Method and apparatus for digital signature

By introducing a security department and a remote signature system into the data processing device, digital certificates and signatures are generated and verified, solving the problems of insufficient traceability and anti-counterfeiting security of digital signatures in the prior art, and achieving higher security and reliability.

CN115776374BActive Publication Date: 2026-01-02塞巴斯蒂安·阿姆莱德
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211056164.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-01-05
Filing Date
2022-08-31
Publication Date
2026-01-02
Estimated Expiration
2042-08-31

AI Technical Summary

Technical Problem

Existing digital signature methods are inadequate in terms of traceability and anti-counterfeiting security.

Method used

By introducing a security unit into the data processing device, generating and storing private keys and random number generators that cannot be extracted, and combining this with a remote signature system, digital certificates and signatures can be generated and verified, ensuring the security and reliability of the private key.

Benefits of technology

It improves the traceability and anti-counterfeiting security of digital signatures, prevents forgery and fraud, supports the backup and recovery of data processing devices, and enhances system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115776374B_ABST
    Figure CN115776374B_ABST
Patent Text Reader

Abstract

The invention provides a method and apparatus for digital signing. The invention relates to a data processing apparatus comprising a secure part, wherein the secure part comprises a private key, an unencrypted private certificate key and a seed generated based on the private certificate key, wherein the private key, the unencrypted private certificate key and the seed cannot be extracted from the secure part. The invention further relates to a method, wherein the method uses a data processing apparatus, the method comprising: receiving, by the secure part, a request to sign; generating, in the secure part, a signature signed using a private key derived from the seed and signing the signature using the unencrypted private certificate key, thereby generating a signature signed using the unencrypted private certificate key; and outputting the signature signed using the private key derived from the seed and the signature signed using the unencrypted private certificate key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present invention relates to digital signatures. Digital signatures can be used, for example, to sign blockchain transactions, smart contracts or to provide timestamps. BACKGROUND

[0002] While many methods of providing digital signatures are known, they have certain disadvantages and shortcomings, in particular with respect to traceability and forgery security. SUMMARY

[0003] The present invention seeks to overcome or at least alleviate the disadvantages and shortcomings of prior art methods. It is therefore an object of the present invention to provide a technique for digital signatures that is improved over the prior art, for example with respect to traceability and / or forgery security.

[0004] The present invention meets these objects.

[0005] In a first aspect, the present invention relates to a method. The method comprises providing a data processing device, wherein the data processing device comprises a secure part, wherein the secure part comprises a private key that cannot be extracted from the secure part, wherein the secure part comprises a public key corresponding to the private key; the data processing device providing a signing request, the public key and a serial number; an external data processing device generating a signed digital certificate based on the signing request, the public key and the signing request; and providing the signed digital certificate to the data processing device. It is to be understood that the method according to the first aspect relates to setting up and initializing the data processing device. In order to distinguish between the data processing device before and after initialization, the data processing device that has not yet been initialized can also be referred to as a local or initial data processing device.

[0006] The secure part can comprise a random number generator that cannot be extracted from the secure part, and the method can comprise the random number generator generating the serial number.

[0007] The private key can be generated based on an output from the random number generator.

[0008] The data processing device can be a smart card.

[0009] The smart card can have near field communication functionality.

[0010] The method can comprise providing the signed digital certificate to a data processing system; the data processing system receiving personal user data from a user; providing the public certificate key to the data processing system; the data processing system generating a signed digital system certificate signed with the public certificate key based on the personal user data, the signed digital certificate and the public certificate key; and providing the signed digital system certificate to the data processing device. It is to be understood that providing the public certificate key to the data processing system also comprises generating the public certificate key by the data processing system.

[0011] The method can comprise generating a public certificate key and a corresponding private certificate key, encrypting the private certificate key using a public key, thereby generating a wrapped key, and providing the wrapped key to a secure part of the data processing device.

[0012] Generating a public certificate key and a corresponding private certificate key, encrypting the private certificate key using a public key, thereby generating a wrapped key, and providing the wrapped key to a secure part of the data processing device can be performed by a data processing system, and wherein the wrapped key is provided from the data processing system to the secure part of the data processing device.

[0013] Generating a public certificate key and a corresponding private certificate key, encrypting the private certificate key using a public key, thereby generating a wrapped key, and providing the wrapped key to a secure part of the data processing device can be performed by another data processing system; the method can further comprise providing the public key from the data processing device to the other data processing system; wherein providing the public certificate key to the data processing system comprises providing the public certificate key from the other data processing system to the data processing system.

[0014] The method can comprise decrypting, in the secure part, the wrapped key using the private key, thereby obtaining the private certificate key.

[0015] The method can comprise generating, in the secure part, a seed based on the private certificate key.

[0016] By the described method, a data processing device can be set up and initialized. It will be appreciated that after performing the method, the data processing device comprises a signed digital certificate and a signed digital system certificate (signed by the public certificate key). Furthermore, the secure part of the data processing device further comprises a seed, a private key and a private certificate key.

[0017] In another aspect, the application relates to an initialization method for initializing a data processing device comprising a secure part, wherein the initialization method comprises generating, in a remote signing system, a remote asymmetric key pair comprising a remote private key and a remote public key, providing the remote public key to the secure part of the data processing device, and generating a signing credential, wherein the remote signing system is configured to sign a data structure upon receiving the signing credential.

[0018] The signing credential can be generated by the remote signing system.

[0019] The initialization method can further comprise providing the signing credential to the data processing device, e.g. to the secure part of the data processing device.

[0020] The application also relates to a combination method. The combination method comprises the method as discussed above and the initialization method as discussed above. The data processing device of the method is the data processing device of the initialization method. It will be understood that the security part of the method is the security part of the initialization method.

[0021] In another aspect, the application relates to a data processing device comprising a security part; wherein the security part comprises a private key, an unencrypted private certificate key and a seed generated based on the private certificate key, wherein the private key, the unencrypted private certificate key and the seed cannot be extracted from the security part.

[0022] Such a data processing device, for example obtained by the method according to the first aspect, can have improved functionality.

[0023] In particular, by means of the seed and the private certificate key, the data processing device can sign a signature, for example of a transaction that can then be output (for example, broadcast).

