Secure authenticated channel
Abstract
A protocol (i.e. method) and corresponding apparatuses for calculating a session key. Two peers with knowledge of a common Diffie-Hellman permanent key, K<SUB>perrn</SUB>, and the identity and public key of the other peer. A first peer chooses a first ephemeral private key x and calculates the first corresponding ephemeral public key g<SUP>x</SUP>, which is sent to the second peer. The second peer calculates a second ephemeral public key g<SUP>y</SUP> in the same manner, and an ephemeral shared key K<SUB>eph</SUB>, hashes g<SUP>y</SUP>, K<SUB>eph</SUB>, K<SUB>perm</SUB>, and its identity, and sends g<SUP>y</SUP> and the hash to the first peer. The first peer calculates K<SUB>eph</SUB>, verifies the hash, and hashes g<SUP>x</SUP>, K<SUB>eph</SUB>, K<SUB>pem</SUB>, and its identity, and sends it to the second peer that verifies this hash. Thereafter, both peers obtain a session key by hashing K<SUB>eph</SUB>. The apparatuses may then use the session key to establish a secure authenticated channel (SAC).

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
2 claims: 2 independent, 0 dependent
- 1CLAIMS 1. A method of calculating a session key shared by a first and a second device (11 , 21), the first device having a certificate (Ca) comprising a public key (ga) and an identity corresponding to itself (ID3), and knowledge of the identity corresponding to itself (IDa), a private key (a), and the public key (ga), the second device having a certificate (Cb) comprising a public key (gb) and an identity corresponding to itself (IDb), and knowledge of the identity corresponding to itself (IDb), a private key (b), and the public key (gb), the method comprising the steps of:at the first device: - choosing a first ephemeral private key (x);- calculating a first ephemeral public key (gκ);- sending its certificate (Ca) and the first ephiemeral public key (gx) to the second device;at the second device: - receiving the certificate of the first device (Ca) and the first ephemeral public key (gx);- verifying the certificate of the first device(Ca);- choosing a second ephemeral private key (y);- calculating a second ephemeral public key (gy);- calculating an ephemeral shared key (KePh) from the first ephemeral public key (gx) and the second ephemeral private key (y);- calculating a permanent key (KpΘrm) from the public key of the first device (ga) and its own private key (b);- calculating a first value (H(gy, KΘPh, Kperm, IDb)) from the second ephemeral public key (gy), the ephemeral shared key (Kθph), the permanent key (KpΘrm), and the identity corresponding to itself (IDb);- sending its certificate (Cb), the second ephemeral public key (gy) and the first value (H(gy Keph, Kperm, IDb)) to the first device;at the first device: - receiving the certificate of the second device (Cb), the second ephemeral public key (gy) and the first value (H(gy, Keph, Kpθrm, IDb)) from the second device;- verifying the certificate of the second device(Cb);- calculating the ephemeral shared key (Kθph) from the second ephemeral public key (gy) and the first ephemeral private key (x);- calculating the permanent key (Kpθrm) from the public key of the first device (gb) and its own private key (a);- verifying the first value (H(gy, Keph, KpΘrtn, IDb));- calculating a second value (H(gx, Keph, Kperm, IDa)) from the first ephemeral public key (gx), the ephemeral shared key (KθPh), the permanent key (Kperm), and the identity corresponding to itself (IDa);- sending the second value (H(gx, Keph, Kpθrm, IDa)) to the second device;at the second device: - receiving the second value (H(gx, Keph, Kperm, ID3));- verifying the second value (H(gx, Keph, Kperm, ID3));and - calculating a session key (KseSs) as a function of the ephemeral shared at the first device: - calculating the session key (KseSs) as a function of the ephemeral shared key (Keph).
