1460732127-2818f4d3-695c-47db-9394-c4d812f128c4

1. A cryptographic method, including:
generating, at a first entity, a first public key MB, the first public key MB being session specific;
receiving from a second entity, at the first entity, a second public key MA, the second public key MA being session specific;
generating, at the first entity, a first secret SB by hashing one or more parameters that are known to the first entity and the second entity, at least one of the parameters being a result of hashing one or more of the following: a first password PB, the first public key MB, and the second public key MA;
generating, at the first entity, a first session key KB, the first session key KB being different from the first secret SB, both the first session key KB and the first secret SB being computed from the second public key MA;
encrypting, at the first entity, a first random nonce NB with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting, at the first entity, the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random nonce;
transmitting the encrypted random nonce from the first entity to the second entity;
receiving a response to the encrypted random nonce; and
authenticating through determining whether the response includes a correct modification of the first random nonce NB.
2. The method of claim 1 wherein authenticating through
determining whether the response includes a correct modification includes:
checking whether a received modification of the first random nonce NB equals a modification of the first random nonce NB applied by the first entity.
3. The method of claim 1 wherein said authenticating includes:
checking whether a received modification of the first random nonce less a modification thereof as applied thereto by the first entity equals the first random nonce.
4. The method of claim 1 wherein generating the first session key KB includes:
generating a first random number RB, and
computing the first session key KB from the second public key MA raised to the exponential power of the first random number RB, modulo a parameter \u03b2B.
5. The method of claim 1 wherein said generating the first secret SB includes:
combining the second public key MA and the first public key MB with a first password PB to produce a first result, and
hashing the first result with a secure hash.
6. The method of claim 5 wherein the secure hash is a one-way hash function.
7. The method of claim 6 wherein the one-way hash function is one of the Secure Hash Algorithm, the Message Digest 5, Snefru, Nippon Telephone and Telegraph Hash, and the Gosudarstvennyl Standard.
8. The method of claim 1 wherein said generating the first secret SB includes:
combining a first password PB and at least one of the second public key MA and the first public key MB to generate a first combined result, and
combining the first combined result and at least one of the second public key MA, the first password PB, and the first public key MB to generate a second combined result.
9. The method of claim 1 wherein the first random nonce NB is encrypted using a symmetrical encryption algorithm.
10. The method of claim 9, wherein the symmetrical encryption algorithm is one of the Data Encryption Standard and the block cipher CAST.
11. The method of claim 1 wherein encrypting the first random nonce NB includes superencrypting the first random nonce NB.
12. The method of claim 11, wherein superencrypting the first random nonce NB includes:
encrypting the first random nonce NB with the first secret SB to produce the first encrypted result; and
encrypting the first encrypted result using the first session key KB.
13. The method of claim 12 wherein said authenticating includes:
decrypting the response using the first session key KB to generate a first decrypted result; and
decrypting the first decrypted result using the first secret SB.
14. The method of claim 1, wherein the response includes a combination of a second random nonce NA and a modification of the first random nonce;
and wherein the method further includes:
extracting the second random nonce NA from the response;
modifying the second random nonce NA to obtain a modified second random nonce;
encrypting the modified second random nonce using the first session key KB and the first secret SB to obtain an encrypted package; and
transmitting the encrypted package from the first entity.
15. The method of claim 14 wherein said encrypting the modified second random nonce includes:
generating a string of random bits IB;
encrypting a combination of the string of random bits IB and the modified second random nonce using the first secret SB to generate a first result; and
encrypting the first result using the first session key KB.
16. The method of claim 14 wherein the encrypted package is transmitted for authentication of the first entity in opening a two-way communication channel.
17. A computer readable storage medium containing executable computer program instructions which, when executed, cause a first computer system to perform a cryptographic method including:
generating, at the first computer system, a first public key MB, the first public key MB being session specific;
receiving from a second computer system, at the first computer system, a second public key MA, the second public key MA being session specific;
generating, at the first computer system, a first secret SB by hashing one or more parameters that are known to the first computer system and the second computer system, at least one of the parameters being a result of hashing one or more of the following: a first password PB, the first public key MB, and the second public key MA;
generating, at the first computer system, a first session key KB, the first session key KB being different from the first secret SB, both the first session key KB and the first secret SB being computed from the second public key MA;
encrypting, at the first computer system, a first random nonce NB with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting, at the first computer system, the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random nonce;
transmitting the encrypted random nonce from the first computer system to the second computer system; and
authenticating through determining whether a response to the encrypted random nonce includes a correct modification of the first random nonce NB.
