Nova Patents
CA2525894A1

Key agreement and transport protocol

Abstract

A key establishment protocol includes the generation of a value of cryptographic function, typically a hash, of a session key and public information. This value is transferred between correspondents together with the information necessary to generate the session key. Provided the session key has not been compromised, the value of the cryptographic function will b e the same at each of the correspondents. The value of the cryptographic function cannot be compromised or modified without access to the session key .

CA2525894A1, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Projected expiry passed 17 May 2024, 2.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

5 claims: 2 independent, 3 dependent

  1. 1
    WE CLAIM 1. A method of authenticating a first and second correspondent in a data communication system, the method comprising the steps of:a) said first correspondent generating a first value Ga, and sending said first value to said second correspondent;b) said second correspondent generating a second value Gb;c) said correspondents each obtaining a shared key K;d) said second correspondent computing a first keyed hash of said first and second values and identification information of said first correspondent, said keyed hash using said shared key K;e) said second correspondent sending said first keyed hash, said identification information and said second value to said first correspondent;and f) said first correspondent computing a first verification keyed hash of said first and second values and said identification information of said first correspondent, said verification keyed hash using said shared key K;and g) said first correspondent verifying that said first keyed hash is equal to said first verification keyed hash.
  2. 3
    A method of authenticated key agreement between a first and second correspondent in a data communication system, each of said correspondents having a public and private key pair in a public key encryption system, said method comprising the steps of:a) said first correspondent generating a first value Ga, and sending said first value to said second correspondent;b) said second correspondent generating a second value Gb;c) said correspondents each computing a shared key K from public information of the other correspondent and information that is private to themselves;d) said second correspondent computing a first keyed hash of said first and second values and identification information of said first correspondent, said keyed hash using said shared key K;e) said second correspondent sending said first keyed hash, said identification information and said second value to said first correspondent;and f) said first correspondent computing a first verification keyed hash of said first and second values and said identification information of said first correspondent, said verification keyed hash using said shared key K;and g) said first correspondent verifying that said first keyed hash is equal to said first verification keyed hash.