Method and device for mutual authentification
Abstract
Disclosed is a method for mutual authentication between a station, having a digital rights agent, and a secure removable media device. The digital rights agent initiates mutual authentication by sending a message to the secure removable media device. The secure removable media device encrypts a first random number using a public key associated with the digital rights agent. The digital rights agent decrypts the encrypted first random number, and encrypts a second random number and a first hash based on at least the first random number. The secure removable media device decrypts the encrypted second random number and the first hash, verifies the first hash to authenticate the digital rights agent, and generates a second hash based on at least the second random number. The digital rights agent verifies the second hash to authenticate the secure removable media device.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
25 claims: 24 independent, 1 dependent
- 1The method of mutual authentication between the first an object and a second object, comprising the steps of:1. Спосіб взаємної аутентифікації між першим об'єктом і другим об'єктом, який містить етапи, на яких: with the help of the first object, initiate mutual authentication by sending a message to another object;за допомогою першого об'єкта, ініціюють взаємну аутентифікацію за допомогою відправлення повідомлення другому об'єкту;with the help of the second object, verifies the first one an open key associated with the first object, forms the first random number, Encrypt the first random number using the first public key and send the encrypted first random number in the message to the first object;за допомогою другого об'єкта, верифікують перший відкритий ключ, асоційований з першим об'єктом, формують перше випадкове число, шифрують перше випадкове число за допомогою першого відкритого ключа і відправляють зашифроване перше випадкове число в повідомленні першому об'єкту;with the help of the first object, verifies the second an open key associated with the second object decrypts the encrypted first random number using the first private key that corresponds to the first one the public key, form the second random number, form the first hash on the basis at least the first random number, encrypts the second random number and the first hash with the help of the second public key and send the encrypted second random number and the first hash in the message of the second object;за допомогою першого об'єкта, верифікують другий відкритий ключ, асоційований з другим об'єктом, розшифровують зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формують друге випадкове число, формують перший хеш на основі щонайменше першого випадкового числа, шифрують друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляють зашифровані друге випадкове число і перший хеш в повідомленні другому об'єкту;with the help of the second object, decrypt the encrypted second random the number and first hash with the help of a second private key that corresponds the second public key, verifies the first hash to authenticate the first object, form a second hash based on at least the second random number and send the second hash to the first one object;and за допомогою другого об'єкта, розшифровують зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікують перший хеш, щоб аутентифікувати перший об'єкт, формують другий хеш на основі щонайменше другого випадкового числа і відправляють другий хеш першому об'єкту;і using the first object, verifies the second hash to authenticate the second object. за допомогою першого об'єкта, верифікують другий хеш, щоб аутентифікувати другий об'єкт.
- 2The method of mutual authentication under clause 1, c which first object and the second object extract the session encryption key and key with authentication code message (MAC) with the first random number and the second random numbers based on the key extraction function for use in implementation the connection between the first object and the second object. 2. Спосіб взаємної аутентифікації за п. 1, в якому перший об'єкт і другий об'єкт добувають сеансовий ключ шифрування і ключ з кодом аутентифікації повідомлення (МАС) за допомогою першого випадкового числа і другого випадкового числа на основі функції добування ключів для використання при здійсненні зв'язку між першим об'єктом і другим об'єктом.
- 3The method of mutual authentication under clause 1, c which message triggering mutual authentication includes a hash of at least one trusted root key and the corresponding chain of certificates for the first object. 3. Спосіб взаємної аутентифікації за п. 1, в якому повідомлення, що ініціює взаємну аутентифікацію, включає в себе хеш щонайменше одного довіреного кореневого ключа і відповідний ланцюжок сертифікатів для першого об'єкта.
- 5Method of mutual authentication under clause 1, c which first object is an agent of digital rights, and the second object is a device protected removable media. 5. Спосіб взаємної аутентифікації за п. 1, в якому перший об'єкт є агентом цифрових прав, а другий об'єкт є пристроєм захищеного знімного носія.
- 6Method of mutual authentication under item 1, c which first object is a mobile station. 6. Спосіб взаємної аутентифікації за п. 1, в якому перший об'єкт є мобільною станцією.
- 7Method of mutual authentication under clause 1, c which second object has a limited computing power. 7. Спосіб взаємної аутентифікації за п. 1, в якому другий об'єкт має обмежену обчислювальну потужність.
- 8Method of mutual authentication under clause 1, c which first hash additionally based on at least the second random number such that the first hash is formed on the basis of at least the first random numbers, concatenated with a different random number. 8. Спосіб взаємної аутентифікації за п. 1, в якому перший хеш додатково оснований щонайменше на другому випадковому числі так, що перший хеш формується на основі щонайменше першого випадкового числа, конкатенованого з другим випадковим числом.
- 9The method of mutual authentication according to clause 1, c which second hash additionally based on at least the first random number of 9. Спосіб взаємної аутентифікації за п. 1, в якому другий хеш додатково оснований щонайменше на першому випадковому числі.
- 10Method of mutual authentication under clause 1, c which second hash is additionally based on at least the first hash so that the second hash is formed on the basis of at least the second random numbers concatenated with the first hash. 10. Спосіб взаємної аутентифікації за п. 1, в якому другий хеш додатково оснований щонайменше на першому хеші так, що другий хеш формується на основі щонайменше другого випадкового числа, конкатенованого з першим хешем.
- 11A device for mutual authentication, which contains:a means for initiating mutual authentication;11. Пристрій для взаємної аутентифікації, який містить: засіб ініціювання взаємної аутентифікації;a means of verifying the first public key, forming the first random numbers and encryption of the first random number using the first open the key;засіб верифікації першого відкритого ключа, формування першого випадкового числа і шифрування першого випадкового числа за допомогою першого відкритого ключа;a means of verifying the second public key, decrypting the encrypted the first random number with the help of the first private key that corresponds the first open key, the formation of the second random number, the formation first hash based on at least the first random number and encryption of the second one random number and first hash with the help of a second public key;засіб верифікації другого відкритого ключа, розшифрування зашифрованого першого випадкового числа за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формування другого випадкового числа, формування першого хеша на основі щонайменше першого випадкового числа і шифрування другого випадкового числа і першого хеша за допомогою другого відкритого ключа;decryption means encrypted second random number and first hash with the help of a second private key that corresponds to the second public key verification the first hash for authentication and the formation of a second hash based on at least the second random number;and засіб розшифрування зашифрованого другого випадкового числа і першого хеша за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікації першого хеша для аутентифікації і формування другого хеша на основі щонайменше другого випадкового числа;і a means of verifying a second hash for authentication. засіб верифікації другого хеша для аутентифікації.
