WO2010069063A1

Acceleration of key agreement protocols

Abstract

The generation of a shared secret key K in the implementation of a key agreement protocol, for example MQV, may be optimized for accelerated computation by selecting the ephemeral public key and the long-term public key of a correspondent to be identical. One correspondent determines whether the pair of public keys of the other correspondent are identical. If it is, a simplified representation of the shared key K is used which reduces the number of scalar multiplication operations for an additive group or exponentiation operations for a multiplicative group. Further optimisation may be obtained by performing simultaneous scalar multiplication or simultaneous exponentiation in the computation of K.

WO2010069063A1, drawing sheet 1
Sheet 1 of 19

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

18 claims: 3 independent, 15 dependent

  1. 1
    CLAIMS:That which is claimed is: 1. The method of generating a shared key at one of a pair of correspondents participating in a public key cryptosystem, said shared key to be used by said one correspondent in communicating with another correspondent over a data communication channel, each of said correspondents respectively having a long-term private key and a corresponding long-term public key, and said shared key having the form of a combination of a long-term private key of one of said correspondents with a long-term public key and an ephemeral public key of another of said correspondents, said method comprising the steps of: a) said one correspondent obtaining said long-term public key of said other correspondent;b) said one correspondent determining whether said ephemeral public key of said other correspondent is the same as said long-term public key of said other correspondent;c) upon determining that said long-term public key and said ephemeral public key of said other correspondent are the same, said one correspondent utilising said long-term public key of said other correspondent as both said long-term public key and said ephemeral public key of said other correspondent in generating said shared key, and d) utilising said shared key to exchange information between said correspondents.
  2. 13
    A cryptographic system having a pair of correspondents communicating over a communication link and sharing a shared key, said shared key being generated by at least one of said correspondents according to the method of any one of claims 1 to 12.
  3. 14
    A cryptographic module associated with one correspondent in a cryptographic system, said module comprising:- a controller;an arithmetic logic unit operable to generate a shared key from a combination of ephemeral and long-term public keys of another correspondent and a private key of the one correspondent;and a comparator operable to determine whether said ephemeral public key and long-term public key of said other correspondent are the same;wherein said controller is operable to instruct said arithmetic unit to utilise said long-term public key as said ephemeral public key in the computation of said shared key if said comparator determines that said keys are the same.