Authentication method

By employing a verifier/provider type authentication method, which utilizes functions to generate an image list and erase unused data, the system addresses the security shortcomings of existing authentication methods in the face of fault injection attacks, thus achieving more secure electronic device authentication.

CN121966871APending Publication Date: 2026-05-01STMICROELECTRONICS INT NV
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STMICROELECTRONICS INT NV
Filing Date
2025-10-28
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing authentication methods are not secure enough against fault injection attacks, are difficult to prevent the cloning of electronic devices, and lack effective data protection.

Method used

An authentication method using a verifier/provider type is employed, where the provider device stores far more data than actually used. An image list is generated and verified through a function, and unused data is erased after authentication to prevent malicious devices from reconstructing all data.

Benefits of technology

It improves the security of authentication, prevents malicious devices from obtaining all data by observing the authentication process, and enhances the protection of electronic devices, especially suitable for the authentication of consumables and terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966871A_ABST
    Figure CN121966871A_ABST
Patent Text Reader

Abstract

The invention relates to an authentication method in which a first device stores a first data set list, comprising the following steps: a) a second device sends a second information list related to data to the first device; b) sending, by the first device to the second device, a third image list, which is generated from the data of the first data set list by means of the first function and which has the same information as the information of the second information list related to the data; and c) verifying, by the second device, whether an image of the data of the third image list conforms to data of a fourth dataset list corresponding to an image of the first dataset list generated by the second function, the information of the first dataset list being included in a second information list related to the data.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication methods Cross-references to related applications

[0001] This application claims priority to French patent application FR2411830, filed on October 29, 2024, the contents of which are incorporated herein by reference in their entirety to the fullest extent permitted by law. Technical Field

[0002] This disclosure generally relates to electronic circuits and devices, and more specifically to the security of electronic circuits and devices. More precisely, this disclosure relates to the implementation of an authentication method that, for example, enables multiple electronic devices to initiate reliable communication. Background Technology

[0003] Communication between two electronic devices or circuits typically occurs before the authentication phase. During this phase, the authentication method implemented by the two devices verifies whether they are authorized to communicate with each other.

[0004] Authentication methods are typically used for communication between terminal devices and electronic or peripheral devices (such as consumables or accessories). In this context, authentication methods verify the peripheral device's access to the terminal device's data and / or functions. Authentication methods are the primary means of preventing malicious devices from attempting to access the data and / or functions of other devices.

[0005] The goal is to at least partially improve known authentication methods.

[0006] More secure authentication methods are needed to allow for more robust authentication of electronic circuits or devices, especially against fault injection attacks.

[0007] In particular, it is necessary to prevent clones of electronic devices from being authenticated at their location.

[0008] There is a need for electronic circuits and devices that can enable more secure authentication methods.

[0009] It needs to be able to overcome all or some of the shortcomings of known authentication methods. Summary of the Invention

[0010] The embodiment provides an authentication method of the verifier / provider type, wherein the prover device stores far more data than the data effectively used and potentially disclosed during the implementation of the authentication method.

[0011] According to a first aspect, an embodiment provides a method for authenticating a first device to a second device, wherein the first device stores a first data group list, the method comprising the following steps: a) the second device sending a second information list related to data to the first device; b) the first device sending a third image list to the second device, the third image list being generated from data in the first data group list by a first function and having the same information as the information in the second information list related to data; and c) the second device verifying whether the images generated from the data in the third image list by a second function conform to data in a fourth data group list corresponding to the images in the first data group list, wherein the information in the first data group list is included in the second information list related to data.

[0012] Another embodiment provides an electronic device configured to operate as a first device in a method for authenticating a first device to a second device, the first device storing a first data group list, and the method comprising the steps of: a) the second device sending a second information list associated with data to the first device; b) the first device sending a third image list to the second device, the third image list being generated from data in the first data group list by a first function and having the same information as the second information list associated with data; and c) the second device verifying whether the images generated from the data in the third image list by a second function conform to data in a fourth data group list corresponding to images in the first data group list, the information of the first data group list being included in the second information list associated with data.

[0013] Another embodiment provides an electronic device configured to operate as a second device in a method for authenticating a first device to a second device, the first device storing a first data group list, and the method comprising the steps of: a) the second device sending a second information list associated with data to the first device; b) the first device sending a third image list to the second device, the third image list being generated from data in the first data group list by a first function and having the same information as the second information list associated with data; and c) the second device verifying whether the images generated from the data in the third image list by a second function conform to data in a fourth data group list corresponding to images in the first data group list, the information of the first data group list being included in the second information list associated with data.

[0014] According to an embodiment, the method further includes step d): before step a): the first device sends a fourth data group list to the second device.

[0015] According to an embodiment, the method further includes step e) performed between steps b) and c): the first device deletes the entire data group of data from the first data group list, the information of which forms part of the third image list.

[0016] According to an embodiment, the second information list related to the data is a data index list.

