EP1197034A1 - System for protected storage and management in a ttp server - Google Patents
System for protected storage and management in a ttp serverInfo
- Publication number
- EP1197034A1 EP1197034A1 EP00942100A EP00942100A EP1197034A1 EP 1197034 A1 EP1197034 A1 EP 1197034A1 EP 00942100 A EP00942100 A EP 00942100A EP 00942100 A EP00942100 A EP 00942100A EP 1197034 A1 EP1197034 A1 EP 1197034A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- key
- user
- enciphered
- seskey
- pubkeya
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3297—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
- H04L9/0897—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/30—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/321—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
Definitions
- TTP Trusted Third Party
- the invention relates to, in other words, a timeless key and storage system for the benefit of the long-term storage of electronically exchanged (digitally protected) information and protectedly making available (secure retrieving) the stored data.
- the object of the invention is to overcome said drawbacks.
- the invention provides for a system having means for carrying out the functionalities: "Secure Archiving”, “Re-encryption” and “Secure Retrieval”, which will be discussed below.
- the optional items “Digital Sign” and “Time Stamp” will be discussed separately.
- a file is transmitted from a first user to a second user in a safe way
- the file is enciphered with a symmetrical session key, which in its turn is enciphered with the public key of the second user.
- Said second user may decipher the session key with his private key and decipher the file itself with the session key deciphered in this manner .
- the session key is also enciphered by the first user with the public key of an "in-line" TTP server (i.e., included in the transmission channel between the first and second users) , which TTP server deciphers the session key received with his private key.
- the TTP server enciphers the deciphered session key with a "public" storage key.
- the session key enciphered with said public storage key and the file enciphered with the session key are subsequently stored in a storage medium of the TTP.
- public and private keys constitute an asymmetric pair of keys. If a file or a code is enciphered with the public key of an asymmetric pair of keys, said file or code may be deciphered only with the help of the associated private key and vice versa.
- the public keys are available to "the public", e.g., by way of a publicly accessible data base, such as www.pgp.com.
- the users and the TTP each dispose of a pair of keys, each consisting of a public and a private key, and in particular intented for protecting the mutual data exchange of the files and codes.
- the TTP disposes of a pair of keys which is used within the TTP only; the "public” and private keys serve as protected storage or recovery ("secure retrieval"), as the case may be, of files and codes.
- the public storage key is not, as is normally the case for public keys, put at the disposal of the public.
- the TTP server may at regular points in time store the file once again in the storage medium.
- the session key with which the file was enciphered is first recovered by deciphering - with the private storage key - the stored (enciphered) session key. Subsequently, the enciphered file stored in the storage medium is deciphered with the recovered session key.
- the TTP server then generates a new asymmetric pair of storage keys, consisting of a new public storage key (which is not made available outside the TTP) and a new private storage key, and a new version of the symmetrical session key, whereafter the TTP enciphers the deciphered file with the new session key and stores it in the storage medium.
- the TTP also enciphers the new session key with the new public storage key and stores said enciphered session key in the storage medium.
- the symmetrical session key is recovered from the storage medium by deciphering, with the private storage key, the stored enciphered session key.
- the recovered session key is subsequently enciphered with the current public key of the first or second user, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, enciphered with the session key.
- the user may recover the session key therefrom by deciphering with his private key. Subsequently, the user may decipher the file enciphered with the session key using the recovered session key.
- the public key of the first user may - as is well-known - be used to verify a digital signature of the file.
- a problem arises if - which frequently occurs - the first user at a certain point in time, after the file has been stored in the TTP server, generates a new pair of keys (comprising a public and a private key) and discontinues the old one. For this reason, it is of importance to store the (original) public key of the first user in the TTP server, since only said original key may be used for verifying the digital signature of the stored, later retrievable file.
- the TTP server after having received the enciphered file, also enciphers the - at that point in time publicly available - public key of the first user, with the public storage key, and stores said enciphered public key in the storage medium.
- the public key of the first user may — upon retrieving the stored file — be recovered from the storage medium by deciphering, with the private storage key, said stored key.
- the public key of the first user recovered in this manner is subsequently enciphered with the — at that point in time publicly available — public key of the retrieving first or second user, and transmitted by way of the transmission channel.
