发明名称 Authentication of user computers
摘要 In an approach for authenticating a user computer, connectable to a mobile network, a computer retrieves an attribute credential, the attribute credential certifying a set of user attributes and a device identifier for identifying the user computer to the mobile network. The computer requests a location credential, the location credential certifying a device identifier and location data indicating a current location of the user computer determined by the mobile network. Additionally, the computer produces an authentication token comprising the attribute credential, the location credential, the location data, and a proof for proving that the device identifier in the attribute credential equals the device identifier in the location credential. Furthermore, the computer sends the authentication token for authentication.
申请公布号 US9578505(B2) 申请公布日期 2017.02.21
申请号 US201514692441 申请日期 2015.04.21
申请人 International Business Machines Corporation 发明人 Buhler Peter;Camenisch Jan L.;Ortiz-Yepes Diego A.;Preiss Franz-Stefan
分类号 H04L29/06;H04W12/06 主分类号 H04L29/06
代理机构 代理人 Carpenter Maeve
主权项 1. A computer-implemented method for authenticating a user computer, connectable to a mobile network, the method comprising: retrieving, by one or more computing devices, an attribute credential, the attribute credential certifying a set of user attributes and a device identifier for identifying the user computer to the mobile network; requesting, by one or more computing devices, a location credential, the location credential certifying a device identifier and location data indicating a current location of the user computer determined by the mobile network; producing, by one or more computing devices, an authentication token comprising the attribute credential, the location credential, the location data and a proof for proving that the device identifier in the attribute credential equals the device identifier in the location credential; sending, by one or more computing devices, the authentication token for authentication of the user computer; and producing, by one or more computing devices, a blinded attribute credential by randomized blinding of the attribute credential, wherein the authentication token includes the blinded attribute credential and wherein the proof verifies possession by the user computer of the attribute credential in the blinded attribute credential.
地址 Armonk NY US