- 2A first device (11) for participating, with a second device (21), in the calculation of a shared session key, the first device having a certificate (Ca) comprising a public key (ga) and an identity corresponding to itself (IDa), and knowledge of the identity corresponding to itself (IDa), a private key (a), and the public key (ga), the first device comprising a processor (12) for:- choosing an ephemeral private key (x);- calculating a first ephemeral public key (gx);- sending its certificate (Ca) and the first ephemeral public key (gx) to the second device;- receiving a certificate of the second device (Cb), a second ephemeral public key (gy) and a first value (H(gy, Kθph, Kpem, IDb)) from the second device, the certificate (Cb) comprising a public key (gb) and an identity of the second device (IDb), and the first value (H(gy, Kθph, Kperm, IDb)) being calculated from the second ephemeral public key (gy), an ephemeral shared key (Kθph), a permanent key (Kperm), and the identity corresponding to the second device (IDb);- verifying the certificate of the second device(Cb);- calculating the ephemeral shared key (KθPh) from the second ephemeral public key (gy) and the ephemeral private key (x);- calculating the permanent key (Kpθrm) from the public key of the first device (gb) and its own private key (a);- verifying the first value (H(gy, Keph, Kperm, IDb));- calculating a second value (H(gx, KθPh, Kperm, ID3)) from the first ephemeral public key (gx), the ephemeral shared key (KΘph), the permanent key (Kpθrm), and the identity corresponding to itself (ID3);- sending the second value (H(gx, Keph, Kpemi, ID3)) to the second device;and - calculating a session key (KseSs) as a function of the ephemeral shared 3. A second device (21) for participating, with a first device (11), in the calculation of a shared session key, the second device having a certificate (Cb) comprising a public key (gb) and an identity corresponding to itself (IDb), and knowledge of the identity corresponding to itself (IDb), a private key (b), and the public key (gb), the second device comprising a processor (22) for: - receiving a certificate of the first device (C3) and a first ephemeral public key (gx), the certificate comprising a public key (ga) and an identity of the first device (IDa);- verifying the certificate of the first device (Ca);- choosing an ephemeral private key (y);- calculating a second ephemeral public key (gy);- calculating an ephemeral shared key (KePh) from the first ephemeral public key (gx) and the ephemeral private key (y);- calculating a permanent key (Kperm) from the public key of the first device (ga) and its own private key (b);- calculating a first value (H(gy, Keph, Kperm, IDb)) from the second ephemeral public key (gy), the ephemeral shared key (Keph), the permanent key (Kpθrm), and the identity corresponding to itself (IDb);- sending its certificate (Cb)1 the second ephemeral public key (gy) and the first value (H(gy, Keph, Kpθrm, IDb)) to the first device;- receiving a second value (H(gx, Keph, Kpθrm, ID3)) from the first device, the second value being calculated from the first ephemeral public key (gx), the ephemeral shared key (Keph), the permanent key (Kperm), and the identity corresponding to the first device (ID3);- verifying the second value (H(gx, Keph, Kperm, ID8));and - calculating the session key (KseSs) as a function of the ephemeral shared key (KΘPh).
Independent claims2
17 paragraphs in 1 section, as filed
SECURE AUTHENTICATED CHANNEL
[0001] The invention relates generally to secure authenticated channels, and in particular to calculation of session keys for establishment of such channels for protection of digital content, for example in a digital television system. [0002] Secure authenticated channels, well known in the art of cryptography, are established to allow two mutually authenticated devices (often called peers) to exchange information confidentially. A secure authenticated channel should preferably have the following characteristics:
- mutual authentication of the peers; - key confirmation, i.e. a common secret is established and at least one peer is able to verify that the secret indeed is common;
- forward secrecy, i.e. old session keys cannot be calculated even when long-term secret keys (such as certificate secret keys) are known.
[0003] These characteristics can be formally proven mathematically, and it has been proven that if there exists a way to circumvent one of the above characteristics for a given cryptographic protocol, then the whole protocol may be broken with relative ease.
[0004] Over the years, the cryptographic community has proposed many protocols for secure authenticated channels. Only a few of these channels have been proven to fulfill the characteristics above.
