EP1197034A1 - System for protected storage and management in a ttp server - Google Patents

System for protected storage and management in a ttp server

Info

Publication number
EP1197034A1
EP1197034A1 EP00942100A EP00942100A EP1197034A1 EP 1197034 A1 EP1197034 A1 EP 1197034A1 EP 00942100 A EP00942100 A EP 00942100A EP 00942100 A EP00942100 A EP 00942100A EP 1197034 A1 EP1197034 A1 EP 1197034A1
Authority
EP
European Patent Office
Prior art keywords
key
user
enciphered
seskey
pubkeya
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP00942100A
Other languages
German (de)
French (fr)
Inventor
Marten De Boer
Geert Kleinhuis
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Koninklijke KPN NV
Original Assignee
Koninklijke KPN NV
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Koninklijke KPN NV filed Critical Koninklijke KPN NV
Publication of EP1197034A1 publication Critical patent/EP1197034A1/en
Withdrawn legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3297Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/083Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • H04L9/0897Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/321Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures

Definitions

  • TTP Trusted Third Party
  • the invention relates to, in other words, a timeless key and storage system for the benefit of the long-term storage of electronically exchanged (digitally protected) information and protectedly making available (secure retrieving) the stored data.
  • the object of the invention is to overcome said drawbacks.
  • the invention provides for a system having means for carrying out the functionalities: "Secure Archiving”, “Re-encryption” and “Secure Retrieval”, which will be discussed below.
  • the optional items “Digital Sign” and “Time Stamp” will be discussed separately.
  • a file is transmitted from a first user to a second user in a safe way
  • the file is enciphered with a symmetrical session key, which in its turn is enciphered with the public key of the second user.
  • Said second user may decipher the session key with his private key and decipher the file itself with the session key deciphered in this manner .
  • the session key is also enciphered by the first user with the public key of an "in-line" TTP server (i.e., included in the transmission channel between the first and second users) , which TTP server deciphers the session key received with his private key.
  • the TTP server enciphers the deciphered session key with a "public" storage key.
  • the session key enciphered with said public storage key and the file enciphered with the session key are subsequently stored in a storage medium of the TTP.
  • public and private keys constitute an asymmetric pair of keys. If a file or a code is enciphered with the public key of an asymmetric pair of keys, said file or code may be deciphered only with the help of the associated private key and vice versa.
  • the public keys are available to "the public", e.g., by way of a publicly accessible data base, such as www.pgp.com.
  • the users and the TTP each dispose of a pair of keys, each consisting of a public and a private key, and in particular intented for protecting the mutual data exchange of the files and codes.
  • the TTP disposes of a pair of keys which is used within the TTP only; the "public” and private keys serve as protected storage or recovery ("secure retrieval"), as the case may be, of files and codes.
  • the public storage key is not, as is normally the case for public keys, put at the disposal of the public.
  • the TTP server may at regular points in time store the file once again in the storage medium.
  • the session key with which the file was enciphered is first recovered by deciphering - with the private storage key - the stored (enciphered) session key. Subsequently, the enciphered file stored in the storage medium is deciphered with the recovered session key.
  • the TTP server then generates a new asymmetric pair of storage keys, consisting of a new public storage key (which is not made available outside the TTP) and a new private storage key, and a new version of the symmetrical session key, whereafter the TTP enciphers the deciphered file with the new session key and stores it in the storage medium.
  • the TTP also enciphers the new session key with the new public storage key and stores said enciphered session key in the storage medium.
  • the symmetrical session key is recovered from the storage medium by deciphering, with the private storage key, the stored enciphered session key.
  • the recovered session key is subsequently enciphered with the current public key of the first or second user, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, enciphered with the session key.
  • the user may recover the session key therefrom by deciphering with his private key. Subsequently, the user may decipher the file enciphered with the session key using the recovered session key.
  • the public key of the first user may - as is well-known - be used to verify a digital signature of the file.
  • a problem arises if - which frequently occurs - the first user at a certain point in time, after the file has been stored in the TTP server, generates a new pair of keys (comprising a public and a private key) and discontinues the old one. For this reason, it is of importance to store the (original) public key of the first user in the TTP server, since only said original key may be used for verifying the digital signature of the stored, later retrievable file.
  • the TTP server after having received the enciphered file, also enciphers the - at that point in time publicly available - public key of the first user, with the public storage key, and stores said enciphered public key in the storage medium.
  • the public key of the first user may — upon retrieving the stored file — be recovered from the storage medium by deciphering, with the private storage key, said stored key.
