Authentication method for authenticating a first party to a second party
An authentication method authenticates a first party to a second party, where an operation is performed on condition that the authentication succeeds. If the first party is not authenticated, then if the first party qualifies for a sub-authorization, the operation is still performed. Further, a device that includes a first memory area holding a comparison measure, which is associated with time, and which is also used in said authentication procedure, a second memory area holding a limited list of other parties which have been involved in an authentication procedure with the device, and a third memory area, holding compliance certificates concerning parties of said list.
1. A digital device arranged for acting as a party in a current authentication procedure in which certificates are used for determining compliance of parties involved in the current authentication procedure, wherein the digital device comprises:
a first memory area for holding a comparison measure, which is concerned with time, and which is used in said current authentication procedure;
a second memory area for holding a limited list of other parties which have been involved in authentication procedures with the digital device;
a third memory area for holding compliance certificates with dates of issuances concerning the other parties of said limited list; and
a grace-counter set to a predetermined number equal to a number of times that the party is allowed to be sub-authorized after failing the current authentication procedure and configured to be decremented when a date of issuance of a compliance certificate concerning the party is compliant with the comparison measure stored in the first memory area,
wherein the digital device is configured to:
communicate to a further digital device compliance information for the current authentication procedure indicative of the compliance of the parties,
update the first memory with a more recent comparison measure, when said more recent comparison measure is available, and
in conjunction with said update, update the third memory area with more recent compliance certificates concerning the other parties of said limited list.
2. The digital device as claimed in claim 1 , wherein the digital device is arranged for:
updating the other parties of said limited list with a current party involved in the current authentication procedure.
3. The digital device of claim 1 , wherein the grace-counter is set to the predetermined number when the party is authenticated.