Method and apparatus for security in a data processing system
Abstract
"SECURITY METHOD AND EQUIPMENT IN A DATA PROCESSING SYSTEM". It is a method and equipment for secure transmissions. Each user is provided with a registration key. An updated long-term broadcast key is encrypted using the registration key and provided periodically to a user. An updated short key is encrypted using the broadcast key. The short key is available with each broadcast message, where sufficient information to calculate the short key is provided in an Internet protocol header that precedes the broadcast content. Broadcasts are then encrypted using the short key, in which the user decodes the broadcast message using the short key.

Term
Term ended
Projected expiry passed 8 October 2022, 4 years ago.
- Priority
- Filed
- Projected expiry
- Today
5 claims: 1 independent, 4 dependent
- 1REIVINDICAÇÕES 1. Um método para transmissões seguras, o método compreendendo:determinar uma chave de curta duração para uma mensagem a ser transmitida, a chave de curta duração possuindo um identificador de chave curta duração;determinar uma chave de acesso para a mensagem, a chave de acesso possuindo um identificador de chave de acesso;codificar a mensagem com a chave de acesso;formar um cabeçalho de protocolo Internet que compreenda o identificador de chave de curta duração;e transmitir a mensagem codificada com o cabeçalho de protocolo Internet.
- 2O método, de acordo com a reivindicação 1, no qual o identificador de chave de curta duração compreende o identificador de chave de acesso.
- 30 método, de acordo com a reivindicação 2, no qual o identificador de chave de curta duração compreende qual a chave de curta duração é calculada como uma função do identificador de chave de curta duração e da chave de acesso. 6. O método, de acordo com a reivindicação 5, no qual o identificador de chave de curta duração é calculado pela codificação do identificador de chave de curta duração com a chave de acesso. 2/5 7. O método, de acordo com a reivindicação 1, no qual o cabeçalho de protocolo Internet é parte de um cabeçalho ESP. 8. O método, de acordo com a reivindicação 7, no qual o cabeçalho de protocolo Internet compreende também um segundo número aleatório, o segundo número aleatório possuindo um identificador de números aleatórios. 9. O método, de acordo com a reivindicação 8, no qual o identificador de chave de curta duração compreende o identificador de chave de acesso e o identificador de números aleatórios. 10. O método, de acordo com a reivindicação 9, no qual o identificador de chave de curta duração compreende também um valor de índice de parâmetro de segurança. 11. 0 método, de acordo com a reivindicação 10, no qual o valor de índice de parâmetro de segurança é um número aleatório. 12. O método, de acordo com a reivindicação 8, no qual a chave de curta duração é calculada como uma função do identificador de chave de curta duração, do segundo número aleatório e da chave de acesso. 13. 0 método, de acordo com a reivindicação 12, no qual o identificador de chave de curta duração é calculado pela codificação do identificador de chave de curta duração e do segundo número aleatório com a chave de acesso. 14. Um método para recepção segura de uma transmissão, o método compreendendo:receber um identificador de chave de curta duração específico de uma transmissão, o identificador de chave de curta duração correspondendo a uma chave de curta duração;3/5 determinar uma chave de acesso com base no identificador de chave de curta duração;codificar o identificador de chave de curta duração com a chave de acesso de modo a recuperar a chave de curta duração;e decodificar a transmissão utilizando-se a chave de curta duração. 15. O método, de acordo com a reivindicação 14, compreendendo também: armazenar o identificador de chave de curta duração e a chave de curta duração em uma unidade de armazenamento de memória. 16. O método, de acordo com a reivindicação 14, no qual o identificador de chave de curta duração é constituído por um número aleatório e um por um identificador de chave de acesso associado à chave de acesso. 17. O método, de acordo com a reivindicação 14, no qual a codificação do identificador de chave de curta duração compreende também codificar o identificador de chave de curta duração e um número aleatório com a chave de acesso de modo a recuperar a chave de curta duração. 18. Um elemento de infra-estrutura em um sistema de comunicação sem fio que suporta uma opção de serviço de broadcast, o elemento de infra-estrutura compreendendo: um conjunto de circuitos de recepção;uma unidade de identificação de usuário, operativa para recuperar uma chave de curta duração para decodificar uma mensagem de broadcast, compreendendo: uma unidade de processamento operativa para decodificar informações de chave;e uma unidade de equipamento móvel adaptada para aplicar a chave de curta duração
- 44/5 para decodificar a mensagem de broadcast, compreendendo:uma unidade de armazenamento de memória para armazenar uma pluralidade de chaves de curta duração e identificadores de chave de curta duração. 19. O elemento de infra-estrutura, de acordo com a reivindicação 15, no qual a unidade de identificação de usuário compreende também uma segunda unidade de armazenamento de memória para armazenar uma pluralidade de chaves de acesso e identificadores de chave de acesso. 20. O elemento de infra-estrutura, de acordo com a reivindicação 15, no qual a unidade de armazenamento de memória é uma unidade de armazenamento de memória segura. 21. Um elemento de infra-estrutura para um sistema de comunicação sem fio, compreendendo: dispositivo para receber um identificador de chave de curta duração específico de uma transmissão, o identificador de chave de curta duração correspondendo a uma chave de curta duração;dispositivo para determinar uma chave de acesso com base no identificador de chave de curta duração;dispositivo para codificar o identificador de chave de curta duração com a chave de acesso de modo a recuperar a chave de curta duração;e dispositivo para decodificar a transmissão utilizando a chave de curta duração. 22. Um dispositivo de armazenamento de sinais digitais, compreendendo: um primeiro conjunto de instruções para receber um identificador de chave de curta duração específico de
- 55/5 uma transmissão, o identificador de chave de curta duração correspondendo a uma chave de curta duração; um segundo conjunto de instruções para determinar uma chave de acesso com base no identificador de chave de curta duração; um terceiro conjunto de instruções para codificar o identificador de chave de curta duração com a chave de acesso de modo a recuperar a chave de curta duração; e um quarto conjunto de instruções para decodificar a transmissão utilizando a chave de curta duração. 23. Um sinal de comunicação transmitido em uma onda portadora, compreendendo:uma primeira parte correspondente a um identificador de chave de curta duração, o identificador de chave de curta duração possuindo uma chave de curta duração correspondente;e uma segunda parte correspondente a uma carga útil de transmissão codificada utilizando a chave de curta duração. 24. O sinal de comunicação, de acordo com a reivindicação 23, no qual o identificador de chave de curta duração compreende: uma parte de número aleatório;e um identificador de chave de acesso correspondente a uma chave de acesso. 1/22 2/22 Ο Xt
Independent claims5
242 paragraphs in 5 sections, as filed
(54) Title: SECURITY METHOD AND EQUIPMENT IN A DATA PROCESSING SYSTEM (30) Unionist Priority: 10/9/2001 us 09 / 973,301 (71) Depositor (s): Qualcomm Incorporated (US) (72) Inventor ( es): Philip Hawkes, Nikolai KN Leung, Gregory G. Rose (74) Attorney: Montaury Pimenta, Machado & Lioce S / C Ltda (86) International Order: pct US02 / 32054 of 10/8/2002 (87) International Publication: wo 03/032573 of 17/04/2003 (57 ) Abstract: SECURITY METHOD AND EQUIPMENT IN A DATA PROCESSING SYSTEM. It is a method and equipment for secure transmissions. Each user is provided with a registration key. An updated long-term broadcast key is encrypted using the registration key and provided periodically to a user. An updated short key is encrypted using the broadcast key. The short key is available with each broadcast message, where sufficient information to calculate the short key is provided in an Internet protocol header that precedes the broadcast content. Broadcasts are then encrypted using the short key, where the user decodes the broadcast message using the short key.
<img file="BR0213214A_D0001.tif" />
SEND MESSAGE BC
ENCODED WITH SPI_SK
ESP 216 HEADER
<img file="BR0213214A_D0002.tif" />
Invention Patent Descriptive Report: METHOD AND SAFETY EQUIPMENT IN A DATA PROCESSING SYSTEM
FUNDAMENTALS
Field
The present invention relates generally to data processing systems and, specifically, to methods and equipment for obtaining security in a data processing system.
Foundation
Security in data processing and information systems, including communication systems, contributes to accountability, clarity, accuracy, confidentiality, operational capacity, as well as an excessive amount of other desired criteria. Encryption, or the general field of cryptography, is used in electronic commerce, wireless communications, and broadcasting (broadcasting), and has an unlimited range of applications. In electronic commerce, encryption is used to prevent fraud in and verify financial transactions. In data processing systems, encryption is used to verify the identity of a participant. Encryption is also used to prevent piracy, protect web pages and prevent access to confidential documents, as well as various security measures.
