Method for signing or decrypting data with a cryptographic key, as well as computer program product and device therefor

The method addresses non-deterministic key generation in PUF-based cryptographic systems by selecting multiple physical properties to generate keys, ensuring continuous encryption and decryption through automated key renewal, stabilizing signature verification and decryption.

DE102023108678B4Active Publication Date: 2026-01-29TRUSTNXT GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102023108678
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-04-05
Publication Date
2026-01-29
Estimated Expiration
2043-04-05

AI Technical Summary

Technical Problem

Existing cryptographic systems using physically unclonable functions (PUFs) face challenges due to unpredictable changes in hardware properties over time, leading to non-deterministic key generation and decryption failures during transitional periods, making key redistribution impractical and data decryption impossible.

Method used

A method that selects physical properties based on indicators to generate cryptographic keys, allowing for multiple keys from different property sets, ensuring at least one valid key remains even if one key becomes invalid, and automates key renewal based on time or state changes.

Benefits of technology

Ensures continuous data encryption and decryption by maintaining at least one valid key, even during hardware property changes, without manual user intervention, thus stabilizing signature verification and decryption processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Methods for signing and / or decrypting data (18) with a cryptographic key (20, 20a, 20b), comprising the steps: a) Receiving (40) a request (42) to generate at least one key (20, 20a, 20b) for signing or decrypting data (18), b) Recording (43) an indicator (34), c) Selecting (44) at least one physical property (30a, 30b, 30c, 30d) of at least one component (26a, 26b, 26c, 26d) of a device (10) depending on the indicator (34), d) Generating (46) at least one key (20, 20a, 20b) depending on the selected physical property (30a, 30b, 30c, 30d) and e) Signing (48) and / or decrypting the data (18) depending on the at least one key (20, 20a, 20b), wherein, depending on the indicator (34) in step c), a set (54a, 54b, 54c) with several, in particular two, physical properties (30a, 30b, 30c, 30d) is selected, wherein in step d) a key (20, 20a, 20b) is generated depending on each of the selected physical properties (30a, 30b, 30c, 30d), and in step e) the data (18) is signed and / or decrypted with each of the generated keys (20, 20a, 20b).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to signing and / or decrypting data with a cryptographic key. Furthermore, the invention relates to a device for signing and / or decrypting data with a cryptographic key and a computer program for executing the method on the device.

[0002] It is generally known from the state of the art to link data with a signature, namely a digital signature. With the signature, specifically an electronic or digital signature, a signatory or signature creator can be uniquely identified and the integrity of the signed data can be verified. For example, in asymmetric cryptographic methods, a sender or signatory creates a signature for the data to be signed using a private key. The signature is then added to the data. A recipient of the data and the signature can use a previously obtained public key of the sender to verify that the signature and the data originate from the sender.

[0003] Instead of or in addition to adding a signature, data can also be encrypted and decrypted using keys, especially cryptographic keys. For encryption, the aforementioned asymmetric cryptography method, also known as asymmetric encryption, can be used. This involves encrypting data with a recipient's public key, which the recipient can then decrypt with their private key.

[0004] Devices designed for signing or decryption typically store a key, especially a private key, in a memory that is often specially protected against unauthorized access. This ensures that a key, particularly the private key, cannot be used by unauthorized individuals to sign or decrypt data. However, protecting a memory against unauthorized access is very complex, and complete key protection is difficult to achieve. For this reason, it is desirable to avoid storing secret keys altogether whenever possible.

[0005] One method that eliminates the need to store secret keys is based on the use of so-called "physically unclonable functions," also known as PUFs. These PUFs are hardware structures within a semiconductor that serve to uniquely identify the semiconductor and, from this, secure keys for cryptographic methods. Thus, a PUF represents a unique, individual characteristic bound to a physical object, such as a device for signing or decrypting.

[0006] Specifically, the physical properties of a component, such as a semiconductor, are used to generate a secret key only when needed. For example, the charge decay curve of a capacitor is recorded, and starting values ​​for generating a complex key are extracted from the time course of the charge decay. Alternatively, the charge decay curve, converted into digital information such as a bit sequence, can itself be used as the key. The use of "physically unclonable functions" thus eliminates the need to store the key, as it can be deleted immediately after use for signing or decryption and regenerated at any time.