- 12Device for mutual authentication under p. 11, which further includes a means for extracting a session key encryption and a key with an authentication code message (MAC) with the first random number and the second random numbers based on the key extraction function for use in implementation the connection between the first object and the second object. 12. Пристрій для взаємної аутентифікації за п. 11, який додатково містить засіб добування сеансового ключа шифрування і ключа з кодом аутентифікації повідомлення (МАС) за допомогою першого випадкового числа і другого випадкового числа на основі функції добування ключів для використання при здійсненні зв'язку між першим об'єктом і другим об'єктом.
- 13Device for mutual authentication under p. 11, in which the first hash is additionally based on at least the second random number such that the first hash is formed on the basis of at least the first random numbers, concatenated with a different random number. 13. Пристрій для взаємної аутентифікації за п. 11, в якому перший хеш додатково оснований щонайменше на другому випадковому числі так, що перший хеш формується на основі щонайменше першого випадкового числа, конкатенованого з другим випадковим числом.
- 14Device for mutual authentication under p. 11, in which the second hash is additionally based on at least the first random number of 14. Пристрій для взаємної аутентифікації за п. 11, в якому другий хеш додатково оснований щонайменше на першому випадковому числі.
- 15Device for mutual authentication under p. 11, in which the second hash is additionally based on the first hash so that the second hash is formed on the basis of the second random number concatenated with the first hash. 15. Пристрій для взаємної аутентифікації за п. 11, в якому другий хеш додатково оснований на першому хеші так, що другий хеш формується на основі другого випадкового числа, конкатенованого з першим хешем.
- 16Station that has mutual authentication with a protected removable media device that contains:16. Станція, яка має взаємну аутентифікацію з пристроєм захищеного знімного носія, яка містить: agent of digital rights, while: агент цифрових прав, при цьому: The digital rights agent initiates mutual authentication by sending a message to the protected removable media device, at This device protects secured removable media the first public key associated with the digital rights agent, forms the first random number encrypts the first random number using the first open key and sends the encrypted first random number in the message to the agent digital rights;агент цифрових прав ініціює взаємну аутентифікацію за допомогою відправлення повідомлення пристрою захищеного знімного носія, при цьому пристрій захищеного знімного носія верифікує перший відкритий ключ, асоційований з агентом цифрових прав, формує перше випадкове число, шифрує перше випадкове число за допомогою першого відкритого ключа і відправляє зашифроване перше випадкове число в повідомленні агенту цифрових прав;digital rights agent verifies the second open The key associated with the protected removable media device decrypts encrypted the first random number using the first private key which corresponds to the first open key, forms a second random number, forms the first hash based on at least the first random number, encrypts the second random number and the first hash with the help of a second public key and sends the encrypted second random the number and first hash in the message in the device protected removable media, at this secured removable media device decrypts the encrypted second random number and the first hash with a second private key that matches the second public key verifies first hash to authenticate agent of digital rights, forms a second hash based on at least the second random number and sends a second hash digital rights agent;and агент цифрових прав верифікує другий відкритий ключ, асоційований з пристроєм захищеного знімного носія, розшифровує зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формує друге випадкове число, формує перший хеш на основі щонайменше першого випадкового числа, шифрує друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляє зашифровані друге випадкове число і перший хеш в повідомленні в пристрій захищеного знімного носія, при цьому пристрій захищеного знімного носія розшифровує зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікує перший хеш, щоб аутентифікувати агент цифрових прав, формує другий хеш на основі щонайменше другого випадкового числа і відправляє другий хеш агенту цифрових прав;і The digital rights agent verifies the second hash to authenticate the protected removable media device. агент цифрових прав верифікує другий хеш, щоб аутентифікувати пристрій захищеного знімного носія.
- 17A station that has mutual authentication, for para. 16, in which the digital rights agent and the device of the protected removable media extract the session encryption key and message authentication key (MAC) key using the first one. a random number and a second random number based on the extraction function keys for use in communication between the agent of digital rights and secured removable media device. 17. Станція, яка має взаємну аутентифікацію, за п. 16, в якій агент цифрових прав і пристрій захищеного знімного носія добувають сеансовий ключ шифрування і ключ коду аутентифікації повідомлення (МАС) за допомогою першого випадкового числа і другого випадкового числа на основі функції добування ключів для використання при здійсненні зв'язку між агентом цифрових прав і пристроєм захищеного знімного носія.
- 18A station that has mutual authentication for clause 16, in which the message sent with the help of a digital rights agent to initiate mutual authentication, includes a hash of at least one trusted root key and appropriate chain of certificates for a digital rights agent. 18. Станція, яка має взаємну аутентифікацію, за п. 16, в якій повідомлення, відправлене за допомогою агента цифрових прав, щоб ініціювати взаємну аутентифікацію, включає в себе хеш щонайменше одного довіреного кореневого ключа і відповідний ланцюжок сертифікатів для агента цифрових прав.
- 19A station that has mutual authentication, for Item 18, in which chain of certificates for a digital rights agent includes public key associated with a digital rights agent. 19. Станція, яка має взаємну аутентифікацію, за п. 18, в якій ланцюжок сертифікатів для агента цифрових прав включає в себе відкритий ключ, асоційований з агентом цифрових прав.
- 20A station that has mutual authentication for para. 16, in which message sent with the device protected a removable carrier of the digital rights agent having the first random number encrypted, additionally includes a certificate chain for a secured removable device carrier 20. Станція, яка має взаємну аутентифікацію, за п. 16, в якій повідомлення, відправлене за допомогою пристрою захищеного знімного носія агенту цифрових прав, яке має зашифроване перше випадкове число, додатково включає в себе ланцюжок сертифікатів для пристрою захищеного знімного носія.
