Using Elliptic Curve Cryptography for Personal Device Security to Share Secrets
By using elliptic curve encryption technology between the electronic device and the key device, deterministic key DK and asymmetric encryption pairs, the risk of stealing during key transmission is solved and the security of data is improved.
Patent Information
- Application Number
- CN202210865047.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2016-11-15
- Filing Date
- 2017-02-14
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2037-02-14
AI Technical Summary
In the prior art, when the hard disk data of an electronic device is protected, the secret key is easily stolen by a third party during transmission, resulting in damage to data security.
By using elliptic curve encryption between the electronic device and the key device, a deterministic key DK is determined and based on the key and asymmetric encryption pair, the secret is determined for encrypting or decrypting the data.
It improves the security of electronic device data, prevents theft of keys during transmission, and enhances the intensity of data protection.
Smart Images

Figure CN115225268B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application with Chinese application number 201780009436.9 (corresponding to PCT international application number PCT / IB2017 / 050815), application date February 14, 2017, and invention title "Using Elliptic Curve Cryptography for Personal Device Security to Share Secrets". Technical Field
[0002] The present disclosure generally relates to computer-related security and the field of cryptography. More specifically, it provides methods, systems, and devices for encrypting data stored on an electronic device. It is particularly suitable for enhancing the security of personal computing devices, including but not limited to mobile phones, tablet devices, or laptop computers. The present disclosure also relates to methods, systems, and devices for decrypting encrypted data. Background Art
[0003] Cryptography involves techniques for protecting data on the hard disk of an electronic device, for example, in the case where the electronic device is lost or stolen. The electronic device may include a laptop computer, a desktop computer, a tablet computer, a mobile communication device, and any other form of computing device. The electronic device may be associated with a natural person, a group of people (such as company employees), a system (such as a banking system), and so on.
[0004] In some cases, data on the hard disk of an electronic device can be protected by a password, a passphrase, or a PIN. However, short codes such as a 4 - 8 character PIN can be easily determined by trying different combinations of characters. Passwords and passphrases may be more secure than a PIN. However, the level of security depends on the user's ability to remember a long set of code words or sentences.
[0005] In other cases, an encryption key can be used to protect data on the hard disk of an electronic device. The encryption key can be stored on a USB drive, and the USB drive needs to be physically connected to the electronic device to transfer the encryption key. However, due to the electromagnetic signals generated during the transfer of the encryption key from the USB drive to the electronic device, the transferred key may still be obtained by a third party.
[0006] Therefore, a problem in such encrypted data protection is the transmission of the secret key to the electronic device.
[0007] Any discussion in this specification of documents, acts, materials, devices, articles, etc. should not be regarded as an admission that any one or all of these matters form part of the basis of the prior art or are common general knowledge in the relevant fields of the present disclosure prior to the priority date of each claim of this application.
[0008] Throughout the specification, the word "comprise" or variations such as "comprises" or "comprising" shall be understood to imply the inclusion of the stated element, integer or step, or group of elements, integers or steps, but not the exclusion of any other element, integer or step, or group of elements, integers or steps.
[0009] The following documents provide background material related to the technical background of the present invention: WO2015 / 175854A2, CN103440209B, US2007055880, US2010023771, DEI02010002241, US2012011362, US2012100833, US2012331287, WO2013053058, US8522011, US2014082358, US2015213433 and EP2975570. Summary of the Invention
[0010] The present invention can provide a computer-implemented method. It can provide a secure method. It can provide a method for encrypting data at an electronic device (S), the electronic device being associated with a key device (C). The electronic device can also be associated with a first asymmetric encryption pair having a first electronic device private key (V 1S ) and a first electronic device public key (P 1S ), and the key device can be associated with a second asymmetric encryption pair having a first key device private key (V 1C ) and a first key device public key (P 1C );
[0011] The method can include the following steps:
[0012] The electronic device determines a deterministic key (DK);
[0013] The electronic device receives a first key device public key (P 1C ) from the key device;
[0014] Based on at least the first electronic device private key (V 1S ) and the deterministic key (DK), the electronic device determines a second electronic device private key (V 2S ), and
[0015] Based on at least the first key device public key (P 1C ) and the deterministic key (DK), the electronic device determines a second key device public key (P 2C );
[0016] Based on at least the second electronic device private key (V 2S ) and the second key device public key (P 2C), determine the secret;
[0017] Using the determined secret or an encryption key based on the determined secret, the electronic device encrypts the data; and / or
[0018] Send information indicating the deterministic key (DK) to a key device capable of storing information.
[0019] The method may further include the key device storing the information indicating the deterministic key (DK).
[0020] The deterministic key (DK) may be based on the message (M). The method may include the step of the electronic device generating the message (M). The method may further include determining a deterministic key (DK) based on determining the hash of the message (M). The step of storing the information indicating the deterministic key on the key device may include storing the message (M) on the key device.
[0021] The method may include determining a second electronic device public key (P 1S ) and the deterministic key (DK) based on at least the first electronic device public key (P 2S ).
[0022] The method may further include: the electronic device sending an indication notification to the key device, the indication notification utilizing a public elliptic curve cryptography (ECC) system having a common generator (G).
[0023] The first electronic device public key (P 1S ) and the first key device public key (P 1C ) may be based on the corresponding first electronic device private key (V 1S ) and the first key device private key (V 1C ) and the elliptic curve point multiplication of the common generator (G).
[0024] The method may include generating a first electronic device private key (V 1S ) and a first electronic device public key (P 1S ). For example, the first electronic device private key (V 1S ) may be generated based on a random integer within an allowable range specified in the public ECC system; and the first electronic device public key (P 1S ) may be generated based on the elliptic curve point multiplication of the first electronic device private key (V1C) and the common generator (G), and the first electronic device public key (P 1S ) is generated according to the following formula: P 1S = V 1S × G.
[0025] According to the following formula, based on the first electronic device private key (V 1S) and scalar addition with a deterministic key (DK) to generate a second electronic device private key (V2S): V 2S = V 1S + DK.
[0026] The second electronic device public key (P 2S ) can be based at least on elliptic curve point addition of the first electronic device public key (P 1S ) and the deterministic key (DK). In a particular example, according to the following formula, the second electronic device public key (P 2S ) can be based on elliptic curve point addition of the first electronic device public key (P 1S ) and the deterministic key (DK) and an elliptic curve point multiplication of the common generator (G): P 2S = P 1S + DK × G.
