Method for publishing certification information representative of selectable subsets of rights and apparatus and portable data storage media used to practice said method
    2.
    发明授权
    Method for publishing certification information representative of selectable subsets of rights and apparatus and portable data storage media used to practice said method 失效
    用于发布代表权利和装置的可选子集的认证信息的方法以及用于实践所述方法的便携式数据存储介质

    公开(公告)号:US06704867B1

    公开(公告)日:2004-03-09

    申请号:US09280529

    申请日:1999-03-30

    申请人: Robert A Cordery

    发明人: Robert A Cordery

    IPC分类号: H04L908

    摘要: A method for certification by a plurality of certifying authorities of the public key of a user wishing to communicate using a public key encryption system while asserting only a subset of rights. A plurality of certifying stations and a user station exchange information and the user station derives a plurality of private keys from the exchanged information. The certifying stations also publish related information and their public keys. The user communicates using a private key formed by summing selected ones of said plurality of private keys corresponding to asserted rights. A third party can derive the public key corresponding to the user's summed private key by operating on the published information with a summation of the certifying station public keys.

    摘要翻译: 一种用于通过使用公开密钥加密系统进行通信的用户的公开密钥进行认证的方法,同时只支持一部分权限。 多个认证站和用户站交换信息,并且用户站从交换的信息中导出多个私钥。 验证站还会发布相关信息及其公钥。 用户使用通过对与所声明的权限相对应的所述多个私钥中的所选择的私钥进行求和而形成的私钥进行通信。 第三方可以通过使用认证台公钥的总和对所发布的信息进行操作来导出与用户的总和私钥对应的公开密钥。

    METHOD FOR VERIFYING THE AUTHENTICITY OF A SENDER OF A MAIL ITEM
    4.
    发明申请
    METHOD FOR VERIFYING THE AUTHENTICITY OF A SENDER OF A MAIL ITEM 审中-公开
    验证邮件发件人的正当性的方法

    公开(公告)号:US20150154813A1

    公开(公告)日:2015-06-04

    申请号:US14558671

    申请日:2014-12-02

    申请人: Deutsche Post AG

    IPC分类号: G07B17/04 G07B17/00

    摘要: Systems and methods herein relate to verifying an authentication of a sender of a mail item. Certain implementations may include various steps, such as: the sender applying a machine-readable postage indicium having an embedded electronic seal onto the mail item, the sender electronically transmitting the seal to a logistics service provider, the logistics service provider reading a received seal out of a received postage indicium of the mail item received by the logistics service provider, the recipient detecting a postage indicium of the mail item delivered to the recipient by means of a mobile reading device and transmitting said postage indicium to the logistics service provider, the logistics service provider reading a delivered seal out of the delivered postage indicium, and/or the logistics service provider comparing the delivered seal with the transmitted seal.

    摘要翻译: 这里的系统和方法涉及验证邮件项目的发送者的认证。 某些实现可以包括各种步骤,例如:发送者将具有嵌入式电子密封件的机器可读邮资标签应用于邮件项目,发送者将密封件电子地传送到物流服务提供商,物流服务提供商读取收到的密封件 物流服务提供商接收到的邮件的接收邮资标签,接收者通过移动阅读设备检测传送给接收者的邮件的邮资标签,并将所述邮资标签传送到物流服务提供商,物流 服务提供商从交付的邮资标签和/或物流服务提供商处阅读交付的密封件,将传送的密封件与传输的密封件进行比较。

    Method for publishing certification information certified by a plurality of authorities and apparatus and portable data storage media used to practice said method
    5.
    发明授权
    Method for publishing certification information certified by a plurality of authorities and apparatus and portable data storage media used to practice said method 失效
    用于发布由多个机构认证的认证信息的方法以及用于实践所述方法的装置和便携式数据存储介质

    公开(公告)号:US06738899B1

    公开(公告)日:2004-05-18

    申请号:US09280527

    申请日:1999-03-30

    申请人: Robert A. Cordery

    发明人: Robert A. Cordery

    IPC分类号: H04L930

    摘要: A method for certifying the public key of a user wishing to communicate using a public key encryption system by a plurality of certifying authorities. A plurality of certifying stations and a user station exchange information and the user station derives a public key from the exchanged information. The certifying stations also publish related information and their public keys. A third party can derive the public key corresponding to the user's private key by operating on the published information with a summation of the certifying station keys.

