Systems and method for certifying digital signatures
72 claims: 51 independent, 21 dependent
- 1Module de sécurité électronique portable (1), comprenant :- une mémoire de données électronique (10)- une clé de client privée secrète (102) stockée dans la mémoire de données électronique (10), d'une première paire de clés numériques qui se composent de la clé de client (102) privée secrète et d'une clé client publique (101) et- un module de signature (105) pour la génération d'une signature numérique de client à partir de données d'objets à signer avec la clé de client (102) privée, caractérisé par- une clé privée secrète stockée dans la mémoire de données électronique (10), d'une seconde paire de clés numériques qui se composent de la clé privée secrète d'un fournisseur de services de sécurité (104) et d'une clé publique du fournisseur de services de sécurité (103),- un module de certification (105a) placé dans le module de signature (105) pour générer un certificat numérique de signature à partir de la signature client avec la clé privée du fournisseur de services de sécurité (104). Portable, electronic security module (1), comprising: - an electronic data store (10),- a secret private customer key (102), stored in the electronic data store (10), of a first digital key pair consisting of a secret private customer key (102) and a public customer key (101), and- a signature module (105) for generating a digital customer signature from object data to be signed using the private customer key (102), characterised by: - a secret private key, stored in the electronic data store (10), of a second digital key pair consisting of the secret private key (104) of a security provider and a public key (103) of the security provider, and- a certification module (105a), installed in the signature module (105), for generating a digital signature certificate from the customer signature using the private key (104) of the security provider. Tragbares elektronisches Sicherheitsmodul (1), umfassend: - einen elektronischen Datenspeicher (10),- einen im elektronischen Datenspeicher (10) gespeicherten geheimen privaten Kundenschlüssel (102) eines ersten digitalen Schlüsselpaars, das aus dem geheimen privaten Kundenschlüssel (102) und einem öffentlichen Kundenschlüssel (101) besteht, und- ein Signierungsmodul (105) zum Erzeugen einer digitalen Kundensignatur aus zu signierenden Objektdaten mit dem privaten Kundenschlüssel (102), gekennzeichnet durch: - einen im elektronischen Datenspeicher (10) gespeicherten geheimen privaten Schlüssel eines zweiten digitalen Schlüsselpaars, das aus dem geheimen privaten Schlüssel eines Sicherheitsanbieters (104) und einem öffentlichen Schlüssel des Sicherheitsanbieters (103) besteht, und- ein im Signierungsmodul (105) angebrachtes Zertifizierungsmodul (105a) zum Erzeugen eines digitalen Signaturzertifikats aus der Kundensignatur mit dem privaten Schlüssel des Sicherheitsanbieters (104).
- 2Electronic security module (1) according to claim 1, characterised in that it comprises a customer identification (106) stored in the electronic data store (10), and the certification module (105a) is designed such that it generates the signature certificate using additionally the customer identification (106). Elektronisches Sicherheitsmodul (1) nach Anspruch 1, dadurch gekennzeichnet, dass es eine im elektronischen Datenspeicher (10) gespeicherte Kundenidentifizierung (106) umfasst, und dass das Zertifizierungsmodul (105a) so beschaffen ist, dass es das Signaturzertifikat zudem aus der Kundenidentifizierung (106) erzeugt. Module électronique de sécurité (1) selon la revendication 1, caractérisé en ce qu'il comprend une identification de client (106) stockée dans la mémoire de données électronique (10), et en ce que le module de certification (105a) est réalisé de sorte qu'il génère le certificat de signature en outre à partir de l'identification client (106)
- 3Electronic security module (1) according to one of the claims 1 or 2, characterised in that it comprises personal customer attributes (107), stored in the electronic data store (10), and the certification module (1 05a) is designed such that it generates the signature certificate using additionally the customer attributes (107). Elektronisches Sicherheitsmodul (1) nach einem der Ansprüche 1 oder 2, dadurch gekennzeichnet, dass es im elektronischen Datenspeicher (10) gespeicherte persönliche Kundenattribute (107) umfasst, und dass das Zertifizierungsmodul (105a) so beschaffen ist, dass es das Signaturzertifikat zudem aus den Kundenattributen (107) erzeugt. Module électronique de sécurité (1) selon l'une des revendications 1 ou 2, caractérisé en ce qu'il comprend des attributs personnels (107) de clients stockés dans la mémoire de données électronique (10) et en ce que le module de certification (105a) est réalisé de sorte qu'il génère le certificat de signature en outre à partir des attributs de clients (107).
- 4Electronic security module (1) according to claim 3, characterised in that it comprises an attribute updating module (108) for receiving attribute updating instructions and for updating the customer attributes (107) based on received attribute updating instructions. Elektronisches Sicherheitsmodul (1) nach Anspruch 3, dadurch gekennzeichnet, dass es ein Attributaktualisierungsmodul (108) umfasst zum Entgegennehmen von Attributaktualisierungsinstruktionen und zur Aktualisierung der Kundenattribute (107) basierend auf entgegengenommenen Attributaktualisierungsinstruktionen. Module de sécurité électronique (1) selon la revendication 3, caractérisé en ce qu'i comprend un module d'actualisation d'attributs (108) pour la réception d'instructions d'actualisation d'attributs et pour l'actualisation d'attributs de clients (107) en se basant sur les instructions d'actualisation d'attributs.
- 5Electronic security module (1) according to one of the claims 1 to 4, characterised in that it comprises a time determining module (109) for determining current time data, and the certification module (105a) is designed such that it generates the signature certificate using additionally the determined time data. Elektronisches Sicherheitsmodul (1) nach einem der Ansprüche 1 bis 4, dadurch gekennzeichnet, dass es ein Zeitbestimmungsmodul (109) zur Bestimmung von aktuellen Zeitangaben umfasst, und dass das Zertifizierungsmodul (105a) so beschaffen ist, dass es das Signaturzertifikat zudem aus den bestimmten Zeitangaben erzeugt. Module de sécurité électronique (1) selon l'une des revendications 1 à 4, caractérisé en ce qu'il comprend un module de détermination de temps (109) pour la détermination d'indications actuelles de temps et en ce que le module de certification (105a) est réalisé de sorte qu'il génère le certificat de signature en outre à partir des indications définies de temps.