[0024] For example, by using the unencrypted private certificate key that can be provided by an external entity, an additional verification can be provided. For example, the private certificate key can be issued by an identified entity, and if the key issued by such an entity is used, another user can only identify the signature, thereby providing a whitelist functionality.

[0025] The data processing device can comprise a signed digital certificate.

[0026] The security part comprises a random number generator.

[0027] The data processing device can be a smart card.

[0028] The smart card can have a near field communication functionality.

[0029] The data processing device can comprise a serial number generated by the random number generator.

[0030] The data processing device can comprise a signed digital system certificate, wherein the signed digital system certificate is signed using a public certificate key corresponding to the private certificate key, and wherein the signed digital system certificate is based on personal user data, the signed digital certificate and the public certificate key.

[0031] As the data processing device can comprise a signed digital certificate and / or a signed digital system certificate, any of these certificates can also be appended to the signature of a transaction, such that the present technology also enables a user of the data processing device to provide an identification basis where needed or desired.

[0032] The data processing device can be obtainable, and preferably can be obtained by the method as discussed before.

[0033] The described technology, in particular the described method for initializing a data processing device, also allows to generate a data processing device with corresponding functionality, for example in case of loss of the data processing device. In particular, the private certificate key can again be wrapped in the same way and provided to another data processing device (i.e. by the public key) and decrypted in the same way. Thus, for example in case of loss of the data processing device, the unencrypted private certificate key and the seed derived from the unencrypted private certificate key can also be provided to another data processing device, thereby providing the respective functionality to the other data processing device. The respective considerations also apply to the digital system certificate, in case of provision of a new identity of the user, the digital system certificate can also be provided with most of the corresponding data. In summary, embodiments of the present technology thus also allow the implementation of a backup solution.

[0034] It will also be understood that the described technology allows to revoke the described certificates. That is, for example, in case of loss of the data processing device, an external entity generating one of the certificates can revoke the corresponding certificate, thereby increasing the security of the data processing device.

[0035] It will be understood that in some cases at least one of the certificates of the data processing device can also be output together with the signed signature. This allows to check whether the certificate is still valid.

[0036] Furthermore, as discussed, the unencrypted private certificate key only exists in the secure part of the data processing device and cannot be extracted from the secure part. Thus, the respective data processing device cannot be forged by the user either.

[0037] The data processing device can be configured to only allow signing of the data structure signed by the key derived from the seed by the unencrypted private certificate key.

[0038] The data processing device can be configured to only allow signing of the data structure signed by the key derived from the seed by the key.

[0039] The present invention also relates to a data processing device, wherein the data processing device comprises a secure part, wherein the secure part comprises a remote public key.

[0040] The data processing device can be initialized by the initialization method discussed above.

[0041] In all aspects, the secure part can comprise the remote public key.

[0042] The data processing device can be obtained by the combination method discussed above.

[0043] The remote public key can correspond to a remote private key stored in a remote signature system.

[0044] The data processing apparatus can further comprise signing the credential to trigger signing by the remote signing system.

[0045] In yet another aspect, the application relates to a method, wherein the method uses the data processing apparatus according to any of the preceding apparatus embodiments, the method comprising:

[0046] receiving, in the secure part, a signing request,

[0047] generating, in the secure part, at least one signature, and

[0048] outputting the at least one signature.

[0049] The method can use the data processing apparatus discussed above. Generating the at least one signature can comprise generating a signature signed using a private key derived from the seed and signing the signature using the unencrypted private certificate key, thereby generating a signature signed using the unencrypted private certificate key, and outputting the at least one signature can comprise outputting the signature signed using the private key derived from the seed and the signature signed using the unencrypted private certificate key.

[0050] The method can further comprise, in the secure part, signing the signature using the private key, thereby generating a signature signed using the private key, and outputting the signature signed using the private key together with the signature signed using the private key derived from the seed and the signature signed using the unencrypted private certificate key.

[0051] The method can use the data processing apparatus discussed previously, and the method can further comprise outputting the signed digital certificate together with the signature signed using the private key derived from the seed and the signature signed using the unencrypted private certificate key.

[0052] The method can use the data processing apparatus as discussed previously, and the method can further comprise outputting the signed digital system certificate together with the signature signed using the private key derived from the seed and the signature signed using the unencrypted private certificate key.

[0053] The method can further comprise the remote signing system receiving the signing request, the remote signing system signing the signing request using a remote private key corresponding to a remote public key, thereby generating a pre-signature, the secure part receiving the pre-signature, and in the secure part verifying that the pre-signature is the signing request signed using the remote private key using the remote public key, wherein in accordance with successfully verifying that the pre-signature is the signing request signed using the remote private key using the remote public key, generating the at least one signature in the secure part and outputting the at least one signature.

[0054] The method can further comprise the remote signing system receiving a signing credential, wherein the remote signing system signs the signing request using a remote private key corresponding to the remote public key, such that the pre-signature can be generated from the remote signing system receiving the signing credential.

[0055] The method can further comprise disabling the capability of the remote signing system to sign using the remote private key.

[0056] By using this technique, the signing functionality of the data processing device is linked to a remote signing system, which can be cloud-based. In particular, the signing functionality of the data processing device (e.g. a smart card) depends on the data processing device receiving a pre-signature (i.e. a signing request signed using a remote private key of the remote signing system). Only when the data processing device receives a pre-signature signed by the remote signing system, the data processing device signs the signing request.

[0057] This allows controlling the signing functionality of the data processing device by the signing functionality of the remote signing system. For example, in case of a loss of the data processing device, the respective remote private key in the remote signing system can be blocked, thereby blocking the signing functionality of the data processing device, which can increase the security against fraud, for example in case of a theft of the data processing device.

[0058] The application is also defined by the following numbered embodiments.

[0059] In the following, method embodiments will be discussed. These embodiments are abbreviated by a letter M followed by a number. Whenever a method embodiment is referred to in this text, those embodiments are meant.

