发明名称 REISSUE OF CRYPTOGRAPHIC CREDENTIALS
摘要 Methods and apparatus are provided for effecting reissue in a data processing system of a cryptographic credential certifying a set of attributes, the credential being initially bound to a first secret key stored in a first tamper-resistant processing device (10). A backup token is produced using the first tamper-resistant processing device (10). The backup token comprises a commitment to said set of attributes and first proof data permitting verification that the set of attributes in said commitment corresponds to the set of attributes certified by said credential. The backup token is stored in backup memory (14). If the first tamper-resistant device should be lost or stolen, then at a second tamper- resistant processing device (10) storing a second secret key, the second secret key is blinded to produce a blinded key. A credential template token is produced from the backup token and the blinded key. The credential template token is sent to a credential issuer (2) of the data processing system (1) via user apparatus (6) of the system. At the credential issuer (2), said verification is performed using the first proof data and the credential template token is used to provide a reissued credential, certifying said set of attributes, to the second tamper-resistant device via said user apparatus (6), the reissued credential being bound to the second secret key.
申请公布号 WO2014068427(A1) 申请公布日期 2014.05.08
申请号 WO2013IB59267 申请日期 2013.10.10
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION;IBM RESEARCH GMBH 发明人 CAMENISCH, JAN LEONHARD;LEHMANN, ANJA;NEVEN, GREGORY
分类号 H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项
地址