EP2315390B1

Key agreement and transport protocol with implicit signatures

Abstract

This record has no abstract on file.

EP2315390B1, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

13 claims: 1 independent, 12 dependent

  1. 1
    A method of establishing a key K at a correspondent A in a public key data communication system, the key K for use in communication with a correspondent B over a communication channel, said correspondent A having a private key d A and a public key Q A , wherein said public key Q A is derived from a point P on an elliptic curve defined over a finite field and said private key d A , said method comprising:said correspondent A selecting a first random integer k and obtaining a first function by scalar multiplication of said point P and said first random integer k;said correspondent A generating a signature s A by combining said random integer k, said private key d A and an integer derived from said first function;said correspondent A sending to said correspondent B, a message including said first function;said correspondent A receiving from said correspondent B, a message including a second function, the second function obtained by scalar multiplication of said point P and a second random integer m selected by said correspondent B;said correspondent A constructing said key K by scalar multiplication of public information of said correspondent B and the signature s A ;wherein said signature s A is not transmitted by said correspondent A;and wherein said signature s A is obtained by computing ( k + r A d A ) mod n , wherein n is an order of said point P.