DE102019001731A1 - Authorization procedure using one-time passwords - Google Patents
Authorization procedure using one-time passwords Download PDFInfo
- Publication number
- DE102019001731A1 DE102019001731A1 DE102019001731.5A DE102019001731A DE102019001731A1 DE 102019001731 A1 DE102019001731 A1 DE 102019001731A1 DE 102019001731 A DE102019001731 A DE 102019001731A DE 102019001731 A1 DE102019001731 A1 DE 102019001731A1
- Authority
- DE
- Germany
- Prior art keywords
- server
- password
- client
- time password
- access
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/45—Structures or tools for the administration of authentication
- G06F21/46—Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Abstract
Ein Autorisierungsverfahren mittels Einmalpasswörtern befähigt den Client und den Server, unabhängig vom jeweils anderen, ein eigenes Passwort zur Absicherung der eigenen Interessen an der zu schützenden Netzwerkresource einzurichten. Zumindest der Client wird verpflichtet, vor der Autorisierung eines Zugriffs ein neues zufälliges Einmalpasswort zu generieren, das in keinem mathematischen oder funktionalem Verhältnis zu früheren oder zukünftigen Einmalpasswörtern steht, und dieses Zug um Zug mit der Autorisierung des aktuellen Zugriffs beim jeweils anderen Verfahrenspartner zu aktualisieren. Eine Autorisierung erfolgt nicht ohne vorherige Einrichtung eines neuen Einmalpasswortes und neue Einmalpasswörter können nur eingerichtet werden, wenn die Autorisierung mittels des aktuellen Einmalpasswortes erfolgreich abgeschlossen werden kann.An authorization procedure using one-time passwords enables the client and the server, independently of the other, to set up their own password to protect their own interests in the network resource to be protected. At least the client is obliged to generate a new, random one-time password, which has no mathematical or functional relationship to previous or future one-time passwords, before authorizing access, and to update this step by step with the authorization of the current access at the other procedural partner. Authorization does not take place without first setting up a new one-time password and new one-time passwords can only be set up if the authorization can be successfully completed using the current one-time password.
Description
Gebiet der ErfindungField of invention
Die vorliegende Erfindung betrifft ein Autorisierungsverfahren mittels Einmalpasswörtern und insbesondere ein Verfahren zur automatischen Einrichtung von zufälligen Einmalpasswörtern zwischen dem Client und dem Server und zur getrennten Absicherung der Schutzinteressen des Clients und Servers.The present invention relates to an authorization method by means of one-time passwords and in particular to a method for automatically setting up random one-time passwords between the client and the server and for separately safeguarding the protection interests of the client and server.
Beschreibung der ErfindungDescription of the invention
Es ist bekannt, Zugriffe eines Clients auf eine von einem Server in einer Client-Server-Netzwerkumgebung angebotenen Netzwerkresource von der Kenntnis eines Zugriffspasswortes abhängig zu machen. Weiterhin ist bekannt, dass die Speicherung der Zugriffspasswörter am Server zu Sicherheitsproblemen führen kann, da diese am Server entwendet und Dritte so unbemerkt Zugriff auf die Netzwerkresource erlangen können. Aus diesem Grund ist es gängige Praxis, am Server mittels kryptologischer Hashfunktionen Kontrollwerte der Passwörter zu hinterlegen. Aus diesen Kontrollwerten können die Passwörter nicht wieder hergestellt werden, aber ein Passwort kann dadurch bestätigt werden, dass sich aus ihm mittels der Hashfunktion der gleiche Hashwert berechnen lässt.It is known to make access by a client to a network resource offered by a server in a client-server network environment dependent on knowledge of an access password. It is also known that the storage of access passwords on the server can lead to security problems, as they are stolen from the server and third parties can gain access to the network resource without being noticed. For this reason, it is common practice to store password control values on the server using cryptological hash functions. The passwords cannot be restored from these control values, but a password can be confirmed by the fact that the same hash value can be calculated from it using the hash function.
Das Passwort bleibt ein privates Geheimnis des Clients, bis der Client das Passwort zum Zwecke der Autorisierungsprüfung gegenüber dem Server offenbaren muss. Aus Sicht des Clients kann nicht ausgeschlossen werden, dass der Server das Passwort speichert. Die Passwortsicherheit ist so für den Anwender nicht mehr gegeben.The password remains a private secret of the client until the client has to reveal the password to the server for the purpose of the authorization check. From the client's point of view, it cannot be ruled out that the server will save the password. Password security is no longer given for the user.