- 21A station that has mutual authentication for Item 20, in which chain of certificates for the protected removable media device includes an open key associated with a secured removable device carrier 21. Станція, яка має взаємну аутентифікацію, за п. 20, в якій ланцюжок сертифікатів для пристрою захищеного знімного носія включає в себе відкритий ключ, асоційований з пристроєм захищеного знімного носія.
- 22A station that has mutual authentication for Item 16, in which station is a mobile station. 22. Станція, яка має взаємну аутентифікацію, за п. 16, в якій станція є мобільною станцією.
- 23A station that has mutual authentication for 16, in which the first hash is additionally based on at least the second random such that the digital rights agent forms the first hash based on at least the first random number concatenated with the second random number. 23. Станція, яка має взаємну аутентифікацію, за п. 16, в якій перший хеш додатково оснований щонайменше на другому випадковому числі так, що агент цифрових прав формує перший хеш на основі щонайменше першого випадкового числа, конкатенованого з другим випадковим числом.
- 24A machine-readable medium comprising:24. Машинозчитуваний носій, який містить: A code to force a computer to force a digital rights station agent initiate mutual authentication with help sending a message to a protected removable media device, in this case The protected removable media device verifies the first one an open key associated with a digital rights agent generates the first random one number encrypts the first random number using the first public key and sends the encrypted first random number in the message to the digital agent rights;код для спонукання комп'ютера змушувати агента цифрових прав станції ініціювати взаємну аутентифікацію за допомогою відправлення повідомлення пристрою захищеного знімного носія, при цьому пристрій захищеного знімного носія верифікує перший відкритий ключ, асоційований з агентом цифрових прав, формує перше випадкове число, шифрує перше випадкове число за допомогою першого відкритого ключа і відправляє зашифроване перше випадкове число в повідомленні агенту цифрових прав;code to force the computer to force the digital rights agent of the station to verify the second public key associated with the device Protected removable media, decrypt the encrypted first random number for using the first private key that corresponds to the first public key, to form a second random number, to form the first hash on the basis of at least the first random number, to encrypt the second random number and the first hash using the second public key and send encrypted second random number and the first hash in the message in the device of the protected removable media, at This protected removable media device decrypts the encrypted second random number and first hash with the help of a second private key that corresponds the second public key, verifies the first hash to authenticate the digital rights agent, forms a second hash based on at least the second random number and sends a second hash to the agent digital rights;and код для спонукання комп'ютера змушувати агента цифрових прав станції верифікувати другий відкритий ключ, асоційований з пристроєм захищеного знімного носія, розшифровувати зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формувати друге випадкове число, формувати перший хеш на основі щонайменше першого випадкового числа, шифрувати друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляти зашифровані друге випадкове число і перший хеш в повідомленні в пристрій захищеного знімного носія, при цьому пристрій захищеного знімного носія розшифровує зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікує перший хеш, щоб аутентифікувати агент цифрових прав, формує другий хеш на основі щонайменше другого випадкового числа і відправляє другий хеш агенту цифрових прав;і code to force the computer to force the digital rights agent to verify the second hash to authenticate the device protected removable media. код для спонукання комп'ютера змушувати агента цифрових прав верифікувати другий хеш, щоб аутентифікувати пристрій захищеного знімного носія.
- 25A machine-readable medium comprising:25. Машинозчитуваний носій, який містить: code to force the computer to force the protected removable media device to verify the first public key associated with the agent digital rights, to form the first random number, to encrypt the first random number with the help of the first public key and send encrypted first random number in the message of the digital rights agent, with the digital rights agent verifying the second public key associated with the device Protected Removable Media, decrypts encrypted first random number using the first private key that matches the first open the key generates a second random number, forms the first hash based on at least the first random number, encrypts the second random number and first hash with the help of a second public key and sends encrypted second random number and first hash in message in device protected removable media;код для спонукання комп'ютера змушувати пристрій захищеного знімного носія верифікувати перший відкритий ключ, асоційований з агентом цифрових прав, формувати перше випадкове число, шифрувати перше випадкове число за допомогою першого відкритого ключа і відправляти зашифроване перше випадкове число в повідомленні агенту цифрових прав, при цьому агент цифрових прав верифікує другий відкритий ключ, асоційований з пристроєм захищеного знімного носія, розшифровує зашифроване перше випадкове число за допомогою першого закритого ключа, який відповідає першому відкритому ключу, формує друге випадкове число, формує перший хеш на основі щонайменше першого випадкового числа, шифрує друге випадкове число і перший хеш за допомогою другого відкритого ключа і відправляє зашифровані друге випадкове число і перший хеш в повідомленні в пристрій захищеного знімного носія;A code to force a computer to force a protected removable media device decrypt the encrypted second random number and the first hash with the help of the second private key that corresponds to the second public key, verifies the first hash to authenticate the agent digital rights, form a second hash based on at least the second random number and send the second hash of the digital rights agent, while the digital rights agent verifies second hash to authenticate a secured removable device carrier код для спонукання комп'ютера змушувати пристрій захищеного знімного носія розшифровувати зашифровані друге випадкове число і перший хеш за допомогою другого закритого ключа, який відповідає другому відкритому ключу, верифікувати перший хеш, щоб аутентифікувати агент цифрових прав, формувати другий хеш на основі щонайменше другого випадкового числа і відправляти другий хеш агенту цифрових прав, при цьому агент цифрових прав верифікує другий хеш, щоб аутентифікувати пристрій захищеного знімного носія.
Independent claims24
164 paragraphs in 10 sections, as filed
'HOW'
UKRAINE
(19) and A (11) 95313 (13) C2
(51) IPC
H04b 9/32 (2006.01)
MINISTRY OF EDUCATION SCIENCE OF UKRAINE
STATE DEPARTMENT OF INTELLECTUAL PROPERTY
DESCRIPTION
TO THE INVENTORY PATENT
(54) METHOD AND APPARATUS FOR MUTUAL AUTHENTICATION
1
(21) a200904513
(22) Oct 05, 2007
(24) July 25, 2011
(86) PCT / ЕИЗ2007 / 080525, 05.10.2007
(31) 60 / 850,882
(32) 10.10.2006
(33) from
(31) 11 / 866,946
(32) October 03, 2007
(33) from
(46) July 25, 2011, no. 14, 2011
(72) ПЕРЕС АРАМ, из, ДОНДТИ ЛАКШМИНАТХРЕДДИ, из
(73) kveklkomom incorporated, from
(56) ΜΘΠΘΖΘ5 А ф Уап ОогесПОЇ Р С; Yapeeyope with A.
