1. In a portable electronic authorization device (PEAD) with inaccessible storage of a user’s private key, a method for approving a transaction request originating from an electronic transaction system, comprising:
receiving at said portable electronic authorization device first digital data, said first digital data representing said transaction request; and
if said transaction request is approved by a user of said portable electronic authorization device, decrypting the user private key using a decryption key stored at and transmitted to the PEAD from a remote server, and transmitting a second digital data to said electronic transaction system, said second digital data being encrypted by said user private key but without transmission of the private key alone.
2. In an electronic authorization system with inaccessible storage of a user’s private key, at a portable electronic authorization device (PEAD) a method for approving a transaction request originating from an electronic transaction system, comprising:
receiving at said electronic authorization system first digital data, said first digital data representing said transaction request; and
if said transaction request is approved by a user of said electronic authorization system, decrypting the user private key using a decryption key stored at and transmitted to the PEAD from a remote server, transmitting a second digital data to said electronic transaction system, said second digital data being encrypted by said user private key but without transmission of the private key alone.
3. A method as claimed in claim 1 wherein decrypting the user private key includes sending a request from the PEAD to the server including a password from the user of the PEAD but not including transmission of the user’s private key to the server.
4. A method as claimed in claim 3 wherein the request includes transmitting a user password or pass phrase.
5. A method as claimed in claim 4 wherein the password or pass phrase is keyed in at the PEAD.
6. A method as claimed in claim 5 wherein if the password or pass phrase provided to the server is incorrect, the PEAD is informed and the event is recorded.
7. A method as claimed in claim 6 wherein once a certain number of failures due to an uncorrected password or pass phrase have occurred, the users account associated with the private key is deactivated.
8. A method as claimed in claim 7 wherein upon deactivation of the account, the server will refuse to provide the decryption key.
9. A method as claimed in claim 1 wherein the user private key is stored in the PEAD encrypted with a symmetric key scheme.
10. A method as claimed in claim 9 wherein the symmetric key scheme is 3DES.
11. A method as claimed in claim 10 wherein the 3DES key is stored in the remote server associated with an authorization test password or pass phrase for the user.
12. A method as claimed in claim 11 wherein whenever the user needs to authorize a transaction, the user inputs the password or pass phrase at a keyboard at the PEAD.
13. A method as claimed in claim 12 where upon the password or pass phrase being keyed into the PEAD, it is transmitted to the remote server, the remote server returning the symmetric key to the PEAD for decrypting the private key.
14. A method as claimed in claim 13 wherein after finishing the signing process, both the 3DES key and the plain private key, the password or pass phrase entered by the user are deleted from the PEAD.
15. A method as claimed in claim 14 wherein the remote server will monitor and detect any unauthorized attempted access of the symmetric key stored at the server, and notifies the PEAD user through e-mail alert, phone call or message alert.
16. A method as claimed in claim 2 wherein decrypting the user private key includes sending a request from the electronic authorization system to the server including a password from the user of the electronic authorization system.
17. A method as claimed in claim 16 wherein the request includes transmitting a user password or pass phrase.
18. A method as claimed in claim 17 wherein the password or pass phrase is keyed in at the electronic authorization system.
19. A method as claimed in claim 18 wherein if the password or pass phrase provided to the server is incorrect, the electronic authorization system is informed and the event is recorded.
20. A method as claimed in claim 19 wherein once a certain number of failures due to an uncorrected password or pass phrase have occurred, the users account associated with the private key is deactivated.
21. A method as claimed in claim 20 wherein upon deactivation of the account, the server will refuse to provide the decryption key.
22. A method as claimed in claim 2 wherein the user private key is stored in the electronic authorization system encrypted with a symmetric key scheme.
23. A method as claimed in claim 22 wherein the symmetric key scheme is 3DES.
24. A method as claimed in claim 23 wherein the 3DES key is stored in the remote server associated with an authorization test password or pass phrase for the user.
25. A method as claimed in claim 24 wherein whenever the user needs to authorize a transaction, the user inputs the password or pass phrase at a keyboard at the electronic authorization system.
26. A method as claimed in claim 25 where upon the password or pass phrase being keyed into the electronic authorization system, it is transmitted to the remote server, the remote server returning the symmetric key to the electronic authorization system for decrypting the private key.
