CA2579259A1

Key agreement and transport protocol with implicit signatures

Abstract

A key establishment protocol between a pair of correspondents includes the generation by each correspondent of respective signatures. The signatures are derived from information that is private to the correspondent and information that is public. After exchange of signatures, the integrity of exchange messages can be verified by extracting the public information contained in the signature and comparing it with information used to generate the signature. A common session key may then be generated from the public and private information of respective ones of the correspondents.

CA2579259A1, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 16 April 2016, 10.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

16 claims: 3 independent, 13 dependent

  1. 1
    WE CLAIM 1. A method of authenticating a pair of correspondents A,B to permit exchange of information therebetween, each of said correspondents having a respective private key a,b and a public key Ρα,Ρβ derived from a generator a and respective ones of said private keys a,b, said method including the steps of i) a first of said correspondents A selecting a first random integer x and exponentiating a function f(a) including said generator to a power g(x) to provide a first exponentiated function f(a)g(x);ii) said first correspondent A generating a first signature sA from said random integer x and said exponentiated function f(a)g(x);iii) said first correspondent A forwarding to a second correspondent B a first message including said first exponentiated function f(a)g(x) and said signature sA;iv) said correspondent B selecting a second random integer y and exponentiating a function f1(a) including said generator to a power g(y) to provide a second exponentiated function f’ (a)g(y) and generating a signature sB obtained from said second integer y and said second exponentiated function f’ (a)g(y) ;v) said second correspondent B forwarding a second message to said first correspondent A including said second exponentiated function f' (a)g(y) and said signature sB;21604482.1 CA 02579259 2007-03-07 vi) each of said correspondents verifying the integrity of messages received by them by computing from said signature and said exponentiated function in such a received message a value equivalent to said exponentiated function and comparing said computed value and the value of said exponentiated function transmitted thereto;vii) each of said correspondents constructing a session key K by exponentiating information made public by another correspondent with said random integer that is private to itself .
  2. 13
    14. A method according to of correspondent B is of a form (p-1);where rB is derived from
  3. 14
    15. A method according to of correspondent B is of a form (p-1) .