CA2176972C

Key agreement and transport protocol with implicit signatures

Abstract

A key establishment protocol between a pair of correspondents includes the generation by each correspondent of respective signatures. The signatures are derived from information that is private to the correspondent and information that is public. After exchange of signatures, the integrity of exchange messages can be verified by extracting the public information contained in the signature and comparing it with information used to generate the signature. A common session key may then be generated from the public and private information of respective ones of the correspondents.

CA2176972C, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 16 May 2016, 10.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

1 claim: 1 independent, 0 dependent

  1. 1
    CA 02176972 2007-10-23 21. A method of establishing a session key between a pair of correspondents A, B in a public key data communication system to permit exchange of information therebetween over a communication channel, each of said correspondents having a respective private key a, b and a public key p A , Pb derived from a generator a and respective ones of said private keys a, b, said method comprising:i) a first of said correspondents A selecting a first random integer x and exponentiating a first function f(a) including said generator to a power g(x) to provide a first exponentiated function f(a) g(x) ;ii) said first correspondent A generating a first signature s A from said random integer x said exponentiated function f(a) gW ;iii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(a) g(x) ;iv) said first correspondent receiving from said correspondent B, a message including a second exponentiated function f'(a) g(y) , said second exponentiated function f'(a) g(y) having been generated by exponentiating a second function f(a) including said generator to a power g(y), said correspondent B having selected a second random integer y and having generated a signature Sb obtained from said second integer y and said second exponentiated function f(a) g(y) ;and vi) said first correspondent A constructing a session key K by exponentiating information made public by said second correspondent B with information that is private to said first correspondent A. 22. A method according to claim 21 wherein said message forwarded by said first correspondent includes an identification of the first correspondent. 23. A method according to claim 21 wherein said message forwarded by said second correspondent includes an identification of said second correspondent. 24. A method according to claim 23 wherein said message forwarded by said first correspondent includes an identification of the first correspondent. 21691396.1 CA 02176972 2007-10-23 25. A method according to claim 21 wherein said first function f(a) including said generator is said generator itself. 26. A method according to claim 21 wherein said second function f'(a) including said generator is said generator itself. 27. A method according to claim 26 wherein said first function f(a) including said generator is said generator itself. 28. A method according to claim 21 wherein said first function f(a) including said generator includes the public key p B of said second correspondent. 29. A method according to claim 21 wherein said second function f'(a) including said generator includes the public key p A of said first correspondent A. 30. A method according to claim 21 wherein said signature generated by a respective one of the correspondents combine the random integer, exponentiated function and private key of that one correspondent. 31. A method according to claim 30 wherein said signature s A of correspondent A is of the form x-r A aa a mod (p-1). 32. A method according to claim 30 wherein said signature s A of correspondent A is of the form x + aa“ (p B ) x mod(/? -1). 33. A method according to claim 30 wherein said signature s A of correspondent A is of the form ~(r a Y'' aa“ mod(/? -1) where xi is a second random integer selected by A and r = a V| . 34. A method according to claim 30 wherein said signature s B of correspondent B is of the form y + r B ba b mod(/ -1). 21691396.1 CA 02176972 2007-10-23 35. A method according to claim 30 wherein said signature Sb of correspondent B is of the form y + ba b (p A ) v mod(/? -1). 36. A method according to claim 30 wherein said signature Sb of correspondent B is of the form yr ~/β5' boc b mod(p-l) where yi is a second integer selected by correspondent B and r. =a y '. 1 37. A method according to claim 31 wherein said correspondent A selects a second integer xi and forwards f A to correspondent B where = o/' and said correspondent B selects a second random integer y, and sends to correspondent A, where r Bj — Ot each of said correspondents computing a pair of keys k b k 2 equivalent to a xy and a x ' y ' respectively, said session key K being generated by XORing ki and k 2 . 38. A method according to claim 21 wherein said first signature Sa is also generated from said private key a to bind said integer x and said private key a;said second signature s B is also generated from said private key b to bind said integer y and said private key b;and whereby subsequent decryption of information confirms establishment of a common key and thereby the identity of said second correspondent B. 39. A computer readable medium comprising computer executable instructions for performing the steps according to any one of claims 21 to 38. 40. A cryptographic unit operable to execute computer readable instructions for performing the steps according to any one of claims 21 to 38. 21691396.1