18. A distributed readable storage medium containing executable computer program instructions which, when executed, cause a first computer system and a second computer system to perform a computer cryptographic method through a network, the method comprising:
generating at the first computer system a first public key MB, the first public key MB being session specific;
generating at the second computer system a second public key MA, the second public key MA being session specific;
receiving at the first computer system the second public key MA;
generating, at the first computer system, a first secret SB by hashing one or more parameters that are known to the first computer system and the second computer system, at least one of the parameters being a result of hashing one or more of the following: a first password PB, the first public key MB, and the second public key MA;
generating at the first computer system a session key KB, the session key KB being different from the first secret SB, both the session key KB and the first secret SB being computed from the second public key MA;
generating at the first computer system a first random nonce NB;
encrypting at the first computer system the first random nonce NB with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting at the first computer system the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random nonce;
transmitting the encrypted random nonce and the first public key MB from the first computer system to the second computer system to establish the session key at the second computer system;
receiving at the first computer system from the second computer system a response to the encrypted random nonce; and
authenticating the second computer system at the first computer system through determining whether the response includes a correct modification of the first random nonce NB.
19. A computer system for performing a cryptographic method through a network, the computer system comprising:
a processor;
a network interface coupled to the network and coupled to the processor, the network interface to receive a request including information on a user identification; and
a storage device coupled to the processor, the storage device to store a user password corresponding to the user identification, and wherein the processor is to perform a method, including:
receiving a second public key MA through the network interface from a second computer system, the second public key MA being session specific;
generating, at the first computer system, a first secret SB by hashing one or more parameters that are known to the first computer system and the second computer system, at least one of the parameters being a result of hashing one or more of the following: a first password PB, the first public key MB, and the second public key MA;
generating a first session key KB, the session key KB being different from the first secret SB, both the session key KB and the first secret SB being computed from the second public key MA;
generating a first public key MB, the first public key MB being session specific;
generating a first random nonce NB, the first random nonce NBB;
encrypting the first random nonce NB with the session key KB or the first secret SB to obtain a first encrypted result;
encrypting the first encrypted result with the other one of the session key KB or the first secret SB to obtain an encrypted random nonce;
transmitting the encrypted random nonce and the first public key MB through the network interface;
authenticating through determining whether a response to the encrypted random nonce includes a correct modification of the first random nonce.
20. The computer system of claim 19 wherein the network is a network operating according to a hypertext transfer protocol; and the first public key MB is transmitted with the encrypted random nonce for session key exchange.
21. A cryptographic method, comprising:
receiving at a first entity a second public key MA and an encrypted second random number from a second entity;
generating a first secret SB by hashing one or more parameters that are known to the first entity and the second entity, at least one of the parameters being a result of hashing one or more of the following: a first password PB, a first public key MB, and the second public key MA;
generating a first session key KB, the session key KB being different from the first secret SB, both the session key KB and the first secret SB being computed from the second public key MA;
decrypting, using the first secret SB and the first session key KB, to retrieve a second random number NA from the encrypted second random number;
modifying the second random number NA to obtain a modified second random number;
encrypting the modified second random number with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random package; and
transmitting the encrypted random package from the first entity.
22. The method of claim 21, wherein said decrypting includes:
decrypting the encrypted second random number using the first session key KB to generate the first decrypted result; and
decrypting the first decrypted result using at least a first password PB and the second public key MA.
23. The method of claim 21 wherein said generating the first session key KB includes:
generating a first random number RB, and
computing the first session key KB from the second public key MA raised to the exponential power of the first random number RB, modulo a parameter \u03b2B.
24. The method of claim 21 wherein said generating the first secret SB includes:
combining the first public key MB with the first password PB to produce a first result, and hashing the first result with a secure hash.
25. The method of claim 24 wherein the secure hash is a one-way hash function.
26. The method of claim 25 wherein the one-way hash function is one of the Secure Hash Algorithm, the Message Digest 5, Snefru, Nippon Telephone and Telegraph Hash, and the Gosudarstvennyl Standard.
27. The method of claim 21 wherein said generating the first secret SB includes:
combining the first password PB and the first public key MB to generate a first combined result, and
combining the first combined result and at least one of the second public key MA, the first password PB, and the first public key MB to generate the first secret SB.
28. The method of claim 21, wherein said encrypting the modified second random number includes superencrypting the modified second random number.
29. The method of claim 21, further including:
generating a first random number NB; and
wherein said encrypting the modified second random number includes:
encrypting a combination of the first random number NB and the modified second random number.
