Patent · US Expired

Method and apparatus for providing public key security control for a cryptographic processor

US6339824B1 · kind B1 · utility

22Cited by
20References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 30, 1997
Grant dateJan 15, 2002
Priority date
Expiry dateJun 30, 2017

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2209/68
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Public key security control (PKSC) is provided for a cryptographic module by means of digitally signed communications between the module and one or authorities with whom it interacts. Authorities interact with the crypto module by means of unsigned queries seeking nonsecret information or signed commands for performing specified operations. Each command signed by an authority also contains a transaction sequence number (TSN), which must match a corresponding number stored by the crypto module for the authority. The TSN for each authority is initially generated randomly and is incremented for each command accepted from that authority. A signature requirement array (SRA) controls the number of signatures required to validate each command type. Upon receiving a signed command from one or more authorities, the SRA is examined to determine whether a required number of authorities permitted to sign the command have signed the command for each signature requirement specification defined for that command type. A command requiring multiple signatures is held in a pending command register (PCR) while awaiting the required cosignatures. The crypto module also stores a single crypto module sig…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.