Nova Patents
WO9847260A3

Publicly verifiable key recovery

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

1 claim: 1 independent, 0 dependent

  1. 1
    What Is Claimed Is:1. A method for publicly verifying that a message encrypted with a key can be recovered by a recovery agent, the key being determined according to a Diffie- Hellman key exchange, the method comprising the steps of: providing, by a first party to the message, recovery information determined from a public key associated with the recovery agent, a public key associated with a second party to the message, and a private key associated with said first party, wherein the recovery agent is able to determine the key from said recovery information;and providing, by said first party, verification information that verifies that the key is determinable from said recovery information without revealing private information. 2. The method of claim 1, further comprising the steps of: determining, by said first party, the key based on said second party's public key and said first party's private key;and determining, by said second party, the key based on said first party's public key and said second party's private key. 3. The method of claim 1, further comprising the steps of: determining, by said first party, the key according to the following relationship: S j = y 2 Xl mod p wherein: j is the key determined by said first party, y 2 is said second party's public key, Xj is said first party's private key, and p is a large public prime number;and and;determining, by said second party, the key according to the following relationship: s 2 = y 1 Xl mod p wherein: s 2 is the key determined by said first party, yj is said second party's public key, x 2 is said first party's private key, and p is said large public prime number. 4. The method of claim 1, wherein said step of providing recovery information further comprises the step of: determining said recovery information according to the following relationship: *= OV ) ' mod P wherein: t is said recovery information, y 2 is said second party's public key, y r is the recovery agent's public key, X, is the first party's private key, and p is said large public prime number. 5. The method of claim 1, wherein said step of providing verification information comprises the step of: providing said verification information to said second party. 6. The method of claim 1, wherein said step of providing verification information comprises the step of: providing said verification information to the recovery agent. 7. The method of claim 1, wherein said step of providing verification information comprises the step of: providing said verification information to a verifier. 8. The method of claim 1, wherein said step of providing verification information comprises the step of: providing said verification information in a data verification field associated with the message. 9. The method of claim 1, further comprising the step of: verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information. 10. The method of claim 9, wherein said step of verifying comprises the step of: verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information, said step of verifying performed by said second party. 11. The method of claim 9, wherein said step of verifying comprises the step of: verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information, said step of verifying performed by the recovery agent. 12. The method of claim 9, wherein said step of verifying comprises the step of: verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information, said step of verifying performed by a verifier. 13. The method of claim 9, wherein said step of verifying comprises the steps of: accessing a data verification field associated with the message to obtain said verification information;and verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information. 14. The method of claim 9, wherein said step of verifying comprises the steps of: accessing a data recovery field associated with the message to obtain said recovery information and said verification information;and verifying, using said recovery information and said verification information, that the key can be recovered by the recovery agent from the recovery information. 15. The method of claim 1, wherein said step of providing verification information comprises the step of: interactively providing verification information that verifies that the key is determinable from said recovery information without revealing private information. 16. The method of claim 15, wherein said step of interactively providing verification information comprises the step of: performing a challenge-response digital signature protocol. 17. The method of claim 15, wherein said step of interactively providing verification information comprises the steps of: performing a first challenge-response digital signature protocol;and performing a second challenge-response digital signature protocol. 18. The method of claim 15, wherein said step of interactively providing verification information comprises the steps of: performing a first challenge-response El Gamal digital signature protocol;and performing a second challenge-response El Gamal digital signature protocol. 