MX383704B - Método, dispositivo, servidor y sistema para autenticar a un usuario. - Google Patents

Método, dispositivo, servidor y sistema para autenticar a un usuario.

Info

Publication number
MX383704B
MX383704B MX2018007332A MX2018007332A MX383704B MX 383704 B MX383704 B MX 383704B MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 383704 B MX383704 B MX 383704B
Authority
MX
Mexico
Prior art keywords
server
cryptogram
vector
data
user
Prior art date
Application number
MX2018007332A
Other languages
English (en)
Other versions
MX2018007332A (es
Inventor
Jean- Michel Desjardins
Marie Lathiere
Original Assignee
Gemalto Sa
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Gemalto Sa filed Critical Gemalto Sa
Publication of MX2018007332A publication Critical patent/MX2018007332A/es
Publication of MX383704B publication Critical patent/MX383704B/es

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3827Use of message hashing
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3829Payment protocols; Details thereof insuring higher security of transaction involving key management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0625Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation with splitting of the data block into left and right halves, e.g. Feistel based algorithms, DES, FEAL, IDEA or KASUMI
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Finance (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Storage Device Security (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

La invención se refiere a un método 40 para autenticar a un usuario. De acuerdo con la invención, el método comprende los siguientes pasos. Un dispositivo 12 tiene acceso 41 a una clave y al menos un vector inicial. Al menos un vector inicial es previamente generado utilizando un primer algoritmo, al menos un vector de referencia y datos de autenticación de usuario de referencia. Al menos el vector de referencia es previamente generado sin utilizar los datos de autenticación de usuario de referencia. El dispositivo tiene acceso a los datos 42 y a datos de autenticación de usuario proporcionado 46. El dispositivo genera 48 al menos un vector intermedio utilizando un segundo algoritmo, al menos un vector inicial y los datos de autenticación de usuario proporcionados. El dispositivo genera 410 un criptograma utilizando un tercer algoritmo 22, la clave, al menos un vector intermedio y los datos. Un servidor 18 recibe una solicitud 414 para autenticar a un usuario acompañada por el criptograma y los datos. El servidor tiene acceso 416 a la clave y al menos a un vector de referencia. El servidor genera 418 un criptograma de referencia utilizando el tercer algoritmo, la clave, al menos un vector de referencia y los datos. El servidor verifica 420 si el criptograma de referencia coincide o no con el criptograma. Si el criptograma de referencia coincide o no coincide con el criptograma, entonces el servidor autentica 422 o no autentica 424 al usuario respectivamente. La invención también se relaciona con un dispositivo, servidor y método correspondientes.
MX2018007332A 2015-12-16 2016-10-20 Método, dispositivo, servidor y sistema para autenticar a un usuario. MX383704B (es)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
EP15307028.9A EP3182315A1 (en) 2015-12-16 2015-12-16 Method, device, server and system for authenticating a user
PCT/EP2016/075258 WO2017102142A1 (en) 2015-12-16 2016-10-20 Method, device, server and system for authenticating a user

Publications (2)

Publication Number Publication Date
MX2018007332A MX2018007332A (es) 2018-08-24
MX383704B true MX383704B (es) 2025-03-14

Family

ID=55070809

Family Applications (1)

Application Number Title Priority Date Filing Date
MX2018007332A MX383704B (es) 2015-12-16 2016-10-20 Método, dispositivo, servidor y sistema para autenticar a un usuario.

Country Status (10)

Country Link
US (1) US20190266603A1 (es)
EP (2) EP3182315A1 (es)
KR (1) KR20180086436A (es)
AU (2) AU2016373702A1 (es)
BR (1) BR112018010287B1 (es)
ES (1) ES2896274T3 (es)
MX (1) MX383704B (es)
PL (1) PL3391266T3 (es)
SG (2) SG10202005715QA (es)
WO (1) WO2017102142A1 (es)

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11154442B1 (en) 2017-04-28 2021-10-26 Patroness, LLC Federated sensor array for use with a motorized mobile system and method of use
US12393205B2 (en) 2017-08-10 2025-08-19 Luci Mobility, Inc. System and method for navigation support for a motorized mobile system
US11075910B2 (en) * 2017-08-10 2021-07-27 Patroness, LLC Secure systems architecture for integrated motorized mobile systems
US11334070B2 (en) 2017-08-10 2022-05-17 Patroness, LLC Systems and methods for predictions of state of objects for a motorized mobile system
US10656652B2 (en) 2017-08-10 2020-05-19 Patroness, LLC System and methods for sensor integration in support of situational awareness for a motorized mobile system
US20190228410A1 (en) * 2018-01-24 2019-07-25 Mastercard International Incorporated Method and system for generating and using contextual cryptograms for proximity and e-commerce payment
CA3138670C (en) 2018-08-21 2023-04-25 Visa International Service Association System, method, and computer program product for mobile device transactions
CN110929238B (zh) * 2019-10-29 2022-02-01 维沃移动通信有限公司 一种信息处理方法及设备
US12048658B1 (en) 2020-03-06 2024-07-30 Luci Mobility, Inc. Systems and methods for pressure injury mitigation
KR20210133471A (ko) * 2020-04-29 2021-11-08 삼성전자주식회사 전자 장치 및 그의 제어 방법
EP3937036A1 (en) 2020-07-09 2022-01-12 Thales DIS France SA Method, user device, verifier device, server and system for authenticating user data while preserving user privacy
CN112055019B (zh) 2020-09-03 2022-09-27 深圳市百富智能新技术有限公司 一种建立通信信道的方法及用户终端
KR102802979B1 (ko) 2020-09-21 2025-04-30 주식회사 엘지에너지솔루션 상호 인증 방법 및 그 방법을 제공하는 인증장치
WO2024196700A1 (en) * 2023-03-17 2024-09-26 Mastercard International Incorporated Contactless provisioning systems and methods
US20250337581A1 (en) * 2024-04-24 2025-10-30 Paypal, Inc. Mechanisms for Utilizing Tokens and Cryptograms in Operations