  • the public key of the first user recovered in this manner is subsequently enciphered with the — at that point in time publicly available — public key of the retrieving first or second user, and transmitted by way of the transmission channel.
  • the user may recover the original public key of the first user by deciphering his current private key; subsequently, the digital signature of the recovered file may be verified using the recovered original public key of the first user.
  • the TTP server may generate a time stamp and store it, linked to the stored file and enciphered with the public storage key, in the storage medium.
  • the time stamp is deciphered and subsequently enciphered with the public key valid for said user and transmitted to the user.
  • the user may decipher the enciphered time stamp with his current private key.
  • Figures 1, 2 and 3 illustrate the functions "Secure Archiving", “Re-encryption” and "Secure
  • FIG. l "Secure Archiving" A file Txt is transmitted from a first user A to a second user B after having been enciphered with a symmetical session key SesKey. Said session key is enciphered with the public key FubKeyB of the second user. The latter may decipher the session key with his private key SecKeyB and the file itself with the deciphered session key. b
  • the session key is also enciphered by the first user with the public key of the TTP server PubKeyTTP, which, after having received it, deciphers said session key with his private key SecKeyTTP . Thereafter the TTP server enciphers the deciphered session key with a "public" storage key PubStorKey of the TTP.
  • the (transmission) keys of the users A and B each form an asymmetrical pair of keys, KeyPairA and KeyPairB, respectively, consisting of PubKeyA and SecKeyA, and PubKeyB and SecKeyB, respectively.
  • the TTP uses the pair of keys KeyPairTTP, consisting of PubKeyTTP and SecKeyTTP.
  • the public key PubKeyA of the first user A may be used to verify a digital signature DigSign of the file Txt.
  • the TTP server after having received the enciphered file (Txt) SesKey, also enciphers the - at that point in time publicly available - public key PubKeyA from the first user A, with the public storage key PubStorKey, and stores said enciphered public key (PubKeyA) PubStorKey in the storage medium DB.
  • the TTP server may generate a time stamp TSta p and store it, after enciphering with the public storage key PubStorKey and linked to the stored file, in the storage medium DB as (TStamp) PubStorKey.
  • FIG. 2 "Re-encryption"
  • the TTP server deciphers the enciphered file (Txt) SesKey stored in the storage medium with the session key SesKey, which for that purpose is recovered by deciphering the stored session key (SesKey) PubStorKey with the private storage key SecStorKey.
  • the TTP server subsequently generates a fresh pair of storage keys StorKeyPair, comprising a new "public” storage key PubStorKey' and a new private storage key SecStorKey' , as well as a new version of the symmetrical session key SesKey' .
  • the TTP subsequently enciphers the deciphered file Txt with the new session key SesKey' and stores the file (Txt) SesKey' enciphered in this manner in the storage medium DB.
  • the TTP also enciphers the new session key with the new public storage key PubStorKey' and stores the session key
  • the TTP server also deciphers the enciphered public key (PubKeyA) PubStorKey stored in the storage medium of the first user with the private storage key SecStorKey, and subsequently enciphers the deciphered public key PubKeyA with the newly generated public storage key PubStorKey' and stores the public key (PubKeyA) PubStorKey ' enciphered in this manner in the storage medium.
  • PubKeyA public key
  • PubStorKey PubStorKey
  • the TTP server also deciphers the enciphered time stamp (TStamp) PubStorKey stored in the storage medium with the private storage key SecStorKey, and subsequently enciphers the deciphered time stamp with the newly generated public storage key PubStorKey' and stores the time stamp (TStamp) PubStorKey' enciphered in this manner in the storage medium.
  • TTP stamp time stamp
  • PubStorKey stored in the storage medium with the private storage key SecStorKey
  • FIG. 3 "Secure Retrieval"
  • the symmetrical session key SesKey is recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored enciphered session key (SesKey) PubStorKe .
  • the recovered session key SesKey is subsequently enciphered with the then current public key PubKeyA * or PubKeyB", as the case may be, from the querying first or second user A or B, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, with the user, after having received the enciphered session key (SesKey) PubKeyA *" or (SesKey) PubKeyB * " , being capable of recovering the session key therefrom by deciphering, with his private key SecKeyA" or SecKeyB", as the case may be, and subsequently being capable of deciphering the file (Txt) SesKey using the recovered session key.
  • the original public key PubKeyA of the first user may be recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored public key (PubKeyA) PubStorKey of the first user enciphered with the public storage key.
  • the deciphered public key PubKeyA of the first user recovered in this manner is subsequently enciphered with the current public key PubKeyA' or PubKeyB " ", as the case may be, of the retrieving first or second user A or B, as the case may be, and transmitted to the user by way of the transmission channel .
  • the time stamp is first retrieved by deciphering (TStamp) PubStorKey with the private storage key SecStorKey.
  • the recovered time stamp is subsequently enciphered with the user's current public key PubKeyA' or PubKeyB' , as the case may be, and transmitted to said user.
  • the user may decipher the enciphered time stamp (TStamp) PubKeyA' or (TStamp) PubKeyB" , as the case may be, with his current private key SecKeyA' or SecKeyB ' , as the case may be .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Storage Device Security (AREA)

