MX383704B - Método, dispositivo, servidor y sistema para autenticar a un usuario. - Google Patents
Método, dispositivo, servidor y sistema para autenticar a un usuario.Info
- Publication number
- MX383704B MX383704B MX2018007332A MX2018007332A MX383704B MX 383704 B MX383704 B MX 383704B MX 2018007332 A MX2018007332 A MX 2018007332A MX 2018007332 A MX2018007332 A MX 2018007332A MX 383704 B MX383704 B MX 383704B
- Authority
- MX
- Mexico
- Prior art keywords
- server
- cryptogram
- vector
- data
- user
- Prior art date
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/606—Protecting data by securing the transmission between two devices or processes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3825—Use of electronic signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3827—Use of message hashing
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0618—Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
- H04L9/0625—Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation with splitting of the data block into left and right halves, e.g. Feistel based algorithms, DES, FEAL, IDEA or KASUMI
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/56—Financial cryptography, e.g. electronic payment or e-cash
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Finance (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Storage Device Security (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
La invención se refiere a un método 40 para autenticar a un usuario. De acuerdo con la invención, el método comprende los siguientes pasos. Un dispositivo 12 tiene acceso 41 a una clave y al menos un vector inicial. Al menos un vector inicial es previamente generado utilizando un primer algoritmo, al menos un vector de referencia y datos de autenticación de usuario de referencia. Al menos el vector de referencia es previamente generado sin utilizar los datos de autenticación de usuario de referencia. El dispositivo tiene acceso a los datos 42 y a datos de autenticación de usuario proporcionado 46. El dispositivo genera 48 al menos un vector intermedio utilizando un segundo algoritmo, al menos un vector inicial y los datos de autenticación de usuario proporcionados. El dispositivo genera 410 un criptograma utilizando un tercer algoritmo 22, la clave, al menos un vector intermedio y los datos. Un servidor 18 recibe una solicitud 414 para autenticar a un usuario acompañada por el criptograma y los datos. El servidor tiene acceso 416 a la clave y al menos a un vector de referencia. El servidor genera 418 un criptograma de referencia utilizando el tercer algoritmo, la clave, al menos un vector de referencia y los datos. El servidor verifica 420 si el criptograma de referencia coincide o no con el criptograma. Si el criptograma de referencia coincide o no coincide con el criptograma, entonces el servidor autentica 422 o no autentica 424 al usuario respectivamente. La invención también se relaciona con un dispositivo, servidor y método correspondientes.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP15307028.9A EP3182315A1 (en) | 2015-12-16 | 2015-12-16 | Method, device, server and system for authenticating a user |
| PCT/EP2016/075258 WO2017102142A1 (en) | 2015-12-16 | 2016-10-20 | Method, device, server and system for authenticating a user |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| MX2018007332A MX2018007332A (es) | 2018-08-24 |
| MX383704B true MX383704B (es) | 2025-03-14 |
Family
ID=55070809
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| MX2018007332A MX383704B (es) | 2015-12-16 | 2016-10-20 | Método, dispositivo, servidor y sistema para autenticar a un usuario. |
Country Status (10)
| Country | Link |
|---|---|
| US (1) | US20190266603A1 (es) |