30. The method of claim 29 which further includes:
receiving at the first entity a response to the encrypted random package;
decrypting the response to obtain a combination of a string of random bits and a modified first random nonce; and
retrieving the modified first random nonce from the combination of the string of random bits and the modified first random nonce;
determining whether the modified first random nonce was correctly modified from the first random number NB.
31. The method of claim 30 wherein said determining whether the modified first random nonce was correctly modified includes:
checking whether the modified first random nonce equals a modification of the first random nonce as applied to the first random nonce by the first entity.
32. The method of claim 30 wherein said determining whether the modified first random nonce was correctly modified includes:
checking whether the modified first random nonce less a modification thereof as applied thereto by the first entity equals the first random nonce.
33. A computer readable storage medium containing executable computer program instructions which, when executed, cause a first computer system to perform a cryptographic method including:
receiving at the first computer system a second public key MA and an encrypted second random number from a second computer system;
generating a first secret SB by hashing one or more parameters that are known to the first computer system and the second computer system, at least one of the parameters being a result of hashing one or more of the following: a first password PB, a first public key MB, and the second public key MA;
generating a first session key KB, the session key KB being different from the first secret SB, both the session key KB and the first secret SB being computed from the second public key MA;
decrypting, using the first secret SB and the first session key KB, to retrieve the second random number NA from the encrypted second random number;
modifying the second random number NA to obtain a modified second random number;
encrypting the modified second random number with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random package;
transmitting the encrypted random package from the first computer system for authentication.
34. A distributed readable storage medium containing executable computer program instructions which, when executed, cause a first computer system and a second computer system to perform a cryptographic method through a network, the method including:
receiving, from the second computer system and at the first computer system, a second public key MA and an encrypted second random number;
generating a first secret SB by hashing one or more parameters that are known to the first computer system and the second computer system, at least one of the parameters being a result of hashing one or more of the following: a first password PB, a first public key MB, and the second public key MA;
generating a first session key KB, the session key KB being different from the first secret SB, both the session key KB and the first secret SB being computed from the second public key MA;
decrypting, using the first secret SB, to retrieve a second random number NA from the encrypted second random number;
modifying the second random number NA to obtain a modified second random number;
encrypting the modified second random number with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random package;
transmitting the encrypted random package from the first computer system to the second computer system.
35. A computer system for performing a cryptographic method through a network, the computer system comprising:
a processor;
a network interface coupled to the network and coupled to the processor, the network interface to receive a request including information on a user identification; and
a storage device coupled to the processor, the storage device to store a user password associated with the user identification, and wherein the processor is to perform a method, including
generating a first public key MB;
receiving a second public key MA and an encrypted second random number through the network interface from a second computer system;
generating a first secret SB by hashing one or more parameters that are known to the first computer system and the second computer system, at least one of the parameters being a result of hashing one or more of the following: a first password PB, a first public key MB, and the second public key MA;
generating a first session key KB, the session key KB being different from the first secret SB, both the session key KB and the first secret SB being computed from the second public key MA;
decrypting, using the first secret SB and the first session key KB, to retrieve the second random number NA from the encrypted second random number;
modifying the second random number NA to obtain a modified second random number;
encrypting the modified second random number with the first session key KB or the first secret SB to obtain a first encrypted result;
encrypting the first encrypted result with the other one of the first session key KB or the first secret SB to obtain an encrypted random package;
transmitting the encrypted random package through the network interface.
36. The computer system of claim 35 wherein the network is a network operating according to a hypertext transfer protocol; and the first public key MB is transmitted for session key exchange before the encrypted second random number is received.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. An information handing system having apparatus for setting adequate drive strength based upon direct current (DC) trace resistance, said system comprising:
a printed circuit board, the printed circuit board having at least one layer of conductive signal traces;
a resistance detection trace, wherein the resistance detection trace is configured to have characteristics substantially the same as a worst case signal trace of the at least one layer of conductive signal traces;
a test voltage coupled to a first end of the resistance detection trace;
a trace termination resistor coupled to a second end of the resistance detection trace;
a voltage comparator having a first input coupled to the second end of the resistance detection trace and the trace termination resistor;
a drive strength reference voltage coupled to a second input of the voltage comparator, wherein
if a voltage at the second end of the resistance detection trace is greater than the drive strength reference voltage at the second input then the voltage comparator has an output at a first logic level, and
if a voltage at the second end of the resistance detection trace is less than or equal to the drive strength reference voltage at the second input then the voltage comparator has an output at a second logic level.
2. The information handing system according to claim 1, wherein the characteristics of the resistance detection trace are length and cross-sectional area.
