IP Library Granted Patent US 12,483,428
Granted Patent B2
US 12,483,428 · App. 18/488,609 · Granted Nov 25, 2025

Communication devices for use in challenge-response rounds and corresponding operating methods

Inventors: Peter Bukovjan (Graz, AT); Nikita Veshchikov (Brussels, BE)
Assignee: NXP B.V.
H04L9/3271H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,428
App. No.
18/488,609
Granted
Nov 25, 2025
Kind
B2
Abstract

In accordance with a first aspect of the present disclosure, a communication device for use in one or more challenge-response rounds is provided, comprising: a response generation unit configured to generate, in each challenge-response round, a response to a challenge received from an external communication device, wherein said response is generated by performing a cryptographic function on said challenge, and wherein the cryptographic function takes said challenge and a cryptographic key as inputs; a key selection unit configured to select said cryptographic key from a set of cryptographic keys by executing a predefined key selection algorithm that has been shared with the external communication device. Further aspects of the present disclosure relate to another communication device for use in one of more challenge-response rounds, corresponding methods of operating communication devices, and computer programs for carrying out said methods.

Claims (47)

1 . A communication device for use in one or more challenge-response rounds, comprising:

a key selection unit configured to:

execute a predefined key selection algorithm that has been shared with an external communication device;

generate a set of cryptographic keys according to the key selection algorithm; and

select a cryptographic key from the set of cryptographic keys; and

a response generation unit coupled to the key selection unit and configured to:

receive the selected cryptographic key from the key selection unit;

receive a challenge from the external communication device;

perform a cryptographic function utilizing the received challenge and the selected cryptographic key; and

generate, in each challenge-response round, a response based on the performed cryptographic function.

2 . The communication device of claim 1 , wherein selecting the cryptographic key comprises selecting a different cryptographic key from the set of cryptographic keys for each challenge-response round.

3 . The communication device of claim 1 , wherein selecting the cryptographic key comprises selecting the cryptographic key from a subset of the set of cryptographic keys, wherein the subset does not include all the cryptographic keys from the set.

4 . The communication device of claim 1 , wherein selecting the cryptographic key comprises selecting the same cryptographic key from the set of cryptographic keys for a predefined number of consecutive challenge-response rounds.

5 . The communication device of claim 1 , wherein selecting the cryptographic key comprises selecting the cryptographic key from the set of cryptographic keys in a predefined order.

6 . The communication device of claim 5 , wherein the predefined order depends on at least one of the following parameters: an identifier of the communication device, a randomization key, and an authentication round.

7 . The communication device of claim 1 , wherein generating the set of cryptographic keys comprises deriving the cryptographic keys from a master key.

8 . The communication device of claim 1 , wherein the communication device acts as a prover in an authentication protocol.

9 . A method of operating a communication device for use in one or more challenge-response rounds, the method comprising performing in each challenge-response round:

executing a predefined key selection algorithm that has been shared with an external communication device;

generating a set of cryptographic keys according to the key selection algorithm;

selecting a cryptographic key from the set of cryptographic keys;

receiving a challenge from the external communication device;

performing a cryptographic function utilizing the received challenge and the selected cryptographic key;

generating a response based on the performed cryptographic function; and

transmitting the response to the external communication device.

10 . The method of claim 9 , wherein the method is embodied in a computer program comprising executable instructions stored in a non-transitory medium which, when executed by a communication device, performs the method.

11 . A communication device for use in one or more challenge-response rounds, comprising:

a key selection unit configured to:

execute a predefined key selection algorithm that has been shared with an external communication device;

generate a set of cryptographic keys according to the key selection algorithm; and

select a cryptographic key from the set of cryptographic keys; and

a response verification unit configured to:

receive a response from the external communication device; and

verify, for each challenge-response round, the response using the selected cryptographic key.

12 . The communication device of claim 11 , wherein selecting the cryptographic key comprises selecting, in each challenge-response round, a different cryptographic key from said set of cryptographic keys.

