WO2009076879A1 - 一种实体双向鉴别方法和系统 - Google Patents
一种实体双向鉴别方法和系统 Download PDFInfo
- Publication number
- WO2009076879A1 WO2009076879A1 PCT/CN2008/073389 CN2008073389W WO2009076879A1 WO 2009076879 A1 WO2009076879 A1 WO 2009076879A1 CN 2008073389 W CN2008073389 W CN 2008073389W WO 2009076879 A1 WO2009076879 A1 WO 2009076879A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- entity
- message
- time
- signature
- varying parameter
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/321—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
Definitions
- the invention relates to a physical two-way authentication method and system.
- Entity authentication methods using asymmetric cryptography can be divided into two types, one-way authentication and two-way authentication.
- the uniqueness or timeliness of identification is identified by time-varying parameters and is often used as a time-series, sequence number, random number, etc. for time-varying parameters. If the time stamp or the sequence number is used as the time-varying parameter, the one-way authentication only needs to use one message, and the two-way authentication needs to use two messages. If the random number is used as the time-varying parameter, the one-way authentication needs to use two messages. Pass-through, two-way authentication requires three messages or four messages (ie, parallel authentication for two messages).
- the verifier must have a valid public key of the claimant before or during the operation, otherwise the authentication process may be compromised or not successfully completed.
- the three-way method of two-way authentication is taken as an example:
- the authentication system has ⁇ and two authentication entities; Cer x represents the certificate of the entity; x represents the signature of the entity; R x represents the random number generated by the entity; and is an optional text field.
- Step Sl l entity send random number 3 ⁇ 4, optional text 73 ⁇ 4 to entity
- Step S12 The entity ⁇ sends the token 7bfe « ⁇ S, the optional certificate Cer ⁇ to the entity's valid public key.
- Step S14 After entity B obtains the public key of entity ⁇ , verify the signature of TokenAB in step S12, verify the correctness of the specifier, and check the random number 3 ⁇ 4 and Tbfew ⁇ S sent in step S11. Whether the random number in the 3 ⁇ 4 matches; the entity completes the verification of the entity ⁇ ;
- Step S15 The entity sends a token 7bfe « ⁇ 4, an optional certificate Cer ⁇ to the entity's valid public key;
- Step S17 After entity A obtains the public key of entity B, it verifies the signature of TokenBA in S15, checks the correctness of specifier A, and checks whether the random number sent in step S12 matches the random number R A in TokenBA and Whether the random number R B received in S 11 and the random number R B in TokenBA match; the entity completes the verification of the entity.
- the three-pass authentication mechanism must be successful in ensuring that entity A and each have their own valid public key, and how to obtain the public key of the other party and its validity, the agreement itself is not involved.
- This guarantee requirement condition cannot be satisfied in many current application environments.
- the communication network usually adopts an entity authentication mechanism to implement the user access control function. Before the authentication mechanism is successfully completed, the user is prohibited from accessing the network, and thus the user cannot or is difficult before the authentication.
- the access certificate authority obtains the validity of the remote physical key of the peer network, and the authentication process cannot be performed.
- the present invention provides an entity two-way authentication method and system to solve the problem in the prior art that the authentication process cannot be performed because the network cannot be accessed before the authentication succeeds.
- the first entity sends a first message carrying a time-varying parameter, an identity ID A, and a signature; after receiving the first message, the second entity sends a time-varying parameter to the trusted third party and
- R B The second message of the first entity's identity ID A and its own identity ID B ;
- the trusted third party After receiving the second message, the trusted third party returns a third message carrying its own signature time-varying parameter and time-varying parameter to the second entity;
- the second entity After the second entity receives the third message, when the trusted third party signature verification passes and the time varying parameter matches the locally stored time varying parameter, the verification result of the first entity is obtained, and when the verification result indicates the When the first entity is legally valid, the public key of the first entity is obtained to verify the signature of the first entity in the first message, and when the verification is passed, the signature carries the trusted third party, a fourth message of the second entity signature and the time varying parameter;
- the first entity After receiving the fourth message, the first entity obtains the verification result of the second entity when the trusted third party signature verification passes and the time varying parameter matches the locally stored time varying parameter, and when the verification result indicates the When the second entity is legally valid, the public key of the second entity is obtained to verify the signature of the second entity in the fourth message, and the authentication process is completed.