Weiterhin ist bekannt, dass die wiederholte Verwendung eines Passwortes dazu führen kann, dass jemand, der die Netzwerkkommunikation belauscht, durch das Abfangen des Passwortes unberechtigten Zugriff auf die Netzwerkresource erlangen kann. Es ist bekannt, dass dieses Problem durch die Verwendung von Einmalpasswörtern (One-Time-Password) umgangen werden kann. (RFC 2289, Network Working Group, Stanford University, Februar 1998; RFC 4226, Network Working Group, Stanford University, Dezember 2005; RFC 6238, Internet Engineering Task Force, Mai 2011)It is also known that the repeated use of a password can lead to someone eavesdropping on the network communication being able to gain unauthorized access to the network resource by intercepting the password. It is known that this problem can be circumvented by using one-time passwords. (RFC 2289, Network Working Group, Stanford University, February 1998; RFC 4226, Network Working Group, Stanford University, December 2005; RFC 6238, Internet Engineering Task Force, May 2011)
Nach gängiger Praxis werden in den Verfahren zur Bildung der Einmalpasswörter mathematische Berechnungen oder Ableitungsfunktionen zur Generierung der Passwörter auf der Clientseite und der Kontrollwerte auf der Serverseite verwendet. Der Server prüft somit, ob der Client das erforderliche Passwort oder den erforderlichen Beweis des Passwortes korrekt berechnen oder herleiten kann. Da der Server aber nicht nur das Berechnungsergebnis bestätigen, sondern dieses auch selbst berechnen muss, kann der Server den Prüfungsbeweis selbst antreten. Ein infiltriertes Serversystem könnte sich so selbst autorisieren. Dies ist bei einer üblichen Passwortprüfung, bei der der Server einen Hashwert des Passwortes als Kontrollwert speichert, nicht der Fall. Der Client muss das zum Hashwert passende Passwort liefern, um sich zu autorisieren. Der Server kann das Passwort nicht aus dem Hashwert ableiten und kennt somit den Eingabewert der Prüfungsfunktion nicht. Es besteht zusätzlich das Risiko, dass ein Angreifer in einem System funktional berechneter Werte neue Werte berechnen kann, sobald er Kenntnis über die verwendete Funktion oder zuvor verwendete Werte erlangt hat.According to current practice, mathematical calculations or derivation functions for generating the passwords on the client side and the control values on the server side are used in the method for forming the one-time passwords. The server thus checks whether the client can correctly calculate or derive the required password or the required proof of the password. Since the server not only has to confirm the calculation result but also has to calculate it itself, the server can provide the test evidence itself. An infiltrated server system could thus authorize itself. This is not the case with a customary password check in which the server saves a hash value of the password as a control value. The client must supply the password that matches the hash value in order to be authorized. The server cannot derive the password from the hash value and therefore does not know the input value of the test function. There is also the risk that an attacker can calculate new values in a system of functionally calculated values as soon as he has knowledge of the function used or previously used values.
Ein neu angelegtes zufälliges Passwort ist so lange sicher, bis es zur Autorisierungsprüfung dem Server gegenüber offenbart werden muss. Es wäre wünschenswert, diesen initialen Sicherheitszustand nach jeder Autorisierung wiederherstellen zu können. Dazu müsste nach jedem Zugriff ein neues zufälliges Passwort am Client und der entsprechende Kontrollwert am Server aktiviert werden, ohne dass es eine mathematische oder funktionale Beziehung zwischen dem alten und dem neuen Passwort oder zwischen dem alten und dem neuen Kontrollwert gibt.A newly created, random password is secure until it has to be revealed to the server for the authorization check. It would be desirable to be able to restore this initial security status after each authorization. For this purpose, a new random password on the client and the corresponding control value on the server would have to be activated after each access, without there being a mathematical or functional relationship between the old and the new password or between the old and the new control value.
Dazu ist bekannt, dass das Ereignis der Autorisierung des Zugriffs eines Clients auf eine Serveranwendung dazu verwendet werden kann, das Passwort und den am Server hinterlegten Kontrollwert zu ändern. (Patent
Dieses Verfahren schließt den Prozess der Aktualisierung eines Passwortes an den Prozess der Autorisierung an. Der Client wird nach erfolgreicher Autorisierung vom Server bei Bedarf zum Wechsel des Passwortes aufgefordert. Selbst wenn der Server so konfiguriert wird, dass der Client nach jeder Autorisierung aufgefordert wird, das Passwort zu ändern, ist der Zugriff bereits erfolgt, bevor das Verfahren zur Änderung des Passwortes durchlaufen ist. Es wäre also möglich, dieses Verfahren nach der Autorisierung durch den Client abzubrechen und so die Änderung des Passwortes auszuhebeln.This procedure connects the process of updating a password to the process of authorization. After successful authorization, the client will be prompted by the server to change the password if necessary. Even if the server is configured so that the client is prompted to change the password after each authorization, the access has already occurred before the procedure for changing the Password has passed. It would therefore be possible to cancel this process after authorization by the client and thus cancel the change in the password.
Die Vergabe, Verwaltung und Absicherung des Zugriffspasswortes ist nach dem bisherigen Stand der Technik Aufgabe des Servers. Der Anwender darf am Client bestenfalls den Inhalt des Passwortes im Rahmen vorgegebener Passwortrichtlinien bestimmen. Gerade auf die Absicherung des Zugriffspasswortes hat der Anwender der Netzwerkresource, die vielleicht sensible Daten des Anwenders speichert oder Zugriff auf sensible Lebens- oder Geschäftsbereiche des Anwenders hat, keinen Einfluss.The assignment, administration and protection of the access password is the task of the server according to the current state of the art. At best, the user can determine the content of the password on the client within the framework of specified password guidelines. The user of the network resource, which may store sensitive user data or have access to sensitive areas of life or business of the user, has no influence on securing the access password.
