首页> 外国专利> A hybrid public key algorithm/data encryption algorithm key distribution method based on control vectors

A hybrid public key algorithm/data encryption algorithm key distribution method based on control vectors

机译:基于控制向量的混合公钥算法/数据加密算法密钥分配方法

摘要

The patent describes a method and apparatus for securely distributing an initial Data Encryption Algorithm (DEA) key-encrypting key by encrypting a key record (consisting of the key-encrypting key and control information associated with that key-encrypting key) using a public key algorithm and a public key belonging to the intended recipient of the key record. The patent further describes a method and apparatus for securely recovering the distributed key-encrypting key by the recipient by decrypting the received key record using the same public key algorithm and private key associated with the public key and re-encrypting the key-encrypting key under a key formed by arithmetically combining the recipient's master key with a control vector contained in the control information of the received key record. Thus the type and usage attributes assigned by the originator of the key-encrypting key in the form of a control vector are cryptographically coupled to the key-encrypting key such that the recipient may only use the received key-encrypting key in a manner defined by the key originator.;The patent further describes a method and apparatus to improve the integrity of the key distribution process by applying a digital signature to the key record and by including identifying information (i.e., an originator identifier) in the control information of the key record. The integrity of the distribution process is enhanced by verifying the digital signature and originator identifier at the recipient node.
机译:该专利描述了一种通过使用公钥对密钥记录(由密钥加密密钥和与该密钥加密密钥相关联的控制信息)进行加密来安全地分发初始数据加密算法(DEA)密钥加密密钥的方法和装置。算法和属于密钥记录的预期接收者的公共密钥。该专利还描述了一种方法和设备,用于通过使用相同的公钥算法和与公钥相关联的私钥解密接收到的密钥记录,并由接收者安全地恢复所分配的密钥加密密钥,并在以下情况下对密钥加密密钥进行重新加密:通过将接收者的主密钥与接收到的密钥记录的控制信息中包含的控制向量进行算术组合而形成的密钥。因此,由密钥加密密钥的始发者以控制向量的形式分配的类型和使用属性以密码方式耦合到密钥加密密钥,以使接收者只能以以下方式定义的方式使用接收到的密钥加密密钥:该专利还描述了一种方法和装置,其通过将数字签名应用于密钥记录并且通过在密钥的控制信息中包括识别信息(即,发起者标识符)来改善密钥分发过程的完整性。记录。通过在接收方节点上验证数字签名和始发者标识符,可以增强分发过程的完整性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号