- the user may recover the original public key of the first user by deciphering his current private key; subsequently, the digital signature of the recovered file may be verified using the recovered original public key of the first user.
- the TTP server may generate a time stamp and store it, linked to the stored file and enciphered with the public storage key, in the storage medium.
- the time stamp is deciphered and subsequently enciphered with the public key valid for said user and transmitted to the user.
- the user may decipher the enciphered time stamp with his current private key.
- Figures 1, 2 and 3 illustrate the functions "Secure Archiving", “Re-encryption” and "Secure
- FIG. l "Secure Archiving" A file Txt is transmitted from a first user A to a second user B after having been enciphered with a symmetical session key SesKey. Said session key is enciphered with the public key FubKeyB of the second user. The latter may decipher the session key with his private key SecKeyB and the file itself with the deciphered session key. b
- the session key is also enciphered by the first user with the public key of the TTP server PubKeyTTP, which, after having received it, deciphers said session key with his private key SecKeyTTP . Thereafter the TTP server enciphers the deciphered session key with a "public" storage key PubStorKey of the TTP.
- the (transmission) keys of the users A and B each form an asymmetrical pair of keys, KeyPairA and KeyPairB, respectively, consisting of PubKeyA and SecKeyA, and PubKeyB and SecKeyB, respectively.
- the TTP uses the pair of keys KeyPairTTP, consisting of PubKeyTTP and SecKeyTTP.
- the public key PubKeyA of the first user A may be used to verify a digital signature DigSign of the file Txt.
- the TTP server after having received the enciphered file (Txt) SesKey, also enciphers the - at that point in time publicly available - public key PubKeyA from the first user A, with the public storage key PubStorKey, and stores said enciphered public key (PubKeyA) PubStorKey in the storage medium DB.
- the TTP server may generate a time stamp TSta p and store it, after enciphering with the public storage key PubStorKey and linked to the stored file, in the storage medium DB as (TStamp) PubStorKey.
- FIG. 2 "Re-encryption"
- the TTP server deciphers the enciphered file (Txt) SesKey stored in the storage medium with the session key SesKey, which for that purpose is recovered by deciphering the stored session key (SesKey) PubStorKey with the private storage key SecStorKey.
- the TTP server subsequently generates a fresh pair of storage keys StorKeyPair, comprising a new "public” storage key PubStorKey' and a new private storage key SecStorKey' , as well as a new version of the symmetrical session key SesKey' .
- the TTP subsequently enciphers the deciphered file Txt with the new session key SesKey' and stores the file (Txt) SesKey' enciphered in this manner in the storage medium DB.
- the TTP also enciphers the new session key with the new public storage key PubStorKey' and stores the session key
- the TTP server also deciphers the enciphered public key (PubKeyA) PubStorKey stored in the storage medium of the first user with the private storage key SecStorKey, and subsequently enciphers the deciphered public key PubKeyA with the newly generated public storage key PubStorKey' and stores the public key (PubKeyA) PubStorKey ' enciphered in this manner in the storage medium.
- PubKeyA public key
- PubStorKey PubStorKey
- the TTP server also deciphers the enciphered time stamp (TStamp) PubStorKey stored in the storage medium with the private storage key SecStorKey, and subsequently enciphers the deciphered time stamp with the newly generated public storage key PubStorKey' and stores the time stamp (TStamp) PubStorKey' enciphered in this manner in the storage medium.
- TTP stamp time stamp
- PubStorKey stored in the storage medium with the private storage key SecStorKey
- FIG. 3 "Secure Retrieval"
- the symmetrical session key SesKey is recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored enciphered session key (SesKey) PubStorKe .
- the recovered session key SesKey is subsequently enciphered with the then current public key PubKeyA * or PubKeyB", as the case may be, from the querying first or second user A or B, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, with the user, after having received the enciphered session key (SesKey) PubKeyA *" or (SesKey) PubKeyB * " , being capable of recovering the session key therefrom by deciphering, with his private key SecKeyA" or SecKeyB", as the case may be, and subsequently being capable of deciphering the file (Txt) SesKey using the recovered session key.
