Nova Patents
EP1548976B1

A message deciphering method

Abstract

This record has no abstract on file.

EP1548976B1, drawing sheet 1
Sheet 1 of 81

Term

Term ended

Expired 24 December 2023, 2.8 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

22 claims: 22 independent, 0 dependent

  1. 1
    A method for decrypting encrypted messages sent by a transmission device to a first electronic device (SIM) associated with a first trusted authority (TA-SIM) and to a second electronic device (ME), the method comprising the steps of:a) associating a single joint identity with the first (SIM) and the second (ME) devices which is identificative of a common entity comprising the first (SIM) and the second (ME) devices;b) executing, by the transmission device, a single public key encryption operation of a message in clear by using the joint identity and transmitting the encrypted message simultaneously to the first (SIM) and the second (ME) devices;c) generating, by the first (SIM) and the second (ME) devices a first (WSIM) and a second (WME) decryption token, respectively;said tokens being obtained on the basis of quantities provided by at least said first trusted authority;d) providing said first token to the second device and said second token to the first device;e) generating, by starting from said tokens, by the first and second devices, a joint decryption key (W) in order to decrypt the encrypted message. Ein Verfahren zum Entschlüsseln verschlüsselter Nachrichten, die durch eine Übertragungsvorrichtung an eine erste elektronische Vorrichtung (SIM), die einer ersten vertrauenswürdigen Autorität (TA-SIM) zugeordnet ist, und an eine zweite elektronische Vorrichtung (ME) gesendet werden, wobei das Verfahren die folgenden Schritte umfasst: a) Zuordnen einer einzigen gemeinschaftlichen Identität zu der ersten (SIM) und der zweiten (ME) Vorrichtung, die identifizierend ist für eine gemeinsame Entität, die die erste (SIM) und die zweite (ME) Vorrichtung umfasst;b) Ausführen einer einzigen Öffentlicher-Schlüssel-Verschlüsselungsoperation an einer unverschlüsselten Nachricht durch die Übertragungsvorrichtung durch Verwenden der gemeinschaftlichen Identität und Übertragen der verschlüsselten Nachricht gleichzeitig an die erste (SIM) und die zweite (ME) Vorrichtung;c) Generieren eines ersten (WSIM) bzw. eines zweiten (WME) Entschlüsselungs-Tokens durch die erste (SIM) und die zweite (ME) Vorrichtung;wobei die Token auf der Basis von Größen erhalten werden, die durch zumindest die erste vertrauenswürdige Autorität bereitgestellt werden;d) Liefern des ersten Tokens an die zweite Vorrichtung und des zweiten Tokens an die erste Vorrichtung;e) Generieren eines gemeinschaftlichen Entschlüsselungsschlüssels (W), um die verschlüsselte Nachricht zu entschlüsseln, durch die erste und zweite Vorrichtung ausgehend von den Token. Procédé pour décrypter des messages cryptés envoyés par un dispositif de transmission à un premier dispositif électronique (SIM) associé à un premier tiers de confiance (TA-SIM) et à un deuxième dispositif électronique (ME), le procédé comprenant les étapes consistant à: a) associer une identité conjointe unique avec le premier (SIM) et le deuxième (ME) dispositifs qui identifie une entité commune comprenant le premier (SIM) et le deuxième (ME) dispositifs;b) exécuter, par le dispositif de transmission, une seule opération de cryptage de clé publique d'un message en clair en utilisant l'identité conjointe et en transmettant le message crypté simultanément au premier (SIM) et au deuxième (ME) dispositifs;c) générer, par le premier (SIM) et le deuxième (ME) dispositifs un premier (WSIM) et un deuxième (WME) jetons de décryptage, respectivement;lesdits jetons étant obtenus sur la base de quantités fournies par au moins ledit premier tiers de confiance;d) pourvoir ledit premier jeton au deuxième dispositif et ledit deuxième jeton au premier dispositif;e) générer, en commençant à partir desdits jetons, par le premier et le deuxième dispositifs, une clé de décryptage conjointe (W) afin de décrypter le message crypté.
