Nova Patents
SE546367C2

Cryptographic signing of a data item

Abstract

ABSTRACT it is provided a method for performing a cryptographic signing operation of a data item. The method is performed in a server and comprises the steps of: receiving, from a smartcard reader, a request for a data item to be collectively signed, the request comprising an indication ofthe data item and an identifier of a smartcard, wherein the collective signing requires the use ofboth a smartcard secret key and a server secret key for the collective signature to be valid; establishing a secure channel with the smartcard; collaborating with the smartcard over the secure channel to provide a collective signature ofthe data item, wherein the server bases the signature on the data item and a server secret key, wherein the server secret key is specifically associated with the smartcard secret key, resulting in a collective signature; and sending the collective signature to the smartcard reader.

SE546367C2, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority and filed
  2. Granted
  3. Today

11 claims: 4 independent, 7 dependent

  1. 1
    A method for performing a cryptographic signing operation of a data item, the method being performed in a server (1) and comprising the steps of:receiving (40), from a smartcard reader (3), a request for a data item to be collectively signed, the request comprising an indication of the data item and an identifier of a smartcard, wherein the collective signing requires the use of both a smartcard secret key and a server secret key for the collective signature to be valid;querying (41) a user associated with the smartcard to sign the data item by sending a query (12) to a user device (5) and determining that the query result was affirmative;establishing (43) a secure channel with the smartcard;collaborating (44) with the smartcard (2) over the secure channel to provide a collective signature of the data item, wherein the server bases computation of the collective signature on the data item, a server secret key and data received from the smartcard (2), wherein the server secret key is specifically associated with the smartcard secret key, resulting in a collective signature;and sending (46) the collective signature to the smartcard reader (3).
  2. 4
    The method according to any one of the preceding claims, further comprising the steps of:obtaining (48) a verified identity associated with the smartcard;and sending (49) the verified identity to the smartcard reader (3).
  3. 5
    A server (1) for performing a cryptographic signing operation of a data item, the server (1) comprising:a processor (160);and a memory (164) storing instructions (167) that, when executed by the processor, 546 367 cause the server (1) to: receive, from a smartcard reader (3), a request for a data item to be collectively signed, the request comprising an indication of the data item and an identifier of a smartcard, wherein the collective signing requires the use of both a smartcard secret key and a server secret key for the collective signature to be valid;query a user associated with the smartcard to sign the data item by sending a query (12) to a user device (5) and determine that the query result was affirmative;establish a secure channel with the smartcard secret;collaborate with the smartcard (2) over the secure channel to provide a collective signature of the data item, wherein the server bases computation of the collective signature on the data item, a server secret key and data received from the smartcard, wherein the server secret key is specifically associated with the smartcard secret key, resulting in a collective signature;and send the collective signature to the smartcard reader (3).
  4. 8
    The server (1) according to any one of claims 5 to 7, further comprising instructions (167) that, when executed by the processor, cause the server (1) to:obtain a verified identity associated with the smartcard;and send the verified identity to the smartcard reader (3).
  5. 9
    A computer program (167, 91) for performing a cryptographic signing operation of a data item, the computer program comprising computer program code which, when run on a server (1) causes the server (1) to:receive, from a smartcard reader (3), a request for a data item to be collectively signed, the request comprising an indication of the data item and an identifier of a smartcard, wherein the collective signing requires the use of both a smartcard secret 546 367 key and a server secret key for the collective signature to be valid;query a user associated with the smartcard to sign the data item by sending a query (12) to a user device (5) and determine that the query result was affirmative;establish a secure channel with the smartcard;collaborate with the smartcard (2) over the secure channel to obtain a collective signature of the data item, wherein the server bases computation of the collective signature on the data item, a server secret key and data received from the smartcard, wherein the server secret key is specifically associated with the smartcard secret key, resulting in a collective signature;and send the collective signature to the smartcard reader (3).
  6. 11
    A system (9) comprising the server (1) according to any one of claims 5 to 8 and a smartcard (2) for performing a cryptographic signing operation of a data item, the smartcard comprising:a processor (160);and a memory (164) storing instructions (167) that, when executed by the processor, cause the smartcard (2) to: establish a connection with a smartcard reader (3);send, to the smartcard reader (3) connection details to the server (1) associated with the smartcard (2);establish a secure channel with the server (1);and collaborate with the server (1) over the secure channel to provide a collective signature of the data item, wherein the smartcard bases the collective signature on the data item and a smartcard secret key, wherein the collective signing requires the use of both the smartcard key and a server secret key for the collective signature to be valid.