3. The information handing system according to claim 1, wherein the drive strength reference voltage is substantially equal to a minimum specified receiver input voltage level.
4. The information handing system according to claim 1, wherein the test voltage is from an output of a data driver.
5. The information handing system according to claim 4, wherein the output of the data driver is ANDed with the output of the voltage comparator.
6. The information handing system according to claim 1, wherein the trace termination resistor is approximately 62.5 ohms for approximately a 50 ohm characteristic bus trace impedance.
7. The information handing system according to claim 1, wherein the trace termination resistor is approximately 75 ohms for approximately a 60 ohm characteristic bus trace impedance.
8. The information handing system according to claim 1, wherein the drive strength reference voltage is derived from a reference voltage source.
9. The information handing system according to claim 8, wherein the reference voltage source is a band-gap reference voltage source.
10. The information handing system according to claim 1, wherein the output of the voltage comparator causes data driver drive strength to increase on the at least one layer of the conductive signal traces when the voltage comparator output is at the second logic level.
11. The information handing system according to claim 1, wherein the first logic level is a logic one and the second logic level is a logic zero.
12. The information handing system according to claim 1, wherein the first logic level is a logic zero and the second logic level is a logic one.
13. An information handing system having apparatus for setting adequate drive strength based upon direct current (DC) trace resistance, said system comprising:
a printed circuit board, the printed circuit board having a plurality of conductive signal trace layers;
a plurality of resistance detection traces, each of the plurality of resistance detection traces has a corresponding layer of the plurality of conductive signal trace layers, wherein each of the plurality of resistance detection traces is configured to have characteristics substantially the same as a worst case signal trace of the corresponding one of the plurality of conductive signal trace layers;
a test voltage coupled to a first end of each of the plurality of resistance detection traces;
a plurality of trace termination resistors having corresponding ones coupled to a second end of each of the plurality of resistance detection traces;
a plurality of voltage comparators, each having a first input coupled to the second end of the corresponding one of the plurality of resistance detection traces and the corresponding one of the plurality of trace termination resistors;
a drive strength reference voltage coupled to a second input of the plurality of voltage comparator, wherein,
if a voltage at the second end of a one of the plurality of resistance detection traces is greater than the drive strength reference voltage at the second input then the corresponding one of the plurality of voltage comparators has an output at a first logic level, and
if a voltage at the second end of the one of the plurality of resistance detection traces is less than or equal to the drive strength reference voltage at the second input then the corresponding one of the plurality of voltage comparators has an output at a second logic level.
14. The information handing system according to claim 13, wherein the characteristics of the resistance detection trace are length and cross-sectional area.
15. The information handing system according to claim 13, wherein the drive strength reference voltage is substantially equal to a minimum specified receiver input voltage level.
16. The information handing system according to claim 13, wherein the test voltage is from an output of a data driver.
17. The information handing system according to claim 13, wherein the trace termination resistor is approximately 62.5 ohms for approximately a 50 ohm characteristic bus trace impedance.
18. The information handing system according to claim 13, wherein the trace termination resistor is approximately 75 ohms for approximately a 60 ohm characteristic bus trace impedance.
19. The information handing system according to claim 13, wherein the drive strength reference voltage is derived from a reference voltage source.
20. The information handing system according to claim 19, wherein the reference voltage source is a band-gap reference voltage source.
21. The information handing system according to claim 13, wherein when the output of a one of the plurality of voltage comparators is at the second logic level a corresponding data driver drive strength is increased.
22. A method for setting adequate drive strength based upon direct current (DC) trace resistance, said method comprising the steps of:
a) driving a resistance detection trace on a printed circuit board with a test voltage coupled to a first end of the resistance detection trace, wherein the resistance detection trace is configured to have characteristics substantially the same as a worst case signal trace on the printed circuit board; and
b) comparing a voltage at a second end of the resistance detection trace with a drive strength reference voltage, wherein if the voltage at the second end of the resistance detection trace is less than or equal to the drive strength reference voltage then increase a data driver drive strength.
23. The method according to claim 22, wherein the step of driving the resistance detection trace is done with a data driver.
24. The method according to claim 22, wherein the step of comparing is done with a voltage comparator.
25. The method according to claim 22, wherein the second end of the resistance detection trace is terminated with a resistor selected for a characteristic impedance of the resistance detection trace.
26. The method according to claim 22, wherein the drive strength reference voltage is substantially equal to a minimum specified receiver input voltage level.
27. The method according to claim 22, wherein steps a) and b) are repeated for each layer of the printed circuit board having conductive signal traces.