UA95313C2

Method and device for mutual authentification

Abstract

Disclosed is a method for mutual authentication between a station, having a digital rights agent, and a secure removable media device. The digital rights agent initiates mutual authentication by sending a message to the secure removable media device. The secure removable media device encrypts a first random number using a public key associated with the digital rights agent. The digital rights agent decrypts the encrypted first random number, and encrypts a second random number and a first hash based on at least the first random number. The secure removable media device decrypts the encrypted second random number and the first hash, verifies the first hash to authenticate the digital rights agent, and generates a second hash based on at least the second random number. The digital rights agent verifies the second hash to authenticate the secure removable media device.

UA95313C2, drawing sheet 1
Sheet 1 of 1

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

25 claims: 24 independent, 1 dependent

  1. 1
    The method of mutual authentication between the first an object and a second object, comprising the steps of:1. Спосіб взаємної аутентифікації між першим об'єктом і другим об'єктом, який містить етапи, на яких: with the help of the first object, initiate mutual authentication by sending a message to another object;за допомогою першого об'єкта, ініціюють взаємну аутентифікацію за допомогою відправлення повідомлення другому об'єкту;with the help of the second object, verifies the first one an open key associated with the first object, forms the first random number, Encrypt the first random number using the first public key and send the encrypted first random number in the message to the first object;за допомогою другого об'єкта, верифікують перший відкритий ключ, асоційований з першим об'єктом, формують перше випадкове число, шифрують перше випадкове число за допомогою першого відкритого ключа і відправляють зашифроване перше випадкове число в повідомленні першому об'єкту;with the help of the first object, verifies the second an open key associated with the second object decrypts the encrypted first random number using the first private key that corresponds to the first one the public key, form the second random number, form the first hash on the basis at least the first random number, encrypts the second random number and the first hash with the help of the second public key and send the encrypted second random number and the first hash in the message of the second object;за допомогою першого об'єкта, верифікують другий відкритий ключ, асоційований з другим об'єктом, розшифровують зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формують друге випадкове число, формують перший хеш на основі щонайменше першого випадкового числа, шифрують друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляють зашифровані друге випадкове число і перший хеш в повідомленні другому об'єкту;with the help of the second object, decrypt the encrypted second random the number and first hash with the help of a second private key that corresponds the second public key, verifies the first hash to authenticate the first object, form a second hash based on at least the second random number and send the second hash to the first one object;and за допомогою другого об'єкта, розшифровують зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікують перший хеш, щоб аутентифікувати перший об'єкт, формують другий хеш на основі щонайменше другого випадкового числа і відправляють другий хеш першому об'єкту;і using the first object, verifies the second hash to authenticate the second object. за допомогою першого об'єкта, верифікують другий хеш, щоб аутентифікувати другий об'єкт.
  2. 2
    The method of mutual authentication under clause 1, c which first object and the second object extract the session encryption key and key with authentication code message (MAC) with the first random number and the second random numbers based on the key extraction function for use in implementation the connection between the first object and the second object. 2. Спосіб взаємної аутентифікації за п. 1, в якому перший об'єкт і другий об'єкт добувають сеансовий ключ шифрування і ключ з кодом аутентифікації повідомлення (МАС) за допомогою першого випадкового числа і другого випадкового числа на основі функції добування ключів для використання при здійсненні зв'язку між першим об'єктом і другим об'єктом.
  3. 3
    The method of mutual authentication under clause 1, c which message triggering mutual authentication includes a hash of at least one trusted root key and the corresponding chain of certificates for the first object. 3. Спосіб взаємної аутентифікації за п. 1, в якому повідомлення, що ініціює взаємну аутентифікацію, включає в себе хеш щонайменше одного довіреного кореневого ключа і відповідний ланцюжок сертифікатів для першого об'єкта.
  4. 5
    Method of mutual authentication under clause 1, c which first object is an agent of digital rights, and the second object is a device protected removable media. 5. Спосіб взаємної аутентифікації за п. 1, в якому перший об'єкт є агентом цифрових прав, а другий об'єкт є пристроєм захищеного знімного носія.
  5. 6
    Method of mutual authentication under item 1, c which first object is a mobile station. 6. Спосіб взаємної аутентифікації за п. 1, в якому перший об'єкт є мобільною станцією.
  6. 7
    Method of mutual authentication under clause 1, c which second object has a limited computing power. 7. Спосіб взаємної аутентифікації за п. 1, в якому другий об'єкт має обмежену обчислювальну потужність.
  7. 8
