EP1432170A2

Method and apparatus for generating different cryptographic secure procedures concerning messages in a host device

Abstract

Verfahren und Anordnung zur unterschiedlichen Erzeugung kryptographischer Sicherungen von Mitteilungen in einem Hostgerät, wobei zur kryptographischen Sicherung einer Mitteilung für einen ersten Zweck eine erste Signatur zur kryptographischen Sicherung einer Mitteilung für einen zweiten Zweck eine zweite Signatur eingesetzt wird, wobei sich die Signaturen in der Art ihrer Erzeugung unterscheiden. Eine Cryptologik (20) weist eine Anzahl an Logikschaltungen (21, 22, 23) und einen Umschalter (24, 26) auf und ist extern vom postalischen Sicherheitsgerät (10) angeordnet und mindestens mit ihrem Ausgang (d) mit einem Informationseingang (i) des postalischen Sicherheitsgerätes (10) verbunden, das eine Logikschaltung (12) aufweist, die einen digitalen Signaturalgorithmus auf das vom Ausgang (d) gelieferte Ausgangssignal anwendet, um Daten für eine Signatur zu erzeugen.

EP1432170A2, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 6 November 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 8 independent, 9 dependent

  1. 1
    Method for differently generating cryptographic backups of messages in a host device, a first signature being used for cryptographically securing a message for a first purpose and a second signature for cryptographically securing a message for a second purpose, characterized in that the signatures differ in the way they are generated.
  2. 5
    Arrangement for the different generation of cryptographic backups of messages in a host device, at least with a postal security device (10), characterized in that a cryptology (20) is arranged externally from the postal security device (10) and at least its output (d) is connected to an information input (i) of the postal security device (10) and that the postal security device (10) has a logic circuit (12) which applies a digital signature algorithm to the output signal provided by output (d) to generate data for a signature.
  3. 7
    Arrangement according to claims 5 and 6, characterized in that the host-controlled cryptology (20) has a number of logic circuits (21, 22, 23) and a changeover switch (24, 26) which is controlled by the host (1).
  4. 8
    Arrangement, according to claims 5 to 7, characterized in that a first logic circuit (21) for a first crypto-algorithm and a second logic circuit (22) for a second crypto-algorithm are connected on the input side and lead on the output side to contacts (I and II) of the switch (24), the latter on the output side at the input of the second logic circuit ( 12) that generates the signature. (Fig.2)
  5. 9
    Arrangement, according to claims 5 to 7, characterized in that the postal security device (10) has a first logic circuit (11) for a first crypto-algorithm and a second logic circuit (12) which generates data for a signature that the host-controlled cryptology (20) has a second and third logic circuit (22) and (23) and a changeover switch (24), wherein the first logic circuit (11) of the postal security device (10) and the second and third logic circuits (22) and (23) are connected on the output side to the information input (i) of the postal security device (10), the information input (i) being connected to the second logic circuit (12) is connected on the input side, and that the changeover switch (24) has an input for a message (m) and contacts (I, II and III), each at the input (e 1 , e 2 , e 3 ) of the logic circuits (11, 22, 23). (Fig.5a)
  6. 10
    Arrangement, according to claims 5 to 7, characterized in that a first logic circuit (21) for a first crypto-algorithm has an input (e 1 ) for a message (m) and an exit (a 1 ) which has an input (e 3 ) for a further logic circuit (23) for a further crypto-algorithm, the output (a 3 ) is present at the information input (i) of a second logic circuit (12) of the postal security device (10), the second logic circuit (12) generating the signature.
  7. 12
    Arrangement according to claims 10 to 11, characterized in that a first and a second switch (24, 26) are provided in the host-controlled cryptology (20), the switch (24 and 26) being connected to a control data input (c 1 , c 2 ) are controllable by a host, contacts (I and II) of the switch (24) with the outputs (a 1 ) and (a 3 ) of the first and third logic circuits (21) and (23) and that the second switch (24) on the output side forms the output (d) which is connected to the information input (i) of the postal security device (10). (Fig.9)
  8. 13
    Arrangement, according to claims 5 and 6, characterized in that the postal security device (10) and the crypto logic (20) each have at least one logic circuit (11) and (23) and that the crypto logic (20) has a first host-controlled changeover switch (26) which has a key (k1, k2) for the further crypto-algorithm of the further logic circuit (23) switches over that a second PSD-controlled switch (14) is provided in the postal security device (10), contacts (I or II) of the second switch (14) with the outputs (a 1 or a 3 ) of the first and third logic circuits (11) and (23) are connected. (Fig. 10)