[0017] According to an embodiment, the second information list related to the data is a list of data values.

[0018] According to an embodiment, the method includes step f) between step d) and step a), wherein the first device sends a fifth information list associated with the data group already used to implement the authentication method to the second device, and in step a), the second information list associated with the data does not include information already included in the fifth information list associated with the data group.

[0019] According to an embodiment, the fifth information list associated with the data group includes a pair, which includes a data index and a value of data associated with the data index.

[0020] According to an embodiment, the method further includes: step G), implemented by a second device after step f): verifying a fifth information list associated with the data group.

[0021] According to an embodiment, in step d), the first device further sends a certificate, and the method includes step h) after step d): the second device performs certificate verification.

[0022] According to an embodiment, the first device includes a counter configured to count the number of times the first device implements the authentication method.

[0023] According to an embodiment, when the counter exceeds the maximum value, the first device stops implementing the authentication method and does not authenticate the second device.

[0024] According to an embodiment, the second device is configured to verify the value of the counter.

[0025] According to the embodiment, if the verification in step c) is successful, the first device authenticates the second device; if the verification in step b) is unsuccessful, the first device does not authenticate the second device.

[0026] Another embodiment provides an authentication system that includes the first device and the second device as described above.

[0027] Another embodiment provides a computer program product including program code instructions that, when executed on a computer, are used as a first device or as a second device to perform the steps of the aforementioned method.

[0028] According to a second aspect, an embodiment provides a method for authenticating a first device to a second device, wherein the first device stores a first data group list, the method comprising the following steps: a) the first device sending to the second device a second data group list corresponding to images generated by a first function of the first data group list; b) the first device sending to the second device a fourth image list, the fourth image list being generated by a second function from data of the first data group list and having the same information as the third list; and c) the second device verifying whether the images of the fourth list data conform to the data of the second data group list, wherein the information of the second data group list is included in the third list.

[0029] An embodiment provides a device configured to operate as a first device according to an authentication method.

[0030] An embodiment provides a device configured to operate as a second device according to an authentication method.

[0031] An embodiment provides a system including a first device and a second device configured to implement an authentication method.

[0032] An embodiment provides a computer program product including program code instructions that, when executed on a computer, are used as a first device and / or as a second device to perform the steps of the aforementioned method.

[0033] The alternatives related to the first aspect are applicable as much as possible to the embodiments of the second aspect.

[0034] According to a third aspect, an embodiment provides a method for authenticating a first device to a second device, wherein the first device stores a first data group list, the method comprising the following steps: a) the first device sending a second data group list corresponding to images generated by a first function of the first list to the second device; b) the second device sending a third information list related to the data to the first device; c) the first device sending a fourth image list to the second device, the fourth image list being generated by a second function from the data of the first data group list and having the same information as the information in the third information list related to the data; and d) the second device verifying whether the images in the data of the fourth image list conform to the data of the second data group list, wherein the information of the second data group list is included in the third information list related to the data.

[0035] An embodiment provides a device configured to operate as a first device according to an authentication method.

[0036] An embodiment provides a device configured to operate as a second device according to an authentication method.

[0037] An embodiment provides a system including a first device and a second device configured to implement an authentication method.

[0038] An embodiment provides a computer program product including program code instructions that, when executed on a computer, are used as a first device and / or as a second device to perform the steps of the aforementioned method.

[0039] The alternatives described with respect to the first aspect are applicable as much as possible to the embodiments of the third aspect. Attached Figure Description

[0040] The foregoing features and advantages, as well as other features and advantages, are described in detail in the remainder of the disclosure, which is by way of example and not limitation, of specific embodiments and with reference to the accompanying drawings, in which:

[0041] Figure 1 shows an example of an electronic device configured to implement an authentication method in an implementation mode;

[0042] Figure 2 shows a block diagram illustrating an implementation mode of a method for authenticating a first device to a second device;

[0043] Figure 3 shows a block diagram illustrating the implementation of the steps in the implementation mode of Figure 1; and

[0044] Figure 4 shows a block diagram illustrating another implementation mode of a method for authenticating a first device to a second device. Detailed Implementation

[0045] In the various figures, the same elements are represented by the same reference numerals. In particular, common structural and / or functional elements in various embodiments may have the same reference numerals and may have exactly the same structure, dimensions, and material properties.

[0046] For clarity, only those steps and elements that help to understand the described embodiments are shown and described in detail.

[0047] Unless otherwise stated, when two elements are said to be connected to each other, it means a direct connection without any intermediate elements other than a conductor. When two elements are said to be coupled to each other, it means that the two elements can be connected or can be connected via one or more other elements.

[0048] In the following description, unless otherwise stated, when referring to absolute positional qualifiers (such as "front", "back", "up", "down", "left", "right", etc.), or relative positional qualifiers (such as "up", "down", "above", "below", etc.), or orientation qualifiers (such as "horizontal", "vertical", etc.), the orientation of the accompanying drawings shall be mentioned.

