×

Methods for secure enrollment and backup of personal identity credentials into electronic devices

  • US 20040139329A1
  • Filed: 08/06/2003
  • Published: 07/15/2004
  • Est. Priority Date: 08/06/2002
  • Status: Active Grant
First Claim
Patent Images

1. A process for enrolling at least one personal identity credential into a personal identification device, wherein access to a personal identity credential is controlled by use of a biometric, comprising:

  • a. producing a personal identification device, wherein a manufacturer maintains a database of a unique identifier and a unique public key for each personal identification device that it produces;

    b. distributing a public key possessed by said manufacturer to the personal identification device;

    c. creating an asymmetric key pair, comprising a private device key and a public device key, within the personal identification device;

    d. distributing the public key of the asymmetric key pair and a unique device identifier to the manufacturer;

    e. creating a first digital certificate containing the public key and the unique identifier;

    f. securely distributing the first digital certificate to the personal identification device;

    g. storing the public key and the unique identifier within the manufacturer'"'"'s database;

    h. disabling all functionality of the personal identification device;

    i. requesting enrollment permission from an enrollment authority;

    j. validating the request for enrollment permission;

    k. presenting the first digital certificate to the enrollment authority;

    l. verifying that the personal identification device is the legitimate possessor of the first digital certificate;

    m. presenting a second digital certificate possessed by the enrollment authority;

    n. verifying that the enrollment authority is the legitimate possessor of the second digital certificate;

    o. creating a symmetric session key; and

    p. using the symmetric session key to securely transmit the personal identity credential and the associated biometric to the personal identification device.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×