JPH07140897A - オフライン端末による携帯用オブジェクトの認証方法、携帯物品、及び対応する端末 - Google Patents

オフライン端末による携帯用オブジェクトの認証方法、携帯物品、及び対応する端末

Info

Publication number
JPH07140897A
JPH07140897A JP6150484A JP15048494A JPH07140897A JP H07140897 A JPH07140897 A JP H07140897A JP 6150484 A JP6150484 A JP 6150484A JP 15048494 A JP15048494 A JP 15048494A JP H07140897 A JPH07140897 A JP H07140897A
Authority
JP
Japan
Prior art keywords
value
terminal
portable object
authentication
primary
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP6150484A
Other languages
English (en)
Other versions
JP2777060B2 (ja
Inventor
Jacques Patarin
ジヤツク・パタラン
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Bull CP8 SA
Original Assignee
Bull CP8 SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Bull CP8 SA filed Critical Bull CP8 SA
Publication of JPH07140897A publication Critical patent/JPH07140897A/ja
Application granted granted Critical
Publication of JP2777060B2 publication Critical patent/JP2777060B2/ja
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
    • G07F7/1016Devices or methods for securing the PIN and other transaction-data, e.g. by encryption
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/409Device specific authentication in transaction processing
    • G06Q20/4097Device specific authentication in transaction processing using mutual authentication between devices and transaction partners
    • G06Q20/40975Device specific authentication in transaction processing using mutual authentication between devices and transaction partners using encryption therefor
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
    • G07F7/1008Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3234Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Theoretical Computer Science (AREA)
  • General Business, Economics & Management (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Finance (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Storage Device Security (AREA)
  • Input From Keyboards Or The Like (AREA)
  • Inspection Of Paper Currency And Valuable Securities (AREA)
  • Telephone Function (AREA)
  • Communication Control (AREA)
  • Crystals, And After-Treatments Of Crystals (AREA)

Abstract

(57)【要約】 【目的】 暗号を含まず、かつ携帯用オブジェクトの処
理回路によってモジュール乗算を行わしめる必要なくオ
フライン端末によって携帯用オブジェクトを確証する方
法を提供する。 【構成】 本発明は、オフライン端末(1)によって伝
送される一次値(Qi)の関数である二次値(Rx)を
供給するのに適した処理回路(4)を含むオフライン端
末(1)による携帯用オブジェクト(2)の認証方法に
関する。本発明によれば、端末の中に一連の一次値(Q
i)と一連の制御値(Ui)を集める認証テーブル
(5)を配置し、各制御値は本物の携帯用オブジェクト
の処理回路によって計算された二次値(Rx)から片方
向関数によって変換されたものであり、携帯用オブジェ
クトを端末に接続すると、前記のテーブルの一次値(Q
i)の1つを携帯用オブジェクトに伝送し、片方向関数
を携帯用オブジェクトから受けとった二次値(Rx)に
適用し、そして得られた結果をテーブルの該当制御値
(Ui)と比較する。

