EP1599008B1

Method of providing a signing key for digitally signing, verifying or encrypting data

Abstract

This record has no abstract on file.

EP1599008B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 19 May 2024, 2.3 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

11 claims: 8 independent, 3 dependent

  1. 1
    Method of providing a key for digitally signing and/or verifying and/or encrypting data to be exchanged between a first party and a second party, comprising the following steps:- transmitting (M_02, M_02a) an identification code, which is uniquely identifying said first party, from said first party to a gateway (CCBS), - verifying said identification code by said gateway (CCBS) by using an authentication server (AUC), wherein existing authentication mechanisms according to the GSM, global system for mobile communications, standard are used for said step of verifying, - creating (120) a signing key by said gateway, - providing (130) said signing key to said first party and/or to said second party, said method being characterized in that said step of creating (120) comprises creating a plurality of signing keys, each of which is valid for a single use only, and in that said step of providing (130) comprises providing said signing keys to said first party and to said gateway (CCBS) after creating said signing keys, and providing a signing key to said second party from said gateway (CCBS) upon a request from said second party to said gateway (CCBS).
  2. 3
    Method according to one of the preceding claims, characterized by providing (130) a long-life signing key which may be used for a plurality of signing and authenticating transactions.
  3. 5
    Method according to one of the claims 3 to 4, characterized by storing (135, 135a) said long-life signing key and/or said plurality of signing keys and/or said extra key and/or said plurality of extra keys.
  4. 6
    Method according to one of the preceding claims, characterized by transmitting said signing key or keys and/or said extra key or keys via a short message service (SMS) of a mobile communications infrastructure and/or via a/another secure connection, to said first party and/or to said second party.
  5. 7
    Method according to one of the preceding claims, characterized by using said signing key or keys for enciphering a communication between said first party and said second party.
  6. 8
    Method according to one of the preceding claims, characterized by using said signing key or keys and/or said extra key or keys for authorizing transactions, in particular payment transactions, and/or for accessing single-sign-on services.
  7. 9
    Method according to one of the preceding claims, characterized by verifying a creditworthiness of said first party.
  8. 10
    Method according to one of the preceding claims, characterized by using a ciphering key Kc obtained by using an A8-algorithm according to the GSM standard as said signing key.
  9. 11
    Gateway (CCBS) capable of performing the method according to one of the preceding claims.