- the third message is sent when the legality verification of the first entity and the second entity is completed.
- the first entity and the second entity are legal: the identity of the first entity and the second entity in the second message is a certificate, and the certificate is valid.
- the first entity and the second entity are legal: the identity of the first entity and the second entity in the second message is a specifier, and the first entity is And the public key of the second entity exists and is valid.
- the time varying parameter may be a random number, a time stamp or a sequence number.
- the embodiment of the invention also discloses a ternary peer-to-peer authentication system, comprising: a first entity, a second entity and a third entity as a trusted third party, wherein:
- the first entity is configured to: send, to the second entity, a first message carrying a time-varying parameter, a self-identity identifier/2, and a signature; and receiving, by the second entity, a third entity signature, a second entity signature, and After the fourth message of the time varying parameter R A , when the third entity signature verification passes and the time varying parameter R A matches the locally stored time varying parameter, the verification result of the second entity is obtained, and when the verification result indicates the second When the entity is legal, the public key of the second entity is obtained to verify the signature of the second entity in the fourth message;
- the second entity is configured to: after receiving the first message, send, to the third entity, a second message that carries a time-varying parameter and a first entity identity identifier, and receives the first message
- the third entity returns the third message carrying the third entity signature time-varying function and the time-varying parameter R B
- the third entity signature verification passes and the time-varying parameter and the local storage in the third message
- the third entity is configured to: receive the second message, and return the third to the second entity
- the third message is sent when the legality verification of the first entity and the second entity is completed.
- the first entity and the second entity are legal: the identity of the first entity and the second entity in the second message is a certificate, and the certificate is valid.
- the first entity and the second entity are legal: the identity of the first entity and the second entity in the second message is a specifier, and the first entity is And the public key of the second entity exists and is valid.
- the time varying parameter may be a random number, a time stamp or a sequence number.
- the invention adopts a three-entity framework, and the authentication entity needs to obtain the public key or certificate of the trusted third party before the authentication, and obtains the user certificate issued by the trusted third party to itself or hands over the public key to the trusted third party. Without knowing in advance the valid public key of the peer authentication entity.
- the public key of the authentication entity and its validity are automatically passed to the required peers through the search and verification of the trusted third party.
- the invention defines an online retrieval and authentication mechanism of the public key, realizes centralized management thereof, simplifies the operating conditions of the protocol, and facilitates its application implementation.
- FIG. 1 is a schematic diagram of identification of a three-pass authentication mechanism in the prior art
- FIG. 2 is a schematic diagram of a bidirectional authentication method according to an embodiment of the present invention.
- Figure 3 is a schematic diagram of the entity ⁇ verification process in the method shown in Figure 2;
- Figure 4 is a schematic diagram of the entity ⁇ verification process in the method shown in Figure 2;
- FIG. 5 is a schematic structural diagram of a ternary peer authentication system according to an embodiment of the present invention.
- the technical solutions in the embodiments of the present invention will be clearly and completely described in the following with reference to the drawings in the embodiments of the present invention. It is apparent that the described embodiments are only a part of the embodiments of the invention, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
- FIG. 2 it is a schematic diagram of an entity bidirectional authentication method according to an embodiment of the present invention.
- the method of the embodiment of the present invention involves three entities, two authentication entities and a trusted third party TTP (Trusted Third Party), and the trusted third party TTP is a trusted third party that authenticates the entities ⁇ and B.
- TTP Trusted Third Party
- This system for realizing peer-to-peer authentication between two entities through a trusted third party 7P is called a Tri-element Peer Authentication (TePA) system.