Description

【発明の詳細な説明】
【0001】
【産業上の利用分野】本発明は、オフライン端末による
携帯用オブジェクトの認証方法、並びに携帯物品さらに
同方法の実施を可能にする端末に関する。
【0002】
【従来の技術】中央機構に接続されることなく携帯用オ
ブジェクトを認証できる端末は、オフライン端末によっ
て理解される。
【0003】情報技術的方法による財物またはサービス
の配達が常に増加発展していることは周知である。ネッ
トワークによって供給される財物またはサービスへのア
クセスは、携帯用オブジェクト、一般には認可された機
関から交付された記憶カードが接続される端末によって
許可される。財物またはサービスにアクセスできるよう
にする前に、各端末は認可された機関によって交付され
ていない携帯用オブジェクトを排除するために、その端
末に接続される携帯用オブジェクトを承認することが必
要である。
【0004】1つの周知の認証方法は、オンラインで認
証を行うように中央認証機関に各端末を接続することか
ら成り、したがってこの中央認証機関は、認可された機
関によって交付されたものではないオブジェクトを認証
させようとする不正行為者に対してすべてのアクセスを
妨げるように保護されている。このような手法は、端末
と中央認証機関との間で常に機能しなければならない通
信ネットワークが莫大となるために、いつも極めてコス
ト高となる。
【0005】認証のコストを最小化するために、端末を
オフラインにすることが多く、こうして各端末で認証処
理を可能にする方法を実施する。
【0006】
【課題を解決しようとする課題】オフライン端末による
認証方法は現在2通りが知られている。第1の方法によ
れば、端末は暗号を含み、この暗号を実施するアルゴリ
ズムを活用する。しかし、端末は不正行為に対して完全
な方法で保護することが困難な場所で実施されるこを目
的とし、不正行為者による暗号の発見は、同じ暗号を有
する別の端末によって認証される携帯用オブジェクトを
作成する可能性を不正行為者に与えることになる。した
がって、暗号を効果的に保護するために、コストのかか
る手段を実施することが必要になる。
【0007】第2の周知の方法によれば、オフライン端
末はアクセス可能なコードを含むが、従って携帯用オブ
ジェクトの中にモジュール乗算を使用する暗号化アルゴ
リズムを搭載する必要があり、このことは一般にコスト
が高すぎる処理回路を携帯用オブジェクトに配置するこ
とを意味する。
【0008】本発明の目的は、暗号を含まず、かつ携帯
用オブジェクトの処理回路によってモジュール乗算を行
わしめる必要なくオフライン端末によって実施すること
のできる方法を提供することである。
【0009】
【課題を解決するための手段】この目的実現の見地か
ら、本発明によれば、オフライン端末によって伝送され
る一次値の関数である二次値を供給するのに適した処理
回路を含む携帯用オブジェクトを前記のオフライン端末
によって認証する方法であって、前記の端末の中に一連
の一次値と一連の制御値を集める認証テーブルを配置
し、各制御値は、本物の携帯用オブジェクトの処理回路
によって計算された二次値から片方向関数によって変換
されたものであり、携帯用オブジェクトを端末に接続す
ると前記のテーブルの一次値の1つを携帯用オブジェク
トに伝送し、片方向関数を携帯用オブジェクトから受け
とった二次値に適用し、そして得られた結果をテーブル
の該当制御値と比較すること、を特徴とする前記の認証
方法を提唱する。
【0010】
【作用】こうして、このテーブルにアクセスしようとす
る不正行為者にとっては、片方向関数による二次値の変
換値がテーブルの制御値と同じになるように、携帯用オ
ブジェクトによって供給されるべき二次値を制御値から
決定することは不可能となる。
【0011】本発明はまた、前記の方法を実施するのに
適した携帯用オブジェクト及び端末にも関する。
【0012】本発明による携帯用オブジェクトは、外部
リーディング・アクセス不能で認証暗号(K)を含むメ
モリと処理回路を含み、またこの携帯用オブジェクト
は、暗号(K)とオブジェクトが導入される端末によっ
てオブジェクトに伝送される一次値(Qi)との関数で
ある二次値(Ri)を供給するために対称ディジタル化
アルゴリズムを使用することを特徴とする。
【0013】本発明による端末に関しては、これは一連
の一次値(Qi)と一連の制御値(Ui)、端末に接続
された携帯用オブジェクトを認証する場合に受けとられ
た二次値(Ri)に適用するのに適した装置、片方向関
数(f)、及び得られた結果とテーブルの該当制御値と
の比較器を含む。
【0014】本発明の他の特性と利点は、本発明による
方法の各種バージョンを下記の添付図を参照して説明し
た記述によって明らかにされよう。
【0015】
【実施例】図1では、本発明による方法の目途は、全般
的に1で示すオフライン端末による全般的に2で示す携
帯用オブジェクトの認証を可能にすることであり、この
携帯用オブジェクトは外部リーディング・アクセス不能
メモリ3を含み、さらに認証暗号Kと処理回路4を含
み、この処理回路は、暗号Kの関数である二次値Riと
端末によって伝送される一次値Qiを供給するために、
その分野では周知方法で対称ディジタル化アルゴリズム
を、そしてさらに一般的にはスクランブル化アルゴリズ
ムを含む。本発明の第1変形実施例では、暗号Kは端末
に接続できるすべての携帯用オブジェクトについて同一
である。
【0016】一連の説明の中では、一次値Qiを語「質
問」によって指定し、二次値Riは語「返答」によって
指定することにする。
【0017】限定されない例として、対称ディジタル化
アルゴリズムは例えば質問Qiに対する返答が式Ri=
DESK(Qi)で与えられるように、DATA ENCRYPTIO
N STANDARD(データ暗号化規格)すなわちDESの略記
で周知のアルゴリズムにすることができる。
【0018】さらに、端末1の中に一連の質問Q1、Q
2、・・・Qi・・・、Qn及び制御値U1、U2、・
・・Ui・・・、Unを含むテーブル5を置くが、制御
値U1、U2、・・・Ui・・・、Unは、本物の携帯
用オブジェクトの処理回路によって計算された返答R
1、R2、・・・Ri・・・、Rnの片方向関数による
変換数値である。従ってUi=f(Ri)となる。片方
向関数fは例えば2乗モジュロmであり、ここでmは秘
密保持された2つの大きな素数の積である。質問Qiに
ついては制御値は次のようになる。
【0019】Ui=(Ri)2モジュロm これについて、片方向関数は特別の情報なしに一方向に
計算されることができるが、逆の方法に計算されること
はできない関数であることが想起される。上記の例では
実際には、Riがわかっているので(Ri)2モジュロ
を計算することは可能であるが、Uiのみを知ってRi
を決定することは不可能である。
【0020】本発明による方法では、制御値は、本物の
携帯用オブジェクトによって与えられたいろいろな返答
への片方向関数を、テーブルに含まれるために準備され
ているいろいろな質問に次々に適用して、認可された機
関によって計算され、それから、一組の質問と制御値は
端末のテーブルに装荷される。各端末は、それに固有の
質問Q1、・・・、Qnを持つことができる。
【0021】さらに、端末1は処理回路6を有し、この
処理回路は、認証されるべき携帯用オブジェクトが端末
に接続されて1つの質問Qiがそれに伝達されると、そ
の携帯用オブジェクトによって与えられる返答Rxに同
じ片方向関数を適用する。端末1はまた比較器7を含
み、この比較器は、テーブルの質問Qiに対応する制御
値Uiを、携帯用オブジェクトに伝達される質問Qiに
応答して携帯用オブジェクトによって与えられる返答R
xの片方向関数による変換値と比較する。
【0022】接続された携帯用オブジェクトが本物であ
る場合には、返答RxはRiと同じであり、従ってその
片方向関数による変換値はUiと同じである。そして端
末は問題の携帯用オブジェクトと連絡を保って所定の動
作に進む。これとは反対に携帯用オブジェクトが本物で
ない場合には、返答RxはRiと同じではなく、その結
果、片方向関数による変換値は制御値Uiとは異なり、
この携帯用オブジェクトは排除される。これについて、
テーブル5へのアクセスは公開にすることができ、端末
の中に返答R1、R2、・・・Ri・・・、Rnを含む
テーブルを含めることは幻想を抱かせるものである、と
留意されたい。それは、暗号Kも対称処理回路も含まな
い携帯用オブジェクトであるが、全く単純には端末によ
って問題Qiを伝送するときに返答Riを端末に伝送す
るようにテーブル5と同じテーブルを作製することは、
不正行為者にとっては容易であるからである。また、返
答Riの決定は関数Ui=f(Ri)を逆転させること
は可能であると想定するので、返答Riの値を見出だす
ことは、テーブル5にアクセスしようとする不正行為者
には不可能であること、に留意されたい。これについ
て、片方向関数fは完全に片方向の関数にすることがで
きること、すなわち関数fの逆である計算可能な関数、
つまりfが2乗モジュロmである前述の例におけるよう