Systems that employ encryption, often referred to as cryptographic systems, can be partitioned into symmetric cryptographic systems and asymmetric cryptographic systems. A symmetric encryption system uses the same key (that is, the secret key) to encrypt and decrypt a
2/57 message. Whereas an asymmetric encryption system uses a first key (ie, the public key) to encrypt a message and uses a second, different key (ie, the private key) to decrypt it. Asymmetric cryptographic systems are also called public key cryptographic systems. There is a problem with cryptographic systems with respect to securely providing a sender's secret key to a recipient. In addition, there is a problem when keys or other encryption mechanisms are updated frequently. In a data processing system, methods for securely updating keys incur additional processing time, memory storage, and other processing overhead. In a wireless communication system, updating keys uses valuable bandwidth otherwise available for transmission.
The prior art does not provide a method for updating keys for a large group of mobile stations so that they can access an encrypted broadcast. There is a need, therefore, for a safe and efficient method to update keys in a data processing system. There is also a need for a safe and efficient method for updating keys in a wireless communication system.
SUMMARY
The modalities presented here meet the needs mentioned above by presenting a method to obtain security in a data processing system. In one respect, a method for secure transmissions includes determining a short key for a message for transmission, where the short key has a short key identifier, determining a passkey for the message, where the key of
3/57 access has an access key identifier, encrypt the message with the access key, form an Internet protocol header that comprises the short key identifier and transmit the encrypted message with the Internet protocol header.
In another aspect, in a wireless communication system that supports a broadcast service option, an infrastructure element includes a set of reception circuits, a user identification unit, operative to retrieve a short key for decode a broadcast message, and a mobile equipment unit adapted to apply the short-term key to decode the broadcast message. The user identification unit includes an operating processing unit for decoding key information. The mobile equipment unit includes a memory storage unit for storing a multitude of short-term keys and short-term key identifiers.
In yet another aspect, a digital signal storage device includes a first set of instructions for receiving a specific short-term key identifier for a transmission, the short-term key identifier corresponding to a short-term key, a second set instructions for determining a passkey based on the short-term key identifier, a third set of instructions for encrypting the short-term key identifier with the passkey in order to retrieve the short-term key, and a fourth set of instructions for decoding the transmission using the short-term key.
4/57
<td>SHORT</td><td>DESCRIPTION OF THE DRAWINGS</td><td></td>
<td>The figure</td><td>IA is a diagram of a</td><td>system</td>
<td>cryptographic.</td><td></td><td></td>
<td>The figure</td><td>1B is a diagram of a</td><td>system</td>
symmetric cryptographic.
<td>THE</td><td>figure</td><td>1C</td><td>it's a diagram</td><td>in</td><td>a system</td>
<td colspan="4">asymmetric cryptographic.</td><td></td><td></td>
<td>THE</td><td>figure</td><td>ID</td><td>is a diagram of</td><td>one</td><td>system of</td>
<td>coding</td><td>PGP.</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>figure</td><td>1 AND</td><td>is a diagram of</td><td>one</td><td>system of</td>
<td colspan="2">PGP decoding.</td><td></td><td></td><td></td><td></td>
<td>THE</td><td>figure</td><td> 2</td><td>is a diagram of</td><td>one</td><td>system of</td>
spectral spreading communication that supports numerous users.
Figure 3 is a block diagram of the communication system that supports broadcast transmissions.
Figure 4 is a block diagram of a mobile station in a wireless communication system.
Figures 5A and 5B exemplify models that describe the update of keys within a mobile station used to control access to the broadcast.
Figure 6 is a model that describes cryptographic operations within a UIM.
Figures 7A-7D exemplify a method for implementing security encryption in a wireless communication system that supports broadcast transmissions.
Figures 8A-8D exemplify the application of a security encryption method in a wireless communication system that supports broadcast transmissions.
Figure 9A exemplifies the format of an IPSec packet for an Internet Protocol transmission.
5/57
Figure 9Β exemplifies a Security Association Identifier or SPI (Security Association Identifier) as applicable to an IPSec package.
Figure 9C exemplifies a memory storage device for storing SPI information on a mobile station.
Figure 9D exemplifies a memory storage device for storing Broadcast Access Keys (BAKs) on a mobile station.
Figures 10 and 11 exemplify a method for providing security to a broadcast message on a wireless communication system.
Figure 12A exemplifies a Security Association Identifier or SPI as applicable to an IPSec package.
Figure 12B exemplifies a memory storage device for storing SPI information on a mobile station.
Figures 13 and 14 exemplify a method for providing security to a broadcast message in a wireless communication system.
DETAILED DESCRIPTION
The word exemplary is used exclusively here to mean that it serves as an example, case or illustration. Any modality described here as an example should not necessarily be understood as preferred or advantageous over other modalities.
Wireless communication systems are widely used to provide different types of communication, such as voice, data and so on. These systems can be based on code division multiple access (CDMA), time division multiple access (TDMA) or other modulation techniques. A CDMA system offers
6/57 certain advantages over other types of systems, including increased system capacity.
A system can be designed to support one or more standards, such as the TIA / EIA / IS-95-B Mobile Station-Base Station Compatibility Standard for Broadband and Dual-Mode Spectral Scattering, referred to here as the standard IS-95, the standard offered by a consortium called the 3Geration Partnership Project, referred to here as 3GPP and embodied in a set of documents that includes Documents Nos. 3G TS 25 211, 3G TS 25 212, 3G TS 25 213, 3G TS 25 214 and 3G TS 25 302, referred to here as the W-CDMA standard, the standard offered by a consortium called the 3-Generation 2 Partnership Project, referred to here as 3GPP2, and the TR-45 5, referred to here as the cdma2000 standard, previously called Is-2000 MC. The standards mentioned above are hereby expressly incorporated here by way of reference.
Each standard specifically defines data processing for transmission from the base station to the mobile station and vice versa. As an exemplary modality, the following discussion considers a communication system with spectral spreading compatible with cdma2000 systems. Alternative modalities may incorporate another standard / system. Still other modalities can apply the security methods presented here to any type of data processing system that uses a cryptographic system.
A cryptographic system is a method of hiding messages that allows a specific group of users to extract the message. Figure IA illustrates a basic cryptographic system, 10. Cryptography is the technique of creating and using cryptographic systems. Cryptographic analysis is the technique of breaking systems
7/57 cryptographic, that is, receiving and understanding the message when you are not within the specific group of users who have been allowed access to the message. The original message is referred to as a plaintext message or plain text. The encoded message is called encoded text, where encoding includes any means for converting plain text into encoded text. Decryption includes any means to convert encoded text to plain text, that is, to recover the original message. As shown in figure IA, the plain text message is encoded to form an encoded text. The encoded text is then received and decoded in order to recover the plain text. Although the terms plain text and coded text generally refer to data, coding concepts can be applied to any digital information, including audio and video data presented in digital form. Although the description of the invention presented here uses the terms plain text and coded text compatible with the encryption technique, these terms do not exclude other forms of digital communication.
A cryptographic system is based on secrets. A group of entities shares a secret if an entity outside this group cannot obtain the secret without a substantially large amount of resources.
A cryptographic system can be an assembly of algorithms, where each algorithm is labeled and the labels are called keys. A symmetric encryption system, often referred to as a cryptographic system, uses the same key (that is, the secret key) to encrypt and decrypt a message. A symmetric coding system, 20, is shown in figure 1B, in which both the
8/57 encryption and decryption use the same private key.
In contrast, an asymmetric encryption system uses a first key (such as the public key) to encrypt a message and uses a different key (such as the private key) to decrypt it. Figure 1C shows an asymmetric encryption system, 30, in which one key is provided for encryption and a second key for decryption. Asymmetric cryptographic systems are also called public key cryptographic systems. The public key is published and is available to encrypt any message, but only the private key can be used to decrypt the message encrypted with the public key.
There is a problem with symmetric cryptographic systems in securely delivering a sender's secret key to a recipient. In one solution, a messenger can be used to provide the information, or a more effective and secure solution can be to use a public key cryptographic system, such as a public key cryptographic system defined by Rivest, Shamir and Adleman (RSA), which is discussed below. 0 RSA system is used in the popular security tool referred to as PGPPretty Good Privacy, which is also detailed below. For example, a cryptographic system originally registered changed letters in plain text by shifting each letter into n in the alphabet, where n is a predetermined constant integer value. In such a scheme, an A is replaced by a D, etc., in which a given coding scheme can incorporate several different values of n. In this encryption scheme, n is the key. Intended recipients are provided with the
9/57 encoding before receiving the encoded text. In this way, those who know the technique must be able to decode the encoded text in order to recover the plain text. However, by calculating the key with knowledge of the encoding, the non-targeted parts may be able to intercept and decode the encoded text, creating a security problem.