- / CeW x represents the validity of the certificate
- PublicKeyx entity X (X represents A or beta]) public key
- / ⁇ ) ⁇ represented by the specifier entity certificate CeW x or to the identity of the entity X
- 3 ⁇ 4b x represents an entity
- the verification result consists of a certificate (3 ⁇ 4 ⁇ and its validity / ⁇ or consists of the entity and its public key PublicKeyx, Tbfew is a token field, defined as follows:
- TokenAB sS A (R A ⁇ ⁇ ID A ⁇ ⁇ Textl)
- TokenTB R A ⁇ ⁇ Pub A ⁇ ⁇ Pub B ⁇ ⁇ Text3)
- TokenTBl R B ⁇ ⁇ Pub A ⁇ ⁇ Text5 ⁇ ⁇ sS TP (R B ⁇ ⁇ Pub A ⁇ ⁇ Text5)
- TokenTB2 R A ⁇ ⁇ Pub B ⁇ ⁇ Text6 ⁇ ⁇ sS TP (R A ⁇ ⁇ Pub B ⁇ ⁇ Text6)
- TokenBAl sS B (Text311 TokenTB ⁇
- TokenBA2 sS B (TokenTB2 ⁇ ⁇ Text4)
- Step S21 the entity sends a message 1 to the entity, and the message 1 includes a time-varying parameter, an identity ID A , a token TokenAB, and an optional text 7&7;
- Step S22 after receiving the message 1, the entity B sends a message 2 to the trusted third party, the message 2 includes time-varying parameters R A and R B , identity IDs A and ID B, and optional text Text2;
- Step S23 After receiving the message 2, the trusted third party checks whether the entity and the entity are legal;
- the identity of the entity ⁇ and the entity B in the message 2 is a specifier, the entity A and the corresponding public key of the entity are searched and checked; and if the public key is not searched or invalid, the message 2 or the return message is directly discarded. 3; If the public key is searched and valid, return message 3;
- Step S24 After checking the legality of the entity and the entity, the trusted third party returns a message 3 to the entity, and the message 3 includes the token TokenTB and the optional text Text3 or includes the tokens TokenTBl and TokenTB2;
- Step S25 After receiving the message 3, the entity performs verification
- Step S31 verifying the signature of the trusted third party TTP of TokenTB or TokenTB1, if the verification is successful, proceeding to step S32; otherwise, ending the process;
- Step S32 checking whether the time-varying parameter 3 ⁇ 4 in the message 2 matches the time-varying parameter 3 ⁇ 4 in the TokenTB TokenTB1, and if yes, executing step S32, otherwise ending the process;
- Step S33 obtaining the verification result of the entity ⁇ , if the entity ⁇ is legally valid, executing step S34, otherwise ending the process;
- Step S34 Acquire the public key of the entity A, and verify the signature of the entity A of the TokenAB in the message 1. If the signature is correct, it is determined that the verification is passed.
- the operation of verifying the signature of the trusted third party TTP of TokenTB or TokenTB1 may be performed by checking whether the time varying parameter in message 2 matches the time varying parameter in TokenTB or TokenTB1. After that.
- step S33 if entity A is illegal, step S26 may be directly executed.
- Step S26 After completing the verification of the message 3, the entity B sends a message 4 to the entity A, and the message 4 Including tokens TokenTB, TokenBAl, optional text Text3 and Text4 or including tokens TokenTB2, 73 ⁇ 4 " ⁇ 2 and optional text 73 ⁇ 4x; it should be noted that if message 3 includes token TokenTB and optional text Text3, then the message 4 includes tokens TokenTB, TokenBAl, optional texts Text3 and Text4; if message 3 includes tokens TokenTBl and TokenTB2, then message 4 l includes tokens TokenTB 2, 7bfe « ⁇ 42 and optional text 73 ⁇ 4c.
- Step S27 After receiving the message 4, the entity performs verification
- Step S41 Verify the signature of the trusted third party TTP of TokenTB or TokenTB2. If the verification is successful, proceed to step S42; otherwise, end the process;
- Step S42 checking whether the time-varying parameter R A in the message 1 matches the time-varying parameter in TokenTB or TokenTB2, if yes, step S43 is performed; otherwise, the process ends;
- Step S43 obtaining the verification result of the entity, if the entity is legally valid, executing step S44, otherwise ending;
- Step S44 Obtain the public key of the entity B, verify the signature of the entity B of the TokenBAl or the TokenBA2, and complete the authentication after the verification is passed.
- the signature verification operation TokenTB TokenTB2 trusted third party TTP may TokenTB TokenTB2 when the variable operating parameter R A matches the message after checking in the time varying parameter 1.
- the time varying parameter in the present invention may be a random number, a time stamp or a sequence number.
- the embodiment of the present invention also provides a system for implementing the above method, that is, a Tri-element Peer Authentication (TePA) system.
