Nova Patents
WO02065696A1

A security architecture

Abstract

A method for distributing private keys and certificates to cryptographic devices (1). According to the invention the method comprises the steps of: providing a first CA-system (5) at the manufacture of the devices; providing a temporary private key and a temporary certificate from the first CA-system (5) to each device (1) during the manufacturing of the device (1); delivering said devices (1) to customers; providing a second CA-system (11) at a customer node (10), this being performed at this process step or earlier in the process; for each delivered cryptographic device: connecting the device to a network, which is reachable from the customer node (10); authenticating the device as being from said manufacture; automatically replacing the temporary private key and the temporary certificate with a new private key and a new certificate and also automatically providing the device with a CA-certificate, the new certificates being signed by the second CA-system (11) which is notified of the connection of the device (1) as soon as the device (1) has connected to the network.

WO02065696A1, drawing sheet 1
Sheet 1 of 3

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

14 claims: 7 independent, 7 dependent

  1. 1
    CLAIMS 1. A method for distributing private keys and certificates to cryptographic devices (1), characterised in that it comprises the steps of:- providing a first CA-system (5) at the manufacture of the devices;- providing a temporary private key and a temporary certificate from the first CA- system (5) to each device (1) during the manufacture of the device (1);- delivering said devices (1) to customers;- providing a second CA-system (11) at a customer node (10), this being performed at this process step or earlier in the process;for each delivered cryptographic device: - connecting the device (1) to a network, which is reachable from the customer node (10);- authenticating the device (1) as being from said manufacture;- automatically replacing the temporary private key and the temporary certificate with a new private key and a new certificate and also automatically providing the device with a CA-certificate, the new certificates being signed by the second CA- system (11) which is notified of the connection of the device (1) as soon as the de- vice (1) has connected to the network.
  2. 5
    A method according to any one of the claims 1-4, characterised in that it further comprises the steps of:- sending the request from the device through a communication means (35) provided in the device;- signing the request in the communication means (35) using the temporary private key before it is sent to the customer node (10);- encrypting the request by the communication means (35) before it is sent to the customer node (10);- receiving and decrypting the answers from the second CA-system (11) in the communication means (35).
  3. 6
    A method according to any one of the preceding claims, characterised in that it comprises decrypting the request in an authentication module (21) when the request from the device (1) is received in the customer node (10) and encrypting the answer in the authentication module (21) before it is sent to the device (1).
  4. 7
    A method according to any one of the claims 1-6, characterised by including the identity of the device and optional parameters in the request, this identity and the parameters being used in the configuration of the certificate.
  5. 8
    A method according to any one of the preceding claims, characterised in that it further comprises the steps of:- receiving a request for a new private key, a new certificate and a CA-certificate from the device (1) in the second CA-system (11);- generating a new private key, a new pμblic key and configuring a new certificate comprising said new public key in the second CA-system (11);- signing said new certificate and a CA-certificate in the second CA-system (11);- automatically answering the request by sending the requested new private key, new certificate and CA-certificate to the device (1) from the second CA-system.
  6. 9
    A cryptographic device, characterised in that the device (1) is adapted to receive a temporary private key and a temporary certificate from a first CA-system (5) pro- yided at the manufacture during the manufacture of the device (1) and in that it comprises an activating client (33) which is adapted to be activated as soon as the device is connected to a network and an address to a customer node (10) has been provided, the activating client (33) being adapted to replace the temporary private key and the temporary certificate with a new private key, a new certificate and a CA-certificate, the certificates being signed by a second CA-system (11) comprised in the customer node (10), which is reachable from the network.
  7. 13
    A device according to any one of the claims 9-12, characterised in that it comprises a first CA-client (3) adapted to request the first temporary private key and the temporary certificate from the first CA-system (5).
  8. 14
    A system used to distribute private keys and certificates to cryptographic devices, characterised in that it comprises:- a first CA-system (5) located at the manufacture, which first CA-system (5) is adapted to.provide the device (1) with a temporary private key and a temporary certificate during the manufacture of the device (1);- a second CA-system (11), being the customer's CA-system, located in a customer node (10), which is reachable from the device (1) when it has been connected to a network by, for example the end user, said second CA-system (11) being adapted to provide the device (1) with a new private key, a new certificate which is signed by the second CA-system and with a CA-certificate, said new private key and new certificate being adapted to automatically replace the temporary private key and the temporary certificate in the device (1) when the device (1) is being customized;an authentication module (21) being adapted to verify that the device (1) has been produced at said manufacture by using a factory CA-certificate provided to the authentication module (21) from the first CA-system (5). A system according to claim 14, characterised in that the authentication module (21) is provided in the customer node (10) and is connected to the second CA- system (11) through an authorization module (19), which is adapted to verify if the request is allowed, and through a second CA-client, which is adapted to transform the request into an xml-request and forward it to the second CA-system (11). A system according to claim 14 or 15, characterised in that the authentication module (21) is a https-server. A system according to any one of the claims 14-16, characterised in that it com- prises a communication means (35), which is located in the device (1) and is adapted to sign and encrypt the request before it is sent to the customer node (10) and decrypt and optionally verify the retrieved answer. A system according to any one of the claims 14-17, characterised in that the sys- tern comprises a loading station (4) at the site of manufacture, which loading station (4) is adapted to load the necessary software, for example a first CA-client (3), which is adapted to send out a request for a temporary private key and a temporary certificate to the first CA-system (5), to the device (1) during the manufacture and also to indicate for the device (1) when it should send out the request to the first CA-system (5).