Der im Patentanspruch 1 angegebenen Erfindung liegt das Problem zugrunde, für ein am Client festgelegtes Zugriffspasswort den urspünglichen Sicherheitszustand eines frisch eingerichteten zufälligen Passwortes Zug um Zug mit jeder Zugriffsautorisierung wiederherzustellen.The invention specified in
Dieses Problem wird durch die im Patentanspruch 1 aufgeführten Merkmale gelöst.This problem is solved by the features listed in
Die mit der Erfindung erzielten Vorteile bestehen insbesondere darin, dass das vom Client jeweils neu generierte Einmalpasswort zufällig vom ursprünglichen Passwort abgeleitet wird. Es gibt kein mathematisches oder funktionales Verhältnis zwischen den Passwörtern oder den Kontrollwerten der einzelnen Zugriffe. Es wird für jeden Zugriff ein neues, zufälliges Einmalpasswort eingerichtet, das dem Server bis zu dem Zeitpunkt unbekannt bleibt, in dem es entwertet wird.The advantages achieved with the invention are, in particular, that the one-time password generated by the client is randomly derived from the original password. There is no mathematical or functional relationship between the passwords or the control values of the individual accesses. A new, random one-time password is set up for each access, which remains unknown to the server until the point in time at which it is canceled.
Der Server kann einen zugriffsberechtigenden Kontrollwert nicht selbst berechnen und das Passwort kann aus dem Kontrollwert nicht abgeleitet werden, was eine Eigenautorisierung eines infiltrierten Servers unmöglich macht.The server cannot itself calculate an access-authorized control value and the password cannot be derived from the control value, which makes self-authorization of an infiltrated server impossible.
Das neue Einmalpasswort wird vor dem Autorisierungsschritt vorbereitet, als Bedingung für eine erfolgreiche Autorisierung vorausgesetzt und mit erfolgreicher Autorisierung sofort aktiviert. Eine erneute Verwendbarkeit des alten Einmalpasswortes ist somit ausgeschlossen.The new one-time password is prepared before the authorization step, required as a condition for successful authorization and activated immediately with successful authorization. This means that the old one-time password cannot be used again.
Die Autorisierungsprüfung ist abhängig von der beiderseitigen Kenntnis des im selben Verfahrenslauf vereinbarten neuen Kontrollwertes. Dies stellt sicher, dass nur der Client, der im vorherigen Schritt des Verfahrens den Kontrollwert aus seinem zufälligen neuen Einmalpasswort generiert hat, im nächsten Schritt des gleichen Verfahrens vom Server autorisiert werden kann. So kann kein unberechtiger Client in das laufende Autorisierungsverfahren eindringen.The authorization check is dependent on mutual knowledge of the new control value agreed in the same process run. This ensures that only the client that generated the control value from its random new one-time password in the previous step of the procedure can be authorized by the server in the next step of the same procedure. This means that no unauthorized client can intrude into the ongoing authorization process.
Gleichzeitig kann die Autorisierungsprüfung am Server nur gelingen, wenn der Kontrollwert des neuen Einmalpasswortes am Client und am Server übereinstimmen. Ein asynchroner neuer Kontrollwert, der ein Scheitern eines späteren Autorisierungsversuches mittels des neuen Einmalpasswortes verursachen würde, führt zum Abbruch des aktuellen Verfahrenslaufs. Dies stellt sicher, dass ein Zugriff nur autorisiert und ein neues Einmalpasswort eingerichtet wird, wenn das neu vereinbarte Einmalpasswort auch anwendbar ist.At the same time, the authorization check on the server can only succeed if the control value of the new one-time password on the client and the server match. An asynchronous new control value, which would cause a later authorization attempt using the new one-time password to fail, leads to the current process run being aborted. This ensures that access is only authorized and a new one-time password is set up if the newly agreed one-time password can also be used.
Eine vorteilhafte Ausgestalung der Erfindung ist im Patentanspruch 2 angegeben. Die Weiterbildung nach Patentanspruch 2 ermöglicht es dem Server, den Zugriff auf die Netzwerkresource durch ein zusätzliches serverseitiges Passwort abzusichern. Das erfindungsgemäße Verfahren, gibt dem Client als Eigentümer oder Anwender der Inhalte der Netzwerkresource die Kontrolle über den Zugriff auf die Netzwerkresource. So kann beispielsweise der Zugriff auf sensible personenbezogene Daten mittels des Verfahrens derart abgesichert werden, dass sich einem infiltrierten Server die zugangsrelevanten Daten nicht offenbaren. Der Server hat aber keine Kontrolle mehr über die Absicherung der Netzwerkresource und kann eigenen Verpflichtungen vielleicht nicht mehr in ausreichendem Maße nachkommen. Die Weiterbildung nach Patentanspruch 2 ermöglicht es dem Server, seiner Verantwortung zur Absicherung des Zugriffs auf die Netzwerkresource unabhängig vom Clientpasswort nachzukommen.An advantageous embodiment of the invention is specified in claim 2. The development according to claim 2 enables the server to secure access to the network resource with an additional server-side password. The method according to the invention gives the client, as the owner or user of the contents of the network resource, control over access to the network resource. For example, access to sensitive personal data can be secured using the method in such a way that the access-relevant data is not revealed to an infiltrated server. However, the server no longer has control over securing the network resource and may no longer be able to meet its own obligations to a sufficient extent. The development according to claim 2 enables the server to meet its responsibility for securing access to the network resource regardless of the client password.
Eine vorteilhafte Ausgestalung der Erfindung ist im Patentanspruch 3 angegeben. Die Weiterbildung nach Patentanspruch 3 ermöglicht es dem Server, den Zugriff auf die Netzwerkresource durch ein zusätzliches serverseitiges Passwort abzusichern, indem für jeden Verfahrenslauf ein neues zufälliges Einmalpasswort zur Wahrung der Passwortsicherheit generiert und an den Client übermittelt wird. Die Autorisierung des Zugriffs und die Aktivierung des neuen Clienteinmalpasswortes und des neuen Servereinmalpasswortes ist nur möglich, wenn der Client sich mittels des aktuellen Clienteinmalpasswortes und des aktuellen Servereinmalpasswortes autorisieren kann.An advantageous embodiment of the invention is specified in claim 3. The development according to claim 3 enables the server to secure access to the network resource with an additional server-side password by generating a new random one-time password for each process run to ensure password security and transmitting it to the client. The authorization of access and the activation of the new client one-time password and the new server one-time password is only possible if the client can authorize itself using the current client one-time password and the current server one-time password.