Abstract

System for protected storage in a TTP server. A file (Txt) is transmitted from a first (A) to a second user (B) after being enciphered with a session key (SesKey), which is enciphered with the public key (PublKeyB) of the second user. The session key (SesKey) is also enciphered by the first user with the public key (PublKey/TTP) of the TTP server which, after having received it, deciphers said session key with his private key (SecKeyTTP). The TTP server subsequently enciphers the session key (SesKey) and the (original) public key (PubKeyA) of the first user (A) with a 'public' storage key (PubStorKey). The enciphered session key ((SesKey)PubStorKey) and public key ((PubKeyA)PubStorKey) of the first user are stored, together with the enciphered file ((Txt)SesKey), in a storage medium (DB). They are recoverable by the TTP, by deciphering with the private storage key (SecStorKey), and may be transmitted after having been enciphered with the current public keys (PubKeyA' or PubKeyB', as the case may be) of the users.

Description

System for protected storage and management in a TTP server.
BACKGROUND OF THE INVENTION
The invention relates to a system for protected storage and management in a TTP server [TTP = Trusted Third Party] of copies of digital files transmitted, by way of a transmission channel, from a first to a second user.
The invention relates to, in other words, a timeless key and storage system for the benefit of the long-term storage of electronically exchanged (digitally protected) information and protectedly making available (secure retrieving) the stored data.
The few known systems have the following drawbacks : 1) Current protection techniques have a restricted hackability duration guarantee. 2) Limited protection guarantees prior to, during and after long-term storage.
3) Much storage space and effort are required for key management .
4) Protected long-term storage and the associated key and storage management is now either not regulated or very complex in setup .
5) Due to the ever changing software and hardware, it is very difficult to guarantee electronic timelessness.
B. SUMMARY OF THE INVENTION
The object of the invention is to overcome said drawbacks. For this purpose, the invention provides for a system having means for carrying out the functionalities: "Secure Archiving", "Re-encryption" and "Secure Retrieval", which will be discussed below. In this connection, the optional items "Digital Sign" and "Time Stamp" will be discussed separately.
"Secure Archiving"
If, according to the current state of the art, a file is transmitted from a first user to a second user in a safe way, the file is enciphered with a symmetrical session key, which in its turn is enciphered with the public key of the second user. Said second user may decipher the session key with his private key and decipher the file itself with the session key deciphered in this manner . According to the invention, the session key is also enciphered by the first user with the public key of an "in-line" TTP server (i.e., included in the transmission channel between the first and second users) , which TTP server deciphers the session key received with his private key. Thereafter, the TTP server enciphers the deciphered session key with a "public" storage key. The session key enciphered with said public storage key and the file enciphered with the session key are subsequently stored in a storage medium of the TTP. It should be noted that above and below there is spoken of public and private keys. These are generally known. In general, a public and a private key constitute an asymmetric pair of keys. If a file or a code is enciphered with the public key of an asymmetric pair of keys, said file or code may be deciphered only with the help of the associated private key and vice versa. In general, the public keys are available to "the public", e.g., by way of a publicly accessible data base, such as www.pgp.com. In the present application, it is assumed that the users and the TTP each dispose of a pair of keys, each consisting of a public and a private key, and in particular intented for protecting the mutual data exchange of the files and codes. In addition, the TTP disposes of a pair of keys which is used within the TTP only; the "public" and private keys serve as protected storage or recovery ("secure retrieval"), as the case may be, of files and codes. The public storage key is not, as is normally the case for public keys, put at the disposal of the public.
"Re-encryption"
By way of "periodic maintenance" - from security considerations - the TTP server may at regular points in time store the file once again in the storage medium. For this purpose, the session key with which the file was enciphered is first recovered by deciphering - with the private storage key - the stored (enciphered) session key. Subsequently, the enciphered file stored in the storage medium is deciphered with the recovered session key.
The TTP server then generates a new asymmetric pair of storage keys, consisting of a new public storage key (which is not made available outside the TTP) and a new private storage key, and a new version of the symmetrical session key, whereafter the TTP enciphers the deciphered file with the new session key and stores it in the storage medium.
