EP4179694A1 - Bereitsteller- und empfänger-kryptosysteme mit kombinierten algorithmen - Google Patents
Bereitsteller- und empfänger-kryptosysteme mit kombinierten algorithmenInfo
- Publication number
- EP4179694A1 EP4179694A1 EP21742801.0A EP21742801A EP4179694A1 EP 4179694 A1 EP4179694 A1 EP 4179694A1 EP 21742801 A EP21742801 A EP 21742801A EP 4179694 A1 EP4179694 A1 EP 4179694A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- cryptographic
- data
- algorithms
- algorithm
- cryptosystem
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
- H04L9/16—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0825—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/088—Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
Definitions
- the invention relates to a method and system for data exchange between two cryptographic systems using an asymmetric cryptographic algorithm.
- Asymmetric cryptographic algorithms also referred to as asymmetric cryptographic methods, consist of two functionally complementary cryptographic algorithms that are to be executed by the respective participants in the method, such as encryption and decryption, signing and signature verification. tion and key agreement procedures. The types of procedures mentioned are indispensable for security-related IT applications. At the moment there are only a few asymmetric cryptographic methods in practical use. This is probably at least partly due to the fact that asymmetric cryptographic methods often have several participants who are organisationally independent. All participants must support a specific asymmetric cryptographic method (e.g.
- a problem with this approach is the need to rewrite the software used to perform the cryptographic operations, because the additional cryptographic data is no longer contained in the fields in which the participants previously expected this data according to established cryptographic standards.
- the approach is limited to X.509 certificates and requires the definition of certificate verifications for these certificates.
- the invention is based on the object of creating an improved method and system for data exchange between a provider cryptosystem and a recipient cryptosystem.
- the objects on which the invention is based are each achieved with the features of the independent patent claims.
- Embodiments of the invention are given in the dependent claims. the The embodiments listed below can be freely combined with one another, provided they are not mutually exclusive.
- the invention relates to a method for data exchange between a provider cryptosystem and a recipient cryptosystem.
- the procedure includes:
- the input data can be, for example, a data value, a data set, a key, a part of a key, a message, a part of the message or one derived from the data value, the data set, the key, the message or a part of the message value (e.g. a flash value of the message).
- the result data can be, for example, a reconstructed copy of at least parts of the input data, the result of a signature check, a jointly agreed or random key, or the like.
- the provision of the combined cryptographic data can, for example, take place directly via an interface between the two cryptosystems, for example by the provider cryptosystem sending a message with the combined generated cryptographic data and transmitted it to the recipient cryptosystem, for example via a network, for example the Internet.
- the provider cryptosystem may provide the composite cryptographic data indirectly, e.g., by storing the composite cryptographic data in a storage medium readable by the recipient cryptosystem.
- the data can be stored in a database, e.g. an archive.
- the recipient cryptosystem then reads the composite cryptographic data from the database.
- the provider cryptosystem and the receiver cryptosystem are different cryptosystems.
- the provider cryptosystem and the recipient cryptosystem can be identical.
- the provider cryptosystem can first generate the composite cryptographic data by encrypting input data and store it in a database. At a later point in time, possibly years later, the same cryptosystem reads this data again in its function as recipient cryptosystem and has to decrypt the data again.
- embodiments of the invention may be used to make RSA cryptosystems quantum computer secure.
- RSA is an asymmetric cryptographic method that can be used by RSA cryptosystems for both encryption and digital signing. It uses a key pair consisting of a private key, which is used to decrypt or sign data, and a public key, which is used to encrypt or verify signatures. The private key is kept secret and cannot be calculated from the public key.
- the security of the RSA method is essentially based on the difficulty of factoring large numbers. This security is called into question by the advent of quantum computers, so that embodiments of the invention can be used to use RSA algorithms as the first and/or second cryptographic algorithms together with other quantum computer-safe algorithms to generate or create composite cryptographic signatures process.
- embodiments of the invention can also be used to calculate algorithms such as DSA and DH, whose security is based on the difficulty of finding the discrete logarithm, and the algorithms ECDSA and ECDH, whose security is based on the difficulty of finding the discrete logarithm on elliptic rule Curves consists of replacing with quantum computer-safe algorithms.
- algorithms such as DSA and DH, whose security is based on the difficulty of finding the discrete logarithm
- ECDSA and ECDH whose security is based on the difficulty of finding the discrete logarithm on elliptic rule Curves consists of replacing with quantum computer-safe algorithms.
- the provider cryptosystem only provides the composed cryptographic data and preferably also an identifier of the second control algorithm and optionally parameters for the implementation of the second control algorithm.
- additional data is also provided.
- the composite cryptographic data may be a composite signature of a message.
- the electronic document for which the signature was generated is preferably provided in addition to the composite signature.
- Embodiments of the invention may have the advantage that both the provider cryptosystem and the recipient cryptosystem are highly flexible. Both on the provider cryptosystem and on the receiver cryptosystem, several algorithms, each functionally complementary, for example, which belong to different asymmetric cryptographic methods, can be implemented. These are now selected and/or combined according to the information in the first or second control algorithm in order to generate the composite cryptographic data.
- the composite cryptographic data can thus contain the results of two or more different first cryptographic algorithms. This can mean, for example, that the composite cryptographic data contains multiple digital signatures that were generated for the same electronic document using different signature algorithms (first cryptographic algorithms).
- the transmission of such a composite signature to the recipient system has the advantage that at least when the recipient system supports at least one signature verification algorithm that corresponds to a signature generation algorithm used to generate the composite signature, the recipient system may already be able to do so to verify the signature.
- the composite cryptographic data can also be be a composite encrypted data set generated by encrypting input data using multiple cryptographic keys (in parallel or sequentially), or a communication key generated by combining multiple participant-specific key agreement algorithms. Since the combined cryptographic data transmitted is composed of the cryptographic output of two or more different first cryptographic algorithms, the information content of the transmitted data is higher than if only the output of a single cryptographic algorithm were transmitted. This allows the recipient cryptosystem to respond in a very flexible way.
- the second control algorithm can be specified in such a way that several second cryptographic algorithms must be successfully applied to the composite cryptographic data obtained in order for a correct result or a confirmation of integrity to be obtained of the signed document is obtained.
- the first control algorithm specifies a selection and/or sequence of first cryptographic algorithms that is functionally complementary to the selection and/or sequence of the second cryptographic algorithm(s) specified in the second control algorithm.
- the provisioning cryptosystem can contain multiple encryption algorithms V1-V10.
- the receiver cryptosystem can contain several decryption algorithms E1-E10, each of which is complementary to the corresponding encryption algorithm.
- E1 can decrypt a ciphertext formed by V1
- E2 can decrypt a ciphertext formed by V2, and so on be applied as follows:
- V1 (input data) output1 ;
- V2(Output1 ) Output2;
- the individual encryption algorithms can also be used in parallel, so that the combined cryptographic data can be formed, for example, as a concatenation of the individual ciphertext.
- the second control algorithm could identify one or more decryption keys, which are then combined and applied to the corresponding ciphertext in such a way that the original input data or parts thereof are reconstructed.
- the provider cryptosystem implements several first control algorithms.
- the recipient cryptosystem implements a number of second control algorithms.
- a large number of first and/or second control algorithms can be advantageous, since this allows the provider and the recipient cryptosystem to agree in a very flexible manner which cryptographic algorithms are to be used in which sequence in order to ensure data exchange in to be carried out in the desired manner.
- Such changes may be necessary for various reasons. For example, it may turn out that a certain cryptographic algorithm is no longer secure enough or is technically problematic for other reasons. In this case it is possible to change only one algorithm identifier of the first cryptographic algorithms used in the creation of the combined cryptographic data within the first control algorithm.
- the first and/or second control algorithms are in the form of editable instructions, such as a script file, rule, or configuration file. It is also possible Leaned that the first control algorithm to generate the composite cryptographic data uses a larger number of first cryptographic algorithms than the second control algorithm to process this data. This can have the advantage that several different first cryptographic algorithms of the same type of procedure (eg For example, several different signing algorithms or several different encryption algorithms or several different provider-side key agreement algorithms) are used to generate the composite cryptographic data. At least if the different first algorithms are used in parallel, it may be sufficient for the second control algorithm to use a single one second cryptographic algorithm is specified, which is able to correctly process at least part of the composite cryptographic data.
- At least one of the first cryptographic algorithms is an encryption, signing, or key agreement algorithm.
- At least one of the one or more second cryptographic algorithms is an algorithm complementary to the at least one first cryptographic algorithm for decryption, signature verification and key agreement
- each of the first cryptographic algorithms is assigned an algorithm identifier (also “algorithm identifier”).
- the provider cryptosystem is designed to provide the assembled cryptographic data together with parameters for the execution of the second control algorithm.
- the parameters for the execution of the second control algorithm comprise algorithm identifiers of the second cryptographic algorithms to be used by the second control algorithm for processing the combined cryptographic data.
- the algorithm identifiers of the second cryptographic algorithms can be identical to the algorithm identifiers of the first cryptographic algorithms used to generate the composite cryptographic data.
- the algorithm identifier of the "RSA" method can be used both by the first control algorithm to identify a first cryptographic algorithm that implements the provider-side steps of the RSA method and by the second control algorithm to identify a second cryptographic algorithm identify who implements the receiver-side steps of the RSA method.
- the parameters for the execution of the second control algorithm include one or more parameters which control the individual second cryptographic algorithms and are transferred, for example, as arguments to these second cryptographic algorithms.
- These parameters are also referred to below as "component parameters”.
- the component parameters can be identical or different. be different from the component parameters used by the corresponding first cryptographic algorithms.
- the parameters for the execution of the second control algorithm also include input parameters for the second control algorithm, which are used by it directly, ie do not serve as input parameters of individual second cryptographic algorithms. These parameters, which directly control the execution of the second control algorithm, are referred to below as control parameters.
- the control parameters can, for example, specify the minimum number of second cryptographic algorithms that must be successfully executed for the result obtained to be considered valid.
- the second control algorithm is designed to select the second cryptographic algorithm or algorithms used for the calculation of the result data using an algorithm identifier contained in the parameters.
- the algorithm identifier of the first and second cryptographic algorithms which are functionally complementary to one another, is identical and designates an asymmetric cryptographic method of which the first cryptographic algorithm implements the provider-side steps and of which the second cryptographic algorithm implements the receiver-side steps.
- the algorithm identifiers of the first and second cryptographic algorithms are each selected from a group comprising:
- an algorithm identifier of a key agreement algorithm between a first and a second subscriber system wherein the first cryptographic algorithm identified by the algorithm identifier implements the steps performed by the first subscriber system for key agreement and wherein the functionally complementary second cryptographic algorithm implements the steps performed by the second subscriber system for key agreement implemented;
- An algorithm identifier of an asymmetric cryptographic algorithm for encrypted transmission from a first subscriber system to a second subscriber system the first cryptographic algorithm identified by the algorithm identifier implementing the steps carried out by the first subscriber system for encrypting data in a ciphertext and the functionally complementary second cryptographic algorithm implements the steps performed by the second subscriber system for decrypting the ciphertext;
- an algorithm identifier of an asymmetric cryptographic algorithm for creating a digital signature by a first subscriber system and for checking this signature by a second subscriber system the first cryptographic algorithm identified by the algorithm identifier implementing the steps performed by the first subscriber system for generating the signature and wherein the functional complementary second cryptographic algorithm implemented by the second subscriber system steps to check the signature.
- Embodiments of the invention can thus support a large number of different cryptosystems and their conversion to other, possibly more secure, cryptographic algorithms.
- the first control algorithm specifies that the plurality of first cryptographic algorithms are sequentially applied to the output of the previously executed first cryptographic algorithm.
- the first control algorithm may specify that the plurality of first cryptographic algorithms are applied to the input data or portions of the input data in parallel.
- the provider cryptosystem may include a plurality of first control algorithms, some of which provide for parallel execution and others of which provide for sequential execution of a plurality of first cryptographic algorithms.
- the second control algorithm specifies that the plurality of second cryptographic algorithms are applied sequentially to the output of the previously executed second cryptographic algorithm, or that the plurality of second cryptographic algorithms are applied in parallel to the composite cryptographic data or parts of the composite cryptographic data .
