Communication method with encryption key escrow and recovery
Abstract
Procede de communication avec sequestre et recuperation de cle de chiffrement.L'entite qui s'engage dans une session de communication engendre une cle de session (KS) a l'aide d'un generateur pseudo-aleatoire initialise par la cle secrete (Sa ) de l'entite et une valeur initiale (VI). Le message est chiffre par la cle de session. Celle-ci peut etre retrouvee par l'autorite de sequestre (Ta ), qui archive la cle secrete (Sa ) et peut retrouver la valeur initiale (VI). Application aux communications securisees.

Term
Term ended
Projected expiry passed 31 January 2020, 6.6 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
11 claims: 2 independent, 9 dependent
- 1REVENDICATIONS 1. Procédé de communication chiffrée avec séquestre et récupération de clé de chiffrement, mettant en oeuvre :- une première entité (a) comprenant des premiers moyens de cryptologie (MC a ) et munie d'une première identité (Id a ), d'une première clé publique de distribution de clé (P a ) et d'une première clé secrète de distribution de clé (S a ) correspondant à ladite première clé publique (Pa) , - une seconde entité (b) comprenant des seconds moyens de cryptologie (MC b ) et munie d ' une seconde identité (Id b ) , d ' une seconde clé publique de distribution de clé ( P b ) et d ' une seconde clé secrète de distribution de clé (S b ) correspondant à ladite seconde clé publique (P b ) , ce procédé comprenant : iii) une phase préliminaire d'établissement d'une clé de session (KS) phase dans laquelle l'une au moins des entités (a, b) produit une clé de session (KS) et forme un cryptogramme constitué de cette clé chiffrée par la clé publique (P b , P a ) de l'autre entité, l'autre entité (b, a) déchiffrant ledit cryptogramme à l'aide de sa clé secrète (S b , S a ) et recouvrant la clé de session (KS), iv) une phase d'échange de messages (M) dans laquelle les entités (a, b) forment des cryptogrammes E K s(M) constitués par des messages (M) chiffrés par la clé de session (KS) établie dans la phase préliminaire, chaque entité déchiffrant le cryptogramme qu'elle reçoit à l'aide de la clé de session (KS) et recouvrant ainsi le message qui lui a été adressé, ce procédé étant caractérisé par le fait que • il met en oeuvre, en outre, au moins une autorité de séquestre (T a , T b ) associée à l'une des entités (a, b) , cette autorité archivant la clé secrète (S a , S b ) de l'entité associée (a, b) , • dans la phase préliminaire, l'entité (a, b) qui produit la clé de session (KS) met en oeuvre un générateur pseudo-aléatoire (PRG a , PRG b ) connu de l'autorité de séquestre (T a , T b ) associée et initialise ce générateur pseudo-aléatoire à l'aide de sa clé secrète (S a , S b ) et d'une valeur initiale (VI) déduite, par un algorithme connu de l'autorité de séquestre (T a , T b ) , de données appropriées.
- 2Procédé selon la revendication 1, dans lequel l'autorité de séquestre (T a , T b ) associée à l'entité (a, b) qui a produit, dans la phase préliminaire, la clé de session (KS), met en oeuvre un générateur pseudoaléatoire identique à celui de l'entité associée (PRG a , PRG b ) , initialise ce générateur avec ladite valeur initiale (VI) et la clé secrète (S a , S b ) de l'entité associée (a, b) qu'elle a archivée, et recouvre ainsi la clé de session (KS).
- 3Procédé selon la revendication 1, selon lequel l'autorité de séquestre. (T b , T a ) associée à l'entité (b, a) qui n'a pas produit, dans la phase préliminaire, la clé de session (KS), déchiffre le cryptogramme de la clé session (P b (KS), P a (KS)) à l'aide de la clé secrète (Sb, S a ) de l'entité associée (b, a) qu'elle a archivée et recouvre ainsi la clé de session (KS).
- 4Procédé selon l'une quelconque des revendications 1 3, dans lequel la valeur initiale (VI) est déduite des données échangées entre les entités (a, b) dans la phase préliminaire d'établissement de la clé de session (KS).
- 5Procédé selon la revendication 2, dans lequel l'autorité de séquestre obtient la valeur initiale (VI) par essais exhaustifs à partir de données susceptibles de prendre un nombre restreint de valeurs.
