发明名称 Revocation of credentials in secret handshake protocols
摘要 <p>According to a general aspect, a computer-implemented method for a first user to verify an association with a second user through a secret handshake protocol includes maintaining information about a reusable identification handle for the first user, where the information about the reusable identification handle is provided by a trusted third party, maintaining information about a reusable credential for the first user, where the information about the reusable credential is provided by a trusted third party, and maintaining information about a matching reference for verifying an association with another user, where the information about the matching reference is provided by a trusted third party. Information based on the reusable identification handle and based on the reusable credential is transmitted to a potential peer. First information based on a reusable identification handle for the second user is received, and second information based on a reusable credential for the second user is received. A first comparison of a combination of the first information and the second information is performed with the matching reference to determine whether the second user's credentials match the first users matching reference. A second comparison of the first information with information published on a revocation list is performed to determine whether the second user's credentials have been revoked from usage. Based on the first comparison and the second comparison, a determination is made whether or not to verify the association of second user with the first user.</p>
申请公布号 EP2200216(A1) 申请公布日期 2010.06.23
申请号 EP20080291221 申请日期 2008.12.19
申请人 SAP AG 发明人 BEZZI, MICHELE;MONTAGNON, GILLES;SHORT, STUART;SORNIOTTI, ALESSANDRO;TRABELSI, SLIM
分类号 H04L9/32;H04L9/30 主分类号 H04L9/32
代理机构 代理人
主权项
地址