The TTP also enciphers the new session key with the new public storage key and stores said enciphered session key in the storage medium.
"Secure Retrieval"
For protected recovery of the stored file, and transmission thereof to the first and/or second user, the symmetrical session key is recovered from the storage medium by deciphering, with the private storage key, the stored enciphered session key. The recovered session key is subsequently enciphered with the current public key of the first or second user, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, enciphered with the session key. After having received the enciphered session key, the user may recover the session key therefrom by deciphering with his private key. Subsequently, the user may decipher the file enciphered with the session key using the recovered session key.
"Digital Sign"
The public key of the first user may - as is well-known - be used to verify a digital signature of the file. A problem arises if - which frequently occurs - the first user at a certain point in time, after the file has been stored in the TTP server, generates a new pair of keys (comprising a public and a private key) and discontinues the old one. For this reason, it is of importance to store the (original) public key of the first user in the TTP server, since only said original key may be used for verifying the digital signature of the stored, later retrievable file.
For this case, the TTP server, after having received the enciphered file, also enciphers the - at that point in time publicly available - public key of the first user, with the public storage key, and stores said enciphered public key in the storage medium.
Periodically, the TTP server — as "periodical maintenance"
— deciphers the enciphered (original) public key, stored in the storage medium, of the first user having the private storage key, and enciphers the deciphered public key of the first user having the newly generated public storage key, and stores said freshly enciphered key in the storage medium.
The public key of the first user may — upon retrieving the stored file — be recovered from the storage medium by deciphering, with the private storage key, said stored key. The public key of the first user recovered in this manner is subsequently enciphered with the — at that point in time publicly available — public key of the retrieving first or second user, and transmitted by way of the transmission channel. After having received said enciphered public key, the user may recover the original public key of the first user by deciphering his current private key; subsequently, the digital signature of the recovered file may be verified using the recovered original public key of the first user.
"Time Stamp"
If so desired, the TTP server, after the enciphered file has been received and stored, may generate a time stamp and store it, linked to the stored file and enciphered with the public storage key, in the storage medium. In the event of retrieving the stored file by the first or second user, the time stamp is deciphered and subsequently enciphered with the public key valid for said user and transmitted to the user. The user may decipher the enciphered time stamp with his current private key.
DESCRIPTION OF THE FIGURES
Below, the invention is illustrated in further detail by reference to several figures. Figures 1, 2 and 3 illustrate the functions "Secure Archiving", "Re-encryption" and "Secure
Retrieval", including the items "Digital Sign" and the "Time Stamp" .
FIG. l: "Secure Archiving" A file Txt is transmitted from a first user A to a second user B after having been enciphered with a symmetical session key SesKey. Said session key is enciphered with the public key FubKeyB of the second user. The latter may decipher the session key with his private key SecKeyB and the file itself with the deciphered session key. b
The session key is also enciphered by the first user with the public key of the TTP server PubKeyTTP, which, after having received it, deciphers said session key with his private key SecKeyTTP . Thereafter the TTP server enciphers the deciphered session key with a "public" storage key PubStorKey of the TTP. The (transmission) keys of the users A and B each form an asymmetrical pair of keys, KeyPairA and KeyPairB, respectively, consisting of PubKeyA and SecKeyA, and PubKeyB and SecKeyB, respectively. The TTP uses the pair of keys KeyPairTTP, consisting of PubKeyTTP and SecKeyTTP. Finally, for the protected storage of an asymmetrical pair of keys StorKeyPair, consisting of the keys PubStorKey and SecStorKey; contrary to the preceding public keys, PubStorKey nor SecStorKey is publicly available, but is used exclusively within the TTP. The session key (SesKey) PubStorKey enciphered with the public storage key PubStorKey and the file (Txt) SesKey enciphered with the session key SesKey are subsequently stored in the storage medium DB of the TTP.
"Digital Sign"