- 6Procédé selon la revendication 1, dans lequel le générateur pseudo-aléatoire (PRG a , PRG b ) d'une entité (a, b) est initialisé par une fonction à sens unique (H (S a ), H(S b )) de la clé secrète (S a , S b ) de cette entité (a, b).
- 7Procédé selon la revendication 1, dans lequel au moins une première autorité de certification (AC a , AC b ) délivre à l'une des entités (a, b) un certificat (C a , C b ) attestant de la correspondance entre l'identité (Id a , Id b ) de l'entité et la clé publique de distribution de clé (P a , P b ) si et seulement si l'archivage de la clé secrète correspondante (S a , S b ) a bien été effectué auprès de l'autorité de séquestre correspondante (T a , T b ) , la phase préliminaire d'établissement d'une clé de session (KS) et la phase d'échange de messages étant toutes deux subordonnées, dans le moyen de cryptologie (MC a , MC b ) à la validité du 20 certificat (C a , C b ) et à la correspondance effective entre la clé publique (P a , P b ) contenue dans ce certificat et la clé secrète de distribution (S a , S b ) .
- 8Procédé selon la revendication 1, dans lequel, pour au moins l'une des entités (a, b), l'autorité de certification (AC a , AC b ) et l'autorité de séquestre associée à cette entité (T a , T b ) sont réunies en une seule autorité.
- 9Procédé selon la revendication 1, dans lequel l'autorité de séquestre (T a , T b ) est divisée en deux autorités partielles (Tj, T 2 ) ( T b , T b ) archivant chacune une part ( S a , S 2 ) ( S’ b , S b ) de la clé secrète de distribution (S a , S b ) , aucune des deux autorités partielles n'étant capable, à elle seule, de reconstituer la clé secrète de distribution (S a , S b ) , mais les deux autorités partielles étant capables, en coopérant, de reconstituer la clé secrète de distribution, les deux autorités partielles étant à même de s'assurer qu'elles détiennent des parts de clé secrète permettant de reconstituer la clé secrète.
- 10Procédé selon la revendication 1, dans lequel, dans la phase préliminaire d'établissement d'une clé de session :- la première entité produit une première clé de session partielle (KS a ) , forme un premier cryptogramme P b (KS a ) de cette première clé de session partielle (KS a ) chiffrée sous la clé publique (P b ) de la seconde entité (b), envoie ce premier cryptogramme à la seconde entité (b) , - la seconde entité (b) produit une seconde clé de session partielle (KS b ) , forme un second cryptogramme P a (KS b ) constitué de cette seconde clé de session partielle (KS b ) chiffrée sous la clé publique (P a ) de la première entité (a), et envoie ce second cryptogramme à la première entité (a), - les deux entités (b, a) déchiffrent le premier et le second cryptogrammes à l'aide de leur clé secrète (S b , S a ) retrouvent la première et la seconde clés de session partielle (KS a , KS b ) et forment la clé de session (KS) à partir des clés session partielles.
- 11Procédé selon la revendication 10, dans lequel les entités (a, b) forment la clé de session (KS) par une opération logique OU exclusif entre la première et la seconde clés de session partielle (KS a , KS b ) . 12. Procédé selon 1 ' une quelconque des revendications 1 à 11, dans lequel l'autorité de séquestre (T a , T b ) associée à 1'une des entités (a, b) est l'utilisateur de l'entité.
Independent claims11
74 paragraphs in 3 sections, as filed
i
COMMUNICATION PROCESS WITH SEQUESTRE
AND RECOVERY OF THE ENCRYPTION KEY
DESCRIPTION
Technical area
The present invention relates to a communication method in which encryption key sequestration and recovery operations are provided. These operations make it possible to guarantee to one or more previously determined organization (s) (for example a security administrator of a company network, a trusted third party, even, in certain cases, the users of a system). codes themselves), the possibility of recovering, if necessary, the session key used in the communication, and this from the data exchanged. The possibility of recovering a session key may arise from a need for legal interception or key recovery within a company.
The invention finds application in secure communications.