- TePA Tri-element Peer Authentication
- the structure of the system is as shown in FIG. 5, and includes: Entity 51, second entity 52 and third entity 53, wherein:
- the third entity 53 is a trusted third party of the first entity 51 and the second entity 52;
- the first entity 51 is configured to: send, to the second entity, a first message carrying a time-varying parameter, a self-identity identifier, and a token TokenAB; and receive the carrying token TokenTB and TokenBAl or the carrying token TokenTB2 sent by the second entity 52 and The fourth message of TokenBA2, verifying the signature of the third entity 53 of the token TokenTB TokenTB2, and verifying the time-varying parameter R A and Whether the time-varying parameters in the 73 ⁇ 4 ⁇ « 3 ⁇ 4 or 7bfe « 3 ⁇ 42 match, if they match, the verification result of the second entity 52 is obtained, and when the verification result indicates that the second entity 52 is legally valid, the second entity is obtained.
- the public key of 52 is verified by verifying the signature of the second entity 52 of the token TokenBAl TokenBA2 in the fourth message;
- the second entity 52 is configured to: after receiving the first message, send, to the third entity 53, a second message carrying a time varying parameter and a first entity 51 identity identity identity, and receiving
- the third entity 53 returns the carrying token TokenTB or the third message carrying the tokens TokenTB1 and TokenTB2, verifying the signature of the third entity 53 of the token TokenTB TokenTB1, and verifying the time-varying parameter 3 ⁇ 4 and TokenTB or Whether the time-varying parameter 3 ⁇ 4 in the TokenTB1 matches, if yes, the verification result of the first entity 51 is obtained, and when the verification result indicates that the first entity 51 is legally valid, the public key of the first entity 51 is obtained to verify a signature of the first entity 51 of the TokenAB in the first message, and sending the fourth message when the verification is passed;
- the third entity 53 is configured to: receive the second message, when the first message is completed When the validity of the entity 51 and the second entity 52 is verified, the third message is returned to the second entity 52.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer And Data Communications (AREA)
- Mobile Radio Communication Systems (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Information Transfer Between Computers (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Description
Claims
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP08861936A EP2224638A4 (en) | 2007-12-14 | 2008-12-09 | METHOD AND SYSTEM FOR BIDIRECTIONAL AUTHENTICATION OF ENTITY |
| JP2010537240A JP5323857B2 (ja) | 2007-12-14 | 2008-12-09 | エンティティ双方向認証の方法およびシステム |
| US12/808,049 US8417955B2 (en) | 2007-12-14 | 2008-12-09 | Entity bidirectional authentication method and system |
| KR1020107015407A KR101139547B1 (ko) | 2007-12-14 | 2008-12-09 | 엔티티 쌍방향 인증 방법 및 시스템 |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN200710199241.3 | 2007-12-14 | ||
| CN200710199241.3A CN101222328B (zh) | 2007-12-14 | 2007-12-14 | 一种实体双向鉴别方法 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2009076879A1 true WO2009076879A1 (zh) | 2009-06-25 |
Family
ID=39631927