[0060] M1. A method comprising:

[0061] providing a data processing device (50), wherein the data processing device (50) comprises a secure part (52), wherein the secure part (52) comprises a private key (13) that cannot be extracted from the secure part (52), wherein the secure part (52) comprises a public key (14) corresponding to the private key (13),

[0062] the data processing device providing a signing request (15), the public key (14) and a serial number (12),

[0063] based on the signing request (15), the public key (14) and the signing request (15), an external data processing device (60) generating a signed digital certificate (16), and

[0064] providing the signed digital certificate (16) to the data processing device (50).

[0065] M2. The method of the preceding embodiment, wherein the secure portion (11) comprises a random number generator (11) that cannot be extracted from the secure portion (52), wherein the method comprises: the random number generator (11) generating the serial number (12).

[0066] M3. The method of the preceding embodiment, wherein the private key (13) is generated based on output from the random number generator (11).

[0067] M4. The method of any one of the preceding embodiments, wherein the data processing device (50) is a smart card.

[0068] M5. The method of the preceding embodiment, wherein the smart card has near field communication functionality.

[0069] M6. The method of any one of the preceding embodiments, wherein the method comprises:

[0070] providing the signed digital certificate (16) to a data processing system (70),

[0071] the data processing system (70) receiving personal user data (82) from a user (80),

[0072] providing the public certificate key (34) to the data processing system (70),

[0073] the data processing system (70) generating a signed digital system certificate (36) signed using the public certificate key (34) based on the personal user data (82), the signed digital certificate (16), and the public certificate key (34),

[0074] providing the signed digital system certificate (36) to the data processing device (50).

[0075] M7. The method of the preceding embodiment, wherein the method comprises:

[0076] generating a public certificate key (34) and a corresponding private certificate key (33),

[0077] encrypting the private certificate key (33) using the public key (14), thereby generating a wrapped key (40), and

[0078] providing the wrapped key (40) to the secure portion (52) of the data processing device.

[0079] M8. The method of the preceding embodiment, wherein,

[0080] generating, by a data processing system (70), a public certificate key (34) and a corresponding private certificate key (33), encrypting the private certificate key (33) using the public key (14) thereby generating a wrapped key (40), and providing the wrapped key (40) to the secure part (52) of the data processing apparatus, and wherein the wrapped key (40) is provided from the data processing system (70) to the secure part (52) of the data processing apparatus (50). Figure 2a

[0081] M9. The method according to the penultimate implementation, wherein,

[0082] generating, by another data processing system (72), a public certificate key (34) and a corresponding private certificate key (33), encrypting the private certificate key (33) using the public key (14) thereby generating a wrapped key (40), and providing the wrapped key (40) to the secure part (52) of the data processing apparatus,

[0083] wherein the method further comprises providing the public key (14) from the data processing apparatus (50) to the other data processing system (72),

[0084] wherein providing the public certificate key (34) to the data processing system (70) comprises providing the public certificate key (34) from the other data processing system (72) to the data processing system (70).

[0085] [ Figure 2b ]

[0086] M10. The method according to any one of the three preceding implementations, wherein the method comprises:

[0087] decrypting, in the secure part (52), the wrapped key (40) using the private key (13) thereby obtaining the private certificate key (33).

[0088] M11. The method according to the preceding implementation, wherein the method comprises:

[0089] generating, in the secure part (52), a seed (21) based on the private certificate key (33).

[0090] In the following, initialization implementations will be discussed. These implementations are abbreviated by the letter I followed by a number. Whenever reference is made in this text to initialization implementations, those implementations are meant.

[0091] I1. An initialization method for initializing a data processing apparatus (50), the data processing apparatus (50) comprising a secure part (52), wherein the initialization method comprises:​

[0092] generating a remote asymmetric key pair (200, 202) comprising a remote private key (200) and a remote public key (202) in a remote signing system (20),

[0093] providing the remote public key (202) to a secure part (52) of the data processing device, and

[0094] generating a signing credential (220), wherein the remote signing system (20) is configured to sign the data structure upon receiving the signing credential (220).

[0095] I2. The initialization method according to the preceding implementation, wherein the signing credential (220) is generated by the remote signing system (20).

[0096] I3. The initialization method according to any of the two preceding implementations, further comprising providing the signing credential (220) to the data processing device (50), for example to the secure part (52) of the data processing device (50).

[0097] C1. A combined method, wherein the combined method comprises the method according to any of the preceding method implementations and the initialization method according to any of the preceding initialization implementations, wherein the data processing device (50) of the method is the data processing device (50) of the initialization method.

[0098] It will be appreciated that the secure part of the method is the secure part of the initialization method.

[0099] In the following, device implementations will be discussed. These implementations are abbreviated by a letter A followed by a number. Whenever a device implementation is referred to in this text, these implementations are meant.

[0100] A1. A data processing device (50) comprising a secure part (52),

[0101] wherein the secure part (52) comprises:

[0102] a private key (13),

[0103] an unencrypted private certificate key (33), and

[0104] a seed (21) generated based on the private certificate key (33),

[0105] wherein the private key (13), the unencrypted private certificate key (33), and the seed (21) cannot be extracted from the secure part (52).

[0106] A2. The data processing device (50) according to the preceding embodiment, wherein the data processing device (50) comprises a signed digital certificate (16).

[0107] A3. The data processing device (50) according to any one of the preceding device embodiments, wherein the security part (52) comprises a random number generator (11).

[0108] A4. The data processing device (50) according to any one of the preceding device embodiments, wherein the data processing device (50) is a smart card.

[0109] A5. The data processing device (50) according to the preceding embodiment, wherein the smart card has near field communication functionality.

[0110] A6. The data processing device (50) according to any one of the preceding embodiments with the features of embodiment A3, wherein the data processing device comprises a serial number (12) generated by the random number generator (11).

[0111] A7. The data processing device (50) according to any one of the preceding device embodiments, wherein the data processing device (50) comprises a signed digital system certificate (36), wherein the signed digital system certificate (36) is signed using a public certificate key (34) corresponding to a private certificate key (33), and wherein the signed digital system certificate (36) is based on personal user data (82), the signed digital certificate (16) and the public certificate key (34).

[0112] A8. The data processing device (50) according to any one of the preceding device embodiments, wherein the data processing device (50) is obtainable, and preferably the data processing device (50) is obtained by a method according to embodiment M11.

