Teleconferencing method for a secure key management system
Abstract
A secure teleconferencing method for a key management system is shown. This method directly establishes a secure teleconference among a number of terminals without the intervention of a certifying authority. The terminals (A-D) of this system have been previously certified by a common certification authority. Upon detection of a secure teleconference, the terminals orient themselves in a master/slave (1-16,22,23) configuration. The terminals exchange certification messages (24-43,45). As a result, each terminal determines the identity of the other terminals (44,46). Under the supervision of the master terminal, the terminals establish a single session, session key which permits secure communication among the terminals (47-58). A new session key is randomly generated for each teleconference call. A minimum number of messages is exchanged to establish the secure teleconference.

Term
Term ended
Expired 31 May 2010, 16.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
15 claims: 7 independent, 8 dependent
- 1The claims defining the invention are as follows:wixatt xi» x«iadsw3ii 1. A secure teleconferencing method for a key management system included a plurality of terminals previously certified by a common authority of said key management : ystem, said secure teleconferencing method comprising the steps of: connecting at least three of said terminals in an unsecure teleconference call via a switching network;selecting any one of said connected terminals to be a master terminal;selecting all of said connected terminals, except said master terminal, as slave terminals;establishing by each terminal that each of said remaining connected terminals is certified by a common certification authority;directly developing a single-session session key among said connected terminals;and initiating a secure teleconference call among each of said connected terminals to provide for secure voice and data communication among said connected terminals. ‘-2-:-A secure teloeon-ferencing-method as-claimed inclaim 1, wherein said step of establishing includes the steps of : transmitting an access doma Lymes sage from said master terminal to each of said slaye terminals;receiving said accessxiomain message by each of said slave terminals;,/ determining bv/dach of said slave terminals whether said master tpdminal and each said slave terminal have a common acceis domain;respemding by each of said slave terminals to said master terminal with an access domain message of each said oibave fep<fminal/—and--
- 10A secure teleconferencing method as claimed in claim 9, wherein said step of directly developing further includes the step of generating a set of pseudorandom numbers by said 10 master terminal, each pseudorandom number of said set corresponding to each of said terminals. «25· • · Λ ft ft ft ft ft ft ft · ft ft 0 ft « ft ft ft • ft ft ft ft ft t t ft 9' • I ft « « « • t £ :30: < < 1 « « t ( t t c t t t t I (( ( t (, K '3’3
- 11A secure teleconferencing method as claimed in claim 10, wherein said step of generating a set of pseudorandom numbers includes the steps of:generating a pseudorandom number corresponding to each of said terminals connected in said teleconference, each pseudorandom number being an exclusive-OR of each of said set of pseudorandom numbers corresponding to each terminal, except said pseudorandom number corresponding to one terminal which is to receive said pseudorandom number;and transmitting by said master terminal each corresponding pseudorandom number of said set of pseudorandom numbers to said corresponding terminal in an appropriate time slot.
- 12A secure teleconferencing method as claimed in claim 11, wherein said step of generating a set of pseudorandom numbers further includes the step of encrypting said set of pseudorandom numbers with an asymmetric RSA-type function.
- 13A secure teleconferencing method as claimed in claim 12, wherein said step of establishing further includes the steps of :receiving in said appropriate time slot by each of said slave terminals said corresponding one of said set of pseudorandom numbers;and exclusive-ORing said pseudorandom number stored by said slave terminal with said received one of said set of pseudorandom numbers to produce said session key.
