EP1292872B2

A method for the application of implicit signature schemes

Abstract

This record has no abstract on file.

EP1292872B2, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Expired 11 June 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

3 claims: 3 independent, 0 dependent

  1. 1
    A method for certifying a correspondent (12, 14) in a data communication system through the use of a certifying authority (20) having control of a certificate's validity, said method comprising the steps of:a) said certifying authority (20) generating a first random number (cA);b) generating transaction specific implicit signature components γA. sA, based on said first random number (cA);c) publishing a public key Qc of said certifying authority (20) for use in verifying said correspondent (12, 14);d) forwarding said transaction specific implicit signature components from said certifying authority (20) to said correspondent (12, 14);wherein said certifying authority (20) recertifies said correspondent's (12, 14) transaction specific implicit signature components by changing said value of said first random number (cA);wherein said first random number (cA) has said value for one certification period, said value being changed for other of said certifications periods, wherein ki is said first random number generated by said certifying authority (20) for an ith certification period and said transaction specific implicit signature components include: i, where i is a current certification period;sA, where sAi = ric + ki + cA(mod n), n is a large prime number, c is a long term private key of said certifying authority (20), cA is a second random number, and ri = h(γA ∥ Ai ∥ cP ∥ kiP ∥ i), where Ai includes at least one distinguishing feature of said correspondent (12, 14) and transaction specific information, P is a point on a curve, and h indicates a secure hash function;wherein γA = aP + cAP, and where aP is a long term public key of said correspondent (12, 14) and γA has previously been determined by said certifying authority (20) and forwarded to said correspondent (12, 14). Procédé pour certifier un correspondant (12, 14) dans un système de communication de données par l'intermédiaire de l'utilisation d'une autorité de certification (20) ayant le contrôle de la validité d'un certificat, ledit procédé comprenant les étapes consistant à : a) générer, par ladite autorité de certification (20), un premier nombre aléatoire (cA) ;b) générer des éléments de signature implicite spécifiques à une transaction γA, sA, sur la base dudit premier nombre aléatoire (cA) ;c) publier une clé publique Qc de ladite autorité de certification (20) pour une utilisation lors de la vérification dudit correspondant (12, 14) ;d) transférer lesdits éléments de signature implicite spécifiques à une transaction de ladite autorité de certification (20) audit correspondant (12, 14) ;ladite autorité de certification (20) recertifiant les éléments de signature implicite spécifiques à une transaction du correspondant (12, 14) en changeant ladite valeur dudit premier nombre aléatoire (cA) ;ledit premier nombre aléatoire (cA) ayant ladite valeur pendant une période de certification, ladite valeur étant changée pendant une autre desdites périodes de certification, ki étant ledit premier nombre aléatoire généré par ladite autorité de certification (20) pendant une ième période de certification et lesdits éléments de signature implicite spécifiques à une transaction comprenant : i, où i est une période de certification actuelle ;SA, où sAi = ric + ki + cA (mod n), n est un grand nombre premier, c est une clé privée à long terme de ladite autorité de certification (20), cA est un second nombre aléatoire, et ri = h (γA ∥ Ai ∥ cP ∥ kiP ∥ i), où Ai comprend au moins une caractéristique de distinction dudit correspondant (12, 14) et des informations spécifiques à une transaction, P est un point sur une courbe, et h indique une fonction de hachage sécurisée ;γA = aP + cAP, où aP est une clé publique à long terme dudit correspondant (12, 14) et γA a été précédemment déterminé par ladite autorité de certification (20) et transféré audit correspondant (12, 14). Verfahren zum Zertifizieren eines Korrespondenten (12, 14) in einem Datenkommunikationssystem durch die Verwendung einer Zertifizierungsstelle (20), welche die Kontrolle über die Gültigkeit eines Zertifikats hat, wobei das Verfahren folgende Schritte umfasst: a) Generieren einer ersten Zufallszahl (cA) durch die Zertifizierungsstelle (20);b) Generieren von transaktionsspezifischen impliziten Signaturkomponenten γA, sA, basierend auf der ersten Zufallszahl (cA);c) Veröffentlichen eines öffentlichen Schlüssels Qc der Zertifizierungsstelle (20) zur Verwendung beim Überprüfen des Korrespondenten (12, 14);d) Weiterleiten der transaktionsspezifischen impliziten Signaturkomponenten von der Zertifizierungsstelle (20) an den Korrespondenten (12, 14);wobei die Zertifizierungsstelle (20) die transaktionsspezifischen impliziten Signaturkomponenten des Korrespondenten (12, 14) erneut zertifiziert, indem sie den Wert der ersten Zufallszahl (cA) ändert;wobei die erste Zufallszahl (cA) den Wert für eine Zertifizierungsperiode aufweist, wobei der Wert für andere der Zertifizierungsperioden geändert wird, wobei ki die erste Zufallszahl ist, die durch die Zertifizierungsstelle (20) für eine i. Zertifizierungsperiode generiert wird, und die transaktionsspezifischen impliziten Signaturkomponenten Folgendes umfassen: i, wobei i eine aktuelle Zertifizierungsperiode ist;sA, wobei sAi = ric + ki + cA(mod n), n eine große Primzahl ist, c ein langfristiger privater Schlüssel der Zertifizierungsstelle (20) ist, cA eine zweite Zufallszahl ist, und ri = h(γA ∥ Ai ∥ cP ∥ kiP ∥ i), wobei Ai mindestens ein Differenzierungsmerkmal des Korrespondenten (12, 14) und transaktionsspezifische Informationen umfasst, P ein Punkt auf einer Kurve ist, und h eine sichere Hash-Funktion angibt;wobei γA = aP + cAP, und wobei aP ein langfristiger öffentlicher Schlüssel des Korrespondenten (12, 14) ist, und γA durch die Zertifizierungsstelle (20) zuvor bestimmt und an den Korrespondenten (12, 14) weitergeleitet wurde.
  2. 2
    A method as defined in claim 1, wherein said published information further includes kiP and i. Procédé tel que défini à la revendication 1, dans lequel lesdites informations publiées comprennent en outre kiP et i. Verfahren nach Anspruch 1, wobei die veröffentlichten Informationen ferner kiP und i umfassen.
  3. 3
    A method as defined in claim 2, wherein said correspondent (12, 14) is recertified by forwarding said transaction specific implicit signature components for said first random number having said changed value from said certifying authority (20) to said correspondent (12, 14). Procédé tel que défini à la revendication 2, dans lequel ledit correspondant (12, 14) est recertifié par transfert desdits éléments de signature implicite spécifiques à une transaction pour ledit premier nombre aléatoire ayant ladite valeur changée de ladite autorité de certification (20) audit correspondant (12, 14). Verfahren nach Anspruch 2, wobei der Korrespondent (12, 14) erneut zertifiziert wird, indem die transaktionsspezifischen impliziten Signaturkomponenten für die erste Zufallszahl, die den geänderten Wert aufweisen, von der Zertifizierungsstelle (20) an den Korrespondenten (12, 14) weitergeleitet werden.