Id spoofing prevention with ubiquitous signature certificate
Abstract
[Task] Provide methods and devices to prevent identity spoofing by mint using ubiquitous signature authentication.
Solution.When the registration server received the identification information from the user and also received a new signature authentication request from the user, including the step of allowing the user to access the registration server, the registration server queried the directory and set out. Get information about the user. When the registration server receives information from the directory that the user who has made a name for himself already owns the signature authentication, the registration server notifies the user that it will not issue a new signature authentication until the old signature authentication is abolished. This prevents identity spoofing by unauthorized users to obtain valid signature authentication. Further, when the registration server receives information from the directory indicating that the identified user is not in the directory, the registration server notifies the user that it will not issue signature authentication.

Term
Term ended
Projected expiry passed 11 June 2021, 5.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
9 claims: 4 independent, 5 dependent
- 1【特許請求の範囲】 【請求項1】 IDスプーフィング防止方法であって、 ユーザが登録サーバにアクセスすることを許可するステップと、 登録サーバがユーザからの識別情報を受信するとともに、ユーザによる新たな署名認証要求を受信したときに、前記登録サーバがディレクトリに問い合わせ、前記識別されたユーザに関する情報を取得するステップと、 登録サーバが、識別されたユーザが既に署名認証を所有することを示す情報を前記ディレクトリから受信したとき、前記登録サーバが、古い署名認証を廃棄するまで、新たな署名認証を発行しないことをユーザに通知することによって、有効な署名認証を取得するための不正ユーザのIDスプーフィングを防止するステップと、を含む方法。
- 2【請求項2】 IDスプーフィング防止方法であって、 ユーザが登録サーバにアクセスすることを許可するステップと、 前記登録サーバがユーザからの識別情報を受信するとともに、ユーザによる新たな署名認証要求を受信したとき、前記登録サーバがディレクトリに問い合わせ、前記識別されたユーザに関する情報を取得するステップと、 前記登録サーバが、前記識別されたユーザがディレクトリ内にないことを示す情報を、前記ディレクトリから受信したとき、前記登録サーバは、前記ユーザに、署名認証を発行しないことを通知することによって、有効な署名認証を取得するための不正ユーザのIDスプーフィングを防止するステップと、を含む方法。
- 3【請求項3】 請求項2記載の方法であって、更に、前記ディレクトリにおいて、ユーザ識別子およびそれらに対応するディジタル署名認証を提供するステップを含む方法。
- 4【請求項4】 請求項2記載の方法であって、更に、ユーザ識別子を含む信頼性のあるデータベースを備えるステップを含み、前記ディレクトリを前記信頼性のあるデータベースから更新する方法。
- 5【請求項5】 IDスプーフィング防止装置であって、 ユーザによるアクセスを許可する登録レジスタと、 前記登録サーバによってアクセス可能なディレクトリであって、全てのユーザに関する情報を格納する、ディレクトリと、を備え、 前記登録サーバが、前記ユーザから情報を受信するとともに、前記ユーザによる新たな署名認証要求を受信したとき、前記登録サーバは前記ディレクトリに問い合わせ、前記識別されたユーザに関する情報を取得し、 前記登録サーバが、前記識別されたユーザが既に署名認証を所有していることを示す情報を前記ディレクトリから受信したとき、前記登録サーバは、古い署名認証を廃棄するまで新たな署名認証を発行しないことをユーザに通知することによって、有効な署名認証を取得しようとする不正ユーザのIDスプーフィングを防止する、装置。
- 6【請求項6】 IDスプーフィング防止装置であって、 ユーザによるアクセスを許可する登録レジスタと、 前記登録サーバによってアクセス可能なディレクトリであって、全てのユーザに関する情報を格納する、ディレクトリと、を備え、 前記登録サーバが、前記ユーザから情報を受信するとともに、前記ユーザによる新たな署名認証要求を受信したとき、前記登録サーバは前記ディレクトリに問い合わせ、前記識別されたユーザに関する情報を取得し、 前記登録サーバが、前記識別されたユーザが前記ディレクトリ内にないことを示す情報を前記ディレクトリから受信したとき、前記登録サーバは、前記ユーザは企業の有効構成員ではなく、署名認証を発行しないことを、前記ユーザに通知する、装置。
- 7【請求項7】 請求項6記載の装置において、前記ディレクトリは、識別子、およびそれらに対応するディジタル署名認証を含む装置。
- 8【請求項8】 請求項6記載の装置であって、更に、ユーザ識別子を含む信頼性のあるデータベースを備え、前記ディレクトリを前記信頼性のあるデータベースから更新する装置。
- 9【請求項9】 請求項6記載の装置であって、更に、ユーザの以前の署名認証を廃棄する個人廃止局を備え、前記個人廃止局が、個人的にユーザを認識するように選択される装置。
Independent claims9
85 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to digital signature authentication in PKI (Public Key Infrastructure), and more specifically, the present invention relates to prevention of ID spoofing by hackers in a PKI system.
