Preparation of a control device for secure communication
A method for producing a control device includes the following steps: generating, by the control device, a first asymmetric cryptographic key pair with a first private key and a first public key; transmitting the first public key to an external entity; generating, by the external entity, a second asymmetric cryptographic key pair with a second private key and a second public key; encrypting, by the external entity, the second private key using the first public key; transmitting the encrypted second private key from the external entity to the control device; and decrypting, by the control device, the encrypted second private key using the first private key.
1 . A method for equipping a control apparatus including a programmable microcomputer or microcontroller circuit with cryptographic keys, the method comprising the following steps:
generating, by the control apparatus, a first asymmetric cryptographic key pair having a first private key and a first public key;
transmitting the first public key, which was generated by the control apparatus, from the control apparatus to an external signing entity;
generating, by the external signing entity, a second asymmetric cryptographic key pair having a second private key and a second public key, and signing the second public key using a signing key pair;
encrypting, by the external signing entity, the second private key with the first public key;
transmitting the encrypted second private key from the external signing entity to the control apparatus; and
decrypting, by the control apparatus, the encrypted second private key with the first private key;
wherein the control apparatus uses the second asymmetric cryptographic key pair for communication with an external server.
2 . The method according to claim 1 , which comprises creating, by the external signing entity, a cryptographic certificate based on the second public key and storing the cryptographic certificate on a key server.
3 . The method according to claim 1 , which comprises determining multiple second key pairs by the external signing entity, encrypting and transmitting multiple second private keys to the control apparatus, and decrypting the multiple second private keys by the control apparatus.
4 . The method according to claim 1 , which comprises establishing encrypted communication between the control apparatus and a further external entity using the second key pair.
5 . The method according to claim 1 , wherein only the control apparatus is able to decrypt the encrypted second private key using the first private key.
6 . A control apparatus for a predetermined appliance, the control apparatus including a programmable microcomputer or microcontroller circuit configured to:
generate a first asymmetric cryptographic key pair having a first private key and a first public key;
transmit the first public key, which was generated by the control apparatus, to an external signing entity that generates a second asymmetric cryptographic key pair having a second private key and a second public key and that signs the second public key using a signing key pair;
receive the second private key that is encrypted using the first public key, the second private key being a part of the second asymmetric cryptographic key pair;
decrypt the second private key using the first private key; and
use the second asymmetric cryptographic key pair for communication with an external server.
7 . The control apparatus according to claim 6 , further comprising an interface for communication with the external signing entity.
8 . The control apparatus according to claim 6 , configured to control the predetermined appliance and to use the first private key for encrypting an item of information related to controlling the appliance and to store the item of information locally.
9 . A household appliance, comprising a control apparatus according to claim 6 .
10 . An external signing entity for a control apparatus including a programmable microcomputer or microcontroller circuit, the external signing entity comprising a processor configured to:
receive a first public key from the control apparatus, the first public key being a part of a first cryptographic key pair;
generate a second asymmetric cryptographic key pair having a second private key and a second public key, and sign the second public key using a signing key pair;
encrypt the second private key using the first public key; and
transmit the encrypted second private key to the control apparatus to use the second asymmetric cryptographic key pair for communication with an external server.
11 . A system, comprising: the external signing entity according to claim 10 , and a device with a control apparatus for a predetermined appliance;
the control apparatus including a programmable microcomputer or microcontroller circuit configured to:
generate a first asymmetric cryptographic key pair having a first private key and a first public key;
transmit the first public key to the external signing entity that generates a second asymmetric cryptographic key pair having a second private key and a second public key and signs the second public key using a signing key pair;
receive the second private key that is encrypted using the first public key, the second private key being a part of the second asymmetric cryptographic key pair; and
decrypt the second private key using the first private key; and
use the second asymmetric cryptographic key pair for communication with an external server.