbols; the BPSK module connected to the processor is used to convert the BPSK symbols into the coded interleaved bit stream of the access code; and the de-interleaving connected to the BPSk module A device for deinterleaving the coded and interleaved bitstream; a decoding module connected to the deinterleaver is used for recovering the access code from the coded and deinterleaved bitstream. The device may further include: a storage medium for storing an encryption key; a processor connected to the storage medium and the converter, for verifying the access code using the encryption key, and if verified If the access code is issued, the access is granted. In addition, the FFT module converts the multiple tones into multiple groups of repeated BPSK symbols, and generates a group of selected BPSK symbols; wherein, the BPSK module converts the group of selected BPSK symbols.
In another embodiment, a method for verification may include: receiving a plurality of tones encoded with an access code; generating a plurality of parallel BPSK symbols according to the plurality of tones; converting the BPSK symbols into all The coded interleaved bit stream of the access code; de-interleaved the coded interleaved bit stream; and the access code is recovered from the coded de-interleaved bit stream. Here, the step of performing FFT includes: generating repeated BPSK symbols; wherein, the method further includes: generating a set of selected BPSK symbols according to the repeated BPSK symbols; wherein, the step of performing BPSK includes: The selected BPSK symbol is converted into a coded interleaved bit stream. In addition, the step of performing FFT includes: converting the IFFT symbols into groups of repeated three BPSK symbols; wherein, the step of generating the selected group of BPSK symbols
200480021026.9 The first includes: selecting three BPSK symbols from the three repeated BPSK symbols of these groups to generate the selected BPSK symbol of the group. Alternatively, the step of performing the FFT includes: converting the IFFT symbols into multiple sets of repeated three BPSK symbols; wherein the step of generating the selected set of BPSK symbols includes: selecting a set of repeated three BPSK symbols to generate the The group selects the BPSK symbol.
In another embodiment, an apparatus for verification may include: a module for receiving a plurality of tones encoded with an access code; a module for generating a plurality of parallel BPSK symbols according to the plurality of tones; and A module for converting the BPSK symbol into a coded interleaved bit stream of the access code; a module for deinterleaving the coded interleaved bit stream; and a module for recovering the access from the coded deinterleaved bit stream Code module.
BRIEF DESCRIPTION OF THE DRAWINGS The various embodiments will be described in detail below in conjunction with the drawings. In these drawings, the same symbols refer to the same components, in which: Figure 1 shows a system for digital authentication through a voice channel; Figure 2 shows An exemplary embodiment of a token is shown; Fig. 3 shows an exemplary embodiment of a verification machine; Fig. 4 shows an exemplary method of digital authentication using a voice channel; Figs. 5A and 5B show BPSK symbols Figure 5C shows an example of a LUT; Figure 6 shows an exemplary method of digital verification using a sound channel; Figures 7A and 7B show the original repeated BPSK symbol group and the restored repeated BPSK symbol group; Figures 7C and 7D show examples of selected BPSK symbol groups; Figure 8 shows an exemplary embodiment of a token; Figure 9 shows another exemplary method of digital authentication using a voice channel; Figure 10 shows An exemplary method for digital verification using a voice channel is shown; FIGS. 11A to 11D show other exemplary systems for digital verification through a voice channel; FIG. 12 shows an exemplary embodiment of a receiver;
200480021026.9 Fig. 13 shows another embodiment of the receiver; and Figs. 14A and 14B show an exemplary housing of the token.
DETAILED DESCRIPTION Generally, the disclosed embodiments use a voice channel to perform digital authentication on users or entities. In the following description, specific details are given to facilitate a thorough understanding of these embodiments. However, those skilled in the art should understand that these embodiments may also be implemented without these specific details. For example, the circuit can be given in block diagram form so as not to obscure the embodiments with unnecessary details. However, in other examples, in order to better explain these embodiments, well-known circuits, structures, and technologies can be given in detail.
It should also be noted that these embodiments can be described as processes represented by flowcharts, structural diagrams, or block diagrams. Although the flowchart can describe multiple operations as a sequential process, many of the operations can be performed in parallel or simultaneously. In addition, the order of operations can be rearranged. When the operation is complete, the process ends. Procedures can correspond to methods, functions, procedures, subroutines, subroutines, and so on. When the process corresponds to a function, its end corresponds to the function returning to the calling function or the main function.
In addition, as disclosed herein, the term "sonic wave" refers to an acoustic wave or pressure wave or vibration traveling through a gas, liquid, or solid. Sound waves include ultrasonic waves, audio waves and subsonic waves. The term "audio wave" refers to the frequency of the sound wave within the sound spectrum, approximately 20 Hz to 20 kHz. The term "ultrasonic wave" refers to the frequency of the sound wave above the sound spectrum. The term "subsonic wave" refers to the frequency of sound waves below the sound spectrum. The term "storage medium" means one or more devices used to store data, including read-only memory (ROM), random access memory (RAM), disk storage media, optical storage media, flash memory and/or Other machine-readable media. The term "machine-readable medium" includes, but is not limited to, portable or fixed storage devices, optical storage devices, wireless channels, and various other devices, which can store, contain, or carry instructions and/or data. The term "tone" refers to an acoustic carrier signal with a specific tone and vibration, which carries digital data. The term "multiple tones" refers to three or more tones. The term "authentication" refers to the authentication of an entity, and the terms "authentication" and "verification" can be used interchangeably.