More complicated and sophisticated cryptographic systems use strategic keys that prevent the interception and decryption of unintended parts. A classic cryptographic system uses E-coding and D-decoding functions, so that:
D_K (E__K (P)) = P, for any plain text P (1)
In a public-key cryptographic system, E_K is easily computed from a known public key Y, which in turn is computed from K. Public key Y is published, so that anyone can encrypt messages. The D_K decryption function is computed from the public key Y, but only with knowledge of a private key K. Without the private key K, an unintended recipient cannot decode the encrypted text thus generated. In this way, only the recipient who generated K can decode messages.
RSA is a public key cryptographic system defined by Rivest, Shamir and Adleman, in which, for example, simple texts consider positive integers up to 2<sup>512</sup>. Keys are quadruple (p, g, e, d), with p given as a prime number of 256 bits, g as a prime number of 2 58 bits and d and large numbers with (from - 1) divisible by (p-1) ( g-1). In addition, define the encoding function as:
E_K (P) = P<sup>and</sup> mod pg, D_K (C) = C<sup>d</sup> mod pg.
(2)
10/57
Although E_K is easily computed from the pair (pg, e), there is no known simple way to compute D_K from the pair (pg, e). Therefore, the recipient who generates K can publish (pg, e). It is possible to send a secret message to the recipient since he is the one capable of reading the message.
PGP combines aspects of symmetric and asymmetric coding. Figures ID and 1E show a cryptographic system PGP, 50, in which a simple text message is encoded and retrieved. In the figure ID, the plain text message is compressed in order to save the transmission time of the modem and space on the disk. Compression reinforces cryptographic security by adding another level of translation to encoding and decoding processing. Most cryptographic analysis techniques exploit patterns found in plain text, in order to break the secret code. Compression reduces these patterns in plain text, thereby increasing resistance to cryptographic analysis. Note that a modality does not include: plain text or other messages that are too short to compress, or that do not compress well.
PGP then creates a session key, which is a one-time secret key. This key is a random number that can be generated from any (any) event (s), such as random movements of a computer mouse and / or cursor movements while typing. The session key works with a secure encryption algorithm to encrypt plain text, resulting in encrypted text. Once the data is encrypted, the session key is then encrypted in the recipient's public key. The session key encoded in the public key
11/57 is transmitted together with the encoded text to the recipient.
For decryption, as shown in figure 1E, the recipient's PGP copy uses a private key to retrieve the temporary session key, which PGP then uses to decode the conventionally encrypted encrypted text. The combination of encryption methods takes advantage of the convenience of public key encryption and the speed of symmetric encryption. Symmetric encryption is generally much faster than public key encryption. Public key encryption, in turn, provides a solution to the issues of key distribution and data transmission. In combination, performance and key distribution are enhanced without sacrificing security.
A key is a value that works with a cryptographic algorithm to produce specific encrypted text. Keys are basically very large numbers. The key size is measured in bits. In public key cryptography, security increases with the size of the key, but the size of the public key and the size of the symmetrically encrypted private key are generally not related. Although the public and private keys are mathematically related, there is a difficulty in obtaining a private key given only one public key. Obtaining the private key is possible given sufficient time and computing power, making selecting the key size an important security issue. The ideal purpose is to maximize the key size for security reasons, while minimizing the key size to facilitate quick processing. Larger keys will be cryptographically secure for a longer period of time. An additional consideration is the
12/57 expected interceptor, specifically: 1) what is the importance of a message to a third party; and 2) how much resource a third party will have to decode the message.
Note that the keys are stored in encrypted form. PGP specifically stores keys in two files: one for public keys and one for private keys. These files are called keyrings. In the application, the PGP encryption system adds the public keys of the target recipients to the sender's public keyring. The sender's private keys are stored on the sender's private keyring.
As discussed in the examples given above, the method of distributing keys used in encryption and decryption can be complicated. The problem of key exchange involves first ensuring that keys are exchanged so that both the sender and the receiver can perform encryption and decryption, respectively, and for bidirectional communication, so that the sender and receiver can both encrypt and decrypt. decode messages. In addition, it is desirable that the exchange of keys is done in order to prevent interception by a third and unintended party.
Finally, an additional consideration concerns authentication, assuring the recipient that the message was encrypted by an intended sender and not by a third party. In a private key exchange system, keys are exchanged secretly, providing greater security in successful key exchange and valid authentication. Note that the private key encryption scheme implicitly provides authentication. The underlying assumption in a cryptographic private key system is that only the intended sender will have the key capable of
13/57 encode the messages transmitted to the intended receiver. Although public-key cryptographic methods solve an essential aspect of the 'key exchange problem', specifically their resistance to analysis even with the presence of a passive eavesdropper during key exchange, they still do not solve all problems. related to the exchange of keys. In particular, since the keys are considered to be 'public knowledge' (particularly with RSA), some other mechanism is desirable to provide authentication. Authentication is desirable as possession of keys only, and while sufficient to encrypt messages, it is not evidence of a unique unique identity of the sender, nor is it possession of a corresponding decryption key in itself sufficient to establish the identity of the recipient.
One solution is to develop a key distribution mechanism that ensures that the keys listed are actually those of the given entities, sometimes called a trusted authority, certification authority or third party guarantee agent. Typically, the authority does not actually generate keys, but it does ensure that the key lists and related identities, maintained and announced for reference by senders and recipients, are correct and not compromised. In another method, users are counted on to distribute and track each other's keys and trust in an informal, distributed way. According to the RSA system, if a user wishes to send evidence of his identity in addition to an encrypted message, a signature is encrypted with the private key. The receiver can use the RSA algorithm in reverse to verify that the information is decoded, so that only the sender can have
14/57 encrypted the plain text by using the secret key. Typically, the encoded 'signature' is a 'message compilation' that comprises a unique mathematical 'summary' of the secret message (if the signature was static across multiple messages, since previous known recipients could misuse it) . In this way, theoretically, only the sender of the message can generate a valid signature for that message, thus authenticating it to the receiver.
A message build is often computed using a cryptographic hash function. A cryptographic hash function computes a value (with a fixed number of bits) from any entry, regardless of the length of the entry. One property of the cryptographic hash function is this: given an output value, it is computationally difficult to determine an input that will result in that output. An example of a cryptographic hash function is SHA-1, as described in Secure Hash Standard, FIPS PUB 180-1, promulgated by the Federal Publications of Information Processing Standards (FIPS PUBS) and issued by the National Institute of Standards and Technology.
Figure 2 serves as an example of a communication system 100 that supports numerous users and is capable of implementing at least some aspects and modalities of the invention. Any of several algorithms and methods can be used to program transmissions in system 100. System 100 provides communication for numerous cells, from 102A to 102G, each of which is served by a corresponding base station, from 104A to 104G, respectively . In the exemplary embodiment, some of the base stations 104 have several receiving antennas, and others have only one receiving antenna. Similarly,
15/57 some of the base stations 104 have multiple transmit antennas, and others have unique transmit antennas. There are no restrictions on combinations of transmit and receive antennas. Therefore, it is possible for a base station 104 to have multiple transmit antennas and a single receive antenna, or to have multiple receive antennas and a single transmit antenna, or to have both single and multiple transmit and receive antennas.
Terminals 106 in the coverage area can be fixed (i.e., stationary) or mobile. As shown in figure 2, several terminals 106 are dispersed throughout the system. Each terminal 106 communicates with at least one and possibly more base stations 104 in the downlink and uplink at any given time, depending, for example, on whether a soft handoff is used or whether the terminal is designed and operated ( concurrently or sequentially) to receive multiple broadcasts from multiple base stations. Soft handoff in CDMA communication systems is well known in the art and is described in detail in U.S. Patent No. 5 101 501, entitled Method and System for providing a Soft Handoff in a CDMA Cellular Telephone System, which is assigned to the assignee of the present invention.
The downlink refers to the transmission from the base station to the terminal, and the uplink refers to the transmission from the terminal to the base station. In the exemplary embodiment, some of the terminals 106 have several receiving antennas and others have only one receiving antenna. In figure 2, base station 104A transmits data to terminals 106A and 106J on the downlink, base station 104B transmits data to terminals 106 and 106J, base station 104C transmits data to terminal 106C and so on.
16/57
The growing demand for wireless data transmission and the expansion of services available through wireless communication technology have led to the development of specific data services. A service that is referred to as High Data Rate (HDR). An exemplary HDR service is proposed in the High Rate Packet Data Air Specification cdma2000 EIA / TIA-IS856, referred to as the HDR specification. The HDR service is generally a cover for a voice communication system that provides an effective method of transmitting data packets in a wireless communication system. As the amount of data transmitted and the number of transmissions increases, the limited bandwidth available for radio transmissions becomes an essential resource. Therefore, there is a need for an effective and reasonable method to program transmissions in a communication system that optimizes the use of the width.