  2. 2
    Das Verfahren gemäß Anspruch 1, das einen Schritt eines Bereitstellens einer zweiten vertrauenswürdigen Autorität (TA-ME) umfasst, die der zweiten Vorrichtung (ME) zugeordnet ist und verschieden und autonom ist bezüglich der ersten vertrauenswürdigen Autorität (TA-SIM), wobei die zweite vertrauenswürdige Autorität weitere Größen für die Generierung des ersten (WSIM) und des zweiten (WME) Tokens an die erste (SIM) und an die zweite Vorrichtung liefert. Procédé selon la revendication 1, comprenant une étape consistant à fournir un deuxième tiers de confiance (TA-ME), associé au deuxième dispositif (ME) et distinct et autonome par rapport audit premier tiers de confiance (TA-SIM), ledit deuxième tiers de confiance fournissant des quantités supplémentaires au premier (SIM) et au deuxième dispositifs pour la génération desdits premier (WSIM) et deuxième (WME) jetons. The method according to claim 1, comprising a step of providing a second trusted authority (TA-ME), associated with the second device (ME) and distinct and autonomous with respect to said first trusted authority (TA-SIM), said second trusted authority providing further quantities to the first (SIM) and to the second devices for the generation of said first (WSIM) and second (WME) tokens.
  3. 3
    Das Verfahren gemäß Anspruch 2, bei dem der Schritt c) die folgenden Schritte umfasst:- Liefern einer ersten (r1SIM;KiSIM) und einer zweiten (r2SIM;s'SIM) Größe an die erste (SIM) und die zweite (ME) Vorrichtung für die Generierung des ersten (WSIM) bzw. des zweiten (WME) Entschlüsselungs-Tokens;wobei die erste und die zweite Größe durch die erste vertrauenswürdige Autorität (TA-SIM) generiert werden;- Liefern einer dritten (r1ME;KiME) und einer vierten (r2ME;s'EM) Größe an die erste und zweite Vorrichtung für die Generierung des zweiten bzw. des ersten Entschlüsselungs-Tokens, wobei die dritte und die vierte Größe durch die zweite vertrauenswürdige Autorität (TA-ME) generiert werden. Procédé selon la revendication 2, dans lequel ladite étape c) inclut les étapes consistant à: - pourvoir aux premier (SIM) et au deuxième (ME) dispositifs, une première (r1SIM;KiSIM) et une deuxième (r2SIM;s'SIM) quantités pour la génération desdits premier (WSIM) et deuxième (WME) jetons de décryptage, respectivement;lesdites première et deuxième quantités étant générées par le premier tiers de confiance (TA-SIM);- pourvoir au deuxième et au premier dispositifs, une troisième (r1ME;KiME) et une quatrième (r2ME;s'ME) quantités pour la génération desdits deuxième et premier jetons de décryptage, respectivement, lesdites troisième et quatrième quantités étant générées par le deuxième tiers de confiance (TA-ME). The method according to claim 2, wherein said step c) includes the steps of: - providing to the first (SIM) and to the second (ME) devices, first (r1SIM;KiSIM) and second (r2SIM;s'SIM) quantities for the generation of said first (WSIM) and second (WME) decryption tokens, respectively;said first and second quantities being generated by the first trusted authority (TA-SIM);- providing to the second and first devices, third (r1ME;KiME) and fourth (r2ME;s'ME) quantities for the generation of said second and first decryption tokens, respectively, said third and fourth quantities being generated by the second trusted authority (TA-ME).
