EP2363977A1

Methods and devices for computing a shared encryption key

Abstract

Embodiments described herein are generally directed to methods and devices in which computing devices, and mobile devices in particular, establish a shared encryption key for a device group comprising at least three mobile devices. In accordance with one example embodiment, a public key of a mobile device is computed using a shared password as performed in accordance with authentication acts of a password-authenticated key exchange protocol, and transmitted to at least one other mobile device of the group. A public value is computed as a function of a mobile device private key and of a public key of at least one other mobile device of the device group, in accordance with a group key establishment protocol. The public values of the mobile devices of the device group are used to compute a shared encryption key.

EP2363977A1, drawing sheet 1
Sheet 1 of 8

Term

3.4 yearsto projected expiry

Projected expiry 26 February 2030, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 3 independent, 12 dependent

  1. 1
    A method of computing a shared encryption key (k) for a group of n mobile devices, the group (400A, 400B) of n mobile devices comprising at least three mobile devices, wherein the method comprises, for an i-th mobile device of the group of n mobile devices:computing (510) a public key (X i ) for the mobile device for transmission to at least one first other mobile device of the group of n mobile devices, wherein the public key (X i ) for the mobile device is a function of at least a private key (x i ) associated with the mobile device and of a shared password ( π ) known to all mobile devices of the group of n mobile devices;computing (524) a public value (K i ) for the mobile device for transmission to each of all other mobile devices of the group of n mobile devices, wherein the public value (K i ) for the mobile device is a function of at least the private key (x i ) associated with the mobile device and of a public key of each of at least one second other mobile device of the group of n mobile devices;and using (534) the public value (K1, .... K i - 1 , K ¡+1 ,...K n ) of each of all other mobile devices of the group of n mobile devices to compute the shared encryption key (k) in accordance with a group key establishment protocol.
  2. 11
    The method of any one of claims 8 to 10, when dependent on claim 5, wherein the key confirmation value (V i ) for the mobile device, is a function of at least the hash (h 1 (π)) of the shared password, and at least one of the first Diffie-Hellman result (L i ) or the second Diffie-Hellman result (R i ) for the mobile device.
  3. 15
    A mobile device configured to compute a shared encryption key (k) in a group of n mobile devices, the mobile device comprising:a processor (102);and a memory (106, 108);wherein the processor (102) is configured to perform all the steps of the method as claimed in any one of the preceding claims.