EP0820670A1 - Procede pour l'echange cryptographique de cles assiste par ordinateur entre un ordinateur utilisateur (u) et un ordinateur reseau (n) - Google Patents

Procede pour l'echange cryptographique de cles assiste par ordinateur entre un ordinateur utilisateur (u) et un ordinateur reseau (n)

Info

Publication number
EP0820670A1
EP0820670A1 EP96908004A EP96908004A EP0820670A1 EP 0820670 A1 EP0820670 A1 EP 0820670A1 EP 96908004 A EP96908004 A EP 96908004A EP 96908004 A EP96908004 A EP 96908004A EP 0820670 A1 EP0820670 A1 EP 0820670A1
Authority
EP
European Patent Office
Prior art keywords
computer unit
network
user
key
user computer
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP96908004A
Other languages
German (de)
English (en)
Inventor
Günther Horn
Klaus Müller
Volker Kessler
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Infineon Technologies AG
Original Assignee
Siemens AG
Siemens Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Siemens AG, Siemens Corp filed Critical Siemens AG
Publication of EP0820670A1 publication Critical patent/EP0820670A1/fr
Withdrawn legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • H04L9/0841Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless

Definitions

  • a public network key that is available in the user computer unit is exponentiated with the second random number r and thus forms a first intermediate key
  • a network constant constn is then encrypted in the network computer unit N with the checked session key K using the function f and forms a second response B.
  • a third message M3 is formed in the network computer unit N and contains at least the second response B.
  • the third message M3 is encoded in the network computer unit N and transmitted to the user computer unit U.
  • the certification message has at least one identity information of a certification computer unit, from which the network computer unit N can receive a network certificate CertN, which can be verified by the user computer unit U.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer And Data Communications (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

L'invention concerne un procédé pour l'échange de clés cryptographiques, dans lequel la longueur des informations transmises est considérablement réduite et les caractéristiques de sécurité sont considérablement améliorées par rapport aux procédés connus. Une première clé intermédiaire et une deuxième clé intermédiaire sont formées, en fonction de nombres aléatoires générés, dans un ordinateur réseau et dans un ordinateur utilisateur. Une clé de session est calculée par combinaison OU exclusif en mode bit de la première clé intermédiaire et de la deuxième clé intermédiaire. Les clés ne sont jamais transférées en texte en clair. Par utilisation d'une fonction qui peut être, par exemple, une fonction d'encodage symétrique, une fonction parasite ou une fonction unidirectionnelle, l'ordinateur réseau et l'ordinateur utilisateur s'authentifient mutuellement.
EP96908004A 1995-04-13 1996-04-03 Procede pour l'echange cryptographique de cles assiste par ordinateur entre un ordinateur utilisateur (u) et un ordinateur reseau (n) Withdrawn EP0820670A1 (fr)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
DE19514084 1995-04-13
DE19514084A DE19514084C1 (de) 1995-04-13 1995-04-13 Verfahren zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer Benutzercomputereinheit U und einer Netzcomputereinheit N
PCT/DE1996/000591 WO1996032791A1 (fr) 1995-04-13 1996-04-03 Procede pour l'echange cryptographique de cles assiste par ordinateur entre un ordinateur utilisateur (u) et un ordinateur reseau (n)

Publications (1)

Publication Number Publication Date
EP0820670A1 true EP0820670A1 (fr) 1998-01-28

Family

ID=7759676

Family Applications (1)

Application Number Title Priority Date Filing Date
EP96908004A Withdrawn EP0820670A1 (fr) 1995-04-13 1996-04-03 Procede pour l'echange cryptographique de cles assiste par ordinateur entre un ordinateur utilisateur (u) et un ordinateur reseau (n)

Country Status (8)

Country Link
US (1) US6064741A (fr)
EP (1) EP0820670A1 (fr)
JP (1) JPH10510692A (fr)
KR (1) KR19980703838A (fr)
CN (1) CN1186580A (fr)
DE (1) DE19514084C1 (fr)
RU (1) RU2175465C2 (fr)
WO (1) WO1996032791A1 (fr)

