Credentials with optimized selective retrieval
By using signatures or hash tables generated by trusted authorities to bind additional data in the access control system, the performance limitations caused by storing hashes in access control devices are solved, and efficient and secure additional data verification is achieved.
Patent Information
- Application Number
- CN202380104280.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-26
- Publication Date
- 2026-06-23
AI Technical Summary
In existing access control systems, access control readers need to store hashes of a large amount of additional data to verify their authenticity, which limits device performance.
By establishing a communication session between the access control device and the user device, and using signatures or hash tables generated by a trusted authority to bind additional data, the amount of hashes stored in the access control device is reduced, and signatures or hash tables are used to verify the authenticity of the additional data.
This reduces the amount of data stored in access control devices, improves the overall efficiency and performance of the devices, and ensures the reliability and security of additional data verification.
Smart Images

Figure CN122270889A_ABST
Abstract
Description
Background Technology
[0001] Access control readers are widely used in various setups to control access to restricted areas. These readers typically connect to a server that manages access control policies and configurations. User equipment employs various encryption protocols to securely communicate with such readers. Summary of the Invention
[0002] In some aspects, the techniques described herein relate to a method comprising: establishing a communication session between a first device and a second device; transmitting from the first device to the second device credentials associated with a subset of additional data; receiving from the second device a request for a first portion of the additional data; providing the second device with binding information for the first portion of the additional data, the binding information securely linking the first portion of the additional data to credentials; and enabling the second device to use the binding information to authenticate the first portion of the additional data.
[0003] In some respects, the techniques described herein relate to a method in which a second device includes an access control reader, and where a first device includes a user equipment.
[0004] In some respects, the techniques described herein relate to a method that also includes controlling access to protected resources by a second device based on credentials received from a first device.
[0005] In some respects, the techniques described herein relate to a method that also includes storing a list of identifiers for each piece of additional data in a credential; generating a first signature for the credential by a trusted authority; and using the first signature to verify the authenticity of the credential including the list of identifiers.
[0006] In some respects, the techniques described herein relate to a method that also includes generating multiple signatures by a trusted authority, wherein each signature is associated with a corresponding set of additional data in a subset of additional data.
[0007] In some respects, the techniques described herein relate to a method in which binding information of a first portion of additional data includes a second signature associated with the first portion of the additional data from a plurality of signatures, wherein the authenticity of the first portion of the additional data is verified by a second device using the second signature.
[0008] In some aspects, the technology described herein relates to a method that further includes: receiving, by a first device, an additional request for a second portion of additional data from a second device; providing the second device with a third signature from a plurality of signatures associated with the second portion of the additional data; and enabling the second device to use the third signature to authenticate the second portion of the additional data.
[0009] In some respects, the techniques described herein relate to a method that also includes storing multiple hashes of identifiers in a credential, each of the multiple hashes being associated with a different set of identifiers for the additional data in a subset of the additional data.
[0010] In some respects, the techniques described herein relate to a method that further includes: associating a first hash among a plurality of hashes with a first hash table; and storing a first plurality of individual hashes in the first hash table, wherein the first individual hash among the first plurality of individual hashes is associated with a first portion of additional data and a first identifier of an identifier group, and a second individual hash among the first plurality of individual hashes is associated with a second portion of additional data and a second identifier of an identifier group, wherein the binding information of the first portion includes the first individual hash.
[0011] In some respects, the techniques described herein relate to a method that further includes: associating a second hash among a plurality of hashes with a second hash table; and storing a second plurality of individual hashes in the second hash table, a third individual hash among the second plurality of individual hashes being associated with a third portion of additional data and a third identifier of an identifier group, the first hash table being associated with a first group or a first category, and the second hash table being associated with a second group or a second category.
[0012] In some respects, the techniques described herein involve a method in which the authenticity of a first portion of the additional data is verified by a second device using a first separate hash.
[0013] In some respects, the techniques described herein relate to a method that further includes, in response to a request to receive a first portion of additional data: determining that an identifier of the first portion of the additional data is associated with a first hash; and transmitting the first hash and an identifier of a first hash table from a first device to a second device.
[0014] In some respects, the techniques described herein relate to a method that further includes obtaining a first separate hash from a first hash table by a second device based on an identifier of a first portion of the additional data; accessing the first portion of the additional data from an external source; and verifying the authenticity of the first portion of the additional data using the first separate hash.
[0015] In some respects, the techniques described herein involve a method that also includes associating random values with a first hash table to prevent the leakage of information about portions of additional data represented by a first hash of the first hash table.
[0016] In some respects, the techniques described herein relate to a method that further includes: associating a first random value with a first portion of separate data to prevent information about the first portion of the additional data from being leaked via a first separate hash; and associating a second random value with a second portion of separate data to prevent information about the second portion of the additional data from being leaked via a second separate hash.
[0017] In some respects, the techniques described herein relate to a method that also includes: applying an iterative hash function to a subset of additional data to generate a full hash through multiple iterations; and storing in the credential the full hash generated in response to applying the iterative hash function to the subset of additional data, wherein the full hash is derived by a second device based on some of the subset of additional data and a portion of the full hash, the full hash being provided to the second device and used as binding information.
[0018] In some aspects, the techniques described herein relate to a method that further includes: generating a sequence of data blocks, each data block in the sequence corresponding to a different portion of a subset of additional data, the full hash being calculated based on the sequence of data blocks; receiving a request for a first set of data blocks in the sequence of data blocks as a request for a first portion of the additional data; obtaining a partial hash from a second set of data blocks in the sequence of data blocks, the second set of data blocks being earlier than the first set of data blocks in the sequence of data blocks; transmitting the partial hash, the first set of data blocks, and the second set of data blocks from a first device to a second device; and having the second device calculate the full hash based on the partial hash, the first set of data blocks, and the second set of data blocks.
[0019] In some respects, the techniques described herein involve a method that also includes verifying the authenticity of the first set of data blocks by comparing the calculated full hash with the full hash provided as part of the credentials to the second device.
[0020] In some aspects, the technology described herein relates to a system comprising: one or more processors coupled to a memory including non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: establishing a communication session between a first device and a second device; transmitting from the first device to the second device credentials associated with a subset of additional data; receiving from the second device a request for a first portion of the additional data; providing the second device with binding information for the first portion of the additional data, the binding information securely linking the first portion of the additional data to the credentials; and enabling the second device to use the binding information to verify the first portion of the additional data.
[0021] In some aspects, the technology described herein relates to a non-transitory computer-readable medium comprising non-transitory computer-readable instructions that, when executed by one or more processors, configure one or more processors to perform operations including: establishing a communication session between a first device and a second device; transmitting from the first device to the second device credentials associated with a subset of additional data; receiving from the second device a request for a first portion of the additional data; providing the second device with binding information for the first portion of the additional data, the binding information securely linking the first portion of the additional data to credentials; and enabling the second device to authenticate the first portion of the additional data using the binding information.
[0022] In some respects, any of the different techniques described above for binding datasets to credentials can be combined into a single credential. For example, a technique using an identifier that is a signature for the data can be combined with a technique for storing multiple hash tables (which store hashes of some portions of the additional data), and / or with a technique in which a second device derives or computes the full hash based on individual portions of the additional data and / or data blocks of the requested portion of the additional data, as well as partial hashes associated with a previous sequence of data blocks of the individual portions of the additional data. Attached Figure Description
[0023] Figure 1 This is a block diagram of an example access control system based on some examples.
[0024] Figure 2 Example credential structures are shown based on some examples.
[0025] Figure 3 Example credential structures are shown based on some examples.
[0026] Figure 4 Example credential structures are shown based on some examples.
[0027] Figure 5 This is a flowchart illustrating example operations of an access control system based on some examples.