に、いくつかのパラメータが知られていると逆転可能で
あるが、これらのパラメータは端末には含まれていない
ために実際にはありえないような関数は、実際に存在し
ないことに留意されたい。
【0023】端末1のアクセス可能な性質が理由で、本
発明による方法の最も簡単なバージョンは、テーブル5
を参照するのみでなく、気づかれることなくこれを変更
することのできる人物に対して研究された安全性を保証
することはできない。このような人物にとっては、一方
では端末によって伝送される質問に対する返答を伝達す
る何らかのアルゴリズムを有する不正携帯用オブジェク
トを製造し、他方では端末のテーブル5の制御値を、こ
れらの制御値が不正携帯用オブジェクトによって供給さ
れた返答に片方向関数を適用した結果になるように、変
更することは実際に可能である。比較器7による比較の
結果は実際にこの場合には満足できるものとして考えら
れ、したがって、これは端末によって制御される動作に
進む。このような不正を避けるために、図2に示す本発
明によるさらに複雑精巧化されたバージョンを準備す
る。
【0024】この本発明の第2バージョンでは、端末
は、前述のように一連の質問と一連の制御値を含むのみ
ならず、この他に、質問と該当制御値との組合せの非対
称解読機能による変換値である一連の符号定数S1、S
2、・・・Si・・・Snを含むテーブル5を有する。
質問Qiが例えば64ビットの連続であり、該当制御値
Uiが例えば128ビットの1組であれば、例えばQi
UiQiUiの順序に従って質問と制御値を続けて2回
並べて質問と制御値の組合せを作り、それから認証テー
ブル5に入れるべき該当符号定数Siを決定するため
に、認可された機関が非対称解読機能をこの組合せに適
用する。非対称解読機能は例えば、こうして作られた組
合せの平方根モジュロmである。この平方根モジュロm
は、端末にどうしても入れられないパラメータを知って
いるときにのみ決定されることができる。
【0025】カードを認証するときには、一方では本発
明の方法の簡略バージョンについて記載した手順を適用
し、それから返答が満足できる場合には、端末で処理回
路8及び処理回路9を使って前記の組合せQiUiQi
Uiを実行し、さらに符号定数Siに対して、符号定数
Siの値を決定するために認可された機関によって使用
された非対称解読機能の逆関数を適用し、それから比較
器10で、処理回路8によって実行された組合せと処理
回路9による符号定数Siの変換値とを比較する。ここ
で、この逆非対称関数いわゆる前記の例における平方根
モジュロmは直接非対象解読関数を適用するために必要
であったパラメータを知る必要はない、ということに留
意されたい。したがって、不正行為者によって気付かれ
る可能性のある端末によるこの逆関数の実現は、この不
正行為者に対して、符号定数が制御値と矛盾がないよう
に制御値と同時に導入すべき符号定数を決定できないよ
うにする。特に、予測されていたように不正行為者が贋
のカードを作り、最初の比較が満足されるように該当制
御値を偽造する場合には、第2の比較が同様に満足され
るように制御値に結び付くべき符号定数を決定すること
は、不正行為者にとっては不可能となる。したがって方
法のセキュリティは、本発明の最も簡単なバージョンに
対して改善される。
【0026】端末のテーブル5を変更はしないが、一時
的に認証カードを取得して、テーブルの質問をすべて次
々に伝送し、片方向関数を適用する前に携帯用オブジェ
クトによって伝送された返答Riを端末に通すことは、
不正行為者にはやはり可能である。すべての返答が整う
と、返答Riを質問Qiに単に結び付けるテーブルを含
み、質問Qiが端末によって発せられる度に返答Riを
端末に伝送する贋の携帯用オブジェクトを作成すること
は、不正行為者にとってはやはり可能である。この不正
行為に対抗するために、本発明によって2つの解決法が
企てられる。
【0027】第1の解決法は、端末に接続することので
きる携帯用オブジェクトの数に対して非常に多い数の質
問をテーブルが含んでいるときに使用できるもので、こ
の解決法によれば、該当質問がいったん携帯用オブジェ
クトに伝送された後にテーブルの完全な1行が消され
る。したがって質問に対する返答を傍受しようとする不
正行為者は、同じ質問が新たに伝送されない限りこれら
の質問を使用することができない。これについて、テー
ブル5を入れ替えるかまたは変更するために遠隔通信線
によって認可された機関の中央機構に規則的かつ几帳面
に、端末を接続することが好ましい、ということに留意
されたい。端末が極めて頻繁にアクセス要求を受けとる
場合には、数千の行を含むテーブル5を準備することが
できる。
【0028】図3に示す第2の解決法によれば、テーブ
ルの各質問にテーブルの記号表示Itを含める。例え
ば、質問が64ビットの1組から成るときには、各質問
の最初の10ビットは同じものであり、テーブルの記号
表示を構成する。したがって各質問QiはItPiの形
となり、ここでPiだけが質問によって変わる。したが
ってネットワークの各端末は、他の端末の異なった記号
表示を有するテーブルを含む。さらに、携帯用オブジェ
クトのメモリ11の中に各テーブルまたは最後の10テ
ーブル、または端末に接続されると携帯用オブジェクト
に伝送される質問を有する最も頻繁なテーブルの記号表
示を記憶し、そして記憶された各記号表示に、記号表示
を含む質問が携帯用オブジェクトに伝送される度に増分
を行うカウンタ12を関連させる。その上に、限界値が
携帯用オブジェクトのメモリ13の中に記憶され、カウ
ンタ12の値は、質問が処理回路4に伝送される度に比
較器14によって限界値と比較される。カウンタが記憶
された限界値に達すると、携帯用オブジェクトの処理回
路4は携帯用オブジェクトが該当端末の質問にこれ以上
返答しないように遮断される。こうして、不正行為者に
対してテーブルのすべての質問の取得を禁止し、そして
端末によって伝送される質問の確率的性格を考慮に入れ
て、端末による贋のカードの認証という危険性を最小に
する。この場合、テーブルの寸法は前記の例よりも小さ
く、例えば、10の質問の1つの限界値を有する100
行を持つテーブルを準備することができる。この場合、
記号表示も含めてかなり高いテーブル変更頻度を準備す
ることが好ましい。
【0029】携帯用オブジェクトの回路の遮断を引き起
こす限界値に達することを避けるために、慎重な不正行
為者は、毎回複数のテーブルの各々に限界値以下の行数
を取り込んで、いろいろな記号表示を含む複数のテーブ
ルを混合し、こうして構成された新しいテーブルの質問
に対する返答のすべてを得るようにすることができる。
図4に示す本発明のこの態様の変形によれば、質問の各
々の中のみならずテーブルのメモリ15の中にも、テー
ブルの記号表示の記憶が準備され、そして質問を携帯用
オブジェクトに伝送する前に、比較器16によって質問
の部分Ixをテーブルの記号表示Itと比較して、この
メモリが含むテーブルの記号表示が問題のテーブルに実
際に該当することを確認する。異常が確認された場合に
は、端末は動作を停止し、検査を行うべく、認可された
機関のもとで警報が発せられる。
【0030】携帯用オブジェクトのメモリ飽和を避ける
ために、テーブルを変更するときには携帯用オブジェク
トのカウンタをゼロに戻すことが好ましい。このために
例えば、決まった日付にいろいろな端末のテーブルの変
更を実施し、携帯用オブジェクトの中にカウンタをゼロ
化した日付を記憶する。こうして携帯用オブジェクトが
端末に接続される度に、カウンタの最終ゼロ化の日付が
テーブルの最終変更の前であるかどうかを検査し、そし
てこの場合に、該当記号表示を排除して携帯用オブジェ
クトのカウンタをゼロに戻すことが可能である。
【0031】他の実施変形例によれば、いろいろな暗号
を含む携帯用オブジェクトの認証を可能にするための、
それぞれが1つの暗号に関連する複数の異なったテーブ
ルを備えた端末を準備することができる。したがって各
携帯用オブジェクトは、前記の方法が正しく進行できる
ように、その認証に役立つべきテーブル識別手段を含む
ことになる。接続されると、携帯用オブジェクトは端末
にその暗号に関連するテーブル識別手段を伝送し、した
がって認証の次の動作は前記の本発明による方法と一致
する。
【0032】テーブルの記号表示の利用に関する本発明
の態様を本発明による方法の基礎バージョンに関連させ
て説明したが、さらにまた、この態様を複数のテーブル
を有する複雑精巧化されたバージョンと関連させて準備
することもできる。
【0033】もちろん、本発明は説明されたいろいろな
バージョンに限定されることはなく、特許請求の範囲で
定義されるように、本発明の範囲を逸脱することなく様
々な実施変形をもたらすことができる。
【図面の簡単な説明】
【図1】本発明による方法の第1バージョンの概略図で
ある。
【図2】図1の方法をさらに複雑精巧化したバージョン
の概略図である。
【図3】図1に示すものと同じ本発明による方法のある
バージョンに関して本発明の有利な態様を示す概略図で
ある。
【図4】図3に示す方法の実施変形例の概略図である。