HAPPY ARROW
CURRENT DRIVER. [CDS REFLECTORS FROM THE OWN SUMMARY OF THE APPROVAL OF THE ANTICIPATHES, 19970101 SRS Rhee, Vos Raisop, Pb, iZ - ^ BN978-0-8493-8523-0; ^ BN 0-8493-8523-7;
Rad (5): 403 - 405,506-515,570; HR 002165287
iZ 6769060 В1; July 27, 2004
IZ 7024690 В1; 04.04.2006
MO 2005/091551 A; 29.09.2005
(57) 1. A method of mutual authentication between the first object and the second object, which contains the stages in which:
with the help of the first object, initiate mutual authentication by sending a message to the second object;
with the help of the second object, verifies the first public key, associated with the first object, form the first random number, encrypting the first random number with the first public key and send encrypted the first random number in the message first ob ' the object;
with the help of the first object, verifies the second public key associated with the second object, decrypting the encrypted first case-number with the help of the first closed key that corresponds to the first open key, forming the second random number, form the first hash on the basis of at least the first case-number, encrypts the second random number and the first hash with the help of the second open key and send encrypted second random
2
the number and first hash in the message of the second object;
with the help of the second object, decrypt the second random number and the first hash with the help of a second private key that tells the second public key, verifies the first hash to authenticate the first object, form a second hash based on at least another random number and send second ishe first object; and
using the first object, verifies a second hash to authenticate the second object.
2. The method of mutual authentication according to claim 1, wherein the first object and the second object extract a session key encryption key and a key with an authentication message code (MAC) with the first exponent number and the second random number on the key functions of obtaining keys for use in connection with the first object and another object.
3. The method of mutual authentication according to claim 1, wherein the message initiating the mutual authentication includes a hash of at least one trusted root key and a corresponding chain of certificate certificates for the first object.
4. The method of mutual authentication according to claim 1, wherein the message from the second object to the first object having the encrypted first random number further includes a chain of certificates for the second object.
5. The method of mutual authentication according to claim 1, wherein the first object is an agent of digital rights, and the second object is a device of a protected removable media.
6. The method of mutual authentication according to claim 1, wherein the first object is a mobile station.
7. The method of mutual authentication according to claim 1, wherein the second object has a limited computational power.
8. The method of mutual authentication according to claim 1, wherein the first hash is additionally based on at least a second random number such that the first hash is formed on the basis of at least the first Y-pack number concatenated with the second random number.
9. The method of mutual authentication under paragraph 1, in which the second hash additionally based on at least the first random number.
iA (11) 95313 (13) C2
σ>
3
95313
4
10. The method of mutual authentication according to claim 1, wherein the second hash is additionally based on at least the first hash so that the second hash is formed on the basis of at least the second random number concatenated with the first hash.
11. Mutual authentication device, which contains: means of initiating mutual authentication, a means of verifying the first public key, formulating the first random number and encrypting the first random number using the first key;
a means of verifying the second public key, rozciphering the encrypted first random number with the help of the first private key that corresponds to the first public key, the formation of the second random number, the formation of the first hash based on at least the first-case number and encryption of the second random number and the first hash with the help of a second key;
a means of decrypting the encrypted second Y-pack number and the first hash with the second closed key, which corresponds to the second open key, the verification of the first hash for authentication and the formation of a second hash on the basis of at least the second random number; and a means of verifying the second hash for authentication.
12. The device for mutual authentication according to claim 11, further comprising: a means for extracting a session key encryption key and a key with an authentication code message (MAC) using a random number and a second random number on the basis of the key extraction function for use in communication between the first object and another object.
13. The device for mutual authentication according to claim 11, wherein the first hash additionally is based on at least the second random number so that the first hash is formed on the basis of at least the first random number, concatenated with a random random number.
14. A device for mutual authentication according to claim 11, wherein the second hash additionally is based on at least one first random number.
15. The device for mutual authentication according to claim 11, wherein the second hash is further based on the first hash so that the second hash is formed on the basis of the second random number concatenated with the first hash.
16. A station that has mutual authentication with the device of a protected removable media containing: a digital rights agent, while:
the digital rights agent initiates a mutual authentication by sending a message to the device of the secured removable media, while the device of the secured removable media verifies the first public key associated with the agent of the cipher rights, generates the first random number, encrypts the first random number with the first public key and Sends the first random number to the encrypted file in the notification of the digital rights agent;
the digital rights agent verifies the second open key associated with the protected removable media device, decrypting the encrypted first
a random number with the help of the first closed switch that corresponds to the first open key, forms a second random number, forms the first hex on the basis of at least the first random number, encrypts the second random number, and the first hex with the second public key, and repmits the encrypted second random number and the first hash in a message in the device of the protected removable media, while the device of the secured removable medium decrypts the second encrypted random number and the first hash with the help of a second private key that corresponds the second hidden key, verifies the first hash to authenticate the digital rights agent, forms a secondhis based on at least the second random number and sends a second hash to the digital agent; and
The digital rights agent verifies a second hash to authenticate a protected removable device device.
17. The station that has mutual authentication according to claim 16, wherein the digital rights agent and the secure removable media device extract the session key encryption and the message authentication code key (MAC) using the first random number and the second random number based on the function -getting keys for use in connection with the digital rights agent and the case of protected removable media.
18. A station that has mutual authentication in accordance with claim 16, wherein the message sent by the digital rights agent to initiate mutual authentication includes a hash of at least one trusted root key and the corresponding chain of certificates for the digital rights agent.
19. A station that has mutual authentication in accordance with claim 18, wherein the certificate chain for the digital rights agent includes an open key associated with the digital rights agent.
20. The station that has mutual authentication according to claim 16, wherein the message sent by the device of the secured removable media carrier of the digital rights holder having the encrypted first Y-pack number further includes a certificate branch for the protected device removable media.
21. A station that has mutual authentication, in accordance with paragraph 20, in which chain of certificates for a protected removable media device includes an open key associated with a protected removable media device.