[0007] It is important to note that the states or physical properties of hardware structures typically change over time. Physical properties used, such as the activation state of a sensor for key generation, can therefore be altered by sensor aging or by cosmic radiation. A device that uses a pre-selected hardware structure or component to generate a key will, after a certain period of time, produce keys that differ from those originally generated with the same hardware structure or component. If such a deviation occurs, then, in the case of an asymmetric cryptography method, a private key generated by the hardware structure will change.Data that is to be decrypted or signed with a private key, but which was previously encrypted with a valid public key, or whose integrity is to be verified with a previously valid public key, can no longer be decrypted or signed for integrity verification with the changed private key. Therefore, it is necessary to distribute a public key that corresponds to the new private key.

[0008] Such a redistribution of keys is impractical, and data already encrypted with old public keys cannot be decrypted because an old private key cannot be reconstructed. Furthermore, the change in a physical property during a transition period may not occur deterministically. The switch between an old and a new key is difficult to predict, and a reversion from the new key to the old key may even occur during the transition period.

[0009] Accordingly, during a transition period in which a physical property of a component changes from an original or previous state to a modified state depending on external influences such as temperature, the same physical property of the component can lead to the generation of an original key at times and a modified key at other times. Unambiguous decryption or verification of the signature is then no longer possible. For a user, using the hardware structure to generate the key is therefore impractical or even impossible, especially during the transition period of the physical property of the hardware structure.

[0010] Documents EP 1 588 371 B1, US 9,082,514 B1, US 2001 / 0033012 A1 and DODDA, Akhil [et al.]: Graphene-based physically unclonable functions that are reconfigurable and resilient to machine learning attacks, in: Nature Electronics, Vol. 4, 2021, No. 5, pp. 364-374, DOI: 10.1038 / s41928-021-00569-x deal with physically uncopyable functions and their use for encryption. Document EP 1 588 371 B1 further discloses that a component, depending on whose physical properties are used for key generation, can be selected by addressing data, so that a component with stable physical properties can be chosen.

[0011] The invention is therefore based on the objective of addressing the problems of the prior art. In particular, a way is to be found to sign or decrypt data with a key generated from a PUF, taking into account a transitional state of the PUF, i.e., a changing physical property of a component. In any case, an alternative to what is known from the prior art is to be found.

[0012] The invention relates to a method for signing and / or decrypting data with a cryptographic key according to claim 1.

[0013] Accordingly, the invention relates to a method for signing and / or decrypting data using a cryptographic key. A cryptographic key corresponds, for example, to a bit sequence, preferably of a predefined length.

[0014] According to the invention, the method initially comprises receiving a request to generate at least one cryptographic key for signing or decrypting data. A request can, for example, be generated automatically within a device. An example of such a request is the start of an application intended to decrypt data. Another request can be the general start-up, i.e., the booting up or startup, of a device capable of signing or decrypting data. A request can also be received from a user interface. The receipt of a request can therefore be considered a trigger to initiate a signing or decryption process.

[0015] In the next step, an indicator is captured. This indicator might include, for example, data read from a storage location, data generated within the device, or data received from a user interface. A physical property is then selected based on this indicator.

[0016] A physical property is associated with at least one component of a device. Therefore, a physical property of at least one component is selected. The physical property describes, for example, a measurable physical behavior of the component or of several components that exhibit this physical property together, preferably under predefined conditions.

[0017] A physical property of at least one component includes, for example, the discharge curve of a capacitor over time. The predefined conditions can, for example, correspond to a predefined state of charge of the capacitor, from which the charging curve is measured. Furthermore, a physical property can include any other time behavior of a component. In the case of several first components, for example, different resistors, the physical property can correspond to the resistance values ​​of each resistor or to a mathematical combination of the resistance values. Preferably, a physical property of at least one component corresponds to a "physically unclonable function".

[0018] A special feature is that the physical property is selected depending on the indicator. Preferably, several physical properties are predefined, and one or more of these predefined properties are selected for the subsequent procedure depending on the indicator.

[0019] Subsequently, in a further step, at least one key is generated depending on the at least one physical property, and then data is signed and / or decrypted depending on the at least one key.

[0020] By selecting the physical property depending on the indicator, it becomes possible to provide several different physical properties for generating a key and to select these depending on the indicator. This allows, for example, if it is determined that a physical property, preferably a PUF (Power Function Key), has changed and thus a key generated from it differs from the previously generated key, a different physical property can be selected simply by changing the indicator.

