Method realizing public key acquiring, certificater verification and bidirectional identification of entity

A public key certificate, entity technology, applied in the direction of user identity/authority verification, electrical components, transmission systems, etc., can solve the problems of complex protocols, non-compliance, limited user equipment storage resources, etc., to improve efficiency and effect, meet the Identify the effect of requirements

CN101364875BActive Publication Date: 2010-08-11CHINA IWNCOMM
0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2010-08-11

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention relates to a method for achieving public key acquisition, certificate validation and two-way authentication of an entity. The method comprises the following steps: (1) transmitting a message 1 to an entity B by an entity A; (2) transmitting a message 2 to the entity A by the entity B after receiving the message 1; (3) transmitting a message 3 to a credible third party TP by the entity A after receiving the message 2; (4) determining response RepTA after the credible third party TP receives the message 3; (5) returning a message 4 to the entity A by the credible third party TP; (6) processing the message 4 after the entity A receives the message 4; (7) returning a message 5 to the entity B by the entity A; and (8) acquiring the authentication result of the entity A after the entity B receives the message 5 from the entity A. The method can achieve public key acquisition, certificate validation and two-way authentication of the entity by fusing in one protocol, thereby facilitating the execution efficiency and the effect of the protocol and facilitating the combination with various public acquisition and public key certificate state enquiry protocols. The method suits with a user-access point-server network structure accessed to the network.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to a method for realizing public key acquisition, certificate verification and two-way authentication of an entity. Background technique

[0002] In the current computer network and communication network, before the user logs into the network for secure communication, entity authentication between the user and the network must be completed, either one-way authentication or two-way authentication. The authentication mechanism used is generally divided into two categories: based on symmetric key algorithm and based on public key (asymmetric key) algorithm.

[0003] The authentication mechanism based on the public key algorithm and technology requires that the participant entity must have a pair of keys, that is, a public-private key pair, and the public key needs to be notified to other participant entities. Available notification methods include out-of-band notification method and certificate method, among which the out-of-band no...

Examples

Embodiment Construction

[0034] Referring to Fig. 2, the method of the present invention involves three security elements, namely two entities A and B and a trusted third party TP, through the online trusted third party TP, two-way authentication is completed between entities A and B, and obtaining The status of the peer entity's valid public key or public key certificate.

[0035] Entity A or B is represented by entity X; then R X Indicates the random number generated by entity X; Cert X is the public key certificate of entity X; ID X Is the identity of entity X, by the certificate Cert X Or the entity's distinguisher X indicates; ReqX indicates the request generated by entity X, requesting information such as the valid public key of the peer entity or the state of the public key certificate; ReqXT indicates the request generated by entity X or forwarded to the trusted third party TP Request; RepX represents the response sent to entity X for ReqX, that is, responds to entity X with the requested ent...