22. A station that has mutual authentication, according to claim 16, wherein the station is a mobile station.
23. The station that has mutual authentication according to claim 16, wherein the first hash is additionally based on the least on the second random number so that the digital rights agent forms the first hash on the basis of at least the first random number concatenated with the second random number.
24. A machine-readable medium comprising:
a code to force the computer to force the agent of the digital rights of the station to initiate a mutual authentication by sending a message to the protected removable media device, when this device is protected by a removable media verifi-
5
95313
6
kues the first public key associated with the agent of digital rights, forms the first random number, encrypts the first random number with the help of the first public key and sends the first random number in the message to the agent of digital rights;
code to force the computer to force the agent digital rights station to verify the second decryption key associated with the device protected by removable media, decrypt encrypted the first random number using the first secret key that corresponds to the first open the key, to form the second random number, to form the first hash on the basis at least the first random number, to encrypt the second random number and the first hash with the help of another public key and send encrypted the second random number and the first hash in the message. in a protected removable media device, when this protected removable media device decompresses the encrypted second random number and a second hash with a second private key corresponding to the second public key, verifies the first hash to authenticate the digital rights agent , forms the second hash on the basis of a little less than the second random number and sends the second hash of the agent of digital rights; and
code to force the computer to force the agent to digitally verify the second hash to authenticate the device protected removable media.
25. A machine-readable medium comprising: a code to force a computer to force a protected removable media device to verify a prior public key associated with the agent of the cryptographic rights, to form the first random number, to encrypt the first random number with the first public key, and to send encrypted-vaine first random number in the message of the agent of digital rights, while the digital agent verifies the second public key associated with the device protected removable media, decrypts the encrypted first random number according to first-Help the private key that vidpovidayepershomu public key form the second attack, the number-term forms the first hash-based thaton least the first random number, encrypts the second random number and the first hash with the help of a second public key and sends an encrypted second random number and the first hash in the message in the device protected removable media; the code to force the computer to force the protections of the protected removable media to decrypt the encrypted second random number and the first hash with the help of a second private key that tells the second public key, verifies the first hash to authenticate the digital agent, to form a second hash based on at least the second random time als and send the second hash digital rights agent, and the rights ahenttsyfrovyh verifies the second hash to auten tyfikuvaty-protected removable storage device.
This patent application claims priority in the forward application No. 60 / 850,882, entitled "MENTIONAL LETTERS OF LITHUANIAN ORGANIZATIONS", filed October 10, 2006. The previous application is submitted to the successor of the application and the data is explicitly included in this document by reference.
The present invention generally relates to a wireless communication, and more particularly to a mutual authentication.
A mobile subscriber may need to access content protected by a system that would require authentication with the help of another object or agent. The popular proto-scope of authentication is the protocol for the exchange of keys on the Internet (IE), described in the CSG 4306. However, the protocol IEC assumes that objects in the process of authentication have sufficient computing power or processing power, so that the speed of authentication creates problems.
Thus, in the art, there is a need for effective mutual authentication with a device with limited processing power.
The aspect of the present invention may be in the spirit of mutual authentication between the first object and the second object. In the method, the first entity initiates mutual authentication by directing the message to the second object. The second object verifies the first public key, associ-
with the first object, forms the first random-ve number, encrypts the first random number by the help of the first public key and sendscipher the first random number in the message of the first object. The first object verifies the second public key, associated with the second object, decrypts the encrypted first Y-drop number using the first closed switch that corresponds to the first open key, forms a second random number, forms the first hex on the basis of at least the first random number, encrypts the second random number and the first by using the second public key and repelling the encrypted second random number and the first hash in the message of the second object. The second object decrypts the encrypted second random number and the first hash with the help of a second closed key that corresponds to the second open key, verifies the first hash to authenticate the first object, forms a second hash on the basis of the least of the second random number and sends the second hash to the first object. The first object verifies the second hash to authenticate the second object.
In more detailed aspects of the invention, the first object and the second object extract the session key encryption and the message authentication code key (MAC) using the first random number and the second random number based on the function
7
95313
8
The extraction of keys for use in connection with the first object and the second object.
Additionally, a message triggering mutual authentication may include a hash of at least one trusted root key and the corresponding chain of certificates for the first object. A chain of certificates for the first object can include an open key associated with the first object. In addition, the notification from the second object to the first object, which has encrypted the first random number, can additionally include a chain of certificates for the second object. A chain of certificates for the second object may include an open key associated with the second object.
In other more detailed aspects of the invention, the first object may be a digital rights cell and a second object may be in the form of a protected removable media. The second object may have a limited computing power. In addition, the first hash may additionally be based on the second random number so that the first hash is formed on the basis of the first random number, concatenated with the second random number. The second hash may additionally be based on the first random number or additionally based on the first hash so that the second hash can be based on the second random integer concatenated with the first hash.
Another aspect of the invention may consist of a device for mutual authentication, which includes a means for initiating mutual authentication, a means for verifying the first public key, formulating the first random number, and encrypting the first random number using the first key, the verifier of the second open key, decryption of the encrypted first random number using the firstclosed key that corresponds to the first open-key, the formation of the second random ch-sl, the formation of the first he based on the least-first random number and encryption of the second random number and the first hash with the help of the second public key, the decryption means of the encrypted second random number and the first hash with the help of a second closed key corresponding to the second public key,
Another aspect of the invention may be a mobile station that has a mutually authenticated device with a protected removable media device and includes a digital rights agent. Agent of digital rights initiates mutual authentication by sending a message to a device of a secured removable media, while the device protected by a removable media verifies the first public key associated with the agent of digital rights, forms the first random number, encrypts the first random number with the first public key and sends the encrypted first random number of the message to the agent of digital rights. Agent of digital
rights verifies the second public key, associated with a protected removable media device, decrypts the encrypted first random ch-layer using the first private key that corresponds to the first public key, forms the second random number, forms the first hash on the basis of at least the first random number, encrypts the second random number and first hash with the help of the second public key and sendsciphered second random number and the first hash message in the device protected removable carrier, with the device protected sh Immunosystem decrypts the encrypted second random number and the first hash with the help of a second closing key that corresponds to the second open key, verifies the first hash to authenticate the digital rights agent, generates a second hash on an os-new of at least the second random number and reigns the second hash of the digital rights agent. The Digital Rights Agent verifies the second hash to authenticate the secured removable media device.