- 14A secure teleconferencing method as claimed in claim 13, said step of establishing further including the step of 5 exclusive-ORing by said master terminal eacn of said pseudorandom numbers transmitted by said slave terminals with said stored pseudorandom number by said master terminal to produce said session key. 10 15. A secure teleconferencing method as claimed in claim 14, wherein said step of initiating includes the steps of:generating a crypto synchronization message by said master terminal;transmitting said generated crypto synchronization 15 message to each of said slave terminals;receiving by each of said slave terminals said crypto synchronization message;and initializing with said crypto synchronization message a symmetric encrypt/decrypt function of each of said connected 20 terminals. t ( 4 < « < 4 » »4 « 1 « 4 € 4, t » « t t I t H t I t « I f 4 S ( t < s t t ‘ * I i ( 16. A secure teleconferencing method via a switching network for establishing a secure teleconference among a plurality of interconnected terminals which have been previously certified by a common authority, said secure teleconferencing method comprising the steps of: selecting any one of said connected terminals to be a master terminal;( 1t 4 t til t 4: « I I * I t t < ft « < t It f'3 5' ο < -a ο ο β β ft © 6 β © ft ©'ft © ft 0ft 6 ft ft Ο Ο « ft ft ft 0 ft ft ft ft ft * ft ft 4 ft ft ft ft β β ft ft ft ft ft Aft ft ft ft O »-> ft ft ft ft * ft ft ft ftft ft ft « « * ft 0 selecting all of said connected terminals, except said master terminal, as slave terminals;10 establishing by each terminal that each of said remaining interconnected terminals is certified by a common certification authority;directly developing a single-session session key among said connected terminals;and
- 1515 initiating a secure teleconference call among each of said interconnected terminals to provide for secure voice and data communication among said interconnected terminals. Π Λβ'. A secure teleconferencing method via a switching network for establishing a secure teleconference among a plurality of interconnected terminals which have been previously certified by a common authority, said secure 5 teleconferencing method comprising the steps of:selecting any one of said connected terminals to be a master terminal;selecting all of said connected terminals, except said master terminal, as slave terminals;10 establishing by each terminal that each of said remaining interconnected terminals is certified by a common certification authority;and directly developing a single-session session key among said connected terminals for providing secure voice 15 and data communication among said interconnected terminals. A secure teleconferencing method substantially as described and shown in the drawings.
Independent claims7
203 paragraphs in 3 sections, as filed
COMPLETE SPECIFICATION (ORIGINAL)
Class Int. Class
Application Number:
Lodged:
Complete Specification Lodged:
Accepted:
Published:
Priority
Related Art:
eoe e ♦ e β e ft o <sup>e</sup> ft β β β o · «
• «» « « <
< ϊ < e t
Applicant(s):
lit'·' «<ί <' Motorola, Inc.
1303 East Algonquin Road, Schaumburg, Illinois, 60196, UNITED STATES OF AMERICA ···· Address for Service is:
«ft ft ft ft ft .··;·. PHILLIPS ORMONDE & FITZPATRICK * * <sup>* * ····</sup> Patent and Trade Mark Attorneys
367 Collins Street «//’· Melbourne 3000 AUSTRALIA
Complete Specification for the invention entitled:
. TELECONFERENCING METHOD FOR A SECURE KEY MANAGEMENT SYSTEM
Our Ref : 175503 POF Code: 113712/1437
The following statement is a full description of this invention, including the best method of performing it known to applicant(s):
6006
- 1 la
TELECONFERENCING METHOD FOR A SECURE KEY MANAGEMENT SYSTEM © €* &
Q O' M Oft© Θ
O 3 $ © o © 6 6 0 0 ©
© © « © ft <9 © ©
O © ft ©ft o © ft ft ©
Q Ο β ©ft © © © © © ft o © © o © © © is ©
9 9 0 O © © ft ft © © ft • o © © ft © ©
4ί» » I β » • a « < a < t β «
Background of the Invention<sup>1</sup>5 The·present invention pertains to secure communications among users of a key management system and more particularly to a method for providing secure teleconferencing through the use of an unforgeable certification process.
In modern day telephony, specialized circuitry within the switching system provides for teleconferencing.
Teleconferencing is simultaneous voice or data exchange between three or more users of a communication system. Typically, specialized networks and circuitry within the network of a switching system provide for interconnecting a number of users in a teleconference.
In secure communications systems, the problems of establishing connections among multiple users for voice or data exchange is further complicated by various security protocols. Establishing a secure teleconference between multiple users via a secure network of a switching system is very difficult . This is due to the fact that the terminal devices in a secure teleconferencing system may demand point-to-point, on-line establishment of traffic keys.
Further, establishing a session key between terminal devices connected to a secure network of a switching system requires transmission of many messages between the system and the users. This is very cumbersome and time consuming.
An object of the present invention is to provide a method to enable any number of terminal devices connected to a switching network to establish a secure conference arrangement by establishing an unforgeable certification method to provide a single session traffic key with a minimal number of point-to-point message exchanges between the terminal devices .
<img file="AU629641B2_D0001.tif" />
In accomplishing the object of the present invention, a novel teleconferencing method for a secure key management system is shown.
