Method and arrangement for enabling encrypted communication
Abstract
In a communication network comprising a central unit (CU) having a secret master key (MK), and a number of local units (LU1, LU2, ... LUN) each having its own public key (PK1, PK2, ... PKN), to enable encrypted communication between local units (LU1, LU2, ... LUN), the local units (LU1, LU2, ... LUN) transfer their public keys (PK1, PK2, ... PKN) to the central unit (CU) which calculates functional values (FV1, FV2, ... FVN) from the master key (MK) and the respective public key (PK1, PK2, ... PKN), and which transfers the functional values (FV1, FV2, ... FVN) to the respective local unit (LU1, LU2, ... LUN). Each local unit (LU1, LU2, ... LUN) then transferts its public key (PK1, PK2, ... PKN) to the other local units (LU1, LU2, ... LUN), and each local unit (LU1, LU2, ... LUN) calculates respective session keys from its own individual functional value (FV1, FV2, ... FVN) received from the central unit (CU), and the respective public key (PK1, PK2, ... PKN) received from the other local units (LU1, LU2, ... LUN). Communication being enabled only between local units (LU1, LU2, ... LUN) having calculated identical session keys.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
6 claims: 2 independent, 4 dependent
- 1CLAIMS 1. In a communication network comprising a central unit (CU) having a secret master key (MK), and a number of local units (LUl, LU2 ... LUN) each having its own public key (PKl , PK2 ... PKN), a method of enabling encrypted communication between local units (LUl, LU2 ... LUN), characterized in that, • in advance of any communication between local units (LUl , LU2 ... LUN), - each local unit (LUl, LU2 ... LUN) transfers its public key (PKl, PK2 ... PKN) to the central unit (CU), - the central unit (CU) calculates, for each local unit (LUl, LU2 ... LUN), an individual functional value (FVl, FV2 ... FVN) from the master key (MK) and the respective public key (PKl, PK2 ... PKN) transferred from the respective local unit (LUl, LU2 ... LUN), the functional values (FVl, FV2 ... FVN) being calculated by means of a function H(x, y) of such a nature that H(H(x, y), z) = H(H(x, z), y), and that it is computationally infeasible to calculate x with a knowledge of values of y and values of H(x, y), and - the central unit transfers the respective individual functional value (FVl, FV2 ... FVN) in a secure manner to the respective local unit (LUl, LU2 ... LUN), and • to enable communication between any number of the local units (LUl, LU2 ... LUN), - each local unit (LUl, LU2, LU3) which is to participate in the communication, transfers its public key (PKl, PK2, PK3) to the other local units (LUl, LU2, LU3) that are to participate in the communication, and - each local unit (LUl, LU2, LU3) calculates respective session keys from its own individual functional value (FVl, FV2, FV3) received from the central unit (CU), and the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3) that are to participate in the communication by applying the function H(x, y) in sequence to the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3), communication being enabled only between local units (LUl, LU2, LU3) having calculated identical session keys.
- 4In a communication network comprising a central unit (CU) having a secret master key (MK), and a number of local units (LUl, LU2 ... LUN) each having its own public key (PKl, PK2 ... PKN), an arrangement for enabling encrypted communication between local units (LUl, LU2 ... LUN), characterized in that, • in advance of any communication between local units (LUl, LU2 ... LUN), - each local unit (LUl, LU2 ... LUN) is adapted to transfer its public key (PKl, PK2 ... PKN) to the central unit (CU), - the central unit (CU) is adapted to calculates, for each local unit (LUl, LU2 ... LUN), an individual functional value (FVl, FV2 ... FVN) from the master key (MK) and the respective public key (PKl, PK2 ... PKN) transferred from the re- spective local unit (LUl , LU2 ... LUN), the functional values (FVl , FV2 ... FVN) being calculated by means of a function H(x, y) of such a nature that H(H(x, y), z) = H(H(x, z), y), and that it is computationally infeasible to calculate x with a knowledge of values of y and values of H(x, y), and - the central unit is adapted to transfer the respective individual functional value (FVl, FV2 ... FVN) in a secure manner to the respective local unit (LUl, LU2 ... LUN), and • to enable communication between any number of the local units (LUl, LU2 ... LUN), - each local unit (LUl, LU2, LU3) which is to participate in the communication, is adapted to transfer its public key (PKl, PK2, PK3) to the other local units (LUl, LU2, LU3) that are to participate in the communication, and - each local unit (LUl, LU2, LU3) is adapted to calculate respective session keys from its own individual functional value (FVl, FV2, FV3) received from the central unit (CU), and the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3) that are to participate in the communication by applying the function H(x, y) in sequence to the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3), communication being enabled only between local units (LUl, LU2, LU3) having calculated identical session keys.