  4. 4
    Das Verfahren gemäß Anspruch 1, bei dem eine erste (IDSIM) und eine zweite (IDME) Identität der ersten (SIM) bzw. der zweiten (ME) Vorrichtung zugeordnet werden und eine weitere erste (IDTA-SIM) und eine weitere zweite (IDTA-ME) Identität der ersten (TA-SIM) und der zweiten (TA-ME) vertrauenswürdigen Autorität zugeordnet werden; wobei das Verfahren zusätzlich den folgenden Schritt umfasst:- Generieren eines ersten (H(IDSIM)) und eines zweiten (H(IDME)) öffentlichen Schlüssels, die durch ein Anwenden einer ersten Hash-Funktion auf die erste und die zweite Identität erhalten werden. Procédé selon la revendication 1, dans lequel une première (IDSIM) et une deuxième (IDME) identités sont associées au premier (SIM) et au deuxième (ME) dispositifs respectivement et une première identité supplémentaire (IDTA-SIM) et une deuxième identité supplémentaire (IDTA-ME) sont associées au premier (TA-SIM) et au deuxième (TA-ME) tiers de confiance;le procédé comprenant en plus les étapes consistant à: - générer une première (H (IDSIM)) et une deuxième (H (IDME)) clés publiques, obtenues en appliquant une première fonction de hachage à la première et à la deuxième identités. The method according to claim 1, wherein first (IDSIM) and second (IDME) identities are associated with the first (SIM) and the second (ME) devices respectively and further first (IDTA-SIM) and further second (IDTA-ME) identities are associated with the first (TA-SIM) and the second (TA-ME) trusted authorities;the method additionally comprising the steps of: - generating a first (H(IDSIM)) and a second (H(IDME)) public keys, obtained by applying a first hash function to the first and the second identities.
  5. 5
    Das Verfahren gemäß Anspruch 3 und 4, bei dem:- die erste (r1SIM) und die zweite (r2SIM) Größe durch die erste vertrauenswürdige Autorität (TA-SIM) ausgehend von einer ersten Zufallszahl (rSIM) und dem ersten öffentlichen Schlüssel (H(IDSIM)) der ersten Vorrichtung (SIM) bzw. ausgehend von der ersten Zufallszahl und dem zweiten öffentlichen Schlüssel (H(IDME)) der zweiten Vorrichtung (ME) berechnet werden;- die dritte (r1ME) und die vierte (r2ME) Größe ausgehend von einer zweiten Zufallszahl (rME) und dem zweiten öffentlichen Schlüssel (H(IDME)) bzw. ausgehend von der zweiten Zufallszahl und dem ersten öffentlichen Schlüssel (H(IDSIM)) berechnet werden. Procédé selon les revendications 3 et 4, dans lequel: - ladite première (r1SIM) et ladite deuxième (r2SIM) quantités sont calculées par le premier tiers de confiance (TA-SIM) en commençant à partir d'un premier nombre aléatoire (rSIM) et à partir de la première clé publique (H (IDSIM)) du premier dispositif (SIM) et en commençant à partir du premier nombre aléatoire et à partir de la deuxième clé publique (H (IDME)) du deuxième dispositif (ME), respectivement;- ladite troisième (r1ME) et ladite quatrième (r2ME) quantités sont calculées en commençant à partir d'un deuxième nombre aléatoire (rME) et à partir de la deuxième clé publique (H (IDME)) et en commençant à partir du deuxième nombre aléatoire et à partir de la première clé publique (H (IDSIM)), respectivement. The method according to claims 3 and 4, wherein: - said first (r1SIM) and said second (r2SIM) quantities are calculated by the first trusted authority (TA-SIM) by starting from a first random number (rSIM) and from the first public key (H(IDSIM)) of the first device (SIM) and by starting from the first random number and from the second public key (H(IDME)) of the second device (ME), respectively;- said third (r1ME) said fourth (r2ME) quantities are calculated by starting from a second random number (rME) and from the second public key (H(IDME)) and by starting from the second random number and from the first public key (H(IDSIM)), respectively.
