WO2007115982A3 - Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants - Google Patents

Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants Download PDF

Info

Publication number
WO2007115982A3
WO2007115982A3 PCT/EP2007/053268 EP2007053268W WO2007115982A3 WO 2007115982 A3 WO2007115982 A3 WO 2007115982A3 EP 2007053268 W EP2007053268 W EP 2007053268W WO 2007115982 A3 WO2007115982 A3 WO 2007115982A3
Authority
WO
WIPO (PCT)
Prior art keywords
devices
protection method
corresponding computer
authentication
client terminal
Prior art date
Application number
PCT/EP2007/053268
Other languages
English (en)
Other versions
WO2007115982A2 (fr
Inventor
Pascal Urien
Mohamad Badra
Original Assignee
Groupe Des Ecoles Des Telecommunications - Ecole Nationale Superieure Des Telecommunications
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Groupe Des Ecoles Des Telecommunications - Ecole Nationale Superieure Des Telecommunications filed Critical Groupe Des Ecoles Des Telecommunications - Ecole Nationale Superieure Des Telecommunications
Priority to CA002648377A priority Critical patent/CA2648377A1/fr
Priority to US12/296,392 priority patent/US20100005290A1/en
Priority to EP07727739A priority patent/EP2012907A2/fr
Publication of WO2007115982A2 publication Critical patent/WO2007115982A2/fr
Publication of WO2007115982A3 publication Critical patent/WO2007115982A3/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer And Data Communications (AREA)
  • Storage Device Security (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

L'invention concerne un procédé d'authentification d'un terminal client auprès d'un serveur d'authentification, ledit terminal client possédant un certificat d'authentification. Selon l'invention, un tel procédé comprend les phases suivantes: obtention d'au moins un paramètre de cryptage par ledit terminal client; chiffrement dudit certificat d'authentification par ledit terminal client, à partir dudit au moins un paramètre de cryptage, délivrant un certificat d'authentification chiffré; transmission dudit certificat d'authentification chiffré audit serveur; obtention dudit au moins un paramètre de cryptage par ledit serveur; déchiffrement dudit certificat d'authentification chiffré, à partir dudit au moins un paramètre de cryptage; authentification et délivrance d'une assertion d'authentification si l'authentification est positive.
PCT/EP2007/053268 2006-04-07 2007-04-03 Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants WO2007115982A2 (fr)

Priority Applications (3)

Application Number Priority Date Filing Date Title
CA002648377A CA2648377A1 (fr) 2006-04-07 2007-04-03 Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants
US12/296,392 US20100005290A1 (en) 2006-04-07 2007-04-03 Method of identity protection, corresponding devices and computer softwares
EP07727739A EP2012907A2 (fr) 2006-04-07 2007-04-03 Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0603114 2006-04-07
FR0603114A FR2899749B1 (fr) 2006-04-07 2006-04-07 Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants.

Publications (2)

Publication Number Publication Date
WO2007115982A2 WO2007115982A2 (fr) 2007-10-18
WO2007115982A3 true WO2007115982A3 (fr) 2009-10-15

Family

ID=37772855

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2007/053268 WO2007115982A2 (fr) 2006-04-07 2007-04-03 Procede de protection d'identite, dispositifs, et produit programme d'ordinateur correspondants

Country Status (7)

Country Link
US (1) US20100005290A1 (fr)
EP (1) EP2012907A2 (fr)
CN (1) CN101657992A (fr)
CA (1) CA2648377A1 (fr)
FR (1) FR2899749B1 (fr)
RU (1) RU2451398C2 (fr)
WO (1) WO2007115982A2 (fr)

