EP0800293A2

Circuit and method for generating cryptographic keys

Abstract

A circuit for, and method of, generating a cryptographic key at a communications node. The circuit includes: (1) communications circuitry for communicating a first seed during a first communications session and communicating a second seed during a second communications session temporally separated from the first communications session and (2) processor circuitry for creating the cryptographic key from the first and second seeds, the communicating of the first and second seeds occurring during the temporally-separated first and second communications sessions, respectively, thereby to enhance a privacy of the cryptographic key.

EP0800293A2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 25 March 2017, 9.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

30 claims: 20 independent, 10 dependent

  1. 1
    Apparatus associated with a communications node, for generating a cryptographic key at said communications node, comprising:communications circuitry for communicating a first seed during a first communications session and communicating a second seed during a second communications session temporally separated from said first communications session;andprocessor circuitry for creating said cryptographic key from said first and second seeds, said communicating of said first and second seeds occurring during said temporally-separated first and second communications sessions, respectively, thereby to enhance a privacy of said cryptographic key.
  2. 4
    Apparatus as recited in any of the preceding claims wherein said communications circuitry comprises:first communications circuitry for transmitting said first seed from said communications node to another communications node during said first communications session;andsecond communications circuitry for receiving said second seed from said other communications node during said second communications session.
  3. 5
    Apparatus as recited in any of the preceding claims wherein said processor circuitry further generates verification data for verifying said cryptographic key.
  4. 6
    Apparatus as recited in any of the preceding claims wherein said communications circuitry communicates verification data during said second communications session.
  5. 7
    Apparatus as recited in any of the preceding claims wherein said communications node is a mobile node of a wireless telecommunications network.
  6. 8
    Apparatus as recited in any of claims 1 to 6 wherein said communications node is a client station of a computer network.
  7. 9
    Apparatus for independently generating cryptographic keys at first and second communications nodes, comprising:communications circuitry for transmitting first and third seeds between said first and second communications nodes during a first communications session over a first communications channel and transmitting a second seed between said first and second communications nodes during a second communications session temporally separated from said first communications session and over a second communications channel separate from said first communications channel;andprocessor circuitry for generating verification data and said cryptographic keys from said first, second and third seeds at both said first and second communications nodes, said processor circuitry employing said verification data during said second communications session to verify said transmitting of said first, second and third seeds, said transmitting of said first and second seeds occurring during said temporally-separated first and second communications sessions and over said separate first and second communications channels, respectively, to thereby enhance a privacy of said cryptographic keys.
  8. 12
    Apparatus as recited in any of the preceding claims wherein said second communications session is conducted over a wireless communications channel.
  9. 13
    Apparatus comprising:a communications network having a base station for communicating signals via wireless communications channels;a secure database, associated with said base station, for containing cryptographic keys, said cryptographic keys allowing transmission of encrypted signals from said base station;a plurality of wireless terminals couplable to said base station via said wireless communications channels to allow communication of signals therebetween, each of said plurality of wireless terminals having a memory associated therewith for storing a cryptographic key allowing transmission of encrypted signals from said each of said plurality of wireless terminals to said base station;anda key management system for independently generating cryptographic keys at said base station and a selected one of said plurality of wireless terminals, comprising:communications circuitry, associated with said base station and said selected one of said plurality of wireless terminals, for transmitting a first seed between said base station and said selected one of said plurality of wireless terminals during a first communications session and transmitting a second seed between said base station and said selected one of said plurality of wireless terminals during a second communications session temporally separated from said first communications session, andprocessor circuitry, associated with said base station and said selected one of said plurality of wireless terminals, for generating said cryptographic keys from said first and second seeds at both said base station and said selected one of said plurality of wireless terminals and storing one of said cryptographic keys in said secure database, said transmitting of said first and second seeds occurring during said temporally-separated first and second communications sessions, respectively, to thereby enhance a privacy of said cryptographic keys.
  10. 16
    Apparatus as recited in any of claims 13 to 15 wherein said communications circuitry communicates verification data between said base station and said selected one of said plurality of wireless terminals during said second communications session.
  11. 17
    Apparatus as recited in any of the preceding claims wherein said first seed is 8 to 10 digits in length and said second seed is 24 digits in length.
  12. 18
    A method of generating a cryptographic key at a communications node, comprising the steps of:communicating a first seed during a first communications session and communicating a second seed during a second communications session temporally separated from said first communications session;andcreating said cryptographic key from said first and second seeds, said communicating of said first and second seeds occurring during said temporally-separated first and second communications sessions, respectively, thereby to enhance a privacy of said cryptographic key.
  13. 21
    The method as recited in any of claims 18 to 20 wherein said step of communicating comprises the steps of:transmitting said first seed from said communications node to another communications node during said first communications session;andreceiving said second seed from said other communications node during said second communications session.
  14. 22
    The method as recited in any of claims 18 to 21 further comprising the step of further generating verification data for verifying said cryptographic key.
  15. 23
    The method as recited in any of claims 18 to 22 wherein said step of communicating further comprises the step of communicating verification data during said second communications session.
  16. 24
    The method as recited in any of claims 18 to 23 wherein said communications node is a mobile node of a wireless telecommunications network.
  17. 25
    The method as recited in any of claims 18 to 23 wherein said communications node is a client station of a computer network.
  18. 26
    A method of independently generating cryptographic keys at first and second communications nodes, comprising:transmitting first and third seeds between said first and second communications nodes during a first communications session over a first communications channel;transmitting a second seed between said first and second communications nodes during a second communications session temporally separated from said first communications session and over a second communications channel separate from said first communications channel;andgenerating verification data and said cryptographic keys from said first, second and third seeds at both said first and second communications nodes, said verification data employed during said second communications session to verify said transmitting of said first, second and third seeds, said transmitting of said first and second seeds occurring during said temporally-separated first and second communications sessions and over said separate first and second communications channels, respectively, to thereby enhance a privacy of said cryptographic keys.
  19. 29
    The method as recited in any of claims 18 to 28 wherein said second communications session is conducted over a wireless communications channel.
  20. 30
    The method as recited in any of claims 18 to 29 wherein said first seed is 8 to 10 digits in length and said second seed is 24 digits in length.
Independent claims20