<td>band</td><td colspan="2">available.</td><td colspan="3">In the exemplary modality, the 100 system</td>
<td>shown</td><td>at</td><td>figure 2</td><td>it's compatible</td><td>with a system of</td><td>type</td>
<td>CDMA that</td><td colspan="3">have HDR service.</td><td></td><td></td>
<td></td><td>In</td><td>wake up</td><td colspan="2">with one modality, the system</td><td> 100</td>
<td>supports</td><td>one</td><td>service</td><td colspan="2">multimedia broadcast</td><td>high</td>
<td colspan="2">velocity</td><td>referred</td><td>as a Service</td><td>Broadcast</td><td>High</td>
<td colspan="2">velocity</td><td>(HSBS</td><td>High-Speed</td><td>Broadcast Service).</td><td>a</td>
exemplary application for HSBS is dragging on video of films, sporting events, etc. The HSBS service is a packet data service based on the Internet Protocol (IP). According to the exemplary modality, a service provider indicates the availability of such a high-speed broadcast service to users. Users who want the HSBS service subscribe in order to receive the service and can discover the schedule of broadcast services through advertisements, the
17/57
Short Management (SMS), Wireless Application Protocol (WAP), etc. Mobile users are referred to as Mobile Stations (MSs). Base stations (BSs) transmit parameters similar to HSBS in overhead messages. When an MS wants to receive the broadcast session, the MS reads the overhead messages and learns the appropriate settings. The MS then tunes to the frequency that contains the HSBS channel and receives the broadcast service content.
The service under consideration is a high speed multimedia broadcast service. This service is referred to as the High Speed Broadcast Service (HSBS) in this document. One such example is dragging on video of films, sporting events, etc. This service is likely to be a packet data service based on the Internet Protocol (IP).
The service provider will indicate the availability of such a high speed broadcast service to users. Users of the mobile station who desire such a service will subscribe to receive this service and can discover the broadcast service program through advertisements, SMS, WAP, etc. The base stations will transmit parameters related to the broadcast service in overhead messages. The units that wish to listen to the broadcast session will read these messages in order to determine the appropriate settings, tune in to the frequency that contains the high speed broadcast channel and start receiving the content of the broadcast service.
There are several possible subscription / revenue models for HSBS service, including open access, controlled access and partially controlled access. For free access, no subscription is required by the mobile to receive the service. BS transmits the content without coding, and interested mobile devices can receive the
18/57 content. The income for the service provider can be generated through advertisements, which can also be transmitted on the broadcast channel. For example, upcoming movie clips can be streamed for which studios will pay the service provider.
For controlled access, MS users will subscribe to the service and pay the corresponding fee to receive the broadcast service. Users who have not subscribed to the service cannot receive the HSBS service. Controlled access can be obtained by encrypting the transmission / HSBS content, so that only users who have a subscription can decode the content. They can use encryption key exchange procedures over the air. This scheme offers high security and prevents theft of the service.
A hybrid access scheme, referred to as partially controlled access, provides the service as a subscription-based service that is encrypted with intermittent unencrypted ad streams. These advertisements may be intended to encourage subscriptions to the encoded HSBS service. The programming of such non-coded segments can be known to the MS through external means.
A wireless communication system, 200, is shown in figure 3, in which video and audio information is provided to the Packaged Data Services Network (PDSN) 202 by a Content Server (CS-Content Server), 201. The video and audio information can be televised programming or radio broadcasting. The information is provided as packaged data, such as in IP packets. PDSN 202 processes IP packets for distribution within an Access Network (NAAccess NetWork). As shown, AN is defined as the
19/57 parts of the system that include a BS 204 in communication with several MSs 206. The PDSB 202 is coupled to the BS 204. For HSBS service, the BS 204 receives the information flow from the PDSN 202 and provides the information, in one channel assigned to subscribers within the 200 system. To control access, the content is encrypted by CS 201 before being supplied to PDSN 202. Subscribed users receive the decryption key so that IP packets can be decoded.
Figure 4 details an MS, 300, similar to MS 206 in figure 3. The MS 300 has an antenna, 302, coupled to a set of receiving circuits, 304. The MS 300 receives transmissions from a similar BS (not shown) to BS 204 of figure 3. The MS 300 includes a User Identification Module (UIM), 308, and a Mobile Device (ΜΕ), 306. The set of reception circuits is coupled to UIM 308 and ME 306. The UIM 308 applies security verification procedures for the HSBS transmission and provides the ME 306 with several keys. The ME 306 can be coupled to a 312 processing unit. The ME 306 performs substantial processing, which includes, but is not limited to, , decoding of HSBS content streams. The ME 306 includes a memory storage unit (MEM), 310. In the exemplary modality, the data in the ME 3 06 processing unit (not shown) and the data in the ME memory storage unit, MEM, 310 can be easily accessed by a non-subscriber through limited resources and, therefore, ME 306 is said to be unsafe. Any information passed to the ME 306 or processed by the ME 306 remains securely secret for only a small amount of time. It is therefore desirable that any secret information, such as a key (s), for example, shared with the ME 3 06 be changed frequently.
20/57
UIM 3.08 is entrusted with storing and processing secret information (such as encryption keys, for example) that must remain secret for a long time. Since UIM 308 is a secure unit, the secrets that are necessarily stored in it do not require a system to change secret information frequently. The UIM 308 includes a processing unit referred to as the Secure UIM Processing Unit (SUPU), 316, and a memory storage unit referred to as the Secure UIM Memory Unit (SUMU), 314 , which is reliably safe. Within UIM 308, SUMU 314 stores secret information in order to discourage unauthorized access to information. If the information is obtained from UIM 3 08, access will require a significantly large amount of resources. Also within UIM 308, SUPU 316 performs computations on values that can be external to UIM 308 and / or internal to UIM308. Computation results can be stored in SUMU 314 or passed to ME 306. Computations performed with SUPU 316 can only be obtained from UIM 308 by an entity with a significantly large amount of resources. Similarly, the outputs of the SUPU 316 that are designated as being stored within the SUMU 314 (but not transmitted to the ME 306) are designated so that the unauthorized interception requires a significantly large amount of resources. In one embodiment, UIM 308 is a stationary unit within the MS 300. Note that in addition to secure memory and processing within UIM 308, UIM 308 may also include non-secure memory and processing (not shown) to store information, including phone numbers,
21/57 e-mail addresses, information on web pages and URL addresses and / or programming functions, etc.
Alternative modalities may have a removable and / or reprogrammable UIM. In the exemplary modality, the SUPU 316 does not have significant processing power for functions other than security and key procedures, where security and key procedures can typically be used to allow the encoding of HSBS broadcast content. Alternative modalities can implement a UIM with higher processing power.
The UIM 308 is associated with a specific user and is basically used to check whether the MS 300 is entitled to the privileges provided to the user, such as access to the mobile telephone network, for example. Therefore, a user is associated with UIM 3.08, not an MS 300. The same user can be associated with multiple UIMs 308.
The broadcast service faces a problem in determining how to distribute keys to users with a subscription. To decode the broadcast content at a specific time, the ME must know the current decryption key. To avoid theft of the service, the decryption key must be changed frequently, such as, for example, the service updating the key every minute. These decryption keys are called Short-Term Key (SK). SK is used to decode broadcast content for a short period of time, so that SK can be assumed to have some amount of intrinsic monetary value for a user. For example, this intrinsic monetary value may be part of the registration costs. Suppose that the cost of obtaining a SK from the MEM 310 memory storage unit
22/57 subscriber exceeds SK's intrinsic monetary value. In other words, the cost of illegitimately obtaining SK exceeds the reward, resulting in no net benefit. Consequently, the need to protect SK in the memory storage unit, MEM 310, is reduced. However, if a secret key has a longer life span than SK's, the cost of illegitimate obtaining this secret key may actually be less than the reward. In this situation, there is a net benefit in illegitimate obtaining such a key from the MEM 310 memory storage unit. Hence, ideally, the MEM 310 memory storage unit will not store secrets with a longer life span than SK.
It is assumed that the channels used by the CS (not shown) to distribute SK to the various subscriber units are not secure. In other words, an optimal design will assume that the channels are not safe and will design SK accordingly. Therefore, when distributing a given SK, the CS wants to use a technique that hides the SK value from non-subscribed users. In addition, the CS distributes the SK to each of a potentially large number of subscribers for processing in the respective MEs within a relatively short time frame. The known secure methods of key transmission are traditionally slow and require transmission of a large number of keys. Key transmission methods are generally not feasible for the desirable combination of security and effectiveness criteria. The exemplary modality is a feasible method of distributing decryption keys to a large set of subscribers within a short time frame, so that non-subscribers cannot obtain the decryption keys.
