EP2104268B1

Key agreement and transport protocol with implicit signatures

Abstract

This record has no abstract on file.

EP2104268B1, drawing sheet 1
Sheet 1 of 40

Term

Term ended

Expired 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

9 claims: 4 independent, 5 dependent

  1. 1
    A method of establishing a session key K at a correspondent A in a public key data communication system, the session key for use in communication with a correspondent B over a communication channel, said correspondent A having a private key a and a public key p A , wherein said public key p A is derived from a generator α of a group and said private key a, said method comprising:said correspondent A selecting a random integer x and exponentiating said generator α to obtain an exponentiated function of the form α x ;said correspondent A generating a signature s A by combining said random integer x, said exponentiated function and said private key a;said correspondent A sending to said correspondent B a message including said exponentiated function;said correspondent A computing said session key K by exponentiating public information of said correspondent B with said signature s A ;wherein said signature s A is not transmitted by said correspondent A;and wherein said signature s A of said correspondent A is of the form of one of: x = r A ‾ a mod G ;x + r A ⁢ a ⁢ α a mod G ;x + r A ⁢ a mod G ;wherein r A is said exponentiated function, r A is an integer derived from said exponentiated function, and G is an order of said generator α.
  2. 3
    A method according to any one of the preceding claims wherein said random integer x is selected such that 1 ≤ x ≤ G - 1.
  3. 4
    A method according to any one of the preceding claims wherein said generator α is a generator of a multiplicative group Z p * , wherein p is a prime number.
  4. 5
    A method according to any one of claims 1 to 3 wherein said generator α is a point P on an elliptic curve defined over a finite field Fq, and wherein exponentiation is performed by scalar multiplication on said elliptic curve.
  5. 8
    A computer readable medium having stored thereon computer readable instructions for performing the method of any one of claims 1 to 7.