WO2000074298A1 - Technique for split knowledge backup and recovery of a cryptographic key - Google Patents

Technique for split knowledge backup and recovery of a cryptographic key Download PDF

Info

Publication number
WO2000074298A1
WO2000074298A1 PCT/US2000/013381 US0013381W WO0074298A1 WO 2000074298 A1 WO2000074298 A1 WO 2000074298A1 US 0013381 W US0013381 W US 0013381W WO 0074298 A1 WO0074298 A1 WO 0074298A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
cryptographic key
data segments
random number
cryptographic
Prior art date
Application number
PCT/US2000/013381
Other languages
French (fr)
Inventor
George M. Brookner
Lorenz R. Frey
Original Assignee
Ascom Hasler Mailing Systems, Inc.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ascom Hasler Mailing Systems, Inc. filed Critical Ascom Hasler Mailing Systems, Inc.
Priority to EP00937559A priority Critical patent/EP1183816A4/en
Priority to CA2374968A priority patent/CA2374968C/en
Publication of WO2000074298A1 publication Critical patent/WO2000074298A1/en
Priority to US11/708,750 priority patent/US7916871B2/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/085Secret sharing or secret splitting, e.g. threshold schemes

Definitions

  • the present invention is directed to a technique for secure communications, and in particular to a private/public key cryptographic scheme for such communications.
  • a postal security device In prior art, a postal security device (PSD) is used in a franking system for storing a fund therein for postage dispensation. When the stored fund runs out, a data center needs to be contacted to download more funds into the PSD such that it can continue to issue postage. Because of the sensitive nature of the communications between the PSDs and the data center, which involves the transfer of funds, the critical funds-related communications are typically encrypted and/or cryptographically signed.
  • each PSD contains a private/public key set in accordance with a well known cryptographic methodology.
  • the private key of each PSD is used to encrypt and cryptographically sign a message to be sent to the data center, which has knowledge of each PSD ' s public key.
  • the data center decrypts and verifies the authenticity of the message using the public key associated with the particular PSD.
  • the resulting cleartext message may contain, among others, a request for additional funds to be downloaded into the PSD.
  • the data center then sends a response message to the PSD authorizing the further issuance of postage (i.e. downloading funds to the PSD) . It is also typical that such a response message is cryptographically signed by the data center.
  • the data center has at least one private key therein to sign the response message .
  • the public key corresponding to such a private key is known by the PSDs served by the data center, and is used by the PSDs to authenticate the response message.
  • the private key of the data center be kept secret.
  • the private key is securely maintained in a module known as a security device (SD) , which may be a secured personal computer (PC), in the data center.
  • SD security device
  • PC personal computer
  • a cryptographic key e.g., a private key, in the above- described data center
  • a cryptographic key is processed to generate multiple data segments from which the cryptographic key is recoverable.
  • At least one of the data segments is a function of a random number and at least part of the cryptographic key.
  • the data segments are provided to trusted entities, e.g., individuals, for safe keeping thereof. Each entity has no knowledge of the data segment provided to another entity.
  • the trusted entities are required to input the respective data segments into a system where they are recombined to yield the original key.
  • error checking is performed to verify that the recovered key is identical to the original key.
  • Fig. 1 illustrates an arrangement which includes a franking system capable of communicating with a data center m accordance with the invention
  • Fig. 2 is a flow diagram illustrating the process by which a first trusted entity obtains its key segment for recovering a private key m the data center;
  • Fig. 3 is a flow diagram illustrating the process by which a second trusted entity obtains its key segment for recovering the private key
  • Fig. 4 is a flow diagram illustrating the process by which the first trusted entity inputs its key segment ;
  • Fig. 5 is a flow diagram illustrating the process by which the second trusted entity enters its key segment
  • Fig. 6 is a flow diagram illustrating a process for verifying that a restored private key is identical to the original private key
  • Figs. 7A and 7B jointly illustrate a process for deriving key segments from the original private key.
  • Fig. 1 illustrates an arrangement embodying the principles of the invention.
  • this arrangement includes franking system 100 which in cooperation with data center 125 generates postage indicia serving as proof of postage.
  • System 100 includes computer 105 of conventional design, printer 115, postal security device (PSD) 110 capable of authorizing printing of postage indicia on printer 115, and modem 120 for communications with data center 125.
  • PSD postal security device
  • the arrangement of Fig. 1 may be used for a variety of purposes other than the printing of postage indicia.
  • the arrangement may also be used for issuing tickets such as lottery tickets and event tickets.
  • Data center 125 includes key management system
  • K S security device
  • SD security device
  • I/O interface 140 for input/output of information.
  • KMS 135 and SD 130 interact with each other to provide the facility to back up and recover at least one cryptographic key, e.g., private key 133, stored in SD 130.
  • PSD 110 is used for storing a fund therein for postage dispensation.
  • PSD 110 needs to communicate with data center 125 to download more funds thereto such that it can continue to issue postage.
  • the critical funds-related communications are encrypted and/or cryptographically signed.
  • KMS 135 in this instance cryptographically signs messages to PSD 110 using private key 133, in accordance with the well known digital signature algorithm (DSA) pursuant to the Digital Signature Standard (DSS) , described in Federal Information Processing Standards Publication (FIPS Pub)
  • the resulting message may be authenticated in PSD 110 using the public key (not shown) therein corresponding to private key 133. It should be noted that one may utilize, instead of the DSA, the RSA or Elliptic Curve or other well known cryptographic methodology for data authentication purposes.
  • a private key e.g., private key 133
  • a data center such as through tampering or equipment failure
  • multiple key segments are generated based on private key 133, which are respectively distributed to trusted entities, e.g., trusted users. Each trusted entity has no knowledge of others' key segments.
  • Each key segment may be recorded m a recordable medium, e.g., a printout or a storage device .
  • the original key can be restored only when all of the trusted entities produce the respective key segments, based on which the original key is reconstructed.
  • KMS 135 and SD 130 m data center 125 interact with each other to provide the facility to back up and recover private key 133 m accordance with the invention.
  • the input and output of key segment information is accomplished using I/O interface 140.
  • key segment information is output from data center 125 m the form of a printout using a printer connected to interface 140.
  • the key segment information may be downloaded directly into a storage device connected to interface 140.
  • a trusted user may enter key segment information into data center 125 via a keyboard connected to interface 140 after the user reads from a printout recording the key segment information.
  • it may be entered by direct communication from a storage device storing the key segment information through interface 140.
  • SD 130 is used to manage private key 133 and the key segment generation algorithms within its secure boundary.
  • private key 133 is maintained m an environment separate from the processing system of KMS 135 which handles all interactions between SD 130 and the users, yet interconnected for normal working application.
  • PINs personal identification numbers
  • identifying the trusted users are stored within SD 130. These PINs are preassigned to the users, respectively.
  • SD 130 includes within its microprocessor system, among other software/firmware applications, critical security-related functionalities such as a library to carry out modular long integer mathematics; the capability of generating random numbers, which is compatible with FIPS Pub 140-1, or other accepted standard for self-tests of the random number generation capability; generation and verification of DSA signatures in accordance with the DSS, and all PIN related functions.
  • critical security-related functionalities such as a library to carry out modular long integer mathematics; the capability of generating random numbers, which is compatible with FIPS Pub 140-1, or other accepted standard for self-tests of the random number generation capability; generation and verification of DSA signatures in accordance with the DSS, and all PIN related functions.
