Patent · US Expired

Session key distribution using smart cards

US5809140A · kind A · utility

58Cited by
3References
26Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 15, 1996
Grant dateSep 15, 1998
Priority date
Expiry dateOct 15, 2016

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L9/0838
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Methods and apparatus are disclosed for providing secure session key distribution using a smart circuit card or other intelligent device. First and second hosts communicate with each other and with a server over a communication network. The first host initiates the session key distribution process by transmitting a session identifier to the server. The first host uses a first smart card storing the first host secret key to generate a first message in the form of a random bit stream which is transmitted to the second host. The server generates a second message as a function of the server secret key and the session identifier, and transmits it to the first host. The second host uses a second smart card storing the second host secret key to generate a third message as a function of the second host secret key and the first message, and transmits the third message to the first host. The first host then uses the first smart card to generate a potential session key pair as a function of the second and third messages and the first host secret key. If the first host accepts the session key pair, it transmits one of the session keys of the pair to the second host. The second host uses the se…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.