State of the prior art
Essentially, two families of key escrow / recovery techniques are known, guaranteeing one or more escrow authorities the ability to reconstitute, from the data exchanged during a communication between two interlocutors or entities a and b, the session key used, in order to decipher this communication. These two families of techniques have the advantage of being able to be implemented without any data exchange having to be carried out at each communication between the entities and the sequestration authority (s) (so-called off process). line).
Family 1: archiving of static key distribution keys with a escrow authority
This family of techniques applies to systems in which the establishment of a session key between the interlocutors uses a key exchange protocol based on the possession, by one of the interlocutors (for example b) of a static secret key (that is to say not renewed at each session). The secret key used by b in the key exchange protocol is archived with a escrow authority (or distributed among several escrow authorities). The possession of this secret allows the sequestration authority (or authorities) to reconstitute, if necessary, any session key exchanged between a and b from the messages of the protocol for establishing this key. An example of this key escrow and recovery method is provided in the article A Proposed Architecture for Trusted Third Party Services, by N. Jefferies, C. Mitchell and M. Walker, published in Lectures Notes in Computer Science 1029, Cryptography Policy and Algorithms Conference, pp. 98-104, Springer Verlag, 1996. It is one of the main methods, belonging to this first family of techniques, which has, until today, been considered in Europe.
Family 2: recovery of dynamic encryption keys (session keys) using legal fields
This second family of techniques does not call, unlike the previous one, the prior archiving of static secret keys used for the exchange of session keys, but the insertion, in the messages exchanged between a and b, when a secure communication, one or more legal fields containing, in a form intelligible only to a receiver authority, information on the session key KS. The key KS (or information on this key) can for example be encrypted under the public key RSA of a receiver authority. The Secure Key Recovery (SKR) protocol, proposed by IBM, is part of this family of techniques.
These two families of techniques have certain drawbacks for securing open applications that it is desired to be able to use between interlocutors located in different countries or different jurisdictions, such as for example secure messaging. When a secure application is likely to be used for international communications, it is desirable that two conditions be met:
(i) each country must be free to set up or not, for communications which concern it, a key escrow / recovery system for this application;
(ii) in each country where a key escrow / recovery system is in place, the authorities empowered to recover, if necessary, the session keys used to encrypt an international communication must be able to do so without having to cooperate, for each interception. , with the authorities of other countries.
However, the known techniques described above do not meet or do not meet these conditions:
- for the methods of the first family, when the method of distribution of the session key considered relates to public key encryption (in particular the RSA encryption used for this use in a very large number of security products), the recovery of the key session of a communication is only possible, without international cooperation, in the country where the secret key used for key distribution has been archived. This difficulty has led some authors (cf. the article by N. Jefferies et al. previously cited) to recommend key escrow / recovery systems based on a more symmetrical key exchange method, related to the Diffie-Hellman scheme. These systems satisfy the previous condition (ii) and could perhaps, subject to certain adaptations constrained conditions, satisfy (i), but they introduce strong points on the key distribution method used, which lead in particular to excluding the use of the RSA algorithm.
- For the processes of the second family, key recovery in the recipient country, from legal fields, is based on the implementation in the issuing country of a key escrow / recovery technique adapted to the recipient country, namely the issuance of intelligible legal fields for the escrow authorities of the recipient country. This constraint is in contradiction with the previous condition (i).
DE Denning's article Descriptions of Key Escrow Systems published in Communications of the ACM, vol. 39, No. 3, March 1996, as well as the article by DE Denning and DK Branstad entitled A taxonomy of Key Recovery Encryption Systems, published in Communications of the ACM, vol. 39, n ° 3, March 1996,
<td>give</td><td>a description</td><td>and</td><td>analysis</td><td>comparative</td><td>of</td>
<td>more than</td><td>thirty systems</td><td>of</td><td colspan="3">escrow and recovery</td>
<td>key.</td><td></td><td></td><td></td><td></td><td></td>
<td>We</td><td>can stick</td><td>at</td><td>two examples</td><td>illustrated</td><td>sure</td>
<td colspan="3">figures 1 and 2 attached</td><td></td><td></td><td></td>
In Figure 1, first of all, we see two entities a, b each equipped with cryptology means not shown and each provided with an identity Id<sub>at</sub>, Id<sub>b</sub>, a public key and a secret encryption key, respectively P<sub>at</sub>, P<sub>b</sub>, and S<sub>at</sub>, S<sub>b</sub>, as well as a C certificate<sub>at</sub>, VS<sub>b</sub> ; we see, moreover, two sequestration authorities T<sub>at</sub> and T<sub>b</sub> associated with the two entities a and b, these two authorities each archiving the secret keys S<sub>at</sub>, S<sub>b</sub> associated entities as well as their C certificates<sub>at</sub> or C<sub>b</sub>. The certificates attest to the correspondence between the secret key and the public key and that the secret key has indeed been archived. The certification authority is not shown in this figure.