  • SD 130 includes such specific functionalities as an identity-based access control mechanism based on the use of the PINs; a highly privileged function to output private key 133 for the key segmenting operation in accordance with the invention; a highly privileged function to enter key material for the key recovery operation; generation of error codes; and a self-test to check the correct segmentation of private key 133, e.g., by comparing bitwise private key 133 with the bitwise exclusive-OR value of key segments.
  • two or more users are entrusted with key segments in accordance with the invention.
  • two users are entrusted with the following Key Segment 1 and Key Segment 2, respectively:
  • R represents a random number or bit string
  • X represents private key 133
  • Fig. 2 illustrates the process for generating Key Segment 1 for a first user in accordance with the invention
  • KMS 135 prompts the first user for entry of his/her PIN.
  • the first user enters PIN1 identifying him/her through I/O interface 140.
  • PIN1 is then sent to SD 130.
  • SD 130 verifies PIN1 by comparing it to the previously established PIN for the first user. SD 130 then generates a random number R.
  • R is a 160 bit number, but a random number of another bit length may be used.
  • a true random number is generated by SD 130.
  • the random number may be generated using a pseudorandom number generator, for example, the one described in Appendix C of ANSI standard X9.17 (Financial Institution Key Management (Wholesale) ) .
  • the hash of R is then computed, resulting in h(R) .
  • the hash function used in this illustrative embodiment is the secure hash algorithm (SHA-1) described in FIPS Pub 180-1. However, another well known secure one-way hash algorithm may be used, instead.
  • SD 130 then computes the hash of private key 133, resulting in h(X) . In this instance, private key 133 is a 160 bit number, although a key of another length may be utilized.
  • the random number R, the hash of the random number h(R) , and the hash of private key 133 h(X) are then sent to KMS 135.
  • KMS 135 independently calculates the hash of received random number R, and compares it with the received h(R) to ensure that there is a match. If there is no match, KMS 135 sets an error condition (EC) to 1. The process is then aborted and an error is indicated, e.g., through a display mechanism (not shown) connected to interface 140.
  • KMS 135 erases or otherwise makes unavailable all traces of data from SD 130, which includes the random number R, and the hash values h(R) and h (X) .
  • KMS 135 also ensures that none of such data remains in any auxiliary device, for example, in a non-volatile memory of a printer. KMS 135 then confirms correct termination of the process. Thus, with the printout, the first user is in possession of Key Segment 1, i.e., R, along with the values h(R) and h (X) associated therewith.
  • Fig. 3 illustrates the process for generating Key Segment 2 for a second user in accordance with the invention.
  • KMS 135 prompts the second user for a PIN.
  • the second user enters his previously established PIN, denoted PIN2 , which is sent to SD 130.
  • PIN2 the previously established PIN
  • SD 130 verifies the identity of the second user by matching the received PIN2 with the previously established PIN for the second user.
  • SD 130 calculates the bitwise exclusive-OR of the random number R and private key X, and performs a hash function on the result.
  • KMS 135 (a) the bitwise exclusive-OR of the random number R and private key X, i.e., R ⁇ X, (b) the hash of the bitwise exclusive-OR of the random number R and private key X, i.e., h(R ⁇ X) , and (c) the hash of the private key X, i.e., h(X) .
  • KMS 135 erases all traces of data received from SD 130, and ensures that any auxiliary devices do not contain any such data. KMS 135 then confirms correct termination of the process to SD 130.
  • the second user is m possession of Key Segment 2, i.e., R ®
  • Key Segments 1 and 2 and their associated hash values are respectively archived by the first and second users at separate locations geographically different from where SD 130 resides.
  • the users independently secure their respective key segments and associated hash values, which may be encrypted and which may be recorded in printouts, storage devices or other recordable mediums.
  • the latter may be kept in a secure environment, e.g., a safe, and each user has no access to the other's key segment information.
  • each user may record all necessary identification information, such as the date of generation of his/her key segment and the identification of the user receiving the key segment .
  • Fig. 4 illustrates a process whereby the first user enters Key Segment 1 to SD 130.
  • KMS 135 prompts the first user for entry of his/her PIN.
  • PIN1 which is sent to SD 130.
  • PIN1 which is sent to SD 130.
  • SD 130 verifies whether the correct PIN has been entered, and indicates any success of the PIN verification to KMS 135.
  • KMS 135 prompts the first user for the entry of Key Segment 1, i.e., R.
  • the first user enters Key Segment 1 (R) .
  • KMS 135 computes the hash of R and displays the result.
  • the first user compares the hash value generated by KMS 135 with the corresponding h (R) previously provided to him/her in the process of Fig. 2. If there is no match, then it is determined that an error has occurred, and the step in box 417 may be repeated by the user for a predetermined number of trials. When the predetermined number of trials is exceeded, the process is aborted.
  • KMS 135 sends Key Segment 1 (R) to SD 130, and erases all traces of Key Segment 1 from the memory of KMS 135 and any auxiliary devices used during the process .
  • Fig. 5 illustrates a process whereby the second user enters Key Segment 2 to SD 130.
  • KMS 135 prompts the second user for his/her PIN.
  • the second user enters PIN2 , which is sent to SD 130.
  • SD 130 verifies whether the correct PIN has been entered and indicates any success of the verification to KMS 135.
  • KMS 135 prompts the second user for entry of Key Segment 2, i.e., R ⁇ X.
  • the second user enters Key Segment 2 (R ® X) to KMS 135.
  • KMS 135 computes h(R ® X) and displays the result.
  • the second user compares the hash value generated by KMS 135 with the corresponding h(R ⁇ X) previously provided to him/her in the process of Fig. 3. If there is no match, it is determined that an error has occurred, and the step in box 525 may be repeated by the second user for a predetermined number of trials. If the predetermined number of trials is exceeded, the process is aborted. In box 528, KMS 135 sends Key
  • Segment 2 (R ⁇ X) to SD 130 and erases all traces of Key Segment 2 from the memory of KMS 135 and any auxiliary devices used during the process.
  • Fig. 6 illustrates the process used for recovering private key 133 and verification of the recovered private key.
  • SD 130 recovers private key X by performing a bitwise exclusive-OR of Key Segment 1 (R) entered by the first user and Key Segment 2
  • SD 130 then computes the hash value of the recovered private key X, i.e., h(X), and sends it to KMS 135.
  • KMS 135 displays the computed h(X) .
  • the first user compares the displayed hash value with the corresponding h(X) previously provided to him/her m the process of Fig. 2.
  • the second user similarly compares the displayed hash value with the corresponding h(X) previously provided to him/her m the process of Fig. 3. This comparison by each of the users is performed independently, without either user seeing the other's record.
  • m box 633 KMS 135 signals to SD 130 that private key 133 is restored and verified. Otherwise, if any of the comparisons does not result m a match, the process is aborted.
  • M users are entrusted with key segments, respectively, based on which the original key is recovered, where M represents an integer greater than or equal to two.
  • M 2 case
  • M > 2 cases similarly follow. For instance, in an M > 2 case, M users may be entrusted with the respective M key segments as follows:
  • FIGs. 7A and 7B jointly illustrate the process whereby X 1# X 2 ... and X M 1 are derived from private key 133, denoted X.
  • X is divided into M-1 portions, denoted portion 1, portion 2, ..., and portion M- 1. It should be noted that portions 1 through M-1 may be m different lengths.
  • X 1 is a bit string as long as X, which includes the same bits and their bit positions as portion 1 of X, with the rest of the bit string stuffed with bits "0" .
  • X 2 is a bit string which includes the same bits and their bit positions as portion 2 of X, with the rest of the bit string stuffed with bits "0"; ...; and X H 1 ⁇ s a bit string which includes the same bits and their bit positions as portion M-1 of X, with the rest of the bit string stuffed with bits "0" .
  • the invention generally applies to other systems and methods where the integrity of a cryptographic key is important, and a secure backup of such a cryptographic key is desirable.
  • the key segments received by the trusted entities may be weighted. For example, in a three-key- segment scheme, one key segment may be privileged or accorded more weight than the other two key segments in that it would allow recovery of private key 133 based on the privileged key segment, combined with either of the other two key segments.
  • system 100 and data center 125 are disclosed herein in a form in which various functions are performed by discrete functional blocks. However, any one or more of these functions could equally well be embodied in an arrangement in which the functions of any one or more of those blocks or indeed, all of the functions thereof, are realized, for example, by one or more appropriate memories, and/or appropriately programmed processors.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

