IP Library › Granted Patent US 11,711,207
Granted Patent B2
US 11,711,207 · App. 17/216,807 · Granted Jul 25, 2023

Quantum safe key exchange scheme

Inventors: Richard Victor Kisley (Charlotte, NC); Michael Miele (Concord, NC); Elizabeth Anne Dames (Harrisburg, NC); Silvio Dragone (Olten, CH)
Assignee: International Business Machines Corporation
H04L9/0841H04L9/0656H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,207
App. No.
17/216,807
Filed
Mar 30, 2021
Granted
Jul 25, 2023
Kind
B2
Art Unit
2495
USPC
713/171
Abstract

Aspects of the invention include a computer-implemented method of executing a hybrid quantum safe key exchange system. The computer-implemented method includes initially retrieving an authenticated random value from a trusted source, generating a first Z value using a first elliptic curve (EC) private key and a first certified form of an EC public key with an EC Diffie-Hellman (ECDH) algorithm, deriving a shared key using the authenticated random value and the first Z value with a key derivation function, decrypting the authenticated random value using a quantum safe algorithm (QSA) private key, generating a second Z value using a second EC private key and a second certified form of the EC public key with the ECDH algorithm and deriving the shared key using the authenticated random value and the second Z value with the key derivation function.

Claims (29)

1. A computer-implemented method of executing a hybrid quantum safe key exchange system, the computer-implemented method comprising:

generating a quantum safe algorithm (QSA) key pair for key encryption management and first and second elliptic curve cryptography (ECC) key pairs for key agreement;

generating a random value;

generating a first Z value using a private key of the first ECC key pair and a certified form of a public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm;

deriving a shared key using the random value and the first Z value with a key derivation function;

encrypting the random value using a public key of the QSA key pair to produce an encrypted random value;

decrypting the encrypted random value using a private key of the QSA key pair to produce the random value;

generating a second Z value using a private key of the second ECC key pair and a certified form of a public key of the first ECC key pair with the ECDH algorithm; and

deriving the shared key using the random value produced by the decrypting and the second Z value with the key derivation function.

2. The computer-implemented method according to claim 1 , wherein the generating of the random value at the trusted source, the generating of the first Z value using the private key of the first ECC key pair and the certified form of the public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm, the deriving of the shared key using the random value and the first Z value with the key derivation function and the encrypting of the random value using the public key of the QSA key pair to produce the encrypted random value are executed separately from the decrypting of the encrypted random value using the private key of the QSA key pair to produce the random value, the generating of the second Z value using the private key of the second ECC key pair and the certified form of the public key of the first key pair with the ECDH algorithm and the deriving of the shared key using the random value produced by the decrypting and the second Z value with the key derivation function are executed at a second computer.

3. The computer-implemented method according to claim 1 , wherein:

the encrypting of the random value comprises a call of a first cryptographic architecture (CA) programming interface, and

each instance of the deriving of the shared key comprises a call of a second CA programming interface.

4. The computer-implemented method according to claim 1 , wherein the key derivation function comprises hashing.

5. A computer program product for executing a hybrid quantum safe key exchange system, the computer program product comprising:

a computer-readable medium having program instructions embodied therewith, the program instructions being readable by a processing system to cause the processing system to execute a method comprising:

generating a quantum safe algorithm (QSA) key pair for key encryption management and first and second elliptic curve cryptography (ECC) key pairs for key agreement;

generating a random value;

generating a first Z value using a private key of the first ECC key pair and a certified form of a public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm;

deriving a shared key using the random value and the first Z value with a key derivation function;

encrypting the random value using a public key of the QSA key pair to produce an encrypted random value;

decrypting the encrypted random value using a private key of the QSA key pair to produce the random value;

generating a second Z value using a private key of the second ECC key pair and a certified form of a public key of the first ECC key pair with the ECDH algorithm; and

deriving the shared key using the random value produced by the decrypting and the second Z value with the key derivation function.

6. The computer program product according to claim 5 , wherein the generating of the random value at the trusted source, the generating of the first Z value using the private key of the first ECC key pair and the certified form of the public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm, the deriving of the shared key using the random value and the first Z value with the key derivation function and the encrypting of the random value using the public key of the QSA key pair to produce the encrypted random value are executed separately from the decrypting of the encrypted random value using the private key of the QSA key pair to produce the random value, the generating of the second Z value using the private key of the second ECC key pair and the certified form of the public key of the first key pair with the ECDH algorithm and the deriving of the shared key using the random value produced by the decrypting and the second Z value with the key derivation function are executed at a second computer.

7. The computer program product according to claim 6 , wherein:

the encrypting of the random value comprises a call of a first cryptographic architecture (CA) programming interface, and

each instance of the deriving of the shared key comprises a call of a second CA programming interface.

8. The computer program product according to claim 6 , wherein the key derivation function comprises hashing.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2021
From: KISLEY, RICHARD VICTOR; MIELE, MICHAEL; DAMES, ELIZABETH ANNE; DRAGONE, SILVIO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055763/0335 →
Continuity (1)
Related Publication 20220321331A1 · Oct 6, 2022