[0021] For example, after receiving a request to generate a key, the device can provide a reference file and sign it with the generated key. A previously stored public key can then be used to verify the signature's validity. If the signature is invalid, this indicates that the key used for signing no longer matches the previously generated key. The indicator can then be modified, for instance, to select a different physical property and avoid non-deterministic behavior during key generation.

[0022] According to a first embodiment, a set of several, in particular more than two or exactly two, physical properties of one or more components is selected depending on the indicator. The set therefore preferably corresponds to one of several predefined sets. Each of the sets comprises several physical properties, which are also preferably predefined for the respective set.

[0023] Preferably, several physical properties are selected, each assigned to at least one component. The components assigned to one physical property are preferably not assigned to any other physical property. Furthermore, at least one key is generated depending on each of the selected physical properties. The data is then signed and / or decrypted using each of the generated keys.

[0024] For example, according to the last-mentioned embodiment, a set is selected depending on the indicator. This set, based on its physical properties corresponding to the discharge curve of a component, generates a key depending on the two discharge curves. The file is then signed and / or decrypted using both keys. If one of the keys fails or is invalid because one of the underlying physical properties has changed, the physical property of the other component is, with sufficient probability, stable. The second key thus remains valid, and a signature can then be verified using a corresponding public key.

[0025] Decryption with at least one of the generated keys is therefore successful. A recipient of the data can thus still verify the signature with the other key or decrypt the data even if one key fails. The probability of a complete failure increases accordingly with the number of selected physical properties in a set.

[0026] When an invalid key or a key that fails is mentioned here and in the following, this refers to a key that is generated from a physical property of a component, but differs from a key previously generated with the physical property of the component due to a change in the state of the physical property.

[0027] Even if a key fails or becomes invalid, i.e., if a physical property of a component changes, data can still be encrypted, decrypted, or signed at any time.

[0028] According to a specific embodiment of the embodiment described above, at least two physical properties are selected in step c). A first physical property of the two physical properties corresponds to a physical property of at least one first component. A second physical property of the two physical properties corresponds to a physical property of at least one second component that differs from the first component.

[0029] According to a further embodiment, at least three physical properties are selected in step c). A first physical property of the three physical properties corresponds to a physical property of at least one first component and one second component. A second physical property of the three physical properties corresponds to a physical property of at least the second and one third component. A third physical property of the three physical properties corresponds to a physical property of at least the third and one first component.

[0030] Each of the three keys is therefore based on the physical properties of at least two components.

[0031] A change in the behavior of a component therefore leads to the failure of two keys. However, this is accepted in order to enable a comparatively higher bit depth for the keys—that is, the number of bits in each key—with a relatively small number of components. A device that, for example, provides only a small number of components for key generation can thus be used to generate the longest possible keys. By using three physical properties and therefore three keys, the failure of one component—that is, a change in its physical properties—still has no effect on at least one of the keys. This one of the three keys remains valid.

[0032] According to a further embodiment, the indicator displays a selectable set from several sets. The sets are preferably predefined. Each set comprises several physical properties. The physical properties of each set are preferably also predefined. At least one physical property of each selectable set differs from a physical property of another set. Thus, for example, if a first set comprises the physical properties A, B, and C, another set comprises the physical properties B, C, and D. Yet another set comprises the physical properties C, D, and E.

[0033] This ensures that if a key fails (i.e., becomes invalid) and is associated with a record via a physical property, a previous record can be replaced by selecting a different record that does not contain the physical property for generating the failed key. By adjusting the indicator, a complete record with associated valid keys can be obtained again.

[0034] Selecting a new set of physical properties expands the group of properties to include previously unused physical properties. No two sets of physical properties are identical.

[0035] According to another embodiment, the sets of physical properties are arranged in a sequence. One or more sets following a previous set each comprise at least one physical property identical to the previous set. Thus, as long as a state of the physical property remains unchanged, an identical physical property leads to the generation of an identical key. For example, a first set of sets comprises physical property A and physical property B, a second set following the first comprises physical property B and physical property C. A further second set following the first comprises, for example, physical property A and physical property C. A third set following the second comprises physical property C and physical property D.