In a secure cryptographic environment, a private key in a private/public key cryptographic scheme needs to be backed up and recovered in case of a loss or corruption of the private key. To back up the private key, multiple key segments are generated based on the private key which are distributed to a corresponding number of trusted individuals, each of whom has knowledge of only his or her key segment. The key can be restored (629) only when all of the trusted individuals provide the respective key segments, based on which the original private key is reconstructed (629). In addition, each trusted individual is uniquely identifiable by a personal identification number. Advantageously, the private key, which is secret, can be backed up and restored (629) without any individual having knowledge of the full key.

Description

Description
TECHNIQUE FOR SPLIT KNOWLEDGE BACKUP AND RECOVERY OF A CRYPTOGRAPHIC KEY
Technical Field
The present invention is directed to a technique for secure communications, and in particular to a private/public key cryptographic scheme for such communications.
Background of the Invention
In prior art, a postal security device (PSD) is used in a franking system for storing a fund therein for postage dispensation. When the stored fund runs out, a data center needs to be contacted to download more funds into the PSD such that it can continue to issue postage. Because of the sensitive nature of the communications between the PSDs and the data center, which involves the transfer of funds, the critical funds-related communications are typically encrypted and/or cryptographically signed.
For example, each PSD contains a private/public key set in accordance with a well known cryptographic methodology. The private key of each PSD is used to encrypt and cryptographically sign a message to be sent to the data center, which has knowledge of each PSD ' s public key. The data center decrypts and verifies the authenticity of the message using the public key associated with the particular PSD. The resulting cleartext message may contain, among others, a request for additional funds to be downloaded into the PSD. The data center then sends a response message to the PSD authorizing the further issuance of postage (i.e. downloading funds to the PSD) . It is also typical that such a response message is cryptographically signed by the data center. To that end, the data center has at least one private key therein to sign the response message . The public key corresponding to such a private key is known by the PSDs served by the data center, and is used by the PSDs to authenticate the response message. To prevent fraud and to ensure a secure environment, it is desirable that the private key of the data center be kept secret. Specifically, the private key is securely maintained in a module known as a security device (SD) , which may be a secured personal computer (PC), in the data center. However, in the event of a loss of the private key, such as through tampering or equipment failure, absent any way to recover the key, it would be necessary to recall each PSD served by the data center to reprogram the PSD with a public key corresponding to the data center's new private key. It is therefore desirable to provide a methodology to back up and recover the data center's private key which is secret in a secure manner which does not require divulgence of all or part of the private key.
Summary of the Invention
In accordance with the invention, a cryptographic key, e.g., a private key, in the above- described data center, is processed to generate multiple data segments from which the cryptographic key is recoverable. At least one of the data segments is a function of a random number and at least part of the cryptographic key. The data segments are provided to trusted entities, e.g., individuals, for safe keeping thereof. Each entity has no knowledge of the data segment provided to another entity.
In the event that the cryptographic key is lost or corrupted, to recover the key, the trusted entities are required to input the respective data segments into a system where they are recombined to yield the original key. In accordance with an aspect of the invention, error checking is performed to verify that the recovered key is identical to the original key. Bπef Description of the Drawing
Further objects, features and advantages of the invention will become apparent from the following detailed description taken m con unction with the accompanying drawing, m which:
Fig. 1 illustrates an arrangement which includes a franking system capable of communicating with a data center m accordance with the invention;
Fig. 2 is a flow diagram illustrating the process by which a first trusted entity obtains its key segment for recovering a private key m the data center;
Fig. 3 is a flow diagram illustrating the process by which a second trusted entity obtains its key segment for recovering the private key; Fig. 4 is a flow diagram illustrating the process by which the first trusted entity inputs its key segment ;
Fig. 5 is a flow diagram illustrating the process by which the second trusted entity enters its key segment;
Fig. 6 is a flow diagram illustrating a process for verifying that a restored private key is identical to the original private key; and
Figs. 7A and 7B jointly illustrate a process for deriving key segments from the original private key.
Detailed Description
Fig. 1 illustrates an arrangement embodying the principles of the invention. By way of example, this arrangement includes franking system 100 which in cooperation with data center 125 generates postage indicia serving as proof of postage. System 100 includes computer 105 of conventional design, printer 115, postal security device (PSD) 110 capable of authorizing printing of postage indicia on printer 115, and modem 120 for communications with data center 125. It should be appreciated that the arrangement of Fig. 1 may be used for a variety of purposes other than the printing of postage indicia. For example, the arrangement may also be used for issuing tickets such as lottery tickets and event tickets. Data center 125 includes key management system
(K S) 135, security device (SD) 130, and I/O interface 140 for input/output of information. In accordance with the invention, KMS 135 and SD 130 interact with each other to provide the facility to back up and recover at least one cryptographic key, e.g., private key 133, stored in SD 130.
As is well known, PSD 110 is used for storing a fund therein for postage dispensation. When the stored fund runs out, PSD 110 needs to communicate with data center 125 to download more funds thereto such that it can continue to issue postage. Because of the sensitive nature of the communications between PSD 110 and data center 125, which involves the transfer of funds, the critical funds-related communications are encrypted and/or cryptographically signed. For example, KMS 135 in this instance cryptographically signs messages to PSD 110 using private key 133, in accordance with the well known digital signature algorithm (DSA) pursuant to the Digital Signature Standard (DSS) , described in Federal Information Processing Standards Publication (FIPS Pub)
186-2. The resulting message may be authenticated in PSD 110 using the public key (not shown) therein corresponding to private key 133. It should be noted that one may utilize, instead of the DSA, the RSA or Elliptic Curve or other well known cryptographic methodology for data authentication purposes.
In prior art, in the event of a loss or corruption of a private key, e.g., private key 133, in a data center such as through tampering or equipment failure, it would be necessary to recall each PSD served by the data center to reprogram the PSD with a public key corresponding to the data center's new private key. However, m accordance with the invention, multiple key segments are generated based on private key 133, which are respectively distributed to trusted entities, e.g., trusted users. Each trusted entity has no knowledge of others' key segments. Each key segment may be recorded m a recordable medium, e.g., a printout or a storage device . The original key can be restored only when all of the trusted entities produce the respective key segments, based on which the original key is reconstructed.