Families Citing this family (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102007009023B4 (de) * 2007-02-23 2011-12-22 Siemens Ag Vorrichtung und Verfahren zum Bereitstellen von RFID-Identifizierungsdaten für einen Authentisierungsserver
US8176328B2 (en) * 2008-09-17 2012-05-08 Alcatel Lucent Authentication of access points in wireless local area networks
CN101378358B (zh) * 2008-09-19 2010-12-15 成都市华为赛门铁克科技有限公司 一种实现安全接入控制的方法及***、服务器
DE102010044518A1 (de) * 2010-09-07 2012-03-08 Siemens Aktiengesellschaft Verfahren zur Zertifikats-basierten Authentisierung
GB201116932D0 (en) * 2011-10-01 2011-11-16 Young Peter J Device to detect unattended open door or draw
US9647835B2 (en) * 2011-12-16 2017-05-09 Akamai Technologies, Inc. Terminating SSL connections without locally-accessible private keys
US9380038B2 (en) * 2012-03-09 2016-06-28 T-Mobile Usa, Inc. Bootstrap authentication framework
US20140006806A1 (en) * 2012-06-23 2014-01-02 Pomian & Corella, Llc Effective data protection for mobile devices
RU2541901C2 (ru) * 2012-08-29 2015-02-20 Общество с ограниченной ответственностью "Гейзер-Телеком" Способ гарантированной защиты передаваемой по радиоканалу информации от неправомерного доступа с помощью специального кодирования (преобразования) информации при открытом хранении параметров кодирования
US10069827B2 (en) * 2012-10-31 2018-09-04 International Business Machines Corporation Extending authentication and authorization capabilities of an application without code changes
US9173095B2 (en) * 2013-03-11 2015-10-27 Intel Corporation Techniques for authenticating a device for wireless docking
US10078754B1 (en) * 2013-09-24 2018-09-18 Amazon Technologies, Inc. Volume cryptographic key management
CN104468124B (zh) * 2014-12-22 2018-04-27 联想(北京)有限公司 基于ssl的认证方法及电子设备
EP3160176B1 (fr) * 2015-10-19 2019-12-11 Vodafone GmbH Usage d'un service d'un réseau central à commutation de paquets mobile sans avoir une carte sim
US10116630B2 (en) * 2016-04-04 2018-10-30 Bitdefender IPR Management Ltd. Systems and methods for decrypting network traffic in a virtualized environment
CN106228070A (zh) * 2016-06-29 2016-12-14 江海职业技术学院 一种计算机信息处理***
EA036373B1 (ru) * 2017-02-07 2020-10-30 Александр Иванович Силаев Интерактивная игровая система, способ интерактивной игры с удалённым доступом
CN109743336B (zh) * 2019-03-05 2021-10-01 上海扩博智能技术有限公司 无人机安全通信方法及***
CN110995414B (zh) * 2019-12-23 2023-08-11 中金金融认证中心有限公司 基于国密算法在tls1_3协议中建立通道的方法
CN113010880B (zh) * 2021-02-08 2022-10-14 上海新时达电气股份有限公司 电梯配件认证方法、***、服务器和存储介质
US11838428B2 (en) * 2021-12-20 2023-12-05 Nokia Technologies Oy Certificate-based local UE authentication

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8117125B1 (en) * 1999-06-11 2012-02-14 Citicorp Developement Center, Inc. Method and system for controlling certificate based open payment transactions
DE19939281A1 (de) * 1999-08-19 2001-02-22 Ibm Verfahren und Vorrichtung zur Zugangskontrolle zu Inhalten von Web-Seiten unter Verwendung eines mobilen Sicherheitsmoduls
DE10025626A1 (de) * 2000-05-24 2001-11-29 Deutsche Telekom Ag Verschlüsseln von abzuspeichernden Daten in einem IV-System
CN1204518C (zh) * 2000-05-25 2005-06-01 迪布尔特有限公司 自动交易机***和方法
NO313480B1 (no) * 2001-01-24 2002-10-07 Telenor Asa Fremgangsmåte for å åpne hele eller deler av et smartkort
US7500100B1 (en) * 2003-09-10 2009-03-03 Cisco Technology, Inc. Method and apparatus for verifying revocation status of a digital certificate
CA2552987C (fr) * 2004-03-26 2013-05-28 Bce Inc. Systeme et procede de securite
JP3761557B2 (ja) * 2004-04-08 2006-03-29 株式会社日立製作所 暗号化通信のための鍵配付方法及びシステム
US7900039B2 (en) * 2005-01-17 2011-03-01 Lg Electronics, Inc. TLS session management method in SUPL-based positioning system

