EP0876027B1

Method and apparatus for achieving perfect forward secrecy in closed user groups

Abstract

This record has no abstract on file.

EP0876027B1, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Expired 28 April 2018, 8.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

27 claims: 26 independent, 1 dependent

  1. 1
    A method for sending data from a first data processing device to a second data processing device in a closed user group having a plurality of nodes, the first data processing device constituting a first node of the plurality of nodes and the second data processing device constituting a second node of the plurality of nodes, wherein each of said nodes includes a unique secret value, a public value and a value of a context variable, the method in the first node comprising the steps of:obtaining a certificate for each of the other nodes in the plurality of nodes and determining said public values for each of the other nodes in the plurality of nodes from said certificates;pre-computing a shared secret for each of said other nodes in the plurality of nodes using the secret value of the first node and said determined public values of each of the other nodes;deleting the secret value of the first node;computing an interchange key from said precomputed shared secret for said first and second nodes;encrypting data to be transmitted to the second node using said interchange key;sending said encrypted data to said second node;notifying said second node of the current value of the context variable for the first node.
  2. 2
    The method as defined by claim 1, further comprising the steps in said second node of:receiving said encrypted data and notification of the current value of the context variable for the first node from the first node;comparing the value of the context variable for the second node to the value of the context variable for the first node;and if the value of the context variable for the first node is greater than the value of the context variable for the second node, computing said interchange key from said precomputed shared secret for said first and second nodes, and setting the value of said context variable for the second node to equal the value of the context variable for the first node if said received encrypted data is determined to be validly encrypted for the value of the context variable of the first node.
  3. 3
    The method as defined by claim 1 or 2, wherein said data to be transmitted to the second node includes a transient key employed to encrypt other data to be transmitted to the second node.
  4. 4
    The method as defined by claim 3, wherein the method in the second node further includes the steps of:decrypting said transient key using said interchange key, and decrypting said other data with said transient key.
  5. 5
    The method as defined by any of claims 2-4, further comprising the step by said second node of:if the value of the context variable for the first node equals the value of the context variable for the second node, computing said interchange key from said precomputed shared secret for said first and second nodes.
  6. 6
    The method as defined by any of claims 2-5, further comprising the step by said second node of:if the value of the context variable for the second node is greater than the value of the context variable for the first node, discarding said data and denoting an error condition.
  7. 7
    The method as defined by any of claims 1-6, further comprising the step, performed after a predetermined time period by each node, of incrementing the value of said context variable provided for each node.
  8. 8
    The method as defined by claim 7, the method in the first node further comprising the steps, performed after said step of incrementing the value of the context variables for each node, of:computing a next interchange key from the current interchange key for each of said other nodes, and deleting said current interchange keys and said pre-computed shared secrets for each of said other nodes.
  9. 9
    The method as recited in any of the preceding claims, wherein for each node of said nodes, said value of the context variable provided for each node is initially set equal to 1.
  10. 11
    The method as defined by claim 10, wherein said one-way function is equal to z M mod p, wherein p is a composite number which is difficult to factor.
  11. 12
    The method as defined by any of claims 1-9, wherein the interchange key is an implicit pair wise secret used as a key for a shared key cryptosystem (SKCS) and derived from a (M^N)ij wherein a is a system parameter.
  12. 13
    The method as defined by claim 12, wherein said other data comprises a data packet which includes a source address, a destination address and an SKCS identifier field.
  13. 14
    The method as defined by claim 12 or 13, wherein said data packet further includes a message indicator field.
  14. 15
    An apparatus for encrypting data for transmission from a first data processing device (10) to a second data processing device in a closed user group having a plurality of nodes, the first data processing device (10) constituting a first node of the plurality of nodes and the second data processing device constituting a second node of the plurality of nodes, each of said nodes including a storage device (14) configured to store a unique secret value, a public value, and a value of a context variable, the apparatus being referred to as the first node comprising:a computation device (13) configured to: determine the public values of said other nodes from a certificate for each of said other nodes pre-compute a shared secret for each of said other nodes from the secret value of the first node and said determined public values of each of the other nodes;delete the secret value of the first node after pre-computing all of the shared secrets for said other nodes;an encrypting device (13;17) configured to derive an interchange key from the precomputed shared secret for said first and second nodes, and encrypt data to be transmitted to the second node using said interchange key;and an interface circuit (17) configured to transmit said encrypted data to said second node and to notify said second node of the value of the context variable for the first node.
  15. 16
    The apparatus as defined by claim 15, wherein said first node further includes:a receiver (17) for receiving encrypted data from the second node, wherein said encrypted data comprises a transient key employed to encrypt other data to be transmitted to the first node;a decrypting device (13;17) coupled to said receiver for decrypting said encrypted data;the decrypting device (13;17) comprising: a comparator configured to compare the value of the context variable for the second node to the value of the context variable for the first node;a key-computation device configured to compute said interchange key from said precomputed shared secret for said first and second nodes if the value of the context variable for the second node is greater than the value of the context variable for the first node;wherein said decrypting device (13;17) is configured to utilize said interchange key to decrypt said transient key, decrypt said other data using said transient key, and set the value of the context variable for the first node equal to the value of the context variable of the second node.
  16. 17
    The apparatus as defined by claim 16, wherein if the value of the context variable for the second node is equal to the value of the context variable for the first node, said first node is adapted to compute said interchange key from said precomputed shared secret for said first and second nodes, and wherein said decrypting device (13;17) is adapted to utilize said interchange key to decrypt said transient key and decrypt said other data using said transient key.
  17. 18
    The apparatus as defined by claim 17, wherein if the value of the context variable for the second node is less than the value of the context variable for the first node, said first node is adapted to discard said data.
  18. 19
    The apparatus as defined by any of claims 15-18, wherein said first node is adapted to increment the value of the context variable after a predetermined time period.
  19. 20
    The apparatus as defined by claim 19, wherein said first node is further adapted to compute a next interchange key from a current interchange key, and delete said current interchange keys and said pre-computed shared secrets for all of said other nodes.
  20. 21
    The apparatus as defined by any of claims 17-20, wherein said other data comprises a data packet which includes a context field adapted to store the value of the context variable for the first node.
  21. 22
    The apparatus as defined by any of claims 15-21, wherein the value of the context variables for the first and second nodes are initially set equal to 1.
  22. 23
    The apparatus as defined by any of claims 15-22, wherein said public value for each of said nodes is a l mod p, where l is said unique secret value for each of said nodes, a and p are system parameters, where p is a composite number which is difficult to factor.
  23. 24
    The apparatus as defined by any of claims 20-23, wherein said next interchange key is computed from said current interchange key by applying a one-way function to said current interchange key.
  24. 25
    The apparatus as defined by any of claims 15-24, wherein said interchange key is an implicit pair wise secret used as a key for a shared key cryptosystem SKCS.
  25. 26
    The apparatus as defined by any of claims 21-25, wherein said data packet includes a source address, a destination address and an SKCS identifier field.
  26. 27
    The apparatus as defined by claim 26, wherein said data packet further includes a message indicator field.
Independent claims26