The certificate may conform to ITU-T Recommendation X509.
The method of communication between these different means comprises the following operations:
A) entity a, which is supposed to engage in a session of transmission of a message M:
• checks the validity of C certificates<sub>at</sub> and C<sub>b</sub>, • produces a session key KS implementing a pseudo-random generator not shown, • uses its cryptology means to encrypt the session key KS with the public key P<sub>b</sub> of the other entity and encrypt the message M with the session key according to a symmetric encryption algorithm, • transmits its identity ID<sub>at</sub> or its certificate Ca, 'the encrypted session key P<sub>b</sub>(KS) and the encrypted message E<sub>KS</sub> (M),
B) entity b, to which the transmission is intended:
• checks the validity of C certificates<sub>at</sub> and C<sub>b</sub>, • retrieves the session key KS using its secret key S<sub>b</sub>, • decrypts the message M using the session key KS.
In such a process, the receiver T<sub>b </sub>can, if desired, also recover the session key KS using the secret key S<sub>b</sub> that it has archived and can thus recover the transmitted message.
This method has a drawback. Indeed, if the receiver T<sub>b</sub> can retrieve the KS session key (because it archived the secret key T<sub>b</sub>) and can thus recover the transmitted message, this is not the case for the receiver T<sub>at</sub>, because it does not have the secret key S<sub>b</sub>. It is then necessary to suppose a cooperation between the authorities of sequestration T<sub>at</sub> and T<sub>b</sub>, which is not obvious in the case of international communications.
This difficulty arises, in particular, from the fact that the key exchange process calls for asymmetric encryption-decryption using a pair of respectively public-secret keys, such as for example in RSA encryption. Some authors have advocated more symmetrical processes, akin to a so-called Diffie-Hellman protocol. This process is illustrated in Figure 2. There are substantially the same means as in Figure 1, namely the two entities a and b and the two sequestration authorities T<sub>at</sub> and T<sub>b</sub>. The parameters of the Diffie-Hellman protocol consist of a large prime number p, called modulus, and a generator number g. The two escrow authorities T<sub>at</sub> and T<sub>b</sub> agreed on these numbers p and g. The secret key S<sub>at</sub> of a is a secret exponent a which is archived in T<sub>at</sub> and the public key of a is P<sub>at</sub>= g<sup>at</sup>. Certificate C<sub>at</sub> contains the public key P<sub>at</sub>= g “. The same goes for entity b: (S<sub>b</sub>= P, P<sub>b</sub>= g<sup>(J</sup>) .
To send a message to entity b, entity a generates a session key KS and addresses to b:
• his certificate C<sub>at</sub> (which contains P<sub>at</sub>= g “), • the session key encrypted by an algorithm E using the key g“<sup>p</sup>, (Eg<sup>aP</sup>(KS)), • the message encrypted by the KS session key (E<sub>KS</sub>(M)).
Knowledge by T<sub>at</sub> of a and the public key P<sub>b</sub>= g<sup>p</sup> of b allows T<sub>at</sub> to calculate (g<sup>p</sup>)<sup>at</sup>= g<sup>Pa</sup>. The same for T<sub>b</sub> who can calculate (g<sup>at</sup>)<sup>p</sup>= g<sup>ap</sup>. Thus, g<sup>aP</sup> is it shared by a and b.
Each authority T<sub>at</sub> or T<sub>b</sub> can therefore find the session key (KS) and therefore recover the message (M).
But, here again, this diagram assumes an agreement between the parties.
The object of the present invention is to remedy these drawbacks by proposing a method which does not require any agreement between the communicating parties, the recovery of the session key and of the message being carried out solely on the basis of the data exchanged in the communication.
