A SYSTEM FOR VERIFYING USER IDENTITY AND AUTHORIZATION AT THE POINT-OF SALE OR ACCESS

GUSTAVUS J. SIMMONS · Cryptologia · 1984

We take for granted that valuable assets and resources, or sensitive and/or high risk facilities, will be physically protected by locks, vaults, alarms, fences, guard forces, etc. Equally important, however, a potential user's identity and authority to use the resource must be verifiable if we are to prevent unauthorized use or access. Elaborate and legally accepted protocols to prevent unauthorized uses are central to all commercial and private transactions. Difficulties arise when the resources are remotely accessible, as in the cases of computer/data files, electronic fund transfers (EFTs), automated bank teller operations, and even in many manned point-of-sale systems. Until recently, no satisfactory counterparts to the established protocols for verifying individual identity and authority had been found. Almost all proposals and systems for achieving this function demand that an individual be able to exhibit a “secret” identifier: a personal identification number (PIN), password, etc. But because such an identifier is transferable, it is not uniquely associated with an individual. We here describe a way to solve this problem, i.e., how to unambiguously identify an individual and to verify his authority to use a resource, using the authentication channel in a novel application of two key cryptography. A personnel identification system using the principles described here—fielded by Sandia National Laboratories in 1980—was the first application of two key cryptography anywhere.

Read the paper · More papers on PaperTik