首页> 外国专利> Method of delivering Direct Proof private keys to devices using an on-line service

Method of delivering Direct Proof private keys to devices using an on-line service

机译:使用在线服务向设备交付直接证明私钥的方法

摘要

Delivering a Direct Proof private key to a device installed in a client computer system in the field may be accomplished in a secure manner without requiring significant non-volatile storage in the device. A unique pseudo-random value is generated and stored in the device at manufacturing time. The pseudo-random value is used to generate a symmetric key for encrypting a data structure holding a Direct Proof private key and a private key digest associated with the device. The resulting encrypted data structure is stored on a protected on-liner server accessible by the client computer system. When the device is initialized on the client computer system, the system checks if a localized encrypted data structure is present in the system. If not, the system obtains the associated encrypted data structure from the protected on-line server using a secure protocol. The device decrypts the encrypted data structure using a symmetric key regenerated from its stored pseudo-random value to obtain the Direct Proof private key. If the private key is valid, it may be used for subsequent authentication processing by the device in the client computer system.
机译:可以以安全的方式将直接证明私钥交付给现场安装在客户端计算机系统中的设备,而无需在设备中大量存储非易失性数据。唯一的伪随机值会在制造时生成并存储在设备中。伪随机值用于生成对称密钥,该对称密钥用于加密包含Direct Proof私钥和与该设备关联的私钥摘要的数据结构。生成的加密数据结构存储在客户端计算机系统可访问的受保护的在线服务器上。在客户端计算机系统上初始化设备后,系统将检查系统中是否存在本地化的加密数据结构。如果不是,则系统使用安全协议从受保护的在线服务器获取关联的加密数据结构。设备使用从其存储的伪随机值重新生成的对称密钥对加密的数据结构进行解密,以获得直接证明私钥。如果私钥有效,则可以将其用于客户端计算机系统中的设备的后续身份验证处理。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号