【0002】
[Conventional technology]
This application applies to US Patent and Trademark Application No. 60 / 210,463 filed with the United States Patent and Trademark Office on June 9, 2000, and US Patent and Trademark Application No. 60 filed with the United States Patent and Trademark Office on September 1, 2000. / Claim the priority of No. 229,336. The contents are incorporated herein by reference.
【0003】
PKI is a policy that enables organizations to generate, issue, and manage public / private cryptographic keys so that users can reliably determine the identity of the owner of each public / private key pair. A collection of policies, procedures, and software. The main components of PKI are (1) a mechanism that reliably conveys the identity of the owner of a key pair to the end user, and (2) a software application that generates and manages a key pair that supports this mechanism. 3) A set of steps to generate and invalidate key pairs that ensure a reliable determination of owner identity, and (4) specify who can obtain public / private key pairs. Includes a set of means to identify how each pair is available.
【0004】
Regarding the component (1) of PKI, most PKIs specify that a user owns a key pair by using an electronic document called digital authentication. Digital authentication includes information that identifies the owner of the key pair, the public key of the pair, and the time period during which the authentication is valid. Digital authentication also identifies technical information about the key itself, such as the algorithm used to generate the key and the length of the key.
【0005】
It is the organization that has the role (responsibility) to verify the identity of the individual, or, in some cases, the other organization to which the certification is issued. The identity of the certification organization is called a certificate authority and is recorded in each certification. Then, each authentication is signed using a public key known only to the certificate authority itself. This allows the user to verify both the integrity of the authentication and the identity of the station that issued it.
【0006】
A certificate authority typically uses one of a number of different off-the-shelf software products to control the creation, renewal, and decommissioning (disposal) of a certificate. These authentication management systems (CMS) take the information obtained by the user registration process, create an authentication, and sign it with the private key of the certificate authority. Applicable CMS software maintains a database of all issued certificates and their status. The CMS is also responsible for decommissioning certifications, as well as issuing a decommissioning list that identifies the date and reason for decommissioning each certification. This information allows trusted users (ie, individuals or systems that perform cryptographic or signature verification actions based on authentication) to review the status of authentication and take advantage of its usability. Become. A list of distribution points from which CRLs can be obtained is specified in the certification itself.
【0007】
When issuing the certificate, the certificate authority states that it has verified that the public key (further, the corresponding private key) found within the certificate belongs to the individual posted (listed) within the certificate. become. Therefore, the integrity of the registration process in operation is very important. This process must provide a mechanism to reliably identify an individual and to verify that the public key posted in the certificate belongs to that individual. Equally important, the certificate authority must also have a procedure to decommission the certificate if the public key is compromised. When a public key is compromised, it poses a problem for the entire foundation that trusts authentication. Because more than one person may have signed a document with its public key, or more than one person has encrypted text with the corresponding public key. This is because there is a possibility that it can be deciphered.