23/57
The exemplary modality is described as transmitting information in Internet Protocol compatible packages, such as the IPSec packages, described below, and therefore the following description presents a brief introduction to the terminology used with reference to IPSec. This terminology is useful in the description of the exemplary modalities, but the use of this terminology is not intended to limit the exemplary modality to communications that use IPSec.
The fundamentals of IPSec are specified in the document RFC 1825 entitled Security Architecture for the Internet Protocol, by R. Atkinson, August 1995, in the document RFC 1826 entitled IP Authentication Header, by R. Atkinson, August 1995, and in the document RFC 1827 entitled R. Enckinsulating Security Payload (ESP), by R. Atkinson, August 1995. 0 Authentication header is a mechanism for providing integrity to IP datagrams, where IP datagrams are usually a collection of useful information, called a payload, combined with network control information and an IP header. Network routers use the IP header to direct the packet to the appropriate network node. In some circumstances, the authentication header may also provide authentication for IP datagrams. ESP (Encapsulating Security Unit) is a mechanism to provide confidentiality and integrity to IP datagrams and can be used in conjunction with the authentication header. IPSec uses security associations to describe parameters, such as the encryption key and encryption algorithm used to encrypt and / or authenticate communications between a group of entities. Note that the concept of association of
24/57 security is also valid when applied to cryptographic systems not based on IPSec.
An IPSec packet includes a 32-bit parameter called the Security Parameter Index (SPI), which is used, in conjunction with the destination address, to identify the security association used to encrypt and / or authenticate the IP datagram content. An entity can store security associations in a security association database and index security associations · according to the Destination Address and SPI. The encrypted content of an IPSec package is often called a payload.
In the exemplary modality, the MS 300 supports HSBS in a wireless communication system. To gain access to HSBS, the user must register and then subscribe to the service. Once the signature is enabled, the different keys are updated as needed. In the registration process, the CS and UIM 308 negotiate a security association and agree on a Registration Key (RKRegistration Key) and other parameters necessary for the security association between the user and the CS. 0 CS can then send UIM 308 more secret information encoded with the RK. The RK is kept as a secret in UIM 308, while the other parameters can be kept in ME 306. The RK is unique for a given UIM 308, that is, each user is assigned a different RK. The registration process alone does not give the user access to HSBS.
As stated above, after registration the user subscribes to the service. In the subscription process, the CS sends UIM 308 the value of a common Broadcast Access Key (BAK - Broadcast Access Key). Note that, although RK is specific to UIM 308, BAK is used to encode a broadcast message for
25/57 multiple users. The CS sends to MS 300, and specifically to UIM 308, the value of the BAK encoded using the unique RK of UIM 308. The UIM 308 is able to retrieve the value of the original BAK from the encoded version using the RK. BAK, together with other parameters, forms a security association between the CS and the group of subscribing users. BAK is kept a secret in the ME 306. The CS then transmits data called SK Information (SKI) which is combined with BAK on UIM 308 in order to obtain the SK. The UIM 308 then passes the SK to the ME 306. In this way, the CS can effectively distribute new SK values to the ME of the subscribing users. Below are several examples of how SK is obtained from SKI and the forms that SKI can take. Registration and subscription processes are discussed in detail, after which SKI and SK are described.
Regarding registration, when a user registers with a given CS, UIM 308 and CS (not shown) establish a security association. That is, UIM 308 and CS agree on a secret RK registry key. The RK is unique for each UIM 308, although if a user has multiple UIMs, these UIMs may share the same RK, depending on the CS policy. This registration can occur when the user subscribes to a broadcast channel offered by the CS, or it can occur before the subscription. A single CS can offer multiple broadcast channels. The CS can choose to associate the user with the same RK for all channels or require the user to register for each channel and associate the same user with different RKs on different channels. Multiple CSs can choose to use the same registration keys or require the user to register and obtain a different RK for each CS.
26/57
Three common roadmaps for establishing this security association include: 1) the Authenticated Key Agreement (AKA) method, which is used in 3GPP systems; 2) the Internet Key Exchange (IKE) method, used in IPSec; and 3) Provision of Services Over the Air (OTASP - Over-The-Air-Service-Providing). In any case, the UIM SUMU 314 memory unit contains a secret key referred to here as key A. For example, using the AKA method, key A is a secret known only to UIM and a Trusted Third Party (TTP), where TTP can consist of more than one entity. TTP is typically the mobile service provider with which the user is registered. All communication between the CS and TTP is secure, and the CS trusts that TTP will not allow unauthorized access to the broadcast service. When the user registers, the CS informs the TTP that the user wishes to register for the service and checks the user's request. TTP uses a function, similar to a cryptographic hash function, to compute the RK from key A and additional data called Registry Key Information (RKI). The TTP passes the RK and / or the RKI to the CS through a secure channel together with other data. The CS sends the RKI to the MS 306. The receiving circuit set 034 passes the RKI to the UIM 308 and can pass the RKI to the ME 306. The UIM 308 computes the RK from the RKI and key A which is stored in the UIM SUMU 314 memory unit. The RK is stored in the UIM SUMU 314 memory unit and is not supplied directly to the ME 306. Alternative modalities can use an IKE script or some other method to establish the RK. The other parameters of the security association between CS and UIM 3 08 must also be negotiated. The RK is kept a secret in UIM 308, while the other parameters of the
27/57 security association can be maintained in ME 306. In the exemplary modality, in which BAK is sent to UIM 308 as an IPSec packet encoded using RK, CS and MS 306 negotiate an SPI value used for index the security association, and this SPI is denoted as SPI_RK.
In the AKA method, RK is a secret shared between CS, UIM and TTP. Therefore, as used here, the AKA method implies that any security association between CS and UIM implicitly includes TTP. The inclusion of TTP in any security association is not considered a breach of security, as the CS trusts that TTP will not assist in unauthorized access to the broadcast channel. As stated above, if a key is shared with the ME 306, it is desirable to change that key frequently. This is due to the risk of access, by a non-subscriber, to the information stored in the MEM 310 memory storage unit and, therefore, of allowing access to a controlled or partially controlled service. The ME 3 06 stores the SK, that is, key information used in decoding the broadcast content, in the MEM 310 memory storage unit. 0 CS sends enough information for subscribers to compute SK. If a subscriber user's ME 306 can compute SK from this information, then the additional information needed to compute SK cannot be secret. In this case, it is assumed that the ME 306 of a non-subscriber user can also compute the SK from this information. Hence, the SK value must be computed on SUPU 316, using a secret key shared by CS and SUMU 314. CS and SUMU 314 share the RK value, however each user has a unique RK value. There is not enough time for the CS to code SK with
28/57 each RK value and transmit these coded values to each subscriber user.
Regarding the subscription, in order to ensure the efficient distribution of SK security information, the CS periodically distributes a common Broadcast Access Key (BAK) to each UIM 3 08 subscriber. For each subscriber, the CS encodes the BAK using the corresponding RK in order to obtain a value called BAKI Information (BAKI). The CS sends the BAKI corresponding to the subscriber user's MS 300. For example, BAK can be transmitted as an encrypted IP packet using the RK corresponding to each MS. In exemplary mode, BAKI is an IPSec package that contains a BAK that is encoded using RK as the key. Since the RK is a key per user, the CS must send the BAK to each subscriber individually; therefore, BAK is not sent through the broadcast channel. The MS 300 becomes BAKI for UIM 308. SUPU 316 computes BAK using the RK value stored in SUMU 314 and the BAKI value. The BAK value is then stored in the SUMU. In the exemplary form, BAKI contains an SPI value denoted as SPI_RK which corresponds to the security association that contains the RK. The MS 300 knows that UIM 308 can decode the payload when the IPSec packet is encrypted according to this security association. Consequently, when the MS 300 receives an IPSec packet encoded according to this security association, the MS 300 passes BAKI to UIM 308 and instructs UIM 308 to use the RK to decode the payload.
It is desirable that the period to update the BAK is sufficient to allow the CS to send the BAK to each subscriber individually, without incurring significant overhead. Since the ME 3 06 is not trusted to keep secrets for a long time, UIM 308 does not provide
29/57 to BAK to ME 306. The other parameters of the security association between the CS and the group of subscribers must also be negotiated. In one mode, these parameters are fixed, while in another mode, these parameters can be sent to MS as part of BAKI. Although BAK is kept a secret in UIM 3.08, the other parameters of the security association can be kept in ME 306. In one embodiment, in which the SK is sent to MS 300 as an IPSec packet encoded using BAK, the CS sends subscribers a SPI used to index the security association, and this SPI is denoted as SPI_BAK.
