EP1320009A2

Method and apparatus for securely storing a public key

Abstract

A method for securely storing a public key for encryption of data in a computing device uses a user-specific key pair which is securely stored in the computing device. A target public key corresponding to a target device is received and a user-specific key pair is obtained from a secure registry. A user-specific private key from the user-specific key pair is used to create a target key verifier based on the target public key. The target key verifier and the target public key are stored in a storage area. The target key verifier and the target public key are retrieved from the storage area and a user-specific public key from the user-specific key pair is applied to the target key verifier to verify the authenticity of the target public key. In the case that the authenticity of the target public key is verified, the data is encrypted with the target public key, thereby creating encrypted data for transmission to the target device.

EP1320009A2, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Projected expiry passed 27 November 2022, 3.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

32 claims: 9 independent, 23 dependent

  1. 1
    A method for securely storing a public key for encryption of data in a computing device, the method using a user-specific key pair which is securely stored in the computing device, the method comprising:a receiving step of receiving a target public key corresponding to a target device;an obtaining step of obtaining a user-specific key pair from a secure registry;a key encrypting step of using a user-specific private key from the user-specific key pair to create a target key verifier based on the target public key;a storing step of storing the target key verifier and the target public key in a storage area;a retrieving step of retrieving the target key verifier and the target public key from the storage area;a verification step of applying a user-specific public key from the user-specific key pair to the target key verifier for verifying the authenticity of the target public key;and a data encrypting step of encrypting data with the target public key, in the case that the authenticity of the target public key is verified, thereby creating encrypted data for transmission to the target device.
  2. 21
    A method for securely storing a printer public key for encryption of print data in a computing device, the method using a user-specific key pair which is securely stored in the computing device, the method comprising:a receiving step of receiving a printer public key corresponding to a printer;an obtaining step of obtaining a user-specific key pair from a secure registry upon receipt of a corresponding user identification;a first hashing step of applying a hashing algorithm to the printer public key to create a first printer key hash;an encryption step of applying an encryption algorithm to encrypt the first printer key hash with a user-specific private key from the user-specific key pair, thereby creating a printer key signature;a storing step of storing the printer key signature and the printer public key in a storage area;a retrieving step of retrieving the printer key signature and the printer public key from the storage area;a second hashing step of applying the hashing algorithm to the retrieved printer public key to create a second printer key hash;a decrypting step of applying a decryption algorithm to decrypt the printer key signature with a user-specific public key from the user-specific key pair, thereby retrieving the first printer key hash;a verification step of applying a verification algorithm to compare the first printer key hash with the second printer key hash, for verifying the authenticity of the retrieved printer public key;and a print data encrypting step of applying an encryption algorithm to print data using the retrieved printer public key, in the case that the authenticity of the retrieved printer public key is verified, to create encrypted print data for transmission to the printer.
  3. 22
    A method for authentication of a printer public key received by a computing device, the method comprising:a first receiving step of receiving in the computing device a printer public key corresponding to a printer;a hashing step of applying a hashing algorithm to the printer public key to create a first printer key hash;a second receiving step of receiving in the computing device a predetermined second printer key hash obtained from a test page printed by the printer, wherein the second printer key hash is input into the computing device by a user-input means connected to the computing device;a verification step of applying a verification algorithm to compare the first printer key hash with the second printer key hash, for verifying the authenticity of the received printer public key;and a storing step of storing, in the case that the authenticity of the received printer public key is verified in the verification step, the received printer public key in a memory area of the computing device.
  4. 23
    A computing device for authenticating a public key for encryption of data, said computing device comprising:a program memory for storing process steps executable to perform a method according to any of Claims 1 to 22;and a processor for executing the process steps stored in said program memory.
  5. 24
    Computer-executable process steps stored on a computer readable medium, said computer-executable process steps for authenticating a public key for encryption of data, said computer-executable process steps comprising process steps executable to perform a method according to any of Claims 1 to 22.
  6. 25
    A computer-readable medium which stores computer-executable process steps, the computer-executable process steps to authenticate a public key for encryption of data, said computer-executable process steps comprising process steps executable to perform a method according to any of Claims 1 to 22.
  7. 26
    An information apparatus which transmits encrypted data to a target device, the information apparatus securely storing a public key for encryption of the data and utilizing a user-specific key pair which is securely stored in the apparatus, comprising:receiving means for receiving a target public key corresponding to a target device;obtaining means for obtaining a user-specific key pair from a secure registry;key encrypting means for using a user-specific private key from the user-specific key pair to create a target key verifier based on the target public key;storing means for storing the target key verifier and the target public key;retrieving means for retrieving the target key verifier and the target public key from the storage means;verification means for applying a user-specific public key from the user-specific key pair to the target key verifier for verifying the authenticity of the target public key;and data encrypting means for encrypting data with the target public key, in the case that the authenticity of the target public key is verified, thereby creating encrypted data for transmission to the target device.
  8. 27
    An information apparatus which transfers encrypted print data to a printer, the apparatus comprising:retrieving means for retrieving a public key from said printer;generating means for generating verification information from the public key;recognizing means for recognizing a printing instruction;verification means for verifying, in response to the recognition of the printing instruction, that the public key is not changed from the retrieved public key;and control means for controlling encryption processing which is performed by using said public key when the retrieved public key is verified as unchanged, and which is not performed when the retrieved public key is verified as changed.
  9. 30
    An information processing method for transferring encrypted print data to a printer, the method comprising:a retrieving step of retrieving a public key from said printer;a generating step of generating verification information from the public key;a recognizing step of recognizing a printing instruction;a verification step of verifying, in response to the recognition of the printing instruction, that the public key is not changed from the retrieved public key;and a control step of controlling encryption processing which is performed by using said public key when the retrieved public key is verified as unchanged, and which is not performed when the retrieved public key is verified as changed.