发明名称 PROTECTING ONE-TIME-PASSWORDS AGAINST MAN-IN-THE-MIDDLE ATTACKS
摘要 To authenticate a user having an associated asymmetric crypto-key having a private/public key pair (D, E) based on a one-time-password, the user partially signs a symmetric session key with the first portion D1 of the private key D. The authenticating entity receives the partially signed symmetric session key via the network and . completes the signature with the second private key portion D2 to recover the symmetric session key. The user also encrypts a one-time-password with the symmetric session key. The authenticating entity also receives the encrypted one-time- password via the network, and decrypts the received encrypted one-time-password with the recovered symmetric session key to authenticate the user.
申请公布号 WO2006119184(A3) 申请公布日期 2007.11.29
申请号 WO2006US16622 申请日期 2006.05.02
申请人 TRICIPHER, INC. 发明人 GANESAN, RAVI;SANDHU, RAVINDERPAL, SINGH;COTTRELL, ANDREW, PAUL;SCHOPPERT, BRETT, JASON;BELLARE, MIHIR
分类号 H04L29/00 主分类号 H04L29/00
代理机构 代理人
主权项
地址