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2008/073389 Ceased WO2009076879A1 (zh) | 2007-12-14 | 2008-12-09 | 一种实体双向鉴别方法和系统 |
Country Status (7)
| Country | Link |
|---|---|
| US (1) | US8417955B2 (zh) |
| EP (1) | EP2224638A4 (zh) |
| JP (1) | JP5323857B2 (zh) |
| KR (1) | KR101139547B1 (zh) |
| CN (1) | CN101222328B (zh) |
| RU (1) | RU2445741C1 (zh) |
| WO (1) | WO2009076879A1 (zh) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2013503513A (ja) * | 2009-08-28 | 2013-01-31 | 西安西▲電▼捷通▲無▼綫▲網▼絡通信股▲分▼有限公司 | オンライン第三者を導入するエンティティ認証方法 |
| JP2013503510A (ja) * | 2009-08-25 | 2013-01-31 | 西安西▲電▼捷通▲無▼▲線▼▲網▼▲絡▼通信股▲ふん▼有限公司 | 事前共有鍵に基づくネットワークセキュリティアクセス制御方法及びそのシステム |
| EP2472772A4 (en) * | 2009-09-30 | 2017-06-28 | China Iwncomm Co., Ltd | Method and system for entity public key acquiring, certificate validation and authentication by introducing an online credible third party |
| EP2472770A4 (en) * | 2009-08-28 | 2017-07-26 | China Iwncomm Co., Ltd | Entity bidirectional authentication method by introducing an online third party |
Families Citing this family (30)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101222328B (zh) | 2007-12-14 | 2010-11-03 | 西安西电捷通无线网络通信股份有限公司 | 一种实体双向鉴别方法 |
| US9443068B2 (en) * | 2008-02-20 | 2016-09-13 | Micheal Bleahen | System and method for preventing unauthorized access to information |
| CN101635624B (zh) * | 2009-09-02 | 2011-06-01 | 西安西电捷通无线网络通信股份有限公司 | 引入在线可信第三方的实体鉴别方法 |
| CN101925060A (zh) * | 2010-08-27 | 2010-12-22 | 西安西电捷通无线网络通信股份有限公司 | 一种资源受限网络的实体鉴别方法及系统 |
| CN102497273B (zh) * | 2011-12-27 | 2018-09-28 | 西安西电捷通无线网络通信股份有限公司 | 一种实体鉴别方法和装置及系统 |
| CN103312499B (zh) * | 2012-03-12 | 2018-07-03 | 西安西电捷通无线网络通信股份有限公司 | 一种身份认证方法及系统 |
| CN103944716B (zh) * | 2013-01-17 | 2017-08-25 | 上海贝尔股份有限公司 | 用户认证的方法和装置 |
| US8954546B2 (en) | 2013-01-25 | 2015-02-10 | Concurix Corporation | Tracing with a workload distributor |
| US20140025572A1 (en) * | 2013-01-25 | 2014-01-23 | Concurix Corporation | Tracing as a Service |
| US8997063B2 (en) | 2013-02-12 | 2015-03-31 | Concurix Corporation | Periodicity optimization in an automated tracing system |
| US8924941B2 (en) | 2013-02-12 | 2014-12-30 | Concurix Corporation | Optimization analysis using similar frequencies |
| US20130283281A1 (en) | 2013-02-12 | 2013-10-24 | Concurix Corporation | Deploying Trace Objectives using Cost Analyses |
| US20130219372A1 (en) | 2013-03-15 | 2013-08-22 | Concurix Corporation | Runtime Settings Derived from Relationships Identified in Tracer Data |
| US9575874B2 (en) | 2013-04-20 | 2017-02-21 | Microsoft Technology Licensing, Llc | Error list and bug report analysis for configuring an application tracer |
| US10657523B2 (en) * | 2013-08-16 | 2020-05-19 | Arm Ip Limited | Reconciling electronic transactions |
| US9292415B2 (en) | 2013-09-04 | 2016-03-22 | Microsoft Technology Licensing, Llc | Module specific tracing in a shared module environment |
| WO2015071778A1 (en) | 2013-11-13 | 2015-05-21 | Concurix Corporation | Application execution path tracing with configurable origin definition |
| CN104954130B (zh) * | 2014-03-31 | 2019-08-20 | 西安西电捷通无线网络通信股份有限公司 | 一种实体鉴别方法及装置 |
| US9331989B2 (en) * | 2014-10-06 | 2016-05-03 | Micron Technology, Inc. | Secure shared key sharing systems and methods |
| CN105577625B (zh) * | 2014-10-17 | 2019-04-23 | 西安西电捷通无线网络通信股份有限公司 | 基于预共享密钥的实体鉴别方法及装置 |
| US9648496B2 (en) | 2015-02-13 | 2017-05-09 | Yoti Ltd | Authentication of web content |
| US9858408B2 (en) | 2015-02-13 | 2018-01-02 | Yoti Holding Limited | Digital identity system |
| US10692085B2 (en) | 2015-02-13 | 2020-06-23 | Yoti Holding Limited | Secure electronic payment |
| US10594484B2 (en) | 2015-02-13 | 2020-03-17 | Yoti Holding Limited | Digital identity system |
| US9852285B2 (en) | 2015-02-13 | 2017-12-26 | Yoti Holding Limited | Digital identity |
| US9785764B2 (en) * | 2015-02-13 | 2017-10-10 | Yoti Ltd | Digital identity |
| US10853592B2 (en) | 2015-02-13 | 2020-12-01 | Yoti Holding Limited | Digital identity system |
| CN106571921B (zh) * | 2015-10-10 | 2019-11-22 | 西安西电捷通无线网络通信股份有限公司 | 一种实体身份有效性验证方法及其装置 |
| CN106572063B (zh) * | 2015-10-10 | 2019-10-29 | 西安西电捷通无线网络通信股份有限公司 | 一种多ttp参与的实体身份有效性验证方法及装置 |
| CN106571919B (zh) * | 2015-10-10 | 2019-10-29 | 西安西电捷通无线网络通信股份有限公司 | 一种实体身份有效性验证方法及其装置 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1345498A (zh) * | 1999-02-11 | 2002-04-17 | 诺基亚网络有限公司 | 一种鉴权方法 |
| US20030041240A1 (en) * | 2001-08-22 | 2003-02-27 | Jim Roskind | Single universal authentication system for internet services |
| US20070245414A1 (en) * | 2006-04-14 | 2007-10-18 | Microsoft Corporation | Proxy Authentication and Indirect Certificate Chaining |
| CN101222328A (zh) * | 2007-12-14 | 2008-07-16 | 西安西电捷通无线网络通信有限公司 | 一种实体双向鉴别方法 |
| CN101247223A (zh) * | 2008-03-06 | 2008-08-20 | 西安西电捷通无线网络通信有限公司 | 一种实用的基于可信第三方的实体双向鉴别方法 |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020157002A1 (en) * | 2001-04-18 | 2002-10-24 | Messerges Thomas S. | System and method for secure and convenient management of digital electronic content |
| AU2003208206A1 (en) * | 2002-03-01 | 2003-09-16 | Research In Motion Limited | System and method for providing secure message signature status and trust status indication |
| KR20040108774A (ko) | 2002-05-09 | 2004-12-24 | 마츠시타 덴끼 산교 가부시키가이샤 | 인증 통신시스템, 인증 통신장치 및 인증 통신방법 |
| CN1191696C (zh) * | 2002-11-06 | 2005-03-02 | 西安西电捷通无线网络通信有限公司 | 一种无线局域网移动设备安全接入及数据保密通信的方法 |
| AU2004237046B2 (en) | 2003-05-02 | 2008-02-28 | Giritech A/S | Pervasive, user-centric network security enabled by dynamic datagram switch and an on-demand authentication and encryption scheme through mobile intelligent data carriers |
| EP1601154A1 (en) * | 2004-05-28 | 2005-11-30 | Sap Ag | Client authentication using a challenge provider |
| CN1260909C (zh) | 2004-09-30 | 2006-06-21 | 西安西电捷通无线网络通信有限公司 | 一种增强无线城域网安全性的方法 |
| BRPI0419162A (pt) | 2004-10-29 | 2007-12-11 | Thomson Licensing | canal seguro e autenticado |
| CN100544249C (zh) | 2004-10-29 | 2009-09-23 | 大唐移动通信设备有限公司 | 移动通信用户认证与密钥协商方法 |
| CN100389555C (zh) * | 2005-02-21 | 2008-05-21 | 西安西电捷通无线网络通信有限公司 | 一种适合有线和无线网络的接入认证方法 |
| CN100550725C (zh) * | 2005-06-17 | 2009-10-14 | 中兴通讯股份有限公司 | 一种用户与应用服务器协商共享密钥的方法 |
| CN100495963C (zh) * | 2006-09-23 | 2009-06-03 | 西安西电捷通无线网络通信有限公司 | 一种公钥证书状态的获取及验证方法 |
| US20080235513A1 (en) * | 2007-03-19 | 2008-09-25 | Microsoft Corporation | Three Party Authentication |
-
2007
- 2007-12-14 CN CN200710199241.3A patent/CN101222328B/zh active Active
-
2008
- 2008-12-09 RU RU2010128379/08A patent/RU2445741C1/ru active
- 2008-12-09 US US12/808,049 patent/US8417955B2/en active Active
- 2008-12-09 EP EP08861936A patent/EP2224638A4/en not_active Ceased
- 2008-12-09 JP JP2010537240A patent/JP5323857B2/ja active Active