Presentation of 1<sup>1</sup> invention
Specifically, the subject of the invention is an encrypted communication method with sequestration and recovery of the encryption key, implementing:
- a first entity (a) comprising first cryptology means (MC<sub>at</sub>) and provided with a first identity (Id<sub>at</sub>), a first public key distribution key (P<sub>at</sub>) and a first secret key distribution key (S<sub>at</sub>) corresponding to said first public key (P<sub>at</sub>) ,
- a second entity (b) comprising second encryption means (MC<sub>b</sub>) and provided with a second identity (Id<sub>b</sub>), a second public key distribution key (P<sub>b</sub>) and a second secret key distribution key (S<sub>b</sub>) corresponding to said second public key (P<sub>b</sub>), this process comprising:
i) a preliminary phase of establishing a session key (KS) phase in which at least one of the entities (a, b) produces a session key (KS) and forms a cryptogram consisting of this key encrypted by the public key (P<sub>b</sub>, P<sub>at</sub>) of the other entity, the other entity (b, a) decrypting said cryptogram using its secret key (S<sub>b</sub>, S<sub>at</sub>) and covering the session key (KS), ii) a message exchange phase (M) in which the entities (a, b) form cryptograms E<sub>K</sub>s (M) consisting of messages (M) encrypted by the session key (KS) established in the preliminary phase, each entity decrypting the cryptogram that it receives using the session key (KS) and thus covering the message which was sent to it, this method being characterized by the fact that • it also implements at least one sequestration authority (T<sub>at</sub>, T<sub>b</sub>) associated with one of the entities (a, b), this authority archiving the secret key (S<sub>at</sub>, S<sub>b</sub>) of the associated entity (a, b), • in the preliminary phase, the entity (a, b) which produces the session key (KS) implements a pseudo-random generator (PRG<sub>at</sub>, PRG<sub>b</sub>) known to the receiver (T<sub>at</sub>, T<sub>b</sub>) associated and initializes this pseudo-random generator using its secret key (S<sub>at</sub>, S<sub>b</sub>) and an initial value (VI) deduced, by an algorithm known to the escrow authority (T<sub>at</sub>, T<sub>b</sub>), appropriate data.
ίο
According to one embodiment, the receiver authority (T<sub>at</sub>, T<sub>b</sub>) associated with the entity (a, b) which produced, in the preliminary phase, the session key (KS), implements a pseudo-random generator identical to that of the associated entity (PRG<sub>at</sub>, PRG<sub>b</sub>), initializes this generator with said initial value (VI) and the secret key (S<sub>at</sub>, S<sub>b</sub>) of the associated entity (a, b) that it has archived, and thus recovers the session key (KS).
According to another embodiment, the escrow authority (T<sub>b</sub>, T<sub>at</sub>) associated with the entity (b, a) which did not produce, in the preliminary phase, the session key (KS), decrypts the cryptogram of the session key (P<sub>b</sub>(KS), P<sub>at</sub>(KS)) using the secret key (S<sub>b</sub>, S<sub>at</sub>) of the associated entity (b, a) which it has archived and thus recovers the session key (KS).
As for the initial value VI, it can either be deduced from the data exchanged between the entities a and b in the preliminary phase of establishing the session key or be obtained by successive tests from data likely to take a given number of values. , this number being sufficiently small for the time taken by the escrow authority to be compatible with the envisaged application.
As indicated in the introduction, the escrow authority can be an authorized third party, or a security administrator of a corporate network, or the user himself (the escrow is then a self-receiver).
Brief description of the drawings
<td>- figure 1, already</td><td>described, illustrates</td><td>a</td><td>process</td>
<td>known asymmetric</td><td>r</td><td></td><td></td>
<td>- figure 2, already common symmetric</td><td>described, illustrates r</td><td>a</td><td>process</td>
<td colspan="2">- Figure 3 illustrates schematically according to the invention.</td><td>a</td><td>process</td>
Description of particular modes of implementation
The method of the invention can be described by first specifying certain initial conditions, then specifying the procedures developed in the user's encryption means and finally describing the procedure for recovering the key.
