BRPI0519861A2 - métodos para autenticar um cliente, e para operar servidor de autenticação dentro de um sistema de comunicações, servidor de autenticação, método para operar um cliente acoplado a uma rede de comunicação, terminal de cliente, e, método para autenticar equipamento de usuário - Google Patents

métodos para autenticar um cliente, e para operar servidor de autenticação dentro de um sistema de comunicações, servidor de autenticação, método para operar um cliente acoplado a uma rede de comunicação, terminal de cliente, e, método para autenticar equipamento de usuário

Info

Publication number
BRPI0519861A2
BRPI0519861A2 BRPI0519861-5A BRPI0519861A BRPI0519861A2 BR PI0519861 A2 BRPI0519861 A2 BR PI0519861A2 BR PI0519861 A BRPI0519861 A BR PI0519861A BR PI0519861 A2 BRPI0519861 A2 BR PI0519861A2
Authority
BR
Brazil
Prior art keywords
client
operating
authentication server
authenticating
server
Prior art date
Application number
BRPI0519861-5A
Other languages
English (en)
Inventor
Vesa Matti Torvinen
Vesa Petteri Lehtovirta
Monica Wifvesson
Original Assignee
Ericsson Telefon Ab L M
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ericsson Telefon Ab L M filed Critical Ericsson Telefon Ab L M
Publication of BRPI0519861A2 publication Critical patent/BRPI0519861A2/pt

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F15/00Digital computers in general; Data processing equipment in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • H04L9/3273Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response for mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Computer And Data Communications (AREA)

Abstract

MéTODOS PARA AUTENTICAR UM CLIENTE, E PARA OPERAR SERVIDOR DE AUTENTICAçãO DENTRO DE UM SISTEMA DE COMUNICAçõES, SERVIDOR DE AUTENTICAçãO, MéTODO PARA OPERAR UM CLIENTE ACOPLADO A UMA REDE DE COMUNICAçãO, TERMINAL DE CLIENTE, E, MéTODO PARA AUTENTICAR EQUIPAMENTO DE USUáRIO. Um método para autenticar um cliente para dois ou mais servidores acoplados juntos através de um a rede de comunicações, onde o cliente e um primeiro servidor possui um segredo compartilhado. O método compreende autenticar o cliente para um primeiro servidor usando mencionado segredo compartilhado, sinalização associada com este processo de autenticação sendo enviado entre o cliente e mencionado primeiro servidor através de um segundo servidor, gerando uma chave de sessão no cliente e no primeiro servidor, e fornecendo a chave de sessão para mencionado segundo servidor, e usando a chave de sessão para autenticar o cliente para o segundo servidor
BRPI0519861-5A 2005-01-28 2005-01-28 métodos para autenticar um cliente, e para operar servidor de autenticação dentro de um sistema de comunicações, servidor de autenticação, método para operar um cliente acoplado a uma rede de comunicação, terminal de cliente, e, método para autenticar equipamento de usuário BRPI0519861A2 (pt)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/EP2005/050372 WO2006079419A1 (en) 2005-01-28 2005-01-28 User authentication and authorisation in a communications system

Publications (1)

Publication Number Publication Date
BRPI0519861A2 true BRPI0519861A2 (pt) 2009-03-24

Family

ID=34960251

Family Applications (1)

Application Number Title Priority Date Filing Date
BRPI0519861-5A BRPI0519861A2 (pt) 2005-01-28 2005-01-28 métodos para autenticar um cliente, e para operar servidor de autenticação dentro de um sistema de comunicações, servidor de autenticação, método para operar um cliente acoplado a uma rede de comunicação, terminal de cliente, e, método para autenticar equipamento de usuário

Country Status (9)

Country Link
US (1) US8555345B2 (pt)
EP (1) EP1842319B1 (pt)
JP (1) JP4643657B2 (pt)
KR (1) KR100995423B1 (pt)
CN (1) CN101112038B (pt)
BR (1) BRPI0519861A2 (pt)
CA (1) CA2594468A1 (pt)
IL (1) IL184606A0 (pt)
WO (1) WO2006079419A1 (pt)