Another aspect of the invention may be in a computer software product comprising a machine readable medium that contains a code for prompting the computer of the station having an agent of cryptographic rights to initiate mutual authentication by sending a message in the context of a protected removable media, -Secure protected removable media verifies the first open key, associated with the agent of digital rights, forms the first random number, encrypts the first random number using the first key and sends encrypted the first random number in the message digital rights agent, code for causing the computer-wool will make digital rights agent to verify druhyyvidkrytyy key associated with the device schenoho pro-removable media, decrypt zashyf-together for the first random number by dopomohoyupershoho private key, which corresponds to the first open key, to form the second random number, to form the first hash on the basis of at least the first random number, encrypted the second random number and the first hash with the second public key and send the encrypted second random number and the first hash in the message in a protected removable media device, while the protected removable media device decrypts the encrypted second random number and the first hash with a second closed key corresponding to the second public key, verifies the non- the second hash to authenticate the agency's digital rights, generates a second hash based on the least second random number, and sends the second digital rights holder hash, and the code for prompting the computer to force the digital agent to verify the second hash to authenticate the device protected removable media .
Another aspect of the invention may be a computer software product comprising a machine readable media that contains a code for causing the computer to force the device protected by the removable media to verify the first disconnected key associated with the digital agent, to form the first random number, the cipher -
9
95313
10
the first random number using the first public key and send encrypted the first random number in the message to the agent of the cryptographic rights; the digital rights agent verifies the second public key associated with the device of the secured removable media, decrypting the encrypted first random number for with the help of the first private key, which corresponds to the first public key, forms the second random number, forms the first hash on the basis of at least the first random number, encrypts the second random number and the first hash for the dop hoyu Dru-Gogo's public key and sends zashyfrovanidruhe random number and first hash in a message to the universe protected removable storage device, and computer koddlya encouraging '
Brief description of the drawings:
1 is an example of a wireless communication system;
2 is a block diagram of a mobile station and device protected by a removable carrier, which has mutual authentication;
FIG. 3 is a block diagram of a method for mutually authenticating between a mobile station and a protected removable media device. FIG.
The word "exemplary" is used in this document to mean "such as serves as an example, a special case or illustration." Any embodiment described in this document as "exemplary" does not necessarily have to be construed as preferred or advantageous in the spirit of other embodiments.
A remote station, also known as mobile station (M3), access terminal (AT), subscriber device or subscriber unit, may be mobile or stationary and can exchange data with one or more base stations, also known as base transmitting stations (VT3) or nodes B The remote station transmits and receives data packets via one or more base stations to the base station controller, also known as the radio control controller (PNO). Base stations and base station controllers are parts of the network, which is called less access. The access network moves the packet data between a plurality of remote stations. The network access may be further connected to additional networks outside of the access network, for example, to the corporate intranet or to the Internet,gentlemen A remote station that has established an active connection of a traffic channel with one or more base stations, is called an active remote station and is believed to be in the state of the transmission of traffic. Remote station that locates
In the process of establishing an active connection of the traffic channel with one or more base stations, it is believed to be in the states of the connection setup. A remote station can be any data device that communicates through a wireless channel. A remote station can additionally be any of several types of devices, including, but not limited to, a PC board, a board of the RIAA, an external or internal modem, or a wireless telephone. Communication line, through which the remote station sends signals to the base station, is called the ascending line of the communication, also known as the reverse link. The communication line through which the base station sends signals to the remote station is called the downlink line, also known as a straight line of communication.
With reference to FIG. 2, the wireless communication system 100 includes one or more mobile stations (M3) 102, one or more base stations (B3) 104, one or more base station controllers (B3C) 106, and a base network 108 . The base network can be connected to In-ternet 110 and public dial-up network (P3ТNN) 112 through proper transit connections. A typical wireless mobile station can include a pocket TV-background or a travel computer. The non-conductive communication system 100 may employ any number of multi-access technologies such as multiple-access code division access (COMA), time-division multiple access (TOMA), multiple-frequency access (RUMA), multiple access with spatial partitioning (3І0МА),
A number of low-cost devices with limited computing power appear on the market, such as smart cards and flash memory (in many different form factors). Such devices may require authentication. For example, there is a need for these devices to retain the rights to use in digital rights management (DRM) systems. Before exchanging rights with these devices, we must have mutual authentication of both objects involved in the exchange, in order to limit the exchange of authorized objects. These embodiments provide an effective way to perform mutual authentication, as well as provide an approved secrecy exchange that can be used in the subsequent exchange of data between the objects being promoted. Efficiency is achieved and relative to the computing power, and relative speed.
As is apparent to those skilled in the art, mutual authentication schemes can be used at any time when mutual authentication is required between the two entities. Cross-reference authentication is not limited to specific applications (such as digital rights management), systems, and devices used in this document for the purpose of describing the implementation options.
11
95313
12
One embodiment of the invention performs mutual authentication with exchange of sub-keys, using the exchange of 4 messages. It requires 2 verification of the signature with the opening key (+1 for each intermediate certificate), 2 public key encryption, 2 public key encryption, 2 hash formations and 2 hash verifications. The specific number of message exchanges, open-key verifications, public key decoders, hash formations and hash verifications can be partitioned or changed according to the required achievable security and efficiency indicators.
The efficiency of the protocol increases on the account of minimizing the number of cryptographic operations with an open key and through the use of hash functions in order to provide evidence of ownership ofclosing material that is exchanging.
An effective protocol for mutual authentication and exchange of confirmation keys is described for use with devices that have limitations on the speed of the calculations. Efficiency is achieved by minimizing the number of operations with an open key and using cryptographic hashes in order to provide proof-reading.
The protocol is illustrated with links to Figures 2 and 3 showing the method 300 (FIG. 3) for mutually authentication. The steps below correspond to the numbered arrows in FIG. 3.