To that end, KMS 135 and SD 130 m data center 125 interact with each other to provide the facility to back up and recover private key 133 m accordance with the invention. The input and output of key segment information is accomplished using I/O interface 140.
For example, m this instance key segment information is output from data center 125 m the form of a printout using a printer connected to interface 140. Alternatively, the key segment information may be downloaded directly into a storage device connected to interface 140. Similarly, m this instance a trusted user may enter key segment information into data center 125 via a keyboard connected to interface 140 after the user reads from a printout recording the key segment information. Alternatively, it may be entered by direct communication from a storage device storing the key segment information through interface 140. It should also be noted that many other input/output methodologies may be used, instead. In this illustrative embodiment, SD 130 is used to manage private key 133 and the key segment generation algorithms within its secure boundary. As a result, private key 133 is maintained m an environment separate from the processing system of KMS 135 which handles all interactions between SD 130 and the users, yet interconnected for normal working application. In addition, personal identification numbers (PINs) for identifying the trusted users are stored within SD 130. These PINs are preassigned to the users, respectively.
Specifically, SD 130 includes within its microprocessor system, among other software/firmware applications, critical security-related functionalities such as a library to carry out modular long integer mathematics; the capability of generating random numbers, which is compatible with FIPS Pub 140-1, or other accepted standard for self-tests of the random number generation capability; generation and verification of DSA signatures in accordance with the DSS, and all PIN related functions. In addition, SD 130 includes such specific functionalities as an identity-based access control mechanism based on the use of the PINs; a highly privileged function to output private key 133 for the key segmenting operation in accordance with the invention; a highly privileged function to enter key material for the key recovery operation; generation of error codes; and a self-test to check the correct segmentation of private key 133, e.g., by comparing bitwise private key 133 with the bitwise exclusive-OR value of key segments.
To back up private key 133 without compromising the security of the key or allowing anyone's access to the full key, two or more users are entrusted with key segments in accordance with the invention. Without loss of generality, in this example two users are entrusted with the following Key Segment 1 and Key Segment 2, respectively:
Key Segment 1 = R ; (i) Key Segment 2 = R θ X , (ii)
where R represents a random number or bit string; X represents private key 133; and the "θ" symbol represents a bitwise exclusive-OR operation. It can be shown that X can be reconstructed or recovered based on Key Segment 1 and Key Segment 2 in the following manner: X = Key Segment 1 θ Key Segment 2
= R θ (R ® X) . (iii)
Fig. 2 illustrates the process for generating Key Segment 1 for a first user in accordance with the invention, in box 201 KMS 135 prompts the first user for entry of his/her PIN. In box 202, the first user enters PIN1 identifying him/her through I/O interface 140. PIN1 is then sent to SD 130. In box 203, SD 130 verifies PIN1 by comparing it to the previously established PIN for the first user. SD 130 then generates a random number R.
In this illustrative embodiment, R is a 160 bit number, but a random number of another bit length may be used. Preferably, a true random number is generated by SD 130. However, the random number may be generated using a pseudorandom number generator, for example, the one described in Appendix C of ANSI standard X9.17 (Financial Institution Key Management (Wholesale) ) .
The hash of R is then computed, resulting in h(R) . The hash function used in this illustrative embodiment is the secure hash algorithm (SHA-1) described in FIPS Pub 180-1. However, another well known secure one-way hash algorithm may be used, instead. SD 130 then computes the hash of private key 133, resulting in h(X) . In this instance, private key 133 is a 160 bit number, although a key of another length may be utilized. The random number R, the hash of the random number h(R) , and the hash of private key 133 h(X) are then sent to KMS 135. In box 204, KMS 135 independently calculates the hash of received random number R, and compares it with the received h(R) to ensure that there is a match. If there is no match, KMS 135 sets an error condition (EC) to 1. The process is then aborted and an error is indicated, e.g., through a display mechanism (not shown) connected to interface 140.
Otherwise, if there is a match, KMS 135 sets EC = 0 and prints, for the first user, the values of EC, R, h(R) and h (X) on a printout in a predetermined format, e.g., in concatenation. Alternatively, the delivery of such values could be via an encrypted email function to the user requiring the user entry of a decryption key. In box 205, the first user verifies that no error has occurred, i.e., EC = 0 , and confirms the correct termination of the process. In box 206, KMS 135 erases or otherwise makes unavailable all traces of data from SD 130, which includes the random number R, and the hash values h(R) and h (X) . KMS 135 also ensures that none of such data remains in any auxiliary device, for example, in a non-volatile memory of a printer. KMS 135 then confirms correct termination of the process. Thus, with the printout, the first user is in possession of Key Segment 1, i.e., R, along with the values h(R) and h (X) associated therewith.
Fig. 3 illustrates the process for generating Key Segment 2 for a second user in accordance with the invention. In box 307, KMS 135 prompts the second user for a PIN. In box 308, the second user enters his previously established PIN, denoted PIN2 , which is sent to SD 130. In box 309, SD 130 verifies the identity of the second user by matching the received PIN2 with the previously established PIN for the second user. SD 130 then calculates the bitwise exclusive-OR of the random number R and private key X, and performs a hash function on the result. SD 130 sends to KMS 135 (a) the bitwise exclusive-OR of the random number R and private key X, i.e., R θ X, (b) the hash of the bitwise exclusive-OR of the random number R and private key X, i.e., h(R θ X) , and (c) the hash of the private key X, i.e., h(X) . In box 310, KMS 135 based on item (a) just received independently calculates h (R Φ X), and then compares the calculated value to item (b) just received from SD 130. If there is no match, KMS 135 sets EC = 1. In addition, the process is aborted and an error is indicated.
Otherwise, if there is a match, KMS 135 sets EC = 0, and prints, for the second user, the values EC, R θ
X, h(R θ X) and h(X) on a printout m a predetermined format, e.g., m concatenation. In box 311, the second user verifies that there is no error, and then confirms the correct termination of the process. In box 312, KMS 135 erases all traces of data received from SD 130, and ensures that any auxiliary devices do not contain any such data. KMS 135 then confirms correct termination of the process to SD 130. Thus, with the printout, the second user is m possession of Key Segment 2, i.e., R ®
X, along with the values h(R θ X) and h(X) associated therewith.
