发明名称 INITIAL SECRET KEY ESTABLISHMENT INCLUDING FACILITIES FOR VERIFICATION OF IDENTITY
摘要 An issuer offers any type of service secured with a secret cryptographic key assigned to an applicant according to the present invention, which includes a secret key registration process. Usually, the secret key will be loaded on a portable memory device or other secret key store of the applicant. As preliminary steps, the issuer sets up its public key for the Probabilistic Encryption Key Exchange (PEKE) cryptosystem, and the applicant obtains a copy of a secret key registration software, a copy of the issuer's public key, and an uninitialized portable memory device. Once initiated by the applicant, the registration software generates an internal PEKE secret key. The applicant chooses a registration pass query and pass reply that the registration software MACs and encrypts with a key derived from the PEKE secret key. The registration software derives the key assigned to the applicant from the PEKE secret key, and loads it into the secret key store. A message is sent to the issuer data processing center where the cryptographic processing (PEKE, MAC, encryption) is reversed. Using an alternate channel (e.g. telephone conversation) an issuer agent verifies the identity of the applicant: the agent asks the pass query, the applicant replies with the pass reply, and the issuer verifies the applicant's knowledge of some relevant personal data. The issuer agent can approve the applicant's registration in the issuer database. There is no need for the issuer to personalize either the software or the secret key store before delivery to the applicant, and there is a single personal contact between the applicant and the issuer agent.
申请公布号 CA2289452(A1) 申请公布日期 1998.11.19
申请号 CA19982289452 申请日期 1998.05.07
申请人 CONNOTECH EXPERTS-CONSEILS INC. 发明人 MOREAU, THIERRY
分类号 H04L9/08;(IPC1-7):H04L9/00 主分类号 H04L9/08
代理机构 代理人
主权项
地址