Figure 1 shows an exemplary system 100 for digital authentication through a voice channel.
200480021026.9 In the system 100, the verifier device 110 controls access to a secure network, system, and/or application through a public communication infrastructure such as the Internet 120. Although it can be accessed through public communication facilities other than the Internet 120, for illustrative purposes, the system 100 will be described with reference to the Internet 120. For access via the Internet 120, devices such as the token 130 pass through a wireless communication device (WCD ) 140 provides the access code to the authenticator device 110. The access code is transmitted from the token 130 to the WCD 140 through the voice channel. The encryption key stored securely in the token 130 is used to generate an access code and encode it into a sound wave for communication. More specifically, the generated access code is encoded into multiple tones using multi-carrier modulation, and the access code is recovered from the multiple tones using corresponding multi-carrier demodulation.
The user of the token 130 can also provide user information, such as a user name, to the verifier device 110. Here, the user information can be encoded into a sound wave and transmitted to the WCD 140 together with the access code. Alternatively, the user information can also be directly input into the WCD 140. Then, the WCD 140 may forward the access code and user information to the verification machine 110 via the Internet 120 for authentication. In other embodiments, the user information may be the assigned identification number of the token 130. Therefore, the user does not have to input user information. The identification number is automatically encoded into a sound wave and transmitted to the WCD 140 together with the access code. After the access is granted, the WCD 140 can be used to communicate with a secure network or system.
In order to forward the access code and/or user information, WCD 140 can recover the access code and/or user information from the sound wave, if it is encoded. Then, the WCD 140 may forward the access code and/or user information to the verifier device 110. Alternatively, the sound wave encoded with the access code and the sound wave encoded with the user information, if they are encoded, can be transmitted to the authenticator device 110. Thus, the authenticator device 110 can recover the access code and/or user information from the sound wave. Here, the access code and/or user information, or sound waves encoded with the access code and/or user information, can be transmitted through any known communication technology that allows access to the Internet 120 in the system 100.
The token 130 is usually a portable device, and may be small enough to be carried in a pocket and attached to a key fob. The physical possession of the token 130 provides an aspect of the required verification, just as the physical possession of a key enables an individual to achieve access through a locked door. Therefore, the token 130 is used as an authentication tool and, in addition to communicating through sound waves,
200480021026.9 In addition, the token 130 does not need to have traditional wireless communication capabilities in order to directly send the access code to the authenticator device 110 through the Internet 120 or other wireless and wired infrastructure. That is, in some embodiments, the token 130 does not support wireless communication capabilities, and does not include wireless modems, network cards, and/or other wireless links, leading to private or public communication infrastructure, such as the Internet 120. Therefore, the WCD 140 sends the access code via the Internet 120. However, it should be noted that in other embodiments, the token 130 may also be embedded in other devices, such as wireless phones or personal digital assistants. In addition, although the WCD 140 is shown as a personal desktop computer, it can be a variety of other computer devices, such as, but not limited to: laptop computers, PDAs, home, office, or vehicle wireless phones, or security devices.
The access code is generated using an encryption key, and the encryption key is securely stored in the token 130. The encryption key can be put into the token 130 at the time of manufacture, which is unknown to the user. Here, two encryption keys can be used for digital authentication: symmetric cryptography and asymmetric cryptography. In a symmetric cryptographic system, the secret key or symmetric key in the token 130 is shared and placed in the verifier device 110. The token 130 uses the key to generate a digital signature, and sends the digital signature to the verifier device 110 for authentication. The verifier device 110 verifies the digital signature based on the same key. In an asymmetric cryptographic system, a private key and a public key are generated for the user. The public key is shared with the verifier device 110, and the private key is kept secret in the token 130. The private key is used to generate a digital signature and send it to the verifier device 110. Then, the verifier device 110 verifies the digital signature based on the user's public key.
In the above description, the verifier device 110 verifies the encryption key corresponding to the user based on the user information sent together with the access code. The verifier device 110 may also be implemented as a part of a secure network or system to be accessed by the user. Alternatively, the verifier device 110 may be located outside a secure network or system. In addition, although FIG. 1 shows one verifier device 110, it is obvious to those skilled in the art that there can be more than one verifier device, and each device controls access to one or more networks/systems. .