Zwei vorteilhafte Ausgestaltungen der Erfindung sind in den Patentansprüchen 4 und 5 angegeben. Die Weiterbildung nach Patentanspruch 4 oder 5 sichert das Verfahren zusätzlich gegen Missbrauch einzelner Verfahrensläufe ab, da die Kenntnis geheimer Informationen vergangener Verfahrensabläufe vorausgesetzt wird. Two advantageous embodiments of the invention are specified in claims 4 and 5. The further development according to patent claim 4 or 5 additionally safeguards the process against misuse of individual process sequences, since knowledge of secret information from past process processes is a prerequisite.
Eine vorteilhafte Ausgestaltung der Erfindung ist im Patentanspruch 6 angegeben. Die Weiterbildung nach Patentanspruch 6 ermöglicht es, das Verfahren durch Parameter abzusichern, die systemseitig am Client ausgelesen werden. So kann das Verfahren an die am Client eingesetzte Hard- oder Software gebunden werden.An advantageous embodiment of the invention is specified in claim 6. The further development according to patent claim 6 makes it possible to secure the method using parameters that are read out by the system on the client. In this way, the process can be linked to the hardware or software used on the client.
Eine vorteilhafte Ausgestaltung der Erfindung ist im Patentanspruch 7 angegeben. Die Weiterbildung nach Patentanspruch 7 ermöglicht es, das Verfahren durch Parameter abzusichern, die systemseitig am Server ausgelesen und nicht vom Client als Datenwert angeliefert werden. So kann das Verfahren an die am Server eingesetzte Hard- oder Software oder die Netzwerkkommunikation gebunden werden.An advantageous embodiment of the invention is specified in claim 7. The further development according to patent claim 7 makes it possible to secure the method using parameters that are read out by the system on the server and are not supplied as data values by the client. In this way, the process can be linked to the hardware or software used on the server or to the network communication.
Eine vorteilhafte Ausgestaltung der Erfindung ist im Patentanspruch 8 angegeben. Die Weiterbildung nach Patentanspruch 8 ermöglicht es, das Verfahren gegen Asynchronitäten zwischen den Einmalpasswörtern des Clients und den Kontrollwerten des Servers abzusichern.An advantageous embodiment of the invention is specified in claim 8. The development according to claim 8 makes it possible to secure the method against asynchrony between the one-time passwords of the client and the control values of the server.
FigurenlisteFigure list
Die Merkmale, die der Erfindung Neuheit verleihen, werden in den beiliegenden Ansprüchen näher erläutert. Die Erfindung selbst wird jedoch am besten anhand der nachstehenden detaillierten Beschreibung verständlich, die unter Bezugnahme auf die Zeichnungen eine exemplarische Ausführungsform der Erfindung beschreibt:
- (
1 ) ist eine schematische Darstellung der Initialisierung des Verfahrens nach den Patentansprüchen 4 und 5, - (
2 ) ist eine schematische Darstellung eines Verfahrenslaufs des Verfahrens nach den Patentansprüchen 4 und 5.
- (
1 ) is a schematic representation of the initialization of the method according to claims 4 and 5, - (
2 ) is a schematic representation of a process run of the method according to claims 4 and 5.
Beschreibung der FormelnDescription of the formulas
- A ?= BA? = B
- Bedeutet, dass geprüft wird, ob A gleich B ist.Means that it is checked whether A equals B.
- H (A, B, C)H (A, B, C)
- Bedeutet, dass die Funktion H mit den Funktionsparametern A, B und C angewendet wird.Means that the function H is used with the function parameters A, B and C.
XOR-Verknüpfung als symmetrische VerschlüsselungXOR link as symmetrical encryption
Der Begriff „XOR-Verknüpfung“ meint eine bitweise Verknüpfung der entsprechenden Werte mittels der binären XOR-Logik. Die XOR-Verknüpfungen stehen in diesem beschriebenen Ausführungsbeispiel für die einfachste Form einer symmetrischen Verschlüsselung. Andere Ausführungsformen können statt der XOR-Verkmüpfung jede andere symmetrische Verschlüsselung verwenden.
Detaillierte Beschreibung der eines bevorzugten AusführungsbeispielsDetailed description of a preferred embodiment
Ein Ausführungsbeispiel der Erfindung ist in den Zeichnungen dargestellt und wird im Folgenden näher beschrieben. Die beigefügten Zeichnungen, der technische Inhalt und die detaillierte Beschreibung beziehen sich auf eine bevorzugte Ausführungsform der Erfindung, was jedoch nicht als Beschränkung des Erfindungsgegenstandes aufzufassen ist. Alle gleichwertigen Variationen und Änderungen, die entsprechend den beigefügten Ansprüchen der vorliegenden Erfindung vorgenommen werden, sich durch diese Ansprüche abgedeckt.An embodiment of the invention is shown in the drawings and is described in more detail below. The attached drawings, the technical content and the detailed description relate to a preferred embodiment of the invention, which, however, is not to be interpreted as a restriction of the subject matter of the invention. All equivalent variations and changes made according to the appended claims of the present invention are intended to be covered by these claims.