- a sequential execution of algorithms can be advantageous in application scenarios where a particularly high level of security is required. Because both the provider side and the receiver side must support and execute several cryptographic algorithms at the same time in order to transform input data correctly into the composite cryptographic data or to reconstruct or verify this input data using the composite cryptographic data. Running algorithms in parallel can be advantageous in application scenarios where compatibility with a large number of heterogeneous receiver systems that may support different algorithms of the same type is to be established. Because when the first cryptographic algorithms are used in parallel, the composite cryptographic data preferably includes partial data that can be processed individually by a corresponding cryptographic algorithm, regardless of whether the receiver system supports all second cryptographic algorithms that are required to process all of these partial data would be required. This can have the advantage of providing a particularly flexible, adaptable data exchange method for cryptosystems for the most varied of applications and security requirements.
- the second control algorithm is a complementary algorithm to the first control algorithm that specifies that the plurality of second cryptographic algorithms are to be applied in a functionally complementary sequential or parallel manner to the composite cryptographic data and/or the output of the respectively previously applied second algorithm , as specified in the first control algorithm.
- the first control algorithm can provide for a sequential application of the first encryption algorithms V1, V2 and V3 and the second control algorithm must provide for a sequential application of the corresponding decryption algorithms E3, E2 and E1.
- At least the first control algorithm contains Boolean operators and/or arithmetic operators which connect several of the first cryptographic algorithms with one another, the operators specifying how the cryptographic data output by the individual first cryptographic algorithms is to be processed combine to obtain the composite cryptographic data.
- the second control algorithm contains Boolean operators and/or arithmetic operators, which connect several of the second cryptographic algorithms with one another in such a way that their combined application to the transmitted composite cryptographic data and/or to an output of a previously executed second cryptographic Algorithm leads to a functionally complementary data processing to the execution of the first cryptographic algorithms.
- the first (or second) cryptographic algorithms may implement provider-side (or receiver-side) steps of different cryptographic key agreement keys.
- the first (or second) control algorithm may contain instructions and arithmetic operators that specify how the keys generated by each first (or second) cryptographic algorithm can be combined into a 'final key'.
- the combination can be done bit by bit using an XOR combination. It is also possible that a bit of a certain key (or several of the keys) is entangled (eg by multiplication or addition) by a factor (eg "3" or any other number) according to an arithmetic operator.
- first and second control algorithms can be defined that must functionally correspond to each other and can be used, for example, in applications where knowledge of a specific control algorithm (and its exact operators and factors) is required to prove identity or authorization is used.
- the first and/or second control algorithm have an identifier.
- the first and have one to this functionally complementary second control algorithm a common identifier.
- this identifier (and the corresponding functionality of the control algorithms) is designed as one of the following identifiers (whereby the provider cryptosystem and/or the recipient cryptosystem can contain several control algorithms that use different ones of the following mentioned identifiers and functions supported):
- the SIGNATURE AND identifier identifies a first control algorithm of the provider cryptosystem.
- This first control algorithm specifies that a signature is to be calculated in each case by means of one or more first cryptographic algorithms, each of which implements a signing algorithm.
- the SIGNATURE AND identifier identifies a second control algorithm of the recipient cryptosystem, which specifies, by means of one or more second cryptographic algorithms, each of which implements a signature verification algorithm, to verify a signature that corresponds to this signature verification algorithm (i.e. is functionally complementary ) signing algorithm was created.
- the second control algorithm specifies that the result data is calculated in such a way that it confirms the integrity and/or authenticity of the composed cryptographic data precisely when all of the signature checks carried out by the signature checking algorithms show that the checked signature is valid.
- the SIGNATURE-OR identifier identifies a first control algorithm of the provider cryptosystem. This first control algorithm specifies that a signature is to be calculated in each case by means of one or more first cryptographic algorithms, each of which implements a signing algorithm.
- the SIGNATURE-OR identifier identifies a second control algorithm of the recipient cryptosystem.
- the second control algorithm specifies that one or more second cryptographic algorithms, each of which implements a signature verification algorithm, are used to verify a signature that was created using a signature verification algorithm that corresponds to the signature verification algorithm, at least until at least one of the signature verification algorithms comes to the conclusion that the signature is valid or until all signature verification algorithms of the recipient cryptosystem have been carried out.
- the result data are calculated in such a way that they confirm the integrity and/or authenticity of the combined cryptographic data precisely when at least one of the signature verification algorithms has the result that the signature checked in each case is valid.
- the SIGNATURE K out of N identifier identifies a first control algorithm of the provider cryptosystem.
- This first control algorithm specifies that a signature is to be calculated in each case by means of one or more first cryptographic algorithms, each of which implements a signing algorithm.
- the SIGNATURE K out of N identifier identifies a second control algorithm of the recipient cryptosystem.
- the second control algorithm specifies, by means of K second cryptographic algorithms, each of which implements a signature verification algorithm, to verify a signature that was created using a corresponding signing algorithm, at least until at least K of the signature verification algorithms come to the conclusion that the respectively verified signature is valid or until all of the signature verification algorithms have been performed.
- the result data are calculated in such a way that they confirm the integrity and/or authenticity of the assembled cryptographic data precisely when at least K of the signature verification algorithms result in the signature being verified being valid, with K being a number greater than 0, preferably greater 1 is K and N are integers greater than 0, with N being greater than or equal to K.
- the "Signature K out of N” method is an example of how the parametric specifications of two functionally complementary first and second control algorithms can be different.
- the parameter “K” has no function in the provider system.
- it defines the minimum number of second cryptographic algorithms that must be successfully applied to the composed cryptographic data in order to be able to successfully complete the procedure (e.g. signature verification, key agreement, decryption, etc.).
- the KEY AGREEMENT AGGREGATE identifier identifies a first control algorithm of the provider cryptosystem.
- This first control algorithm specifies using one or more first cryptographic algorithms, each of which implements key agreement steps on the provider side according to a specific key agreement method, to calculate a cryptographic key in each case and to calculate a final key by aggregating all of these keys.
- the aggregation may include the steps of: bringing all keys to a uniform length, e.g., by truncating some of the keys to a predefined length and/or padding some of the keys to the desired length with predefined values; bitwise aligning (matching) the keys of predefined length; and aggregating the bit information of the aligned keys bit by bit using an XOR function or another aggregation function.
- the result is an end key of the desired length.
- any other function that aggregates the bits of several keys at a specific position in a defined way can also be used.
- the KEY AGREEMENT AGGREGATE identifier identifies a second control algorithm of the recipient cryptosystem.
- the second control algorithm specifies, by means of one or more second cryptographic algorithms, the respective receiver-side steps of a key agreement method implement computing a cryptographic key at a time, and computing a final key by aggregating all of these keys.
- the DATA ENCRYPTION ITERATIVE identifier identifies a first control algorithm of the provider cryptosystem.
- the first control algorithm specifies that a ciphertext is to be calculated according to a specific encryption method using one or more first cryptographic algorithms, each of which implements an encryption algorithm.
- the encryption algorithms are executed sequentially.
- the first encryption algorithm executed uses the input data as input and all encryption algorithms executed subsequently use the ciphertext generated by the previously executed encryption algorithm as input.
- the DATA ENCRYPTION ITERATIVE identifier identifies a second control algorithm of the receiver cryptosystem.
- the second control algorithm specifies using one or more second cryptographic algorithms, each of which implements a decryption algorithm, to decrypt a ciphertext according to a specific decryption method in order to obtain decrypted data.
- the decryption algorithms are executed sequentially.
- the first decryption algorithm executed uses the ciphertext provided by the provider computer system as input and all subsequently executed decryption algorithms use the decrypted data generated by the previously executed decryption algorithm as input.
- the decryption algorithm executed first (second cryptographic algorithm) are made available to the recipient cryptosystem.
- the component parameters of the second cryptographic algorithms performed later are then only extracted step by step in the course of the sequential decryption, for example when the first control algorithm applies the individual encryption algorithms to the output of the previously executed encryption algorithm.
- the algorithm identifiers and component parameters required by some algorithms of all second cryptographic algorithms to be executed can be seen directly from the parameters provided by the provider cryptosystem in addition to the combined cryptographic data, so that the recipient cryptosystem can determine all the second cryptographic algorithms before the start of execution whether it supports all of the second cryptographic algorithms defined in the parameters for the second control algorithm by means of the algorithm identifiers.
- the DATA ENCRYPTION- PARALLEL identifier identifies a first control algorithm of the provider cryptosystem.
- the first control algorithm specifies calculating a ciphertext using one or more first cryptographic algorithms, each of which implements an encryption algorithm, with each of the encryption algorithms using the input data or parts thereof as input.
- the DATA ENCRYPTION- PARALLEL identifier identifies a second control algorithm of the recipient cryptosystem.
- the second control algorithm specifies using a plurality of second cryptographic algorithms, each of which implements a decryption algorithm, to decrypt a ciphertext according to a specific decryption method in order to obtain decrypted data, with each of the decryption algorithms using the ciphertext provided by the provider computer system as a inputs used.
- the parallel encryption of data using several encryption methods can make sense, particularly in the context of encrypted data archives, to ensure that even after years and decades, at least one decryption method that is then still widespread can be used to at least extract the partial data corresponding to this decryption method from the composite cryptographic to be able to decrypt the data set.
- KEY CONTAINER The KEY-CONTAINER identifier identifies a first control algorithm of the provider cryptosystem. This first control algorithm specifies how an individual, composite key is formed using one or more first cryptographic algorithms, each of which describes a key.
- This composite key can, for example, be a concatenate of individual keys, each of which is formed by one of the first cryptographic algorithms.
- the individual cryptographic keys can have different functions, e.g. serve as an encryption key or signing key or decryption key or signature verification key.
- the execution of a "KEY CONTAINER" control algorithm can thus be used to form a key concatenate, which serves as a container for several cryptographic keys of the same or different function.
- the recipient cryptosystem can be provided with a large number of keys for a wide variety of purposes, so that the number of data exchange steps and the associated number of data exchanges via the network increases Amount of data transferred Reduced resource consumption for establishing a connection.
- the KEY-CONTAINER identifier also identifies a second control algorithm of the recipient cryptosystem, which specifies how one or more cryptographic keys can be extracted from the composite cryptographic data and/or used via one or more second cryptographic algorithms.
- the second cryptographic algorithms used by the second control algorithm each specify a method for extracting, reconstructing and/or using a cryptographic key from those parts of the composite cryptographic data that was created using a first cryptographic algorithm that corresponds to this second cryptographic algorithm.
- the result data consist of the cryptographic keys extracted and/or reconstructed from the container or the combined cryptographic data.
- the composite cryptographic data contains algorithm identifiers and optionally component parameters of at least some of the second cryptographic algorithms to be used for processing the composite cryptographic data.
- the algorithm identifiers and component parameters can be part of the assembled cryptographic data, eg in some embodiments with iterative encryption the algorithm identifiers and component parameters provided by the previously executed encryption algorithm can also be encrypted in order to form a ciphertext.
- the algorithm identifiers and optional component parameters are provided separately but together with the composite cryptographic data (and optional control parameters for the second control algorithm). This has the advantage that the recipient cryptosystem can very quickly determine by analyzing the separately provided algorithm identifiers whether it can perform the second control function with the second cryptographic algorithms identified by the algorithm identifiers at all, or whether individual second cryptographic algorithms, for example are not supported at all.
- the composite cryptographic data can be provided, for example, in the same data structure together with the said parameters (algorithm identifiers of the second cryptographic algorithms to be used by the second control algorithm and optional component parameters of these second cryptographic algorithms and control parameters), the composite cryptographic data and the parameters eg are stored in different fields.
- the algorithm identifier of the individual second cryptographic algorithms can, for example, be an identifier of the cryptographic method implemented by the respective first cryptographic algorithm, such as "RSA" or "DH” or the algorithm identifiers used according to established standards.
- Embodiments can have the advantage that the provider cryptosystem can ensure a minimum level of security on the receiver side during data processing by specifying the selection of the second cryptographic algorithms by the first control function and storing them in the data structure. Precise knowledge of the recipient cryptosystem Supported cryptographic algorithms is not necessary, however, since a second control algorithm, which provides an OR or K-out-of-N operation, can also work if only a single or an arbitrarily composed selection K of the second cryptographic algorithms specified in the data structure provided is used supported by the receiving system.
- the recipient cryptosystem could perform a first control function which is a SIGNATURE OR control function and which applies three different signing methods to input data to obtain the composite cryptographic signature, namely RSA, Tesla and Dilithium.
- the data structure provided contains the "SIGNATURE-OR" identifier of the second control algorithm and the corresponding algorithm identifiers Tesla, Dilithium and RSA of the second signature verification method to be combined. This means that older, non-quantum-secure recipient cryptosystems can also check the composite signature, provided they support RSA. Receiver systems that have already completely switched to quantum-secure processes such as Tesla or Dilithium can also check the composite signature.
