EP0737907A2

Cryptographic data security in a secured computer system

Abstract

A data communication system providing for the secure transfer and sharing of data via a local area network and/or a wide area network. The system includes a secure processing unit which communicates with a personal keying device and a crypto media controller attached to a user's workstation. The communication between these processing elements generates a variety of data elements including keys, identifiers and attributes. The data elements are used to identify and authenticate the user, assign user security access rights and privileges, and assign media and device attributes to a data access device according to a predefined security policy. The data elements are manipulated, combined, protected and distributed through the network to the appropriate data access devices, which prevents the user from obtaining unauthorized data.

EP0737907A2, drawing sheet 1
Sheet 1 of 38

Term

Term ended

Projected expiry passed 15 April 2013, 13.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

7 claims: 4 independent, 3 dependent

  1. 1
    In a computing system having a security server and a controller which can communicate with the security server, a method of identifying and authenticating a first user from a plurality of users seeking access to the security server, wherein the method comprises the steps of:providing a cryptographic key;assigning a user unique identifier to each user, wherein the step of assigning comprises assigning a first user unique identifier to the first user;assigning a personal keying device to each user, wherein each personal keying device comprises input means for entering user input and storage means for storing an encrypted last countersign and an encrypted version of the user unique identifier of the user to whom the personal keying device is assigned;storing, in the security server, an expected personal identification number associated with the first user unique identifier;attaching the personal keying device assigned to the first user to the controller;entering, at the input means of the personal keying device, a user-entered personal identification number;combining the user-entered personal identification number, the first user unique identifier and the last countersign into a message;encrypting the message with the cryptographic key and transmitting the encrypted message to the security server;decrypting the message and comparing the user-entered personal identification number to the expected personal identification number;if the user-entered personal identification number matches the expected personal identification number, comparing the decrypted last countersign to a stored value to determine the first user's access rights.
  2. 3
    A computing system comprising a security server and a controller which can communicate with the security server, and a plurality of users seeking access to the security server, a method of controlling access by a plurality of users including a first user, to privileged operations, wherein the method comprises the steps of:providing a cryptographic key;assigning a user unique identifier to each user, wherein the step of assigning comprises assigning a first user unique identifier to the first user;assigning a personal keying device to each user, wherein each personal keying device comprises input means for entering user input and storage means for storing an encrypted last countersign and an encrypted version of the user unique identifier of the user to whom the personal keying device is assigned;attaching the personal keying device assigned to the first user to the controller;identifying and authenticating the first user to the security server;invoking an attention signal;combining the attention signal and the first user unique identifier into a message;encrypting the message with the cryptographic key and transmitting the encrypted message to the security server;decrypting the message and determining, from the first user unique identifier, privileges granted to the first user;determining a new countersign;encrypting the new countersign with the cryptographic key and transmitting the new countersign to the controller;anddecrypting the new countersign and displaying the decrypted new countersign to the first user.
  3. 6
    A trusted path system for securing computing transactions by a user, the system comprising:a secure computer, wherein the secure computer comprises:a logic and control unit;a cryptographic unit connected to the logic and control unit;a communication unit connected to the logic and control unit;storage means for storing a plurality of cryptographic keys, a user unique identifier and a last authentication token;andan authentication token generator for generating a new authentication token;an untrusted communications system connected to the communication unit of the secure computer;a workstation which communicates through the untrusted communications system to the secure computer, wherein the workstation comprises:a logic and control unit;a communication unit connected to the logic and control unit;andstorage means for storing a workstation identifier;anda personal unit which communicates to the workstation, wherein the personal unit comprises:a logic and control unit;a cryptographic unit, connected to the logic and control unit, which encrypts and decrypts messages passed between the personal unit and the security server;a keyboard connected to the logic and control unit;a display connected to the logic and control unit;a communication unit, connected to the logic and control unit, for communicating with the communication unit of the workstation;andstorage means for storing the user unique identifier, the last authentication token and one or more cryptographic keys from the plurality of cryptographic keys.
  4. 7
    A trusted path system for communication between a workstation and a secure computer over an untrusted communication medium, comprising:a logic and control unit in the workstation and in the secure computer;an end-to-end authentication token exchange protocol used to assure the logic and control unit in the workstation is communicating with an authentic logic and control unit in the secure computer, and vice versa;the token exchange protocol operating by chaining transactions together so that a forged transaction entered into the interaction between workstation and secure computer is detected the very next time a legitimate transaction is received by a logic and control unit;a cryptographic checksum protocol used to assure transactions between the logic and control units have not been tampered with, the checksum protocol authenticating single transactions between the workstation and the secure computer rather than sequences of transaction;andan identification and authentication protocol invoked when a user wishes to interact with the secure computer for some period of time, using the keyboard and displaying of the workstation and the untrusted communications medium, the period of interaction being a session, and the act of initiating a session called logon, and that of terminating one is called logout.