EP1549019B1

Trusted and unsupervised digital certificate generation using a security token

Abstract

This record has no abstract on file.

EP1549019B1, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Expired 22 December 2024, 1.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

27 claims: 14 independent, 13 dependent

  1. 1
    A method for issuing a trustworthy digital certificate (260) comprising the following steps:- a security token (75) is functionally coupled to a computer system (105), said security token being in processing communications with at least a registration authority (110) via said computer system, and - said computer system sends (305;306) a digital certificate generation request (225) to said registration authority, characterized in that it further comprises the following steps: - upon reception (305;306) of said digital certificate generation request, said registration authority both: ■ performs a security transaction (310, 315, 320;311, 316) with said security token using a critical security parameter (205') securely stored in said security token, ■ sends (310;326) a PKI key pair generation command (230) to said security token, - after completion of said PKI key pair generation, said PKI key pair (235, 240) is operatively stored (315;331) in said security token and the public key (235) of said PKI key pair is sent (320;336) to said registration authority, and - upon successfulness of said security transaction (320;316), said registration authority activates (335;341) the generation of said digital certificate by a certificate authority (115) using said public key.
  2. 6
    The method according to any claim 1 to 5, wherein said digital certificate (260) includes said public key (235).
  3. 7
    The method according to any claim 1 to 6, wherein said digital certificate (260) is stored in said security token (75).
  4. 8
    The method according to any claim 1 to 7, wherein said PKI key pair (235, 240) is generated externally to said security token (75).
  5. 9
    The method according to any claim 1 to 7, wherein said PKI key pair (235, 240) is generated internally by said security token (75).
  6. 10
    The method according to any claim 1 to 9, wherein said security transaction (310, 315, 320;311, 316) comprises a challenge/response protocol, a keyed hashed message authentication code, a digital signature or a combination thereof.
  7. 11
    The method according to any claim 1 to 10, wherein said certificate authority (115) and said registration authority (110) are separate entities.
  8. 12
    The method according to any claim 1 to 10, wherein said certificate authority (115) and said registration authority (110) is a unified entity.
  9. 13
    The method according to any claim 1 to 12, wherein, upon reception (305; 306) of said digital certificate generation request (225):- said registration authority sends a first command (230) to said security token (75) which causes said PKI key pair (235, 240) to be operatively installed inside said security token, - said registration authority sends a second command (245) using a critical security parameter (205) associated with said security token to form a cryptogram, and sends said cryptogram to said security token, - said security token deciphers said cryptogram using a pre-established critical security parameter (205') operatively stored inside said security token, and returns to at least said registration authority at least one datagram derived from said cryptogram.
  10. 17
    The method according to any claim 13 to 16, wherein said second command includes a retrieve public key command.
  11. 18
    The method according to any claim 13 to 17 further including the steps of - enciphering said at least one datagram using said pre-established critical security parameter (205') by said security token (75), - deciphering said at least one datagram using said critical security parameter (205) by at least said registration authority (110).
  12. 19
    A system for issuing a trustworthy digital certificate (260) comprising a security token (75), a computer system (105) and a registration authority (110), wherein:- said security token is functionally coupled to said computer system and in processing communications with at least said registration authority via said computer system, and - said computer system is adapted to at least receive input from an entity and initiate a digital certification generation process between said security token and said registration authority by sending (305;306) a digital certificate generation request (225) to said registration authority, characterized in that : - said registration authority comprises means for, upon reception of said digital certificate generation request, both: ■ performing a security transaction (310, 315, 320;311, 316) with said security token using a critical security parameter (205') securely stored in said security token, ■ sending a PKI key pair generation command (230) to said security token, - said security token comprises means for, after completion of said PKI key pair generation, storing said PKI key pair (235, 240) and sending the public key (235) of said PKI key pair to said registration authority, and - said registration authority comprises means for, upon successfulness of said security transaction, activating the generation of said digital certificate by a certificate authority (115) using said public key.
  13. 24
    A computer program stored on a computer-readable medium containing instructions which upon execution carry out the following method step, while a security token (75) is functionally coupled to a computer system (105), said security token being in processing communications with at least a registration authority (110) via said computer system:- said computer system sends (305;306) a digital certificate generation request (225) to said registration authority, characterized in that it further contains instructions which upon execution carry out the following method steps: - upon reception (305;306) of said digital certificate generation request, said registration authority both: ■ performs a security transaction (310, 315, 320;311, 316) with said security token using a critical security parameter (205') securely stored in said security token, ■ sends (310;326) a PKI key pair generation command (230) to said security token, - after completion of said PKI key pair generation, said PKI key pair (235, 240) is securely stored (315;331) in said security token and the public key (235) of said PKI key pair is sent (320;336) to said registration authority, and - upon successfulness of said security transaction (320;316), said registration authority activates (335;341) the generation of said digital certificate by a certificate authority (115) using said public key.
  14. 27
    The computer program according to any claim 24 to 26, wherein said instructions are stored in a code format including byte code, compiled, interpreted, compliable or interpretable.