    Method of mutual authentication under clause 1, c which first hash additionally based on at least the second random number such that the first hash is formed on the basis of at least the first random numbers, concatenated with a different random number. 8. Спосіб взаємної аутентифікації за п. 1, в якому перший хеш додатково оснований щонайменше на другому випадковому числі так, що перший хеш формується на основі щонайменше першого випадкового числа, конкатенованого з другим випадковим числом.
  8. 9
    The method of mutual authentication according to clause 1, c which second hash additionally based on at least the first random number of 9. Спосіб взаємної аутентифікації за п. 1, в якому другий хеш додатково оснований щонайменше на першому випадковому числі.
  9. 10
    Method of mutual authentication under clause 1, c which second hash is additionally based on at least the first hash so that the second hash is formed on the basis of at least the second random numbers concatenated with the first hash. 10. Спосіб взаємної аутентифікації за п. 1, в якому другий хеш додатково оснований щонайменше на першому хеші так, що другий хеш формується на основі щонайменше другого випадкового числа, конкатенованого з першим хешем.
  10. 11
    A device for mutual authentication, which contains:a means for initiating mutual authentication;11. Пристрій для взаємної аутентифікації, який містить: засіб ініціювання взаємної аутентифікації;a means of verifying the first public key, forming the first random numbers and encryption of the first random number using the first open the key;засіб верифікації першого відкритого ключа, формування першого випадкового числа і шифрування першого випадкового числа за допомогою першого відкритого ключа;a means of verifying the second public key, decrypting the encrypted the first random number with the help of the first private key that corresponds the first open key, the formation of the second random number, the formation first hash based on at least the first random number and encryption of the second one random number and first hash with the help of a second public key;засіб верифікації другого відкритого ключа, розшифрування зашифрованого першого випадкового числа за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формування другого випадкового числа, формування першого хеша на основі щонайменше першого випадкового числа і шифрування другого випадкового числа і першого хеша за допомогою другого відкритого ключа;decryption means encrypted second random number and first hash with the help of a second private key that corresponds to the second public key verification the first hash for authentication and the formation of a second hash based on at least the second random number;and засіб розшифрування зашифрованого другого випадкового числа і першого хеша за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікації першого хеша для аутентифікації і формування другого хеша на основі щонайменше другого випадкового числа;і a means of verifying a second hash for authentication. засіб верифікації другого хеша для аутентифікації.
  11. 12
    Device for mutual authentication under p. 11, which further includes a means for extracting a session key encryption and a key with an authentication code message (MAC) with the first random number and the second random numbers based on the key extraction function for use in implementation the connection between the first object and the second object. 12. Пристрій для взаємної аутентифікації за п. 11, який додатково містить засіб добування сеансового ключа шифрування і ключа з кодом аутентифікації повідомлення (МАС) за допомогою першого випадкового числа і другого випадкового числа на основі функції добування ключів для використання при здійсненні зв'язку між першим об'єктом і другим об'єктом.
  12. 13
    Device for mutual authentication under p. 11, in which the first hash is additionally based on at least the second random number such that the first hash is formed on the basis of at least the first random numbers, concatenated with a different random number. 13. Пристрій для взаємної аутентифікації за п. 11, в якому перший хеш додатково оснований щонайменше на другому випадковому числі так, що перший хеш формується на основі щонайменше першого випадкового числа, конкатенованого з другим випадковим числом.
  13. 14
    Device for mutual authentication under p. 11, in which the second hash is additionally based on at least the first random number of 14. Пристрій для взаємної аутентифікації за п. 11, в якому другий хеш додатково оснований щонайменше на першому випадковому числі.
  14. 15
    Device for mutual authentication under p. 11, in which the second hash is additionally based on the first hash so that the second hash is formed on the basis of the second random number concatenated with the first hash. 15. Пристрій для взаємної аутентифікації за п. 11, в якому другий хеш додатково оснований на першому хеші так, що другий хеш формується на основі другого випадкового числа, конкатенованого з першим хешем.
  15. 16