Families Citing this family (54)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10361802B1 (en) 1999-02-01 2019-07-23 Blanding Hovenweep, Llc Adaptive pattern recognition based control system and method
UA53651C2 (uk) * 1996-06-05 2003-02-17 Сіменс Акцієнгезельшафт Спосіб криптографічного обміну кодами між першим комп'ютерним пристроєм та другим комп'ютерним пристроєм
AUPO323496A0 (en) 1996-10-25 1996-11-21 Monash University Digital message encryption and authentication
US6151395A (en) 1997-12-04 2000-11-21 Cisco Technology, Inc. System and method for regenerating secret keys in diffie-hellman communication sessions
DE19822795C2 (de) * 1998-05-20 2000-04-06 Siemens Ag Verfahren und Anordnung zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer ersten Computereinheit und einer zweiten Computereinheit
US6038322A (en) 1998-10-20 2000-03-14 Cisco Technology, Inc. Group key distribution
JP2000305453A (ja) 1999-04-21 2000-11-02 Nec Corp 暗号化装置,復号装置,および暗号化・復号装置
US6879994B1 (en) * 1999-06-22 2005-04-12 Comverse, Ltd System and method for processing and presenting internet usage information to facilitate user communications
DE19938197A1 (de) * 1999-08-12 2001-03-08 Deutsche Telekom Ag Verfahren zur Schlüsselvereinbarung für eine Gruppe von mindestens drei Teilnehmern
CN100393030C (zh) * 1999-11-30 2008-06-04 三洋电机株式会社 记录装置
US6640303B1 (en) * 2000-04-28 2003-10-28 Ky Quy Vu System and method for encryption using transparent keys
AU7182701A (en) 2000-07-06 2002-01-21 David Paul Felsher Information record infrastructure, system and method
US20020078352A1 (en) * 2000-12-15 2002-06-20 International Business Machines Corporation Secure communication by modification of security codes
US7181017B1 (en) 2001-03-23 2007-02-20 David Felsher System and method for secure three-party communications
WO2004023709A1 (fr) * 2002-09-04 2004-03-18 Medialingua Group Procede de composition de certificats numeriques, delivrance et gestion fournissant un modele de distribution de certificats numeriques multiniveaux et nombreux comptes d'acces fondes sur l'utilisation du certificat numerique et de l'infrastructure de cle publique
US20040019786A1 (en) * 2001-12-14 2004-01-29 Zorn Glen W. Lightweight extensible authentication protocol password preprocessing
US20030149874A1 (en) * 2002-02-06 2003-08-07 Xerox Corporation Systems and methods for authenticating communications in a network medium
US7937089B2 (en) * 2002-02-06 2011-05-03 Palo Alto Research Center Incorporated Method, apparatus, and program product for provisioning secure wireless sensors
RU2219670C1 (ru) * 2002-04-08 2003-12-20 Государственный научно-исследовательский испытательный институт проблем технической защиты информации Государственной технической комиссии при Президенте Российской Федерации Способ создания ключа для группы компьютеров вычислительной сети
US7142674B2 (en) * 2002-06-18 2006-11-28 Intel Corporation Method of confirming a secure key exchange
US7581096B2 (en) * 2002-08-30 2009-08-25 Xerox Corporation Method, apparatus, and program product for automatically provisioning secure network elements
US7185199B2 (en) * 2002-08-30 2007-02-27 Xerox Corporation Apparatus and methods for providing secured communication
US7275156B2 (en) * 2002-08-30 2007-09-25 Xerox Corporation Method and apparatus for establishing and using a secure credential infrastructure
US7904720B2 (en) * 2002-11-06 2011-03-08 Palo Alto Research Center Incorporated System and method for providing secure resource management
US7549047B2 (en) * 2002-11-21 2009-06-16 Xerox Corporation Method and system for securely sharing files
US9818136B1 (en) 2003-02-05 2017-11-14 Steven M. Hoffberg System and method for determining contingent relevance
US8023958B2 (en) * 2003-03-05 2011-09-20 Qualcomm Incorporated User plane-based location services (LCS) system, method and apparatus
US7426271B2 (en) * 2003-04-25 2008-09-16 Palo Alto Research Center Incorporated System and method for establishing secondary channels
US7454619B2 (en) * 2003-06-24 2008-11-18 Palo Alto Research Center Incorporated Method, apparatus, and program product for securely presenting situation information
KR100807926B1 (ko) * 2003-10-14 2008-02-28 텔레폰악티에볼라겟엘엠에릭슨(펍) 암호 키 생성의 효율적인 관리
US20050100166A1 (en) * 2003-11-10 2005-05-12 Parc Inc. Systems and methods for authenticating communications in a network medium
US8345882B2 (en) * 2003-11-11 2013-01-01 Siemens Aktiengesellschaft Method for safeguarding data traffic between a first terminal and a first network and a second terminal and a second network
US7757076B2 (en) * 2003-12-08 2010-07-13 Palo Alto Research Center Incorporated Method and apparatus for using a secure credential infrastructure to access vehicle components
US20050129240A1 (en) * 2003-12-15 2005-06-16 Palo Alto Research Center Incorporated Method and apparatus for establishing a secure ad hoc command structure
EP1626598A1 (fr) * 2004-06-21 2006-02-15 Axalto SA Procédé de sécurisation d'un protocole d'authentification et distribution de clés
US7552322B2 (en) * 2004-06-24 2009-06-23 Palo Alto Research Center Incorporated Using a portable security token to facilitate public key certification for devices in a network
US7450723B2 (en) * 2004-11-12 2008-11-11 International Business Machines Corporation Method and system for providing for security in communication
MY142227A (en) * 2005-02-04 2010-11-15 Qualcomm Inc Secure bootstrapping for wireless communications
RU2286022C1 (ru) * 2005-03-09 2006-10-20 Николай Андреевич Молдовян Способ формирования ключа шифрования
KR100636232B1 (ko) 2005-04-29 2006-10-18 삼성전자주식회사 해시 체인을 이용하여 디바이스들간의 인접성을 검사하는방법 및 장치
US7814313B2 (en) * 2005-06-29 2010-10-12 Nokia Corporation System, terminal, network entity, method and computer program product for authorizing communication message
US8874477B2 (en) 2005-10-04 2014-10-28 Steven Mark Hoffberg Multifactorial optimization system and method
CN1881869B (zh) * 2005-11-01 2010-05-05 华为技术有限公司 一种实现加密通信的方法
RU2408991C2 (ru) * 2006-01-13 2011-01-10 Квэлкомм Инкорпорейтед Защита конфиденциальности в системах связи
US8788807B2 (en) 2006-01-13 2014-07-22 Qualcomm Incorporated Privacy protection in communication systems
EP3761598B1 (fr) * 2006-10-20 2023-12-20 Nokia Technologies Oy Génération de clés de protection dans des réseaux mobiles de prochaine génération
WO2009000111A1 (fr) * 2007-06-27 2008-12-31 Gemalto Sa Procédé servant à authentifier deux entités, dispositif électronique correspondant et système
US8379854B2 (en) * 2007-10-09 2013-02-19 Alcatel Lucent Secure wireless communication
RU2412548C1 (ru) * 2009-08-26 2011-02-20 Николай Андреевич Молдовян Способ формирования общего секретного ключа двух удаленных абонентов телекоммуникационной системы
RU2420892C1 (ru) * 2009-10-28 2011-06-10 Дмитрий Николаевич Молдовян Способ формирования общего секретного ключа двух удаленных абонентов
CN103873227A (zh) * 2012-12-13 2014-06-18 艺伦半导体技术股份有限公司 一种fpga加密数据流的解密电路及解密方法
CN103036675A (zh) * 2012-12-14 2013-04-10 中国地质大学(武汉) 基于动态密钥的数据通信方法、发送端和接收端
US10469245B2 (en) 2014-12-24 2019-11-05 Koninklijke Philips N.V. Cryptographic system and method
US12537668B2 (en) 2022-05-17 2026-01-27 Samsung Electronics Co., Ltd Authentication mechanism for computational storage download program

