EP0576224A2

Cryptographic key management apparatus and method.

Abstract

The present invention provides for a cryptographic key management method and apparatus in which the cryptographic keys are provided as vector keys characterized in that they comprise a key value and control information for specifying the use to which the key can be put by members of a communications domain. Each domain member is associated with at least one pair of vector keys and the keys in each pair share the same key value. One of the keys in each pair is provided as a public key and specified for encrypting, or verifying the seal of, messages sent from the domain member associated therewith and the other is provided as a private key and specified for decrypting, or generating a seal for, messages sent to the domain member associated therewith.

EP0576224A2, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 18 June 2013, 13.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 5 independent, 5 dependent

  1. 1
    Cryptographic key management apparatus having a plurality of key means for a plurality of members of a communications domain, each key means comprising a cryptographic key value and control information specifying key usage, characterized in that said plurality of key means comprises a plurality of domain vector keys each paired with a member vector key, each pair of vector keys sharing the same cryptographic key value and the domain vector keys being specified as public keys for data encryption and data seal verification and the member vector keys being specified as private keys for data decryption and data seal generation, wherein said plurality of domain vector keys are located in store means accessible to said plurality of domain members and each domain member is associated with at least one of said pairs, and in that a plurality of master keys are provided to protect the plurality of vector keys.
  2. 5
    Apparatus according to any one of the preceding claims, characterized in that said communication domain is arranged to delimit the scope of use of said vector keys.
  3. 6
    Apparatus according to any one of the preceding claims, characterized in that said master keys comprise a domain master key shared by said domain members to protect said domain vector keys and a plurality of member master keys each of which is unique to a respective domain member to protect the respective member vector key of each domain member.
  4. 7
    Apparatus according to any one of the preceding claims, characterized in that said cryptographic key value and said control information of each vector key is arranged as a single data structure.
  5. 8
    A method of managing cryptograhpic keys having a key value and control information for specifying the use of the keys by members of a communications domain, characterized by arranging the cryptographic keys as public and private key pairs which share the same key value, associating at least one pair with each domain member, specifying each pubic key for data encryption and data seal verification and each private key for data decryption and data seal generation, locating the cryptographic keys in store means accessible to all domain members and by providing master keys to protect the cryptographic keys.