EP2416524A2

System and method for secure transaction of data between wireless communication device and server

Abstract

The present application provides a system and method for a set of Extensible Authentication Protocols (EAPs) based on ECC (Elliptic Curve Cryptography) and SKE (Symmetric Key Encryption) mechanisms (with a suitable permutation) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost. According to one embodiment, a method and system of ECC and SKE based EAPs (through a permutation technique) which can avoid replay attacks. The application also provides a light weight security with better performance in comparison to the lower layer chip level security provided by 2G, 3G or 4G Applications and no certificates exchanged during the communication.

EP2416524A2, drawing sheet 1
Sheet 1 of 5

Term

4.7 yearsto projected expiry

Projected expiry 27 May 2031, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 3 independent, 12 dependent

  1. 1
    A method of authenticating a wireless communication device, comprising the steps of:transmitting a first message to a server from a communication device;generating a random number at the server, the said random number is masked;generating a first encrypted signal at the server by bundling a second message with the masked random number;transmitting the first encrypted signal from the server to the communication device;decrypting the first encrypted signal at the communication device;retrieving the random number at the communication device, the mask is removed;generating a signature signal at the communication device;generating a second encrypted signal at the communication device;transmitting the second encrypted signal from the communication device to the server;decrypting the second encrypted signal at the communication device;validating the second encrypted signal by comparing the corresponding signature values of the server and the communication device at the server;generating a response based on the comparison of the signature values at the server;and transmitting the response to the communication device by the server.
  2. 2
    The method of Claim 1, wherein the first encrypted signal is generated by bundling the second message with at least one of the hash values associated with the masked random number, a public key and the nonce value associated with the random number.
  3. 3
    The method of Claim 1, wherein encrypting the second signal by bundling a third message with a signature signal associated with a private key of the communication device.
  4. 4
    A method of authenticating a wireless communication device, comprising the steps of:transmitting a first message to a server from a communication device;generating a first random number and a prime number at the server, the said random and prime numbers are masked;generating a first encrypted signal at the server by bundling a second message with at least one of the masked random number and the masked prime number;transmitting the first encrypted signal from the server to the communication device;decrypting the first encrypted signal at the communication device;retrieving the first random number and the prime number at the communication device, removing the corresponding mask;generating a second random number at the communication device;generating a second encrypted signal at the communication device;transmitting the second encrypted signal from the communication device to the server;decrypting the second encrypted signal at the communication device;retrieving the second random number at the communication device;validating the second encrypted signal by comparing the corresponding hash values and nonce values of the server and the communication device at the server;generating a response based on the comparison of the hash values and nonce values at the server;and transmitting the response to the communication device by the server.
  5. 5
    The method of Claim 4, further comprising transmitting a 192-bit pre-shared private (encryption) key from the server to the communication device using an AES-CTR algorithm.
  6. 6
    The method of Claim 4, wherein the second random number is generated using a Pseudo Random Number Generator (PNRG) method.
  7. 7
    The method of Claim 4, wherein the second encrypted signal is generating by bundling a third message with at least one of the hash value associated with the second random number and nonce value associated with a private key, the said private key is generated using a Deterministic Random Sequence Generation (DSRG) process.
  8. 8
    The method of Claim 4, wherein decrypting the second encrypted signal includes retrieving the private key.
  9. 9
    The method of Claim 4, wherein validating the second encrypted signal by comparing either one of the corresponding value of hash value associated with the second random number and nonce values associated with the private key of the communication device.
  10. 10
    A system for authenticating a wireless communication device, comprising:a random number generator at a server configured to generate a first random number, the random number is masked;a prime number generator at the server configured to generate a prime number;a first encryption module at the server configured to generate a first encrypted signal by bundling a second message with at least one data signal from the first random number or the prime number;a communication device configured to receive the first encrypted signal from the server;a first decryption module at the communication device configured to decrypt the first encrypted signal and retrieve at least one of the first random number or prime number, the corresponding mask is removed;a random number generator at the communication device configured to generate a second random number;a signature signal generation module at the communication device configured to generate a signature signal;a second encryption module at the communication device configured to generate a second encrypted signal by bundling a third message with at least one data signal from the signature signal or the second random number;a transceiver at the communication device configured to transmit the second encrypted signal from the communication device to the server;a second decryption module at the server configured to decrypt the second encrypted signal;and a validation module at the server configured to validate the second encrypted signal by comparing at least one of the corresponding signature values, hash values and nonce values of the server and the communication device.
  11. 11
    The system of Claim 10, wherein the first encryption module is configured to generate the first encrypted signal by bundling the second message with at least one of the hash value associated with the masked random number, hash value associated with the random number, a public key and the nonce value associated with the random number.
  12. 12
    The system of Claim 10, wherein the second encryption module is configured to generate the second encrypted signal by bundling the third message with at least one of the a private key, the corresponding signature signals associated therewith the private key and hash value of the second random number.
  13. 13
    The system of Claim 10, wherein the second decryption module is configured to retrieve the private key from the second encrypted signal.
  14. 14
    The system of Claim 10, wherein validation module is configured to validate the second encrypted signal by comparing either one of the corresponding value of a public key of the communication device, hash values and nonce values of the server and the communication device.
  15. 15
    The system of Claim 10, wherein the communication device is a wireless communication device enabled to operate using a 2G, 3G, or 4G communication protocol.