Nova Patents
WO2006048043A1

Secure authenticated channel

Abstract

A protocol (i.e. method) and corresponding apparatuses for calculating a session key. Two peers with knowledge of a common Diffie-Hellman permanent key, K<SUB>perrn</SUB>, and the identity and public key of the other peer. A first peer chooses a first ephemeral private key x and calculates the first corresponding ephemeral public key g<SUP>x</SUP>, which is sent to the second peer. The second peer calculates a second ephemeral public key g<SUP>y</SUP> in the same manner, and an ephemeral shared key K<SUB>eph</SUB>, hashes g<SUP>y</SUP>, K<SUB>eph</SUB>, K<SUB>perm</SUB>, and its identity, and sends g<SUP>y</SUP> and the hash to the first peer. The first peer calculates K<SUB>eph</SUB>, verifies the hash, and hashes g<SUP>x</SUP>, K<SUB>eph</SUB>, K<SUB>pem</SUB>, and its identity, and sends it to the second peer that verifies this hash. Thereafter, both peers obtain a session key by hashing K<SUB>eph</SUB>. The apparatuses may then use the session key to establish a secure authenticated channel (SAC).

WO2006048043A1, drawing sheet 1
Sheet 1 of 2

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

2 claims: 2 independent, 0 dependent

  1. 1
    CLAIMS 1. A method of calculating a session key shared by a first and a second device (11 , 21), the first device having a certificate (Ca) comprising a public key (ga) and an identity corresponding to itself (ID3), and knowledge of the identity corresponding to itself (IDa), a private key (a), and the public key (ga), the second device having a certificate (Cb) comprising a public key (gb) and an identity corresponding to itself (IDb), and knowledge of the identity corresponding to itself (IDb), a private key (b), and the public key (gb), the method comprising the steps of:at the first device: - choosing a first ephemeral private key (x);- calculating a first ephemeral public key (gκ);- sending its certificate (Ca) and the first ephiemeral public key (gx) to the second device;at the second device: - receiving the certificate of the first device (Ca) and the first ephemeral public key (gx);- verifying the certificate of the first device(Ca);- choosing a second ephemeral private key (y);- calculating a second ephemeral public key (gy);- calculating an ephemeral shared key (KePh) from the first ephemeral public key (gx) and the second ephemeral private key (y);- calculating a permanent key (KpΘrm) from the public key of the first device (ga) and its own private key (b);- calculating a first value (H(gy, KΘPh, Kperm, IDb)) from the second ephemeral public key (gy), the ephemeral shared key (Kθph), the permanent key (KpΘrm), and the identity corresponding to itself (IDb);- sending its certificate (Cb), the second ephemeral public key (gy) and the first value (H(gy Keph, Kperm, IDb)) to the first device;at the first device: - receiving the certificate of the second device (Cb), the second ephemeral public key (gy) and the first value (H(gy, Keph, Kpθrm, IDb)) from the second device;- verifying the certificate of the second device(Cb);- calculating the ephemeral shared key (Kθph) from the second ephemeral public key (gy) and the first ephemeral private key (x);- calculating the permanent key (Kpθrm) from the public key of the first device (gb) and its own private key (a);- verifying the first value (H(gy, Keph, KpΘrtn, IDb));- calculating a second value (H(gx, Keph, Kperm, IDa)) from the first ephemeral public key (gx), the ephemeral shared key (KθPh), the permanent key (Kperm), and the identity corresponding to itself (IDa);- sending the second value (H(gx, Keph, Kpθrm, IDa)) to the second device;at the second device: - receiving the second value (H(gx, Keph, Kperm, ID3));- verifying the second value (H(gx, Keph, Kperm, ID3));and - calculating a session key (KseSs) as a function of the ephemeral shared at the first device: - calculating the session key (KseSs) as a function of the ephemeral shared key (Keph).
  2. 2
    A first device (11) for participating, with a second device (21), in the calculation of a shared session key, the first device having a certificate (Ca) comprising a public key (ga) and an identity corresponding to itself (IDa), and knowledge of the identity corresponding to itself (IDa), a private key (a), and the public key (ga), the first device comprising a processor (12) for:- choosing an ephemeral private key (x);- calculating a first ephemeral public key (gx);- sending its certificate (Ca) and the first ephemeral public key (gx) to the second device;- receiving a certificate of the second device (Cb), a second ephemeral public key (gy) and a first value (H(gy, Kθph, Kpem, IDb)) from the second device, the certificate (Cb) comprising a public key (gb) and an identity of the second device (IDb), and the first value (H(gy, Kθph, Kperm, IDb)) being calculated from the second ephemeral public key (gy), an ephemeral shared key (Kθph), a permanent key (Kperm), and the identity corresponding to the second device (IDb);- verifying the certificate of the second device(Cb);- calculating the ephemeral shared key (KθPh) from the second ephemeral public key (gy) and the ephemeral private key (x);- calculating the permanent key (Kpθrm) from the public key of the first device (gb) and its own private key (a);- verifying the first value (H(gy, Keph, Kperm, IDb));- calculating a second value (H(gx, KθPh, Kperm, ID3)) from the first ephemeral public key (gx), the ephemeral shared key (KΘph), the permanent key (Kpθrm), and the identity corresponding to itself (ID3);- sending the second value (H(gx, Keph, Kpemi, ID3)) to the second device;and - calculating a session key (KseSs) as a function of the ephemeral shared 3. A second device (21) for participating, with a first device (11), in the calculation of a shared session key, the second device having a certificate (Cb) comprising a public key (gb) and an identity corresponding to itself (IDb), and knowledge of the identity corresponding to itself (IDb), a private key (b), and the public key (gb), the second device comprising a processor (22) for: - receiving a certificate of the first device (C3) and a first ephemeral public key (gx), the certificate comprising a public key (ga) and an identity of the first device (IDa);- verifying the certificate of the first device (Ca);- choosing an ephemeral private key (y);- calculating a second ephemeral public key (gy);- calculating an ephemeral shared key (KePh) from the first ephemeral public key (gx) and the ephemeral private key (y);- calculating a permanent key (Kperm) from the public key of the first device (ga) and its own private key (b);- calculating a first value (H(gy, Keph, Kperm, IDb)) from the second ephemeral public key (gy), the ephemeral shared key (Keph), the permanent key (Kpθrm), and the identity corresponding to itself (IDb);- sending its certificate (Cb)1 the second ephemeral public key (gy) and the first value (H(gy, Keph, Kpθrm, IDb)) to the first device;- receiving a second value (H(gx, Keph, Kpθrm, ID3)) from the first device, the second value being calculated from the first ephemeral public key (gx), the ephemeral shared key (Keph), the permanent key (Kperm), and the identity corresponding to the first device (ID3);- verifying the second value (H(gx, Keph, Kperm, ID8));and - calculating the session key (KseSs) as a function of the ephemeral shared key (KΘPh).