CA2172860C

Method of token verification in a key management system

Abstract

A method of token verification in a Key ManagementSystem provides a logical device identifier and a masterkey created in a logical security domain to a transactionevidencing device, such as a digital postage meter. Themethod creates a master key record in a key verificationbox, securely stores the master key record in a KeyManagement System archive, and produces in thetransaction evidencing device evidence in the logicalsecurity domain of transaction information integrity.The method inputs the evidence of the transactioninformation integrity to a token verification box, andinputs in the token verification box the master keyrecord from the Key Management System archive. Themethod determines in the token verification box that themaster key is valid in logical security domain, uses inthe token verification box the master key to verify theevidence of transaction information integrity, andoutputs from the token verification box an indication ofthe result of the verification of the evidence oftransaction information integrity. The master key recordincludes the logical device identifier, the master keyand a digital signature associating the logical deviceidentifier and the master key. The method checks thedigital signature to verify the association of thelogical device identifier and the master key within thelogical security domain.

CA2172860C, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Expired 28 March 2016, 10.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

14 claims: 3 independent, 11 dependent

  1. 1
    What is Claimed is:1. A method of token verification in a KeyManagement System, comprising the steps of: providing to a transaction evidencing device a master key created in a logical security domain and a logical device identifier;creating a master key record in a key verification box;transaction transaction storing the master key record in a Key Management System archive;performing a predetermined operation on information relating to each transaction in the evidencing device to produce evidence of information integrity in the logical security domain;inputting the evidence of the transaction information integrity to a token verification box;inputting in the token verification box the master key record from the Key Management System archive;determining in the token verification box that the master key is valid in the logical security domain;using in the token verification box the master key to verify the evidence of transaction information integrity;and outputting from the indication of the result token verification box an of the verification of the evidence of transaction information integrity.
  2. 5
    A method of token verification in a Key Management System, comprising the steps of:providing to a transaction evidencing device a master key created in a logical security domain and a logical device identifier;creating a master key record in a key verification box;storing the master key record in a Key Management System archive;creating a temporal token key record using the master key in a token key distribution box;storing the token key record in a Key Management System archive;producing in the transaction evidencing device the token key;producing in the transaction evidencing device a token in the logical security domain using the token key;inputting the token to a distributed token verification box;inputting in the distributed token verification box the token key record from the Key Management System archive;determining in the distributed token verification box that the token key is valid in the logical security domain;using in the distributed token verification box the token key to verify the token;and outputting from the distributed token verification box an indication of the result of the verification of the token. „ : 2172860
  3. 10
    A method of token verification in a Key Management System, comprising the steps of:providing to a transaction evidencing device a master key created in a logical security domain and a logical device 20 identifier;creating a master key record in a key verification process ;storing the master key record in a Key Management System archive ;25 performing a predetermined operation on information relating to each transaction in the transaction evidencing device to produce evidence of transaction information integrity in the logical security domain;inputting the evidence of the transaction information 30 integrity to a token verification process;inputting to the token verification process the master key record from the Key Management System archive;determining in the token verification process that the master key is valid in the logical security domain;38a using in the token verification process the master key to verify the evidence of transaction information integrity;and outputting from the token verification process an 5 indication of the result of the verification of the evidence of transaction information integrity.