Nothing Special   »   [go: up one dir, main page]

MX2018007332A - Metodo, dispositivo, servidor y sistema para autenticar a un usuario. - Google Patents

Metodo, dispositivo, servidor y sistema para autenticar a un usuario.

Info

Publication number
MX2018007332A
MX2018007332A MX2018007332A MX2018007332A MX2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A
Authority
MX
Mexico
Prior art keywords
server
cryptogram
vector
data
user
Prior art date
Application number
MX2018007332A
Other languages
English (en)
Inventor
Michel Desjardins Jean-
LATHIERE Marie
Original Assignee
Gemalto Sa
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Gemalto Sa filed Critical Gemalto Sa
Publication of MX2018007332A publication Critical patent/MX2018007332A/es

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3827Use of message hashing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0625Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation with splitting of the data block into left and right halves, e.g. Feistel based algorithms, DES, FEAL, IDEA or KASUMI
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Storage Device Security (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

La invención se refiere a un método 40 para autenticar a un usuario. De acuerdo con la invención, el método comprende los siguientes pasos. Un dispositivo 12 tiene acceso 41 a una clave y al menos un vector inicial. Al menos un vector inicial es previamente generado utilizando un primer algoritmo, al menos un vector de referencia y datos de autenticación de usuario de referencia. Al menos el vector de referencia es previamente generado sin utilizar los datos de autenticación de usuario de referencia. El dispositivo tiene acceso a los datos 42 y a datos de autenticación de usuario proporcionado 46. El dispositivo genera 48 al menos un vector intermedio utilizando un segundo algoritmo, al menos un vector inicial y los datos de autenticación de usuario proporcionados. El dispositivo genera 410 un criptograma utilizando un tercer algoritmo 22, la clave, al menos un vector intermedio y los datos. Un servidor 18 recibe una solicitud 414 para autenticar a un usuario acompañada por el criptograma y los datos. El servidor tiene acceso 416 a la clave y al menos a un vector de referencia. El servidor genera 418 un criptograma de referencia utilizando el tercer algoritmo, la clave, al menos un vector de referencia y los datos. El servidor verifica 420 si el criptograma de referencia coincide o no con el criptograma. Si el criptograma de referencia coincide o no coincide con el criptograma, entonces el servidor autentica 422 o no autentica 424 al usuario respectivamente. La invención también se relaciona con un dispositivo, servidor y método correspondientes.
MX2018007332A 2015-12-16 2016-10-20 Metodo, dispositivo, servidor y sistema para autenticar a un usuario. MX2018007332A (es)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
EP15307028.9A EP3182315A1 (en) 2015-12-16 2015-12-16 Method, device, server and system for authenticating a user
PCT/EP2016/075258 WO2017102142A1 (en) 2015-12-16 2016-10-20 Method, device, server and system for authenticating a user

Publications (1)

Publication Number Publication Date
MX2018007332A true MX2018007332A (es) 2018-08-24

Family

ID=55070809

Family Applications (1)

Application Number Title Priority Date Filing Date
MX2018007332A MX2018007332A (es) 2015-12-16 2016-10-20 Metodo, dispositivo, servidor y sistema para autenticar a un usuario.

Country Status (10)

Country Link
US (1) US20190266603A1 (es)
EP (2) EP3182315A1 (es)
KR (1) KR20180086436A (es)
AU (2) AU2016373702A1 (es)
BR (1) BR112018010287B1 (es)
ES (1) ES2896274T3 (es)
MX (1) MX2018007332A (es)
PL (1) PL3391266T3 (es)
SG (2) SG10202005715QA (es)
WO (1) WO2017102142A1 (es)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11075910B2 (en) * 2017-08-10 2021-07-27 Patroness, LLC Secure systems architecture for integrated motorized mobile systems
US20190228410A1 (en) * 2018-01-24 2019-07-25 Mastercard International Incorporated Method and system for generating and using contextual cryptograms for proximity and e-commerce payment
CA3138670C (en) * 2018-08-21 2023-04-25 Visa International Service Association System, method, and computer program product for mobile device transactions
CN110929238B (zh) * 2019-10-29 2022-02-01 维沃移动通信有限公司 一种信息处理方法及设备
US12048658B1 (en) 2020-03-06 2024-07-30 Luci Mobility, Inc. Systems and methods for pressure injury mitigation
KR20210133471A (ko) 2020-04-29 2021-11-08 삼성전자주식회사 전자 장치 및 그의 제어 방법
EP3937036A1 (en) * 2020-07-09 2022-01-12 Thales DIS France SA Method, user device, verifier device, server and system for authenticating user data while preserving user privacy
CN112055019B (zh) * 2020-09-03 2022-09-27 深圳市百富智能新技术有限公司 一种建立通信信道的方法及用户终端

