EP1254534A1 - Procede de communication avec sequestre et recuperation de cle de chiffrement - Google Patents
Procede de communication avec sequestre et recuperation de cle de chiffrementInfo
- Publication number
- EP1254534A1 EP1254534A1 EP01904002A EP01904002A EP1254534A1 EP 1254534 A1 EP1254534 A1 EP 1254534A1 EP 01904002 A EP01904002 A EP 01904002A EP 01904002 A EP01904002 A EP 01904002A EP 1254534 A1 EP1254534 A1 EP 1254534A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- key
- entity
- session
- secret
- authority
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 57
- 238000004891 communication Methods 0.000 title claims abstract description 25
- 238000011084 recovery Methods 0.000 title claims description 22
- 230000009919 sequestration Effects 0.000 description 7
- 230000003068 static effect Effects 0.000 description 3
- 238000004364 calculation method Methods 0.000 description 2
- 230000006978 adaptation Effects 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 238000010835 comparative analysis Methods 0.000 description 1
- 238000003780 insertion Methods 0.000 description 1
- 230000037431 insertion Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
Definitions
- the subject of the present invention is a communication method in which sequestration and encryption key recovery operations are provided. These operations make it possible to guarantee to one or more ' previously determined organization (s) (for example a security administrator of a corporate network, a trusted third party, or even, in some cases, the users of an encryption system themselves), the possibility of recovering, if necessary, the session key used in the communication, and this from the data exchanged.
- the possibility of recovering a session key can arise from a need for legal interception or recovery of keys within a company.
- the invention finds an application in secure communications.
- This family of techniques applies to systems in which the establishment of a session key between the interlocutors uses a key exchange protocol based on the possession, by one of the interlocutors (for example b) of a static secret key (i.e. not renewed at each session).
- the secret key used by b in the key exchange protocol is archived with a receiver authority (or distributed among several receiver authorities).
- the possession of this secret allows the authority (or authorities) of receiver (s) to reconstitute, if necessary, any session key exchanged between a and b from the messages of the protocol for establishing this key.
- An example of this sequestration and key recovery method is provided in the article "A Proposée Architecture for Trusted Third Party Services", by N. Jeffe ⁇ es, C. Mitchell and M.
- this second family of techniques does not call for the prior archiving of static secret keys used for the exchange of session keys, but for the insertion, ⁇ ans the messages exchanged between a and b, during secure communication, one or more legal fields containing, in an intelligible form only for an escrow authority, information on the KS session key.
- the key KS (or information on this key) can for example be encrypted under the public key RSA of an escrow authority.
- the "Secure Key Recovery” (SKR) protocol proposed by IBM is part of this family of techniques.
- each country must be free to set up or not set up, for the communications which concern it, a key escrow / recovery system for this application; (ii) in each country where a system of sequestration / key recovery is implemented, the authorities empowered to recover, if necessary, the session keys used to encrypt an international communication must be able to do so without having to cooperate, for each interception, with the authorities of other countries.
- the known and previously described techniques do not meet or meet these conditions poorly:
- FIG. 1 first of all, we see two entities a, b each equipped with cryptology means not shown and each provided with an identity Id a , Idb. a public key and a secret encryption key, respectively P â , Pb. and S a , S b , as well as a certificate C a , C b ; we see, moreover, two escrow authorities T a and T b associated with the two entities a and b, these two authorities each archiving the secret keys S a , S D of the associated entities as well as their certificates C a or C b .
- the certificates attest to the correspondence between secret key and public key and that the secret key has indeed been archived.
- the certification authority is not shown in this figure.
- the certificate may conform to ITU-T recommendation X509.
- the method of communication between these different means comprises the following operations: A) the entity a, which is supposed to engage in a session for transmitting a message M:
- the parameters of the Diffîe-Hellman protocol consist of a large prime number p, called the module, and a generator number g.
- the two escrow authorities T a and T D have agreed on these numbers p and g.
- the secret key S a of a is a secret exponent ⁇ which is archived in T a and the public key ⁇ e a is
- Each authority T a or T b can therefore find the session key (KS) and therefore recover the message (M). But, here again, this scheme presupposes an agreement between the parties.
- the object of the present invention is to remedy these drawbacks by proposing a method which does not require any agreement between the communicating parties. the recovery of the session key and the message taking place from the only data exchanged in the communication.
