EP2315391A2

Key agreement and transport protocol with implicit signatures

Abstract

A key establishment protocol between a pair of correspondents includes the generation by each correspondent of respective signatures. The signatures are derived from information that is private to the correspondent and information that is public. After exchange of signatures, the integrity of exchange messages can be verified by extracting the public information contained in the signature and comparing it with information used to generate the signature. A common session key may then be generated from the public and private information of respective ones of the correspondents.

EP2315391A2, drawing sheet 1
Sheet 1 of 59

Term

Term ended

Projected expiry passed 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

13 claims: 7 independent, 6 dependent

  1. 1
    A method of transporting a session key K from a correspondent A to a correspondent B in a public key data communication system to establish a common key to permit exchange of information over a communication channel, said correspondent A having a private key a and a public key p A , wherein said public key p A is derived from a generator α and said private key a, said method including the steps of:said correspondent A selecting a random integer x and exponentiating a function f(α) including said generator to a power g(x) to provide an exponentiated function f(α) g(x) ;said correspondent A generating a first signature s A by combining said random integer x, said exponentiated function f(α) g(x) and said private key a;said correspondent A forwarding to said correspondent B a message including said exponentiated function f(α) g(x) , whereby said correspondent B can utilize said public key p A of said first correspondent, information in said message and information private to said correspondent B to establish a session key K';and said correspondent A computing said session key K by exponentiating information made public by said correspondent B with information that is private to said correspondent A, wherein said session key K corresponds to said session K'.
  2. 4
    A method according to any of claims 1 to 3 wherein said generator α is a generator of the multiplicative group Z * p .
  3. 6
    A method according to any of claims 1 to 5 wherein said random integer x is selected such that 1 ≤ x ≤ p - 2 , wherein p is a prime.
  4. 7
    A method according to any of claims 1 to 6 wherein said exponentiated function f(α) including said generator is said generator itself.
  5. 8
    A method according to any of claims 1 to 7 wherein said power g(x) is the random integer x.
  6. 9
    A method according to any of claims 1 to 8 wherein said generator α is a point P of order n on an elliptic curve defined over a finite field Fq, and wherein exponentiation is performed by scalar multiplication on said elliptic curve.
  7. 11
    A method according to any of claims 1 to 10 wherein said first correspondent A avoids transmission of said first signature S A .