MX2018007332A - Metodo, dispositivo, servidor y sistema para autenticar a un usuario. - Google Patents

Metodo, dispositivo, servidor y sistema para autenticar a un usuario.

Info

Publication number
MX2018007332A
MX2018007332A MX2018007332A MX2018007332A MX2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A
Authority
MX
Mexico
Prior art keywords
server
cryptogram
vector
data
user
Prior art date
Application number
MX2018007332A
Other languages
English (en)
Inventor
Michel Desjardins Jean-
LATHIERE Marie
Original Assignee
Gemalto Sa
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Gemalto Sa filed Critical Gemalto Sa
Publication of MX2018007332A publication Critical patent/MX2018007332A/es

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3827Use of message hashing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0625Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation with splitting of the data block into left and right halves, e.g. Feistel based algorithms, DES, FEAL, IDEA or KASUMI
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash

Abstract

La invención se refiere a un método 40 para autenticar a un usuario. De acuerdo con la invención, el método comprende los siguientes pasos. Un dispositivo 12 tiene acceso 41 a una clave y al menos un vector inicial. Al menos un vector inicial es previamente generado utilizando un primer algoritmo, al menos un vector de referencia y datos de autenticación de usuario de referencia. Al menos el vector de referencia es previamente generado sin utilizar los datos de autenticación de usuario de referencia. El dispositivo tiene acceso a los datos 42 y a datos de autenticación de usuario proporcionado 46. El dispositivo genera 48 al menos un vector intermedio utilizando un segundo algoritmo, al menos un vector inicial y los datos de autenticación de usuario proporcionados. El dispositivo genera 410 un criptograma utilizando un tercer algoritmo 22, la clave, al menos un vector intermedio y los datos. Un servidor 18 recibe una solicitud 414 para autenticar a un usuario acompañada por el criptograma y los datos. El servidor tiene acceso 416 a la clave y al menos a un vector de referencia. El servidor genera 418 un criptograma de referencia utilizando el tercer algoritmo, la clave, al menos un vector de referencia y los datos. El servidor verifica 420 si el criptograma de referencia coincide o no con el criptograma. Si el criptograma de referencia coincide o no coincide con el criptograma, entonces el servidor autentica 422 o no autentica 424 al usuario respectivamente. La invención también se relaciona con un dispositivo, servidor y método correspondientes.
MX2018007332A 2015-12-16 2016-10-20 Metodo, dispositivo, servidor y sistema para autenticar a un usuario. MX2018007332A (es)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
EP15307028.9A EP3182315A1 (en) 2015-12-16 2015-12-16 Method, device, server and system for authenticating a user
PCT/EP2016/075258 WO2017102142A1 (en) 2015-12-16 2016-10-20 Method, device, server and system for authenticating a user

Publications (1)

Publication Number Publication Date
MX2018007332A true MX2018007332A (es) 2018-08-24

Family

ID=55070809

Family Applications (1)

Application Number Title Priority Date Filing Date
MX2018007332A MX2018007332A (es) 2015-12-16 2016-10-20 Metodo, dispositivo, servidor y sistema para autenticar a un usuario.

Country Status (10)

Country Link
US (1) US20190266603A1 (es)
EP (2) EP3182315A1 (es)
KR (1) KR20180086436A (es)
AU (2) AU2016373702A1 (es)
BR (1) BR112018010287B1 (es)
ES (1) ES2896274T3 (es)
MX (1) MX2018007332A (es)
PL (1) PL3391266T3 (es)
SG (2) SG10202005715QA (es)
WO (1) WO2017102142A1 (es)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11075910B2 (en) * 2017-08-10 2021-07-27 Patroness, LLC Secure systems architecture for integrated motorized mobile systems
US20190228410A1 (en) * 2018-01-24 2019-07-25 Mastercard International Incorporated Method and system for generating and using contextual cryptograms for proximity and e-commerce payment
EP3642761B1 (en) 2018-08-21 2022-11-02 Visa International Service Association System, method, and computer program product for mobile device transactions
CN110929238B (zh) * 2019-10-29 2022-02-01 维沃移动通信有限公司 一种信息处理方法及设备
KR20210133471A (ko) * 2020-04-29 2021-11-08 삼성전자주식회사 전자 장치 및 그의 제어 방법
EP3937036A1 (en) * 2020-07-09 2022-01-12 Thales DIS France SA Method, user device, verifier device, server and system for authenticating user data while preserving user privacy
CN112055019B (zh) * 2020-09-03 2022-09-27 深圳市百富智能新技术有限公司 一种建立通信信道的方法及用户终端

