WO0130016A2

A method for prohibiting transacting parties from subsequently repudiating an executed transaction with a trusted third party

Abstract

A protocol for prohibiting non-repudiation by transacting parties involved in an executed electronic transaction, whereby a trusted third party is responsible for ensuring non-repudiation. In this protocol, a sender uses a secret sharing technology to divide the original session key into a first sub-session key and a second sub-session key. The first and second sub-session keys must be combined into the original session key in order for a recipient to decrypt a product that is encrypted with the original session key. The sender includes the first sub-session key that is encrypted with a recipient's public key and an encrypted product in a first message. Then the sender transmits the first message to the recipient. The recipient uses the first message as evidence of non-repudiation of origin, i.e., evidence of non-repudiation that the sender sent the transaction. The recipient transmits, to the sender, a second message requesting the second sub-session key. The sender may use the second message as evidence of non-repudiation of receipt, i.e., evidence of non-repudiation that the recipient received the transaction. Thereafter, the sender includes the second sub-session key which is encrypted with the trusted third party's public key in a third message that is forwarded to the trusted third party.

WO0130016A2, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

42 claims: 2 independent, 40 dependent

  1. 1
    WHAT IS CLAIMED:1. A method for ensuring non-repudiation by transacting parties involved in an executed electronic transaction, the transacting parties using a trusted third party to resolve repudiation disputes, the method comprising the steps of: generating, by a sending party, a session key and dividing the session key into a plurality of sub-session keys comprising a first sub-session key and a second sub-session key;sending, by the sending party to a receiving party, a first cryptographic message, the first cryptographic message including a product that is encrypted with the session key, a digital signature ofthe sending party, and an encrypted first sub-session key;requesting upon receipt ofthe first cryptographic message, by the receiving party from the sending party, the second sub-session key in a second message, the second message including the receiving party digital signature;transmitting upon receipt ofthe second message, from the sending party to a trusted third party, a third cryptographic message with the encrypted second sub-session key, the second sub-session key encrypted with the trusted third party's public key;obtaining, by the trusted third party, the second sub-session key from the third cryptographic message and generating a fourth cryptographic message;publishing, by the trusted third party, the fourth cryptographic message on the trusted third party's web site;retrieving, by the receiving party, the fourth cryptographic message from the trusted third party's web site;and combining, by the receiving party, a predefined number ofthe plurality of sub- session keys into a required session key in order to retrieve encrypted product from the first cryptographic message.
  2. 22
    A system for ensuring non-repudiation by transacting parties involved in an executed electronic transaction, the transacting parties using a trusted third party to resolve repudiation disputes, the system comprises:means for generating, by a sending party, a session key and dividing the session key into a plurality of sub-session keys comprising a first sub-session key and a second sub-session key;means for sending, by the sending party to a receiving party, a first cryptographic message, the first cryptographic message including a product that is encrypted with the session key, a digital signature ofthe sending party, and an encrypted first sub-session key;means for requesting upon receipt ofthe first cryptographic message, by the receiving party from the sending party, the second sub-session key in a second message, the second message including the receiving party's digital signature;means for transmitting upon receipt ofthe second message, from the sending party to a trusted third party, a third cryptographic message with the encrypted second sub-session key, the second sub-session key encrypted with the trusted third party's public key;means for obtaining, by the trusted third party, the second sub-session key from the third cryptographic message and generating a fourth cryptographic message;means for publishing, by the trusted third party, the fourth cryptographic message on the trusted third party's web site;means for retrieving, by the receiving party, the fourth cryptographic message from the trusted third party's web site;and means for combining, by the receiving party, a predefined number ofthe plurality of sub-session keys into a required session key in order to retrieve encrypted product from the first cryptographic message.