[0049] Unless otherwise stated, expressions such as “approximately,” “roughly,” “basically,” and “on the order of magnitude” indicate a percentage of 10%, preferably 5%.

[0050] The embodiments described below relate to the implementation of an authentication method capable of authenticating a first electronic device to a second electronic device, for example, for future communication between the first and second devices. More specifically, these embodiments are authentication methods for a verifier / provider type (also referred to as a verifier / candidate type), in which a verifier device (here, the second device) selects one or more data segments to be disclosed by a prover device (here, the first device) and requests that it disclose this data. The prover device then sends back the requested one or more data segments or the result of an application transformation of this data to the verifier device so that the verifier device can verify whether the prover device possesses the correct data. If the verification result is correct, the prover device authenticates the verifier device. The authentication system is an electronic system that includes both the verifier device and the prover device.

[0051] The embodiments described below relate more specifically to the implementation of an authentication method in which a verifying device selects a data segment from a set of data sent by a proving device to perform verification. A key feature of these embodiments is that the proving device stores significantly more data than is actually used and potentially disclosed during the implementation of the authentication method. Instead of storing all used data, each data segment is included in a set of data (hereinafter referred to as a data tuple), where only a portion of the data is used for the implementation of authentication. Once one or more data segments of a tuple have been used by the implementation of authentication, the remaining unused data in the tuple is erased. This authentication method is described in detail with reference to Figures 2 through 4. This type of method is particularly effective against malicious attacks in which a spy device (also known as a clone) attempts to replace the proving device. In fact, due to the embodiments described below, it is impossible for a spy device to access or learn all the secret data or secrets stored by the proving device by observing its already implemented authentication.

[0052] Furthermore, the embodiments described below are particularly suitable for authenticating “consumable” type electronic devices to so-called “terminal” electronic devices. For example, such devices are ink cartridges (consumables) configured to operate on a certain type of printer (terminal), or cards configured to operate with a payment terminal.

[0053] Furthermore, the above embodiments are particularly suitable for use in any type of industrial market requiring certification. More specifically, this certification approach can be applied to: the automotive industry, such as in the fields of vehicle electrification or advanced driver assistance systems (ADAS); industrial sectors, such as in the fields of green energy, infrastructure electrification, the Internet of Things (IoT), and smart homes, where electricity and energy consumption and data exchange are key elements; the personal electronics industry, such as in the fields of mobile phones and the Internet of Things (IoT) and high-speed interfaces; and the communications equipment, computer, and peripheral equipment industries, such as in the fields of infrastructure and data centers and in the field of low Earth orbit (LEO) satellites.

[0054] Figure 1 is a block diagram that schematically illustrates an example architecture of an electronic device 100 configured to implement an authentication method. Device 100 can be either a verifying device or a proving device in the authentication method. The authentication method is described with reference to Figures 2 through 4.

[0055] According to an example, electronic device 100 includes a processor 101 (CPU) configured to perform various processing operations on data stored in memory and / or provided by other circuitry of device 100. According to an embodiment, processor 101 is configured to implement an authentication method.

[0056] According to the example, the electronic device 100 also includes one or more different types of memory 102 (MEM), which include, for example, non-volatile memory, volatile memory, and / or read-only memory. Each memory 102 is configured to store different types of data. According to an embodiment, one or more memories 102 are configured to preferably securely store data capable of implementing authentication methods.

[0057] According to the example, the electronic device 100 also includes a secure element 103 (SE) configured to process sensitive and / or confidential data. The secure element 103 may include its own processor(s), its own memory, etc. According to an embodiment, the secure element 101 may be configured to implement authentication methods, or at least store data that allows the implementation of authentication methods.

[0058] According to the example, the electronic device 100 may also include one or more interface circuits 104 (input / output) configured to send and / or receive data originating from the external device 100. The interface circuits 104 may also be configured to display data, such as a display screen. According to embodiments, the interface circuits(s) 104 are configured to implement authentication methods, or at least store data capable of implementing authentication methods.

[0059] According to the example, the electronic device 100 also includes different functional operation circuits 105 (FCT1) and 106 (FCT2) configured to perform different functions. For example, circuits 105 and 106 may include measurement circuits, data conversion circuits, etc. According to the embodiment, circuits 105 and 106 may include one or more circuits configured to implement an authentication method or at least store data capable of implementing the authentication method.

[0060] According to the example, the electronic device 100 also includes one or more data buses 107 configured to transmit data between its various components.

[0061] According to an embodiment, a system comprising two devices of the type 100 can be configured to implement an authentication method. Such a system is called an authentication system.

[0062] More generally, electronic device 100 may be a computer including means or program code instructions for performing the steps of the authentication method according to an embodiment. According to a first example, electronic device 100 may be a computer including means or program code instructions for performing the steps of the authentication method according to an embodiment as a proving device. According to a second example, electronic device 100 may be a computer including means or program code instructions for performing the steps of the authentication method according to an embodiment as a verifying device. According to a third example, electronic device 100 may be a computer including means or program code instructions for performing the steps of the authentication method according to an embodiment as both a proving device and a verifying device.

