US2014281502A1PendingUtilityA1
Method and apparatus for embedding secret information in digital certificates
Est. expiryMar 15, 2033(~6.6 yrs left)· nominal 20-yr term from priority
H04L 9/3265H04L 9/3263H04L 9/3268H04L 9/3242H04L 9/30H04L 2209/24G06F 21/335H04L 2209/64
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and system is provided for embedding cryptographically modified versions of secret in digital certificates for use in authenticating devices and in providing services subject to conditional access conditions.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of enabling provision of a service to a first entity, comprising the steps of:
receiving a service request in a second entity from the first entity, the service request comprising a leaf digital certificate generated and digitally signed by a certification entity and provided to the first entity, the leaf digital certificate having a unique identifier of the first entity and a two-way cryptographic function of a secret generated according to a provision key unknown to the first entity and the digital certificate digitally signed by a private key of the certification entity according to an asymmetric crypto algorithm; recovering the secret in the second entity from the leaf digital certificate; and enabling provision of the service to the first entity according to the recovered secret.
2 . The method of claim 1 , wherein the step of recovering the secret comprises:
recovering the two-way cryptographic function of the secret from the digitally signed digital certificate; and inverting the two-way cryptographic function to recover the secret.
3 . The method of claim 2 , wherein the step of inverting the two way cryptographic function comprises:
inverting the two-way cryptographic function according to the provision key.
4 . The method of claim 3 , wherein the two-way cryptographic function is a symmetric function and the provision key is a symmetric key known to the certification entity and the service enabling entity.
5 . The method of claim 3 , wherein the two-way cryptographic function is an asymmetric function and the provision key is an encryption key and the two-way cryptographic function is inverted according to a decryption key corresponding to the encryption key.
6 . The method of claim 2 , wherein the step of recovering the two-way cryptographic function of the secret from the digital certificate comprises:
attempting verifying the digitally signed leaf digital certificate; and recovering the two way cryptographic function of the secret from the leaf digital certificate only if the leaf digital certificate is verified.
7 . The method of claim 6 , wherein the leaf digital certificate is verified according to a public key of the certification entity.
8 . The method of claim 6 , wherein:
the first entity is a member of a class of devices, and the certification entity comprises a sub-certification entity providing the leaf digital certificate to the first entity and other leaf digital certificates to each of the other devices in the class of devices; each leaf digital certificate comprises a unique identifier of each associated device and an associated secret unique to the associated device; each leaf digital certificate is digitally signed according to a trusted sub-certification entity digital certificate provided by the sub-certification entity; and the method further comprises:
determining if the sub-certification entity certificate or any digital certificate in a chain up to a root of trust has been revoked; and
verifying the leaf digital certificate only if the trusted digital sub-certification entity digital certificate and any digital certificate in the chain up to the root of trust has not been revoked.
9 . The method of claim 8 , wherein the step of determining if the trusted sub-certificate has been revoked comprises:
receiving, from the second entity, a list identifying revoked sub-certification entity certificates; and determining that the trusted sub-certification entity certificate has been revoked if the list identifies the trusted sub-certification entity certificate.
10 . The method of claim 1 , wherein the certification entity further provides the secret to the first entity and the provision of the service is enabled at least in part on a match between the secret provided to the first entity and the secret recovered by the second entity.
11 . The method of claim 10 , wherein the secret is provided to the first entity in a same message as the digital certificate.
12 . The method of claim 1 , wherein the provision of the service is enabled only if the digital certificate and all digital certificates in the chain from the digital certificate up to a root of trust are not a member of a set of revoked digital certificates.
13 . The method of claim 12 , further comprising the steps of:
receiving, in the second entity, a list identifying revoked digital certificates; and determining if the digital certificate is among the identified the revoked digital certificates; enabling the provision of the service only if the digital certificate and all digital certificates in the chain from the digital certificate up to a root of trust are not among the identified revoked digital certificates.
14 . An apparatus for enabling provision of a service to a first entity the apparatus disposed in a second entity and comprising:
a communications module, for transceiving information, wherein the information comprises:
a service request from the first entity, the service request comprising a leaf digital certificate generated and digitally signed by a certification entity and provided to the first entity, the leaf digital certificate having a unique identifier of the first entity and a two-way cryptographic function of a secret generated according to a provision key unknown to the first entity and the digital certificate digitally signed by a private key of the certification entity according to an asymmetric crypto algorithm;
a processor, for executing instructions stored in a memory communicatively coupled to the processor, the instructions including instructions for: recovering the secret in the second entity from the leaf digital certificate; and enabling provision of the service to the first entity according to the recovered secret.
15 . The apparatus of claim 14 , wherein the instructions for recovering the secret comprise instructions for:
recovering the two-way cryptographic function of the secret from the digitally signed digital certificate; and inverting the two-way cryptographic function to recover the secret.
16 . The apparatus of claim 15 , wherein:
the instructions for inverting the two way cryptographic function comprise instructions for inverting the two-way cryptographic function according to the provision key;
17 . The apparatus of claim 16 , wherein the two-way cryptographic function is a symmetric function and the provision key is a symmetric key known to the certification entity and the service enabling entity.
18 . The apparatus of claim 16 , wherein the two-way cryptographic function is an asymmetric function and the provision key is an encryption key and the two-way cryptographic function is inverted according to a decryption key corresponding to the encryption key.
19 . The apparatus of claim 15 , wherein the instructions recovering the two-way cryptographic function of the secret from the digital certificate comprise instructions for:
attempting verifying the digitally signed leaf digital certificate; and recovering the two way cryptographic function of the secret from the leaf digital certificate only if the leaf digital certificate is verified.
20 . The apparatus of claim 19 , wherein:
the first entity is a member of a class of devices, and the certification entity comprises a sub-certification entity providing the leaf digital certificate to the first entity and other leaf digital certificates to each of the other devices in the class of devices; each leaf digital certificate comprises a unique identifier of each associated device and an associated secret unique to the associated device; each leaf digital certificate is digitally signed according to a trusted sub-certification entity digital certificate provided by the sub-certification entity; and the instructions further comprise instructions for:
determining if the sub-certification entity certificate or any digital certificate in a chain up to a root of trust has been revoked; and
verifying the leaf digital certificate only if the trusted digital sub-certification entity digital certificate and any digital certificate in the chain up to the root of trust has not been revoked.Join the waitlist — get patent alerts
Track US2014281502A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.