发明名称 A SCALABLE AUTHENTICATION SYSTEM
摘要 <p>Disclosed is a key management method for administering a token with an administrative server and an authentication server wherein a set of keys stored therein in use differs so that at least a mutually exclusive key is stored in each of the token, the administrative server or the authentication server, the method comprising the steps of: the token transmitting an identity proxy ID 1 encrypted with an encryption key Key 1; the administrative server generating data Key 1a and Key 1b from Key 1 stored therein, whereby Key 1a and Key 1b can be used in conjunction to derive Key 1 but not separately; the administrative server generating an identity proxy ID 2 and an encryption key Key 2, whereby the administrative server records a token profile comprising an association information among ID 2, Key 1b and Key 2; the administrative server communicating ID 2, Key 1a and Key 2 to the token and the token storing ID 2, Key 1a and Key 2 wherein Key 2 is stored therein encrypted with Key 1; the administrative server communicating the token profile to the authentication server and deleting Key 1b and Key 2 from its records thereafter; the authentication server requesting ID 2 from the token and the token transmitting ID 2 thereto; the authentication server identifying Key 1b and Key 2 associated with the transmitted ID 2 and generating a new encryption key Key 3; the authentication server recording Key 3's association with ID 2 in the token profile and communicating Key 3 to the token; and the token storing Key 3 therein encrypted with Key 2, whereby the administrative server stores ID 1, ID 2 and Key 1, the authentication server stores ID 2, Key 1b, Key 2, and Key 3, and the token stores ID 1, ID 2, Key 1a, Key 2, and Key 3, wherein the token stores Key 2 encrypted with Key 1 and stores Key 3 encrypted with Key 2 therein.</p>
申请公布号 WO2013132224(A3) 申请公布日期 2013.12.05
申请号 WO2013GB50341 申请日期 2013.02.14
申请人 DISTRIBUTED MANAGEMENT SYSTEMS LTD 发明人 PHILIPSZ, BASIL
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址