- the method also includes an identification of each of the second cryptographic algorithms used for the calculation of the result data within a plurality of second cryptographic algorithms by the recipient cryptosystem before or during the calculation of the result data using the algorithm identifier, provided along with the composite cryptographic data.
- Each of the identified second cryptographic algorithms implements receiver system-side steps of the same cryptographic method as a sem corresponding (functionally complementary) first cryptographic algorithm.
- one of the first cryptographic methods is an RSA algorithm
- an identifier identifying the RSA algorithm is provided as the algorithm identifier of that first cryptographic algorithm by the provider cryptosystem along with the composite cryptographic data.
- the RSA algorithm identifier thus also automatically determines that the second cryptographic algorithm corresponding to it is RSA.
- the identifier of the second control algorithm and optionally its control parameters are provided by the provider cryptosystem, but not algorithm identifiers and control parameters of the individual second cryptographic algorithms.
- the identifier of the second control algorithm only determines the type of combination of the individual second algorithms (e.g. AND or OR variant, SEQUENTIAL or PARALLEL variant, K out of N variant, etc.), not the selection of the second algorithm.
- the recipient cryptosystem can be configured, for example, in such a way that all second cryptographic algorithms supported by the recipient system are used and combined according to the second control algorithm.
- the second control algorithm is provided as a template that is completed by the recipient cryptosystem in response to receipt of the composed cryptographic data and the associated parameters (algorithm identifiers of the second cryptographic algorithms and optionally also their component parameters and optional control parameters).
- algorithm identifiers of the second cryptographic algorithms are not included in the template in this embodiment.
- one of the first cryptographic methods used by the first control algorithm is an RSA algorithm rithmus
- an algorithm identifier of the RSA algorithm is transmitted from the provider cryptosystem to the recipient cryptosystem along with the composite cryptographic data.
- the RSA algorithm identifier is transferred to the template as an input parameter for the second control algorithm specified in the template, and the template and thus also the second control algorithm are completed.
- the provider cryptosystem and the recipient cryptosystem do not have to have agreed in advance that the provider-side or recipient-system-side steps of the RSA method must be carried out when executing the first or functionally complementary second control algorithm. Rather, this information is defined dynamically and individually for the concretely transmitted composite cryptographic data by the parameters transmitted together with these and can therefore be dynamically and very flexibly for each of the recipients' System to be used second cryptographic algorithms are set.
- the provider cryptosystem is designed to enable a user via a GUI to specify the first cryptographic algorithms used by the one or more of the first control algorithms, with the specification preferably being reversible, so that it can be changed during the operation of the provider -Kryptosystems can be changed at any time.
- the method includes the receipt of configuration data from a user or an application program by the provider cryptosystem, eg via the GUI, the configuration data specifying several first cryptographic algorithms and, for example, algorithm identifiers and optionally also component parameters.
- the first control function is created or modified such that the first cryptographic algorithms used by the first control algorithm are those identified in the configuration data.
- the executed first cryptographic algorithms define the identity of the second cryptographic algorithms selected and/or combined by the second control algorithm (e.g. by means of the algorithms contained in the transferred parameters rithm identifiers, which can be supplemented by the optional component parameters).
- the recipient cryptosystem is designed to select the second control algorithm based on an identifier provided together with the composite cryptographic data and the second cryptographic algorithms used by the second control algorithm based on the algorithm identifiers also provided.
- provider cryptosystem can specify which second control algorithm must be executed with which second cryptographic algorithm in order to process the combined cryptographic data.
- the provider cryptosystem can thus determine the security level of the receiver-side processing.
- providing the composite cryptographic data includes storing the composite cryptographic data in a single first predefined field of a data structure agreed between the provider cryptosystem and the recipient cryptosystem.
- the recipient cryptosystem is configured to read and parse the first predefined field of the data structure to obtain the composite cryptographic data.
- this data structure can be transmitted directly to the recipient cryptosystem, e.g. via a network.
- the data structure can also be stored in a volatile or non-volatile data memory, e.g. in a database used as an archive, with the recipient system currently or at a future point in time having read rights with regard to this data memory.
- the provider cryptosystem can generate a number of different signatures using a number of signature generation methods, which are stored (for example in concatenated form) as composite cryptographic data in the first predefined field.
- the composite th cryptographic data can also contain several ciphertexts generated in parallel or one ciphertext generated sequentially or an agreed final key or a Key container etc. included.
- the provider cryptosystem stores an identifier of the second control algorithm to be executed by the recipient cryptosystem in order to select those second cryptographic algorithms and to coordinate their combination that are to be used to process the composite cryptographic data provided .
- the identifier can be, for example, one of the above identifiers, e.g., SIGNATURE-OR, SIGNATURE-AND, etc.
- the identifier of the second control algorithm is stored in a second predefined field of the data structure.
- the recipient cryptosystem reads and parses the identifier from the second predefined field of the data structure and selects the second control algorithm based on the read identifier.
- the algorithm identifiers of the second control algorithms to be used by the second control algorithm and optionally the component parameters required by them and optionally the control parameters required by the second control algorithm are also stored in the data structure saved. This data is preferably stored as parameters of the second control algorithm.
- the second field of the data structure has a structure predefined in a standard with a predetermined first input area for a single (conventional) cryptographic algorithm identifier and a predetermined second input area for the parameters of this (conventional) cryptographic algorithm, the identifier of the second control algorithm in the first input area and said parameters of the second control algorithm are stored in the second input area.
- the agreed data structure is a certificate, in particular an X.509 certificate.
- the first predefined field is a field defined in a standard, in particular a conventional standard for cryptographic algorithms and/or data structures, for specifying a single cryptographic algorithm. Examples of such standards are:
- the multiple first cryptographic algorithms include multiple cryptographic signing algorithms according to multiple different signing methods.
- the second cryptographic algorithms include several cryptographic signature checking algorithms, each of which is implemented according to one of the different signing methods.
- computing the composite cryptographic data includes:
- the signature can, for example, include parameters (in particular algorithm identifiers and optionally used component parameters of the signing algorithm used in each case) which identify the signing method used by the respective cryptographic signing algorithm and which also implicitly identify a suitable signature verification algorithm;
- each parameter created may be part of the composite cryptographic data or, preferably, provided separately and in connection with the composite cryptographic data;
- the parameters (algorithm identifiers and optionally used component parameters of the respectively applied signing algorithms as well as optional control parameter) stored in a second predefined field of the data structure.
- the transmission of at least the combined cryptographic data from the provider cryptosystem to the recipient cryptosystem takes place in the course of a transmission of the input data and the data structure to the recipient cryptosystem.
- each signature generated by one of the first cryptographic algorithms consists of a pair of algorithm identifier and the value of the signature.
- the algorithm identifier can be provided in conjunction with parameters that the identified algorithm needs as input in order to be able to verify the signature.
- the signatures of the individual signing algorithms are preferably stored as a composite signature in the first field.
- the algorithm identifiers and component parameters of the signing algorithms and optionally control parameters of the second control algorithm are stored as parameters for the second control algorithm together with the identifier of the second control algorithm in the second field.
- the parameters may include a plurality of component parameters and algorithm identifiers “composite” from the component parameters of the first cryptographic algorithms and may be considered “composite parameters” stored separately from the composite cryptographic data.
- the composite cryptographic data on the one hand and the combination of the identifier of the second control algorithm with the "composite" parameters on the other hand form a tuple of cryptographic data, (control) algorithm identifiers and parameters, which is entered into the corresponding fields and input areas of standard-compliant cryptographic data structures can be stored without having to break up or change the data structure, although the combined cryptographic data and parameters have a significantly higher information content and can be used more flexibly than the corresponding data and parameters of individual cryptographic algorithms for which these data structures were originally designed.
- the composite cryptographic data can thus be provided as a pair similar to cryptographic data from individually used cryptographic algorithms, namely, for example, as a combination of the (composite) cryptographic data on the one hand and an algorithm identifier (of the second control algorithm) and its parameters on the other.
- the calculation of the result data by the recipient cryptosystem includes:
- the result data may include a result as to whether the provider cryptosystem or a message from the provider cryptosystem is to be treated as having integrity and/or as originating from a particular provider entity.
- the second control algorithm is specified by the first control algorithm and an identifier of the specified second control algorithm is stored in the data structure along with the composite cryptographic data.
- a specific cryptographic program or program module for specific applications or functions run a specific first control algorithm that specifies, for example, that a certain number (eg three) signing algorithms each have a digital Generate a signature for an electronic document and write these three signatures as the composite cryptographic data in the first field of the data structure.
- the first control algorithm can be designed to write a "SIGNATURE AND" identifier and the algorithm identifiers of the used signing algorithms together with optional component parameters and optional control parameters for the SIGNATURE AND control algorithm in the second field of the data structure.
- the recipient cryptosystem is configured to select and execute the second control algorithm depending on the identifier specified in the second field.
- the multiple first cryptographic algorithms include multiple cryptographic encryption algorithms according to multiple different encryption methods.
- the multiple second cryptographic algorithms include multiple cryptographic decryption algorithms corresponding to the multiple different encryption methods.
- computing the composite cryptographic data includes:
- the encrypted data output from each of the encryption algorithms can optionally include parameters; these parameters can include algorithm identifiers for the encryption methods used by the respective cryptographic encryption algorithm and optionally also component parameters for these encryption methods and/or control parameters for the second control algorithm; Preferably, however, these parameters do not go into the subsequent encryption algorithms as input, but are output separately in the form of composite parameters together with the composite cryptographic data; and
- the multiple cryptographic encryption algorithms are applied sequentially to the input data or to the output of the most recently performed encryption algorithm.
- the output of the most recently applied cryptographic encryption algorithm is used as the composite cryptographic data.
- the composite cryptographic data can be sequentially encrypted data, which are transformed back into the input data by sequentially applying the second cryptographic algorithms to the output of the previously executed second algorithm.
- the application of the multiple cryptographic encryption algorithms is such that each of the multiple encryption algorithms is applied to the input data to produce an encrypted output value, respectively, and the computation of the composite cryptographic data is a concatenation or other form of combination of the encrypted output values to the combined cryptographic data.
- the concatenation can take place in such a way that a delimiter, which is also known to the second control algorithm, separates the partial data generated by the individual first cryptographic algorithms.
- the second control algorithm can use the delimiter to divide the combined cryptographic data into partial data and assign the individual second cryptographic algorithms for further processing.
- the concatenation is preferably not based on a delimiter, but on the basis of a TLV (tag length value), ie a fixed character sequence length that can be specified, for example, in ASN.1 Distinguished Encoding Rules (DER) coding, or using XML , so that the receiver system provides the various first cryptographic algorithms provided parts of the composite cryptographic data based on the fixed set character sequence length can determine.
- TLV tag length value
- DER Distinguished Encoding Rules
- the calculation of the result data by the recipient cryptosystem includes:
- the result data containing at least one part of the input data in unencrypted form.
- This step can also be carried out together with the previous step of generating the decrypted data, for example when the second cryptographic algorithms are used serially.
- the multiple cryptographic decryption algorithms are applied sequentially to the output of the last decryption algorithm performed. The output of the most recently applied cryptographic decryption algorithm is used as the result data.
- the application of the multiple cryptographic decryption algorithms is such that each of the multiple decryption algorithms is applied to the encrypted data contained in the field to generate decrypted data, respectively, using the decrypted data of one of the decryption algorithms as the result data.
- the plurality of first cryptographic algorithms comprises a plurality of provider-side key agreement algorithms according to a plurality of different key agreement methods.
- the second cryptographic algorithms include several receiver-side key agreement algorithms, which are each implemented corresponding to one of the different key agreement methods.
- computing the composite cryptographic data includes:
- key data are cryptographic keys and/or seeds (data values, e.g. random numbers used as basis of a calculation) or parameters for generating cryptographic keys or these wherein the key data comprises algorithm identifiers and optionally associated component parameters that identify the key agreement method used by the respective provider-side key agreement algorithm;
- the parameters of the individual key agreement algorithms can be provided in the composite cryptographic data or, preferably, linked to it separately;
- the algorithm identifiers and optionally associated component parameters of the individual first cryptographic algorithms, the identifier of the second control algorithm and optional control parameters are preferably stored in a second data field of the data structure.
- the transmission of at least the combined cryptographic data from the provider cryptosystem to the recipient cryptosystem takes place in the course of a transmission of the input data and the data structure to the recipient cryptosystem.
