System and method for key amplification

The key amplification method enhances cryptographic key exchange by generating a set of high-entropy keys using shared secrets and system identifiers, addressing security and exchange rate challenges in quantum computing environments.

JP2026524903APending Publication Date: 2026-07-24ANGOKA LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
ANGOKA LTD
Filing Date
2024-07-02
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing cryptographic key exchange methods, particularly in the context of quantum computing, face challenges in maintaining key security and entropy due to potential attacks and reduced key exchange rates, especially in optical links.

Method used

A method and system for key amplification involving systems that generate and share random numbers, nonces, and keys using shared secrets and system identifiers, employing encryption and derivation functions to create a set of high-entropy keys, enhancing security and exchange rates.

Benefits of technology

The method increases the effective key exchange rate while preserving key entropy, effectively generating a set of high-entropy keys resistant to attacks, including replay attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026524903000001_ABST
    Figure 2026524903000001_ABST
Patent Text Reader

Abstract

A method for key amplification by a first and second system in a network having a key to be amplified, a shared secret, shared first system identification information, shared second system identification information, a shared first key, and a shared second key is provided. Each system (i) generates a new random number and creates a combination of the new random number and the shared first key, (ii) generates a shared nonce derived from each system identification information using a predetermined shared process, (iii) generates a shared key using a predetermined shared process and encrypts the combination using the shared nonce with the shared key, (iv) receives the encrypted combination from the other system, (v) decrypts the encrypted combination using the shared nonce with the shared key to obtain the combination, (vi) generates a key for a set of keys which is a function of the first system's combination, the second system's combination, the shared second key, and the shared secret, and (vii) repeats (i) to (vi) to generate further keys for a set of keys which include amplification of the key to be amplified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to systems and methods for key amplification, and more particularly, but not limited to, systems and methods for quantum key amplification, where amplification refers to the process of using a key to generate a set of keys.

Background Art

[0002] Keys are essential tools in the field of cryptography and are used to encrypt and decrypt information sent from one party to another. Cryptographic keys often contain bit sequences and can be of different lengths. When a key is used for encryption, the strength of the encryption will depend on the security of the key. The security of the key can be influenced by several aspects of the key, such as the process of key generation, the exchange of keys for encryption and decryption, and the length of the key.

[0003] If the key should not be easily guessed, key generation needs to involve some random processes, such as the use of a random number generator. Key generation should achieve a high entropy of the key, i.e., unpredictability.

[0004] The process of key exchange between entities should preferably be through a protected communication channel that is not accessible by external entities. However, there are many types of attacks by external entities, and the security of the key during exchange may not be guaranteed. This is especially true in the case of quantum computing.

[0005] However, methods for key exchange that are not easily affected by attacks by quantum computers have been developed. One such method is Quantum Key Distribution (QKD). However, QKD depends on optical links and may be troubled by a reduction in the key exchange rate due to the optical medium.

Summary of the Invention

[0006] There is a constant search for ways to increase the security or entropy of cryptographic keys. [Means for solving the problem]

[0007] According to the first aspect, a method for key amplification by a first system and a second system of a network is provided, comprising a key to be amplified, a shared secret, a shared first system identity, a shared second system identity, a shared first key, and a shared second key. (i) Each system generates a new random number and creates a combination of the random number and the shared first key, (ii) Each system generates a shared nonce derived from at least each system identification information using a predetermined shared process, (iii) Each system generates a shared key using a predetermined shared process and uses the shared key to encrypt the combination using a shared nonce, (iv) Each system receives an encrypted combination from another system, (v) Each system uses a shared key to decrypt the encrypted combination using a shared nonce to obtain the combination, (vi) Each system generates a key of a set of keys, which is a combination of the first systems, a combination of the second systems, a shared second key, and a shared secret function. (vii) Each system repeats steps (i) through (vi) a predetermined number of times to generate further keys for a set of keys, including the amplification of the key to be amplified. Includes.

[0008] The first system and the second system may share a secret by configuring each of the first and second systems using a shared secret. Configuring each of the first and second systems using a shared secret may include delivering the secret to the first and second systems in a secure environment.

