EP0472939B1

Cryptographic key version control facility

Abstract

This record has no abstract on file.

EP0472939B1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Expired 31 July 2011, 15.2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

8 claims: 4 independent, 4 dependent

  1. 1
    A cryptographic apparatus (102) permitting nondisruptive, dynamic master key changes, comprising:a) a cryptographic engine (103,113) for performing cryptographic operations on supplied data (114) using a supplied key (115), said supplied key being enciphered under an enciphering master key (MK, 106) ;b) master key register means (108,801,802,803) comprising: 1) a first master key register (801) for holding a first master key;2) a second master key register (802) for holding a second master key;and 3) state register means (SR,803) having a plurality of possible values, said values identifying said first register and said second register as empty, as containing a new master key, as containing a current master key, or as containing an old master key;said cryptographic apparatus is characterised in comprising: c) means for ensuring that the supplied key is enciphered under the current master key comprising: c1) exception means (107,109,110) for identifying a mismatch between the encrypting key (RMKVN, 109,906;MKVP, 61B) used to encipher the supplied key (61A), and the current master key (MKVN, 110;CMKVP 62A);c2) verification means, (OMKVP, 62C), responsive to said exception means, for verifying that the mismatch exists because the encrypting key, used to encipher the supplied key, is now present in the old master key register;c3) means (RFOMK, fig.7) for reenciphering the supplied key from the old master key contained in the old master key register to the current master key in the current master key register, when said verification means so verifies the mismatch;c4) a master key version-number register (110) for holding a master key version number (MKVN), the master key version number being supplied and associated with the current master key when the current master key is placed in the current master key register (801,802);and c5) key token means (61,901) for identifying an encrypting key (RMKVN, 109,906;MKVP, 61B) used to encipher the supplied key (61A);wherein the key token means comprises a master key verification pattern (MKVP, 61B) uniquely associated with an associated master key by means of a one-way function.
  2. 5
    The cryptographic apparatus of anyone of claims 1 to 4, further comprising means (RTNMK, fig. 3) for reenciphering a key enciphered under the current master key to being enciphered under the new master key.
  3. 6
    The cryptographic apparatus of anyone of claims 1 to 5, further comprising means for restricting the use of functions of the cryptographic apparatus to a possessor of an authorization pattern (24) derived from an associated master key by a oneway function.
  4. 8
    A method for making dynamic nondisruptive changes to a current master key controlling a cryptographic apparatus in a data processing system, said method comprising the steps of:a) associating a current version number (MKVN) with the current master key;b) replacing the current master key with a new master key having an associated new master key version number in a master key version number register (110), said current master key thereafter being termed an old master key and said new master key being termed thereafter the current master key, the current master key version number thereafter being termed an old master key version number (OMKVN, 62D), and the new master key version number being termed the current master key version number (CMKVN, 62B);and c) providing, as part of a request for a cryptographic function, a supplied token (901) uniquely associated with a supplied user key (907, 61A);said method is characterised in further comprising the steps of: d) determining a supplied version number (RMKVN, 109,906;MKVP, 61B) associated with the supplied user key;e) comparing (117) the supplied version number with the current version number (MKVN, 110;CMKVP, 62A), and signalling an exception if said comparing resulted in an unequal condition;f) if said comparing resulted in the exception being signalled, automatically reenciphering the supplied user key from under the old master key to under the current master key if the supplied version number matches the old master key version number;g) continuing with the request for the cryptographic function using the automatically reenciphered supplied user key;h) causing the master key version number register (110) to be reset to a predetermined value ("φ") following a system reset or an initialization (IPL) of a system containing the cryptographic apparatus;i) deriving an authorization pattern (24) from the current master key by a one-way function;j) prohibiting any cryptographic function requiring the current master key from executing when the master key version number register has the predetermined value;and k) requiring a master key version number reset function to supply the authorization pattern in order to successfully reset the master key version number to a value other than the predetermined value.