smime-2----Page:11
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16  17  18  19  20  21 

Algorithm Review
Generate random value z range 0…n-1
Encrypt z with recip. pub. key c=E(z)
Derive a KEK k = KDF(z)
Encrypt CEK with KEK wk = KEKk(cek)
EncryptedKeyValue c || wk
PPT Version