IP Library Granted Patent US 12,189,754
Granted Patent B2
US 12,189,754 · App. 17/654,167 · Granted Jan 7, 2025

Authentication method and device

Inventor: Michael Peeters (Tourinnes-la-Grosse, BE)
Assignee: STMicroelectronics Belgium
G06F21/44H04L9/0866H04L9/16H04L9/3271H04L63/0428H04L63/08H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,754
App. No.
17/654,167
Granted
Jan 7, 2025
Kind
B2
Abstract

The present disclosure relates to authenticating a first device to a second device, including at least two successive verification operations comprising the following successive steps. The second device generates a first data, and sends the first data to the first device. The first device generates a third data and a fourth data used by the following verification operation and sends the third data to the second device. The second device checks the third data indicating whether the check was successful or not.

Claims (57)

1. An authentication method of a prover device to a verifier device, the method comprising:

at least two successive verification operations, each operation comprising, successively:

generating, by the verifier device, first data from second data generated by the verifier device in a preceding verification operation;

sending, by the verifier device, the first data to the prover device;

generating, by the prover device, third data and fourth data used by a following verification operation, by applying a first function taking as input at least the first data and the fourth data generated in the preceding verification operation;

sending, by the prover device, the third data to the verifier device;

verifying, by the verifier device, the third data using a second function taking as input the first data and the third data; and

outputting, by the verifier device, information indicating whether the verification was successful, and the second data used by the following verification operation; and

authenticating the prover device to the verifier device in response to:

for each verification operation, the information indicating that the verification was successful; and

the fourth data of the prover device and the second data of the verifier device of a last verification operation being correct.

2. The method according to claim 1 , wherein, during implementation of a first verification operation, the verifier device uses fifth data to generate the first data, and the prover device uses sixth data to generate the third data and the fourth data.

3. The method according to claim 2 , wherein the fifth data is different for each verification operation, and the sixth data is different for each verification operation.

4. The method according to claim 2 , wherein, during implementation of each verification operation, the verifier device uses the fifth data to generate the first data, and the prover device uses the sixth data to generate the third data and the fourth data.

5. The method according to claim 2 , wherein the verifier device generates the first data from the second data generated in the preceding verification operation and the fifth data, and the first function takes as input the first data, the fourth data generated in the preceding verification operation, and the sixth data.

6. The method according to claim 1 , further comprising an identification operation preceding the at least two successive verification operations, the identification operation comprising:

the prover and verifier devices exchanging identification numbers; and

in response to at least one of the devices not recognizing the identification number of the other device, implementing the at least two successive verification operations.

7. The method according to claim 1 , wherein the first function of one of the at least two successive verification operations is different from the first function of another one of the at least two successive verification operations.

8. The method according to claim 1 , wherein the second function of the at least two successive verification operations is different from the second function of another of the at least two successive verification operations.

9. The method according to claim 1 , wherein the prover and verifier devices send data to each other in an encrypted manner.

10. The method according to claim 9 , wherein, during implementation of each of the at least two successive verification operations, the prover and verifier devices send the data to each other in the encrypted manner using a first encryption key.

11. The method according to claim 10 , wherein the first encryption key is different for each implementation of each of the at least two successive verification operations.

12. The method according to claim 11 , wherein the first encryption key depends on the first encryption key of the preceding verification operation.

13. The method according to claim 1 , wherein, of the at least two successive verification operations, there is at least a first verification operation in which the second function generates seventh data, in addition, which is sent to the verifier device, and

of the at least two successive verification operations there is at least one second verification operation, successive to the first verification operation, wherein:

the verifier device further generates eighth data by applying the first function to the seventh data and sends the eighth data to the prover device; and

the prover device decrypts ninth data using the eighth data to generate the third data.

14. The method according to claim 13 , wherein the prover device uses the eighth data to decrypt ninth data, and the first function further takes the ninth data as input to generate the third data.