  6. 6
    Das Verfahren gemäß Anspruch 3 und 4, bei dem:- die erste (KiSIM) und die zweite (s'SIM) Größe ausgehend von einem ersten Hauptschlüssel (sTA-SIM) und dem ersten öffentlichen Schlüssel (H(IDSIM)) bzw. ausgehend von dem ersten Hauptschlüssel und dem zweiten öffentlichen Schlüssel (H(IDME)) berechnet werden;- die dritte (KiME) und die vierte (s'ME) Größe ausgehend von einem zweiten Hauptschlüssel (sTA-ME) und dem zweiten öffentlichen Schlüssel (H(IDME)) bzw. ausgehend von dem zweiten Hauptschlüssel und dem ersten öffentlichen Schlüssel (H(IDSIM)) berechnet werden. Procédé selon les revendications 3 et 4, dans lequel: - ladite première (KiSIM) et ladite deuxième (s'SIM) quantités sont calculées en commençant à partir d'une première clé maîtresse (STA-SIM) et à partir de la première clé publique (H (IDSIM)) et en commençant à partir de la première clé maîtresse et à partir de la deuxième clé publique (H (IDME)), respectivement;- ladite troisième (KiME) et ladite quatrième (s'ME) quantités sont calculées en commençant à partir d'une deuxième clé maîtresse (STA-ME) et à partir de la deuxième clé publique (H (IDME)) et en commençant à partir de la deuxième clé maîtresse et à partir de la première clé publique (H (IDSIM)), respectivement;The method according to claims 3 and 4, wherein: - said first (KiSIM) and said second (s'SIM) quantities are calculated by starting from a first master key (sTA-SIM) and from the first public key (H(IDSIM)) and by starting from the first master key and from the second public key (H(IDME)), respectively;- said third (KiME) and said fourth (s'ME) quantities are calculated by starting from a second master key (sTA-ME) and from the second public key (H(IDME)) and by starting from the second master key and from the first public key (H(IDSIM)), respectively;
  7. 7
    Das Verfahren gemäß Anspruch 3, bei dem der Schritt des Generierens des ersten Halb-Entschlüsselung-Tokens (WSIM) durch die erste Vorrichtung (SIM) den Schritt eines Anwendens einer bilinearen Funktion auf die Summe von der ersten (r1SIM) und der vierten (r2ME) Größe und auf einen ersten Punkt einer additiven Gruppe umfasst. Procédé selon la revendication 3, dans lequel l'étape de générer le premier demi-jeton de décryptage (WSIM) par le premier dispositif (SIM), comprend l'étape d'appliquer une fonction bilinéaire à la somme de la première (r1SIM) et de la quatrième (r2ME) quantités, et à un premier point d'un groupe additif. The method according to claim 3, wherein the step of generating the first half decryption token (WSIM) by the first device (SIM), comprises the step of applying a bilinear function to the sum of the first (r1SIM) and the fourth (r2ME) quantities, and to a first point of an additive group.
  8. 8
    Das Verfahren gemäß Anspruch 7, bei dem der Schritt des Generierens des zweiten Halb-Entschlüsselung-Tokens (WME) durch die zweite Vorrichtung (ME) den Schritt eines Anwendens der bilinearen Funktion auf die Summe von der zweiten (r2SIM) und der dritten (r1ME) Größe und auf einen ersten Punkt umfasst. Procédé selon la revendication 7, dans lequel l'étape de générer le deuxième demi-jeton de décryptage (WME) par le deuxième dispositif (ME), comprend l'étape d'appliquer la fonction bilinéaire à la somme de la deuxième (r2SIM) et de la troisième (r1ME) quantités, et à un premier point. The method according to claim 7, wherein the step of generating the second half decryption token (WME) by the second device (ME), comprises the step of applying the bilinear function to the sum of the second (r2SIM) and the third (r1ME) quantities, and to a first point.
  9. 9
    Das Verfahren gemäß Anspruch 2, bei dem der Schritt e) den Schritt eines unabhängigen Anwendens einer zweiten Hash-Funktion auf ein inneres Produkt von dem ersten (WSIM) und dem zweiten (WME) Halb-Entschlüsselung-Token durch jede Vorrichtung umfasst, um den gemeinschaftlichen Entschlüsselungsschlüssel (W) zu generieren. Procédé selon la revendication 2, dans lequel ladite étape e) comprend l'étape d'appliquer, indépendamment par chaque dispositif, une deuxième fonction de hachage à un produit interne entre le premier (WSIM) et le deuxième (WME) demi-jetons de décryptage, afin de générer ladite clé de décryptage conjointe (W). The method according to claim 2, wherein said step e) comprises the step of applying, independently by each device, a second hash function to an internal product between the first (WSIM) and the second (WME) half decryption tokens, in order to generate said joint decryption key (W).