- the subject of the invention is an encrypted communication method with escrow and recovery of encryption key, implementing:
- a comprising first cryptology means (MC a ) and provided with a first identity (Id a ), a first public key distribution key (P a ) and a first secret key key distribution (S a ) corresponding to said first public key (P a ),
- a second entity comprising second cryptology means (MC) and provided with a second identity (Id b ), a second public key distribution key (P D ) and a second secret key of key distribution (S b ) corresponding to said second public key (P b ),
- this method comprising: i) a preliminary phase of establishing a session key (KS) phase in which at least one of the entities (a, b) produces a session key (KS) and forms a cryptogram consisting of this key encrypted by the public key (P D , P a ) of the other entity, the other entity (b, a) decrypting said cryptogram using its secret key (S b , S a ) and covering the session key ( KS), ii) a message exchange phase (M) in which the entities (a, b) form E KS cryptograms (M) constituted by messages (M) encrypted by the session key (KS) established in the preliminary phase, each entity decrypting the cryptogram it receives using the session key
- the entity (a, b) which produces the session key (KS) implements a pseudo-random generator (PRG a ,? RG b ) known to the escrow authority (T a , T) associated and initializes this pseudo-random generator using its secret key (S a , S b ) and an initial value (VI) deduced, by an algorithm known to the escrow authority (T a , T b ), of appropriate data.
- PRG a ,? RG b pseudo-random generator
- PRG a ,? RG b pseudo-random generator
- the escrow authority (T a , T b ) associated with the entity (a, b) which produced, in the preliminary phase, the session key (KS), implements a pseudo-random generator identical to that of the associated entity (PRG a , PRG b ), initializes this generator with said initial value (VI) and the secret key (S a , S) of the associated entity (a, b ) that it has archived, and thus covers the session key (KS).
- the escrow authority can be an approved third party, or a security administrator of a corporate network, or the user himself (the escrow is then a "self-escrow") .
- FIG. 3 schematically illustrates a method according to the invention.
- the secret key S a of the public key key encryption system used by the entity a for the purpose of establishing session keys is archived with the escrow authority T a .
- Possession by a certificate from a CA proves archiving with T has the secret key S corresponding to the public key P was actually achieved.
- the certification authority AC and the third party receiver T a may be the same body, or two separate bodies having signed an agreement.
- the generation of the secret key S a can, depending on in the case, be carried out by the user a or by the third party T a .
- MC a means the software and hardware resources implementing the cryptographic calculations of establishing a session key and encryption of a during a secure communication.
- client software for secure messaging can be viewed as a means of cryptology.
- the key generation method used in MC-typically the key generation algorithm used to generate a session key KS when a initiates a secure session with an interlocutor b- must be a pseudo-random generator GPA known to T a , and whose seeds, that is to say the inputs from which the values produced by the generator are calculated, are made up :
- the size of the initial value VI can be limited between 20 and 40 bits of effective size, so that, when the secret key S a is known, the recovery of _.
- generator output remains possible by exhaustive search even when the exact value of VI is lost, ii) it must be difficult to predict information on S a (or on H (S a )) from a set of values of VI and corresponding output values GPA (S a , VI) or G? A (H (S a ), VI), iii) it must be difficult to predict information relating to the outputs GPA (S a , VI) or GPA (H (S a ), VI) for the different values of VI when the value of S a (or H (S a ) ) is unknown.
- T a There are two separate procedures for recovering the session key KS used to encrypt a secure communication between user a and correspondent b, by T a or an authority authorized to access the secret S a archived by T a : i) If the session key KS is produced by b and received by a encrypted using the public key P a from a, then T a can recover the key KS by decrypting using the archived secret S a the cryptogram P a (KS) transmitted in the key distribution protocol.
- KS GPA (S a , VI) or KS ⁇ GPA (H (S a ), VI ).
- T a By combining the elementary procedures i) and ii) defined above, T a remains able to recover the session key in the case where a more complex session key establishment protocol is used between a and b.
- a more complex session key establishment protocol is used between a and b.
- T a would be able to recover KSI using the procedure i) defined above and to find KS2 using the procedure ii), and therefore, from these two values, to recover KS.
- the method which has just been described can be implemented according to variants in which the information that constitutes the secret key S a is not archived with a single entity T a , but divided into "parts" archived with separate third parties.
- the secret key S a of a can be constituted by a secret RSA exponent d.