Independent claims2
27 paragraphs in 5 sections, as filed
METHOD AND ARRANGEMENT FOR ENABLING ENCRYPTED COMMUNICATION
0002TECHNICAL FIELD The invention relates generally to encrypted communication and more specifically to a method and an arrangement for key distribution to enable encrypted communication between local units having their own public keys in a communication network that also comprises a central unit having a secret master key.
BACKGROUND OF THE INVENTION
0004To enable secure communication within arbitrary groups of local units in such a communication network, the central unit has to certify the respective local unit, and each local unit of the group should be able to check that the other units in fact belong to the group in question, i.e. that they have been certified by the central unit.
0005Today, a group of local units can be certified e.g. by means of different types of certificates based on so called public key cryptography.
0006To enable secure communication between local units certified by the central unit is complicated in that someone within the group has to generate a secret session key which, then, is to be encrypted with the public keys of the other local units of the group, and, then finally, sent out to the respective group member. Thereafter, the communication can start.
SUMMARY OF THE INVENTION
0008The object of the invention is to enable each local unit in a group of local units that are to participate in an encrypted communication, to check that any other local unit in fact belongs to the group, and to enable encrypted communications within arbitrary groups of local units. This is attained in accordance with the invention in that session keys are calculated in each local unit based on the public keys from the other local units and a functional value calculated by the central unit, and that encrypted communication is en- abled only between local units having calculated identical session keys.
0009By means of any known symmetric encryption algorithm, these session keys are then used to encrypt data to be exchanged between the local units.
0010By means of the invention, the calculation work is distributed between the local units instead of being concentrated to the unit initiating the communication.
BRIEF DESCRIPTION OF THE DRAWING
0012The invention will be described more in detail below with reference to the appended drawing on which Fig. 1 schematically illustrates a first stage of the method according to the invention in a communication network, and Fig. 2 illustrates a second stage of the method according to the invention in part of the communication network in Fig. 1.
DESCRIPTION OF THE INVENTION
0014Fig. 1 schematically illustrates a communication network comprising a central unit CU and a plurality of local units LUl, LU2, LU3 ... LUN.
0015Encrypted communication is to be established between any number of local units in the network.
0016The central unit CU has a secret master key MK and each local unit LUl, LU2, LU3 ... LUN has its own open or public key PKl, PK2, PK3 ... PKN as schematically indicated on the drawing. In accordance with the invention, in advance of any communication between any number of the local units LUl, LU2, LU3 ... LUN, the local units transfer their respective public keys PKl, PK2, PK3 ... PKN to the central unit CU, e.g. upon re- quest by the central unit CU, as illustrated by means of arrows from the respective local unit to the central unit CU in Fig. 1.
0017In accordance with the invention, upon receipt of the respective public keys PKl, PK2, PK3 ... PKN from the local units, the central unit CU calculates, for each local unit LUl, LU2. LU3 ... LUN, an individual functional value FV1, FV2, FV3 ... FVN from the master key MK and the respective public key PKl, PK2, PK3 ... PKN received from the respective local unit LUl, LU2, LU3 ... LUN.
0018According to the invention, the functional values are calculated by means of a func- tion H(x, y) of such a nature that, on the one hand, H(H(x, y), z) = H(H(x, z), y) and, on the other hand, it is computationally infeasible to calculate x with a knowledge of values of y and values of H(x, y).
0019Using the master key MK as the first argument in the above function, the functional values FV1, FV2, FV3 ... FVN calculated for the local units LUl, LU2, LU3 ... LUN in Fig. 1 will be H(MK, PKl), H(MK, PK2), H(MK, PK3) ... H(MK, PKN).
0020The central unit CU is adapted to transfer the respective individual functional value FV1, FV2, FV3 ... FVN to the respective local unit LUl, LU2, LU3 ... LUN as il- lustrated in Fig. 1 by means of arrows directed from the central unit CU to the respective local unit LUl, LU2, LU3 ... LUN.
0021The transfer of the functional values FV1, FV2, FV3 ... FVN to the local units LUl, LU2, LU3 ... LUN takes place in a secure manner, e.g. via secure links (not shown). Hereby, the preparations for enabling encrypted communication between any number of local units are terminated.
0022With reference to Fig. 2, an embodiment will be described in which it is supposed that the local unit LUl in Fig. 1 desires encrypted communications with the local units LU2 and LU3 in Fig. 1, and that also the communication between the local units LU2 and LU3 should be encrypted.