[0036] By defining the sequence, it is possible to select a subsequent set with the indicator, in which all keys can again be considered valid. Furthermore, backward compatibility is enabled for data that would otherwise require decryption with an invalidated key, since the following set includes at least one physical property that generates a previously valid key. The new set thus generates at least one key to decrypt data that would otherwise require decryption with the keys of a preceding set. For example, if key A from the first set becomes invalid, the system can switch to the second set. In this example, the second set contains keys B and C. If key B were to fail in the first set, the system would switch to the second set, which contains keys A and C.

[0037] According to a further embodiment, a state or a time value is monitored and recorded. A time value includes, for example, a point in time, in particular a date or a duration. A state can be the monitoring of the physical properties of a currently valid set. A state can also correspond to the decay of atoms or a gas discharge. Monitoring a state can, for example, correspond to a measurement by a Geiger counter integrated into the device, which monitors the decay of atoms under consideration in a component whose physical property is being monitored. The Geiger counter can also be used to measure, i.e., monitor, cosmic radiation.

[0038] According to this implementation, if a stored or storable criterion comparable to the time or state remains unfulfilled, a previous value of the indicator is retained. The indicator therefore remains constant in each iteration of the process. The same set of physical properties is executed when repeating the steps according to the invention after receiving a request to generate at least one key, up to and including signing or decrypting the file.

[0039] This means that an identical set or the same physical properties are always selected. This is done according to this embodiment until the criterion is met. In the event that the criterion is met, the indicator, preferably its value, is changed. This selects a set that differs from the previously selected set. Preferably, a set is selected that corresponds to a set following the previously selected set in a sequence of sets.

[0040] A criterion can be an expiry point, such as an expiry date, reaching a certain duration, the detection of a changing physical property by the device, or the detection that the device has been exposed to a certain amount of cosmic radiation.

[0041] An automatic change of the rates depending on the indicator thus occurs depending on time or a state and a criterion.

[0042] Another possible state is the verification of the signature, which, as mentioned above, is performed using the signed reference file and the publicly stored key. The criterion is then the validity or invalidity of the signature.

[0043] A comparison of the state or time value with a criterion thus describes the device's independent recognition that a new key needs to be generated. This recognition can be achieved by detecting changes in hardware structures, i.e., the physical properties of the device, for example, through measured values ​​and reaching tolerance limits.

[0044] According to the embodiment, it is therefore possible to automate the renewal of keys depending on events or time, without a user of a device having to take care to renew the keys in a timely manner.

[0045] According to a further embodiment, several criteria are stored, and after each criterion is met by the state or time, a set with the indicator is selected that differs from one or all of the sets selected before the respective criterion was met. The indicator is thus preferably changed to a value it has not yet assumed. Differing sets correspond to sets with at least one different physical property.

[0046] This allows for a continuous renewal of the keys, excluding sets that have already been used.

[0047] According to a particular embodiment, a control instance is provided that detects a change in a physical property. This can occur, for example, when the device's own public key, which may be stored within the device, changes. This applies if the device's public key is generated based on its own private key, which in turn is generated based on the physical property. A comparison of a stored and a newly generated public key then reveals the change in the physical property. Preferably, the control instance can then adjust the indicator or check whether a changed physical property is stable enough to continue being used to generate a key without changing the indicator.

[0048] According to another embodiment, after detecting a change in a physical property, the control instance outputs at least one new public key, which is generated depending either on the changed physical property with the same indicator or on another physical property selected by a changed indicator.

[0049] According to a further embodiment, the indicator and / or the criterion changes with each iteration of the steps according to the invention, from receiving a request to generate at least one key to signing and / or decrypting the data, depending on the at least one key. Particularly in the case where sentences have a sequence and successive sentences each contain one identical physical property and one modified physical property, a sequence of the encrypted or signed data can thus be identified.

[0050] For example, if a first set contains the physical properties A and B, a second set the physical properties B and C, and a third set the physical properties C and D, then the files are signed with the first set, i.e., with keys derived from physical properties A and B, when the process is executed for the first time. On subsequent runs, the data is signed with the second set, i.e., with the keys generated from physical properties B and C. This process continues, so that a recipient of the data from one run can only decrypt that data if they also received the data from the previous run.

[0051] According to another embodiment, the indicator corresponds to a command or instruction, preferably received from a user interface. The at least one physical property is thus selected depending on the command or instruction. In particular, a set of physical properties dependent on the command or instruction is selected. Preferably, the command or instruction selects a set of physical properties that corresponds to one of several predefined sets of physical properties.