- Two escrow authorities T a and ⁇ ' a respectively responsible for archiving dl and d2 (and the public module n a of a), are capable of:
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer And Data Communications (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0001185A FR2804561B1 (fr) | 2000-01-31 | 2000-01-31 | Procede de communication avec sequestre et recuperation de cle de chiffrement |
| FR0001185 | 2000-01-31 | ||
| PCT/FR2001/000285 WO2001056222A1 (fr) | 2000-01-31 | 2001-01-30 | Procede de communication avec sequestre et recuperation de cle de chiffrement |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1254534A1 true EP1254534A1 (fr) | 2002-11-06 |
Family
ID=8846480
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP01904002A Withdrawn EP1254534A1 (fr) | 2000-01-31 | 2001-01-30 | Procede de communication avec sequestre et recuperation de cle de chiffrement |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20030012387A1 (fr) |
| EP (1) | EP1254534A1 (fr) |
| JP (1) | JP2003521197A (fr) |
| FR (1) | FR2804561B1 (fr) |
| WO (1) | WO2001056222A1 (fr) |
Families Citing this family (20)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR2829644A1 (fr) * | 2001-09-10 | 2003-03-14 | St Microelectronics Sa | Procede securise de transmission de donnees multimedia |
| GB2376392B (en) * | 2001-12-07 | 2003-05-07 | Ericsson Telefon Ab L M | Legal interception of IP traffic |
| GB2390270A (en) * | 2002-06-27 | 2003-12-31 | Ericsson Telefon Ab L M | Escrowing with an authority only part of the information required to reconstruct a decryption key |
| US7900051B2 (en) | 2002-09-10 | 2011-03-01 | Stmicroelectronics S.A. | Secure multimedia data transmission method |
| US7778422B2 (en) * | 2004-02-27 | 2010-08-17 | Microsoft Corporation | Security associations for devices |
| CN101243388A (zh) * | 2005-08-19 | 2008-08-13 | Nxp股份有限公司 | 用于在加密计算中执行求逆运算的电路结构和方法 |
| US8418235B2 (en) * | 2006-11-15 | 2013-04-09 | Research In Motion Limited | Client credential based secure session authentication method and apparatus |
| KR20080084480A (ko) * | 2007-03-16 | 2008-09-19 | 삼성전자주식회사 | 매개 모듈을 이용한 디바이스간의 상호 인증 방법 및 그시스템 |
| US7864960B2 (en) * | 2007-05-31 | 2011-01-04 | Novell, Inc. | Techniques for securing content in an untrusted environment |
| JP5273963B2 (ja) * | 2007-07-23 | 2013-08-28 | 修 亀田 | 擬似乱数の生成方法及び装置、並びに擬似乱数を用いた暗号化方法及び装置 |
| JP5139028B2 (ja) * | 2007-10-24 | 2013-02-06 | エイチジーエスティーネザーランドビーブイ | コンテンツデータ管理システム及び方法 |
| EP2412123B1 (fr) * | 2009-03-26 | 2020-07-08 | Trustcorp S.A. | Procede et dispostif d'archivage d'un document |
| FR2943870B1 (fr) * | 2009-03-26 | 2022-03-11 | Trustseed | Procede et dispositif de chiffrement d'un document |
| US8769288B2 (en) * | 2011-04-22 | 2014-07-01 | Alcatel Lucent | Discovery of security associations |
| CN104393989A (zh) * | 2014-10-30 | 2015-03-04 | 北京神州泰岳软件股份有限公司 | 一种密钥协商方法及装置 |
| CN104735085A (zh) * | 2015-04-15 | 2015-06-24 | 上海汉邦京泰数码技术有限公司 | 一种终端双因子安全登录防护方法 |
| WO2017043206A1 (fr) * | 2015-09-07 | 2017-03-16 | ソニー株式会社 | Dispositif d'imagerie, son procédé de commande et programme |
| CN107704749A (zh) * | 2017-10-25 | 2018-02-16 | 深圳竹云科技有限公司 | 基于U盾验证算法的Windows系统安全登录方法 |
| SG10201801094VA (en) | 2018-02-08 | 2019-09-27 | Huawei Int Pte Ltd | System and method for computing an escrow session key and a private session key for encoding digital communications between two devices |
| JP7469164B2 (ja) * | 2020-06-26 | 2024-04-16 | 川崎重工業株式会社 | 積付用ロボットハンド、ロボット及び物品保持方法 |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5315658B1 (en) * | 1992-04-20 | 1995-09-12 | Silvio Micali | Fair cryptosystems and methods of use |
| NZ329891A (en) * | 1994-01-13 | 2000-01-28 | Certco Llc | Method of upgrading firmware of trusted device using embedded key |
| US5438622A (en) * | 1994-01-21 | 1995-08-01 | Apple Computer, Inc. | Method and apparatus for improving the security of an electronic codebook encryption scheme utilizing an offset in the pseudorandom sequence |
| US5557765A (en) * | 1994-08-11 | 1996-09-17 | Trusted Information Systems, Inc. | System and method for data recovery |
| US5631961A (en) * | 1995-09-15 | 1997-05-20 | The United States Of America As Represented By The Director Of The National Security Agency | Device for and method of cryptography that allows third party access |
| US5633929A (en) * | 1995-09-15 | 1997-05-27 | Rsa Data Security, Inc | Cryptographic key escrow system having reduced vulnerability to harvesting attacks |
| US5937066A (en) * | 1996-10-02 | 1999-08-10 | International Business Machines Corporation | Two-phase cryptographic key recovery system |
