首页> 外国专利> Method of delivering direct proof private keys in signed groups to devices using a distribution CD

Method of delivering direct proof private keys in signed groups to devices using a distribution CD

机译:使用分发CD将签名组中的直接证明私钥传递到设备的方法

摘要

Delivering a Direct Proof private key in a signed group of keys to a device installed in a client computer system in the field may be accomplished in a secure manner without requiring significant non-volatile storage in the device. A unique pseudo-random value is generated and stored along with a group number in the device at manufacturing time. The pseudo-random value is used to generate a symmetric key for encrypting a data structure holding a Direct Proof private key and a private key digest associated with the device. The resulting encrypted data structure is stored in a signed group of keys (e.g., a signed group record) on a removable storage medium (such as a CD or DVD), and distributed to the owner of the client computer system. When the device is initialized on the client computer system, the system checks if a localized encrypted data structure is present in the system. If not, the system obtains the associated signed group record of encrypted data structures from the removable storage medium, and verifies the signed group record. The device decrypts the encrypted data structure using a symmetric key regenerated from its stored pseudo-random value to obtain the Direct Proof private key, when the group record is valid. If the private key is valid, it may be used for subsequent authentication processing by the device in the client computer system.
机译:可以以安全的方式将签名的一组密钥中的直接证明私钥传递给现场安装在客户端计算机系统中的设备,而无需在设备中存储大量非易失性内容。在制造时会生成唯一的伪随机值,并将其与组号一起存储在设备中。伪随机值用于生成对称密钥,该对称密钥用于加密包含Direct Proof私钥和与该设备关联的私钥摘要的数据结构。所得的加密数据结构存储在可移动存储介质(例如CD或DVD)上的签名的密钥组(例如,签名的组记录)中,并分发给客户端计算机系统的所有者。在客户端计算机系统上初始化设备后,系统将检查系统中是否存在本地化的加密数据结构。如果不是,则系统从可移动存储介质中获取加密数据结构的相关签名组记录,并验证签名组记录。当组记录有效时,设备使用从其存储的伪随机值重新生成的对称密钥对加密的数据结构进行解密,以获得直接证明私钥。如果私钥有效,则可以将其用于客户端计算机系统中的设备的后续身份验证处理。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号