EP0725512A2

Data communication system using public keys

Abstract

A data communications system is described in which messages are processed using public key cryptography with a private key unique to one or more users (150) under the control of a portable security device (120), such as a smart card, held by each user, the system comprising: a server (130) for performing public key processing using the private key. The server (130) stores, or has access to, the private key for the, or each, user in encrypted form only. The private key is encrypted with a key encrypting key and each security device (120) comprises means for storing or generating the key encrypting key and providing the key encrypting key to the server (130). The server comprises secure means (360) to retrieve the encrypted private key for the user, decrypt the private key using the key encrypting key, perform the public key processing using the decrypted private key, and delete the decrypted private key after use.

EP0725512A2, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Projected expiry passed 17 January 2016, 10.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

11 claims: 7 independent, 4 dependent

  1. 1
    A communications system in which messages are processed using public key cryptography with a private key (SKa) unique to one or more users (150) under the control of a portable security device (120) held by the, or each, user, the system comprising:a server (130) for performing public key processing using the private key;the server (130) being adapted for data communication with the portable security device (120);characterised in that the server (130) comprises, or has access to, data storage means in which is stored in a secure manner the private key for the, or each, user in encrypted form only, the private key being encrypted with a key encrypting key (KEYa;KOWFa;KEK1a + RNxa), the server comprising secure processing means (360) to receive a message to be processed from the user, retrieve the encrypted private key for the user, decrypt the private key using the key encrypting key, perform the public key processing for the message using the decrypted private key, and delete the key encrypting key and decrypted private key after use, and in that each security device (120) comprises means for storing or generating the key encrypting key and providing the key encrypting key to the server (130) and means for specifying a message to be processed, the system being arranged so that communication of at least the key encrypting key to the server is secure and so that the server can only use the key encrypting key to process the message specified by the user.
  2. 5
    A system as claimed in any preceding claim wherein the key encrypting key is stored in the security device as a reversible function of a password (PINa), the system comprising means to receive from the user (150), and provide to the security device, the password, the security device comprising means to recover the key encrypting key using the reversible function.
  3. 6
    A system as claimed in any preceding claim wherein the key encrypting key (KOWFa) is a one-way function of the private key, the server comprising means to check the recovered value of the private key by deriving therefrom the key-encrypting key and comparing the derived value thereof with the value received from the security device.
  4. 7
    A system as claimed in any preceding claim wherein the key encrypting key is a reversible function of a key stored in the security device (KEK1a) and a random number (RNxa), the server (130) comprising means to provide the random number to the security device (120), wherein the server (130) is arranged to reencrypt the private key each time it is used using a new random number, and to provide the new random number to the security device the next time it is required to perform public key processing for a user.
  5. 8
    A portable security device for use in a communications system as claimed in any preceding claim, the portable security device (120) being adapted to communicate data to a server and comprising means for storing or generating the key encrypting key and providing the key encrypting key to the server (130).
  6. 10
    A server for use in a communications system as claimed in any of claims 1 to 7, the server (130) being adapted for data communications with a portable security device and comprising, or having means to access, secure storage means (350) in which the private key for the, or each, user is stored in encrypted form only, the private key being encrypted with a key encrypting key, the server comprising secure means (360) to retrieve the encrypted private key for the user, decrypt the private key using the key encrypting key, perform the public key processing using the decrypted private key, and delete the decrypted private key and the key encrypting key after use.
  7. 11
    A method for processing messages using public key cryptography with a private key (SKa) unique to one or more users (150) under the control of a portable security device (120) held by the, or each, user, in a system comprising:a server (130) for performing public key processing using the private key, in which system the server (130) is adapted for data communication with the portable security device (120);characterised by the steps of (a) storing in the server, or providing the server with access to, the private key for the, or each, user in encrypted form only, the private key being encrypted with a key encrypting key (KEYa;KOWFa;KEK1i+RN1i);(b) storing or generating in the security device the key encrypting key and providing the key encrypting key to the server (130) in a manner such that at least the key encrypting key is secure in communication to the server;and, in a secure environment in the server (130): (c) receiving a message to be processed specified by the user;(d) retrieving the encrypted private key for the user;(e) verifying that the message was that specified by the user;(f) decrypting the private key using the key encrypting key;(g) performing the public key processing for the message using the decrypted private key;and (h) deleting the decrypted private key and the key encrypting key after use.