- 6Electronic security module (1) according to one of the claims 1 to 5, characterised in that the signature module (105) is designed such that it generates the digital customer signature from a first fingerprint of the object data to be signed, in that the certification module (1 05a) is designed such that it generates the signature certificate using additionally the first fingerprint, when generating the signature certificate it generates a second fingerprint from the data to be used for the generation of the signature certificate, it generates a digital certificate signature from the generated second fingerprint using the private key (104) of the security provider, and it forms the signature certificate from the generated certificate signature and from the generated second fingerprint. Elektronisches Sicherheitsmodul (1) nach einem der Ansprüche 1 bis 5, dadurch gekennzeichnet, dass das Signierungsmodul (105) so beschaffen ist, dass es die digitale Kundensignatur aus einem ersten Fingerprint der zu signierenden Objektdaten erzeugt, dass das Zertifizierungsmodul (105a) so beschaffen ist, dass es das Signaturzertifikat zudem aus dem ersten Fingerprint erzeugt, dass es bei der Erzeugung des Signaturzertifikats einen zweiten Fingerprint aus den für die Erzeugung des Signaturzertifikats zu verwendenden Daten erzeugt, dass es aus dem erzeugten zweiten Fingerprint mit dem privaten Schlüssel des Sicherheitsanbieters (104) eine digitale Zertifikatsignatur erzeugt, und dass es das Signaturzertifikat aus der erzeugten Zertifikatsignatur und dem erzeugten zweiten Fingerprint bildet. Module de sécurité électronique (1) selon l'une des revendications 1 à 5, caractérisé en ce que le module de signature (105) est réalisé de sorte qu'il génère la signature numérique du client à partir d'une première empreinte digitale des données d'objet à signer, en ce que le module de certification (105a) est réalisé de sorte qu'il génère le certificat de signature en outre à partir de la première empreinte digitale, en ce que lors de la génération du certificat de signature, il génère une seconde empreinte digitale à partir des données utilisées pour la génération du certificat de signature, en ce qu'il génère à partir de la seconde empreinte digitale générée avec la clé privée du fournisseur de service de sécurité (104) une signature de certificat numérique et en ce qu'il forme le certificat de signature à partir de la signature de certificat générée et de la seconde empreinte digitale généré.
- 7Electronic security module (1) according to one of the claims 1 to 6, characterised in that it comprises a key administration module (110) for receiving key administration instructions and for activating, deactivating and updating the keys stored in the electronic data store (10) based on received key administration instructions. Elektronisches Sicherheitsmodul (1) nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass es ein Schlüsselverwaltungsmodul (110) umfasst zum Entgegennehmen von Schlüsselverwaltungsinstruktionen und zum Aktivieren, Deaktivieren und Aktualisieren der im elektronischen Datenspeicher (10) gespeicherten Schlüssel basierend auf entgegengenommenen Schlüsselverwaltungsinstruktionen. Module de sécurité électronique (1) selon l'une des revendications 1 à 6, caractérisé en ce qu'il comprend un module de gestion de clé (110) pour la réception d'instructions de gestion de clé et pour l'activation, la désactivation et l'actualisation des clés stockées dans la mémoire de données électronique (10) en se basant sur les instructions de gestion de clé réceptionnées. '
- 8Electronic security module (1) according to one of the claims 1 to 7, characterised in that it is designed as a chipcard, in particular a SIM card. Elektronisches Sicherheitsmodul (1) nach einem der Ansprüche 1 bis 7, dadurch gekennzeichnet, dass es als Chipkarte, insbesondere als SIM-Karte ausgestaltet ist. Module de sécurité électronique (1) selon l'une des revendications 1 à 7, caractérisé en ce qu'il est configuré comme une carte à puce, en particulier comme une carte SIM.
- 9Dispositif électronique (4) comprenant - un premier module de sécurité électronique (41) avec une première mémoire de données électronique (410),- une clé de client privée secrète (102) stockée dans la première mémoire de données électronique (410), d'une première paire de clés numériques qui se composent de la clé de client (102) privée secrète et d'une clé client publique (101) et- un module de signature (105) logé dans le premier module de sécurité (41) pour la génération d'une signature numérique de client à partir de données d'objets à signer avec la clé de client privée (102), caractérisé par- un second module de sécurité électronique (42) avec une seconde mémoire électronique de données (420),- une seconde paire de clés numériques stockées dans la seconde mémoire électronique de données numériques (420), qui se composent de la clé privée secrète d'un fournisseur de service de sécurité (103) et d'une clé publique du fournisseur de services de sécurité (104)- un module d'authentification (423) logé dans le second module de sécurité (42) permettant l'authentification de la clé publique de client (101),- un module de vérification (421) logé dans le second module de sécurité (42) permettant la réception de la signature de client, la réception des données d'objet utilisées pour la génération de la signature client et permettant la vérification de la signature client en utilisant la clé de client publique authentifiée (101) et les objets de données réceptionnés et utilisés pour générer la signature de client, et- un module de certification (422) logé dans le second module de sécurité (42) pour la génération d'un certificat de signature numérique à partir de la signature client vérifiée avec la clé privée du fournisseur de service de sécurité (104). Electronic device (4), comprising:- a first electronic security module (41), with a first electronic data store (410),- a secret private customer key (102), stored in the first electronic data store (410), of a first digital key pair consisting of the secret private customer key (102) and a public customer key (101), and- a signature module (105), installed in the first security module (41), for generating, using the private customer key (102), a digital customer signature from object data to be signed, characterised by: - a second electronic security module (42) with a second electronic data store (420),- a second digital key pair, stored in the second electronic data store (420), consisting of a public key (103) of a security provider and a secret private key (104) of the security provider,- an authentication module (423), installed in the second security module (42), for authenticating the public customer key (101),- a verification module (421), installed in the second security module (42), for receiving the customer signature, for receiving the object data used for generating the customer signature, and for verifying the customer signature using the authenticated public customer key (101) and the received object data used for generating the customer signature, and- a certification module (422), installed in the second security module (42), for generating a digital signature certificate from the verified customer signature using the private key (104) of the security provider. Elektronische Vorrichtung (4), umfassend: - ein erstes elektronisches Sicherheitsmodul (41), mit einem ersten elektronischen Datenspeicher (410),- einen im ersten elektronischen Datenspeicher (410) gespeicherten geheimen privaten Kundenschlüssel (102) eines ersten digitalen Schlüsselpaars, das aus dem geheimen privaten Kundenschlüssel (102) und einem öffentlichen Kundenschlüssel (101) besteht, und- ein im ersten Sicherheitsmodul (41) angebrachtes Signierungsmodul (105) zum Erzeugen einer digitalen Kundensignatur aus zu signierenden Objektdaten mit dem privaten Kundenschlüssel (102), gekennzeichnet, durch: - ein zweites elektronisches Sicherheitsmodul (42) mit einem zweiten elektronischen Datenspeicher (420),- ein im zweiten elektronischen Datenspeicher (420) gespeichertes zweites digitales Schlüsselpaar, bestehend aus einem öffentlichen Schlüssel eines Sicherheitsanbieters (103) und aus einem geheimen privaten Schlüssel des Sicherheitsanbieters (104),- ein im zweiten Sicherheitsmodul (42) angebrachtes Authentifizierungsmodul (423) zum Authentifizieren des öffentlichen Kundenschlüssels (101),- ein im zweiten Sicherheitsmodul (42) angebrachtes Verifizierungsmodul (421) zum Entgegennehmen der Kundensignatur, zum Entgegennehmen der zum Erzeugen der Kundensignatur verwendeten Objektdaten und zur Verifizierung der Kundensignatur unter Verwendung des authentifizierten öffentlichen Kundenschlüssels (101) und der entgegengenommenen zum Erzeugen der Kundensignatur verwendeten Objektdaten, und- ein im zweiten Sicherheitsmodul (42) angebrachtes Zertifizierungsmodul (422) zum Erzeugen eines digitalen Signaturzertifikats aus der verifizierten Kundensignatur mit dem privaten Schlüssel des Sicherheitsanbieters (104).
