Invention Grant
- Patent Title: Scalable authentication system
- Patent Title (中): 可扩展认证系统
-
Application No.: US14382942Application Date: 2013-02-14
-
Publication No.: US09369464B2Publication Date: 2016-06-14
- Inventor: Basil Philipsz
- Applicant: DISTRIBUTED MANAGEMENT SYSTEMS LTD.
- Applicant Address: GB Blackburn
- Assignee: DISTRIBUTED MANAGEMENT SYSTEMS LTD.
- Current Assignee: DISTRIBUTED MANAGEMENT SYSTEMS LTD.
- Current Assignee Address: GB Blackburn
- Agency: Hoffman Warnick LLC
- Priority: GB1204202.4 20120309
- International Application: PCT/GB2013/050341 WO 20130214
- International Announcement: WO2013/132224 WO 20130912
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Disclosed is a key management method for administering a token with an administrative server and an authentication server wherein a set of keys stored therein in use differs so that at least a mutually exclusive key is stored in each of the token, the administrative server or the authentication server, the method comprising the steps of: the token transmitting an identity proxy ID 1 encrypted with an encryption key Key 1; the administrative server generating data Key 1a and Key 1b from Key 1 stored therein, whereby Key 1a and Key 1b can be used in conjunction to derive Key 1 but not separately; the administrative server generating an identity proxy ID 2 and an encryption key Key 2, whereby the administrative server records a token profile comprising an association information among ID 2, Key 1b and Key 2; the administrative server communicating ID 2, Key 1a and Key 2 to the token and the token storing ID 2, Key 1a and Key 2 wherein Key 2 is stored therein encrypted with Key 1; the administrative server communicating the token profile to the authentication server and deleting Key 1b and Key 2 from its records thereafter; the authentication server requesting ID 2 from the token and the token transmitting ID 2 thereto; the authentication server identifying Key 1b and Key 2 associated with the transmitted ID 2 and generating a new encryption key Key 3; the authentication server recording Key 3's association with ID 2 in the token profile and communicating Key 3 to the token; and the token storing Key 3 therein encrypted with Key 2, whereby the administrative server stores ID 1, ID 2 and Key 1, the authentication server stores ID 2, Key 1b, Key 2, and Key 3, and the token stores ID 1, ID 2, Key 1a, Key 2, and Key 3, wherein the token stores Key 2 encrypted with Key 1 and stores Key 3 encrypted with Key 2 therein.
Public/Granted literature
- US20150046695A1 SCALABLE AUTHENTICATION SYSTEM Public/Granted day:2015-02-12
Information query