The public key PubKeyA of the first user A may be used to verify a digital signature DigSign of the file Txt. In this case, the TTP server, after having received the enciphered file (Txt) SesKey, also enciphers the - at that point in time publicly available - public key PubKeyA from the first user A, with the public storage key PubStorKey, and stores said enciphered public key (PubKeyA) PubStorKey in the storage medium DB.
"Time Stamp" After having received and stored the enciphered file
(Txt) SesKey, the TTP server may generate a time stamp TSta p and store it, after enciphering with the public storage key PubStorKey and linked to the stored file, in the storage medium DB as (TStamp) PubStorKey.
FIG. 2: "Re-encryption"
As "periodical maintenance", the TTP server deciphers the enciphered file (Txt) SesKey stored in the storage medium with the session key SesKey, which for that purpose is recovered by deciphering the stored session key (SesKey) PubStorKey with the private storage key SecStorKey. The TTP server subsequently generates a fresh pair of storage keys StorKeyPair, comprising a new "public" storage key PubStorKey' and a new private storage key SecStorKey' , as well as a new version of the symmetrical session key SesKey' . The TTP subsequently enciphers the deciphered file Txt with the new session key SesKey' and stores the file (Txt) SesKey' enciphered in this manner in the storage medium DB.
The TTP also enciphers the new session key with the new public storage key PubStorKey' and stores the session key
(SesKey' ) PubStorKey' enciphered in this manner in the storage medium DB.
"Digital Sign" During the periodical maintenance, the TTP server also deciphers the enciphered public key (PubKeyA) PubStorKey stored in the storage medium of the first user with the private storage key SecStorKey, and subsequently enciphers the deciphered public key PubKeyA with the newly generated public storage key PubStorKey' and stores the public key (PubKeyA) PubStorKey ' enciphered in this manner in the storage medium.
"Time Stamp"
During the periodical maintenance, the TTP server also deciphers the enciphered time stamp (TStamp) PubStorKey stored in the storage medium with the private storage key SecStorKey, and subsequently enciphers the deciphered time stamp with the newly generated public storage key PubStorKey' and stores the time stamp (TStamp) PubStorKey' enciphered in this manner in the storage medium.
FIG. 3: "Secure Retrieval"
For protected recovery of the file Txt, and the transmission thereof to the first and second users A and B, respectively, the symmetrical session key SesKey is recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored enciphered session key (SesKey) PubStorKe . The recovered session key SesKey is subsequently enciphered with the then current public key PubKeyA* or PubKeyB", as the case may be, from the querying first or second user A or B, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, with the user, after having received the enciphered session key (SesKey) PubKeyA*" or (SesKey) PubKeyB*" , being capable of recovering the session key therefrom by deciphering, with his private key SecKeyA" or SecKeyB", as the case may be, and subsequently being capable of deciphering the file (Txt) SesKey using the recovered session key.
"Digital Sign"
The original public key PubKeyA of the first user, necessary for verifying the digital signature of the recovered file, may be recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored public key (PubKeyA) PubStorKey of the first user enciphered with the public storage key. The deciphered public key PubKeyA of the first user recovered in this manner is subsequently enciphered with the current public key PubKeyA' or PubKeyB"", as the case may be, of the retrieving first or second user A or B, as the case may be, and transmitted to the user by way of the transmission channel . After having received said enciphered public key (PubKeyA) PubKeyA- or (PubKeyA) PubKeyB*" , as the case may be, the user may recover the original public key PubKeyA of the first user therefrom by deciphering, with his current private key SecKeyA"" or SecKeyB", as the case may be. Subsequently, the digital signature DigSign of the file Txt may be verified using the recovered public key PubKeyA of the first user.
It should be noted that it is preferable to - otherwise than is shown in FIG. 3 - not transmit the digital signature DigSign unencipheredly to the first or second user, as the case may be, but enciphered with the public key of user A or B, as the case may be: instead of "DigSign", the TTP server then transmits " (DigSign) PubKeyA""" or " (DigSign) PubKeyB*", as the case may be. At the user's side, the digital signature may be recovered by deciphering, with the private keys of A and B, SecKeyA and SecKeyB, respectively.
"Time Stamp"
When the stored file is retrieved by the first or second user, the time stamp is first retrieved by deciphering (TStamp) PubStorKey with the private storage key SecStorKey. The recovered time stamp is subsequently enciphered with the user's current public key PubKeyA' or PubKeyB' , as the case may be, and transmitted to said user. Thereafter, the user may decipher the enciphered time stamp (TStamp) PubKeyA' or (TStamp) PubKeyB" , as the case may be, with his current private key SecKeyA' or SecKeyB ' , as the case may be .