- 10Dispositif électronique (4) selon la revendication 9, caractérisé en ce que le second module de sécurité (42) comprend une identification de client (106) stockée dans la seconde mémoire de données électronique (420) et en ce que le module de certification (422) est réalisé de sorte qu'il génère le certificat de signature en outre à partir de l'identification client (106). Electronic device (4) according to claim 9, characterised in that the second security module (42) comprises a customer identification (106) stored in the second electronic data store (420), and the certification module (422) is designed such that it generates the signature certificate using additionally the customer identification (106). Elektronische Vorrichtung (4) nach Anspruch 9, dadurch gekennzeichnet, dass das zweite Sicherheitsmodul (42) eine im zweiten elektronischen Datenspeicher (420) gespeicherte Kundenidentifizierung (106) umfasst, und dass das Zertifizierungsmodul (422) so beschaffen ist, dass es das Signaturzertifikat zudem aus der Kundenidentifizierung (106) erzeugt.
- 11Dispositif électronique (4) selon l'une des revendications 9 ou 10, caractérisé en ce que le second module de sécurité (42) comprend des attributs personnels de client (107) stockées dans la seconde mémoire de données électronique (420) et en ce que le module de certification (422) est réalisé de manière à générer le certificat de signature en outre à partir des attributs de client (107). Electronic device (4) according to one of the claims 9 or 10, characterised in that the second security module (42) comprises personal customer attributes (107) stored in the second electronic data store (420), and the certification module (422) is designed such that it generates the signature certificate using additionally the customer attributes (107). Elektronische Vorrichtung (4) nach einem der Ansprüche 9 oder 10, dadurch gekennzeichnet, dass das zweite Sicherheitsmodul (42) im zweiten elektronischen Datenspeicher (420) gespeicherte persönliche Kundenattribute (107) umfasst, und dass das Zertifizierungsmodul (422) so beschaffen ist, dass es das Signaturzertifikat zudem aus den Kundenattributen (107) erzeugt.
- 12Dispositif électronique (4) selon la revendication 11, caractérisé en ce que le second module de sécurité (42) comprend un module d'actualisation d'attribut (108) pour la réception d'instructions d'actualisation d'attributs et pour l'actualisation des attributs de client (107) en se basant sur des instructions d'actualisation d'attributs réceptionnées. Electronic device (4) according to claim 11, characterised in that the second security module (42) comprises an attribute updating module (108) for receiving attribute updating instructions and for updating the customer attributes (107) based on received attribute updating instructions. Elektronische Vorrichtung (4) nach Anspruch 11, dadurch gekennzeichnet, dass das zweite Sicherheitsmodul (42) ein Attributaktualisierungsmodul (108) umfasst zur Entgegennahme von Attributaktualisierungsinstruktionen und zur Aktualisierung der Kundenattribute (107) basierend auf entgegengenommenen Attributaktualisierungsinstruktionen.
- 13Dispositif électronique (4) selon l'une des revendications 9 à 12, caractérisé en ce qu'il comprend un module de détermination de temps (109) pour la détermination d'indications actuelles de temps et en ce que le module de certification (422) est réalisé de sorte qu'il génère le module de signature en outre à partir des indications définies de temps Electronic device (4) according to one of the claims 9 to 12, characterised in that it comprises a time determining module (109) for determining current time data, and the certification module (422) is designed such that it generates the signature certificate using additionally the determined time data. Elektronische Vorrichtung (4) nach einem der Ansprüche 9 bis 12, dadurch gekennzeichnet, dass sie ein Zeitbestimmungsmodul (109) zur Bestimmung von aktuellen Zeitangaben umfasst und dass das Zertifizierungsmodul (422) so beschaffen ist, dass es das Signaturzertifikat zudem aus den bestimmten Zeitangaben erzeugt.
- 14Dispositif électronique (4) selon l'une des revendications 9 à 13, caractérisé en ce que le module de signature (105) est réalisé de sorte qu'il génère la signature numérique de client à partir de la première empreinte digitale des données d'objets à signer, en ce que le module de certification (422) est réalisé de sorte qu'il génère le certificat de signature en outre à partir de la première empreinte digitale, en ce qu'il génère lors de la génération du certificat de signature une seconde empreinte digitale à partir des données à utiliser pour la génération du certificat de signature, en ce qu'il génère à partir de la seconde empreinte digitale réalisée avec la clé privée du fournisseur de service de sécurité (104) une signature numérique de certificat et en ce qu'il forme le certificat de signature à partir de la signature produite de certificat et de la seconde empreinte digitale générée. Electronic device (4) according to one of the claims 9 to 13, characterised in that the signature module (105) is designed such that it generates the digital customer signature from a first fingerprint of the object data to be signed, in that the certification module (422) is designed such that it generates the signature certificate using additionally the first fingerprint, when generating the signature certificate it generates a second fingerprint from the data to be used for the generation of the signature certificate, it generates a digital certificate signature from the generated second fingerprint using the private key (104) of the security provider, and it forms the signature certificate from the generated certificate signature and from the generated second fingerprint. Elektronische Vorrichtung (4) nach einem der Ansprüche 9 bis 13, dadurch gekennzeichnet, dass das Signierungsmodul (105) so beschaffen ist, dass es die digitale Kundensignatur aus einem ersten Fingerprint der zu signierenden Objektdaten erzeugt, dass das Zertifizierungsmodul (422) so beschaffen ist, dass es das Signaturzertifikat zudem aus dem ersten Fingerprint erzeugt, dass es bei der Erzeugung des Signaturzertifikats einen zweiten Fingerprint aus den für die Erzeugung des Signaturzertifikats zu verwendenden Daten erzeugt, dass es aus dem erzeugten zweiten Fingerprint mit dem privaten Schlüssel des Sicherheitsanbieters (104) eine digitale Zertifikatsignatur erzeugt, und dass es das Signaturzertifikat aus der erzeugten Zertifikatsignatur und dem erzeugten zweiten Fingerprint bildet.
- 15Dispositif électronique (4) selon l'une des revendications 9 à 14, caractérisé en ce que le second module de sécurité (42) comprend un module de gestion de clé (110) pour la réception d'instructions de gestion de clé et pour l'activation, la désactivation et l'actualisation des clés stockées dans le dispositif électronique (4) en se basant sur des instructions réceptionnées de gestion de clé. Electronic device (4) according to one of the claims 9 to 14, characterised in that the second security module (42) comprises a key administration module (110) for receiving key administration instructions and for activating, deactivating and updating the keys stored in the electronic device (4) based on received key administration instructions. Elektronische Vorrichtung (4) nach einem der Ansprüche 9 bis 14, dadurch gekennzeichnet, dass das zweite Sicherheitsmodul (42) ein Schlüsselverwaltungsmodul (110) umfasst zur Entgegennahme von Schlüsselverwaltungsinstruktionen und zum Aktivieren, Deaktivieren und Aktualisieren der in der elektronischen Vorrichtung (4) gespeicherten Schlüssel basierend auf entgegengenommenen Schlüsselverwaltungsinstruktionen.
- 16Dispositif électronique (4) selon l'une des revendications 9 à 15, caractérisé en ce qu'au moins l'un des module de sécurité (41, 42) sont réalisés comme un module portable qui est relié de manière amovible au dispositif électronique (4). Electronic device (4) according to one of the claims 9 to 15, characterised in that at least one of the two security modules (41, 42) is designed as a portable module, which is removably connected to the electronic device (4). Elektronische Vorrichtung (4) nach einem der Ansprüche 9 bis 15, dadurch gekennzeichnet, dass mindestens eines der beiden Sicherheitsmodule (41, 42) als tragbares Modul ausgestaltet ist, das entfernbar mit der elektronischen Vorrichtung (4) verbunden ist.