[0027] The second key device public key (P 2C ) can be based at least on elliptic curve point addition of the first key device public key (P 1C ) and the deterministic key (DK). In a particular example, according to the following formula, the second key device public key (P 2C ) can be based on elliptic curve point addition of the first key device public key (P 1C ) and the deterministic key (DK) and an elliptic curve point multiplication of the common generator (G): P 2C = P1C + DK × G.
[0028] The method can include determining an encryption key based on the determined secret. For example, the encryption key can be based on the secret and information identifying the electronic device. The identifying information can include the serial number of the electronic device.
[0029] The method can include connecting the electronic device to the key device for mutual communication. For example, the electronic device can be connected to the key device via a wireless protocol (such as Bluetooth) or a communication network (such as the Internet or a local communication network). Alternatively, the electronic device can be connected to the key device by wire, such as via a cable or a suitable port of the electronic device.
[0030] The method can also include storing the first key device public key (P 1C ) at a data memory associated with the electronic device
[0031] Additionally or optionally, the present invention can provide a computer-implemented method for decrypting data at an electronic device, the data being encrypted according to the method of encrypting data as described above, the method of decrypting data including the steps of:
[0032] Receiving, at the electronic device, information indicating the deterministic key (DK) from the key device;
[0033] Determine a secret based on information indicating a deterministic key (DK); and
[0034] At the electronic device, decrypt encrypted data using the secret or an encryption key based on the secret.
[0035] The method may include verifying a key device. To this end, the method may include the electronic device generating a verification message (M A ) and sending the verification message (M A ) to the key device.
[0036] The method may include the key device generating a second asymmetric encryption pair having a second key device private key (V 2C ) and a second key device public key (P 2C ). The second key device private key (V 2C ) may be based on the deterministic verification key (DK A ) and a first key device private key (V 1C ). The second key device public key (P 2C ) may be based on the deterministic verification key (DK A ) and a first key device public key (P 1C ).
[0037] The method may include determining a deterministic verification key (DK A ). For example, a deterministic verification key (DK A ) may be determined based on the verification message (M A ), for example, by determining the hash of the message (M A ).
[0038] The method may include the key device generating a signature verification message (SM A ) based on the deterministic verification key (DK 2C ) and the second key device private key (V A ).
[0039] The method may further include: the electronic device receiving the signature verification message (SM A ) from the key device; verifying the signature message (SM 2C ) using the second key device public key (P A ); and verifying the key device based on the result of verifying the signature verification message (SM A ).
[0040] A method for decrypting data may include an electronic device requesting information indicating a deterministic key (DK) from a key device. In an embodiment where the information indicating the deterministic key (DK) includes a message (M), in response to receiving the request at the key device, the key device may generate a signature message (SM) based on the message (M) and send the signature message (SM) to the electronic device. The signature message (SM) may be generated based on the message (M) and a first key device private key or a second key device private key.
[0041] The method for decrypting data may further include the electronic device verifying the signature message (SM) and retrieving the message (M) such that a secret can be determined at the electronic device for decrypting the data.
[0042] The present invention may also provide a computer-implemented system for implementing any of the above methods or embodiments. It may provide a computer system for encrypting data at an electronic device, the computer system including:
[0043] An electronic device associated with a first asymmetric encryption pair having a first electronic device private key (V 1S ) and a first electronic device public key (P 1S ),
[0044] A key device associated with a second asymmetric encryption pair having a first key device private key (V 1C ) and a first key device public key (P 1C );
[0045] wherein the electronic device includes a processor configured to:
[0046] Determine a deterministic key (DK);
[0047] Receive a first key device public key (P 1C ) from the key device;
[0048] Determine a second electronic device private key (V 1S ) based on at least the first electronic device private key (V 1S ) and the deterministic key (DK), and 2S
[0049] Determine a second key device public key (P 1C ) based on at least the first key device public key (P 1C ) and the deterministic key (DK); 2C
[0050] Determine a secret based on at least the second electronic device private key (V 2S ) and the second key device public key (P 2C ); and
[0051] Encrypt the data on the electronic device using the determined secret or an encryption key based on the determined secret;
[0052] Wherein, store the information indicating the deterministic key (DK) in the key device.
[0053] The deterministic key (DK) can be based on the message (M). The processor can be used to generate the message (M). The processor can also be used to determine a deterministic key (DK) based on the hash of the determined message (M).
[0054] The processor can be used to determine the second electronic device public key (P 1S ) and the deterministic key (DK) at least based on the first electronic device public key (P 2S ).
[0055] In the system, the electronic device can include an interface, and the key device can include a key device interface to establish communication between the electronic device and the key device. For example, the electronic device can be connected to the key device via a wireless protocol (such as Bluetooth) or a communication network (such as the Internet or a local communication network). Or, the electronic device can be connected to the key device by wire, such as via a cable or a suitable port of the electronic device.
[0056] The interface of the electronic device can be used to send a notification indicating the use of a public elliptic curve cryptography (ECC) system with a common generator (G) to the key device interface of the associated key device.
[0057] The first electronic device public key (P 1S ) and the first key device public key (P 1C ) can be based on the elliptic curve point multiplication of the corresponding first electronic device private key (V 1S ) and the first key device private key (V 1C ) with the generator (G).
[0058] The processor can be used to generate the first electronic device private key (V 1S ) and the first electronic device public key (P 1S ). For example, the first electronic device private key (V 1S ) can be generated based on a random integer within the allowable range specified in the public ECC system; the first electronic device public key (P 1C ) can be generated based on the elliptic curve point multiplication of the first electronic device private key (V 1S ) and the public generator (G) according to the following formula: P 1S =V 1S xG.
[0059] According to the following formula, the second electronic device private key (V 2S ) can be based on the first electronic device private key (V1S ) and scalar addition of the deterministic key (DK): V 2S = V 1S + DK.
[0060] The public key of the second electronic device (P 2S ) can be based at least on the public key of the first electronic device (P 1S ) and elliptic curve point addition of the deterministic key (DK). In a specific example, according to the following formula, the public key of the second electronic device (P 2S ) can be based on the public key of the first electronic device (P 1S ) and elliptic curve point addition of the elliptic curve point multiplication of the deterministic key (DK) and the public generator (G): P 2S = P 1S + DK × G.
[0061] The public key of the second key device (P 2C ) can be based at least on the public key of the first key device (P 1C ) and elliptic curve point addition of the deterministic key (DK). In a specific example, according to the following formula, the public key of the second key device (P 2C ) can be based on the public key of the first key device (P 1C ) and elliptic curve point addition of the elliptic curve point multiplication of the deterministic key (DK) and the public generator (G): P 2C = P 1C + DK × G.