| EP (2) | EP3182315A1 (es) |
| KR (1) | KR20180086436A (es) |
| AU (2) | AU2016373702A1 (es) |
| BR (1) | BR112018010287B1 (es) |
| ES (1) | ES2896274T3 (es) |
| MX (1) | MX383704B (es) |
| PL (1) | PL3391266T3 (es) |
| SG (2) | SG10202005715QA (es) |
| WO (1) | WO2017102142A1 (es) |
Families Citing this family (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11154442B1 (en) | 2017-04-28 | 2021-10-26 | Patroness, LLC | Federated sensor array for use with a motorized mobile system and method of use |
| US12393205B2 (en) | 2017-08-10 | 2025-08-19 | Luci Mobility, Inc. | System and method for navigation support for a motorized mobile system |
| US11075910B2 (en) * | 2017-08-10 | 2021-07-27 | Patroness, LLC | Secure systems architecture for integrated motorized mobile systems |
| US11334070B2 (en) | 2017-08-10 | 2022-05-17 | Patroness, LLC | Systems and methods for predictions of state of objects for a motorized mobile system |
| US10656652B2 (en) | 2017-08-10 | 2020-05-19 | Patroness, LLC | System and methods for sensor integration in support of situational awareness for a motorized mobile system |
| US20190228410A1 (en) * | 2018-01-24 | 2019-07-25 | Mastercard International Incorporated | Method and system for generating and using contextual cryptograms for proximity and e-commerce payment |
| CA3138670C (en) | 2018-08-21 | 2023-04-25 | Visa International Service Association | System, method, and computer program product for mobile device transactions |
| CN110929238B (zh) * | 2019-10-29 | 2022-02-01 | 维沃移动通信有限公司 | 一种信息处理方法及设备 |
| US12048658B1 (en) | 2020-03-06 | 2024-07-30 | Luci Mobility, Inc. | Systems and methods for pressure injury mitigation |
| KR20210133471A (ko) * | 2020-04-29 | 2021-11-08 | 삼성전자주식회사 | 전자 장치 및 그의 제어 방법 |
| EP3937036A1 (en) | 2020-07-09 | 2022-01-12 | Thales DIS France SA | Method, user device, verifier device, server and system for authenticating user data while preserving user privacy |
| CN112055019B (zh) | 2020-09-03 | 2022-09-27 | 深圳市百富智能新技术有限公司 | 一种建立通信信道的方法及用户终端 |
| KR102802979B1 (ko) | 2020-09-21 | 2025-04-30 | 주식회사 엘지에너지솔루션 | 상호 인증 방법 및 그 방법을 제공하는 인증장치 |
| WO2024196700A1 (en) * | 2023-03-17 | 2024-09-26 | Mastercard International Incorporated | Contactless provisioning systems and methods |
| US20250337581A1 (en) * | 2024-04-24 | 2025-10-30 | Paypal, Inc. | Mechanisms for Utilizing Tokens and Cryptograms in Operations |
Family Cites Families (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2130186A1 (en) * | 2007-03-14 | 2009-12-09 | Dexrad (Proprietary) Limited | Personal identification device for secure transactions |
| US10354321B2 (en) * | 2009-01-22 | 2019-07-16 | First Data Corporation | Processing transactions with an extended application ID and dynamic cryptograms |
| DE102009055947A1 (de) * | 2009-11-30 | 2011-06-01 | Christoph Busch | Authentisierte Übertragung von Daten |
| RU2663476C2 (ru) * | 2013-09-20 | 2018-08-06 | Виза Интернэшнл Сервис Ассосиэйшн | Защищенная обработка удаленных платежных транзакций, включающая в себя аутентификацию потребителей |
| MX361684B (es) * | 2013-12-02 | 2018-12-13 | Mastercard International Inc | Método y sistema para la transmisión segura de mensajes del servicio de notificación a distancia a dispositivos móviles sin elementos de seguridad. |
| CN107251595B (zh) * | 2015-02-17 | 2021-04-20 | 维萨国际服务协会 | 用户和移动装置的安全认证 |
| US10360558B2 (en) * | 2015-03-17 | 2019-07-23 | Ca, Inc. | Simplified two factor authentication for mobile payments |
| US20170032370A1 (en) * | 2015-07-27 | 2017-02-02 | Mastercard International Incorporated | Electronic payment transactions using machine readable code without requiring online connection |
-
2015
- 2015-12-16 EP EP15307028.9A patent/EP3182315A1/en not_active Withdrawn
-
2016
