Authenticated Key Exchange with Receipt Confirmation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Recent research has shown that existing Authenticated Key Exchange (AKE) protocols such as MQV and ECMQV are not secure against impersonation attacks, highlighting a need for enhanced security measures in key exchange protocols.
Innovation Solution
Extended Authenticated Key Exchange with Key Confirmation (KEA+C and EC-KEA+C) protocols implement three communication passes to verify that both parties have received necessary information, using multiplicative groups of prime fields and elliptic curves to generate session keys based on identities and authenticate parties, ensuring secure key exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional AKE protocols (MQV, ECMQV) are used, then key exchange can be performed, but security against impersonation attacks is insufficient
Solution Approach 1:
The patent applies preliminary action by requiring parties to confirm receipt of key exchange information before generating session keys. The confirmation step is performed in advance of the actual key generation, ensuring that both parties have the necessary information before committing to the key exchange, thereby preventing impersonation attacks.
Solution Approach 2:
The patent implements feedback mechanisms where each party sends confirmation messages to the other party indicating whether they have successfully received the necessary information. This feedback loop allows parties to verify the state of the key exchange process and terminate if confirmation is not received, enhancing security against impersonation.
2Reliability
If key exchange information is sent without confirmation, then communication efficiency is maintained, but security against impersonation attacks deteriorates
Solution Approach 1:
The confirmation step is performed as a preliminary action before session key generation. By verifying information receipt in advance, the protocol prevents wasted computational effort on insecure key exchanges while maintaining efficiency through early termination when confirmations fail.
Solution Approach 2:
The patent performs an additional confirmation step beyond the traditional key exchange process. This partial extra action (confirmation message exchange) provides enhanced security while the overall protocol remains efficient by allowing early termination when confirmations are not received.
3Reliability
If session keys are generated without confirming information receipt, then protocol simplicity is maintained, but security assurance deteriorates
Solution Approach 1:
The confirmation of information receipt is performed as a preliminary action before session key generation. This ensures that both parties have the necessary information before committing to key generation, providing security assurance without significantly increasing protocol complexity.
Solution Approach 2:
The protocol incorporates feedback messages where parties confirm receipt of information. This feedback mechanism provides security assurance by verifying the state of the key exchange, while the feedback structure follows standard cryptographic patterns that minimize additional complexity.
Data Source
AI summary
Extended authenticated key exchange with key confirmation is described. In one aspect, and before computing session keys to exchange information securely between an initiator and a responder, each party of the initiator and the responder, confirms whether the other party has received corresponding information to generate a valid session key. If either party determines that the other respective party has not received the corresponding information, the party terminates the extended authenticated key exchange with key confirmation protocol. Otherwise, when a party determines that the other party has received the corresponding information, the party generates a respective session key. In this manner, when both parties confirm that the other party has received the appropriate information for session key generation, both parties are assured that information can be exchanged between the parties securely using the session keys.