[0062] The processor can be used to determine an encryption key based on the determined secret. For example, the encryption key can be based on the determined secret and the identification information of the electronic device. The identification information can include the serial number of the electronic device.
[0063] The electronic device can include a data memory, where the public key of the first key device (P 1C ) can be stored.
[0064] The key device can include a key device data memory for storing at least information indicating the deterministic key.
[0065] The computer system as described above can also be used to decrypt data, and the processor of the electronic device can be used to:
[0066] Receive information indicating the deterministic key (DK) from the key device;
[0067] Determine a secret based on the information indicating the deterministic key (DK); and
[0068] Use the determined secret or the encryption key based on the determined secret to decrypt the data.
[0069] The processor can be used to verify the key device. For this purpose, the processor can generate a verification message (M A ) and send the verification message (M A ) to the key device.
[0070] The key device can include a key device processor, which can be used to generate a second asymmetric encryption pair having a second key device private key (V 2C ) and a second key device public key (P 2C ). The second key device private key (V 2C ) can be based on the deterministic verification key (DK A ) and the first key device private key (V 1C ). The second key device public key (P 2C ) can be based on the deterministic verification key (DK A ) and the first key device public key (P 1C ).
[0071] The key device processor can be used to determine a deterministic verification key (DK A ). For example, a deterministic verification key (DK A ) can be determined based on the verification message (M A ), for example, by determining the hash of the message (M A ).
[0072] The key device processor can be used to generate a signature verification message (SM A ) based on the deterministic verification key (DK 2C ) and the second key device private key (V A ).
[0073] The processor of the electronic device can be used to: receive the signature verification message (SM A ) from the key device; verify the signature message (SM 2C ) through the second key device public key (P A ); and verify the key device based on the result of verifying the signature verification message (SM A ).
[0074] The processor of the electronic device can request information indicating the deterministic key (DK) from the key device. In an embodiment where the information indicating the deterministic key (DK) includes the message (M), in response to receiving the request at the key device, the key device processor can generate a signature message (SM) based on the message (M) and send the signature message (SM) to the electronic device. The signature message (SM) can be generated based on the message (M) and the first key device private key or the second key device private key.
[0075] The processor of the electronic device can also be used to authenticate the signed message and retrieve the message (M), enabling the determination of a secret for decrypting the data.
[0076] An electronic device for encrypting data, the electronic device being associated with a key device, wherein the electronic device is associated with a first asymmetric encryption pair having a first electronic device private key (V 1S ) and a first electronic device public key (P 1S ), and the key device is associated with a second asymmetric encryption pair having a first key device private key (V 1C ) and a first key device public key (P 1C ); the electronic device includes a processing device configured to:
[0077] Determine a deterministic key (DK);
[0078] Receive the first key device public key (P 1C ) from the associated key device;
[0079] Based on at least the first electronic device private key (V 1S ) and the deterministic key (DK), determine a second electronic device private key (V 2S ), and
[0080] Based on at least the first key device public key (P 1C ) and the deterministic key (DK), determine a second key device public key (P 2C );
[0081] Based on at least the second electronic device private key (V 2S ) and the second key device public key (P 2C ), determine a secret; and
[0082] Encrypt the data on the electronic device using the determined secret or an encryption key based on the determined secret;
[0083] Wherein, the information indicating the deterministic key (DK) is sent to the key device capable of storing it.
[0084] A computer program comprising machine-readable instructions for causing the processing device of the electronic device to implement any of the above methods.
[0085] One or more embodiments or aspects of the present invention may include or use a computer-implemented method for determining a common secret (CS) at a first node (C), the common secret (CS) being shared by the first node (C) and a second node (S). The first node (C) may be associated with a first node master private key (V 1C ) and a first node master public key (P 1C) is associated with a first asymmetric encryption pair, and a second node (S) can be associated with a second asymmetric encryption pair having a second node master private key (V 1S ) and a second node master public key (P 1S ). The method may include:
[0086] Determining a first node second private key (V 1C ) based on at least a first node master private key (V 2C ) and a deterministic key (DK);
[0087] Determining a second node second public key (P 1S ) based on at least a second node master public key (P 2S ) and a deterministic key (DK); and
[0088] Determining a common secret (CS) based on a first node second private key (V 2C ) and a second node second public key (P 2S ),
[0089] wherein the second node (S) has the same common secret (S) based on a first node second public key (P 2C ) and a second node second private key (V 2S ), wherein:
[0090] The first node second public key (P 2C ) is based on at least a first node master public key (P 1C ) and a deterministic key (DK); and
[0091] The second node second private key (V 2S ) is based on at least a second node master private key (V 1S ).
[0092] The deterministic key (DK) is based on a message (M).
[0093] Thus, the present invention can provide techniques and apparatuses for enhancing the security of an electronic device and / or data stored thereon. Because of the enhanced security mechanism of the present invention, the present invention can also provide a better electronic device. BRIEF DESCRIPTION OF THE DRAWINGS
[0094] The following describes examples of the present disclosure with reference to the following drawings:
[0095] Figure 1 is a schematic diagram of an exemplary system for encrypting data;
[0096] Figure 2 is a flowchart of a computer-implemented method for registering Figure 1 an electronic device and a key device;
[0097] Figure 3 is a flowchart of a computer-implemented method for encrypting data at an electronic device using a secret; Figure 1 ;
[0098] Figure 4 is a flowchart of a computer-implemented method for verifying a key device; Figure 1 ;
[0099] Figure 5 is a flowchart of a computer-implemented method for decrypting encrypted data at an electronic device after verifying the key device; and
[0100] Figure 6 shows a schematic diagram of an exemplary processing device. DETAILED DESCRIPTION
[0101] Overview
[0102] A method, apparatus, and system for encrypting data at an electronic device are described below.
[0103] Figure 1 FIG. 1 shows a computer system 1 that includes an electronic device 3 in communication with a key device 5. The electronic device 3 has an associated first processing device 23, and the key device 5 has an associated second processing device 25. The electronic device 3 can be a personal electronic device, such as a laptop computer, desktop computer, tablet computer, mobile communication device, computer server, or any other computing device capable of processing data. In Figure 1 this particular example shown in FIG. 1, the electronic device 3 is represented by a laptop computer.
[0104] The key device 5 can be other personal electronic devices, such as a mobile communication device, a portable storage device, such as a USB drive, and so on. In Figure 1 this particular example shown in FIG. 1, the key device 5 is represented by a mobile communication device.
