发明名称 Challenge-response authentication using a masked response value
摘要 Challenge-response authentication protocols are disclosed herein, including systems and methods for a first device to authenticate a second device. In one embodiment, the following operations are performed by the first device: (a) sending to the second device: (i) a challenge value corresponding to an expected response value known by the first device, and (ii) a hiding value; (b) receiving from the second device a masked response value; (c) obtaining an expected masked response value from the expected response value and the hiding value; and (d) determining whether the expected masked response value matches the masked response value received from the second device. The operations from the perspective of the second device are also disclosed, which in some embodiments include computing the masked response value using the challenge value, the hiding value, and secret information known to the second device.
申请公布号 US9369290(B2) 申请公布日期 2016.06.14
申请号 US201213691101 申请日期 2012.11.30
申请人 Certicom Corp. 发明人 Lambert Robert John
分类号 H04L9/32;H04L9/28 主分类号 H04L9/32
代理机构 Fish & Richardson P.C. 代理人 Fish & Richardson P.C.
主权项 1. A method for a second device to be authenticated by a first device, the method performed by the second device and comprising: the second device receiving from the first device a challenge value and a hiding value; the second device computing a masked response value using the challenge value, the hiding value, and secret information known to the second device; the second device sending to the first device the masked response value for comparison to an expected masked response value, wherein the secret information is not known to the first device, the expected masked response value is computed by the first device using the hiding value and an expected response value known by the first device and corresponding to the challenge value, the challenge value and the expected response value are loaded into memory of the first device at the time of manufacture of the first device; and repeating the receiving, computing, and sending, when authentication of the second device is performed again, using a different hiding value received from the first device and the same challenge value received from the first device.
地址 Mississauga, Ontario CA