- the calculation of the result data by the recipient cryptosystem includes:
- receiver-side key agreement algorithms as a function of those provider-side key data generated with a corresponding to the receiver-side key agreement algorithm corresponding provider-side key agreement algorithm barungsalgorithm were generated;
- the input data contain a text, at least one parameter of a cryptographic method, and/or at least one cryptographic key.
- the invention relates to a provider cryptosystem.
- the provider cryptosystem includes a volatile or non-volatile storage medium with a plurality of first cryptographic algorithms and with at least one first control algorithm, with a first control algorithm being a calculation rule for selecting and/or combining two or more of the first cryptographic algorithms.
- the provider cryptosystem further includes at least one processor configured to:
- the composed cryptographic data can be stored in a data structure, eg a certificate, in a predefined first field.
- the data structure can be part of a message that contains additional data.
- the message can comprise an electronic document and contain a certificate, in the first field of which a signature composed of several individual signatures is contained instead of a conventional signature, with a second field of the data structure containing the cryptosystem used by the recipient to process the data in the first field contained data to be used second control algorithm is specified by means of an identifier.
- the message can also only consist of the data structure.
- the provider cryptosystem can only use the data structure or provide a larger data set or a message that contains additional data in addition to the data structure, eg a signed electronic document.
- the provider cryptosystem is designed to carry out the provider system-side steps of the method.
- the provider cryptosystem includes:
- the first application program is free of cryptographic algorithms and can implement any application, eg a mail program, a program for generating and providing medical data, etc.
- the first application program is interoperable with the first cryptographic application and is configured to carry out the following steps :
- the separation of application logic and cryptography-related functions into different programs and/or modules described here can have the advantage that the application program remains unchanged, even if an old cryptographic application, which always returned very specific cryptographic data for a very specific algorithm, is replaced by a new cryptographic application that now returns composite cryptographic data.
- the application program saves the composite Cryptographic data continues in the same predefined field that is already used, for example, according to today's standards for storing cryptographic data such as signatures or cryptographic keys. Thus, nothing changes for the application program if the previously used cryptographic module, which according to the existing standards wrote individual cryptographic values in individual fields provided for this purpose, is replaced by a new cryptographic program or module, which now contains composite cryptographic writes data into this one field.
- provider cryptosystems with a correspondingly modular separation of application logic and cryptographic functions, it can be ensured that the provider cryptosystem can be switched to new, quantum computer-secure cryptographic algorithms without having to rewrite and/or rewrite application programs for this purpose would have to be compiled.
- the invention relates to a recipient cryptosystem.
- the recipient cryptosystem includes a volatile or non-volatile storage medium with one or more second cryptographic algorithms and at least one second control algorithm.
- the second control algorithm is a calculation rule for selecting and/or combining one or more of the second cryptographic algorithms.
- the recipient cryptosystem further includes at least one processor configured to:
- the recipient cryptosystem is designed to carry out the recipient system-side steps of the method.
- the recipient cryptosystem includes: - a second cryptographic application that uses the second cryptographic
- a second application program which is free of cryptographic algorithms and algorithms with the second cryptographic application is interopera bel.
- the second application program is configured to:
- the first and/or second application program can be designed to process S/MIME messages and certificates or signatures associated therewith, with the actual cryptographic operations being outsourced to the cryptographic application that is interoperable with this application program.
- S/MIME stands for Secure / Multipurpose Internet Mail Extensions and designates a standard for the encryption and signing of MIME objects using a hybrid cryptosystem.
- S/MIME is used in many cryptographic processes to secure the application layer. Typical uses of S/MIME are e-mail, AS2 and many others.
- S/MIME content layer
- TLS transport layer
- the first or second cryptographic application can execute the cryptographic operations in the S/MIME processing on the transport layer.
- the invention relates to a data structure.
- the data structure has a format which has been agreed between a provider cryptosystem and a recipient cryptosystem according to a cryptographic standard.
- the cryptographic standard can in particular be a conventional cryptographic method and/or data structure standard.
- the data structure contains a first predefined field which, according to the cryptographic standard, is used to store cryptographic data for exactly one cryptographic algorithm.
- the first predefined field contains (contrary to this conventional cryptographic standard) composite cryptographic data.
- the composite cryptographic data is composed of partial cryptographic data, each generated by a plurality of cryptographic algorithms.
- the plurality of cryptographic algorithms can be, for example, a plurality of first cryptographic algorithms implemented on a provider cryptosystem.
- the data structure preferably contains a second predefined field which, according to the cryptographic standard, is used to store an algorithm identifier for exactly one cryptographic algorithm.
- the second predefined field contains an identifier of the second control algorithm and algorithm identifiers of the second cryptographic algorithms to be used by this and optionally component parameters and/or control parameters of the second control algorithm.
- Such a data structure can have the advantage that its processing at the application level (eg by an S/MIME program) can be largely identical to the processing of corresponding data structures in which the first field contains the content according to the conventional cryptographic standard.
- the composite cryptographic data generated by a plurality of cryptographic algorithms are according to embodiments. These can be read out by the application program in the same way as before and forwarded to the cryptographic application for processing. Adjustments may be required only in the case of the cryptographic application, since these are designed for this needs to write to or read from the first field and process composite cryptographic data rather than the results of a single cryptographic algorithm.
- the data structure includes a format identifier, e.g., a cryptographic standard identifier or a data structure type identifier.
- a format identifier e.g., a cryptographic standard identifier or a data structure type identifier.
- an X.509 certificate contains a field that shows the version of the X.509 certificate.
- the default value is version 1. If the issuer unique identifier or the subject unique identifier exist, the value must be version 2. The majority of applications used today use V3.
- the data structure is a certificate.
- the certificate can be an X.509 certificate, for example.
- the X.509 certificate can be designed as a TLS certificate, for example.
- the certificate can be a CV certificate (Card Verifyable Certificate).
- the data structure is an X.509 from version V1 or higher, which is assigned to an entity.
- entity can be, for example, a natural or legal person or a technical device or object.
- the cryptographic data of exactly one cryptographic algorithm (to be stored in the first field according to the conventional cryptographic standard) is a ciphertext, a cryptographic key or a digital signature.
- the cryptographic partial data is in each case a ciphertext, a cryptographic key or a digital signature.
- the first field is a field designated according to a cryptographic standard for storing cryptographic data generated by a single cryptographic algorithm.
- the second field is a field designated according to a cryptographic standard for storing an algorithm identifier of a single cryptographic algorithm including optionally present parameter values.
- each of the partial data contains parameters, with the parameters identifying an algorithm identifier that identifies the second cryptographic algorithm with which the partial data is to be processed, and optionally also component parameters that control the processing.
- the composite cryptographic data may include pairs of the outputs generated by each of the first cryptographic algorithms and the algorithm identifiers and optionally also component parameters of the respective second cryptographic algorithm.
- the algorithm identifiers of the second cryptographic algorithms, component parameters optionally assigned to them and optionally present control parameters are stored and provided together as “composite parameters” separately but linked to the composite cryptographic data and an identifier of the second control algorithm.
- the recipient cryptosystem is designed to use an analysis of the composite cryptographic data, which also contain algorithm identifiers, to determine, before the second control algorithm is executed, whether the second cryptographic algorithms identified in the second control algorithm by the recipient - Cryptosystem supported. If not, the second control algorithm is not executed, which saves resources.
- the algorithm identifiers and/or component parameters of the second cryptographic algorithms also implicitly specify the bit length and/or first position of the cryptographic data. This data can enable the recipient cryptosystem to identify the beginning and/or the end of this partial data within the field when the data content of the field is parsed by the recipient cryptosystem.
- the invention relates to a provider cryptosystem with a plurality of first cryptographic algorithms and at least one first control algorithm, which is configured to generate a data structure according to one of the embodiments described here.
- the invention relates to a recipient cryptosystem with a plurality of second cryptographic algorithms and at least one second control algorithm, which is configured to process a data structure according to one of the embodiments described here.
- the invention relates to a provider cryptosystem.
- the provider cryptosystem comprises at least one processor and a volatile or non-volatile storage medium with a plurality of first cryptographic algorithms and at least one first control algorithm.
- a first control algorithm is a calculation rule for selecting and/or combining one or more of the first cryptographic algorithms.
- the at least one processor is configured to:
- the data structure having a format agreed between the provider cryptosystem and a recipient cryptosystem, wherein the first predefined field is filled with the composite cryptographic data;
- the format of a data structure is understood here in particular as a specification of the type and/or position and/or the content of various fields of a data structure.
- the invention relates to a recipient cryptosystem.
- the recipient cryptosystem comprises at least one processor and a volatile or non-volatile storage medium with a plurality of second cryptographic algorithms and at least one second control algorithm.
- a second con- trollalgorithmus is a calculation rule for the selection and/or combination of one or more of the second cryptographic algorithms.
- the at least one processor is configured to:
- the invention relates to a system comprising one or more provider cryptosystems and one or more recipient cryptosystems according to one of the embodiments described here.
- a “cryptosystem” or “cryptographic system” is understood here to mean a data processing system that uses cryptographic algorithms.
- the data processing system can be a standard computer, a notebook, a portable telecommunications device, a server, any other data processing system, or a combination of several of these components.
- a “cryptographic algorithm” is understood here as an algorithm that serves to protect data from unauthorized reading or manipulation and/or at least to make such manipulation recognizable.
- a cryptographic algorithm can be, for example, an encryption algorithm, a decryption algorithm, a signing algorithm, an algorithm for checking a digital signature, or an algorithm for executing user-specific steps of a key agreement method.
- “Composite cryptographic data” is understood here as data that is understood by the combined application of a plurality of (first) cryptographic algorithms and/or by a combination of the data generated by a plurality of first cryptographic algorithms.
- the assembled cryptographic data can be the result of the application of signature generation algorithms (signing algorithms), encryption algorithms or key agreement algorithms, for example.
- sequential execution of algorithms means iterative execution of those algorithms, where the first algorithm executed in the sequence is applied to the input data, and each of the subsequently executed algorithms is applied to the data generated by the immediately preceding algorithm be returned.
- a “parallel” execution of algorithms is understood here as an execution of several algorithms, with each of these algorithms being applied to the input data or parts thereof and producing an output.
- the multiple algorithms can be executed in any sequence in terms of time, e.g. simultaneously or one after the other in any order.
- a “final key” is understood here as a cryptographic key that is calculated as a function of several other keys (intermediate key).
- Partial data of composite cryptographic data is understood here to mean data that is calculated by a single first cryptographic algorithm that was used by the first control algorithm to calculate the composite cryptographic data.
- a "field” is used here to refer to a physical and/or logical area within a data structure which, according to an agreement between two or more cryptosystems, is used to store data of a predefined meaning and/or function and with predefined properties (e.g. data type, length, Position, etc.) is provided.
- a data field can contain multiple input areas, which are also subject to the data storage agreement are provided with a predefined meaning and/or function and with predefined properties.
- the storage of data other than that intended in the data field and/or in an input area within the data field typically leads to errors or to the data processing being aborted.
- the agreement can be implemented, for example, in the form of a cryptographic standard such as X.509 for certificates.
- a “parameter” is a data value or set of data values with a specific function or meaning.
- control parameter is a parameter that directly controls the manner in which a first or second control algorithm is executed.
- a control parameter can, for example, be passed as an argument to a control algorithm.
- a "component parameter” is a parameter that directly controls the manner of execution of a first or second cryptographic algorithm, and optionally thereby also indirectly controls the execution of a control algorithm that uses the first or second cryptographic algorithm.
- a component parameter can be passed as an argument to a cryptographic algorithm and/or the control algorithm that uses this cryptographic algorithm.
- aspects of the present invention may be embodied as an apparatus, method, or computer program or computer program product. Accordingly, aspects of the present invention may take the form of a flardware-only embodiment, a software-only embodiment (including firmware, in-memory software, micro-code, etc.), or an embodiment combining software and flardware aspects, all of which are herein may be referred to generically as "circuit", "module” or “system”. Furthermore, aspects of the present invention may take the form of a computer program product carried by one or more computer-readable media in the form of computer-executable code. A computer program also includes the computer executable code. "Computer executable code” may also be referred to as "computer program instructions”.
- the computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium.
- the computer-readable storage medium may be referred to as a computer-readable non-transitory storage medium.
- the computer-readable storage medium may also be referred to as a tangible computer-readable medium.
- a computer-readable storage medium may also be capable of storing data that is capable of being accessed by the processor of the computing device.
- Examples of computer-readable storage media include, but are not limited to: a floppy disk, a magnetic hard disk, a solid-state hard disk, flash memory, a thumb drive, random access memory (RAM), read-only memory (ROM), an optical disk, a magneto-optical disk, and the register file of the processor.
