EP2315389A2

Key agreement and transport protocol with implicit signatures

Abstract

A key establishment protocol between a pair of correspondents includes the generation by each correspondent of respective signatures. The signatures are derived from information that is private to the correspondent and information that is public. After exchange of signatures, the integrity of exchange messages can be verified by extracting the public information contained in the signature and comparing it with information used to generate the signature. A common session key may then be generated from the public and private information of respective ones of the correspondents.

EP2315389A2, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Projected expiry passed 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

27 claims: 6 independent, 21 dependent

  1. 1
    A method of establishing a session key K at a correspondent A in a public key data communication system to permit exchange of information over a communication channel, said correspondent A having a private key a and a public key p A , wherein said public key p A is derived from a generator α and said private key a, said method comprising the steps of:said correspondent A selecting a first random integer x and exponentiating a first function f(α) including said generator to a power g(x) to provide a first exponentiated function f(α) g(x) ;said correspondent A generating a signature s A by combining said random integer x, said first exponentiated function f(α) g(x) and said private key a;said correspondent A forwarding to a correspondent B a message including said first exponentiated function f(α) g(x) , whereby said correspondent B can utilize information made public by said correspondent A and information private to said correspondent B to compute said session key K;said correspondent A receiving from said correspondent B a message including a second exponentiated function f(α) g(y) ;wherein y is a second random integer selected by said correspondent B, wherein g(y) is a function of said second random integer y, and wherein f(α) is a second function of said generator;and said correspondent A constructing said session key K by exponentiating information made public by said correspondent B with information that is private to said correspondent A.
  2. 4
    A method according to any of claims 1 to 3 wherein said message received by said correspondent A includes an identification of said correspondent B.
  3. 5
    A method according to any one of claims 1 to 4 wherein said information that is private to said correspondent A is the signature s A .
  4. 8
    A method according to any one of claims 1 to 5 wherein said second function f(α) including said generator includes the public key p A of said correspondent A.
  5. 17
    A method according to any of claims 11 to 16 wherein said first random integer x and said second random integer y are selected such that 1 ≤ x ≤ p - 2 and 1 ≤ y ≤ p - 2, wherein p is a prime.
  6. 18
    A method according to any of claims 1 to 9 wherein said generator α is a point P of order n on an elliptic curve defined over a finite field Fq, and wherein exponentiation is performed by scalar multiplication on said elliptic curve.
  7. 23
    A method according to any of claims 18 to 22, wherein said session key K is of the form s A s B P, wherein s B is a signature generated by said correspondent B and obtained by utilizing said second random integer y, said second exponentiated function f(α) g(y) and a private key of said correspondent B.
  8. 24
    A method according to any of claims 18 to 23, wherein the point P is of prime order.