CA2417770A1

Trusted authentication digital signature (tads) system

Abstract

Trusted entity authentication includes creating a public-private key pair (295) in a secure environment (240); storing the private key (295) within a device (240) during its manufacture in the secure environment (240); linking the public key (295) with other information in the secure environment; receiving input within the device comprising verification data (250) of an entity; identifying within the device a verification status based on the verification data (250) and data prestored within the device (240); independent of the verification status identified (260), generating a digita l signature (299) for a message including an indication of the identified verification status using the private key (295); outputting the digital signature for transmission with an EC (210); identifying upon receipt of the EC (210) the information linked with the public key (295) by authenticating the message with the public key (295); and considering the identified information and the indicated verification status (260). The linked information includes device security aspects and the verification status (26 0) regards entity authentication performed by the device.

CA2417770A1, drawing sheet 1
Sheet 1 of 60

Term

Term ended

Projected expiry passed 6 August 2021, 5.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

283 claims: 10 independent, 273 dependent

  1. 1
    CA 02417770 2003-02-03 WO 02/13444 PCT/US01/24563 What is claimed is:1. A method of managing accounts, each account being associated with a respective public key of public-private key pair, comprising: (a) receiving an EC including a digital signature, (b) identifying information linked with a public key associated with one of the customer accounts by successfully authenticating a message associated with the EC using the public key, the information regarding security aspects of a device that generates digital signatures, the public key and corresponding private key having been created within an environment of manufacture of the device and the private key stored within the device prior to release of the device from the environment following its manufacture;and (c) responding to the EC based on, (i) said identified information linked with the public key, and (ii) an indication included in the EC of a verification status out of a plurality of predefined verification statuses, the verification status regarding an entity authentication performed by the device as a function of verification data of an entity input into the device and data prestored within the device.
  2. 37
    A method of establishing trusted entity authentication associated with an EC including a digital signature, comprising the steps of:(a) for a device manufactured within a secure environment, (i) creating a public-private pair before release of the device from the secure environment, (ii) storing the private key within the device for utilization in generating a digital signature before release of the device from the secure environment, and (iii) linking within the secure environment in a secure manner the public key with other information associated with the device;(b) within the device after its manufacture, (i) receiving input comprising verification data of an entity, (ii) identifying within the device a current verification status out of a plurality of predefined verification statuses of the device as a function of the verification data and data prestored within the device, each verification status regarding an entity authentication performed by the device, (iii) independent of the verification status identified, generating a digital signature for a message as a function of said identified verification status, including modifying within the device data representing the message as a function of said identified verification status, said generated digital signature comprising an indication of the identified verification status, and (iv) outputting from the device the digital signature for transmission with the EC to a recipient;and (c) upon receipt of the EC by the recipient, (i) identifying the other information linked with the public key of the device by successfully authenticating the message using the public key of the device, and (ii) responding to the EC based on the indication of the verification status included in the EC and said identified information linked with the public key.
  3. 94
    The method of claims claim 37, wherein said step of generating the digital signature includes encrypting within the device using a private key of a public-private key pair a message digest calculated within the device for said modified data.
  4. 148
    The method of claims 146 or 147, wherein the first comparison marker is assigned a value equated with a successful verification when said comparison results in a match, including an exact match. CA 02417770 2003-02-03 WO 02/13444 PCT/US01/24563 110
  5. 153
    The method of claims 146 or 147, wherein the second comparison marker is assigned a value equated with a successful verification when said comparison results in a match, but not an exact match.
  6. 155
    The method of claims 146 or 147, wherein the first comparison marker is assigned a value representing a difference determined from said comparison between the verification data representing the Secret and the prestored data.
  7. 156
    The method of claims 146 or 147, wherein the second comparison marker is assigned a value representing a degree of match between the verification data representing the biometric data and the prestored data.
  8. 159
    The method of claims 146 or 147, wherein the second comparison marker is assigned a value equated with an unsuccessful verification when said comparison results in an exact match.
  9. 160
    The method of claims 146 or 147, wherein the second comparison marker is assigned a value equated with a successful verification when said comparison results in a proximate match.
  10. 166
    The method of claims 146 or 147, further comprising the step of outputting said assigned value of the first comparison marker.
  11. 167
    The method of claims 146 or 147, further comprising the step of outputting said assigned value of the second comparison marker.
  12. 168
    The method of claims 146 or 147, further comprising the step of outputting said assigned value of the first and second comparison markers.
  13. 169
    The method of claims 146 or 147, wherein said step of modifying comprises embedding said assigned value of the first comparison marker within the data representing the message.
  14. 170
    The method of claims 146 or 147, wherein said step of modifying comprises appending said assigned value of the first comparison marker to the data representing the message.
  15. 173
    The method of claims 146 or 147, wherein said step of modifying comprises embedding said assigned value of the second comparison marker within the data representing the message.
  16. 174
    The method of claims 146 or 147, wherein said step of modifying comprises appending said assigned value of the second comparison marker to the data representing the message.
  17. 232
    The method of claim'37, wherein the device comprises a security card.
