CA2359673C

Self-generation of certificates using a secure microprocessor in a device for transferring digital information

Abstract

The present invention allows consumer communications device in the figure such as an IP telephony adapter (110) to self-generate public key pairs (224) and certificates (214). This eliminates the need for such keys and certificates to be sent to the devices from an outside source so a single-trust ap-proach can be maintained. A manufacturer's certificate is installed into a device at the time of manufacture. The device only issues itself certificates based on a signed request from an external outside server. The device's self-issued certifi-cates incorporate information obtained from the server in a profile. This allows control by the server over a device's self-issued certificates. In order to prevent tampering, and breaking, of the self-issued certificates, the certificate issuing process occurs within a secure microprocessor.

CA2359673C, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Expired 28 January 2020, 6.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

10 claims: 2 independent, 8 dependent

  1. 1
    CA 02359673 2008-11-12 THE EMBODIMENTS OF THE INVENTION IN WHICH AN EXCLUSIVE PROPERTY OR PRIVILEGE IS CLAIMED ARE DEFINED AS FOLLOWS:1. A method for providing self-issuing certificates in a device in a telecommunications system, the device having a certificate-signing key, the method comprising: receiving, from an external source, a request to generate a new certificate, wherein the request includes an encrypted public key! wherein the public key is smaller in size than the certificate-signing key;using a secure microprocessor inside the device to generate a new certificate for the public key;and directing the device to use said new certificate in data transfers.
  2. 10
    An apparatus for providing self-issuing certificates in an electronic device, the device having a certificate-signing key, the apparatus comprising:a cable input interface for receiving a request to generate a new certificate, wherein the request includes an encrypted public key, wherein the public key is smaller in size than the certificate-signing key;a secure microprocessor for generating a new certificate using the public key;and processing circuitry for using the new certificate in data transfers.