    Station that has mutual authentication with a protected removable media device that contains:16. Станція, яка має взаємну аутентифікацію з пристроєм захищеного знімного носія, яка містить: agent of digital rights, while: агент цифрових прав, при цьому: The digital rights agent initiates mutual authentication by sending a message to the protected removable media device, at This device protects secured removable media the first public key associated with the digital rights agent, forms the first random number encrypts the first random number using the first open key and sends the encrypted first random number in the message to the agent digital rights;агент цифрових прав ініціює взаємну аутентифікацію за допомогою відправлення повідомлення пристрою захищеного знімного носія, при цьому пристрій захищеного знімного носія верифікує перший відкритий ключ, асоційований з агентом цифрових прав, формує перше випадкове число, шифрує перше випадкове число за допомогою першого відкритого ключа і відправляє зашифроване перше випадкове число в повідомленні агенту цифрових прав;digital rights agent verifies the second open The key associated with the protected removable media device decrypts encrypted the first random number using the first private key which corresponds to the first open key, forms a second random number, forms the first hash based on at least the first random number, encrypts the second random number and the first hash with the help of a second public key and sends the encrypted second random the number and first hash in the message in the device protected removable media, at this secured removable media device decrypts the encrypted second random number and the first hash with a second private key that matches the second public key verifies first hash to authenticate agent of digital rights, forms a second hash based on at least the second random number and sends a second hash digital rights agent;and агент цифрових прав верифікує другий відкритий ключ, асоційований з пристроєм захищеного знімного носія, розшифровує зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формує друге випадкове число, формує перший хеш на основі щонайменше першого випадкового числа, шифрує друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляє зашифровані друге випадкове число і перший хеш в повідомленні в пристрій захищеного знімного носія, при цьому пристрій захищеного знімного носія розшифровує зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікує перший хеш, щоб аутентифікувати агент цифрових прав, формує другий хеш на основі щонайменше другого випадкового числа і відправляє другий хеш агенту цифрових прав;і The digital rights agent verifies the second hash to authenticate the protected removable media device. агент цифрових прав верифікує другий хеш, щоб аутентифікувати пристрій захищеного знімного носія.
  16. 17
    A station that has mutual authentication, for para. 16, in which the digital rights agent and the device of the protected removable media extract the session encryption key and message authentication key (MAC) key using the first one. a random number and a second random number based on the extraction function keys for use in communication between the agent of digital rights and secured removable media device. 17. Станція, яка має взаємну аутентифікацію, за п. 16, в якій агент цифрових прав і пристрій захищеного знімного носія добувають сеансовий ключ шифрування і ключ коду аутентифікації повідомлення (МАС) за допомогою першого випадкового числа і другого випадкового числа на основі функції добування ключів для використання при здійсненні зв'язку між агентом цифрових прав і пристроєм захищеного знімного носія.
  17. 18
    A station that has mutual authentication for clause 16, in which the message sent with the help of a digital rights agent to initiate mutual authentication, includes a hash of at least one trusted root key and appropriate chain of certificates for a digital rights agent. 18. Станція, яка має взаємну аутентифікацію, за п. 16, в якій повідомлення, відправлене за допомогою агента цифрових прав, щоб ініціювати взаємну аутентифікацію, включає в себе хеш щонайменше одного довіреного кореневого ключа і відповідний ланцюжок сертифікатів для агента цифрових прав.
  18. 19
    A station that has mutual authentication, for Item 18, in which chain of certificates for a digital rights agent includes public key associated with a digital rights agent. 19. Станція, яка має взаємну аутентифікацію, за п. 18, в якій ланцюжок сертифікатів для агента цифрових прав включає в себе відкритий ключ, асоційований з агентом цифрових прав.
  19. 20
    A station that has mutual authentication for para. 16, in which message sent with the device protected a removable carrier of the digital rights agent having the first random number encrypted, additionally includes a certificate chain for a secured removable device carrier 20. Станція, яка має взаємну аутентифікацію, за п. 16, в якій повідомлення, відправлене за допомогою пристрою захищеного знімного носія агенту цифрових прав, яке має зашифроване перше випадкове число, додатково включає в себе ланцюжок сертифікатів для пристрою захищеного знімного носія.
  20. 21
    A station that has mutual authentication for Item 20, in which chain of certificates for the protected removable media device includes an open key associated with a secured removable device carrier 21. Станція, яка має взаємну аутентифікацію, за п. 20, в якій ланцюжок сертифікатів для пристрою захищеного знімного носія включає в себе відкритий ключ, асоційований з пристроєм захищеного знімного носія.
  21. 22
    A station that has mutual authentication for Item 16, in which station is a mobile station. 22. Станція, яка має взаємну аутентифікацію, за п. 16, в якій станція є мобільною станцією.
  22. 23
    A station that has mutual authentication for 16, in which the first hash is additionally based on at least the second random such that the digital rights agent forms the first hash based on at least the first random number concatenated with the second random number. 23. Станція, яка має взаємну аутентифікацію, за п. 16, в якій перший хеш додатково оснований щонайменше на другому випадковому числі так, що агент цифрових прав формує перший хеш на основі щонайменше першого випадкового числа, конкатенованого з другим випадковим числом.
  23. 24