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2130186A1 (en) * 2007-03-14 2009-12-09 Dexrad (Proprietary) Limited Personal identification device for secure transactions
US10354321B2 (en) * 2009-01-22 2019-07-16 First Data Corporation Processing transactions with an extended application ID and dynamic cryptograms
DE102009055947A1 (de) * 2009-11-30 2011-06-01 Christoph Busch Authentisierte Übertragung von Daten
RU2663476C2 (ru) * 2013-09-20 2018-08-06 Виза Интернэшнл Сервис Ассосиэйшн Защищенная обработка удаленных платежных транзакций, включающая в себя аутентификацию потребителей
MX361684B (es) * 2013-12-02 2018-12-13 Mastercard International Inc Método y sistema para la transmisión segura de mensajes del servicio de notificación a distancia a dispositivos móviles sin elementos de seguridad.
CN107251595B (zh) * 2015-02-17 2021-04-20 维萨国际服务协会 用户和移动装置的安全认证
US10360558B2 (en) * 2015-03-17 2019-07-23 Ca, Inc. Simplified two factor authentication for mobile payments
US20170032370A1 (en) * 2015-07-27 2017-02-02 Mastercard International Incorporated Electronic payment transactions using machine readable code without requiring online connection

Also Published As

Publication number Publication date
ES2896274T3 (es) 2022-02-24
SG10202005715QA (en) 2020-07-29
WO2017102142A1 (en) 2017-06-22
PL3391266T3 (pl) 2022-01-24
AU2016373702A1 (en) 2018-06-14
BR112018010287A2 (pt) 2018-11-27
EP3182315A1 (en) 2017-06-21
KR20180086436A (ko) 2018-07-31
BR112018010287B1 (pt) 2023-12-19
US20190266603A1 (en) 2019-08-29
EP3391266A1 (en) 2018-10-24
MX2018007332A (es) 2018-08-24
EP3391266B1 (en) 2021-08-18
AU2020202106B2 (en) 2021-11-04
SG11201803830PA (en) 2018-06-28
AU2020202106A1 (en) 2020-04-09

Similar Documents

Publication Publication Date Title
MX383704B (es) Método, dispositivo, servidor y sistema para autenticar a un usuario.
PH12018501983A1 (en) Method and system for user authentication with improved security
EP4271016A3 (en) Enhanced authentication based on secondary device interactions
MX361152B (es) Aprovisionamiento de licencias de gestión de derechos digitales (drm) en un dispositivo cliente que utiliza un servidor de actualizaciones.
JP2016512675A5 (es)
NZ744540A (en) Systems and methods for providing block chain-based multifactor personal identity verification
MX2017001090A (es) Gestion de claves inalambrica para autenticacion.
IN2014MU00771A (es)
TW201612787A (en) Network authentication method for secure electronic transactions
BR112017003018A2 (pt) fornecimento seguro de uma credencial de autenticação
MX390172B (es) Metodos y sistemas para controlar acceso a espacio fisico.
MX2015015140A (es) Autentificacion de usuario.
WO2016175914A3 (en) Transaction signing utilizing asymmetric cryptography
GB2533727A (en) Registry apparatus, agent device, application providing apparatus and corresponding methods
WO2016167932A3 (en) Authentication of a client device based on entropy from a server or other device
PH12016501786A1 (en) Tag management system, tag management method, information provision system, and information provision method, as well as devices and tag used therefor
WO2016126052A3 (ko) 인증 방법 및 시스템
GB201213279D0 (en) Identity generation mechanism
NZ701459A (en) Systems and methods for secure processing with embedded cryptographic unit
SG10201810422SA (en) Dual channel identity authentication
MY184704A (en) A system and method for authenticating a user based on user behaviour and environmental factors
MX369305B (es) Método para tener acceso a un servicio, primer dispositivo, segundo dispositivo y sistema correspondientes.
FI20145650A7 (fi) Lukkojärjestelmä ja sähköisten avainten luonti lukkojärjestelmässä
WO2016144258A3 (en) Methods and systems for facilitating secured access to storage devices
IN2013CH05960A (es)