[0009] This method may include the step of each system encrypting a secret using an encryption algorithm and a system identifier as a key. The encryption algorithm may include a symmetric-key encryption algorithm. The symmetric-key encryption algorithm may be used in conjunction with one or more hash functions. The system identifier may be an immutable identifier of the system. The system identifier may include one or more physical characteristics of the system, one or more software signatures, or a fingerprint of the system's physically unclonable function (PUF). This method may include each system storing the encrypted secret in the system's secure memory.

[0010] The first system and the second system may share the first system identification information and the second system identification information by configuring each of the first and second systems using the first system identification information and the second system identification information. Configuring each of the first and second systems using the first system identification information and the second system identification information may include delivering the first system identification information and the second system identification information to the first and second systems in a secure environment.

[0011] Each system may store the system identification information of other systems in secure memory.

[0012] For each system, system identification information may identify the system within the network. For each system, system identification information may also include system characteristics. These characteristics may be either physical characteristics of the system or configuration characteristics of the system. Physical characteristics of the system may include the fingerprint of the system's PUF. Configuration characteristics of the system may include one or more identifiers of one or more components of the system. These identifiers may include the system's MAC address, the system's gateway serial number identifier, or the system's transceiver serial number identifier.

[0013] For each system, the system identifier may include challenge-response pairs from a table of challenge-response pairs for the PUF of other systems. The table may be stored in secure memory. The first system may send a randomly selected challenge to the PUF of the second system and verify the second system's response against the table of challenge-response pairs. The second system may send a randomly selected challenge to the PUF of the first system and verify the first system's response against the table of challenge-response pairs.

[0014] The first and second systems may connect to a key repository configured to hold one or more keys, and may retrieve a key to be amplified from the key repository. The key to be amplified may be a high-entropy key. The key to be amplified may be generated using a quantum key distribution (QKD) process.

[0015] Each of the first and second systems may share a first key by deriving it from a key to be amplified using a predetermined algorithm. The first key may include a subset of the key to be amplified. The predetermined algorithm may include selecting a subset of the key to be amplified, for example, by selecting some predetermined bits by applying a mask. The algorithm may further include operations performed on the predetermined bits, including predetermined substitution of the predetermined bits, a hash function on the predetermined bits, or addition or multiplication of the predetermined bits by a predetermined constant.

[0016] Each of the first and second systems may share a second key by deriving the second key from the key to be amplified using a predetermined algorithm. The second key may include a subset of the key to be amplified. The first and second keys may be disparate subsets of the key to be amplified. The predetermined algorithm may include selecting a subset of the key to be amplified, for example, by applying a mask to select some predetermined bits. The algorithm may further include an operation performed on the predetermined bits, which may include a predetermined substitution of the predetermined bits, a hash function on the predetermined bits, or adding or multiplying the predetermined bits by a predetermined constant. The predetermined bits, mask, operation performed on the predetermined bits, predetermined substitution, hash function, and predetermined constant are different from those used for the first key.

[0017] Each system generating a new random number may include the first system generating a new random number for the first system using its random number generator, and the second system generating a new random number for the second system using its random number generator.

[0018] Each system's creation of a new random number and a shared first key may include creating a number that is a function of the new random number and the shared first key. The function may be a SHA-256 hash function. The function may be a derivation function that includes either a hash derivation function or a block cipher derivation function. The function may be chosen to maximize the entropy of the random number and shared first key combination.

[0019] Each system generates a shared nonce derived from its system identifier using a predetermined shared process, which may include combining the value of a repeating marker, which changes with each iteration, with the system identifier. The value of the repeating marker may be a counter value or a timestamp value. In this way, each system generates a new nonce in each iteration, and the nonce is not reused. Since each system's nonce is generated using the changing value of the repeating marker, an element of novelty is introduced to each iteration of the step. This helps prevent replay attacks on the first and second systems.

