Nova Patents
CA2487903C

Key agreement and transport protocol

Abstract

A key establishment protocol based on exponential key exchange techniques included the generation of a value of cryptographic function, typically a hash, of a session key and public information. This value is transferred between correspondents together with the information necessary to generate the session key. Provided the session key has not been compromised, the value of the cryptographic function will be the same at each of the correspondents. The value of the cryptographic function cannot be compromised or modified without access to the session key.

CA2487903C, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Expired 7 March 2023, 3.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

25 claims: 6 independent, 19 dependent

  1. 1
    CA 02487903 2014-11-04 PCT/CA/03/00317 WE CLAIM:1. A method of authenticated key exchange between a first correspondent and a second correspondent in a data communication system, said method comprising the steps of: (a) said first correspondent generating a first public value G A for use as a session public key and sending to said second correspondent said first public value G A and a value x 2 indicating that said first correspondent wants receipt confirmed by said second correspondent;(b) said second correspondent generating a second public value G B for use as another session public key, obtaining a shared key K, generating a value y, that said second correspondent wants to have authenticated by said first correspondent, generating a value y 2 indicating that said second correspondent wants receipt confirmed by said first correspondent, and computing a first keyed hash of said first public value G A , said second public value G B , said value x 2 , said value y 1( and identification information of one of said first correspondent and said second correspondent, said first keyed hash using said shared key K;(c) said second correspondent sending said first keyed hash, said second public value G b , said identification information of one of said first correspondent and said second correspondent, said value y-ι, and said value y 2 to said first correspondent;(d) said first correspondent obtaining said shared key K and computing a first verification keyed hash of said first public value G A , said second public value G B , said value x 2 , said value y-ι, and said identification information of one of said first correspondent and said second correspondent, said first verification keyed hash using said shared key K;and (e) said first correspondent verifying that said first keyed hash equals said first verification keyed hash, wherein a successful verification of said first keyed hash indicates receipt of said value x 2 by said second correspondent.
  2. 4
    The method according to any one of claims 1 to 3 wherein said shared key K is obtained by said first correspondent by combining information private to said first correspondent with public information of said second correspondent, and said shared key K is obtained by said second correspondent by combining information private to said second correspondent with public information of said first correspondent.
  3. 6
    The method according to any one of claims 1 to 5 wherein said value x 2 equals E K (k), the result of applying an encryption function E with said shared key K on a value k, and wherein said second correspondent retrieves the value k from said value x 2 and uses said value k as a shared session key with said first correspondent.
  4. 7
    The method according to any one of claims 1 to 6 wherein said value y! equals E K (k 21 ) and said value z-i equals E K (k 12 ), wherein k 21 and k 12 are either different keys or secret information to be shared between said first correspondent and said second correspondent.
  5. 8
    A method of authenticated key exchange between a first correspondent A and a second correspondent B in a data communication system, said method comprising the steps of:(a) said first correspondent A generating a first public value G A for use as a session public key and sending to said second correspondent B said first value G A and a value x 2 indicating that said first correspondent A wants receipt confirmed by said second correspondent B;(b) said first correspondent A receiving from said second correspondent B a second public value G B used by said second correspondent B as a session public key, a value yi indicating that said second correspondent B wants to have authenticated by said first correspondent A, a value y 2 that said second correspondent B wants receipt confirmed by said first correspondent A, identification information of one of said first correspondent A and said second correspondent B, and a first keyed hash of: said first public value G A , said second public value G B , said value x 2 , said value y n and said identification information of one of said first correspondent A and said second correspondent B, said first keyed hash using a shared key K obtained by said second correspondent B;(c) said first correspondent A obtaining said shared key K;and said first correspondent A computing a first verification keyed hash of said first public value G A , said second public value G B , said value x 2 , said value y 1t and said identification 22631151.1 CA 02487903 2014-11-04 PCT/CA/03/00317 information of one of said first correspondent A and said second correspondent B, said first verification keyed hash using said shared key K;and (d) said first correspondent A verifying that said first keyed hash equals said first verification keyed hash, wherein a successful verification of said first keyed hash indicates receipt of said value x 2 by said second correspondent.