[0005] The protocols that do provide channels with the required characteristics all use a number of different cryptographic primitives: at least one asymmetric primitive (such as asymmetric encryption or digital signature), hash functions, Message Authentication Code (MAC), and, in some of them, other primitives such as symmetric encryption. A problem with these protocols is that they are quite resource consuming and are as such difficult to implement in a device with limited computing capabilities, such as for example a portable security module, like a smart card. Another problem is that the use of many cryptographic primitives makes it difficult to prove that a protocol is secure. [0006] The present invention provides a secure access channel protocol that has the required characteristics and that is particularly suitable for implementation in a device with limited computing capabilities. [0007] Throughout the description, it will be assumed that, as cryptography is a mature art, the basic concepts are well known. These concepts will for reasons of clarity and succinctness not be described more than necessary for the comprehension of the invention.
[0008] In a first aspect, the invention is directed to a method of calculating a session key common to a first and a second device (11, 21 ). The first device has a certificate (C<sub>3</sub>) comprising a public key (g<sup>a</sup>) and an identity corresponding to itself (ID<sub>3</sub>), and knowledge of the identity corresponding to itself (IDg), a private key (a), and the public key (g<sup>a</sup>). The second device has a corresponding certificate and knowledge. The first device chooses a first ephemeral private key (x), calculates a first ephemeral public key (g<sup>x</sup>), and sends its certificate (C<sub>a</sub>) and the first ephemeral public key (g<sup>x</sup>) to the second device. Upon reception of the certificate of the first device (C<sub>a</sub>) and the first ephemeral public key (g<sup>x</sup>), the second device verifies the certificate of the first device(Ca), chooses a second ephemeral private key (y), calculates a second ephemeral public key (g<sup>y</sup>), calculates an ephemeral shared key (K<sub>θP</sub>h) from the first ephemeral public key (g<sup>x</sup>) and the second ephemeral private key (y), calculates a permanent key (K<sub>pθr</sub>m) from the public key of the first device (g<sup>a</sup>) and its own private key (b), calculates a first value (H(g<sup>y</sup>, K<sub>θp</sub>h, K<sub>pe</sub>rm, IDb)) from the second ephemeral public key (g<sup>y</sup>), the ephemeral shared key (K<sub>ep</sub>h), the permanent key (K<sub>per</sub>m), and the identity corresponding to itself (IDb), and sends its certificate (C<sub>b</sub>), the second ephemeral public key (g<sup>y</sup>) and the first value (H(g<sup>y</sup>, K<sub>θPh</sub>, K<sub>pΘrm</sub>, ID<sub>b</sub>)) to the first device. Upon reception of the certificate of the second device (C<sub>b</sub>), the second ephemeral public key (g<sup>y</sup>) and the first value (H(g<sup>y</sup>, K<sub>Θph</sub>, K<sub>pθ</sub>ϊmγ lD<sub>b</sub>)) from trie second device, the first device verifies the certificate of the second device(Cb), calculates the ephemeral shared key (K<sub>ep</sub>h) from the second ephemeral public key (g<sup>y</sup>) and the first ephemeral private key (x), calculates the permanent key (K<sub>per</sub>m) from the public key of the first device (g<sup>b</sup>) and its own private key (a), verifies the first value (H(g<sup>y</sup>, K<sub>ΘP</sub>h, K<sub>pΘ</sub>rm, IDb)), calculates a second value (H(g<sup>x</sup>, K<sub>ΘP</sub>h, Kperm, ID<sub>3</sub>)) from the first ephemeral public key (g<sup>x</sup>), the ephemeral shared key (K<sub>eph</sub>), the permanent key (K<sub>pθrm</sub>), and the identity corresponding to itself (ID<sub>3</sub>), and sends the second value (H(g<sup>x</sup>, K<sub>ep</sub>h, K<sub>perm</sub>, ID<sub>3</sub>)) to the second device. Upon reception of the second value (H(g<sup>x</sup>, K<sub>ep</sub>h, IC<sub>pe</sub>rm, ID<sub>a</sub>)), the second device verifies the second value (H(g<sup>x</sup>, K<sub>ep</sub>h, K<sub>pΘ</sub>rm, ID<sub>3</sub>)), and calculates a session key (K<sub>seS</sub>s) as a function of the ephemeral shared key (K<sub>ep</sub>h). The first device also calculates the session key (Ks<sub>ΘS</sub>s) as a function of the ephemeral shared key (K<sub>eph</sub>). [0009] In