[0020] Each system may use a predetermined shared process to generate a shared nonce derived from its system identification information, which may include combining the system identification information with a repeating marker value that changes with each iteration and one or more parameters that are the same across systems. Combining the system identification information with a repeating marker value that changes with each iteration and one or more parameters that are the same across systems may also include concatenating the system identification information with a repeating marker value that changes with each iteration and one or more parameters that are the same across systems. One or more parameters may include network identification information or a protocol name.

[0021] The generation of a shared key by each system using a predetermined shared process may include generating the shared key using a key derivation function that is a function of a shared secret and a shared second key. The key derivation function may include any of the HMAC-SHA256 function, the KMAC function, the CMAC function, the PBKDF2 function. The key derivation function is used for the shared second key, and the shared second key is a subset of the keys to be amplified that is different from the shared first key subset of the keys to be amplified. Since the shared first key has already been used in a function that combines a random number and the shared first key, this helps to prevent information leakage.

[0022] Each system encrypting the combination using the shared nonce with the shared key may include using a standard symmetric encryption algorithm. The standard symmetric algorithm may include AES-CCM.

[0023] Each system generating the key of the set of keys using the combination of the first system, the combination of the second system, the shared second key, and the shared secret may include generating the key using a key derivation function. The key derivation function may be either hash-based or password-based. The key derivation function may include any of HKDF, scrypt, argon2, PBKDF.

[0024] In addition, a compression function may be applied to the key. The compression function may include any of a leftover hashing function, Trevisan's extractor function, a strong blender function.

[0025] Applying the compression function applies privacy amplification to the key.

[0026] Each system may repeat steps (i) to (vi) a predetermined number of times to generate a set of keys. The process of proceeding from the key to the set of keys is the amplification of the key to be amplified.

[0027] In the method step, shared system identification information, a shared secret, and a shared key are all used to exchange encrypted random numbers. Only when all three are known can the random numbers be correctly decrypted and used to create a set of keys to be shared between systems. The total length of the key set is increased by inserting random numbers in a specific way that preserves or improves the randomness of the keys.

[0028] The key amplification method acquires relatively small keys from a key repository and generates a set of keys with a total length exceeding the length of the original keys, thereby increasing the effective key exchange rate between the first and second systems while preserving the entropy of the keys. This method can generate a set of high-entropy keys.

[0029] According to the second aspect, a first key amplification system and a second key amplification system for a network are provided, each having a key to be amplified, a shared secret, a shared first system identification information, a shared second system identification information, a shared first key, and a shared second key, and each system is A random number generator configured to generate random numbers, A combinatorial engine configured to generate combinations of random numbers and a shared first key, A nonce generator configured to generate a shared nonce derived from at least each system identification information, A key generator configured to generate a shared key, A cryptographic module configured to encrypt combinations using a shared key and a shared nonce, A transceiver configured to send encrypted combinations to other systems and receive encrypted combinations from other systems, A cryptographic module configured to use a shared key to decrypt an encrypted combination using a shared nonce of another system to obtain the combination, A key generator configured to generate a key which is a combination of the first system, a combination of the second system, a shared second key, and a shared secret function. Includes, The first and second systems repeatedly generate keys that form a set of keys, which are amplifications of the keys to be amplified.

[0030] The first and second key amplification systems may be configured using a shared secret. Configuring each of the first and second key amplification systems using a shared secret may include delivering the secret to the first and second systems in a secure environment.

[0031] Each cryptographic module of the first and second key amplification systems may encrypt secrets using an encryption algorithm and a system identifier as keys. The encryption algorithm may include a symmetric key encryption algorithm. The symmetric key encryption algorithm may be used in conjunction with one or more hash functions. The system identifier may be an immutable identifier of the system. The system identifier may include one or more physical characteristics of the system, one or more software signatures, or a fingerprint of the system's physically hard-to-copy function (PUF). Each of the first and second key amplification systems may include memory. The encrypted secrets may be stored in the memory of each system.

[0032] The first and second key amplification systems may be configured using the first system identification information and the second system identification information. Configuring each of the first and second key amplification systems using the first and second system identification information may include delivering the first and second system identification information to the first and second systems in a secure environment. The system identification information may be stored in the memory of each system.