Im Folgenden wird die Erfindung anhand der Zeichnungen detailliert beschrieben.The invention is described in detail below with reference to the drawings.
Ein Server bietet einem Client den Zugriff auf eine Netzwerkresource an. Der Zugriff auf diese Resource soll durch ein Autorisierungsverfahren gemäß dieser Erfindung beschränkt werden. Dieses Autorisierungsverfahren kann dabei alleinstehend eingesetzt, oder mit einem oder mehreren Verfahren kombiniert werden. So ist auch eine Mehrfaktorautorisierung realisierbar.A server offers a client access to a network resource. Access to this resource is to be restricted by an authorization method according to this invention. This Authorization procedures can be used on their own or combined with one or more procedures. In this way, multi-factor authorization can also be implemented.
Zur Einrichtung des Zugriffs (
Zunächst werden am Client alle notwendigen Werte initialisiert (101). Als Erstes muss die Bildung der Kontrollwerte der Einmalpasswörter initialisiert werden. Der Client bestimmt die kryptologische Hashfunktion H, einen zufälligen Salt Sp und eine zufällige Iterationsanzahl Ip. Es können Mindestanforderungen an die Länge oder den Wertebereich der Parameter gestellt werden. Auch ist es möglich, die Hashfunktion H und die Parameter Sp und Ip vorab am Server zu generieren und diese vorab an den Client zu übermitteln. Die Übermittlung muss dabei sicher und idealerweise außerhalb der Netzwerkkommunikation dieses Verfahrens erfolgen.First, all necessary values are initialized on the client (101). First of all, the creation of the control values for the one-time passwords must be initialized. The client determines the cryptological hash function H, a random salt Sp and a random number of iterations Ip. Minimum requirements can be placed on the length or the range of values of the parameters. It is also possible to generate the hash function H and the parameters Sp and Ip in advance on the server and to transmit them to the client in advance. The transmission must take place securely and ideally outside the network communication of this method.
Um ein zufälliges Einmalpasswort OTP aus dem Passwort P abzuleiten, werden ein zufälliger Salt Sotp und eine zufällige Iterationsanzahl Iotp generiert. Es können Mindestanforderungen an die Länge oder den Wertebereich der Parameter gestellt werden. Der Client kann das Einmalpasswort jederzeit aus dem Passwort ableiten, ohne das Einmalpasswort selbst speichern zu müssen. Hierzu berechnet er OTP = H (P,Sotp,Iotp).In order to derive a random one-time password OTP from the password P, a random salt sotp and a random number of iterations Iotp are generated. Minimum requirements can be placed on the length or the range of values of the parameters. The client can derive the one-time password from the password at any time without having to save the one-time password itself. To do this, he calculates OTP = H (P, Sotp, Iotp).
In diesem Ausführungsbeispiel soll nach Patentanspruch 5 eine Abhängigkeit zur Kenntnis aller fortlaufenden Änderungen des Kontrollwertes hergestellt werden. Hierzu wird im späteren Verlauf des Verfahrens jeweils aus der aktuellen Änderung DOTC des Kontrollwertes und dem aus den bisherigen Änderungen abgeleiteten Wert DPC die neue Delta-Password-Chain DPCn = H (DOTC, DPC, Ip ) als neuer Ableitungswert aller zu diesem Zeitpunkt bekannten Änderungen des Kontrollwertes gebildet. Sowohl die Änderung des Kontrollwertes, als auch die Autorisierung des Zugriffs wird durch eine XOR-Verknüpfung mit der Delta-Password-Chain abgesichert.In this embodiment, according to claim 5, a dependency on the knowledge of all continuous changes in the control value is to be established. For this purpose, in the later course of the procedure, the new delta password chain DPCn = H (DOTC, DPC, Ip) is used as the new derivative value of all changes known at this point in time from the current change DOTC of the control value and the value DPC derived from the previous changes of the control value. Both the change of the control value and the authorization of the access are secured by an XOR link with the delta password chain.
Da die Delta-Password-Chain erst nach der Berechnung des im jeweiligen Verfahrenslaufs neu gebildeten Kontrollwertes aus dessen Abweichung zum bestehenden Kontrollwert berechnet werden kann, muss zusätzlich zur Delta-Password-Chain DPC des aktuellen Laufes noch die Delta-Password-Chain DPCotp des letzten Verfahrenslaufs gespeichert werden. Diese war bei der Bildung des aktuellen Kontrollwertes gültig und wird für die Autorisierung des Zugriffs benötigt.Since the delta password chain can only be calculated from its deviation from the existing control value after the calculation of the new control value created in the respective process run, the delta password chain DPCotp of the last run must be added to the delta password chain DPC of the current run Procedure run. This was valid when the current control value was created and is required to authorize access.
Der Client leitet aus dem Passwort P und der Funktion H und den Parametern Sp und Ip zur Bildung des Kontrollwertes einen initialen Kontrollwert HP = H (P, Sp, Ip ) des ursprünglichen Passwortes ab. Dieser wird nicht an den Server übermittelt, sondern dient nur der Initialsierung der Delta-Password-Chain.The client derives an initial control value HP = H (P, Sp, Ip) of the original password from the password P and the function H and the parameters Sp and Ip to form the control value. This is not transmitted to the server, but only serves to initialize the delta password chain.