[0105] The electronic device 3 can communicate with the key device 5 via a wireless protocol (such as Bluetooth) or a communication network (such as the Internet or a local communication network). Alternatively, the electronic device 3 can be physically connected to the key device 5, such as via a USB port of the electronic device or via a cable connection. In Figure 1 this particular example shown in FIG. 1, the electronic device 3 communicates with the key device 5 via Bluetooth 7.
[0106] The electronic device 3 is associated with a first asymmetric encryption pair that has an electronic device master private key (V 1S ) and an electronic device master public key (P 1S )1C ) and the public master key (P) of the key device 1C ). The first and second asymmetric encryption pairs can be generated during registration. The following describes in further detail the registration methods 200 and 300 performed by the electronic device 3 and the key device 5 with reference to Figure 2 . The public keys of each device can be publicly shared between the devices 3 and 5, for example, via Bluetooth 7.
[0107] Embodiments of the present invention may include such a technique (or a variant (s) thereof), which is generally provided as: determining, at a first node (C), a common secret (CS) shared by the first node (C) and a second node (S), wherein the first node (C) is associated with a first asymmetric encryption pair having a first node master private key (V 1C ) and a first node public master key (P 1C ), and the second node (S) is associated with a second asymmetric encryption pair having a second node master private key (V 1S ) and a second node public master key (P 1S ); the method or technique includes:
[0108] determining, at least based on the first node master private key (V 1C ) and a deterministic key (DK), a second private key (V 2C ) of the first node;
[0109] determining, at least based on the second node public master key (P 1S ) and a deterministic key (DK), a second public key (P 2S ) of the second node; and
[0110] determining the common secret (CS) based on the second private key (V 2C ) of the first node and the second public key (P 2S ) of the second node,
[0111] wherein the second node (S) has the same common secret (S) based on the second public key (P 2C ) of the first node and the second private key (V 2S ) of the second node, wherein:
[0112] the second public key (P 2C ) of the first node is at least based on the public master key (P 1C ) of the first node and a deterministic key (DK); and
[0113] the second private key (V 2S ) of the second node is at least based on the master private key (V 1S ) of the second node and a deterministic key (DK).
[0114] A deterministic key (DK) can be based on a message (M).
[0115] According to an illustrative embodiment of the present invention: In order to encrypt data at the electronic device 3, a secret is determined based on a technique similar to the above. The secret is determined according to the private encryption key of the electronic device 3 and the public encryption key of the key device 5. By determining this secret, the data can be encrypted using an encryption key (E) based on the determined secret. In one or more examples, the secret can be used as the encryption key (E). One advantage of this technique is that there is no need to transmit or store the secret or the encryption key (E) on any of the devices 3, 5. Compared with the configurations of the prior art, this provides a more secure solution.
[0116] In order to encrypt data using the secret at the electronic device 3, the method 400 is performed without transferring any private keys between the devices 3, 5. The following is a more detailed description with reference to Figure 3 described in more detail.
[0117] Generally speaking, the method of encrypting data by the electronic device 3 initially includes connecting the electronic device 3 to the key device 5 to communicate with the key device 5. The communication can be established through a wired connection or a wireless connection (such as Bluetooth 7).
[0118] The method further includes determining a deterministic key (DK), and the deterministic key can be based on a message (M) created by the electronic device 3. For example, the processing device 23 of the electronic device 3 can generate the message (M), and then use a standard algorithm to create a hash of the message that forms the deterministic key (DK).
[0119] The method further includes determining a second electronic device private key (V 1S ) at least based on the electronic device master private key (V 2S ) and the deterministic key (DK), and determining a second electronic device public key (V 1C ) based on the key device master public key (P 2C ) and the deterministic key (DK). Then, a secret is determined based on the second electronic device private key (V 2S ) and the second key device public key (P 2C ). Optionally, the method may include determining a second electronic device public key (P 1S ) at least based on the electronic device master public key (P 2S ) and the deterministic key (DK).
[0120] In other method steps, the data can then be encrypted using an encryption key (E) based on the determined secret. As described above, the determined secret itself can be used as the encryption key (E), or the encryption key (E) can be determined based on the secret. After encrypting the data on the electronic device, the secret can be erased, and only the deterministic key (DK) or the message (M) is sent to the key device 5, where it can be securely stored. Subsequently, the encrypted data can be decrypted using the deterministic key (DK) or the message (M) stored on the key device 5.
[0121] It should be understood that the data to be encrypted / decrypted can include one or more individual files, one or more folders including files, or the entire hard drive of the electronic device. In some examples, the method can include prompting the user to select the files and / or folders to be encrypted / decrypted. In such a case, the key device 5 can store information indicating the deterministic keys for each file and folder and link them accordingly.
[0122] Registration methods 200, 300
[0123] The following refers to Figure 2 Examples of the registration methods 200, 300 are described, where the method 200 is performed by the electronic device 3 and the method 300 is performed by the key device 5. This includes establishing a first asymmetric encryption pair and a second asymmetric encryption pair for the respective devices 3, 5.
[0124] The asymmetric encryption pair includes an associated private key and public key, such as the keys used in public key cryptography. In this example, elliptic curve cryptography (ECC) and the properties of elliptic curve operations are used to generate the asymmetric encryption pair.
[0125] The standards for ECC can include known standards, such as those described by the Standards for Efficient Cryptography Group (wwsv.sceg.org). Elliptic curve cryptography is also described in US 5,600,725, US 5,761,305, US 5889,865, US 5,896,455, US 5,933,504, US 6,122,736, US 6,141,420, US 6,618,483, US 6,704,870, US 6,785,813, US 6,078,667, US6,792,530.
[0126] In the methods 200, 300, this includes the electronic device 3 and the key device 5 arranging into a common ECC system and using a common generator (G) in steps 210, 310. In one example, the common ECC system can be based on secp256K1. The common generator (G) can be selected, randomly generated, or assigned.
[0127] InFigure 1 In the specific example shown, where the electronic device 3 is a laptop computer and the key device 5 is a mobile communication device, the communication between the respective devices 3, 5 is implemented by an application programming interface (API), and the API communicates with a dedicated application installed on the mobile communication device 5. To this end, software can be downloaded and installed on a laptop computer compatible with the dedicated application installed on the mobile communication device.
[0128] In a specific example, the key device 5 can provide not only software applications for the key device but also software for the electronic device. In this way, when the key device is connected to the electronic device, the software can be installed on the electronic device by performing an installation from the key device.