Claims

1. System for protectedly storing and managing, in a TTP server, copies of digital files which are transmitted, by way of a transmission channel, from a first to a second user, characterised in that a file (Txt) is transmitted from the first user (A) to a second user (B) after having been enciphered with a symmetrical session key (SesKey) , which session key is enciphered using the public key (PubKeyB) of a first asymmetrical pair of keys (KeyPairB) associated with the second user, which second user, after having received it, may decipher the session key using the private key (SecKeyB) of said first asymmetrical pair of keys (KeyPairB) and subsequently may decipher the file using the session key deciphered in this manner, the session key (SesKey) also being enciphered by the first user (A) using the public key (PubKeyTTP) of a second asymmetrical pair of keys (KeyPairTTP) associated with the TTP server, which TTP server, after having received it, deciphers said session key using the private key (SecKeyTTP) from said second asymmetrical pair of keys (KeyPairTTP) , whereafter the TTP server enciphers the deciphered session key (SesKey) using the public key of a third asymmetrical pair of keys (StorKeyPair) , hereinafter to be referred to as public storage key (PubStorKey) , and stores the session key ( (SesKey) PubStorKey) enciphered with said storage key, together with the file ( (Txt) SesKey) enciphered with the session key (SesKey) , in a storage medium (DB) .
2. System according to claim 1, characterised in that, periodically, the TTP server deciphers the enciphered file ( (Txt) SesKey) stored in the storage medium with the session key (SesKey) , which for that purpose is recovered in advance by deciphering the stored enciphered session key ( (SesKey) PubStorKey) with the private key of the third pair of keys (StorKeyPair) , hereinafter to be referred to as the private storage key (SecStorKey) ; the TTP server subsequently generates a new version of the third pair of keys, comprising a new public storage key
(PubStorKey') and a new private storage key (SecStorKey1), and a new version of the symmetrical session key (SesKey1), whereafter the TTP enciphers the deciphered file (Txt) with the new session key (SesKey1) and stores the file
( (Txt) SesKey ' ) enciphered in this manner in the storage medium (DB) ; the TTP server enciphers the new session key (SesKey') with the new public storage key (PubStorKey1) and stores the session key ( (SesKey' ) PubStorKey' ) enciphered in this manner in the storage medium (DB) .
3. System according to claim 1, characterised in that, for protected recovery of the file (Txt) and transmission thereof to the first user (A) or the second user (B) , as the case may be, the symmetrical session key (SesKey) is recovered from the storage medium by deciphering, with the private storage key (SecStorKey) , the stored enciphered session key ( (SesKey) PubStorKey) , whereafter the recovered session key
(SesKey) is subsequently enciphered with the current public key (PubKeyA' or PubKeyB', as the case may be) of the first or second user (A or B, as the case may be) , and is transmitted to the user by way of the transmission channel, together with a copy of the file ( (Txt) SesKey) stored in the storage medium, with the user, after having received the enciphered session key
( (SesKey) PubKeyA' or (SesKey) PubKeyB' , as the case may be), being capable of recovering the session key therefrom by deciphering using the user's private key (SecKeyA' or SecKeyB', as the case may be) , and subsequently being capable of deciphering the enciphered file ( (Txt) SesKey) using the recovered session key.
