EP1969762A2

Certify and split system and method for replacing cryptographic keys

Abstract

This record has no abstract on file.

Term

0.2 yearsto projected expiry

Projected expiry 12 December 2026, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

36 claims: 8 independent, 28 dependent

  1. 1
    Claims of equivalent WO 2007102907 A2 [0094] CLAIMS 1. A method operational on a token device for replacing asymmetric cryptographic keys, comprising:obtaining a pseudorandom first key pair that comprises a first private key and a corresponding first public key;obtaining a pseudorandom spare second key pair that comprises a second private key and a second public key, signing the second public key with the first private key to obtain a signed certificate;dividing the second key pair and signed certificate into n shares, where n is an integer;and distributing the n shares to at least two shareholders for safekeeping.
  2. 11
    A token device that facilitates replacing cryptographic keys, comprising:means for obtaining a pseudorandom first key pair that comprises a first private key and a corresponding first public key;means for obtaining a pseudorandom spare second key pair that comprises a second private key and a second public key, means for signing the second public key with the first private key to obtain a signed certificate;means for dividing the second key pair and signed certificate into n shares, where n is an integer;and means for distributing the n shares to at least two shareholders for safekeeping.
  3. 15
    A token device that facilitates replacing cryptographic keys, comprising:a key assignment component configured to obtain a pseudorandom first key pair that comprises a first private key and a corresponding first public key, obtain a pseudorandom spare second key pair that comprises a second private key and a second public key, sign the second public key with the first private key to obtain a signed certificate;a distribution component coupled to the key assignment component, the distribution component configured to divide the second key pair and signed certificate into n shares, where n is an integer;and a transmitter that distributes the n shares to at least two shareholders for safekeeping.
  4. 22
    A machine-readable medium having one or more instructions for replacing cryptographic keys, which when executed by a processor causes the processor to:obtain a pseudorandom first key pair that comprises a first private key and a corresponding first public key;obtain a pseudorandom spare second key pair that comprises a second private key and a second public key;sign the second public key with the first private key to obtain a signed certificate;divide the second key pair and signed certificate into n shares, where n is an integer;and distribute the n shares to at least two shareholders for safekeeping.
  5. 27
    A method operational on an authentication device for replacing asymmetric cryptographic keys, comprising:obtaining a first public key associated with a user, the first public key having an associated first private key;receiving a digital certificate of a second public key digitally signed with the first private key;authenticating the user by using the first public key to authenticate the digital certificate;and replacing the first public key with the second public key to secure communications with the user if the digital certificate is successfully authenticated.
  6. 30
    An authentication device, comprising:means for obtaining a first public key associated with a user, the first public key having an associated first private key;means for receiving a digital certificate of a second public key digitally signed with the first private key;means for authenticating the user by using the first public key to authenticate the digital certificate;and means for replacing the first public key with the second public key to secure communications with the user if the digital certificate is successfully authenticated.
  7. 33
    An authentication device, comprising:a communication module configured to receive a first public key associated with a user, the first public key having an associated first private key, and receive a digital certificate of a second public key digitally signed with the first private key;and a processing circuit coupled to the communication module, the processing circuit configured to authenticate the user by using the first public key to authenticate the digital certificate, and replace the first public key with the second public key to secure communications with the user if the digital certificate is successfully authenticated.
  8. 35
    A machine-readable medium having one or more instructions for replacing cryptographic keys, which when executed by a processor causes the processor to:obtain a first public key associated with a user, the first public key having an associated first private key;receive a digital certificate of a second public key digitally signed with the first private key;authenticate the user by using the first public key to authenticate the digital certificate;and replace the first public key with the second public key to secure communications with the user if the digital certificate is successfully authenticated.