EP0254812A2

Cryptovariable initialisation in a public key network.

Abstract

A procedure is disclosed for initialising with security and integrity a large number of terminals in an EFT/POS network with cryptographic variables. Each terminal in the network is provided with a terminal identification known to the key distribution centre, the public key of the key distribution centre is stored in the cryptographic facility of each terminal. A terminal initialiser is designated for each terminal, and the terminal initialiser for each terminal is notified of two expiration times for the purposes of registering the terminal's cryptovariable with the key distribution centre. The cryptovariable is generated by the terminal using its cryptographic facility. Prior to the first expiration time, a registration request is prepared and transmitted to the key distribution centre. The registration request includes the terminal identification and the cryptovariable. When the key distribution centre receives this request, the cryptovariable is temporarily registered and that fact is acknowledged to the requesting terminal. After the expiration of the second time, the registration is complete. Provisions are also made for invalidating a terminal identification in the event that more than one registration is attempted for a given terminal identification or that the registration was not made in time. The same procedure can be used to initialise cryptovariables of users of a network. The protocol is basically the same except that a user identification is used instead of a terminal identification, and the users may be provided with a transportable media, such as a magnetic stripe card or the like, which stores the user cryptovariable and can be read by terminals in the network.

EP0254812A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 14 April 2007, 19.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 8 independent, 2 dependent

  1. 1
    A method of initialising cryptovariables in a multiterminal network which uses a public key algorithm and wherein the number of terminals is not essentially limited, the method comprising establishing a key distribution centre within the network;generating a public and secret key pair for the key distribution centre;providing a cryptographic facility in each terminal that is intended to be secure;storing the public key of the key distribution centre in each such cryptographic facility;providing and storing at the key distribution centre, for each authorised entity - user or terminal - an individual identification;and informing an initialiser - the user or an appointee in the case of a terminal - of two expiration times for the purposes of registering a cryptovariable with the key distribution centre in order that the initialiser can generate a cryptovariable at a or the terminal, using the cryptographic facility and transmit over the network to the key distribution centre a registration request message including the identification and the cryptovariable pair before the first of the expiration times;the key distribution centre temporarily registering the cryptovariable against the identification, if received before the first expiration time and, if any further communication is received before the second expiration period in respect thereof, cancelling the registration, whereas, after the second expiration period, only cancelling the registration upon proof of authorisation.
  2. 3
    A method as claimed in either preceding claim, further comprising the step of preparing and transmitting to the key distribution centre prior to the second expiration time a identification invalidation request message in the event that neither of a positive acknowledgement from the key distribution centre stating that the requested public key was temporarily registered at the key distribution centre and a positive acknowledgement from the key distribution centre stating that the requested identification has been invalidated by the key distribution centre is received.
  3. 4
    A method as claimed in any preceding claim, further comprising the steps of:requesting the key distribution centre to provide a verification of the cryptovariable registration for the identification after the second expiration time has passed;and providing verification of the registration if the identification is valid and a cryptovariable was previously registered.
  4. 6
    A method as claimed in any preceding claim, wherein the public key of the key distribution centre is installed in each terminal at a central location before shipping the terminal to its point of use.
  5. 7
    A method as claimed in any preceding claim, wherein the step of generating is performed by generating a public key and secret key pair for each authorised entity.
  6. 8
    A method as claimed in any of claims 1 to 6, wherein the step of generating is performed by generating a secret authorised entity key using a symmetric algorithm.
  7. 9
    A method as claimed in any preceding claim, further including proving the identification of the designated initialiser after the second expiration time has passed;and requesting the invalidation of the identification if the requested cryptovariable was not registered with the key distribution centre.
  8. 10
    A method as claimed in any preceding claim, wherein, where an authorised entity is a user, the cryptovariable is recorded on a medium readable by terminals in the network.