- 17Cryptographic security method, - in which security method a secret private customer key (102) of a first digital key pair, consisting of the secret private customer key (102) and a public customer key (101), is stored in an electronic device (1, 4),- in which security method, in the electronic device (1, 4) using the private customer key (102), a digital customer signature is generated from the object data to be signed, and- in which security method, using a secret private key of a second digital key pair, consisting of the secret private key of a security provider (104) and a public key of the security provider (104), a digital signature certificate is generated from the customer signature, characterised in that the secret private key of the second digital key pair is stored in the electronic device (1, 4), and in that the digital signature certificate is generated in the electronic device (1, 4). Kryptographisches Sicherheitsverfahren, - in welchem Sicherheitsverfahren in einer elektronischen Vorrichtung (1, 4) ein geheimer privater Kundenschlüssel (102) eines ersten digitalen Schlüsselpaars, das aus dem geheimen privaten Kundenschlüssel (102) und einem öffentlichen Kundenschlüssel (101) besteht, gespeichert wird,- in welchem Sicherheitsverfahren in der elektronischen Vorrichtung (1, 4) mit dem privaten Kundenschlüssel (102) eine digitale Kundensignatur aus zu signierenden Objektdaten erzeugt wird, und- in welchem Sicherheitsverfahren mit einem geheimen privaten Schlüssel eines zweiten digitalen Schlüsselpaars, das aus dem geheimen privaten Schlüssel eines Sicherheitsanbieters (104) und einem öffentlichen Schlüssel des Sicherheitsanbieters (103) besteht, ein digitales Signaturzertifikat aus der Kundensignatur erzeugt wird, dadurch gekennzeichnet, dass der geheime private Schlüssel des zweiten digitalen Schlüsselpaars in der elektronischen Vorrichtung (1, 4) gespeichert wird, und dass das digitale Signaturzertifikat in der elektronischen Vorrichtung (1, 4) erzeugt wird. Procédé de sécurité cryptographique - procédé de sécurité dans lequel une clé de client (102) privée secrète d'une première paire de clé numérique est stockée dans un dispositif électronique (1, 4), la paire se composant de la clé de client privée secrète (102) et d'une clé publique de client (101),- procédé de sécurité dans lequel une signature numérique de client est générée à partir des objets de données à signer dans le dispositif électronique (1, 4) avec la clé privée de client (102), et- procédé de sécurité dans lequel avec une clé privée secrète d'une seconde paire de clés numériques qui se compose de la clé privée secrète d'un fournisseur de sécurité (104) et d'une clé publique du fournisseur de sécurité (103), il est généré un certificat numérique de signature à partir de la signature de client, caractérisé en ce que la clé secrète privée de la seconde paire numérique de clé est stockée dans le dispositif électronique (1, 4), et en ce que le certificat de signature numérique est généré dans le dispositif électronique (1, 4).
- 18Procédé de sécurité selon la revendication 17, caractérisé en ce que dans le dispositif électronique (1, 4) avant la génération du certificat numérique de signature, la clé publique de client (101) est authentifiée et la signature de client est vérifiée en utilisant la clé authentifiée publique de client (101) et des données d'objet utilisées pour la génération de la signature de client. Security method according to claim 17, characterised in that the public customer key (101) is authenticated in the electronic device (1, 4) before generation of the digital signature certificate, and the customer signature is verified using the authenticated public customer key (101) and the object data used for generating the customer signature. Sicherheitsverfahren nach Anspruch 17, dadurch gekennzeichnet, dass in der elektronischen Vorrichtung (1, 4) vor der Erzeugung des digitalen Signaturzertifikats der öffentliche Kundenschlüssel (101) authentifiziert wird und die Kundensignatur unter Verwendung des authentifizierten öffentlichen Kundenschlüssels (101) und der zum Erzeugen der Kundensignatur verwendeten Objektdaten verifiziert wird.
- 19Procédé de sécurité selon l'une des revendications 17 ou 18, caractérisé en ce que dans le dispositif électronique (1, 4), il est stocké une identification de client (106) et en ce que le certificat de signature est généré en outre à partir de l'identification de client (106). Security method according to one of the claims 17 or 18, characterised in that a customer identification (106) is stored in the electronic device (1, 4), and the signature certificate is generated using additionally the customer identification (106). Sicherheitsverfahren nach einem der Ansprüche 17 oder 18, dadurch gekennzeichnet, dass in der elektronischen Vorrichtung (1, 4) eine Kundenidentifizierung (106) gespeichert wird und dass das Signaturzertifikat zudem aus der Kundenidentifizierung (106) erzeugt wird.
- 20Procédé de sécurité selon l'une des revendications 17 à 19, caractérisé en ce que dans le dispositif électronique (1, 4), il est stocké des attributs personnels de client (107) et en ce que le certificat de signature est généré en outre à partir des attributs de client (107). Security method according to one of the claims 17 to 19, characterised in that personal customer attributes (107) are stored in the electronic device (1, 4), and the signature certificate is generated using additionally the customer attributes (107). Sicherheitsverfahren nach einem der Ansprüche 17 bis 19, dadurch gekennzeichnet, dass in der elektronischen Vorrichtung (1, 4) persönliche Kundenattribute (107) gespeichert werden, und dass das Signaturzertifikat zudem aus den Kundenattributen (107) erzeugt wird.
- 21Procédé de sécurité selon la revendication 20, caractérisé en ce que dans le dispositif électronique (1, 4), il est réceptionné des instructions d'actualisation d'attribut et en ce que les attributs de client (107) sont actualisés en se basant sur des instructions réceptionnées d'actualisation d'attribut. Security method according to claim 20, characterised in that attribute updating instructions are received in the electronic device (1, 4), and the customer attributes (107) are updated based on received attribute updating instructions. Sicherheitsverfahren nach Anspruch 20, dadurch gekennzeichnet, dass in der elektronischen Vorrichtung (1, 4) Attributaktualisierungsinstruktionen entgegengenommen werden und dass die Kundenattribute (107) basierend auf entgegengenommenen Attributaktualisierungsinstruktionen aktualisiert werden.
- 22Procédé de sécurité selon l'une des revendications 17 à 22 , caractérisé en ce que dans le dispositif électronique (1, 4), des indications actuelles de temps sont définies et en ce que le certificat de signature est généré en outre à partir des indications définies de temps. Security method according to one of the claims 17 to 22, characterised in that current time data are determined in the electronic device (1, 4), and the signature certificate is generated using additionally the determined time data. Sicherheitsverfahren nach einem der Ansprüche 17 bis 22, dadurch gekennzeichnet, dass in der elektronischen Vorrichtung (1, 4) aktuelle Zeitangaben bestimmt werden und dass das Signaturzertifikat zudem aus den bestimmten Zeitangaben erzeugt wird.
