首页> 外国专利> Cryptographic key, or other secret material, recovery

Cryptographic key, or other secret material, recovery

机译:加密密钥或其他秘密材料的恢复

摘要

Secret material, such as a cryptographic key, that is needed for operation of a computer system (4a), can be stored under password protection on a storage medium for insertion into the computer system as required. If the password is forgotten, or the storage medium is faulty, the secret material will not be accessible. To permit secure recovery of the secret material in these or other circumstances, the secret material is encrypted using a recovery key and stored on the computer system, together with a value used in the generation of the recovery key from the secret material. The secret material is also stored on a remote secure system (5). When recovery of the secret material is required, the value for generating the recovery key is supplied to the remote system and used to generate the recovery key there. The generated recovery key is then supplied to the computer system, where it is used to decrypt the secret material. A new recovery key is then generated using a different value for a future recovery instance. The value can be supplied to the remote system (5) by dictation of a corresponding alphanumeric expression by a computer system operator (6), over a telephone connection (7, 8, 9) to a support technician (10) at the remote system for input thereat, and another alphanumeric expression corresponding to the generated recovery key can be dictated back to the computer system operator for insertion into the computer system and subsequent decryption of the secret material, thus allowing operation of the computer system, in circumstances where there is no data connection link between the two systems.
机译:计算机系统(4a)的操作所需的秘密材料,例如密钥,可以在密码保护下存储在存储介质上,以便根据需要插入计算机系统中。如果忘记密码或存储介质有问题,将无法访问机密材料。为了在这些或其他情况下安全地恢复秘密材料,使用恢复密钥对秘密材料进行加密并与从秘密材料生成恢复密钥时使用的值一起存储在计算机系统上。机密资料也存储在远程安全系统(5)上。当需要恢复机密资料时,用于生成恢复密钥的值将提供给远程系统,并用于在那里生成恢复密钥。然后将生成的恢复密钥提供给计算机系统,在计算机系统中将其用于解密机密材料。然后,为将来的恢复实例使用不同的值来生成新的恢复密钥。可以通过计算机系统操作员(6)通过与远程系统上的支持技术人员(10)的电话连接(7、8、9)指示相应的字母数字表达式,将该值提供给远程系统(5)。在此输入,并且可以将对应于所生成的恢复密钥的另一个字母数字表达式指定给计算机系统操作员,以插入计算机系统并随后对机密材料进行解密,从而在存在以下情况的情况下允许计算机系统进行操作两个系统之间没有数据连接链接。

著录项

  • 公开/公告号EP1059761B1

    专利类型

  • 公开/公告日2003-01-29

    原文格式PDF

  • 申请/专利权人 FUJITSU SERV LTD;

    申请/专利号EP20000304416

  • 发明设计人 ARTHAN ROBIN DENIS;

    申请日2000-05-24

  • 分类号H04L9/08;

  • 国家 EP

  • 入库时间 2022-08-21 23:52:40

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号