13 . The communication device of claim 11 , wherein selecting the cryptographic key comprises selecting the cryptographic key from a subset of the set of cryptographic keys, wherein the subset does not include all the cryptographic keys from said set.

14 . The communication device of claim 11 , wherein selecting the cryptographic key comprises selecting the cryptographic key for a predefined number of consecutive challenge-response rounds.

15 . The communication device of claim 11 , wherein selecting the cryptographic key comprises selecting the cryptographic key from the set of cryptographic keys in a predefined order.

16 . The communication device of claim 15 , wherein the predefined order depends on at least one of the following parameters: an identifier of the communication device, a randomization key, and an authentication round.

17 . The communication device of claim 11 , wherein the communication device acts as a verifier in an authentication protocol.

18 . A method of operating a communication device for use in one of more challenge-response rounds, the method comprising performing in each challenge-response round:

executing a predefined key selection algorithm that has been shared with an external communication device;

generating a set of cryptographic keys according to the key selection algorithm;

selecting a cryptographic key from the set of cryptographic keys;

receiving a response from the external communication device; and

verifying, for each challenge-response round, the response using the selected cryptographic key.

19 . The method of claim 18 , wherein the method is implemented as a computer program comprising executable instructions stored in a non-transitory medium which, when executed by a communication device performs the method.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: BUKOVJAN, PETER; VESHCHIKOV, NIKITA
To: NXP B.V.
Reel/Frame 065254/0539 →
Priority Claims (1)
EP 22207597 · Nov 15, 2022 · regional
Continuity (1)
Related Publication 20240163115A1 · May 16, 2024
References Cited (27)
US 5479514A · Klonowski · 1995 [cited by examiner]
US 8411854B2 · Grzonkowski et al. · 2013 [cited by applicant]
US 8954728B1 · Juels · 2015 [cited by examiner]
US 9154480B1 · Juels · 2015 [cited by examiner]
US 10469260B2 · Hassan · 2019 [cited by applicant]
US 10887107B1 · Chan · 2021 [cited by examiner]
US 10915888B1 · Rule · 2021 [cited by examiner]
US 20060112273A1 · Tuyls · 2006 [cited by examiner]
US 20070198837A1 · Koodli · 2007 [cited by examiner]
US 20080104403A1 · Gueron · 2008 [cited by examiner]
US 20100290618A1 · Slawomir · 2010 [cited by examiner]
US 20160234008A1 · Hekstra · 2016 [cited by examiner]
US 20180013559A1 · Hassan · 2018 [cited by examiner]
US 20190097794A1 · Nix · 2019 [cited by examiner]
US 20210258174A1 · Schoinianakis · 2021 [cited by examiner]
US 20210377057A1 · Poeppelmann · 2021 [cited by examiner]
US 20230038135A1 · Gowanlock · 2023 [cited by examiner]
US 20240008127A1 · Kanneath Abraham · 2024 [cited by examiner]
US 20240072996A1 · Webb · 2024 [cited by examiner]
US 20240073004A1 · Burns · 2024 [cited by examiner]
CN 110493272B · 2020 [cited by applicant]
CN 114863589A · 2022 [cited by applicant]
EP 1011223A1 · 2000 [cited by applicant]
JP 4776378B2 · 2011 [cited by applicant]
KR 20150136957A · 2015 [cited by applicant]
Boureanu, Ioana et al.; “Optimal Proximity Proofs”; International Association for Cryptologic Research, Jan. 16, 2015, pp. 1-21, International Association for Cryptologic Research, Hyderabad, IN. [cited by applicant]
Tomovic, Sinisa et al.; “A Protocol for Provably Secure Authentication of a Tiny Entity to a High Performance Computing One”; Mathematical Problems in Engineering; vol. 2016, Article ID 9289050; Received Dec. 25, 2015; … [cited by applicant]