发明名称 METHOD AND MEANS FOR COMBINING AND MANAGING PERSONAL VERIFICATION AND MESSAGE AUTHENTICATION ENCRYPTIONS FOR NETWORK
摘要 The method and means of transmitting a user's transaction message to a destination node in a computer-secured network operates on the message, and a sequence number that is unique to the transaction message to form a message authentication code in combination with the user's personal identification number. The message authentication code is encrypted with a generated random number and a single session encryption key which also encrypts the user's personal identification number. An intermediate node may receive the encryptions to reproduce the personal identification number that is then used to encrypt the received message and sequence number to produce the random number and a message authentication code for comparison with a decrypted message authentication code. Upon favorable comparison, the random number and the message authentication code are encrypted with a second session encryption key to produce an output code that is transmitted to the destination node along with an encrypted personal identification number. There, the received encryptions are decrypted using the second session key to provide the personal identification number for use in encrypting the message and sequence number to produce a message authentication code for comparison with a decrypted message authentication code. Upon favorable comparison, the transaction is completed and a selected portion of the decrypted random number is returned to the originating node for comparison with the corresponding portion of the random number that was generated there. Upon unfavorable comparison at the destination node or at an intermediate node, a different portion of the decrypted random number is returned to the originating node for comparison with the corresponding portion of the random number that was generated there. The comparisons at the originating node provide an unambiguous indication of the completion or non-completion of the transaction at the destination node.
申请公布号 CA1340092(C) 申请公布日期 1998.10.20
申请号 CA19870545127 申请日期 1987.08.21
申请人 TANDEM COMPUTERS INCORPORATED 发明人 ATALLA, MARTIN M.;HOPKINS, W. DALE
分类号 H04L9/28;(IPC1-7):H04L9/28 主分类号 H04L9/28
代理机构 代理人
主权项
地址