Devices, systems, and methods for performing a digital signature
A data processing device for performing a digital signature includes a secure portion, wherein the secure portion includes a private data processing device key and/or wherein the secure portion includes a seed configured to generate at least one pair of a private data processing device key and a public data processing device key. The data processing device further includes an authorization protocol. The data processing device is configured to digitally sign a data element with a private data processing device key in the secure portion in response to successful completion of the authorization protocol.
1 . A data processing device for performing a digital signature, wherein the data processing device comprises:
a secure portion, wherein the secure portion comprises:
a private data processing device key, and/or
a seed configured to generate at least one pair of the private data processing device key and a public data processing device key;
wherein the secure portion further comprises M public keys, wherein M is a natural number greater than 1;
an N of M scheme, wherein N is a natural number not exceeding M; and
an authorization protocol;
wherein the data processing device is configured to:
digitally sign a data element with the private data processing device key in the secure portion in response to a successful completion of the authorization protocol, wherein the authorization protocol comprises:
receiving the data element;
receiving at least N versions of the data element, wherein each of the N versions is signed by a distinct private key corresponding to one of the M public keys; and
in response to receiving the at least N versions of the data element, verifying the at least N versions of the data element by using at least N of the M public keys; and
send the data element digitally signed with the private data processing device key.
2 . The data processing device according to claim 1 , wherein the secure portion comprises the N of M scheme.
3 . The data processing device according to claim 1 , wherein the secure portion comprises the seed, and wherein the data processing device is configured to receive a key derivation parameter and wherein the secure portion is configured to generate the pair of the private data processing device key and the public data processing device key based on the key derivation parameter.
4 . The data processing device according to claim 3 , wherein the data processing device is configured to send the public data processing device key.
5 . The data processing device according to claim 1 , wherein:
the secure portion comprises the authorization protocol;
the data processing device comprises a device identification code; and
the successful completion of the authorization protocol comprises receiving an identification code and comparing the identification code to the device identification code.
6 . The data processing device according to claim 1 , wherein the data processing device is further configured to, when digitally signing the data element, register the digital signing, and wherein the data processing device comprises a log file configured to register the digital signing.
7 . The data processing device according to claim 1 , wherein the data processing device is configured to change a counter when digitally signing the data element, wherein the counter is signature type specific.
8 . The data processing device according to claim 1 , wherein the data processing device is a card.
9 . The data processing device according to claim 1 , wherein the data processing device comprises a clone indicator, wherein the clone indicator indicates whether another data processing device with corresponding functionality was generated.
10 . A method of initializing a data processing device, wherein the method comprises:
providing the data processing device, wherein the data processing device comprises a secure portion, wherein the secure portion comprises:
a private data processing device key, and/or
a seed configured to generate at least one pair of the private data processing device key and a public data processing device key;
providing an authorization protocol to the data processing device;
providing M public keys to the secure portion of the data processing device, wherein M is a natural number greater than 1;
providing an N of M scheme to the data processing device, wherein N is a natural number not exceeding M;
configuring the data processing device to digitally sign a data element with a private data processing device key in the secure portion in response to a successful completion of the authorization protocol, wherein the successful completion of the authorization protocol comprises:
receiving the data element;
receiving at least N versions of the data element, wherein each of the N versions is signed by a distinct private key corresponding to one of the M public keys; and
verifying, in response to receiving the at least N versions of the data element, the at least N versions of the data element by using at least N of the M public keys; and
sending the data element digitally signed with the private data processing device key.
11 . A system comprising:
a data processing device comprising:
a secure portion, wherein the secure portion comprises:
a private data processing device key, and/or
a seed configured to generate at least one pair of the private data processing device key and a public data processing device key;
wherein the secure portion further comprises M public keys, wherein M is a natural number greater than 1;
an N of M scheme, wherein N is a natural number not exceeding M; and
an authorization protocol;
wherein the data processing device is configured to:
digitally sign a data element with the private data processing device key in the secure portion in response to a successful completion of the authorization protocol, wherein the authorization protocol comprises:
receiving the data element;
receiving at least N versions of the data element, wherein each of the N versions is signed by a distinct private key corresponding to one of the M public keys; and
in response to receiving the at least N versions of the data element, verifying the at least N versions of the data element by using at least N of the M public keys; and
send the data element digitally signed with the private data processing device key; and
a backup device comprising a backup secure portion, wherein the backup secure portion comprises:
the private data processing device key and/or the seed; and
the authorization protocol;
wherein the backup device is configured to digitally sign the data element with the private data processing device key in the backup secure portion in response to the successful completion of the authorization protocol.