【0008】
Reliable individuals and organizations must have a clear understanding of the process by which their certificate authority operates. As a result, most certificate authorities issue a Certificate Practice Statement (CPS) to detail the process of registering a user, issuing a certificate, renewing a certificate, and decommissioning a certificate. CPS is usually published on the certificate authority's website.
【0009】
Authentication often includes additional information that identifies individuals as members of a particular organization, perhaps also their role in that organization. For example, certification can identify a certification holder as either an employee of a company, or a customer or subcontractor or supplier of that company. Therefore, if individuals and organizations rely on this information, a means of determining who is eligible to retain certification is important. These means control the overall operation of the certificate authority.
【0010】
[Problems to be Solved by the Invention and Means for Solving the Problems]
Another flawed PKI system has the problem that ID spoofing, an attempt by hackers to attack the PKI system, is often made. Since the digital signature system is a mechanism for instructing user identity online, one form of mint attack is to steal the identity of the current user, while the second form of hacker attack creates fake users. It is to be. Unfortunately, other defective PKI systems are vulnerable to such attacks.
【0011】
An object of the present invention is to provide a technique for preventing ID spoofing in a PKI system. Another object of the present invention is to prevent identity spoofing by mentha depriving the identity of the current user or by mentha spawning a fake user to gain access to the PKI system.
【0012】
Yet another object of the present invention is to allow the user to access the registration server, and when the registration server receives identification information from the user and further receives a new signature authentication request from the user, the registration server It is to provide a technique to prevent identity spoofing by querying a directory to obtain information about the identified user. When the registration server receives information from the directory that the identified user already has signature authentication, the registration server tells the user that it will not issue a new signature authentication until the old signature authentication is abolished. By notifying, it prevents unauthorized users from obtaining valid signature authentication by ID spoofing.
【0013】
Yet another object of the present invention is to notify the user that the registration server will not issue signature authentication when the registration server receives information from the directory indicating that the identified user is not in the directory. It is to provide the above-mentioned technique.
【0014】
The aforementioned and better understanding of the present invention will become apparent by reading the detailed description and claims of the embodiments below in association with the accompanying drawings. All of these are part of the disclosure of the present invention. The disclosures described and illustrated below and to date are intended to disclose examples of embodiments of the invention, but these are merely examples and examples, and the invention is not limited thereto. Should be clearly understood. The spirit and scope of the invention are limited only by the claims.
【0015】
BEST MODE FOR CARRYING OUT THE INVENTION
Before starting the detailed description of the present invention, the following should be stated. Where appropriate, similar reference numbers and letters shall be used to indicate the same, corresponding, or similar components in different drawings. Further, in the detailed description following, the size / model / value / range may be shown as an example, but the present invention is not limited thereto. Finally, well-known components and connections are not shown in the drawings for the sake of simplification of illustration and description and for the sake of not obscuring the present invention.
【0016】
FIG. 1 is a block diagram showing an example 100 of a network architecture capable of implementing a public key infrastructure (PKI) process according to an example of an embodiment of the present invention. However, it should be understood that the present invention is not limited to the network 100 of FIG. Network 100 is an authoritative database database) Contains data entry 102 that performs the data entry function of 104. The base database 104 resides on server platform 106. Although this description refers to server platform 106, it will be appreciated that the invention is not limited to any particular server architecture. Server platform 106 can be, for example, a UNIX (R) or Windows (R) NT server, but is not limited to these. The basic database 104 contains information about the members of a group or company performing the PKI service according to the invention. The present invention is not limited to the structure of a group company that stores information in the basic database 104. The information in the basic database 104 can include, but is not limited to, the names, addresses, telephone numbers, boss names, employee identifications, etc. of members of the group or company. Directory 108 has the structure of database 104, but is optimized for fast reference of internally stored data rather than fast data entry. The information in directory 108 does not change frequently, but is quickly accessed and functions online as a high-speed phone book that contains reference information about group or company members stored in the basic database 104. Is required to do.
