Invention Grant
US08130961B2 Method and system for client-server mutual authentication using event-based OTP
有权
使用基于事件的OTP进行客户端 - 服务器相互验证的方法和系统
- Patent Title: Method and system for client-server mutual authentication using event-based OTP
- Patent Title (中): 使用基于事件的OTP进行客户端 - 服务器相互验证的方法和系统
-
Application No.: US12028232Application Date: 2008-02-08
-
Publication No.: US08130961B2Publication Date: 2012-03-06
- Inventor: Salah E. Machani , Konstantin Teslenko
- Applicant: Salah E. Machani , Konstantin Teslenko
- Applicant Address: CA Toronto
- Assignee: Diversinet Corp.
- Current Assignee: Diversinet Corp.
- Current Assignee Address: CA Toronto
- Agency: McMillan LLP
- Priority: CA2590989 20070605
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
The invention comprises a method of authenticating and encrypting a client-server communication, comprising the steps of: a) generating a first one-time password (OTP1) and a second one-time password (OTP2) from a cryptographic token; b) generating an encryption key (K_ENC) and a MAC key (K_MAC) based on OTP2; c) preparing and protecting the client data using K_ENC and K_MAC; d) sending a request message from the client to the server, the request message containing the protected client data, a cryptographic token identifier (TID) and OTP1; e) validating OTP1 at the server, and generating OTP2 at the server upon successful validation; f) deriving K_ENC and K_MAC from OTP2 at the server; g) processing the request message and generating result data h) encrypting the result data using K_ENC and creating a digest using K_MAC; i) sending the encrypted result data to the client; and i) decrypting the result data at the client using K_ENC and verifying the authenticity of the result data using K_MAC.
Public/Granted literature
- US20100031051A1 Protocol And Method For Client-Server Mutual Authentication Using Event-Based OTP Public/Granted day:2010-02-04
Information query