会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 7. 发明申请
    • SYSTEM AND METHOD FOR A KEY BLOCK BASED AUTHENTICATION
    • 基于密钥块验证的系统和方法
    • WO2007000711A2
    • 2007-01-04
    • PCT/IB2006052082
    • 2006-06-26
    • KONINKL PHILIPS ELECTRONICS NVSTARING ANTONIUS A M
    • STARING ANTONIUS A M
    • G06F21/10G06F21/44
    • G11B20/00086G06F21/10G06F21/445G06F2221/0755G06F2221/0771G11B20/00188G11B20/00195G11B20/0021G11B20/00246G11B20/00543H04L63/064H04L63/08
    • The present invention relates to a system (70, 80) and a method for a key block based authentication comprising a plurality of drive units (3) comprising a plurality of subsets, wherein a drive unit (3) has a set of node keys (KN d ) and an identifier (ID d ) indicating the subsets said drive unit (3) is part of and wherein an application unit (1) has a key block (AKB). In order to allow identification of a hacked drive unit (3) in order to revoke the hacked drive unit (3) from said key block based authentication, wherein said system is to a large extent compatible with existing systems and methods for a key block based authentication, a system is proposed comprising: - a plurality of drive units (3) comprising a plurality of subsets, wherein a drive unit (3) has a set of node keys (KN d ) and an identifier (ID d ) indicating the subsets said drive unit (3) is part of, - an application unit (1) having a key block (AKB) comprising a plurality of pairs of authorization and authentication keys (KA x , KR authx ), wherein each pair of keys is associated with one of said subsets, - a communication means (72) for submitting said identifier (ID d ) from said drive unit (3) to said application unit (1) and for submitting an authorization key (KA x ) from said application unit (1) to said drive unit (3), and - an authentication means (54) for authenticating said drive unit (3) and said application unit (1) by means of a pair of keys, wherein said application unit (1) comprises a selecting means (62) for selecting said pair of keys from said key block (AKB) corresponding to said identifier (ID d ), wherein said drive unit (3) comprises a decoding means (52) for deriving said authentication key (KR authx ) of said pair of keys from said authorization key (KA x ) of said pair of keys by means of said set of node keys (KN d ).
    • 本发明涉及一种用于基于密钥块的认证的系统(70,80)和方法,其包括多个包括多个子集的驱动单元(3),其中驱动单元(3)具有一组节点密钥 指示所述驱动单元(3)的子集的一部分的标识符(ID&lt; d&gt;),其中应用单元(1)具有密钥块(AKB )。 为了允许识别被入侵的驱动单元(3),以便从所述基于密钥块的认证中撤销被入侵的驱动单元(3),其中所述系统在很大程度上与现有的系统和基于密钥块的方法兼容 提出了一种系统,其包括: - 包括多个子集的多个驱动单元(3),其中驱动单元(3)具有一组节点密钥(KN )和标识符 (3)是所述驱动单元(3)的一部分的子组件(ID), - 具有密钥块(AKB)的应用单元(1),所述密钥块(AKB)包括多对授权和认证密钥(KA 其中每对密钥与所述子集中的一个相关联, - 通信装置(72),用于提交所述标识符(ID&lt; SUB&gt;&gt; 从所述驱动单元(3)向所述应用单元(1)提供从所述应用单元(1)向所述驱动单元(3)提交授权密钥(KA )从所述应用单元(1) ,a d - 用于通过一对密钥认证所述驱动单元(3)和所述应用单元(1)的认证装置(54),其中所述应用单元(1)包括选择装置(62),用于选择所述一对 对应于所述标识符(ID)的所述密钥块(AKB)的密钥,其中所述驱动单元(3)包括一个解码装置(52),用于导出所述验证密钥(KRALAuthx < / SUB>)通过所述一组节点密钥(KN )从所述一对密钥的所述授权密钥(KA×××)中获得。