EP2315391B1

Key agreement and transport protocol with implicit signatures

Abstract

This record has no abstract on file.

EP2315391B1, drawing sheet 1
Sheet 1 of 20

Term

Term ended

Expired 18 October 2016, 9.9 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

6 claims: 3 independent, 3 dependent

  1. 1
    A method of establishing a session key K at a correspondent A in a public key data communication system, the session key K for use in communication with a correspondent B over a communication channel, said correspondent A having a private key d A and a public key Q A , wherein said public key Q A is derived from a point P on an elliptic curve defined over a finite field and said private key d A , said method comprising:said correspondent A selecting a random integer k and obtaining a function by scalar multiplication of said point P and said random integer k;said correspondent A generating a signature s A by combining said random integer k, an integer derived from said function and said private key d A ;said correspondent A sending to said correspondent B, a message including said function;said correspondent A computing said session key K by scalar multiplication of public information of said correspondent B and said signature S A ;wherein said signature s A is not transmitted by said correspondent A;and wherein said signature s A of said correspondent A is of the form k + r A d A mod G, r A is an integer derived from said function and G is an order of said point P and is a prime number.
  2. 3
    A method according to any one of the preceding claims wherein said random integer k is selected such that 1 ≤ k ≤ G - 1.
  3. 6
    A computer readable medium having stored thereon computer readable instructions for performing the method of any one of claims 1 to 3.