摘要:
A system is provided in which a single postal security device (20, 40, 44) has a secure housing, and within the secure housing are two or more accounting register sets (31, 51a, 51b, 51c). Importantly, the two or more accounting register sets (31, 51a, 51b, 51c) are associated with distinct meter licenses (32, 52a, 52b, 52c). Alternatively, the single postal security device (20, 40, 44) can store a single accounting register set (31, 51a, 51b, 51c), but is able to transfer the register set (31, 51a, 51b, 51c) to a nonsecure store (71) such as the hard drive of a personal computer, the register set having been cryptographically signed (72). Later the register set (72) may be retrieved from the nonsecure store (71) and cryptographically authenticated, and restored to its location within the secure housing of postal security device (20, 40, 44). In this way, the postal security (20, 40, 44) may provide service under more than one distinct meter license (32, 52a, 52b, 52c). In a related embodiment, a single meter license (32, 52a, 52b, 52c) is associated with more than one postal security device (20, 40, 44), each with its own secure housing. Each register set (31, 51a, 51b, 51c) is configured to permit being reset (refilled with postage) by means of a cryptographically secure exchange of data over a communications channel (23, 25, 30, 41, 45) to external equipment such as a manufacturer's server (24) or a server (26) operated by the post office.
摘要:
In accordance with the invention, a postal security device (PSD) (10) contains a non-volatile memory (13) which does not depend on battery power such as an EEPROM (13), and contains a nonvolatile memory (14, 16) which does depend on battery power, such as a static RAM. The PSD (10) also contains an encryption engine (12, 14, 22). An encryption key is developed and is stored in the static RAM (14), which is sized to be only large enough to contain the encryption key. A large body of data, too large to fit in the static RAM, is encrypted by means of the encryption engine (12, 14, 22) and with reference to the encryption key, and is stored in the EEPROM (13). This body of data typically includes cryptographic keys and sensitive bit-images. When the PSD is powered, a large RAM (typically a dynamic RAM) (16) is available to receive the large body of data, decrypted using the encryption key. A tamper switch (17) cuts power to both RAMs (14, 16) in the event of tampering.