Claims (10)

    【特許請求の範囲】
  1. 【請求項1】 オフライン端末(1)によって伝送され
    る一次値(Qi)の関数である二次値(Ri)を供給す
    るのに適した処理回路(4)を含む携帯用オブジェクト
    (2)を前記のオフライン端末によって認証する方法で
    あって、前記の端末の中に一連の一次値(Qi)と一連
    の制御値(Ui)を集める認証テーブル(5)を配置
    し、各制御値は、本物の携帯用オブジェクトの処理回路
    によって計算された二次値(Ri)から片方向関数によ
    って変換されたものであり、携帯用オブジェクトを端末
    に接続するときには、前記のテーブルの一次値(Qi)
    の1つを携帯用オブジェクトに伝送し、片方向関数を携
    帯用オブジェクトから受けとった二次値(Rx)に適用
    し、そして得られた結果をテーブルの該当制御値(U
    i)と比較することを特徴とする前記の認証方法。
  2. 【請求項2】 認証テーブル(5)が、各一次値(Q
    i)のために一次値(Qi)と該当制御値(Ui)の組
    合せの非対称関数による変換値である符号定数(Si)
    をさらに含み、携帯用オブジェクトを端末に接続する
    と、一方では選択された一次値と該当制御値との組合せ
    が実施され、他方では該当符号定数に非対称関数の逆関
    数が適用され、そして得られた結果が比較されることを
    特徴とする請求項1に記載の認証方法。
  3. 【請求項3】 テーブルの一次値がいったん携帯用オブ
    ジェクトに伝送された後に削除されることを特徴とする
    請求項1または2に記載の認証方法。
  4. 【請求項4】 テーブルの各一次値にその記号表示(I
    t)が入れられ、携帯用オブジェクトの中に各テーブル
    の記号表示が記憶され、そのテーブルの一次値は携帯用
    オブジェクトが端末に接続されたときに伝送されてお
    り、記憶された各記号表示にカウンタ(12)が関連
    し、伝送された一次値の数が限界値に達すると同じ記号
    表示を有する1つの新しい一次値に対応する二次値が遮
    断されることを特徴とする請求項1または2に記載の認
    証方法。
  5. 【請求項5】 端末のテーブルが変更されるときに携帯
    用オブジェクトの該当カウンタがゼロに戻されることを
    特徴とする請求項4に記載の認証方法。
  6. 【請求項6】 一次値を携帯用オブジェクトに伝送する
    前に、携帯用オブジェクトが含むテーブルの記号表示が
    実際に問題のテーブルに対応するかを確認することを特
    徴とする請求項4または5に記載の認証方法。
  7. 【請求項7】 前記の二次値(Ri)は前記の認証暗号
    (K)の関数であり、端末は複数の認証テーブル(5)
    を所有し、各テーブルは同じ認証暗号(K)の関数であ
    る制御値(Ui)を再集成し、そして携帯用オブジェク
    トは端末に接続されると端末にその認証暗号(K)に関
    連するテーブルの認証手段を伝送し、そのときそのテー
    ブルの一次値が携帯用オブジェクトに伝送されることを
    特徴とする請求項1に記載の認証方法。
  8. 【請求項8】 外部リーディング・アクセス不能で認証
    暗号(K)を含むメモリ(3)と処理回路(4)を含む
    請求項1に記載の認証方法を実施するために適した携帯
    用オブジェクトであって、この携帯用オブジェクトは、
    暗号(K)とオブジェクトが導入される端末によってオ
    ブジェクトに伝送される一次値(Qi)との関数である
    二次値(Ri)を供給するために対称ディジタル化アル
    ゴリズムを使用し、この携帯用オブジェクトは、端末へ
    の接続の度に増分されるカウンタ(12)に付随する端
    末の記号表示(It)を保持するのに適したメモリ(1
    5)と、カウンタの値が所定の限界値を超過したときに
    携帯用オブジェクトに機能動作を停止させる装置を含む
    ことを特徴とする携帯用オブジェクト。
  9. 【請求項9】 請求項1に記載の方法を実施するのに適
    した端末であって、一連の一次値(Qi)と一連の制御
    値(Ui)、端末に接続された携帯用オブジェクトの認
    証手順の際に受けとられる二次値に片方向関数(f)を
    適用するのに適した装置(6)、及び得られた結果とテ
    ーブルの該当制御値を比較する比較器(7)を含むこと
    を特徴とする端末。
  10. 【請求項10】 携帯用オブジェクトを認証するときに
    一次値と制御値との対が変更されていなかったことを確
    証するのに適した装置(9、10)を含むことを特徴と
    する請求項9に記載の端末。
JP6150484A 1993-06-08 1994-06-08 オフライン端末による携帯用オブジェクトの認証方法及び対応する端末 Expired - Fee Related JP2777060B2 (ja)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR9306855A FR2706210B1 (fr) 1993-06-08 1993-06-08 Procédé d'authentification d'un objet portatif par un terminal hors ligne, objet portatif et terminal correspondants.
FR9306855 1993-06-08