[0033] For each key amplification system, system identification information may identify the system within the network. For each key amplification system, system identification information may also include the system's physical characteristics. The first and second key amplification systems may include a PUF (Positive Unit of Function). For each system, the system's physical characteristics may include a fingerprint of the system's PUF.

[0034] For each key amplification system, the system identification information may include the system's configuration characteristics. For each key amplification system, the configuration characteristics may include one or more identifiers of one or more components of the system. The identifiers may include the system's MAC address, the system's gateway's serial number identifier, or the system's transceiver's serial number identifier.

[0035] For each key amplification system, the system identifier may include challenge-response pairs from a table of challenge-response pairs for the PUF of other systems. The table may be stored in secure memory. The first key amplification system may send a randomly selected challenge to the PUF of the second key amplification system and verify the response of the second key amplification system by comparing it against the table of challenge-response pairs. The second key amplification system may send a randomly selected challenge to the PUF of the first key amplification system and verify the response of the first key amplification system by comparing it against the table of challenge-response pairs.

[0036] Each transceiver of the first and second key amplification systems may be connected to a key repository configured to hold one or more keys, and may be configured to retrieve the key to be amplified from the key repository. The key to be amplified may be a high-entropy key. The key to be amplified may be generated using a quantum key distribution (QKD) process.

[0037] Each key generator of the first and second key amplification systems may be configured to use a predetermined algorithm to derive a first key from the key to be amplified. The first key may include a subset of the key to be amplified. The predetermined algorithm may include selecting a subset of the key to be amplified, for example, by selecting some predetermined bits by applying a mask. The algorithm may further include operations performed on the predetermined bits, including predetermined substitution of the predetermined bits, a hash function on the predetermined bits, or addition or multiplication of the predetermined bits by a predetermined constant.

[0038] Each key generator of the first and second systems may be configured to use a predetermined algorithm to derive a second key from the key to be amplified. The second key may include a subset of the key to be amplified. The first and second keys may be disparate subsets of the key to be amplified. The predetermined algorithm may include selecting a subset of the key to be amplified, for example, by selecting some predetermined bits by applying a mask. The algorithm may further include an operation performed on the predetermined bits, which may include a predetermined substitution of the predetermined bits, a hash function on the predetermined bits, or adding or multiplying the predetermined bits by a predetermined constant. The predetermined bits, mask, operation performed on the predetermined bits, predetermined substitution, hash function, and predetermined constant are different from those used for the first key.

[0039] Each combinatorial engine of the first and second key amplification systems may be configured to generate combinations of random numbers and the shared first key by generating a number that is a function of the random number and the shared first key. The function may be a SHA-256 hash function. The function may be a derivation function that includes either a hash derivation function or a block cipher derivation function. The function may be chosen to maximize the entropy of the mixture of random numbers and the shared first key.

[0040] Each nonce generator in the first and second key amplification systems may be configured to generate a shared nonce derived from each system identifier using a predetermined shared process, and to combine the repeating marker value, which changes with each iteration, with each system identifier. The repeating marker value may be a counter value or a timestamp value. In this way, in each iteration, each system generates a new nonce, and the nonce is not reused. Since each system's nonce is generated using the changing value of the repeating marker, an element of novelty is introduced to each iteration of the step. This helps prevent replay attacks on the first and second systems.

[0041] Each nonce generator of the first and second key amplification systems may be configured to use a predetermined shared process to generate a shared nonce derived from each system identifier, and to combine each system identifier with a repeating marker value that changes with each iteration and one or more parameters that are the same in each system. Combining each system identifier with a repeating marker value that changes with each iteration and one or more parameters that are the same in each system may include concatenating each system identifier with a repeating marker value that changes with each iteration and one or more parameters that are the same in each system. One or more parameters may include network identifier information or a protocol name.

[0042] Each key generator of the first and second key amplification systems may be configured to generate a shared key by using a key derivation function which is a function of the shared secret and the shared second key. The key derivation function may include any of the HMAC-SHA256 function, KMAC function, CMAC function, or PBKDF2 function.