Family Cites Families (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5005200A (en) * 1988-02-12 1991-04-02 Fischer Addison M Public key/signature cryptosystem with enhanced digital signature certification
US4956863A (en) * 1989-04-17 1990-09-11 Trw Inc. Cryptographic method and apparatus for public key exchange with authentication
JP2671649B2 (ja) * 1991-07-08 1997-10-29 三菱電機株式会社 認証方式
US5153919A (en) * 1991-09-13 1992-10-06 At&T Bell Laboratories Service provision authentication protocol
US5222140A (en) * 1991-11-08 1993-06-22 Bell Communications Research, Inc. Cryptographic method for key agreement and user authentication
RU2007884C1 (ru) * 1991-11-22 1994-02-15 Борис Владимирович Березин Устройство шифрования двоичной информации "албер"
RU2060593C1 (ru) * 1992-02-13 1996-05-20 Михаил Калистович Жемчугов Способ кодирования цифровой информации и устройство для его осуществления
JP3052244B2 (ja) * 1993-11-10 2000-06-12 富士通株式会社 移動通信システムにおける移動機の登録方法とicカードの登録方法、及びそれらを実現するための移動機、icカード、及びicカード挿入型移動機
PL176458B1 (pl) * 1994-01-13 1999-05-31 Certc0 Llc Sposób szyfrowania systemu komunikacyjnego
FR2717286B1 (fr) * 1994-03-09 1996-04-05 Bull Cp8 Procédé et dispositif pour authentifier un support de données destiné à permettre une transaction ou l'accès à un service ou à un lieu, et support correspondant.
NL9400428A (nl) * 1994-03-18 1995-11-01 Nederland Ptt Inrichting voor het cryptografisch bewerken van datapakketten, alsmede werkwijze voor het genereren van cryptografische bewerkingsdata.