[0063] Figure 2 is a block diagram illustrating a first implementation mode of authentication method 200, which enables a first electronic device P (also referred to as the certifying device P (certifier)) to authenticate a second electronic device V (also referred to as the verifying device V (verifier)). In other words, authentication method 200 is applicable to an authentication system including devices P and V. According to an embodiment, each of devices P and V is of the type with respect to device 100 described in Figure 1.

[0064] As mentioned earlier, authentication method 200 is a verifier / provider type method.

[0065] The initial step 201 (preparation M, C) implemented by device P is a data preparation step for the subsequent steps of method 200. This step can be implemented once and then used for multiple implementations of the authentication method 200.

[0066] According to an embodiment, during this initial step 201, the proving device P generates data to enable it to implement the authentication method 200. More specifically, device P generates a list M200 of s data groups (also referred to as data tuples), where s is an integer greater than or equal to 1. Each group in list M200 includes t data, where t is an integer greater than 1. For example, the data included in list M200 is binary data.

[0067] For the remainder of the description, the list M200 can be represented as a matrix consisting of s rows and t columns, where: each coefficient of the matrix is ​​m200 ij (i is an integer in the range of 0 to s-1, and j is an integer in the range of 0 to t-1) represents a data segment; and each row of the matrix represents a set of t data segments as described above.

[0068] Therefore, list M200 can be represented by the following mathematical formula:

[0069] The proving device P is also configured to implement a function f that device V can also implement. According to an embodiment, function f is a one-way function, i.e., an irreversible function or a quasi-one-way or quasi-reversible function, i.e., a function whose inversion operation requires significant computational resources. By example, function f can be a modular exponentiation function, a scalar multiplication function on an elliptic curve, or a hash function. Other examples of function f will be apparent to those skilled in the art.

[0070] Furthermore, during this initial step 201, the proving device P can generate an image f(M200) of the data in list M200 through the operation of function f. For this purpose, function f is applied to each data segment of the data group in list M200. Therefore, the image f(M200) of list M200 can be represented in matrix form by the following mathematical formula:

[0071] Furthermore, during this initial step 201, the proving device P itself can be proven, for example, by the proving device, i.e., the proving device P can request the proving device to generate a certificate for it. This proof operation aims to obtain a trust proof from a device deemed reliable (hereinafter referred to as the proving device). At the end of the proof operation, device P obtains proof data C200 or certificate C200. According to the example, the proof data depends on the identification data segment IdP200 or the IdP200 identifier of the proving device P. According to the example, the proof data also depends on the data in list f(M200). According to the example, the proof data further depends on function f. Examples of the proof steps are described in detail with reference to Figure 3.

[0072] Following step 201, in step 202 (sending C) performed by device P, authentication method 200 begins with the certifying device P sending data to the verifying device V. According to the example, device P sends its identifier IdP200, its certificate C200, and an image f(M200) of a list M200 generated by the application function f.

[0073] In step 203 (verification of C, f(M)) performed by device V following step 202, device V receives the data sent in step 202, such as identifier IdP200, certificate C200, and image f(M200), and performs verification on this data. According to an embodiment, in step 203, device V performs a verification step for certificate C200. According to an example, in step 203, device V performs a verification step for identifier IdP200. According to an example, in step 203, device V performs a verification step for image f(M200). If the implemented verification indicates that one of the received data does not conform to one or more criteria (output F of step 203), the next step is step 204 (failure); otherwise, the authentication method continues.

[0074] In step 204, performed by device V, device V has determined that the verification step provided a negative result. This indicates that at least one data segment of the multiple data segments provided by device P is non-compliant, and authentication from device P to device V cannot proceed. Therefore, the authentication method stops and ends with the failure of authentication from device P to device V.

[0075] In step 205 (verifying Cnt), performed by device P following step 202, device P verifies the value of an internal counter, Cnt200. This internal counter enables the tracking of the number of times device P implements authentication method 200. Therefore, each time device P successfully implements authentication method 200, it increments the value of the internal counter, Cnt200.

[0076] According to an alternative embodiment, an internal counter can be used to track the number of times device P successfully or unsuccessfully implements authentication method 200. Therefore, the counter can increment each time device P implements authentication method 200 and exposes one or more secrets.

[0077] Therefore, in step 205, the device P verifies that the value Cnt200 does not exceed the maximum value Cnt200Max. If the value Cnt200 is equal to or greater than the maximum value Cnt200Max (output F of step 205), the next step is step 206 (failure); otherwise, the authentication method continues. The maximum value Cnt200Max is defined based on the number of data groups in list M200. According to an embodiment, the maximum value Cnt200Max is less than or equal to the integer s.

[0078] According to an alternative embodiment, step 205 may be performed at other times in the authentication method 200, such as before step 202, after step 207 as described below, or before step 213 as described below.