A secure teleconferencing method may be achieved among a number of interconnected terminals via a switching network. Each of the terminals have previously been certified The secure teleconferencing method may all the teleconferenced terminals have by a common authority, first establish that previously been certified. Each terminal may establish that all the remaining terminals have been previously certified by a common authority. Then, the terminals may collectively develop a unique, single session, session key for providing secure voice and data communication among the interconnected terminals. .
According to one aspect of the present invention there is provided a secure teleconferencing method for a key management system included a plurality of terminals previously certified by a common authority of said key management system, said secure teleconferencing method comprising the steps of:
connecting at least three of said terminals in an unsecure teleconference call via a switching network;
selecting any one of said connected terminals to be a master terminal;
fit ί ί : selecting all of said connected terminals, except l t < *
SS'j said master terminal, as slave terminals;
. 1 t t
«.£<« establishing by each terminal that each of said ,<sub>t</sub> remaining connected terminals is certified by a common Ί' certification authority;
directly developing a single-session session key among said connected terminals; and : initiating a secure teleconference call among each of ! said connected terminals to provide for secure voice and data : ; communication among said connected terminals.
According to a further aspect of the present .3,5' invention there is provided a secure teleconferencing method via a switching network for establishing a secure < <
teleconference among a plurality of interconnected terminals which have been previously certified by a common authority, said secure teleconferencing method comprising the steps of:
<img file="AU629641B2_D0002.tif" />
2a10
2S*· β β β «4 β 4 4 4 4 4 β « 4 .<35.:
« *··*<< 4 t selecting any one of said connected terminals to be a master terminal, selecting all of said connected terminals, except said master terminal, as slave terminals; · establishing by each terminal that each of said remaining interconnected terminals is certified by a common certification authority;
directly developing a single-session session key among said connected terminals; and initiating a secure teleconference call among each of said interconnected terminals to provide for secure voice and data communication among said interconnected terminals.
According to a still further aspect of the present invention there is provided a secure teleconferencing method via a switching network for establishing a secure teleconference among a plurality of interconnected terminals which have been previously certified by a common authority, said secure teleconferencing method comprising the steps of:
selecting any one of said connected terminals to be a master terminal;
selecting all of said connected terminals, except said master terminal, as slave terminals;
establishing by each terminal that each of said remaining interconnected terminals is certified by a common certification authority; and directly developing a single-session session key among said connected terminals for providing secure voice and data communication among said interconnected terminals.
A preferred embodiment of the present invention will now be described with reference to the accompanying drawings wherein: FIG. 1 is a block diagram of a teleconferencing arrangement via a switching network.
FIGS. 2A and 2B are flow charts of a secure teleconferencing method embodying the principles of operation of the present invention.
FIGS. 3A and 3B are timing diagrams of inter-terminal message transmission.
<img file="AU629641B2_D0003.tif" />
ί
2bFIG. 4 is a block diagram depicting the exclusive-OR operation of each terminal.
—\
FIG. 1 depicts a number of terminals (A, B, C· and D) 5 connected to a switching network. This switching network includes circuitry which can provide for teleconferencing among these four terminals. Four terminals are shown here by way of example and not by way of limitation. Almost any number of terminals may be connected in the teleconferencing
<img file="AU629641B2_D0004.tif" />
. 'lUu......
* β * t β « < » « β < ( β t » I ♦ if t i f u t ' t t .t i
U ? :
t i <
t 1 t i i · * ι β ft o t 9 »*80
4 β β ( ft 4
C «
I 4 9 ( ( ft lit t arrangement. The only limitations are the number of terminals which may physically be interconnected by the switching system.
In the present system, each of the terminals is a secure voice and data terminal. Each terminal includes the present secure teleconferencing method. This method may typically be implemented in software. However, hardware implementations are also possible.
The secure terminals A-D are designed for both full duplex and half duplex voice and data communication. Half duplex voice and data communication takes place over two wire communication networks. Full duplex voice and data communication occurs over four-wire telecommunication networks. For full duplex transmission, information is received and transmitted over two separate pairs of wires (channels) simultaneously. In half duplex transmission, a terminal puts energy on the line only when transmitting information. When its transmission is complete, its energy is removed allowing another terminal to transmit on the same channel. Teleconferencing is much more straight forward in the half duplex configuration, since energy is on the line only when a particular terminal is transmitting.