- 23Procédé de sécurité selon l'une des revendications 17 à 22, caractérisé en ce que la signature numérique de client est générée à partir d'une première empreinte digitale des données d'objet à signer et en ce que le certificat de signature est généré en outre à partir des indications définies de temps, en ce que lors de la génération du certificat de signature, il est généré une seconde empreinte digitale à partir des données à utiliser pour la génération de la signature de certificat, en ce qu'à partir de la seconde empreinte digitale, il est généré avec la clé privée du fournisseur de sécurité (104) une signature numérique de certificat et en ce que le certificat de signature est formé à partir de la signature de certificat générée et de la seconde empreinte digitale générée. Security method according to one of the claims 17 to 22, characterised in that the digital customer signature is generated from a first fingerpnnt of the object data to be signed, furthermore the signature certificate is generated from the first fingerprint, when generating the signature certificate a second fingerprint is generated from the data to be used for the generation of the signature certificate, a digital certificate signature is generated from the generated second fingerprint using the private key (104) of the security provider, and the signature certificate is formed from the generated certificate signature and from the generated second fingerprint. Sicherheitsverfahren nach einem der Ansprüche 17 bis 22, dadurch gekennzeichnet, dass die digitale Kundensignatur aus einem ersten Fingerprint der zu signierenden Objektdaten erzeugt, dass das Signaturzertifikat zudem aus dem ersten Fingerprint erzeugt wird, dass bei der Erzeugung des Signaturzertifikats ein zweiter Fingerprint aus den für die Erzeugung des Signaturzertifikats zu verwendenden Daten erzeugt wird, dass aus dem erzeugten zweiten Fingerprint mit dem privaten Schlüssel des Sicherheitsanbieters (104) eine digitale Zertifikatsignatur erzeugt wird, und dass das Signaturzertifikat aus der erzeugten Zertifikatsignatur und dem erzeugten zweiten Fingerprint gebildet wird.
- 24Procédé selon l'une des revendications 17 à 23, caractérisé en ce que dans le dispositif électronique (1, 4), il est réceptionné des instructions de gestion de clé et en ce que les clés stockées dans le dispositif électronique sont activées, désactivées ou actualisées en se basant sur des instructions de gestion de clé réceptionnées. Security method according to one of the claims 17 to 23, characterised in that key administration instructions are received in the electronic device (1, 4), and the keys stored in the electronic device are activated, deactivated or updated based on received key administration instructions. Sicherheitsverfahren nach einem der Ansprüche 17 bis 23, dadurch gekennzeichnet, dass in der elektronischen Vorrichtung (1, 4) Schlüsselverwaltungsinstruktionen entgegengenommen werden, und dass die in der elektronischen Vorrichtung gespeicherten Schlüssel basierend auf entgegengenommenen Schlüsselverwaltungsinstruktionen aktiviert, deaktiviert oder aktualisiert werden.
Independent claims24
65 paragraphs in 1 section, as filed
Technical field
The present invention relates to a cryptographic security procedures and for suitable electronic devices, in particular portable electronic security modules. The invention relates in particular a cryptographic security procedures and ensure appropriate electronic Devices in which a secret private customer key a digital key pair consisting of the secret private customer key and a public customer key is, is stored and in which a digital customer signature from object data to be signed with the private customer key is generated.
State of the art
The generation of digital signatures or electronic signatures and signatures, as they are also known, by means of cryptographic Method is generally known. Conventionally, by means of a hash function To signing a characteristic data set, a so-called fingerprint of the obtained object data. The object data are, for example, a digital Data or text file. The fingerprint is the part of the object data, which for the Generating the digital signature is used. The digital signature is by an asymmetric encryption method from the fingerprint recovered. Asymmetric encryption methods are characterized in that for the encryption and for the decryption respectively different digital keys are used: a public key (Public Key) and a secret private key (private key). The digital Signature to be signed object data is the by encrypting Fingerprints generated with the private key of the signer.
For ensuring and monitoring the binding of a public Key to the identity of a (legal) person are certificates for public uses keys, called public key certificates. A Public Key Certificate is generated by the fact that the public key of the key holder together with an identification of this key holder by a security provider, called a Certificate Authority, electronically is signed. That is, from the public key and the identification a fingerprint is generated and the fingerprint is private with the Key of the security provider is encrypted. For the verification of digital Signatures are publicly accessible through the security provider Certificate directories (Directories Certificate) provided with public key certificates. These directories are also CRL of revoked certificates led (Revocation Lists). The cost of these by the security provider operated infrastructure (Public Key Infrastructure, PKI) are typically the key holders, ie the customer of the security provider, charged.
In known applications, the digital key pair, a Signature module for generating a digital signature with the private Key, and an optional public key certificate portable stored respectively implemented electronic security modules. For increased security, the private key is generated often directly in the security module and need this never leave. Such security modules in usually are designed as smart cards, have by their users only then with an electronic device, such as a communication terminal, be connected when object data at transaction with a digital Signature must be provided. The object data can then, together with the digital signature and optional with the public key certificate be transmitted to a receiver. The receiver must first Check the certificate of the public key and the identity of the sender determine and then verify the signature, that is the accuracy of the check signature. If the object data no certificate of public Key was attached, the beneficiary must this certificate obtain from a certificate directory and to be sure the CRLs consult. If the sender's identity and determines the correctness was found the digital signature, have additional transaction-specific be requested and checked attributes of the sender before the question They may be settled. Examples of such specific sender Attributes include financial information will as payment mode, Bank account, credit card number, credit lines or credit, validity attributes such expiration date, update or validity, further identification information such as customer number, membership number, employee number or ID or authorization information such as tickets, passes or other access and user rights.
The known security mechanisms and above Security modules have several drawbacks. For example, the Infrastructure for public certificates (PKI) rather expensive and the Customers are often unwilling the resulting running costs take. In addition, make also transactions that these known Security mechanisms and security modules use, often as complicated as for the procurement of public certificates and verification the transaction-specific attributes of the sender and additional steps Data transfers between multiple communication partners are necessary. Finally, the certificates for the public keys of a static Nature, because they typically generated once and then, over a long period be, used, for example, over several years, which risk the of abuse raised by unauthorized third parties.
The document XP002210349, "A Multiple Signature Verification Certificate Scheme ", Proceedings of BAS'98, The Third Symposium on Computer Networks, 25th-26th June 1998 Izmir, Turkey, has been of A. Levi et al. a procedure described, in which the integrity and correctness of a first digital Signature is improved in that the first digital signature with turn a second digital signature, a so-called nested Signature provided becomes. Here is a nested signature as a digital signature from the first digital signature generated, that is, the Nested Signature is by encrypting the first digital signature using a private key of a Instance that characterized the integrity and correctness of the first digital signature Reaffirms generated.
Summary of the Invention
It is an object of the present invention, a new cryptographic Safety procedures and for suitable electronic devices propose that not the disadvantages of the prior art exhibit.
According to the present invention, these objectives, in particular achieved by the elements of the independent claims. Further advantageous Embodiments follow moreover from the dependent claims and the description.
In cryptographic security procedures and in suitable electronic devices is a secret private customer key a first digital key pair, the private from the secret Customer key and a public customer key is stored and with the private customer key is to be signed from object data generates a digital customer signature.
The skilled person will understand that in the electronic devices each saved several such secret private customer key can be and that of the customers each one of them for the Processes described below can be selected.
