IP Library › Granted Patent US 12,166,859
Granted Patent B2
US 12,166,859 · App. 18/079,898 · Granted Dec 10, 2024

Method for forming virtual private network providing virtual private network through sealed key exchange based on post quantum cryptography and system for operating virtual private network performing same

Inventors: Hyunchul Jung (Seoul, KR); Chang Nyoung Song (Seoul, KR)
Assignee: NORMA Inc.
H04L9/0819H04L9/0852H04L9/0869H04L9/14H04L9/3093H04L63/0272H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,166,859
App. No.
18/079,898
Granted
Dec 10, 2024
Kind
B2
Abstract

The technical idea of the present invention relates to a method for forming virtual private network providing virtual private network through sealed key exchange based on post quantum cryptography and a virtual private network operating system performing same. A method for forming a virtual private network performed by a server according to an embodiment of the present invention comprises the steps of: generating a public key and a private key; transmitting the public key; receiving a key capsule corresponding to the public key; generating a verification capsule from the key capsule using the private key; generating a symmetric key by verifying the verification capsule; and performing communication through the virtual private network using the symmetric key.

Claims (34)

1. A method for forming a virtual private network performed by a server comprising a processor, the method comprising the steps of:

generating, by the processor, a public key and a private key;

transmitting, by the processor, the public key;

receiving, by the processor, a key capsule corresponding to the public key;

generating, by the processor, a verification capsule from the key capsule utilizing the private key;

generating, by the processor, a symmetric key by verifying the verification capsule; and

performing, by the processor, communication over the virtual private network utilizing the symmetric key,

wherein generating the symmetric key by verifying the verification capsule comprises the steps of:

determining, by the processor, whether the verification capsule is the same as the key capsule;

generating, by the processor, a prekey via a key message and a hash of the public key when the verification capsule is the same as the key capsule; and

generating, by the processor, the symmetric key via the key capsule and a hash of the prekey,

wherein generating, by the processor, the public key and the private key comprises the steps of:

defining, by the processor, a key matrix corresponding to a random polynomial ring; and

sampling, by the processor, a first key vector generated by a lattice-based algorithm and a second key vector having a first distance from the first key vector.

2. The method for forming a virtual private network of claim 1 , wherein the key capsule is generated by capsuling a randomly generated key message and a capsule random value generated by hashing the key message using the public key.

3. The method for forming a virtual private network claim 1 , wherein the generating of the verification capsule from the key capsule using the private key comprises the steps of:

extracting, by the processor, a key message by opening the key capsule using the private key;

generating, by the processor, a release random value by hashing the key message; and

generating, by the processor, the verification capsule by sealing the key message and the release random value with the public key.

4. A method for forming a virtual private network performed by a client including a processor, the method comprising the steps of:

receiving, by the processor, a public key;

generating, by the processor, a key message using a random number generator;

generating, by the processor, a key capsule using the key message;

transmitting, by the processor, the key capsule;

generating, by the processor, a symmetric key using the key capsule; and

performing, by the processor, communication over the virtual private network using the symmetric key,

wherein the generating of the symmetric key using the key capsule comprises the steps of:

generating, by the processor, a prekey by hashing the key message and the public key;

generating, by the processor, a key hash value by hashing the prekey and the key capsule; and

generating, by the processor, the key hash value as the symmetric key,

wherein the public key is generated using a key matrix corresponding to a random polynomial ring, a first key vector sampled corresponding to a lattice, and a second key vector having a first distance from the first key vector on the lattice.

5. The method for forming a virtual private network of claim 4 , wherein the generating of the key capsule using the key message comprises the steps of:

generating, by the processor, a sealing random value by hashing the key message; and

generating, by the processor, the key capsule by capsuling the key message and the capsule random value using the public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2022
From: JUNG, HYUNCHUL; SONG, CHANG NYOUNG
To: NORMA INC.
Reel/Frame 062097/0219 →
Priority Claims (1)
KR 10-2022-0110890 · Sep 1, 2022 · national
Continuity (1)
Related Publication 20240080182A1 · Mar 7, 2024