A. Initial conditions
The secret key S<sub>at</sub> of the public key key encryption system used by entity a for session key establishment purposes is archived with the escrow authority T<sub>at</sub>. Delivery to a, by a certification authority AC designated in advance by T<sub>at</sub>, a C certificate<sub>at</sub> attesting to the correspondence between the identity Id<sub>at</sub> of a and the public key P<sub>at</sub> (for example a certificate conforming to recommendation X509 of the ÜIT-T), must be subject to this archiving. The possession by a of a certificate from AC proves that the archiving with T<sub>at</sub> of the secret key S<sub>at </sub>corresponding to the public key P<sub>at</sub> has actually been achieved. In practice, the certification authority AC and the receiver T<sub>at</sub> can be the same organization, or two separate organizations having entered into an agreement. Generation of the secret key S<sub>at</sub> can, depending on the case, be carried out by user a or by third party T<sub>at</sub>.
B. Procedures in the user's crypto facility
By means of cryptology of noted MC is meant<sub>at</sub>, the software and hardware resources implementing the cryptographic calculations for establishing a session key and for encrypting a during a secure communication. For example, the client software of a secure messaging system can be considered as a means of cryptology.
For the MC cryptology medium<sub>at</sub> user has either in accordance with the third party escrow service offered by T<sub>at</sub>, it must meet the following conditions:
i) Performing MC encryption functions<sub>at </sub>(establishment of a session key, encryption) must be subject to the presence of a C certificate<sub>at</sub> from an AC certification authority designated by T<sub>at</sub> and the secret key S<sub>at</sub> corresponding. MC encryption<sub>at</sub> must verify not only that the C certificate<sub>at</sub> is valid, but still that there is indeed a correspondence between the secret key S<sub>at</sub> and the public key P<sub>at</sub> contained in T<sub>at</sub>. These checks are necessary to ensure that the third party of receiver T<sub>at</sub> is able to recover session keys processed by MC<sub>at</sub>.
ii) The key generation process implemented in MC<sub>at</sub> -typically the key generation algorithm used to generate a KS session key when a initiates a secure session with a party b- must be a known GPA pseudo-random generator of T<sub>at</sub>, and whose seeds, i.e. the inputs from which the values produced by the generator are calculated, are made up:
- the secret key S<sub>at</sub> (or, according to a variant, of a function H (S<sub>at</sub>) of this key);
- from an initial value VI deduced, by an algorithm known to T<sub>at</sub>, variable data contained in the unencrypted part of the communications between a and its interlocutors (for example the date and time), or a counter managed inside MC<sub>at</sub>.
The pseudo-random generator must meet the following conditions:
i) it should be easy to deduce the output value of this generator (typically the session key KS) from S<sub>at</sub> (or H (S<sub>at</sub>)) and the initial value VI. According to a preferred embodiment of the invention, the size of the initial value VI can be limited between 20 and 40 bits of effective size, so that, when the secret key S<sub>at</sub> is known, the recovery of the output value of the generator remains possible by exhaustive search even when the exact value of VI is lost, ii) it must be difficult to predict information on S<sub>at</sub> (or on H (S<sub>at</sub>)) from a set of VI values and GPA (S<sub>at</sub>, VI) or GPA (H (S<sub>at</sub>), VI) corresponding, iii) it must be difficult to predict information relating to the GPA outputs (S<sub>at</sub>, VI) or GPA (H (S<sub>at</sub>), VI) for the different values of VI when the value of S<sub>at</sub> (or H (S<sub>at</sub>)) is unknown.
C. Key recovery procedures
There are two separate procedures for retrieving the KS session key used to encrypt a secure communication between user a and party b, through T<sub>at</sub> or an authority authorized to access the secret S<sub>at</sub> archived by T<sub>at</sub> :
i) If the session key KS is produced by b and received by a encrypted using the public key P<sub>at</sub> of a, then T<sub>at</sub> can recover the key KS by decrypting using the archived secret S<sub>at</sub> the cryptogram P<sub>at</sub>(KS) transmitted in the key distribution protocol.
ii) If the KS session key is produced in the MC encryption means<sub>at</sub> from a and sent to b encrypted under the public key P<sub>b</sub> of b, then T<sub>at </sub>can recover in the data exchanged in clear between a and b the initialization value VI and reconstitute the value of KS using VI and the archived value of S<sub>at</sub>, by performing the calculation KS = GPA (S<sub>at</sub>, VI) or KS = GPA (H (S<sub>at</sub>), VI). In the event that VI and the contents of a counter, or in the event that the effective size of VI is limited and for some reason VI cannot be retrieved from the clear data, it remains possible for T<sub>at</sub> to recover the session key KS by carrying out an exhaustive test of the possible values of VI, and by checking for each one if the value KS = GPA (S<sub>at</sub>, VI) or KS = GPA (H (S<sub>at</sub>), VI) obtained is the correct one.