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO9632791A1 *

Also Published As

Publication number Publication date
JPH10510692A (ja) 1998-10-13
RU2175465C2 (ru) 2001-10-27
US6064741A (en) 2000-05-16
CN1186580A (zh) 1998-07-01
DE19514084C1 (de) 1996-07-11
KR19980703838A (ko) 1998-12-05
WO1996032791A1 (fr) 1996-10-17

Similar Documents

Publication Publication Date Title
DE19514084C1 (de) Verfahren zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer Benutzercomputereinheit U und einer Netzcomputereinheit N
EP0872076B1 (fr) Procede d'echange assiste par ordinateur de codes cryptographiques entre un premier et un second ordinateur
EP1080557B1 (fr) Procede et dispositif d'echange assiste par ordinateur de cles cryptographiques entre une premiere unite d'ordinateur et une seconde unite d'ordinateur
DE69416809T2 (de) Verbesserungen der Sicherheit in Datenverarbeitungssystemen
EP0472714B1 (fr) Procede d'authentification d'un utilisateur utilisant une station de donnees
EP0903026B1 (fr) Procédé de négociation d'une politique de sécurité entre une première et une seconde unité informatique
DE60302276T2 (de) Verfahren zur ferngesteuerten Änderung eines Kommunikationspasswortes
DE60028645T2 (de) Vorrichtung und Verfahren zur Verteilung von Dokumenten
DE69633590T2 (de) Verfahren zur Unterschrift und zur Sitzungsschlüsselerzeugung
DE102010002241B4 (de) Vorrichtung und Verfahren zur effizienten einseitigen Authentifizierung
EP1125395B1 (fr) Procede et systeme pour authentifier une premiere instance et une seconde instance
DE102005024725A1 (de) System und Verfahren für Chaotische Digitale Signatur, Verschlüsselung und Authentifizierung
DE69431426T2 (de) System und Verfahren zur Nachrichtenauthentisierung in einem nicht-schmiedbaren Kryptosystem mit öffentlichen Schlüssel
CH660822A5 (de) Zufallsprimzahlen-erzeugungsmittel in einer mit oeffentlichem schluessel arbeitenden daten-verschluesselungsanlage.
DE69838258T2 (de) Public-Key-Datenübertragungssysteme
EP0903027B1 (fr) Procede de gestion de cles cryptographiques, fonde sur un groupe, entre une premiere unite informatique et des unites informatiques d'un groupe
DE112012000971B4 (de) Datenverschlüsselung
DE602004010494T2 (de) Kryptographische Authentifizierung einer Vorrichtung
DE19518546C1 (de) Verfahren zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer Benutzercomputereinheit U und einer Netzcomputereinheit N
DE19518544C1 (de) Verfahren zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer Benutzercomputereinheit und einer Netzcomputereinheit
DE19518545C1 (de) Verfahren zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer Benutzercomputereinheit und einer Netzcomputereinheit
DE60211008T2 (de) Authentifizierung eines entfernten benutzers zu einem host in einem datenkommunikationssystem
DE19548387C1 (de) Verfahren zur kryptographischen Sicherung der rechnergestützten digitalen Kommunikation zwischen einem Programm und mindestens einer Benutzereinheit
EP1286494B1 (fr) Méthode de génération d'une paire de clés cryptographiques asymétriques de groupe
DE10159690C2 (de) Verfahren zur Vereinbarung eines symmetrischen Schlüssels über einen unsicheren Kanal und zur digitalen Signatur

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 19971006

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AT CH DE ES FR GB IT LI

RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: INFINEON TECHNOLOGIES AG

GRAG Despatch of communication of intention to grant

Free format text: ORIGINAL CODE: EPIDOS AGRA

17Q First examination report despatched

Effective date: 20010724

GRAG Despatch of communication of intention to grant

Free format text: ORIGINAL CODE: EPIDOS AGRA

GRAH Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOS IGRA

GRAH Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOS IGRA

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20021031