AU1109483A

Encryption system key distribution method and apparatus

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 11 January 2003, 23.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 17 independent, 0 dependent

  1. 1
    Claims 1. A key distribution method for communicating cipher keys between two terminals via a key distribution center, KDC, said method comprising 5 establishing between any one terminal and said key distribution center a terminal-unique cipher key, cooperating between said KDC and said one terminal on a subsequent connection between said KDC and said one terminal to establish a session key for use by said one 10 terminal in a subsequent secure transmission between said one terminal and a second terminal, and changing in response to said subsequent connection between said one terminal and said KDC said priorly established terminal-unique cipher key. 15 2. The invention set forth in claxm 1 wherein said session key is generated from the asymmetric exchange of information' between said one terminal and said KDC plus the subsequent exchange of information between said first and second terminals. 20 3. The invention set forth in claim 2 wherein said session key at said one terminal is random with respect to information at said KDC. 4. The invention set forth in claim 2 wherein said session key at said one terminal is underivable with 25 respect to any information at said KDC. ·♦· 5. A key distribution center for controlling the dissemination of session cipher keys between remotely located terminals, said center arranged for switched access to a plurality of said terminals, said center comprising 30 means for establishing communication cipher keys between said center and each said terminal having access thereto, each cipher key unique to each said terminal, means operative when one of said terminals 'gOREA^ OMH accesses said center for bidirectional asymmetrically 35 exchanging information with said accessed terminal using, as a foundation for said exchange, said priorly establish d communication cipher keys, and SUBSTITUTE SHEET Ά WO 83/04461 PCT/US83/00030 means responsive to said exchanged information for communicating to said terminal information allowing said terminal to establish a session cipher key for use with an identified other terminal also having access to said center. 6. The invention set forth in claim 5 wherein said key distribution center further comprising means for changing said established communication cipher keys as a result of said exchanged information. 7. The invention set forth in claim 5 wherein said cipher key establishing means uses information from a prior transmission from a particular terminal for establishing said cipher keys to said particular terminal. 8. The invention set forth in claim 5 wherein ···· said exchanged information includes information generated . · · · in part at said center for the random generation of said * ·· · ··· session key allowing said session key to be underivable with respect to any information at said center. i*··;· 9. λ key distribution center for controlling the!..... distribution of cipher control information among a number of terminals, said center comprising means for individually exchanging encoded information between any of said terminals, said exchange %*·’· for any particular terminal based partially upon a last ·· · information exchange between said particular terminal and said center, !..... · · means for identifying at least two terminals wherj=ja · encrypted session information is to be exchanged and for accepting from said identified terminals certain encryption··, control