Invention Grant
US07752444B2 System and method for providing identity hiding in a shared key authentication protocol
有权
在共享密钥认证协议中提供身份隐藏的系统和方法
- Patent Title: System and method for providing identity hiding in a shared key authentication protocol
- Patent Title (中): 在共享密钥认证协议中提供身份隐藏的系统和方法
-
Application No.: US11314403Application Date: 2005-12-21
-
Publication No.: US07752444B2Publication Date: 2010-07-06
- Inventor: Marcus Leech
- Applicant: Marcus Leech
- Assignee: Nortel Networks Limited
- Current Assignee: Nortel Networks Limited
- Agency: Anderson Gorecki & Manaras LLP
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
A system and method is provided for hiding an initiator's identity (ID), e.g. a ClientID, in a shared key authentication protocol, using authentication based on a hint of the ID. The hint is a function of the ID which cannot be readily inverted to produce the initiator's identity, for example, a hash function over the ID, such as a modular N sum hash of the initiator's identity where N corresponds to N hash buckets in a shared key database; a cryptographic hash over the ID and a corresponding shared key; or a function of the ID which cannot be readily inverted to produce the initiator's identity and a pair of MAC values wherein the MAC values are compared to find a shared key. The resulting hash may be reduced to a required number of bits for identification of a hash bucket in the database. The system and method thereby provide a computationally efficient method of protecting, or hiding, a client ID in a client-server system for shared-key authentication, which avoids the requirement of known systems to send the client ID in clear text early in the message exchange, which leaves known shared-key protocols open to passive and active identity disclosure attacks.
Public/Granted literature
- US20070180247A1 System and method for providing identity hiding in a shared key authentication protocol Public/Granted day:2007-08-02
Information query