The above objectives are by the present invention in particular achieved in the electronic device, a secret private key of a second digital key pair from the secret private key of a security provider and a contracting Key of the security provider exists, is stored, and in that the electronic device with the private key of the security provider a digital signature certificate from the customer signature is generated, preferably from a fingerprint, in particular from a hash, the customer signature. The provision of the signing certificate, which by electronically signing the customer signature using the private key of the security provider is produced, has the advantage that the customer signature by the security provider can be certified without the infrastructure of the security provider taken to generate the signature certificate in claim must be and no additional data requests concerning the Signing certificate Certificate directories are required. As long as the Customer signature and the signature certificate in immediate succession by a indivisible process is generated, ensuring that the correct certified customer signature using the private key of the security provider becomes. The dynamic generation of the signature certificate has the advantage, that there will always be regenerated and that safety, for example, in comparison with a static public key certificate is increased.
In one version is in the electronic device before generating the digital signature certificate of the public customer key authenticated and the customer signature is generated using the authenticated public customer key and for generating the Customer signature used object data, for example, the hash of the object data, Verified. The authentication of the public key and the Verification of customer signature before generating the digital signature certificate have the advantage that the customer signature and the signature certificate may be produced by separate processes, without the Safety is compromised. This design variants are possible, where the customer signature and the signature certificate by processes in two different physical units are produced, for example, in different electronic security modules such as smart cards via communication links connected with each other in an electronic device are.
Preferably, in the electronic device is a customer identification stored and the signing certificate is also from the customer identification generated. By generating the signature certificate from a fingerprint of the customer signature and the customer identification, a ensures certified integration of the identity of the customer to the customer signature are without the infrastructure of the security provider in claim must be taken.
Preferably, personal in the electronic device stored customer attributes and the signing certificate is also from the generated customer attributes. By generating the signature certificate from a Fingerprint customer signature and the customer attributes, a certified ensures connection of customer attributes to the customer signature be taken without the infrastructure of the security provider in claim must become. In addition, the certified client attributes together the customer signature, the signature certificate and the object data be sent directly to the recipient, so that further steps and Data transfers to the location and transfer of customer attributes unnecessary.
Preferably, in the electronic device attribute updating instructions are received and the customer attributes updated based on, accepted attribute updating instructions. By connecting the electronic device with a data terminal or with a communication module can thus customer attributes locally in a service job or the remotely controlled via a communication network, are constantly updated.
In one embodiment are in the electronic device determined current time information and the signature certificate is also made generates certain times. By generating the signature certificate of a fingerprint of the customer signature and the current times , a certified integration of the current time information about the timing the generation of the customer signature can be ensured to the customer signature. This has the advantage that it can be ensured that the customers signature was newly created and used, and not merely an old copy. moreover can a certified transaction date are recorded.
In one embodiment the signing certificate is also made the fingerprint of the object data to be signed generated which for the production the digital customer signature is used. Preferably, in the Generating the signature certificate, a further fingerprint from the production the signature certificate data to be used (the certificate data) generated, from the generated fingerprint is another with the private key the security provider generates a digital signature certificate, and the is signing certificate from the certificate generated signature and the generated further fingerprint formed. By generating the signature certificate from a fingerprint to be used for the generation of the signature certificate Certificate data, in particular the fingerprint of the customer signature, the customer identification, the customer attributes, the current time information and the fingerprint the object to be signed data, a certified integration of these Data to ensure the customer signature.
Preferably, in the electronic device to be key management instructions received and the electronic in Device stored keys are based on, accepted Key Management instructions enabled, disabled, or updated. By connecting the electronic device with a data terminal or with a communication module can thus stored key locally in an office of the security provider, respectively by the security provider preferably managed remotely via a communication network will. This allows the digital keys periodically or when required be changed or blocked individually, thereby increasing safety becomes.
The suitable for the present cryptographic security procedures electronic devices include especially portable electronic security modules, such as smart cards.
Brief Description of Drawings
An embodiment of the present invention is based to an example. The example of the execution by the following attached figures illustrate:<sl><li>1 shows a block diagram schematically a with a Communication terminal connected portable electronic security module and a further electronic device with a first and a represents the second electronic security module, which communication network via a with a control center of a security provider and a terminal a party to a transaction can be connected.</li><li>Figure 2 shows a time chart schematically showing the process sequence the example of a purchase order transaction for the case illustrated, in which the customer signature and the signature certificate by an integral process are generated in a security module.</li><li>Figure 3 shows a time chart schematically showing the process sequence the example of a purchase order transaction for the case illustrated, in which the customer signature and the signature certificate by separate processes in two different security modules are produced.</li></sl>
WAYS OF CARRYING OUT OF THE INVENTION
In Figures 1, 2 and 3 are corresponding to each other, the same Components designated by the same reference numerals.
As a customer, the owner and user of the following below Security modules described designated. The security provider is hereinafter the same as the certificate described in the introduction Authority.
In the figure 1, reference numeral 2 a to the communication network 3 connectable communication terminal. The communication network 3 includes a mobile telephone network and / or a fixed network. The mobile network is for example a GSM (Global System for Mobile Communication) or a UMTS network (Universal Mobile Telephone System) or another, for example, satellite-based mobile radio network. The fixed network is for example the public switched telephone network, an ISDN network (Integrated Services Digital Network) or the Internet. Accordingly, the communication terminal 2 is a mobile phone or a laptop, PDA computers (Personal Digital Assistant) having a communication module for communication via a Mobile network, or a communication terminal having a communication module for communication via a fixed network, such as a PC (Personal Computer).
In the figure 1, reference numeral 1 denotes a portable electronic Security module removably connected to the communication terminal 2 is connected. The security module 1 is connected via a contactless or a contacting interface connected to the communication terminal second The security module 1 includes at least one processor 11 and a electronic data memory 10 for storing digital data and Software programs. The security module 1 is preferably a chip card, For example, as a SIM card (Subscriber Identity Module) running.
In electronic data storage 10 are a first digital key pair, consisting of a public customer key 101 and a secret private customer key 102, and a second digital Key pair consisting of a public key of the security provider 103 and a secret private key of the security provider 104 are stored. In one version can also only the secret private customer key 102 and the secret private key of Security provider 104 are stored in the data memory 10, and the public customer key and the public key of the security provider be publicly accessible stored on a server. In data storage 10 is also a customer identification 106 stored, for example, a IMSI (International Mobile Subscriber Identity) or another subscriber or user identification. To the anonymity of the customer to Transaction partners (other service providers) to maintain, is the customer identification preferably by the security vendor managed ID (or Customer Code), of the identity of the can be assigned to customers only by the security provider. In data storage 10 are also also personal customer attributes 107 stored, For example, financial information will include such payment mode, Bank account, credit card number, credit lines or credit, validity attributes such expiration date, update or validity, further identification information such as customer numbers or numbers with members transaction partners, Employee number or ID, or authorization information as tickets, passes or other access and user rights.
The security module 1 includes functional modules 105, 108, 109 and 110, preferably as programmed software modules for controlling of the processor 11 are carried out and stored in the data memory 10 are. The skilled artisan will understand that the functional modules 105, 108, 109 and 110 may be performed by hardware in whole or in part. The functional modules 105, 108, 109 and 110 comprise a signature module 105, an attribute updating module 108, a time determination module 109 and a key management module 110th
The time determination module 109 determines actual timings, which include the current date and time. The timing module 109 is fully in the security module 1 run and includes a Clock generator and setting register. The timing module 109 may also be designed as a pure programmed software module, the times the refers via the interface from the communication terminal second
The signature module 105 includes cryptographic functions to based on an asymmetric encryption method (for example, Rivest-Shamir-Adleman Encryption, RSA), a digital customer signature from to to generate object data signed using the private customer key 102nd The object to be signed data are digital data such as a digital Text or data file that from about the above-mentioned interface communication terminal 2 are received. The signature module 105 generates initially a fingerprint (eg a so-called hash) of the object data to be signed (Eg with a SHA1 hash function) and therefrom with the private Customer key 102, the digital customer signature. The signature module 105 can the fingerprint of the object data to be signed as an alternative of another module to accept. The signature module 105 stores Moreover, the determined by the time determination module 109 current times the customer signature generated from assigned.