The block diagram of FIG. 2 shows an exemplary embodiment of the token 300, and FIG. 3 shows an exemplary embodiment of the verification machine 300. The token 200 may include: a storage medium 210 for storing an encryption key and a look-up table (LUT); a processor 220 for using the encryption key to generate an access code; and a converter 230 for using the LUT to convert the access code Convert to user visit
200480021026. 9 The multiple tones encoded by the first question code; the audio output unit 240 is used to output multiple tones encoded with the access code for verification. The authenticator device 300 may include: a storage medium 310 for storing an encryption key; a processor 320 for using the encryption key to generate an access code; and an audio input unit 330 for receiving a multiple code encoded with the access code from the token. Tones; converter 340, used to recover access codes from multiple tones. Based on the encryption key, the processor 320 verifies the user's access code.
More specifically, based on multi-carrier modulation, the access code is converted into and from multiple tones. Therefore, the converter 230 modulates the access code into a multi-carrier signal, and the converter 340 uses a multi-carrier system to demodulate the access code from the multi-carrier signal. Co-pending U.S. Application No. 10/356,144 and co-pending U.S. Application No. 10/356,425 describe a multi-carrier system. In multi-carrier modulation, the data stream to be transmitted is divided into multiple interleaved bit streams. In this way, multiple parallel bit streams with very low bit rates are obtained. Then, each bit stream is used to modulate multiple carriers and transmitted through different carrier signals. Generally, carrier modulation involves encoding, interleaving, digital modulation, inverse Fourier transform (IFFT) processing, and up-conversion of the data stream to be transmitted. Demodulation involves down-conversion, FFT processing, digital demodulation, de-interleaving and decoding of the received data stream. However, in converters 230 and 340, LUTs are used to facilitate modulation, as described below.
The converter 230 of the token 200 may include an encoding module 232, an interleaver 234, a binary phase shift keying (BPSK) module 236, and a processor 238. The converter 340 of the verifier device 300 may include a down converter 341, an FFT module 343, a BPSK module 345, a deinterleaver 347, and a decoding module 349. BPSK is a well-known digital modulation technique that is easy to implement. Although BPSK does not lead to the most efficient use of available bandwidth, it is not susceptible to noise. Therefore, BPSK is used to convert code symbols into tones. However, in converters 230 and 340, modulation techniques other than BPSK can also be implemented. In addition, it should be noted that the converter 230 shows a simplified multi-carrier modulator based on BPSK. More typical commercial multi-carrier modulators may have additional components, such as a preamble generator, a serial-to-parallel (S/P) converter, or a parallel-to-serial (P/S) converter. Similarly, the converter 340 shows a simplified multi-carrier demodulator corresponding to the converter 230. A more typical commercial multi-carrier demodulator may also have additional components, such as a synchronization unit, an S/P converter, and a P/P converter. S converter.
Generally, the encoding module 232 is used to encode the bit stream or the bit stream of the access code.
200480021026.9 Second, the interleaver 234 interleaves the coded bitstream to interleave the bitstream or code symbols. The BPSK module 236 generates multiple parallel BPSK symbols according to the code symbols. More specifically, the coded bit stream is serial-parallel converted into parallel code symbols. Then, the BPSK module 236 maps the parallel code symbols into multiple parallel BPSK symbols. Here, the code symbols can be mapped into BPSK symbols and then serial-to-parallel converted into BPSK symbols, or the code symbols can be serial-to-parallel converted and then mapped into BPSK symbols. In addition, the number of BPSK symbols corresponds to the number of tones available in the multi-carrier system. In some embodiments, the frequency range of multi-carrier tones is approximately 1 kHz to 3 kHz, and the allowable bandwidth of each carrier depends on the number of tones. For example, if the number of available tones is 64, each carrier may allow a bandwidth of approximately 31.25 Hz. The processor 238 uses the LUT to convert the multiple BPSK symbols generated above into multiple tones, and performs serial-to-parallel conversion on them. By implementing LUT, BPSK symbols can be directly converted into multiple tones without IFFT processing and up-conversion. The detailed operation of the LUT will be described below in conjunction with FIG. 5.
In order to recover the access code, the process performed by the converter 340 is opposite to the process performed by the converter 230. That is, the down converter 341 demodulates multiple tones into multiple parallel IFFT symbols; the FFT module 343 performs FFT to generate multiple parallel BPSK symbols; the BPSK module 345 converts the BPSK symbols into code symbols or access code encoding Interleave the bit stream; the deinterleaver 347 deinterleaves the code symbols; the decoding module 349 recovers the access code from the encoded code symbols. More specifically, the down converter 341 can demodulate multiple tones into multiple IFFT symbols; S/P performs serial-to-parallel conversion on the IFFT symbols; the FFT module 343 can perform FFT to generate multiple parallel BPSK symbols; BPSK The module 345 can convert the BPSK symbol into multiple parallel code symbols; the deinterleaver 347 can deinterleave the code symbols into a coded bit stream; the P/s can perform parallel-to-serial conversion on the code symbols, and then decode the code symbols by the decoding module 349. Alternatively, multiple tones can be subjected to: serial-to-parallel conversion; FFT processing into multiple parallel BPSK symbols; parallel-to-serial conversion; BPSK processing to perform de-interleaving. Still alternatively, multiple tones can be converted: parallel-to-serial conversion; FFT processed into multiple parallel BPSK symbols; BPSK processed into multiple parallel code symbols; parallel-serial conversion; de-interleaving.