[0052] Accordingly, a user can select a set of predefined physical properties using an internal monitoring control of the device, which, for example, monitors the state of the physical properties, or another application, by means of a command or instruction. Preferably, the sets are predefined and made available for selection. This eliminates the need for the user to select physical properties manually. In the event of an invalid key, the user or an application can select a different set by specifying a command or instruction that allows the generation of valid keys for a new period.

[0053] According to another embodiment, the indicator includes a password or is selected depending on a password. The password is, for example, a string of characters or corresponds to biometric data. A password consisting of biometric data is also called a biometric password and can correspond to a fingerprint or the like. Depending on the password, one of several sets, which in particular correspond to predefined sets, is selected. The several sets preferably each comprise several physical properties, each of which can be used to generate an electronic key.

[0054] Alternatively, depending on the password, at least one physical property can be predefined and selected after predefinition. The password itself thus serves to specify the indicator so that it contains information about which physical properties should be used to generate one or more keys. According to another alternative, at least one of several predefined physical properties is selected depending on the password.

[0055] Accordingly, multiple passwords can be specified, which themselves do not serve to generate the electronic key. Rather, each password is directly assigned to one of several sets of physical properties or physical characteristics. By entering a password, for example by a user, the user, protected by the password, selects a physical property linked to this password using the indicator in order to generate the electronic key.

[0056] This makes key generation even more secure.

[0057] According to a further embodiment, the at least one key generated depending on the at least one physical property comprises one or more key pairs of an asymmetric encryption method. Accordingly, the data is signed depending on the asymmetric key pair such that a hash of the file to be signed is first generated and this hash is then signed with each of the private keys of the generated key pairs. The results of the signing, namely the signature and preferably also the respective public key of the key pairs, are represented in the data metadata. Alternatively, only the result of the signing, i.e., the encrypted or signed hash, can be represented as the signature, with the public keys being transmitted separately.

[0058] This allows for the simple signing and transfer of signed data using a single file containing metadata. The method is therefore preferably used for signing media such as images.

[0059] According to a further embodiment, at least one of the public keys of a key pair is signed with at least one private key of another key pair before being stored in the metadata of the data, in particular a media file such as an image. The private key of the other key pair is preferably a private key of a key that can be generated identically from a current set and a set different from the current set. The set different from the current set is preferably a set that precedes it in the sequence.

[0060] Therefore, if a new public key is generated by or depending on a new set of physical properties, this new public key is first signed with the previous private key. This prevents, or at least counteracts, the inclusion of public keys in the metadata that do not originate from the actual user who signed the file.

[0061] According to another embodiment, a plurality of physical properties is selected depending on the indicator, wherein a plurality comprises, for example, at least 10, at least 20, or at least 50 physical properties. Correspondingly, a plurality of keys is generated from the physical properties.

[0062] The state then represents the proportion or number of valid and invalid keys. Furthermore, a criterion is met if a predefined proportion of the set of keys is identified as invalid. Otherwise, the criterion remains unmet. Once the criterion is met, a new indicator is provided, which is used to select a new set of physical properties. The predefined proportion might correspond, for example, to a percentage of 5%, 10%, or 20%.

[0063] Accordingly, data is signed or decrypted using the multitude of keys generated from the multitude of physical properties until a check within the device detects that a predefined proportion of these keys has become invalid. Only after this predefined proportion is exceeded does the indicator select a new multitude of physical properties, so that from that point on, data is signed or decrypted using a multitude of new keys that are considered valid.

[0064] Furthermore, the invention relates to a computer program product comprising instructions which, when executed on a processor of a computing unit, cause the processor to execute the method according to one of the aforementioned embodiments. A computing unit is preferably a device or part of a device, wherein the device corresponds, for example, to a computer, a tablet, a mobile phone, or the like.

[0065] Furthermore, the invention comprises a device for signing or decrypting data with a cryptographic key. The device is configured to execute a method according to one of the aforementioned embodiments. The device is preferably a mobile device, such as a laptop, mobile phone, or tablet. Alternatively, the device can also correspond to any stationary computer.

[0066] The device preferably comprises a plurality of components, namely electronic components, such as hardware structures, which can be analog or digital structures. According to a particular embodiment, the device itself can be an analog structure configured to execute the method.

