EP1768300B1

Key agreement and transport protocol with implicit signatures

Abstract

This record has no abstract on file.

EP1768300B1, drawing sheet 1
Sheet 1 of 39

Term

Term ended

Expired 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

21 claims: 3 independent, 18 dependent

  1. 1
    A method of establishing a session key between a pair of correspondents A,B in a public key data communication system to permit exchange of information therebetween over a communication channel, each of said correspondents having a respective private key a,b and a public key p A , p B derived from a generator α and respective ones of said private keys a,b, said method including the steps of:i) a first of said correspondents A selecting a first random integer x and exponentiating a first function f(α) including said generator to a power g(x) to provide a first exponentiated function f(α) g(x) ;ii) said first correspondent A generating a first signature S A from said random integer x said exponentiated function f(α) g(x) and said private key a to bind said integer x and said private key a, said first correspondent A maintaining said first signature private to itself;iii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(α) g(x) ;iv) said correspondent B selecting a second random integer y and exponentiating a second function f(α) including said generator to a power g(y) to provide a second exponentiated function f(α) g(y) and generating a signature S B obtained from said second integer y said second exponentiated function f(α) g(y) and said private key b to bind said integer y and said private key b, said second correspondent B maintaining said second signature S B private to itself;v) said second correspondent B forwarding a message to said first correspondent A including said second exponentiated function f(α) g(y) ;and vi) each of said correspondents constructing a session key K by exponentiating information made public by the other correspondent with information that is private to themselves whereby subsequent decryption of information confirms establishment of a common key and thereby the identity of said correspondents.
  2. 4
    A method according to any one of claims 1 to 3 wherein said information that is private to themselves is the respective first signature and second signature.
  3. 7
    A method according to any one of claims I to 4 wherein said first function f(α) including said generator includes the public key p B of said second correspondent.
  4. 8
    A method according to any one of claims 1 to 4 wherein said second function f(α) including said generator includes the public key p A of said first correspondent.
  5. 10
    A method according to any one of claims 1 to 9 wherein said signature generated by a respective one of the correspondents combines the random integer, exponentiated function and private key of that one correspondent.
  6. 17
    A method of transporting a session key K between a pair of correspondents A,B in a public key data communication system to establish a common key to permit exchange of information therebetween over a communication channel, each of said correspondents having a respective private key a,b and a public key p A , p B derived from a generator α and respective ones of said private keys a,b, said method including the steps of:i) a first of said correspondents A selecting a first random integer x and exponentiating a first function f(α) including said generator to a power g(x) to provide a first exponentiated function f(α) g(x) ;ii) said first correspondent A generating a first signature S A from said random integer x and said exponentiated function f(α) g(x) and said private key a to bind said integer and said private key a, said first correspondent A maintaining said first signature private to itself;iii) said first correspondent A forwarding to a second correspondent B a message including said first exponentiated function f(α) g(x) ;iv) said first correspondent computing said session key K from said public key p B of said second correspondent B and said signature S A ;v) said second correspondent B utilizing the public key p A of said first correspondent and information in said message to compute a session key K' corresponding to said session key K.