US2006245590A1PendingUtilityA1

Method of confirming a secure key exchange

Individually held — no corporate assignee on recordPriority: Jun 18, 2002Filed: Jun 30, 2006Published: Nov 2, 2006
Est. expiryJun 18, 2022(expired)· nominal 20-yr term from priority
Inventors:Ernie Brickell
G06F 21/85H04L 9/0841H04L 63/061H04L 2463/062H04L 63/1466
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A key exchange protocol can be performed between components of a system, such as between a computer program being executed by the processor of a PC (or other computer system) and a peripheral. A peripheral with a user input capability and a very limited display capability, such as a keyboard or a mouse, may be used to confirm a key exchange between the system components in a way that requires the user to enter only small amounts of input data (e.g., keystrokes or mouse clicks). Security between components may be enhanced without having a negative impact on usability of the system. Embodiments of the present invention help to deter “man in the middle” attacks wherein an attacker gains control of a system component situated between certain communicating system components.

Claims

exact text as granted — not AI-modified
1 . A method of securely exchanging a symmetric key between first and second components of a system comprising: 
 performing a public key exchange to share a symmetric key;    committing, by the first component, to a first value;    securely exchanging a shared secret between the first component and the second component;    disclosing, by the first component, the first value; and    verifying, by the second component, the correctness of the first component's commitment.    
   
   
       2 . The method of  claim 1 , further comprising: 
 committing, by the second component, to a second value;    disclosing, by the second component, the second value; and    verifying, by the first component, the correctness of the first component's commitment.    
   
   
       3 . The method of  claim 1 , wherein the first value comprises a value computed from the shared secret, a random nonce, and a public key of the first component used in the key exchange.  
   
   
       4 . The method of  claim 1 , wherein the first value comprises a value computed from the shared secret, a random nonce, and the symmetric key derived from the key exchange.  
   
   
       5 . The method of  claim 2 , wherein the second value comprises a value computed from the shared secret, a random nonce, and the symmetric key derived from the key exchange.  
   
   
       6 . The method of  claim 2 , wherein the second value comprises a value computed from the shared secret, a random nonce, and a public key of the second component used in the key exchange.  
   
   
       7 . An article comprising: a machine accessible medium having a plurality of machine accessible instructions, wherein when the instructions are executed by a processor, the instructions provide for securely exchanging a symmetric key between first and second components of a system, the instructions including performing a public key exchange to share a symmetric key; committing, by the first component, to a first value; securely exchanging a shared secret between the first component and the second component; disclosing, by the first component, the first value; and verifying, by the second component, the correctness of the first component's commitment.  
   
   
       8 . The article of  claim 7 , further comprising instructions for committing, by the second component, to a second value; disclosing, by the second component, the second value; and verifying, by the first component, the correctness of the first component's commitment.  
   
   
       9 . The article of  claim 7 , wherein the first value comprises a value computed from the shared secret, a random nonce, and a public key of the first component used in the key exchange.  
   
   
       10 . The article of  claim 7 , wherein the first value comprises a value computed from the shared secret, a random nonce, and the symmetric key derived from the key exchange.  
   
   
       11 . The article of  claim 8 , wherein the second value comprises a value computed from the shared secret, a random nonce, and the symmetric key derived from the key exchange.  
   
   
       12 . The article of  claim 8 , wherein the second value comprises a value computed from the shared secret, a random nonce, and a public key of the second component used in the key exchange.

Join the waitlist — get patent alerts

Track US2006245590A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.