[0028] Figure 6 This is a block diagram illustrating an example software architecture that can be used in conjunction with various hardware architectures described herein.
[0029] Figure 7 This is a block diagram showing the components of a machine according to some examples. Detailed Implementation
[0030] Example methods and systems for optimizing the retrieval of additional data linked to credentials are described. In the following description, numerous specific details are set forth for illustrative purposes in order to provide a thorough understanding of the examples. However, it will be apparent to those skilled in the art that the examples of this disclosure can be practiced without these specific details.
[0031] Typically, access control readers (or various devices) enable access to a variety of protected physical or logical assets or information using exchanged access credentials. For example, a user equipment (UE) can store credentials and transmit them to another device, such as an access control reader. In many cases, the access control reader can request additional information (referred to as supplementary data) associated with the credentials from the UE. In this scenario, the access control reader can send a request for a specific portion of the supplementary data and can receive the requested portion of the supplementary data directly from the UE or from another source. In either case, the UE retrieves the hash associated with the requested portion from the credentials. The access control reader can use the hash received from the UE to verify the authenticity of the received portion of the supplementary data. To allow such verification, each distinct portion of the supplementary data needs to have a corresponding hash stored as part of the credentials. This significantly increases the size of the credentials, which can adversely affect the performance of hardware-constrained devices.
[0032] This disclosure provides mechanisms that allow a receiving device (e.g., an access control reader) to verify the authenticity of received additional data linked to a credential while minimizing the size of the actual credential itself. Specifically, the disclosed examples provide intelligent solutions that can reliably, quickly, securely, and efficiently operate and communicate with access control systems.
[0033] The disclosed example establishes a communication session between a first device and a second device, and transmits credentials associated with a subset of additional data from the first device to the second device. The disclosed example involves the first device receiving a request for a first portion of the additional data from the second device, and providing the second device with binding information for the first portion of the additional data, which securely links the first portion of the additional data to the credentials.
[0034] In some examples, a first technique is provided in which the binding information includes a signature generated by a trusted authority, which is associated with each portion of a subset of the additional data. In this case, the credential can be associated with a first signature generated by the trusted authority, and each portion of the additional data can be associated with a corresponding second signature generated by the trusted authority. The second signature can be used by a second device to verify the authenticity of the portion of the additional data received by the second device. In this case, the credential does not need to store the actual hash of the additional data, because the additional data is verified using the corresponding signature generated by the trusted authority. Storing the signature for each piece of additional data can occupy a significantly smaller amount of space compared to storing the corresponding hash of the data, which improves the overall efficiency of the device.
[0035] In some examples, a second technique is provided in which the binding information includes hashes obtained from one or more hash tables, which are collections or groups of different individual hashes stored for different parts of a subset of the additional data. In this case, the credential may store multiple hash values, each linked or associated with multiple parts of the additional data. To determine the actual hash of a single part of the additional data, the second device obtains the actual hash from another source, such as a hash table associated with the hash stored by the credential. The second device can compute the hash of a particular hash table based on the credential it receives from the first device and / or by actually receiving the hash directly from the first device. In some cases, the actual hash of the hash table is not physically stored with the credential, but is derived or computed by the receiving second device using the data of the credential. The second device can request the actual hash table using the hash table hash value and can provide the hash table hash value to the first device. The first device can search the hash table by comparing the hash table hash value with a list of stored hash values or by directly computing the hash value.
[0036] The second device can find and retrieve a specific hash table linked to the hash, and can search within that specific hash table for the hash associated with the requested portion of the additional data. The second device can use the specific hash received from the first device to verify the authenticity of the hash table, and can use the hash obtained from the hash table to verify the authenticity of the requested portion of the additional data. That is, the second device can retrieve the additional data using its unique identifier, and can verify its authenticity using the hash obtained from the hash table of the additional data. Storing a separate hash for each piece of additional data in one or more hash tables allows for a significantly smaller space usage in the credentials, improving the overall efficiency of the device.
[0037] In some examples, a third technique is provided in which the binding information includes a full hash associated with all additional data linked to the credential. In this case, the full hash can be stored within the credential and can be used by a second device to derive a separate hash for a specific selected portion of the additional data. That is, the second device can receive a selected portion of the additional data requested by the second device from the first device or some external source, along with partial hashes associated with other portions of the additional data preceding the selected portion in the sequence. The second device can then compute the full hash based on the partial hashes of the other portions of the additional data and the selected portion. The second device can then verify the authenticity of the selected portion by comparing the computed full hash with the full hash received as part of the credential. Storing a single full hash for all additional data in the credential, compared to storing multiple separate hashes for each portion of the additional data, allows for a significantly smaller space footprint within the credential, improving the overall efficiency of the device.
[0038] In some cases, the provided first, second, and / or third technologies can be combined in any suitable manner, with binding information used in the first, second, and / or third technologies to securely bind / link additional data to credentials. In these ways, the disclosed examples enable a second device to use the binding information to authenticate a first portion of the additional data. The disclosed examples refer to the access reader as a specific type of access control device, but the disclosed examples are applicable to any type of access control device.
[0039] Figure 1 This is a block diagram illustrating an example system 100 according to various examples. System 100 may be an access control system including: a client device 120; one or more access control devices 110 that control access to protected assets or security resources (e.g., physical or logical resources) via lockable doors, for example; and a server / controller 140 that is communicatively coupled via a network 130 (e.g., LAN, WAN (e.g., the Internet), WiFi, BLE, Ultra-Wideband (UWB) communication protocol, telephone network, or other wired or wireless communication protocol).
[0040] Client device 120 and access control device 110 can be communicatively coupled via electronic messages (e.g., via packets exchanged through the Internet, BLE, UWB, WiFi Direct, NFC, or any other protocol). Although Figure 1A single access control device 110 and a single client device 120 are shown; however, it should be understood that in other examples, multiple access control devices 110 and multiple client devices 120 may be included in system 100. As used herein, the term "client device" may refer to any machine that interfaces with a communication network (e.g., network 130) to exchange credentials with access control device 110 (or vice versa), server / controller 140, another client device 120, or any other component to obtain access to assets or resources protected by access control device 110. In some examples, client device 120 may additionally or alternatively communicate directly with, for example, the access control device or another client device 120.
[0041] In some cases, some or all of the components and functions of server / controller 140 may be included in client device 120 and / or access control device 110. Client device 120 may be, but is not limited to, mobile phones, desktop computers, laptop computers, portable digital assistants (PDAs), smartphones, wearable devices (e.g., smartwatches), tablets, ultrabooks, netbooks, laptops, multiprocessor systems, microprocessor-based or programmable consumer electronics, or any other communication device that a user can use to access the network.
[0042] Access control device 110 may include an access reader device (also referred to as an "access control reader" or "reader") connected to a secure / protected resource (e.g., a door locking mechanism or a back-end server) that controls the secure / protected resource (e.g., a door locking mechanism). The resource associated with access control device 110 may include a door lock, a vehicle's ignition system, or any other device that allows or denies access to a physical component and can be operated to allow or deny access to that physical component. For example, in the case of a door lock, access control device 110 may deny access, in which case the door lock remains locked and the door cannot be opened; or access control device 110 may allow access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, access control device 110 may deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or access control device 110 may allow access, in which case the vehicle ignition system becomes enabled and allows the vehicle to be started.