The next paragraph discusses how SK is updated after a successful subscription process. Within each BAK update period, a short interval is shown during which the SK is distributed on a broadcast channel. CS uses a cryptographic function to determine two values of SK and SKI (SKI Information), so that SK can be determined from BAK and SKI. For example, SKI can be SK coding using BAK as the key. In an exemplary modality, SKI is an IPSec package in which the payload contains the SK value encoded using BAK as the key. Alternatively, SK can be the result of applying a cryptographic hash function to the concatenation of the SKI and BAK blocks. Ideally, CS ensures that SK values cannot be predicted in advance. If SK can be predicted in advance, then an attacker, that is, an illegitimate accessing entity, can send predicted SK values to non-subscriber users.
As an example, suppose that N SK values will be used for a period of 24 hours. If SK is
30/57 predicted with 100% accuracy, the attacker only needs to ask UIM to compute the N keys. The attacker then makes the N keys available to non-subscriber users. Non-subscriber users can download the keys at the beginning of each day and access the HSBS service at a reduced or low cost. If the attacker is only able to predict SK with 50% accuracy, then the attacker needs to send approximately 2N keys. As the accuracy of the predictions decreases, the number of keys to be generated by the attacker increases. An attacker can be deterred from distributing predictions for SK by ensuring that the cost of generating, storing and distributing predictions outweighs the benefit of obtaining illegitimate access. Attackers can be discouraged by ensuring that the accuracy of an attacker's prediction is small enough, thereby increasing the number of keys the attacker will generate to the point that the cost of obtaining illegitimate access outweighs the benefit . Consequently, any scheme for generating SK ideally ensures that an attacker's best predictions have sufficiently small accuracy. In other words, SK computation must include some random value that can only be predicted beforehand with little accuracy.
In an exemplary modality, in which SK is in a coded form, the CS can choose SK using a random or pseudo-random function. In alternative modalities, in which SK is obtained by applying a cryptographic function to SKI and BAK, CS introduces an unpredictable value when forming SKI. Some part of SKI can be predictable. For example, a portion of the SKI can be obtained from the system time during which this SKI is valid. This part, denoted as SKI_PREDICT, cannot be transmitted to the MS 300 as part of the broadcast service. 0
31/57 SKI's rest, SKI_RANDOM, can be unpredictable. That is, SKI_RANDOM is predicted with little accuracy. SKI_RANDOM is transmitted to the MS 300 as part of the broadcast service. SKI_RANDOM is transmitted to the MS 300 as part of the broadcast service. The MS 300 rebuilds SKI from SKI_PREDICT and SKI_RANDOM and supplies SKI to UIM 308. SKI can be rebuilt within UIM 308. The SKI value changes for each new SK. In this way, either the SKI_PREDICT and / or the SKI_RANDOM change when a new SK is computed.
The CS sends SKI_RANDOM to the BS for broadcast transmission. The BS transmits the SKI_RANDOM, which is detected by the antenna 3 02 and passed to the receiving circuit set 304. The receiving circuit set 304 sends the SKI_RANDOM to the MS 300, where the MS 300 rebuilds the SKI. MS 300 sends SKI to UIM 308, where UIM 308 obtains SK using the BAK stored in SUMU 314. The SK is then sent by UIM 3 08 to ME 3 06. ME 3 06 stores SK in the memory storage unit, MEM 310. ME 306 uses SK to decode broadcast transmissions received from CS.
CS and BS agree on certain criteria for when SKI_RANDOM is transmitted. The CS may wish to reduce the intrinsic monetary value in each SK by frequently changing the SK. In this situation, the desire to change the SKI_RANDOM data is offset by the optimization of the available bandwidth. In some exemplary modalities, SKI_RANDOM is sent with the encoded content. This allows the MS 300 to generate the SK and start decoding immediately. In many situations, this will consume bandwidth. An exception is a scheme in which SKI_RANDOM is sent as parameters of the communication. For example, the SPI value in the
32/57
IPSec varies, and can be exploited to include a value of SKI_RANDOM, as discussed in more detail below.
In other modalities, SKI_RANDOM is sent separately from the encoded content. SKI_RANDOM can even be broadcast on a channel other than the broadcast channel. When a user tunes to the broadcast channel, the receiving circuitry 304 obtains information to locate the broadcast channel from a control channel. It may be desirable to allow quick access when a user tunes to the broadcast channel. This requires the ME 306 to obtain SKI within a short period of time. ME 3 06 may already know SKI_PREDICT, but BS supplies SKI_RANDOM to ME 300 within this short period of time. For example, BS can often transmit SKI_RANDOM on the control channel, along with information to locate the broadcast channel, or frequently transmit SKI_RANDOM on the broadcast channel. The more often the BS renews the SKI_RANDOM value, the faster the MS 300 can access the broadcast message. The desire to renew SKI_RANDOM data is counterbalanced by optimizing the available bandwidth, since over-transmitting SKI_RANDOM data can use an unacceptable amount of bandwidth on the control channel or broadcast channel.
In some situations, the CS may choose to use values of SKI_PREDICT and SKI_RANDOM, where both change for each SK value produced. In other situations, the CS may wish to reduce the number of times that the SKI_RANDOM changes, so that the MS 300 does not have to obtain the SKI_RANDOM as often. For example, if
33/57 a user would change frequently between multiple HSBS channels, so it would be better if the SKI_RANDOM value was unlikely to change in the five minutes during which the user is tuned to another channel. If the SKI_RANDOM were to change, then the user would have to wait until the new SKI_RANDOM value was transmitted, which indicates that such a scheme would be more friendly if the SKI_RANDOM remained constant for as long as possible. The CS may wish to use several SK values during the lifetime of a SKI_RANDOM value, using a value for SKI_PREDICT which will have changed whenever the CS wishes to change the SK. One example uses system time; however, the use of system time introduces additional problems with regard to synchronization.
Regarding the encoding and transmission of broadcast content, CS encodes broadcast content using the current SK. The exemplary modality uses an encoding algorithm, such as the Advanced Coding Standard (AES) Cipher Algorithm. In the exemplary mode, the encoded content is then transported by an IPSec packet according to the Encapsulation Safety Payload (ESP) mode of transport, discussed below. The IPSec package also contains an SPI value that instructs the ME 306 to use the current SK to decode the received broadcast content. The encoded content is sent through the broadcast channel.
The receiving circuit set 304 supplies RKI and BAKI directly to UIM 308. In addition, if the CS computes SK from the SKI_RANDOM and SKI_PREDICT values, then the receiving circuit set 304 supplies SKI_RANDOM to a appropriate part of MS 3 00, where it is combined with SKI_PREDICT to obtain SKI.
34/57
In one embodiment, SKI is attached to the encrypted message and is extracted by ME 306. SKI is supplied to UIM 308 by the relevant part of MS 300. UIM 308 computes RK from RKI and key A, decodes BAKI using RK to obtain BAK and compute SK using SKI and BAK in order to generate an SK to be used by ME 306. ME 306 decodes broadcast content using SK. 0 UIM 308 of exemplary modality may not be powerful enough to decode broadcast content in real time and, therefore, SK is passed to ME 3 06 for decoding the broadcast.
Figure 5B shows the transmission and processing of the keys, including RK, BAK and SK, according to an exemplary modality. As shown, at the time of registration, MS 3 00 receives RK information (RKI) and passes it to UIM 308, where SUPU 316 computes RK using RKI and key A, and stores RK in memory storage SUMU 314 of the UIM. The MS 3 00 receives encoded using the UIM 308 specific RK value.
The encoded BAKI is decoded by SUPU 316 in order to recover the BAK, which is stored in the UIM's SUMU 314 memory store. MS 3 00 also periodically obtains SKI. In some exemplary modalities, MS 3 00 receives an SKI_RANDOM which it combines with SKI_PREDICT to form SKI. SUPU 316 computes SK from SKI and BAK. SK is provided to ME 3 06 for decoding broadcast content.
In the exemplary modality, the CS keys are not necessarily encrypted and transmitted to the MSs; the CS<sup>1</sup>
I can use an alternative method. Information from<sup>1 </sup>generated by the CS for transmission to each MS constitute <sup>1 </sup>enough information for the MS to calculate the key. 'As shown in system 350 in figure 6, the RK is generated
35/57 by the CS, but the RK (RKI) information is transmitted to the MS. The CS sends enough information for the UIM to obtain the RK, in which a predetermined function is used to obtain the RK from the information transmitted from the CS. The RKI contains enough information for the MS to determine the original RK for key A and other values, such as system time, using a predetermined public function labeled dl, where:
RK = dl (key A, RKI). (3)
In the exemplary mode, the dl function defines a cryptographic type function. According to one modality, RK is determined as:
RK = SHA '(key A II RKI), (4) where II denotes the concatenation of the blocks containing the key A and RKI, and SHA' (X) denotes the last 128 bits of the given SHA-1 Secure Hash Algorithm input X. In an alternative mode, RK is determined as:
RK = AES (key A, RKI), (5)
Where AES (X, Y) denotes the encoding of the 128-bit RKI block using the 128-bit key A. In another modality based on the AKA protocol, RK is determined as the output of the 3GPP f3 key generation function, where RKI includes the RAND value and the appropriate AMF and SQN values defined by the standard.