[0079] In step 206, performed by device P following step 205, device P has determined that it has executed the authentication method too many times. Authentication from device P to device V cannot proceed. Therefore, the authentication method stops and ends with the failure of device P's authentication to device V.

[0080] Following step 205, in step 207 (sending list L), implemented by device P, the proving device P sends list L200 to the authenticating device V, enabling the identification of data groups previously used to implement authentication method 200 that are part of list M200. By way of example, when device P implements its first authentication method 200, list L200 is an empty list.

[0081] According to an embodiment, list L200 includes indices of data groups from list M200 that have already been used. The index of a data group is the row number corresponding to that group in the matrix representing list M200. In other words, the index of a data group is given by the value of the associated integer i defined above.

[0082] According to another embodiment, list L200 includes indices of data groups that have been used, but also includes data values ​​of these data groups that have been used to implement authentication method 200. In this case, list L200 can be said to include pairs, each pair including an index of a data group that has been used and multiple values ​​of the data group that have been used.

[0083] Alternatively, in step 207, the proving device P may also send the value of its internal counter Cnt200 to the verifying device V.

[0084] In step 208 (verification L), which is implemented by device V following step 207, the verifying device V has received list L200 and implemented one or more verification operations of list L200.

[0085] According to the first example, does the number of indices in the verification list L200 of the verifying device V not exceed the number of data groups in the previously provided image f(M200)? According to a variant, if the verifying device also receives the value Cnt200 from the internal counter of the proving device P, then the number of indices in the verification list L200 of the verifying device V is compatible with the value Cnt200. More specifically, if each implementation of the authentication method 200 uses k data items included in the group, where k is an integer in the range from 1 to s-1, then the number of elements in the list L200 (denoted as #(L200)) follows the following mathematical inequality:

[0086] According to the second example, if list L200 includes data values ​​from groups that have already been used, then the verifying device V verifies whether these data values ​​are correct. To do this, the verifying device V can implement a function f and apply it to the received data.

[0087] According to the third example, if list L200 includes data values ​​from already used groups, then the verification device V verifies whether these data values ​​belong to different data groups.

[0088] Those skilled in the art will be able to find other methods to verify list L200.

[0089] If the performed verification(s) indicate that the received list L200 does not conform to one or more criteria (output F of step 208), the next step is step 204; otherwise, the authentication method continues.

[0090] Following step 208, in step 209 (selecting k data points) implemented by device V, the verifying device V selects k data points from the image f(M200) of the list M200 provided by the proving device P in step 202, where k is an integer in the range of 1 to s-1. In other words, the verifying device V generates a list I200 of k data indices. The so-called index of a data segment here is the row and column number corresponding to that data segment in the matrix representing the list M200 or image f(M200). In other words, the index of the data group is given by the values ​​of the associated integers i and j as defined above. The data selected by the verifying device cannot belong to a data group already used by the proving device in the previous authentication method. In other words, the number of rows of the selected data cannot correspond to the number of rows existing in the list L200.

[0091] According to another embodiment, list I200 does not include a data index, but only includes the values ​​of the image generated by the function f. Generally, list I200 can be said to include partial information related to the data to be used.

[0092] Following step 209, in step 210 (sending index) implemented by device V, the verifying device V sends list I200 to the proving device P.

[0093] In step 211 (preparing k data items), performed by device P following step 210, the proving device P receives list I200 and prepares k data items of list M200 corresponding to the indices of list I200. In other words, the proving device P selects (or more) data groups selected by the verifying device V, and selects the data selected by the verifying device V from those groups. As described below, in step 211, the proving device P prepares data list M(I200) of list M200 corresponding to the indices of list I200.

[0094] According to the variant, in step 211, device P can verify the list I200 it has received, and if the latter is not compliant, then the method stops.

[0095] In step 212 (erasure), which is performed simultaneously by device P and step 211 following step 210, the proving device P erases data from the (multiple) groups or tuples selected by the verifying device V that have not yet been selected by the verifying device V. In other words, the proving device P erases all data from the selected (multiple) groups from list M200, whose indices are not in list M200.

[0096] According to an alternative embodiment, in step 212, the proving device P erases all data from the list M200 of the groups(s) selected by the verifying device V. In practice, data to be sent to the verifying device V is only erased after it has been sent.

[0097] Following step 212, in step 213 (sending k data items), the proving device P sends the requested data list M (I200) to the verifying device V.

[0098] In step 214 (Cnt++), performed by device P following step 213, device P increments the value of its internal counter Cnt200. According to a variant, step 214 can be performed simultaneously with either step 211 or step 213.

[0099] In step 215 (verification), implemented by device V following step 213, the verifying device V receives a list M(I200) of k requested data segments and verifies their compliance. To do this, the verifying device V uses a function f and applies it to each of the multiple data segments in the list M(I200). Then, the verifying device V compares the image generated by function f from the multiple data segments of the list M(I200) with the multiple data segments of the image f(M200) selected due to the index of the list I200.

