IP Library › Granted Patent US 12,192,184
Granted Patent B2
US 12,192,184 · App. 18/063,192 · Granted Jan 7, 2025

Secure session resumption using post-quantum cryptography

Inventor: John A. Nix (Evanston, IL)
H04L63/045H04L9/085H04L9/0852H04L9/0861H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,184
App. No.
18/063,192
Granted
Jan 7, 2025
Kind
B2
Abstract

A server and a device can support secure sessions with both (i) post-quantum cryptography (PQC) key encapsulation mechanisms (KEM) and (ii) session resumption. In an initial secure session, the device and server can mutually generate a first shared secret key K1 from a first KEM based on a device PKI key pair. The device and server can mutually generate a second shared secret key K2 from a second KEM based on a server PKI key pair. The device and server can mutually generate a symmetric ciphering key S2 from both K1 and K2. The server can encrypt an identity for a “pre-shared” secret key (PSK-ID) with S2. The device and server can (i) mutually generate a PSK from both K1 and K2 and (ii) close the initial secure session. The device can transmit a message to resume the session, where the message includes the PSK-ID and a MAC value.

Claims (26)

1. A method for a device to conduct secure communications with a network, the method performed by the device, the method comprising:

a) storing, in nonvolatile memory, a plurality of key encapsulation mechanism (KEM) algorithms comprising a first KEM algorithm;

b) generating, by a processing unit, a device ephemeral private key and a corresponding device ephemeral public key for the first KEM algorithm;

c) transmitting, to the network via a network interface, a first message comprising (i) the device ephemeral public key, and (ii) identifiers for each of the plurality of KEM algorithms and the first KEM algorithm;

d) receiving, from the network via the network interface, a second message comprising a first asymmetric ciphertext and a first symmetric ciphertext of at least a server public key for a second KEM algorithm;

e) conducting a KEM decapsulation (DECAPS) function to generate a first shared secret K1 using the first asymmetric ciphertext and the first KEM algorithm;

f) conducting a KEM encapsulation (ENCAPS) function to generate a second shared secret K2 and a second asymmetric ciphertext using at least (i) the server public key and (ii) the second KEM algorithm;

g) deriving a symmetric ciphering key S2 using at least the K1 and the K2;

h) deriving a “pre-shared” secret key (PSK) using at least the K1 and the K2;

i) receiving, from the network, a third message comprising a second symmetric ciphertext of an identity of the PSK (PSK-ID), wherein the device decrypts the second symmetric ciphertext with the key S2;

j) transmitting, to the network, a fourth message requesting resumption of a secure session, the fourth message comprising the PSK-ID and a random number generated by the device;

k) generating a symmetric ciphering key S3 using the PSK and the random number;

l) Receiving, from the network, a third symmetric ciphertext; and

m) decrypting the third symmetric ciphertext using the key S3.

2. The method of claim 1 , further comprising in step g), deriving a symmetric ciphering key S2 using at least the K1 and the K2 with one of (i) a HMAC-based Extract-and-Expand Key Derivation Function (HKDF) and (ii) a hash-based key derivation function.

3. The method of claim 2 , further comprising in step g) using the HKDF to derive a message authentication code (MAC) key and an initialization vector for the second symmetric ciphertext.

4. The method of claim 1 , further comprising in step h), deriving the PSK using at least plaintext data from the first message and the second message with one of a HKDF and a hash-based key derivation function.

5. The method of claim 1 , further comprising in step h), generating a symmetric ciphering key S3 using the PSK and the random number with one of a HKDF and a hash-based key derivation function.

6. The method of claim 5 , further comprising in step k) using the HKDF to derive a message authentication code (MAC) key and an initialization vector for the third symmetric ciphertext.

7. The method of claim 1 , wherein the first KEM algorithm comprises a first algorithm type for lattice-based cryptography and the second KEM algorithm comprises a second algorithm type for code-based cryptography.

8. The method of claim 1 , wherein the first KEM algorithm comprises a first algorithm type for code-based cryptography and the second KEM algorithm comprises a second algorithm type for lattice-based cryptography.

9. The method of claim 1 , wherein the server public key comprises a server static public key, wherein a plaintext for the first symmetric ciphertext includes a server certificate with the server static public key and an identity for the second KEM algorithm.

10. The method of claim 1 , wherein the server public key comprises a server ephemeral public key, and wherein a plaintext for the first symmetric ciphertext includes a server digital signature over at least the server ephemeral public key and the device ephemeral public key.

11. The method of claim 1 , wherein the symmetric ciphering key S2 comprises a first portion and a second portion, wherein in step i) the device decrypts with the first portion of the key S2, and wherein the second portion of the key S2 comprises an encryption key.