[0067] Further embodiments are shown in the exemplary embodiments explained in more detail in the figures. These show: Fig. 1 a device according to an exemplary embodiment for carrying out the method, Fig. 2 steps of an exemplary implementation of the method, Fig. 3 steps of a preferred embodiment of the method, Fig. 4 another embodiment of a selection step, Fig. 5 a second embodiment of a step for detecting an indicator, Fig. 6 a third embodiment of a step for detecting an indicator and Fig. 7 a fourth embodiment of a step for detecting an indicator.

[0068] Fig. Figure 1 shows a device 10 for signing and / or decrypting data with a cryptographic key. For this purpose, the device includes a memory 12 in which, for example, data to be signed is stored. This data can, for example, correspond to media data, such as image data, originating from an image sensor of a camera.

[0069] Furthermore, the device 10 comprises a microcontroller unit 14, which includes, for example, a processor and other modules required for data processing. A crypto module 16 is provided in the microcontroller unit 14 to sign data 18 received from the memory 12, depending on a key 20. After signing by the device 10, the data 18 can be output at an interface 22 with the signature 23. Encrypted data can also be received via the interface 22 and fed to the crypto module 16 for decryption using the key 20.

[0070] The key 20 is determined by a key generator 24 depending on a physical property of one or more components 26a, 26b, 26c, 26d of the device 10. Accordingly, the device 10 comprises the multiple components 26a, 26b, 26c, 26d. The components 26a, 26b, 26c, 26d correspond, for example, to sensors, further memory modules, digital hardware structures or circuits, as well as analog electrical components.

[0071] For example, the microcontroller unit 14 can send a trigger signal 28 to one or more of the components 26a, 26b, 26c, 26d, so that each of the components 26a, 26b, 26c, 26d, or at least one or more selected components 26a, 26b, 26c, 26d, sends a signal, which is in particular an analog signal. The signal indicates a physical property 30a, 30b, 30c, 30d of the respective component 26a, 26b, 26c, 26d. Depending on the physical property 30a, 30b, 30c, 30d supplied to the key generator 24, the key 20 can be determined.

[0072] Furthermore, a decision-maker 32 is provided which receives an indicator 34 with which one or more of the received physical properties 30a, 30b, 30c, 30d are selected and, after selection, fed to the key generator 24.

[0073] Fig. Figure 2 shows steps according to an embodiment of the method described in Fig. The process is executable using the device 10 shown in Figure 1. In step 40, a request 42 to generate at least one key 20 for signing or decrypting data 18 is received. In step 43, an indicator 34 is then detected. Furthermore, in step 44, at least one physical property 30a, 30b, 30c, 30d of at least one component 26a, 26b, 26c, 26d of the device 10 is selected depending on the indicator 34. In step 46, at least one key 20 is then generated depending on the at least one selected physical property 30a, 30b, 30c, 30d, and in step 48, the data 18 is signed depending on the at least one key 20.

[0074] Fig. Figure 3 shows a special embodiment of steps 44, 46, 48 from Fig. 2. According to this embodiment, in step 44 two physical properties 30a, 30b are selected depending on the indicator 34. Depending on the selected physical properties 30a, 30b, in step 46 two keys 20a, 20b are generated, and in step 48 the data 18 is signed with both keys 20a, 20b. Thus, step 48 outputs a signed file 50, which contains the data 18 itself and, in metadata 21, a first signature 52a and a second signature 52b. The first signature 52a was generated with the first key 20a, and the second signature 52b was generated with the second key 20b.

[0075] Fig. Figure 4 shows another embodiment of selection step 44, in which the physical properties 30a, 30b, 30c, 30d are assigned to several sets 54a, 54b, 54c. Depending on the indicator 34, one of the sets 54a, 54b, 54c is selected and output for step 46. Step 46, which is not shown here, generates a key 20a, 20b for decrypting or signing the data 18, depending on the physical properties 30a, 30b, 30c, 30d of the selected set 54a, 54b, 54c.

[0076] Sentences 54a, 54b, and 54c, for example, are assigned to a sequence 56, where sentence 54a corresponds to the preceding sentence 58, sentence 54b to the subsequent sentence 60, and sentence 54c to a further subsequent sentence 62. Indicator 34, for example, can take the values ​​"1", "2", or "3" in this case. If indicator 34 takes the value "1", the preceding sentence 58 is selected. If the indicator takes the value "2", the subsequent sentence 60 is selected, and if the indicator takes the value "3", the further subsequent sentence 62 is selected.