[0100] If the performed verification(s) indicate that one of the received data segments is non-compliant (output F of step 215), the next step is step 204; otherwise, the next step is step 216 (success).

[0101] In step 216, performed by device V, the verifying device V has effectively verified that all the data provided by the proving device P is correct. Then, the proving device P authenticates to the verifying device V, and the authentication method succeeds. According to the example, step 214 is performed by the proving device P after step 216.

[0102] The advantage of this method is that removing a portion of the unused data from list M200 prevents malicious electronic devices from replacing the certifying device P. In fact, a malicious device without data list M200 cannot reconstruct it entirely based on the data that can be disclosed in the subsequent steps 213 of the implementation of authentication method 200, because a portion of the data set is erased without ever being transmitted.

[0103] Figure 3 is a block diagram illustrating an example implementation of a method 300 for proving electronic equipment (as shown in Figure 2, the proving device P) to electronic equipment C (certificate) (also referred to as the proving device C). In other words, method 300 is suitable for use during step 201 described with respect to Figure 2.

[0104] In initial step 301 (generating M) performed by device P, the proving party device P generates a list M300 of data groups of the type described in Figure 2, M200. In other words, device P generates a list M300 of s data groups. Each group in list M300 includes t data items. The integers s and t are the same as the integers defined with respect to Figure 2.

[0105] In step 302 (application of f), performed by device P following step 301, device P uses the function f defined with respect to FIG2 and applies it to list M300 to obtain image f(M300). Image f(M300) is of the same type as image f(M200) described with respect to FIG2. In other words, function f is applied to each data segment of the data group in list M300.

[0106] In step 303 (sending f(M)) performed by device P following step 302, the proving device P sends image f(M300) to the proving device C. According to the example, the proving device P also sends identification data segment IdP300 or identifier IdP300 to the proving device C.

[0107] In step 304 (verification f(M)) implemented by device C following step 303, the prover device C has received the image f(M300) and the identifier IdP300 (if present) and initiates one or more verification operations on this data.

[0108] According to the first example, the prover device C can verify whether the function f has been correctly applied, for example, by analyzing the format of the data provided by the prover device P.

[0109] According to another example, is the verifier device C verification identifier IdP300 not part of the list of identifiers that are prohibited from providing proof data segments?

[0110] If the performed verification(s) indicate that one of the received data segments does not conform to one or more criteria (output F of step 304), the next step is step 305 (failure); otherwise, the operation continues.

[0111] In step 305, the proving device C has determined that the verification step provides a negative result. This indicates that at least one data segment provided by device P is non-compliant, and proof of device P is impossible. Proof method 300 therefore stops and ends with the failure of proof of device P.

[0112] In step 306 (verifying f(M)) performed by device C following step 304, the data of image f(M300) has been identified as compliant by prover device C. Therefore, prover device C prepares proof data C300. To this end, according to the example, prover device C uses the data of image f(M300) and the identifier IdP300 (if it exists). According to the example, prover device C obtains certificate C by applying a signature function to the data of image f(M300) and the identifier IdP300 (if it exists).

[0113] Following step 306, in step 307 (verification f(M)) performed by device C, the proving device sends certificate C300 to the proving device P. Proving device P is now proven.

[0114] Figure 4 is a block diagram illustrating a second implementation mode of the authentication method 400, which enables a first electronic device P, referred to as the certifying device P (the certifier), to authenticate a second electronic device V (the verifier), referred to as the verifying device V (the verifier). In other words, the authentication method 400 is applicable to an authentication system comprising devices P and V. According to an embodiment, devices P and V belong to the type of device 100 described with respect to Figure 1.

[0115] Authentication method 400 is a method of the verifier / provider type.

[0116] Authentication method 400 is similar to authentication method 200 described with respect to Figure 2. The common elements of methods 200 and 400 will not be described in detail again. Only the differences between methods 200 and 400 will be emphasized.

[0117] More specifically, method 400 is a specific application of method 200, wherein the data generated by the proving device P in the form of a list M400 is secret data, and for this purpose a second function g is used to prove to the verifying device V the knowledge of the requested data in the list M400.

[0118] The initial step 401 (preparation M, C) implemented by device P is a data preparation step for the subsequent steps of method 400. This step can be implemented once and then used for multiple implementations of the authentication method 400.

[0119] According to an embodiment, during this initial step 401, the proving device P generates data to enable it to implement the authentication method 400. More specifically, device P generates a list M400 of s data groups (also referred to as data tuples), where s is an integer greater than or equal to 1. Each group in list M400 includes t data, where t is an integer greater than 1. For example, the data included in list M400 is binary data.

[0120] Similar to list M200 described in Figure 2, list M400 can be represented as a matrix given by the following mathematical formula:

[0121] According to an embodiment, the data in list M400 is secret data, and its value does not need to be disclosed. As an example, the data in list M400 is a signature key.