- the original public key PubKeyA of the first user may be recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored public key (PubKeyA) PubStorKey of the first user enciphered with the public storage key.
- the deciphered public key PubKeyA of the first user recovered in this manner is subsequently enciphered with the current public key PubKeyA' or PubKeyB " ", as the case may be, of the retrieving first or second user A or B, as the case may be, and transmitted to the user by way of the transmission channel .
- the time stamp is first retrieved by deciphering (TStamp) PubStorKey with the private storage key SecStorKey.
- the recovered time stamp is subsequently enciphered with the user's current public key PubKeyA' or PubKeyB' , as the case may be, and transmitted to said user.
- the user may decipher the enciphered time stamp (TStamp) PubKeyA' or (TStamp) PubKeyB" , as the case may be, with his current private key SecKeyA' or SecKeyB ' , as the case may be .
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
System for protected storage in a TTP server. A file (Txt) is transmitted from a first (A) to a second user (B) after being enciphered with a session key (SesKey), which is enciphered with the public key (PublKeyB) of the second user. The session key (SesKey) is also enciphered by the first user with the public key (PublKey/TTP) of the TTP server which, after having received it, deciphers said session key with his private key (SecKeyTTP). The TTP server subsequently enciphers the session key (SesKey) and the (original) public key (PubKeyA) of the first user (A) with a 'public' storage key (PubStorKey). The enciphered session key ((SesKey)PubStorKey) and public key ((PubKeyA)PubStorKey) of the first user are stored, together with the enciphered file ((Txt)SesKey), in a storage medium (DB). They are recoverable by the TTP, by deciphering with the private storage key (SecStorKey), and may be transmitted after having been enciphered with the current public keys (PubKeyA' or PubKeyB', as the case may be) of the users.
Description
System for protected storage and management in a TTP server.
BACKGROUND OF THE INVENTION
The invention relates to a system for protected storage and management in a TTP server [TTP = Trusted Third Party] of copies of digital files transmitted, by way of a transmission channel, from a first to a second user.
The invention relates to, in other words, a timeless key and storage system for the benefit of the long-term storage of electronically exchanged (digitally protected) information and protectedly making available (secure retrieving) the stored data.
The few known systems have the following drawbacks : 1) Current protection techniques have a restricted hackability duration guarantee. 2) Limited protection guarantees prior to, during and after long-term storage.
3) Much storage space and effort are required for key management .
4) Protected long-term storage and the associated key and storage management is now either not regulated or very complex in setup .
5) Due to the ever changing software and hardware, it is very difficult to guarantee electronic timelessness.
B. SUMMARY OF THE INVENTION
The object of the invention is to overcome said drawbacks. For this purpose, the invention provides for a system having means for carrying out the functionalities: "Secure Archiving", "Re-encryption" and "Secure Retrieval", which will be discussed below. In this connection, the optional items "Digital Sign" and "Time Stamp" will be discussed separately.
"Secure Archiving"
If, according to the current state of the art, a file is transmitted from a first user to a second user in a safe way, the file is enciphered with a symmetrical session key, which in its turn is enciphered with the public key of the second user. Said second user may decipher the session key with his private key and decipher the file itself with the session key deciphered in this manner .
According to the invention, the session key is also enciphered by the first user with the public key of an "in-line" TTP server (i.e., included in the transmission channel between the first and second users) , which TTP server deciphers the session key received with his private key. Thereafter, the TTP server enciphers the deciphered session key with a "public" storage key. The session key enciphered with said public storage key and the file enciphered with the session key are subsequently stored in a storage medium of the TTP. It should be noted that above and below there is spoken of public and private keys. These are generally known. In general, a public and a private key constitute an asymmetric pair of keys. If a file or a code is enciphered with the public key of an asymmetric pair of keys, said file or code may be deciphered only with the help of the associated private key and vice versa. In general, the public keys are available to "the public", e.g., by way of a publicly accessible data base, such as www.pgp.com. In the present application, it is assumed that the users and the TTP each dispose of a pair of keys, each consisting of a public and a private key, and in particular intented for protecting the mutual data exchange of the files and codes. In addition, the TTP disposes of a pair of keys which is used within the TTP only; the "public" and private keys serve as protected storage or recovery ("secure retrieval"), as the case may be, of files and codes. The public storage key is not, as is normally the case for public keys, put at the disposal of the public.