In the figure 1, numeral 5 a headquarters of the security provider. The center 5 comprises at least one of the communication network 3-connected computer. As schematically illustrated in Figure 1 is, the Center includes 5 programmed software functions, namely Key management functions 51 for distributing and updating digital Keys of the security provider in the communication network 3 connectable security modules 1, 41, 42 and for activating newly generated Customer keys in the security modules 1, 41, 42, key lock functions 52 to disable keys in the security modules 1, 41, 42 of blocked customers, attribute management functions 53 to update, Add and delete customer attributes in the security modules 1, 41, 42, 54 archive functions for storing and making available Public Key certificates of public customer key in the center 5, and Verification functions 55 for verifying customer signatures in dispute.
The attribute updating module 108 takes over the above-mentioned Interface attribute updating instructions contrary to that in the communication terminal 2 via the communication network 3 from the center 5 of the security provider received. The attribute updating module 108 preferably includes cryptographic functions to verify that the Attribute update instructions of the legitimate Central 5 of the security provider were received. Updated attribute updating module 108 personal customer attributes 107 based on the funds received be verified and attribute updating instructions, thereby Values of customer attributes updated, added or deleted customer attributes.
The key management module 110 takes over the above-mentioned Interface key management instructions contrary to that in the communication terminal 2 via the communication network 3 from the center 5 of the security provider received. includes the key management module 110 preferably cryptographic functions to verify that the Key management instructions of the legitimate Central 5 of the security provider were received. The key management module 110 is activated, disabled and updates the stored key 101, 102, 103, 104 based on the funds received and verified key administration instructions. This allows the center 5 of the security provider public and private keys 103, 104 of the security provider distributed and renewed, newly generated public and private customer key 101, 102 is activated, and disables the digital keys for locked clients will.
The signature module 105 also includes a certification module 105a with cryptographic functions to generate a digital signature certificate from the customer signature using the private key of the security provider 104. This means comprises the certification module 105 a cryptographic Functions based on an asymmetric encryption method a digital signature (certificate signing) from the customer signature for the generation of the signature certificate to be used and further Data (certificate data) with the private key of the security provider generate 104th To be used for the generation of the signature certificate Certificate data preferably comprise in addition to the fingerprint of Customer signature further certificate data:<ul><li>the fingerprint used for generating the customer signature the to be signed object data,</li><li>Time information on the time of generation of the customer signature,</li><li>customer identification 106,</li><li>personal Kundenattribute107 and their update (Possibly including time), and</li><li>Time information on the time of generation of the signature of the Signing certificate (CSR).</li></ul>
For the generation of the signature certificate from the above said Certificate data generates the certification module 105 a first one Fingerprint (hash) of the fingerprint of the customer signature, and preferably includes the above-mentioned another certificate data. Then generated the certification module 105a, the certificate signature by encrypting previously generated fingerprints using the private key of the security provider 104. The signing certificate is obtained from the certificate signature and the Fingerprint used for this purpose formed.
In one embodiment, the certification module used 105a in the certificate data instead of the fingerprint of the customer signature and instead of the fingerprint used for customer signature directly the customer signature. In addition, no fingerprint of the certificate data is formed, but the certificate data itself is the private key of the security provider 104 encrypted. This need only this encrypted certificate data to be transmitted to a transaction partner, the customer signature can the transaction partner by the public key of the be security provider obtained from the encrypted certificate data.
In the figure 1, reference numeral 4 denotes an electronic Device, which a communications terminal 40 and two portable electronic Security modules 41 and 42 includes the non-contact each have a or a contact-type interface removably connected to the communication terminal 40 are connected. The communication terminal 40 includes a Communication module for communication via the communication network 3rd The communication terminal 40 is, for example, as a mobile phone, laptop PDA or computer or PC running.
The security modules 41 and 42 each include at least one Processor 11 and an electronic data storage 410, respectively 420 for storing digital data and software programs. The security modules 41 and 42 are preferably constructed as a chip card; the security module 41 is for example a SIM card.
In electronic data storage 410 is a digital key pair, consisting of the public customer key 101 and from the secret private customer key 102 stored. The security module comprises 41 the functional modules 105 and 109, namely, the signature module 105 and the period determination module 109. The skilled artisan understands that the public Customer key may also be included in a public key certificate.
In electronic data storage 420 is a digital key pair, consisting of the public key of the security provider 103 and from the secret private key of the security provider 104 stored. In the data storage 420 and the client identification 106 and the personal customer attributes 107 stored. The security module comprises 42 the functional modules 108, 109 and 110, namely the attribute updating module 108, the time determination module 109 and the Key Management Module 110th
The security module 42 also includes other functional modules, namely the verification module 421, the certification module 422 and the Authentication module 423, which is preferably as programmed software modules are executed to control the processor 11 and the data memory 420 are stored. The skilled artisan will understand that the functional modules 421, 422 and 423 also run completely or via the hardware part can be.
The authentication module 423 verifies the authenticity of the Customer identification and the public customer key. The authentication module 423 takes either the public customer key or the Public key certificate of the public key customers from the security module 41 opposed. The authentication module 423 checks whether the unanswered public customer key already exists in the security module 42 (Known) and not locked, or it verified the unanswered Public key certificate of the public customer key using the public Key of the security provider and controls contained therein Customer identification.
The verification module 421 accepts a digital customer signature and the object data used for generating the customer signature (either the object data or the fingerprint used the object data) from the security module 41 opposed. Using the public customer key 101, which has been verified by the authentication module 423, verifies the verification module 421 to receiving any client signature, by decrypts it and with the fingerprint of generating Object data customers signature used compares.
The functionality of the certification module 422 is similar to that the certification module 105a. The certification module 422 generates from the verified customer signature using the private key of the security provider 104 a digital signature certificate.
In the following sections with reference to Figure 2, the process flow described the example of a purchase order transaction for the case where the customer signature and the signature certificate in the security module 1 generated by an integral process.
In step S0 is optional an electronic order form from the terminal 6 of a transaction partner, ie the service provider, should be appointed by which a service, information or goods, via the communication network 3 to the communication terminal 2 of the customer transmitted. The terminal 6 of the transaction partner is for example a connected to the Internet computer. The communication between the Communication terminal 2 and the terminal 6 is effected by eg WAP (Wireless Application Protocol).
In step S1, the order data (transaction data) provided by the customer, for example, by filling out the electronic Order form, and the security module 1 for electronic Signing passed. be the customer in step S1 also those of personal Kundenattribute107 selected, the with ordering to be transmitted transaction partner (for example by means of a programmed selection module).
In step S2 in the security module 1, a fingerprint (hash) of the to be signed object data, that is, from the provided in step S1 Order data generated.
be in the security module 1 in step S3, the current times certainly.