BAK is treated differently because multiple users with different RK values must compute the same BAK value. The CS can use any technique to determine BAK. However, the BAKI value associated with a specific UIM 308 must be the BAK encoding under the unique RK associated with that UIM 308. SUPU 316 decodes BAKI using the RK stored in SUMU 314 according to the function labeled d2, according:
36/57
BAK = d2 (BAKI, RK). (6)
In an alternative modality, the CS can compute BAKI by applying a decoding process to BAK using RK, and SUPU 316 obtains BAK by applying the encoding process to BAKI using RK. This is considered equivalent to BAK encoding by CS and BAKI decoding by SUPU 316. Alternative modalities can implement any number of key combinations in addition to or in place of those shown in figure 6.
SK is treated similarly to RK. In some modalities, SKI is first obtained from SKI_PREDICT and SKI_RANDOM, where SKI_RANDOM is the information transmitted from the CS to the MS. Then, a predetermined function labeled d3 is used to obtain SK of SKI and BAK (stored in SUMU 314), according to:
SK = d3 (BAK, SKI) (7)
In one embodiment, the d3 function defines a cryptographic type function. In an exemplary modality, SK is computed as:
SK = SHA (BAKI II SKI), (8) while, in another modality, SK is computed as
SK = AES (BAK, SKI). (9)
A method for securing a broadcast message is shown in figures 7A-7D. Figure 7A illustrates a registration process, 400, in which a subscriber negotiates registration with the CS in step 402. The registration in step 404 provides UIM with a unique RK. The UIM stores the RK in a Secure Memory Unit (SUMU) in step 406. Figure 7B illustrates a signature processing, 420, between a CS and an MS. In step 422, the CS generates a BAK for a BAK TI time period. BAK is valid for the entire period of time
37/57 of BAK Tl, where BAK is updated periodically. In step 424, the CS authorizes UIM to access Broadcast Content (BC) during the BAK Tl time period. In step 426, the CS encodes the BAK using each individual RK for each subscriber. The encoded BAK is referred to as BAKI. The CS then transmits BAKI to UIM in step 428. The UIM receives BAKI and decodes using RK in step 430. The decoded BAKI results in the BAK originally generated. The UIM stores the BAK in a SUMU in step 432.
When the user subscribes to the broadcast service for a specific BAK update period, the CS sends the appropriate information to BAKI, where BAKI corresponds to BAK encoded with RK. This typically occurs before the start of this BAK update period or when the MS tunes into the broadcast channel first during this BAK update period. This can be initiated by MS or CS according to several criteria. Several BAKIs can be transmitted and decoded simultaneously.
Note that when the expiration of the BAK update period is imminent, MS may request the updated BAK from CS if MS has subscribed for the next BAK update period. In an alternative modality, the first timer tl is used by the CS, where, when the timer expires, that is, when the BAK update period has expired, the CS transmits the BAK. The CS may change the BAK value earlier than originally intended. This may be desirable if, for example, BAK's current value is revealed publicly.
Note that it is possible for a user to receive a BAK during a BAK update period, in which, for example,
38/57 example, a subscriber joins the service in the middle of the month when BAK updates are made monthly. In addition, the time periods for BAK and SK updates can be synchronized, so that all subscribers are updated at any given time.
Figure 8A illustrates the registration process in a wireless communication system, 500, according to the exemplary modality. CS 502 negotiates with each subscriber, that is, MS 512, in order to generate a specific RK for each of the subscribers. The RK is provided to the SUMU unit within the UIM of each MS. As shown, CS 5 02 generates RKi, which is stored in SUMUi 510 within UIMi 512. Similarly, CS 502 generates RK<sub>2</sub> and RK<sub>N</sub>, which are stored in SUMU<sub>2</sub> 52 0 within the UIM<sub>2</sub> 522 and SUMU<sub>N</sub> 53 0 within the UIM<sub>N</sub>532, respectively.
Figure 8B illustrates the signature process on the 500 system. The CS 502 also includes several encoders, 504. Each of the 504 encoders receives one of the unique RKs and the BAK value generated on the CS 502. The output of each encoder 504 is a BAKI coded specifically for a subscriber. BAKI is received at the UIM of each MS, such as UIMi 512. Each UIM includes a SUPU and a SUMU, such as the SUPU<sub>X</sub> 514 and the UIM SUMUi 510<sub>X</sub> 512. SUPU includes a decoder, 516, which retrieves BAK by applying RK to UIM. The process is repeated on each subscriber.
Figure 8D illustrates the processing of the BC after registration and signature. The CS 502 includes an encoder, 560, which encodes the BC using the current SK to generate the EBC. The EBC is then transmitted to subscribers. Each MS includes an encoder, such as, for example, encoder 544, which extracts BC from EPC using SK.
39/57
The following description considers four exemplary modalities that can be used to update the SK and spread the content. In the first exemplary modality, SK is obtained from BAK and the SPI value in the header of the IPSec packets that contain the broadcast content. In the second exemplary modality, SK is obtained from BAK, from a random broadcast value denoted as RAND and from the SPI value in the header of the IPSec packets that contain the broadcast content. In the third exemplary modality, SK is obtained from BAK, the system time and a random broadcast value denoted as SK_RAND. In the fourth exemplary embodiment, SK is sent as an IPSec packet encoded using BAK. Still other modalities can provide SK as a combination of the modalities listed above, or by using another mechanism to provide SK to MS often enough to discourage unauthorized access to the broadcast service.
Since the Short Term Key (SK) is used to encode and decode broadcast content and is stored in a memory that can be vulnerable to unauthorized access, where SK is typically changed frequently. There is a problem with the way in which SK should be changed frequently, while balancing the following four objectives at the same time: 1) to minimize SK's update time, or period of total communications interruption (blackout), to a mobile station that has recently tuned in to the broadcast; 2) reduce the amount of bandwidth used to update the SK value to a minimum; 3) increase the level of security; and 4) increase the ease with which SK can be incorporated into IPSec. Frequent updates can reduce the period of total communications interruption, but at the expense of
40/57 need more bandwidth to send frequent updates.
One solution provides a method for obtaining sufficient information to perform SK updates on each encoded broadcast content package without using any additional bandwidth. Therefore, the blackout period can be reduced to a minimum without necessarily incurring additional bandwidth requirements. The four exemplary modalities described here for performing an SK update have several advantages and disadvantages. All four modes provide methods that are safe enough. The first modality eliminates the blackout period and does not use additional bandwidth to update the SK value. The other modalities may incur a blackout period during times of great use. The first modality is also easily incorporated into IPSec.
According to the first modality to perform an SK update, the problems mentioned above are solved by defining the SK that encodes a given IPSec packet as a function of the Broadcast Access Key (BAK) and the SPI in the ESP header. Thus, instead of providing SK in a separate stream, SK is computed from the stream of content. Assuming that MS has already received BAK as described above, MS is able to immediately compute SK for each content package without having to wait for some additional SK update information. This effectively eliminates any waiting time for SK to update to a new broadcast recipient. As soon as MS receives a content pack, MS can immediately determine SK and decode the content.
41/57
Sufficient information for calculating SK in MS is provided in the IPSec package. The IPSec package uses an IP Encapsulation Security Payload (ESP) and is specified in RFC 1827 entitled R. Encapsulating Security Payload (ESP), by R. Atkinson, August 1995, mentioned above. ESP is a mechanism for providing integrity and confidentiality to IP datagrams. In some circumstances, it can provide authentication to IP datagrams. Figure 9A shows an IPSec packet, 600, which includes an IP header, 602, an ESP header, 604, and a payload, 606, according to an embodiment. The Encapsulation Security Payload (ESP) can appear anywhere after the IP header and before the final transport layer protocol. ESP usually consists of an uncoded header followed by encoded data.
The ESP 604 header field includes a Security Association Identifier, referred to as SPI. According to the first modality described above, the IPSec packets containing the broadcast content include an SK-related SPI, labeled SPI_SK. Figure 9B shows the format of the corresponding 32-bit SPI_SK, 610. SPI_SK 610 is decomposed into two parts: SPI_RAND 612 and BAK_ID 614. 0 SPI_RAND 612 is a random number that is statistically random, and is also used to compute the SK which is used to encode and decode the corresponding broadcast content or payload. The SPI_RAND parameter allows the Content Server (CS) to frequently change the effective SK value for the content by changing the SPI_RAND value, thus providing MS with the necessary parameter to compute the SK value immediately. In addition, SPI_RAND plays the role of SPI_RANDOM, discussed above. The random nature of
42/57
SPI_RAND ensures that an attacker does not predict SK values with high accuracy. Since SPI is already a standard parameter in IPSec encoded packets, that is, it is specified for ESP, the present modality does not incur the additional bandwidth typically associated with SK transmission as a separate stream. The BAK_ID indicates which BAK value to use when computing the SK value. In one embodiment, BAK_ID is a four-bit tag, where each tag is associated with a BAK value. When the MS makes a subscription, the MS stores each received BAK_ID and the corresponding BAK value in a memory storage unit. According to one modality, the MS includes a Search Table (LUT) for storing the BAK value (s) identified with each corresponding BAK_ID (s). The LUT DE BAK is contained in the UIM's secure memory.