In this illustrative embodiment, Key Segments 1 and 2 and their associated hash values are respectively archived by the first and second users at separate locations geographically different from where SD 130 resides. The users independently secure their respective key segments and associated hash values, which may be encrypted and which may be recorded in printouts, storage devices or other recordable mediums. The latter may be kept in a secure environment, e.g., a safe, and each user has no access to the other's key segment information. In addition to the key segment and associated hash values, each user may record all necessary identification information, such as the date of generation of his/her key segment and the identification of the user receiving the key segment .
In the event that private key 133 is lost or corrupted m the memory of SD 130, both users need to correctly identify themselves and enter their key segments in order to reconstruct original key 133 in accordance with expression (in) above. Fig. 4 illustrates a process whereby the first user enters Key Segment 1 to SD 130. In box 413, KMS 135 prompts the first user for entry of his/her PIN. In box 414, the first user enters PIN1, which is sent to SD 130. In box 415, SD 130 verifies whether the correct PIN has been entered, and indicates any success of the PIN verification to KMS 135. In box 416, KMS 135 prompts the first user for the entry of Key Segment 1, i.e., R. In box 417, the first user enters Key Segment 1 (R) . In box 418, KMS 135 computes the hash of R and displays the result. In box 419, the first user compares the hash value generated by KMS 135 with the corresponding h (R) previously provided to him/her in the process of Fig. 2. If there is no match, then it is determined that an error has occurred, and the step in box 417 may be repeated by the user for a predetermined number of trials. When the predetermined number of trials is exceeded, the process is aborted. In box 420, KMS 135 sends Key Segment 1 (R) to SD 130, and erases all traces of Key Segment 1 from the memory of KMS 135 and any auxiliary devices used during the process .
Fig. 5 illustrates a process whereby the second user enters Key Segment 2 to SD 130. In box 521, KMS 135 prompts the second user for his/her PIN. In box 522, the second user enters PIN2 , which is sent to SD 130. In box 523, SD 130 verifies whether the correct PIN has been entered and indicates any success of the verification to KMS 135. In box 524, KMS 135 prompts the second user for entry of Key Segment 2, i.e., R θ X. In box 525, the second user enters Key Segment 2 (R ® X) to KMS 135. In box 526, KMS 135 computes h(R ® X) and displays the result. In box 527, the second user compares the hash value generated by KMS 135 with the corresponding h(R θ X) previously provided to him/her in the process of Fig. 3. If there is no match, it is determined that an error has occurred, and the step in box 525 may be repeated by the second user for a predetermined number of trials. If the predetermined number of trials is exceeded, the process is aborted. In box 528, KMS 135 sends Key
Segment 2 (R θ X) to SD 130 and erases all traces of Key Segment 2 from the memory of KMS 135 and any auxiliary devices used during the process.
Fig. 6 illustrates the process used for recovering private key 133 and verification of the recovered private key. In box 629, SD 130 recovers private key X by performing a bitwise exclusive-OR of Key Segment 1 (R) entered by the first user and Key Segment 2
(R θ X) entered by the second user, in accordance with expression (in) above. SD 130 then computes the hash value of the recovered private key X, i.e., h(X), and sends it to KMS 135. In box 630, KMS 135 displays the computed h(X) . In box 631, the first user compares the displayed hash value with the corresponding h(X) previously provided to him/her m the process of Fig. 2. In box 632, the second user similarly compares the displayed hash value with the corresponding h(X) previously provided to him/her m the process of Fig. 3. This comparison by each of the users is performed independently, without either user seeing the other's record. If the respective comparisons by the users both result m a match, m box 633 KMS 135 signals to SD 130 that private key 133 is restored and verified. Otherwise, if any of the comparisons does not result m a match, the process is aborted. In general, in accordance with the invention, M users are entrusted with key segments, respectively, based on which the original key is recovered, where M represents an integer greater than or equal to two. Although the above example fully describes the M = 2 case, M > 2 cases similarly follow. For instance, in an M > 2 case, M users may be entrusted with the respective M key segments as follows:
Key Segment 1 = R ;
Key Segment 2 = R θ Xλ Key Segment 3 = X2 Key Segment M = XM λ
where R represents a random number or bit string as before; and Xl r X2 ... and XM 1 represent derivatives of private key 133, respectively. Figs. 7A and 7B jointly illustrate the process whereby X1# X2 ... and XM 1 are derived from private key 133, denoted X.
As shown m Fig. 7A, X is divided into M-1 portions, denoted portion 1, portion 2, ..., and portion M- 1. It should be noted that portions 1 through M-1 may be m different lengths. As shown m Fig. 7B, X1 is a bit string as long as X, which includes the same bits and their bit positions as portion 1 of X, with the rest of the bit string stuffed with bits "0" . Similarly, X2 is a bit string which includes the same bits and their bit positions as portion 2 of X, with the rest of the bit string stuffed with bits "0"; ...; and XH 1ιs a bit string which includes the same bits and their bit positions as portion M-1 of X, with the rest of the bit string stuffed with bits "0" . It is apparent from the disclosure heretofore that the process whereby each of users 3 through M obtains the key segment corresponding to the user is similar to that of Fig. 3, with Key Segment 2 replaced by the corresponding key segment.
It can be shown that X can be reconstructed or recovered based on Key Segments 1 through M m the following manner:
X = Key Segment 1 θ Key Segment 2 θ Key Segment 3 θ ... θ Key Segment M
= R θ (RΘX θ X2 θ ... θ XM .
It is also apparent from the disclosure heretofore that the process whereby each of users 3 through M enters the corresponding key segment into SD 130 for recovering X is similar to that of Fig. 5, with Key Segment 2 replaced by the corresponding key segment. In addition, the restoration of X and verification of the recovered X here are similar to those described in Fig. 6.
The foregoing merely illustrates the principles of the invention. It will thus be appreciated that those skilled in the art will be able to devise numerous other arrangements which embody the principles of the invention and are thus within its spirit and scope.
For example, the invention is readily understood when presented in the context of a franking system.
However, the invention generally applies to other systems and methods where the integrity of a cryptographic key is important, and a secure backup of such a cryptographic key is desirable. In addition, the key segments received by the trusted entities may be weighted. For example, in a three-key- segment scheme, one key segment may be privileged or accorded more weight than the other two key segments in that it would allow recovery of private key 133 based on the privileged key segment, combined with either of the other two key segments.
Finally, system 100 and data center 125 are disclosed herein in a form in which various functions are performed by discrete functional blocks. However, any one or more of these functions could equally well be embodied in an arrangement in which the functions of any one or more of those blocks or indeed, all of the functions thereof, are realized, for example, by one or more appropriate memories, and/or appropriately programmed processors.

