发明名称 Revocation of credentials in secret handshake protocols
摘要 According to a general aspect, a computer-implemented method for a first user to verify an association with a second user through a secret handshake protocol includes maintaining information about a reusable identification handle for the first user, where the information about the reusable identification handle is provided by a trusted third party, maintaining information about a reusable credential for the first user, where the information about the reusable credential is provided by a trusted third party, and maintaining information about a matching reference for verifying an association with another user, where the information about the matching reference is provided by a trusted third party. Information based on the reusable identification handle and based on the reusable credential is transmitted to a potential peer. First information based on a reusable identification handle for the second user is received, and second information based on a reusable credential for the second user is received. A first comparison of a combination of the first information and the second information is performed with the matching reference to determine whether the second user's credentials match the first users matching reference. A second comparison of the first information with information published on a revocation list is performed to determine whether the second user's credentials have been revoked from usage. Based on the first comparison and the second comparison, a determination is made whether or not to verify the association of second user with the first user.
申请公布号 EP2200216(B1) 申请公布日期 2014.11.26
申请号 EP20080291221 申请日期 2008.12.19
申请人 SAP SE 发明人 BEZZI, MICHELE;MONTAGNON, GILLES;SHORT, STUART;SORNIOTTI, ALESSANDRO;TRABELSI, SLIM
分类号 H04L9/32;H04L9/30 主分类号 H04L9/32
代理机构 代理人
主权项
地址