System, device, and method of provisioning cryptographic data to electronic devices
First Claim
1. A method of cryptographic material provisioning (CMP), the method comprising:
- (a) generating a delegation message at a first provisioning server computer,wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device,wherein generating the delegation message comprises at least one of;
(A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device;
(B) inserting into the delegation message a public key of the second provisioning server computer;
enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;
(b) delivering the delegation message from the first provisioning server computer to the electronic device;
(c) at the second provisioning server, provisioning one or more cryptographic assets to the electronic device, using said association key;
wherein the method comprises, prior to performing step (a);
securely delivering from the second provisioning server computer to the first provisioning server computer, via a secure communication channel, (A) a public encryption key of the second provisioning server computer, and (B) a class-wide association key encrypted with a key that allows the association key to be decrypted by said electronic device.
5 Assignments
0 Petitions
Accused Products
Abstract
System, device, and method of provisioning cryptographic assets to electronic devices. A delegation message is generated at a first provisioning server. The delegation message indicates provisioning rights that are delegated by the first provisioning server to a second provisioning server with regard to subsequent provisioning of cryptographic assets to an electronic device. The delegation message includes an association key unknown to the first provisioning server, encrypted using a public key of the electronic device. The delegation message further includes a public key of the second provisioning server. The electronic device locally generates the association key, which is unknown to the first provisioning server. The delegation message is delivered to the electronic device. Based on the delegation message, cryptographic assets are provisioned by the second provisioning server to the electronic device, using the association key.
47 Citations
15 Claims
-
1. A method of cryptographic material provisioning (CMP), the method comprising:
-
(a) generating a delegation message at a first provisioning server computer, wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device, wherein generating the delegation message comprises at least one of; (A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device; (B) inserting into the delegation message a public key of the second provisioning server computer;
enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;(b) delivering the delegation message from the first provisioning server computer to the electronic device; (c) at the second provisioning server, provisioning one or more cryptographic assets to the electronic device, using said association key; wherein the method comprises, prior to performing step (a);
securely delivering from the second provisioning server computer to the first provisioning server computer, via a secure communication channel, (A) a public encryption key of the second provisioning server computer, and (B) a class-wide association key encrypted with a key that allows the association key to be decrypted by said electronic device. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A method of cryptographic material provisioning (CMP), the method comprising:
-
(a) generating a delegation message at a first provisioning server computer, wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device, wherein generating the delegation message comprises at least one of; (A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device; (B) inserting into the delegation message a public key of the second provisioning server computer, enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;(b) delivering the delegation message from the first provisioning server computer to the electronic device; (c) at the second provisioning server computer, provisioning one or more cryptographic assets to the electronic device, using said association key; wherein generating the delegation message comprises; inserting into the delegation message a public key of the second provisioning server computer, to enable execution of an identification protocol for subsequent personalized provisioning of a cryptographic asset to said electronic device.
-
-
9. A method of cryptographic material provisioning (CMP), the method comprising:
-
(a) generating a delegation message at a first provisioning server computer, wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device, wherein generating the delegation message comprises at least one of; (A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device; (B) inserting into the delegation message a public key of the second provisioning server computer, enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;(b) delivering the delegation message from the first provisioning server computer to the electronic device; (c) at the second provisioning server computer, provisioning one or more cryptographic assets to the electronic device, using said association key; (d) provisioning from the first provisioning server computer to the electronic device, via a one-pass one-way provisioning protocol, at least; (i) the public encryption key of the second provisioning server computer, (ii) the server certificate of the second provisioning server computer, digitally signed by an authorization server computer, (iii) an indication of which cryptographic assets the second provisioning server is authorized to subsequently provision to the electronic device.
-
-
10. A method of cryptographic material provisioning (CMP), the method comprising:
-
(a) generating a delegation message at a first provisioning server computer, wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device, wherein generating the delegation message comprises at least one of; (A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device; (B) inserting into the delegation message a public key of the second provisioning server computer, enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;(b) delivering the delegation message from the first provisioning server computer to the electronic device; (c) at the second provisioning server computer, provisioning one or more cryptographic assets to the electronic device, using said association key; wherein generating the delegation message comprises; inserting into the delegation message one or more flags indicating to the electronic device whether the second provisioning server computer is authorized to provision;
(X) only personalized cryptographic assets, or (Y) only class-wide cryptographic assets for a class of multiple electronic devices, or (Z) both personalized and class-wide cryptographic assets.
-
-
11. A method of cryptographic material provisioning (CMP), the method comprising:
-
(a) generating a delegation message at a first provisioning server computer, wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device, wherein generating the delegation message comprises at least one of; (A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device; (B) inserting into the delegation message a public key of the second provisioning server computer, enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;(b) delivering the delegation message from the first provisioning server computer to the electronic device; (c) at the second provisioning server computer, provisioning one or more cryptographic assets to the electronic device, using said association key; prior to provisioning a particular cryptographic asset from the second provisioning server computer to the electronic device, performing; acquiring by the second provisioning server computer an authorization ticket, from an authorization server computer, indicating that the second provisioning server computer is authorized to provision the particular cryptographic asset to said electronic device. - View Dependent Claims (12, 13, 14)
-
-
15. A system for cryptographic material provisioning (CMP), the system comprising:
-
a first provisioning server computer to generate a delegation message, wherein the delegation message indicates provisioning rights that are delegated by the first provisioning server computer to a second provisioning server computer with regard to subsequent provisioning of cryptographic assets to an electronic device, wherein the first provisioning server computer is to generate the delegation message by performing at least one of; (A) inserting into the delegation message an encrypted association key that was encrypted by the second provisioning server computer using a public key of said electronic device, wherein said association key is unknown to the first provisioning server computer, wherein said public key of said electronic device is usable to encrypt data for subsequent decrypting by said electronic device using said private encryption key of said electronic device; (B) inserting into the delegation message a public key of the second provisioning server computer;
enabling the electronic device to locally generate said association key unknown to the first provisioning server computer;
wherein the association key is retrievable by the second provisioning server computer based on the public key of the second provisioning server computer;wherein, subsequent to delivery of the delegation message from the first provisioning server to the electronic device, the second provisioning server computer is to provision one or more cryptographic assets to the electronic device, using said association key; wherein, prior to generation of the delegation message, the following items are securely delivered from the second provisioning server computer to the first provisioning server computer, via a secure communication channel, (A) a public encryption key of the second provisioning server computer, and (B) a class-wide association key encrypted with a key that allows the association key to be decrypted by said electronic device.
-
Specification