[0129] Reference is now made to method 200 performed by electronic device 3. Method 200 includes arranging a common ECC system and a common generator (G) in step 210. This can include sending information indicating the common ECC system and the common generator from electronic device 3 to key device 5, or receiving information from a third device (such as a remote server computer). For example, electronic device 3 can send a notification indicating the use of a common ECC system with a common generator (G) to key device 5 via Bluetooth 7. Accordingly, key device 5 can be arranged in step 310 by sending a notification indicating an acknowledgement of the use of the common ECC system and the common generator (G).
[0130] Method 200 further includes, in step 220, generating, at electronic device 3, a first asymmetric encryption pair including an electronic device master private key (V 1S ) and an electronic device master public key (P 1S ). In this specific example, the electronic device master private key (V 1S ) is determined at least in part based on a random integer within an allowable range specified in the common ECC system. Then, according to the following formula, the electronic device master public key (P 1S ) is determined based on the elliptic curve point multiplication of the electronic device master private key (P 1S ) and the common generator (G):
[0131] P 1S = V 1S × G (Formula 1)
[0132] Thus, the first asymmetric encryption pair includes:
[0133] V 1S : The electronic device master private key kept secret by the electronic device.
[0134] P 1S : The electronic device master public key made known.
[0135] The electronic device 3 may store the first asymmetric encryption pair in a first data memory 13 associated with the electronic device 3. For security purposes, the main private key (V 1S ) of the electronic device may be stored in a secure part 14 of the first data memory 13 to ensure that the key remains private.
[0136] In this example, method 200 includes sending the public main key (P 1S ) of the electronic device to the key device 3 in step 230. However, this step may not be necessary for encrypting data on the electronic device 3.
[0137] Referring now to method 300 performed by key device 5, in this particular example, the key device 5 receives the public main key (P 1S ) of the electronic device in step 320 and stores the received public main key (P 1S ) of the electronic device in a storage element of the key device 5 in step 330.
[0138] Similar to method 200, method 300 at the key device 5 includes generating a second asymmetric encryption pair including the main private key (V 1c ) and the public main key (P 1c ) of the key device in step 340. The main private key (V 1c ) of the key device is also a random integer within the allowable range specified in the public ECC system. Accordingly, the public main key (P 1c ) of the key device is determined by the following formula:
[0139] P 1c = V 1c × G (Formula 2)
[0140] Therefore, the second asymmetric encryption pair includes:
[0141] V 1c : The main key of the key device kept secret by the key device.
[0142] P 1c : The public main key of the key device made known.
[0143] The key device 5 may store the second asymmetric encryption pair in a second data memory 15 of the key device. Method 300 further includes sending the public main key (P 1c ) of the key device to the electronic device 3 in step 330, where it may be stored in the memory 13.
[0144] In some alternatives, a corresponding public master key can be received and stored in a third data store associated with a third device (e.g., a trusted third party). This may include a third party acting as a public directory, such as a certificate authority. Thus, in some examples, the electronic device 3 can request and receive the key device master public key (P 1c ) only when it is determined that a secret is needed.
[0145] The registration step may only need to occur once as an initial setup. After that, the master key can be reused in security matters to determine secrets that particularly rely on a deterministic key (DK).
[0146] Encrypt data at electronic device 3
[0147] Reference is made below to Figure 3 describe an exemplary method 400 for encrypting data at the electronic device 3 by determining a secret based on the private key of the electronic device 3 and the public key of the key device 5. The secret can be used for only one cycle, and each cycle is a complete round of data encryption and decryption.
[0148] It should be understood that for each encryption and decryption cycle, new private and public keys can be determined for both the electronic device and the key device. For example, new private and public keys can be determined by rehashing a message (M), as further described in detail in the above co-filed application incorporated herein by reference in its entirety. In this way, sub-keys can be created, where each sub-key is linked to the master key.
[0149] Generate message (M) 410
[0150] In this example, method 400 includes, at step 410, generating a message (M) at the electronic device 3. The message (M) can be random, pseudo-random, or user-defined. In one example, the message (M) is based on Unix Time and a nonce (and any value). For example, the message (M) can be provided as:
[0151] Message(M) = Unix Time + nonce (Formula 3)
[0152] In some examples, the message (M) is arbitrary. However, it should be understood that the message (M) can have selected values (such as Unix Time, etc.) that may be useful in certain applications.
[0153] Method 400 includes, at step 420, sending the message (M) to the key device 5 that is to store the message (M) via Bluetooth 7. Importantly, the message (M) can be sent to the key device 5 over an insecure network because the message (M) does not include information about the private key.
[0154] It should be understood that the message (M) can be passed to the key device 5 at any time. For example, after data encryption is completed, the message (M) can be sent to the key device 5.
[0155] Determine a deterministic key 430
[0156] Method 400 further includes a step of determining a deterministic key (DK) based on the message (M) at step 430. In this example, this includes determining the encrypted hash of the message. Examples of encrypted hash algorithms include SHA-256 to create a 256-bit deterministic key (DK). That is:
[0157] DK = SHA-256(M) (Equation 4)
[0158] For generating the encryption key (E), the selection of the message can be arbitrary and will be reselected for each encryption / decryption cycle. In this example, the message (M) is reduced to 160 bits by hashing, thus keeping the message length short.
[0159] It should be understood that other hash algorithms can be utilized. This can include other hash algorithms in the Secure Hash Algorithm (SHA) series. Some specific examples include instances in the SHA-3 subset, including SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256. Other hash algorithms can include algorithms in the RACE Integrity Primitives Evaluation Message Digest (RIPEMD) series. Specific examples can include RIPEMD-160. Other hash functions can be based on the Zemor-Tillich hash function and the knapsack-based hash function.
[0160] Determine a second private key and public keys 440, 450, 460
[0161] Then, method 400 includes determining the following second key based on the deterministic key (DK), i.e., the hash of the message (M), at steps 440, 450, 460.
[0162] At step 440, based on the main private key of the electronic device (V 1S ) and the hash of the message (M), the second private key of the electronic device (V 2S ) is determined. According to the following formula, this can be based on the scalar addition of the main private key of the electronic device (V 1S ) and the hash of the message (M):
[0163] V 2S = V 1S + SHA-256(M) (Equation 5)
[0164] At step 450, based on the main public key of the electronic device (P1S ) and the hash of the message (M) to determine the second electronic device public key (P 2S ). This can be determined according to the following formula:
[0165] P 2S = P 1S + SHA-256(M) × G (Formula 6)
[0166] In step 460, based on the master public key of the key device (P 1c ) and the hash of the message (M) to determine the second key device public key (P 2c ). This can be determined according to the following formula:
[0167] P 2c = P 1c + SHA-256(M) × G (Formula 7)
[0168] It should be noted that in this specific example of applying elliptic curve cryptography, "G" represents the generator, the operator "+" represents elliptic curve point addition, and the operator "×" represents elliptic curve point multiplication.