[0043] Physical access control encompasses a range of systems and methods for managing, for example, personnel access to secure areas or secure assets. Physical access control includes: identification of authorized users or devices (e.g., vehicles, drones, etc.); activation of gates, doors, or other facilities used to protect the security of an area; or activation of control mechanisms (e.g., physical or electronic / software control mechanisms) to allow access to secure assets. Access control device 110 forms part of a physical access control system (PACS), which may include readers (e.g., online or offline readers) that can store authorization data (also referred to as access control information) and can determine whether credentials (e.g., credentials or key devices from cards, clips, or personal electronic devices such as mobile phones, such as radio frequency identification (RFID) chips) are authorized for use with actuators or control mechanisms (e.g., door locks, door openers, software control mechanisms, alarm closing mechanisms, etc.), or the PACS may include a host server, in which, in a centrally managed configuration, readers and actuators (e.g., via controllers) are connected to the host server.
[0044] In a centrally managed configuration, the reader obtains credentials from a credential or key device and passes these credentials to the PACS host server or front-end system. The host server then determines whether the credentials authorize access to a secure area or secure asset and commands the actuator or other control mechanism accordingly by sending an allow / deny message back to the reader via a wired or wireless link. While this document uses examples of physical access control, this disclosure is equally applicable to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, passenger identification in transportation services, access and asset control in unmanned stores, securely stored files on storage devices, etc.).
[0045] Typically, access control device 110 may include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, and a power supply or power supply device. The memory of access control device 110 may be used in conjunction with the execution of application programs or instructions by the processor of access control device 110, and may be used for temporary or long-term storage of program instructions or instruction sets and / or credentials or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory may contain executable instructions used by the processor to run other components of access control device 110 and / or for access determination based on credentials or authorization data.
[0046] The memory of access control device 110 may include a computer-readable medium, which can be any medium capable of containing, storing, transmitting, or transporting data, program code, or instructions for use by or in conjunction with access control device 110. Computer-readable media can be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices. More specific examples of suitable computer-readable media include, but are not limited to, electrical connections with one or more lines or tangible storage media such as portable computer floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), dynamic RAM (DRAM), any typical solid-state storage device, optical disc read-only memory (CD-ROM), or other optical or magnetic storage devices. Computer-readable media includes but should not be confused with computer-readable storage media, which is intended to cover all physical, non-transitory, or similar examples of computer-readable media.
[0047] The processor of access control device 110 may correspond to one or more computer processing devices or resources. For example, the processor may be provided as silicon, a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), any other type of integrated circuit (IC) chip, a collection of IC chips, etc. As a more specific example, the processor may be provided as a microprocessor, a central processing unit (CPU), or multiple microprocessors or CPUs configured to execute instruction sets stored in internal memory and / or the memory of access control device 110.
[0048] The access control device 110 may have one or more antennas and may be configured to provide wireless communication between the access control device 110 and a credential or key device (e.g., client device 120). The antennas may be arranged to operate using one or more wireless communication protocols and operating frequencies, including but not limited to IEEE 802.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, etc. By way of example, the antenna may be an RF antenna, and therefore, RF signals can be transmitted / received in free space for reception / transmission by a credential or key device having an RF transceiver.
[0049] The communication module of access control device 110 can be configured to communicate with one or more different systems or devices (e.g., one or more client devices 120 and / or server / controller 140) remotely or locally, according to any suitable communication protocol. In some cases, the communication module of access control device 110 is configured to efficiently perform the disclosed credential exchange and additional data exchange. That is, the communication module can be implemented as part of access control device 110 and / or client device 120 to perform combined... Figures 2 to 5 The credential exchange protocol under discussion.
[0050] The network interface device of access control device 110 includes hardware to facilitate communication over a communication network (e.g., network 130) with other devices such as one or more client devices 120 and / or server / controller 140 (e.g., a PACS server), utilizing any of a number of transport protocols (e.g., Frame Relay, IP, Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.). Example communication networks may include LANs, WANs, packet data networks (e.g., the Internet), mobile phone networks (e.g., cellular networks), traditional common telephone (POTS) networks, wireless data networks (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the IEEE 802.16 family of standards known as WiMax), the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, etc. In some examples, the network interface device may include an Ethernet port or other physical jack, a Wi-Fi card, a network interface card (NIC), a cellular interface (e.g., an antenna, a filter, and associated circuitry), etc. In some examples, the network interface device may include multiple antennas to perform wireless communication using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) technologies.
[0051] The user interface of access control device 110 may include one or more input devices and / or display devices. Examples of suitable user input devices that may be included in the user interface include, but are not limited to, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera device, a microphone, etc. Examples of suitable user output devices that may be included in the user interface include, but are not limited to, one or more LEDs, an LCD panel, a display screen, a touch screen, one or more lights, speakers, etc. It should be understood that the user interface may also include a combination of user input devices and user output devices, such as a touch-sensitive display.
[0052] Network 130 may include or operate in combination with the following networks: self-organizing network, intranet, extranet, virtual private network (VPN), LAN, wireless network, wireless LAN (WLAN), WAN, wireless WAN (WWAN), metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), POTS network, cellular telephone network, wireless network, Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless network or a cellular network, and coupling may be a CDMA connection, a GSM connection, or other types of cellular or wireless coupling. In this example, coupling can enable any data transmission technology of various types, such as single-carrier radio transmission technology (1xRTT), evolved data optimization (EVDO) technology, general packet radio service (GPRS) technology, enhanced data rate evolution of GSM (EDGE) technology, the 3rd Generation Partnership Project (3GPP) including 3G, fourth-generation wireless (4G) networks, fifth-generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High-Speed Packet Access (HSPA), Global Microwave Access Interoperability (WiMAX), Long Term Evolution (LTE) standard, other standards defined by various standards setting organizations, other short-range or long-range protocols, or other data transmission technologies.
[0053] In some examples, as client device 120 approaches access control device 110 (e.g., enters BLE communication protocol range), client device 120 transmits its credentials over network 130, for example, using a certificate associated with access control device 110. In some cases, credentials can be selected from multiple credentials based on the current geographic location of client device 120. For example, multiple credentials, each associated with a different geographic location, can be stored on client device 120. When client device 120 comes within a certain distance (e.g., within 10 meters) of the geographic location associated with one of these credentials, client device 120 retrieves the associated credential from local storage.
[0054] In some examples, client device 120 provides credentials directly to access control device 110. In such cases, access control device 110 transmits credentials to server / controller 140. Figure 1 The server / controller 140 includes a credential retrieval system 142. The server / controller 140, client device 120, and / or access control device 110 may also include information regarding... Figure 6 and Figure 7The described elements, such as a memory and a processor on which instructions are stored, enable the processor to control the functions of server / controller 140, client device 120, and / or access control device 110 when executed by the processor.
[0055] Server / controller 140 searches a list of credentials stored in credential retrieval system 142 to determine if the received credential matches a credential in a list of authorized credentials for accessing secure assets or resources (e.g., doors or secure areas) protected by access control device 110. In response to determining that the received credential is authorized to access access control device 110, server / controller 140 instructs access control device 110 to perform an operation that grants access to client device 120 (e.g., instructs access control device 110 to unlock a door). In some cases, server / controller 140 may verify the signature of the credential received from client device 120, and if the signature is successfully verified, access is granted.
[0056] In some examples, after client device 120 provides credentials to access control device 110, access control device 110 may determine that one or more additional data links to the received credentials are needed. For example, the credentials may include a password for entering a building. Access control device 110 may then determine that a floor identifier is needed to control access to a specific floor associated with access control device 110. In this case, access control device 110 may request additional data from client device 120 indicating the floor identifier for the credentials.
[0057] like Figure 2 As shown, a credential can store multiple identifiers for different parts of the additional data. Specifically, as... Figure 2 As shown in the example of the first technology 200, the credential 210 can be signed by a trusted authority using a first signature 240, and can store multiple identifiers of additional data, including a first identifier 220 of a first dataset and a second identifier 230 of a second dataset.