Im Ausführungsbeispiel wird DPCotp = H (HP , HP, Ip ) als Delta-Password-Chain des aktuellen Einmalpasswortes initialisiert.In the exemplary embodiment, DPCotp = H (HP, HP, Ip) is initialized as a delta password chain of the current one-time password.
Nun kann der Client den Kontrollwert OTC des ersten Einmalpasswortes OTP wie folgt berechnen: OTC = H (OTP xor DPCotp, Sp, Ip ) xor DPCotpThe client can now calculate the control value OTC of the first one-time password OTP as follows: OTC = H (OTP xor DPCotp, Sp, Ip) xor DPCotp
Die Delta-Password-Chain DPC = H (OTC xor HP, DPCotp, Ip ) wird für das nächste Einmalpasswort vorbereitet.The delta password chain DPC = H (OTC xor HP, DPCotp, Ip) is prepared for the next one-time password.
Damit das erste Einmalpasswort aktiviert werden kann, müssen zum Abschluß der Initialisierung die zugriffsrelevanten Variablen vom Client an den Server übermittelt werden (102) . Dies sind der Kontrollwert OTC, die beiden Delta-Password-Chains DPC und DPCotp und, wenn nicht selbst vom Server definiert, die Hashfunktion H und die Parameter zur Bildung des Kontrollwertes Sp und Ip. Die Übermittlung muss auf sicherem Weg idealerweise außerhalb der Netzwerkkommunikation dieses Verfahrens erfolgen. In diesem Ausführungsbeispiel werden diese Informationen schriftlich ausgetauscht und manuell am Server eingegeben.So that the first one-time password can be activated, the access-relevant variables must be transmitted from the client to the server at the end of the initialization (102). These are the control value OTC, the two delta password chains DPC and DPCotp and, if not defined by the server itself, the hash function H and the parameters for forming the control value Sp and Ip. The transmission must ideally take place in a secure way outside the network communication of this procedure. In this exemplary embodiment, this information is exchanged in writing and entered manually on the server.
In diesem Ausführungsbeispiel soll nach Patentanspruch 3 gezeigt werden, wie der Server zusätzlich mittels eines eigenen Einmalpasswortes den Zugriff auf die Netzwerkresource beschränken kann (103).In this exemplary embodiment, it is intended to show how the server can additionally restrict access to the network resource by means of its own one-time password (103).
Hierzu legt der Server ein Serverpasswort SP fest und initialsiert mittels der vom Client erhaltenen Hashfunktion H und den Hashparametern Sp und Ip einen initialen Kontrollwert HSP = H (SP, Sp, Ip ). Für das erste Server-Einmalpasswort generiert der Server ein zufälliges Ssotp und Isotp als zufälligen Salt und zufällige Iterationsanzahl. Daraus leitet der Server das erste Server-Einmalpasswort SOTP = H (SP, Ssotp, Isotp ) ab.To this end, the server defines a server password SP and initializes an initial control value HSP = H (SP, Sp, Ip) using the hash function H received from the client and the hash parameters Sp and Ip. For the First server one-time password, the server generates a random ssotp and isotp as a random salt and a random number of iterations. The server derives the first server one-time password SOTP = H (SP, Ssotp, Isotp) from this.
Dieses Server-Einmalpasswort soll nach Patentanspruch 4 von allen Änderungen abhängig sein, die zwischen Client und Server zur Aktualisierung des Server-Einmalpasswortes ausgetauscht werden. Dies ist im Fall des Server-Einmalpassworts die Information der Änderung des Passwortes, nicht die Änderung des Kontrollwertes. So werden die Delta-Password-Chains des Server-Einmalpassworts wie folgt initialisiert: SDPCotp = H (HSP , HSP, Ip ) und SDPC = H (SOTP xor HSP, SDPCotp, Ip).According to claim 4, this server one-time password is to be dependent on all changes that are exchanged between the client and server for updating the server one-time password. In the case of the server one-time password, this is the information about the change in the password, not the change in the control value. The delta password chains of the server one-time password are initialized as follows: SDPCotp = H (HSP, HSP, Ip) and SDPC = H (SOTP xor HSP, SDPCotp, Ip).
Der Server berechnet den Kontrollwert SOTC des ersten Server-Einmalpassworts SOTP: SOTC = H (SOTP xor SDPCotp, Sp, Ip) xor SDPCotp.The server calculates the control value SOTC of the first server one-time password SOTP: SOTC = H (SOTP xor SDPCotp, Sp, Ip) xor SDPCotp.
Der Server liefert dem Client als Antwort auf seine Verfahrensinitialisierung die Werte SOTP xor DPC, SDPC xor DPC und SDPCotp xor DPC (
In jedem Verfahrenslauf muss ein neues Client-Einmalpasswort eingerichtet werden, in diesem Ausführungsbeispiel wird nach Patentanspruch 3 auch ein neues Server-Einmalpasswort eingerichtet (
Zur Generierung eines neuen Client-Einmalpassworts (
Um den Kontrollwert am Server zu aktualisieren, wird in diesem Ausführungsbeispiel aus Sicherheitsgründen nicht der gesamte Kontrollwert übermittelt, sondern nur die durch den neuen Kontrollwert bewirkte Änderung des bestehenden Kontrollwertes (
Die Delta-Password-Chain des nächsten Zugriffs wird nach Patentanspruch 5 als Kette der Änderungen des Kontrollwertes wie folgt vorbereitet: DPCn = H (DOTC, DPC, Ip)The delta password chain of the next access is prepared according to claim 5 as a chain of changes to the control value as follows: DPCn = H (DOTC, DPC, Ip)
Um die Übermittlung der Änderung des Kontrollwertes an den Server abzusichern, wird diese mit der Delta-Password-Chain DPC verschlüsselt. XDOTC = DOTC xor DPC.In order to secure the transmission of the change of the control value to the server, it is encrypted with the delta password chain DPC. XDOTC = DOTC xor DPC.
