Nova Patents
CA2174260A1

Key agreement and transport protocol

Abstract

A key establishment protocol includes the generation of a value of cryptographic function, typically a hash, of a session key and public information. This value is transferred between correspondents together with the information necessary to generate the session key. Provided the session key has not been compromised, the value of the cryptographic function will be the same at each of the correspondents. The value of the cryptographic function cannot be compromised or modified without access to the session key.

CA2174260A1, drawing sheet 1
Sheet 1 of 1

Term

Term ended

Projected expiry passed 16 April 2016, 10.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

19 claims: 2 independent, 17 dependent

  1. 1
    WE CLAIM 1. A method of authenticating a pair of correspondents A,B to permit exchange of information therebetween, each of said correspondents having a respective private key a,b and a public key pA,pB derived from a generator a and respective ones of said private keys a,b, said method including the steps of i) a first of said correspondents A selecting a first random integer x and exponentiating a function f(a) including said generator to a power g® to provide a first exponentiated function f(a)*w;ii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(a) *w ;iii) said correspondent B selecting a second random integer y and exponentiating a function f'(a) including said generator to a power gw to provide a second exponentiated function f'(a)*w;iv) said second correspondent B constructing a session key K from information made public by said first correspondent A and information that is private to said second correspondent B, said session key K also being constructible by said first correspondent A for information made public by B and information that is private to said first correspondent A;v) said second correspondent B generating a value h of a function F[7r,K] where F[tt,K] denotes a cryptographic function applied conjointly to π and K and where π is a subset of the public information provided by B thereby to bind the values of π and K;vi) said second of said correspondents B forwarding a message to said first correspondent A including said second exponential function f'(a)g(y) and said value h of said cryptographic function F[ir,K] ;vii) said first correspondent receiving said message and computing a session key K' from information made public by said second correspondent B and private to said first correspondent A;viii) said first correspondent A computing a value h' of a cryptographic function F[ir,Kr];and ix) comparing said values obtained from said cryptographic functions F to confirm their correspondence.
  2. 11
    A method of transporting a key between a pair of correspondents A,B to permit exchange of information therebetween, each of said correspondents having a respective private key a,b and a public key pA,pB derived from a generator a and respective ones of said private keys a,b, said method including the steps of i) a first of said correspondents A selecting a first random integer x and exponentiating a function f(a) including said generator to a power gw to provide a first exponentiated function f(a)gW;ii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(a)gW;iii) said second correspondent B constructing a session key K from information made public by said first correspondent A and information that is private to said second correspondent B, said session key K also being constructible by said first correspondent A from information made public by B and information that is private to said first correspondent A;iv) both of said first correspondent A and said second correspondents B computing a respective value h,h' of function F[ff,K] where F[tt,K] denotes a cryptographic function applied to π and K and where π is a subset of the public information provided by one of said correspondents;v) at least one of said correspondents comparing said values h,h' obtained from said cryptographic function F to confirm their correspondence;