EP2315390A2

Key agreement and transport protocol with implicit signatures

Abstract

A key establishment protocol between a pair of correspondents includes the generation by each correspondent of respective signatures. The signatures are derived from information that is private to the correspondent and information that is public. After exchange of signatures, the integrity of exchange messages can be verified by extracting the public information contained in the signature and comparing it with information used to generate the signature. A common session key may then be generated from the public and private information of respective ones of the correspondents.

EP2315390A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

24 claims: 9 independent, 15 dependent

  1. 1
    A method of authenticating a key established at a correspondent A in a public key data communication system to permit exchange of information over a communication channel, said correspondent A having a private key and a public key, wherein said public key is derived from a generator and said private key, said method comprisingg the steps of:said correspondent A selecting a random integer k and exponentiating a first function including said generator to a power to provide a first exponentiated function r a ;said correspondent A generating a signature s A from said random integer k and an integer r a derived from said first exponentiated function r a ;said correspondent A forwarding to a correspondent B a message derived from said first exponentiated function r a , wherein said correspondent B can utilize information made public by said correspondent A and information private to said correspondent B to construct a session key K;said correspondent A receiving from said correspondent B a message derived from a second exponentiated function r b , wherein r b can be obtained by exponentiating a second function including said generator to a power by said correspondent B;and said correspondent A constructing said session key K by exponentiating information made public by said correspondent B with information that is private to said correspondent A.
  2. 4
    A method according to any of claims 1 to 3 wherein said information that is private to said correspondent A is the signature s A .
  3. 7
    A method according to any of claims 1 to 4 wherein said first function including said generator includes a public key of said correspondent B.
  4. 12
    A method according to any of claims 1 to 10 wherein said generator α is a generator g of a subgroup of Z * p of order q, wherein q is a prime divisor of p-1.
  5. 14
    A method according to any of claims 1 to 10 wherein said generator α is a point P of order n on an elliptic curve defined over a finite field Fq, and wherein exponentiation is performed by scalar multiplication on said elliptic curve.
  6. 19
    A method according to any of claims 14 to 18 wherein said session key K is of the form s A s B P, wherein s B is a signature generated by said correspondent B by utilizing a second random integer and a second integer r b derived from said second exponentiating function r b .
  7. 20
    A method according to any of claims 14 to 19 wherein said signature s A is computed from said random integer k, said integer r a and the private key d a of said first correspondent A as s A = ( k + r a d a ) mod n.
  8. 21
    A method according to any of claims 14 to 20 wherein said correspondent A computes the session key from said signature s A , said second exponentiated function r b , a second integer r b derived from said second exponentiating function r b and a public key Q b of said correspondent B as K = s A ( r b + r b Q b ).
  9. 22
    A method according to any of claims 14 to 21 wherein the point P is of prime order.