Elliptic Curve Key Agreement Protocol for Secure Session Establishment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key agreement protocols for asymmetric cryptosystems face security flaws and performance issues, particularly in withstanding passive and active attacks, ensuring unique session keys, and maintaining forward secrecy, while also being computationally efficient.

Innovation Solution

A two-pass key agreement protocol that uses elliptic curve cryptosystems, where entities generate session private and public keys, combine these with identities to create a common value, and compute a shared secret using ephemeral values, ensuring implicit key authentication and efficient key establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key cryptosystems are used for key agreement, then security is improved through public/private key pairs, but computational efficiency deteriorates due to intensive mathematical operations

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The protocol performs preliminary actions by pre-generating static key pairs and pre-establishing trust relationships before the actual key agreement. This allows the computationally intensive elliptic curve operations to be minimized during the actual key exchange, improving efficiency while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key agreement protocol is segmented into multiple distinct phases: static key generation, ephemeral key generation, public key exchange, and shared secret computation. This segmentation allows each computational task to be optimized independently and performed only when necessary, reducing overall computational overhead

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional key agreement protocols are used, then key establishment is achieved, but security vulnerabilities increase due to susceptibility to passive and active attacks

Engineering Contradiction:
Improvekey establishmentVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The protocol applies preliminary anti-action by incorporating explicit key confirmation mechanisms that prevent man-in-the-middle attacks. Each party verifies the other's identity and the correctness of the shared secret before completing the key agreement, thereby counteracting potential attacks in advance

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The protocol implements feedback through mutual verification steps where each party confirms receipt and correctness of the other's public key and computed shared secret. This feedback mechanism ensures that any tampering or interception is detected, eliminating security vulnerabilities present in protocols lacking such verification

Inventive Principle:
Principle #23Feedback

3Productivity

If symmetric key cryptosystems are used, then processing speed is improved for large data quantities, but key distribution overhead increases and vulnerability to key compromise increases

Engineering Contradiction:
Improveprocessing speedVSAvoidkey distribution overhead
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The protocol merges the advantages of both symmetric and asymmetric cryptosystems by using asymmetric cryptography (elliptic curve) only for the key agreement phase, then transitioning to symmetric cryptography for actual data encryption. This combination achieves fast processing speeds while minimizing key distribution overhead, as only one asymmetric key pair needs to be exchanged rather than multiple symmetric keys

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9571274B2Key agreement protocol
Publication Date: 2017.02.14 INFOSEC GLOBAL
  • US9571274B2 patent drawing
  • US9571274B2 patent drawing
  • US9571274B2 patent drawing

AI summary

The present invention relates to data communication systems and protocols utilized in such systems.