首页> 外国专利> Method and apparatus for providing short-term private keys in public key cryptographic systems

Method and apparatus for providing short-term private keys in public key cryptographic systems

机译:在公钥密码系统中提供短期私钥的方法和装置

摘要

A computing entity, 11, has an associated static public/private key pair formed by a static private key comprising a secret (sA), and a static public key (P,R) comprising both a first element (P) and that element combined with the secret (sA). The secret (sA) is stored in higher-security storage provided, for example, by a smartcard, 20. A short-term private key (St) is provided for use by a computing entity 11 in effecting cryptographic operations during an operational period. This short-term private key (St) is generated, independently of any pending cryptographic operations, by mapping a string (str) to a second element (P') and multiplying that element by said secret (sA), the first and second elements (P,P') being such that a computable bilinear map exists for these elements. The short-term private key (St) is stored in lower-security storage, 15, in the computing entity, 11, for a limited period that encompasses the operational period in respect of which the key (St) was generated. A second embodiment relates to a cryptographic system comprising: a first entity arranged to use the private key of an associated static public/private key pair to form a plurality of different short-term private keys each for use during a corresponding limited operational period; a public key infrastructure for providing a certificate associating the first entity with the public key of its static public/private key pair; and a second entity arranged to use a known formula and known data to migrate the static public key of the first entity, whilst retaining the assurance provided by said certificate, to form short-term public keys each for use, during a corresponding said limited operational period, in carrying out cryptographic operations for which there exist complimentary operations requiring use of the corresponding short-term private key.
机译:计算实体11具有由包括秘密(sA)的静态私钥和包括第一元素(P)和该元素组合的静态公钥(P,R)形成的相关联的静态公/私密钥对。与秘密(sA)。秘密(sA)被存储在例如由智能卡20提供的更高安全性的存储器中。提供短期私有密钥(St)以供计算实体11在操作期间用于实现密码操作。通过将字符串(str)映射到第二个元素(P')并将该元素乘以所说的秘密(sA),第一和第二个元素,与任何未完成的加密操作无关地生成此短期私钥(St) (P,P’)使得对于这些元素存在可计算的双线性图。短期私钥(St)在计算实体11中的较低安全性存储器15中存储有限的时间段,该有限的时间段包括生成密钥(St)所依据的操作周期。第二实施例涉及一种密码系统,包括:第一实体,被布置为使用相关联的静态公/私密钥对的私钥形成多个不同的短期私钥,每个所述短期私钥在对应的有限操作时段内使用;以及公共密钥基础结构,用于提供将第一实体与其静态公共/私有密钥对的公共密钥相关联的证书;第二实体,在对应的所述有限操作期间,在保持所述证书提供的保证的同时,使用已知的公式和已知的数据来迁移第一实体的静态公共密钥,以形成各自使用的短期公共密钥。期间,在进行密码操作时,存在需要使用相应的短期私钥的互补操作。

著录项

  • 公开/公告号GB2419787A

    专利类型

  • 公开/公告日2006-05-03

    原文格式PDF

  • 申请/专利权人 HEWLETT-PACKARD DEVELOPMENT COMPANY L.P.;

    申请/专利号GB20040023889

  • 发明设计人 WENBO MAO;

    申请日2004-10-28

  • 分类号H04L9/30;G06F1/00;H04L9/00;H04L9/16;H04L9/32;

  • 国家 GB

  • 入库时间 2022-08-21 21:16:32

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号