EP3661118B1

System and method for performing secure communications

Abstract

This record has no abstract on file.

EP3661118B1, drawing sheet 1
Sheet 1 of 29

Term

8.3 yearsleft in the term

Expires 27 January 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

12 claims: 7 independent, 5 dependent

  1. 1
    A method of receiving secure communications at a first secure communications terminal (104, 104-1, 104-2) having a processor and a memory operably connected to the processor, the method comprising:maintaining an association with a first client account (A);receiving, from a second secure communications terminal (104, 104-1, 104-2), a message (MSG, MSG1, MSG2) from a second client account (B), a first portion of the message (MSG, MSG1, MSG2) being encrypted by a shared symmetric key (SSK);extracting a key identifier (SSKID, SSKIDA1, SSKIDA2, SSKIDB1, SSKIDB2) from the message (MSG, MSG1, MSG2);obtaining the shared symmetric key (SSK) based on the key identifier (SSKID, SSKIDA1, SSKIDA2, SSKIDB1, SSKIDB2) included in the message (MSG, MSG1, MSG2), the shared symmetric key (SSK) and the key identifier (SSKID, SSKIDA1, SSKIDA2, SSKIDB1, SSKIDB2) having been previously generated by the first client account (A) and included as part of a previous message (MSG, MSG1, MSG2) sent to the second client account (B);decrypting the first portion of the message (MSG, MSG1, MSG2) using the shared symmetric key (SSK) to obtain a message key (MK, MK1, MK2);and decrypting a second portion of the message (MSG, MSG1, MSG2) using the message key (MK, MK1, MK2), wherein the decrypting the first portion of the message (MSG, MSG1, MSG2) further comprises: decrypting the first portion of the message (MSG, MSG1, MSG2) using a private key (PrK, PKR1, PKRA1) of the first client account (A).
  2. 4
    The method of any one of claims 2 to 3, wherein the enhanced public key (PuK, PuK1, PuK2) is unique to the message (MSG, MSG1, MSG2), and the message key (MK, K1, MK2) is unique to the message (MSG, MSG1, MSG2).
  3. 5
    The method of any one of claims 1 to 4, further comprising:maintaining in the memory a unique client key (UCK, UCKA;UCKB) for the first client account (A);and decrypting the key identifier (SSKID, SSKIDA1, SSKIDA2, SSKIDB1, SSKIDB2) using the unique client key (UCK, UCKA, UCKB).
  4. 6
    The method of any one of claims 1 to 5, wherein the message (MSG, MSG1, MSG2) further includes an encrypted key pair (SSK, SSKID, SSKA, SSKIDA, SSKB, SSIKDB) comprising a second client account shared key (SSK, SSKA, SSKB) and a corresponding second client account key identifier (SSKID, SSKIDA, SSKIDB), the encrypted key pair (SSK, SSKID, SSKA SSKIDA, SSKB, SSIKDB) generated by the second client account (B) for use in encrypting, by the first client account (A), a subsequent message (MSG, MSG1, MSG2) to be transmitted to the second client account (B).
  5. 7
    A method of sending secure communications at a first secure communications terminal (104, 104-1, 104-2) having a processor and a memory operably connected to the processor, the method comprising:maintaining an association with a first client account (A);receiving, from a second client account (B), a previous message (MSG, MSG1, MSG2);extracting from the previous message (MSG, MSG1, MSG2) a previous shared symmetric key (SSK) and a previous shared symmetric key identifier (SSKID, SSKIDA, SSKIDB) previously generated by the second client account (B);generating a message key (MK;MK1, MK2) and encrypting a message (MSG, MSG1, MSG2) content using the message key (MK, MK1, MK2);encrypting the message key (MK, MK1, MK2) using the previous shared symmetric key (SSK) and encrypting the message key using a public key (PuK, PuK1, PuK2) of the second client account (B) in addition to encrypting the message key using previous shared symmetric key (SSK, EESK);combining the encrypted message key (MK, MK1, MK2), the encrypted message (MSG, MSG1, MSG2) content and the previous shared symmetric key identifier (SSKID, SSKIDA, SSKIDB) to form a new message (MSG, MSG1, MSG2);and transmitting the new message (MSG, MSG1, MSG2) to a second secure communications terminal (104, 104-1, 104-2) associated with the second client account (B),
  6. 10
    The method of any one of claims 7 to 9, further comprising:generating an encrypted key pair (SSK, SSKID, SSKA, SSKIDA, SSKB, SSIKDB) comprising a next shared key (SSK, SSKA, SSKB) and a corresponding next key identifier (SSKID, SSKIDA, SSKIDB), the encrypted key pair (SSK, SSKID, SSKA, SSKIDA, SSKB, SSIKDB) for use in encrypting a subsequent message (MSG, MSG1, MSG2) to be transmitted by the second client account (B) to the first client account (A);and adding the encrypted key pair (SSK, SSKID, SSKA, SSKIDA, SSKB, SSIKDB) to the new message (MSG, MSG1, MSG2).
  7. 12
    A secure communications terminal (104, 104-1, 104-2) configured to perform the method of any one of claims 7 to 11.