Families Citing this family (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7636940B2 (en) * 2005-04-12 2009-12-22 Seiko Epson Corporation Private key protection for secure servers
DE102005026982A1 (de) * 2005-06-10 2006-12-14 Siemens Ag Verfahren zur Vereinbarung eines Sicherheitsschlüssels zwischen mindestens einem ersten und einem zweiten Kommunikationsteilnehmer zur Sicherung einer Kommunikationsverbindung
JP5123209B2 (ja) * 2006-01-24 2013-01-23 ▲ホア▼▲ウェイ▼技術有限公司 モバイルネットワークに基づくエンドツーエンド通信での認証の方法、システム、および認証センタ
DE102006038037A1 (de) * 2006-08-14 2008-02-21 Siemens Ag Verfahren und System zum Bereitstellen eines zugangsspezifischen Schlüssels
US8145905B2 (en) * 2007-05-07 2012-03-27 Qualcomm Incorporated Method and apparatus for efficient support for multiple authentications
EP2056565A1 (fr) * 2007-10-29 2009-05-06 Axalto Procédé d'authentification d'un utilisateur accédant à un serveur distant à partir d'un ordinateur
US8347374B2 (en) * 2007-11-15 2013-01-01 Red Hat, Inc. Adding client authentication to networked communications
US8918079B2 (en) * 2007-11-19 2014-12-23 Avaya Inc. Determining authentication challenge timing and type
US8978117B2 (en) * 2007-11-19 2015-03-10 Avaya Inc. Authentication frequency and challenge type based on environmental and physiological properties
US9027119B2 (en) * 2007-11-19 2015-05-05 Avaya Inc. Authentication frequency and challenge type based on application usage
KR101731200B1 (ko) 2008-01-18 2017-05-11 인터디지탈 패튼 홀딩스, 인크 M2m 통신을 인에이블하는 방법 및 장치
CN101478755B (zh) * 2009-01-21 2011-05-11 中兴通讯股份有限公司 一种网络安全的http协商的方法及其相关装置
WO2010102259A2 (en) 2009-03-06 2010-09-10 Interdigital Patent Holdings, Inc. Platform validation and management of wireless devices
US8484708B2 (en) * 2009-12-11 2013-07-09 Canon Kabushiki Kaisha Delegating authentication using a challenge/response protocol
US8621212B2 (en) * 2009-12-22 2013-12-31 Infineon Technologies Ag Systems and methods for cryptographically enhanced automatic blacklist management and enforcement
CN102111759A (zh) * 2009-12-28 2011-06-29 中国移动通信集团公司 一种认证方法、系统和装置
KR20140109478A (ko) * 2010-12-30 2014-09-15 인터디지탈 패튼 홀딩스, 인크 통신 핸드오프 시나리오를 위한 인증 및 보안 채널 설정
US8630411B2 (en) 2011-02-17 2014-01-14 Infineon Technologies Ag Systems and methods for device and data authentication
CN104854835B (zh) * 2013-01-17 2018-07-06 英特尔Ip公司 用于dash感知网络应用功能(d-naf)的装置和方法
WO2015004744A1 (ja) * 2013-07-10 2015-01-15 株式会社野村総合研究所 認証装置、認証方法、およびプログラム
CN104426656B (zh) * 2013-08-19 2019-04-05 中兴通讯股份有限公司 数据收发方法及系统、消息的处理方法及装置
US11349675B2 (en) * 2013-10-18 2022-05-31 Alcatel-Lucent Usa Inc. Tamper-resistant and scalable mutual authentication for machine-to-machine devices
JPWO2015064475A1 (ja) * 2013-10-29 2017-03-09 京セラ株式会社 通信制御方法、認証サーバ及びユーザ端末
SE539271C2 (en) 2014-10-09 2017-06-07 Kelisec Ab Mutual authentication
US9967260B1 (en) * 2015-01-26 2018-05-08 Microstrategy Incorporated Enhanced authentication security
EP3151503B1 (de) * 2015-09-29 2019-12-11 Siemens Aktiengesellschaft Verfahren und system zur authentifizierung einer umgebenden web-anwendung durch eine einzubettende web-anwendung
AU2016340025B2 (en) * 2015-10-16 2021-12-09 Kasada Pty Ltd Dynamic Cryptographic Polymorphism (DCP) system and method
EP3427503B1 (en) 2016-03-09 2021-12-15 Telefonaktiebolaget LM Ericsson (publ) Systems and methods for using gba for services used by multiple functions on the same device
CN110198540B (zh) * 2019-05-09 2022-05-24 新华三技术有限公司 Portal认证方法及装置

