Special Files Used In The File Authentication Process - VeriFone VX 680 Reference Manual

Hide thumbs Also See for VX 680:
Table of Contents

Advertisement

F
A
ILE
UTHENTICATION
Introduction to File Authentication
Special Files Used
in the File
Authentication
Process
56
VX 680 R
EFERENCE
The following specially formatted files support the file authentication process:
A digital certificate is a digital public document used to verify the signature of
a file.
A digital signature is a piece of information based on both the file and the
signer's private cryptographic key. The file sender digitally signs the file using
a private key. The file receiver uses a digital certificate to verify the sender's
digital signature.
Signer private keys (*.key files) are securely conveyed to clients on smart
cards. The secret passwords required by clients to generate signature files,
using signer private keys, are sent as PINs over a separate channel such as
registered mail or encrypted e-mail.
Some files, such as private key files, are encrypted and password protected for
data security. Others, such as digital certificates and signature files, do not need
to be kept secure to safeguard the overall security of VeriShield Retain.
Within the VeriShield File Signing Tool tool, you can recognize the special file
types that support the file authentication process by the filename extensions listed
in
Table
8.
Table 8
VeriShield File Signing Tool Filename Extensions
File Type
Signature
Private key
Digital certificate
All digital certificates are generated and managed by the Verifone CA, and are
distributed on request to VX 680 clients—either internally within Verifone or
externally to sponsors.
All certificates issued by the Verifone CA for the VX 680 platform, and for any
Verifone platform with the VeriShield Retain security architecture, are
hierarchically related. That is, a lower-level certificate can only be authenticated
under the authority of a higher-level certificate.
The security of the highest-level certificate, called the platform root certificate, is
tightly controlled by Verifone.
Certificates Contain Keys That Authenticate Signature Files
Sponsor certificate: Certifies a client's sponsorship of the terminal. It does not,
however, convey the right to sign and authenticate files. To add flexibility to the
business relationships that are logically secured under the file authentication
process, a second type of certificate is usually required to sign files.
G
UIDE
Extension
*.p7s
*.key
*.crt

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents