发明名称 Data processing system with verification of authenticity of cryptographic algorithms according to the challenge/response principle
摘要 <p>A data processing system has a security infrastructure, including a first cryptographic support facility, a security service for user data, including a further cryptographic support facility, and a number of cryptographic algorithms, usable by said cryptographic support facilities. In order to protect against a user replacing weak algorithms intended for the protection of data with strong algorithms intended for use by the security infrastructure, a challenge/response mechanism is provided, which enables the cryptographic support facilities to verify authenticity of the algorithms. The challenge/response mechanism is as follows. First, the cryptographic support facility sends a challenge to the algorithm. The algorithm then generates a response by applying a cryptographic function to the challenge, and returns the response to the cryptographic support facility. The cryptographic support facility then checks whether the response has an expected value. Only upon successful authentication does the algorithm reveal a pointer to a function table. The pointer is encrypted under a shared secret key to prevent an "attacker in the middle" attack. <IMAGE></p>
申请公布号 EP0711051(A1) 申请公布日期 1996.05.08
申请号 EP19950306821 申请日期 1995.09.27
申请人 INTERNATIONAL COMPUTERS LIMITED 发明人 PRESS, JAMES
分类号 H04L9/32;(IPC1-7):H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项
地址