EP0735720B1

Method for key distribution and verification in a key management system

Abstract

This record has no abstract on file.

EP0735720B1, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Expired 1 April 2016, 10.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

8 claims: 4 independent, 4 dependent

  1. 1
    A method of verifying evidence of transaction information integrity in a key management system including a transaction evidencing device having a device identifier, the transaction evidencing device producing said evidence of transaction information integrity in a logical security domain comprising the steps of:receiving the evidence of transaction information integrity and device identifier for the transaction evidencing device that produced the evidence of transaction information integrity;inputting the evidence of transaction information integrity and the device identifier to a verification box;based on the device identifier for the transaction evidencing device that produced the evidence of transaction information integrity, obtaining a master key record from an archive of the key management system, the master key record including a master key that said transaction evidencing device should have used to produce said evidence of transaction information integrity;verifying in the verification box that the master key included in the master key record is valid in the logical security domain for which the evidence of transaction information integrity was produced;using the master key in the verification box to verify the evidence of information integrity by calculating the evidence of transaction information integrity using the master key from the master key record and comparing the calculated evidence of transaction information integrity with the received evidence of transaction information integrity;and outputting from the verification box an indication of the result of the verification of the evidence of transaction information integrity.
  2. 2
    The method of Claim 1, wherein the master key record includes the device identifier, the master key and a digital signature associating the device identifier and the master key.
  3. 3
    The method of Claim 2, wherein the step of determining in the verification box that the master key included in the master key record is valid in the logical security domain for which the evidence of transaction information integrity was produced comprises the step of:checking the digital signature to verify the association of the device identifier and the master key within the logical security domain.
  4. 4
    The method of any preceding claim wherein the transaction evidencing device is a digital postage meter.
  5. 5
    A method of verifying evidence of transaction information integrity in a key management system including a transaction evidencing device having a device identifier, the transaction evidencing device producing said evidence of transaction information integrity in a logical security domain comprising the steps of:receiving the evidence of transaction information integrity and device identifier for the transaction evidencing device that produced the evidence of transaction information integrity;inputting the evidence of transaction information integrity and the device identifier to a verification box;based on the device identifier for the transaction evidencing device that produced the evidence of transaction information integrity, obtaining a token key record from an archive of the key management system, the token key record including a token key that said transaction evidencing device should have used to produce said evidence of transaction information integrity, the token key record being created using a master key;verifying in the verification box that the token key included in the token key record is valid in the logical security domain for which the evidence of transaction information integrity was produced;using the token key in the verification box to verify the evidence of information integrity by calculating the evidence of transaction information integrity using the token key from the token key record and comparing the calculated evidence of transaction information integrity with the received evidence of transaction information integrity;and outputting from the verification box an indication of the result of the verification of the evidence of transaction information integrity.
  6. 6
    The method of Claim 5, wherein the token key record includes the device identifier, the token key and a digital signature associating the device identifier and the token key.
  7. 7
    The method of Claim 5 or 6, wherein the step of verifying in the verification box that the token key is valid in logical security domain comprises the step of:checking the digital signature to verify the association of the device identifier and the token key within the logical security domain.
  8. 8
    The method of any one of Claims 5 to 7, wherein the transaction evidencing device is a digital postage meter.