In method 300, object A, for example, a YDRM Agent 202 M3 102 sends a NeIIOA message (step 302) to object B, for example, a protective removable media (3RM) device 204 that has a CLM agent 206. The RMM agent controls access to protected pathname 208 in the RMM device. (Operating system 210 from M3 can directly access the general memory of 212 ZRM devices). NeIiOA consists of hashes of trusted root keys (or root keys themselves) and corresponding certificates of certificates. After receiving this message, object B finds the root key, which it trusts, from the message and finds the chainexercise within the framework of the selected root key. It verifies the chain of certificate objects of the Av framework of the selected root key.
Object B forms a random number of RapV (stage 304).
Object B sends a message to the non-target object A (step 306). NeІІiОВ consists of a chain of certificates В within the framework of the chosen root root with the RapV, encrypted using the open key of object A from the chain of certificates selected after step 302. Upon receipt of this message, object A verifies a chain of serifs of the object B. If it is valid, it decrypts RapD with its closing switch (corresponding to the selected root key).
Note that after selecting the root switch and the chain of certificates exchange, the object A and object B have a certificate chain of each other. Therefore, these parameters may not need to be sent between object A and the object in future messages of NeIIoA and NeІІioO for
future mutual authentication. In this case, the exchange of chain of certificates at stages 302 and 306 may be optional. The Object Fortifies Rape (Stage 308).
Object A sends a Message to the Object B (step 310). The Client consists of a Rapid, concatenated with a hashtap, encapsulated with Rap (A [RapidApp]), andall is encrypted with the help of an open switch B. After receiving this message, the objectB decodes it. Using the deciphered rape, the lash verifies the hash Rap, concatenated from Rap. Note that at this stage object Object A authenticated object A and verified that object A knows Rap.
Object B sends a message to a non-target object A (step 312). The Client is composed of a hash of the encrypted part of the message CuisopyigitA. After receiving this messageobject A verifies a hash. Note that at this stage, object A authenticated object B and translated that object B knows Rap.
At this time, both objects authenticated each other and confirmed that they shared the same Rap and Rap. Rapid and RapidWe can now be used to obtain an encryption session key (KB) and a MAC key (MK) based on the key extraction function (KUEE) for use in subsequent interconnections (step 314).
Details of the messages are given below. The message NeІІоА is sent for to initiate mutual authentication using the verification protocol using the keys. NeIiOA has the parameter "eugenic" and the parameter "gooAppSiApE []". The ejection parameter may be an 8-bit value that contains the protocol vertex of this message. It is displayed as 5 mSv for the full-featured version and 3І_3В for the reduced version. The parameter [] can be an array of rootkills and certificate threads for the object A in the frame of all trusted models that are supported by A. The structure for the parameter, RooyNazyApsSegeSiyip, is the GooyNase parameter, which is the hash of the ZNA-I root-type public key model that trusts , and the Segment Session parameter, the link between the object certificates within the root root key. Certificate about '
The message "NeІІiОВ" continues the mutual authentication using the confirmation protocol using the keys with the object A. The following table describes the options. Non -Identifier options are: "ezio", "ziayiz", "sega siyip" and "epsRap". The parameter eigensop can be 8-bit value, which contains the version of the protocol of this message. It is displayed as 5 MZV for full-function version and 3 I_ZV for a reduced version. The parameter ziasis may be an 8-bit value, which contains the state of the object B, which processes the message NeIiOA. The parameters of the parameter can be 0 for successful execution - not
13
95313
14
there were errors in the previous message, and 1 for Ziagebrooke - object B did not find the root key that it collectively uses with object A. Values 2-255 can be reserved for future use. The parameter TSGiyap is the chain of object certificates In the root keys of the selected NeiIoA message. If the value of your parameter does not indicate successful execution, the TSG parameter is absent. Parameter epsRapV - it is encrypted with the help of RZA-OAPER gAP, using open object key A (from the selected chain certificates). RapV can be a 20-byte value number generated by the object B. If the state value does not show successful implementation, the parameter epsRapV is absent.
The message Keyspace continues mutually authentication using the sub-validation protocol using the keys using the object A. The message Keyspace has a parameter "Vegetable" and the parameter "epsRap". The parameter gvip can be an 8-bit value that contains the protocol version of this message. It can be displayed as 5 MZV for the full-featured version and 3 I_ZV for the reduced version. Parameter Meter can be encrypted with the help of the RZA-OAER structure, which is a parameter of the hapA and the parameter of the parachute. The parameter A can be a 20-byte random number, which is formed using the object A, and the parameeter can be a hash of ZNA-1 for a thread connected to the hapA.
The message KeuSopyigTV completes mutual authentication using the protocol of sub-verification using the keys using the object B. The KerioComputer's message has a parameter "yegviop", the status parameter and the parameter "PaviCoopyIgT". The parameter yevgioop can be 8-bit value, which contains the version of the protocol of this message. It can be displayed as 5MZV for full-featured version and 3 I_ZV for reduced version. The status parameter can be an 8-bit value, which contains the state of the object B, which writes the message. Parameter
PaviCeopsiyGT may be a hash of the CMA-1 structure of the ClientApp, which is decrypted with Object B. If the status parameter value does not indicate a successful execution, this parameter is absent.
Another aspect of the invention may be a mobile station 102 that includes a control processor 216 and an OZ 210 to induce the SMM agent 202 to implement method 300. Another aspect of the invention may be a computer program product that includes a machine readable drive (such as a storage device 218) that contains a code to force the computer to force the SM agent to perform steps 300 of the method.
Those skilled in the art will appreciate that information and signals can be represented by any of a variety of different techno logos and methods. For example, data, instructions, information, signals, bits, symbols, and symbols of the noise-binary sequence, which may be given as an example throughout the description above, may be pre-
tensions, currents, electromagnetic waves, magnetic fields or particles, optic fields or particles, or any combination of the foregoing.
