EP0405215A2

A method for utilizing an encrypted key as a key identifier in a data packet in a computer network.

Abstract

The nodes in a computer network utilize an encrypted key as a key identifier in a data packets transferred between nodes which eliminates the need for a receiving node to perform a memory look up operation to ascertain the key used to encrypt the data. Each node is provided with a master key that is unique to each node. When two nodes want to establish communications they first negotiate a shared key. This shared key is then encrypted under each nodes' master key. The nodes then exchange their respective encrypted key. The encrypted key of the receiving node is placed in the data packet to be sent by the transmitting node. Upon receiving a data packet, the receiving node decrypts the encrypted key to determine the shared key. This shared key is then used to decrypt encrypted data in the data packet.

EP0405215A2, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 11 June 2010, 16.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

26 claims: 24 independent, 2 dependent

  1. 1
    A method for encrypting a shared key in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having the shared key;(b) encrypting the shared key at the second node under the control of the master key of the second node to form an encrypted version of the shared key;and(c) transmitting the encrypted version of the shared key from the second node to the first node.
  2. 2
    A method for building a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having the shared key;and(b) building an encrypted data packet in the first node incorporating an encrypted version of the shared key encrypted under the master key of the second node and data encrypted under the shared key.
  3. 3
    A method for transmitting a data packet, in a network comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having the shared key;and(b) transmitting from the first node to the second node an encrypted data packet including an encrypted version of the shared key encrypted under the control of the master key of the second node and data encrypted under the shared key.
  4. 4
    A method for decrypting a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having the shared key;(b) decrypting an encrypted version of the shared key at the second node under the control of the master key of the second node to obtain the shared key;and(c) decrypting the data at the second node under the control of the shared key.
  5. 5
    A method for building and transmitting a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having a shared key;(b) building an encrypted data packet in the first node incorporating an encrypted version of the shared key encrypted under the master key of the second node and data encrypted under the shared key;and(c) transmitting from the first node to the second node an encrypted data packet including the encrypted version of the shared key encrypted under the control of the master key of the second node and data encrypted under the shared key.
  6. 6
    A method for transmitting and decrypting a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having the shared key;(b) transmitting from the first node to the second node an encrypted data packet including an encrypted version of the shared key encrypted under the control of the master key of the second node and data encrypted under the shared key;(c) decrypting the encrypted version of the shared key at the second node under the control of the master key of the second node to obtain the shared key;and(d) decrypting the data at the second node under the control of the shared key.
  7. 7
    A method for secure transmission of a data packet in a network comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having a shared key;(b) encrypting the shared key at the second node under the control of the master key of the second node to form an encrypted version of the shared key;(c) transmitting the encrypted version of the shared key from the second node to the first node;(d) encrypting data under the control of the shared key at the first node;(e) building an encrypted data packet incorporating the encrypted version of the shared key received from the second node and data encrypted under the control of the shared key;(f) transmitting the encrypted data packet from the first node to the second node;(g) decrypting the encrypted version of the shared key at the second node under the control of the second node's master key to obtain the shared key;and(h) decrypting the data at the second node under the control of the shared key.
  8. 8
    The method of any one of claims 3, 5, 6 and 7 wherein the step of transmitting the encrypted data packet is done serially.
  9. 9
    The method of any one of claims 3, 5, 6 and 7 wherein the first node has a master key to provide for two-way encrypted communications.
  10. 10
    A decrypter comprising:an input device adapted to receive an encrypted data packet including an encrypted version of a shared key encrypted under the control of a master key and encrypted data encrypted under the control of the shared key;a storage device coupled to the input device adapted to store the master key;a portion of the decrypter coupled to the input device and the storage device, adapted to decrypt the encrypted version of the shared key under the control of the master key and decrypt the encrypted data under the control of the shared key.
  11. 11
    An encrypter comprising:a storage device adapted to store at least one shared key and an encrypted version of the at least one shared key;a device coupled to the storage device adapted to encrypt data under the control of the at least one shared key;a packet builder coupled to the storage device and the device, adapted to build a data packet incorporating the encrypted verson of the at least one shared key and the encrypted data.
  12. 13
    A network comprising:at least a first and a second node, each node having a master key and both nodes having a shared key, the nodes being coupled to form a network;a decrypter coupled to the second node;an encrypted data packet at the first node, the encrypted data packet having an encrypted version of the shared key and encrypted data encrypted under the control of the shared key;the first node adapted to transmit the encrypted data packet to the second node;the decrypter adapted to receive the encrypted data packet transmitted from the first node;the decrypter adapted to decrypt the encrypted version of the shared key under the control of the master key of the second node and decrypt the encrypted data under the control of the shared key.
  13. 14
    A network comprising:at least a first and second node, each node having a master key and both nodes having a shared key, the nodes being coupled to form the network;a storage device at the first node adapted to store the shared key and an encrypted version of the shared key encrypted under the control of the master key of the second node;a device coupled to the storage device adapted to encrypt data under the control of the shared key;a packet builder coupled to the storage device and the device, adapted to build a data packet incorporating the encrypted version of the shared key and the encrypted data;the first node adapted to transmit the data packet to the second node;an input device at the second node adapted to receive the encrypted data packet including the encrypted version of the shared key encrypted under the control of the master key of the second node and the encrypted data encrypted under the control of the shared key;a storage device coupled to the input device adapted to store the master key of the second node;and a decrypter coupled to the input device and the storage device, adapted to decrypt the encrypted version of the shared key under the control of the master key at the second node and decrypt the encrypted data under the control of the shared key.