[0077] Fig. Figure 5 shows an embodiment in which the indicator 34 is detected in step 43 by receiving a value, for example value “1”, “2” or “3”, from a user interface 64 as a command 65 of the device 10.

[0078] In Fig. Figure 6 shows an alternative method for acquiring indicator 34 according to a further embodiment. Here, in step 43, a state 66 or a time value 68 is compared with a criterion 70 in a sub-step 72 to acquire the indicator. Indicator 34 has a starting value 74, which, for example, corresponds to the value "1" and is read from a memory 75. This starting value 74 is output as indicator 34 by a selection step 77 as long as criterion 70 is recognized as not fulfilled in sub-step 72. If criterion 70 is fulfilled, indicator 34 is incremented or adjusted in the selection step and output as a new indicator 34. The new indicator 34 is again stored as the starting value 74.

[0079] After the increase, indicator 34, for example, assumes the value "2", so that from this point on, indicator 34 has the value "2". Preferably, after a change to indicator 34, all previously selected indicators 34 are saved, so that, for example, indicators 34 cannot assume a value corresponding to a previous value after each iteration of the procedure. Therefore, indicators 34 used before criteria 70 are met are preferably not reused.

[0080] Fig.Figure 7 shows, according to a further embodiment, the selection of one or more physical properties 30a, 30b, 30c, 30d depending on an indicator 34, which is generated depending on a password 76. In this alternative embodiment of step 43, the password 76 is supplied to a decoder 78, and depending on the output of the decoder 78, in selection step 77, an indicator 34 corresponding to the result of the decoding is selected for the selection of one or more corresponding sets 54a, 54b, 54c of physical properties 30a, 30b, 30c, 30d in order to generate one or more keys 20a, 20b from them. Reference symbol list 10 Device 12 storage locations 14 microcontroller unit 16 Crypto module 18 data 20 keys 20a first key 20b second key 21 Metadata 22 Interface 23 Signatur 24 Key Generator 26a Component 26b Component 26c component 26d component 28 Trigger signal 30a physical property 30b physical property 30c physical property 30d physical property 32 decision-makers 34 Indicator 40 Received Request 42 Request 43 Capture indicator 44 Selecting at least one physical property 46 Generating keys 48 Signing Data 50 signed files 52a first signature 52b second signature 54a sentence 54b sentence 54c sentence 56 order 58 previous sentence 60 subsequent set 62 further subsequent sentence 64 User interface 65 Command 66 condition 68 Time indication 70 Criterion 72. Compare event or time reference with criterion 74 Starting value 75 memory 76 Password 77 Selection step 78 decoders

