ES2723224T3 - Método de protección de un depósito de claves asistido por servidor - Google Patents

Método de protección de un depósito de claves asistido por servidor Download PDF

Info

Publication number
ES2723224T3
ES2723224T3 ES13799010T ES13799010T ES2723224T3 ES 2723224 T3 ES2723224 T3 ES 2723224T3 ES 13799010 T ES13799010 T ES 13799010T ES 13799010 T ES13799010 T ES 13799010T ES 2723224 T3 ES2723224 T3 ES 2723224T3
Authority
ES
Spain
Prior art keywords
server
pin
code
access
passphrase
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
ES13799010T
Other languages
English (en)
Inventor
Michael Webster
Seppo Pohja
Timo Palo
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Thales DIS France SA
Original Assignee
Thales DIS France SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Thales DIS France SA filed Critical Thales DIS France SA
Application granted granted Critical
Publication of ES2723224T3 publication Critical patent/ES2723224T3/es
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)
  • Lock And Its Accessories (AREA)
  • Computer And Data Communications (AREA)

Abstract

Método para acceder a un almacén de datos (DS) previamente bloqueado usando una frase de contraseña (PP) desde un dispositivo (UD), incluyendo dicho método los pasos preliminares de: - para el dispositivo (UD), solicitar (P0) al usuario que introduzca un código personal (PIN) en el dispositivo (UD); - para el dispositivo (UD), calcular (P1) una primera función (F1) de al menos el código personal (PIN); - para el dispositivo (UD), enviar (P2), para el almacenamiento (P3), dicha primera función (F1) a un servidor (SV) que conoce la frase de contraseña (PP); dicho método comprende además los siguientes pasos, cuando el usuario solicita acceso al almacén de datos (DS): - para el dispositivo, solicitar (E0) al usuario que introduzca el código personal (PIN), - para el dispositivo, generar (E2) un código de acceso (AC) aplicando dicha primera función (F1) a al menos el código personal (PIN) introducido; - para el dispositivo, enviar (E3), al servidor (SV), al menos un identificador (IDUD) del dispositivo (UD) y el código de acceso (AC); - para el servidor (SV), comparar (E4) el código de acceso (AC) con la primera función preliminar recibida; - para el servidor (SV), si el código de acceso (AC) es correcto, devolver la frase de contraseña (PP) al dispositivo (UD); - para el dispositivo (DV), desbloquear el almacén de datos (DS) usando la frase de contraseña (PP) recibida en combinación con el código personal (PIN) introducido.
ES13799010T 2012-12-10 2013-11-28 Método de protección de un depósito de claves asistido por servidor Active ES2723224T3 (es)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
EP12306551.8A EP2741444A1 (en) 2012-12-10 2012-12-10 Method for server assisted keystore protection
PCT/EP2013/074998 WO2014090590A1 (en) 2012-12-10 2013-11-28 Method for server assisted keystore protection

Publications (1)

Publication Number Publication Date
ES2723224T3 true ES2723224T3 (es) 2019-08-22

Family

ID=47709781

Family Applications (1)

Application Number Title Priority Date Filing Date
ES13799010T Active ES2723224T3 (es) 2012-12-10 2013-11-28 Método de protección de un depósito de claves asistido por servidor

Country Status (4)

Country Link
US (1) US9768960B2 (es)
EP (2) EP2741444A1 (es)
ES (1) ES2723224T3 (es)
WO (1) WO2014090590A1 (es)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10091190B2 (en) 2015-12-11 2018-10-02 International Business Machines Corporation Server-assisted authentication
WO2018232442A1 (en) * 2017-06-23 2018-12-27 Australian Postal Corporation Method and system for providing secure access to secret information
US10614650B2 (en) * 2017-09-20 2020-04-07 Bradford A. Minsley System and method for managing distributed encrypted combination over-locks from a remote location
CN112968910B (zh) * 2021-03-30 2022-12-27 中国建设银行股份有限公司 一种防重放攻击方法和装置