- Examples of optical discs include compact discs (CD) and digital versatile discs (DVD), for example CD-ROM, CD-RW, CD-R, DVD-ROM, DVD-RW or DVD-R discs.
- the term computer-readable storage medium also refers to various types of recording media capable of being retrieved by the computing device over a network or communications link. For example, data can be retrieved over a modem, over the Internet, or over a local area network.
- Computer-executable code executing on a computer-readable medium may be transmitted over any suitable medium, including but not limited to wireless, wired, fiber optic, RF, etc., or any suitable combination of the foregoing media.
- a computer-readable signal medium may include a propagated data signal containing the computer-readable program code, for example, in a base signal (baseband) or as part of a carrier signal (carrier wave). Such a propagation signal may be in any form including, but not limited to, electromagnetic form, optical form, or any suitable combination thereof.
- a computer-readable signal medium it can any computer-readable medium, other than a computer-readable storage medium, that can transmit, distribute, or transport a program for use by or in connection with any instruction-executing system, apparatus, or apparatus.
- a “computer memory” or “memory” is an example of a computer-readable storage medium.
- Computer memory is any memory accessible to a processor.
- a “computer memory” or “data storage” is another example of a computer-readable storage medium.
- Computer data storage means any volatile or non-volatile computer-readable storage medium. In some embodiments, computer memory can also be computer data storage, or vice versa.
- a "processor” as used herein includes an electronic component capable of executing a program or machine-executable instruction or computer-executable code.
- Reference to computing device including a "processor” should be interpreted to include possibly more than one processor or processing cores.
- the processor may be a multi-core processor.
- a processor can also refer to a collection of processors within a single computer system or distributed across multiple computer systems.
- the term computing device or computer shall also be construed to possibly refer to a collection or network of computing devices or computers, each including a processor or processors.
- the computer-executable code may be executed by multiple processors, which may be distributed within the same computing device or even across multiple computers.
- Computer-executable code may include machine-executable instructions or a program that causes a processor to perform an aspect of the present invention.
- Computer-executable code for performing operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, Smalltalk, C++, or the like, and conventional procedural programming languages such as the “C” programming language or similar programming languages, and translated into machine-executable instructions.
- the computer-executable code may be in high-level language or pre-compiled form and used in conjunction with an interpreter that generates the machine-executable instructions.
- the computer-executable code may run entirely on a user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server .
- the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g. via the internet using an internet service provider).
- LAN local area network
- WAN wide area network
- an internet service provider e.g. via the internet using an internet service provider
- the computer program instructions can be executed on one processor or on multiple processors. In the case of multiple processors, these can be distributed across multiple different entities (e.g. clients, servers). Each processor could execute a part of the instructions intended for the respective entity. Thus, where reference is made to a system or method that includes multiple entities, the computer program instructions should be understood as being adapted to be executed by a processor associated or associated with each entity.
- These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable computing device to create a device such that the instructions executed by the processor of the computer or other programmable computing device provide means for executing the instructions in the block or blocks generate the functions/steps specified in the flow charts and/or block diagrams.
- These computer program instructions may also be stored on a computer-readable medium that can control a computer or other programmable computing device or other device to function in a particular manner such that the instructions stored on the computer-readable medium produce a work of art, including instructions that implement the function/step specified in the block or blocks of the flowcharts and/or block diagrams.
- the computer program instructions may also be stored on a computer, other programmable data processing device, or other device to cause a series of process steps to be executed on the computer, other programmable data processing device, or other device to produce a computer-executed process such that the instructions executed on the computer or other programmable device produce methods for implementing the functions/steps specified in the block or blocks of the flowcharts and/or block diagrams.
- 1A shows an exemplary flow chart of an embodiment of a method according to the invention implemented by the provider
- 1B shows an exemplary flow chart of an embodiment of a method according to the invention implemented at the receiver end
- Figure 2 is a block diagram of a provider cryptosystem
- FIG. 3 is a block diagram of a receiver cryptosystem
- FIG. 4 shows a schematic of a first control algorithm and a data structure with the composite cryptographic data generated according to the first control algorithm
- Fig. 5 shows a scheme of the application of another first control algorithm and a data structure with the composite cryptographic data generated according to it;
- FIG. 7 shows an X.509 certificate as an example of a data structure containing the composed cryptographic data and associated parameters stored in specific fields.
- FIG. 1A shows an exemplary flow chart of an embodiment of a method according to the invention implemented by the provider.
- the method according to FIG. 1A can be implemented, for example, in a provider cryptosystem, as is described for FIG. 2 by way of example.
- the exemplary methods according to FIGS. 1A or 1B can have the advantage that a high degree of agility is supported when using crypto algorithms, which allows cryptographic algorithms to be exchanged step by step, even in heterogeneous multi-subscriber systems, and several cryptographic ones for different IT applications Algorithms to be used in parallel. So far, IT applications have not been prepared for the parallel or redundant use of several cryptographic algorithms, since existing, standardized data structure formats for the corresponding cryptographic algorithms to be exchanged Data, in particular digital signatures, digital certificates, and/or encryption container fields for the output data and/or for the identification of exactly one of these cryptographic algorithms.
- the input data can be any data.
- the input data can be an electronic document that is to be signed in order to make the signature available to the recipient together with the electronic document in order to enable the recipient to check the integrity of the transmitted electronic document by means of a signature check.
- the input data can also be other data, for example cryptographic keys or other data values or data sets that are to be transmitted in encrypted form to the recipient cryptosystem, or random values or parameters that are derived from a key agreement algorithm of a key in several subsequent procedural steps.
- the provider cryptosystem does not apply a single cryptographic algorithm to the input data (or iteratively to the outputs of the other cryptographic algorithms), but two or more cryptographic algorithms.
- the cryptographic algorithms implemented by the provider are also referred to here as “first cryptographic algorithms”.
- a larger number of cryptographic algorithms may be implemented in the provider cryptosystem than are actually used to generate the composite cryptographic data. The selection of these cryptographic algorithms and/or the way in which they are combined is specified in a first control algorithm.
- step 106 the composite cryptographic data calculated using the plurality of first cryptographic algorithms is provided by the provider cryptosystem to the recipient cryptosystem.
- the assembled cryptographic data may be sent to the recipient cryptosystem over a network or stored in a storage medium accessible by the recipient cryptosystem.
- the composite cryptographic data is preferably provided together with an identifier of a second control algorithm and with parameters (algorithm identifiers of the first and implicitly also of the second cryptographic algorithms, and optionally also component parameters and/or control parameters of the second control algorithm).
- the parameters are also referred to as "composite parameters”.
- the composite cryptographic data is stored within a single predefined first field of a data structure agreed between the provider cryptosystem and the recipient cryptosystem.
- an identifier of a second control algorithm which must be used by the recipient cryptosystem for processing the composed cryptographic data, is stored in this data structure.
- this identifier can be stored in a second field together with the composite parameters.
- the first field is preferably a field that is already used according to existing standards for storing cryptographic data of individual cryptographic algorithms.
- the second field is preferably a field that is already used according to existing standards for storing algorithm identifiers and optional algorithm parameters of individual cryptographic algorithms.
- the storage of said composite cryptographic data and parameters in the corresponding fields can have the advantage that it is possible to specify several re-cryptographic algorithms within this data structure (e.g. certificates, signatures or key containers) via the identifier of the second control algorithm.
- the recipient system is to use a different cryptographic algorithm than before, the corresponding rules and standards for signature, verification, encryption, decryption and/or key agreement are not redefined and described each time. Rather, these rules are defined once generically in the form of control algorithms implemented on the receiver side, whose identifiers are known to the provision cryptosystem. Thus, the specific specifications for protocols, certificates, signatures and key containers do not have to be changed each time the provider and/or recipient use a different cryptographic algorithm.
- each of the first control algorithms may specify a choice and/or the manner (e.g., order and/or mode sequential or parallel) which of the first cryptographic algorithms are to be combined and how to obtain the composite cryptographic data.
- each of the first control algorithms selects only cryptographic algorithms of the same type, e.g. only signature algorithms, only encryption algorithms, only algorithms for key agreement etc.
- the execution of the first control algorithms by the provision cryptosystem (and analogously also the execution of the second control algorithms by the recipient cryptosystem) is preferably implemented by a software application or software module, which is separate from the actual application logic (see Figures 2 and 3).
- the output of the first control algorithm, the composed cryptographic data and optionally also the parameters, can be viewed as the output of a new algorithm composed of several individual cryptographic algorithms.
- a second control algorithm functionally complementary to this in the recipient cryptosystem.
- the identifier of the two functionally complementary first and second control algorithms can be identical, even if it represents different calculation steps on the provider side than on the receiver side.
- FIG. 1B shows an exemplary flowchart of an embodiment of a method according to the invention implemented at the receiver end.
- the method according to FIG. 1B can, for example, be implemented in a receiver cryptosystem, as is described for FIG. 3 by way of example.
- the recipient cryptosystem receives the composed cryptographic data. For example, it receives the data directly from a provider cryptosystem, e.g. over a network, or reads the data from a storage medium.
- the recipient cryptosystem processes the composed cryptographic data in order to obtain result data.
- the composite cryptographic data is processed using one or more second cryptographic algorithms.
- the one or more second cryptographic algorithms are selected and/or coordinated and combined by a “second” control algorithm implemented on the receiver side, which preferably receives the algorithm identifiers of the second cryptographic algorithms as an argument.
- the algorithm identifiers can be read from the data structure, for example with optionally additionally present control parameters and/or component parameters.
- This second control algorithm is preferably defined by an identifier which was received together with the composite cryptographic data and determined by the provider cryptosystem. It is possible that only a single second cryptographic algorithm to process the composite crypto- graphical data is used, although several first cryptographic algorithms were used to calculate the composite cryptographic data (e.g. in "OR" control algorithms).
- step 112 the recipient cryptosystem automatically executes a software and/or hardware function depending on the result data.
- the composite cryptographic data could be the input data in encrypted form and the result data could represent the decrypted, reconstructed input data.
- the automated software and/or hardware function could include outputting the reconstructed, decrypted data to a user or storing the data in decrypted form.
- the composite cryptographic data could be a composite signature of an electronic document or its hash value
- the result data could be the result or results of one or more signature verification processes.
- the electronic document could be considered trustworthy and forwarded or stored for further processing, or discarded as manipulated.
- a mechanical locking mechanism it is also possible for a mechanical locking mechanism to be opened or released if the result is that the signature is valid.
- the verified signature could be the signature of a user's identity document, and the signature could be verified as part of an authentication process, for example to grant access to a protected area or room and/or to grant access to software functions or data .
- the composite cryptographic data could be a final key that has been negotiated in the course of a key agreement process between the provider cryptosystem and the recipient cryptosystem. This final key can now be used, for example, to set up a cryptographically secured communication channel between the provider cryptosystem and the recipient cryptosystem.
- the composite cryptographic data is a key container comprising a plurality of different cryptographic keys which are made available again individually by the second control algorithm and/or used according to their respective function, eg to encrypt or decrypt data in order to Sign data, verify signatures, etc.
- FIG. 2 shows a block diagram of a provider cryptosystem 200.
- the provider cryptosystem can be implemented, for example, as a standard computer system, server computer system, distributed cloud computer system or other data processing system.
- the cryptosystem 200 includes one or more processors 202 and a volatile or non-volatile storage medium 204.
- the storage medium preferably includes at least one application program 206, for example an e-mail program for processing S/MIME data, and a first cryptographic program 212.
- the first application program and the first cryptographic program are operatively coupled to one another by a data exchange interface. It is also possible for the first cryptographic program to be a program library or a program module integrated into the first application program.
- the first cryptographic program 212 includes a plurality of multiple first cryptographic algorithms 214-224.
- the first cryptographic algorithms can all be of the same type or of different types.
- the first cryptographic algorithms 214-220 each implement a different signing scheme.
- the first cryptographic algorithm 222 is an encryption algorithm and the first cryptographic algorithm 224 is a key agreement algorithm.
- the cryptographic program comprises a calculation module 226, which contains or can read in one or more first control algorithms 228-232.
- Each of these first control algorithms specifies a selection and/or a combination (in terms of the way in which the algorithms and/or the outputs of the algorithms are to be combined with one another) of a plurality of first cryptographic algorithms, with preferably only first cryptographic algorithms of the same type are connected.
- a large number of first and complementary second control algorithms are possible, which are preferably identified with the same identifier, such as:
- SIGNATURE-AND here a composite signature is generated by computing a signature by each of the signature algorithms selected by the first control algorithm and then combining (e.g. concatenating) these signatures into a composite signature.