In converters 230 and 340, more typical token and verifier devices may have additional components. In some embodiments, the token 200 may further include: an amplifier 260 for amplifying multiple tones from the converter 230; an exciter or actuator 270 for
200480021026.9 first receives a signal from the user to activate the authentication process. The actuator 260 may be, but is not limited to: a switch, a button switch, a toggle switch, or a dial or voice activation device. The token 200 may also include a clock module 250 for generating time elements. In these situations, the processor 220 may use the encryption key and the time element to generate the access code. Similarly, the verification machine device 300 may also include a clock module 350 for generating time elements. In these situations, the processor 320 may use the encryption key and the time element to generate the access code.
The token 200 and the clock modules 250 and 350 in the validator device 300 are synchronized to periodically generate a time element as needed, for example, every minute, every hour, every day, or other selected increments. This type of authentication is often referred to as an authentication-based session because the access code changes with each time period. In addition, the storage media 210 and 310 may be a database of encryption keys, corresponding to different users of the network, system, or application. Therefore, the user information is sent to the verifier device 300, as described above, so that an appropriate encryption key is used in the verifier 300 during the authentication process.
Figure 4 shows an exemplary method 400 for using a voice channel to transmit access codes. For accessing a secure network, system or application, the processor 220 uses the encryption key to generate an access code (410). Thereafter, based on the access code, multiple parallel BPSK symbols are generated (420), and then, using the LUT, these BPSK symbols are converted into multiple tones encoded with the access code (430). More specifically, the bit stream of the access code is encoded into an encoded bit stream. The coded bit stream can be: serial-to-parallel conversion; interleaved into multiple parallel code symbols; BPSK mapped into multiple parallel BPSK symbols; using LUT, converted into multiple tones. Alternatively, the coded bit stream can be interleaved; BPSK mapping; and then serial-to-parallel converted into multiple parallel BPSK symbols to convert into multiple tones. Alternatively, the coded bit stream can be interleaved, and then serial-to-parallel converted into multiple parallel code symbols for BPSK processing. Here, the encryption key and the LUT may be stored in the storage medium 210, and the processor. 238 may use the LUT stored in the storage medium 210 to convert the BPSK symbol into multiple tones. Then, multiple tones encoded with the access code are output for authentication (440).
More specifically, the LUT is calculated in advance to map the BPSK symbol into a specified tone. For example, each specific sequence of BPSK symbols can be mapped, the latter corresponding to a different available tone. Therefore, instead of performing IFFT on the BPSK symbol and modulating the IFFT symbol, the LUT directly converts the BPSK symbol into multiple tones.
200480021026.9 First, in some embodiments, in order to enhance the recovery of the access code, the BPSK symbols are repetitively selected a number of times before the BPSK symbols are converted. Then, the LUT can be calculated in advance to map multiple sets of BPSK symbols into multiple tones. 5A to 5C show examples of conversion from repeated BPSK symbols to corresponding tones. Assuming that the BPSK symbol sequence {01110010} is shown in Figure 5A, a group of two BPSK symbols {01, 11,00, 10} are repeated twice to obtain repeated BPSK symbols {0101, 1111,0000, 1010}, as shown in Figure 5B Shown. These repeated BPSK symbols can be found in the LUT and converted into corresponding tones. Figure 5C shows an exemplary LUT that can be used to convert these groups of BPSK symbols that are repeated twice. Here, each of the LUT entries 0000-1111 corresponds to one of the tones T1-T16. Based on this LUT, these repeated BPSK symbols will correspond to the tones {T6, T16, T1, T11}.
It should be noted that if the BPSK symbol is not repeated, the BPSK symbol shown in Figure 5A will correspond to the tone {T8, T3}. In addition, if it is repeated, BPSK can be repeated two or more times. In addition, more than two BPSK symbols can be grouped into one group of BPSK symbols, and multiple groups of BPSK symbols can be repeated selected times to convert into multiple tones. According to the number of grouped BPSK symbols in a group and the number of repetitions of the group, LUTo can also be adjusted. For example, a group of three BPSK symbols can be repeated three times. In this case, the LUT can have 512 entries in the range OOOOOOOOO-lllllllllo. Then, the LUT can be used to convert these groups of repeated three BPSK symbols into tones.
In order to further enhance the recovery of the access code, a reference tone with a reference phase may be added to the multiple tones. Then, the reference tone and multiple tones are output together. In addition, multiple tones can be amplified and then output multiple tones. In addition, if the clock module is implemented, the processor 220 uses the encryption key and the time element to generate the access code. Then, when the user inputs a command through the actuator 270, an access code can be generated, converted, and output from the token 200.
