US20020078345A1

System and method for authentication in a crypto-system utilizing symmetric and asymmetric crypto-keys

Claim Score by NHIP

Read claim 14, the broadest

Abstract

A system and method for authentication of a crypto-system user is provided. A user is authenticated by the use of both symmetric and asymmetric crypto-keys. A user associated with a first asymmetric crypto-key having a public portion and multiple private portions is represented by a first network station. The user transmits a first request for authentication to a second network station. The second network station is associated with a second asymmetric crypto-key having a public portion and at least one private portion. A first one of the multiple private portions of the first crypto-key is stored at the second network station. The second network station generates a shared symmetric crypto-key and encrypts the shared crypto-key with the first private portion of the first crypto-key to form a first message. The second network station signs the first message with a private portion of the second crypto-key and transmits the first message to the first network station. The second network station also encrypts the shared crypto-key with the public portion of a third crypto-key to form a second message. The second network station signs the second message and transmits it to a third network station. The third network station, associated with the third crypto-key, authenticates the second network station, further encrypts the second message with a second private portion of the first crypto-key stored at the third network station, forming a third message. The third network station transmits the third message to the first network station. The first network station authenticates the first network station, combines the first and third messages to form a fourth message, further encrypts the fourth message with another private portion of the first crypto-key, forming a fifth message. The first network station applies the public portion of the first crypto-key to the fifth message to recover the shared crypto-key. The first network station encrypts a second authentication request with the shared crypto-key to form a sixth message, and transmits the sixth message to authenticate the user.

US20020078345A1, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Projected expiry passed 3 November 2022, 3.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

21 claims: 3 independent, 18 dependent

  1. 1
    A system for authentication of network stations utilizing symmetric and asymmetric crypto-keys, each network station being associated with a different asymmetric crypto-key having a public portion and at least one private portion, comprising:a first network station associated with a first asymmetric crypto-key having multiple private portions, configured to transmit a first request for authentication;a second network station associated with a second asymmetric crypto-key, having a first private portion of the first asymmetric crypto-key stored thereat, configured to (i) generate a shared symmetric crypto-key, (ii) encrypt the shared symmetric crypto-key with the first private portion of the first asymmetric crypto-key to form a first message and sign the first message with the private portion of the second asymmetric crypto-key, (iii) transmit the signed first message to the first network station responsive to the transmitted request for authentication, (iv) encrypt the shared symmetric crypto-key with a public portion of a third asymmetric crypto-key to form a second message and sign the second message with a private portion of the second asymmetric crypto-key, and (v) transmit the second message;and a third network station associated with the third asymmetric crypto-key, a second private portion of the first asymmetric crypto-key stored thereat, configured to (i) authenticate the second network station by applying the public portion of the second asymmetric crypto-key to the second message, (ii) recover the shared symmetric crypto-key by applying a private portion of the third asymmetric crypto-key to the second message, (iii) encrypt the recovered shared symmetric crypto-key by applying the second private portion of the first asymmetric crypto-key to the recovered shared symmetric crypto-key to form a third message, and (iv) transmit the third message;wherein the first network station is further configured to (i) authenticate the second network station by applying the public portion of the second asymmetric crypto-key to the first message, (ii) combine the first message and the third message to form a fourth message, (iii) further encrypt the fourth message by applying a third private portion of the first asymmetric crypto-key to the fourth message to form a fifth message, (iv) recover the shared symmetric crypto-key by applying the public portion of the first asymmetric crypto-key to the fifth message, (v) encrypt a second authentication request with the shared symmetric crypto-key to form a sixth message, and (vi) transmit the sixth message to authenticate the first network station.
  2. 10
    A system for authentication of network stations utilizing symmetric crypto-keys and asymmetric crypto-keys, comprising:a user network station associated with an asymmetric crypto-key having multiple private portions and a public portion, configured to transmit a request for authentication to any one of a plurality of authentication network stations;and a plurality of authentication network stations, each associated with an asymmetric crypto-key including a public portion and a private portion and each having a different private portion of the multiple private portions of the asymmetric crypto-key stored thereat, each configured to (i) generate a challenge, (ii) encrypt the challenge with that portion of the multiple private portion asymmetric crypto-key stored thereat, sign the encrypted challenge with the private portion of the asymmetric crypto-key associated with that authentication network station and transmit the signed and encrypted challenge to the user network station in response to the request for authentication from the user network station, (iii) encrypt the challenge with the public portion of the asymmetric crypto-key associated with each of the other of the plurality of authentication network stations, sign each encrypted challenge with the private portion of the asymmetric crypto-key associated with that authentication network station, and transmit each signed and encrypted challenge to the respective others of the plurality of authentication network stations associated with the public portion of the asymmetric crypto-key used to encrypt each respective challenge, and (iv) receive a signed and encrypted challenge from each of the other of the plurality of authentication network stations and verify the signature of each received challenge;wherein the user network station is further configured to (i) verify each of a plurality of signed and encrypted challenges, (ii) combine the plurality of signed and encrypted challenges to form a single encrypted challenge, (iii) further encrypt the single encrypted challenge with yet another private portion of the multiple private portion asymmetric crypto-key, (iv) decrypt the further encrypted single encrypted challenge with the public portion of the multiple private portion asymmetric crypto-key, and (v) encrypt a second authentication request with the decrypted challenge and transmit the encrypted second authentication request to at least one of the plurality of authentication network stations to authenticate the user network station.
  3. 14
    Broadest claimClaim Score 21, narrow(NHIP)A method for authentication of network users in a cryptosystem in which each network user is associated with a crypto-key having a public portion and at least one private portion, comprising:receiving a first request for authentication from a first network user by a second network user;generating a shared symmetric crypto-key;encrypting the shared symmetric crypto-key with a first private portion of a first crypto-key to form a first message, the first asymmetric crypto-key associated with the first network user, the first asymmetric crypto-key having multiple private portions and a public portion;signing the first message with a private portion of a second asymmetric crypto-key associated with the second network user;transmitting the signed first message to the first network user responsive to the request for authentication;encrypting the shared symmetric crypto-key with a public portion of a third asymmetric crypto-key associated with a third network user to form a second message;signing the second message with the private portion of the second asymmetric crypto-key;transmitting the signed second message to the third network user;authenticating the second network user by applying the public portion of the second asymmetric crypto-key to the signed second message;recovering the shared symmetric crypto-key by applying a private portion of the third asymmetric crypto-key to the second message;encrypting the recovered shared symmetric crypto-key by applying a second private portion of the first asymmetric crypto-key to the recovered shared symmetric crypto-key to form a third message;transmitting the third message to the first network station;authenticating the first network user by applying the public portion of the first asymmetric crypto-key to the signed first message;combining the first message and the third message to form a fourth message;further encrypting the fourth message by applying a third private portion of the first asymmetric crypto-key to the fourth message to form a fifth message;recovering the shared symmetric crypto-key by applying the public portion of the first asymmetric crypto-key to the fifth message;encrypting a second authentication request with the shared symmetric crypto-key to form a sixth message;and transmitting the sixth message to at least one of the second user station and the third user station.