4. System according to claim 1, the public key (PubKeyA) of the first user (A) being used to verify a digital signature (DigSign) of the file (Txt) , characterised in that the TTP server, after having received the enciphered file ( (Txt) SesKey) , also enciphers the then current public key (PubKeyA) of the first user (A) using the public storage key (PubStorKey) , and stores said enciphered public key ( (PubKeyA) PubStorKey) in the storage medium (DB) .
5. System according to claim 4, characterised in that, periodically, the TTP server deciphers the enciphered public key (PubKeyA) of the first user stored in the storage medium with the private storage key (SecStorKey) ; the TTP server subsequently generates a new version of the third pair of keys, comprising a new public storage key (PubStorKey1) and a new private storage key (SecStorKey1); - the TTP server enciphers the deciphered public key
(PubKeyA) of the first user with the new public storage key (PubStorKey1) and stores said public key
( (PubKeyA) PubStorKey') , enciphered in this manner, in the storage medium.
6. System according to claim 4 , characterised in that the public key (PubKeyA) of the first user is recovered from the storage medium by deciphering, with the private storage key (SecStorKey) , the stored enciphered public key ( (PubKeyA) PubStorKey) of the first user, that said original public key (PubKeyA) recovered in this manner is subsequently enciphered with the current public key (PubKeyA1 or PubKeyB1, as the case may be) of the first or second user (A or B, as the case may be) , and is transmitted by way of the transmission channel to the first or second user, as the case may be, with the user, after having received said enciphered public key ((PubKeyA) ubKeyA' or (PubKeyA) PubKeyB1 , as the case may be) being capable of recovering the original public key (PubKeyA) of the first user therefrom by deciphering with his current private key (SecKeyA1 or SecKeyB1, as the case may be), and subsequently being capable of verifying the digital signature (DigSign) of the file (Txt) using the original public key (PubKeyA) of the first user recovered in this manner.
7. System according to claim 6, characterised in that the digital signature (DigSign) is enciphered with the current public key (PubKeyA1 or PubKeyB1, as the case may be) of the first or second user (A or B, as the case may be) , and is transmitted to said first or second user, as the case may be, whereafter the receiving user recovers the digital signature by deciphering the received, enciphered digital signature ( (DigSign) PubKeyA' or (DigSign) PubKeyB ' , as the case may be) with his private key (SecKeyA1 or SecKeyB1, as the case may be).
8. System according to claim 1, characterised in that the TTP server, after having received the enciphered file ( (Txt) SesKey) generates a time stamp (TStamp) and stores it, linked to the stored file and enciphered with the public storage key (PubStorKey) , in the storage medium (DB) .
9. System according to claim 8, characterised in that, in the event of retrieving the stored file by the first or second user (A or B, as the case may be) the enciphered time stamp ( (TStamp) PubStorKey) is recovered by deciphering with the private storage key (SecStorKey) , the recovered time stamp is subsequently enciphered with the current public key (PubKeyA1 or PubKeyB1, as the case may be) for the querying user, and is transmitted to said user, whereafter the user may decipher the enciphered time stamp ( (TStamp) PubKeyA' or (TStamp) PubKeyB' , as the case may be) with the private key (SecKeyA' or SecKeyB', as the case may be) current for said user.
EP00942100A 1999-06-25 2000-06-19 System for protected storage and management in a ttp server Withdrawn EP1197034A1 (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
NL1012435A NL1012435C2 (en) 1999-06-25 1999-06-25 System for secure storage and management in a TTP server.
NL1012435 1999-06-25
PCT/EP2000/005642 WO2001001629A1 (en) 1999-06-25 2000-06-19 System for protected storage and management in a ttp server