Figure 6 shows an exemplary method 600 for verifying an access code using a voice channel. For verification, the audio input module 330 receives multiple tones encoded with access codes (610). The down converter 341 down-converts or demodulates the multiple tones into multiple parallel IFFT symbols (620). Then, FFT The module 343 performs FFT to generate multiple parallel BPSK symbols (630). The BPSK module 345 converts BPSK symbols into an encoded bit stream
200480021026.9 The first or code symbol (640) is then de-interleaved (650) by the de-interleaver 347. More specifically, multiple tones can be demodulated; serial-parallel converted into multiple parallel IFFT symbols; FFT Processed into multiple parallel BPSK symbols; BPSK mapped into multiple parallel code symbols; de-interleaved into encoded code symbols. Alternatively, multiple tones can be demodulated; serial-to-parallel conversion; IFFT processing; then, parallel-to-serial conversion into BPSK symbols for de-interleaving. Or, multiple tones can be demodulated; serial-to-parallel conversion; FFT processing; BPSK mapping; and then parallel-to-serial conversion into multiple parallel BPSK symbols for de-interleaving. Thereafter, the decoding module 349 recovers the access code (660) from the encoded code symbol. Then, the processor 320 uses the encryption key to verify the access code (670), and if the access code is verified, the access is granted (680). Here, the encryption key may be stored in the storage medium 310.
In the distortion method 600, if the BPSK symbol is repeated for conversion, the multiple tones are demodulated and FFT processed to obtain repeated BPSK symbols. Then, according to the repeated BPSK symbols, a group of selected BPSK symbols is generated, and the group of selected BPSK symbols is converted into code symbols or coded interleaved bit stream. Here, the BPSK module 345 can generate the selected group of BPSK symbols according to the repeated BPSK symbols, and convert the selected group into code symbols. Figures 7A to 7D show how to generate the selected set of BPSK symbols.
As shown in the figure, a group of two BPSK symbols are repeated twice to obtain the original BPSK symbol A1B1A2B2C1D1C2D2, and then demodulate it into A'1 B'1A'2B'2C' 1D' 1 C'2D'2. By selecting one of these two sets of repeated BPSK symbols, the selected BPSK symbol can be generated, as shown in FIG. 7C. Or, by selecting each BPSK symbol from any group of repeated BPSK symbols, the selected BPSK symbol can be generated, as shown in Fig. 7D. Here, it should be noted that multiple tones can be converted into multiple sets of more than two BPSK symbols. For example, multiple tones can be converted into multiple sets of repeated three BPSK symbols. In this case, by selecting each BPSK symbol from the three repeated BPSK symbols of these groups, the selected BPSK symbol of the group can be generated. Or, by selecting a group of repeated three symbols, the selected group of BPSK symbols can be generated.
In addition, if a reference tone with a reference phase is received, the reference tone is used to convert multiple tones into multiple BPSK symbols. In addition, if the clock module is implemented, the processor 320 uses the encryption key and the time element to verify the access code.
200480021026.9 First, if the processing power or speed of the token is limited, the LUT can use multiple tones to send the access code to greatly improve efficiency and performance. However, some embodiments may not implement and use LUTo. FIG. 8 shows another exemplary embodiment of a token 800 that does not use a LUT.
The token 800 includes: a storage medium 810 for storing an encryption key; a processor 820 for using the encryption key to generate an access code; a converter 830 for converting the access code into multiple tones; an audio output unit 840 , Used to output multiple tones encoded with access codes for verification. In some embodiments, the token 800 may include an amplifier 860, an exciter or actuator 870, and a clock module 880, just as the amplifier 260, actuator 270, and clock module 280 of the token 200 are implemented.
Generally, the components implemented by the token 800 are the same as those in the token 200. However, the modulation of the converter 830 is not based on the LUT. Therefore, it is not necessary to store the LUT in the storage medium 810. In addition, the processing of the converter 830 is based on the use of repeated BPSK symbols. More specifically, the converter 830 of the token 800 may include: an encoding module 83 for encoding the bit stream of the access code; an interleaver 833 for interleaving the encoded bit stream; and a BPSK module 835 for converting Interleaved bit stream or code symbols are converted into BPSK symbols, and a selected number of groups of repeated BPSK symbols are generated; IFFT module 837 is used to perform IFFT on the repeated BPSK symbols; up-converter 839 is used to modulate the IFFT symbols for access Multiple tones of code encoding.
Therefore, serial-to-parallel conversion is performed on the coded bit stream, and then mapped into multiple parallel BPSK symbols. According to each parallel BPSK symbol, a selected number of groups of repeated BPSK symbols are generated. That is, multiple sets of parallel repeated BPSK symbols are generated, corresponding to multiple parallel BPSK symbols. Then, multiple groups of repeated BPSK symbols can be subjected to IFFT processing and parallel-to-serial conversion for output. Here, the code symbols can be mapped into BPSK symbols and then serial-to-parallel converted into BPSK symbols, or the code symbols can be serial-to-parallel converted and then mapped into BPSK symbols.