[0113] A9. The data processing device (50) according to any one of the preceding device embodiments, wherein the data processing device (50) is configured to only allow signing of a data structure signed by a key derived from a seed (21) by the unencrypted private certificate key (33).

[0114] A10. The data processing device (50) according to any one of the preceding device embodiments, wherein the data processing device (50) is configured to only allow signing of a data structure signed by a key derived from a seed (21) by the private key (13).

[0115] A11. A data processing device (50), wherein the data processing device (50) comprises a security part (52), wherein the security part (52) comprises a remote public key (202).

[0116] A12. The data processing device (50) according to the preceding embodiment, wherein the data processing device (50) is initialized by an initialization method according to any one of the preceding initialization embodiments.

[0117] A13. The data processing device (50) according to any one of embodiments Al to A10, wherein the security part (52) comprises a remote public key (202).

[0118] A14. The data processing device (50) according to the preceding embodiment, wherein the data processing device (50) is obtained by a combination method according to embodiment CI.

[0119] A15. The data processing device (50) according to any one of the four preceding embodiments, wherein the remote public key (202) corresponds to a remote private key (200) stored in the remote signing system (20).

[0120] A16. The data processing device (50) according to the preceding embodiment, wherein the data processing device (50) further comprises a signing credential (20) to trigger a signature by the remote signing system (20).

[0121] N1. A method, wherein the method uses a data processing device (50) according to any one of the preceding device embodiments, the method comprising:

[0122] receiving, by the security part (52), a signing request (100),

[0123] generating, in the security part (52), at least one signature (121, 133, 113, 250), and

[0124] outputting the at least one signature (121, 133, 113, 250).

[0125] N2. The method according to the preceding embodiment, wherein the method uses a data processing device (50) according to any one of the preceding device embodiments with the features of embodiment Al, wherein

[0126] generating the at least one signature (121, 133, 113, 250) comprises generating a signature (121) signed using a private key derived from the seed (21) and signing the signature (121) using the unencrypted private certificate key (33), thereby generating a signature (133) signed using the unencrypted private certificate key (33), and

[0127] Outputting the at least one signature (121, 133, 113, 250) comprises outputting the signature (121) signed using the private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key.

[0128] N3. The method according to the preceding implementation form, wherein the method further comprises:

[0129] In the security part (52), the signature (121) is signed using the private key (13), thereby generating a signature (113) signed using the private key (13),

[0130] The signature (113) signed using the private key (13) is outputted together with the signature (121) signed using the private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key.

[0131] N4. The method according to any one of the two preceding implementation forms, wherein the method uses a data processing device (50) according to any one of the preceding device implementation forms with the features of implementation form A2,

[0132] wherein the method further comprises outputting the signed digital certificate (16) together with the signature (121) signed using the private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key.

[0133] N5. The method according to any one of the three preceding implementation forms, wherein the method uses a data processing device (50) according to any one of the preceding device implementation forms with the features of implementation form A7,

[0134] wherein the method further comprises outputting the signed digital system certificate (36) together with the signature (121) signed using the private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key.

[0135] N6. The method according to any one of the five preceding implementation forms, wherein the method uses a data processing device according to any one of the preceding device implementation forms with the features of implementation form A11 or A13, wherein the method further comprises:

[0136] The remote signature system (20) receives a signing request (100),

[0137] The remote signature system (20) signs the signing request (100) using a remote private key (200) corresponding to the remote public key (202), thereby generating a pre-signature (210);

[0138] The security part (52) receives the pre-signature (210), and

[0139] The verification of the pre-signature (210) in the security part (52) that the pre-signature (210) is a signed request (100) signed using the remote private key (200) is using the remote public key (202),

[0140] wherein, according to the successful verification of the pre-signature (210) in the security part (52) that the pre-signature (210) is a signed request (100) signed using the remote private key (200) using the remote public key (202), at least one signature (121, 133, 113, 250) is generated in the security part (52) and the at least one signature (121, 133, 113, 250) is output.

[0141] N7. The method according to the preceding embodiment,

[0142] wherein the method further comprises receiving, by the remote signing system (20), a signing credential (220),

[0143] wherein, according to the reception of the signing credential (220) by the remote signing system (20), the remote signing system (20) signs the signed request (100) using the remote private key (200) corresponding to the remote public key (202), thereby generating the pre-signature (210).

[0144] N8. The method according to any one of the two preceding embodiments,

[0145] wherein the method further comprises disabling the ability of the remote signing system (20) to sign using the remote private key (200). BRIEF DESCRIPTION OF DRAWINGS

[0146] Embodiments of the present technology will now be described with reference to the accompanying drawings, and the embodiments should be understood to be illustrative of, rather than limiting of, the scope of the present technology.

[0147] Figure 1 A setting of a data processing apparatus according to an embodiment of the present technology is depicted;

[0148] Figure 2a An initialization of a data processing apparatus according to an embodiment of the present technology is depicted;

[0149] Figure 2b Another initialization of a data processing apparatus according to another embodiment of the present technology is depicted;

[0150] Figure 3 Steps of the initialization of an embodiment of the present technology are depicted in more detail;

[0151] Figure 4 A signing process according to an embodiment of the present technology is depicted;

[0152] Figure 5 a flowchart depicting the initialization of the data processing device corresponding to Figure 1 a flowchart of the setup of the corresponding data processing device;

[0153] Figure 6 a flowchart depicting the initialization of the data processing device corresponding to Figure 2a or Figure 2b and Figure 3 a flowchart of the initialization of the corresponding data processing device;

[0154] Figure 7 a flowchart depicting the signing process corresponding to Figure 5 a flowchart of the signing process corresponding to

[0155] Figure 8 a flowchart depicting another initialization of the data processing device according to an embodiment of the present technology (which can be used together with the initialization of the data processing device corresponding to Figure 2a / Figure 2b or independently of the initialization of the data processing device corresponding to Figure 2a / Figure 2b );

[0156] Figure 9 a flowchart depicting the signing process according to an embodiment of the present technology; and

[0157] Figure 10 a flowchart depicting another signing process according to an embodiment of the present technology. DETAILED DESCRIPTION

[0158] Figure 1 A data processing device 50 is depicted which can be implemented as a smart card (e.g. a smart card with near field communication (NFC) functionality). In the following, reference will also be made to the smart card 50, but the skilled person will understand that the data processing device 50 can also be implemented in a different way than a smart card, regardless of whether reference is made to a smart card or a data processing device. Before its initialization, the data processing device 50 can also be referred to as a raw or native data processing device 50.