[0058] In some cases, client device 120 can receive additional data requests as unique identifiers for the additional data. For example, access control device 110 can receive credential 210 from client device 120. Access control device 110 can use a first signature 240 associated with credential 210 to verify the authenticity of credential 210. After verifying the authenticity of credential 210, access control device 110 can request a first dataset from the additional data linked in credential 210. In response, credential 210 provides client device 120 with a first identifier 220 for the first dataset. Client device 120 can retrieve the corresponding first dataset and can provide the retrieved first dataset to access control device 110 in a first data packet 250. The first data packet 250 may include the first dataset, a first signature 240, and a second signature 252. The second signature 252 may be generated by a trusted authority for the first dataset. Access control device 110 can use the second signature 252 to verify the authenticity of the first dataset in the first data packet 250.
[0059] In some examples, access control device 110 may use a first identifier 220 to communicate with an external source, such as an external database. Access control device 110 may receive a first dataset from the external source. The external source may provide access control device 110 with a first data packet 250 including a second signature 252. Access control device 110 may use the second signature 252 to verify the authenticity of the dataset included in the first data packet 250. In this case, access control device 110 may use a separate signature generated by the same or different trusted authorities to verify the authenticity of credential 210, independent of verifying the authenticity of the requested portion of additional data linked to credential 210. In this way, a signature can be used to authenticate the additional data instead of using a space-consuming hash to verify its authenticity.
[0060] In some cases, access control device 110 may request a second portion of additional data, such as a second dataset corresponding to the second identifier 230. In this case, client device 120 may retrieve the corresponding second dataset and provide the retrieved second dataset to access control device 110 in a second data packet 260. The second data packet 260 may include the second dataset, a first signature 240, and a third signature 262. The third signature 262 may be generated by a trusted authority for the second dataset. Access control device 110 may use the third signature 262 to verify the authenticity of the second dataset in the second data packet 260.
[0061] In the first technique 200, as many identifiers as possible are assigned to the dataset (corresponding to different portions of the additional data linked to credential 210), and it may include, for example, a hash or signature of the credential to bind it to credential 210. In some cases, to protect against tampering, the dataset also needs to be signed by the same trusted authority. The selection of the dataset can be accomplished by using identifiers (e.g., ID1, ID2, etc.). Identifiers can be much smaller in size than hashes, which saves storage space associated with storing credential 210. Access control device 110 can check this binding by matching / binding (e.g., the signature of credential 210 and a matching signature in the dataset itself).
[0062] The authenticity of the dataset is guaranteed by corresponding signatures from a trusted authority (e.g., second signature 252 and third signature 262). This allows each dataset to be set up to be larger (because it includes two signatures), but typically does not require requesting multiple datasets, making the overall data exchange smaller.
[0063] like Figure 3 As shown, a credential can store multiple hashes (or hash values), each hash associated with a different set of additional data. Specifically, as... Figure 3 As shown in the example of the second technique 300, credential 310 can be signed by a trusted authority using a signature. Credential 310 can store multiple hashes, each hash associated with a different set of additional data or identifiers linked to credential 310. For example, credential 310 can store a first hash 320 (or a first set of hashes) associated with a first dataset (corresponding to ID1) and a second dataset (corresponding to ID2). Credential 310 can also store a second hash 322 (or a second set of hashes) associated with a third dataset (corresponding to ID3).
[0064] In some examples, a first hash 320 may be associated with a first hash table 330, and a second hash 322 may be associated with a second hash table 340. The first hash table 330 may store a list of individual hashes (or individual hash values) including a first individual hash 332 and a second individual hash 334. The first individual hash 332 may be associated with a first dataset corresponding to ID1, and the second individual hash 334 may be associated with a second dataset corresponding to ID2. The second hash table 340 may store a list of another individual hash (or individual hash value) including a third individual hash 342 corresponding to a third dataset corresponding to ID3.
[0065] In some examples, the first hash table 330 may store binding information (e.g., hash or signature) of the first dataset corresponding to ID1, and the second separate hash table 334 may store binding information (e.g., hash or signature) of the second dataset corresponding to ID2. The second hash table 340 may store a list of additional binding information for the third dataset corresponding to ID3.
[0066] In some examples, the credentials may store an identifier for a first hash table 330. The client device 120 can use this identifier to locate the hash table 330 when the access control device 110 requests it using that identifier. In this case, the access control device 110 can utilize additional bindings contained within the first hash table 330 to verify its authenticity. The additional binding information may include the signature of a previously received credential or the hash of the credential. The first hash table 330 may also be signed by a trusted authority. In this way, the size of the first hash table 330 can be increased while the size of the credentials can be decreased.
[0067] In some examples, client device 120 may receive an identifier for a dataset from access control device 110. The identifier may be generated or determined by access control device 110 based on credentials 310 received from client device 120. Client device 120 may use this identifier to determine which of a plurality of group hashes is associated with that identifier. For example, client device 120 may determine that the identifier corresponds to ID2. In this case, client device 120 may determine that ID2 is associated with a first hash 320 and not with a second hash 322. In this case, access control device 110 retrieves the hash 320 associated with the first hash table 330.
[0068] Access control device 110 can use hash 320 to access first hash table 330. That is, access control device 110 can download or retrieve first hash table 330 from an external source. Access control device 110 can generate a hash of the retrieved first hash table 330 and can compare the generated hash with the first hash 320 received from client device 120. If the two hash values match (the locally generated hash and the hash received from client device 120), access control device 110 determines that first hash table 330 is authenticated. In response, access control device 110 searches for a separate hash associated with the requested dataset in first hash table 330 based on the identifier of the requested dataset (e.g., ID2). In this case, access control device 110 retrieves a second separate hash 334 associated with the identifier in first hash table 330. Access control device 110 can obtain dataset 350 associated with the identifier from client device 120, external sources, and / or from first hash table 330.
[0069] In some examples, client device 120 can directly access the first hash table 330 and retrieve a second separate hash 334 associated with the identifier received from access control device 110 from the first hash table 330, instead of sending a link to the first hash table 330 to access control device 110. Client device 120 can then send the retrieved second separate hash 334 to access control device 110. Access control device 110 can also obtain a dataset associated with the identifier from client device 120, external sources, and / or from the first hash table 330. Access control device 110 can generate a hash for the obtained dataset and compare the generated hash value with a hash value already retrieved from the first hash table 330 (e.g., the second separate hash 334). If the two hash values match, access control device 110 determines that the dataset is authenticated.
[0070] In the second technique 300, a hash table is used to bind the credential 310 and the dataset. If a dataset included in the dataset group associated with the hash table is requested, the hash table only needs to be sent to the access control device 110 (from the client device 120 or an external source) and can be pre-computed and stored or computed at runtime. The binding between different data elements is accomplished via hashing. The hash of the hash table is part of the credential 310. The hash of the dataset is part of the hash table.
[0071] In some cases, to limit the size of the hash table (e.g., the first hash table 330), multiple hash tables may exist, which can be organized according to groups and / or categories. Each hash table can hold a limited number of dataset hashes. For example, client device 120 may determine that a first supplementary dataset corresponding to ID1 and ID2 corresponds to a first category. In this case, client device 120 may associate the first supplementary dataset with the same hash table that stores their respective individual hash values. Similarly, client device 120 may determine that a second supplementary dataset corresponding to ID3 corresponds to a second category. In this case, client device 120 may associate the second supplementary dataset with a separate and distinct hash table that stores the individual hash values of the second supplementary dataset corresponding to ID3.