Claims

Cl aims
1. Apparatus for processing a cryptographic key, the apparatus comprising: a processor for generating a plurality of data segments, at least one of the data segments being a function of a random number and at least part of the cryptographic key; and an interface for providing the data segments, the cryptographic key being recoverable from the data segments .
2. The apparatus of claim 1 wherein a second one of the data segments comprises the random number.
3. The apparatus of claim 1 wherein the data segments are provided to a plurality of entities, respectively .
4. The apparatus of claim 3 wherein each entity has no knowledge of the data segment provided to another entity.
5. The apparatus of claim 3 wherein each entity is identified by a different personal identification number
(PIN) .
6. The apparatus of claim 1 wherein the cryptographic key includes a private key in accordance with a cryptographic methodology.
7. The apparatus of claim 6 wherein the cryptographic methodology includes a digital signature algorithm (DSA) methodology.
8. The apparatus of claim 1 wherein the interface also provides a hash value of the cryptographic key for verification of a recovered cryptographic key.
9. The apparatus of claim 1 wherein the random number is a pseudo random number.
10. Apparatus for recovering a cryptographic key, the apparatus comprising: an interface for receiving a plurality of data segments, at least one of the data segments being a function of a random number and at least part of the cryptographic key; and a processor for recovering the cryptographic key based on the data segments.
11. The apparatus of claim 10 wherein a second one of the data segments comprises the random number.
12. The apparatus of claim 10 wherein the data segments are provided to a plurality of entities, respectively.
13. The apparatus of claim 12 wherein each entity has no knowledge of the data segment provided to another entity.
14. The apparatus of claim 12 wherein each entity is identified by a different PIN.
15. The apparatus of claim 10 wherein the cryptographic key includes a private key in accordance with a cryptographic methodology.
16. The apparatus of claim 15 wherein the cryptographic methodology includes a DSA methodology.
17. The apparatus of claim 10 wherein the interface also provides a hash value of the cryptographic key for verification of the recovered cryptographic key.
18. The apparatus of claim 10 wherein the random number is a pseudo random number.
19. An arrangement comprising: a first apparatus for communicating with a second apparatus, at least part of communications between the first apparatus and the second apparatus being encoded using a cryptographic key, the first apparatus further comprising: a first processor for generating a plurality of data segments which are associated with a plurality of entities, respectively, at least one of the data segments being a function of a random number and at least part of the cryptographic key, the data segments being provided to the respective entities; an interface for receiving from the entities the data segments associated with the entities; and a second processor for recovering the cryptographic key based on the data segments.
20. The arrangement of claim 19 wherein the interface also provides a hash value of the at least one data segment for verification of an entry of the at least one data segment .
21. The arrangement of claim 19 wherein the first processor is the same as the second processor.
22. The arrangement of claim 19 wherein the communications concern transfer of funds.
23. The arrangement of claim 19 wherein the second apparatus includes a postal security device.
24. The arrangement of claim 19 wherein the first apparatus includes a device for storing the cryptographic key therein.
25. The arrangement of claim 19 wherein the cryptographic key is a private key in accordance with a cryptographic methodology.
26. A method for processing a cryptographic key comprising : generating a plurality of data segments, at least one of the data segments being a function of a random number and at least part of the cryptographic key; and providing the data segments, the cryptographic key being recoverable from the data segments.
27. The method of claim 26 wherein a second one of the data segments comprises the random number.
28. The method claim 26 wherein the data segments are provided to a plurality of entities, respectively.
29. The method of claim 28 wherein each entity has no knowledge of the data segment provided to another entity.
30. The method of claim 28 wherein each entity is identified by a different PIN.
31. The method of claim 26 wherein the cryptographic key includes a private key in accordance with a cryptographic methodology.
32. The method of claim 26 wherein the cryptographic methodology includes a DSA methodology.
33. The method of claim 26 further comprising providing a hash value of the cryptographic key for verification of a recovered cryptographic key.
34. The method of claim 26 wherein the random number is a pseudo random number.
35. A method for recovering a cryptographic key comprising : receiving a plurality of data segments, at least one of the data segments being a function of a random number and at least part of the cryptographic key; and recovering the cryptographic key based on the data segments.
36. The method of claim 35 wherein a second one of the data segments comprises the random number.
37. The method of claim 35 wherein the data segments are provided to a plurality of entities, respectively.
38. The method of claim 37 wherein each entity has no knowledge of the data segment provided to another entity.
39. The method of claim 37 wherein each entity is identified by a different PIN.
40. The method of claim 35 wherein the cryptographic key includes a private key in accordance with a cryptographic methodology.
41. The method of claim 40 wherein the cryptographic methodology includes a DSA methodology.
42. The method of claim 35 wherein the interface also provides a hash value of the cryptographic key for verification of the recovered cryptographic key.
43. The method of claim 35 wherein the random number is a pseudo random number.
44. An method for use in an arrangement which includes a first apparatus for communicating with a second apparatus, at least part of communications between the first apparatus and the second apparatus being encoded using a cryptographic key, the method comprising: generating a plurality of data segments which are associated with a plurality of entities, respectively, at least one of the data segments being a function of a random number and at least part of the cryptographic key, the data segments being provided to the respective entities; receiving from the entities the data segments associated with the entities; and recovering the cryptographic key based on the data segments.
45. The method of claim 44 further comprising providing a hash value of the at least one data segment for verification of an entry of the at least one data segment .
46. The method of claim 44 wherein the communications concern transfer of funds.
PCT/US2000/013381 1999-05-26 2000-05-16 Technique for split knowledge backup and recovery of a cryptographic key WO2000074298A1 (en)

Priority Applications (3)

Application Number Priority Date Filing Date Title
EP00937559A EP1183816A4 (en) 1999-05-26 2000-05-16 Technique for split knowledge backup and recovery of a cryptographic key
CA2374968A CA2374968C (en) 1999-05-26 2000-05-16 Technique for split knowledge backup and recovery of a cryptographic key
US11/708,750 US7916871B2 (en) 1999-05-26 2007-02-21 Technique for split knowledge backup and recovery of a cryptographic key

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US13595399P 1999-05-26 1999-05-26
US60/135,953 1999-05-26

Related Child Applications (2)