Publications (2)

Publication Number Publication Date
JPH07140897A true JPH07140897A (ja) 1995-06-02
JP2777060B2 JP2777060B2 (ja) 1998-07-16

Family

ID=9447874

Family Applications (1)

Application Number Title Priority Date Filing Date
JP6150484A Expired - Fee Related JP2777060B2 (ja) 1993-06-08 1994-06-08 オフライン端末による携帯用オブジェクトの認証方法及び対応する端末

Country Status (14)

Country Link
US (1) US5528231A (ja)
EP (1) EP0628935B1 (ja)
JP (1) JP2777060B2 (ja)
KR (1) KR0143568B1 (ja)
CN (1) CN1132128C (ja)
AT (1) ATE166478T1 (ja)
CA (1) CA2124891C (ja)
DE (1) DE69410348T2 (ja)
DK (1) DK0628935T3 (ja)
ES (1) ES2117764T3 (ja)
FR (1) FR2706210B1 (ja)
NO (1) NO307017B1 (ja)
SG (1) SG54225A1 (ja)
TW (1) TW263575B (ja)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003030143A (ja) * 2001-04-30 2003-01-31 Matsushita Electric Ind Co Ltd 携帯用記憶装置を用いるコンピュータネットワークセキュリティシステム
WO2007072746A1 (ja) * 2005-12-20 2007-06-28 Matsushita Electric Industrial Co., Ltd. 認証システム、及び認証装置
JP2008252879A (ja) * 2007-03-01 2008-10-16 Mitsubishi Electric Information Technology Centre Europa Bv ユーザを認証する方法、ユーザ端末を認証する装置、及びユーザ端末を認証する認証サーバ