- 2016-10-20 AU AU2016373702A patent/AU2016373702A1/en not_active Abandoned
- 2016-10-20 SG SG10202005715QA patent/SG10202005715QA/en unknown
- 2016-10-20 SG SG11201803830PA patent/SG11201803830PA/en unknown
- 2016-10-20 EP EP16787776.0A patent/EP3391266B1/en active Active
- 2016-10-20 US US16/062,812 patent/US20190266603A1/en not_active Abandoned
- 2016-10-20 KR KR1020187016690A patent/KR20180086436A/ko not_active Ceased
- 2016-10-20 BR BR112018010287-3A patent/BR112018010287B1/pt active IP Right Grant
- 2016-10-20 MX MX2018007332A patent/MX383704B/es unknown
- 2016-10-20 WO PCT/EP2016/075258 patent/WO2017102142A1/en not_active Ceased
- 2016-10-20 ES ES16787776T patent/ES2896274T3/es active Active
- 2016-10-20 PL PL16787776T patent/PL3391266T3/pl unknown
-
2020
- 2020-03-23 AU AU2020202106A patent/AU2020202106B2/en active Active
Also Published As
| Publication number | Publication date |
|---|---|
| ES2896274T3 (es) | 2022-02-24 |
| SG10202005715QA (en) | 2020-07-29 |
| WO2017102142A1 (en) | 2017-06-22 |
| PL3391266T3 (pl) | 2022-01-24 |
| AU2016373702A1 (en) | 2018-06-14 |
| BR112018010287A2 (pt) | 2018-11-27 |
| EP3182315A1 (en) | 2017-06-21 |
| KR20180086436A (ko) | 2018-07-31 |
| BR112018010287B1 (pt) | 2023-12-19 |
| US20190266603A1 (en) | 2019-08-29 |
| EP3391266A1 (en) | 2018-10-24 |
| MX2018007332A (es) | 2018-08-24 |
| EP3391266B1 (en) | 2021-08-18 |
| AU2020202106B2 (en) | 2021-11-04 |
| SG11201803830PA (en) | 2018-06-28 |
| AU2020202106A1 (en) | 2020-04-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| MX383704B (es) | Método, dispositivo, servidor y sistema para autenticar a un usuario. | |
| PH12018501983A1 (en) | Method and system for user authentication with improved security | |
| EP4271016A3 (en) | Enhanced authentication based on secondary device interactions | |
| MX361152B (es) | Aprovisionamiento de licencias de gestión de derechos digitales (drm) en un dispositivo cliente que utiliza un servidor de actualizaciones. | |
| JP2016512675A5 (es) | ||
| NZ744540A (en) | Systems and methods for providing block chain-based multifactor personal identity verification | |
| MX2017001090A (es) | Gestion de claves inalambrica para autenticacion. | |
| IN2014MU00771A (es) | ||
| TW201612787A (en) | Network authentication method for secure electronic transactions | |
| BR112017003018A2 (pt) | fornecimento seguro de uma credencial de autenticação | |
| MX390172B (es) | Metodos y sistemas para controlar acceso a espacio fisico. | |
| MX2015015140A (es) | Autentificacion de usuario. | |
| WO2016175914A3 (en) | Transaction signing utilizing asymmetric cryptography | |
| GB2533727A (en) | Registry apparatus, agent device, application providing apparatus and corresponding methods | |
| WO2016167932A3 (en) | Authentication of a client device based on entropy from a server or other device | |
| PH12016501786A1 (en) | Tag management system, tag management method, information provision system, and information provision method, as well as devices and tag used therefor | |
| WO2016126052A3 (ko) | 인증 방법 및 시스템 | |
| GB201213279D0 (en) | Identity generation mechanism | |
| NZ701459A (en) | Systems and methods for secure processing with embedded cryptographic unit | |
| SG10201810422SA (en) | Dual channel identity authentication | |
| MY184704A (en) | A system and method for authenticating a user based on user behaviour and environmental factors | |
| MX369305B (es) | Método para tener acceso a un servicio, primer dispositivo, segundo dispositivo y sistema correspondientes. | |
| FI20145650A7 (fi) | Lukkojärjestelmä ja sähköisten avainten luonti lukkojärjestelmässä | |
| WO2016144258A3 (en) | Methods and systems for facilitating secured access to storage devices | |
| IN2013CH05960A (es) |