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008111012A1 (en) * 2007-03-14 2008-09-18 Dexrad (Proprietary) Limited Personal identification device for secure transactions
US10354321B2 (en) * 2009-01-22 2019-07-16 First Data Corporation Processing transactions with an extended application ID and dynamic cryptograms
DE102009055947A1 (de) * 2009-11-30 2011-06-01 Christoph Busch Authentisierte Übertragung von Daten
SG11201602093TA (en) * 2013-09-20 2016-04-28 Visa Int Service Ass Secure remote payment transaction processing including consumer authentication
CN111160902B (zh) * 2013-12-02 2023-06-23 万事达卡国际股份有限公司 用于向不带有安全元件的移动设备安全传送远程通知服务消息的方法及系统
US10116447B2 (en) * 2015-02-17 2018-10-30 Visa International Service Association Secure authentication of user and mobile device
US10360558B2 (en) * 2015-03-17 2019-07-23 Ca, Inc. Simplified two factor authentication for mobile payments
US20170032370A1 (en) * 2015-07-27 2017-02-02 Mastercard International Incorporated Electronic payment transactions using machine readable code without requiring online connection

Also Published As

Publication number Publication date
EP3391266B1 (en) 2021-08-18
EP3391266A1 (en) 2018-10-24
SG10202005715QA (en) 2020-07-29
AU2020202106A1 (en) 2020-04-09
BR112018010287A2 (pt) 2018-11-27
AU2016373702A1 (en) 2018-06-14
ES2896274T3 (es) 2022-02-24
EP3182315A1 (en) 2017-06-21
PL3391266T3 (pl) 2022-01-24
KR20180086436A (ko) 2018-07-31
BR112018010287B1 (pt) 2023-12-19
AU2020202106B2 (en) 2021-11-04
SG11201803830PA (en) 2018-06-28
US20190266603A1 (en) 2019-08-29
WO2017102142A1 (en) 2017-06-22

Similar Documents

Publication Publication Date Title
MX2018007332A (es) Metodo, dispositivo, servidor y sistema para autenticar a un usuario.
PH12018501983A1 (en) Method and system for user authentication with improved security
WO2018071191A3 (en) Method and system for data security based on quantum communication and trusted computing
MX361152B (es) Aprovisionamiento de licencias de gestión de derechos digitales (drm) en un dispositivo cliente que utiliza un servidor de actualizaciones.
MX2018004510A (es) Metodos y sistemas para controlar acceso a espacio fisico.
WO2016175914A3 (en) Transaction signing utilizing asymmetric cryptography
WO2016167932A3 (en) Authentication of a client device based on entropy from a server or other device
TW201612787A (en) Network authentication method for secure electronic transactions
MX366390B (es) Gestion de claves inalambrica para autenticacion.
GB201213279D0 (en) Identity generation mechanism
GB201221433D0 (en) A method and system of providing authentication of user access to a computer resource on a mobile device
EA201790385A1 (ru) Способ цифровой подписи электронного файла и способ аутентификации
GB2533727A (en) Registry apparatus, agent device, application providing apparatus and corresponding methods
WO2014151730A3 (en) Identity escrow management for minimal disclosure credentials
JP2016512675A5 (es)
MX355189B (es) Autentificacion de usuario.
WO2015030903A3 (en) Image based key derivation function
WO2016126052A3 (ko) 인증 방법 및 시스템
PH12016501786A1 (en) Tag management system, tag management method, information provision system, and information provision method, as well as devices and tag used therefor
WO2013106094A3 (en) System and method for device registration and authentication
IN2014MU00771A (es)
WO2010060704A3 (en) Method and system for token-based authentication
NZ701459A (en) Systems and methods for secure processing with embedded cryptographic unit
WO2016144257A3 (en) Method and system for facilitating authentication
AU2017261844A1 (en) Authenticating a user