Application Number Title Priority Date Filing Date
US09979343 A-371-Of-International 2000-05-16
US11/708,750 Continuation US7916871B2 (en) 1999-05-26 2007-02-21 Technique for split knowledge backup and recovery of a cryptographic key

Publications (1)

Publication Number Publication Date
WO2000074298A1 true WO2000074298A1 (en) 2000-12-07

Family

ID=22470544

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2000/013381 WO2000074298A1 (en) 1999-05-26 2000-05-16 Technique for split knowledge backup and recovery of a cryptographic key

Country Status (4)

Country Link
US (1) US7916871B2 (en)
EP (1) EP1183816A4 (en)
CA (1) CA2374968C (en)
WO (1) WO2000074298A1 (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6473743B1 (en) * 1999-12-28 2002-10-29 Pitney Bowes Inc. Postage meter having delayed generation of cryptographic security parameters
GB2410656A (en) * 2004-01-29 2005-08-03 Toshiba Res Europ Ltd Secure delivery of encryption key by splitting it amongst messages from many sources to hinder interception
US7894599B2 (en) 2006-12-04 2011-02-22 International Business Machines Corporation Enhanced data security with redundant inclusive data encryption segments

Families Citing this family (43)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7613812B2 (en) * 2002-12-04 2009-11-03 Microsoft Corporation Peer-to-peer identity management interfaces and methods
US7949996B2 (en) 2003-10-23 2011-05-24 Microsoft Corporation Peer-to-peer identity management managed interfaces and methods
US7496648B2 (en) * 2003-10-23 2009-02-24 Microsoft Corporation Managed peer name resolution protocol (PNRP) interfaces for peer to peer networking
US8688803B2 (en) 2004-03-26 2014-04-01 Microsoft Corporation Method for efficient content distribution using a peer-to-peer networking infrastructure
CN101375284B (en) * 2004-10-25 2012-02-22 安全第一公司 Secure data parser method and system
US7571228B2 (en) * 2005-04-22 2009-08-04 Microsoft Corporation Contact management in a serverless peer-to-peer system
US8036140B2 (en) * 2005-04-22 2011-10-11 Microsoft Corporation Application programming interface for inviting participants in a serverless peer to peer network
US8438115B2 (en) * 2005-09-23 2013-05-07 Pitney Bowes Inc. Method of securing postage data records in a postage printing device
CN105978683A (en) 2005-11-18 2016-09-28 安全第公司 Secure data parser method and system
US8352482B2 (en) * 2009-07-21 2013-01-08 Vmware, Inc. System and method for replicating disk images in a cloud computing based virtual machine file system
US8234518B2 (en) * 2009-07-21 2012-07-31 Vmware, Inc. Method for voting with secret shares in a distributed system
US8352490B2 (en) 2009-10-22 2013-01-08 Vmware, Inc. Method and system for locating update operations in a virtual machine disk image
EP2553904A2 (en) 2010-03-31 2013-02-06 Rick L. Orsini Systems and methods for securing data in motion
EP2651072A3 (en) 2010-09-20 2013-10-23 Security First Corp. Systems and methods for secure data sharing
WO2013059871A1 (en) 2011-10-28 2013-05-02 The Digital Filing Company Pty Ltd Registry
WO2014127147A1 (en) 2013-02-13 2014-08-21 Security First Corp. Systems and methods for a cryptographic file system layer
FR3024002B1 (en) 2014-07-21 2018-04-27 Ercom Eng Reseaux Communications METHOD FOR SECURING A SECRET OF A USER AND METHOD FOR RESTORING A SECRET OF A USER
US10693639B2 (en) * 2017-02-28 2020-06-23 Blackberry Limited Recovering a key in a secure manner
US10957445B2 (en) 2017-10-05 2021-03-23 Hill-Rom Services, Inc. Caregiver and staff information system
KR20240093786A (en) 2018-01-17 2024-06-24 티제로 아이피, 엘엘씨 Multi-approval system using m of n keys to restore a customer wallet
US11095446B2 (en) * 2018-02-27 2021-08-17 Anchor Labs, Inc. Cryptoasset custodial system with different rules governing access to logically separated cryptoassets and proof-of-stake blockchain support
EP3766204A4 (en) * 2018-03-15 2021-12-15 tZERO IP, LLC Splitting encrypted key and encryption key used to encrypt key into key components allowing assembly with subset of key components to decrypt encrypted key
WO2019204650A1 (en) * 2018-04-19 2019-10-24 PIV Security LLC Peer identity verification
WO2020076722A1 (en) 2018-10-12 2020-04-16 Medici Ventures, Inc. Encrypted asset encryption key parts allowing for assembly of an asset encryption key using a subset of the encrypted asset encryption key parts
US11082235B2 (en) 2019-02-14 2021-08-03 Anchor Labs, Inc. Cryptoasset custodial system with different cryptographic keys controlling access to separate groups of private keys
US11494763B2 (en) 2019-08-19 2022-11-08 Anchor Labs, Inc. Cryptoasset custodial system with custom logic
US11301845B2 (en) 2019-08-19 2022-04-12 Anchor Labs, Inc. Cryptoasset custodial system with proof-of-stake blockchain support
US11100497B2 (en) 2019-08-20 2021-08-24 Anchor Labs, Inc. Risk mitigation for a cryptoasset custodial system using a hardware security key
US11562349B2 (en) 2019-08-20 2023-01-24 Anchor Labs, Inc. Risk mitigation for a cryptoasset custodial system using data points from multiple mobile devices
US11501291B2 (en) 2019-08-23 2022-11-15 Anchor Labs, Inc. Cryptoasset custodial system using encrypted and distributed client keys
US11657140B2 (en) 2019-12-10 2023-05-23 Winkk, Inc. Device handoff identification proofing using behavioral analytics
US11652815B2 (en) 2019-12-10 2023-05-16 Winkk, Inc. Security platform architecture
US11928193B2 (en) 2019-12-10 2024-03-12 Winkk, Inc. Multi-factor authentication using behavior and machine learning
US11936787B2 (en) 2019-12-10 2024-03-19 Winkk, Inc. User identification proofing using a combination of user responses to system turing tests using biometric methods
US11328042B2 (en) 2019-12-10 2022-05-10 Winkk, Inc. Automated transparent login without saved credentials or passwords
US12073378B2 (en) 2019-12-10 2024-08-27 Winkk, Inc. Method and apparatus for electronic transactions using personal computing devices and proxy services
US11574045B2 (en) 2019-12-10 2023-02-07 Winkk, Inc. Automated ID proofing using a random multitude of real-time behavioral biometric samplings
US11553337B2 (en) 2019-12-10 2023-01-10 Winkk, Inc. Method and apparatus for encryption key exchange with enhanced security through opti-encryption channel
EP4111639A4 (en) 2020-02-26 2024-02-28 tZERO IP, LLC Secret splitting and metadata storage
US11843943B2 (en) 2021-06-04 2023-12-12 Winkk, Inc. Dynamic key exchange for moving target
US12095751B2 (en) 2021-06-04 2024-09-17 Winkk, Inc. Encryption for one-way data stream
US11824999B2 (en) * 2021-08-13 2023-11-21 Winkk, Inc. Chosen-plaintext secure cryptosystem and authentication
US20240291650A1 (en) * 2022-02-15 2024-08-29 Google Llc Secure environment for operations on private data

