Nova Patents
EP1548665A2

Data card verification system

Abstract

A method of verifying a pair of correspondents in electronic transaction, the correspondents each including first and second signature schemes and wherein the first signature scheme is computationally more difficult in signing than verifying and the second signature scheme is computationally more difficult in verifying than signing. The method comprises the step of the first correspondent signing information according to the first signature scheme and transmitting the first signature to the second correspondent, the second correspondent verifying the first signature received from the first correspondent, wherein the verification is performed according to the first signature scheme. The second correspondent then signs information according to the second signature scheme and transmits the second signature to the first correspondent, the first correspondent verifies the second signature received from the second correspondent, wherein the verification is performed according to the second signature algorithm; the transaction is rejected if either verification fails. The method thereby allows one of the correspondents to participate with relatively little computing power while maintaining security of the transaction.

EP1548665A2, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 3 February 2018, 8.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

14 claims: 8 independent, 6 dependent

  1. 1
    A certificate sent from a first correspondent (102, 104) to a second correspondent (104,102) as a data stream during an electronic transaction conducted over a data transmission system (100), said correspondents each including respective signing and verifying algorithms of a first signature scheme and a second signature scheme different from said first scheme and utilizing an elliptic curve cryptosystem, said data stream comprising:a) a first value (122) signed by said first correspondent according to said second signature scheme;b) a second value (116) signed by a certificate authority according to said first signature scheme;whereby said second correspondent may verify the signature on said second value and thereby verify the signature on said first value.
  2. 2
    A certificate as defined in claim 1, wherein said first signature scheme is computationally more difficult in signing than verifying, while said second signature scheme is computationally more difficult in verifying than signing, thereby allowing said first correspondent to participate with relatively little computing power while maintaining security of the transaction.
  3. 3
    A certificate as defined in claim 1, wherein said first signature scheme is an RSA type scheme.
  4. 4
    A certificate as defined in claim 1, wherein said second value comprises public information of said first correspondent including a public key for use in said elliptic curve cryptosystem.
  5. 5
    A method of generating a certificate (116, 122) in a public key cryptosystem (100) comprising the steps of:a) obtaining from a correspondent public information including a public key to be utilized by said correspondent in an elliptic curve cryptosystem, said public information being related to a private key generated by said correspondent;and b) signing said public information utilizing an RSA cryptosystem.
  6. 7
    A certificate (116,122) for use in a public key cryptosystem comprising:a) public information for use in verifying a signature in an elliptic curve cryptosystem;and b) a signature on said public information performed according to an RSA cryptosystem.
  7. 9
    A certificate (116,122) signed by a certificate authority (104) according to a first signature scheme containing public information of a correspondent (102) for use in a second signature scheme different to said first signature scheme and utilizing an elliptic curve cryptosystem.
  8. 14
    A computer program comprising instructions for programming a processor to carry out all of those steps of any of claims 1 to 5 performed by one of said correspondents.