a second aspect, the invention is directed to a first device (11 ) for participating, with a second device (21 ), in the calculation of a session key. The first device has a certificate (C<sub>a</sub>) comprising a public key (g<sup>a</sup>) and an identity corresponding to itself (ID<sub>8</sub>), and knowledge Df the identity corresponding to itself (ID<sub>3</sub>), a private key (a), and the public key (g<sup>a</sup>). The first device comprises a processor (12) for choosing an ephemeral private key (x); calculating a first ephemeral public key (g<sup>x</sup>); sending its certificate (Ca) and the first ephemeral public key (g<sup>x</sup>) to the second devi ce; receiving a certificate of the second device (Cb), a second ephemeral public key (g<sup>y</sup>) and a first value (H(g<sup>y</sup>, K<sub>ep</sub>h, K<sub>pθ</sub>rm, IDb)) from the second device, the certificate (C<sub>b</sub>) comprising a public key (g<sup>b</sup>) and an identity of the second device (IDb), and the first value (H(g<sup>y</sup>, K<sub>θP</sub>h, K<sub>pe</sub>rm, IDb)) being calculated from the second ephemeral public key (g<sup>y</sup>), an ephemeral shared key (Ke<sub>P</sub>h), a permanent key (Kperm), and the identity corresponding to the second device (IDb); verifying the certificate of the second device(C<sub>b</sub>); calculating the ephemeral shared key (K<sub>ep</sub>h) from the second ephemeral public key (g<sup>y</sup>) and the ephemeral private key (x); calculating the permanent key (K<sub>pθrm</sub>) from the public key of the first device (g<sup>b</sup>) and its own private key (a); verifying the first value (H(g<sup>y</sup>, K<sub>ep</sub>h, Kperm, IDb)); calculating a second value (H(g<sup>x</sup>, K<sub>θP</sub>h, K<sub>pe</sub>rm, IQa)) from the first ephemeral public key (g<sup>x</sup>), the ephemeral shared key (K<sub>θP</sub>h), the permanent key (K<sub>pθ</sub>rm), and the identity corresponding to itself (ID<sub>3</sub>); sending the second value (H(g<sup>x</sup>, K<sub>eph</sub>, K<sub>pΘ</sub>rm, ID<sub>a</sub>)) to the second device; and calculating a session key (K<sub>SΘS</sub>s) as a function of the ephemeral shared key
(K<sub>ep</sub>h).
[0010] In a third aspect, the invention is directed to a second device (21) for participating, with a first device (11), in the calculation of a session key. The second device has a certificate (Cb) comprising a public key (g<sup>b</sup>) and an identity corresponding to itself (ID<sub>b</sub>), and knowledge of the identity corresponding to itself (ID<sub>b</sub>), a private key (b), and the public key (g<sup>b</sup>). The second device comprises a processor (22) for receiving a certificate of the first device (C<sub>3</sub>) and a first ephemeral public key (g<sup>x</sup>), the certificate comprising a public key (g<sup>a</sup>) and an identity of the first device (ID<sub>3</sub>); verifying the certificate of the first device (C<sub>8</sub>); choosing an ephemeral private key (y); calculating a second ephemeral public key (g<sup>y</sup>); calculating an ephemeral shared key (K<sub>θPh</sub>) from the first ephemeral public key (g<sup>x</sup>) and the ephemeral private key (y); calculating a permanent key (K<sub>pe</sub>rm) from the public key of the first device (g<sup>a</sup>) and its own private key (b); calculating a first value (H(g<sup>y</sup>, Keph, Kperm, ID<sub>b</sub>)) from the second ephemeral public key (g<sup>y</sup>), the ephemeral shared key (K<sub>ep</sub>h), the permanent key (K<sub>pθ</sub>rm), and the identity corresponding to itself (ID<sub>b</sub>); sending its certificate (Cb), the second ephemeral public key (g<sup>y</sup>) and the first value (H(g<sup>y</sup>, K<sub>ep</sub>h, K<sub>pe</sub>rm, ID<sub>b</sub>)) to the first device; receiving a second value (H(g<sup>x</sup>, K<sub>ΘP</sub>h, K<sub>pθ</sub>rm, ID<sub>3</sub>)) from the first device, the second value being calculated from the first ephemeral public key (g<sup>x</sup>), the ephemeral shared key (K<sub>θP</sub>h), the permanent key (K<sub>P</sub>erm), and the identity corresponding to the first device (ID<sub>a</sub>); verifying the second value (H(g<sup>x</sup>, K<sub>ep</sub>h, K<sub>perm)</sub> ID<sub>3</sub>)); and calculating the session key (K<sub>seS</sub>s) as a function of the ephemeral shared key
(Keph)-
[0011] Figure 1 illustrates the session key exchange according to an embodiment of the present invention.