  10. 10
    Das Verfahren gemäß Anspruch 5 und 6, das die folgenden Schritte umfasst:- Zuordnen eines gemeinschaftlichen öffentlichen Schlüssels, der der Summe des zweiten (H(IDME)) und des ersten (H(IDSIM)) öffentlichen Schlüssels entspricht, zu der gemeinsamen Entität, die die erste (SIM) und die zweite (ME) Vorrichtung umfasst;- Zuordnen eines gemeinschaftlichen privaten Schlüssels, der als das Produkt des gemeinschaftlichen öffentlichen Schlüssels und der Summe der zweiten (rME) und der ersten (rSIM) Zufallszahl definiert ist oder alternativ als das Produkt des gemeinschaftlichen öffentlichen Schlüssels und der Summe des zweiten (sTA-ME) und des ersten (sTA-SIM) Hauptschlüssels definiert ist, zu der gemeinsamen Entität. Procédé selon les revendications 5 et 6, comprenant les étapes consistant à: - associer à l'entité commune comprenant le premier (SIM) et le deuxième (ME) dispositifs, une clé publique conjointe correspondant à la somme de la deuxième (H (IDME)) et de la première (H (IDSIM)) clés publiques.- associer, avec ladite entité commune, une clé privée conjointe définie comme le produit de ladite clé publique conjointe et de la somme du deuxième (rME) et du premier (rSIM) nombres aléatoires ou, alternativement, définie comme le produit de la clé publique conjointe et de la somme de la deuxième (STA-ME) et de la première (STA-SIM) clés maîtresses. The method according to claims 5 and 6, comprising the steps of: - associating with the common entity comprising the first (SIM) and the second (ME) devices, a joint public key corresponding to the sum of the second (H(IDME)) and the first (H(IDSIM)) public keys.- associating, with said common entity, a joint private key defined as the product of said joint public key and the sum of the second (rME) and the first (rSIM) random numbers or, alternatively, defined as the product of the joint public key and the sum of the second (sTA-ME) and the first (sTA-SIM) master keys.
  11. 11
    Das Verfahren gemäß Anspruch 2, bei dem der Schritt b) bezüglich der Übertragungsvorrichtung die folgenden Schritte umfasst:- Erfassen eines weiteren ersten und eines weiteren zweiten Punktes von der ersten (TA-SIM) bzw. der zweiten (TA-ME) vertrauenswürdigen Autorität für die Generierung eines gemeinschaftlichen öffentlichen Punktes;- Generieren des ersten Punktes als das Produkt einer weiteren Zufallszahl und eines Punkts und einer Zeichenfolge von Bits, um die unverschlüsselte Nachricht zu verschlüsseln;- Generieren der verschlüsselten Nachricht, die den ersten Punkt in einem ersten. Teil und das Ergebnis einer XOR-Verknüpfung zwischen Bits zwischen der unverschlüsselten Nachricht und der Zeichenfolge in einem zweiten Teil umfasst. Procédé selon la revendication 2, dans lequel ladite étape b) comprend, en rapport avec le dispositif de transmission, les étapes consistant à: - acquérir un premier point supplémentaire et un deuxième point supplémentaire à partir du premier (TA-SIM) et du deuxième (TA-ME) tiers de confiance, respectivement, pour la génération d'un point public conjoint;- générer le premier point comme le produit d'un nombre aléatoire supplémentaire et d'un point et d'une chaîne de bits afin de crypter le message en clair;- générer le message crypté comprenant le premier point dans une première partie et le résultat d'une opération de OU exclusif entre des bits entre le message en clair et ladite chaîne dans une deuxième partie. The method according to claim 2, wherein said step b) comprises, with relation to the transmission device, the steps of: - acquiring a further first and a further second point from the first (TA-SIM) and the second (TA-ME) trusted authorities, respectively, for the generation of a joint public point;- generating the first point as the product of a further random number and a point and a string of bits in order to encrypt the message in clear;- generating the encrypted message comprising the first point in a first part and the result of an XOR operation between bits between the message in clear and said string in a second part.