[0072] In some cases, whenever there are restrictions on read access to some datasets, each such dataset and / or the hash table associated with that dataset can contain different random numbers, such that its hash does not reveal information about its contents (e.g., to prevent leakage). In some cases, the credentials themselves may also include random numbers. In these cases, the signatures of the credentials, datasets, and / or hash tables can be generated by a trusted institution using different random numbers. Alternatively or concurrently, the hash of the hash table and / or the individual hash value of the dataset can be generated using random numbers, if any, and that random number is included as part of the hash table and / or the individual hash value. In this way, randomness can be added to any part of the data discussed above and below.
[0073] like Figure 4 As shown, the voucher can store a full hash corresponding to all additional data associated with the voucher. Specifically, as... Figure 4 As shown in the example of the third technology 400, credential 410 can be signed by a trusted authority using a signature. Credential 410 can store a single full hash associated with all additional data linked to credential 410. For example, credential 410 can store a full hash 420 associated with all datasets linked to credential 410, including a first dataset, a second dataset, and a third dataset.
[0074] The Merkle-Damgård iterative hash function can be used to generate a full hash 420 through multiple iterations. Specifically, this function computes a hash for any message m by dividing m into blocks of a given size and iteratively processing each block, where in each iteration, the input is the partial hash computed up to that point. The hash of m is the output of the iteration on the last block (padded to the right if its original size is smaller than the block size). In some cases, the first, second, and third datasets can be divided into one or more separate sequences, such that each dataset is requested only with subsequent datasets in its sequence, and not necessarily with preceding datasets. For example, this is suitable for multi-level security scenarios where each dataset can be a more sensitive composite of data contained in subsequent datasets in its sequence (e.g., such a sequence could be "sensitive medical data", "basic medical data", "biometric data", "basic identification data").
[0075] In some examples, a first dataset can be divided into a first plurality of equal-sized blocks 430 (e.g., blocks 1 to n). If the first dataset cannot fit into blocks of equal size, dummy data can be added to one or more blocks to generate blocks of equal size. A second dataset can be divided into a second plurality of equal-sized blocks 432 (e.g., blocks 1 to n). If the second dataset cannot fit into blocks of equal size, dummy data can be added to one or more blocks to generate blocks of equal size. A third dataset can be divided into a third plurality of equal-sized blocks 434 (e.g., blocks 1 to n). If the third dataset cannot fit into blocks of equal size, dummy data can be added to one or more blocks to generate blocks of equal size.
[0076] After dividing the dataset into multiple equal-sized blocks 430, a second set of equal-sized blocks 432, and a third set of equal-sized blocks 434, these blocks are arranged sequentially or in a specified order. For ease of reference, the first set of equal-sized blocks 430 may correspond to a portion of data in the sequence that is later than the third set of equal-sized blocks 434. In some cases, the first set of equal-sized blocks 430 may correspond to a portion of data in the sequence that is earlier than the third set of equal-sized blocks 434.
[0077] In the initial configuration and personalization, credentials and associated additional data are created and bound together. Client device 120 (or other personalization entity, such as server / controller 140) generates a full hash 420 by iteratively calculating the hash values of each set of blocks in a first plurality of equal-sized blocks 430, a second plurality of equal-sized blocks 432, and a third plurality of equal-sized blocks 434. For example, server / controller 140 calculates the initial hash based on the third plurality of equal-sized blocks 434. Then, server / controller 140 updates the initial hash by calculating a new hash using the initial hash and the second plurality of equal-sized blocks 432. Finally, server / controller 140 updates the hash by calculating the full hash 420 using the hash calculated in the previous iteration and the first plurality of equal-sized blocks 430. Server / controller 140 stores the full hash 420 in credential 410 to complete the personalization and creation of credential 410. In some cases, after the full hash 420 is created and bound to the credential 410 and stored by the client device 120, the client device 120 provides the full hash 420 together with the credential 410 to the access control device 110 upon request.
[0078] In some examples, client device 120 receives a request for a single dataset, such as a first dataset. In this case, client device 120 provides access control device 110 with a data block 444 corresponding to the first dataset. In some cases, access control device 110 obtains data block 444 from an external source, in which case data block 444 is excluded from data packet 440. Access control device 110 receives data packet 440 from client device 120 including a partial hash 442, which corresponds to a data block preceding data block 444 in the sequence. The partial hash 442 excludes the hash value of data block 444.
[0079] Access control device 110 can regenerate the full hash (which corresponds to the full hash generated during personalization and credential creation) based on data block 444 and partial hash 442. Access control device 110 can then compare the regenerated full hash with the full hash 420 received along with credential 410. If the two hash values match, access control device 110 determines that data block 444 is authenticated.
[0080] Specifically, a full hash 420 is computed for each sequence of the dataset. In the byte string S used as input to this computation, if the original size of each dataset is smaller than the block size, each dataset is right-padded, and a random current value block is prepended into S. The resulting full hash 420 is then included in a credential 410, which can be signed by a trusted authority. For each sequence, dataset 1, ..., dataset n, whenever access control device 110 requests subsequent datasets m, ..., dataset n and the request is accepted, the response from client device 120, excluding those datasets, includes a partial hash (e.g., partial hash 442) computed on the left-hand side of S up to dataset m (which is excluded). This partial hash can be pre-computed and stored, or computed at runtime in response to a request for additional data. Access control device 110 can then use the partial hash and the received datasets to recompute the full hash of S and can check whether the result matches the full hash contained in the credential 410 for that dataset sequence.
[0081] In some examples, a single credential may store additional data or may be linked to additional data, according to the first technology 200, the second technology 300, and / or the third technology 400. That is, for the same or different sets of additional data, the credential may implement any one of the first technology 200, the second technology 300, and / or the third technology 400, or a combination of the first technology 200, the second technology 300, and / or the third technology 400.
[0082] Figure 5This is a flowchart illustrating an example process or method 500 of an access control system 100 according to some examples. The process or method 500 may be implemented with computer-readable instructions executable by one or more processors, such that the operation of the process or method 500 may be performed partially or wholly by functional components of the system 100; therefore, the process or method 500 is described below by way of example with reference to the system 100. However, in other examples, at least some of the operations of the process or method 500 may be deployed on various other hardware configurations. Some or all of the operations of the process or method 500 may be performed in parallel, out of order, or omitted entirely.
[0083] At operation 501, as discussed above, server / controller 140 (e.g., PACS server), access control device 110 and / or client device 120 establish a communication session between the first device and the second device, and transmit credentials associated with a subset of additional data from the first device to the second device.
[0084] At operation 502, as discussed above, client device 120 receives a request for a first portion of additional data from access control device 110.
[0085] At operation 503, as discussed above, client device 120 provides access control device 110 with binding information for a first portion of supplementary data, which securely links the first portion of the supplementary data to a credential. The binding information may be a credential, a supplementary dataset, part of one or more hash tables, and / or may be derived by access control device 110 using information contained in the credential.
[0086] At operation 504, as discussed above, the client device 120, server / controller 140, and / or access control device 110 are enabled to authenticate the first part of the additional data using the binding information.
[0087] Figure 6 This is a block diagram illustrating an example software architecture 606 that can be used in conjunction with various hardware architectures described herein. Figure 6 This is a non-limiting example of a software architecture, and it should be understood that many other architectures can be implemented to facilitate the functionality described herein. Software architecture 606 can be implemented in, for example... Figure 7 The execution is performed on the hardware of machine 700, which includes processor 704, memory 714, and input / output (I / O) components 718, etc. A representative hardware layer 652 is shown and can represent, for example... Figure 7The machine 700. A representative hardware layer 652 includes a processing unit 654 having associated executable instructions 604. The executable instructions 604 represent executable instructions of the software architecture 606, including implementations of the methods, components, etc., described herein. Hardware layer 652 also includes a memory and / or storage device 656, which also has executable instructions 604. Hardware layer 652 may also include other hardware 658. Software architecture 606 can be deployed on... Figure 1 In any one or more of the components shown.