19. The method of claim 18, wherein said step of performing a first challenge- response comprises the steps of: receiving a challenge;determining a response based on said challenge and said recovery information;and sending said response as at least a portion of said verification information. 20. The method of claim 19, wherein said step of receiving a challenge comprises the step of: receiving a random integer from a challenger. 21. The method of claim 19, wherein said step of determining a response comprises the step of: determining said response based on said recovery information, said second party's public key, the recovery agent's public key, and said challenge. 22. The method of claim 19, wherein said step of determining a response comprises the step of: determining said response according to the following relationship: b j = (A 1 ) "1 (c 1 - ,JC j ) mod /7 - 1 wherein: (a„ bj is said response, Cj is said challenge, kj is a randomly generated integer, y 2 is said second party's public key, y r is the recovery agent's public key, x, is the first party's private key, and p is a large public prime number. 23. The method of claim 18, wherein said step of performing a second challenge-response comprises the steps of: receiving a challenge;determining a response based on said challenge and said recovery information;and sending said response as at least a portion of said verification information. 24. The method of claim 23, wherein said step of receiving a challenge comprises the step of: receiving a random integer from a challenger. 25. The method of claim 23, wherein said step of determining a response comprises the step of: determining said response based on said recovery information, said second party's public key, the recovery agent's public key, and said challenge. 26. The method of claim 23, wherein said step of determining a response comprises the step of: determining said response according to the following relationship: a = ( — — ) 2 mod p y r g b 2 = ( A 2 ) " H^ - β jX,) mod /7 - 1 wherein: (a 2 > bj is sa 'd response, c 2 is said challenge, k 2 is a randomly generated integer, 2 is said second party's public key, y r is the recovery agent's public key, Xj is the first party's private key, and p is a large public prime number. 27. The method of claim 15, wherein said step of interactively providing verification information comprises the steps of: performing a first challenge-response El Gamal digital signature protocol, said first challenge-response including the steps of: receiving a first challenge;determining a first response according to the following relationship: b χ = (k 1 ) '1 (c 1 - fl j JC j ) mod /7 - 1 wherein: (a Jf bj) is said first response, Cj is said first challenge, kj is a first randomly generated integer, y 2 is said second party's public key, y r is the recovery agent's public key, Xj is the first party's private key, and p is a large public prime number, and sending said first response;and performing a second challenge-response El Gamal digital signature protocol, said second challenge-response including the steps of: receiving a second challenge, determining a second response according to the following relationship: a. = ( — — ) 2 mod p y r g = (*2) _1 ( c 2 _ β 2*ι) mod / 7 - 1 wherein: (a 2 , bj is said second response, c 2 is said second challenge, k 2 is a second randomly generated integer, y 2 is said second party's public key, y τ is the recovery agent's public key, Xj is the first party's private key, and p is a large public prime number, and sending said second response, wherein said first response and said second response comprise at least a portion of said verification information. 28. The method of claim 27, further comprising the step of: verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information. 29. The method of claim 28, wherein said step of verifying comprises the steps of: determining a verification result according to the following verification relationship: V = v, I v 2 wherein: ι = ' β, β ι ' " (y 2 / y r i mod / 7 v 2 = (^i)" 2fl 2 2 - (y 2 / y r g Cϊ mod / 7 V is said verification result, (a lf bj) is said first response, (a 2 , bj is said second response, Cj is said first challenge, c 2 is said second challenge, t is said recovery information, y s is said first party's public key, y 2 is said second party's public key, y r is the recovery agent's public key, p is a large public prime number;and verifying that said recovery information enables the key to be recovered if said verification result is zero. 30. The method of claim 1, wherein said step of providing verification information comprises the step of: non-interactively providing verification information that verifies that the key is determinable from said recovery information without revealing private information. 31. The method of claim 30, wherein said step of non-interactively providing verification information comprises the step of: performing a non-interactive challenge-response digital signature protocol. 32. The method of claim 30, wherein said step of non-interactively providing verification information comprises the steps of: performing a first non-interactive challenge-response digital signature protocol;and performing a second non-interactive challenge-response digital signature protocol. 33. The method of claim 30, wherein said step of non-interactively providing verification information comprises the steps of: performing a first non-interactive challenge-response El Gamal digital signature protocol;and performing a second non-interactive challenge-response El Gamal digital signature protocol. 