[0159] The data processing device 50 comprises a secure part 52, which can also be referred to as a secure enclave 52. The secure part 52 can provide hardware and software protection for keeping the data in the secure part 52 secret. More specifically, the data processing device 50 (e.g. a smart card) can be programmed such that only defined data can leave the secure part 52, while other data cannot leave the secure part 52. The secure part 52 can comprise one or more secure microcontrollers and one or more secure memory components.

[0160] The secure part 52 comprises a random number generator 11 (and it should be understood that this term also includes a pseudo-random number generator).

[0161] In a first step S1 (see also Figure 5 ), a random number generator 11 generates a random serial number 12. Furthermore, in a step S2, a private key 13 and a public key 14 pair are generated in a secure part 52. The keys 13, 14 are asymmetric cryptographic keys. This can be based on the random number generated by the random number generator 11, and it should be understood that it does not matter whether step S2 is performed after step S1 or before step S1. The data processing device 50 is configured such that the private key 13 cannot be extracted from the secure part 52.

[0162] In a further step S3, the random serial number 12, the public key 14 and a signing request 15 are provided to an external data processing device 60, and in a step S4, the external data processing device 60 generates and signs a digital certificate 16, for example by using a root certificate.

[0163] The digital certificate 16 can be an X509 digital certificate and is signed by a root certificate of the external data processing device 60. The digital certificate 16 contains the serial number 12, the public key 14, and can also contain information about the type of the data processing device 50. The digital certificate 16 can provide functions related to digital signing and decryption on the card.

[0164] In a further step S5, the digital certificate 16 is provided to the data processing device 50. After this step, the serial number 12 of the data processing device 50 is unique and cannot be forged due to the digital certificate 16.

[0165] It should be understood that the steps S1 to S5 described in connection with Figure 1 typically involve a factory setting of the data processing device 50, for example a smart card 50.

[0166] As depicted in Figure 2a and Figure 6 , in a step T1, the identity of a user 80 can be verified by using a data processing system 70, which can also be referred to as a third party authentication system 70 or a third party authentication authority 70. It should be understood that the data processing system 70 typically comprises a processor and a memory storing data. During the identity verification process, the user can provide personal data 82 to the data processing system 70.

[0167] In a further step T2, the data processing system 70 generates a public certificate key 34 and a private certificate key 33 pair. It should be understood that these keys are normal asymmetric cryptographic keys, and that the specification of these keys as "certificate" keys should only distinguish them from the keys 13 and 14. It should thus be understood that the certificate keys 33, 34 are different from the keys 13, 14.

[0168] In step T3, the public certificate key 34 and the personal user data 82 are provided, in addition the signed digital certificate 16 (the latter from the data processing device 50) and based thereon the certificate signing request 90 is generated. In the depicted embodiment, this step T3 is performed in the data processing system 70. However, it is to be understood that this step T3 can also be performed outside the data processing system 70.

[0169] A further step T4 can be performed in the data processing system 70, wherein step T4 can comprise different sub-steps. In sub-step T4a, the authenticity of the digital certificate 16 can be verified. In sub-step T4b, a digital certificate 36 signed using the public certificate key 34 can be generated, which will be referred to as the digital system certificate 36 (just to distinguish its terminology from the digital certificate 16). The digital system certificate 36 can comprise the personal user data 82 (e.g. the name of the user, the passport ID of the user and / or the address of the user), the public certificate key 34 and the signed digital certificate 16. In sub-step T4c, the private certificate key 33 can be encrypted using the public key 14, thereby generating the wrapped (or encrypted) private certificate key 40 (in this respect, it is to be noted that the public key 14 is contained in the signed digital certificate 16 and thus also in the certificate signing request 90).

[0170] In step T5, the wrapped private certificate key 40 and the digital system certificate 36 are provided to the data processing device 50.

[0171] However, although in the depicted embodiment many functions performed by the data processing system 70 are described, it is to be understood that this is merely exemplary and that these functions and steps can also be performed by different systems. This is for example exemplarily depicted in Figure 2a the depicted embodiment of Figure 2b the depicted embodiment of Figure 2b the depicted embodiment of Figure 2a the depicted embodiment of Figure 2b the depicted embodiment of

[0172] In particular, the further data processing system 72 can generate the public certificate key 34 and the private certificate key 33 pair (i.e. step T2, see Figure 6), and the public certificate key 34 can be provided to the data processing system 70. In the data processing system 70, the public certificate key 34 is used to generate a certificate signing request 90 (step T3) and to generate a digital system certificate 36 signed using the public certificate key 34 (as previously discussed). Furthermore, the digital certificate key can then be provided to the data processing apparatus 50.

[0173] Furthermore, the public key 14 can be provided from the data processing apparatus 50 to an additional data processing system 72 (where it is to be understood that the public key 14 can be extracted from the secure portion 52 of the data processing apparatus 50). Furthermore, in the additional data processing system 72, the public key 14 can be used to wrap (i.e. encrypt) the private certificate key 33 (sub-step T4c), thereby generating a wrapped private certificate key 40, which can then be provided to the data processing apparatus (part of step T5).

[0174] Figure 3 An enlarged portion of the data processing apparatus 50 is depicted to further illustrate additional steps performed after the wrapped certificate key 40 is received by the processing apparatus 50. As depicted, the wrapped certificate key 40 is provided to the secure portion 52 of the data processing apparatus 50.

[0175] In step T6 performed in the secure portion 52, the wrapped certificate key 40 is decrypted by means of the private key 13, thereby deriving the unencrypted private certificate key 33, which cannot be extracted from the secure portion 52. In step T7 performed in the secure portion 52, based on the unencrypted private certificate key 33, the seed 21 is generated. For example, the function to derive the seed 21 from the unencrypted private certificate key 33 can be via a hard-coded secret inside the secure portion 52 of the data processing apparatus 50. For example, the seed 21 can be a BIP32 seed, and the seed 21 can be derived through a plurality of SHA256 and AES encryption algorithms.