  12. 12
    Das Verfahren gemäß Anspruch 11, das den Schritt eines Wiederherstellens der unverschlüsselten Nachricht durch ein Ausführen einer weiteren XOR-Verknüpfung zwischen Bits zwischen der verschlüsselten Nachricht und dem gemeinschaftlichen Entschlüsselungsschlüssel (W) umfasst, wobei der gemeinschaftliche Entschlüsselungsschlüssel mit der Zeichenfolge von Bits mathematisch übereinstimmend ist. Procédé selon la revendication 11, comprenant l'étape de restaurer le message en clair en effectuant une opération de OU exclusif supplémentaire entre des bits entre le message crypté et la clé de décryptage conjointe (W), ladite clé de décryptage conjointe étant mathématiquement concordante avec la chaîne de bits. The method according to claim 11, comprising the step of restoring the message in clear by carrying out a further XOR operation between bits between the encrypted message and the joint decryption key (W), said joint decryption key being mathematically coincident with the string of bits.
  13. 13
    Das Verfahren gemäß Anspruch 3, das ferner die folgenden Schritte umfasst:- Senden einer verschlüsselten Nachricht, die die erste Größe (r1SIM) und die zweite Größe (r2SIM;s'SIM) enthält, von der ersten vertrauenswürdigen Autorität (TA-SIM) an die erste (SIM) bzw. die zweite (ME) Vorrichtung:- Senden einer verschlüsselten Nachricht, die die vierte Größe (r2ME;s'ME) und die dritte Größe (r1ME) enthält, von der zweiten vertrauenswürdigen Autorität (TA-ME) an die erste (SIM) bzw. die zweite (ME) Vorrichtung. Procédé selon la revendication 3 comprenant les étapes supplémentaires de: - envoyer un message crypté contenant la première quantité (r1SIM) et la deuxième quantité (r2SIM;s'SIM), à partir du premier tiers de confiance (TA-SIM) au premier (SIM) et au deuxième (ME) dispositifs, respectivement.- envoyer un message crypté contenant la quatrième quantité (r2ME;S'ME) et la troisième quantité (r1ME), à partir du deuxième tiers de confiance (TA-ME) au premier (SIM) et au deuxième (ME) dispositifs, respectivement. The method according to claim 3 comprising the further steps of: - sending of an encrypted message containing the first quantity (r1SIM) and the second quantity (r2SIM;s'SIM), from the first trusted authority (TA-SIM) to the first (SIM) and the second (ME) devices, respectively.- sending of an encrypted message containing the fourth quantity (r2ME;s'ME) and the third quantity (r1ME), from the second trusted authority (TA-ME) to the first (SIM) and the second (ME) devices, respectively.
  14. 14
    Das Verfahren gemäß Anspruch 13, bei dem der Schritt des Sendens der ersten Größe (r1SIM) von der ersten vertrauenswürdigen Autorität (TA-SIM) an die erste Vorrichtung (SIM) durch ein Verschlüsseln einer derartigen Größe gemäß einem Verschlüsselungsverfahren vom symmetrischen Typ oder einem identitätsbasierten Verschlüsselungsverfahren ausgeführt wird. Procédé selon la revendication 13, dans lequel ladite étape d'envoi de la première quantité (r1SIM) depuis le premier tiers de confiance (TA-SIM) au premier dispositif (SIM) est effectuée en cryptant une telle quantité en conformité avec un procédé cryptographique de type symétrique ou un procédé de cryptage basé sur une identité. The method according to claim 13, wherein said step of sending the first quantity (r1SIM) from the first trusted authority (TA-SIM) to the first device (SIM) is carried out by encrypting such quantity in accordance with a symmetrical type cryptographic method or an identity based encryption method.
