IL113259A

Apparatus and method for safe communication handshake and data transfer

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

35 claims: 5 independent, 30 dependent

  1. 1
    MB 18 CLAIMS What is claimed is:1. A system for safe key distribution to authorized or any other users, to facilitate establishing a safe communication link, comprising: (A) A safe key distribution center including: (1) Computer means for storing a list of said users and their respective encryption keys, for retrieving data from and updating said list and for performing related control functions, according to predefined procedures and received messages from said users;(2) Channel interface means for connecting said computer means in said center to said users through a communication channel to receive and transmit digital messages with said users;and (B) A key management device attaching to each one of said user's encryption machine for the purpose of key distribution, and including: (1) Channel interface means for connecting with another user or said key distribution center through a communication channel, to transmit digital data containing said key or a message with said another user. (2) Key management controller means for accepting the desired addressee or initiator details, for obtaining said key from said center through said channel interface, and for transferring said key to said encryption machine, connected to said channel interface and to said encryption machine.
  2. 7
    9. The method for distributing a safe key according to Claim B, wherein said procedure includes the steps of:(A) Said initiator gets the encryption key for said desired addressee using encrypted communications with said center;(B) Said initiator initiates communications with said addressee using-said addressee encryption key;(C) Said addressee gets the encryption key for said initiator using-encrypted communications with said center;and (D) Said addressee responds to said initiator using said initiator encryption key, to establish said secure communication link. MB 20
  3. 15
    19..A key management device attaching to each one of said user's encryption machine for the purpose of key distribution, and comprising:(A) Channel interface means for connecting with another user or said key distribution center through a communication channel, to transmit or receive digital data relating to said key or handshaking data. (B) Key management controller means for accepting the desired addressee or initiator details, for obtaining said key from said center through said channel interface, and for transferring said key to said encryption machine, connected to said channel interface means and to said encryption machine. (C) wherein said communication channel may be independent of and is secured against the key distribution center.
  4. 20
    24. The key management device according encryption machine is used for encryption of related communications . to Claim 19, wherein said the secure link establishment
  5. 29
    34. A method for safe distribution of encryption keys, to make possible to establish a secure link between parties which are at separate locations and which parties had no previous secure communications therebetween, wherein a first user desiring to establish a secure communication:session with a second user performs steps comprising: (A) generatiing an encryption key pair, comprising a secret private key and a known public key;(B) storing (he private key in digital storage means at the first user’s facility, to be used for received messages decryption;(C) sending a digital message to a key distribution center, the message including identification data for the first user and the public encryption key;(D) receiving a digital certificate from the center and storing it in the digital memory!» wherein the certificate includes the identification data, the public key and time-related information indicating the date of preparation of the certificate, all encrypted with the secret private key of the center;(E) using th$ certificate for establishing a secure link with the second user, by sending the certificate to the second user it is desired to establish secure communications therewith;(F) occasionally and anonymously interrogating the center for the certificate pertaining to the first user, to ensure the information in the center was not tampered with;and wherein tne second user, addressed by the first user desiring to establish a secure communication session performs steps comprising: 113259/1 - 25 - (A’) receiving a message from the first user, the message including a certificate with information pertaining to the first user and including identification data for the first user, the public key for the first user and information indicating the date of preparation of the certificate, all encrypted with the secret private key of the center;(B’) decrypting the message using the public, known key of the center, to reveal the identification, the public key and the date for the first user;(C’) making a decision of either to trust the certificate or to verify it, where in the former case go to step (K’) below and in the latter case got to step (D‘) below;(D’) inquiring the key distribution center about the first user, receiving the answer from the center including the correct up-to-date certificate pertaining to the first user;(E’) decrypting the answer using the public, known key of the center;(F’) if the key and user identification in the answer are identical to those in the certificate decrypted in step (B’) above, then verification is positive, go to step (G') below, else end;(G’) generating an encryption key pair, comprising a secret private key and a known public key;(H1) storing the private key in digital storage means at the second user’s facility, to be used for the decryption of received messages;(Γ) sending a digital message to a key distribution center, the message including identification data for the second user and the public encryption key;(J’) receiving a digital certificate from the center and storing it in the digital memory, wherein the certificate includes the identification data, the public key and time-related information indicating the date of preparation of the certificate, all encrypted with the secret private key of the center;and (K’) acknowledge to the first user the reception of a valid certificate, to indicate that the second user is ready to accept an encrypted message from the first user. 113259/1 - 26 -