In step S4, the customer signature is generated in the security module 1, by the generated at step S2 fingerprint ordering data the private customer key 102 is encrypted.
In step S5, the security module 1, a fingerprint (hash) of the creates customer signature generated in step S4.
(optional) in the security module 1 in step S6, the above-described further certificate data for generating the signature certificate provided. In particular, in step S6, a fingerprint (hash) is generated, the from the fingerprint generated in step S5 (hash), the customer signature, the fingerprint generated in step S2 (hash) of the order data, the in Step S3 certain times, the customer identification 106, the in Step S1 selected personal customer attributes 107, and the update date the customer attributes exists.
In step S7, in the security module 1 the prepared in step S6 Signing certificate completed by the fingerprint generated in step S6 (Hash) is encrypted with the private key of the security provider 104 will, whereby the contents of the signing certificate to digitally sign becomes. The signing certificate includes the certificate signature and the need for Fingerprint of the certificate data.
In step S8, the order data provided in step S1, the customer signature generated in the step S4 and in the steps S6 and S7 generated signing certificate through the communication terminal 2 the communication network 3 is transmitted to the terminal of the transaction partner 6th
In step S9, which is the terminal of the transaction partner 6 in the Step S8 received signature certificate verified by the public Key of the security provider is decrypted, the fingerprint of Order data is compared with the order data and the time information on the date of the customer signature is verified. Due to the verified Signing Certificate can found in the terminal of the transaction partner 6 be that the customer in question is known to the security provider if the customer due to the included customer attributes for the transaction is authorized and creditworthy, to which updated the customer attributes refreshed, and that the customer signature, if necessary is verifiable. Based on this information, it is for the transaction partners usually possible without additional clarifications delivery according trigger the ordering data.
Steps S1 to S7 for generating the customer signature, and the Signing Certificate can be made subject to the condition that the customer in the communication terminal 2 a secret code (Personal Identification Number or password) inputs.
In the following sections with reference to Figure 3, the process flow described the example of a purchase order transaction for the case where the customer signature and the signature certificate by separate Processes in the security module 41 and the security module 42 is generated.
In steps S0 to S4, as described above, in the security module 41 customer signature from the provided by the customer created order data by a fingerprint of the order data with the private customer key 102 is encrypted.
In step S10, the customer signature generated in step S4 and the public customer key, respectively, the corresponding public key certificate together with the provided in step S1 and order data the determined in step S3 current time information to the security module 42 to hand over. The selection of customer attributes is preferably only in a made later step. The current time information can also only in Security module 42 determines.
In step S11, in the authentication module 423, the authenticity the customer identification and of the margin received in step S10 public established customer key (with or without public key certificate). If no authentication can be achieved, the ordering process is aborted. Otherwise, the security module 42 the unanswered at the step S10 Customer signature verified by the customers signature with the public customer key is decrypted and the decrypted data with a fingerprint (hash) of the received data in step S10 Order is compared. If the customer signature can not be verified may, no signature certificate is generated. If the customer signature verified positive is, in step S11 by the customer and those of personal Kundenattribute107 selected, with the order to the transaction partner to be communicated and the procedure is continued in step S5.
In steps S5 to S7 in the security module 42 from the verified the signature certificate described customer signature as above generates.
In step S8, the order data provided in step S1, the customer signature generated in step S4 and the generated in step S7 Signature certificate by the communication terminal 40 via the communication network 3 transmits to the terminal the transaction partner 6 and there verified described in step S9 above the received signature certificate.
Finally, it should be noted that the use of Security modules 1, 41 and 42 is not limited to use with communication terminals 2, 40 is limited, but that they in networked as well as in are uncrosslinked electronic devices used, for example in electronic audio and video recording devices to sign Tonrespektive Image data, as well as in network gateway and proxies.
2 sheets
Sheet 1 Sheet 2
Every citation, both waysCites: the store holds 3 of 4
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN104168117A | Cited by | China | Search report |
| EP0892521A | Cites | European Patent Office (EPO) | – |
| WO0126400A | Cites | World Intellectual Property Organization (WIPO) | – |
| WO0149054A | Cites | World Intellectual Property Organization (WIPO) | – |
| LEVI A ET AL: "A Multiple Signature Based Certificate Verification Scheme" PROCEEDINGS OF BAS'98, THE THIRD SYMPOSIUM ON COMPUTER NETWORKS, 25-26 JUNE 1998, IZMIR, TÜRKIYE, [Online] 1998, Seiten 1-10, XP002210349 Gefunden im Internet: <URL:http://citeseer.nj.nec.com/cache/pape rs/cs/2506/http:zSzzSzmercan.cmpe.boun.edu .trzSz~levizSzbas98.pdf/a-multiple-signatu re-based.pdf> [gefunden am 2002-11-13] | Non-patent | – | – |
9 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 02405418 | European Patent Office (EPO) | A | |
| EP20020405418 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| EP1365537A1 | European Patent Office (EPO) | A1 | |
| US2003221104A1 | United States of America | A1 | |
| JP2004032731A | Japan | A | |
| EP1365537B1This record | European Patent Office (EPO) | B1 | |
| AT270800T | Austria | T | |
| ATE270800T1 | Austria | T1 | |
| DE50200601D1 | Germany | D1 | |
| DK1365537T3 | Denmark | T3 | |
| US7225337B2 | United States of America | B2 |
65 legal events, as 10 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Ep patent expiredExpiredMAE | MAE | FI | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Patent ceasedCeasedPL | PL | CH | |
| Ep patent expiredExpiredEUP | EUP | DK | |
| Patent expired because of reaching the maximum lifetime of a patentExpiredMK | MK | NL | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Name/firm changedPFA | PFA | CH | |
| Change of name or company nameCD | CD | FR | |
| Transmission of propertyTP | TP | FR | |
| Nl: assignments of ep-patentsNLS | NLS | EP | |
| Nl: assignments of ep-patentsNLS | NLS | EP | |
| Nl: modifications of names registered in virtue of documents presented to the patent office pursuant to art. 16 a, paragraph 1NLT1 | NLT1 | EP | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20091119 AND 20091125732E | 732E | GB | |
| Name/firm changedPFA | PFA | CH | |
| AssignmentPUE | PUE | CH | |
| AssignmentPUE | PUE | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Translation of granted ep patentGrantedTRGR | TRGR | SE | |
| Ep patent with danish claimsT3 | T3 | DK | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Designation fees paidAKX | AKX | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedGERMANFG4D | FG4D | IE | |
| New agentNV | NV | CH | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1365537
- Publication, DOCDB
- 1365537
- Publication, EPODOC
- EP1365537
- Application
- 2405418
- Application, DOCDB
- 02405418
- Application, EPODOC
- EP20020405418
Titles3
- German
- Vorrichtungen und Verfahren zur Zertifizierung von digitalen Unterschriften
- English
- Systems and method for certifying digital signatures
- French
- Systèmes et procédé servant à certifier des signatures numériques
Classification
- CPC, 7
- H04L9/3263
- H04L63/062
- H04L63/0823
- H04L9/3247
- H04L2209/56
- H04L2209/80
- G06F21/64
- IPC, 3
- G06K19 10
- H04L9 10
- H04L9 32
Designated states26
- Contracting states, 20
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye
- Extension states, 6
- Albania
- Lithuania
- Latvia
- North Macedonia
- Romania
- Slovenia
