EP1501238B1

Method and system for key distribution comprising a step of authentication and a step of key distribution using a KEK (key encryption key)

Abstract

This record has no abstract on file.

EP1501238B1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Expired 23 July 2023, 3.2 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

10 claims: 3 independent, 7 dependent

  1. 1
    A method for authentication, data communication, storage and retrieval in a distributed key cryptography system, wherein there are provided at least one client system (300), comprising data storage means (311, 313) initially storing at least one encrypted first key encrypting key (Wk), (Wpu1, Wpr1), first and second hashing functions able to compute at least first and second hashes from at least one passphrase, a server system (100) comprising data storage means (111, 121) initially storing a first hash at least one encrypted second key encrypting key (Dk), (Dpr1) encrypted by a second hash value, at least one encrypted symmetric third key (Fk), (F1) being encrypted by means of the first key encrypting key, and encrypted data, the method comprising the following steps:a) the at least one client system (300) hashing the at least one passphrase using the first hashing function, so as to compute the first hash, b) the at least one client system (300) transmitting, via telecommunication means (200, 203), the first hash to the server system (100);c) the server system (100) performing an authentication of the first hash comparing it with the first hash stored on the storage means of the server;d) the server system (100) providing the at least one client system (300) with the at least one second key encrypting key (Dk), (Dpr1) in encrypted form over telecommunication means (200, 203) if said authentication is successful, characterized in that e) the at least one client system (300) hashes the passphrase by means of the second hashing function, so as to produce the second hash;f) the at least one client system (300) utilizes the second hash for decrypting the at least one encrypted second key encrypting key (Dk), (Dpr1);g) the at least one client system (300) utilizes the decrypted second key encrypting key (Dk), (Dpr1) for decrypting the at least one first key encrypting key (Wk), (Wpu1, Wpr1), stored in encrypted form only in storage means (311, 313) of the client system (300);h) the server system (100) transmits the at least one encrypted symmetric third key (Fk), (F1), stored in encrypted form in storage means (111, 121) of the server system (100), to the at least one client system (300);i) the at least one client system (300) decrypts the at least one third Key (Fk), (F1) by means of the at least one first key encrypting key (Wk), (Wpu1, Wpr1);j) the at least one client system (300) decrypts data by means of the at least one third key (Fk), (F1).
  2. 7
    System for authentication, data communication, storage and retrieval in a distributed key cryptography system, comprising at least one client system (300), comprising data storage means (311, 313) storing initially at least one encrypted first key encrypting key (Wk), (Wpu1, Wpr1), first and second hashing functions that can perform encryption and decryption operations and able to compute at least first and second hashes from a passphrase string, a server system (100) comprising data storage means (111, 121) initially storing a first hash at least one encrypted second key encrypting key (Dk), (Dpr1) encrypted by a second hash value, at least one encrypted symmetric third key (Fk), (F1) being encrypted by means of the first key encrypting key, and encrypted data, and a) means in the at least one client system (300) for hashing a passphrase using the first hashing function, so as to compute the first hash;b) means in the at least one client system (300) for transmitting, via telecommunication means (200, 203), the first hash to the server system (100);c) means in the server system (100) performing an authentication of the first hash comparing it with the first hash stored on the storage means of the server;d) means in the server system (100) providing the at least one client system (300) with at least one second key encrypting key (Dk), (Dpr1, Dpr2) in encrypted form over telecommunication means (200, 203) if said authentication is successful, characterized in that there are provided e) means in the at least one client system (300) hashing the passphrase by means of the second hashing function, so as to produce a second hash;f) means in the at least one client system (300) for utilizing the second hash for decrypting the at least one encrypted second key encrypting key (Dk), (Dpr1) ;g) means in the at least one client system (300) for utilizing the decrypted second key encrypting key (Dk), (Dpr1) for decrypting the at least one first key encrypting key (Wk), (Wpu1, Wpr1), stored in encrypted form only in storage means (311, 313) of the client system (300);h) means in the server system (100) for transmitting the at least one symmetric third key (Fk), (F1), stored in encrypted form in storage means (111, 121) of the server system (100), to the at least one client system (300);i) means for decrypting the symmetric third key (Fk), (F1) by means of the first key encrypting key (Wk), (Wpu1, Wpr1);j) means in the client system (300) for decrypting data by means of the at least one_symmetric third key (Fk).
  3. 9
    A computer program product in a computer usable medium, comprising:a) instructions in at least one client system (300), for initially storing at least one encrypted first key encrypting key (Wk), (Wpu1, Wpr1), first and second hashing functions able to compute at least first and second hashes from at least one passphrase, b) instructions in a server system (100) for initially storing a first hash at least one encrypted second key encrypting key (Dk), (Dpr1) encrypted by a second hash value, at least one encrypted symmetric third key (Fk), (F1) being encrypted by means of the first key encrypting key, and encrypted data, c) instructions in the at least one client system (300) for hashing the at least one passphrase using a first hashing function, so as to produce a first hash, and using a second hashing function so as to produce a second hash;d) instructions in the client system for transmitting, via telecommunication means (200), the first hash to the at least one client system (300);e) instructions in the server system (100) for performing an authentication of the first hash comparing it with the first hash stored in the server system (100);f) instructions in the server system (100) for providing the at least one client system (300) with the at least one second key encrypting key (Dk), (Dpr1), in encrypted form over telecommunication means (200, 203);g) instructions in the at least one client system (300) for hashing the at least one_passphrase by means of the second hashing function, so as to produce the second hash;h) instructions in the at least one client system (300) for utilising the second hash for decrypting the at least one encrypted second key encrypting key (Dk), (Dpr1);i) instructions in the at least one client system (300) for utilizing the decrypted at least one_second key encrypting key (Dk), (Dpr1) for decrypting the at least one first key encrypting key (Wk), (Wpu1, Wpr1 stored in encrypted form in storage means of the at least one_client system (300);j) instructions in the server system (100) for transmitting a symmetric third key (Fk), stored in encrypted form in storage means of the server system (100), to the at least one client system (300);k) instructions in the at least one client system (300) for decrypting data by means of the at least one symmetric third key (Fk);l) instructions in for decrypting the at least one symmetric third key (Fk), (F1) by means of the at least one first key encrypting key (Wk) (Wpu1, Wpr1);