  15. 15
    Das Verfahren gemäß Anspruch 13, bei dem der Schritt des Sendens der zweiten Größe (r2SIM;s'SIM) von der ersten vertrauenswürdigen Autorität (TA-SIM) an die zweite Vorrichtung (ME) durch ein Verschlüsseln einer derartigen Größe gemäß einem identitätsbasierten Verschlüsselungsverfahren ausgeführt wird. Procédé selon la revendication 13, dans lequel ladite étape d'envoi de la deuxième quantité (r2SIM;S'SIM) depuis le premier tiers de confiance (TA-SIM) au deuxième dispositif (ME) est effectuée en cryptant une telle quantité en conformité avec un procédé de cryptage basé sur une identité. The method according to claim 13, wherein said step of sending the second quantity (r2SIM;s'SIM) from the first trusted authority (TA-SIM) to the second device (ME) is carried out by encrypting such quantity in accordance with an identity based encryption method.
  16. 16
    Das Verfahren gemäß Anspruch 14, das zusätzlich den Schritt des Generierens einer elektronischen Signatur ausgehend von der ersten Größe (r1SIM) durch dieselbe erste vertrauenswürdige Autorität (TA-SIM) umfasst. Procédé selon la revendication 14, comprenant en plus l'étape de générer, par le même premier tiers de confiance (TA-SIM), une signature électronique en commençant à partir de ladite première quantité (r1SIM). The method according to claim 14, additionally comprising the step of generating, by the same first trusted authority (TA-SIM), an electronic signature by starting from said first quantity (r1SIM).
  17. 17
    Das Verfahren gemäß Anspruch 16, das den Schritt eines Sendens einer Nachricht, die die erste Größe (r1SIM) und die elektronische Signatur umfasst, an die erste Vorrichtung (SIM) durch die erste vertrauenswürdige Autorität (TA-SIM) umfasst, wobei die Nachricht gemäß einem identitätsbasierten Verschlüsselungsverfahren verschlüsselt ist. Procédé selon la revendication 16, comprenant l'étape d'envoyer un message comprenant ladite première quantité (r1SIM) et ladite signature électronique au premier dispositif (SIM) par le premier tiers de confiance (TA-SIM), ledit message étant crypté en conformité avec un procédé de cryptage basé sur une identité. The method according to claim 16, comprising the step of sending a message comprising said first quantity (r1SIM) and said electronic signature to the first device (SIM) by the first trusted authority (TA-SIM), said message being encrypted in accordance with an identity based encryption method.
  18. 18
    Das Verfahren gemäß Anspruch 4, das den Schritt eines Sendens der ersten (IDSIM) und der weiteren ersten (ID-TA-SIM) Identität von der ersten (SIM) an die zweite (ME) Vorrichtung und eines Sendens der zweiten (IDME) und der weiteren zweiten (IDTA-ME) Identität von der zweiten an die erste Vorrichtung umfasst. Procédé selon la revendication 4, comprenant l'étape d'envoyer ladite première identité (IDSIM) et ladite première identité supplémentaire (IDTA-SIM) depuis le premier (SIM) au deuxième (ME) dispositif, et d'envoyer ladite deuxième identité (IDME) et ladite deuxième identité supplémentaire (IDTA-ME) depuis le deuxième au premier dispositif. The method according to claim 4, comprising the step of sending said first (IDSIM) and said further first (IDTA-SIM) identities from the first (SIM) to the second (ME) device, and of sending said second (IDME) and said further second (IDTA-ME) identities from the second to the first device.
  19. 19
    Das Verfahren gemäß Anspruch 18, das den Schritt eines Sendens einer verschlüsselten Nachricht, die die zweite (IDME) und die weitere zweite (IDTA-ME) Identität enthält, an die erste vertrauenswürdige Autorität (TA-SIM) durch die erste Vorrichtung (SIM) umfasst, wobei die Nachricht gemäß einem Verschlüsselungsverfahren vom symmetrischen Typ oder einem identitätsbasierten Verschlüsselungsverfahren verschlüsselt ist. Procédé selon la revendication 18, comprenant l'étape d'envoyer un message crypté contenant ladite deuxième identité (IDME) et ladite deuxième identité supplémentaire (IDTA-ME) au premier tiers de confiance (TA-SIM) par le premier dispositif (SIM), ledit message étant crypté en conformité avec un type symétrique ou à un procédé de cryptage basé sur une identité. The method according to claim 18, comprising the step of sending an encrypted message containing said second (IDME) and said further second (IDTA-ME) identities to the first trusted authority (TA-SIM) by the first device (SIM), said message being encrypted in accordance with a symmetrical type or an identity based encryption method.
