WO0048357A1

Method and arrangement for enabling encrypted communication

Abstract

In a communication network comprising a central unit (CU) having a secret master key (MK), and a number of local units (LU1, LU2, ... LUN) each having its own public key (PK1, PK2, ... PKN), to enable encrypted communication between local units (LU1, LU2, ... LUN), the local units (LU1, LU2, ... LUN) transfer their public keys (PK1, PK2, ... PKN) to the central unit (CU) which calculates functional values (FV1, FV2, ... FVN) from the master key (MK) and the respective public key (PK1, PK2, ... PKN), and which transfers the functional values (FV1, FV2, ... FVN) to the respective local unit (LU1, LU2, ... LUN). Each local unit (LU1, LU2, ... LUN) then transferts its public key (PK1, PK2, ... PKN) to the other local units (LU1, LU2, ... LUN), and each local unit (LU1, LU2, ... LUN) calculates respective session keys from its own individual functional value (FV1, FV2, ... FVN) received from the central unit (CU), and the respective public key (PK1, PK2, ... PKN) received from the other local units (LU1, LU2, ... LUN). Communication being enabled only between local units (LU1, LU2, ... LUN) having calculated identical session keys.

WO0048357A1, drawing sheet 1
Sheet 1 of 1

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

6 claims: 2 independent, 4 dependent

  1. 1
    CLAIMS 1. In a communication network comprising a central unit (CU) having a secret master key (MK), and a number of local units (LUl, LU2 ... LUN) each having its own public key (PKl , PK2 ... PKN), a method of enabling encrypted communication between local units (LUl, LU2 ... LUN), characterized in that, • in advance of any communication between local units (LUl , LU2 ... LUN), - each local unit (LUl, LU2 ... LUN) transfers its public key (PKl, PK2 ... PKN) to the central unit (CU), - the central unit (CU) calculates, for each local unit (LUl, LU2 ... LUN), an individual functional value (FVl, FV2 ... FVN) from the master key (MK) and the respective public key (PKl, PK2 ... PKN) transferred from the respective local unit (LUl, LU2 ... LUN), the functional values (FVl, FV2 ... FVN) being calculated by means of a function H(x, y) of such a nature that H(H(x, y), z) = H(H(x, z), y), and that it is computationally infeasible to calculate x with a knowledge of values of y and values of H(x, y), and - the central unit transfers the respective individual functional value (FVl, FV2 ... FVN) in a secure manner to the respective local unit (LUl, LU2 ... LUN), and • to enable communication between any number of the local units (LUl, LU2 ... LUN), - each local unit (LUl, LU2, LU3) which is to participate in the communication, transfers its public key (PKl, PK2, PK3) to the other local units (LUl, LU2, LU3) that are to participate in the communication, and - each local unit (LUl, LU2, LU3) calculates respective session keys from its own individual functional value (FVl, FV2, FV3) received from the central unit (CU), and the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3) that are to participate in the communication by applying the function H(x, y) in sequence to the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3), communication being enabled only between local units (LUl, LU2, LU3) having calculated identical session keys.
  2. 4
    In a communication network comprising a central unit (CU) having a secret master key (MK), and a number of local units (LUl, LU2 ... LUN) each having its own public key (PKl, PK2 ... PKN), an arrangement for enabling encrypted communication between local units (LUl, LU2 ... LUN), characterized in that, • in advance of any communication between local units (LUl, LU2 ... LUN), - each local unit (LUl, LU2 ... LUN) is adapted to transfer its public key (PKl, PK2 ... PKN) to the central unit (CU), - the central unit (CU) is adapted to calculates, for each local unit (LUl, LU2 ... LUN), an individual functional value (FVl, FV2 ... FVN) from the master key (MK) and the respective public key (PKl, PK2 ... PKN) transferred from the re- spective local unit (LUl , LU2 ... LUN), the functional values (FVl , FV2 ... FVN) being calculated by means of a function H(x, y) of such a nature that H(H(x, y), z) = H(H(x, z), y), and that it is computationally infeasible to calculate x with a knowledge of values of y and values of H(x, y), and - the central unit is adapted to transfer the respective individual functional value (FVl, FV2 ... FVN) in a secure manner to the respective local unit (LUl, LU2 ... LUN), and • to enable communication between any number of the local units (LUl, LU2 ... LUN), - each local unit (LUl, LU2, LU3) which is to participate in the communication, is adapted to transfer its public key (PKl, PK2, PK3) to the other local units (LUl, LU2, LU3) that are to participate in the communication, and - each local unit (LUl, LU2, LU3) is adapted to calculate respective session keys from its own individual functional value (FVl, FV2, FV3) received from the central unit (CU), and the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3) that are to participate in the communication by applying the function H(x, y) in sequence to the respective public key (PKl, PK2, PK3) received from the other local units (LUl, LU2, LU3), communication being enabled only between local units (LUl, LU2, LU3) having calculated identical session keys.