FIG. 9 shows an exemplary method 900 corresponding to the token 800 sending an access code through a voice channel. For accessing a secure network, system or application, the processor 820 uses the encryption key to generate an access code (910). Thereafter, based on the access code, multiple sets of parallel repeated EPSK symbols are generated (920), and IFFT transformation is performed to generate IFFT symbols (930). Then, the IFFT symbol is modulated into multiple tones encoded with access codes (940), and the audio output unit
200480021026.9 No. 840 can output multiple tones for authentication (980). Here, the encryption key can be stored in the storage medium 810.
More specifically, the bit stream of the access code can be encoded, serial-to-parallel converted, interleaved, and BPSK mapped into multiple parallel BPSK symbols. Each parallel BPSK symbol is repeated a selected number of times, as shown in FIGS. 5A to 5C, thereby generating multiple sets of parallel repeated BPSK symbols for IFFT processing. Alternatively, the coded bit stream can be interleaved, BPSK mapped, and then serial-to-parallel converted into multiple parallel BPSK symbols for repetition. Still alternatively, the coded bit stream can be interleaved, and then serial-to-parallel converted into multiple parallel code symbols for BPSK processing.
In addition, as in the token 200, a reference tone having a reference phase can be added to multiple tones. Then, the reference tone and multiple tones are output together. In addition, multiple tones can be amplified and then output multiple tones. In addition, if the clock module is implemented, the processor 820 uses the encryption key and the time element to generate an access code. Then, when the user inputs a command through the actuator 870, an access code can be generated, converted, and output from the token 800.
Although the modulation of the converter 830 is not based on the use of LUTs, the verifier device 300 can perform the modulation and the corresponding method 600, as shown in FIGS. Therefore, the converter 340 corresponding to the converter 830 may include: a down converter 341 for demodulating multiple tones into IFFT symbols; an FFT module 343 for performing FFT to generate repeated BPSK symbols; and a BPSK module 345, used to generate a group of selected BPSK symbols according to the repeated BPSK symbols, and convert the selected group of BPSK symbols into code symbols or access codes encoding interleaved bit stream; de-interleaver 347, used to convert the code The symbols are de-interleaved; the decoding module 349 is used to recover the access code from the coded and de-interleaved bit stream. As in the token 200, modulation techniques other than BPSK can also be implemented in the converters 830 and 340. FIG. 10 shows an exemplary method 1000, which corresponds to the converter 830 using a voice channel to verify the access code. For verification, the audio input module 330 receives multiple tones encoded with the access code (1010)-the down converter 341 down-converts or demodulates the multiple tones into IFFT symbols (1020)-then, the FFT module 343 performs FFT , To generate repeated BPSK symbols (1030), and then, based on the repeated BPSK symbols, generate a set of selected BPSK Symbol (1040). Here, the group of selected BPSK symbols can be generated, as shown in Figures 7A to 7D. The BPSK module 345 converts the selected BPSK symbols into coded interleaved bits
200480021026.9 The code symbol (1050) of the first stream or access code. Thereafter, the deinterleaver 347 deinterleaves the coded interleaved bit stream (1060), and the decoding module 949 recovers the access code (1070) from the coded deinterleaved bit stream. The processor 320 uses the encryption key stored in the storage medium 910, Verify the access code (1080), if the access code is verified, then grant access (1090). As in the verifier device 300, if a reference tone with a reference phase is received, the reference tone is used to convert multiple tones into IFFT symbols . Then, the reference tone and multiple tones are output together. In addition, if the clock module is implemented, the processor 320 uses the encryption key and the time element to verify the access code.
As mentioned above, the access code and/or password can be: encoded into multiple tones; transmitted through public communication facilities such as the Internet 120; recovered from multiple tones; verified to access secure networks, systems, and/ Or apply.
The system 100 is just an example, and there may be other digital authentication systems through a voice channel. 11A to 11D show other exemplary digital authentication systems through a voice channel. In FIG. 11A, multiple tones encoded with an access code can be output from the token 1110 and sent to the receiver device 1120. Then, the access code is forwarded from the receiver device 1120 to the verification via the wireless or wired communication infrastructure device 1140Machine equipment1130. In FIG. 11B, a plurality of tones encoded with an access code are output from the token 1Π0, and transmitted to the receiver 1120 through the wireless or wired telephone 1150. Thereafter, the access code is forwarded from the receiver device 1120 to the authenticator device 1130 through the wireless or wired communication infrastructure device 1140. In FIGS. 11A and 11B, the receiver device 1120 is far away from the authenticator device 1130. In some cases, the receiver device 1120 may be far away from the authenticator device 1130, or be a part of the authenticator device 1130, as shown in FIG. 11C. In FIG. 11C, the token 1110 directly outputs the multiple tones encoded with the access code to the receiver/verifier device 1160. Alternatively, the multiple tones encoded with the access code can also be input from the token 1110 through the wireless or wired telephone 1150. Tones and transmitted to the receiver/verifier 1160. Therefore, multiple tones encoded with the access code can be forwarded from the receiver device H20 to The authenticator device 1130, the authenticator device 1130 can recover the access code. In some embodiments, the access code can be recovered from multiple tones first, and then the recovered access code is forwarded from the receiver device 1120 to the verifier device 1130 for authentication. FIG. 12 shows an example of the receiver 1200 corresponding to the token 200, and FIG. 13 shows the
