Nova Patents
EP0223122A2

Secure component authentication system.

Abstract

A system for authenticating components in a communications system using cryptographic techniques to determine if each has the proper key without disclosing information which would be useful to an impostor in deriving the key. A random number (32) generated at a first terminal is encrypted under its key (K1) for transmission as a first value (X) to a second terminal whose identity is to be authenticated. The second terminal decrypts the transmitted first value using its key (K2) deriving a second value (which equals the random number if the keys are identical.) The second terminal then encrypts its key using the second value as the key, generating a third (Z) value which is transmitted back to the first terminal for verification. The first terminal then verifies the third value, either by decrypting it using the random number as the key to obtain its key or by encrypting its key using the random number as key to derive the third number (if the two keys are identical.) Optionally, roles of the two terminals are then reversed after the second terminal has been identified, allowing the second terminal to authenticate the first terminal.

EP0223122A2, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 28 October 2006, 19.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

9 claims: 4 independent, 5 dependent

  1. 1
    A method whereby a first terminal (20) may authenticate a second terminal (10) wherein the terminals each posses an encryption key (K1,K2) and the second terminal is authenticated if the encryption keys are equal, the steps of the method comprising:generating a first number (RN) at the first terminal and creating a second number (X) by encrypting the first number using the encryption key K1 of the first terminal;transmitting the second number to the second terminal;generating a third number (Y) at the second terminal by decryping the second number using the encryption key (K2) of the second terminal;generating a fourth number (Z) at the second terminal by encrypting the encryption key of the second terminal using the third number as the key;transmitting the fourth number to the first terminal;and verifying at said first terminal that said fourth number equals the encryption of said encryption key of said first terminal using said first number as key to thereby authenticate said second terminal.
  2. 7
    A method whereby a first terminal determines whether a second terminal is using the same encryption key, the steps of the method comprising:transmitting from said first terminal to said second terminal a first value representing the encryption of a secret value under the first terminal's encryption key;deriving at the second terminal a second value by decrypting the first value using the second terminal's encryption key;transmitting from said second terminal to said first terminal a third value representing the secret key encrypted using the second value as key;and verifying at the first terminal that said third value represents the decryption of said first value using the first terminal's key forming an intermediate result followed by encryption of the first terminal's key using the intermediate result as key to verify that the first and second terminal have the same keys, whereby authentication of the second terminal occurs if and only if the encryption keys used by said first and second terminals are equal.
  3. 8
    A method of the type described in Claim 7 wherein the intermediate result in the verifying step equals said secret value and said second value if the encryption keys of said first and second terminals are equal.
  4. 9
    A secure encryption system wherein a first terminal challenges a second terminal which responds with a response based upon the challenge, the improvement wherein the second terminal includes means for decrypting the challenge using its key and means for encrypting its key using the decrypted challenge as key to generate its response and the first terminal includes means for performing similar steps using its key and the challenge in order to verify the response.