  6. 11
    The method according to any one of claims 8 to 10 wherein said shared key K is obtained by said first correspondent A by combining information private to said first correspondent A with public information of said second correspondent B.
  7. 13
    The method according to any one of claims 8 to 12 wherein said value x 2 equals E K (k), the result of applying an encryption function E with said shared key K on a value k, and wherein said value k is retrievable by said second correspondent B and is used as a shared session key with said first correspondent A.
  8. 14
    The method according to any one of claims 8 to 13 wherein said value yi equals E K (k 21 ) and said value z·, equals E K (k 12 ), wherein k 21 and k 12 are either different keys or secret information to be shared between said first correspondent A and said second correspondent B.
  9. 15
    A method of authenticated key exchange between a first correspondent A and a second correspondent B in a data communication system, said method comprising the steps of:(a) said second correspondent B receiving from said first correspondent A a first public value G A used by said first correspondent A as a session public key, and a value x 2 that said first correspondent A wants receipt confirmed by said second correspondent B;(b) said second correspondent B generating a second public value G B used as a session public key, obtaining a shared key K, generating a value y 3 that said second correspondent B wants to have authenticated by said first correspondent A, generating a value y 2 that said second correspondent B wants receipt confirmed by said first correspondent A, and computing a first keyed hash of said first public value G a , said second public value G B , said value x 2 , said value y 3 , and identification information of one of said first correspondent A and said second correspondent B, said first keyed hash using said shared key K;(c) said second correspondent B sending to said first correspondent A said first keyed hash, said identification information of one of said first correspondent A and said second correspondent B, said second public value G B , said value y n and said value y 2 , whereby said first correspondent is able to use said first public value G A , said second public value G B , said value x 2 , said value y 1( and said identification information of one of said first correspondent A and said second correspondent B to compute a first verification keyed hash and to verify said first keyed hash equals said 22631151.1 CA 02487903 2014-11-04 PCT/CA/03/00317 first verification keyed hash, wherein a successful verification of said first keyed hash indicates receipt of said value x 2 by said second correspondent;(d) said second correspondent B receiving from said first correspondent A a second keyed hash using said shared key K, identification information of another of said first correspondent A and said second correspondent B, and a value ζ Ί that said first correspondent A wants to have authenticated by said second correspondent B;(e) said second correspondent B computing a second verification keyed hash of said first public value G A , said second public value G B , said value y 2 , said value z 1t and said identification information of another of said first correspondent A and said second correspondent B, said second verification keyed hash using said shared key K;and (f) said second correspondent B verifying that said second verification keyed hash is equal to said second keyed hash, whereby a successful verification of said second keyed hash indicates receipt of said value y 2 by said second correspondent.
  10. 18
    The method according to any one of claims 15 to 17 wherein said value x 2 equals E K (k), the result of applying an encryption function E with said shared key K on a value k, and wherein said second correspondent B retrieves said value k from said value x 2 and uses said value k as a shared session key with said first correspondent A. 22631151.1 CA 02487903 2014-11-04 PCT/CA/03/00317
  11. 19
    The method according to any one of claims 15 to 18 wherein said value yi equals E K (k 21 ) and said value z-, equals E K (k 12 ), wherein k 21 and k 12 are either different keys or secret information to be shared between said first correspondent A and said second correspondent B.
  12. 20
    The method according to any one of claims 15 to 19 wherein said second correspondent B receives from said first correspondent A a value z 2 to be used during a subsequent session.
  13. 21
    The method according to any one of claims 1 to 20 wherein method steps are performed using an underlying elliptic curve.
  14. 22
    The method according to any one of claims 1 to 21 wherein each said keyed hash is a cryptographic hash.
  15. 23
    A system comprising a first correspondent and a second correspondent configured to perform the method steps of any one of claims 1 to 7.
  16. 24
    A device comprising a correspondent configured to perform the method steps of any one of claims 8 to 20.
  17. 25
    A computer readable medium having stored thereon computer readable instructions for performing the method of any one of claims 8 to 20. 22631151.1
Independent claims17