IP Library › Granted Patent US 9,078,126
Granted Patent B2
US 9,078,126 · App. 14/000,645 · Granted Jul 7, 2015

Method of sharing a session key between wireless communication terminals using a variable-length authentication code

Inventors: Jeong Hyun Yi (Gyeonggi-do, KR); Gun-Il Ma (Seoul, KR); Hyeong Chan Lee (Seoul, KR)
Assignee: SOONGSIL UNIVERSITY RESEARCH CONSORTIUM TECHNO-PARK
H04W12/04H04L9/0841H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,078,126
App. No.
14/000,645
Granted
Jul 7, 2015
Kind
B2
Abstract

Disclosure relates to a method of sharing a session key between wireless communication terminals using a variable-length authentication code. The method includes: generating a public key by using an own private key; generating a message including the public key and a first random number and encoding the message using an own secret key to exchange an encrypted message with the other terminal; decoding the encrypted message of the other terminal by receiving a secret key of the other terminal; generating an authentication code by calculating the first random number and a second random number included in the decoded message; obtaining a medium value from the authenticated code; and generating a session key by using a public key included in the decoded message of the other terminal.

Claims (47)

1. A method of sharing a session key between wireless communication terminals based on a Diffie-Hellman (DH) protocol, the method comprising:

generating a public key by using an own private key;

generating a message including the public key and a first random number;

encoding the message using an own secret key to exchange an encrypted message with the other terminal, wherein the message further comprises an identifier and a reflection attack verification value and wherein the secret key is a disposable key;

decoding the encrypted message of the other terminal by receiving a secret key of the other terminal;

checking the reflection attack verification value of the other terminal included in the decoded message;

generating an authentication code by calculating the first random number and a second random number included in the decoded message, wherein the first and second random numbers are comprised of bit streams having a value of 0 or 1, wherein the generating of the authentication code comprises performing an exclusive OR operation on the first random number and the second random number, wherein the authentication code is divided into n bits (where n is a natural number of 2 or more), wherein the divided authentication code corresponds to one grid, and wherein each grid is indicated by one color;

obtaining a medium value from the authenticated code; and

generating a session key by using the public key included in the decoded message of the other terminal,

wherein the obtaining of the medium value from the authentication code comprises:

dividing the authentication code into 2 or more bits and inputting the divided authentication code to an out-of-band (OOB) function to obtain the medium value; and

displaying the medium value on a screen including a plurality of grids,

wherein the number S′ of grids required to display the medium value is obtained by the following equation:

S

′

=

S

log

2

⁢

k

where S is the number of grids required when the number of colors for displaying the medium value is 2, k is the number of colors used to display the medium value and is 2 m (where m is a number of bits to the divided authentication code).

2. The method of claim 1 , wherein the obtaining of the medium value from the authentication code comprises:

inputting the authentication code to an OOB function to obtain the medium value; and

controlling a plurality of light emitting diodes (LEDs) to turn on or off according to the medium value.

3. The method of claim 1 , wherein the obtaining of the medium value from the authentication code comprises:

inputting the authentication code to an OOB function to obtain the medium value; and

playing a stored sound source file according to the medium value.

4. A wireless communication terminal for sharing a session key with the other terminal based on a Diffie-Hellman (DH) protocol, the wireless communication terminal comprising:

at least one hardware processor;

a storage unit configured to store a public key generated by using an own private key using the at least one hardware processor;

an encoding unit configured to generate a message including the public key and a first random number and encode the message using an own secret key to exchange an encrypted message with the other terminal using the at least one hardware processor, wherein the message further comprises an identifier and a reflection attack verification value and wherein the secret key is a disposable key;

a decoding unit configured to decode the encrypted message of the other terminal by receiving a secret key of the other terminal using the at least one hardware processor, wherein the decoding unit checks the reflection attack verification value of the other terminal included in the decoded message;

an authentication code generating unit configured to generate an authentication code by calculating the first random number and a second random number included in the decoded message using the at least one hardware processor, wherein the first and second random numbers are comprised of bit streams having a value of 0 or 1, wherein the authentication code generating unit generates an authentication code by performing an exclusive OR operation on the first random number and the second random number, wherein the authentication code is divided into n bits (where n is a natural number of 2 or more), wherein the divided authentication code corresponds to one grid, wherein each grid is indicated by one color;

an out-of-band (OOB) converting unit configured to obtain a medium value from the authenticated code using the at least one hardware processor; and

a session key generating unit configured to generate a session key by using a public key included in the decoded message of the other terminal using the at least one hardware processor,

wherein the OOB converting unit obtains the medium value from the authentication code divided into 2 or more bits and inputted to the OOB converting unit and displays the medium on a screen including a plurality of grids,

wherein the number S′ of grids required to display the medium value is obtained by the following equation:

S

′

=

S

log

2

⁢

k

where S is the number of grids required when the number of colors for displaying the medium value is 2, k is the number of colors used to display the medium value and is 2 m (where m is a number of bits to the divided authentication code).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2013
From: YI, JEONG HYUN; MA, GUN-IL; LEE, HYEONG CHAN
To: SOONGSIL UNIVERSITY RESEARCH CONSORTIUM TECHNO-PARK
Reel/Frame 031058/0848 →
Priority Claims (1)
KR 10-2011-0038900 · Apr 26, 2011 · national
Continuity (1)
Related Publication 20130332739A1 · Dec 12, 2013