[0012] Figure 1 illustrates the session key exchange according to an embodiment of the present invention.
[0013] Before the start of the method, the first device 11 knows its identity ID<sub>3</sub>, its own private key a and public key g<sup>a</sup>. g<sup>a</sup> is a short notation for g<sup>a</sup> mod p, where a is the first device's private key, g is a known generator and p is a known prime number, as is well known in the art. The second device 21 has the corresponding knowledge: ID<sub>b</sub>, b, g<sup>b</sup>. Certificates for the devices comprise the public key and the identity; C<sub>a</sub>(g<sup>a</sup>, ID<sub>3</sub>) and C<sub>b</sub>(g<sup>b</sup>, ID<sub>b</sub>), respectively. The devices 11, 12 also have processors (CPU) 12, 22 adapted to effect the steps of the method.
[0014] In step 252, the first device 11 chooses, preferably randomly, a first ephemeral private key x and calculates an ephemeral public key g<sup>x</sup>, that it sends together with its certificate C<sub>a</sub>(g<sup>a</sup>, ID<sub>3</sub>) to the second device 21 in message 254.
[0015] Upon reception of message 254, the second device 21 verifies the certificate C<sub>a</sub>(g<sup>a</sup>, ID<sub>a</sub>) of the first device 11; step 256. If the verification is unsuccessful, the second device 21 abandons the method. However, if the verification is successful, then it chooses, preferably randomly, a second ephemeral private key y, and calculates a second ephemeral public key g<sup>y</sup>, a ephemeral shared key K<sub>θP</sub>h = g^, and a Diffie-Hellman permanent key K<sub>pe</sub>rm = g<sup>ab</sup>, in step 258.
[0016] In step 260, the second device 21 then calculates a first hash value H(g<sup>y</sup>, K<sub>θ</sub>ph, Kperm, IDb) using the second ephemeral public key g<sup>y</sup>, the ephemeral shared key Ke<sub>P</sub>h, the Diffie-Hellman permanent key K<sub>pe</sub>rm, and its identity ID<sub>b</sub>, and a suitable hash function, for example one of the many functions known in the art. It should be known that other suitable functions than hash functions may be used for this and the following hash value calculations of the embodiment. The second device 21 then sends the second ephemeral public key g<sup>y</sup>, its certificate C<sub>b</sub>(g<sup>b</sup>, ID<sub>b</sub>), and the first hash value H(g<sup>y</sup>, K<sub>θP</sub>h, Kp<sub>θrm</sub>, ID<sub>b</sub>) to the first device 11 in message 262. [0017] Upon reception of message 262, the first device 11 verifies the certificate C<sub>b</sub>(g<sup>b</sup>, ID<sub>b</sub>) of the second device 21 ; step 264. If the verification is unsuccessful, the first device 11 abandons the method. However, if the verification is successful, the first device 11 computes the ephemeral shared key K<sub>ep</sub>h and the Diffie-Hellman permanent key K<sub>pe</sub>rm in step 266. In step 268, the first device 11 verifies the first hash value, using the same hash function as the second device 21 used in step 260. If the first hash value is not verified, then the first device 11 aborts the method, but if the first hash value is verified, then the first device 11 calculates a second hash value H(g<sup>x</sup>, K<sub>ep</sub>h, Kperm, ID<sub>3</sub>) in step 270, using the first ephemeral public key g<sup>x</sup>, the ephemeral shared key K<sub>ep</sub>h, the Diffie-Hellman permanent key K<sub>PΘ</sub>rm and its identity ID<sub>a</sub>. The first device 11 sends the second hash value H(g<sup>x</sup>, K<sub>θP</sub>h, K<sub>per</sub>m, ID<sub>a</sub>) to the second device 21 in message 272.
