EP1768300A1

Key agreement and transport protocol with implicit signatures

Abstract

A key establishment protocol between a pair of correspondents includes the generation by each correspondent of respective signatures. The signatures are derived from information that is private to the correspondent and information that is public. After exchange of signatures, the integrity of exchange messages can be verified by extracting the public information contained in the signature and comparing it with information used to generate the signature. A common session key may then be generated from the public and private information of respective ones of the correspondents.

EP1768300A1, drawing sheet 1
Sheet 1 of 40

Term

Term ended

Projected expiry passed 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

21 claims: 2 independent, 19 dependent

  1. 1
    A method of establishing a session key between a pair of correspondents A,B in a public key data communication system to permit exchange of information therebetween over a communication channel, each of said correspondents having a respective private key a,b and a public key p A , p B derived from a generator .α. and respective ones of said private keys a,b, said method including the steps of:i) a first of said correspondents A selecting a first random integer x and exponentiating a first function f(α) including said generator to a power g(x) to provide a first exponentiated function f(α) g(x) ;ii) said first correspondent A generating a first signature S A from said random integer x said exponentiated function f(α) g(x) and said private key a to bind said integer x and said private key a, said first correspondent A maintaining said first signature private to itself;iii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(α) g(x) ;iv) said correspondent B selecting a second random integer y and exponentiating a second function f(α) including said generator to a power g(y) to provide a second exponentiated function f(α) g(y) and generating a signature S B obtained from said second integer y said second exponentiated function f(α) g(y) and said private key b to bind said integer y and said private key b, said second correspondent B maintaining said second signature S B private to itself;v) said second correspondent B forwarding a message to said first correspondent A including said second exponentiated function f(α) g(y) ;and vi) each of said correspondents constructing a session key K by exponentiating information made public by the other correspondent with information that is private to themselves whereby subsequent decryption of information confirms establishment of a common key and thereby the identity of said correspondents.
  2. 4
    A method according to any one of claims 1 to 3 wherein said information that is private to themselves is the respective first signature and second signature.
  3. 7
    A method according to any one of claims 1 to 4 wherein said first function f(α) including said generator includes the public key p B of said second correspondent.
  4. 8
    A method according to any one of claims 1 to 4 wherein said second function f(α) including said generator includes the public key p A of said first correspondent.
  5. 10
    A method according to any one of claims 1 to 9 wherein said signature generated by a respective one of the correspondents combine the random integer, exponentiated function and private key of that one correspondent.
  6. 17
    A method of transporting a session key K between a pair of correspondents A,B in a public key data communication system to establish a common key to permit exchange of information therebetween over a communication channel, each of said correspondents having a respective private key a,b and a public key p A , p B derived from a generator α and respective ones of said private keys a,b, said method including the steps of:i) a first of said correspondents A selecting a first random integer x and exponentiating a first function f(α) including said generator to a power g(x) to provide a first exponentiated function f(α) g(x) ;ii) said first correspondent A generating a first signature S A from said random integer x and said exponentiated function f(α) g(x) and said private key a to bind said integer and said private key a, said first correspondent A maintaining said first signature private to itself;iii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(α) g(x) ;iv) said first correspondent computing said session key K from said public key p B of said second correspondent B and said signature S A ;v) said second correspondent B utilizing the public key p A of said first correspondent and information in said message to compute a session key K' corresponding to said session key K,.