| US6483920B2 (en) * | 1996-12-04 | 2002-11-19 | Bull, S.A. | Key recovery process used for strong encryption of messages |
| US5920630A (en) * | 1997-02-25 | 1999-07-06 | United States Of America | Method of public key cryptography that includes key escrow |
| US6058188A (en) * | 1997-07-24 | 2000-05-02 | International Business Machines Corporation | Method and apparatus for interoperable validation of key recovery information in a cryptographic system |
| US6151395A (en) * | 1997-12-04 | 2000-11-21 | Cisco Technology, Inc. | System and method for regenerating secret keys in diffie-hellman communication sessions |
| US6754820B1 (en) * | 2001-01-30 | 2004-06-22 | Tecsec, Inc. | Multiple level access system |
-
2000
- 2000-01-31 FR FR0001185A patent/FR2804561B1/fr not_active Expired - Fee Related
-
2001
- 2001-01-30 EP EP01904002A patent/EP1254534A1/fr not_active Withdrawn
- 2001-01-30 WO PCT/FR2001/000285 patent/WO2001056222A1/fr not_active Ceased
- 2001-01-30 JP JP2001555258A patent/JP2003521197A/ja not_active Withdrawn
- 2001-01-30 US US10/181,598 patent/US20030012387A1/en not_active Abandoned
Non-Patent Citations (1)
| Title |
|---|
| See references of WO0156222A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| FR2804561B1 (fr) | 2002-03-01 |
| US20030012387A1 (en) | 2003-01-16 |
| JP2003521197A (ja) | 2003-07-08 |
| FR2804561A1 (fr) | 2001-08-03 |
| WO2001056222A1 (fr) | 2001-08-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1254534A1 (fr) | Procede de communication avec sequestre et recuperation de cle de chiffrement | |
| EP3506556B1 (fr) | Méthode d'échange de clés authentifié par chaine de blocs | |
| EP3010177B1 (fr) | Procédé d'authentification d'un dispositif client auprès d'un serveur à l'aide d'un élément secret | |
| EP1151576B1 (fr) | Procede cryptographique a cles publique et privee | |
| EP2887574A1 (fr) | Procédé de conversion d'un contenu à acces conditionnel | |
| FR2952778A1 (fr) | Procede de transmission de donnees securise et systeme de chiffrement et de dechiffrement permettant une telle transmission | |
| WO2008113950A2 (fr) | Chiffrement broadcast base sur identite | |
| EP1072124A2 (fr) | Procede de verification de l'usage de cles publiques engendrees par un systeme embarque | |
| FR2916592A1 (fr) | Procede de securisation d'echange d'information,dispositif, et produit programme d'ordinateur correspondant | |
| WO2023046557A1 (fr) | Système et méthode de génération de clé secrète sûre | |
| EP2643943A1 (fr) | Procede et systeme d'acces conditionnel a un contenu numerique, terminal et dispositif d'abonne associes | |
| EP4413687A1 (fr) | Procédé de génération d'un nombre pseudo-aléatoire et procédé de chiffrement symétrique d'un message | |
| FR3153207A1 (fr) | Procédé hybride d'échange de clés robuste aux attaques quantiques | |
| FR2923968A1 (fr) | Procede de partage d'un secret fort entre deux parties dont l'une dispose de peu de puissance de traitement. | |
| EP1642413B1 (fr) | Procede de chiffrement/dechiffrement d un message et disposi tif associe | |
| EP2652899A2 (fr) | Procédé et système d'accès conditionnel à un contenu numérique, terminal et dispositif d'abonné associés | |
| WO2008113952A2 (fr) | Chiffrement base sur identite | |
| FR2899750A1 (fr) | Procede et terminal pour securiser la generation d'une cle de chiffrement | |
| FR2786049A1 (fr) | Procede de cryptographie a cle dynamique | |
| EP4629558A1 (fr) | Procédé et dispositif de communication sécurisé utilisant un identifiant dérivé de manière déterministe | |
| EP4580114A1 (fr) | Procédé amélioré d'échange de clés s'appuyant sur un réseau quantique ; infrastructure de communication associée | |
| FR2892251A1 (fr) | Procede cryptographique mettant en oeuvre un systeme de chiffrement base sur l'identite | |
| EP4580115A1 (fr) | Procédé d'échange de clés à intégrité garantie s'appuyant sur un réseau quantique ; infrastructure de communication associée | |
| WO2024175864A1 (fr) | Procede et dispositif de stockage en ligne reparti de fichiers dans un contexte zero confiance | |
| FR3158002A1 (fr) | Procédé amélioré d’échange de clés s’appuyant sur un réseau quantique et un service de sécurité ; infrastructure de communication associée. |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20020716 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: ARDITTI, DAVID Inventor name: GILBERT, HENRI Inventor name: BARITAUD, THIERRY Inventor name: CHAUVAUD, PASCAL |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20080801 |