摘要 |
A method and device for device association. A user (150) enters (200) login and password on a first device (110) that searches (210) for reachable devices (120, 130). The first device (110) asks (220) the reachable devices (120, 130) if they know the login, preferably by sending a salted hash of the login. The devices that know the login respond positively and the first device (110) lists (230) the responding devices. The first device (110) then successively performs (240) Secure Remote Authentication (SRP) with each device on the list until an authentication succeeds or there are no further devices on the list. The SRP authentication makes sure that the first device (110) knows the login and that the other device knows a password verifier without transmitting any knowledge that allows recuperation of this info by an eavesdropper. The authenticated devices then establish (260) a secure channel over which a community secret key is transferred (280), and the first device also calculates and stores (270) the password verifier.
|