12 . The system according to claim 11 , wherein the private data processing device key and/or the seed, and the authorization protocol are provided to the backup secure portion by a cryptographic information exchange protocol.
13 . A method of generating a backup device, wherein the method comprises:
providing a data processing device, wherein the data processing device comprises:
a secure portion, wherein the secure portion comprises:
a private data processing device key, and/or
a seed configured to generate at least one pair of the private data processing device key and a public data processing device key;
wherein the secure portion further comprises M public keys, wherein M is a natural number greater than 1;
an N of M scheme, wherein N is a natural number not exceeding M; and
an authorization protocol;
wherein the data processing device is configured to:
digitally sign a data element with a private data processing device key in the secure portion in response to a successful completion of the authorization protocol, wherein the authorization protocol comprises:
receiving the data element;
receiving at least N versions of the data element, wherein each of the N versions is signed by a distinct private key corresponding to one of the M public keys; and
in response to receiving the at least N versions of the data element, verifying the at least N versions of the data element by using at least N of the M public keys; and
send the data element digitally signed with the private data processing device key;
providing a second data processing device comprising a backup secure portion;
providing the private data processing device key and/or the seed, the M public keys, the N of M scheme, and the authorization protocol, to the second data processing device and thereby generating the backup device; and
configuring the backup device to digitally sign the data element with the private data processing device key in the backup secure portion in response to the successful completion of the authorization protocol.
14 . A method for testing a prior use of a data processing device comprising:
a secure portion, wherein the secure portion comprises:
a private data processing device key, and/or
a seed configured to generate at least one pair of the private data processing device key and a public data processing device key;
wherein the secure portion further comprises M public keys, wherein M is a natural number greater than 1;
an N of M scheme, wherein N is a natural number not exceeding M; and
an authorization protocol;
wherein the data processing device is configured to:
digitally sign a data element with a private data processing device key in the secure portion in response to a successful completion of the authorization protocol, wherein the authorization protocol comprises:
receiving the data element;
receiving at least N versions of the data element, wherein each of the N versions is signed by a distinct private key corresponding to one of the M public keys; and
in response to receiving the at least N versions of the data element, verifying the at least N versions of the data element by using at least N of the M public keys;
send the data element digitally signed with the private data processing device key; and
when digitally signing the data element:
register the digital signing, and wherein the data processing device comprises a log file configured to register the digital signing; and/or
change a counter, wherein the counter is signature type specific;
wherein the method comprises:
the data processing device outputting data of the counter and/or outputting data of the log file; and
verifying whether there was the prior use of the data processing device by means of the data of the counter and/or the data of the log file.
15 . The method according to claim 14 , wherein:
the data processing device comprises a clone indicator, wherein the clone indicator indicates whether another data processing device with corresponding functionality was generated; and
the method further comprises:
the data processing device outputting data of the clone indicator; and
assessing, by means of the data of the clone indicator, whether another data processing device with corresponding functionality was generated.
16 . The method according to claim 14 , wherein the method further comprises:
the data processing device receiving a test data element;
the data processing device signing the test data element with the data processing device private key and thus generating a signed test data element; and
the data processing device outputting the signed test data element;
wherein the data processing device signing the test data element does not lead to a change of the counter.
17 . The method according to claim 14 , wherein:
a backup data processing device is configured to change a backup counter when digitally signing the data element; and/or wherein the backup device is further configured to, when digitally signing the data element, register the digital signing, wherein the backup data processing device comprises a backup log file configured to register the digital signing;
assessing whether another data processing device with corresponding functionality was generated yields a positive result; and
the method further comprises:
the backup data processing device outputting data of the backup counter and/or outputting data of the backup log file; and
verifying whether there was a prior use of the backup data processing device by means of the data of the backup counter and/or the data of the backup log file.