Um den Kontrollwert zu aktualisieren (203), extrahiert der Server die Änderung des Kontrollwertes durch Entschlüsselung des XDOTC mittels des eigenen DPC: DOTC = XDOTC xor DPC, bildet dann seinerseits den neuen Kontrollwert OTCn = OTC xor DOTC und berechnet die neue Delta-Password-Chain DPCn = H (DOTC, DPC , Ip).In order to update the control value (203), the server extracts the change in the control value by decoding the XDOTC using its own DPC: DOTC = XDOTC xor DPC, then in turn forms the new control value OTCn = OTC xor DOTC and calculates the new delta password Chain DPCn = H (DOTC, DPC, Ip).
Dann initialisiert der Server nach Patentanspruch 3 sein nächstes Server-Einmalpasswort (
Um das Server-Einmalpasswort am Client zu ändern (
Der Server liefert dem Client die Abweichung DSOTP des Server-Einmalpasswortes verschlüsselt mit der aktuellen Delta-Password-Chain SDPC des Server-Einmalpassworts (XSOTP = DSOTP xor SDPC) und den Beweis der korrekten Berechnung der neuen Delta-Password-Chain DPCn des Client-Einmalpasswortes als Bestätigung für die ordnungsgemäße Aktualisierung des Client-Kontrollwertes (
Der Client überprüft, ob seine Delta-Password-Chains die gleiche Abweichung aufweisen. DDPC ?= DPCn xor DPC (
Scheitert diese Prüfung, bricht der Client den aktuellen Verfahrenslauf ab, ohne das neue Einmalpasswort zu aktivieren.If this check fails, the client cancels the current process run without activating the new one-time password.
Ansonsten aktualisiert der Client sein Server-Einmalpasswort (
Dann startet der Client seine eigentliche Autorisierungsanfrage (
Das für die Anfrage verwendete Client-Einmalpasswort OTPauth ist durch OTP abhängig vom urspünglichen Passwort, der zum Zeitpunkt der Einrichtung des Kontrollwertes gültigen Delta-Password-Chain DPCotp und dem zuvor zwischen Client und Server vereinbartem neuen Kontrollwert OTCn.The OTPauth client one-time password used for the request is dependent on the original password, the delta password chain DPCotp valid at the time the control value was set up and the new control value OTCn previously agreed between client and server.
Das für die Anfrage verwendete Server-Einmalpasswort SOTPauth ist durch SOTP abhängig vom urspünglichen Serverpasswort, der zum Zeitpunkt der Einrichtung des Server-Einmalpasswortes gültigen Delta-Password-Chain SDPCotp des Serverpasswortes und dem zuvor zwischen Client und Server vereinbartem neuen Server-Einmalpasswort SOTPn.The server one-time password SOTPauth used for the request is dependent on the original server password, the delta password chain SDPCotp of the server password that was valid at the time the server one-time password was set up and the new server one-time password SOTPn previously agreed between the client and server.
Der Server prüft das Client-Einmalpasswort anhand des Client-Kontrollwertes, der Delta-Password-Chain des letzten Laufes und des vereinbarten neuen Kontrollwertes (
Scheitert diese Prüfung, bricht der Server den aktuellen Verfahrenslauf ab, ohne den Zugriff zu autorisieren und ohne das neue Einmalpasswort zu aktivieren.If this check fails, the server aborts the current process run without authorizing access and without activating the new one-time password.
Zusätzlich prüft der Server das Server-Einmalpasswort anhand des Server-Kontrollwertes, der Delta-Password-Chain des Serverpasswortes des letzten Laufes und des vereinbarten neuen Server-Einmalpasswortes (
Scheitert diese Prüfung, bricht der Server den aktuellen Verfahrenslauf ab, ohne den Zugriff zu autorisieren und ohne das neue Einmalpasswort zu aktivieren.If this check fails, the server aborts the current process run without authorizing access and without activating the new one-time password.
Ansonsten aktualisiert der Server seine Parameter für den nächsten Lauf (
- OTC = OTCn
- DPCotp = DPC
- DPC = DPCn
- OTC = OTCn
- DPCotp = DPC
- DPC = DPCn
Und nach Patentanspruch 4 auch die Paramter des Server-Einmalpasswortes für den nächsten Lauf:
- SOTC = SOTCn
- SDPCotp = SDPC
- SDPC = SDPCn
- Ssotp = Ssn
- Isotp = Isn
- SOTC = SOTCn
- SDPCotp = SDPC
- SDPC = SDPCn
- Ssotp = Ssn
- Isotp = Isn
Der Server autorisiert den Zugriff des Clients (
Daraufhin aktualisiert der Client seine Parameter des Client-Einmalpasswortes für den nächsten Lauf (
- Sotp = Sn
- Iotp = In
- DPCotp = DPC
- DPC = DPCn
- Sotp = Sn
- Iotp = In
- DPCotp = DPC
- DPC = DPCn
Und nach Patentanspruch 4 auch die Paramter des Server-Einmalpasswortes für den nächsten Lauf (
- SOTP = SOTPn
- SDPCotp = SDPC
- SDPC = SDPCn
- SOTP = SOTPn
- SDPCotp = SDPC
- SDPC = SDPCn
ZITATE ENTHALTEN IN DER BESCHREIBUNG QUOTES INCLUDED IN THE DESCRIPTION
Diese Liste der vom Anmelder aufgeführten Dokumente wurde automatisiert erzeugt und ist ausschließlich zur besseren Information des Lesers aufgenommen. Die Liste ist nicht Bestandteil der deutschen Patent- bzw. Gebrauchsmusteranmeldung. Das DPMA übernimmt keinerlei Haftung für etwaige Fehler oder Auslassungen.This list of the documents listed by the applicant was generated automatically and is included solely for the better information of the reader. The list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions.
