IP Library Granted Patent US 10,454,674
Granted Patent B1
US 10,454,674 · App. 14/726,618 · Granted Oct 22, 2019

System, method, and device of authenticated encryption of messages

Inventors: Hagai Bar-El (Rehovot, IL); Alexander Klimov (Hadera, IL)
Assignee: ARM LIMITED
H04L9/0861H04L9/0656H04L9/0869H04L9/3242H04L63/0428H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,674
App. No.
14/726,618
Granted
Oct 22, 2019
Kind
B1
Abstract

System, device, and method of authenticated encryption of messages. A message intended for authenticated encryption is stored; and a secret authentication key and a secret encryption key are stored. A key-stream set of blocks is generated, each block including pseudo-random bits. The aggregate length of the key-stream is equal to or greater than the message-length of the message. Each block of the key-stream is generated by a deterministic pseudo-random number generator function that is instantiated with the secret encryption key. The key-stream is generated on a block-by-block basis, until the key-stream reaches in aggregate the message-length of the message. Each block of bits of the message is encrypted, on a per-block basis, with a corresponding block from the key-stream. Authentication is performed on the result of the encrypting operation, or on the message, by applying a keyed cryptographic checksum function that ascertains integrity and that utilizes the secret authentication key.

Claims (21)

1. A method comprising:

(a) receiving at an electronic device an encrypted message that comprises: (i) a payload encrypted with a secret one-time key; and (ii) an outer integrity protection layer comprising a keyed cryptographic checksum generated by utilizing a secret key;

wherein said encrypted message is part of a group of encrypted messages that are intended for decryption;

wherein said encrypted message has a message-identifier;

wherein a secret cryptographic key is stored only in (I) said electronic device and in (II) an authorized server apparatus which sends said encrypted message to said electronic device;

wherein said secret cryptographic key comprises at least three concatenated sub-keys;

wherein a first sub-key of said secret cryptographic key is utilized by said authorized server for authenticated encryption of provisioning-messages that provision digital assets to said electronic device,

wherein a second sub-key of said secret cryptographic key is utilized by said authorized server for authenticated encryption of query-messages that query said electronic device,

wherein the third sub-key of said secret cryptographic key is utilized by said electronic device as an outer integrity protection layer to verify integrity of an encrypted message received at said electronic device without firstly decrypting the payload of said message;

(b) checking the keyed cryptographic checksum of the outer integrity protection layer of the message, against said third sub-key that is securely stored within said electronic device;

(c) if the checking result is negative, then: (i) aborting decryption of the payload of said message, and (ii) aborting cryptographic verification of said message; and (iii) avoiding utilization of a secret one-time key generated by said electronic device for decrypting said payload;

(d) if the checking result is positive, then: utilizing a one-time key generated by said electronic device, for decrypting said payload;

wherein the method comprises: protecting said recipient device from incoming fake messages, by checking at the recipient device, prior to attempting to decrypt a particular message, that an index number of said particular message is not a same index number of any other message that was received for decryption at said recipient device.

2. The method of claim 1 , wherein in step (c), the method further comprises:

if the checking result is negative, then: aborting any further cryptographic processing of said message.

3. The method of claim 1 , wherein in step (d), the method further comprises:

if the checking result is positive, then: recording within a storage of said electronic device, an indication that said one-time key is discarded and cannot be re-used for subsequent cryptographic operations by said electronic device.

4. The method of claim 1 , wherein the receiving of step (a) comprises:

receiving at the electronic device an encrypted message that comprises: (i) a payload encrypted with a secret one-time key; and (ii) an outer integrity protection layer comprising a keyed cryptographic checksum generated by utilizing a secret non-one-time key;

wherein the checking of step (b) comprises:

checking the keyed cryptographic checksum of the outer integrity protection layer of the message, against a non-one-time key that is generated by said electronic device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2017
From: ARM TECHNOLOGIES ISRAEL LIMITED
To: ARM LIMITED
Reel/Frame 043906/0343 →
CHANGE OF NAME Recorded Oct 4, 2015
From: DISCRETIX TECHNOLOGIES LTD.
To: ARM TECHNOLOGIES ISRAEL LTD.
Reel/Frame 036746/0538 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2015
From: BAR-EL, HAGAI; KLIMOV, ALEXANDER
To: DISCRETIX TECHNOLOGIES LTD.
Reel/Frame 035903/0543 →
Continuity (4)
Continuation In Part 14187275 · Feb 23, 2014
Continuation In Part 12947381 · Dec 9, 2010
Provisional Application 62006274 · Jun 2, 2014
Provisional Application 61272890 · Nov 16, 2009
Cited By (5)
US 12,225,115 US 12,244,685 US 12,418,516 US 12,585,778 US 12,634,121