Claims

[1] Method for signing and / or decrypting data (18) with a cryptographic key (20, 20a, 20b), comprising the steps: a) Receiving (40) a request (42) to generate at least one key (20, 20a, 20b) for signing or decrypting data (18), b) Recording (43) an indicator (34), c) Selecting (44) at least one physical property (30a, 30b, 30c, 30d) of at least one component (26a, 26b, 26c, 26d) of a device (10) depending on the indicator (34), d) Generating (46) at least one key (20, 20a, 20b) depending on the selected physical property (30a, 30b, 30c, 30d) and e) Signing (48) and / or decrypting the data (18) depending on the at least one key (20, 20a, 20b), wherein, depending on the indicator (34) in step c), a set (54a, 54b, 54c) with several, in particular two, physical properties (30a, 30b, 30c, 30d) is selected, wherein in step d) a key (20, 20a, 20b) is generated depending on each of the selected physical properties (30a, 30b, 30c, 30d), and in step e) the data (18) is signed and / or decrypted with each of the generated keys (20, 20a, 20b). [2] Method according to claim 1, wherein in step c) at least three physical properties (30a, 30b, 30c, 30d) are selected, wherein a first physical property (30a, 30b, 30c, 30d) of the three physical properties (30a, 30b, 30c, 30d) corresponds to a physical property (30a, 30b, 30c, 30d) of at least one first component (26a, 26b, 26c, 26d) and a second component (26a, 26b, 26c, 26d), and a second physical property (30a, 30b, 30c, 30d) of the three physical properties (30a, 30b, 30c, 30d) corresponds to at least one physical property (30a, 30b, 30c, 30d). of the second and a third component (26a, 26b, 26c, 26d) corresponds and a third physical property (30a, 30b, 30c, 30d) of the three physical properties (30a, 30b, 30c, 30d) corresponds to a physical property (30a, 30b, 30c, 30d) of at least the third and the first component (26a, 26b, 26c, 26d). [3] Method according to claim 1 or 2, wherein the indicator (34) indicates a selectable set of several, in particular predefined, sets (54a, 54b, 54c), each comprising several, in particular predefined, physical properties (30a, 30b, 30c, 30d), wherein at least one physical property (30a, 30b, 30c, 30d) of each set (54a, 54b, 54c) differs from a physical property (30a, 30b, 30c, 30d) of each other set (54a, 54b, 54c). [4] Method according to claim 3, wherein the sets (54a, 54b, 54c) of physical properties (30a, 30b, 30c, 30d) have a sequence (56) and in the sequence (56) one or more sets (54a, 54b, 54c) following a previous set (54a, 54b, 54c) each comprise at least one physical property (30a, 30b, 30c, 30d) identical to the previous set (54a, 54b, 54c). [5] Method according to any of the preceding claims, wherein a state (66) or a time reference (68), comprising a point in time, in particular a date, or a duration of time, is monitored or recorded, wherein In the event that a stored or storeable criterion (70) comparable to the time specification (68) or the state (66), in particular an expiry date (70) or an expiry period, remains unfulfilled, an indicator for recording is specified which remains constant and is selected with the same set (54a, 54b, 54c) when repeating steps a) to e), and wherein In the event that criterion (70) is met, an indicator for detection is specified which is modified from the constant indicator and with which a set (54a, 54b, 54c) that differs from the previously selected set (54a, 54b, 54c), preferably a set (54a, 54b, 54c) that follows in the sequence of sets (54a, 54b, 54c), is selected in step c). [6] Method according to claim 5, wherein several criteria (70) are stored and, after each of the criteria (70) is met by the state or the time specification, a set (54a, 54b, 54c) is selected which differs from one or all of the sets (54a, 54b, 54c) that were selected before the respective criterion (70) was met. [7] Method according to any of the preceding claims, wherein the indicator (34) and / or the criterion (70) changes with each iteration of steps a) to e). [8] Method according to any of the preceding claims, wherein the indicator (34) comprises a command or an instruction (65) to select in step c) at least one property (30a, 30b, 30c, 30d) or set (54a, 54b, 54c) of physical properties (30a, 30b, 30c, 30d), in particular several predefined sets (54a, 54b, 54c) of physical properties (30a, 30b, 30c, 30d), dependent on the command or instruction (65). [9] Method according to one of the preceding claims, wherein the indicator (34) comprises a password (76), in particular a string or biometric data, or is generated depending on a password and depending on the password (76) one of several sets (54a, 54b, 54c), which in particular correspond to predefined sets (54a, 54b, 54c), is selected or depending on the password (76) at least one physical property (30a, 30b, 30c, 30d) is predefined and / or selected. [10] Method according to one of the preceding claims, wherein the at least one key comprises at least one key pair of an asymmetric encryption method and in step e) a hash of the data to be signed is signed with the private key or each of the generated key pairs, wherein the results of the signing and preferably the respective public key of the key pairs are represented as signatures in metadata of the data. [11] Method according to claim 10, wherein at least one or all of the public keys of a key pair in the metadata are additionally signed with at least one private key of a further key pair and are stored in the metadata after signing, wherein the private key of the further key pair is preferably a private key of a key that can be generated identically from a current set and a set different from the current set, in particular a set preceding in sequence. [12] Method according to one of the preceding claims, wherein in step c) a plurality of physical properties (30a, 30b, 30c, 30d) and in step e) a plurality of keys are generated from the physical properties (30a, 30b, 30c, 30d), wherein a state represents a monitoring of the validity and invalidity of the keys and wherein a criterion (70) is satisfied if a predefined proportion of the plurality of keys is recognized as invalid and the criterion (79) otherwise remains unfulfilled. [13] Computer program product comprising instructions which, when executed on a processor of a computer unit, cause the processor to execute the method according to any one of claims 1 to 12. [14] Device (10) for signing and / or decrypting data with a cryptographic key, wherein the device is configured to perform a method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Tamper-resistant packaging and approach using magnetically-set data

    EP1588371B1

  • Anti tamper encapsulation for an integrated circuit

    US20010033012A1

  • Method and apparatus for physically unclonable function burn-in

    US9082514B1