15. A prover device comprising:

a non-transitory memory comprising instructions; and

a processor in communication with the non-transitory memory, wherein the processor executes the instructions to authenticate the prover device to a verifier device, the authentication comprising:

at least two successive verification operations, each operation comprising, successively:

receiving first data from the verifier device, the first data generated by the verifier device from second data generated by the verifier device in a preceding verification operation;

generating third data and fourth data used by a following verification operation, by applying a first function taking as input at least the first data and the fourth data generated in the preceding verification operation; and

sending the third data to the verifier device for verification using a second function taking as input the first data and the third data; and

verifying the prover device to authorized to communicate with the verifier device in response to the fourth data of the prover device of a last verification operation being correct.

16. The prover device according to claim 15 , wherein the non-transitory memory is configured to store the first, third, and fourth data.

17. The prover device according to claim 15 , wherein the authentication further comprises an identification operation preceding the at least two successive verification operations, the identification operation comprising:

exchanging identification numbers with the verifier device; and

in response to at least one of the devices not recognizing the identification number of the other device, implementing the at least two successive verification operations.

18. A verifier device comprising:

a non-transitory memory comprising instructions; and

a processor in communication with the non-transitory memory, wherein the processor executes the instructions to authenticate a prover device to the verifier device, the authentication comprising:

at least two successive verification operations, each operation comprising, successively:

generating first data from second data generated by the verifier device in a preceding verification operation;

sending the first data to the prover device;

receiving third data from the prover device, the third data and fourth data used by a following verification operation generated by the prover device by applying a first function taking as input at least the first data and the fourth data generated in the preceding verification operation;

verifying the third data using a second function taking as input the first data and the third data; and

outputting information indicating whether the verification was successful, and the second data used by the following verification operation; and

verifying the prover device to authorized to communicate with the verifier device in response to:

for each verification operation, the information indicating that the verification was successful; and

the second data of the verifier device of a last verification operation being correct.

19. The verifier device according to claim 18 , wherein the non-transitory memory is configured to store the first, second, and fourth data and the information.

20. The verifier device according to claim 18 , wherein the authentication further comprises an identification operation preceding the at least two successive verification operations, the identification operation comprising:

exchanging identification numbers with the prover device; and

in response to at least one of the devices not recognizing the identification number of the other device, implementing the at least two successive verification operations.

Assignments (2)
CHANGE OF NAME Recorded Oct 9, 2024
From: PROTON WORLD INTERNATIONAL
To: STMICROELECTRONICS BELGIUM
Reel/Frame 069174/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2022
From: PEETERS, MICHAEL
To: PROTON WORLD INTERNATIONAL N.V.
Reel/Frame 059211/0335 →
Priority Claims (1)
FR 2103602 · Apr 8, 2021 · national
Continuity (1)
Related Publication 20220327194A1 · Oct 13, 2022
References Cited (21)
US 5241598A · Raith · 1993 [cited by applicant]
US 7363492B2 · Kuhlman · 2008 [cited by examiner]
US 20050188200A1 · Kwok · 2005 [cited by applicant]
US 20070094505A1 · Futa et al. · 2007 [cited by applicant]
US 20090135725A1 · Tanaka et al. · 2009 [cited by applicant]
US 20110276844A1 · Potter et al. · 2011 [cited by applicant]
US 20120143830A1 · Cormode · 2012 [cited by examiner]
US 20130279697A1 · Garcia Morchon et al. · 2013 [cited by applicant]
US 20150278506A1 · Jun · 2015 [cited by examiner]
US 20180152305A1 · Jacquin et al. · 2018 [cited by applicant]
US 20180352433A1 · Vendelbo · 2018 [cited by examiner]
US 20200272724A1 · Peeters · 2020 [cited by examiner]
CN 1665181A · 2005 [cited by applicant]
CN 1788453A · 2006 [cited by applicant]
CN 101123501A · 2008 [cited by applicant]
CN 101317426A · 2008 [cited by applicant]
CN 103003799A · 2013 [cited by applicant]
CN 107534551A · 2018 [cited by applicant]
CN 109309689A · 2019 [cited by applicant]
“Zero Knowledge Authentication”—Rob Leslie, Sedicii, Jul. 30, 2015 https://sedicii.com/news/Zero-Knowledge-Authentication/ (Year: 2015). [cited by examiner]
“Secure Comparator: a ZKP-Based Authentication System”—Korchagin et al., Cossacklabs, Mar. 2015 https://www.cossacklabs.com/files/secure-comparator-paper-rev12.pdf (Year: 2015). [cited by examiner]