【0017】
Certificate Authority 110 is conventional commercial software that runs on the server platform 106 that stores the authentication and related information used by the present invention, as described in detail below. The registration authority 112 is also commercially available software that can be executed on the server platform 106 with respect to the registration performed by the present invention, as described in detail below. Key station 114 is also commercially available server software that can be run on server platform 106 to recover keys from group or corporate members, as described in more detail below. Windows (R) 2000 A domain certificate authority (CA) 116 can use the authentication provided by the present invention to perform a single sign-on to the network of FIG. The legacy server 118 runs the legacy application program 120. Old-fashioned servers can be mainframes, minicomputers, workstations, or other servers capable of running old-fashioned software applications designed to run on PKI processes in accordance with the present invention. It is not limited. The legacy application 120 is client-side accessible by a custom client 128, such as an emulator or custom database graphic user interface (GUI). Examples of emulators are IBM 3270 terminal emulators or vt100 terminal emulators.
【0018】
The registration web page 122 can be one or more pages and serves as a user interface to the network 100 shown in FIG. Web server 124 is a software application that supports web page 122 or other HTML output to a web browser client. Web server clients can be Apache, Microsoft Internet Information Server applications, but are not limited to these. The web browser 126 resides on the client platform 128. The client platform 128 can be any user computer. The web browser 126 is a client software application that browses web pages, such as, but not limited to, the HTML or XML protocol or other protocols. Web browser 126 is programmed to operate with PKI certification issued by Certificate Authority 110. An example of a web browser with this capability is Netscape. Navigator and Microsoft Internt Explorer.
【0019】
Token 130 can be a smart card, USB (Universal Serial Bus), or any other hardware token that can generate, store, and use PKI authentication. User 132 is a person who uses network 100. User 132 can be migrated through a number of states, including new users, current users, and old users. Old users are no longer members of a group or company. In describing Network 100, we refer to two levels of security, but the number of security levels is not limited to the present invention, and each level corresponds to a different security requirement. Level 1 search engine 134 may be a search engine that is allowed to search network 100, but has the lowest security level and is only allowed access to level 1 data. it can. Level 1 data can be freely distributable data, but not limited to it. Level 2 data can be considered enterprise-specific. The level 2 search engine 136 can be a search engine that is allowed to search both level 1 and level 2 data.
【0020】
A level N search engine (not shown) can be a search engine that is allowed to search the entire server that processes data from level 1 to N. Protection level server 138 with Level 1 data is a web server that contains only Level 1 data. Level 1 data is protected so that users must have (at least) Level 1 access to access Level 1 data. Protected web server 140 with Level 2 data is a web server that houses Level 2 data. Level 2 data is protected so that users must have at least Level 2 access to access Level 2 servers. Users with Level 2 access can access both Level 1 and Level 2 servers. A protected web server with Level N data (not shown) is a web server that houses Level N data accessible to Level N or higher users.
【0021】
VPN Extranet 142 is a software application that acts as a network gateway. As shown, this can be either an older server 118 and an older application 120, or an external network such as the Internet. The individual abolition authority 144 can be a person engaged in the abolition (invalidation) of members from the network 100. The individual registration authority 146 can be a person engaged in the registration of members in the network 100. The personal restoration approver 148 can be a person engaged in obtaining a restoration of certification. The restore agent 150 can be the person who restores the authentication, and only needs to restore the authentication when the authentication is first designated as recoverable by another person. The personal role approval 152 can be a person who approves different role functions within the network 100. The web server manager (administrator) can be one or more people engaged in various web functions in the network 100.
【0022】
FIG. 2 is a partial block diagram showing mint ID spoofing in another defective PKI system. For simplicity, the search engines 134 and 136 in FIG. 1 have been replaced with a single search engine 254 and the protected web servers 138 and 140 in FIG. 1 have been replaced with a single protected web server 258.
【0023】
In step 1 of Figure 2, user-1 (232) obtains signature authentication by a normal PKI process. In step 2, when User-1 attempts to access Protected Web Server 258, User-1 must present its signature authentication to Protected Web Server 258. Protected web server 258 recognizes signature authentication and grants access to user-1.
