EP0855815A2

Certification of cryptographic keys for chipcards

Abstract

The invention relates to a procedure for the certification of cryptographic keys for chipcards. In this procedure, a certification-key and a certificate are transferred to the chipcard. The first part of the certificate includes the cryptographic key and the second part of the certificate includes a digital signature of the first part of the certificate. The digital certificate is subsequently checked by means of the certification-key on the chipcard.

EP0855815A2, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 21 November 2017, 8.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

21 claims: 21 independent, 0 dependent

  1. 1
    Procedure for the certification of a cryptographic key for a chipcard, with the following procedural steps:a) Transfer of a certification-key to the chipcard, b) Transfer of a certificate to the chipcard, whereby a first part of the certificate includes the cryptographic key and a second part of the certificate includes a digital signature of the first part of the certificate, and c) Testing the digital signature by means of the certification-key on the chipcard.
  2. 2
    Procedure in accordance with Claim I characterised in that the testing of the digital signature on the chipcard includes the following steps:c1) Conversion of the digital signature by means of the certification-key, c2) Production of an electronic fingerprint of the first part of the certificate, and c3) Comparison of the converted digital signature with the electronic fingerprint of the first part of the certificate.
  3. 3
    Procedure in accordance with Claim I characterised in that the testing of the digital signature on the chipcard includes the following steps:c1) Production of an electronic fingerprint of the first part of the certificate, c2) Conversion of the electronic fingerprint by means of the certification-key and a set of equations, and c3) Comparison of the converted electronic fingerprint with a reference value which is transferred onto the chipcard with the certificate.
  4. 4
    Procedure in accordance with Claim I distinguished by a further procedural step:Marking of the cryptographic key as a certified key in the event that when the digital signature is checked, this is verified as being the same as the digital signature of the first part of the certificate.
  5. 5
    Procedure in accordance with Claim 1 distinguished by a further procedural step:Checking whether or not the certification-key can be used to certify the cryptographic key.
  6. 6
    Procedure in accordance with Claim 4 distinguished by a further procedural step:Using the certificated key for carrying out security-sensitive instructions.
  7. 7
    Procedure in accordance with Claim 1 characterised in that the certificated key is used as a further certification-key for the certification of a further cryptographic key.
  8. 8
    Procedure in accordance with Claim 1 characterised in that the cryptographic key can be used for the execution of a non-security-sensitive instruction after the certificate has been transferred to the chipcard.
  9. 9
    Procedure in accordance with Claims 2 or 3 characterised in that on each occasion when producing the digital signature of the first part of the certificate and when producing the electronic fingerprint of the first part of the certificate a hash-value is calculated by means of the hash-algorithm.
  10. 10
    Procedure in accordance with Claim 1 characterised in that the first part and second part of the certificate are transferred to the chipcard independently of one another.
  11. 11
    Procedure in accordance with Claim 1 characterised in that the first part of the certificate includes administrative data.
  12. 12
    Procedure in accordance with Claim 11 characterised in that the cryptographic key is assigned to one or several applications of the chipcard by means of the administrative data.
  13. 13
    Procedure in accordance with Claim 1, characterised in that the certification-key is transferred to the chipcard during personalisation of the chipcard.
  14. 14
    Procedure in accordance with Claim 4 characterised in that the marking of the cryptographic key as a certificated key is carried out by means of setting a bit in a status-byte of the cryptographic key.
  15. 15
    Procedure in accordance with Claim 4 characterised in that the marking of the cryptographic key as a certificated key is carried out by means of an entry of the cryptographic key in a table in the chipcard.
  16. 16
    Procedure in accordance with Claim 4 characterized in that the marking of the cryptographic key as a certificated key is carried out by storing the cryptographic key in a given memory area of the chipcard.
  17. 17
    Certificate for certification of a cryptographic key for a chipcard, characterised by a first part and a second part, whereby the two parts are separated from one another and whereby the first part includes the cryptographic key and the second part includes a digital signature of the first part.
  18. 18
    Certificate in accordance with Claim 17 characterised in that the certificate is capable of being transferred to the chipcard and can be evaluated by a processor on the chipcard.
  19. 19
    Certificate in accordance with Claim 17 characterised in that the first part of the certificate includes administrative data.
  20. 20
    Certificate in accordance with Claim 19 characterised in that the cryptographic key is capable of being assigned to one or several applications by the administrative data, and by means of the administrative data, it is possible to prevent any misuse of the cryptographic key for other applications which differ from the one or several applications.
  21. 21
    Certificate in accordance with Claim 19, characterised in that the administrative data includes the indication of a path of a memory storage area on the chipcard, whereby the cryptographic key can be stored exclusively in this memory storage area.
Independent claims21