Publications (1)

Publication Number Publication Date
EP1197034A1 true EP1197034A1 (en) 2002-04-17

Family

ID=19769452

Family Applications (1)

Application Number Title Priority Date Filing Date
EP00942100A Withdrawn EP1197034A1 (en) 1999-06-25 2000-06-19 System for protected storage and management in a ttp server

Country Status (4)

Country Link
EP (1) EP1197034A1 (en)
AU (1) AU5683800A (en)
NL (1) NL1012435C2 (en)
WO (1) WO2001001629A1 (en)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002271312A (en) * 2001-03-14 2002-09-20 Hitachi Ltd Public key management method
GB0215911D0 (en) 2002-07-10 2002-08-21 Hewlett Packard Co Method and apparatus for encrypting data
US8984636B2 (en) 2005-07-29 2015-03-17 Bit9, Inc. Content extractor and analysis system
CN108471404B (en) * 2018-02-28 2020-10-16 深圳市达仁基因科技有限公司 File sharing method and device, computer equipment and storage medium
EP3899911A1 (en) * 2018-12-19 2021-10-27 Telit Communications S.P.A. Systems and methods for managing a trusted application in a computer chip module
CN118678126B (en) * 2024-08-21 2024-10-25 杭州海康威视数字技术股份有限公司 Self-adaptive cross-domain code stream password security protection method, system and equipment

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5001752A (en) * 1989-10-13 1991-03-19 Fischer Addison M Public/key date-time notary facility
US6584565B1 (en) * 1997-07-15 2003-06-24 Hewlett-Packard Development Company, L.P. Method and apparatus for long term verification of digital signatures

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO0101629A1 *

Also Published As

Publication number Publication date
WO2001001629A1 (en) 2001-01-04
NL1012435C2 (en) 2000-12-28
AU5683800A (en) 2001-01-31

Similar Documents

Publication Publication Date Title
US6819766B1 (en) Method and system for managing keys for encrypted data
US6160891A (en) Methods and apparatus for recovering keys
US6317829B1 (en) Public key cryptography based security system to facilitate secure roaming of users
US20070168656A1 (en) Method for enabling a user to initiate a password protected backup of the user's credentials
US6370250B1 (en) Method of authentication and storage of private keys in a public key cryptography system (PKCS)
US8296827B2 (en) Method for enabling an administrator to configure a recovery password
US20100005318A1 (en) Process for securing data in a storage unit
US20050094817A1 (en) Method and system for multiple symmetric encryption for .ZIP files
CN103546547B (en) A kind of cloud storage file encryption system
KR970067054A (en) How to Create and Distribute Password Envelopes
CN105681031B (en) A kind of storage encryption gateway key management system and method
CN102088443B (en) Method and system for subscribing digital periodical with copyright protection
WO2001097440A3 (en) Encryption system that dynamically locates keys
EP0892521A3 (en) Method and apparatus for long term verification of digital signatures
CN101924739A (en) Method for encrypting, storing and retrieving software certificate and private key
CN101388774A (en) Method for automatically authenticate and recognize customer identity between different customers and login
US7770213B2 (en) Method and apparatus for securely forgetting secrets
WO2007089266A3 (en) Administration of data encryption in enterprise computer systems
CA2251193A1 (en) Method and apparatus for encoding and recovering keys
EP1197034A1 (en) System for protected storage and management in a ttp server
WO2008065351A1 (en) Self encryption
KR100586030B1 (en) How to Manage Encryption Key Recovery Information
CN108173880B (en) File encryption system based on third party key management
CN116346497A (en) Mechanism for supporting audit of end-to-end encryption
Anton et al. Linux unified key setup (LUKS)-the good, the bad, the ugly

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20020125

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE

AX Request for extension of the european patent

Free format text: AL;LT;LV;MK;RO;SI

17Q First examination report despatched

Effective date: 20030404

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20031015