27. A method as claimed in claim 26 wherein after finishing the signing process, both the 3DES key and the plain private key, the password or pass phrase entered by the user are deleted from the electronic authorization system.
28. A method as claimed in claim 27 wherein the remote server will monitor and detect any unauthorized attempted access of the symmetric key stored at the server, and notifies the electronic authorization system user through e-mail alert, phone call or message alert.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A method of establishing a tunnel from a first interface between a first network and a second network to a second interface between the second network and a third network, the first and third networks operating in accordance with a first transmission protocol and having addresses in accordance with a first addressing convention, and the second network operating in accordance with a second transmission protocol and having addresses in accordance with a second addressing convention, the tunnel being for the transport of messages from a first host on the first network to a second host on the third network, the method comprising:
sending from the first host an address request message in accordance with the first transmission protocol, referred to herein as a first type address request message, containing the name of the second host;
upon receipt of the address request message at a name to address conversion system of the third network, returning an address response message in accordance with the first transmission protocol, referred to herein as a first type address response message, and containing the address of the second host in a response address field;
upon receipt of that first type address response message at the second interface,
converting it to an address response message in accordance with the second transmission protocol, referred to herein as a second type address response message; and
augmenting that converted second type address response message by fields respectively containing the address of the second interface in accordance with the second addressing convention and the address of the second host in accordance with the first addressing convention; and
upon receipt of that augmented that converted second type address response message at the first interface,
converting it to a first type address response message,
retrieving the contents of the augmenting fields,
storing at the first interface a mapping of the retrieved address of the second host and the retrieved address of the second interface for use in encapsulating messages from the first host addressed to the second host, and
replacing the content of the response address field of the resulting first type address response message by the retrieved address of the second host.
2. A method as in claim 1, wherein for establishing a tunnel in the reverse direction for the transport of messages from the second host to the first host, the method further comprises:
upon receipt at the first interface of a message from the first host addressed to the second host, encapsulating that received message in accordance with the first mapping; and
upon receipt of the encapsulated message at the second interface,
un-encapsulating that received encapsulated message,
retrieving from the encapsulating header the address of the first interface in accordance with the second addressing convention,
retrieving from the un-encapsulated message the address of the first host in accordance with the first addressing convention, and
storing at the second interface a mapping of the retrieved address of the first host and the retrieved address of the first interface for use in encapsulating messages from the second host addressed to the first host.
3. A method as in claim 1, including setting a time to live for a said stored mapping, and rendering that stored mapping unuseable upon the expiry of the time to life.
4. A method as in claim 3, wherein the rendering step deletes that stored mapping.
5. A method of sending packets from a first host on a first network via a second network to a second host on a third network, the first and third networks operating in accordance with a first transmission protocol and having addresses in accordance with a first addressing convention, and the second network operating in accordance with a second transmission protocol and having addresses in accordance with a second addressing convention, comprising:
establishing a tunnel from a first interface between the first network and the second network to a second interface between the second network and the third network in accordance with the method of claim 1;
upon receipt by the first host of the resulting first type address response message from the first interface, retrieving the content of the response address field;
generating one or more packets for transmission having a header including source and destination address fields, the source address field containing the address of the first host, and the destination address field containing the retrieved content of the response address field;
sending the or each generated packet to the first interface;
for the or each said generated packet received by the first interface, accessing the stored mappings in accordance with the destination address of the received generated packet,
retrieving the stored interface address of the mapping whose retrieved host address matches the destination address of the received generated packet,
generating an encapsulated packet having a payload formed by the received generated packet, and having a header including source and destination address fields, the source address field containing the address of the first interface, and the destination address field containing the retrieved interface network address,
sending the encapusulated packet to the second interface; and
for the or each encapsulated packet received by the second interface, un-encapsulating the received encapsulated packet to recover the original generated packet forming its payload, and
sending that recovered packet to the second host.
6. A method as in claim 5, including storing the retrieved content in association with the name of the second host.
7. A method as in claim 6, including offsetting a time to live for the stored retrieved content, and rendering that stored retrieved content unuseable upon the expiry of the time to live.
8. A method as in claim 7, wherein the rendering step deletes the stored retrieved content.