IP Library › Granted Patent US 12,580,746
Granted Patent B2
US 12,580,746 · App. 18/840,223 · Granted Mar 17, 2026

Method for securely negotiating symmetrical keys between two participants in a communication

Inventors: Viktor Friesen (Karlsruhe, DE); Viktor Pavlovic (Stuttgart, DE); Philipp Weber (Tauberbischofsheim, DE)
Assignee: MERCEDES-BENZ GROUP AG
H04L9/083H04L9/0869H04L9/0891
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,746
App. No.
18/840,223
Filed
Aug 21, 2024
Granted
Mar 17, 2026
Kind
B2
Art Unit
2435
USPC
713/155
Abstract

A method for securely negotiating symmetrical keys between at least two participants of a communication involves each of the participants being equipped in pairs with a common secret or can be equipped indirectly via a further participant, which respectively shares a common secret with each other the two other participants. The participants are each equipped in pairs with at least one common key derivation function or can thus be equipped indirectly via the further participant. If a symmetrical key or the renewal of a symmetrical key is needed, it is derived based on the common secret and one of the key derivation functions according to a derivation rule, which includes at least the key derivation function to be used and at least one parameter for the key derivation function and is communicated to one of the participants by the other participant.

Claims (27)

1 . A method for securely negotiating symmetrical keys between at least two participants of a communication, the method comprising:

equipping the at least two participants in pairs with a common secret, wherein the at least two participants are directly equipped in pairs with the common secret or the at least two participants are indirectly equipped with the common secret via a further participant that shares the common secret with the at least two participants;

determining that a new symmetrical key or a renewed symmetrical key is required; and

deriving, responsive to the determination that the new symmetrical key or the renewed symmetrical key is required, the new symmetrical key or the renewed symmetrical key based on the common secret and one of a plurality of key derivation functions according to a derivation rule,

wherein the derivation rule comprises at least one of the plurality of key derivation function, an input and output selection function respectively defining a number of incoming and outgoing bits, and at least one parameter for the at least one of the plurality of key derivation functions,

wherein the at least one of the plurality of key derivation functions is a key derivation function used to derive the new or renewed symmetrical key,

wherein the key base of the at least one key of the plurality of derivation functions is determined using the input selection function, which selects certain bits of the common secret and leaves the selected bits in an existing order or changing the existing order of the selected bits, and a result of the input selection function is used as the key base of the at least one of the plurality of key derivation functions,

wherein the at least two participants are control devices each having a secure hardware security module, and

wherein the derivation rule is transmitted from a first one of the at least two participants to a second one of the at least two participants.

2 . The method of claim 1 , wherein

the at least one of the plurality of key derivation functions uses a key base, a salt, and an output length as the at least one parameter,

the key base is a secret known to the at least two participants or can be derived by a secret known to the at least two participants,

the salt is a random or pseudo-random bit string of a predetermined length, and

the output length is a natural number specifying a length of an output of the at least one key of the plurality of derivation functions.

3 . The method of claim 2 , wherein the derivation rule further comprises the salt and the output length.

4 . The method of claim 3 , wherein the new or renewed symmetrical key is generated by the derivation rule based on the output selection function selecting certain bits from an output of the key derivation function output length and arranging the selected certain bits in a selected order or in a new order.

5 . The method of claim 3 , wherein the input or output selection function operates as a rearranging selection function as defined by a sequence of bit positions.

6 . The method of claim 3 , wherein the input or output selection function is an order-preserving selection function as defined by a sequence of bit spacings or by bit spacings and corresponding bit quantities.

7 . The method of claim 3 , wherein the input or output selection function is an order-preserving selection function defined by a bit string, wherein bits of the bit string define inclusion or non-inclusion of corresponding bits in the output of the selection function.

8 . The method of claim 3 , wherein the derivation rule is transmitted to the second one of the at least two participants without at least one of the input and output selection functions, wherein, instead of transferring at least one of the selection functions, a reference to a common known input or output selection function is transferred.

9 . The method of claim 3 , wherein different regions of the common secret are used by different input selection functions.

10 . The method of claim 9 , wherein corresponding input selection functions are chosen for several derivation rules in such a way that selection of individual bit positions of the common secret is evenly distributed by the input selection function, or for two random different input selection functions, a number of bit positions of the common secret selected by the two input selection functions is evenly distributed.

11 . The method of claim 9 , wherein the bit positions of the common secret selected by a respective input selection function are set by a random or pseudo-random number generator, wherein bit positions are selected from an entirety of the common secret or from a predetermined region of the common secret.

12 . The method of claim 1 , wherein transferred data is symmetrically authenticated by the key defined by the derivation rule.

13 . The method of claim 12 , wherein the derivation rule is part of the data authenticated by the key defined by the derivation rule.

14 . The method of claim 1 , wherein the derivation rule is transferred as an unencrypted part of a message encrypted with the key defined by the derivation rule.

15 . The method of claim 1 , wherein one of the at least two participants or the further participant is a central confidential authority.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2024
From: FRIESEN, VIKTOR; PAVLOVIC, VIKTOR; WEBER, PHILIPP
To: MERCEDES-BENZ GROUP AG
Reel/Frame 068665/0437 →
Priority Claims (1)
DE 10 2022 000 638.3 · Feb 22, 2022 · national
Continuity (1)
Related Publication 20250184122A1 · Jun 5, 2025
References Cited (21)
US 9385862B2 · Escott · 2016 [cited by examiner]
US 10936744B1 · Trepetin · 2021 [cited by examiner]
US 10938555B2 · Foerder · 2021 [cited by applicant]
US 10958424B1 · Chhabra · 2021 [cited by examiner]
US 11212090B1 · Griffin · 2021 [cited by examiner]
US 20060101270A1 · Laitinen · 2006 [cited by examiner]
US 20080037785A1 · Gantman · 2008 [cited by examiner]
US 20110261961A1 · Dharmaraju · 2011 [cited by examiner]
US 20130275757A1 · Harrington · 2013 [cited by examiner]
US 20160132699A1 · Miller · 2016 [cited by examiner]
US 20190097982A1 · Bhattacharyya · 2019 [cited by examiner]
US 20200221297A1 · Hu · 2020 [cited by examiner]
US 20200280436A1 · Nix · 2020 [cited by applicant]
US 20220038283A1 · Vermeulen · 2022 [cited by examiner]
US 20230308424A1 · Nix · 2023 [cited by examiner]
DE 102016106602A1 · 2017 [cited by applicant]
DE 102020003739A1 · 2020 [cited by applicant]
WO 2017178201A1 · 2017 [cited by applicant]
ETSI; “Quantum-Safe Virtual Private Networks; [Cyber-QSC Verion 0.0.5 Release 0];” ETSI TR 1DD DDD V0.0.5; Apr. 2018; pp. 1-40. [cited by applicant]
International Search Report and Written Opinion mailed Apr. 20, 2023 in related/corresponding International Application No. PCT/EP2023/051380. [cited by applicant]
Office Action created Feb. 8, 2023 in related/corresponding DE Application No. 10 2022 000 638.3. [cited by applicant]