0023In accordance with the invention, each local unit that is to communicate encrypted with any other local unit has to exchange public keys with that other local unit.
0024In the embodiment in Fig. 2, as mentioned above, it is supposed that the encrypted communication is initiated by the local unit LUl.
0025Thus, the local unit LUl sends one message to the local unit LU2 and one message to the local unit LU3 informing them of its desire for an encrypted communication between the three local units, and requesting them to transfer their respective public keys PK2 and PK3.
0026Based on these messages, the local unit LU2 requests the local units LUl and LU3 to transfer their public keys PKl and PK3, respectively, and the local unit LU3 requests the local units LUl and LU2 to transfer their respective public keys PKl and PK2.
0027This is schematically illustrated in Fig. 2 by means of arrows in both directions between the local units LUl, LU2, LU3. In case the local units in question have been involved in a mutual encrypted communication earlier, the respective public keys can already be stored in the respective local unit and do not have to be transferred again.
0028In accordance with the invention, based on its own individual functional value FV1, FV2, FV3 received from the central unit CU, and the respective public key received from the other local units, each local unit LUl, LU2, LU3 calculates session keys by applying the above function H(x, y) in sequence.
0029Thus, the session key calculated by the local unit LUl will be H(H(FV1 , PK2),
0030PK3). Inserting FV1 as calculated above by the central unit CU, the session key calculated by the local unit LUl will be H(H(H(MK, PKl), PK2), PK3). The session key calculated by the local unit LU2 will be H(H(FV2, PKl), PK3) or H(H(H(MK, PK2), PKl), PK3) with FV2 inserted as above, and the session key calculated by the local unit LU3 will be H(H(FV3, PKl), PK2) or H(H(H(MK, PK3), PKl), PK2) with FV3 inserted as above.
0031As apparent, due to the symmetry of the function H(x, y), the session keys calculated by the respective local units are identical which is a prerequisite condition for an encrypted communication to be enabled between the local units in question according to the invention.
0032By means of the invention, it will be possible to establish encrypted communications in a simpler manner.
Contents5
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| US8630414B2 | Cited by | United States of America | – | Applicant |
| CN109684860A | Cited by | China | – | Search report |
| WO2009118606A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| FR2922392A1 | Cited by | France | – | Search report |
| CN109711207A | Cited by | China | – | Search report |
| WO2009047325A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| WO2009118606A2 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| EP0739105A1 | Cites | European Patent Office (EPO) | A | International search |
| US5588061A | Cites | United States of America | A | International search |
| US5812669A | Cites | United States of America | A | International search |
4 members in 3 offices
Members4
| Document | Office | Kind | |
|---|---|---|---|
| SE9900472D0 | Sweden | D0 | |
| SE9900472L | Sweden | L | |
| WO0048357A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| AU2953800A | Australia | A |
6 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Ep: pct application non-entry in european phase122 | 122 | WO | |
| Procedure relating to pct application: ceased to have effect for deCeased8642 | 8642 | DE | |
| Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)DFPE | DFPE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO |
Numbers
- Publication
- 00/48357
- Application
- 233
Titles2
- English
- METHOD AND ARRANGEMENT FOR ENABLING ENCRYPTED COMMUNICATION
- French
- PROCEDE ET DISPOSITIF PERMETTANT D'EFFECTUER UNE COMMUNICATION CHIFFREE
Classification
- IPC, 2
- H04L9 08
- H04L9 30
Designated states103
- Regional, 53
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zimbabwe
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
- Tajikistan
- Turkmenistan
- Austria
- Belgium
- Switzerland
- Cyprus
and 29 moreShow fewer
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 50
- United Arab Emirates
- Albania
- Australia
- Bosnia and Herzegovina
- Barbados
- Bulgaria
- Brazil
- Canada
- China
- Costa Rica
- Cuba
- Czechia
- Dominica
- Estonia
- Grenada
- Georgia
- Croatia
- Hungary
- Indonesia
- Israel
- India
- Iceland
- Japan
- Democratic People’s Republic of Korea
and 26 moreShow fewer
- Republic of Korea
- Saint Lucia
- Sri Lanka
- Liberia
- Lithuania
- Latvia
- Morocco
- Madagascar
- North Macedonia
- Mongolia
- Mexico
- Norway
- New Zealand
- Poland
- Romania
- Singapore
- Slovenia
- Slovakia
- Türkiye
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Viet Nam
- Yugoslavia, later Serbia and Montenegro (until 2006)
- South Africa