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
BRPI0808238A2 (pt) * 2007-03-14 2014-07-29 Dexrad Proprietary Aparelho de identificação, sistema de identificação e autenticação e método para identificar uma pessoa"
US10354321B2 (en) * 2009-01-22 2019-07-16 First Data Corporation Processing transactions with an extended application ID and dynamic cryptograms
DE102009055947A1 (de) * 2009-11-30 2011-06-01 Christoph Busch Authentisierte Übertragung von Daten
AU2014321178A1 (en) * 2013-09-20 2016-04-14 Visa International Service Association Secure remote payment transaction processing including consumer authentication
KR102325361B1 (ko) * 2013-12-02 2021-11-12 마스터카드 인터내셔날, 인코포레이티드 보안 요소 없이 모바일 장치들에게 원격 알림 서비스 메시지를 보안 전송하는 방법 및 시스템
AU2016220072B2 (en) * 2015-02-17 2020-01-02 Visa International Service Association Secure authentication of user and mobile device
US10360558B2 (en) * 2015-03-17 2019-07-23 Ca, Inc. Simplified two factor authentication for mobile payments
US20170032370A1 (en) * 2015-07-27 2017-02-02 Mastercard International Incorporated Electronic payment transactions using machine readable code without requiring online connection

Also Published As

Publication number Publication date
US20190266603A1 (en) 2019-08-29
SG11201803830PA (en) 2018-06-28
AU2020202106B2 (en) 2021-11-04
BR112018010287A2 (pt) 2018-11-27
PL3391266T3 (pl) 2022-01-24
ES2896274T3 (es) 2022-02-24
KR20180086436A (ko) 2018-07-31
WO2017102142A1 (en) 2017-06-22
BR112018010287B1 (pt) 2023-12-19
SG10202005715QA (en) 2020-07-29
AU2020202106A1 (en) 2020-04-09
EP3391266A1 (en) 2018-10-24
EP3391266B1 (en) 2021-08-18
EP3182315A1 (en) 2017-06-21
AU2016373702A1 (en) 2018-06-14

Similar Documents

Publication Publication Date Title
MX2018007332A (es) Metodo, dispositivo, servidor y sistema para autenticar a un usuario.
PH12018501983A1 (en) Method and system for user authentication with improved security
WO2018071191A3 (en) Method and system for data security based on quantum communication and trusted computing
MX2016014461A (es) Aprovisionamiento de licencias de gestion de derechos digitales (drm) en un dispositivo cliente que utiliza un servidor de actualizaciones.
AU2018256309A1 (en) Systems and methods for device verification and authentication
TW201612787A (en) Network authentication method for secure electronic transactions
WO2016175914A3 (en) Transaction signing utilizing asymmetric cryptography
GB201213279D0 (en) Identity generation mechanism
WO2016167932A3 (en) Authentication of a client device based on entropy from a server or other device
GB201221433D0 (en) A method and system of providing authentication of user access to a computer resource on a mobile device
MX366390B (es) Gestion de claves inalambrica para autenticacion.
EA201790385A1 (ru) Способ цифровой подписи электронного файла и способ аутентификации
GB2533727A (en) Registry apparatus, agent device, application providing apparatus and corresponding methods
WO2014151730A3 (en) Identity escrow management for minimal disclosure credentials
WO2016126052A3 (ko) 인증 방법 및 시스템
JP2016512675A5 (es)
MX355189B (es) Autentificacion de usuario.
IN2014MU00771A (es)
WO2015030903A3 (en) Image based key derivation function
PH12016501786A1 (en) Tag management system, tag management method, information provision system, and information provision method, as well as devices and tag used therefor
WO2010060704A3 (en) Method and system for token-based authentication
NZ701459A (en) Systems and methods for secure processing with embedded cryptographic unit
EP4274286A3 (en) Secure login with authentication based on a visual representation of data
SG10201810422SA (en) Dual channel identity authentication
AU2017261844A1 (en) Authenticating a user