[0043] Each cryptographic module of the first and second key amplification systems may be configured to encrypt combinations using a shared nonce with a shared key by employing a standard symmetric encryption algorithm. A standard symmetric algorithm may include AES-CCM.

[0044] Each key generator of the first and second key amplification systems may be configured to use a key derivation function to generate each key in the key set using the combination of the first system, the combination of the second system, a shared second key, and a shared secret. The key derivation function may be hash-based or password-based. The key derivation function may include HKDF, scrypt, argon2, or PBKDF.

[0045] Each key generator of the first and second key amplification systems may be configured to apply a compression function to each key in the key set. The compression function may include a residual hash function, a Trevisan extractor function, or a strong blender function.

[0046] Next, embodiments of the present invention will be described as merely examples, with reference to the attached drawings. [Brief explanation of the drawing]

[0047] [Figure 1] This is a schematic diagram of the first key amplification system and the second key amplification system according to the second embodiment. [Figure 2] This is a flowchart of the key amplification method according to the first embodiment. [Modes for carrying out the invention]

[0048] Referring to Figure 1, the first key amplification system 1 comprises a random number generator 3, a combinatorial engine 5, a nonce generator 7, a key generator 9, a cryptographic module 11, a transceiver 13, a memory 15, and a PUF 17. The second key amplification system 21 comprises a random number generator 23, a combinatorial engine 25, a nonce generator 27, a key generator 29, a cryptographic module 31, a transceiver 33, a memory 35, and a PUF 37. The first and second key amplification systems 1 and 21 are part of a network. It will be understood that other key amplification systems may be included in the network. A key amplification system may include network devices, such as a gateway device or any server connected to the network.

[0049] The first and second key amplification systems 1 and 21 each have a key to be amplified, a shared secret, shared first system identification information, shared second system identification information, a shared first key, and a shared second key.

[0050] The first and second key amplification systems 1 and 21 are configured to deliver secrets to the system in a secure environment using a shared secret.

[0051] Each cryptographic module 11, 31 of the first and second key amplification systems 1, 21 encrypts the shared secret using the encryption algorithm and system identifier as the key. In this embodiment, the identifier of each key amplification system 1, 21 includes the fingerprint of the system's PUF 17, 37. The encrypted secret is stored in the memories 15, 35 of each system 1, 21.

[0052] The first and second key amplification systems 1 and 21 are configured to deliver the first and second system identification information to the system in a secure environment using the first and second system identification information. The system identification information is stored in the memories 15 and 35 of each key amplification system 1 and 21. In this embodiment, the system identification information includes the fingerprints of the PUFs 17 and 37 of systems 1 and 21.

[0053] Each transceiver 13, 33 of the first and second key amplification systems 1, 21 is connected to a key repository (not shown) configured to hold one or more keys, and is configured to retrieve a key q to be amplified from the key repository.

[0054] The key generators 9 and 29 of the first and second key amplification systems 1 and 21, respectively, are configured to use a predetermined algorithm to derive a first key q' from key q. The predetermined algorithm may include selecting a subset of key q to be amplified, for example, by selecting some predetermined bits by applying a mask. The algorithm may further include operations performed on the predetermined bits, including predetermined substitution of the predetermined bits, a hash function on the predetermined bits, or addition or multiplication of the predetermined bits by a predetermined constant.

[0055] The key generators 9 and 29 of the first and second key amplification systems 1 and 21, respectively, are configured to use a predetermined algorithm to derive a second key q'' from key q. The first key q' and the second key q'' each contain a subset of key q to be amplified. The predetermined algorithm may include selecting a subset of key q to be amplified, for example, by applying a mask to select some predetermined bits. The algorithm may further include operations performed on the predetermined bits, including predetermined substitution of the predetermined bits, a hash function on the predetermined bits, or adding or multiplying the predetermined bits by a predetermined constant. The predetermined bits, mask, operations performed on the predetermined bits, predetermined substitution, hash function, and predetermined constant are different from those used for the first key.