- the verification (to be carried out by the receiver cryptosystem) of a SIGNATURE AND control algorithm implemented at the receiver end returns as result data that the composite signature is valid if all signatures of the individual signatures used to generate the composite signature are valid.
- SIGNATURE-OR here, as with SIGNATURE-AND, a composite signature is generated by computing a signature by each of the signature algorithms selected by the first control algorithm and then combining these signatures into a composite signature.
- the verification (to be carried out by the receiver cryptosystem) of a SIGNATURE OR control algorithm implemented at the receiver end returns as result data that the composite signature is valid if at least one signature of the plurality of signatures used to generate the composite signature is valid.
- the verification (to be carried out by the receiver cryptosystem) of a SIGNATURE-K-of-N control algorithm implemented at the receiver end returns as result data that the composite signature is valid if at least K of the signatures of the N signatures used to generate the composite signature is valid.
- KEY AGREEMENT-XOR The keys agreed with the individual first cryptographic key agreement algorithms are padded or shortened to a common length and then combined with XOR to form a final key.
- the final key represents the composite cryptographic represents data and is used as the cryptographic key ultimately agreed between the provider cryptosystem and the recipient cryptosystem.
- the recipient computer system cryptosystem must implement all key agreement algorithms (in the form of second cryptographic algorithms) that are functionally more complementary to the key agreement methods used by the provider cryptosystem as the first cryptographic algorithms to generate the final key. Otherwise, the key agreement between the provider cryptosystem and the recipient cryptosystem fails.
- KEY ENCRYPTION-SEQUENTIAL A symmetric key is encrypted with a first cryptographic algorithm, which is a specified encryption algorithm. The ciphertext is then encrypted again using a further first cryptographic algorithm which implements a different encryption algorithm. The resulting ciphertext is then encrypted with a further first cryptographic algorithm that implements a further different encryption key. Etc. The output of the last executed encryption algorithm is provided as the composite cryptographic data.
- the decryption (to be undertaken by the recipient cryptosystem) of a ciphertext generated according to the first control algorithm KEYSCRIPT-SEQUENTIALLY includes the application of functionally complementary decryption keys in reverse order to the ciphertext received from the provider cryptosystem. If the recipient cryptosystem implements all the required decryption algorithms and has the necessary decryption keys, it is able to reconstruct the original input data and use it as the result data.
- KEY CONTAINER here a composite key is generated, obtained by concatenating keys identified and/or calculated by the algorithms selected by the first control algorithm.
- the composite key can be formed by concatenation, for example.
- the second control algorithm which is functionally complementary to this first control algorithm, extracts the individual keys from the container and preferably also uses them according to their type in a cryptographic method.
- Each of the first control algorithms can thus itself be regarded as a new, cryptographic algorithm, which is composed of several (first) cryptographic algorithms.
- the calculation module 226 could, for example, comprise a first control algorithm 228 according to SIGNATURE AND, a further first control algorithm 230 according to SIGNATURE OR and a further first control algorithm 232 according to KEY ENCRYPTION SEQUENTIAL.
- the first application program could provide input data 208, for example an electronic document such as an e-mail, to the first cryptographic program 212.
- the provision can optionally be made with a default follow which of the first control algorithms to generate a signature for the electronic document should be used.
- the first cryptographic program receives the input data 208 and performs, for example, the first control algorithm 230 (SIGNATURE OR).
- the control algorithm 230 provides for a combination of the three generated signatures, for example by concatenating the individual signatures.
- the individual signatures can be separated from one another, e.g. by means of specified separators (delimiters), over-specified maximum lengths or in some other way.
- the concatenate of signatures thus obtained is stored as the composite cryptographic data 236 in a data structure 234 and returned to the first application program 206 .
- an identifier of the second control algorithm to be used for processing the composite cryptographic data 236 is written into the data structure 234 .
- the provider cryptosystem 200 is designed to provide the data structure with the composite cryptographic data 236 and the identifier of the second control algorithm (SIGNATURE OR) to the recipient cryptosystem 240 .
- the provider cryptosystem includes an interface 210 in order to send the data structure 234 directly to the recipient cryptosystem 240 .
- the provider cryptosystem can also have an interface for storing the data structure 234 in a storage medium 242 .
- the storage medium 242 is a storage medium to which the recipient cryptosystem currently or in the future has read access.
- Figure 3 shows a block diagram of a receiver cryptosystem 240.
- the recipient cryptosystem 240 includes one or more processors 302 as well as a volatile or non-volatile storage medium 304.
- the recipient cryptosystem can be designed in the form of a wide variety of data processing systems, as already described for the provider cryptosystem.
- the cryptosystem 240 comprises one or more processors 302 and a volatile or non-volatile storage medium 304.
- the recipient cryptosystem includes an interface 310 for receiving the composite cryptographic data.
- the composite cryptographic data may be received as part of a data structure 234, where the data structure may be a standard data structure such as an X.509 certificate.
- the interface 310 can be, for example, an interface for receiving a data structure 234 from the provider cryptosystem via a network or an interface for reading the data structure 234 from a storage medium 242.
- the storage medium preferably includes at least one application program 306, for example an e-mail program for processing S/MIME data, and a cryptographic program 312.
- the application program 306, also referred to as the “second application program”, and the “second” cryptographic program 312 are operatively coupled to each other through a data exchange interface. It is also possible for the second cryptographic program to be a program library or a program module integrated into the second application program.
- the second cryptographic program 312 includes a plurality of multiple second cryptographic algorithms 314-324.
- the second cryptographic algorithms may all be of the same type or of different types.
- the second cryptographic algorithms 314-320 each implement a different signature verification method.
- the second cryptographic algorithm 322 is a decryption algorithm and the second cryptographic algorithm 324 is a key agreement algorithm.
- each of the second algorithms may be functionally complementary to a first algorithm 214-224 of the provider cryptosystem.
- the second algorithms of a recipient cryptosystem may be functionally complementary to a set of first algorithms that are stored distributed in different provider cryptosystems. This can have the advantage that the recipient cryptosystem can process composite cryptographic data from a large number of different provider cryptosystems with a nem different set of first cryptographic algorithms who can process the same.
- the cryptographic program includes a calculation module 326, which includes or can read one or more second control algorithms 328-332.
- Each of these second control algorithms specifies a selection and/or a combination (in the sense of how algorithms and/or the outputs of the algorithms are to be combined) of a plurality of second cryptographic algorithms, preferably only second cryptographic algorithms of the same type being connected will.
- the second control algorithms are preferably functionally complementary to a first control algorithm, e.g. one of the control algorithms described with reference to Figure 2, such as SIGNATURE AND, SIGNATURE OR, etc.
- the calculation module is configured to receive and evaluate the data structure 234 from the application program.
- the data structure also contains an identifier of a second control algorithm, here e.g. control algorithm 330, and thereby determines the second control algorithm which is executed by the recipient cryptosystem in response to the receipt of the data structure.
- the selected second control algorithm is a SIGNATURE OR control algorithm that is functionally complementary to the first control algorithm 230 (SIGNATURE OR) that created the composite cryptographic data 236 .
- the received data structure preferably also contains parameters.
- Algorithm identifiers and optionally also parameters of the individual second cryptographic algorithms 316, 318 and 320 (“component parameters”) can be specified in these parameters, which are used by the second control algorithm to process the composed cryptographic data in order to obtain the result data 308 .
- the parameters can, for example, also specify delimiters or maximum character sequence lengths that separate the cryptographic data generated by the individual first cryptographic algorithms from one another, or else tive parameters that directly control the execution of the second control algorithm (“control parameters”).
- the result data 308 would specify that the composite signature 236 is valid if any of the signatures generated by the first cryptographic algorithms, as verified by a corresponding signature verification algorithm 316-320, result in that the signature is valid.
- the composite cryptographic data 236 is stored in a data structure 234, the structure of which has been agreed between the provider cryptosystem and the recipient cryptosystem. This means that both cryptosystems agree on which data is or is stored in which field of the data structure.
- the agreement can preferably be based on the fact that the structure of the data structure is defined in a (conventional) standard.
- the parameters of the second control algorithm stored together with the identifier of the second control algorithm in the data structure 234 include algorithm identifiers and optionally also component parameters of one or more second cryptographic algorithms to be selected and/or combined by the second control algorithm .
- the parameters can also contain control parameters of the second control algorithm.
- the manner in which a first and/or second cryptographic algorithm is executed and/or the official algorithm identifier is typically specified in cryptographic standards.
- a first and/or second cryptographic algorithm may be a variant of RSA.
- Different variants of the RSA and their identifiers are described in the RFC 8017 standard, for example.
- a first and/or second cryptographic algorithm may be the ECDSA algorithm described in the ANSI X9.62 standard.
- the first and/or second control algorithms include, receive and/or use parameters.
- the parameters include algorithm identifiers of the individual first or second cryptographic algorithms selected and/or combined by these control algorithms, the parameters optionally also containing component parameters of these cryptographic algorithms and/or control parameters used directly by the control algorithms.
- the algorithm identifiers and component parameters are defined according to existing conventional standards.
- the identifier of the second control algorithm and all of the parameters mentioned above and used by this second control algorithm are preferably stored in the fields of a standardized cryptographic data structure provided for individual cryptographic algorithms according to existing standards.
- the identifier and parameters may be denoted, for example, according to the ASN.1 notation explained with respect to FIG. This has the advantage that the program on the application level, which receives such a cryptographic data structure, may already have partially processed it and forwarded the extracted identifiers, parameters and cryptographic data to a cryptographic module, does not have to be rewritten. Because the structure of the fields of the data structure has not changed.
- algorithm identifier SEQUENCE ⁇ algorithm OBJECT IDENTIFIER
- the second control algorithm is specified as shown above:
- the identifier of the second control algorithm e.g. "SIGNATURE-OR”
- OID in the same format as the OIDs of individual cryptographic algorithms, e.g "1.2.3.4.5.6.7.8.9”.
- Algorthmldentifier uses the values of several signature algorithms used as second cryptographic algorithms, each of which consists of OID and parameters.
- the storage of the composite cryptographic data described for this embodiment in a predefined first field and the identifier of the second control algorithm and associated second parameters in a second field, which according to conventional data structure standards for storing cryptographic data or algorithm identifiers of a single cryptographic algorithm can have the advantage that the processing application software of the recipient cryptosystem "knows" without changing the code how to read out the composed cryptographic data and the identifier of the second control algorithm and forward it to the cryptographic software.
- standard conformity can be achieved very easily by specifying for each composite algorithm (with its own OID) in the corresponding definition (possibly published as a standard) how the keys, signatures and ciphers are to be handled.
- composite keys and composite signatures ie keys or signatures composed of two or more keys or signatures, can be simple concatenations of the individual keys and signatures generated by the first cryptographic algorithms.
- the ciphertext is the result of the most recently performed component encryption.
- FIG. 4 shows a schematic of a first control algorithm and a data structure with the composite cryptographic data generated according to the first control algorithm.
- an identifier 402 of the first control algorithm and an identifier 410 of the second control algorithm that is to be used to process the generated composite cryptographic data are specified.
- the identifiers 402 and 410 are ty- typically identical, but can also be different in some embodiments.
- the first control algorithm is preferably implemented using a series of parameters 404, 408, 412, 416 as input and/or outputting.
- the parameters 408 include algorithm identifiers of those first cryptographic algorithms that are to be used to generate the composite cryptographic data, optionally component parameters required by them (e.g. B1, B2 for signing algorithm/signature verification algorithm B, component parameters C1, C2 and C3 for signing algorithm/signature verification algorithm C, the signing algorithm/signature checking algorithm D does not require any component parameters) and optionally also control parameters 404, 412 for the first (and possibly also for the functionally corresponding second) control algorithm itself.
- component parameters required by them e.g. B1, B2 for signing algorithm/signature verification algorithm B, component parameters C1, C2 and C3 for signing algorithm/signature verification algorithm C, the signing algorithm/signature checking algorithm D does not require any component parameters
- control parameters 404, 412 for the first (and possibly also for the functionally corresponding second) control algorithm itself.
- a control parameter 404, 410 in the case of SIGNATURE K-of-N could specify the value K from the set of the first cryptographic algorithms.
- the value K is a number less than or equal to N and specifies the minimum number of signatures that must be verified as valid so that the composite signature check carried out in its entirety by the second control algorithm has the result that a signed document is valid.
- KEY AGREEMENT e.g. the bit length to which the results of the individual algorithms must be shortened or padded can be used as a control parameter. How the first and/or second algorithms are to be combined is specified by the identifier of the first or second control algorithm, e.g. AND / OR / AGGREGATE / etc.