The present method pertains more readily to the half duplex communication mode. However, via time sharing existing channels or establishing a new channel, one per added terminal, this method is also applicable to the full duplex transmission mode. Each of the terminals A-D include a half duplex modem. Each terminal includes input devices such as a push button for indicating that the teleconferencing mode is selected and that the secure mode is selected. Each terminal also includes the ability to display the identify of each of the other teleconferencers. These identities may be scrolled on a visual display for the user of each terminal.
i;
. t ft a e β o « 0 β 0 9
O 0 0 0 9 *
9« a β e « o <t β 1 « « « 4 β β β 6
Ο Ο » ο ο « β β Ο 4
Ο Ο ¢4 β Ο ο ο © β β S ο ο ο Ο ο «β φ ο β ο ο ο « soft ft
I t t 4 It C < 1
For security, each of the terminals employ a type of asymmetric RSA public encryption and private decryption process. The encryption process is noted by EM and the decryption process is noted by DM.
Turning now to FIGS. 2A and B, the secure teleconferencing method is shown. First, the users go off hook, block 1. Next, all the users are established in an unsecured teleconferenced arrangement via a usually switching system procedures, block 2. This is accomplished in the typical manner through conference circuitry in the switching network. The call or data transmission at this point is unsecured.
To accomplish the teleconference, each of the users of terminals A-D selects the conference mode via pushing a conference push button on his or her terminal. Next, one of the users presses the secure key on his or her terminal, block 3. This serves two functions. First, that terminal becomes the master terminal for controlling the teleconference function. Since all of the terminals include the present method, any of the terminals may be the master for the teleconference. The determination of the master terminal for teleconference is determined by the first to press the secure key on his terminal.
The second function of the master terminal is to transmit its access domain message in half duplex to each of the other conferenced terminals. To accomplish this, the master transmits P1800 data, block 3, stops transmitting for 256 bits (block 4), and sends P1800 data of 776 bits (block 5) followed by SCR1 data (scrambled ones for synchronization), block 6. Meanwhile, the slaves are set in the half duplex mode, block 7. The slave confirms the stop gap, block 8. The slaves detect the P1800 data, block 9, and train their modem to receive, 10. The master sends the ίΓ β Ο -Β 0 0 ο ο 9 Ο ο
Ο R5 « Ο Ο
0 9 Ο
Ο ««»099 Ο Ο
Ο »9
9 9
Ο Ο « Ο
Ο 0 9
0 Ο β 60 Ο
Ο Ο 9 Ο
6ίί0 Ο Ο β ο« « ί
·«»<<« < Ί
It 4 « < € i • 4 access domain message (ADM), 11. This is followed by an end of message (Ε0Μ) indication, block 12.
Next, each slave receives the access domain message and stores it for later processing, block 13. The access domain messages of the master and other slave terminals are processed when the master's authentication message has been received.
The transmission of master's access domain message occurs as shown in FIG. 3A. The master first sends a P1800 protocol, followed by a gap, followed by another P1800 protocol, an SCR1 (scrambled l's and 0's for modem synchronization) bit stream and then the bit stream of the access domain message, followed by an end of message (not shown). Each slave then responds in an appropriate time slot, is determined by a queue index function. This queue index function may be implemented in a number of ways, such as, a strictly arbitrary sequence.
The master terminal then sets its modem in the receive mode, blocks 14 and 15.
Next, each slave in the teleconference responds with its access domain message in the selected time slot. Since the slave terminals have received the master's access domain message, the NO path has been followed from block 16 to block 17. Next, it is the slave's turn to send its access domain message, the YES path is followed from block 17 to block 18. In FIG. 3A, slave 1 responds with its P1800 protocol (block 18) followed by SCRl (block 19), and its access domain message ADM block 20 followed by EOM, block 21. Similarly, each slave responds in its time slot. Slave
2 responds in time slot 2. Slave n responds in time slot n.
The master terminal receives all the access domain messages of each of the slaves, block 22. Block 23 determines whether all the slaves have responded. If all the slaves have not responded, block 23 transfers control to block 14 * λ*.· » ·<
« ββ « 0 9 • ο ο ο
C & © ο © β Ο Ο © β β
© © β β < < © « © e © ο © ο β © -α &
ο & ©
Ο <> 0 © © © ο © © »© © © © « ο © © © © © θ © © « W © to wait for a response. When all the slave terminals respond, the master (block 24) processes the access domain messages of each of the slaves.
Next, the master sends its authentication message to 5 each of the slaves, blocks 25 through 28. The authentication message of the master terminal is given by equation (1).