[0088] exist Figure 6 In the example architecture, software architecture 606 can be conceptualized as a stack of layers, where each layer provides specific functionality. For example, software architecture 606 may include layers such as operating system 602, libraries 620, framework / middleware 618, applications 616, and a presentation layer 614. Operationally, applications 616 and / or other components within a layer can initiate API calls 608 through the software stack and receive messages 612 in response to API calls 608. The layers shown are representative in nature, and not all software architectures have all layers. For example, some mobile operating systems or dedicated operating systems may not provide framework / middleware 618, while other operating systems may provide such a layer. Other software architectures may include additional or different layers.
[0089] Operating system 602 can manage hardware resources and provide public services. Operating system 602 may include, for example, a kernel 622, services 624, and drivers 626. Kernel 622 can act as an abstraction layer between hardware and other software layers. For example, kernel 622 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, etc. Services 624 can provide other public services to other software layers. Drivers 626 are responsible for controlling or interfacing with the underlying hardware. For example, depending on the hardware configuration, drivers 626 may include display drivers, camera drivers, BLE drivers, UWB drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, etc.
[0090] Library 620 provides common infrastructure used by application 616 and / or other components and / or layers. Library 620 provides functionality that allows other software components to perform tasks more easily than by directly interfacing with the underlying operating system 602 functions (e.g., kernel 622, services 624, and / or drivers 626). Library 620 may include system libraries 644 (e.g., the C standard library), which can provide functions such as memory allocation, string manipulation, and mathematical functions. Additionally, library 620 may include API libraries 646, such as media libraries (e.g., libraries supporting the rendering and manipulation of various media formats such as MPREG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., OpenGL frameworks that can be used to render two-dimensional (2D) and three-dimensional (3D) graphics content on a display), database libraries (e.g., SQLite that provides various relational database functions), web libraries (e.g., WebKit that provides web browsing functionality), and so on. Library 620 may also include various other libraries 648 to provide many other APIs to application 616 and other software components / devices.
[0091] The framework / middleware 618 (sometimes also called middleware) provides a higher level of common infrastructure that can be used by applications 616 and / or other software components / devices. For example, the framework / middleware 618 can provide a variety of graphical user interface functions, advanced resource management, advanced location services, etc. The framework / middleware 618 can provide a wide range of other APIs that can be used by applications 616 and / or other software components / devices, some of which may be specific to a particular operating system 602 or platform.
[0092] Application 616 includes built-in application 638 and / or third-party application 640. Examples of representative built-in applications 638 may include, but are not limited to: contact applications, browser applications, book reader applications, location applications, media applications, messaging applications, and / or game applications. Third-party applications 640 may include applications developed by entities other than platform-specific vendors using the Android™ or iOS™ Software Development Kit (SDK), and may be mobile software running on mobile operating systems such as iOS™, Android™, Windows® Phone, or other mobile operating systems. Third-party applications 640 may activate API calls 608 provided by the mobile operating system (e.g., operating system 602) to facilitate the functionality described herein.
[0093] Application 616 can use built-in operating system functions (e.g., kernel 622, service 624, and / or driver 626), libraries 620, and frameworks / middleware 618 to create a UI for interacting with the system's user. Alternatively or additionally, in some systems, interaction with the user can be achieved through a presentation layer, such as presentation layer 614. In these systems, the application / component "logic" can be separated from the user-interacting parts of the application / component.
[0094] Figure 7 This is a block diagram illustrating components of a machine 700 according to some examples, which is capable of reading instructions from a machine-readable medium (e.g., a machine-readable storage medium) and executing any or more of the methods discussed herein. Specifically, Figure 7 A graphical representation of machine 700 is shown as an example of a computer system, within which instructions 710 (e.g., software, program, application, app, or other executable code) can be executed to cause machine 700 to perform any or more of the methods discussed herein.
[0095] Therefore, instruction 710 can be used to implement the devices or components described herein. Instruction 710 transforms a general, unprogrammed machine 700 into a specific machine 700 programmed to perform the described and illustrated functions in the described manner, such as client device 120, access control device 110, or server / controller 140. In alternative examples, machine 700 operates as a standalone device or can be coupled (e.g., networked) to other machines. In a networked deployment, machine 700 can operate as a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. Machine 700 may include, but is not limited to, server computers, client computers, personal computers (PCs), tablet computers, laptop computers, netbooks, set-top boxes (STBs), PDAs, entertainment media systems, cellular phones, smartphones, mobile devices, wearable devices (e.g., smartwatches), smart home devices (e.g., smart home appliances), other smart devices, web devices, network routers, network switches, network bridges, or any machine capable of sequentially or otherwise executing instructions 710 that specify the actions to be taken by machine 700. Furthermore, although only a single machine 700 is shown, the term "machine" should also be considered to include a collection of machines that individually or jointly execute instructions 710 to perform any or more of the methods discussed herein.
[0096] Machine 700 may include processor 704, memory / storage device 706, and I / O components 718, which may be configured to communicate with each other, for example, via bus 702. In the example, processor 704 (e.g., CPU, Reduced Instruction Set Computing (RISC) processor, Complex Instruction Set Computing (CISC) processor, Graphics Processing Unit (GPU), Digital Signal Processor (DSP), ASIC, Radio Frequency Integrated Circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, processors 708 and 712 capable of executing instruction 710. The term "processor" is intended to include multi-core processor 704, which may include two or more independent processors (sometimes referred to as "cores") capable of executing instructions simultaneously. Although Figure 7 Multiprocessor 704 is shown, but machine 700 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.
[0097] Memory / storage device 706 may include memory 714, such as main memory, or other memory storage devices, a database, and storage cells 716, which processor 704 can access, for example, via bus 702. Storage cells 716 and memory 714 store instructions 710 that implement any or more of the methods or functions described herein. Instructions 710 may also reside wholly or partially within memory 714, storage cells 716, at least one of processors 704 (e.g., the processor's cache memory), or any suitable combination thereof during execution by machine 700. Therefore, memory 714, storage cells 716, and the memory of processor 704 are examples of machine-readable media.
[0098] I / O component 718 may include various components for receiving input, providing output, generating output, transmitting information, exchanging information, capturing measurements, etc. The specific I / O component 718 included in a particular machine 700 will depend on the type of machine. For example, a portable machine such as a mobile phone is likely to include a touch input device or other such input mechanism, while a headless server machine is likely not to include such a touch input device. It should be recognized that I / O component 718 may include... Figure 7Many other components are not shown. The grouping of I / O components 718 according to function is merely for the sake of simplicity in the following discussion, and the grouping is by no means limiting. In various examples, I / O components 718 may include output components 726 and input components 728. Output components 726 may include visual components (e.g., displays such as plasma display panels (PDPs), LED displays, LCDs, projectors, or cathode ray tube (CRTs), auditory components (e.g., speakers), force-sensitive components (e.g., vibration motors, resistance mechanisms), other signal generators, etc. Input components 728 may include alphanumeric input components (e.g., keyboards, touchscreens configured to receive alphanumeric input, photoelectric keyboards, or other alphanumeric input components), point-based input components (e.g., mice, touchpads, trackballs, joysticks, motion sensors, or other pointing instruments), haptic input components (e.g., physical buttons, touchscreens or other haptic input components that provide position and / or force for touch or touch gestures), audio input components (e.g., microphones), etc.
