Systems and methods for preventing transmitted cryptographic parameters from compromising privacy
View Patent ↗A method for secure cryptographic communication comprises transmitting information that identifies a group key from a first device to a second device. The method further comprises, in the first device, using the group key to encrypt an input vector, transmitting the encrypted input vector, encrypting privacy-sensitive information using a device key, an encryption algorithm, and the input vector, and transmitting the encrypted privacy-sensitive information to the second device.
1. A method for secure cryptographic communication, comprising:
transmitting plain text information that can be used to reference a group key from a first device to a second device in a first transmission;
in the first device, using the group key to encrypt an input vector;
in the first device, transmitting the encrypted input vector in a second transmission;
in the first device, encrypting privacy-sensitive information using a device key, an encryption algorithm, and the input vector; and
in the first device, transmitting the encrypted privacy-sensitive information to the second device in a third transmission.
2. The method of claim 1 , wherein the group key is referenced by a tuple comprising privacy-insensitive information.
3. The method of claim 2 , wherein the privacy-insensitive information includes information related to an issuing authority and an expiration date.
4. An RFID device, comprising:
an antenna;
a memory configured to store information including a group key, information that can be used to reference the group key, an input vector, a device key and privacy-sensitive information; and
a processor coupled with the memory and the antenna, the processor configured to:
transmit the information in plain text that can be used to reference the group key stored in the memory via the antenna in a first transmission,
use the group key to encrypt an input vector,
transmit the encrypted input vector via the antenna in a second transmission,
encrypt the privacy-sensitive information stored in the memory using the device key, an encryption algorithm, and the input vector, and
transmit the encrypted privacy-sensitive information in a third transmission.
5. The RFID device of claim 4 , wherein the group key is referenced by a tuple comprising privacy-insensitive information.
6. The RFID device of claim 5 , wherein the privacy-insensitive information comprises information related to an issuing authority and an expiration date.
7. A communication system, comprising:
a first device comprising:
an antenna;
a memory configured to store information including a group key, information that can be used to reference the group key, an input vector, a device key and privacy-sensitive information, and
a processor coupled with the memory and the antenna, the processor configured to:
transmit in plain text the information that can be used to reference the group key stored in the memory via the antenna in a first transmission,
use the group key to encrypt an input vector,
transmit the encrypted input vector via the antenna in a second transmission,
encrypt the privacy-sensitive information stored in the memory using the device key, an encryption algorithm, and the input vector, and
transmit the encrypted privacy-sensitive information in a third transmission; and
a second device comprising:
an antenna, and
a processor coupled with the antenna, the processor configured to
receive the information that can be used to reference the group key in the first transmission via the antenna;
use the received information to reference the group key;
receive the encrypted input vector in the second transmission via the antenna;
receive the encrypted privacy-sensitive information in the third transmission via the antenna;
use the referenced group key to decrypt the input vector; and
use the decrypted input vector and the encryption algorithm to decrypt the privacy-sensitive information.
8. The system of claim 7 , wherein the group key is referenced by a tuple comprising privacy-insensitive information.
9. The system of claim 8 , wherein the privacy-insensitive information comprises information related to an issuing authority and an expiration date.