Method for determining inquiry answer type bidirectional identification and business, and encipher device applying the method

An encryption device and identity confirmation technology, applied in the direction of secure communication device, data processing application, transmission system, etc., can solve the problem of not being tampered and deceived.

CN101471770AInactive Publication Date: 2009-07-01毛华
1 Cites 11 Cited by

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
Publication Date
2009-07-01
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
Patent Text Reader

Abstract

The invention relates to a secure communication device and a method, in particular to a device and a method for sending and receiving a code by adopting a special manner. In the question answering mutual identity and transaction confirmation method and the device adopting the method, the confirmation method comprises identity verification and transaction content confirmation, and has the characteristic of mutual authentication. An encryption device is separated from the outside completely, and has no electronic connecting interface, so that the hacker attack can be avoided, and the device can also be used in the environment of no personal computer. In the device and the method, not only does a server identify a client in a unilateralism manner, but the client also discriminates the validity of the server through checking the validity of a quenstion and answers the quenstion after confirming the validity of the quenstion only, thereby effectively resisting fishing trap. By adopting the method and the encryption device, identity verification and electronic transaction can be performed safely in unsafe environments such as an Internet bar, etc.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The present invention relates to a secure communication device and method, in particular to a device and method for sending and receiving passwords in a special way. Background technique

[0002] At present, service agencies usually use three methods for identity and transaction confirmation: static passwords, dynamic passwords, USB password locks and smart cards and other hardware encryption methods. These three methods have their own advantages and disadvantages: the static password is easy to use but extremely insecure, and it is easy to be monitored and invalidated. At present, the methods of using dynamic passwords usually include dynamic passwords sent by short messages, two-dimensional password retrieval cards printed on paper, and the like. SMS dynamic passwords improve security, but there are also problems such as relying on the operator's network to send SMS, being unavailable in areas where SMS is not smooth, and requiring payment to teleco...

Examples

Embodiment 1

[0083] Using the two-way authentication method of the two parties of the transaction using the encryption device 1, the authentication method includes identity confirmation, and the identity confirmation includes the following steps:

[0084] (a) The customer service provider distributes independent encryption devices to dedicated customers;

[0085] (b) The user connects to the server through the network or telephone and enters the customer account number K;

[0086] (c) The server retrieves the server password Mo and the encryption algorithm Fo indicating the identity of the server according to the client account K;

[0087] (d) The server generates a random number N, calculates the encrypted result Q, Q=Fo(K, Mo, N), and displays N and Q to the user;

[0088] (e) The user inputs his account number K, random number N and encryption result Q on the encryption device;

[0089] (f) The encryption device calls the encryption algorithm fo of the verification server that comes w...

Embodiment 2

[0096] Using the two-way authentication method of the two parties of the transaction using the encryption device 1, the authentication method includes identity confirmation and transaction content confirmation, the identity confirmation is the same as the steps in embodiment 1, and the transaction content confirmation includes the following steps:

[0097] (A) The user enters the account T of the other party online;

[0098] (B) The server generates a random number Y, and calculates Q'=Fo(T, Mo, Y), and displays Y and Q' to the user;

[0099] (C) The user inputs T, Y and Q' on the encryption device;

[0100] (D) The encryption device invokes the encryption algorithm fo, and uses the mo stored on the encryption device to calculate the encryption result q', q'=fo(T, mo, Y);

[0101] (E) The encryption device compares q' and Q', if they are equal, it means that mo=Mo, fo=Fo, and the T value has not been tampered with, the server is not a trap, continue; if they are not equal, an...