[0018] Upon reception of the message 272, the second device 21 verifies the second hash value H(g<sup>x</sup>, K<sub>ep</sub>h, K<sub>per</sub>m, ID<sub>3</sub>) in step 274, using the same hash function as the one used by the first device 10 in step 270. If the second hash value is not verified, then the second device 21 aborts the protocol, but if the second hash value is verified, then the second device 21 calculates, in step 276, a session key K<sub>sess</sub> by calculating the hash value of the ephemeral shared key K<sub>θP</sub>h- Then it sends a "ready" message 278 to the first device 11 to indicate that the second hash value H(g<sup>x</sup>, K<sub>ΘP</sub>h, K<sub>perm</sub>, ID<sub>3</sub>) has been successfully verified and the session key K<sub>sess</sub> has been calculated. [0019] Upon reception of the "ready" message 278 from the second device 21 , the first device 11 calculates, in step 280, the same session key K<sub>sΘSS</sub> by calculating the hash value of the ephemeral shared key K<sub>ep</sub>h, using the same hash function as that used by the second device 21 in step 276. Then the first device 11 sends a "ready" message 282 to the second device 21 to indicate that it too has calculated the session key K<sub>seS</sub>s- [0020] At this point, both the first device 11 and the second device 21 possess the session key K<sub>seS</sub>s that can be used to protect information sent between them. With the protocol according to the invention, the confidentiality of the private keys is assured, the authentication and the key confirmation are mutual. Furthermore, the forward secrecy and the robustness against leakage of previous session key are assured as well. A person skilled in the art will appreciate that the three hash functions described in connection with steps 212, 220, and 226 may be different, the same, or that two of them are the same while the third is different. [0021] It should be noted that where this description makes reference to random numbers, these numbers are often in practice pseudo-random. [0022] The expression "security module" encompasses any kind of security module, portable or stationary, that comprises a processor and can be used to establish a secure authenticated channel according to the invention, such as for example smart cards, PC cards (formerly known as PCMCIA cards), and integrated circuits soldered to the Printed Circuit Board of an apparatus such as a television. [0023] The embodiment described hereinbefore is particularly suited for implementation in a digital television set and a security module. However, a person skilled in the art will appreciate that the invention may be implemented and used by any kind of device with the necessary resources, i.e. a processor and preferably a memory storing the necessary information. Non-limitative examples of other devices are DVD players, computers interacting with external accessories, and Automatic Teller Machines (ATMs) and bankcards.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US8218773B2 | Cited by | United States of America | – | Applicant | – |
| US8693695B2 | Cited by | United States of America | – | Applicant | – |
| US8495375B2 | Cited by | United States of America | – | Applicant | – |
| EP3086226A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| EP2876569A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| EP2955654A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| US8412943B2 | Cited by | United States of America | – | Applicant | – |
| US8336083B2 | Cited by | United States of America | – | Applicant | – |
| EP3067811A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| US9280657B2 | Cited by | United States of America | – | Applicant | – |
| EP2955657A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| EP2073484A1 | Cited by | European Patent Office (EPO) | – | Examiner | – |
| EP2955656A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| US2010281275A1 | Cited by | United States of America | – | Pre-grant | – |
| US8464060B2 | Cited by | United States of America | – | Applicant | – |
| US7646872B2 | Cited by | United States of America | – | Applicant | – |