[0176] Thus, after completion of step T7, the seed 21 is present in the secure portion 52 of the data processing apparatus 50.

[0177] Generally, it is to be understood that steps T1 to T7 can involve an initialization of the data processing apparatus. By means of the initialization, the data processing apparatus 50 can be equipped with additional functionality.

[0178] For example, the data processing apparatus 50 can be used as discussed in connection with Figure 4 and Figure 7

[0179] ​In step U1, a signing request 100 is provided to the data processing device 50, more specifically to the security part 52 of the data processing device 50. For example, the signing request 100 can be a signing request 100 related to a transaction on a blockchain network or a signing request related to a smart contract.

[0180] In step U2, the respective signing request is fulfilled, i.e. the respective signature 121 for the request is generated. The signature 121 is generated based on the signing request 100 and the private key derived from the seed 21, and it is understood that both the seed 21 and the private key derived from the seed 21 cannot be extracted from the security part 52.

[0181] In step U3, the signature 121 is also signed using the private certificate key 33 and thus a certificate signature 133 is generated, which is the signature 121 signed using the private certificate key 33.

[0182] In step U4, the signature 121 can also be signed using the private key 13 and thus a key signature 133 can be generated, which is the signature 121 signed using the private key 13.

[0183] The data processing device 50 can be configured (e.g. hard-coded) such that the private certificate key 33 and the private key 13 can only be used for signing data structures that have previously been signed by the key derived from the seed 21.

[0184] In step U5, the signature 121, the certificate signature 133 and the key signature 113, if present, can be output from the data processing device 50, e.g. these data can be broadcast and can be provided to e.g. a blockchain node to cause a blockchain transaction. However, it is understood that the present technology is not limited to a blockchain implementation, but can also be used in connection with e.g. a smart contract, a timestamp or compliance data.

[0185] It is understood that the seed 21 is generated based on the private certificate key 33 (see Figure 3 ). Thus, the signed transaction signature 121 can only be generated if the data processing device 50 has been initialized as described before (otherwise, the data processing device 50 would not have access to the seed 21). This also applies to the signed transaction signatures 133 and 113, as they are based on the signed transaction signature 121, which is based on the seed 21, which in turn is based on a proper initialization. For the signed transaction signature 133, the dependency on a correct initialization is also caused by the transaction signature 133 being signed by the private certificate key 33, which is also only present on the data processing device 50 after a successful initialization.

[0186] As discussed, the data processing apparatus 50 can be configured such that it can only sign digital signatures (e.g. generate signatures 121, 133 and 113) and not data structures that are different from digital signatures. Furthermore, the data processing apparatus 50 can also be configured such that the private certificate key 33 and the private key 13 can only be used to sign signatures that have already been signed by a key derived from the seed 21. By limiting the ability to sign data structures, the risk of forgery can be greatly reduced.

[0187] Furthermore, it will be appreciated that the data processing apparatus 50 can also output the signed digital certificate 16 and / or the digital system certificate 36 signed using the public key 34.

[0188] Further embodiments of the present technology will now be described with reference to Figure 8 and Figure 10 .

[0189] It will be appreciated that Figure 8 is an initialization process for initializing the data processing apparatus 50. It will also be appreciated that the initialization steps discussed in connection with Figure 8 may be additional initialization steps discussed in connection with Figure 2a or Figure 2b . That is, the skilled person will appreciate that in addition to the steps described with reference to Figure 2a and / or Figure 2b , the steps described with reference to Figure 8 may also be performed. However, the initialization steps discussed in connection with Figure 2a may also be performed independently of the steps described in connection with Figure 2b and Figure 8 .

[0190] Figure 9 and Figure 10 depict signing processes that can be performed using a data processing apparatus 50 initialized with the steps depicted in Figure 8 .

[0191] More specifically, Figure 10 depicts a signing process that generally corresponds to the signing processes discussed with reference to Figure 4 , but includes additional features. It will be appreciated that Figure 10 the signing processes depicted in Figure 10 are based on the signing processes discussed in with additional steps, as will be discussed below.

[0192] Figure 8 Again, a data processing apparatus 50 is depicted, which can be the data processing apparatus discussed previously, more specifically, Figure 8 Again, initialization steps of the data processing apparatus 50 are depicted. Furthermore, Figure 8A remote signing system 20 is also depicted. The remote signing system 20 generates a remote asymmetric key pair comprising a remote private key 200 and a remote public key 202. It should be understood that the term “remote” in the remote private key 200 and the remote public key 202 should not limit the properties of these keys, but rather distinguish these keys 200, 202 from other keys used in this specification. After generating these remote keys 200, 202, the remote public key 202 is transmitted from the remote signing system 20 to the data processing device 50, more specifically to the security part 52 of the data processing device 50.

[0193] Furthermore, a signing credential 220 corresponding to the remote keys 200, 202 is generated and also transmitted to e.g. the data processing device 50. For example, the signing credential can be stored in the security part 52 of the data processing device 50. However, it should be understood that this is merely exemplary and that the signing credential 220 can also not be present on the data processing device 50, but can e.g. be stored elsewhere.

[0194] In Figure 8 , it is depicted that the signing credential 220 and the remote public key 202 are transmitted to the data processing device 50 separately. However, it should be understood that this is merely exemplary and that the signing credential 220 and the remote public key 202 can also be transmitted simultaneously. Furthermore, it should be understood that the steps described with reference to Figure 8 also relate to the initialization, it should also be understood that the signing credential 220 and the remote public key 202 can also be transmitted simultaneously with the wrapped private certificate key 40 (if the initialization with Figure 2a and / or Figure 2b is used).

[0195] When the signing credential 220 is later provided to the remote signing system 20, the remote signing system 20 will sign a provided data structure (e.g. a transaction request).