[0169] Furthermore, it should be noted that for the encryption of data, it may not be necessary to determine the second electronic device public key P 2S . As further detailed below, in order to determine the secret, the second electronic device public key P 2S may not be necessary.
[0170] Determine a secret 470
[0171] Then, the electronic device 3 can determine the secret in step 470 based on the determined second electronic device private key (V 2S ) and the determined second key device public key (P 2C ). According to the following formula, the secret can be determined by the electronic device 3:
[0172] CS = V 2S × P 2C (Formula 8)
[0173] Secret and encryption key
[0174] The secret can be used as a symmetric encryption key or as a basis for determining a symmetric encryption key.
[0175] In this specific example, the method 400 includes a further step 480: determining an encryption key (E) based on the determined secret. The encryption key (E) is also based on the serial number of the electronic device to ensure that the encryption key (E) is dedicated to the electronic device 3. The encryption key (E) is determined according to the following formula:
[0176] E = SHA256(SHA256(salt + secret) + serial number) (Equation 9)
[0177] where salt = message(M)
[0178] In this specific example, the concept of random salt is used to determine the encryption key (E). It should be understood that any suitable technique (if any) for calculating the encryption key (E) based on the determined secret can be used.
[0179] Method 400 also includes encrypting data at electronic device 3 using the determined encryption key (E) in step 490. It should be understood that any suitable method for encrypting data using the encryption key (E) can be used.
[0180] Importantly, electronic device 3 does not need to store the encryption key (E) or the secret, as it can be recalculated based on the message (M) stored on the data memory of key device 5.
[0181] Decryption of encrypted data
[0182] After encrypting the data at electronic device 3, the method of decrypting the encrypted data at electronic device 3 is described below with reference to Figure 4 and Figure 5 To decrypt the data, electronic device 3 recalculates the secret previously determined during data encryption.
[0183] At the beginning, electronic device 3 is connected to key device 5 for communication with each other. The step of connecting the respective devices 3, 5 may include determining whether the corresponding software running on the devices is compatible and synchronized.
[0184] Verify 500 key device 5
[0185] Before decrypting the encrypted data at electronic device 3, in this specific example, key device 5 is initially verified by electronic device 3.
[0186] The method 500 for verifying key device 5 is described below with reference to Figure 4 The method 500 for verifying key device 5 may be part of the data decryption cycle at electronic device 3.
[0187] Method 500 includes, in step 510, generating at electronic device 3 a verification message (M A ) that will be used to verify that key device 5 is key device 5. It should be understood that the generated message (M A ) can be used alone to verify key device 5. However, in some examples, the verification message (M A ) can form as described in reference Figure 3The message (M) is for the encryption process in the next encryption - decryption cycle.
[0188] Method 500 includes, at step 520, receiving a verification message (M A ) at the key device 5 from the electronic device 3 via Bluetooth 7.
[0189] Then, at step 530, the key device 5 determines a deterministic verification key (DK A ) based on the message (M A ). For example, the deterministic verification key (DK A ) can be the hash of the verification message, similar to step 430 of method 400, and can be determined according to the following formula:
[0190] DK A = SH A -256(M A )(Formula 10)
[0191] Then, the key device 5 determines a new asymmetric encryption pair based on the deterministic verification key (DK A ). Specifically in this example, method 500 includes determining a second key device private key V 2C at step 540 according to the following formula:
[0192] V 2C = V 1C + SHA - 256(M A )(Formula 11)
[0193] Method 500 also includes determining a second key device public key P 2C at step 550 according to the following formula.
[0194] P 2C = P 1C + SHA - 256(M A )×G(Formula 12)
[0195] Method 300 also includes, at step 560, generating a signature message (SM A ) based on the verification message (M 2C ) and the determined second key device private key (V A ). Generating the signature message includes applying a digital signature algorithm to digitally sign the verification message (M A ). In one example, this includes applying the second key device private key (V 2C ) to the message in the Elliptic Curve Digital Signature Algorithm (ECDSA) to obtain the signature message (SM A ). The verification message (M A ) can be signed according to the following formula:
[0196] SM A = Sig-V 2C <M A > (Formula 13)
[0197] Examples of ECDSA include ECDSA based on ECC systems with secp256k1, secp256r1, secp384r1, se3cp521r1.
[0198] Subsequently, at step 570, the signed verification message (SM A ) is sent to the electronic device 3 for verification of the key device 5.
[0199] Method 500 includes receiving, at step 580, the signed verification message (SM A ) from the key device 5. Then, at step 590, the electronic device 3 can authenticate the signature on the signed verification message (SM 2C ) by the second key device public key (P A ) determined at step 550.
[0200] The authentication of the digital signature can be accomplished according to the Elliptic Curve Digital Signature Algorithm (ECDSA). Importantly, the signed verification message (SM 2C ) signed by the second key device private key (V A ) should be correctly authenticated only by the corresponding second key device public key (P 2C ) because V 2C and P 2C form an encryption pair. Since these keys are deterministic with respect to the key device master private key (V 1C ) and the key device master public key (P 1C ) generated during key device registration, the authenticated signed verification message (SM A ) can be used as the basis for verifying that the so-called key device 5 that sent the signed message (SM A ) is the same key device 5 as the key device 5 during registration.
[0201] Recalculate encryption key (E) to decrypt encrypted data
[0202] After successfully verifying the key device 5, the electronic device 3 decrypts the encrypted data by recalculating the secret and thereby recalculating the encryption key (E). An exemplary method 600 for decrypting the encrypted data is described below with reference to Figure 5 Method 600 includes, at step 610, requesting the message (M) previously used and stored on the key device 5 during the encryption cycle, as described in step 420 of method 400.