<img file="AU629641B2_D0005.tif" />
<img file="AU629641B2_D0006.tif" />
ο
Μ 9 © « « © Ο θ © Ο « ©do ο ©
AM<sub>m</sub> - [(IDmaster,EM<sub>mas</sub>ter)1xDMkca Equation (1)
The Authentication Message identifies the particular master terminal, its public or encrypt key and the private decrypt key of its certification authority (KCA). This message is valid only if it is certified by the key certification authority. Further, each of the other terminals may decode this message only if they are certified under the same key certification authority.
Block 16 determines for each slave terminal that this is the authentication message. As a result, block 16 transfers control to block 29 which processes the master access domain message (ADM<sub>m</sub>) and the other slaves' access domain messages (ADM<sub>sn</sub>'s) . Once the access domain messages have been thereby exchanged, each terminal can determine the identity of the terminal to which it is connected via the teleconference and that they are certified by a common certifying authority such as a KCA. FIG. 3B depicts this transmission of the master. This transmission consists of the 1800 protocol followed by the SRC1 bits, followed by the authorization message and an EOM (not shown). The master terminal sets itself to receive the authentication messages of the slaves, blocks 31 and 32. Next, each slave terminal processes the authentication message of the master (AM<sub>m</sub>) ,
PS ^UdtOrca-ncAop·block 30. Each slave terminal generates a unique/randetftnumber (RN<sub>s</sub>)and a random>component message (RCM) from the
<img file="AU629641B2_D0007.tif" />
ps e.o A ό r ο-n <Xo γλ random/number, block 33. The RCM is made by encrypting the ·“* PSC-oAoro-nAo rrv slave's unique random·^ number in the master's public key as shown in Equation (2):
(RNg(n)) X EM<sub>m</sub>aster - RCMg(n)
Equation (2) a p © a © t a t> o a a © a a a δ aw® o a ft ·» ·» « 4 pse-oAtf rour\A o m.
Each slave, then, stores a copy of its unique sandogfrjnunber for later use in the final stages of this process. Each slave then responds in its appropriate time slot with its psaoAo i-tviiom authorization message followed by its randem-^component message. The slave authorization message is similar to the master's authorization message. It is shown in Equation (3) .
AMs ~ t(IDslaverEMslave)]KDMkca
Equation (3)
SHCtJ 3 C © 0 0 ©
0 0 0 P © X «0 ί
M 4 t ( ( * 1 «ft ( ft
It includes the identity of the slave, the public key of the slave covered by the private key of the certifying authority or KCA.
When each slave determines that its time slot is present, that slave broadcasts its authorization message (AM<sub>S</sub>), block 34. The slave terminal initialize its modem, blocks 35 and 36. Next, the authorization message (AM<sub>S</sub>) and P 5 ev> Aotcko A om gandom^component message (RCMg) of each slave is transmitted to each of the other slaves, including the master terminal, block 37, followed by an end of message (EOM), block 38. Block 38 transfers control to block 34. Since this slave terminal has transmitted its AM<sub>S</sub> and RCMg, block 34 transfers control to block 39.
The transmission for slave 1 is shown in FIG. 3B.
First the 1800 protocol is sent, then the SCR1 bits, the authorization message of slave 1, followed by approximately
200 milliseconds of filler- which is a predefined binary bit pseo<\or-<xv\ pattern and finally the »^anddm|Component message of the , i
<img file="AU629641B2_D0008.tif" />
, <
«9 «9 4 © ft
0> Ο 4 tt * Ο
1>'J< 9
Ο <?Ο OS φ tt » ft ft β ® 5 9 > «ι β ft « ft ο ft ft « β <
« 4 I ί < 1 ι t I . U 4 slave 1 and end of message indication (not shown). Each slave similarly responds in its assigned time slot.
Each slave terminal sets its modem to receive the other terminals AMs and RCMs messages, blocks 40 and 41. Each slave terminal receives the other slave terminals' AMs and ROMs, block 42. Also, simultaneously the master terminal receives each of the slave terminals' AM<sub>S</sub> and RCMs messages, block 43.
When all the slave terminals have responded, each block of each slave terminal transfers control to block 44.
Simultaneously, when the master terminal has received all the AMs and RCM<sub>S</sub> messages, block 45 transfers control to block 46. , \ v <sub>Λ</sub> pseu Λο ro-n <Aoro
The gandom^component message of each terminal includes a unique random number generated by that terminal. This ps <s-u AoccuacVo/v-, ra-ndeminumber is transmitted to the master terminal and is pse-Odorcu-iAorA
The random··.number is k pseoAoro-(\tkc,m also stored within the terminal.
encrypted with the master's public key to form the^-randomcomponent message. Therefore, even through all of the other slave terminals in the teleconference may receive the RCM, they will not be able to decrypt it.