  18. 248
    The method of claims 245 or 246, further comprising receiving the data representing the message in addition to receiving the digital signature.
  19. 249
    The method of claims 245 or 246, wherein the message is predefined.
  20. 250
    The method of claims 245 or 246, wherein one of the predefined verification statuses represents a successfill verification.
  21. 256
    The method of claims 245 or 246, wherein one of the predefined verification status represents a difference between verification data input into the device and data prestored within the device.
  22. 257
    The method of claims 245 or 246, wherein one of the predefined verification statuses represents a degree of match between biometric verification data input into the device and biometric data prestored within the device. CA 02417770 2003-02-03 WO 02/13444 PCT/US01/24563 116
  23. 264
    The method of claims 1 or 37, wherein the device is a personal device of a user.
  24. 265
    The method of claims 1 or 37, wherein the device is a handheld device.
  25. 266
    An electronic apparatus comprising a computer-readable medium including computerexecutable instructions that perform one of the steps of the method of 1 or 37.
  26. 267
    An electronic apparatus comprising circuitry for performing one of the steps of the method of claims 1 or 37.
  27. 268
    An electronic apparatus comprising means for performing one of the steps of the method of claims 1 or 37.
  28. 269
    The method of claims 1 or 37, wherein the device includes a random number generator.
  29. 273
    The method of 272, wherein said digital signature is generated using a digital signature algorithm requiring a random number, and further comprising using said received digital signature as a random number in an application requiring a random number.
  30. 280
    A system in which a recipient of an EC authenticates an entity by solely conducting message authentication with respect to a received electronic communication that includes both a unique identifier associated with an account maintained by the recipient and a digital signature for a message regarding the account, comprising the steps of:(a) before receipt of the electronic communication, (i) associating a public key of a public-private key pair with the unique identifier by the recipient, and (ii) identifying information linked with the public key, including information regarding security aspects of the device to which the private key of the public-private key pair belongs, the public key and corresponding private key having been created within an environment of manufacture of the device and the private key having been stored within the device prior to release of the device from the environment following its manufacture;and (b) thereafter, (i) using only the digital signature in the electronic communication and the public key associated with the account identifier to the conduct message authentication, and (ii) upon successful authentication of the message, responding to the message based on, (A) said identified information linked with the public key, and (B) an indication included in the EC of a verification status of the device out of a plurality of predefined verification statuses, the verification status regarding an entity authentication performed by the device as a function of verification data of the entity input into the device and data prestored within the device.
  31. 281
    A system in which a recipient of an EC authenticates an entity by solely conducting message authentication with respect to a received electronic communication that includes CA 02417770 2003-02-03 WO 02/13444 PCT/US01/24563 118 both a unique identifier associated with an account maintained by the recipient and a digital signature for a message regarding the account, comprising the steps of:(a) before receipt of the electronic communication, (i) associating a public key of a public-private key pair with the unique identifier by the recipient, and (ii) identifying information linked with the public key, including information regarding security aspects of the device to which the private key of the public-private key pair belongs;and (b) thereafter, (i) using only the digital signature in the electronic communication and the public key associated with the account identifier to the conduct message authentication, and (ii) upon successful authentication of the message, responding to the message based on, (A) said identified information linked with the public key, and (B) an indication included in the EC of a verification status of the device out of a plurality of predefined verification statuses, the verification status regarding an entity authentication performed by the device as a function of verification data of the entity input into the device and data prestored within the device.
  32. 282
    A system in which a recipient of an EC authenticates an entity by solely conducting message authentication with respect to a received electronic communication that includes both a unique identifier associated with an account maintained by the recipient and a digital signature for a message regarding the account, comprising the steps of:(a) before receipt of the electronic communication, associating a public key of a public-private key pair with the unique identifier by the recipient;and thereafter (b) using only the digital signature in the electronic communication and the public key associated with the account identifier to conduct the message authentication, and upon successful authentication of the message, responding to the message based on an indication included in the EC of a verification status of the device out of a plurality of predefined verification statuses, the verification status regarding an entity authentication performed by the device as a function of verification data of the entity input into the device and data prestored within the device.
  33. 283
    A system in which a recipient of an EC authenticates an entity by solely conducting message authentication with respect to a received electronic communication that includes both a unique identifier associated with an account maintained by the recipient and a digital signature for a message regarding the account, comprising the steps of:CA 02417770 2003-02-03 WO 02/13444 119 PCT/US01/24563 before receipt of the electronic communication, (i) associating a public key of a public-private key pair with the unique identifier by the recipient, and (ii) identifying information linked with the public key, including information regarding security aspects of the device to which the private key of the public-private key pair belongs, the public key and corresponding private key having been created within an environment of manufacture of the device and the private key having been stored within the device prior to release of the device from the environment following its manufacture;and (b) thereafter, (i) using only the digital signature in the electronic communication and the public key associated with the account identifier to the conduct message authentication, and (ii) upon successful authentication of the message, responding to the message based on said identified information linked with the public key.
Independent claims33