[0203]
[0204] Then, method 600 includes receiving a message (M) at step 630. In this specific example, before the message (M) is sent to the electronic device 3, the key device 5 signs the message (M) using the second key device private key (V 2C ) at step 620. The message (M) is signed according to the following formula:
[0205] SM = Sig-V 2C <m>(Formula 14)
[0206] Method 600 further includes, at step 650, verifying the signed message (SM). This can be done by independently determining the second key device public key (P 2C ) and then applying the Elliptic Curve Digital Signature Algorithm (ECDSA) to the SM and P 2C . The second key device public key can be determined according to the following formula:
[0207] P 2C = P 1C + SHA-256(M) x G (Formula 15)
[0208] Then, method 600 includes, at step 660, retrieving the message (M) from the signed message (M) such that the electronic device 3 can recompute the secret at step 670 after steps 430 to 470, as referenced Figure 3 .
[0209] In a further step 680, the encryption key (E) is redetermined based on the secret and the serial number of the electronic device, as referenced in step 480 of method 400. Once the encryption key (E) is determined, the data can be decrypted at step 690.
[0210] It should be understood that, for decrypting encrypted data, the verification method referenced Figure 4 may not be necessary for some embodiments.
[0211] Processing device
[0212] As described above, the electronic device 3 and the key device 5 can be personal electronic devices, such as a laptop computer, a tablet computer, a mobile communication device, a computer server, and so on. The electronic device can include processing devices 23, 25, data memories 13, 15, and a user interface 14.
[0213] Figure 6 An example of processing devices 23 and 25 is shown. The processing devices 23 and 25 can be used in the electronic device 3 or the key device 5. The processing devices 23 and 25 include a processor 1510, a memory 1520, and an interface device 1540, which communicate with each other via a bus 1530. The memory 1520 stores instructions and data for implementing the above methods 200, 300, 400, 500, and 600, and the processor 1510 executes the instructions from the memory 1520 to implement the methods 200, 300, 400, 500, and 600. The interface device 1540 may include a communication module that facilitates communication with a communication network (such as Bluetooth 7) and, in some examples, facilitates communication with the user interface 14 and peripherals (such as data storage 13 and 15). It should be noted that although the processing device 1501 can be an independent network element, the processing device 1501 can also be a part of another network element. In addition, some of the functions performed by the processing device 1501 can be distributed among multiple network elements. For example, the electronic device 3 can have multiple processing devices 23 to perform a part of the methods 200, 400, and the methods 500, 600 in a secure local area network associated with the electronic device 3.
[0214] In cases where the present disclosure describes a user, issuer, merchant, vendor, or other entity performing a particular action (including signing, issuing, determining, calculating, sending, receiving, creating, etc.), this wording is used for clarity. It should be understood that these actions are performed by a computing device operated by these entities.
[0215] Signing may include performing an encryption function. This function has a plaintext input and a key input, such as a private key. The processor can execute this function to calculate a number or string that can be used as a signature. The signature is then provided together with the plaintext to provide a signed text. If the message text or the key changes by one bit, the signature changes completely. Although calculating the signature requires little computational power, it is practically impossible to recreate a message with a given signature. In this way, if the private key is available, only the plaintext can be changed and an effective signature can be attached. In addition, other entities can easily confirm the signature using the publicly available public key.
[0216] In most cases, encryption and decryption include a processor that performs an encryption function to calculate an output string representing an encrypted message or a plaintext message, respectively.
[0217] Keys, tokens, metadata, transactions, offers, contracts, signatures, scripts, metadata, invitations, etc. refer to binary data represented as numbers, texts, or strings stored in a data memory, such as variables of the "string" or "int" type or other types or program code in a text file.
[0218] When two items are associated, this indicates that there is a logical connection between these items. For example, in a database, the identifiers of two items can be stored in the same record to associate the two items with each other. In a transaction, the identifiers of two items can be included in a transaction string to associate the two items with each other.
[0219] Authorizing another entity can include calculating a signature string of a transaction using a private key and providing the signature string to the entity to allow the entity to confirm the transaction using the signature.
[0220] A user having an account with another entity can include an entity that stores information about the user, such as an email address, a name, and possibly a public key. For example, the entity can maintain a database, such as SQL, OrientDB, MongoDB, and so on. In some examples, the entity can also store one or more of the user's private keys.
[0221] Those skilled in the art should understand that various changes and / or modifications can be made to the above embodiments without departing from the broad general scope of the present disclosure. Therefore, the above embodiments should be considered illustrative rather than restrictive in all respects.< / m>
Claims
1. A computer-implemented method for encrypting data at an electronic device, the electronic device S being configured to communicate with a key device C, wherein, The electronic device is also associated with a first asymmetric encryption pair, and the key device is associated with a second asymmetric encryption pair, the first asymmetric encryption pair having a first electronic device private key V 1S and a first electronic device public key P 1S , the second asymmetric encryption pair having a first key device private key V 1C and a first key device public key P 1C , the method comprising: determine a deterministic key DK at the electronic device; Based at least on the first electronic device private key V 1S and the deterministic key DK, determine a second electronic device private key V at the electronic device 2S ; Determine a second key device public key P at the electronic device based at least on the first key device public key P 1C and the deterministic key DK 2C ; Based at least on the second electronic device private key V 2S and the second key device public key P 2C , determine a secret; encrypt the data at the electronic device using the determined secret or an encryption key based on the determined secret; send information indicating the deterministic key DK to the key device; Based at least on the first electronic device private key V 1S and the deterministic key DK, determine an updated second electronic device private key V at the electronic device 2S ; Determine, at the electronic device, an updated second key device public key P based at least on the first key device public key P 1C and the deterministic key DK 2C ; Based at least on the updated second electronic device private key V 2S and the updated second key device public key P 2C , determine the updated secret; and encrypt the data at the electronic device using the determined updated secret or an encryption key based on the determined updated secret.
2. The method according to claim 1, further comprising: store, at the key device, information indicating the deterministic key DK.
3. The method according to claim 1, wherein the deterministic key DK is based on a message M.
4. The method according to claim 3, comprising the steps of: generating the message M at the electronic device and determining the deterministic key DK based on determining a hash of the message M.
5. The method according to claim 1, comprising the step of: determining a second electronic device public key P based at least on the first electronic device public key P 1S and the deterministic key DK 2S .
6. The method according to claim 5, comprising: send a notification from the electronic device to the key device, the notification indicating the use of a public elliptic curve cryptography (ECC) system with a common generator G.
7. The method according to claim 6, wherein, The first electronic device public key P 1S and the first key device public key P 1C are based on elliptic curve point multiplications of the corresponding first electronic device private key V 1S and the first key device private key V 1C and the public generator G.