[0196] It should be understood that the steps depicted in Figure 2a / Figure 2b and Figure 3 may also be performed in addition to the steps discussed in connection with Figure 8 (e.g. before, simultaneously with or after the steps in Figure 2a / Figure 2b and Figure 3 ), however, they can also be performed independently. If the steps depicted in Figure 2a / Figure 2b and Figure 3 are performed in addition to the steps discussed in connection with Figure 8The data processing apparatus 50 that has undergone the initialization process of combining the steps depicted in

[0197] In Figure 9 another embodiment for generating a signature is depicted in Figure 9 It will be understood that some of the steps of the embodiment depicted in Figure 4 correspond to the steps depicted in Figure 4 and Figure 9 corresponding reference signs are used in

[0198] More specifically, Figure 9 the signature generation of a data processing apparatus 50 that is initialized using an initialization process comprising the steps discussed in Figure 8 is depicted.

[0199] Thus, the data processing apparatus 50 has a secure part 52 and the remote public key 202 is stored in the secure part 52. Furthermore, the signing credential 220 is used in the signature generation depicted in Figure 9 The signing credential 220 can for example be stored in the secure part 52 of the data processing apparatus 50. However, it will be understood that this is optional.

[0200] As depicted in Figure 9 the signature process uses the signing request 100. The signing request 100 is provided to the remote signature system 20. Furthermore, the signing credential 220 is provided to the remote signature system 20. In the depicted embodiment, the signing credential 220 is provided to the remote signature system 20 from the secure part 52 of the data processing apparatus 50. However, it will be understood that this is merely exemplary and that the signing credential 220 can also be provided to the remote signature system 20 in a different way.

[0201] The remote signature system 20 comprises a remote private key 200. It will be understood that the term “remote” in the remote private key 200 is not to limit the properties of this private key 200 but to distinguish this private key 200 from other private keys used in this specification.

[0202] Upon receiving the correct signing credential 220, the remote signature system 20 generates a pre-signature 210 based on the signing request 100 and the remote private key 200, thereby generating a pre-signature 210 that is the signing request signed by the remote private key 200. It will thus be understood that the generation of the pre-signature 210 depends on the receipt of the correct signing credential 220.

[0203] Thus, the signing credential 220 instructs the remote signature system 20 to provide the pre-signature 210.

[0204] In the depicted embodiment, the signing credential 220 is provided from the data processing device 50 to the remote signing system 20. More specifically, the signing credential 220 is stored in the secure part 52 of the data processing device 50. However, it should be appreciated that this is merely exemplary and that the signing credential 220 can also be stored on e.g. another device and provided to the remote signing system 20 from such other device.

[0205] The pre-signature 210 is transmitted to the data processing device 50, more specifically to the secure part 52 of the data processing device 50. Further, the signing request 100 is also provided to the secure part 52 of the data processing device. For example, the signing request 100 can be transmitted from the remote signing system 10 to the secure part 52 of the data processing device 50. However, it should be appreciated that this is merely exemplary and that the signing request 100 can also be provided to the secure part 52 of the data processing device 50 in a different way.

[0206] The secure part 52 of the data processing device 50 comprises a remote public key 202 corresponding to the remote private key 200. By means of the remote public key 202, the data processing device 50 determines whether the pre-signature 210 is valid, i.e. whether the signing request 100 has been signed by the remote private key 200.

[0207] If this is the case, at least one signature 250 is generated based on the signing request 100 and a signing routine. For example, at least one signing key and / or seed, together denoted by reference sign 260, can be used to generate the at least one signature 250 in the secure part 52. The at least one signature 250 can be broadcasted and can be provided to e.g. a blockchain node 110 to cause a blockchain transaction. However, it should be appreciated that the present technology is not limited to a blockchain implementation, but can also be used in connection with e.g. a smart contract, a timestamp or compliance data.

[0208] Thus, the described embodiments in connection with Figure 8 and Figure 9 allow for different key management. By means of the described embodiments in connection with Figure 8 and Figure 9 the remote signing system 20 is also used for signing.

[0209] Thus, for example in case of loss of the data processing device 50, the remote signing system 20 can be used to lock the signing functionality of the data processing device 50. In other words, access to the remote signing system 20 can be suppressed or the remote key pair 200, 210 is used to securely lock the functionality of the data processing device 50. It should be appreciated that this allows for temporarily or permanently locking the functionality of the data processing device 50.

[0210] For example, in case the data processing device 50 initialized in the above-described manner is lost, the corresponding remote key pair 200, 210 can be inhibited at the remote signing system 20. Thus, the data processing device 50 can no longer be used.

[0211] Further, a new data processing device 50 can be set up and initialized in the same manner, in particular with the same seed 21, but with a new remote key pair 200, 210. Thus, a corresponding data processing device 50 can be set up and initialized.

[0212] In summary, the embodiment thus allows the data processing device 50 to be remotely activated, deactivated, for example temporarily blocked or explicitly blocked, and replaced without the need to replace the seed.

[0213] Figure 10 An embodiment of the signature generation corresponding to the signature generation depicted in Figure 9 is depicted. However, in this embodiment, more details of the signature routine are depicted.

[0214] That is, the embodiment in Figure 10 is a possible implementation of the embodiment discussed in Figure 9 where more details of the signature routine are discussed.

[0215] In particular, it is to be understood that until the point of determining the validity of the pre-signature 210, Figure 10 the process depicted in Figure 9 is the same as the process depicted in Figure 9 , so reference can be made to the description of up to this point.

[0216] Figure 4 If this is the case, i.e. when it is determined that the signing request 100 has been signed by the remote private key 200, the signing request 100 is subjected to the signature routine comprising the steps previously referred to in .

[0217] In other words, Figure 10 a combination of the embodiments of Figure 9 (up to the point of determining that the signing request 100 has been signed by the remote private key) and Figure 4 (from the start of providing the signing request 100 to the security provider) is depicted.

[0218] Thus, the advantages described above with reference to Figure 4 and Figure 9 can be combined. Whenever relative terms such as "approximately", "substantially" or "about" are used in this specification, such terms are also to be interpreted as including the exact term. That is, for example, "substantially straight" is to be interpreted as also including "(exactly) straight".