| WO2009056048A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| US8417955B2 | Cited by | United States of America | – | Applicant | – |
| US10025918B2 | Cited by | United States of America | – | Applicant | – |
| EP2073430A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US9154827B2 | Cited by | United States of America | – | Applicant | – |
| EP2793157A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| EP3086226A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP2793158A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| EP2955655A1 | Cited by | European Patent Office (EPO) | – | Applicant | – |
| US8452017B2 | Cited by | United States of America | – | Applicant | – |
| US7894605B2 | Cited by | United States of America | – | Applicant | – |
| US2004081321A1 | Cites | United States of America | A | International search | 1-3 |
| US5889865A | Cites | United States of America | A | International search | 1-3 |
| US5953420A | Cites | United States of America | A | International search | 1-3 |
25 members in 12 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004052722 | European Patent Office (EPO) | W | |
| WO2004EP52722 | – | – | – |
Members25
| Document | Office | Kind | |
|---|---|---|---|
| AU2004324546A1 | Australia | A1 | |
| WO2006048043A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| MX2007005037A | Mexico | A | |
| KR20070070198A | Republic of Korea | A | |
| EP1805929A1 | European Patent Office (EPO) | A1 | |
| CN101048970A | China | A | |
| BRPI0419162A | Brazil | A | |
| EP1906587A2 | European Patent Office (EPO) | A2 | |
| EP1906587A3 | European Patent Office (EPO) | A3 | |
| AU2008201456A1 | Australia | A1 | |
| JP2008518530A | Japan | A | |
| KR20090119791A | Republic of Korea | A | |
| AU2004324546B2 | Australia | B2 | |
| AU2008201456B2 | Australia | B2 | |
| RU2009102230A | Russian Federation | A | |
| EP1805929B1 | European Patent Office (EPO) | B1 | |
| AT477636T | Austria | T | |
| ATE477636T1 | Austria | T1 | |
| DE602004028670D1 | Germany | D1 | |
| ES2348240T3 | Spain | T3 | |
| JP4719749B2 | Japan | B2 | |
| KR101075316B1 | Republic of Korea | B1 | |
| KR101075334B1 | Republic of Korea | B1 | |
| CN101048970B | China | B | |
| RU2488226C2 | Russian Federation | C2 |
19 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Entry into the national phaseENP | ENP | BR | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Entry into the national phaseENP | ENP | AU | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO |
Numbers
- Publication
- 2006/048043
- Publication, DOCDB
- 2006048043
- Publication, EPODOC
- WO2006048043
- Application
- 52722
- Application, DOCDB
- 2004052722
- Application, EPODOC
- WO2004EP52722
Titles2
- English
- SECURE AUTHENTICATED CHANNEL
- French
- VOIE AUTHENTIFIÉE SÉCURISÉE
Classification
- CPC, 2
- H04L9/0841
- H04L9/30
Designated states126
- Regional, 71
- African Regional Intellectual Property Organization (ARIPO)
- Botswana
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Mozambique
- Namibia
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Eurasian Patent Organization (EAPO)
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
and 47 moreShow fewer
- Tajikistan
- Turkmenistan
- European Patent Office (EPO)
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- African Intellectual Property Organization (OAPI)
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 55
- United Arab Emirates
- Antigua and Barbuda
- Albania
- Australia
- Bosnia and Herzegovina
- Barbados
- Brazil
- Belize
- Canada
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Croatia
- Indonesia
- Israel
- India
- Iceland
and 31 moreShow fewer
- Japan
- Democratic People’s Republic of Korea
- Republic of Korea
- Saint Lucia
- Sri Lanka
- Liberia
- Lithuania
- Latvia
- Morocco
- Madagascar
- North Macedonia
- Mongolia
- Mexico
- Nicaragua
- Norway
- New Zealand
- Oman
- Papua New Guinea
- Philippines
- Seychelles
- Singapore
- Syrian Arab Republic
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- Yugoslavia, later Serbia and Montenegro (until 2006)
- South Africa