Nova Patents
CA2746830C

Acceleration of key agreement protocols

Abstract

The generation of a shared secret key K in the implementation of a key agreement protocol, for example MQV, may be optimized for accelerated computation by selecting the ephemeral public key and the long-term public key of a correspondent to be identical. One correspondent determines whether the pair of public keys of the other correspondent are identical. If it is, a simplified representation of the shared key K is used which reduces the number of scalar multiplication operations for an additive group or exponentiation operations for a multiplicative group. Further optimisation may be obtained by performing simultaneous scalar multiplication or simultaneous exponentiation in the computation of K.

CA2746830C, drawing sheet 1
Sheet 1 of 22

Term

3.2 yearsleft in the term

Expires 16 December 2029.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

29 claims: 26 independent, 3 dependent

  1. 1
    CA 02746830 2015-02-18 1 CLAIMS:
  2. 2
    2 That which is claimed is:
  3. 3
    ' . ' :< /
  4. 4
    4 1. A method of generating a shared key at one of a pair of correspondents participating
  5. 5
    5 in a public key cryptosystem, said shared key to be used by said one correspondent in
  6. 6
    6 communicating with another correspondent over a data communication channel, each of said
  7. 7
    7 correspondents respectively having a long-term private key and a corresponding long-term
  8. 8
    8 public key, and said shared key having the form of a combination of a long-term private key
  9. 9
    9 of one of said correspondents with a long-term public key and an ephemeral public key of
  10. 10
    10 another of said correspondents, said method comprising the steps of:
  11. 11
    11 a) said one correspondent obtaining said long-term public key of Said other
  12. 12
    12 correspondent;
  13. 13
    13 b) said one correspondent determining whether said ephemeral public key of said
  14. 14
    14 other correspondent is the same as said long-term public key of said other
  15. 15
    15 correspondent;
  16. 16
    16 c) upon determining that said long-term public key and said ephemeral public
  17. 17
    17 key of said other correspondent are the same, said one correspondent utilising said long-term
  18. 18
    18 public key of said other correspondent as both said long-term public key and said
  19. 19
    ephemera] public key of said other correspondent in generating said shared key, and
  20. 20
    20 d) utilising said shared key to exchange information between said
  21. 21
    21 correspondents.
  22. 23
    24 public key and said ephemeral public key of said other correspondent are the same, said one
  23. 24
    25 correspondent generates said shared key by computing an equivalent representation of said
  24. 25
    26 combination.
  25. 27
    29 value of said one correspondent with said long-term public key of said other correspondent,
  26. 28
    30 and said intermediate value binds said long-term private key and long-term public key of said
  27. 29
    31 one correspondent with an ephemeral private key of said one correspondent. -25 CA 02746830 2011-06-14 4. The method according to any one of claims 3 or 4 wherein said cryptosystem is implemented over an additive group and said shared key is dependent on (R B + RbQ b ) , R B is an ephemeral public key of said other correspondent, Q B is a long-term public key of said other correspondent and Rb is an integer derived from R B , and said method further includes the step of said one correspondent computing said shared key K from an equivalent representation having the form vQ B , where v is dependent on (1 + Rb) . 5. The method according to claim 4 wherein said shared key is generated according to an ECMQV key agreement protocol and has the form K = hs A (R B + RbQ b ) where h is the cofactor of an elliptic curve group and s A is said intermediate value, said method further including the step of computing said shared key K as v Q B where v -hs A () + Rb ). 6. The method according to claim 3 wherein said shared key is generated according to an MQV key agreement protocol implemented over a multiplicative group and requires a shared key of the form K = (R B (Q B ) B ) sA where Àfiis the ephemeral public key of the other correspondent, Qb is the long-term public key of said other correspondent, R b is an integer derived from said ephemeral public key, and s A is said intermediate value, said method further including the step of computing said shared key as Rb , where y = hs A R B + hs A and h is the cofactor of the group. Ί. The method according to claim 3 wherein said shared key is generated according to an MTI key agreement protocol and has the form K = (a y ) a Ζβ Χ where a is an ephemeral public key of said other correspondent, Zb is a long-term public key of said other correspondent, x is an ephemeral private key of said one correspondent and a is a long-term private key of said one correspondent, and said method includes the step of said one correspondent computing said shared key as K = (Zb) o+x . -26CA 02746830 2011-06-14 8. The method according to any one of claims 2 to 7 including the step of comparing said short term public key and said long-term public key received from said other correspondent to determine if said keys are the same. 9. The method according to any one of claims 2 to 7 including the step of examining a message received from said other correspondent for an indicator that said public keys are the same and computing said equivalent representation upon identifying said indicator. 10. The method according to any one of claims 2 to 7 wherein said equivalent representation is a linear combination of said long-term public key and said method includes the steps of accumulating said shared key from precomputed values derived from said longterm public key. 11. The method according to claim 10 wherein said cryptosystem is implemented over an additive group and said precomputed values are multiples of said long-term public key. 12. The method according to claim 10 wherein said cryptosystem is implemented over a multiplicative group and said precomputed values are results of exponentiation of said longterm public key. 13. A cryptographic system having a pair of correspondents communicating over a communication link and sharing a shared key, said shared key being generated by at least one of said correspondents according to the method of any one of claims 1 to 12. 14. A cryptographic module associated with one correspondent in a cryptographic system, said module comprising:- a controller;an arithmetic logic unit operable to generate a shared key from a combination of ephemeral and long-term public keys of another correspondent and a private key of the one correspondent;and a comparator operable to determine whether said ephemeral public key and long-term public key of said other correspondent are the same;-27CA 02746830 2014-01-20 wherein said controller is operable to instruct said arithmetic unit to utilise said long-term public key as said ephemeral public key in the computation of said shared key if said comparator determines that said keys are the same. 15. The cryptographic module according to claim 14 wherein said controller is operable to direct said arithmetic logic unit to compute an equivalent representation of said combination in computing said shared key. 16. The cryptographic module according to claim 15 wherein precomputed values derived from said long-term public key of said other correspondent are stored in a memory and said arithmetic logic unit is operable to use said precomputed values in computing said shared key. 17. The cryptographic module according to claim 14 wherein said comparator is operable to compare a pair of values representing said long-term public key and said ephemeral key. 18. The cryptographic module according to claim 14 wherein said comparator is operable to compare an indicator with a known value, the indicator based on a pair of values representing said long-term public key and said ephemeral key. -2822495970.1
Independent claims27