34. The method of claim 33, wherein said step of performing a first non- interactive challenge-response comprises the steps of: determining a challenge;generating a hash of said challenge;determining a response based on said challenge and said recovery information;and providing said challenge, said hash, and said response as at least a portion of said verification information. 35. The method of claim 34, wherein said step of determining a challenge comprises the step of: generating a random integer. 36. The method of claim 34, wherein said step of determining a response comprises the step of: determining said response based on said recovery information, said second party's public key, the recovery agent's public key, and said challenge. 37. The method of claim 34, wherein said step of determining a response comprises the step of: determining said response according to the following relationship: f l ι = ( )* 1 od p b j = (k i ) ~1 (c 1 - a t x χ ) mod /7 - 1 wherein: (a„ bj is said response, Cj is said hash of said challenge, kj is a randomly generated integer, y 2 is said second party's public key, y r is the recovery agent's public key, Xj is the first party's private key, and p is a large public prime number. 38. The method of claim 33, wherein said step of performing a second non- interactive challenge-response comprises the steps of: determining a challenge;generating a hash of said challenge;determining a response based on said challenge and said recovery information;and providing said challenge, said hash, and response as at least a portion of said verification information. 39. The method of claim 38, wherein said step of determining a challenge comprises the step of: generating a random integer. 40. The method of claim 38, wherein said step of determining a response comprises the step of: determining said response based on said recovery information, said second party's public key, the recovery agent's public key, and said challenge. 41. The method of claim 38, wherein said step of determining a response comprises the step of: determining said response according to the following relationship: 2 = ( — — ) 2 mod p y r g b 2 - (k 2 ) ~1 (c 2 - fl j -X j ) mod /7 - 1 wherein: (a 2 , bj is said response, c 2 is said hash of said challenge, k 2 is a randomly generated integer, y 2 is said second party's public key, y r is the recovery agent's public key, Xj is the first party's private key, and p is a large public prime number. 42. The method of claim 30, wherein said step of non-interactively providing verification information comprises the steps of: performing a first non-interactive challenge-response El Gamal digital signature protocol, said first challenge-response including the steps of: determining a first challenge, generating a first hash of said first challenge, determining a first response according to the following relationship: aι = OVJV)* 1 mod P b j = (k ι y 1 (c 1 - Λ J ΛT J ) mod /7 - 1 wherein: (a lf bj is said first response, Cj is said first hash of said first challenge, kj is a first randomly generated integer, y 2 is said second party's public key, y r is the recovery agent's public key, X is the first party's private key, and p is a large public prime number, and providing said first challenge, said first hash, and said first response as a first portion of said verification information;and performing a second non-interactive challenge-response El Gamal digital signature protocol, said second challenge-response including the steps of: determining a second challenge, generating a second hash of said second challenge, determining a second response according to the following relationship: , = ( — — ) 2 mod p y r g b 2 = (k 2 ) ~1 (c 2 - fl j -K j ) mod /7 - 1 wherein: (a 2 , bj is said second response, c 2 is said second hash of said second challenge, k 2 is a second randomly generated integer, y 2 is said second party's public key, y r is the recovery agent's public key, x, is the first party's private key, and p is a large public prime number, and providing said challenge, said hash, and said second response as a second portion of said verification information. 43. The method of claim 42, further comprising the step of: verifying, using said verification information, that the key can be recovered by the recovery agent from the recovery information. 44. The method of claim 43, wherein said step of verifying comprises the steps of: verifying that said first hash was generated from said first challenge;verifying that said second hash was generated from said second challenge;determining a verification result according to the following verification relationship: V = Vj \ v 2 wherein: v, = r^ , 1 - (y 2 /y r ) Cl mod p v2 = (' / ι) β2fl 2 2 - (y 2 / y r g) C2 mod P V is said verification result, (α 7 , bj) is said first response, (a 2 , b is said second response, Cj is said first hash of said first challenge, c 2 is said second hash of said second challenge, t is said recovery information, y } is said first party's public key, y 2 is said second party's public key, y r is the recovery agent's public key, p is a large public prime number;and verifying that said recovery information enables the key to be recoverederification result is zero.