8. The method according to claim 6, comprising the steps of: generating the private key V of the first electronic device based on a random integer within an allowable range specified in the common ECC system 1S ; and based on the private key V of the first electronic device 1S and elliptic curve point multiplication of the common generator G, generating the public key P of the first electronic device according to the following formula 1S : P 1S = V 1S × G.
9. The method according to claim 6, comprising the steps of: based on the scalar addition of the private key V of the first electronic device 1S and the deterministic key DK, generating the private key V of the second electronic device according to the following formula 2S : V 2S = V 1S + DK.
10. The method according to claim 6, comprising the step of: generating the public key P of the second electronic device based at least on elliptic curve point addition of the public key P of the first electronic device 1S and the deterministic key DK. 2S .
11. The method according to claim 10, wherein, The public key P of the second electronic device 2S Based on the public key P of the first electronic device according to the following formula 1S And the elliptic curve point addition of the elliptic curve point multiplication of the deterministic key DK and the public generator G P 2S = P 1S + DK × G.
12. The method according to claim 6, comprising the step of: generating the second key device public key P based on elliptic curve point addition of at least the first key device public key P 1C and the deterministic key DK 2C .
13. The method according to claim 12, wherein, The public key P of the second key device 2C Based on the public key P of the first key device according to the following formula 1C And the elliptic curve point addition of the elliptic curve point multiplication of the deterministic key DK and the public generator G P 2C = P 1C + DK × G。 14. The method according to claim 1, comprising the step of: determining the encryption key based on the determined secret and identification information of the electronic device.
15. The method according to claim 1, comprising the step of storing the first key device public key P at a data memory associated with the electronic device 1C .
16. The method according to any one of claims 1-15, further comprising the step of: receive, at the electronic device, information from the key device, the information indicating the deterministic key DK; determine a secret based on the received information indicating the deterministic key DK; and decrypt the encrypted data at the electronic device using the secret or an encryption key based on the secret.
17. The method according to claim 16, comprising the step of: generating a verification message M at the electronic device A and sending the verification message M A to the key device.
18. The method according to claim 17, comprising the step of determining a deterministic verification key DK by determining a hash of the message M A A . 19. The method according to claim 18, comprising the step of generating, at the key device, a second asymmetric encryption pair having a second key device private key V 2C and a second key device public key P 2C .
20. The method according to claim 19, wherein, The private key V of the second key device 2C Based on the deterministic verification key DK A and the private key V of the first key device 1C , and the public key P of the second key device 2C Based on the deterministic verification key DK A and the public key P of the first key device 1C .
21. The method according to claim 20, comprising the steps of: Based on the deterministic verification key DK A and the second key device private key V 2C , a signature verification message SM A ; Receiving, at the electronic device, the signature verification message SM from the key device A ; and Verify the signature verification message SM by the public key P of the second key device 2C and verify the key device based on the result of verifying the signature verification message SM A ; and verify the key device based on the result of verifying the signature verification message SM A .
22. The method according to claim 3, comprising: request, at the electronic device, information indicating the deterministic key DK from the key device; generate a signed message SM at the key device based on the message M; send the signed message SM to the electronic device; authenticate the signed message SM at the electronic device; and retrieve the message M such that the secret for decrypting the data can be determined at the electronic device.
23. A computer system for encrypting data at an electronic device, the computer system comprising: An electronic device, associated with a first asymmetric encryption pair, the first asymmetric encryption pair having a first electronic device private key V 1S and a first electronic device public key P 1S , A key device, associated with a second asymmetric encryption pair having a first key device private key V 1C and a first key device public key P 1C , wherein the key device is configured to communicate with the electronic device; wherein the electronic device includes a processor configured to: determine a deterministic key DK; Determine the second electronic device private key V based at least on the first electronic device private key V 1S and the deterministic key DK 2S ; Determine a second key device public key P based at least on the first key device public key P 1C and the deterministic key DK 2C ; Based at least on the second electronic device private key V 2S and the second key device public key P 2C determine a secret; encrypt data on the electronic device using the determined secret or an encryption key based on the determined secret; Determine an updated second electronic device private key V based at least on the first electronic device private key V 1S and the deterministic key DK 2S ; Determine an updated second key device public key P 1C at least based on the first key device public key P 2C ; Based at least on the updated second electronic device private key V 2S and the updated second key device public key P 2C , determine the updated secret; and encrypt data on the electronic device using the determined updated secret or an encryption key based on the determined updated secret; wherein information indicating the deterministic key DK is stored in the key device.
24. The computer system according to claim 23 is further configured to decrypt data, and the processor of the electronic device is configured to: receive information indicating the deterministic key DK from the key device; determine the secret based on the information indicating the deterministic key DK; and decrypt the data by using the determined secret or an encryption key based on the determined secret.
25. An electronic device for encrypting data, the electronic device being configured to communicate with a key device, wherein the electronic device is associated with a first asymmetric encryption pair, and the key device is associated with a second asymmetric encryption pair, the first asymmetric encryption pair having a first electronic device private key V 1S and a first electronic device public key P 1S , the second asymmetric encryption pair having a first key device private key V 1C and a first key device public key P 1C , the electronic device including a processing device configured to: determine a deterministic key DK; Determine the private key V of the second electronic device based at least on the private key V of the first electronic device 1S and the deterministic key DK 2S ; Determine a second key device public key P based at least on the first key device public key P 1C and the deterministic key DK 2C ; Determine a secret based at least on the second electronic device private key V 2S and the second key device public key P 2C ; and encrypt the data on the electronic device by using the determined secret or an encryption key based on the determined secret; Determine an updated second electronic device private key V based at least on the first electronic device private key V 1S and the deterministic key DK 2S ; Determine an updated second key device public key P based at least on the first key device public key P 1C and the deterministic key DK 2C ; Based at least on the updated second electronic device private key V 2S and the updated second key device public key P 2C , determine an updated secret; and encrypt the data on the electronic device by using the determined updated secret or an encryption key based on the determined updated secret; wherein, information indicating the deterministic key DK is sent to the key device.
26. A computer-readable storage medium storing a computer program, wherein, the computer program includes machine-readable instructions for causing a processing device of an electronic device to implement the method according to any one of claims 1 to 22.
Citation Information
Patent Citations
Method and a device for securing access to wallets containing crypto-currencies
EP2975570A1
Authenticated key exchange with derived ephemeral keys
US20070055880A1
Implicit certificate verification
US20100023771A1
System and Method for Performing Device Authentication Using Key Agreement
US20120011362A1
Access Method and System for Cellular Mobile Communication Network
US20120100833A1