Families Citing this family (111)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6092117A (en) * 1994-09-02 2000-07-18 Packard Bell Nec System and method for automatically reconnecting a wireless interface device to a host computer
US6262719B1 (en) 1994-09-02 2001-07-17 Packard Bell Nec, Inc. Mouse emulation with a passive pen
US5867106A (en) * 1994-09-02 1999-02-02 Packard Bell Nec Password switch to override remote control
US6292181B1 (en) 1994-09-02 2001-09-18 Nec Corporation Structure and method for controlling a host computer using a remote hand-held interface device
US5974558A (en) * 1994-09-02 1999-10-26 Packard Bell Nec Resume on pen contact
FR2730076B1 (fr) * 1995-01-31 1997-03-28 Sorep Sa Procede d'authentification par un serveur du porteur d'un objet portatif a microprocesseur, serveur et objet portatif correspondants
NL1001376C2 (nl) * 1995-05-11 1996-11-12 Nederland Ptt Werkwijze voor het uitvoeren van een elektronische betalingstransactie met een variabel aantal betalingseenheden, alsmede betaalmiddel en stelsel voor toepassing van de werkwijze.
US6148344A (en) * 1995-10-16 2000-11-14 Nec Corporation System and method for enabling an IPX driver to accommodate multiple LAN adapters
US6126327A (en) * 1995-10-16 2000-10-03 Packard Bell Nec Radio flash update
US6005533A (en) * 1995-10-16 1999-12-21 Packard Bell Nec Remote occlusion region
US6924790B1 (en) 1995-10-16 2005-08-02 Nec Corporation Mode switching for pen-based computer systems
US7512671B1 (en) * 1995-10-16 2009-03-31 Nec Corporation Computer system for enabling a wireless interface device to selectively establish a communication link with a user selectable remote computer
US5996082A (en) * 1995-10-16 1999-11-30 Packard Bell Nec System and method for delaying a wake-up signal
US6108727A (en) * 1995-10-16 2000-08-22 Packard Bell Nec System having wireless interface device for storing compressed predetermined program files received from a remote host and communicating with the remote host via wireless link
FI102235B1 (fi) * 1996-01-24 1998-10-30 Nokia Telecommunications Oy Autentikointiavainten hallinta matkaviestinjärjestelmässä
AU764405B2 (en) * 1996-04-19 2003-08-21 Canon Kabushiki Kaisha Enciphering method, deciphering method and certifying method
JPH09284272A (ja) * 1996-04-19 1997-10-31 Canon Inc エンティティの属性情報に基づく暗号化方式、署名方式、鍵共有方式、身元確認方式およびこれらの方式用装置
US5736932A (en) * 1996-07-03 1998-04-07 At&T Corp Security for controlled access systems
DE19737693A1 (de) * 1997-08-29 1999-03-04 Philips Patentverwaltung Verfahren zur Überprüfung der Unverfälschtheit einer elektrischen Schaltung
KR100406107B1 (ko) * 1998-03-16 2004-03-22 엘지전자 주식회사 교환기내의시험장치에서가입자선로측정방법
EP1078139A2 (de) * 1998-04-29 2001-02-28 Siemens Aktiengesellschaft Verfahren zur authentifikation
NL1011790C2 (nl) * 1999-04-14 2000-10-17 Koninkl Kpn Nv Chipkaartsysteem.
RU2202827C2 (ru) * 1999-11-03 2003-04-20 Закрытое акционерное общество "Алкорсофт" Способ формирования ценного документа (варианты)
US7111176B1 (en) 2000-03-31 2006-09-19 Intel Corporation Generating isolated bus cycles for isolated execution
US6934817B2 (en) * 2000-03-31 2005-08-23 Intel Corporation Controlling access to multiple memory zones in an isolated execution environment
US7194634B2 (en) * 2000-03-31 2007-03-20 Intel Corporation Attestation key memory device and bus
US7089418B1 (en) 2000-03-31 2006-08-08 Intel Corporation Managing accesses in a processor for isolated execution
US6769058B1 (en) 2000-03-31 2004-07-27 Intel Corporation Resetting a processor in an isolated execution environment
US6754815B1 (en) 2000-03-31 2004-06-22 Intel Corporation Method and system for scrubbing an isolated area of memory after reset of a processor operating in isolated execution mode if a cleanup flag is set
US7013481B1 (en) 2000-03-31 2006-03-14 Intel Corporation Attestation key memory device and bus
US7013484B1 (en) 2000-03-31 2006-03-14 Intel Corporation Managing a secure environment using a chipset in isolated execution mode
US6760441B1 (en) 2000-03-31 2004-07-06 Intel Corporation Generating a key hieararchy for use in an isolated execution environment
US6976162B1 (en) * 2000-06-28 2005-12-13 Intel Corporation Platform and method for establishing provable identities while maintaining privacy
US7389427B1 (en) 2000-09-28 2008-06-17 Intel Corporation Mechanism to secure computer output from software attack using isolated execution
US7793111B1 (en) * 2000-09-28 2010-09-07 Intel Corporation Mechanism to handle events in a machine with isolated execution
US7215781B2 (en) * 2000-12-22 2007-05-08 Intel Corporation Creation and distribution of a secret value between two devices
US7035963B2 (en) * 2000-12-27 2006-04-25 Intel Corporation Method for resolving address space conflicts between a virtual machine monitor and a guest operating system
US6907600B2 (en) 2000-12-27 2005-06-14 Intel Corporation Virtual translation lookaside buffer
US7225441B2 (en) * 2000-12-27 2007-05-29 Intel Corporation Mechanism for providing power management through virtualization
US7818808B1 (en) 2000-12-27 2010-10-19 Intel Corporation Processor mode for limiting the operation of guest software running on a virtual machine supported by a virtual machine monitor
US7117376B2 (en) * 2000-12-28 2006-10-03 Intel Corporation Platform and method of creating a secure boot that enforces proper user authentication and enforces hardware configurations
US7272831B2 (en) 2001-03-30 2007-09-18 Intel Corporation Method and apparatus for constructing host processor soft devices independent of the host processor operating system
ES2182709A1 (es) * 2001-07-09 2003-03-01 Crespo Jose Agustin Franc Vega Sistema portable de almacenamiento y emision de claves preestablecidas para la autenticacion y procedimiento de autenticacion.
US7191440B2 (en) 2001-08-15 2007-03-13 Intel Corporation Tracking operating system process and thread execution and virtual machine execution in hardware or in a virtual machine monitor
US7024555B2 (en) 2001-11-01 2006-04-04 Intel Corporation Apparatus and method for unilaterally loading a secure operating system within a multiprocessor environment
US7103771B2 (en) * 2001-12-17 2006-09-05 Intel Corporation Connecting a virtual token to a physical token
US20030126453A1 (en) * 2001-12-31 2003-07-03 Glew Andrew F. Processor supporting execution of an authenticated code instruction
US7308576B2 (en) * 2001-12-31 2007-12-11 Intel Corporation Authenticated code module
US7480806B2 (en) * 2002-02-22 2009-01-20 Intel Corporation Multi-token seal and unseal
US7124273B2 (en) * 2002-02-25 2006-10-17 Intel Corporation Method and apparatus for translating guest physical addresses in a virtual machine environment
US7631196B2 (en) 2002-02-25 2009-12-08 Intel Corporation Method and apparatus for loading a trustable operating system
US7069442B2 (en) 2002-03-29 2006-06-27 Intel Corporation System and method for execution of a secured environment initialization instruction
US7028149B2 (en) 2002-03-29 2006-04-11 Intel Corporation System and method for resetting a platform configuration register
US20030196096A1 (en) * 2002-04-12 2003-10-16 Sutton James A. Microcode patch authentication
US20030196100A1 (en) * 2002-04-15 2003-10-16 Grawrock David W. Protection against memory attacks following reset
US7127548B2 (en) 2002-04-16 2006-10-24 Intel Corporation Control register access virtualization performance improvement in the virtual-machine architecture
US7840803B2 (en) * 2002-04-16 2010-11-23 Massachusetts Institute Of Technology Authentication of integrated circuits
US20030229794A1 (en) * 2002-06-07 2003-12-11 Sutton James A. System and method for protection against untrusted system management code by redirecting a system management interrupt and creating a virtual machine container
US7142674B2 (en) * 2002-06-18 2006-11-28 Intel Corporation Method of confirming a secure key exchange
US20040003321A1 (en) * 2002-06-27 2004-01-01 Glew Andrew F. Initialization of protected system
US6996748B2 (en) 2002-06-29 2006-02-07 Intel Corporation Handling faults associated with operation of guest software in the virtual-machine architecture
US7124327B2 (en) 2002-06-29 2006-10-17 Intel Corporation Control over faults occurring during the operation of guest software in the virtual-machine architecture
US7296267B2 (en) * 2002-07-12 2007-11-13 Intel Corporation System and method for binding virtual machines to hardware contexts
US7165181B2 (en) * 2002-11-27 2007-01-16 Intel Corporation System and method for establishing trust without revealing identity
US20040117532A1 (en) * 2002-12-11 2004-06-17 Bennett Steven M. Mechanism for controlling external interrupts in a virtual machine system
US7073042B2 (en) 2002-12-12 2006-07-04 Intel Corporation Reclaiming existing fields in address translation data structures to extend control over memory accesses
US7900017B2 (en) * 2002-12-27 2011-03-01 Intel Corporation Mechanism for remapping post virtual machine memory pages
US20040128345A1 (en) * 2002-12-27 2004-07-01 Robinson Scott H. Dynamic service registry
US20040128465A1 (en) * 2002-12-30 2004-07-01 Lee Micheil J. Configurable memory bus width
US7415708B2 (en) * 2003-06-26 2008-08-19 Intel Corporation Virtual machine management using processor state information
US20050044292A1 (en) * 2003-08-19 2005-02-24 Mckeen Francis X. Method and apparatus to retain system control when a buffer overflow attack occurs
WO2005029746A2 (en) * 2003-09-12 2005-03-31 Rsa Security Inc. System and method providing disconnected authentication
US7287197B2 (en) * 2003-09-15 2007-10-23 Intel Corporation Vectoring an interrupt or exception upon resuming operation of a virtual machine
US7424709B2 (en) 2003-09-15 2008-09-09 Intel Corporation Use of multiple virtual machine monitors to handle privileged events
US7739521B2 (en) * 2003-09-18 2010-06-15 Intel Corporation Method of obscuring cryptographic computations
US7610611B2 (en) * 2003-09-19 2009-10-27 Moran Douglas R Prioritized address decoder
US20050080934A1 (en) 2003-09-30 2005-04-14 Cota-Robles Erik C. Invalidating translation lookaside buffer entries in a virtual machine (VM) system
US7237051B2 (en) 2003-09-30 2007-06-26 Intel Corporation Mechanism to control hardware interrupt acknowledgement in a virtual machine system
US7177967B2 (en) 2003-09-30 2007-02-13 Intel Corporation Chipset support for managing hardware interrupts in a virtual machine system
US7366305B2 (en) * 2003-09-30 2008-04-29 Intel Corporation Platform and method for establishing trust without revealing identity
US7636844B2 (en) 2003-11-17 2009-12-22 Intel Corporation Method and system to provide a trusted channel within a computer system for a SIM device
US20050108171A1 (en) * 2003-11-19 2005-05-19 Bajikar Sundeep M. Method and apparatus for implementing subscriber identity module (SIM) capabilities in an open platform
US20050108534A1 (en) * 2003-11-19 2005-05-19 Bajikar Sundeep M. Providing services to an open platform implementing subscriber identity module (SIM) capabilities
US8156343B2 (en) 2003-11-26 2012-04-10 Intel Corporation Accessing private data about the state of a data processing machine from storage that is publicly accessible
US8037314B2 (en) * 2003-12-22 2011-10-11 Intel Corporation Replacing blinded authentication authority
US20050152539A1 (en) * 2004-01-12 2005-07-14 Brickell Ernie F. Method of protecting cryptographic operations from side channel attacks
US7802085B2 (en) 2004-02-18 2010-09-21 Intel Corporation Apparatus and method for distributing private keys to an entity with minimal secret, unique information
US20050216920A1 (en) * 2004-03-24 2005-09-29 Vijay Tewari Use of a virtual machine to emulate a hardware device
US7356735B2 (en) 2004-03-30 2008-04-08 Intel Corporation Providing support for single stepping a virtual machine in a virtual machine environment
US7620949B2 (en) * 2004-03-31 2009-11-17 Intel Corporation Method and apparatus for facilitating recognition of an open event window during operation of guest software in a virtual machine environment
US7490070B2 (en) 2004-06-10 2009-02-10 Intel Corporation Apparatus and method for proving the denial of a direct proof signature
US20050288056A1 (en) * 2004-06-29 2005-12-29 Bajikar Sundeep M System including a wireless wide area network (WWAN) module with an external identity module reader and approach for certifying the WWAN module
US7305592B2 (en) * 2004-06-30 2007-12-04 Intel Corporation Support for nested fault in a virtual machine environment
US7840962B2 (en) * 2004-09-30 2010-11-23 Intel Corporation System and method for controlling switching between VMM and VM using enabling value of VMM timer indicator and VMM timer value having a specified time
US8146078B2 (en) 2004-10-29 2012-03-27 Intel Corporation Timer offsetting mechanism in a virtual machine environment
WO2006053304A2 (en) * 2004-11-12 2006-05-18 Pufco, Inc. Volatile device keys and applications thereof
US8924728B2 (en) 2004-11-30 2014-12-30 Intel Corporation Apparatus and method for establishing a secure session with a device without exposing privacy-sensitive information
US8533777B2 (en) * 2004-12-29 2013-09-10 Intel Corporation Mechanism to determine trust of out-of-band management agents
US7395405B2 (en) * 2005-01-28 2008-07-01 Intel Corporation Method and apparatus for supporting address translation in a virtual machine environment
KR101366376B1 (ko) * 2006-01-24 2014-02-24 베라요, 인크. 신호 제너레이터에 기반한 장치 보안
US8014530B2 (en) 2006-03-22 2011-09-06 Intel Corporation Method and apparatus for authenticated, recoverable key distribution with no database secrets
CN101542496B (zh) * 2007-09-19 2012-09-05 美国威诚股份有限公司 利用物理不可克隆功能的身份验证
US8683210B2 (en) * 2008-11-21 2014-03-25 Verayo, Inc. Non-networked RFID-PUF authentication
KR101224717B1 (ko) * 2008-12-26 2013-01-21 에스케이플래닛 주식회사 소프트웨어 라이센스 보호 방법과 그를 위한 시스템, 서버,단말기 및 컴퓨터로 읽을 수 있는 기록매체
US8811615B2 (en) * 2009-08-05 2014-08-19 Verayo, Inc. Index-based coding with a pseudo-random source
US8468186B2 (en) * 2009-08-05 2013-06-18 Verayo, Inc. Combination of values from a pseudo-random source
CA2830283C (en) 2011-03-25 2016-11-01 Certicom Corp. Interrogating an authentication device
CA2832348C (en) 2011-05-06 2018-07-24 Certicom Corp. Managing data for authentication devices
US9727720B2 (en) 2012-11-30 2017-08-08 Certicom Corp. Challenge-response authentication using a masked response value
US9369290B2 (en) 2012-11-30 2016-06-14 Certicom Corp. Challenge-response authentication using a masked response value
US10645077B2 (en) * 2013-12-02 2020-05-05 Thales Dis France Sa System and method for securing offline usage of a certificate by OTP system

