EP1747638B1

Systems and methods to securely generate shared keys

Abstract

This record has no abstract on file.

EP1747638B1, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Expired 2 May 2025, 1.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 3 independent, 16 dependent

  1. 1
    A method carried out by a first system for establishing a secure bidirectional communication path between the first system and a second system for an exchange of one or more messages, the method comprising:generating (108, 204, 210) a first key pair having a first public key and a first private key;generating (108, 204, 210) a second key pair having a second public key and a second private key, the second public key being generated based upon a shared secret known to the first system and the second system;wherein the first public key is independent of the shared secret;sending (110, 206) the second public key and the first public key to the second system;receiving (118, 208, 214) a third public key and a fourth public key generated by the second system, the fourth public key being generated based upon the shared secret;wherein the third public key is independent of the shared secret;calculating (120, 212, 216) a first master key based upon the first private key, the second private key, the third public key and the fourth public key, wherein the first master key is configured to be used in encryption of one or more messages;generating (432, 462) a new second key pair having a new second public key and a new second private key;wherein the new second public key is independent of the shared secret;receiving (446, 460) a new fourth public key from the second system;wherein the new fourth public key is independent of the shared secret;and calculating (440, 464) a new master key based upon the first private key, the new second private key, the third public key, and the new fourth public key using an elliptic curve calculation.
  2. 18
    A first system for establishing a secure bidirectional communication path to a second system for exchanging one or more messages, comprising:means for generating (108, 204, 210) a first key pair having a first public key and a first private key;means for generating (108, 204, 210) a second key pair having a second public key and a second private key, the second public key being generated based upon a shared secret known to the first system and the second system;wherein the first public key is generated independent of the shared secret;means for sending (110, 206) the second public key and the first public key to the second system;means for receiving (118, 208, 214) a third public key and a fourth public key generated by the second system, the fourth public key being generated based upon the shared secret;wherein the third public key is independent of the shared secret;means for calculating (120, 212, 216) a first master key based upon the first private key, the second private key, the third public key and the fourth public key, wherein the first master key is configured to be used in encryption of one or more messages;means for generating (432, 462) a new second key pair having a new second public key and a new second private key;wherein the new second public key is generated independent of the shared secret;means for receiving (446, 460) a new fourth public key from the second system;wherein the new fourth public key is independent of the shared secret;and means for calculating (440, 464) a new master key based upon the first private key, the new second private key, the third public key, and the new fourth public key using an elliptic curve calculation.
  3. 19
    A first system for establishing a secure bidirectional communication path to a second system for exchanging one or more messages, comprising:a memory;and a processing unit coupled to the memory, wherein the processing unit is configured to execute steps of: generating (108, 204, 210) a first key pair having a first public key and a first private key;generating (108, 204, 210) a second key pair having a second public key and a second private key, the second public key being generated based upon a shared secret known to the first system and the second system;wherein the first public key is generated independent of the shared secret;sending (110, 206) the second public key and the first public key to the second system;receiving (118, 208, 214) a third public key and a fourth public key generated by the second system, the fourth public key being generated based upon the shared secret;wherein the third public key is independent of the shared secret;calculating (120, 212, 216) a first master key based upon the first private key, the second private key, the third public key and the fourth public key, wherein the first master key is configured to be used in encryption of one or more messages;generating (432, 462) a new second key pair having a new second public key and a new second private key;wherein the new second public key is generated independent of the shared secret;receiving (446, 460) a new fourth public key from the second system;wherein the new fourth public key is independent of the shared secret;and calculating (440, 464) a new master key based upon the first private key, the new second private key, the third public key, and the new fourth public key using an elliptic curve calculation.