×

ACCESS CONTROL SYSTEM AND A USER TERMINAL

  • US 20130254541A1
  • Filed: 08/28/2012
  • Published: 09/26/2013
  • Est. Priority Date: 03/22/2012
  • Status: Abandoned Application
First Claim
Patent Images

1. An access control system including a user terminal, a data storage unit and a service providing server mutually connected via a network,the user terminal comprising:

  • a key set generation unit configured to generate a key set including a public key, a master key, and a public parameter as a parameter opened, by using an ID-based signature scheme based on seed information;

    a key set storage to store the key set;

    an ID generation unit configured to generate an ID including an identifier of a service, an issue date and a validity period of a secret key corresponding to a service provided by the service providing server;

    a first ID storage to store the ID;

    a secret key generation unit configured to generate the secret key based on the master key and the ID; and

    a first transmit unit configured to transmit the ID and the secret key to the service providing server, and to transmit the public key, the public parameter and a revocated ID to the data storage device;

    the service providing server comprising;

    a signature data generation unit configured to generate signature data based on the ID and the secret key;

    a second ID storage to store the ID;

    a secret key storage to store the secret key;

    a data request generation unit configured to generate a data request command including a data request, the signature data and the ID; and

    a third transmit unit configured to transmit the data request command to the data storage device;

    the data storage device comprising;

    a first data storage to store measurement data measured from a measurement target device;

    a revocated ID list storage to store the revocated ID;

    a public key storage to store the public key and the public parameter;

    a revocated ID list storage controller configured to decide whether the ID is same as the revocated ID;

    a signature verification unit configured to verify the data request based on the signature data, the public key and the public parameter; and

    a second transmit unit configured to transmit the measurement data to the service providing server, when the ID is not same as the revocated ID and when authenticity of the data request is verified;

    wherein, in the user terminal,the ID generation unit generates a new ID including an identifier of a new service, an issue date and a validity period of a new secret key corresponding to the new service,the secret key generation unit generates the new secret key based on the master key and the new ID, andthe first transmit unit transmits the new ID and the new secret key to the service providing server,wherein, in the service providing server,the second ID storage stores the new ID, andthe secret key storage stores the new secret key.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×