US20160099920A1

Method for establishing a cryptographically protected communication channel

Claim Score by NHIP

Read claim 16, the broadest

Abstract

Some embodiments are directed to a cryptographic method for providing an electronic first device, an electronic second device and an electronic intermediary device, the cryptographic method establishing a cryptographically protected communication channel between the first device and the second device. The method comprises establishing a session identifier (SID) between the first device and the intermediary device. The first device sends the session identifier and a first key element to the second device over an out-of-band channel. The second device sends a registration message comprising the session identifier to the intermediary device. The first and second device can communicate through the intermediary device protected using a shared key derived at the first and second device.

US20160099920A1, drawing sheet 1
Sheet 1 of 9

Term

9.7 yearsto projected expiry

Projected expiry 20 June 2036, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 4 independent, 16 dependent

  1. 1
    A cryptographic method for an electronic first device, an electronic second device and an electronic intermediary device, the cryptographic method establishing a cryptographically protected communication channel between the first device and the second device, the first device and the second device being arranged to digitally communicate with the intermediary device over a computer network, the method comprising by the first device and/or the intermediary device:establishing a session identifier (SID), by the first device: generating a first random number (α) and determining a first key element from at least the first random number, the first key element being arranged for later constructing a shared cryptographic key shared between the first device and the second device, by the first device: sending the session identifier and the first key element to the second device over an out-of-band channel, by the first device: applying a key derivation function to at least the first random number thus obtaining the shared cryptographic key for protecting communication, by the second device: applying a key derivation function to at least the first key element thus obtaining the shared cryptographic key, by the second device: sending a registration message comprising the session identifier to the intermediary device, by the first device and/or second device: communicating over the cryptographically protected communication channel by: generating a message, cryptographically protecting the message using the shared cryptographic key, sending said cryptographically protected message to the intermediary device, and by the intermediary device: forwarding said cryptographically protected message to the other of the first or second device.
  2. 16
    Broadest claimClaim Score 65, broad(NHIP)An electronic intermediary device for establishing a cryptographically protected communication channel between a first device and a second device, the intermediary device comprising a communication unit arranged to communicate with the first device and the second device over a computer network, a session identifier unit arranged to establish a session identifier (SID) with the first device, a registration unit arranged to receive a registration message comprising the session identifier from the second device, a forwarding unit arranged to receive a message cryptographically protected using a shared cryptographic key from the first device or the second device, forward said cryptographically protected message to the other of the first or second device.
  3. 17
    An electronic first device for establishing a cryptographically protected communication channel between the first device and a second device, the first device comprising a communication unit arranged to communicate with an intermediary device over a computer network, first device being arranged to establish a session identifier (SID) with the intermediary device, a cryptographic unit arranged to generate a first random number (α), and determine a first key element from at least the first random number, the first key element being arranged for later constructing a shared cryptographic key shared between the first device and the second device, a sending out-of-band communication unit arranged to send the session identifier and the first key element to a second device over an out-of-band channel, the cryptographic unit being further arranged to apply a key derivation function to at least the first random number obtaining the shared cryptographic key for protecting communication, a message unit arranged to generate a message, cryptographically protect the message using the shared cryptographic key, and send said cryptographically protected message to the intermediary device, and/or to receive a message cryptographically protected using the shared cryptographic key, decrypt and/or validate said received message using the shared cryptographic key.
  4. 18
    An electronic second device for establishing a cryptographically protected communication channel between a first device and the second device, the second device comprising a communication unit arranged to communicate with an intermediary device over a computer network, a receiving out-of-band communication unit arranged to receive a session identifier and a first key element from the first device over an out-of-band channel, a cryptographic arranged to apply a key derivation function to at least the first key element obtaining a shared cryptographic key for protecting communication, a registration unit arranged to send a registration message comprising the session identifier to the intermediary device a message unit arranged to generate a message, cryptographically protect the message using the shared cryptographic key, and send said cryptographically protected message to the intermediary device, and/or to receive a message cryptographically protected using the shared cryptographic key, decrypt and/or validate said received message using the shared cryptographic key.