[0056] Referring to Figure 2, the iteration of the key amplification method performed by the first and second key amplification systems 1 and 21 to generate a set of keys is illustrated.

[0057] In each iteration, each key amplification system 1, 21 generates a new random number. The random number generators 3, 23 of each system 1, 21 are configured to generate a new random number.

[0058] In each iteration, each key amplification system 1, 21 generates a combination of a random number and a shared first key q'. The combination engines 5, 25 of each system 1, 21 are configured to generate a combination of a random number and a shared first key q'. In this embodiment, this involves generating a number that is a function of the random number and the shared first key q'. The function may be a SHA-256 hash function. The function may be a derivation function that includes either a hash derivation function or a block cipher derivation function.

[0059] In each iteration, each key amplification system generates a shared nonce derived from system identification information. In this embodiment, the nonce generators 7, 27 of each system 1, 21 are configured to use a predetermined shared process to generate a shared nonce derived from each system identification information, combining each system identification information with a repeating marker value that changes with each iteration and one or more parameters that are the same in each system. The repeating marker value may be a counter value or a timestamp value. In this way, in each iteration, each system generates a new nonce, and the nonce is not reused. Since the nonce of each system is generated using the changing value of the repeating marker, an element of novelty is introduced to each iteration of the step. This helps prevent replay attacks on the first and second systems. Combining each system identification information with a repeating marker value that changes with each iteration and one or more parameters that are the same in each system may include concatenating each system identification information with a repeating marker value that changes with each iteration and one or more parameters that are the same in each system. One or more parameters may include network identification information or a protocol name.

[0060] In each iteration, each key amplification system 1, 21 generates a shared key. The key generators 9, 29 of each system 1, 21 are configured to generate a shared key. Each shared key is generated by using a predetermined sharing process, which involves generating the shared key using a key derivation function K, which is a function of the shared secret and the shared second key. The key derivation function K may include any of the HMAC-SHA256 function, KMAC function, CMAC function, or PBKDF2 function.

[0061] In each iteration, each key amplification system 1, 21 uses a shared key to encrypt the combination using a shared nonce. The cryptographic modules 11, 31 of each system 1, 21 are configured to use the shared key to encrypt the combination using a shared nonce. Standard symmetric encryption algorithms such as AES-CCM are used.

[0062] In each iteration, each key amplification system 1, 21 receives an encrypted combination from the other system. The transceivers 13, 33 of each system 1, 21 are configured to send an encrypted combination to the other system and to receive an encrypted combination from the other system.

[0063] In each iteration, the cryptographic modules 11 and 31 of each key amplification system 1 and 21 use the shared key to decrypt the encrypted combination using the shared nonce and obtain the combination.

[0064] In each iteration, each key amplification system 1, 21 generates a key which is a combination of the first system, a combination of the second system, a shared second key q'', and a shared secret function. The key generators 9, 19 of each system 1, 21 are configured to generate a key using a key derivation function. The key derivation function may be hash-based or password-based. The key derivation function may include HKDF, scrypt, argon2, or PBKDF.

[0065] In each iteration, a compression function may also be applied to the key. The compression function may include a residual hash function, a Trevisan extractor function, or a strong blender function. Using a compression function applies privacy amplification to the key.

[0066] When each key amplification system 1, 21 repeats the step a predetermined number of times, a set of keys is generated that includes amplification of the key q to be amplified. This creates a set of keys from the key q to be amplified, thereby amplifying the key q. [Explanation of Symbols]

[0067] 1. First Key Amplification System 3. Random number generator 5 Combination Engines 7. Nance Generator 9 Key generator 11 Cryptographic Modules 13 Transceivers 15 memory 17 PUF 21. Second Key Amplification System 23 Random number generator 25 Combination Engines 27. Nance Generator 29 Key generator 31 Cryptographic Modules 33 transceivers 35 memory 37 PUF

