F
ILE
A
UTHENTICATION
Introduction to File Authentication
34
V200
C
R
EFERENCE
G
UIDE
Special Files Used
in the File
Authentication
Process
The following specially formatted files support the FA process:
•
A
digital certificate
(*crt file)
is a digital public document used to verify the
signature of a file.
•
A
digital signature
(*.p7s file) is a piece of information based on both the file
and the signer’s private cryptographic key. The file sender digitally signs the
file using a private key. The file receiver uses a digital certificate to verify the
sender’s digital signature.
•
Signer private keys
are securely conveyed to clients on smart cards. On
V200c, private keys are not kept in files. The secret passwords required by
clients to generate signature files, using signer private keys, are sent as PINs
over a separate channel such as registered mail or encrypted e-mail.
Digital certificates and signature files, do not need to be kept secure to safeguard
the overall security of VeriShield.
The special file types that support the file authentication process are recognized
by their filename extensions.
All digital certificates are generated and managed by the Verifone CA, and are
distributed on request to terminal clients—either internally within Verifone or
externally to sponsors.
All certificates issued by the Verifone CA for the terminal platform, and for any
Verifone platform with the VeriShield security architecture, are hierarchically
related. That is, a lower-level certificate can only be authenticated under the
authority of a higher-level certificate.
The security of the highest-level certificate, called the platform root certificate, is
tightly controlled by Verifone.
The required cryptographically related private keys that support the file
authentication process are also generated and distributed by the Verifone CA.
Certificates Contain Keys That Authenticate Signature Files
•
Sponsor certificate: Certifies a client’s sponsorship of the terminal. It does not,
however, convey the right to sign and authenticate files. To add flexibility to the
business relationships that are logically secured under the file authentication
process, a second type of certificate is usually required to sign files.
Table 5
VeriShield File Signing Tool Filename Extensions
File Type
Extension
Signature
*.p7s
Digital certificate
*.crt
Summary of Contents for V200c
Page 1: ...Verifone Part Number DOC420 004 EN B Revision B V200c Reference Guide...
Page 8: ...PREFACE Conventions and Acronyms 8 V200C REFERENCE GUIDE...
Page 14: ...USING THE TERMINAL KEYS The Keypad 14 V200C REFERENCE GUIDE...
Page 32: ...SYSTEM MODE System Mode Menus 32 V200C REFERENCE GUIDE...
Page 56: ...SYSTEM MESSAGES Information Messages 56 V200C REFERENCE GUIDE...
Page 60: ...PORT PINOUTS V200c Port Pinout Definitions 60 V200C REFERENCE GUIDE...
Page 62: ...ASCII TABLE The ASCII Table 62 V200C REFERENCE GUIDE...