- 2008-12-09 KR KR1020107015407A patent/KR101139547B1/ko active Active
- 2008-12-09 WO PCT/CN2008/073389 patent/WO2009076879A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1345498A (zh) * | 1999-02-11 | 2002-04-17 | 诺基亚网络有限公司 | 一种鉴权方法 |
| US20030041240A1 (en) * | 2001-08-22 | 2003-02-27 | Jim Roskind | Single universal authentication system for internet services |
| US20070245414A1 (en) * | 2006-04-14 | 2007-10-18 | Microsoft Corporation | Proxy Authentication and Indirect Certificate Chaining |
| CN101222328A (zh) * | 2007-12-14 | 2008-07-16 | 西安西电捷通无线网络通信有限公司 | 一种实体双向鉴别方法 |
| CN101247223A (zh) * | 2008-03-06 | 2008-08-20 | 西安西电捷通无线网络通信有限公司 | 一种实用的基于可信第三方的实体双向鉴别方法 |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2013503510A (ja) * | 2009-08-25 | 2013-01-31 | 西安西▲電▼捷通▲無▼▲線▼▲網▼▲絡▼通信股▲ふん▼有限公司 | 事前共有鍵に基づくネットワークセキュリティアクセス制御方法及びそのシステム |
| US8646055B2 (en) | 2009-08-25 | 2014-02-04 | China Iwncomm Co., Ltd. | Method and system for pre-shared-key-based network security access control |
| JP2013503513A (ja) * | 2009-08-28 | 2013-01-31 | 西安西▲電▼捷通▲無▼綫▲網▼絡通信股▲分▼有限公司 | オンライン第三者を導入するエンティティ認証方法 |
| US8763100B2 (en) | 2009-08-28 | 2014-06-24 | China Iwncomm Co., Ltd. | Entity authentication method with introduction of online third party |
| EP2472770A4 (en) * | 2009-08-28 | 2017-07-26 | China Iwncomm Co., Ltd | Entity bidirectional authentication method by introducing an online third party |
| EP2472772A4 (en) * | 2009-09-30 | 2017-06-28 | China Iwncomm Co., Ltd | Method and system for entity public key acquiring, certificate validation and authentication by introducing an online credible third party |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20100091257A (ko) | 2010-08-18 |
| RU2445741C1 (ru) | 2012-03-20 |
| JP2011507363A (ja) | 2011-03-03 |
| US20100262832A1 (en) | 2010-10-14 |
| RU2010128379A (ru) | 2012-01-20 |
| EP2224638A4 (en) | 2013-03-27 |
| US8417955B2 (en) | 2013-04-09 |
| JP5323857B2 (ja) | 2013-10-23 |
| CN101222328A (zh) | 2008-07-16 |
| EP2224638A1 (en) | 2010-09-01 |
| KR101139547B1 (ko) | 2012-04-27 |
| CN101222328B (zh) | 2010-11-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2009076879A1 (zh) | 一种实体双向鉴别方法和系统 | |
| KR101254868B1 (ko) | 고속 핸드오프를 지원하는 엔티티 양방향 신원 방법 | |
| RU2458481C2 (ru) | Способ и система двусторонней идентификации объекта на основе доверенной третьей стороны | |
| US8510565B2 (en) | Bidirectional entity authentication method based on the credible third party | |
| CN101364876B (zh) | 一种实现实体的公钥获取、证书验证及鉴别的方法 | |
| WO2011022918A1 (zh) | 一种引入在线第三方的实体双向鉴别方法 | |
| KR101405509B1 (ko) | 온라인 제 3 신뢰 기관을 도입함으로써 엔티티 공개키 획득, 인증서 검증 및 인증을 수행하는 방법 및 시스템 | |
| CN101645776B (zh) | 一种引入在线第三方的实体鉴别方法 | |
| WO2011026296A1 (zh) | 引入在线可信第三方的实体鉴别方法 | |
| CN118972065A (zh) | 一种证书管理方法及相关装置 | |
| WO2011075906A1 (zh) | 一种实现实体的公钥获取、证书验证及鉴别的方法 | |
| WO2011075907A1 (zh) | 一种实现实体的公钥获取、证书验证及双向鉴别的方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 08861936 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2010537240 Country of ref document: JP Ref document number: 12808049 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2008861936 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 20107015407 Country of ref document: KR Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2010128379 Country of ref document: RU |