12. The method of claim 1 , wherein the secure session comprises step c) through step i).

13. The method of claim 1 , wherein the device comprises one of a personal computer, a laptop computer, a mobile handset, a router, and a server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2026
From: NIX, JOHN A., JR.
To: ADEIA EMERGING TECHNOLOGIES INC.
Reel/Frame 074245/0975 →
Continuity (2)
Provisional Application 63287384 · Dec 8, 2021
Related Publication 20230308424A1 · Sep 28, 2023
References Cited (48)
US 8681996B2 · Sabev · 2014 [cited by applicant]
US 8782774B1 · Pahl et al. · 2014 [cited by applicant]
US 9531685B2 · Gero et al. · 2016 [cited by applicant]
US 9673977B1 · Kalach · 2017 [cited by applicant]
US 9819656B2 · Carlson · 2017 [cited by applicant]
US 9985782B2 · McCallum · 2018 [cited by applicant]
US 10169587B1 · Nix · 2019 [cited by applicant]
US 10218504B1 · Kalach et al. · 2019 [cited by applicant]
US 10412063B1 · Mandich et al. · 2019 [cited by applicant]
US 11153080B1 · Nix · 2021 [cited by applicant]
US 20020166048A1 · Coulier · 2002 [cited by applicant]
US 20090049299A1 · Jablon et al. · 2009 [cited by applicant]
US 20130051551A1 · El Aimani · 2013 [cited by applicant]
US 20130114810A1 · Kobayashi et al. · 2013 [cited by applicant]
US 20140089658A1 · Raghuram · 2014 [cited by applicant]
US 20140195804A1 · Hursti · 2014 [cited by applicant]
US 20150067338A1 · Gero et al. · 2015 [cited by applicant]
US 20150271146A1 · Holyfield · 2015 [cited by applicant]
US 20160065370A1 · Le Saint · 2016 [cited by applicant]
US 20170012974A1 · Sierra et al. · 2017 [cited by applicant]
US 20190097794A1 · Nix · 2019 [cited by applicant]
US 20190149527A1 · Rhidian · 2019 [cited by applicant]
US 20190386825A1 · Bhattacharya et al. · 2019 [cited by applicant]
US 20200235929A1 · Jacobs et al. · 2020 [cited by applicant]
US 20200259647A1 · Goncalves · 2020 [cited by examiner]
US 20200304305A1 · Garcia Morchon et al. · 2020 [cited by applicant]
US 20200314115A1 · Nabeesa et al. · 2020 [cited by applicant]
US 20200374129A1 · Dilles et al. · 2020 [cited by applicant]
US 20200396060A1 · Wu · 2020 [cited by examiner]
US 20200403978A1 · Allen et al. · 2020 [cited by applicant]
US 20210058242A1 · Donsomsakunkij et al. · 2021 [cited by applicant]
US 20210083862A1 · Pointcheval et al. · 2021 [cited by applicant]
US 20220345298A1 · Cap · 2022 [cited by examiner]
US 20230254132A1 · Ramanathan · 2023 [cited by examiner]
US 20240273221A1 · Shea · 2024 [cited by examiner]
WO 2022060471A2 · 2022 [cited by applicant]
Guerin, et al., “Method for Exchanging Cryptographic Keys for Quantum-secure Communication Between a Server and a Client”, Jul. 22, 2021, DE 102020200726 A1 (English Translation), pp. 1-29 (Year: 2021). [cited by examiner]
Wikipedia, “Post-Quantum Cryptography Standardization”, Oct. 29, 2021. [cited by applicant]
GSM Association, “iUICC POC Group Primary Platform requirements”, Release 1.0, May 17, 2017. [cited by applicant]
ETSI Technical Standard 103 465 v. 15.0.0, “Smart Cards; Smart Secure Platform (SSP); Requirements Specification”, May 2019. [cited by applicant]
Bos, et al, “CRYSTALS—Kyber: a CCA-secure module-lattice-based KEM”, NIST PQC Round 1 Submission Package, Nov. 2017. [cited by applicant]
Jao, et al, “Supersingular Isogeny Key Encapsulation”, NIST PQC Round 2 Submission Package, Apr. 17, 2019. [cited by applicant]
Krawczyk, et al, “HMAC-based Extract-and-Expand Key Derivation Function (HKDF)”, Internet Engineering Task Force (IETF), RFC 5869, May 2010. [cited by applicant]
Aragon, et al, “BIKE—Bit-Flipping Key Encapsulation”, NIST PQC Conference, Apr. 13, 2018. [cited by applicant]
Fischlin, et al, “Multi-Stage Key Exchange and the Case of Google's QUIC Protocol”, Association for Computing Machinery Conference on Computer and Communications Security 2014, p. 1193-1204, 2014. [cited by applicant]
Krawczyk, et al, “The OPTLS Protocol and TLS 1.3”, Proc. IEEE European Symposium on Security and Privacy, 2016. [cited by applicant]
European Telecommunications Standards Institute (ETSI), Technical Report 103 823 V1.1.1, “Cyber; Quantum-Safe Public-Key Encryption and Key Encapsulation”, Sep. 2021. [cited by applicant]
Internet Engineering Task Force (IETF) Request for Comments (RFC) 8446, “The Transport Layer Security (TLS) Protocol Version 1.3”, Aug. 2018. [cited by applicant]