AU5552196A

Multi-step digital signature method and system

Abstract

A multi-step signing system and method uses multiple signing devices (11, 13, 15, 17, 19) to affix a single signature which can be verified using a single public verification key. Each signing device possesses a share of the signature key and affixes a partial signature in response to authorization from a plurality of authorizing agents (23, 25, 27, 29, 31). In a serial embodiment, after a first partial signature has been affixed, a second signing device exponentiates the first partial signature. In a parallel embodiment, each signing device affixes a partial signature, and the plurality of partial signatures are multiplied together to form the final signature. Security of the system is enhanced by distributing capability to affix signatures among a plurality of signing devices and by distributing authority to affix a partial signature among a plurality of authorizing agents.

AU5552196A, drawing sheet 1
Sheet 1 of 39

Term

Term ended

Projected expiry passed 19 April 2016, 10.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

11 claims: 11 independent, 0 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A digital signing method comprising steps of: generating shares of a private signature key;storing shares in separate electronic signing devices;certifying multiple authorizing agents for signing devices;and for each of a plurality of signing devices, affixing a partial signature to an electronic message in response to authorization from a minimum number of authorizing agents;wherein a plurality of partial signatures constitutes a digital signature.
  2. 2
    A system for affixing digital signatures to electronic documents comprising:a plurality of intercommunicative signing devices, each signing device comprising an electronic device programmed to receive an electronic document and to affix a partial signature using a signature key share in response to a predetermined number of authorizations;and a plurality of authorizing agents, each agent communicative with an associated signing device, each anent comprising an electronic device programmed to provide an authorization to an associated signing device.
  3. 3
    A system of interlocked rings of signing devices for affixing digital signatures to electronic documents comprising:a first set of signing devices, said first set comprising a plurality of electronic devices, each device programmed to receive an electronic document and affix a partial signature for a first signature key, a plurality of said partial signatures comprising a first digital signature;WO 96/39765 PCT/US96/05317 a second set of signing devices, said second set comprising a plurality of electronic devices, each device programmed to receive an electronic document and affix a partial signature for a second signature key, a plurality of 5 said partial signatures comprising a second digital signature;wherein said first includes at least one member which is not in said second set, and said first and second sets include at least one common member.
  4. 4
