IP Library Granted Patent US 11,533,310
Granted Patent B2
US 11,533,310 · App. 17/168,455 · Granted Dec 20, 2022

Authentication method

Inventors: Sebastian Fach (Schwalbach a. Ts., DE); Gilles Yvars (Schwalbach a. Ts., DE); Ahmad Sabouri (Schwalbach a. Ts., DE)
Assignee: CONTINENTAL TEVES AG & CO. OHG
H04L63/0884B60R25/24H04L63/0442H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,533,310
App. No.
17/168,455
Granted
Dec 20, 2022
Kind
B2
Abstract

An authentication method and system for mutual authentication between a first entity and a third entity via a second entity, based on an authentication protocol used by the first entity and the third entity. The second entity forwards mutual authentication messages between the first entity and the third entity. An apparatus is configured to perform an authentication method for a mutual authentication between a first entity and a third entity via a second entity, based on an authentication protocol used by the first entity and the third entity, the second entity forwards mutual authentication messages between the first entity and the third entity.

Claims (42)

1. An authentication method for mutual authentication between a first entity and a third entity via a second entity, based on an authentication protocol used by the first entity and the third entity, wherein the second entity forwards mutual authentication messages between the first entity and the third entity, comprising:

a) frontloading, by the third entity, a first part of the authentication protocol to the second entity and keeping at least a missing part of the authentication protocol at the third entity, the frontloaded first part of the authentication protocol comprising a first encrypted number, the third entity, after frontloading the first part of the authentication protocol, turning from a High Power Mode into a Low Power Mode;

b) initiating the mutual authentication;

c) starting the mutual authentication based on the frontloaded first part of the authentication protocol, the starting comprising generating a second encrypted number by the first entity, the second encrypted number comprising content of the first encrypted number;

d) sending, by the second entity, a wake-up signal to the third entity;

e) rerouting, by the second entity, the mutual authentication messages, when the third entity woke up from Low Power Mode, the rerouting comprising transmitting the second encrypted number from the second entity to the third entity; and

f) continuing, by the third entity, after rerouting the mutual authentication messages to the third entity, the mutual authentication based on the missing part of the authentication protocol, the missing part of the authentication protocol comprising instructions for the third entity to derive a session key based on the second encrypted number and instructions for the first entity to derive a session key based on a third encrypted number generated and transmitted by the third entity, the third encrypted number comprising content of the second encrypted number, and continuing comprising using the respective session keys by the first entity and the third entity to exchange authenticated messages between the first entity and the third entity.

2. The authentication method according to claim 1 , wherein the rerouting starts when the third entity woke up from Low Power Mode and when the frontloaded first part of the authentication protocol between the second entity and the first entity is completed.

3. The authentication method according to claim 1 , wherein the frontloading a first part of the authentication protocol comprises:

i) pre-generating, by the third entity, the first part of the authentication protocol;

ii) transmitting, by the third entity, the pre-generated first part of the authentication protocol from the third entity to the second entity;

iii) receiving, by the second entity, the pre-generated first part of the authentication protocol from the third entity; and

iv) storing, by the second entity, the received first part of the authentication protocol on the second entity.

4. The authentication method according to claim 1 , wherein the frontloading comprises generating a random number and encrypting the random number with a symmetric key to derive a first encrypted number, wherein the symmetric key is derived using a one-way key derivation function based on pre-shared asymmetric key material of the first entity and the third entity.

5. The authentication method according to claim 1 , wherein the frontloading comprises adding, by the third entity, an identifier to the first part of the authentication protocol.

6. The authentication method according to claim 5 , wherein the identifier is a public key associated with the respective first entity and/or a serial number associated with the respective first entity.

7. The authentication method according to claim 1 , wherein the sending, by the second entity, a wake-up signal to the third entity, is carried out by the second entity, by one of:

in the initiating, immediately when the first entity operatively connects to the second entity

or

if an identifier for identifying the first entity is added to the first part of the authentication protocol, in accordance with an identification of the first entity.

8. The authentication method according to claim 1 , wherein the starting comprises, pre-generating, by the first entity, a second encrypted number and storing the second encrypted number in a secured area at the first entity.