[0122] The device P is also configured to implement function f. Function f has been described with reference to Figure 2. According to a specific example, function f can be a function that enables the retrieval of the public signature key from the private signature key.

[0123] The proving device P is also configured to implement a function g. According to an example, function g is a signature function that enables a signature to be provided based on a private key. According to a specific example, function g is, for example, a signature function based on modular exponentiation or scalar multiplication on an elliptic curve. Other examples of function g can be used by those skilled in the art. According to another embodiment, function g is an identity function, in which case method 400 is the same as method 200.

[0124] Furthermore, during this initial step 401, the proving device P can generate an image f(M400) of the data in list M400 using a function f. According to the example, image f(M400) represents the public key associated with the private key in list M400. For this purpose, function f is applied to each data segment in the data group of list M400. Therefore, the image f(M400) of list M400 can be represented using the following mathematical formula:

[0125] Furthermore, during this initial step 401, the proving device P can be proven, for example, by the proving device, such as through a proof method of the type described in FIG3. At the end of the proof operation, device P acquires proof data C400 or a certificate C400.

[0126] Following step 401, in step 402 (sending C) performed by device P, authentication method 400 begins with the certifying device P sending data to the verifying device V. According to the example, device P sends its identifier IdP400, certificate C400, and an image f(M400) of list M400 via function f.

[0127] In step 403 (verification of C, f(M)) performed by device V following step 402, device V receives the data sent in step 402, namely the identifier IdP400, certificate C400, and image f(M400), and performs verification on this data. The verification operation(s) performed in step 403 are of the same type as the verification operation(s) performed in step 203 of method 200. If the performed verification(s) indicates that one of the received data segments is non-compliant (output F of step 403), the next step is step 404 (failure); otherwise, the authentication method continues.

[0128] In step 404, performed by device V, device V has determined that the verification step provided a negative result. This indicates that at least one data segment of the multiple data segments provided by device P is non-compliant, and authentication from device P to device V cannot proceed. Therefore, the authentication method stops and ends with the failure of authentication from device P to device V.

[0129] In step 405 (verifying Cnt), performed by device P following step 402, device P verifies the value of an internal counter, Cnt400. This internal counter enables the tracking of the number of times device P implements authentication method 400. Therefore, each time device P successfully implements authentication method 400, it increments the value of the internal counter, Cnt400.

[0130] According to an alternative embodiment, an internal counter can be used to track the number of times device P successfully or unsuccessfully implements authentication method 400. Therefore, the counter can increment each time device P implements authentication method 400 and uses one or more secrets.

[0131] Therefore, in step 405, the device P verifies that the value Cnt400 does not exceed the maximum value Cnt400Max. If the value Cnt400 is equal to or greater than the maximum value Cnt400Max (output F of step 405), the next step is step 406 (failure); otherwise, the authentication method continues.

[0132] According to an alternative embodiment, step 405 may be performed at other times in the authentication method 400, such as before step 402, after step 407 as described below, or before step 413 as described below.

[0133] In step 406, performed by device P, device P has determined that it has executed the authentication method too many times. Authentication from device P to device V cannot proceed. Therefore, the authentication method stops and ends with the failure of device P's authentication to device V.

[0134] In step 407 (sending list L), performed by device P following step 405, the proving device P sends list L400 to the verifying device V so that the data group previously used to implement authentication method 400 can be identified in list M400.

[0135] According to an embodiment, similar to list L200 in method 200, list L400 includes indices of used data groups from list M400, but may also include data values ​​of these groups that have been used to implement authentication method 400. In this case, list L400 may be said to include pairs, each pair including an index of a used data group and multiple data values ​​of the used data group(s). According to an example, the data values ​​of the group may be a signature generated from a private key.

[0136] In step 408 (verification L), performed by device V following step 407, the verifying device V has received list L400 and implements one or more verification operations for list L400. Step 408 is similar to step 208 of method 200 and implements similar verification operations. Those skilled in the art will be able to find other methods for verifying list L400.

[0137] If the performed verification(s) indicate that the received list L400 does not conform to one or more criteria (output F of step 408), the next step is step 404; otherwise, the authentication method continues.

[0138] In step 409 (selecting k data points), performed by device V following step 408, the verifying device V selects k data points from the image f(M400) of the list M400 provided by the proving device P in step 402, where k is an integer in the range 0 to s. In other words, the verifying device V generates a list I400 of k data indices.

[0139] Following step 409, in step 410 (sending index) implemented by device V, the verifying device sends list I400 to the proving device P.

[0140] In step 411 (preparing k data items), performed by device P following step 410, the proving device P receives list I400 and prepares k data items of list M400 corresponding to the indices of list I400. In other words, the proving device P selects (multiple) data groups selected by the verifying device V, and selects the data selected by the verifying device V from those groups(multiple). It can then be said that in step 411, the proving device P prepares data list M(I400) of list M400 corresponding to the indices of list I400.