Zitierte PatentliteraturPatent literature cited
- US 2003/0204724 A1 [0007]US 2003/0204724 A1 [0007]
Claims (8)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102019001731.5A DE102019001731A1 (en) | 2019-03-12 | 2019-03-12 | Authorization procedure using one-time passwords |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102019001731.5A DE102019001731A1 (en) | 2019-03-12 | 2019-03-12 | Authorization procedure using one-time passwords |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| DE102019001731A1 true DE102019001731A1 (en) | 2020-09-17 |
Family
ID=72289389
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| DE102019001731.5A Ceased DE102019001731A1 (en) | 2019-03-12 | 2019-03-12 | Authorization procedure using one-time passwords |
Country Status (1)
| Country | Link |
|---|---|
| DE (1) | DE102019001731A1 (en) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5606663A (en) * | 1993-12-24 | 1997-02-25 | Nec Corporation | Password updating system to vary the password updating intervals according to access frequency |
| US6539479B1 (en) * | 1997-07-15 | 2003-03-25 | The Board Of Trustees Of The Leland Stanford Junior University | System and method for securely logging onto a remotely located computer |
| US20030204724A1 (en) * | 2002-04-30 | 2003-10-30 | Microsoft Corporation | Methods for remotely changing a communications password |
| US20070061572A1 (en) * | 2003-10-28 | 2007-03-15 | Hideki Imai | Authentication system and remotely-distributed storage system |
-
2019
- 2019-03-12 DE DE102019001731.5A patent/DE102019001731A1/en not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5606663A (en) * | 1993-12-24 | 1997-02-25 | Nec Corporation | Password updating system to vary the password updating intervals according to access frequency |
| US6539479B1 (en) * | 1997-07-15 | 2003-03-25 | The Board Of Trustees Of The Leland Stanford Junior University | System and method for securely logging onto a remotely located computer |
| US20030204724A1 (en) * | 2002-04-30 | 2003-10-30 | Microsoft Corporation | Methods for remotely changing a communications password |
| US20070061572A1 (en) * | 2003-10-28 | 2007-03-15 | Hideki Imai | Authentication system and remotely-distributed storage system |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE60036112T2 (en) | SERVER SUPPORTED RECOVERY OF A STRONG SECRET FROM A WEAK SECRET | |
| DE102014220808B4 (en) | Method and device for logging in medical devices | |
| DE102013203415B4 (en) | Create a derived key from a cryptographic key using a non-cloning function | |
| DE102010027586B4 (en) | Method for the cryptographic protection of an application | |
| DE112018003825T5 (en) | BLOCKCHAIN AUTHORIZATION CHECK BY HARD / SOFT TOKEN CHECK | |
| DE102017209961B4 (en) | Method and device for authenticating a user on a vehicle | |
| DE102017214359A1 (en) | A method for safely replacing a first manufacturer's certificate already placed in a device | |
| DE10151277A1 (en) | Method for authenticating a network access server with authentication server e.g. for communications network, requires sending access query message to network access server | |
| DE102012208834A1 (en) | Authentication of a product to an authenticator | |
| DE212015000047U1 (en) | Secure login without passwords | |
| DE102018002466A1 (en) | Method and device for establishing a secure data transmission connection | |
| DE102014214823A1 (en) | Determination of a delay | |
| DE102016205122A1 (en) | Method for exchanging messages between security-relevant devices | |
| DE102017220490A1 (en) | Method and device for enabling the authentication of products, in particular industrially manufactured devices, and computer program product | |
| WO2013007686A1 (en) | Method for generating and verifying an electronic pseudonymous signature | |
| EP3954082B1 (en) | Method for securely exchanging encrypted messages | |
| DE102014213454A1 (en) | Method and system for detecting a manipulation of data records | |
| DE102019216203A1 (en) | Proof-of-work based on block encryption | |
| EP3288215A1 (en) | Method and device for outputting authenticity certifications and a security module | |
| WO2017144649A1 (en) | Safeguarding of entry authorisations for fixed-location installations | |
| WO2008022917A1 (en) | Method for authentication | |
| DE102022000857B3 (en) | Procedure for the secure identification of a person by a verification authority | |
| DE102015208525A1 (en) | Generate a cryptographic key | |
| EP3358488A1 (en) | Method for detecting unauthorised copies of a digital security token | |
| EP3617976A1 (en) | Method for operating a distributed database system, distributed database system, and industrial automation |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| R086 | Non-binding declaration of licensing interest | ||
| R012 | Request for examination validly filed | ||
| R016 | Response to examination communication | ||
| R002 | Refusal decision in examination/registration proceedings | ||
| R003 | Refusal decision now final |