CA2309435C

Protectedly reading out an enciphered, cryptographic key

Abstract

Method and apparatus for protectedly reading out an enciphered, cryptographic key (Ksec) stored in a first memory (2) of a first communication apparatus (8; 8'), comprising the following steps: a) making available a first predetermined number (PW; X) by the first communication apparatus (8; 8'); b) receiving the first predetermined number (PW; X) by the second communication apparatus; c) calculating a Message Authentication Code (MAC) by the second communication apparatus on a second predetermined number, using the first predetermined number (PW; X), and with the aid of a predetermined key (Kicc); d) making available the Message Authentication Code by the second communication apparatus (6; 13); e) deciphering the cryptographic key by the first communication apparatus (8; 8'), using the Message Authentication Code as a deciphering key.

CA2309435C, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Expired 5 November 2018, 7.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

16 claims: 5 independent, 11 dependent

  1. 1
    CA 02309435 2000-05-05 WO 99/24943 PCT/EP98/07211 CLAIMS 1. Method for protectedly reading out an enciphered, cryptographic key (Ksec) stored in a first memory (2) of a first communication apparatus (8; 8'), comprising the following steps:a. making available a first predetermined number (PW;X) by the first communication apparatus (8;8') to a second communication apparatus (6;13);b. receiving the first predetermined number (PW;X) by the second communication apparatus ;c. calculating a Message Authentication Code (MAC) by the second communication apparatus on a second predetermined number, using the first predetermined number (PW;X) and with the aid of a predetermined key (Kj.cc) ;d. making available the Message Authentication Code by the second communication apparatus (6;13) to the first communication apparatus (8;8');e. receiving the Message Authentication Code by the first communication apparatus (8;8');f. deciphering the cryptographic key by the first communication apparatus (8;8'), using the Message Authentication Code as a deciphering key.
  2. 9
    Communication apparatus (8; 8') provided with a memory (2) having stored therein at least an enciphered, cryptographic key (Ksec), a processor (1) connected to the memory, and means (5; 12) for making available information, the processor (1) being designed for carrying out the following steps:CA 02309435 2002-12-12 20181-197 lia a. making available a first predetermined number (PW;X);b. receiving a Message Authentication Code (MAC), which has been calculated by a second communication 5 apparatus on a second predetermined number, using the first predetermined number (PW;X), and with the aid of a predetermined key (Kicc) ;c. deciphering the cryptographic key, using the Message Authentication Code received as a deciphering key. CA 02309435 2000-05-05 WO 99/24943 PCT/EP98/07211
  3. 12
    Communication apparatus according to any of the claims 9, 10 or 11, characterised in that the communication apparatus (8) is further provided with a card reader (5) connected to the processor (1) for making available the first predetermined number (PW;X) and receiving a Message Authentication Code (MAC) from a chip card (6).
  4. 13
    Communication apparatus according to any of the claims 9, 10 or 11, characterised in that the communication apparatus (8*) is further provided with a monitor (12) connected to the processor (1) for making available the first predetermined number (PW;X) and an input device (3) for receiving a Message Authentication Code (MAC) from a chip card (6).
  5. 14
    Communication apparatus (6; 13) provided with a memory (11; 17), a processor (10; 15) connected to the memory, and means (9; 14) for receiving information, the processor (10; 15) being designed for carrying out the following steps :a. receiving a first predetermined number (PW;X);b. calculating a Message Authentication Code (MAC) on a second predetermined number, using the first predetermined number (PW;X), and with the aid of a predetermined key (Kicc);c. making available the Message Authentication Code.