EP0505302B1

Authentication protocols in communication networks

Abstract

This record has no abstract on file.

EP0505302B1, drawing sheet 1
Sheet 1 of 73

Term

Term ended

Expired 11 February 2012, 14.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

18 claims: 12 independent, 6 dependent

  1. 1
    A method of authenticating users on a communications connection in a network, comprising the steps of:(a) transmitting a first challenge N1 from a first user A to a second user B, (b) transmitting a first response to the first challenge N1 and a second challenge N2 from the second user B to the first user A, (c) verifying at the first user A that the first response is correct, (d) transmitting a second response to the second challenge N2 from the first user A to the second user B, and (e) verifying at the second user B that the second response is correct, said method of authenticating characterized in that: said first and second response are respectively of the minimum forms    f(S1, N1,...) and g(S2, N2,...), where S1 and S2 are shared secrets between the first and second users (A,B) and f() and g() are functions selected such that    f, (S1, N1',...) = g(S2, N2,...) cannot be solved for N1' without knowledge of S1 and S2, wherein f'() and N1' represent expressions on a reference connection with a user that knows S1 or S2 and that transmits the correct first or second responses.
  2. 3
    The method of claims 1 or 2 wherein S1 = S2 = S and wherein S is a data encryption key.
  3. 7
    The method set forth in claims 4 to 5, wherein f() = E[q op E[r]],and g() = E[t], wherein op is a mathematical or boolean operation, q = q(N1, ...), r = r(D1, ...), t = t(N2, ...), E = data encryption with an encryption key.
  4. 8
    The method set forth in claims 4 to 5, wherein f() = E[q op E[r]], and g() = E[t], wherein op is a mathematical or boolean operation, q = q(D1, ...), r = r(N1, ...), t = t(N2, ...), E = data encryption with an encryption key.
  5. 9
    The method set forth in claims 4, 5 or 8 wherein f() = E[D1 op E[N1]] and g() = E[N2].
  6. 10
    The method set forth in claims 4, 5 or 8 wherein f() = E[N1 op E[D1]] and g() = E[N2].
  7. 11
    The method set forth in claims 4, 5 or 8 wherein f() = E[N1 op [D1 op E[N2 op E[N1]]]] and g() = E[N2 op E[N1 op E[N1]]].
  8. 12
    The method set forth in claims 4, 5 or 8 wherein f() = E[N1 op [D1 op E[N2 op E[N1]]]] and g() = E[N2 op E[N1]].
  9. 13
    The method set forth in claims 4, 5 or 8 wherein f() = Eb[N1] and g() = E[N2]. where Eb = encryption with data encryption key K op D1.
  10. 14
    An arrangement at a network node for authenticating network users, comprising :means for transmitting a first challenge N1 to a user, means for receiving a first response to the first challenge and a second challenge N2 from the user, means for verifying the first response, means for transmitting a second response to the second challenge to the user, and means for verifying the second response at the user, characterized by said first response being of the minimum form    f(S1, N1), and said second response being of the minimum form    g(S2, N2,...), where S1 and S2 are shared secrets between authorized users and f() and g() are functions selected such that    f'(S1, N1',...) = g(S2, N2) cannot be solved for N1' without knowledge of S1 and S2, wherein f'() and N1' represent expressions on a reference connection with a user that knows S1 or S2 and that transmits the correct first or second responses.
  11. 16
    The arrangement of claims 14 or 15 wherein S1 = S2 = S and wherein S is a data encryption key.
  12. 17
    The arrangement of claims 14, 15 or 16 wherein f() further includes an indication of the direction D1 of flow of the message containing f(), as in    f(S1, N1, D1,...) and f() is selected such that    f'(S, N1',D1',...) = f(S, N2, D1,...) cannot be solved for N1' without knowledge of S1 and S2, wherein f'() represents an expression on the reference connection and D1' is the flow direction indicator of the message containing f'() on the reference connection with a user that knows S1 or S2 and transmits the correct first or second responses.
  13. 18
    An arrangement at a network node for authenticating a network user, comprising :means for transmitting a challenge N1 to a user, means for receiving a response to the challenge from the user, and means for verifying the response, characterized in that said response is of the minimum form    f(S1, N1, D1...), wherein S1 is a shared secret between the first and second users, D1 is an indication of the direction of flow of the message containing f() and f() is a function selected such that    f'(S1, N1',D1',...) = f(S1, N1, D1,...) cannot be solved for N1' without knowledge of S1, wherein f'(), N1' and D1' represent expressions on a reference connection with a user that knows S1 and that transmit the correct first response.