[0099] In another example, I / O component 718 may include various other components such as biometric component 739, motion component 734, environmental component 736, or positioning component 738. For example, biometric component 739 may include components for detecting expressions (e.g., gestures, facial expressions, speech, body posture, or eye tracking), measuring biosignals (e.g., blood pressure, heart rate, body temperature, sweating, or brain waves), and recognizing people (e.g., voice recognition, retinal recognition, facial recognition, fingerprint recognition, or EEG-based recognition). Motion component 734 may include: accelerometer component (e.g., accelerometer), gravity sensor component, rotation sensor component (e.g., gyroscope), etc. Environmental component 736 may include, for example, a lighting sensor component (e.g., a photometer), a temperature sensor component (e.g., one or more thermometers that detect ambient temperature), a humidity sensor component, a pressure sensor component (e.g., a barometer), an hearing sensor component (e.g., one or more microphones that detect background noise), a proximity sensor component (e.g., an infrared sensor that detects nearby objects), a gas sensor (e.g., a gas detection sensor that detects the concentration of hazardous gases for safety purposes or measures pollutants in the atmosphere), or other components that can provide indications, measurements, or signals corresponding to the surrounding physical environment. Positioning component 738 may include a position sensor component (e.g., a GPS receiver component), an altitude sensor component (e.g., an altimeter or barometer from which air pressure can be derived to determine altitude), an orientation sensor component (e.g., a magnetometer), etc.
[0100] Various technologies can be used to implement communication. I / O component 718 may include communication component 740, which is operable to couple machine 700 to network 737 or device 729 via coupling 724 and coupling 722, respectively. For example, communication component 740 may include network interface component or other suitable device to interface with network 737. In further examples, communication component 740 may include wired communication component, wireless communication component, cellular communication component, NFC component, Bluetooth® component (e.g., Bluetooth® Low Energy), Wi-Fi® component, and other communication components that provide communication via other forms. Device 729 may be another machine or any peripheral device from various peripheral devices (e.g., a peripheral device coupled via USB).
[0101] Furthermore, the communication component 740 can detect identifiers or may include components operable to detect identifiers. For example, the communication component 740 may include an RFID tag reader component, an NFC smart tag detection component, an optical reader component (e.g., an optical sensor for detecting one-dimensional barcodes such as Universal Product Code (UPC) barcodes, multi-dimensional barcodes such as Quick Response (QR) codes, Aztec codes, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D barcodes, and other optical codes) or an acoustic detection component (e.g., a microphone for identifying audio signals with tags). Additionally, various information can be derived from the communication component 740, such as location obtained via Internet Protocol (IP) geolocation, location obtained via Wi-Fi® signal triangulation, location obtained by detecting NFC beacon signals that can indicate a specific location, etc.
[0102] Glossary:
[0103] In this context, "carrier signal" refers to any intangible medium capable of storing, encoding, or carrying transient or non-transient instructions executed by a machine, and includes digital or analog communication signals or other intangible media to facilitate the transmission of such instructions. Instructions can be transmitted or received over a network using transient or non-transient transmission media via network interface devices and using any of a number of well-known transmission protocols.
[0104] In this context, "client device" refers to any machine that interfaces with a communication network to obtain resources from one or more server systems or other client devices, or to communicate directly with such other devices or server systems. Client devices can be, but are not limited to, mobile phones, desktop computers, laptop computers, PDAs, smartphones, tablet computers, ultrabooks, netbooks, multiprocessor systems, microprocessor-based or programmable consumer electronics, game consoles, STBs, or any other communication device that a user can use to access the network.
[0105] In this context, "communication network" refers to one or more parts of a network, which can be an ad hoc network, intranet, extranet, VPN, LAN, BLE network, UWB network, WLAN, WAN, WWAN, MAN, the Internet, a part of the Internet, a part of the PSTN, POTS network, cellular telephone network, wireless network, Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or part of a network may include a wireless network or a cellular network, and coupling may be a CDMA connection, a GSM connection, or other types of cellular or wireless coupling. In this example, coupling can implement any data transmission technology of various types, such as 1xRTT, EVDO, GPRS, EDGE, 3GPP (including 3G and 4G networks), UMTS, HSPA, WiMAX, LTE standards, other technologies defined by various standards-setting organizations, other long-distance protocols, or other data transmission technologies.
[0106] In this context, "machine-readable medium" refers to a component, device, or other tangible medium capable of temporarily or permanently storing instructions and data, and may include, but is not limited to, RAM, ROM, buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage devices (e.g., erasable programmable read-only memory (EEPROM)) and / or any suitable combination thereof. The term "machine-readable medium" should be considered to include a single medium or multiple media capable of storing instructions (e.g., a centralized or distributed database or associated cache and server). The term "machine-readable medium" will also be considered to include any medium or combination of media capable of storing machine-executable instructions (e.g., code) such that, when executed by one or more processors of the machine, the instructions cause the machine to perform any or more of the methods described herein. Therefore, "machine-readable medium" refers to a single storage device or apparatus, as well as a "cloud-based" storage system or storage network comprising multiple storage devices or apparatuses. The term "machine-readable medium" does not include signals themselves.
[0107] In this context, a “component” refers to a device, physical entity, or logic having boundaries defined by function or subroutine calls, branch points, APIs, or other technologies that provide partitioning or modularity for specific processing or control functions. Components can be combined via their interfaces with other components to perform machine processing. A component can be part of a program that is an encapsulated functional hardware unit designed for use with other components and typically performs a specific function. Components can constitute software components (e.g., code implemented on a machine-readable medium) or hardware components. A “hardware component” is a tangible unit capable of performing certain operations and can be configured or arranged in some physical manner. In various examples, one or more computer systems (e.g., standalone computer systems, client computer systems, or server computer systems) or one or more hardware components (e.g., processors or processor groups) of a computer system can be configured by software (e.g., an application or application portion) to perform certain operations described herein.
[0108] Hardware components can also be implemented mechanically, electronically, or by any suitable combination thereof. For example, a hardware component may include a dedicated circuit system or logic permanently configured to perform certain operations. A hardware component may be a dedicated processor, such as an FPGA or ASIC. A hardware component may also include programmable logic or a circuit system temporarily configured by software to perform certain operations. For example, a hardware component may include software executed by a general-purpose processor or other programmable processor. Once configured by such software, the hardware component becomes a specific machine (or a specific part of a machine) uniquely tailored to perform the configured function, and is no longer a general-purpose processor. It will be understood that decisions to implement hardware components mechanically in a dedicated and permanently configured circuit system or in a temporarily configured (e.g., software-configured) circuit system may be driven by cost and time considerations. Accordingly, the phrase “hardware component” (or “hardware-implemented component”) should be understood to include tangible entities, i.e., entities physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate or perform certain operations described herein. Consider an example where hardware components are temporarily configured (e.g., programmed), without requiring each hardware component to be configured or instantiated at any given point in time. For instance, where the hardware components include a general-purpose processor configured by software to become a dedicated processor, this general-purpose processor can be configured as different dedicated processors (e.g., including different hardware components) at different times. The software accordingly configures one or more specific processors to constitute a specific hardware component, for example, at one moment and as different hardware components at different moments.
[0109] Hardware components can provide information to and receive information from other hardware components. Therefore, the described hardware components can be considered communicatively coupled. In the presence of multiple hardware components, communication can be achieved through signal transmission between or among two or more hardware components (e.g., via appropriate circuitry and buses). In examples where multiple hardware components are configured or instantiated at different times, such communication between hardware components can be achieved, for example, by storing information in a memory structure accessible to the multiple hardware components and retrieving information from that memory structure. For example, a hardware component can perform an operation and store the output of that operation in a memory device to which it is communicatively coupled. Other hardware components can then access the memory device at a subsequent time to retrieve and process the stored output.