  14. 15
    A method for building a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having a shared key;and(b) building a data packet at the first node, the data packet comprising an encrypted version of the shared key encrypted under the master key of the second node, data and an integrity check vector incorporated in the data packet as a function of the shared key and the data.
  15. 16
    A method for transmitting a data packet, in a network comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both having a shared key;and(b) transmitting from the first node to the second node a data packet including an encrypted version of the shared key encrypted under the control of the master key of the second node, data and an integrity check vector incorporated in the data packet as a function of the shared key and the data.
  16. 17
    A method for building and transmitting a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having a shared key;(b) building a data packet incorporating an encrypted version of the shared key encrypted under the master key of the second node, data and an integrity check vector incorporated in the data packet as a function of the shared key and the data;and(c) transmitting from the first node to the second node an encrypted version of the data packet including the encrypted version of the shared key encrypted under the control of the master key of the second node, data and an integrity check vector incorporated in the data packet as a function of the shared key and the data.
  17. 18
    A method for transmitting and verifying the integrity of a data packet in a network, comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having a shared key;(b) transmitting from the first node to the second node a data packet including an encrypted version of the shared key encrypted under the control of the master key of the second node, data and an integrity check vector incorporated in the data packet as a function of the shared key and the data;(c) decrypting an encrypted version of the shared key as it is received by the second node under the control of the master key of the second node to obtain the shared key;(d) calculating at the second node the integrity check vector utilizing the data of the data packet as received and the shared key at the second node;and(e) comparing the calculated integrity check vector to the integrity check vector received by the second node in the data packet.
  18. 19
    A method for high integrity transmission of a data packet including an integrity check vector in a network comprising the steps of:(a) coupling a first node to a second node, the second node having a master key that is unique to that node and both nodes having a shared key;(b) encrypting the shared key at the second node under the control of the master key of the second node to form an encrypted version of the shared key;(c) transmitting the encrypted version of the shared key from the second node to the first node;(d) building a data packet at the first node, the data packet comprising an encrypted version of the shared key encrypted under the master key of the second node, data and an integrity check vector incorporated in the data packet as a function of the shared key and the data;(e) transmitting the data packet from the first node to the second node;(f) decrypting the encrypted version of the shared key as it is received at the second node under the control of the second node's master key to obtain the shared key;(g) calculating at the second node the integrity check vector utilizing the data of the data packet as it received at the second node and the shared key of the data packet;and(h) comparing the calculated integrity check vector to the integrity check vector received by the second node in the data packet.
  19. 20
    The method of any one of claims 16, 17 and 18 wherein the step of transmitting the data packet is done serially.
  20. 21
    The method of any one of claims 16, 17 and 18 wherein the first node has a master key to provide for two-way communications.
  21. 22
    A packet builder comprising:a storage device adapted to store at least one shared key and an encrypted version of the at least one shared key;a device coupled to the storage device adapted to calculate an integrity check vector utilizing data and the at least one shared key;and a portion of the packet builder coupled to the storage device and the device, adapted to build a data packet incorporating the encrypted version of the at least one shared key, the data and the integrity check vector.
  22. 24
    An integrity checking device comprising:an input device adapted to receive a data packet including an encrypted version of at least one shared key encrypted under the control of a master key, data and an integrity check vector incorporated in the data packet as a function of the at least one shared key and the data;a storage device coupled to the input device adapted to store the master key;a decrypter coupled to the input device and the storage device, adapted to decrypt the encrypted version of the at least one shared key under the control of the master key;and a portion of the integrity checking device coupled to the input device and the decrypter, adapted to calculate an integrity check vector utilizing the data of the data packet and the at least one shared key of the data packet and compare the calculated integrity check vector to the integrity check vector in the data packet.
  23. 25
    A network comprising:at least a first and a second node, each node having a master key and both nodes having a shared key, the nodes being coupled to form a network;a decrypter coupled to the second node;a data packet at the first node, the data packet having an encrypted version of the shared key and an integrity check vector;the first node adapted to transmit the data packet to the second node;the decrypter adapted to receive the data packet transmitted from the first node;the decrypter adapted to decrypt the encrypted version of the shared key under the control of the master key of the second node;an integrity checking device coupled to the decrypter adapted to calculate an integrity check vector utilizing the data as received at the second node and the at least one shared key and compare the calculated integrity check vector to the integrity check vector in the data packet.
  24. 26
    A network comprising:at least a first and second node, each node having a master key and both nodes having a shared key, the nodes being coupled to form the network;a first storage device at the first node adapted to store at least one shared key and an encrypted version of the at least one shared key encrypted under the control of a master key;a device coupled to the first storage device adapted to calculate an integrity check vector utilizing data and the at least one shared key;and a packet builder at the first node coupled to the first storage device and the device, adapted to build a data packet incorporating the encrypted version of the at least one shared key, the data and the integrity check vector;the first node adapted to transmit the data packet to the second node;an input device at the second node adapted to receive the data packet;a second storage device at the second node coupled to the input device, adapted to store the master key;a decrypter coupled to the input device and the second storage device, adapted to decrypt the encrypted version of the at least one shared key under the control of the master key;an integrity checking device coupled to the input device and the decrypter, adapted to calculate an integrity check vector utilizing the data as received at the second node and the at least one shared key and compare the calculated integrity check vector to the integrity check vector in the data packet.
Independent claims24