Claims

1. A method for amplifying keys by a first system and a second system of a network, comprising a key to be amplified, a shared secret, a shared first system identification information, a shared second system identification information, a shared first key, and a shared second key, (i) Each system generates a new random number and creates a combination of the new random number and the shared first key, (ii) Each system generates a shared nonce derived from at least each system identification information using a predetermined shared process, (iii) Each system generates a shared key using a predetermined shared process and uses the shared key to encrypt the combination using the shared nonce, (iv) Each system receives the encrypted combination from the other systems, (v) Each system uses the shared key to decrypt the encrypted combination using the shared nonce to obtain the combination, (vi) each system generates a key for a set of keys, the combination of the first system, the combination of the second system, the shared second key, and the shared secret function, (vii) Each system repeats steps (i) through (vi) a predetermined number of times to generate further keys for the set of keys, including the amplification of the key to be amplified. Methods that include...

2. The method according to claim 1, wherein the first system and the second system share the secret by configuring each of the first and second systems using the shared secret in a secure environment.

3. The method according to claim 1 or 2, wherein each system includes the step of encrypting the secret using an encryption algorithm and an identifier of the system as a key, the identifier of the system including one or more physical characteristics of the system, one or more software signatures, or a fingerprint of the physically hard-to-copy function (PUF) of the system.

4. The method according to any one of claims 1 to 3, wherein the first system and the second system share the first system identification information and the second system identification information by configuring each of the first and second systems using the first system identification information and the second system identification information in a secure environment.

5. The method according to any one of claims 1 to 4, wherein the first system and the second system are connected to a key repository configured to hold one or more keys, and the key to be amplified is retrieved from the key repository.

6. The method according to any one of claims 1 to 5, wherein each of the first and second systems shares the first key by deriving the first key from the key to be amplified using a predetermined algorithm, and shares the second key by deriving the second key from the key to be amplified using a predetermined algorithm.

7. The method according to any one of claims 1 to 6, wherein the shared first key is a subset of the key to be amplified, and the shared second key is a subset of the key to be amplified.

8. The method according to any one of claims 1 to 7, wherein the step of each system creating a combination of the new random number and the shared first key includes the step of creating a number that is a function of the random number and the shared first key.

9. The method according to any one of claims 1 to 8, wherein each system generates a shared nonce derived from at least each system identification information by combining a repeating marker value that changes with each iteration with each system identification information using a predetermined shared process.

10. The method according to claim 9, wherein each system generates the shared nonce derived from at least each system identification information by combining the value of the repetition marker which changes with each iteration and one or more parameters which are the same for each system with each system identification information, using the predetermined shared process.

11. The method according to any one of claims 1 to 10, wherein in each iteration, each system uses the predetermined shared process to generate the shared nonce derived from at least each system identification information, and the iteration marker value which changes with each iteration.

12. The method according to any one of claims 1 to 11, wherein each system generates the shared key using the predetermined sharing process and a key derivation function which is a function of the shared secret and the shared second key.

13. The method according to any one of claims 1 to 12, wherein each system generates a key for the set of keys using the combination of the first system, the combination of the second system, the shared second key, and the shared secret, the step of generating the key using a key derivation function.

14. The method according to claim 13, wherein the compression function is applied to the keys of the set of keys.

15. A first key amplification system and a second key amplification system for a network, each having a key to be amplified, a shared secret, a shared first system identification information, a shared second system identification information, a shared first key, and a shared second key, wherein each system A random number generator configured to generate random numbers, A combinatorial engine configured to create a combination of the aforementioned random number and the aforementioned shared first key, A nonce generator configured to generate a shared nonce derived from at least each system identification information, A key generator configured to generate a shared key, A cryptographic module configured to encrypt the combination using the shared nonce with the shared key, A transceiver configured to send encrypted combinations to other systems and receive encrypted combinations from other systems, The cryptographic module is configured to use the shared key to decrypt the encrypted combination using the shared nonce of the other system and obtain the combination, The combination of the first system, the combination of the second system, the shared second key, and the key generator configured to generate the key which is the shared secret function. The first and second systems repeatedly generate keys that form a set of keys which are amplifications of the key to be amplified. A first key amplification system and a second key amplification system for the network.