EP1599008A1

Method of providing a signing key for digitally signing, verifying or encrypting data

Abstract

The present invention relates to a method of providing a key, in particular for digitally signing, verifying or encrypting data to be exchanged between a first party and a second party, comprising steps of transmitting (100) an identification code, which is uniquely identifying said first party, from said first party to a gateway (CCBS), verifying (110) said identification code by said gateway (CCBS) by using (111) an authentication server (AUC), and creating (120) a signing key. Said method is characterized by providing (130) said signing key to said first party and/or to said second party. A transmission of said signing key via a secure communications channel, in particular via a GSM-based communications infrastructure, improves the security of payment transactions. The present invention further relates to a mobile terminal (1) and a gateway (CCBS).

EP1599008A1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 19 May 2024, 2.3 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

14 claims: 10 independent, 4 dependent

  1. 1
    Method of providing a key, in particular for digitally signing verifying or encrypting data to be exchanged between a first party and a second party, comprising the following steps:- transmitting (M_02, M_02a) an identification code, which is uniquely identifying said first party, from said first party to a gateway (CCBS), - verifying said identification code by said gateway (CCBS) by using an authentication server (AUC), - creating (120) a signing key, said method being characterized by - providing (130) said signing key to said first party and/or to said second party.
  2. 3
    Method according to one of the preceding claims, characterized by providing (130) a long-life signing key.
  3. 4
    Method according to one of the preceding claims, characterized by providing (130) a plurality of signing keys.
  4. 7
    Method according to one of the preceding claims, characterized by transmitting said signing key(s) and/or said extra key(s) via a short message service (SMS) of a mobile communications infrastructure and/or via a/another secure connection, to said first party and/or to said second party.
  5. 8
    Method according to one of the preceding claims, characterized by using said signing key for enciphering a communication between said first party and said second party.
  6. 9
    Method according to one of the preceding claims, characterized by using said signing key(s) and/or said extra key(s) for authorizing transactions, in particular payment transactions, and/or for accessing single-sign-on services.
  7. 10
    Method according to one of the preceding claims, characterized by verifying a creditworthiness of said first party.
  8. 11
    Method according to one of the preceding claims, characterized by using a ciphering key Kc obtained by using an A8-algorithm according to the GSM standard as said signing key.
  9. 12
    Mobile terminal (1) capable of performing the following steps:- transmitting (M_02) an identification code, which is uniquely identifying said mobile terminal (1) and/or a first party using said communications terminal (1), to a second party and/or a gateway (CCBS), - receiving an authentication request (M_03c) from said gateway (CCBS), - creating an authentication response (M_03d), - transmitting said authentication response (M_03d) to said gateway (CCBS), - receiving and/or creating and/or storing at least one signing key (Kc).
  10. 14
    Gateway (CCBS) capable of performing the following steps:- receiving an identification code, which is uniquely identifying a mobile terminal (1) and/or a first party using said mobile terminal (1), - verifying said identification code by using an authentication server (AUC), - creating (120) at least one signing key (Kc), - providing (130) said mobile terminal (1) and/or said first party and/or said second party with said signing key(s) and/or storing said signing key(s).