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US4283599A (en) * 1979-01-16 1981-08-11 Atalla Technovations Method and apparatus for securing data transmissions
FR2526977B1 (fr) * 1982-05-14 1988-06-10 Cii Honeywell Bull Procede et dispositif pour authentifier ou certifier au moins une information contenue dans une memoire d'un support electronique notamment amovible et portatif tel qu'une carte
US4630201A (en) * 1984-02-14 1986-12-16 International Security Note & Computer Corporation On-line and off-line transaction security system using a code generated from a transaction parameter and a random number
US4719566A (en) * 1985-10-23 1988-01-12 International Business Machines Corporation Method for entrapping unauthorized computer access
FR2592510B1 (fr) * 1985-12-31 1988-02-12 Bull Cp8 Procede et appareil pour certifier des services obtenus a l'aide d'un support portatif tel qu'une carte a memoire
US4829296A (en) * 1986-04-30 1989-05-09 Carey S. Clark Electronic lock system
US4731841A (en) * 1986-06-16 1988-03-15 Applied Information Technologies Research Center Field initialized authentication system for protective security of electronic information networks
US4779090A (en) * 1986-08-06 1988-10-18 Micznik Isaiah B Electronic security system with two-way communication between lock and key
FR2612315A1 (fr) * 1987-03-13 1988-09-16 Trt Telecom Radio Electr Procede pour simultanement lire a distance et certifier une information presente dans une memoire d'un support electronique
CA1321649C (en) * 1988-05-19 1993-08-24 Jeffrey R. Austin Method and system for authentication

