IP Library Granted Patent US 8,645,694
Granted Patent B2
US 8,645,694 · App. 11/575,786 · Granted Feb 4, 2014

Method of authentication based on polyomials

Inventors: Geert Jan Schrijen (Eindhoven, NL); Thomas Andreas Maria Kevenaar (Eindhoven, NL)
Assignee: Koninklijke Philips N.V.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,645,694
App. No.
11/575,786
Granted
Feb 4, 2014
Kind
B2
Abstract

There is provided an authentication method for a system ( 10 ) comprising several devices ( 30 ). The method involves: a) providing each device ( 30 ) with an identity value (pi: i=1, . . . , n) and a polynomial (P) for generating a polynomial key; (b) including a verifier device (p 1 ) and a prover device (P 2 )amongst said devices ( 30 ); (c) arranging for the prover device (p 2 ) to notify its existence to the verifier device (P 1 ); (d) arranging for the verifier device (p i ) to challenge the prover device (p 2 ) to encrypt a nonce using the prover (P 2 )device's polynomial (P) key and communicate the encrypted nonce as a response to the verifier device (p 1 ); (e) arranging for the verifier device (p 1 ) to receive the encrypted nonce as a further challenge from the prover device (p Z ) and: (i ) encrypt the challenge using the polynomial keys generated from a set of stored device identities; or (ii) decrypt the challenge received using the set of polynomial keys; until said verifier device (p 1 ) identifies an authentication match.

Claims (37)

1. A method of authentication based on polynomials for a system comprising a plurality of devices operable to mutually communicate, said method comprising:

providing each of said plurality of devices with a corresponding identity value together with an associated polynomial for generating a unique polynomial key for each device;

arranging for the plurality of devices to include a verifier device and a prover device;

arranging for the prover device to notify its existence to the verifier device;

arranging for the verifier device to issue a first challenge to the prover device to encrypt a nonce using the prover device's unique polynomial key and communicate the encrypted nonce as a response back to the verifier device;

arranging for the verifier device to receive the encrypted nonce as the response from the prover device and:

to decrypt the response received from the prover device using each of the unique polynomial keys until said verifier device identifies a match between the decrypted response and the first challenge;

said match being indicative of authentication;

wherein a random value is additionally created by the prover device and encrypted together with a response from the verifier device for sending back to the verifier device, said random value being operable to function as a session key.

2. The method as claimed in claim 1 , wherein issuance of the identity values and associated polynomials is undertaken via a trusted third party.

3. The method as claimed in claim 1 , further including establishing a session key which can be used for further subsequent communications for providing mutual authentication for said plurality of devices and for providing privacy to at least one of said plurality of devices.

4. The method as claimed in claim 1 , wherein the first challenge from the verifier device to the prover device is implemented such that the nonce is a random number.

5. The method as claimed in claim 1 , said method further including configuring the system so that said plurality of devices includes multiple prover devices and multiple verifier devices, said multiple prover devices including a subset of prover devices operable to authenticate to a particular verifier device of the multiple verifier devices.

6. The method as claimed in claim 1 , wherein said prover devices are implemented as smart cards or tags enabling access to services related to or coupled to a given verifier device.

7. The method as claimed in claim 1 , wherein the prover device is operable to apply a hash function or keyed hash function to create a response to the first challenge from the verifier device.

8. A system comprising a plurality of devices operable to mutually communicate, said system comprising:

a trusted third party to provide each of said plurality of devices with a corresponding identity value together with an associated polynomial for generating a unique polynomial key for each device;

the plurality of devices to include a verifier device and a prover device;

the prover device to notify its existence to the verifier device;

the verifier device to issue a first challenge to the prover device to encrypt a nonce using the prover device's unique polynomial key and communicate the encrypted nonce as a response back to the verifier device;

the verifier device to receive the encrypted nonce as the response from the prover device and:

to decrypt the response received from the prover device using each of the unique polynomial keys until said verifier device identifies a match between the decrypted response and the first challenge;

said match being indicative of authentication;

wherein a random value is additionally created by the prover device and encrypted together with a response from the verifier device for sending back to the verifier device, said random value being operable to function as a session key.

9. The system as claimed in claim 8 , the system being adapted for providing at least one of:

authentication associated with financial transactions executed within banking systems; and

controlling access by way of tags or similar portable identifiers authenticating within a system operable according to the method.

10. A non-transitory data carrier comprising software executable on computing hardware to implement the method as claimed in claim 1 .

11. A smart card or tag for undertaking authentication in an authentication system, the system comprising:

a trusted third party to provide each of said plurality of devices with a corresponding identity value together with an associated polynomial for generating a unique polynomial key for each device;

the plurality of devices to include a verifier device and a prover device;

the prover device to notify its existence to the verifier device;

the verifier device to issue a first challenge to the prover device to encrypt a nonce using the prover device's unique polynomial key and communicate the encrypted nonce as a response back to the verifier device;

the verifier device to receive the encrypted nonce as the response from the prover device and:

to decrypt the response received from the prover device using each of the unique polynomial keys until said verifier device identifies a match between the decrypted response and the first challenge;

said match being indicative of authentication;

wherein a random value is additionally created by the prover device and encrypted together with a response from the verifier device for sending back to the verifier device, said random value being operable to function as a session key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2007
From: SCHRIJEN, GEERT JAN; KEVENAAR, THOMAS ANDREAS MARIA
To: KONINKLIJKE PHILIPS ELECTRONICS N V
Reel/Frame 019049/0318 →
Priority Claims (1)
EP 04104780 · Sep 30, 2004 · regional
Continuity (1)
Related Publication 20080209214A1 · Aug 28, 2008