NL2014743B1

A first entity, a second entity, an intermediate node, methods for setting up a secure session between a first and second entity, and computer program products.

Abstract

The inventation relates to a method for setting up a secure session between a first entity and a second entity. In an embodiment, the first entity is a user authentication device and the second entity is an application running on a platform. The method comprisesgenerating a first random number. Auser enters a first string, derived from said number, into the second entity. Further, the method includes applying a one-way function to the first string or to a derivative thereof, obtaining an encoded string. The method also comprises transmitting the encoded string to an intermediate node that is in connection to the first entity and the second entity. Further, the method comprise the step of sharing a second random number with the second entity. The method also comprises a step of deriving a secret key from the first and the second string.

NL2014743B1, drawing sheet 1
Sheet 1 of 11

Term

8.6 yearsto projected expiry

Projected expiry 30 April 2035, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

35 claims: 22 independent, 13 dependent

  1. 1
    Claims 1. A method for performing an instruction on a platform application, comprising the steps of:- preparing a persistent instruction on a user workplace application that is remotely connected to the platform application;5 - forwarding the persistent instruction to the platform application;- setting up a secure connection between the platform application and an authentication device;- performing an authorization dialog between the transaction system application and the authentication device;and 10 - executing the instruction only when the authorization dialog has successfully finished.
  2. 5
    5 - receiving an encoded string from a first and second entity, the encoded string being obtained by applying a one-way function to a first string or to a derivative thereof, the first string being derived from a first random number generated by a first entity;- verifying whether the encoded strings received from the first and second 10 entity are the same;- if the verifying step has a positive result, authorizing the first and second entity to share a second string being derived from a second random number generated by the first or second entity, respectively. 5. A method according to any of the preceding claims, wherein the 15 platform application is a user workplace application, a cloud application, an authentication provider application, or a transaction system application.
  3. 6
    A method according to any of the preceding claims, wherein the first string is first random number or a random message produced from said first random number. 20
  4. 7
    A method according to any of the preceding claims, wherein, in the step of applying a one-way function, the derivative of the first string is obtained by performing a hash function to the first string.
  5. 8
    A method according to any of the preceding claims, wherein the second string is transmitted in an encrypted manner. 25
  6. 9
    A method according to any of the preceding claims, wherein the intermediate node is an authentication provider securely connected to the authentication device.
  7. 10
    A method according to any of the preceding claims, wherein the secure session is used to support secure one-way or two-way data transfer, such as transfer of a message, a decryption and/or encryption key, or an authorization dialog.
  8. 11
    A method according to any of the preceding claims, wherein the authorization dialog includes the steps of:5 - transmitting a code, from the transaction system application to the authentication device for entering the code into the user workplace application;- transmitting the code from the user workplace application to the transaction system application;and 10 - verifying whether the code received by the transaction system application is the same as the code transmitted by said transaction system application.
  9. 12
    A method according to any of the preceding claims, wherein the step of transmitting the second string is implemented by exporting the second string to a user, via an I/O interface of one entity, for manually 15 entering the second string into an I/O interface of the other entity.
  10. 13
    A method according to any of the preceding claims, further including a step of authorizing a document in a cloud application.
  11. 14
    A method according to any of the preceding claims, wherein the authentication device includes a cellular phone, PDA, smart card, token or 20 electronic key.
  12. 15
    A platform application that is remotely connected to a user workplace application and that has a secure connection with an authentication device, the platform application comprising a processor that is arranged for:25 - receiving a persistent instruction prepared on the user workplace;- performing an authorization dialog with the authentication device, via the secure connection;and - executing the instruction only when the authorization dialog has successfully finished.
  13. 19
    A network, comprising a platform application according to claim 25 15 or 16, an authentication device according to claim 17, and an intermediate node according to claim 18.
  14. 20
    A computer program product for performing an instruction on a platform application, the computer program product comprising computer readable code for facilitating a processing unit to perform the steps of:- preparing a persistent instruction on a user workplace application that is remotely connected to the platform application;- forwarding the persistent instruction to the platform application;- setting up a secure connection between the platform application and an authentication device;- performing an authorization dialog between the transaction system application and the authentication device;and - executing the instruction only when the authorization dialog has successfully finished.
  15. 24
    A method according to any of the preceding claims 1-14, wherein the context is shown to a user via a middleware.
  16. 25
    A method according to any of the preceding claims 1-14 and 24, wherein a step of securely associating the qKey server with the secure element also includes an association with a user token.
  17. 26
    A method according to any of the preceding claims 1-14, 24 and 25, wherein the association is performed statically or dynamically.
  18. 27
    A method according to any of the preceding claims 1-14 and 24-26, wherein the association is performed by performing the steps of:- generating, by the secure element, an asset and an activation announce message, - exporting the activation announce message from the secure element and entering it to the display and pin entry device.
  19. 28
    A method according to any of the preceding claims 1-14 and 24-27, wherein a static or dynamic association is established between middleware and qKey API, between middleware and secure element, between middleware and display and pin entry device, between qKey API and display and pin entry device, and/or between qKey API and secure element.
  20. 29
    A method according to any of the preceding claims 1-14 and 24-28, wherein the display and entry token are implement as an app on a user token.
  21. 34
    A method according to any of the preceding claims 1-14 and 24-33, wherein the qKey server and/or the secure element sends a message 5 including context to a pre-specified address of the app.
  22. 35
    A method according to any of the preceding claims 1-14 and 24-34, wherein the announce message is subsequently used to establish an end-2end connection between a mobile phone having the app and the device which uses or communicates with the middleware. 1/9 10 40
Independent claims22