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003030143A (ja) * 2001-04-30 2003-01-31 Matsushita Electric Ind Co Ltd 携帯用記憶装置を用いるコンピュータネットワークセキュリティシステム
WO2007072746A1 (ja) * 2005-12-20 2007-06-28 Matsushita Electric Industrial Co., Ltd. 認証システム、及び認証装置
JP2007195155A (ja) * 2005-12-20 2007-08-02 Matsushita Electric Ind Co Ltd 認証システム、及び認証装置
JP2008252879A (ja) * 2007-03-01 2008-10-16 Mitsubishi Electric Information Technology Centre Europa Bv ユーザを認証する方法、ユーザ端末を認証する装置、及びユーザ端末を認証する認証サーバ

Also Published As

Publication number Publication date
KR950001527A (ko) 1995-01-03
AU6462394A (en) 1994-12-15
EP0628935A1 (fr) 1994-12-14
DK0628935T3 (da) 1998-10-12
DE69410348T2 (de) 1998-09-24
ATE166478T1 (de) 1998-06-15
EP0628935B1 (fr) 1998-05-20
JP2777060B2 (ja) 1998-07-16
CN1113584A (zh) 1995-12-20
AU673599B2 (en) 1996-11-14
NO942118D0 (no) 1994-06-07
NO942118L (no) 1994-12-09
CN1132128C (zh) 2003-12-24
CA2124891C (fr) 1999-02-23
NO307017B1 (no) 2000-01-24
FR2706210B1 (fr) 1995-07-21
TW263575B (ja) 1995-11-21
DE69410348D1 (de) 1998-06-25
CA2124891A1 (fr) 1994-12-09
SG54225A1 (en) 1998-11-16
US5528231A (en) 1996-06-18
ES2117764T3 (es) 1998-08-16
KR0143568B1 (ko) 1998-08-17
FR2706210A1 (fr) 1994-12-16

Similar Documents

Publication Publication Date Title
US6163771A (en) Method and device for generating a single-use financial account number
JP2777060B2 (ja) オフライン端末による携帯用オブジェクトの認証方法及び対応する端末
US7844550B2 (en) Method and device for generating a single-use financial account number
Simmons A survey of information authentication
CA2256881C (en) An automatic safe public communication system
US5371796A (en) Data communication system
US4912762A (en) Management of cryptographic keys
US6061791A (en) Initial secret key establishment including facilities for verification of identity
EP0824814B1 (en) Methods and apparatus for authenticating an originator of a message
US10089627B2 (en) Cryptographic authentication and identification method using real-time encryption
WO1997045979A9 (en) Method and apparatus for initialization of cryptographic terminal
WO1997045979A2 (en) Method and apparatus for initialization of cryptographic terminal
FI86486C (fi) Foerfarande foer att arrangera teleroestningen pao ett saekert saett.
EP0225010A1 (en) A terminal for a system requiring secure access
US6606387B1 (en) Secure establishment of cryptographic keys
US7991151B2 (en) Method for secure delegation of calculation of a bilinear application
US20020131600A1 (en) Authentication and data security system for communications
CN110519223A (zh) 基于非对称密钥对的抗量子计算数据隔离方法和系统
GB2267631A (en) Data communication system
JPS59158639A (ja) 自動照合の方法および装置
Caponetto et al. A new chaotic system for the authentication and electronic certification procedures
KR20180089951A (ko) 전자화폐 거래 방법 및 시스템
Kunjadić et al. Payment Cards Counterfeiting Methods and Pin Uncovering
Roijakkers Security in signalling and digital signatures
from Zero-Knowledge Louis Claude Guillou 1) and Jean-Jacques Quisquater 2)

Legal Events

Date Code Title Description
R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

S111 Request for change of ownership or part of ownership

Free format text: JAPANESE INTERMEDIATE CODE: R313113

S531 Written request for registration of change of domicile

Free format text: JAPANESE INTERMEDIATE CODE: R313531

R350 Written notification of registration of transfer

Free format text: JAPANESE INTERMEDIATE CODE: R350

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20090501

Year of fee payment: 11

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20100501

Year of fee payment: 12

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20110501

Year of fee payment: 13

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20120501

Year of fee payment: 14

LAPS Cancellation because of no payment of annual fees