【0024】
In step 3 of FIG. 2, mint 236 impersonates user 1 and requests signature authentication from the local registrant 270. Other flawed PKI systems do not enforce rules that allow only one signature authentication per user, so mint 236 is given signature authentication.
【0025】
In step 4 of Figure 2, the mentha now has valid User-1 signature authentication, allowing unauthorized access to the protected web server 258. Thus, another flawed PKI system was unable to prevent unauthorized access to the protected web server.
【0026】
Alternatively, this other flawed PKI system could enforce a rule that allows only one signature authentication per user, but does not require all users to have signature authentication. In such a case, in step 5 of FIG. 2, mint 236 instead requests signature authentication as user-2, and since user-2 does not yet have signature authentication, signature authentication is given. Again, mint 236 is subsequently granted access to protected web server 258. This is because they have valid signature authentication, again, another flawed PKI system could not prevent unauthorized access to the protected web server.
【0027】
According to the present invention, an entity needs to have a practical way of identifying all members of the entity. That is, each member of the company, for example, each user, has a unique identifier such as an employee number. The basic database of all such identifiers must be maintained accurately as appropriate.
【0028】
Further, according to the present invention, every member of the enterprise must have digital signature authentication. However, a member of a company cannot have more than one digital signature certificate. Furthermore, according to the present invention, an entity must have a directory that identifies the one-to-one correspondence between members (users) and their digital signature authentication.
【0029】
According to the present invention, when a mint or other hostile user attempts to create a fake digital signature certificate, it queries the corporate directory and the hacker attempts to create a new signature certificate for an existing user. Prevent this attempt. In addition, if the mentha is trying to create a false user's signature authentication, this attempt is also prevented.
【0030】
FIG. 3 is a block diagram showing an example of preventing ID spoofing by a hacker in the PKI system according to the present invention. In step 1 of FIG. 3, the data entry 102 periodically updates the basic database 104 to accurately reflect the current number of employees in the company. In step 2 of FIG. 3, the basic database 104 periodically updates directory 108 to ensure that the directory is accurate and up-to-date.
【0031】
In step 3 of Figure 3, mint 236 accesses web server 124, identifies himself as a user on registered web page 122, and attempts to fraudulently obtain valid signature authentication. In step 4 of FIG. 3, the registered web server 124 queries directory 108 to obtain information about this user. In step 5, directory 108 provides information about the user to web server 124 in response to a query by web server 124. More specifically, the directory 108 notifies the web server 124 that the user already owns the signature certificate, and further informs the web server 124 that the old signature certificate is obsolete (discarded) until the new signature certificate is abolished. Notify you not to issue. This frustrates fraudulent attempts to obtain valid signature authentication for mentha. This attempt is frustrated because, according to the present invention, it must be presented in order to abolish (disable) the user's previous signature authentication.
【0032】
In step 6a, mint 236 accesses web server 124 in an attempt to abolish the user's previous signature authentication. According to the present invention, this attempt is frustrated because in order to abolish the user's previous signature authentication, it must be presented.
【0033】
Alternatively, in step 6b, mint 236 attempts to impersonate the user, approaches the personal abolition station 144, and requests the personal abolition station 144 to abolish the user's previous signature authentication. However, this attempt is also frustrated. This is because the personal registration authority 144 has been specifically selected to personally recognize the user (eg, the user's supervisor).
【0034】
In step 7 of Figure 3, mint 236 challenges a different technique in his fraudulent attempt to obtain a valid signature certificate. That is, the mint 236 accesses the registered web server 124 and falsely identifies himself as a new user on the registered web page 122. In step 8 of FIG. 3, the registered web server 124 queries directory 108 to obtain information about the user, as in step 4 above. In step 9 of FIG. 3, directory 108 provides information about the new user to the registration web server 124. That is, directory 108 tells the registered web server 124 that the user already owns the signature certificate and will not issue a new signature certificate until the old signature certificate is abolished. Alternatively, if the user does not exist in directory 108, directory 108 notifies registered web server 124 of the fact that it will not issue a new signature certificate to registered web server 124. Therefore, Hacker is once again frustrated by his fraudulent attempt to obtain a valid signature certificate.
【0035】
This is the end of the description of an example of the embodiment. Although the present invention has been described with reference to the exemplary embodiments, it will be appreciated by those skilled in the art that a number of other modifications and embodiments that fall within the spirit and scope of the principles of the invention will also be recalled. Yeah. That is, within the scope of the disclosure, drawings, and claims described above, reasonable modifications and changes can be made in the components and / or arrangement of the combinational composition of the subject matter without departing from the spirit of the present invention. In addition to modifications and changes in components and / or arrangements, alternative usage will be apparent to those skilled in the art.
【0036】
For example, the specific composition of the elements shown in the drawings is by no means unique. In addition, the various server platforms can be combined or separated to meet specific needs. Furthermore, one company representative can perform more than one function and vice versa.
[Simple explanation of drawings]
[Figure 1]
It is a block diagram which shows the architecture example of the network which can carry out the PKI process of this invention.
[Figure 2]
It is a partial block diagram which illustrates ID spoofing by mint in another defective PKI system.
[Fig. 3]
It is a block diagram which shows an example which prevents ID spoofing by mint in the PKI system by this invention.
[Explanation of symbols]
100 networks 102 Data entry 104 Basic database 106 server platform 108 directory 110 Certificate Authority 112 Registration Bureau 114 Key Recovery Bureau 116 Domain Certificate Authority (CA) 118 Old-fashioned server 120 Old-fashioned application program 122 Registration web page 124 web server 126 web browser 128 client platform 130 tokens 132 users
28 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7434047B2 | Cited by | United States of America | Search report |
| JP2005084933A | Cited by | Japan | Examiner |
| JPH05298174A | Cites | Japan | Search report |
| JPH11120141A | Cites | Japan | Search report |
73 members in 7 offices
Priority claims20
| Document | Office | Kind | Date |
|---|---|---|---|
| 21046300 | United States of America | P | |
| 21046300 | United States of America | P | |
| 21052400 | United States of America | P | |
| 21052400 | United States of America | P | |
| 60210463 | United States of America | – | |
| 60210524 | United States of America | – | |
| 22933600 | United States of America | P | |
| 22933600 | United States of America | P | |
| 60229336 | United States of America | – | |
| 09823701 | United States of America | – | |
| 82370101 | United States of America | A | |
| 82370101 | United States of America | A | |
| 2000210463 | – | – | – |
| 2000210524 | – | – | – |
| 2000229336 | – | – | – |
| 2001823701 | – | – | – |
| US20000210463P | – | – | – |
| US20000210524P | – | – | – |
| US20000229336P | – | – | – |
| US20010823701 | – | – | – |
Members73
| Document | Office | Kind | |
|---|---|---|---|
| EP1074427A2 | European Patent Office (EPO) | A2 | |
| WO0110667A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2001055066A | Japan | A | |
| AU3359900A | Australia | A | |
| US6199945B1 | United States of America | B1 | |
| KR20010020638A | Republic of Korea | A | |
| EP1162779A2 | European Patent Office (EPO) | A2 | |
| EP1162780A2 | European Patent Office (EPO) | A2 | |
| EP1162781A2 | European Patent Office (EPO) | A2 | |
| EP1162782A2 | European Patent Office (EPO) | A2 | |