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
AURA T, ELLISON C: "Privacy and Accountability in Certificate Systems", HELSINKI UNIVERSITY OF TECHNOLOGY, LABORATORY FOR THEORETICAL COMPUTER SCIENCE. RESEARCH REPORTS 61, April 2000 (2000-04-01), pages 1 - 18, XP002423043, ISSN: 0783-5396, ISBN: 951-22-5000-4, Retrieved from the Internet <URL:http://citeseer.ist.psu.edu/cs> [retrieved on 20070302] *
PERSIANO P, VISCONTI I: "A Secure and Private System for Subscription-Based Remote Services", ACM TRANSACTIONS ON INFORMATION AND SYSTEMS SECURITY, vol. 6, no. 4, November 2003 (2003-11-01), USA, pages 472 - 500, XP002423044, ISSN: 1094-9224 *
SAMFAT D ET AL: "UNTRACEABILITY IN MOBILE NETWORKS", MOBICOM. PROCEEDINGS OF THE ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 13 November 1995 (1995-11-13), pages 26 - 36, XP000197826 *

Also Published As

Publication number Publication date
RU2008142008A (ru) 2010-05-20
FR2899749B1 (fr) 2008-07-04
US20100005290A1 (en) 2010-01-07
EP2012907A2 (fr) 2009-01-14
FR2899749A1 (fr) 2007-10-12
CN101657992A (zh) 2010-02-24
RU2451398C2 (ru) 2012-05-20
CA2648377A1 (fr) 2007-10-18
WO2007115982A2 (fr) 2007-10-18

Similar Documents

Publication Publication Date Title
WO2007115982A3 (fr) Procede de protection d&#39;identite, dispositifs, et produit programme d&#39;ordinateur correspondants
WO2009022560A1 (fr) Dispositif client, dispositif serveur et programme
WO2010026561A3 (fr) Appareil, système, procédé et composants logiciels correspondants pour le cryptage et le traitement de données
WO2008024559A3 (fr) Procédé et appareil d&#39;authentification d&#39;applications à des services sécurisés
GB2512249A (en) Secure peer discovery and authentication using a shared secret
GB2496354B (en) A method and system of providing authentication of user access to a computer resource via a mobile device using multiple separate security factors
WO2012087692A3 (fr) Système et procédé de communication sécurisée dans un système de communication
GB2498039B (en) Password recovery service
WO2008032304A3 (fr) Procede et systeme de collecte et de distribution securisees de donnees
MY162283A (en) Method and apparatus for mutual authentication
WO2011103561A3 (fr) Système de chiffrement utilisant des navigateurs web et des serveurs web non sécurisés
WO2014151730A3 (fr) Gestion de dépôt d&#39;identité pour des références minimales de divulgation
WO2008039582A3 (fr) Système et procédé pour sécuriser les applications logicielles
WO2014139341A8 (fr) Procédé et système de gestion de clé
GB2528226A (en) Method performed by at least one server for processing a data packet from a first computing device to a second computing device to permit end-to-end
WO2012092423A3 (fr) Extension de la confidentialité des données dans une application de lecteurs
EP2544400A3 (fr) Système de communication cryptographique et procédé de communication cryptographique basé sur les PUF
WO2011017099A3 (fr) Communication sécurisée utilisant la cryptographie asymétrique et des certificats légers
WO2009151832A3 (fr) Procédé et système pour sécuriser une transaction de paiement
TW200641642A (en) Stateless methods for resource hiding and access control support based on URI encryption
WO2007125486A3 (fr) accès amélioré à un domaine
WO2008026060A3 (fr) Procédé, système et dispositif pour la synchronisation d&#39;un serveur et d&#39;un dispositif mobile
EP2498200A4 (fr) Procédé d&#39;authentification pendant la mise à jour d&#39;un logiciel incorporé dans un terminal d&#39;information, système et programme correspondant
WO2016130406A3 (fr) Protection de la sécurité de données sensibles
IN2014KN02750A (fr)

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200780019624.6

Country of ref document: CN

WWE Wipo information: entry into national phase

Ref document number: 2648377

Country of ref document: CA

WWE Wipo information: entry into national phase

Ref document number: 8433/DELNP/2008

Country of ref document: IN

Ref document number: 2007727739

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2008142008

Country of ref document: RU

WWE Wipo information: entry into national phase

Ref document number: 12296392

Country of ref document: US