CPC H04L 9/0869 (2013.01) [H04L 9/0643 (2013.01); H04L 9/085 (2013.01); H04L 9/32 (2013.01)] | 20 Claims |
1. A method for securely sharing and authenticating a last secret, the method comprising:
generating, by a cryptographic module on a first network node, a seed and an envelope around the seed, the seed configured for deriving or recovering a last secret being a last cryptographic element controlling access to a secure entity; and
transmitting, by the cryptographic module, the seed to a computing system on a second node different than the first node, the computing system being configured to decrypt the envelope of the enveloped seed to recover the seed, and obtain the last secret based on the seed,
wherein the cryptographic module is prevented from deriving the last secret.
|