"Re-encryption"
By way of "periodic maintenance" - from security considerations - the TTP server may at regular points in time store the file once again in the storage medium. For this purpose, the session key with which the file was enciphered is first recovered by deciphering - with the private storage key - the stored (enciphered) session key. Subsequently, the enciphered file stored in the storage medium is deciphered with the recovered session key.
The TTP server then generates a new asymmetric pair of storage keys, consisting of a new public storage key (which is not made available outside the TTP) and a new private storage key, and a new version of the symmetrical session key, whereafter
the TTP enciphers the deciphered file with the new session key and stores it in the storage medium.
The TTP also enciphers the new session key with the new public storage key and stores said enciphered session key in the storage medium.
"Secure Retrieval"
For protected recovery of the stored file, and transmission thereof to the first and/or second user, the symmetrical session key is recovered from the storage medium by deciphering, with the private storage key, the stored enciphered session key. The recovered session key is subsequently enciphered with the current public key of the first or second user, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, enciphered with the session key. After having received the enciphered session key, the user may recover the session key therefrom by deciphering with his private key. Subsequently, the user may decipher the file enciphered with the session key using the recovered session key.
"Digital Sign"
The public key of the first user may - as is well-known - be used to verify a digital signature of the file. A problem arises if - which frequently occurs - the first user at a certain point in time, after the file has been stored in the TTP server, generates a new pair of keys (comprising a public and a private key) and discontinues the old one. For this reason, it is of importance to store the (original) public key of the first user in the TTP server, since only said original key may be used for verifying the digital signature of the stored, later retrievable file.
For this case, the TTP server, after having received the enciphered file, also enciphers the - at that point in time publicly available - public key of the first user, with the public storage key, and stores said enciphered public key in the storage medium.
Periodically, the TTP server — as "periodical maintenance"
— deciphers the enciphered (original) public key, stored in the storage medium, of the first user having the private storage key,
and enciphers the deciphered public key of the first user having the newly generated public storage key, and stores said freshly enciphered key in the storage medium.
The public key of the first user may — upon retrieving the stored file — be recovered from the storage medium by deciphering, with the private storage key, said stored key. The public key of the first user recovered in this manner is subsequently enciphered with the — at that point in time publicly available — public key of the retrieving first or second user, and transmitted by way of the transmission channel. After having received said enciphered public key, the user may recover the original public key of the first user by deciphering his current private key; subsequently, the digital signature of the recovered file may be verified using the recovered original public key of the first user.
"Time Stamp"
If so desired, the TTP server, after the enciphered file has been received and stored, may generate a time stamp and store it, linked to the stored file and enciphered with the public storage key, in the storage medium. In the event of retrieving the stored file by the first or second user, the time stamp is deciphered and subsequently enciphered with the public key valid for said user and transmitted to the user. The user may decipher the enciphered time stamp with his current private key.
DESCRIPTION OF THE FIGURES
Below, the invention is illustrated in further detail by reference to several figures. Figures 1, 2 and 3 illustrate the functions "Secure Archiving", "Re-encryption" and "Secure
Retrieval", including the items "Digital Sign" and the "Time Stamp" .
FIG. l: "Secure Archiving" A file Txt is transmitted from a first user A to a second user B after having been enciphered with a symmetical session key SesKey. Said session key is enciphered with the public key FubKeyB of the second user. The latter may decipher the session key with his private key SecKeyB and the file itself with the deciphered session key.
b
The session key is also enciphered by the first user with the public key of the TTP server PubKeyTTP, which, after having received it, deciphers said session key with his private key SecKeyTTP . Thereafter the TTP server enciphers the deciphered session key with a "public" storage key PubStorKey of the TTP. The (transmission) keys of the users A and B each form an asymmetrical pair of keys, KeyPairA and KeyPairB, respectively, consisting of PubKeyA and SecKeyA, and PubKeyB and SecKeyB, respectively. The TTP uses the pair of keys KeyPairTTP, consisting of PubKeyTTP and SecKeyTTP. Finally, for the protected storage of an asymmetrical pair of keys StorKeyPair, consisting of the keys PubStorKey and SecStorKey; contrary to the preceding public keys, PubStorKey nor SecStorKey is publicly available, but is used exclusively within the TTP. The session key (SesKey) PubStorKey enciphered with the public storage key PubStorKey and the file (Txt) SesKey enciphered with the session key SesKey are subsequently stored in the storage medium DB of the TTP.