    A machine-readable medium comprising:24. Машинозчитуваний носій, який містить: A code to force a computer to force a digital rights station agent initiate mutual authentication with help sending a message to a protected removable media device, in this case The protected removable media device verifies the first one an open key associated with a digital rights agent generates the first random one number encrypts the first random number using the first public key and sends the encrypted first random number in the message to the digital agent rights;код для спонукання комп'ютера змушувати агента цифрових прав станції ініціювати взаємну аутентифікацію за допомогою відправлення повідомлення пристрою захищеного знімного носія, при цьому пристрій захищеного знімного носія верифікує перший відкритий ключ, асоційований з агентом цифрових прав, формує перше випадкове число, шифрує перше випадкове число за допомогою першого відкритого ключа і відправляє зашифроване перше випадкове число в повідомленні агенту цифрових прав;code to force the computer to force the digital rights agent of the station to verify the second public key associated with the device Protected removable media, decrypt the encrypted first random number for using the first private key that corresponds to the first public key, to form a second random number, to form the first hash on the basis of at least the first random number, to encrypt the second random number and the first hash using the second public key and send encrypted second random number and the first hash in the message in the device of the protected removable media, at This protected removable media device decrypts the encrypted second random number and first hash with the help of a second private key that corresponds the second public key, verifies the first hash to authenticate the digital rights agent, forms a second hash based on at least the second random number and sends a second hash to the agent digital rights;and код для спонукання комп'ютера змушувати агента цифрових прав станції верифікувати другий відкритий ключ, асоційований з пристроєм захищеного знімного носія, розшифровувати зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формувати друге випадкове число, формувати перший хеш на основі щонайменше першого випадкового числа, шифрувати друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляти зашифровані друге випадкове число і перший хеш в повідомленні в пристрій захищеного знімного носія, при цьому пристрій захищеного знімного носія розшифровує зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікує перший хеш, щоб аутентифікувати агент цифрових прав, формує другий хеш на основі щонайменше другого випадкового числа і відправляє другий хеш агенту цифрових прав;і code to force the computer to force the digital rights agent to verify the second hash to authenticate the device protected removable media. код для спонукання комп'ютера змушувати агента цифрових прав верифікувати другий хеш, щоб аутентифікувати пристрій захищеного знімного носія.
  24. 25
    A machine-readable medium comprising:25. Машинозчитуваний носій, який містить: code to force the computer to force the protected removable media device to verify the first public key associated with the agent digital rights, to form the first random number, to encrypt the first random number with the help of the first public key and send encrypted first random number in the message of the digital rights agent, with the digital rights agent verifying the second public key associated with the device Protected Removable Media, decrypts encrypted first random number using the first private key that matches the first open the key generates a second random number, forms the first hash based on at least the first random number, encrypts the second random number and first hash with the help of a second public key and sends encrypted second random number and first hash in message in device protected removable media;код для спонукання комп'ютера змушувати пристрій захищеного знімного носія верифікувати перший відкритий ключ, асоційований з агентом цифрових прав, формувати перше випадкове число, шифрувати перше випадкове число за допомогою першого відкритого ключа і відправляти зашифроване перше випадкове число в повідомленні агенту цифрових прав, при цьому агент цифрових прав верифікує другий відкритий ключ, асоційований з пристроєм захищеного знімного носія, розшифровує зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формує друге випадкове число, формує перший хеш на основі щонайменше першого випадкового числа, шифрує друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляє зашифровані друге випадкове число і перший хеш в повідомленні в пристрій захищеного знімного носія;A code to force a computer to force a protected removable media device decrypt the encrypted second random number and the first hash with the help of the second private key that corresponds to the second public key, verifies the first hash to authenticate the agent digital rights, form a second hash based on at least the second random number and send the second hash of the digital rights agent, while the digital rights agent verifies second hash to authenticate a secured removable device carrier код для спонукання комп'ютера змушувати пристрій захищеного знімного носія розшифровувати зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікувати перший хеш, щоб аутентифікувати агент цифрових прав, формувати другий хеш на основі щонайменше другого випадкового числа і відправляти другий хеш агенту цифрових прав, при цьому агент цифрових прав верифікує другий хеш, щоб аутентифікувати пристрій захищеного знімного носія.
Independent claims24