Nova Patents
CA2746830A1

Acceleration of key agreement protocols

Abstract

The generation of a shared secret key K in the implementation of a key agreement protocol, for example MQV, may be optimized for accelerated computation by selecting the ephemeral public key and the long-term public key of a correspondent to be identical. One correspondent determines whether the pair of public keys of the other correspondent are identical. If it is, a simplified representation of the shared key K is used which reduces the number of scalar multiplication operations for an additive group or exponentiation operations for a multiplicative group. Further optimisation may be obtained by performing simultaneous scalar multiplication or simultaneous exponentiation in the computation of K.

CA2746830A1, drawing sheet 1
Sheet 1 of 20

Term

3.2 yearsto projected expiry

Projected expiry 16 December 2029, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

18 claims: 3 independent, 15 dependent

  1. 1
    CA 02746830 2011-06-14 WO 2010/069063 PCT/CA2009/001846 CLAIMS:That which is claimed is: 1. The method of generating a shared key at one of a pair of correspondents participating in a public key cryptosystem, said shared key to be used by said one correspondent in communicating with another correspondent over a data communication channel, each of said correspondents respectively having a long-term private key and a corresponding long-term public key, and said shared key having the form of a combination of a long-term private key of one of said correspondents with a long-term public key and an ephemeral public key of another of said correspondents, said method comprising the steps of: a) said one correspondent obtaining said long-term public key of said other correspondent;b) said one correspondent determining whether said ephemeral public key of said other correspondent is the same as said long-term public key of said other correspondent;c) upon determining that said long-term public key and said ephemeral public key of said other correspondent are the same, said one correspondent utilising said long-term public key of said other correspondent as both said long-term public key and said ephemeral public key of said other correspondent in generating said shared key, and d) utilising said shared key to exchange information between said correspondents.
  2. 4
    The method according to any one of claims 3 or 4 wherein said cryptosystem is implemented over an additive group and said shared key is dependent on (R B + RbQ b ), R b is an ephemeral public key of said other correspondent, Q B is a long-term public key of said other correspondent and Rb is an integer derived from R B , and said method further includes the step of said one correspondent computing said shared key K from an equivalent representation having the form vQ B , where v is dependent on (1 + Rn).
  3. 8
    The method according to any one of claims 2 to 7 including the step of comparing said short term public key and said long-term public key received from said other correspondent to determine if said keys are the same.
  4. 9
    The method according to any one of claims 2 to 7 including the step of examining a message received from said other correspondent for an indicator that said public keys are the same and computing said equivalent representation upon identifying said indicator.
  5. 10
    The method according to any one of claims 2 to 7 wherein said equivalent representation is a linear combination of said long-term public key and said method includes the steps of accumulating said shared key from precomputed values derived from said longterm public key.
  6. 13
    A cryptographic system having a pair of correspondents communicating over a communication link and sharing a shared key, said shared key being generated by at least one of said correspondents according to the method of any one of claims 1 to 12.
  7. 14
    A cryptographic module associated with one correspondent in a cryptographic system, said module comprising ία controller;an arithmetic logic unit operable to generate a shared key from a combination of ephemeral and long-term public keys of another correspondent and a private key of the one correspondent;and a comparator operable to determine whether said ephemeral public key and long-term public key of said other correspondent are the same;-27CA 02746830 2011-06-14 WO 2010/069063 PCT/CA2009/001846 wherein said controller is operable to instruct said arithmetic unit to utilise said long-term public key as said ephemeral public key in the computation of said shared key if said comparator determines that said keys are the same.