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP0673178B1 (en) * 1994-03-17 2005-02-16 Kokusai Denshin Denwa Co., Ltd Authentication method for mobile communications
US5537474A (en) * 1994-07-29 1996-07-16 Motorola, Inc. Method and apparatus for authentication in a communication system
JP2001243196A (ja) * 2000-03-01 2001-09-07 Fujitsu Ltd 携帯電話とicカードを利用した個人認証システム
FI20000760A0 (fi) * 2000-03-31 2000-03-31 Nokia Corp Autentikointi pakettidataverkossa
US7254237B1 (en) * 2001-01-12 2007-08-07 Slt Logic, Llc System and method for establishing a secure connection
JP4213664B2 (ja) 2002-06-12 2009-01-21 テレフオンアクチーボラゲット エル エム エリクソン(パブル) サービス合意の否認防止(non−repudiation)
GB0314971D0 (en) * 2003-06-27 2003-07-30 Ericsson Telefon Ab L M Method for distributing passwords
US7496755B2 (en) * 2003-07-01 2009-02-24 International Business Machines Corporation Method and system for a single-sign-on operation providing grid access and network access
CN100592678C (zh) * 2004-02-11 2010-02-24 艾利森电话股份有限公司 用于网络元件的密钥管理
US7966646B2 (en) * 2006-07-31 2011-06-21 Aruba Networks, Inc. Stateless cryptographic protocol-based hardware acceleration

Also Published As

Publication number Publication date
JP4643657B2 (ja) 2011-03-02
IL184606A0 (en) 2007-12-03
JP2008529368A (ja) 2008-07-31
US20090013381A1 (en) 2009-01-08
WO2006079419A1 (en) 2006-08-03
KR20070102722A (ko) 2007-10-19
US8555345B2 (en) 2013-10-08
KR100995423B1 (ko) 2010-11-18
CA2594468A1 (en) 2006-08-03
EP1842319B1 (en) 2017-12-27
EP1842319A1 (en) 2007-10-10
CN101112038B (zh) 2013-04-24
CN101112038A (zh) 2008-01-23

Similar Documents

Publication Publication Date Title
BRPI0519861A2 (pt) métodos para autenticar um cliente, e para operar servidor de autenticação dentro de um sistema de comunicações, servidor de autenticação, método para operar um cliente acoplado a uma rede de comunicação, terminal de cliente, e, método para autenticar equipamento de usuário
CN105337977B (zh) 一种动态双向认证的安全移动通讯系统及其实现方法
ATE527797T1 (de) Verfahren und einrichtungen zur benutzerauthentifikation
DE602005001613D1 (de) Einrichten eines sicheren kontexts zur übermittlung von nachrichten zwischen computersystemen
CN105306211B (zh) 一种客户端软件的身份认证方法
DK2011301T3 (da) Indretning af og fremgangsmåde til sikker datatransmission
BR0203323A (pt) Aperfeiçoamento introduzido em sistema de terminal de comunicação
WO2011017099A3 (en) Secure communication using asymmetric cryptography and light-weight certificates
NO20080532L (no) Distribuert enkel logg-pa-tjeneste
TW200640220A (en) System and method for providing a multi-credential authentication protocol
TW200802025A (en) Single one-time password token with single pin for access to multiple providers
WO2004046849A3 (en) Cryptographic methods and apparatus for secure authentication
WO2009112693A3 (fr) Procede d'authentification et de signature d'un utilisateur aupres d'un service applicatif, utilisant un telephone mobile comme second facteur en complement et independamment d'un premier facteur
FI20001837A0 (fi) Autentikointi
SG143152A1 (en) System and method for secure record protocol using shared knowledge of mobile user credentials
SG143127A1 (en) Client credential based secure session authentication method and apparatus
WO2009065154A3 (en) Method of and apparatus for protecting private data entry within secure web sessions
CN104901935A (zh) 一种基于cpk的双向认证及数据交互安全保护方法
ATE531184T1 (de) Iptv-sicherheit in einem kommunikationsnetz
CN104754571A (zh) 用于多媒体数据传输的用户认证实现方法、装置及其系统
PL2150915T3 (pl) Protokół bezpiecznego logowania
CN107615704A (zh) 一种网络防钓鱼的装置、方法和系统
JP2014060742A5 (ja) 認証および鍵合意(AKA)機構に基づくKerberos対応アプリケーションへの認証されたユーザアクセスのための方法および装置
CN108964895B (zh) 基于群组密钥池和改进Kerberos的User-to-User身份认证系统和方法
CN103179564B (zh) 基于移动终端认证的网络应用登录方法

Legal Events

Date Code Title Description
B08F Application dismissed because of non-payment of annual fees [chapter 8.6 patent gazette]

Free format text: REFERENTE A 10A ANUIDADE.

B08K Patent lapsed as no evidence of payment of the annual fee has been furnished to inpi [chapter 8.11 patent gazette]

Free format text: REFERENTE AO DESPACHO 8.6 PUBLICADO NA RPI 2291 DE 02/12/2014.