    摘要翻译: 一种用于通过多个认证机构使用公开密钥加密系统验证希望进行通信的用户的公开密钥的方法。 多个认证站和用户站交换信息,并且用户站从所交换的信息中导出公钥。 验证站还会发布相关信息及其公钥。 第三方可以通过对发布的信息进行操作来获得对应于用户的私钥的公钥,并且通过验证站密钥的总和来获得。

    Method for checking postage stamps on letters and parcels
    6.
    发明申请
    Method for checking postage stamps on letters and parcels 审中-公开
    检查邮票邮票的方法

    公开(公告)号:US20040054631A1

    公开(公告)日:2004-03-18

    申请号:US10399244

    申请日:2003-05-13

    IPC分类号: G06F017/60 H04K001/00

    摘要: The invention relates to a method for checking postage stamps on letters and parcels, at a checkpoint. Said checkpoint deciphers the identity and authenticity of a customer system having generated the production of the stamp by decoding cryptographic security elements originating from a trusted certification point. According to the invention, this method is carried out in such a way that means contained in the checking unit determine a key for which the probability of having been used to encode the data at the certification point is particularly high.

    摘要翻译: 本发明涉及一种用于在检查点检查邮票上邮票的方法。 所述检查点通过解码源自受信任认证点的加密安全性元件来解密生成印章生产的客户系统的身份和真实性。 根据本发明,这种方法是以包含在检查单元中的装置确定在认证点被用于编码数据的概率特别高的密钥来进行的。

    Method and apparatus for authenticating messages
    7.
    发明授权
    Method and apparatus for authenticating messages 失效
    用于认证消息的方法和装置

    公开(公告)号:US5142577A

    公开(公告)日:1992-08-25

    申请号:US628820

    申请日:1990-12-17

    申请人: Jose Pastor

    发明人: Jose Pastor

    摘要: A method and system for authenication of communications. More particularly the subject application discloses a method and apparatus whereby a third party may validate that a communication is an authentic communication from a second party sent with the authorization of a first party. For example, the third party may be a postal service, the second party may be a mailer, and the communication may be a postal indicia showing that a mail piece has been properly franked. The first party and the second party share an encryption key, or a series of keys. The first party also has a second encryption key which the third party has the ability to decrypted. In the subject invention the first party encrypts a key shared with the second party with the first party's second key and transmits this to the second party. The second party then uses its copy of the key to encrypt information and appends its encrypted information to the message received from the first party and transmits all this to the third party. The third party may then decrypt the copy of the key encrypted by the first party and use this information to decrypt the information encrypted by the second party. The known technique of eliptical logarithms may be used to provide highly secure encryption of short messages. The second party may be a mailer and the apparatus of the subject invention may include a postage meter which prints the information transmitted to the third party, who may be a postal service, on a mail piece as a postal indicia.

    摘要翻译: 通信认证的方法和系统。 更具体地,本申请公开了一种方法和装置,其中第三方可以验证通信是从第一方的授权发送的第二方的真实通信。 例如,第三方可以是邮政服务,第二方可以是邮寄者,并且该通信可以是显示邮件已经被正确地打包的邮戳。 第一方和第二方共享加密密钥或一系列密钥。 第一方也有第二个加密密钥,第三方有能力进行解密。 在本发明中,第一方使用第一方的第二密钥加密与第二方共享的密钥,并将其发送给第二方。 然后,第二方使用其密钥副本来加密信息,并将其加密信息附加到从第一方接收的消息,并将所有信息传送给第三方。 然后,第三方可以解密由第一方加密的密钥的副本,并使用该信息来解密由第二方加密的信息。 可以使用已知的椭圆对数技术来提供短消息的高度安全的加密。 第二方可以是邮寄者,并且本发明的装置可以包括邮寄计费器,其将作为邮政服务的发送给第三方的信息作为邮戳打印在邮件上。

    Method for verifying the expected postal security device in a postage metering system
    8.
    发明授权
    Method for verifying the expected postal security device in a postage metering system 失效
    用于验证邮资计费系统中的预期邮政安全设备的方法

    公开(公告)号:US06260144B1

    公开(公告)日:2001-07-10

    申请号:US08754568

    申请日:1996-11-21

    IPC分类号: H04K900

    摘要: A PSD has a private key which is associated with a specific public key that is stored in the host PC. The host PC sends the PSD public key private key to the PSD. If the PSD determines that the received PSD public key corresponds to its private key, the system has determined that the expected PSD is connected to the Host system and the PSD is activated to accept postal value requests from the host PC. Additionally, a PSD state identification, such as a checksum of a PSD transaction log file stored in the host may be verified by the PSD, which also has stored therein a PSD transaction log file. In this manner the PSD verifies that the PSD has performed all transactions with the host PC sending the checksum. Methods for verifying in the PSD that the expected host PC is coupled to the PSD mirrors the two embodiments for verifying the expected PSD.

