EP0738058A2

Method and apparatus for the secure distribution of encryption keys

Abstract

Apparatus for transferring the encryption key in a secure way, to facilitate establishing a secure communication link, comprises a key management device attaching to each user's encryption machine for the purpose of key distribution, and a secure encryption key distribution center. A key management device is attached to each user's encryption machine, containing a list of secure communication partners and their respective encryption keys. The encryption key and other parameters are transferred automatically to the encryption machine. The called machine receives the caller identification, and the encryption key and other parameters are transferred automatically. The device displays to each user the true, reliable identity of the other party. If the desired addressee data is not found in the local data list, the key management device connects a secure key distribution center. The communication with the key distribution center is protected by encryption using the public key method. The key distribution center creates, for each user, a "certificate" which includes the user public key, user identification and issue date, all encrypted with the center's private key. The certificate can be used to access a multitude of remote databases or other information services on an irregular basis, without the need to subscribe to all of them. It may be also used for secure payment over insecure links using credit cards and/or for caller identification. The certificate method is used for flexible authorization schemes, to indicate changing time period of validity or authorizations/ permits.

EP0738058A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 2 April 2016, 10.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

8 claims: 3 independent, 5 dependent

  1. 1
    A center (11) for safe key distribution to authorized and/or unauthorized users (1,2,3), to facilitate establishing a safe communication link, including:(A) Computer means for storing a list of said users and their respective encryption keys, for retrieving data from and updating said list, for preparing digital messages for said users and for performing related control functions, according to predefined procedures and received digital messages from said users;and(B) Channel interface means for connecting said computer means in said center to said users through a communication channel to receive and transmit said digital messages with said users.
  2. 5
    A method for facilitating occasional users to access a multitude of remote databases or other information services on an irregular basis with the support of an authorization center, including the steps of:(A) The key management center signs agreements with a multitude of information and/or services providers, for said providers to accept irregular users which are authorized by said center as attested by presenting a digital certificate issued by said center, and to charge said center for the said information/services provided;(B) said center accepts and authorizes said users to use the information services it has business relations with, including the steps of: (1) a user accesses the center from a remote site;(2) the user identifies himself/herself, for example by providing a name or pseudonym, and a credit card number, which may be encrypted using the center's public key;(3) the center checks the validity of the credit card;and(4) if the credit card is valid, then the user is issued a certificate which includes the information supplied by the user and additional optional information like the issue date and center details, all encrypted with the private key of the center;and(C) the user thus authorized accesses the desired remote services, presents the certificate and is accepted as a user of that service.
  3. 7
    A key management device attaching to each one of a plurality of user's (1) encryption machines (21) for the purpose of public key distribution, and including:(A) Channel interface means (41) for connecting with another user (2) or a key distribution center (11) through a communication channel (103), to transmit and/or receive digital messages containing information identifying said user and said public key for said user;and(B) Key management controller means (314) for accepting the desired addressee or initiator details, for obtaining said key from said center through said channel interface, and for transferring said key to said encryption machine,onnected to said channel interface and to said encryption machine.