[0219] Whenever steps are recited in the above or in the claims below, it should be noted that the order in which the steps are recited is potentially incidental. That is, unless otherwise specified, the steps recited in the claims are potentially performed in any order. That is, when the literature states that steps A and B are performed, it is not necessarily meant that step A is performed before step B, but it is also possible that step A is performed at least partially concurrently with step B, or that step B is performed before step A. Furthermore, when step (X) is said to be performed before another step (Z), this does not mean that there are no steps between step (X) and step (Z). That is, step (X) before step (Z) encompasses the case where step (X) is performed directly before step (Z), but also the case where step (X) is performed before step (Z) preceded by one or more steps (Y1),.... The same considerations apply when terms like "after" or "before" are used.

[0220] While in the foregoing the preferred embodiments have been described with reference to the drawings, the skilled person will understand that these embodiments have been provided for illustrative purposes only and should in no way be construed as limiting the scope of the invention as defined by the claims.

[0221]

[0222]

[0223] Table: Reference signs used in the description

Claims

1. A data processing apparatus (50), comprising a security unit (52), wherein The security unit (52) includes: Private key (13), Unencrypted private certificate key (33), and The seed (21) generated based on the unencrypted private certificate key (33) The private key (13), the unencrypted private certificate key (33), and the seed (21) cannot be extracted from the security department (52). The data processing device (50) includes a signed digital system certificate (36), wherein the signed digital system certificate (36) is signed using a public certificate key (34) corresponding to the private certificate key (33), and wherein the signed digital system certificate (36) is based on personal user data (82), the signed digital certificate (16), and the public certificate key (34).

2. The data processing device (50) according to claim 1, wherein The data processing device (50) includes the signed digital certificate (16).

3. The data processing device (50) according to claim 1, wherein The security unit (52) includes a random number generator (11).

4. The data processing device (50) according to claim 3, wherein The data processing device includes a serial number (12) generated by the random number generator (11).

5. The data processing device (50) according to claim 1, wherein The data processing device (50) is a smart card, wherein the smart card has near-field communication functionality.

6. The data processing device (50) according to claim 1, wherein The data processing device (50) is configured to allow signing of data structures signed with a key derived from a seed (21) only with the unencrypted private certificate key (33).

7. The data processing device (50) according to claim 1, wherein The data processing device (50) is configured to allow signing of data structures signed with a key derived from a seed (21) only via the private key (13).

8. The data processing device (50) according to claim 1, wherein The security unit (52) includes a remote public key (202).

9. The data processing apparatus (50) according to any one of claims 1 to 8, wherein, The data processing device (50) can be obtained by a method comprising: A data processing apparatus (50) is provided, wherein the data processing apparatus (50) includes the security unit (52), wherein the security unit (52) includes a private key (13) that cannot be extracted from the security unit (52), and wherein the security unit (52) includes a public key (14) corresponding to the private key (13). The data processing device provides a signing request (15), the public key (14), and a serial number (12). Based on the signing request (15), the public key (14), and the signing request (15), the external data processing device (60) generates the signed digital certificate (16), and The signed digital certificate (16) is provided to the data processing device (50). The signed digital certificate (16) is provided to the data processing system (70). The data processing system (70) receives personal user data (82) from the user (80). The public certificate key (34) is provided to the data processing system (70). The data processing system (70) generates a signed digital system certificate (36) using the public certificate key (34) based on the personal user data (82), the signed digital certificate (16), and the public certificate key (34). providing the signed digital certificate (16) to the data processing device (50), generating the public certificate key (34) and the corresponding private certificate key (33), encrypting the private certificate key (33) using the public key (14), thereby generating a wrapped key (40), and providing the wrapped key (40) to a security part (52) of the data processing device, decrypting the wrapped key (40) using the private key (13) in the security part (52), thereby obtaining the private certificate key (33), generating the seed (21) in the security part (52) based on the private certificate key (33).

10. A method of using a data processing device (50), the data processing device (50) comprising a security part (52), wherein, the security part (52) comprising: a private key (13), an unencrypted private certificate key (33), and a seed (21) generated based on the unencrypted private certificate key (33), wherein the private key (13), the unencrypted private certificate key (33), and the seed (21) cannot be extracted from the security part (52), the method comprising: the security part (52) receiving a signing request (100), generating, in the security part (52), a signature (121) signed using a private key derived from the seed (21), and signing the signature (121) using the unencrypted private certificate key (33), thereby generating a signature (133) signed using the unencrypted private certificate key (33), outputting the signature (121) signed using a private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key (33).

11. The method of claim 10, wherein, the method further comprising: signing, in the security part (52), the signature (121) using the private key (13), thereby generating a signature (113) signed using the private key (13), outputting the signature (113) signed using the private key (13) together with the signature (121) signed using a private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key.

12. The method of claim 10, wherein, the data processing device (50) comprising a signed digital certificate (16), wherein the method further comprises outputting the signed digital certificate (16) together with the signature (121) signed using a private key derived from the seed (21) and the signature (133) signed using the unencrypted private certificate key.

13. The method according to claim 10, wherein the data processing device (50) comprising a signed digital system certificate (36), wherein the signed digital system certificate (36) is signed using a public certificate key (34) corresponding to the private certificate key (33), and wherein the signed digital system certificate (36) is based on personal user data (82), the signed digital certificate (16), and the public certificate key (34), wherein the method further comprises outputting the signed digital system certificate (36) together with a signature (121) signed using a private key derived from the seed (21) and a signature (133) signed using the unencrypted private certificate key.

14. The method according to any one of claims 10 to 13, wherein the secure part (52) of the data processing device (50) comprises a remote public key (202), wherein the method further comprises: the remote signing system (20) receives the signing request (100), the remote signing system (20) signs the signing request (100) using a remote private key (200) corresponding to the remote public key (202), thereby generating a pre-signature (210), the secure part (52) receives the pre-signature (210), and in the secure part (52), the pre-signature (210) is verified to be a signing request (100) signed using the remote private key (200) using the remote public key (202), wherein, in accordance with a successful verification of the pre-signature (210) to be a signing request (100) signed using the remote private key (200) using the remote public key (202), at least one signature (121, 133, 113, 250) is generated in the secure part (52) and outputted.

15. The method of claim 10, wherein, the data processing device (50) is the data processing device according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Storing blockchain private keys in a SIM card

    EP3474209A1

  • Secure Firmware Transaction Signing Platform Apparatuses, Methods and Systems

    US20180262341A1

  • A method and an apparatus for securely signing application data

    WO2014106181A2