US20060013402A1

Method of delivering Direct Proof private keys to devices using an on-line service

Claim Score by NHIP

Read claim 17, the broadest

Abstract

Delivering a Direct Proof private key to a device installed in a client computer system in the field may be accomplished in a secure manner without requiring significant non-volatile storage in the device. A unique pseudo-random value is generated and stored in the device at manufacturing time. The pseudo-random value is used to generate a symmetric key for encrypting a data structure holding a Direct Proof private key and a private key digest associated with the device. The resulting encrypted data structure is stored on a protected on-liner server accessible by the client computer system. When the device is initialized on the client computer system, the system checks if a localized encrypted data structure is present in the system. If not, the system obtains the associated encrypted data structure from the protected on-line server using a secure protocol. The device decrypts the encrypted data structure using a symmetric key regenerated from its stored pseudo-random value to obtain the Direct Proof private key. If the private key is valid, it may be used for subsequent authentication processing by the device in the client computer system.

US20060013402A1, drawing sheet 1
Sheet 1 of 15

Term

Projected expiry 3 November 2026.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

35 claims: 5 independent, 30 dependent

  1. 1
    A method comprising:establishing a protected on-line server to support key retrieval requests from client computer systems;generating a key service public/private key pair for use in secure key retrieval processing;generating a pseudo-random value for a device;generating an encrypted data structure associated with the device, the encrypted data structure comprising a private key;generating an identifier, based on the pseudo-random value, for the encrypted data structure;storing the identifier and the encrypted data structure on the protected on-line server;and storing the pseudo-random value and a hash value of the key service public key into non-volatile storage within the device.
  2. 9
    An article comprising:a first storage medium having a plurality of machine readable instructions, wherein when the instructions are executed by a processor, the instructions provide for establishing a protected on-line server to support key retrieval requests from client computer systems;generating a key service public/private key pair for use in secure key retrieval processing;generating a pseudo-random value for a device;generating an encrypted data structure associated with the device, the encrypted data structure comprising a private key;generating an identifier, based on the pseudo-random value, for the encrypted data structure;storing the identifier and the encrypted data structure on the protected on-line server;and storing the pseudo-random value and a hash value of the key service public key into non-volatile storage within the device.
  3. 17
    Broadest claimClaim Score 83, broad(NHIP)A method comprising:determining if an encrypted data structure, comprising a private key, associated with a device installed in a computer system is stored in a memory on the computer system;and if the encrypted data structure is not stored, obtaining the encrypted data structure associated with the device from a protected on-line server accessible by the computer system, the server storing a database of encrypted data structures.
  4. 28
    An article comprising:a storage medium having a plurality of machine readable instructions, wherein when the instructions are executed by a processor, the instructions provide for obtaining a private key for a device installed in a computer system by determining if an encrypted data structure, comprising a private key, associated with a device installed in a computer system is stored in a memory on the computer system;and if the encrypted data structure is not stored, obtaining the encrypted data structure associated with the device from a protected on-line server accessible by the computer system, the server storing a database of encrypted data structures.
  5. 34
    A system for delivering a private key to a device installed in a client computer system using a secure protocol comprising:a protected on-line server accessible to the client computer system and configured to generate a key service public/private key pair, to store a database of encrypted data structures, each encrypted data structure including a private key corresponding to a selected device, and to securely communicate a selected one of the encrypted data structures to the device;a protected system coupled to the protected server and configured to generate the encrypted data structure associated with the device, to receive the key service public key from the protected server, and to send the encrypted data structure to the protected on-line server;and a production system coupled to the protected system and configured to receive a hash value of the key service public key and a unique pseudo-random value from the protected system, and to store the hash value of the key service public key and the unique pseudo-random value into a non-volatile storage of the device prior to installation of the device into the client computer system.