IP Library Granted Patent US 10,291,596
Granted Patent B2
US 10,291,596 · App. 15/516,932 · Granted May 14, 2019

Installation of a terminal in a secure system

Inventor: Elise Revell (Rånäs, SE)
Assignee: KELISEC AB
H04L63/0435H04L9/083H04L9/0819H04L9/0822H04L9/0869H04L9/3236H04L63/062H04L63/0807H04W12/04H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,291,596
App. No.
15/516,932
Granted
May 14, 2019
Kind
B2
Abstract

A system comprising a terminal and a server, wherein the terminal is installed in the system by the server being configured to: identify the terminal; generate key generation data, comprising at least one data seed; distribute the at least one seed to the terminal; generate key data and meta data based on said at least one seed and a function; store an identifier for the terminal along with the key data and the meta data for the terminal, wherein the terminal is arranged to receive the at least one seed from the server; generate key data and meta data based on said at least one seed and the same function; store the key data and the meta data, wherein the key data and the meta data stored in the terminal are the same as the key data and the meta data stored in the server.

Claims (48)

1. A system comprising a terminal and a server, wherein the terminal is installed in the system by the server being configured to:

identify the terminal;

generate key generation data, comprising at least one data seed;

distribute the at least one data seed to the terminal;

generate key data, to be used for generating a symmetric encryption key, and meta data, to be used for generating an authentication token, based on said at least one data seed and a function for generating numbers;

store an identifier for the terminal along with the key data and the meta data for the terminal

generate a random encryption key;

distribute the random encryption key to the terminal; and

encrypt the at least one data seed with the random encryption key, wherein the terminal is arranged to:

receive the at least one data seed from the server;

generate key data and meta data based on said at least one data seed and the same function for generating numbers;

store the key data and the meta data, wherein the key data and the meta data stored in the terminal are the same as the key data and the meta data stored in the server;

receive the random encryption key;

receive the encrypted at least one data seed from the server; and

decrypt the at least one data seed with the random encryption key.

2. The system according to claim 1 , wherein said terminal is configured to generate a symmetric encryption key based on the key data for the terminal as well as the key data for a second terminal to which a secure communication channel is to be established .

3. The system according to claim 1 , wherein said server is configured to generate an identifier for the terminal distribute the identifier to the terminal and then receive the identifier from the terminal and identify the terminal based on the identifier.

4. The system according to claim 1 , wherein the function for generating numbers is a cryptographic hash function.

5. The system according to claim 1 , wherein the terminal is configured to

generate an authentication token based on the meta data, and

send the authentication token to the server and wherein the server is configured to

receive the authentication token and

authenticate the authentication token by comparing it to the meta data stored for the terminal.

6. The system according to claim 1 , wherein the system is an apparatus and the first terminal is an external device to be installed in the apparatus and the apparatus is configured to execute the server or communicate with the server.

7. A method for use in a system comprising a terminal and a server, said method being for installing the terminal in the system, the method comprising:

the server identifying the terminal;

the server generating key generation data, comprising at least one data seed;

the server distributing the at least one data seed to the terminal;

the server generating key data, to be used for generating a symmetric encryption key, and meta data, to be used for generating an authentication token, based on said at least one data seed and a function for generating numbers;

the server storing an identifier for the terminal along with the key data and the meta data for the terminal;

the server generating a random encryption key;

the server distributing the random encryption key to the terminal;

the server encrypting the at least one data seed with the random encryption key;

the terminal receiving the at least one data seed from the server;

the terminal generating key data and meta data based on said at least one data seed and the same function for generating numbers;

the terminal storing the key data and the meta data, wherein the key data and the meta data stored in the terminal are the same as the key data and the meta data stored in the server;

the terminal receiving the random encryption key;

the terminal receiving the encrypted at least one data seed from the server; and

the terminal decrypting the at least one data seed with the random encryption key.

8. A non-transitory computer readable storage medium encoded with instructions that, when executed on a processor, performs the method according to claim 7 .

9. The method according to claim 7 , the terminal generating a symmetric encryption key based on the key data for the terminal as well as the key data for a second terminal to which a secure communication channel is to be established.

10. The method according to claim 7 , the server generating an identifier for the terminal, distributing the identifier to the terminal, receiving the identifier from the terminal, and identifying the terminal based on the identifier.

11. The method according to claim 7 , wherein the function for generating numbers is a cryptographic hash function.

12. The method according to claim 7 , the terminal:

generating an authentication token based on the meta data, and

sending the authentication token to the server; and the server:

receiving the authentication token, and

authenticating the authentication token by comparing it to the meta data stored for the terminal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2017
From: REVELL, ELISE
To: KELISEC AB
Reel/Frame 042287/0435 →
Priority Claims (1)
SE 1451209 · Oct 9, 2014 · national
Continuity (1)
Related Publication 20170257352A1 · Sep 7, 2017