EP1292882A1

Method and device for encrypting a message

Abstract

Method and device for secure wireless transmission of information from a sender to a receiver. A sending device is arranged for obtaining a message, a sender identity and a receiver identity and includes encryption means for encrypting the message to be transmitted. A transmission channel is established from the sending device to a receiving device for transmitting the encrypted information to the receiving device. A secure note is used for defining the receiving device. In the receiving device, there is arranged decryption means for decrypting the information and display means for presenting the message to the receiver. Optionally, the receipt of the message is verified to the sender. Preferably, the message is encrypted in the sending device by a symmetric key and decrypted by the receiving device by the same key. The symmetric key is added to the message after encryption with the symmetric key and the symmetric key is encrypted by a public key belonging to the receiver, whereupon the already encrypted symmetric key is encrypted by a private key belonging to the sender. In the receiving device, the symmetric key is decrypted by the public key of the sender in the receiving device and by the private key of the receiver, whereupon the symmetric key is used for decrypting the message. The sender and the receiver identifie themselves to the sending device and the receiving device by verification means. Preferably, a random seed for generating encryption key is obtained by the verification means during the identification step and/or the message step. Preferably, the sending device is an Anoto pen.

EP1292882A1, drawing sheet 1
Sheet 1 of 15

Term

Term ended

Projected expiry passed 7 June 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

40 claims: 16 independent, 24 dependent

  1. 1
    Claims of equivalent WO 0195091 A1 CLAIMS 1. A method for encrypting a message for secure transmission of said message from a sending device to a receiver, comprising the steps of obtaining optical data, generating an encryption key using said optical data as random seed, and encrypting said message using said encryption key in an encryption algorithm.
  2. 5
    The method according to any one of claims 2-4, wherein the step of generating an encryption key comprises the steps of processing said optical data according to a prede- termined scheme, organizing said processed optical data in data fields, wherein each data field has a predetermined size, and organizing said data fields in a predetermined order in data records.
  3. 8
    The method according to any one of claims 5-7, wherein the step of processing said optical data comprises the steps of rearranging the order of said data fields within at least one data record of a first series of data records according to a first reordering algorithm, thereby obtaining a first series of rearranged data records, and rearranging the order of said data fields within at least one data record of a second series of data records according to a second reordering algorithm, thereby obtaining a second series of rearranged data records .
  4. 10
    The method according to any one of claims 5-7, wherein the step of generating an encryption key comprises the steps of processing a set of a predetermined number of said data records in a first step using a first hash function, thereby obtaining a first output, processing said first output in a second step using an iterative algorithm, thereby obtaining a second output , and using said second output as said encryption key or for generating said encryption key.
  5. 15
    The method according to any one of the preceding claims, wherein the encryption key comprises key data and input data, the method further comprising the steps of using a first subset of said optical data for generating said key data, and using a second subset of said optical data for generating said input data.
  6. 16
    The method according to any one of the preceding claims, wherein said encryption algorithm for encrypting said message is a symmetric encryption algorithm.
  7. 19
    The method according to any one of the preceding claims, wherein said steps are performed in a digital pen comprising an optical sensor and said sending device.
  8. 20
    Computer readable medium comprising instructions for bringing a computer to perform a method according to any one of the preceding claims.
  9. 21
    Device for encrypting a message for secure wireless transmission of said message from a sender to a receiver, comprising receiving means for receiving optical data, said op- tical data representing values of an optical parameter, processing means for generating an encryption key using said optical data as random seed, and encryption means for encrypting the message to be transmitted using said encryption key.
  10. 26
    Device according to any one of claims 23-25, wherein said processing means is further arranged to rearrange the order of said data fields within at least one data record of a first series of data records according to a first reordering algorithm, thereby obtaining a first series of rearranged data records, and rearrange the order of said data fields within at least one data record of a second series of data records according to a second reordering algorithm, thereby ob- taining a second series of rearranged data records.
  11. 28
    The device according to any one of claims 23-25, wherein the processing means is further arranged to process a set of a predetermined number of said data records in a first step using a first hash function, thereby obtaining a first output, process said first output in a second step using an iterative algorithm, thereby obtaining a second output, and use said second output as said encryption key or for generating said encryption key.
  12. 33
    Device according to any one of claims 21-32, wherein said encryption means is further arranged to en- crypt said message using a symmetric encryption algorithm.
  13. 34
    Device according to any one of claims 21-33, wherein said encryption means is further arranged to use a subset of said optical data as key data for said encryption algorithm, and use a second subset of said optical data as input data for said encryption algorithm.
  14. 37
    A sending device arranged for obtaining a message and for sending said message to a receiver, comprising an optical sensor for obtaining optical data, a device as claimed in any one of claims 20-34 for encrypting said message prior to transmission thereof, and transmitting means for transmitting said message.
  15. 39
    An information management system comprising a plurality of products (P) provided with a position code pattern, a plurality of digital pens (DP) capable of reading said position code, and a server means (ALS) communicating with said digital pens (DP) in at least one communication network, said server means (ALS) including a position data base (GSDB) which associates positions coded by said position code (PC) with rules for information management, wherein said digital pens (DP) are arranged to communicate to said server means (ALS) informa- tion which is registered on said products (P) in the form of at least one position which is coded by said position code, wherein each digital pen comprises a device as claimed in any one of claims 21-36.
  16. 40
    A method for authentication of a sent message, wherein said message is sent from a sender to a receiver, comprising the steps of obtaining optical data, using said optical data for generating random number data, encrypting said random number data, and using said encrypted random number data for authentication of said message .
Independent claims16