Fast Bilateral Key Confirmation via Elliptic Curve Scalar Multiplication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for creating secure communication channels between devices are often slow and inefficient, particularly in access control systems where fast and secure authentication is crucial for granting access to physical or logical assets.
Innovation Solution
The method involves transmitting nonces and identities between initiator and responder devices, using asymmetric key pairs and public key certificates, to establish a secure session key through a process of mutual key confirmation, enabling fast bilateral key confirmation with a low number of scalar multiplications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If traditional key confirmation methods are used, then security is maintained, but the authentication process becomes slow and inefficient
Solution Approach 1:
The patent changes the mathematical parameters of the key confirmation process by using elliptic curve cryptography with scalar multiplications. This allows the system to achieve fast bilateral key confirmation while maintaining security, resolving the contradiction between speed and reliability in authentication.
2Reliability
If more scalar multiplications are performed, then key confirmation security is enhanced, but the computation time increases
Solution Approach 1:
The patent applies partial action by performing a limited number of scalar multiplications (specifically 2 scalar multiplications per device) to achieve sufficient security for key confirmation. This partial approach provides adequate security without the excessive computation time that would result from performing more scalar multiplications, thus resolving the contradiction between security enhancement and time loss.
Data Source
AI summary
A method for creating a secure channel between devices for secure communication therebetween. The method comprises transmitting a first nonce from an initiator device to a responder device; receiving, at the initiator device, a second nonce and an identity of the responder device; transmitting an identity of the initiator device and a first set of one or more encrypted data objects from the initiator device to the responder device; receiving, at the initiator device, a second set of one or more encrypted data objects from the responder device; and generating, at the initiator device, a session key for secure communication between the initiator and responder devices.


