Patent ReferencesCryptographic apparatus and method Public key cryptographic apparatus and method Cryptographic communications system and method Paired-secure message identification controller for computers and the like Secure TV scrambling system using framing code switching Controlled use of cryptographic keys via generating station established control values Data authentication using modification detection codes based on a public one way encryption function Data cryptography operations using control vectors Personal identification number processing using control vectors Secure management of keys using extended control vectors Inventors
ApplicationNo. 748407 filed on 08/22/1991US Classes:380/280, Control vector or tag380/30, Public key380/281, Using master key (e.g., key-encrypting-key)713/175By generation of certificateExaminersPrimary: Cangialosi, SalvatoreAttorney, Agent or FirmInternational ClassH04L 009/30AbstractThe patent describes a method and apparatus for securely distributing an initial Data Encryption Algorithm (DEA) key-encrypting key by encrypting a key record (consisting of the key-encrypting key and control information associated with that key-encrypting key) using a public key algorithm and a public key belonging to the intended recipient of the key record. The patent further describes a method and apparatus for securely recovering the distributed key-encrypting key by the recipient by decrypting the received key record using the same public key algorithm and private key associated with the public key and re-encrypting the key-encrypting key under a key formed by arithmetically combining the recipient's master key with a control vector contained in the control information of the received key record. Thus the type and usage attributes assigned by the originator of the key-encrypting key in the form of a control vector are cryptographically coupled to the key-encrypting key such that the recipient may only use the received key-encrypting key in a manner defined by the key originator.The patent further describes a method and apparatus to improve the integrity of the key distribution process by applying a digital signature to the key record and by including identifying information (i.e., an originator identifier) in the control information of the key record. The integrity of the distribution process is enhanced by verifying the digital signature and originator identifier at the recipient node.Other References
Field of SearchPublic key | |