| EP1162783A2 | European Patent Office (EPO) | A2 | |
| EP1162807A2 | European Patent Office (EPO) | A2 | |
| EP1164745A2 | European Patent Office (EPO) | A2 | |
| WO0196140A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU6669901A | Australia | A | |
| EP1175037A2 | European Patent Office (EPO) | A2 | |
| EP1175038A2 | European Patent Office (EPO) | A2 | |
| EP1175039A2 | European Patent Office (EPO) | A2 | |
| JP2002033726A | Japan | A | |
| JP2002049311A | Japan | A | |
| JP2002057660A | Japan | A | |
| JP2002057661A | Japan | A | |
| JP2002064485A | Japan | A | |
| US2002024245A1 | United States of America | A1 | |
| JP2002082913A | Japan | A | |
| JP2002123492A | Japan | A | |
| JP2002124944AThis record | Japan | A | |
| JP2002135244A | Japan | A | |
| JP2002135245A | Japan | A | |
| US2002138724A1 | United States of America | A1 | |
| US2002141592A1 | United States of America | A1 | |
| US2002144111A1 | United States of America | A1 | |
| US2002176582A1 | United States of America | A1 | |
| US6488333B2 | United States of America | B2 | |
| US6494531B1 | United States of America | B1 | |
| EP1074427A3 | European Patent Office (EPO) | A3 | |
| EP1162782A3 | European Patent Office (EPO) | A3 | |
| EP1162781A3 | European Patent Office (EPO) | A3 | |
| US2003208690A1 | United States of America | A1 | |
| EP1162807A3 | European Patent Office (EPO) | A3 | |
| EP1175038A3 | European Patent Office (EPO) | A3 | |
| EP1162783A3 | European Patent Office (EPO) | A3 | |
| EP1175037A3 | European Patent Office (EPO) | A3 | |
| EP1162779A3 | European Patent Office (EPO) | A3 | |
| EP1175039A3 | European Patent Office (EPO) | A3 | |
| EP1164745A3 | European Patent Office (EPO) | A3 | |
| EP1162780A3 | European Patent Office (EPO) | A3 | |
| US6898710B1 | United States of America | B1 | |
| JP3660274B2 | Japan | B2 | |
| US6934393B2 | United States of America | B2 | |
| US6934859B2 | United States of America | B2 | |
| US6941455B2 | United States of America | B2 | |
| US7028180B1 | United States of America | B1 | |
| US7028181B1 | United States of America | B1 | |
| US7047409B1 | United States of America | B1 | |
| EP1162807B1 | European Patent Office (EPO) | B1 | |
| US7069440B2 | United States of America | B2 | |
| DE60119834D1 | Germany | D1 | |
| EP1175038B1 | European Patent Office (EPO) | B1 | |
| KR100611570B1 | Republic of Korea | B1 | |
| DE60121517D1 | Germany | D1 | |
| EP1162781B1 | European Patent Office (EPO) | B1 | |
| DE60119834T2 | Germany | T2 | |
| DE60122828D1 | Germany | D1 | |
| DE60121517T2 | Germany | T2 | |
| DE60122828T2 | Germany | T2 | |
| US7275155B1 | United States of America | B1 | |
| US2007234039A1 | United States of America | A1 | |
| EP1162780B1 | European Patent Office (EPO) | B1 | |
| DE60132733D1 | Germany | D1 | |
| DE60132733T2 | Germany | T2 | |
| US7747852B2 | United States of America | B2 | |
| EP1175039B1 | European Patent Office (EPO) | B1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 2002-124944
- Publication, DOCDB
- 2002124944
- Publication, EPODOC
- JP2002124944
- Application
- 175361
- Application, DOCDB
- 2001175361
- Application, EPODOC
- JP20010175361
Titles2
- Japanese
- 【発明の名称】遍在署名認証を用いたIDスプーフィング防止
- English
- [Title of the Invention] Prevention of ID spoofing using ubiquitous signature authentication
Classification
- CPC, 13
- H04L63/0442
- G06F21/33
- G06F21/604
- G06F21/6209
- G06F21/6218
- G06F2221/2153
- H04L9/006
- H04L9/3263
- H04L63/0815
- H04L63/0823
- H04L63/083
- H04L63/126
- H04L63/1466
- IPC, 6
- G06F21 33
- G06F21 60
- G06F21 62
- G09C1 00
- H04L9 32
- H04L29 06