"Digital Sign"
The public key PubKeyA of the first user A may be used to verify a digital signature DigSign of the file Txt. In this case, the TTP server, after having received the enciphered file (Txt) SesKey, also enciphers the - at that point in time publicly available - public key PubKeyA from the first user A, with the public storage key PubStorKey, and stores said enciphered public key (PubKeyA) PubStorKey in the storage medium DB.
"Time Stamp" After having received and stored the enciphered file
(Txt) SesKey, the TTP server may generate a time stamp TSta p and store it, after enciphering with the public storage key PubStorKey and linked to the stored file, in the storage medium DB as (TStamp) PubStorKey.
FIG. 2: "Re-encryption"
As "periodical maintenance", the TTP server deciphers the enciphered file (Txt) SesKey stored in the storage medium with the session key SesKey, which for that purpose is recovered by deciphering the stored session key (SesKey) PubStorKey with the
private storage key SecStorKey. The TTP server subsequently generates a fresh pair of storage keys StorKeyPair, comprising a new "public" storage key PubStorKey' and a new private storage key SecStorKey' , as well as a new version of the symmetrical session key SesKey' . The TTP subsequently enciphers the deciphered file Txt with the new session key SesKey' and stores the file (Txt) SesKey' enciphered in this manner in the storage medium DB.
The TTP also enciphers the new session key with the new public storage key PubStorKey' and stores the session key
(SesKey' ) PubStorKey' enciphered in this manner in the storage medium DB.
"Digital Sign" During the periodical maintenance, the TTP server also deciphers the enciphered public key (PubKeyA) PubStorKey stored in the storage medium of the first user with the private storage key SecStorKey, and subsequently enciphers the deciphered public key PubKeyA with the newly generated public storage key PubStorKey' and stores the public key (PubKeyA) PubStorKey ' enciphered in this manner in the storage medium.
"Time Stamp"
During the periodical maintenance, the TTP server also deciphers the enciphered time stamp (TStamp) PubStorKey stored in the storage medium with the private storage key SecStorKey, and subsequently enciphers the deciphered time stamp with the newly generated public storage key PubStorKey' and stores the time stamp (TStamp) PubStorKey' enciphered in this manner in the storage medium.
FIG. 3: "Secure Retrieval"
For protected recovery of the file Txt, and the transmission thereof to the first and second users A and B, respectively, the symmetrical session key SesKey is recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored enciphered session key (SesKey) PubStorKe . The recovered session key SesKey is subsequently enciphered with the then current public key PubKeyA* or PubKeyB", as the case may be, from the querying first or
second user A or B, as the case may be, and transmitted to said user by way of the transmission channel, together with a copy of the file stored in the storage medium, with the user, after having received the enciphered session key (SesKey) PubKeyA*" or (SesKey) PubKeyB*" , being capable of recovering the session key therefrom by deciphering, with his private key SecKeyA" or SecKeyB", as the case may be, and subsequently being capable of deciphering the file (Txt) SesKey using the recovered session key.
"Digital Sign"
The original public key PubKeyA of the first user, necessary for verifying the digital signature of the recovered file, may be recovered from the storage medium by deciphering, with the private storage key SecStorKey, the stored public key (PubKeyA) PubStorKey of the first user enciphered with the public storage key. The deciphered public key PubKeyA of the first user recovered in this manner is subsequently enciphered with the current public key PubKeyA' or PubKeyB"", as the case may be, of the retrieving first or second user A or B, as the case may be, and transmitted to the user by way of the transmission channel . After having received said enciphered public key (PubKeyA) PubKeyA- or (PubKeyA) PubKeyB*" , as the case may be, the user may recover the original public key PubKeyA of the first user therefrom by deciphering, with his current private key SecKeyA"" or SecKeyB", as the case may be. Subsequently, the digital signature DigSign of the file Txt may be verified using the recovered public key PubKeyA of the first user.