- N may be 3 and K2.
- the three signing methods B, C and D identified by the algorithm identifiers are applied to the input data 208, e.g. a document to be signed, with the algorithms B and C having component parameters B1, B2,
- the signatures 418, 420, 422 obtained are concatenated and stored as the composite cryptographic data 236, for example in a first field 438 of a data structure 234, which is an X.509 certificate is.
- the identifier 410 of the second control algorithm and a number of parameters 412, 416 to be used by this are stored in a second field 440 of the data structure.
- cryptosystems that use X.509 certificates can be prepared and converted to quantum computer-secure cryptographic processes.
- the composed cryptographic data and/or the identifier of the second control algorithm in X.509 certificates can be stored in the following certificate areas or fields i, ii, iii and/or iv, which are currently used to store cryptographic data and algorithm identifiers of individual cryptographic algorithms are used.
- a corresponding certificate 700 is shown as an example in FIG. 7, to which reference is also made here: i. signatureAlgorithm Field 702, 440: in accordance with a conventional cryptographic standard (see RFC 5280, 4.1.1.2), this field specifies which algorithm is used by the Certification Authority (CA) to sign the certificate.
- CA Certification Authority
- Algorithmidentifier SEQUENCE ⁇ algorithm OBJECT IDENTIFIER
- the certificate 234 would therefore contain the following information in the signatureAlgorithm field 440:
- N does not need to be specified as a parameter of the control algorithm because the value N results from the number of second cryptographic algorithms listed in second_krypto_algs.
- the entire signatureAlgorithm data structure looks in this example for the second control algorithm "SIGNATURE-K- out-N” like this:
- Algorithmidentifier :: SEQUENCE ⁇ algorithm SIGNATURE-K-of-N,
- the certificate field "signature” 704 must contain the same content as field (i) "signatureAlgorithm", see RFC 5280, 4.1.1.2. iii. SignatureValue field (see RFC 5280, 4.1.1.3) 706, 438: This is a field 438 for storing the certificate authority's signature over the content of the certificate with the signatureAlgorithm algorithm and the certificate authority's private key.
- the formal description in ASN.1 is: SignatureValue BIT STRING.
- the certificate 234 would therefore contain the composed cryptographic data in the first field 438, in the named standard the field SignatureValue, which results from the sign nature with the control algorithm mentioned under (i) and (ii) and its parameters has revealed.
- the field SignatureValue results from the sign nature with the control algorithm mentioned under (i) and (ii) and its parameters has revealed.
- this is the juxtaposition of the results of the individual first cryptographic algorithms, which are also shown as a BIT STRING.
- the resulting SEQUENCE OF BIT STRING is preferably also subjected to a type conversion to BIT STRING.
- the entire SignatureValue data structure looks like this:
- SubjectPublicKeyInfo field (see RFC 5280, 4.1.2.7) 708: This is a certificate domain for storing the public key of the certificate subject and an algorithm identifier of the cryptographic algorithm with which this key can be used.
- the cryptographic algorithm can be, for example, a signature algorithm or an algorithm of another type of algorithm.
- the SubjectPublicKeylnfo field is of type SubjectPublicKeylnfo, which is defined as
- SubjectPublicKeyInfo SEQUENCE ⁇ algorithm Algorithm Identifier, subjectPublicKey BIT STRING ⁇
- the certificate in this area would contain a first field 438 and be identified by the term "subjectPublicKey” and a second field 440 and be identified by the term "algorithm”.
- the 2nd field contains the ID of the SCFILÜSSEL-CONTAINER control algorithm and, as parameters, the algorithms of the various keys contained in the 1st field as concatenation.
- this certificate area 708 would therefore contain the following information:
- SubjectPublicKeylnfo SEQUENCE ⁇ algorithm " KEY CONTAINER and parameters", subjectPublicKey [composite cryptographic data] ⁇
- Algorithm Identifier SEQUENCE ⁇ algorithm OBJECT IDENTIFIER,
- parameter is ANY DEFINED BY algorithm OPTIONAL ⁇ , it is again defined by the identifier of the control algorithm KEY-CONTAINER and parameters.
- the parameters again consist of the sequence of algorithm identifiers of the first cryptographic algorithms and optionally their respective parameters.
- algorithm :: SIGNATURE OR identifier
- the composite cryptographic data is the sequence of public keys assigned to the entity in the certificate and which in this order match the algorithm identifier sequence_key_algorithms named in Parameters.
- the combined cryptographic data is stored in the subjectPublicKey field from SubjectPublicKeyInfo and results in SCHLÜSSEL-CONTAINER as a SEQUENCE OF BIT STRING and is also subjected to a type conversion to BIT STRING.
- the entire signatureValue data structure looks like this:
- SubjectPublicKeylnfo SEQUENCE ⁇ algorithm SEQUENCE ⁇ algorithm KEY CONTAINER,
- X.509 certificates with composite cryptographic data can be processed in compliance with the following standards: - ITU-T X.509 (10/2019) Information technology - Open Systems Interconnection - The Directory: Public-key and attribute certificate frameworks (identical to ISO/IEC 9594-8)
- the identifier of the second control algorithm is stored in an X.509 certificate, e.g parameters of the signatureAlgorithm field.
- the signature field of the tbsCertificate field contains the same information as the signatureAlgorithm field.
- the composite cryptographic data is stored in the signatureValue field.
- the identifier of the second control algorithm is stored in an X.509 certificate, for example in the field algorithm of the field algorithm of the field subjectPublicKeyInfo as OBJECT IDENTIFIER, the parameters of the second control algorithm and the algorithm identifier of the second cryptographic algorithm together their parameters are stored in the Parameters field of the algorithm field of the subjectPublicKeyInfo field.
- the composite cryptographic data is stored in the subjectPublicKey field of the subjectPublicKeyInfo field.
- FIG. 7 is intended to illustrate that it is possible to store the composite cryptographic data of a number of first control algorithms in the same certificate.
- the certificate area iv or only the certificate fields i-iii contain composite cryptographic data or identifiers of control algorithms together with composite parameters and the other areas of the certificate contain conventional ones contain cryptographic data, identifiers and parameters from only a single conventional cryptographic algorithm.
- Composed cryptographic data can also be stored and read out in data structures according to the Cryptographic Message Syntax (see RFC 5652: Cryptographic Message Syntax (CMS), September 2009) without having to change anything in the standard.
- CMS Cryptographic Message Syntax
- the signed-data content type is used in CMS to sign data (see RFC 5652, section 5).
- the signatures of the individual signers are contained in a data structure area of the type SignerInfo called "signerlnfo".
- the identifier of the control algorithm, its control parameters and, as further parameters, the algorithm identifiers of the second cryptographic algorithms together with their component parameters can be inserted into the field 440 signatureAlgorithm.
- the identifier of the control algorithm is a SIGNATURE-OR, a SIGNATURE-AND, or a SIGNATURE-K-of-N.
- the composite cryptographic data comprises a juxtaposition of the results of the individual first cryptographic algorithms that still undergo a type conversion to OCTET STRING have been subjected to.
- the composed cryptographic data is used in field 438 "signature" of the data structure area SignerInfo.
- the enveloped-data content type is used in CMS to encrypt data (see RFC 5652, Section 6).
- a content-encryption key for (e.g. symmetrical) file encryption is generated at random and the content-encryption key is encrypted individually (e.g. asymmetrically) for each recipient.
- a RecipientInfo record is included in the enveloped-data content type data.
- This data structure area may have an area named KeyTransRecipientlnfo, KeyAgreeRecipientlnfo and other areas of analogous function.
- the identifier of the control algorithm, its control parameters and, as additional parameters, the algorithm identifiers of the second cryptographic algorithms together with their component parameters are used in the “keyEncryptionAlgorithm” field 440 there.
- the identifier of the control algorithm a DATA ENCRYPTION ITERATIVE can be used.
- the composite cryptographic data includes the results of the first cryptographic algorithms executed in succession, which were also subjected to a type conversion to OCTET STRING.
- the composed cryptographic data is used in the “encryptedKey” field 438 of the data structure.
- the identifier of the control algorithm and its control parameters are stored in the “keyEncryptionAlgorithm” field there, and the algorithm identifiers of the second cryptographic algorithms together with their component parameters are stored as additional parameters.
- a KEY AGREEMENT AGGREGATE can be used as an identifier for the control algorithm.
- OriginatorPublicKey SEQUENCE ⁇ algorithm Algorithm Identifier, publicKey BIT STRING ⁇
- the OriginatorPublicKey structure contains the algorithm field of type Algorithm Identifier. According to embodiments of the invention, this field contains the identifier of the control algorithm, optionally its control parameters and the sequence of algorithm identifiers of the second cryptographic algorithms. For example, the identifier of the control algorithm KEY-CONTAINER can be used. In this case, the composite cryptographic data is the concatenation of the public keys in the order in which they are specified in the parameters of the control algorithm. b) The encryption key used for the encryption is contained in the recipientEncryptionKeys field for a recipient of the recipientEncryptionKey type (see in particular RFC 5652, 6.2.2).
- RecipientEncryptedKey SEQUENCE ⁇ rid KeyAgreeRecipientldentifier, encryptedKey EncryptedKey ⁇
- the key encryptedKey is calculated by the first control algorithm specified in the keyEncryptionAlgorithm field from the KeyAgreeRecipientInfo structure, including the first cryptographic algorithms specified in the parameters and the keys specified and specified under a).
- the composite cryptographic data calculated with the control algorithm - the encryption key - is the result of an aggregation (e.g. with XOR) of the results of the executed first cryptographic algorithms.
- the composite cryptographic data is stored in the recipientEncryptedKey field of the KeyAgreeRecipien tlnfo data structure.
- the data structure according to the Cryptographic Message Syntax is used to verify or check the correctness and integrity of passports and other travel documents.
- Standards that describe the nature of the documents and their electronic data are, for example, ICAO Doc 9303, Machine Readable Travel Documents, Seventh Edition, 2015, Part 11: Security Mechanisms for MRTDs, and ICAO Doc 9303, Machine Readable Travel Documents, Seventh Edition , 2015, Part 12: Public Key Infrastructure for MRTDs.
- These travel documents (machine-readable travel documents - MRTD) contain electronic data whose integrity can be verified by checking the signature in the Document Security Object (SOD).
- SOD Document Security Object
- the signature corresponds to the signature of documents according to CMS (RFC 5652), so it is an example of a file signature that is commonly used and its conversion to quantum-secure signatures by storing composite cryptographic signatures and associated data in the above fields can be carried out.
- the data structure according to the Cryptographic Message Syntax is used to verify or check the correctness and integrity of ID cards, in particular the German ID card and German residence permits.
- the correctness and integrity of the The electronic data stored on ID cards and residence permits depends on the IT application used by checking the signature in the Document Security Object (SOD) in the EF file. CardSecurity or in the file EF. ChipSecurity detected.
- SOD Document Security Object
- SOD Document Security Object
- the signature corresponds to the signature of documents RFC 5652.
- Certificate requirements contain the technical part of a certificate application, with which the applicant applies for a certificate from a certification authority. It is often referred to as PKCS#10 because the first standard for such certificate requests was Standard #10 in the RSA Laboratories series of Public Key Cryptography Standards (now RFC 2986: PKCS #10: Certification Request Syntax is used). Specification, version 1.7, November 2000). According to RFC 2986, a PKCS#10 certificate request looks like this:
- CertificationRequest SEQUENCE ⁇ certificationRequestlnfo CertificationRequestlnfo, signatureAlgorithm Algorithmldentifier ⁇ SignatureAlgorithms ⁇ , signature BIT STRING
- signatureAlgorithm Like field 702 in the X.509 certificate, designates the algorithm with which the content of the PKCS#10 certificate request is certificationRequestInfo, is signed.
- the second control algorithm with its parameters is entered in the “signatureAlgorithm” field, which serves as the second field 440 .
- Signature Corresponds to the field signatureValue 706 and contains the value of the signature.
- the “signature” field of the certificate request which as the first field 438 contains the combined cryptographic data, i.e. the signature that was formed according to the algorithm described in i), is stored.
- the content of the PKCS#10 certificate request is certificationRequestlnfo and is defined according to RFC 2986 as
- ⁇ iv. subjectPKInfo Corresponds to the SubjectPublicKeyInfo 708 certificate area.
- This certificate area contains a public key, which is intended to be contained in the applicant's X.509 certificate, in accordance with the use previously envisaged in the prior art.