9. A data processing system comprising a processor and memory configured to perform the authentication method for mutual authentication between a first entity and a third entity via a second entity, based on an authentication protocol used by the first entity and the third entity, wherein the second entity forwards mutual authentication messages between the first entity and the third entity, comprising:

a) frontloading a first part of the authentication protocol to the second entity and keeping at least a missing part of the authentication protocol at the third entity, the frontloaded first part of the authentication protocol comprising a first encrypted number, the third entity, after frontloading the first part of the authentication protocol, turning from a High Power Mode into a Low Power Mode;

b) initiating the mutual authentication;

c) starting the mutual authentication based on the frontloaded first part of the authentication protocol, the starting comprising generating a second encrypted number by the first entity, the second encrypted number comprising content of the first encrypted number;

d) sending, by a second entity, a wake-up signal to the third entity;

e) rerouting, by the second entity, the mutual authentication messages, when the third entity woke up from Low Power Mode, the rerouting comprising transmitting the second encrypted number from the second entity to the third entity; and

f) continuing, after rerouting the mutual authentication messages to the third entity, the mutual authentication based on the missing part of the authentication protocol, the missing part of the authentication protocol comprising instructions for the third entity to derive a session key based on the second encrypted number and instructions for the first entity to derive a session key based on a third encrypted number generated and transmitted by the third entity, the third encrypted number comprising content of the second encrypted number, and continuing comprising using the respective session keys by the first entity and the third entity to exchange authenticated messages between the first entity and the third entity.

10. A computer program product comprising instructions which, when the program is executed by a computer having a processor and memory, cause the computer to carry out an authentication method for mutual authentication between a first entity and a third entity via a second entity, based on an authentication protocol used by the first entity and the third entity, wherein the second entity forwards mutual authentication messages between the first entity and the third entity, comprising:

a) frontload a first part of the authentication protocol to the second entity and keeping at least a missing part of the authentication protocol at the third entity, the frontloaded first part of the authentication protocol comprising a first encrypted number, the third entity, after frontloading the first part of the authentication protocol, turning from a High Power Mode into a Low Power Mode;

b) initiating the mutual authentication;

c) starting the mutual authentication based on the frontloaded first part of the authentication protocol, the starting comprising generating a second encrypted number by the first entity, the second encrypted number comprising content of the first encrypted number;

d) sending, by a second entity, a wake-up signal to the third entity;

e) rerouting, by the second entity, the mutual authentication messages, when the third entity woke up from Low Power Mode, the rerouting comprising transmitting the second encrypted number from the second entity to the third entity; and

f) continuing, after rerouting the mutual authentication messages to the third entity, the mutual authentication based on the missing part of the authentication protocol, the missing part of the authentication protocol comprising instructions for the third entity to derive a session key based on the second encrypted number and instructions for the first entity to derive a session key based on a third encrypted number generated and transmitted by the third entity, the third encrypted number comprising content of the second encrypted number, and continuing comprising using the respective session keys by the first entity and the third entity to exchange authenticated messages between the first entity and the third entity.

11. A non-transitory computer-readable data storage medium comprising instructions which, when executed by a computer having a processor and memory, cause the computer to carry out an authentication method for mutual authentication between a first entity and a third entity via a second entity, based on an authentication protocol used by the first entity and the third entity, wherein the second entity forwards mutual authentication messages between the first entity and the third entity, comprising:

a) frontloading a first part of the authentication protocol to the second entity and keeping at least a missing part of the authentication protocol at the third entity, the frontloaded first part of the authentication protocol comprising a first encrypted number, the third entity, after frontloading the first part of the authentication protocol, turning from a High Power Mode into a Low Power Mode;

b) initiating the mutual authentication;

c) starting the mutual authentication based on the frontloaded first part of the authentication protocol, the starting comprising generating a second encrypted number by the first entity, the second encrypted number comprising content of the first encrypted number;

d) sending, by a second entity, a wake-up signal to the third entity;

e) rerouting, by the second entity, the mutual authentication messages, when the third entity woke up from Low Power Mode, the rerouting comprising transmitting the second encrypted number from the second entity to the third entity; and

f) continuing, after rerouting the mutual authentication messages to the third entity, the mutual authentication based on the missing part of the authentication protocol, the missing part of the authentication protocol comprising instructions for the third entity to derive a session key based on the second encrypted number and instructions for the first entity to derive a session key based on a third encrypted number generated and transmitted by the third entity, the third encrypted number comprising content of the second encrypted number, and continuing comprising using the respective session keys by the first entity and the third entity to exchange authenticated messages between the first entity and the third entity.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Aug 27, 2024
From: CONTINENTAL TEVES AG & CO. OHG; CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
To: CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
Reel/Frame 068794/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2021
From: FACH, SEBASTIAN; YVARS, GILLES; SABOURI, AHMAD
To: CONTINENTAL TEVES AG & CO. OHG
Reel/Frame 056196/0559 →
Priority Claims (1)
EP 20315016 · Feb 7, 2020 · regional
Continuity (1)
Related Publication 20210250351A1 · Aug 12, 2021
Cited By (1)
US 12,593,198