JP2005328574A

Cryptographic system and method with key escrow feature

Abstract

Problem to be solved.To provide a cryptographic system and method with a commercial key escrow feature for enabling access from a country with citizens including an employer of a user or foreign users.

Solution.The invention provides a cryptographic system and method with a key escrow feature that uses a method for splitting user's private encryption keys into components and for sending those components to trusted agents chosen by the particular users. The methods for key escrow and receiving an escrow certificate to be executed by a chip device that also self-certifies are also applied herein to a more generalized case of registering a trusted device with a trusted third party and receiving authorization from that party enabling the device to communicate with other trusted devices. The method comprises the steps of: depositing a plurality of asymmetric encryption keys to be used by a plurality of users in a trusted escrow center; confirming the plurality of keys in the escrow center; and authenticating the authorization of the plurality of keys in the case of confirmation.

Copyright (C)2006,JPO&NCIPI

Term

Term ended

Projected expiry passed 8 August 2025, 1.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

12 claims: 2 independent, 10 dependent

  1. 1
    The trusted device is authorized to perform an electronic transaction between a first user and a second party, and the trusted device performs in the electronic transaction according to a predetermined rule that cannot be changed by the user. A method of providing such a guarantee that a request for authorizing the electronic transaction is electronically transmitted from the trusted device to a third party, wherein the request is the credit. Whether the trusted device should be authorized to perform the transaction, at least in part, in response to the determination that the trusted device operates only in accordance with the rules, including the identified information of the device. Is electronically transmitted from the third party to the trusted device to grant the authority to execute the electronic transaction, and the third party grants the authority to grant the authority. The second party from the trusted device assuring that the trusted device is authorized to perform the electronic transaction and will perform only in accordance with the rules, including the proof that it has been given. Electronically send to A method comprising electronically transmitting transaction data from the trusted device to the second party in accordance with the rules. 信用された装置に対し第1ユーザと第2者との間での電子トランザクションを行う権限を与え、そして前記ユーザにより変更することのできない所定のルールに従って前記信用された装置が前記電子トランザクションにおいて行うことの保証を提供する方法であって、前記方法は、 前記電子トランザクションを行う権限を与えるための要求を前記信用された装置から第3者に電子的に送信し、なお、前記要求は前記信用された装置の識別情報を含み、 前記信用された装置が前記ルールに従ってのみ動作するという決定に応じて、前記信用された装置が少なくとも部分的に前記トランザクションを実行する権限を与えられるべきか否かを前記第3者により決定し、 前記電子トランザクションを実行する権限を与えることを前記第3者から前記信用された装置に電子的に送信し、前記権限の付与は前記第3者が前記権限を与えたという証明を含み、 前記信用された装置に前記電子トランザクションを行う権限が与えられそして前記ルールにのみに従って実行するであろうことの保証として前記証明を前記信用された装置から前記第2者へ電子的に送信し、 前記ルールに従ってトランザクションデータを前記信用された装置から前記第2者へ電子的に送信することを含む方法。
  2. 7
    The trusted device is associated with the public and private keys of the asymmetric cryptosystem, and the step of sending the request comprises sending the public key of the device to the third party. The method described in. 前記信用された装置はそれが非対称暗号システムの公開キーおよび秘密キーと関連しており、そして前記要求を送信するステップは前記第三者に前記装置の公開キーを送信するステップを含む請求項1に記載の方法。