EP2293166B1

Authentication method for authenticating a first party to a second party

Abstract

This record has no abstract on file.

EP2293166B1, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Expired 30 May 2025, 1.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 11 independent, 8 dependent

  1. 1
    An authentication method for authenticating a first party to a second party, where an operation is performed on condition that the authentication succeeds, comprising the steps of:- verifying whether the first party is authenticated or not, the verifying comprising - comparing a date of issuance measure of a compliance certificate with a comparison measure of the second party, the comparison measure comprising a range of allowed validity numbers, - verifying if the first party is compliant or not according to the compliance certificate concerning the first party, wherein the first party is authenticated only if it is compliant and if it is determined by the comparison that the date of issuance measure is not out of date;and - if the first party is not authenticated, then qualifying the first party for a sub-authorization during a grace period determined by the range of allowed validity numbers, wherein, if the first party qualifies for the sub-authorization, the operation is still performed, the first party being non-qualified for said sub-authorization if the date of issuance measure is lower than a minimum validity number of said range of allowed validity numbers, - wherein the minimum validity number of said range of allowed validity numbers is a previous validity number stored at the second party.
  2. 5
    An authentication method according to any one of the preceding claims, wherein the grace period is determined by the value of a grace-counter associated with a number of times that first parties have been qualified for the sub-authorization.
  3. 7
    An authentication method according to any one of the preceding claims, wherein said compliance certificate is a Groups Certificate.
  4. 8
    An authentication method according to any one of the preceding claims, wherein the operation comprises accessing content.
  5. 10
    An authentication method according to any one of the preceding claims, wherein said first party is a software application and said second party is a device.
  6. 11
    An authentication method according to any one of the preceding claims wherein the second party holds a limited list of first parties, comprising the steps of:storing, at the second party, an updated set of compliance certificates containing compliance certificates concerning first parties on said list of first parties.
  7. 12
    An authentication method according to claim as in any one of the preceding claims, comprising the step of:- updating, at the second party, the comparison measure, which is associated with time, and which is also used in said authentication procedure, wherein storing the updated set of compliance certificates is in conjunction with said updating.
  8. 13
    A digital device that is arranged for acting as a second party in an authentication method for authenticating a first party to a second party, the device performing an operation on condition that the authentication succeeds, in which certificates are used for determining the compliance of parties involved in the authentication procedure, wherein the device comprises a first memory area holding a comparison measure, which is associated with time, and which is also used in said authentication procedure, the digital device being arranged for:- verifying whether the first party is authenticated or not, the verifying comprising - comparing a date of issuance measure of a compliance certificate with the comparison measure, the comparison measure comprising a range of allowed validity numbers, - verifying if the first party is compliant or not according to the compliance certificate concerning the first party, wherein the first party is authenticated only if it is compliant and if it is determined by the comparison that the date of issuance measure is not out of date;and - if the first party is not authenticated, then qualifying the first party for a sub-authorization during a grace period determined by the range of allowed validity numbers, wherein, if the first party qualifies for the sub-authorization, the operation is still performed, the first party being non-qualified for said sub-authorization if the date of issuance measure is lower than a minimum validity number of said range of allowed validity numbers, - wherein minimum validity number of said range of allowed validity numbers is a previous validity number stored at the second party.
  9. 17
    An authentication method for authenticating a first party to a second party according to any one of claims 1-12, comprising the steps of:- verifying whether the first party is authenticated;and - if the first party is not authenticated, entering an identification of the first party into a local storage holding a list of non-authenticated first parties, which storage is accessible to the second party, wherein said step of verifying comprises a step of verifying whether the first party is a member of said list.
  10. 18
    An authentication method according to any one of the preceding claims, wherein the second party obtains said comparison measure from a data carrier.
  11. 19
    A computer program product, directly loadable into the internal memory of a digital device, comprising software code portions for causing the device to perform the steps of the authentication method according to any one of claims 1-12, 17 and 18.