As a result of these transmissions, each slave terminal receives all the authorization messages of the other terminals. Each slave then processes each of the authorization messages of the other slaves, block 44. This includes extracting the identity of each of the other slaves which have been covered by the private key of the certifying authority. The identity of each of the slaves is then scrolled on a viewing device of the terminal in the order in which they are received. As a result, each terminal has established the certified identity of each of the other conferees .
The master terminal has also received each of the authentication messages of the other terminals and processed \
<img file="AU629641B2_D0009.tif" />
ft Ο 0 0 ft 0 0 θ 0 ft ο β ο 2 5* ft β 0 ft Ο βββ ο
Ο θ β 9 ft ft β ο β
Oft ft β ο ο ft ft ft » β * Oft ft
Ο β β ft » » ο
A ft 0 β ft · θ ft 9
Ο Ο
Ο ft ft ft Ο ft ft ο ft »
Oft Oft ο Ο » «I ft »9
35.
Β 9 ft 9 « ft
r. · « » » t them similarly to that described above for the slave, block 46. Next, the master decrypts each of the slave's pseudorandom component message, block 46. Since each of the slave's pseudorandom component message has been convered with the master's public key, the master may decrypt them by applying his private key since this is an asymmetric or one-way function. Each slave sets its modem to receive a message from the master terminal, blocks 47 and 48.
When the master terminal receives each of the authorization messages, it decodes each of the other terminals' identification. In addition, the master terminal then scrolls each of the identities of the slave terminals on each visual display on the terminal. Next, the master terminal decrypts each of the slave's pseudorandom component message. Since each of the slaves have covered their pseudorandom component with the master's public encrypt key, only the master is able to decode each of the pseudorandom component messages by application of his private decrypt key. The pseudorandom component is a predetermined number of bits of information. The pseudorandom component is, as its name implies, generated pseudorandomly by each of the terminals. The larger in terms of bits the pseudorandom component is, the more difficult this component is to determine for purposes of listening. As a result, the master terminal obtains each of the slave terminals pseudorandom components. In addition, the master terminal has stored its previuosly generated pseudorandom component.
Next, the master terminal generates a set of pseudorandom numbers based upon each of the slave's pseudorandom numbers and the master's pseudorandom component or number, block 49. The equations for generating this set of pseudorandom numbers are shown by Equation Set (4).
RNs(1)+RNs(2)+ RNs(1)+RNs (2) + RNs(l)+RNs(2)+
RNs(l) + RNs(3) + RNs(2) + RNs (3) +
<img file="AU629641B2_D0010.tif" />
RNs)n-1)+RNm
RNs(n-2)+RNs(n)+RNra
RNs(n-3)+RNs(n-1)+RNs(n)+RNm
RNs(n) + RNm
RNs (n) + RNm
Equation Set (4)
RNs(n)' RNs(n-1) RNs(n-2)'
RNs(2)' RNs(1)’
Examining the last equation of the sets of equations in Equation Set (4) as an example, it can be seen that the new pseudorandom number for slave 1 RNs(l)' is comprised of each of the pseudorandom numbers of the other slaves and the master. These pseudorandom numbers are exclusive-ORd. Each of the + symbols represents an exclusive-OR operation. The new pseudorandom number for slave 2 RNs(2)' is an exclusive-OR of each of the other terminal’s pseudorandom numbers except terminal 2. As a result, the master terminal generates one new pseudorandom number for each of the terminals in the teleconference which is an exclusive-OR of all the other terminals in that teleconferenced pseudorandom number except the terminal to which that pseudorandom number is to be sent.
The terminal to which the pseudorandom number is to be sent has previously stored its own pseudorandom number.
Therefore in FIG. 4, when a given terminal receives the new pseudorandom number from the master terminal, it must simply exclusive-OR 99 its own stored pseudorandom number with the primed pseudorandom number sent from the master terminal. As a result, the terminals have developed a session key. This session key is useful only for this session and is generated for each teleconference call. The generation and transmission of the session key also obeys the two-man rule, in that ; ,··, interception of a single message will not result in obtaining ft »2*5·,, the pseudorandom component and hence, the session key.
