Nova Patents
CA2228958C

Data card verification system

Abstract

A method of verifying a pair of correspondents in electronic transaction the correspondents each including a first and second signature schemes and wherein the first signature scheme is computationally more difficult in signing than verifying and the second signature scheme is computationally more difficult in verifying than signing. The method comprises the step of the first correspondent signing information according to the first signature scheme and transmitting the first signature to the second correspondent, the second correspondent verifying the first signature received from the first correspondent, wherein the verification is performed according to the first signature scheme. The second correspondent then signs information according to the second signature scheme and transmits the second signature to the first correspondent, the first correspondent verifies the second signature received from the second correspondent, wherein the verification is performed according to the second signature algorithm; the transaction is rejected if either verification fails. The method thereby allows one of the correspondents to participate with relatively little computing power while maintaining security of the transaction.

CA2228958C, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 3 February 2018, 8.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

38 claims: 9 independent, 29 dependent

  1. 1
    CA 02228958 2015-09-04 What is claimed is:1. A method of verifying authenticity of messages exchanged between a pair of correspondents in an electronic transaction conducted over a data transmission system, said correspondents each including respective signing and verifying portions of a first signature scheme and a second signature scheme different to said first scheme and utilizing an elliptic curve cryptosystem, said method comprising the steps of: one of said correspondents signing a message according to a signing portion of one of said schemes associated with said one correspondent to provide a first signed message and transmitting said first signed message to another of said correspondents;said other correspondent utilizing said verifying portion of said one signature scheme to verify said first signed message received from said one correspondent;said other correspondent signing another message by utilizing said signing portion of the other of said signature schemes to provide a second signed message and transmitting said second signed message to said one correspondent;and said one correspondent verifying said second signed message received from said other correspondent by utilizing said verification portion of said other of said signature schemes;wherein one of said signing steps and one of said verifying steps is performed according to said second signature scheme utilizing an elliptic curve cryptosystem;and rejecting said transaction if either verifying steps fails.
  2. 5
    A method of verifying authenticity of messages exchanged between a pair of correspondents in electronic transaction conducted over a data transmission system, said correspondents each including respective signing and verifying portions of a first signature scheme and a second signature scheme, different from said first scheme and utilizing an elliptic curve cryptosystem said method comprising the steps of:one of said correspondents transmitting to another of said correspondents, a first certificate including public key and identification information of said first correspondent;said other correspondent verifying said first certificate and extracting said public key said identification information therefrom;said other correspondent generating a first challenge R| and transmitting said challenge to said one correspondent;said one correspondent signing said received challenge R, in accordance with said signing portion of one of said signature schemes to provide a second certificate C2;said one correspondent generating a second challenge and transmitting said second challenge along with said second certificate C2 to said other correspondent;said other correspondent verifying said second certificate C2 in accordance with said verification portion of one of said signature schemes;said other correspondent signing a second challenge R2 in accordance with said signing portion of the other of said signature schemes to provide a third certificate and transmitting said third certificate to said one correspondent;and said one correspondent verifying said third certificate in accordance with said verification portion of said other of said signature schemes, and rejecting said transaction if either said signature is not verified. CA 02228958 2015-09-04
  3. 6
    A smart card for use in an electronic transaction with a correspondent, said card comprising:a memory including: a verification algorithm of a first signature scheme to implement a verification of signatures performed according to a first signature generation algorithm by said correspondent;a signing algorithm of second signature scheme different to said first signature scheme and utilizing elliptic curve cryptography, said signing algorithm implementing signatures according to a second signature generation algorithm;a program for invoking said algorithms;and processor means for running said first verification algorithm for verifying a first message signed by said correspondent and for running said second signature for signing a second message for transmission to said correspondent.
  4. 9
    A method of generating a certificate in a public key cryptosystem, said method comprising the steps of:a) obtaining from a correspondent public information including a public key capable of being used in an elliptic curve cryptosystem, said public information being related to a private key generated by said correspondent;b) signing said public information utilizing an RSA cryptosystem to obtain a signature on said information;and c) combining said signature and said public information to provide said certificate. CA 02228958 2015-09-04
  5. 12