information, and ·..... · · means for modifying, according to a pre-established pattern, accepted information from said identified terminals and for communicating said modified information to the other of said terminals so as to allow each of said terminals to thereafter establish, independent of any information available at said center, a cipher key allowing said session information to be encrypted. SUBSTITUTE SHEET WO 83/04461 PCT/US83/00030 1/17 FIG. I KDC CONFIGURATION TERMINAL TERMINAL A B TERMINAL X OMH X WIPO WO 83/04461 PCT/US83/00030
  2. 2
    2/17 ··· 0· FIG. 2 INITIAL SYSTEM SETUP « 0·· • ·· 0 · • · 0 · UREAcZ OMPI WO 83/04461 PCT/US83/00030
  3. 3
    3/17 ··· ·· FIG. 3 TERMINAL A A .FROM FIG. <1 1 L J RE AT/\ OMPI λ WO 83/04461 PCT/l )883/00030
  4. 4
    4/17 /76 4 TERMINAL A ·« ·9· WO 83/04461 PCT/US83/00030
  5. 5
    5/17 FIG. 5 KDC WO 83/C4461 PCT/US83/00030
  6. 6
    6/17 FIG. 6 BETWEEN CALLS IDLE STATE (FOR TERMINAL A) »··* ···· ···· • · · ·· · • · ···» e <* SEMI-PERM REGISTER TEMP REGISTER TERMINAL A ADDRESS FIG. 7 START OF SECURE CALL (A TO B) SETUP-GENERATION OF KDC-A LINK KEYS .jj FCT/US83/00030 WO 83/04461 ·· · · • · · · • ·· · • · · • · · • · · ·
  7. 7
    7/17 FIG. 8 GENERATION OF B-A LINK KEYS FIG. 9 FIRST STEP IN UPDATE OF VERIFICATION INFORMATION ?CT/t)583/00030 WO 83/04461
  8. 8
    8/17 FIG. /0 SECOND STEP IN UPDATE OF VERIFICATION INFORMATION SEMI-PERM REGISTER TEMP REGISTER F!6. // COMPUTATION OF A-KDC MESSAGE • · • · · • · ······
  9. 9
    9 · ····· • · «. .· . WO 83/04461 PCT/US83/OOO30 -9/17 F/G. !2 IDLE STATE WHILE WAITING FOR RETURN MESSAGE FROM KDC • · · · • · · · • · · · • · · • · · • · « · • · β · ·φ SEMI-PERM REGISTER TEMP REGISTER TERMINAL A ADDRESS FIG. !3 DECRYPTION OF RETURN MESSAGE FROM KDC TERMINAL A WO 83/04461 PCT/US83/00030 9· · 9 9 «·«· 9 99 9 9 99 9 99 9 9 9 9 9 9 9 9 9 9 9 9 9 9
  10. 10
    10/17 FIG. 14 VERIFICATION CHECK I SEMI-PERM REGISTER TEMP REGISTER IF (ZERO) THEN CONTINUE ELSE WARN CUSTOMER OF SUSPECTED INTRUDER I TERMINAL A ADDRESS •99999 9 · FIG. !5 START OF KEY EXCHANGE WITH B CALCULATION OF DIFFIE-HELLMAN KEYS WO 83/04461 PCT/US83/00030 • « · · ' · ···· • ·· · • 9 · ®β β ···· • · • · · ·
  11. 11
    11/17 FIG. /6 IDLE WAIT STATE FOR RETURN MESSAGE FROM B SEMI-PERM REGISTER TEMP REGISTER I TERMINAL A ADDRESS TERMINAL A SEMI-PERM REGISTER F/G. 17 DECRYPTION OF MESSAGE FROM B AND CALCULATION OF SESSION TEMP REGISTER' ZERO WO 83/04461 PCT/US83/00030 ·'
  12. 12
    12/17 F/G. 18 KEY STORAGE DURING CALL SEMI-PERM REGISTER TEMP REGISTER F/G. /9 IDLE STATE FOLLOWING CALL COMPLETION • · ··· ·· «· • « • ·
  13. 13
    13/17 WO 83/04461 PCT/US83/00030 ·· · · ·« ·· <\··· • · · • Λ · • · · · • · • · ·· • · · ο β · • · FIG. 20 IDLE STATE BETWEEN CALLS FIG. 2! DECRYPTION OF MESSAGE FROM A WO 83/04461 PCT/US83/00030 '
  14. 14
    14/17 • ft · · • ·« e • ·· · ·· · ···· • · · · · · • · FIG. 22 FIRST STEP IN THE UPDATE OF VERIFICATION INFORMATION FIG. 23 SECOND -STEP’THE UPDATE OF VERIFICATION INFORMATION WO 83/04461 PCT/US83/00030
  15. 15
    15/17 • · · • · · · • · »· • ·· · • · · • · · • · · · • · • « · · FIG. 24 GENERATION OF NEW KDC-A LINK KEYS FIG. 25 GENERATION OF DIFFIE-HELLMAN ALGORITHM PARAMETERS PCT/US83/00030
  16. 16
    16/17 WO 83/04461 • et» ···· ···· • · · a » · • ·· « • « ···· 9«···· • * FIG. 26 INTERNAL EXCHANGE OF INFORMATION BETWEEN A & B'S REGISTERS • * >· « «I WO 83/04461 PCT/US83/00030
  17. 17
    17/17 • « > · • '· »W ··· · • e ♦ ·-· · ··· · • · ··«« · «····· • a ······ » · ·» ·· • · · • · • *· • · « • «4 fl ··<··· • · € · · FIG. 28 IDLE STATE BETWEEN CALLS
Independent claims17