[0141] Furthermore, contrary to authentication method 200, the proving device P applies function g to list M(I400) to obtain image g(M(I400)). For this purpose, function g is applied to each data segment of list M(I400). Here, function g has the function of preventing data disclosure during the transmission of data from list M400 to the verifying device V. Furthermore, according to the example, function g is a function that generates a signature using a private key, and the message to be signed is fixed and predetermined. According to another example, the message to be signed is selected by device V.

[0142] In step 412 (erasure), which is performed simultaneously by device P and step 411 following step 410, the proving device P erases the data in the group selected by the verifying device V that has not yet been selected by the verifying device V. In other words, the proving device P erases all data from the selected group from list M400, the indices of which are not in list M400.

[0143] According to an alternative embodiment, in step 412, the proving device P erases all data from the group selected by the verifying device V from list M400.

[0144] Following step 412, in step 413 (sending k data items) implemented by device P, the proving device P sends the requested data list g(M(I400)) to the verifying device V.

[0145] In step 414 (Cnt++) performed by device P following step 413, the proving device P increments the value of its internal counter Cnt400.

[0146] Following step 413, in step 415 (verification) implemented by device V, the verifying device V receives a list g(M(I400)) of k requested data items and verifies their compliance. For this purpose, the verifying device V can use a verification function different from the function f and the list f(I400); according to the example, this verification function corresponds to a list of public keys. According to the example, the verifier verifies the correctness of the signature of the list g(M(I400)) based on the public signature key of the list f(I400).

[0147] If the performed verification(s) indicate that one of the received data segments is non-compliant (output F of step 415), the next step is step 404; otherwise, the next step is step 416 (success).

[0148] In step 416, performed by device V, the verifying device V has verified that all the data provided by the proving device P is correct. Then, the proving device P authenticates to the verifying device V, and the authentication method succeeds. According to the example, step 414 is performed by the proving device P after step 416.

[0149] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations can be combined, and other variations will occur to those skilled in the art.

[0150] Finally, based on the functional indications given above, the actual implementation of the embodiments and variations is within the capabilities of those skilled in the art.

Claims

1. A method for authenticating a first device to a second device, wherein the first device stores a first data group list, the method comprising the following steps: a) The second device sends a second list of data-related information to the first device; b) The first device sends a third image list to the second device, the third image list being generated from the data of the first data group list by a first function and having the same information as the information of the second information list related to the data; and c) The second device verifies whether the image in the data of the third image list matches the data in the fourth data group list corresponding to the image generated by the second function in the first data group list, wherein the information of the first data group list is included in the second information list related to the data.

2. The method according to claim 1, further comprising step d): prior to step a), whereby the first device sends the fourth data group list to the second device.

3. The method of claim 2, further comprising step f) between step d) and step a): the first device sends a fifth information list associated with the data groups already used to implement the authentication method from the fourth data group list to the second device, wherein in step a), the second information list associated with the data does not include information already included in the fifth information list.

4. The method of claim 3, wherein the fifth list comprises a pair, the pair comprising a data index and a value of the data associated with the data index.

5. The method according to claim 3, further comprising step g): after step f), the second device verifies the fifth information list.

6. The method of claim 2, wherein step d) further comprises sending a certificate by the first device, and the method further comprises step h) after step d): verifying the certificate by the second device.

7. The method of claim 1, further comprising step e) between step b) and step c): the entire data group from which the information of data forming part of the third image list is erased by the first device from the first data group list.

8. The method of claim 1, wherein the second information list related to the data is a data index list.

9. The method of claim 1, wherein the second information list associated with the data is a list of data values.

10. The method of claim 1, further comprising using a counter of the first device to count the number of times the first device implements the authentication method.

11. The method of claim 10, further comprising: When the counter exceeds the maximum value, the first device stops implementing the authentication method, so that the first device is not authenticated by the second device.

12. The method of claim 10, further comprising verifying the value of the counter by the second device.

13. The method of claim 1, wherein when step c) verification is successful, the first device authenticates the second device, and wherein when step c) verification is unsuccessful, the first device does not authenticate the second device.

14. The method of claim 1, wherein the second list of data-related information sent in step a) does not include information used in any prior implementation of the authentication method between the first device and the second device.

15. The method of claim 14, further comprising sending a fifth data list from the first device to the second device, the fifth data list including information related to data groups of the fourth data group list used in the prior implementation of the authentication method, wherein the second data-related information list does not include the information in the fifth data list.

16. An electronic device configured to operate as the first device in the authentication method according to claim 1.

17. An electronic device configured to operate as the second device in the authentication method according to claim 1.

18. An authentication system comprising a first device and a second device configured to implement the method of claim 1.

19. A computer program product comprising program code instructions that, when the program is executed on a computer, are configured to perform the steps of the method according to claim 1 as either the first device or the second device.

Citation Information

Patent Citations

  • new AMIDED MALEIC ACIDS, PROCESS FOR THEIR PREPARATION AND THEIR APPLICATION AS MEDICINES

    FR2411830A1