EP0977397A2

Method for transferring sensitive information using initially unsecured communication

Abstract

In the method for transferring sensitive information using unsecured communication, a first party receives a public key of a second party, produces an encryption result by performing keyed encryption on at least a first random number using the public key, and transfers the encryption result to the second party over an unsecured communication channel. The second party decrypts the encryption result to obtain the first random number. Authorizing information is then transferred from the first party to the second party over a first encrypted and authenticated communication channel established using the first random number. Sensitive information is further transferred from the second party to the first party over a second encrypted and authenticated communication channel established using the first random number if the second party accepts the authorizing information. Numerous applications exist for the system and method, including the wireless industry wherein the first party is a mobile and the second party is a network.

EP0977397A2, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 20 July 2019, 7.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 2 independent, 15 dependent

  1. 1
    A method for transferring sensitive information to a first party using initially unsecured communication, comprising:(a) receiving, at said first party, a public key of a second party;(b) producing an encryption result by performing keyed encryption on at least a first random number using said public key;(c) transferring said encryption result from said first party to said second party;(d) transferring authorizing information to said second party over a first encrypted and authenticated communication channel established using said first random number;and (e) receiving sensitive information from said second party over a second encrypted and authenticated communication channel established using said first random number.
  2. 10
    A method for transferring sensitive information from a first party using initially unsecured communication channel, comprising:(a) outputting a public key of said first party;(b) receiving, at said first party, an encryption result from a second party, said encryption result being a result of performing keyed encryption on at least a first random number using said public key of said first party;(c) decrypting said encryption result to obtain said first random number;(d) receiving authorizing information from said second party over a first encrypted and authenticated communication channel established using said first random number;and (e) transferring sensitive information to said second party over a second encrypted and authenticated communication channel established using said first random number if said authorizing information is acceptable.