Those skilled in the art will have to take into account that the various illustrative logic blocks, modules, circuits and steps of the algorithm, describing the connection with the embodiments disclosed in this document, can be implemented as electron hardware, a computer Computer software or a combination of them. To clearly illustrate this interchangeability of hardware tools and software, various illustrative components, blocks, modules, circuits and stages described above, in general, based on their functionality. Implemented this functionality as a device-no means or software, depends on the specific version of application and structural restrictions imposed on the system in this loop. Qualified professionals can implement the described functionality in various ways for each specific application,
Various illustrative logical blocks, modules, and circuits described in connection with the embodiments disclosed in this document can be implemented or executed using a processor for general purpose, a digital signal processor (UPS), a specialized integrated circuit (ISIS) , programmable gate matrix (RRCA) or other programmable logic device, discrete logic element or transistor logic, discrete hardware components, or any combination of the above, prize-winning in order to execute uvaty described in this document th function. Processor general-value can be a microprocessor, but the alternative variant of the processor can beany traditional processor, controller, myc-controller or end-machine. The processor can be implemented as a combination of calculating devices,
The steps of the method or algorithm described in connection with the embodiments disclosed in this document may be implemented directly in hardware, in a software module implemented by the processor, or in a combination thereof. The program module can be permanently ro-shifted to RAM, flash memory, ROM, memory SRAM, EERROM memory, registers, hard disk, removable disk, CD or any other form of storage medium known in the art. A typical storage medium of data is connected to the processor, and the processor can read information and record information on storage media. In an alternate-native version, storage media can be embedded in the processor. Processor and media storage of data can be permanently placed in AZIS. AZIS can be permanently placed in the
15
95313
16
Tuvac Terminal. In the alternative, the processor and storage medium can be permanently located as discrete components in the user-vacuum terminal.
In one or more exemplary embodiments, the described functions may be implemented in hardware, software, software, hardware or any of these combinations. If implemented in software as a computer software product, the functions can be stored or transmitted as some or more of the instructions or code on the machine-drive carrier. Machine-readable media include itself as computer storage media, as well as the medium of communication, which includes any transmission medium, which simplifies the migration of the computer program from one place to another. Storage carriers may be any available media that can be accessed through a computer. As an example, and not limitation, these machine-readable media may contain VAM, POM, EVER, OR-WME or other memories' an optical drive, a magnetic disk drive, or other magnetic storage device, or any other carrier that can be used to transfer or store the necessary software code in the background. the number of instructions or data structures that can be accessed using a computer. Also, any connection is properly called the machine-readable carrier. For example, if software is transferred from a web site, server, or other remote source via coaxial cable, fiber optic cable, twisted pair, digital subscriber line (ULZ) or wireless technology such as infrared, radio transmitting and microwave ovens, coaxial cable, fiber optic cable, "twisted pair", microwave oven or wireless technology such as infrared,
carriers The term "disc" as used herein includes, in this document, a compact disc (ÎÎ), a laser disk, an optical disk, a digital digital drive (ûνû), a floppy disk, and a binary CD, while disks usually reproducedata by magnetic means or reproduce the dataoptical way using lasers. Combi nations of the above should also include the number of machine-readable media.
A prior description of the disclosed embodiments is provided in order to allow any person in the art to create or use the present invention. Various modifications to these embodiments should be apparent to those skilled in the art, and the general principles of the disclosure of this document may be applied to other embodiments without departing from the spirit and scope of the invention. Thus, the present invention is not intended to be limited by the embodiments embodied in the present document, but must satisfy the widest range consistent with the principles and new features disclosed in this document.
Reference positions
100 wireless communication system
102 wireless mobile station
104 base station
106 base station controller
108 base network
110 Internet
112 telephone dial-up network of public use
202 YMM Agent
204 device for protected removable media
206 ZVM agent
208 is a protected memory
210 operating system
212 total memory
216 control processor
218 storage device
300 method for mutual authentication
17
95313
18
Computer layout A. Ryabko Subscription Circulation 23 copies.
Ministry of Education and Science of Ukraine
State Department of Intellectual Property, st. Uritskogo, 45, Kyiv, SME, 03680, Ukraine
State Enterprise "Ukrainian Institute of Industrial Property", st. Glazunova, 1, Kyiv - 42, 01601
Contents10
1 sheet
Sheet 1
33 members in 19 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 60850882 | United States of America | – | |
| 85088206 | United States of America | P | |
| 11866946 | United States of America | – | |
| 60850882 | – | – | – |
| US20060850882P | – | – | – |
Members33
| Document | Office | Kind | |
|---|---|---|---|
| AU2007307906A1 | Australia | A1 | |
| CA2663644A1 | Canada | A1 | |
| WO2008045773A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008045773A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2008155260A1 | United States of America | A1 | |
| TW200830834A | Taiwan Province of China | A | |
| NO20091813L | Norway | L | |
| KR20090067200A | Republic of Korea | A | |
| MX2009003684A | Mexico | A | |
| EP2082525A2 | European Patent Office (EPO) | A2 | |
| CN101523800A | China | A | |
| JP2010506542A | Japan | A | |
| HK1136115A1 | Hong Kong, China | A1 | |
| RU2009117677A | Russian Federation | A | |
| AU2007307906B2 | Australia | B2 | |
| RU2420896C2 | Russian Federation | C2 | |
| UA95313C2This record | Ukraine | C2 | |
| TWI368427B | Taiwan Province of China | B | |
| JP2013017197A | Japan | A | |
| CN101523800B | China | B | |
| KR101284779B1 | Republic of Korea | B1 | |
| CA2663644C | Canada | C | |
| BRPI0718048A2 | Brazil | A2 | |
| IL197590A | Israel | A | |
| US8892887B2 | United States of America | B2 | |
| US2015074403A1 | United States of America | A1 | |
| US9112860B2 | United States of America | B2 | |
| MY162283A | Malaysia | A | |
| EP2082525B1 | European Patent Office (EPO) | B1 | |
| ES2662071T3 | Spain | T3 | |
| NO342744B1 | Norway | B1 | |
| HUE036864T2 | Hungary | T2 | |
| BRPI0718048B1 | Brazil | B1 |
Numbers
- Publication
- 00095313
- Publication, DOCDB
- 95313
- Publication, EPODOC
- UA95313
- Application
- 200904513
- Application, DOCDB
- 200904513
- Application, EPODOC
- UA20090004513
Titles3
- English
- METHOD AND DEVICE FOR MUTUAL AUTHENTIFICATION
- Russian
- СПОСОБ И УСТРОЙСТВО ДЛЯ ВЗАИМНОЙ АУТЕНТИФИКАЦИИ
- Ukrainian
- СПОСІБ ТА ПРИСТРІЙ ДЛЯ ВЗАЄМНОЇ АУТЕНТИФІКАЦІЇ
Classification
- IPC, 1
- H04L9 32