EP3318003A1

Confidential authentication and provisioning

Abstract

This record has no abstract on file.

EP3318003A1, drawing sheet 1
Sheet 1 of 8

Term

9.8 yearsto projected expiry

Projected expiry 30 June 2036, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

1 claim: 1 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2017004466 A1 WHAT IS CLAIMED IS:1. A computer-implemented method comprising: encrypting, by an authentication server, an authentication challenge to obtain an encrypted authentication challenge;sending, by the authentication server, the encrypted authentication challenge to a user device;receiving, by the authentication server, an encrypted authentication response from the user device;generating, by an authentication server, a first shared secret using an authentication server private key and a user device authentication public key;decrypting, by the authentication server, the encrypted authentication response using the first shared secret to obtain an authentication response including the authentication challenge;and authenticating, by the authentication server, the user device based on the authentication response. 2. The method of claim 1, wherein the authentication challenge is encrypted using the user device authentication public key, the user device authentication public key having been previously obtained from the user device via a registration process. 3. The method of claim 2, wherein the registration process comprises: receiving, from the user device, a signed user device authentication public key generated by the user device signing the user device authentication public key using a user device attestation private key, the user device attestation private key corresponding to a user device attestation public key. 4. The method of claim 3, wherein the signed user device authentication public key is received in an encrypted registration response, the method further comprising: decrypting the encrypted registration response to obtain the signed user device authentication public key;and validating the signed user device authentication public key using the user device attestation public key. 5. The method of claim 1, wherein the authentication challenge is a signed authentication challenge, wherein the user device generated the signed challenge by signing the authentication challenge using a user device authentication private keycorresponding to the user device authentication public key, wherein the authenticating of the user device includes verifying the signed challenge using the user device authentication public key. 6. The method of claim 1, further comprising receiving, by theauthentication server, an identifier from the user device, the identifier associated with a user device authentication public key. 7. The method of claim 1, further comprising: receiving, by the authentication server, a blinded user device authentication public key and an encrypted user device blinding factor from the user device;decrypting, by the authentication server, the encrypted user device blinding factor using the first shared secret to obtain the user device blinding factor;and verifying, by the authentication server, the blinded user device authentication public key using the user device blinding factor and the user device authentication public key. 8. The method of claim 1, further comprising sending, by the authentication server, provisioning data to the user device in response to verifying the signed challenge. 9. A computer-implemented method comprising: receiving, by a user device, an encrypted authentication challenge from the authentication server;decrypting, by the user device, the encrypted authentication challenge to obtain an authentication challenge;generating, by the user device, a first shared secret using a user device authentication private key corresponding to a user device authentication public key and an authentication server public key;encrypting, by the user device, an authentication response including the authentication challenge using the first shared secret to obtain an encrypted authentication response;and sending, by the user device, the encrypted authentication response to the authentication server, wherein the authentication server authenticates the user device based on the authentication response. 10. The method of claim 9, further comprising generating, by the user device, a signed authentication challenge by signing the authentication challenge using the user device authentication private key, wherein the authentication challenge of the authentication response is the signed authentication challenge. 11. The method of claim 9, further comprising sending, by a user device, an identifier to the authentication server, the identifier associated with the user device authentication public key. 12. The method of claim 9, wherein the authentication server generates the shared secret using the user device authentication public key and a authentication server private key, and decrypts the encrypted authentication response using the first shared secret. 13. The method of claim 9, further comprising: generating, by the user device, a user device blinding factor;and generating, by the user device, a blinded user device authentication public key using the user device authentication public key and the user device blinding factor, wherein the second user device public key is the blinded user device authentication public key. 14. The method of claim 13, further comprising: encrypting, by the user device, the user device blinding factor using the first shared secret to obtain an encrypted user device blinding factor;and sending, by the user device, the encrypted user device blinding factor to the authentication server, wherein the authentication server verifies the blinded user device authentication public key using the user device blinding factor and the user device authentication public key. 15. The method of claim 9, further comprising: receiving, by the user device, an encrypted authentication server certificate from the authentication server;and decrypting, by the user device, the encrypted authentication server certificate using the first shared secret to obtain a authentication server certificate, the authentication server certificate including the authentication server public key. 16. The method of claim 9, further comprising receiving, by the user device, encrypted provisioning data, wherein the user device decrypts the encrypted provisioning data using the first shared secret to obtain provisioning data. 17. The method of claim 9, further comprising: signing, by the user device, the user device authentication public key using a user device attestation private key to obtain a signed user device authentication public key, the user device attestation private key corresponding to a user device attestation public key;encrypting, by the user device, the signed user device authentication public key to obtain an encrypted registration response;and sending, by the user device, the encrypted registration response to an authentication server. 18. The method of claim 17, further comprising encrypting, by the user device, a user device attestation certificate including a user device attestation public key to obtain an encrypted user device attestation certificate, wherein the encrypted registration response includes the encrypted user device attestation certificate. 19. The method of claim 9, further comprising: receiving, by the user device, a blinded authentication server public key and an encrypted authentication server certificate from the authentication server;generating, by the user device, a second shared secret using the blinded authentication server public key and the user device authentication private key;decrypting, by the user device, the encrypted authentication server certificate using the second shared secret to obtain an authentication server certificate including the authentication server public key;encrypting, by the user device, the user device authentication public key using the second shared secret to obtain an encrypted user device authentication public key;and sending, by the user device, the encrypted user device authentication public key to the authentication server. 20. The method of claim 9, further comprising receiving, by the user device, a provisioning server certificate from an authentication server, the provisioning server certificate including the authentication server public key. 21. The method of claim 9, further comprising: receiving, by the user device, input from a user of the user device;authenticating, by the user device, the user based on the input;and generating, by the user device, the user device authentication private key and the user device authentication public key in response to authenticating the user. 22. A computer readable medium storing a plurality of instructions for controlling a computer system to perform an operation of any of the methods above. 23. A system comprising: the computer product of claim 22;and one or more processors for executing instructions stored on the computer readable medium. 24. A system comprising means for performing any of the methods above. 25. A system comprising modules that respectively perform the steps of of the above methods.