    A method of generating a certificate in a public key cryptosystem, said method comprising:a) obtaining from a correspondent, a first set of data representing public information of said correspondent associated with a first signature scheme, said first signature scheme utilizing an elliptic curve cryptosystem, said public information being related to a private key generated by said correspondent;b) signing a second set of data according to a second signature scheme that is different than said first signature scheme to obtain a signature;and c) combining said first set of data and said signature to generate said certificate.
  6. 15
    The method according to any one of claims 12 to 14 wherein said certificate includes an ID of said correspondent and said step of signing said public information relates said ID to said public information including said public key.
  7. 16
    The method according to any one of claims 12 to 15, wherein said public information comprises a public key for use in said elliptic curve cryptosystem.
  8. 17
    The method according to any one of claims 12 to 16, wherein said second signature scheme is computationally more difficult in signing than verifying, while said first signature scheme CA 02228958 2015-09-04 is computationally more difficult in verifying than signing, thereby allowing said correspondent to participate with relatively little computing power while maintaining security of a transaction.
  9. 18
    The method according to any one of claims 12 to 17, wherein said second set of data is signed by a certificate authority.
  10. 19
    A computer readable medium comprising computer executable instructions for generating certificate including instructions for performing the method according to any one of claims 12 to 18.
  11. 20
    A method of generating a signature for a certificate of a correspondent, said certificate for use in electronic communications, said method comprising:obtaining a first set of data including identification data and public information, the public information related to a private key by cryptographic operations of a first cryptosystem;and signing a second set of data related to said first set of data utilizing a cryptographic processor implementing a second cryptosystem that is different to said first cryptosystem to obtain said signature.
  12. 23
    The method according to any one of claims 20 to 22, wherein said certificate comprises said identification data, a public key corresponding to said private key and said signature.
  13. 24
    The method according to any one of claims 20 to 23, wherein said public information comprises a public key related to said private key. CA 02228958 2015-09-04
  14. 25
    The method according to any one of claims 20 to 24, wherein said first cryptosystem is an elliptic curve cryptosystem.
  15. 26
    The method according to any one of claims 20 to 25, wherein said signing utilizing said second cryptosystem is computationally more difficult in signing than verifying, while a signing utilizing said first cryptosystem is computationally more difficult in verifying than signing.
  16. 27
    The method according to any one of claims 20 to 26, wherein said second set of data is signed by a certificate authority.
  17. 28
    The method according to any one of claims 20 to 27, wherein said correspondent is a device.
  18. 29
    A computer readable medium comprising computer executable instructions for causing a processor to carry out the steps of any one of claims 20 to 28.
  19. 30
    An apparatus including a cryptographic processor to perform cryptographic operations and configured to carry out the steps of any one of claims 20 to 28.
  20. 31
    A method performed at a first computing device in a communication system, said method comprising:receiving a first signed message from a second computing device in said communication system, said first signed message generated using a signing algorithm of a first signature scheme;utilizing a verifying algorithm of said first signature scheme to verify said first signed message;signing a message by utilizing a signing algorithm of a second signature scheme different to said first signature scheme, to generate a second signed message, said second signature scheme being an elliptic curve signature scheme;sending said second signed message to said second computing device for verification of said second signed message using a verifying algorithm of said second signature scheme, CA 02228958 2015-09-04 wherein said signing algorithm of said first signature scheme is computationally more difficult than said verifying algorithm of said first signature scheme, and wherein said verifying algorithm of said second signature scheme is computationally more difficult than said signing algorithm of said second signature scheme, thereby allowing said first computing device to participate with less computing power as compared to the second computing device and wherein said first computing device cooperates with the second computing device for mutual authentication and said mutual authentication being rejected if either verification fails, further wherein the first computing device utilizes respective parts of said first and second signature schemes for verification and signing, said respective parts being different from corresponding respective parts used by said second computing device for verification and signing.
  21. 34
    The method according to any one of claims 31 to 33, further comprising:providing a first challenge value, said first challenge value utilized in generation of said first signed message received from said second computing device.
  22. 35
    The method according to any one of claims 31 to 34, wherein said message utilized in generation of said second signed message comprises a second challenge value provided to said first computing device.
  23. 36
    The method according to any one of claims 31 to 35, wherein said first computing device proceeds with a transaction in response to successful verification of said first signed message and said second signed message. CA 02228958 2015-09-04
  24. 37
    A computer readable medium comprising computer executable instructions for causing a processor to carry out the method according to any one of claims 31 to 36.
  25. 38
    An apparatus including a cryptographic processor to perform cryptographic operations and configured to carry out the method according to any one of claims 31 to 36.
Independent claims25