[0110] Hardware components can also initiate communication with input or output devices and operate on resources (e.g., collections of information). Various operations of the example methods described herein can be performed, at least in part, by one or more processors that are temporarily or permanently configured (e.g., via software) to perform the relevant operations. Whether temporarily or permanently configured, such processors can constitute processor-implemented components that operate to perform one or more operations or functions described herein. As used herein, "processor-implemented component" refers to a hardware component implemented using one or more processors. Similarly, the methods described herein can be implemented, at least in part, by processors, where a particular processor or one or more processors are examples of hardware. For example, at least some operations of the method can be performed by one or more processors or processor-implemented components. Furthermore, one or more processors can also operate to support the execution of relevant operations in a "cloud computing" environment or as "Software as a Service" (SaaS). For example, at least some operations can be performed by a group of computers (as an example of a machine including processors), where these operations are accessible via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., APIs). The execution of certain operations can be distributed across processors, rather than residing within a single machine, but deployed across multiple machines. In some examples, the processor or processor-implemented component may reside in a single geographic location (e.g., within a home environment, office environment, or server cluster). In other examples, the processor or processor-implemented component may be distributed across several geographic locations.
[0111] In this context, "processor" refers to any circuit or virtual circuit (a physical circuit simulated by logic executed on an actual processor) that manipulates data values according to control signals (e.g., "commands," "opcodes," "machine codes," etc.) and generates corresponding output signals used to operate the machine. For example, a processor can be a CPU, a RISC processor, a CISC processor, a GPU, a DSP, an ASIC, an RFIC, or any combination thereof. A processor can also be a multi-core processor with two or more independent processors (sometimes called "cores") capable of executing instructions simultaneously.
[0112] Changes and modifications may be made to the disclosed examples without departing from the scope of this disclosure. Such and other changes or modifications are intended to be included within the scope of this disclosure as set forth in the appended claims.
[0113] An abstract of this disclosure is provided to allow the reader to quickly determine the nature of the technical disclosure. This abstract is submitted, but it should be understood that it is not intended to interpret or limit the scope or meaning of the claims. Furthermore, as can be seen in the foregoing detailed description, various features are combined in a single example for the purpose of simplification. The approach of this disclosure is not to be construed as reflecting an intention that the claimed example requires more features than are expressly listed in each claim. Rather, as reflected in the appended claims, the inventive subject matter may lie in fewer features than in a single disclosed example. Therefore, the appended claims are thus incorporated into the detailed description, wherein each claim is itself an independent example.
Claims
1. A method comprising: Establish a communication session between the first device and the second device; Transmit credentials associated with a subset of additional data from the first device to the second device; The first device receives a request for a first portion of the additional data from the second device; The binding information of a first portion of the additional data is provided to the second device, the binding information securely linking the first portion of the additional data to the credential; as well as This enables the second device to use the binding information to authenticate the first portion of the additional data.
2. The method according to claim 1, wherein, The second device includes an access control reader; and The first device includes user equipment.
3. The method according to claim 1, further comprising: The second device controls access to the protected resources based on the credentials received from the first device.
4. The method according to claim 1, further comprising: Store a list of identifiers for each piece of additional data in the subset of the additional data in the credential; A trusted institution generates a first signature for the credential; as well as The authenticity of the credentials, which include the list of the identifiers, is verified using the first signature.
5. The method according to claim 4, further comprising: Multiple signatures are generated by the trusted authority, each signature being associated with a corresponding set of additional data in the subset of the additional data.
6. The method according to claim 5, wherein, The binding information of the first part of the additional data includes a second signature associated with the first part of the additional data from among the plurality of signatures, wherein the authenticity of the first part of the additional data is verified by the second device using the second signature.
7. The method according to claim 6, further comprising: The first device receives an additional request for a second portion of the additional data from the second device; Provide a third signature, one of the plurality of signatures, associated with the second portion of the additional data, to the second device; as well as This enables the second device to use a third signature to authenticate the second portion of the additional data.
8. The method according to claim 1, further comprising: The credential stores multiple hashes of identifiers, each of which is associated with a different set of identifiers for the additional data in a subset of the additional data.
9. The method according to claim 8, further comprising: Associate the first hash among the plurality of hashes with the first hash table; as well as A first set of individual hashes is stored in a first hash table. The first individual hash in the first set of individual hashes is associated with a first portion of the additional data and a first identifier of the identifier group. The second individual hash in the first set of individual hashes is associated with a second portion of the additional data and a second identifier of the identifier group. The binding information in the first portion includes the first individual hash.
10. The method of claim 9, further comprising: Associate the second hash among the plurality of hashes with the second hash table; as well as A second hash table stores a second plurality of individual hashes, a third individual hash in the second plurality of individual hashes being associated with a third portion of the additional data and a third identifier of the identifier group, a first hash table being associated with a first group or a first category, and a second hash table being associated with a second group or a second category.
11. The method according to claim 9, wherein, The authenticity of the first portion of the additional data is verified by the second device using a first separate hash.
12. The method according to claim 9, further comprising: In response to receiving a request for the first portion of the additional data: The identifier of the first portion of the additional data is associated with the first hash; as well as The first device transmits the first hash and the identifier of the first hash table to the second device.
13. The method of claim 12, further comprising: The second device obtains a first separate hash from the first hash table based on the identifier of the first portion of the additional data; Access the first portion of the additional data from an external source; as well as The first separate hash is used to verify the authenticity of the first part of the additional data.
14. The method of claim 9, further comprising: The random value is associated with the first hash table to prevent the leakage of information about the portion of the additional data represented by the first hash of the first hash table.
15. The method of claim 9, further comprising: Associate a first random value with a first portion of the individual data to prevent information about the first portion of the additional data from being leaked via a first individual hash. as well as The second random value is associated with the second part of the separate data to prevent information about the second part of the additional data from being leaked through the second separate hash.
16. The method according to claim 1, further comprising: An iterative hash function is applied to a subset of the additional data to generate a full hash through multiple iterations; as well as The credential stores the full hash generated in response to applying the iterative hash function to the subset of additional data, wherein the full hash is derived by the second device based on some of the subset of additional data and a portion of the full hash, and the full hash is provided to the second device and used as the binding information.
17. The method of claim 16, further comprising: A sequence of data blocks is generated, each data block in the sequence corresponding to a different part of the subset of the additional data, and the full hash is calculated based on the sequence of data blocks; Receive a request for a first set of data blocks in the sequence of data blocks, as a request for a first portion of the additional data; Obtain a partial hash of a second set of data blocks in the sequence of data blocks, the second set of data blocks being earlier than the first set of data blocks in the sequence of data blocks; The partial hash and the first data block set are transmitted from the first device to the second device; as well as The second device calculates the full hash based on the partial hash, the first data block set, and the second data block set.
18. The method of claim 17, further comprising: The authenticity of the first data block set is verified by comparing the calculated full hash with the full hash provided to the second device as part of the credential.
19. A system comprising: One or more processors coupled to a memory, the memory including non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, the operations including: Establish a communication session between the first device and the second device; Transmit credentials associated with a subset of additional data from the first device to the second device; The first device receives a request for a first portion of the additional data from the second device; Provide the second device with binding information for a first portion of the additional data, the binding information securely linking the first portion of the additional data to the credential; and This enables the second device to use the binding information to authenticate the first portion of the additional data.
20. A non-transitory computer-readable medium comprising non-transitory computer-readable instructions, said non-transitory computer-readable instructions, when executed by one or more processors, configuring said one or more processors to perform operations, said operations including: Establish a communication session between the first device and the second device; Transmit credentials associated with a subset of additional data from the first device to the second device; The first device receives a request for a first portion of the additional data from the second device; The binding information of a first portion of the additional data is provided to the second device, the binding information securely linking the first portion of the additional data to the credential; as well as This enables the second device to use the binding information to authenticate the first portion of the additional data.