200480021026.9 An example of the receiver 1300 corresponding to the first token 800, used to recover the access code.
The receiver 1200 includes: a storage medium 1210 for storing a LUT corresponding to the LUT in the storage medium 210; an audio input unit 1220 for receiving a plurality of tones encoded with an access code from a token user; a converter 1230 for To use LUT to recover access codes from multiple tones. The converter 1230 may include: a processor 1232 for using LUT to convert multiple tones into BPSK symbols; a BPSK module for performing demodulation based on BPSK, thereby converting BPSK symbols into code symbols or coding interleaving of access codes Bit stream; de-interleaver 1236, used to de-interleave code symbols; decoding module 1238, used to recover access codes from encoded code symbols.
The receiver 1300 includes: an audio input unit for receiving a sound wave encoded with an access code from a token user; a converter 1320. The converter 1320 may include: a down converter 1321 for demodulating multiple tones into IFFT symbols; FFT The module 1323 is used to perform FFT to generate repeated BPSK symbols; the BPSK module 1325 is used to generate a group of selected BPSK symbols according to the repeated BPSK symbols, and convert the selected BPSK symbols of the group into access codes Encoding and interleaving bitstream; deinterleaver 1327, for deinterleaving the encoding and interleaving bitstream; decoding module 1329, for recovering access codes from the encoding and deinterleaving bitstream.
Generally, the method corresponding to the receiver 1200 for recovering the access code also corresponds to the method described in FIG. 6. However, the receiver 1200 does not verify the restored access code, and does not authorize access based on the access code. Similarly, the method corresponding to the receiver 1300 for recovering the access code also corresponds to the method described in FIG. 11. However, the receiver 1300 does not verify the restored access code, and does not authorize access based on the access code.
Therefore, the access code and/or password can be encoded into multiple tones and recovered from them. By using the voice channel to input the access code for authentication, a display or constant calculations required to display the access code are not required, thereby extending the battery life of the token. In addition, since the access code is not manually entered by the user, errors are not prone to occur, especially in systems where the user needs to enter the access code more than once during each visit. In addition, since standard speakers and/or microphones can be used, the system can be easily implemented without significant cost increase.
Finally, through hardware, software, firmware, middleware, microcode or any combination
200480021026.9 is the first implementation of the embodiment. When implemented by software, firmware, middleware or microcode, the program code or code segment to perform the necessary tasks can be stored in a machine-readable medium, such as storage medium 210, 310, 810, 1210 or other storage medium (not shown) ). Processors, such as processors 220, 230, 820 or other processors (not shown), can perform necessary tasks. A code segment can represent a process, function, subroutine, program, routine, subroutine, module, software package, class, or any combination of instructions, data structures, or program expressions. A code segment can be connected to another code segment or hardware circuit by transmitting and/or receiving information, data, arguments, parameters, or memory content. Information, arguments, parameters, data, etc. can be transferred, forwarded or transmitted in any suitable way, including memory sharing, message transfer, tag transfer, network transfer, etc.
In addition, it is obvious to those skilled in the art that the components of the tokens 200 and 800 can be rearranged without affecting the operation of the tokens. Likewise, the components of the verifier device 300 and/or the receivers 1200 and 1300 can be rearranged without affecting its operation. In addition, the components of the token 200, 800, the authenticator device 300, and/or the receiver 1200, 1300 may be implemented together. For example, the processor 238 and the processor 220 may be implemented together, and the processor 348 and the processor 320 may be implemented together.
In addition, in some embodiments, a display can be used to implement the token. The exemplary embodiment of the token shown in FIG. 14A has a receiving part 1410, which is implemented with a display 1420, an actuator 1430, and an audio output unit 1440. Another exemplary embodiment of the token shown in FIG. 18B has a receiving part 1450, which is implemented with a display 1460, an actuator 1470, an audio output unit 1480, and a hole 1480 passing through the receiving part 1450.
Therefore, the foregoing embodiments are only examples, and should not be construed as limiting the present invention. The description of these embodiments is illustrative, and does not limit the protection scope of the claims. Therefore, the content of this application can be easily applied to other types of devices, and various substitutions, modifications, and changes are obvious to those skilled in the art.