    摘要翻译: PSD具有与存储在主机PC中的特定公钥相关联的私钥。 主机PC将PSD公钥私钥发送到PSD。 如果PSD确定接收到的PSD公钥对应于其私钥,则系统已经确定预期的PSD连接到主机系统并且PSD被激活以接受来自主机的邮件请求。 此外,PSD状态识别(例如存储在主机中的PSD事务日志文件的校验和)可以由PSD验证,PSD也存储有PSD事务日志文件。 以这种方式,PSD验证PSD已经执行与主机PC发送校验和的所有事务。 在PSD中验证预期主机PC耦合到PSD的方法反映了两个实施例,以验证预期的PSD。

    Cryptographic key management and validation system
    9.
    发明授权
    Cryptographic key management and validation system 失效
    加密密钥管理和验证系统

    公开(公告)号:US5812666A

    公开(公告)日:1998-09-22

    申请号:US553812

    申请日:1995-10-23

    摘要: A Key Management System for generating, distributing and managing cryptographic keys used by an information transaction system that employs cryptographic means to produce evidence of information integrity. The system comprises a plurality of functionally distinct secure boxes operatively coupled to each other. Each of the secure boxes performs functions for key generation, key installation, key verification or validation of tokens. Computers, operatively coupled to the secure boxes, provide system control and facilitate communication among the secure boxes. A plurality of separate logical security domains provide domain processes for key generation, key installation, key verification and validation of tokens produced by the transaction evidencing device within the domain using the key management functions. A plurality of domain archives, corresponding respectively to each of the security domains, securely and reliably record key status records and master keys for each domain. The Key Management System installs the master keys in the transaction evidencing device and validates the tokens. The secure boxes include a key generation box for generating, encrypting and signing a master key; a key installation box for receiving, verifying and decrypting the signed master key and for installing the master key into the transaction evidencing device; a key verification box for verifying the installation of the master key in the transaction evidencing device, a token verification box for verifying the tokens, and at least one manufacturing box for generating domain keys and distributing the domain keys among the secure boxes for each of the domains.

    摘要翻译: 一种密钥管理系统,用于生成,分发和管理信息交易系统使用的加密密钥,该信息交易系统采用加密手段来产生信息完整性的证据。 该系统包括可操作地彼此耦合的多个功能不同的安全盒。 每个安全盒都执行密钥生成,密钥安装,密钥验证或令牌验证的功能。 可操作地耦合到安全盒的计算机提供系统控制并促进安全盒之间的通信。 多个单独的逻辑安全域提供用于密钥生成,密钥安装,密钥验证和使用密钥管理功能由域内的交易证明设备产生的令牌的验证的域过程。 分别对应于每个安全域的多个域归档安全可靠地记录每个域的密钥状态记录和主密钥。 密钥管理系统将主密钥安装在事务证明设备中,并验证令牌。 安全盒包括用于生成,加密和签名主密钥的密钥生成盒; 用于接收,验证和解密签名的主密钥并将主密钥安装到交易证明设备中的密钥安装箱; 用于验证主密钥在交易证明设备中的安装的关键验证框,用于验证令牌的令牌验证盒,以及用于生成域密钥的至少一个制造盒,以及在每个的安全盒中分配域密钥 域名

    Method of token verification in a key management system
    10.
    发明授权
    Method of token verification in a key management system 失效
    密钥管理系统中令牌验证的方法

    公开(公告)号:US5661803A

    公开(公告)日:1997-08-26

    申请号:US414896

    申请日:1995-03-31

    摘要: A method of token verification in a Key Management System provides a logical device identifier and a master key created in a logical security domain to a transaction evidencing device, such as a digital postage meter. The method creates a master key record in a key verification box, securely stores the master key record in a Key Management System archive, and produces in the transaction evidencing device evidence in the logical security domain of transaction information integrity. The method inputs the evidence of the transaction information integrity to a token verification box, and inputs in the token verification box the master key record from the Key Management System archive. The method determines in the token verification box that the master key is valid in logical security domain, uses in the token verification box the master key to verify the evidence of transaction information integrity, and outputs from the token verification box an indication of the result of the verification of the evidence of transaction information integrity. The master key record includes the logical device identifier, the master key and a digital signature associating the logical device identifier and the master key. The method checks the digital signature to verify the association of the logical device identifier and the master key within the logical security domain.

    摘要翻译: 密钥管理系统中的令牌验证方法为逻辑安全域中创建的逻辑设备标识符和主密钥提供给诸如数字邮资计费器之类的交易证明设备。 该方法在密钥验证框中创建主密钥记录,将主密钥记录安全地存储在密钥管理系统归档中,并在交易证明装置中产生交易信息完整性的逻辑安全域中的证据。 该方法将交易信息完整性的证据输入令牌验证框,并在令牌验证框中输入密钥管理系统归档中的主密钥记录。 该方法在令牌验证框中确定主密钥在逻辑安全域中有效,在令牌验证框中使用主密钥验证交易信息完整性的证据,并从令牌验证框输出结果的指示 验证交易信息完整性的证据。 主密钥记录包括逻辑设备标识符,主密钥和与逻辑设备标识符和主密钥相关联的数字签名。 该方法检查数字签名以验证逻辑设备标识符与主密钥在逻辑安全域内的关联。