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5694471A (en) * 1994-08-03 1997-12-02 V-One Corporation Counterfeit-proof identification card
US8225089B2 (en) * 1996-12-04 2012-07-17 Otomaku Properties Ltd., L.L.C. Electronic transaction systems utilizing a PEAD and a private key
US6742129B1 (en) * 1999-12-08 2004-05-25 Carrier Corporation Software security mechanism
US7149311B2 (en) 2001-02-08 2006-12-12 Lucent Technologies Inc. Methods and apparatus for providing networked cryptographic devices resilient to capture
US7895443B2 (en) * 2002-11-05 2011-02-22 Safenet, Inc. Secure authentication using hardware token and computer fingerprint
US7210166B2 (en) * 2004-10-16 2007-04-24 Lenovo (Singapore) Pte. Ltd. Method and system for secure, one-time password override during password-protected system boot
US20070005963A1 (en) * 2005-06-29 2007-01-04 Intel Corporation Secured one time access code
US7873835B2 (en) * 2006-03-31 2011-01-18 Emc Corporation Accessing data storage devices
CA2692083C (en) * 2007-06-26 2017-06-06 G3-Vision Limited Authentication system and method
US8272038B2 (en) * 2008-05-19 2012-09-18 International Business Machines Corporation Method and apparatus for secure authorization

Also Published As

Publication number Publication date
WO2014090590A1 (en) 2014-06-19
EP2741444A1 (en) 2014-06-11
US20150318992A1 (en) 2015-11-05
EP2929649B1 (en) 2018-11-28
EP2929649A1 (en) 2015-10-14
US9768960B2 (en) 2017-09-19

Similar Documents

Publication Publication Date Title
EP4271016A3 (en) Enhanced authentication based on secondary device interactions
PH12018502160A1 (en) Systems and methods for secure storage of user information in a user profile
MX2016010086A (es) Metodo y sistema para generar una llave de almacenamiento avanzada en un dispositivo movil sin elementos de seguridad.
BR112015022767A2 (pt) espaço de armazenamento de rede codificado
BR112014004858A2 (pt) método para um backup seguro e recuperação de dados de configuração de um dispositivo de usuário em uma extremidade, e dispositivo utilizando o método
NZ714230A (en) System and methods for encrypting data
CO7101199A2 (es) Administración de objetos en una cadena de suministro, mediante el empleo de un identificador seguro
MX383704B (es) Método, dispositivo, servidor y sistema para autenticar a un usuario.
NZ725656A (en) System and method for medical device identifier
BR112016014106A2 (pt) Método para intensificar a segurança de um dispositivo de comunicação, e, dispositivo de comunicação
ES2722533T3 (es) Sistema y método para gestionar la instalación de un paquete de aplicación que requiera un acceso a permisos de riesgo alto
WO2014179145A3 (en) Drive level encryption key management in a distributed storage system
CL2018003279A1 (es) Uso de región aislada segura basada en hardware para prevenir la piratería y el engaño en dispositivos electrónicos
BR112016024453A8 (pt) método implementado por computador para gerenciar conjunto de dados, sistema de computação e meio de armazenamento legível por computador físico
AR102007A1 (es) Sistema, método implementado por computadora y dispositivo informático de autenticación para acceder a recursos en base a desafíos
MX369234B (es) Metodo y dispositivo de administracion de datos confidenciales, y metodo y sistema de autenticacion de seguridad.
BR112017003018A2 (pt) fornecimento seguro de uma credencial de autenticação
BR112013001728A2 (pt) métodos para criptografar um valor introduzido em um dispositivo de usuário, para verificar um valor comunicado a um sistema de autenticação via uma rede de comunicações, e para comunicar um valor introduzido em um dispositivo de usuário a um sistema de autenticação via uma rede de comunicações, dispositivo de usuário, sistema, software, e, meio legível por computador.
AR097524A1 (es) Encriptación de datos y tarjeta inteligente que almacena datos encriptados
BR112017005824A2 (pt) método, e, dispositivo móvel.
MX2016002141A (es) Acceso habilitado a datos.
GB2538927A (en) Methods and apparatus to identify media using hash keys
AR101574A1 (es) Métodos y nodos para la correspondencia del abono con la identidad de usuario del servicio
GB201307395D0 (en) Systems and methods for storing and verifying security information
PH12014500964A1 (en) Security mechanism for external code