    An electronic method for delegated use of an 10 electronic key comprising steps of:storing said key in a first electronic device;communicating an electronic delegation certificate to a delegate;sending a request and the delegation certificate 15 from the delegate to the first electronic device;and using said first electronic device to use the electronic key in response to the request and the delegation certificate. 1/19 Γ r ι FIGURE 1 WO 96/39765 PCT/US96/05317 WO 96/39765 PCT/US96/05317 DATA CENTER SIGNING DEVICE 39 AGENT TABLE SVR MESSAGE SERVER 4Z SYSTEM KE SVR I I I I LAN/WAN ;NETWORK f I I I ( I t FIGURE 2 2/19 3/19 FIGURE 4 PCT/US96/05317 4/19 I t I ί FIGURE 5 WO 96/39765 PCT/US96/05317 WO 96/39765 PCT/US96/05317 103 FIGURE 6
  5. 5
    5/19 FIGURE 7
  6. 6
    6/19 91 11 93 ;91 15 97 ! I O σι L WO 96/39765 PCT/US96/05317 AUTHORIZING — «ng AGENT 3a KSAA3a iKSM3a -SWA SIGNING DEVICE 3 KS SWA KSM3a -SWA AUTHORIZING AGENT 1a KSAA1a KSM1a -SWA SIGNING DEVICE 1 KSSWA KSSD1 -SWA HEADER CERT -AA3a HEADER CERT -AA3a = [HASH(CERT) ] 123 123 —SD3 = 125 —SD3 -SWA [hash(cert) SD3 ] = [hASH(CERT) J I- a ] -SWA = Q-SD3) S SWA FIGURE 8
  7. 7
    7/19 (START HERE) 137 DOC 139 132 --HEADER -AA1a AUTHORIZING AGENT 1b AUTHORIZING AGENT 1a KSAA1a KS^1a -SWA KSAA1b 131 HEADER DOC AUTHORIZING AGENT 2a KSAA2a KSAA2a -SWA 143
  8. 8
    8/19 SIGNING DEVICE 1 KS SWA KSAA1a -SWA ----------» , KSAA1b -SWA 141 FIGURE 9 AUTHORIZING AGENT2b 145 KSAA2b KSM2b -SWA — 147 149 WO 96/39765 PCT/US96/05317 £ HEADER DOC -AAla 137 -AAla = [hash(cert) ^18
  9. 9
    9/19 HEADER DOC -AA1a -AA1o 139 -AA1b = [HASH(CERTr-nAA1a)J^ M1b FIGURE 10 WO 96/39765 PCT/US96/05317 WO 96/39765 PCT/US96/05317 169a 169b 169c FIGURE 11
  10. 10
    10/19 WO 96/39765 PCT/US96/05317 161 ./ 181a 181b 181c FIGURE 12
  11. 11
    11/19 213 215 217 219 221 223 225 227 229 COMMAND:ADD AUTHORIZING AGENT AGENT NAME_______________ AGENT TITLE__________________ SIGNING DEVICE ID NO.__________ AUTHORIZATION EXPIRATION DATE ADMINISTRATIVE CLASS KEY ID CODES KEY1 « KEYn___________________ TRUSTED DEVICE ID CODE 231 203 20S 207 209 211 233 FIGURE 13 FIGURE 14 WO 96/39765 PCT/US96/05317 -SWA Ci 261 COMMAND: ADD MANUFACTURER MANUFACTURER NAME MODEL NUMBER Γ MFG CERTIFICATE 243 245 247 249 263 265 267 269 -SWA FIGURE 15 251 COMMAND: DELETE MANUFACTURER MANUFACTURER NAME ~ -SWA 253 255 273 275 277 COMMAND: ADD MODEL NUMBER MFG NAME_____________ MODEL NUMBER -SWA FIGURE 17 271 WO 96/39765 PCT/US96/05317 FIGURE 16 FIGURE 18 % 281 COMMAND: ADD SIGNING DEVICE DEVICE ID CODE DEVICE CERTICIFATE -MFG 14/19 DEVICE CERTICIFATE + KE DEV MFG KEY ID CODES KEY SHARES -SWA FIGURE 19 283 285 287 289 — i’91 — 292 FIGURE 20 WO 96/39765 PCT/US96/05317 301 303 315 305 307 309 313 RECEIVING DEVICE CERTIFICATE -CA 311 FIGURE 21a FIGURE 21b WO 96/39765 PCT/US96/05317 -SWA 16/19 325 327 329 FIGURE 22 WO 96/39765 PCT/US96/05317 WO 96/39765 PCT/US96/05317 co GENERATE 17/19 FIGURE 23 WO 96/39765 I n AUTH. AGENT 5a Τ~Ξ~ΞΞ?ι AUTH. 4_ AGENT 1a 391a 391a 391a PCT/US96/05317 385 391a 391b 373 391b 387 CAO SIGNING DEVICE 1 CAO SIGNING DEVICE 5 ΓγΞΞΞΞΞΞι AUTH. 4_ AGENT 4a AUTH. _ AGENT E1 SIGNING DEVICE D AUTH. _ AGENT D1 FIGURE 24 PARENT CERTIFYING AUTHORITY Γ..... 4 AUTH. 4_ AGENT 2a CAO SIGNING DEVICE 2 383 r------ h AUTH. 4 AGENT 3a SIGNING DEVICE B AUTH. 4. AGENT C1 391b 18/19 389 391a ---------------------------------1 ZL AUTH. H. AGENT A1 391b 377 391b AUTH. 4_ AGENT B1 ·) LAN/WAN WO 96/39765 PCT/US96/05317