It should be noted that it is preferable to - otherwise than is shown in FIG. 3 - not transmit the digital signature DigSign unencipheredly to the first or second user, as the case may be, but enciphered with the public key of user A or B, as the case may be: instead of "DigSign", the TTP server then transmits " (DigSign) PubKeyA""" or " (DigSign) PubKeyB*", as the case may be. At the user's side, the digital signature may be recovered by deciphering, with the private keys of A and B, SecKeyA and SecKeyB, respectively.
"Time Stamp"
When the stored file is retrieved by the first or second user, the time stamp is first retrieved by deciphering
(TStamp) PubStorKey with the private storage key SecStorKey. The recovered time stamp is subsequently enciphered with the user's current public key PubKeyA' or PubKeyB' , as the case may be, and transmitted to said user. Thereafter, the user may decipher the enciphered time stamp (TStamp) PubKeyA' or (TStamp) PubKeyB" , as the case may be, with his current private key SecKeyA' or SecKeyB ' , as the case may be .
Claims
1. System for protectedly storing and managing, in a TTP server, copies of digital files which are transmitted, by way of a transmission channel, from a first to a second user, characterised in that a file (Txt) is transmitted from the first user (A) to a second user (B) after having been enciphered with a symmetrical session key (SesKey) , which session key is enciphered using the public key (PubKeyB) of a first asymmetrical pair of keys (KeyPairB) associated with the second user, which second user, after having received it, may decipher the session key using the private key (SecKeyB) of said first asymmetrical pair of keys (KeyPairB) and subsequently may decipher the file using the session key deciphered in this manner, the session key (SesKey) also being enciphered by the first user (A) using the public key (PubKeyTTP) of a second asymmetrical pair of keys (KeyPairTTP) associated with the TTP server, which TTP server, after having received it, deciphers said session key using the private key (SecKeyTTP) from said second asymmetrical pair of keys (KeyPairTTP) , whereafter the TTP server enciphers the deciphered session key (SesKey) using the public key of a third asymmetrical pair of keys (StorKeyPair) , hereinafter to be referred to as public storage key (PubStorKey) , and stores the session key ( (SesKey) PubStorKey) enciphered with said storage key, together with the file ( (Txt) SesKey) enciphered with the session key (SesKey) , in a storage medium (DB) .
2. System according to claim 1, characterised in that, periodically, the TTP server deciphers the enciphered file ( (Txt) SesKey) stored in the storage medium with the session key (SesKey) , which for that purpose is recovered in advance by deciphering the stored enciphered session key ( (SesKey) PubStorKey) with the private key of the third pair of keys (StorKeyPair) , hereinafter to be referred to as the private storage key (SecStorKey) ; the TTP server subsequently generates a new version of the third pair of keys, comprising a new public storage key
(PubStorKey') and a new private storage key (SecStorKey1), and a new version of the symmetrical session key (SesKey1), whereafter the TTP enciphers the deciphered file (Txt) with the new session key (SesKey1) and stores the file
( (Txt) SesKey ' ) enciphered in this manner in the storage medium (DB) ; the TTP server enciphers the new session key (SesKey') with the new public storage key (PubStorKey1) and stores the session key ( (SesKey' ) PubStorKey' ) enciphered in this manner in the storage medium (DB) .
3. System according to claim 1, characterised in that, for protected recovery of the file (Txt) and transmission thereof to the first user (A) or the second user (B) , as the case may be, the symmetrical session key (SesKey) is recovered from the storage medium by deciphering, with the private storage key (SecStorKey) , the stored enciphered session key ( (SesKey) PubStorKey) , whereafter the recovered session key
(SesKey) is subsequently enciphered with the current public key (PubKeyA' or PubKeyB', as the case may be) of the first or second user (A or B, as the case may be) , and is transmitted to the user by way of the transmission channel, together with a copy of the file ( (Txt) SesKey) stored in the storage medium, with the user, after having received the enciphered session key
( (SesKey) PubKeyA' or (SesKey) PubKeyB' , as the case may be), being capable of recovering the session key therefrom by deciphering using the user's private key (SecKeyA' or SecKeyB', as the case may be) , and subsequently being capable of deciphering the enciphered file ( (Txt) SesKey) using the recovered session key.