- the identifiers of the first and second fields correspond to the identifiers described for certificate range 708 of X.509 certificates (see in particular RFC 5280, which relates to SubjectPublicKeyInfo in certificates, and RFC 2986, which relates to the subjectPKInfo field in PKCS#10 ) and contain the same SubjectPublicKeylnfo type definition as quoted on page 74)
- subjectPKInfo is an area of a data structure 234 consisting of a 1st field 438 and a 2nd field 440.
- the 2nd field contains the ID of the control algorithm (e.g KEY CONTAINER) and as parameters the algorithm identifiers of the various in the 1 . Key contained in the field as a concatenation.
- CertificateList SEQUENCE ⁇ tbsCertList TBSCertList, signatureAlgorithm Algorithm Identifier, signatureValue BIT STRING ⁇
- a revocation list contains the field "signatureAlgorithm", which is used as a "second field” 440 and that "signature Value” field used as “first field” 438 .
- the data structure is a blocking list in which the identifier of the second control algorithm is stored in the "signatureAl gorithm” field, with the "signatureValue” field, in which the bit sequence of the individual algorithm signature is normally stored, according to embodiments of the invention the composite cryptographic data is stored.
- the "signatureAlgorithm” field thus serves here as a "second field” 440 for storing the identifier of the second control algorithm and the composite parameters and the "signature value” field as a "first field” 438 for storing the associated composite cryptographic data.
- the data structure is validity information for certificates, the identifier of the second control algorithm being stored in the “signatureAlgorithm” field, and the composite cryptographic data, preferably a composite cryptographic signature, being stored in the “signature” field.
- the "signatureAlgo rithm” field thus serves here as a "second field” 440 for storing the identifier of the second control algorithm and the composite parameters and the "signature” field as a "first field” 438 for storing the associated composite cryptographic data.
- FIG. 5 shows a scheme of the application of another first control algorithm and a data structure with the composite cryptographic data generated according to this.
- FIG. 4 illustrates the parallel application of several first cryptographic algorithms to the input data 208
- FIG. 5 shows the sequential (iterative) application of several first algorithms to the input data.
- a first cryptographic algorithm A 502 is first applied directly to the input data 208 in order to generate a first ciphertext 508 .
- This serves as an input to a second cryptographic algorithm B 504 which encrypts the ciphertext 508 to generate another ciphertext 510 .
- the method can be iteratively applied multiple times until the algorithm last applied returns a ciphertext 510 which is used as composite cryptographic data.
- the second control algorithm is typically not of the "OR" type, since all second cryptographic algorithms that are complementary to the iteratively applied first cryptographic algorithms must be applied to reconstruct the input data. If even one of these second cryptographic algorithms is missing in the chain, the method cannot be carried out. Nevertheless, an iterative application of the first cryptographic algorithms in the context of the transition to quantum computer-secure methods can also be helpful.
- the three encryption algorithms applied first could be conventional non-quantum secure encryption methods. The fact that several methods are used increases security. The provider cryptosystem can use these three encryption methods, for example, to provide a composite ciphertext for a recipient cryptosystem that has not yet been upgraded.
- the provider cryptosystem can contain an additional first control algorithm, which also provides a fourth level of encryption with the quantum computer-secure encryption algorithm.
- This composite ciphertext generated in four iterative encryption steps, can be sent to another recipient cryptosystem, which has four complementary decryption methods, including a quantum computer-secure decryption method.
- the ciphertext 510 represents the composite cryptographic data or a part thereof and is stored in a first field 438 of a predefined data structure 234 in which cryptographic data of a single cryptographic algorithm is stored by default.
- the identifier 410 of the "DATA ENCRYPTION-ITERATIVE" control algorithm and associated parameters, in particular the algorithm identifiers of the functionally complementary decryption algorithms C, B and A with the respective required component parameters 414 are stored in a second field 440 of this data structure, in which standard identifiers and Parameters of a single cryptographic algorithm are stored.
- the recipient cryptosystem Since the recipient cryptosystem has direct access to the algorithm identifiers of all algorithms A, B, C required for decryption in the second field 440, it can decide to carry out decryption and the corresponding second control algorithm. must not be carried out from the outset if it does not support at least one of the required second cryptographic algorithms.
- FIG. 6 shows a scheme for the application of a further first control algorithm and a data structure with the composite cryptographic data generated according to this.
- the application of this first control algorithm is similar to the algorithm described for Figure 5, with the difference that the component parameters of the respective encryption algorithms together with those from the previously calculated ciphertext of each are used as input to calculate the ciphertext of the next step in the sequence.
- only algorithm identifiers and component parameters of the encryption algorithm 506 C executed last or of the decryption algorithm to be executed first must be provided as parameters in plain text together with the combined cryptographic data 236 to the recipient cryptosystem, the algorithm identifiers and component parameters of the other encryption or decryption algorithms B, A arise during the decryption.
- the embodiments according to FIG. 5 are preferred.
- FIG. 7 shows an exemplary X.509 certificate containing composite cryptographic data and associated parameters from two different control algorithms stored in specific fields (see description of FIG. 4).
- first field 440 second field 502 encryption algorithm A 504 encryption algorithm B 506 encryption algorithm C
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102020117999.5A DE102020117999A1 (de) | 2020-07-08 | 2020-07-08 | Bereitsteller- und Empfänger-Kryptosysteme mit kombinierten Algorithmen |
| PCT/EP2021/068805 WO2022008587A1 (de) | 2020-07-08 | 2021-07-07 | Bereitsteller- und empfänger-kryptosysteme mit kombinierten algorithmen |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4179694A1 true EP4179694A1 (de) | 2023-05-17 |
Family
ID=76958969
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP21742801.0A Pending EP4179694A1 (de) | 2020-07-08 | 2021-07-07 | Bereitsteller- und empfänger-kryptosysteme mit kombinierten algorithmen |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20230269080A1 (de) |
| EP (1) | EP4179694A1 (de) |
| DE (1) | DE102020117999A1 (de) |
| WO (1) | WO2022008587A1 (de) |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2021056069A1 (en) * | 2019-09-25 | 2021-04-01 | Commonwealth Scientific And Industrial Research Organisation | Cryptographic services for browser applications |
| JP2023072170A (ja) * | 2021-11-12 | 2023-05-24 | キヤノン株式会社 | 情報処理装置および情報処理装置の制御方法 |
| CN115208587B (zh) * | 2022-09-15 | 2022-12-09 | 三未信安科技股份有限公司 | 一种基于密码模块的密码算法的实现系统及方法 |
| US12170725B2 (en) * | 2022-10-03 | 2024-12-17 | At&T Intellectual Property I, L.P. | Methods, systems, and procedures for quantum secure ecosystems |
| CN119544233A (zh) * | 2023-08-28 | 2025-02-28 | 华为技术有限公司 | 一种基于安全协商的通信方法及装置 |
| CN118842659B (zh) * | 2024-09-23 | 2024-12-20 | 北京隐算科技有限公司 | 一种基于RSA的n选k不经意传输方法 |
| US20260106764A1 (en) * | 2024-10-14 | 2026-04-16 | Institute For Basic Science | Electronic signature device using multiple electronic signature scheme and electronic signature system including the same |
| CN120434044B (zh) * | 2025-07-02 | 2025-11-04 | 山东云海国创云计算装备产业创新中心有限公司 | 一种加密方法、装置、设备、存储介质及计算机程序产品 |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6941459B1 (en) * | 1999-10-21 | 2005-09-06 | International Business Machines Corporation | Selective data encryption using style sheet processing for decryption by a key recovery agent |
| DE102006012180A1 (de) * | 2006-03-16 | 2007-09-20 | Manfred Hoffleisch | Kryptographisches Verfahren |
| US20100278338A1 (en) | 2009-05-04 | 2010-11-04 | Mediatek Singapore Pte. Ltd. | Coding device and method with reconfigurable and scalable encryption/decryption modules |
| US8918648B2 (en) * | 2010-02-25 | 2014-12-23 | Certicom Corp. | Digital signature and key agreement schemes |
| US10375043B2 (en) * | 2014-10-28 | 2019-08-06 | International Business Machines Corporation | End-to-end encryption in a software defined network |
| EP3110065A1 (de) * | 2015-06-24 | 2016-12-28 | medisite Technology GmbH | Verschlüsselungsfilter |
| US10666437B2 (en) * | 2017-11-07 | 2020-05-26 | Harris Solutions NY, Inc. | Customizable encryption/decryption algorithm |
| US11563590B1 (en) * | 2018-04-03 | 2023-01-24 | Amazon Technologies, Inc. | Certificate generation method |
| US11184157B1 (en) * | 2018-06-13 | 2021-11-23 | Amazon Technologies, Inc. | Cryptographic key generation and deployment |
| US12058113B2 (en) * | 2019-06-19 | 2024-08-06 | Amazon Technologies, Inc. | Hybrid key exchanges for double-hulled encryption |
| US11322050B1 (en) * | 2020-01-30 | 2022-05-03 | Wells Fargo Bank, N.A. | Systems and methods for post-quantum cryptography optimization |
-
2020
- 2020-07-08 DE DE102020117999.5A patent/DE102020117999A1/de active Pending
-
2021
- 2021-07-07 WO PCT/EP2021/068805 patent/WO2022008587A1/de not_active Ceased
- 2021-07-07 EP EP21742801.0A patent/EP4179694A1/de active Pending
- 2021-07-07 US US18/004,100 patent/US20230269080A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| WO2022008587A1 (de) | 2022-01-13 |
| DE102020117999A1 (de) | 2022-01-13 |
| US20230269080A1 (en) | 2023-08-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2022008587A1 (de) | Bereitsteller- und empfänger-kryptosysteme mit kombinierten algorithmen | |
| DE112021006229B4 (de) | Hybride schlüsselableitung zum sichern von daten | |
| DE60305775T2 (de) | Verfahren und Gerät zur Berechnung von Haschwerten in einem kryptographischen Koprozessor | |
| DE602005002652T2 (de) | System und Verfahren für das Erneuern von Schlüsseln, welche in Public-Key Kryptographie genutzt werden | |
| DE102009024604B4 (de) | Erzeugung eines Session-Schlüssels zur Authentisierung und sicheren Datenübertragung | |
| EP3182318B1 (de) | Signaturgenerierung durch ein sicherheitstoken | |
| EP1125395B1 (de) | Verfahren und anordnung zur authentifikation von einer ersten instanz und einer zweiten instanz | |
| DE112015002927B4 (de) | Generierung und Verwaltung geheimer Chiffrierschlüssel auf Kennwortgrundlage | |
| DE112011100182T5 (de) | Transaktionsprüfung für Datensicherheitsvorrichtungen | |
| DE102021129514A1 (de) | Binden von post-quanten-zertifikaten | |
| DE202008013415U1 (de) | Datenverarbeitungssystem zur Bereitstellung von Berechtigungsschlüsseln | |
| DE102015210734A1 (de) | Verwaltung kryptographischer schlüssel | |
| DE102010055699A1 (de) | Kryptographisches Verfahren | |
| WO2015022150A1 (de) | Unterstützung einer entschlüsselung von verschlüsselten daten | |
| DE19702049C1 (de) | Zertifizierung kryptografischer Schlüssel für Chipkarten | |
| DE102011003919A1 (de) | Mobilfunkgerätbetriebenes Authentifizierugssystem unter Verwendung einer asymmetrischen Verschlüsselung | |
| DE19622630C1 (de) | Verfahren zum gruppenbasierten kryptographischen Schlüsselmanagement zwischen einer ersten Computereinheit und Gruppencomputereinheiten | |
| DE112012000971B4 (de) | Datenverschlüsselung | |
| EP2863610A2 (de) | Verfahren und System zum manipulationssicheren Bereitstellen mehrerer digitaler Zertifikate für mehrere öffentliche Schlüssel eines Geräts | |
| EP3672142A1 (de) | Verfahren und system zur sicheren übertragung eines datensatzes | |
| EP3552344B1 (de) | Bidirektional verkettete blockchainstruktur | |
| CN114510734B (zh) | 数据访问控制方法、装置及计算机可读存储介质 | |
| WO2018085870A1 (de) | Verfahren zum austausch von datenfeldern von zertifizierten dokumenten | |
| DE102015111715B4 (de) | Sichere elektronische Unterzeichnung von Information | |
| DE60021985T2 (de) | Verfahren ind vorrichtung zur sicheren erzeugung von öffentlichen/geheimen schlüsselpaaren |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20230208 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| P01 | Opt-out of the competence of the unified patent court (upc) registered |
Effective date: 20230526 |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20250509 |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: BUNDESDRUCKEREI GMBH |