200480021026.9
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN105528816A | Cited by | China | Search report |
67 members in 17 offices
Priority claims13
| Document | Office | Kind | Date |
|---|---|---|---|
| 10625710 | United States of America | – | |
| 62571003 | United States of America | A | |
| 62571003 | United States of America | A | |
| 10785313 | United States of America | – | |
| 78531304 | United States of America | A | |
| 78531304 | United States of America | A | |
| 2004023580 | United States of America | W | |
| 2004023580 | United States of America | W | |
| 10625710 | – | – | – |
| 10785313 | – | – | – |
| US20030625710 | – | – | – |
| US20040785313 | – | – | – |
| WO2004US23580 | – | – | – |
Members67
| Document | Office | Kind | |
|---|---|---|---|
| US2003120925A1 | United States of America | A1 | |
| WO03056745A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002364095A1 | Australia | A1 | |
| US2003159050A1 | United States of America | A1 | |
| CA2476485A1 | Canada | A1 | |
| WO03071770A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003219752A1 | Australia | A1 | |
| TW200307438A | Taiwan Province of China | A | |
| US2004133789A1 | United States of America | A1 | |
| KR20040075026A | Republic of Korea | A | |
| EP1464138A1 | European Patent Office (EPO) | A1 | |
| US2004221166A1 | United States of America | A1 | |
| MXPA04007869A | Mexico | A | |
| MXPA04007869A | Mexico | A | |
| EP1481535A1 | European Patent Office (EPO) | A1 | |
| AU2004301642A1 | Australia | A1 | |
| CA2533316A1 | Canada | A1 | |
| WO2005011191A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2004262288A1 | Australia | A1 | |
| CA2532812A1 | Canada | A1 | |
| WO2005013180A2 | World Intellectual Property Organization (WIPO) | A2 | |
| NZ534700A | New Zealand | A | |
| BR0307657A | Brazil | A | |
| JP2005514831A | Japan | A | |
| CN1620779A | China | A | |
| JP2005518721A | Japan | A | |
| CN1650603A | China | A | |
| IL163527A0 | Israel | A0 | |
| RU2004127588A | Russian Federation | A | |
| CO5611229A2 | Colombia | A2 | |
| MXPA06000801A | Mexico | A | |
| MXPA06000804A | Mexico | A | |
| EP1647106A1 | European Patent Office (EPO) | A1 | |
| EP1654688A2 | European Patent Office (EPO) | A2 | |
| KR20060052856A | Republic of Korea | A | |
| KR20060056334A | Republic of Korea | A | |
| EP1464138A4 | European Patent Office (EPO) | A4 | |
| EP1481535A4 | European Patent Office (EPO) | A4 | |
| CN1842989A | China | A | |
| TWI268688B | Taiwan Province of China | B | |
| JP2006528391A | Japan | A | |
| JP2007507916A | Japan | A | |
| WO2005013180A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US7251730B2 | United States of America | B2 | |
| CN101061663AThis record | China | A | |
| RU2313916C2 | Russian Federation | C2 | |
| AU2003219752B2 | Australia | B2 | |
| US7487362B2 | United States of America | B2 | |
| US7533735B2 | United States of America | B2 | |
| US2009141890A1 | United States of America | A1 | |
| EP1481535B1 | European Patent Office (EPO) | B1 | |
| KR100952551B1 | Republic of Korea | B1 | |
| AT462239T | Austria | T | |
| ATE462239T1 | Austria | T1 | |
| IL163527A | Israel | A | |
| DE60331817D1 | Germany | D1 | |
| JP4565840B2 | Japan | B2 | |
| CN101944246A | China | A | |
| JP2011008801A | Japan | A | |
| JP4648313B2 | Japan | B2 | |
| JP4680505B2 | Japan | B2 | |
| US7966497B2 | United States of America | B2 | |
| KR101059405B1 | Republic of Korea | B1 | |
| EP1654688A4 | European Patent Office (EPO) | A4 | |
| CN101061663B | China | B | |
| US8391480B2 | United States of America | B2 | |
| CN103793817A | China | A |
6 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Termination of patent right due to non-payment of annual feeCF01 | CF01 | CN | |
| Applications withdrawn, deemed to be withdrawn, or refused after publication in hong kongWithdrawnWD | WD | HK | |
| Grant of patent or utility modelGrantedC14 | C14 | CN | |
| Requests to designate patent in hong kongDE | DE | HK | |
| Entry into substantive examinationC10 | C10 | CN | |
| PublicationC06 | C06 | CN |
Numbers
- Publication
- 101061663
- Publication, DOCDB
- 101061663
- Publication, EPODOC
- CN101061663
- Application
- 800210269
- Application, DOCDB
- 200480021026
- Application, EPODOC
- CN200480021026
Titles2
- Chinese
- 通过声音信道进行数字认证
- English
- Digital authentication via voice channel
Classification
- CPC, 19
- G07F7/1008
- H04L9/32
- G06F21/34
- G06F21/35
- G06Q20/3272
- G06Q20/341
- G06Q20/4014
- G06Q20/4097
- G06Q20/40975
- G07F7/1016
- G07F7/1025
- G07F19/20
- H04L9/3226
- H04L9/3271
- H04L2209/80
- H04L63/0853
- G07C9/23
- H04W12/65
- H04L9/30
- IPC, 6
- H04L9 32
- G06F21 34
- G06F21 35
- G07C9 00
- G07F7 10
- G09C1 00