4. System according to claim 1, the public key (PubKeyA) of the first user (A) being used to verify a digital signature (DigSign) of the file (Txt) , characterised in that the TTP server, after having received the enciphered file ( (Txt) SesKey) , also enciphers the then current public key (PubKeyA) of the first user (A) using the public storage key (PubStorKey) , and stores said enciphered public key ( (PubKeyA) PubStorKey) in the storage medium (DB) .
5. System according to claim 4, characterised in that, periodically, the TTP server deciphers the enciphered public key (PubKeyA) of the first user stored in the storage medium with the private storage key (SecStorKey) ; the TTP server subsequently generates a new version of the third pair of keys, comprising a new public storage key (PubStorKey1) and a new private storage key (SecStorKey1); - the TTP server enciphers the deciphered public key
(PubKeyA) of the first user with the new public storage key (PubStorKey1) and stores said public key
( (PubKeyA) PubStorKey') , enciphered in this manner, in the storage medium.
6. System according to claim 4 , characterised in that the public key (PubKeyA) of the first user is recovered from the storage medium by deciphering, with the private storage key (SecStorKey) , the stored enciphered public key ( (PubKeyA) PubStorKey) of the first user, that said original public key (PubKeyA) recovered in this manner is subsequently enciphered with the current public key (PubKeyA1 or PubKeyB1, as the case may be) of the first or second user (A or B, as the case may be) , and is transmitted by way of the transmission channel to the first or second user, as the case may be, with the user, after having received said enciphered public key ((PubKeyA) ubKeyA' or (PubKeyA) PubKeyB1 , as the case may be) being capable of recovering the original public key (PubKeyA) of the first user therefrom by deciphering with his current private key (SecKeyA1 or SecKeyB1, as the case may be), and subsequently being capable of verifying the digital signature (DigSign) of the file (Txt) using the original public key (PubKeyA) of the first user recovered in this manner.
7. System according to claim 6, characterised in that the digital signature (DigSign) is enciphered with the current public key (PubKeyA1 or PubKeyB1, as the case may be) of the first or second user (A or B, as the case may be) , and is transmitted to said first or second user, as the case may be, whereafter the receiving user recovers the digital signature by deciphering the received, enciphered digital signature ( (DigSign) PubKeyA' or (DigSign) PubKeyB ' , as the case may be) with his private key (SecKeyA1 or SecKeyB1, as the case may be).
8. System according to claim 1, characterised in that the TTP server, after having received the enciphered file ( (Txt) SesKey) generates a time stamp (TStamp) and stores it, linked to the stored file and enciphered with the public storage key (PubStorKey) , in the storage medium (DB) .
9. System according to claim 8, characterised in that, in the event of retrieving the stored file by the first or second user (A or B, as the case may be) the enciphered time stamp ( (TStamp) PubStorKey) is recovered by deciphering with the private storage key (SecStorKey) , the recovered time stamp is subsequently enciphered with the current public key (PubKeyA1 or PubKeyB1, as the case may be) for the querying user, and is transmitted to said user, whereafter the user may decipher the enciphered time stamp ( (TStamp) PubKeyA' or (TStamp) PubKeyB' , as the case may be) with the private key (SecKeyA' or SecKeyB', as the case may be) current for said user.