*> 4 ft *** The master terminal covers each of the newly ee^efte generated primed pseudorandom numbers with the public encrypt e ' ft key of the slave terminal to receive that pseudorandom number ewe in Equation Set (5):
[RN(1)’]xEM<sub>slavel</sub> = RCMm (1) [RN<2)’]xEM<sub>slave2</sub> = RCMm (2) as shown ft re o w © »© «» ο
35.
ft Λ ft » {RN(n-l)’]xEM<sub>slave</sub> = RCMm (n-1) {RN(n)’]xEM<sub>slave (n)</sub> = RCMm (n)
<img file="AU629641B2_D0011.tif" />
ί
Again, since the new primed pseudorandom number is covered by the slave public encrypt key, only that particular slave may decode using his private decrypt key the new primed pseudorandom component message. The master generates one such pseudorandom component message for each slave, covering that message with the slave's public encrypt key.
Next, the master general js a crypto synchronization pattern (CS), block 50. The master terminal now formats the final secure call setup message. This message is formulated with the P1800 protocol (block 51) followed by the SCR1 information (block 52), followed by the pseudorandom component message of each slave in the appropriate, time slot. A predetermined amount of filler bits follow the last pseudorandom component message. After the filler bits, the crypto synchronization message is sent to all terminals by the master. The crypto synchronization message indicates the point at which the symmetric encrypt/decrypt function is to begin. The master terminal then transmits the formatted message (corresponding primed pseudorandom number) followed by crypto synchronization message, block 53, followed by an EOM, block 54.
25· : 3o:
<img file="AU629641B2_D0012.tif" />
a a a w a a a a “3*5
<img file="AU629641B2_D0013.tif" />
I
Λ©γλ ft < t ·
I ft ft « β β β I « » a © β © a ft β » ft <
β β <
pseud orcxnAom
Each slave terminal then receives its new primed^randoro component message, block 55. In addition, each terminal receives the crypto synchronization message, block 56.
pseuAero-nAopA
Next, each terminal processes the new primedirandom— component message by exclusive-ORing the primed^randem component which it received with its own previously stored pS eu ό.ν orv\
-random^component, block 57. This exclusive-OR produces a session key. Each of the terminals now have this session key. Therefore, this session key may be used by each terminal's symmetric encrypt/decrypt process to provide secure communications between each of the terminals in a teleconferencing arrangement. A minimal number of messages has been used to achieve security.
Lastly, each terminal processes the crypto synchronization message, block 58. This starts each of the symmetric encrypt/decrypt functions at a predetermined point. Therefore, since each terminal has the key and the starting point, it can encode and decode information transmitted to and received from the other terminals in a secure manner.
Although the preferred embodiment of the invention has been illustrated, and that form described in detail, it will be readily apparent to those skilled in the art that various modifications may be made therein without departing from the spirit of the invention or from the scope of the appended claims .
<img file="AU629641B2_D0014.tif" />
ί:
< t < ft I («14 t « ♦ « « ft 4 « « * 0
Contents3
14 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US3674936A | Cites | United States of America | Search report |
| US4182933A | Cites | United States of America | Search report |
| US4888801A | Cites | United States of America | Search report |
12 members in 7 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 36189889 | United States of America | A | |
| 361898 | – | – | – |
| US19890361898 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| AU5615590A | Australia | A | |
| EP0402083A2 | European Patent Office (EPO) | A2 | |
| US5003593A | United States of America | A | |
| KR920003783A | Republic of Korea | A | |
| EP0402083A3 | European Patent Office (EPO) | A3 | |
| AU629641B2This record | Australia | B2 | |
| EP0402083B1 | European Patent Office (EPO) | B1 | |
| DE69029877D1 | Germany | D1 | |
| ES2097134T3 | Spain | T3 | |
| DE69029877T2 | Germany | T2 | |
| KR0155164B1 | Republic of Korea | B1 | |
| HK1007261A1 | Hong Kong, China | A1 |
Numbers
- Publication, DOCDB
- 629641
- Publication, EPODOC
- AU629641B
- Application
- 5615590
- Application, DOCDB
- 5615590
- Application, EPODOC
- AU19900056155
Titles
- English
- TELECONFERENCING METHOD FOR A SECURE KEY MANAGEMENT SYSTEM
Classification
- CPC, 5
- H04M3/16
- H04L9/0833
- H04M3/56
- H04M11/06
- H04M2203/609