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5276737A (en) * 1992-04-20 1994-01-04 Silvio Micali Fair cryptosystems and methods of use
US5557346A (en) * 1994-08-11 1996-09-17 Trusted Information Systems, Inc. System and method for key escrow encryption
US5764767A (en) * 1996-08-21 1998-06-09 Technion Research And Development Foundation Ltd. System for reconstruction of a secret shared by a plurality of participants
US5857022A (en) * 1994-01-13 1999-01-05 Certco Llc Enhanced cryptographic system and method with key escrow feature
US5937066A (en) * 1996-10-02 1999-08-10 International Business Machines Corporation Two-phase cryptographic key recovery system
US6041317A (en) * 1996-11-19 2000-03-21 Ascom Hasler Mailing Systems, Inc. Postal security device incorporating periodic and automatic self implementation of public/private key pair
US6052469A (en) * 1996-07-29 2000-04-18 International Business Machines Corporation Interoperable cryptographic key recovery system with verification by comparison

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5241597A (en) * 1991-02-01 1993-08-31 Motorola, Inc. Method for recovering from encryption key variable loss
US5454038A (en) * 1993-12-06 1995-09-26 Pitney Bowes Inc. Electronic data interchange postage evidencing system
NZ500372A (en) * 1995-06-05 2001-04-27 Certco Inc Delegated use of electronic signature
US5764772A (en) * 1995-12-15 1998-06-09 Lotus Development Coporation Differential work factor cryptography method and system
US5815573A (en) * 1996-04-10 1998-09-29 International Business Machines Corporation Cryptographic key recovery system

Patent Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5276737A (en) * 1992-04-20 1994-01-04 Silvio Micali Fair cryptosystems and methods of use
US5276737B1 (en) * 1992-04-20 1995-09-12 Silvio Micali Fair cryptosystems and methods of use
USRE35808E (en) * 1992-04-20 1998-05-26 Bankers Trust Company Fair cryptosystems and methods of use
US5857022A (en) * 1994-01-13 1999-01-05 Certco Llc Enhanced cryptographic system and method with key escrow feature
US5557346A (en) * 1994-08-11 1996-09-17 Trusted Information Systems, Inc. System and method for key escrow encryption
US5640454A (en) * 1994-08-11 1997-06-17 Trusted Information Systems, Inc. System and method for access field verification
US5956403A (en) * 1994-08-11 1999-09-21 Network Association, Inc. System and method for access field verification
US6052469A (en) * 1996-07-29 2000-04-18 International Business Machines Corporation Interoperable cryptographic key recovery system with verification by comparison
US5764767A (en) * 1996-08-21 1998-06-09 Technion Research And Development Foundation Ltd. System for reconstruction of a secret shared by a plurality of participants
US5937066A (en) * 1996-10-02 1999-08-10 International Business Machines Corporation Two-phase cryptographic key recovery system
US6041317A (en) * 1996-11-19 2000-03-21 Ascom Hasler Mailing Systems, Inc. Postal security device incorporating periodic and automatic self implementation of public/private key pair

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"SECRET SHARING", APPLIED CRYPTOGRAPHY, XX, XX, 1 January 1996 (1996-01-01), XX, pages 71 - 73, XP002931093 *
See also references of EP1183816A4 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6473743B1 (en) * 1999-12-28 2002-10-29 Pitney Bowes Inc. Postage meter having delayed generation of cryptographic security parameters
GB2410656A (en) * 2004-01-29 2005-08-03 Toshiba Res Europ Ltd Secure delivery of encryption key by splitting it amongst messages from many sources to hinder interception
GB2410656B (en) * 2004-01-29 2006-04-12 Toshiba Res Europ Ltd Communication device networks
US7894599B2 (en) 2006-12-04 2011-02-22 International Business Machines Corporation Enhanced data security with redundant inclusive data encryption segments

Also Published As

Publication number Publication date
CA2374968A1 (en) 2000-12-07
EP1183816A4 (en) 2005-09-14
US7916871B2 (en) 2011-03-29
EP1183816A1 (en) 2002-03-06
US20080031460A1 (en) 2008-02-07
CA2374968C (en) 2010-11-16

Similar Documents

Publication Publication Date Title
CA2374968C (en) Technique for split knowledge backup and recovery of a cryptographic key
EP0725512B1 (en) Data communication system using public keys
US5142577A (en) Method and apparatus for authenticating messages
US4825050A (en) Security transaction system for financial data
EP1374473B1 (en) Method and apparatus for secure cryptographic key generation, certification and use
US4458109A (en) Method and apparatus providing registered mail features in an electronic communication system
EP0539727B1 (en) Cryptographic facility environment backup/restore and replication in a public key cryptosystem
US8583928B2 (en) Portable security transaction protocol
US7716491B2 (en) Generation and management of customer pin's
CN1565117B (en) Data certification method and apparatus
JP3020958B2 (en) A device that checks the authenticity of a document
US6079018A (en) System and method for generating unique secure values for digitally signing documents
US6061791A (en) Initial secret key establishment including facilities for verification of identity
US6073125A (en) Token key distribution system controlled acceptance mail payment and evidencing system
CN101110141A (en) Method for key diversification on an ic card
JPH01197786A (en) Apparatus for verifying authenticity of several documents
CN109918888B (en) Anti-quantum certificate issuing method and issuing system based on public key pool
CN111639348B (en) Management method and device of database keys
JPH11298470A (en) Key distribution method and system
EP0811955A2 (en) Secure apparatus and method for printing value with a value printer
US6738899B1 (en) Method for publishing certification information certified by a plurality of authorities and apparatus and portable data storage media used to practice said method
US6847951B1 (en) Method for certifying public keys used to sign postal indicia and indicia so signed
US20050005077A1 (en) Method, data processing device, and loading device for loading data into a memory with complete memory occupancy
EP0998074B1 (en) Method of digital signature, and secret information management method and system
GB2391669A (en) Portable device for verifying a document's authenticity

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): CA US

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE

121 Ep: the epo has been informed by wipo that ep was designated in this application
DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
WWE Wipo information: entry into national phase

Ref document number: 2000937559

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2374968

Country of ref document: CA

Ref country code: CA

Ref document number: 2374968

Kind code of ref document: A

Format of ref document f/p: F

WWE Wipo information: entry into national phase

Ref document number: 09979343

Country of ref document: US

WWP Wipo information: published in national office

Ref document number: 2000937559

Country of ref document: EP