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| NL1012435A NL1012435C2 (en) | 1999-06-25 | 1999-06-25 | System for secure storage and management in a TTP server. |
| NL1012435 | 1999-06-25 | ||
| PCT/EP2000/005642 WO2001001629A1 (en) | 1999-06-25 | 2000-06-19 | System for protected storage and management in a ttp server |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1197034A1 true EP1197034A1 (en) | 2002-04-17 |
Family
ID=19769452
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP00942100A Withdrawn EP1197034A1 (en) | 1999-06-25 | 2000-06-19 | System for protected storage and management in a ttp server |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP1197034A1 (en) |
| AU (1) | AU5683800A (en) |
| NL (1) | NL1012435C2 (en) |
| WO (1) | WO2001001629A1 (en) |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2002271312A (en) * | 2001-03-14 | 2002-09-20 | Hitachi Ltd | Public key management method |
| GB0215911D0 (en) | 2002-07-10 | 2002-08-21 | Hewlett Packard Co | Method and apparatus for encrypting data |
| US8984636B2 (en) | 2005-07-29 | 2015-03-17 | Bit9, Inc. | Content extractor and analysis system |
| CN108471404B (en) * | 2018-02-28 | 2020-10-16 | 深圳市达仁基因科技有限公司 | File sharing method and device, computer equipment and storage medium |
| EP3899911A1 (en) * | 2018-12-19 | 2021-10-27 | Telit Communications S.P.A. | Systems and methods for managing a trusted application in a computer chip module |
| CN118678126B (en) * | 2024-08-21 | 2024-10-25 | 杭州海康威视数字技术股份有限公司 | Self-adaptive cross-domain code stream password security protection method, system and equipment |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5001752A (en) * | 1989-10-13 | 1991-03-19 | Fischer Addison M | Public/key date-time notary facility |
| US6584565B1 (en) * | 1997-07-15 | 2003-06-24 | Hewlett-Packard Development Company, L.P. | Method and apparatus for long term verification of digital signatures |
-
1999
- 1999-06-25 NL NL1012435A patent/NL1012435C2/en not_active IP Right Cessation
-
2000
- 2000-06-19 EP EP00942100A patent/EP1197034A1/en not_active Withdrawn
- 2000-06-19 WO PCT/EP2000/005642 patent/WO2001001629A1/en not_active Ceased
- 2000-06-19 AU AU56838/00A patent/AU5683800A/en not_active Abandoned
Non-Patent Citations (1)
| Title |
|---|
| See references of WO0101629A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2001001629A1 (en) | 2001-01-04 |
| NL1012435C2 (en) | 2000-12-28 |
| AU5683800A (en) | 2001-01-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US6819766B1 (en) | Method and system for managing keys for encrypted data | |
| US6160891A (en) | Methods and apparatus for recovering keys | |
| US6317829B1 (en) | Public key cryptography based security system to facilitate secure roaming of users | |
| US20070168656A1 (en) | Method for enabling a user to initiate a password protected backup of the user's credentials | |
| US6370250B1 (en) | Method of authentication and storage of private keys in a public key cryptography system (PKCS) | |
| US8296827B2 (en) | Method for enabling an administrator to configure a recovery password | |
| US20100005318A1 (en) | Process for securing data in a storage unit | |
| US20050094817A1 (en) | Method and system for multiple symmetric encryption for .ZIP files | |
| CN103546547B (en) | A kind of cloud storage file encryption system | |
| KR970067054A (en) | How to Create and Distribute Password Envelopes | |
| CN105681031B (en) | A kind of storage encryption gateway key management system and method | |
| CN102088443B (en) | Method and system for subscribing digital periodical with copyright protection | |
| WO2001097440A3 (en) | Encryption system that dynamically locates keys | |
| EP0892521A3 (en) | Method and apparatus for long term verification of digital signatures | |
| CN101924739A (en) | Method for encrypting, storing and retrieving software certificate and private key | |
| CN101388774A (en) | Method for automatically authenticate and recognize customer identity between different customers and login | |
| US7770213B2 (en) | Method and apparatus for securely forgetting secrets | |
| WO2007089266A3 (en) | Administration of data encryption in enterprise computer systems | |
| CA2251193A1 (en) | Method and apparatus for encoding and recovering keys | |
| EP1197034A1 (en) | System for protected storage and management in a ttp server | |
| WO2008065351A1 (en) | Self encryption | |
| KR100586030B1 (en) | How to Manage Encryption Key Recovery Information | |
| CN108173880B (en) | File encryption system based on third party key management | |
| CN116346497A (en) | Mechanism for supporting audit of end-to-end encryption | |
| Anton et al. | Linux unified key setup (LUKS)-the good, the bad, the ugly |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20020125 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE |
|
| AX | Request for extension of the european patent |
Free format text: AL;LT;LV;MK;RO;SI |
|
| 17Q | First examination report despatched |
Effective date: 20030404 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20031015 |