By combining the elementary procedures i) and ii) defined above, T<sub>at</sub> remains capable of recovering the session key in the event that a more complex session key establishment protocol is used between a and b. We can consider, by way of example, the following protocol: b generates a secret value KSI and transmits it to a encrypted under the public key P<sub>at</sub> of a; a generates a secret value KS2 and transmits it to b encrypted under the public key P<sub>b</sub> of b; a and b calculate the session key KS, equal to the exclusive OR of the values KSI and KS2 (KS = K1 XOR K2). For a protocol of this kind, T<sub>at</sub> would be able to recover KSI using procedure i) defined above and recover KS2 using procedure ii), and therefore, from these two values, recover KS.
The method which has just been described can be implemented according to variants in which the information that constitutes the secret key S<sub>at</sub> is not archived with a single entity T<sub>at</sub>, but divided into shares archived with separate third-party receivers.
For example, the secret key S<sub>at</sub> of a can be made up of a secret RSA exponent d. This secret can be split into two parts dl and d2 such that dl + d2 = d. Two Receivership Authorities T<sub>at</sub> and T '<sub>at</sub>, respectively responsible for archiving dl and d2 (and the public module n<sub>at</sub> of a), are capable of:
• to check, without revealing their part of the secret d, that they are indeed able to calculate the secret function associated with the key S<sub>at</sub> ; To do this, it suffices for each of them to calculate, modulo n, the power of the input value determined by its share, 5 then for the values obtained to be multiplied between them modulo n<sub>at</sub>, • to recover a session key KS from the data of the protocol for establishing this key (by revealing, if necessary, to the other third party or to an interception authority their share of the key S<sub>at</sub>) .
Contents3
1 sheet
Sheet 1
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2010108994A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO2010108994A2 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| FR2943870A1 | Cited by | France | – | Search report | – |
| WO2010108994A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| US5438622A | Cites | United States of America | A | Search report | 1 |
| US5438622A | Cites | United States of America | A | Search report | 1 |
| CLARK A J: "Key Recovery -- Why, How, Who?", COMPUTERS & SECURITY. INTERNATIONAL JOURNAL DEVOTED TO THE STUDY OF TECHNICAL AND FINANCIAL ASPECTS OF COMPUTER SECURITY,NL,ELSEVIER SCIENCE PUBLISHERS. AMSTERDAM, vol. 16, no. 8, 1997, pages 669 - 674, XP004101383, ISSN: 0167-4048 | Non-patent | – | – | Search report | – |
| MENEZES ET AL.: "HANDBOOK OF APPLIED CRYPTOGRAPHY", 1997, CRC PRESS, BOCA RATON, XP002153192 | Non-patent | – | – | Search report | – |
6 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0001185 | France | A | |
| FR20000001185 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| WO0156222A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2804561A1This record | France | A1 | |
| FR2804561B1 | France | B1 | |
| EP1254534A1 | European Patent Office (EPO) | A1 | |
| US2003012387A1 | United States of America | A1 | |
| JP2003521197A | Japan | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Notification of lapseLapsedST | ST |
Numbers
- Publication
- 2804561
- Publication, DOCDB
- 2804561
- Publication, EPODOC
- FR2804561
- Application
- 1185
- Application, DOCDB
- 0001185
- Application, EPODOC
- FR20000001185
Titles2
- French
- PROCEDE DE COMMUNICATION AVEC SEQUESTRE ET RECUPERATION DE CLE DE CHIFFREMENT
- English
- COMMUNICATION METHOD WITH SEQUESTRE AND ENCRYPTION KEY RECOVERY
Classification
- CPC, 3
- H04L9/0894
- H04L9/14
- H04L9/0841
- IPC, 2
- H04L9 08
- H04L9 32