Advanced postage payment system employing pre-computed digital tokens
and with enhanced security
    2.
    发明授权
    Advanced postage payment system employing pre-computed digital tokens and with enhanced security 失效
    高级邮资支付系统采用预先计算的数字令牌和增强的安全性

    公开(公告)号:US5655023A

    公开(公告)日:1997-08-05

    申请号:US242564

    申请日:1994-05-13

    摘要: A method and system for postage payment include the generation of a plurality of dispensable discrete items of encrypted data. Each of the items of encrypted data, which may be digital tokens, have a specific value. The generated plurality of discrete items of encrypted data are stored on a portable medium. A prepayment value is also stored on the portable medium. The dispensing of the stored plurality of discrete items of encrypted data is limited based on the prepayment value stored on the portable medium. The medium may be a device or member having memory for storing a plurality of dispensable tokens. The portable member or device may have a housing with a register within the housing. The postage prepayment value is stored in the register. The plurality of discrete items of encrypted data is stored in the housing with each of the items of encrypted data adapted to be formatted for printing. Structure within the housing is coupled to the plurality of discrete items of encrypted data and to the prepayment register for enabling at least one selected item of encrypted data to be communicated outside of the housing if the value stored in register is at least equal to the specific value of the selected item of encrypted data.

    摘要翻译: 用于邮资支付的方法和系统包括生成多个可分配的离散的加密数据项。 可以是数字令牌的加密数据的每个项目都具有特定的值。 生成的多个离散的加密数据项被存储在便携式介质上。 预付费值也存储在便携式媒体上。 基于存储在便携式介质上的预付费值来限制存储的多个离散项目的加密数据的分配。 介质可以是具有用于存储多个可分配令牌的存储器的设备或构件。 便携式构件或设备可以具有在壳体内具有寄存器的壳体。 邮资预付款值存储在寄存器中。 多个离散项目的加密数据被存储在外壳中,其中每个加密数据项适于被格式化以进行打印。 外壳内的结构耦合到多个离散项目的加密数据和预付费寄存器,用于使存储在寄存器中的值至少等于特定值的至少一个选定项目的加密数据在外部通信。 所选择的加密数据项的值。

    Method of token verification in a key management system
    3.
    发明授权
    Method of token verification in a key management system 失效
    密钥管理系统中令牌验证的方法

    公开(公告)号:US5661803A

    公开(公告)日:1997-08-26

    申请号:US414896

    申请日:1995-03-31

    摘要: A method of token verification in a Key Management System provides a logical device identifier and a master key created in a logical security domain to a transaction evidencing device, such as a digital postage meter. The method creates a master key record in a key verification box, securely stores the master key record in a Key Management System archive, and produces in the transaction evidencing device evidence in the logical security domain of transaction information integrity. The method inputs the evidence of the transaction information integrity to a token verification box, and inputs in the token verification box the master key record from the Key Management System archive. The method determines in the token verification box that the master key is valid in logical security domain, uses in the token verification box the master key to verify the evidence of transaction information integrity, and outputs from the token verification box an indication of the result of the verification of the evidence of transaction information integrity. The master key record includes the logical device identifier, the master key and a digital signature associating the logical device identifier and the master key. The method checks the digital signature to verify the association of the logical device identifier and the master key within the logical security domain.

    摘要翻译: 密钥管理系统中的令牌验证方法为逻辑安全域中创建的逻辑设备标识符和主密钥提供给诸如数字邮资计费器之类的交易证明设备。 该方法在密钥验证框中创建主密钥记录,将主密钥记录安全地存储在密钥管理系统归档中,并在交易证明装置中产生交易信息完整性的逻辑安全域中的证据。 该方法将交易信息完整性的证据输入令牌验证框,并在令牌验证框中输入密钥管理系统归档中的主密钥记录。 该方法在令牌验证框中确定主密钥在逻辑安全域中有效,在令牌验证框中使用主密钥验证交易信息完整性的证据,并从令牌验证框输出结果的指示 验证交易信息完整性的证据。 主密钥记录包括逻辑设备标识符,主密钥和与逻辑设备标识符和主密钥相关联的数字签名。 该方法检查数字签名以验证逻辑设备标识符与主密钥在逻辑安全域内的关联。

    System and method for authenticating indicia using identity-based signature scheme
    5.
    发明授权
    System and method for authenticating indicia using identity-based signature scheme 有权
    使用基于身份的签名方案对标记进行身份验证的系统和方法

    公开(公告)号:US08676715B2

    公开(公告)日:2014-03-18

    申请号:US11810488

    申请日:2007-06-06

    IPC分类号: G06Q20/00

    摘要: Methods and systems for verification of indicia that do not require key management systems, and in which revocation of key pairs is easily performed without adding costs to the verification process are provided. Indicia are generated and authenticated utilizing an identity-based encryption (IBE) scheme. A key generating authority generates a private key for a PSD, distributes the private key securely to the PSD, and provides public information for use by a verification service when verifying cryptographic digital signatures generated with the private key. The corresponding public key is a string consisting of PSD information that is provided as part of the indicium. The verification service can verify the signature of each indicium by obtaining the public key string from the indicium, and utilizing the key generating authority's public information.

    摘要翻译: 提供了用于验证不需要密钥管理系统的标记的方法和系统,并且容易地执行密钥对的撤销而不增加验证过程的成本。 使用基于身份的加密(IBE)方案来生成和认证标识符。 密钥生成机构为PSD生成私钥,将私钥安全地分配给PSD,并且在验证使用私钥生成的加密数字签名时,提供公开信息供验证服务使用。 相应的公钥是由作为标记的一部分提供的PSD信息组成的字符串。 验证服务可以通过从标记获取公钥字符串,并利用密钥生成机构的公开信息来验证每个标记的签名。

    Mail processing system with unique mailpiece authorization assigned in
advance of mailpieces entering carrier service mail processing stream

    公开(公告)号:US5936865A

    公开(公告)日:1999-08-10

    申请号:US714726

    申请日:1996-09-16

    摘要: A mailing list is created including destination addresses for mailpieces to be submitted to a carrier service for delivery. A unique mailpiece identifier associated with mailpieces on the mailing list is generated by the carrier or other trusted third party. The unique mailpiece identifier is printed on the mailpiece with which it is associated. The mailpieces with the printed unique identifier are submitted to the carrier service. The carrier service obtains the printed unique identifier from the mailpiece. The obtained unique identifier from each said mailpiece is utilized to verify that data associated with the mailpiece has been processed by the carrier or trusted third party. When the unique number has been obtained from the mailpieces, the carrier service, if desired, may note this fact in the carrier records to prevent reuse of the unique identifier. The carrier service as part of issuing the unique identification may: charge the mailer's account of other fund depository for the carrier service charges associated with the mailpiece; and/or, assign a destination delivery code; and/or, provide address hygiene for the mailpiece; and/or change of address processing. When the unique identifier is obtained from the mailpiece, a delivery point destination code may be printed on the mailpiece, based on the corrected address. As an alternative, the destination delivery code may be provided to the mailer with the unique mailpiece identifier to be printed on the mailpiece by the mailer. Various cryptographic techniques may be employed to authenticate the mailer and the carrier service and to protect the transmitted information between the parties. The payment for the carrier services can be implemented prior in time to the entry of the mailpieces to the carrier service mailstream. Unauthorized mailpieces may be out sorted early in the carrier service processing procedure.