EP1107504A2

Method of updating encryption keys in a data communication system

Abstract

The invention discloses a method of updating, in nodes on both ends of a secure link, the encryption key they share to encrypt and decrypt data. When having to transmit data from one of the nodes (14) towards its peer remote node (16), a data base (22) in the forwarding node, is first updated from the data to be transmitted. Then, encryption is performed and data transmitted to the peer remote node while a next-to-use encryption key is derived from the new contents of the data base. When received, data are decrypted with the current value of the encryption key and the peer remote node data base is updated identically from the received decrypted data after which a next-to-use encryption key is derived, thereby obtaining in the peer remote node, a next-to-use identical key. The data base is preferably the dictionary (46) of a data compression/decompression system used simultaneously with encryption/decryption to transmit data over the secure link. While keys are frequently updated, for improved security, the invention does not require that key updates need to be actually distributed.

EP1107504A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 28 September 2020, 6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

15 claims: 6 independent, 9 dependent

  1. 1
    Method of updating an encryption key in a data communication system comprising a transmitting node (14) which receives clear data from a transmitting DTE (10) and a receiving node (16) which transmits clear data to a receiving DTE (12), said transmitting and receiving nodes forming a security association (20) sharing said encryption key for communicating cipher data between them and including identically involving data bases (22 or 24); said method comprising the steps of :Upon transmitting data from said transmitting node to said receiving node : - updating said data base (22), in said transmitting node by using said clear data received from said transmitting DTE, - encrypting (62) in said transmitting node data to be transmitted by using the current value of said encryption key, - transmitting (64) encrypted data to said receiving node, and - deriving (68) from the new contents of said data base in said transmitting node, a next-to-use encryption key, Upon receiving encrypted data in said receiving node : - decrypting (76) in said receiving node, received encrypted data by using the current value of said encryption key, - updating identically said data base (24) in said receiving node, by using the received decrypted data, - deriving (80) from contents of said updated data base in said receiving node, a next-to-use decryption key identical to said next-to-use encryption key.
  2. 6
    The method according to any one of the previous claims, wherein said steps of deriving said next-to-use encryption/decrytion key further include the step of obtaining a digest from the current contents of said evolving data base (22, 24), said step of obtaining a digest further including the step of utilizing directly said digest as the next-to-use key or combining said digest to said current key to get a next-to-used key.
  3. 10
    The method according to any one of the previous claims, wherein a new security association (20) is formed periodically or upon overflowing of the packet sequence number.
  4. 11
    The method according to any one of the previous claims, wherein a new security association (20) is formed periodically or upon detecting transmission errors.
  5. 13
    The method according to any one of the previous claims, wherein said data base (22, 24) is reset to a secret set of values on initialization.
  6. 14
    A secure data communications system comprising means adapted for carrying out the method according to any one of the previous claims.
  7. 15
    A computer-like readable medium comprising instructions for carryinig out the method according to any one of the claims 1 to 13.