IP Library › Granted Patent US 12,192,337
Granted Patent B2
US 12,192,337 · App. 18/330,410 · Granted Jan 7, 2025

Quantum safe key exchange scheme

Inventors: Richard Victor Kisley (Charlotte, NC); Michael Miele (Concord, NC); Elizabeth Anne Dames (Harrisburg, NC); Silvio Dragone (Olten, CH)
Assignee: International Business Machines Corporation
H04L9/0841H04L9/0656H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,337
App. No.
18/330,410
Granted
Jan 7, 2025
Kind
B2
Abstract

Aspects of the invention include a computer-implemented method of executing a hybrid quantum safe key exchange system. The computer-implemented method includes initially retrieving an authenticated random value from a trusted source, generating a first Z value using a first elliptic curve (EC) private key and a first certified form of an EC public key with an EC Diffie-Hellman (ECDH) algorithm, deriving a shared key using the authenticated random value and the first Z value with a key derivation function, decrypting the authenticated random value using a quantum safe algorithm (QSA) private key, generating a second Z value using a second EC private key and a second certified form of the EC public key with the ECDH algorithm and deriving the shared key using the authenticated random value and the second Z value with the key derivation function.

Claims (23)

1. A method of executing a hybrid quantum safe key exchange system, the method comprising:

generating a quantum safe algorithm (QSA) key pair for key encryption management and first and second elliptic curve cryptography (ECC) key pairs for key agreement;

generating a first Z value using a private key of the first ECC key pair and a certified form of a public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm;

deriving a shared key using a random value, generated at a trusted source, and by using the first Z value with a key derivation function;

encrypting the random value using a public key of the QSA key pair to produce an encrypted random value, which is retrievable from the trusted source;

decrypting the encrypted random value using a private key of the QSA key pair to produce the random value;

generating a second Z value using a private key of the second ECC key pair and a certified form of a public key of the first ECC key pair with the ECDH algorithm; and

deriving the shared key using the random value produced by the decrypting and the second Z value with the key derivation function.

2. The method according to claim 1 , wherein:

the generating of the first Z value using the private key of the first ECC key pair and the certified form of the public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm, the deriving of the shared key using the random value and the first Z value with the key derivation function and the encrypting of the random value using the public key of the QSA key pair to produce the encrypted random value are executed at a first computer, and

the decrypting of the encrypted random value using the private key of the QSA key pair to produce the random value, the generating of the second Z value using the private key of the second ECC key pair and the certified form of the public key of the first ECC key pair with the ECDH algorithm and the deriving of the shared key using the random value produced by the decrypting and the second Z value with the key derivation function are executed at a second computer.

3. The method according to claim 1 , wherein:

the encrypting comprises a call of a first cryptographic architecture (CCA) programming interface, and

each instance of the deriving of the shared key comprises a call of a second CCA programming interface.

4. The method according to claim 1 , wherein the key derivation function comprises hashing.

5. A computer-implemented method of executing a hybrid quantum safe key exchange system, the computer-implemented method comprising:

generating a quantum safe algorithm (QSA) key pair for key encryption management and first and second elliptic curve cryptography (ECC) key pairs for key agreement;

generating a first Z value using a private key of the first ECC key pair and a certified form of a public key of the second ECC key pair with an EC Diffie-Hellman (ECDH) algorithm;

deriving a shared key using a random value, generated at a trusted source, and by using the first Z value with a key derivation function;

encrypting the random value using a public key of the QSA key pair to produce an encrypted random value, which is retrievable from the trusted source;

decrypting the encrypted random value using a private key of the QSA key pair to produce the random value;

generating a second Z value using a private key of the second ECC key pair and a certified form of a public key of the first ECC key pair with the ECDH algorithm; and

deriving the shared key using the random value produced by the decrypting and the second Z value with the key derivation function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2023
From: KISLEY, RICHARD VICTOR; MIELE, MICHAEL; DAMES, ELIZABETH ANNE; DRAGONE, SILVIO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063877/0218 →
Continuity (2)
Continuation 17216807 · Mar 30, 2021
Related Publication 20230318814A1 · Oct 5, 2023
References Cited (24)
US 10333703B2 · Arnold et al. · 2019 [cited by applicant]
US 10498530B2 · Nix · 2019 [cited by applicant]
US 10621352B2 · Nix · 2020 [cited by applicant]
US 10630467B1 · Gilbert et al. · 2020 [cited by applicant]
US 10708046B1 · Ashrafi · 2020 [cited by applicant]
US 10797879B2 · Liu · 2020 [cited by applicant]
US 10958653B1 · Miller · 2021 [cited by examiner]
US 20180254894A1 · Arnold et al. · 2018 [cited by applicant]
US 20190245681A1 · Alwen · 2019 [cited by examiner]
US 20200280436A1 · Nix · 2020 [cited by examiner]
US 20220321331A1 · Kisley et al. · 2022 [cited by applicant]
US 20230012013A1 · Livshin · 2023 [cited by examiner]
WO 2016209939A1 · 2016 [cited by applicant]
WO 2017190223A1 · 2017 [cited by applicant]
WO 2021044214A2 · 2021 [cited by applicant]
Anonymous “Asymmetric Symmetric-Encryption Double RC4)”—An Very Low Complexity & Secure Authentication Algorithm, IP.com No. IPCOM000154900D; Original Publication Date: Jul. 17, 2007; 4 pgs. [cited by applicant]
Anonymous “Sharing Confidential Data Between Application Users in a Combined (symmetric/asymmetric) encryption scheme”, IP.com No. IPCOM000228586D; IP.com Publication Date: Jun. 20, 2013; 6 pgs. [cited by applicant]
Gooch, Robert P., et al. “Quantum Safe Key Distribution System”, IP.com No. IPCOM000245174D; IP.com Publication Date: Feb. 16, 2016; 12 pgs. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/EP2022/057718; International Filing Date Mar. 23, 2022; Date of mailing Jun. 27, 202022; 13 pages. [cited by applicant]
International Search Report; International Application No. TW 111103284; International Filing Date: Jan. 26, 2022; Date of mailing: Dec. 16, 2022; 10 pages. [cited by applicant]
Kaplan, M., et al. “Breaking Symmetric Cryptosystems using Quantum Period Finding”, retrieved at: https://obj.umiacs.umd.edu/extended_abstracts/QCrypt_2016_paper_38.pdf; Paper 38; 2016; 3 pgs. [cited by applicant]
List of IBM Patents or Patent Applications Treated as Related; Appendix P; Date Filed: Jun. 7, 2023; 2 pages. [cited by applicant]
Murthy, S.G.K., et al. “Secure Key Distribution using Quantum Cryptography”, Global Journal of Computer Science and Technology Cloud & Distributed; vol. 12, Issue 12, V. 1.0; 2012; Online ISSN: 0975-4172 & Print ISSN: 0… [cited by applicant]
Xu, Jia et al. “Practical Quantum-Safe Stateful Hybrid Key Exchange Protocol”, retrieved at: https://eprint.iacr.org/2020/763.pdf; Mar. 2020; 17 pgs. [cited by applicant]