  20. 20
    Das Verfahren gemäß Anspruch 18, das den Schritt eines Sendens einer verschlüsselten Nachricht, die die zweite (IDME), die weitere zweite (IDTA-ME) Identität und optional die erste Identität (IDSIM) enthält, von der ersten Vorrichtung (SIM) an die erste vertrauenswürdige Autorität (TA-SIM) umfasst, wobei die Nachricht eine elektronische Signatur der oben genannten Identitäten umfasst, die durch die erste Vorrichtung generiert werden und gemäß einem identitätsbasierten Verschlüsselungsverfahren verschlüsselt sind. Procédé selon la revendication 18, comprenant l'étape d'envoyer un message crypté contenant la deuxième identité (IDME), la deuxième identité supplémentaire (IDTA-ME) et, optionnellement, la première identité (IDSIM) au premier tiers de confiance (TA-SIM) depuis le premier dispositif (SIM), ledit message comprenant une signature électronique des identités susmentionnées généré par le premier dispositif et étant crypté en conformité avec un procédé de cryptage basé sur une identité. The method according to claim 18, comprising the step of sending an encrypted message containing the second (IDME), the further second (IDTA-ME) identities and, optionally, the first identity (IDSIM) to the first trusted authority (TA-SIM) from the first device (SIM), said message comprising an electronic signature of the aforesaid identities generated by the first device and being encrypted in accordance with an identity based encryption method.
  21. 21
    Das Verfahren gemäß Anspruch 1, bei dem der Schritt d) die folgenden Schritte umfasst:- Senden des ersten Entschlüsselungs-Tokens (WSIM) von der ersten Vorrichtung (SIM) zu der zweiten Vorrichtung (ME) in einer verschlüsselten Weise;- Senden des zweiten Entschlüsselungs-Tokens (WME) von der zweiten Vorrichtung (ME) an die erste Vorrichtung (SIM) in einer verschlüsselten Weise. Procédé selon la revendication 1, dans lequel ladite étape d) comprend les étapes consistant à: - envoyer le premier jeton de décryptage (WSIM) depuis le premier dispositif (SIM) au deuxième dispositif (ME) d'une manière cryptée;- envoyer le deuxième jeton de décryptage (WME) depuis le deuxième dispositif (ME) au premier dispositif (SIM) d'une manière cryptée. The method according to claim 1, wherein said step d) comprises the steps of: - sending the first decryption token (WSIM) from the first device (SIM) to the second device (ME) in an encrypted manner;- sending the second decryption token (WME) from the second device (ME) to the first device (SIM) in an encrypted manner.
  22. 22
    An encrypted communication system using keys comprising:- a first electronic device (SIM) associated with a first trusted authority (TA-SIM),- a second electronic device (ME) associated with a second trusted authority (TA-ME),characterised by being configured in such a manner that the encrypted communication is established in accordance with at least one of the preceding claims. Ein Verschlüsselte-Kommunikation-System, das Schlüssel verwendet und folgende Merkmale umfasst: - eine erste elektronische Vorrichtung (SIM), die einer ersten vertrauenswürdigen Autorität (TA-SIM) zugeordnet ist,- eine zweite elektronische Vorrichtung (ME), die einer zweiten vertrauenswürdigen Autorität (TA-ME) zugeordnet ist,dadurch gekennzeichnet, dass dasselbe in einer derartigen Weise konfiguriert ist, dass die verschlüsselte Kommunikation gemäß zumindest einem der vorhergehenden Ansprüche eingerichtet ist. Système de communication crypté utilisant des clés comprenant: - un premier dispositif électronique (SIM) associé à un premier tiers de confiance (TA-SIM),- un deuxième dispositif électronique (ME) associé à un deuxième tiers de confiance (TA-ME),caractérisé en étant configuré d'une telle manière que la communication cryptée est établie en conformité avec au moins l'une des revendications précédentes.
Independent claims22