摘要 |
For a set (Lk) of embedded systems, an authorized operator with identifier (OP<SUB>j</SUB>) creates a mother public key (KpM) and a mother private key (KsM). The identifier (OP<SUB>j</SUB>), the range of identifiers referenced (Lk) and the mother public key (KpM) are published. For each embedded system (SN<SUB>i</SUB>), a diversified key (KsM<SUB>i</SUB>) is created from the identifier (SN<SUB>i</SUB>) and stored. For every public key (Kp) generated by an embedded system, a cryptographic control value (Sc<SUB>i</SUB>) is calculated on the public key (Kp), an algorithm identifier (CA 1 ) and the utilization parameters (U) of this key, using a zero knowledge signature algorithm, and a certification request message (MRCA) that includes control value (Sc<SUB>i</SUB>), the identifier of the operator (Op<SUB>j</SUB>), and identifier (SN<SUB>i</SUB>) is transmitted to a certification authority, which retrieves the identifier (Op<SUB>j</SUB>) and the value of the mother public key (KpM). |