Figure 9D shows a LUT DE BAK, 630. Each entry in LUT 63 0 identifies the BAK_ID, the corresponding BAK value and the expiration of the combination validity. Expiration is introduced due to the small number of BAK_ID values. Alternative modalities can avoid the use of expiration values in the LUT DE BAK. In one mode, only 16 BAK_ID values are used. If a new BAK is issued every month, then the BAK_ID value must be repeated after 16 months. At this point, there may be confusion as to the valid BAK value. Expiration provides a waiting period after which a new entry replaces the expired entry. The BAK LUT may need to store more than one BAK value. One reason for this is that the CS may wish to send BAK values to the MS before they become valid. In addition, the CS may wish to have several BAK values that are valid at the same time, in which different BAK values can be used in computing different SK values. If the
43/57
LUT DE BAK does not contain a current BAK corresponding to BAK_ID, so MS can make a subscription to recover the valid BAK.
After extracting SPI_RAND and BAK_ID from SPI_SK and retrieving the BAK corresponding to BAK_ID, UIM computes the SK value from BAK and SPI_RAND using a cryptographic function g:
SK = g (BAK, SPI_RAND). (10)
In one embodiment, the function g (BAK, SPI_RAND) corresponds to the encoding of the SPI_RAND filled for 128-bit bits with zeros, using the AES encoding algorithm with BAK as the key:
SK = AES (BAK, SPI_RAND). (11)
In another modality, the function g (BAK, SPI_RAND) corresponds to the computation of the least significant 128 bits of the SHA-1 output applied to the concatenation of BAK and SPI_RAND:
SK = SHA (BAK, SPI_RAND). (12)
Thus, it is not necessary for UIM to compute the SK value for each packet received by MS. The MS stores each of the SPI_SK values with the corresponding SK values in a memory storage unit, such as a Search Table (LUT). The MS can store the values of SPI_SK and SK as a security association in the Security Association Database (SAD): a LUT in which the MS stores typical security associations needed for other applications. Security associations are indexed according to the destination address and the SPI. When a new SK is generated from a new SPI_SK value, the old security association is replaced by the new security association that contains the new SPI_SK and SK values. Alternatively, the MS can store the SPI_SK values
44/57 and SK in an SK_LUT, with an SK_LUT allocated to each broadcast channel. Figure 9C shows an SK LUT, 620. Each entry in LUT 620 identifies the SPI_SK and the corresponding SK value. When the MS receives a packet of broadcast content, the ME first checks the SAD or SK LUT to see if the table contains a SPI_SK value equal to the SPI of the received packet. If the table contains such a value, then the ME uses this value, otherwise UIM computes the new SK value. The CS can also have a LUT DE BAK, a SAD or an SK_LUT.
Figures 10 and 11 show a modality to perform an SK update. Figure 10 illustrates a method, 700, for driving the CS. For each IP packet, the CS determines the BAK that will be used to obtain the SK, and determines the BAK_ID corresponding to the BAK in step 702. The BAK_ID can be any type of identifier that allows discrimination between various BAK values. CS sends BAK and BAK_ID to individual users by subscribing in step 706. Users can subscribe at different times before and during the subscription period. Steps 7 02 and 706 can take place before the subscription period begins. In step 710, the CS chooses a random value for the SPI_RAND value. If the BAK_ID is represented by means of b bits, then the SPI_RAND is represented by means of (32-b) bits. The SPI_RAND value must not be repeated during the lifetime of a BAK. Once SPI_RAND and BAK_ID are known, CS combines them (ie, concatenates BAK_ID with SPI_RAND) in order to form SPI_SK in step 712. In step 714, CS forms SK using a cryptographic function to combine the SPI_RAND with the BAK corresponding to the BAK_ID in order to form the SK. The CS then encodes the broadcast message or part of the message with SK in step 716, and
45/57 sends the encoded message in step 718. Note that the encoded broadcast message is part of an IP packet that includes the header and the ESP header. The ESP header includes the SPI_SK. In the 720 decision diamond, the CS decides whether to change the SK. If the CS decides to change the SK, then the CS continues to the decision diamond 724, where the CS decides to change the BAK. If the CS decides not to change the BAK, then the CS proceeds to step 710. If the CS decides to change the BAK, then the CS proceeds to step 702.
Figure 11 illustrates the corresponding operation on the receiver, such as, for example, an MS. Method 750 starts when the receiver receives the IP packet, which includes the SPI_SK in the ESP header, in step 752. Note that the receiver extracts the SPI_SK information from the IP packet. Upon receipt of SPI_SK, the receiver first checks whether the SK corresponding to the received SPI_SK value is stored in memory.
In one embodiment, the SPI_SK is stored in the SK LUT stored in the ME 306 unit in figure 4, and in another embodiment, the SPI_SK is stored in the security associations database: both of these tables are denoted in figure 11 by the SPI table . The SPI table is checked on decision diamond 754. If the SK value is stored in memory on the receiver, the receiver is able to decode the payload of the content pack using the SK value stored in step 756. If the receiver does not have the SK value stored in memory, the receiver extracts the BAK_ID and SPI_RAND from the SPI_SK in step 758. In step 760, the receiver then checks whether the BAK LUT has a valid BAK entry corresponding to BAK_ID, then the receiver selects this value and proceeds to step 764. If the LUT DE BAK does not have a valid BAK corresponding to the BAK_ID, as, for example, when the
46/57 user wants to subscribe for this period, then the receiver subscribes in order to obtain the valid BAK, as shown in step 762. The new BAK is stored with BAK_ID in BAK_LUT, and the receiver proceeds to step 764 The receiver combines the BAK corresponding to the BAK_ID value, that is, the BAK_ID in the received SPI_SK, and the SPI_RAND value (also in the received SPI_SK) in order to compute the new SK in step 764. 0 The receiver then uses the new SK value in order to decode the content packet payload in step 766. The receiver also stores this SK value indexed by the corresponding SPI_SK and possibly the destination address of the IPSec packets.
SK is computed directly from BAK's knowledge and the SPI_SK value in the content package. BAK changes less frequently than SK, BAK being able to change once a month, for example. Therefore, the receiver can determine the SK value immediately from the content packets without additional delay and without requiring more bandwidth to send the SK update.
According to one modality, the SK calculation is given as:
SK = f (SPI_SK, BAK) where the function is defined as the SPI_SK encoding using BAK. Since SPI_SK is made from SPI_RAND and BAK_ID, Equation (13) can also be determined as:
SK = f (SPI_RAND, BAK_ID). (14)
The second exemplary modality for performing a SK update introduces an additional aspect of a random nature in SK computing, where SK is defined as a function of BAK, SPI_RAND and an additional parameter, RAND. The RAND parameter is kept constant for various values of
47/57
SK. The RAND allows more different SK values to be obtained from a single BAK by varying the SPI. However, if a 96-bit RAND is used, then there can be up to 2<sup>218</sup> SK values that can be obtained from a single BAK by varying both SPI_RAND and RAND. (These numbers do not account for the bits of the SPI that are used to represent the BAK_ID). Now, instead of SPI_SK identifying BAK only, SPI_SK must also contain information to identify RAND. To implement the RAND value, the SPI_SK is formulated in three parts: 1) the BAK_ID to identify the BAK value to be used; 2) the RAND_ID to identify the RAND value to be used; and 3) the SPI_RAND value to provide the random nature that changes frequently in SPI_SK.
Figure 12A shows an SPI_SK, 800, portion of an IP packet, including an SPI_RAND, 802, a BAK__ID, 804, and a RAND_ID, 806. The SPI_RAND 802 and BAK_ID 804 are as described above. In order to keep SPI_SK at a predetermined or specified bit length, SPI_RAND 802 can use fewer bits than SPI_RAND 612, as in figure 9B, in order to provide bits for RAND_ID 806. 0 RAND_ID 806 corresponds to the RAND value used in calculating the SK, and can be a four-bit tag or other identifier. The corresponding RAND_ID (s) and corresponding RAND value (s) are stored in a LUT on the receiver. Figure 12B shows a RAND LUT, 820. The RAND LUT 820 includes an entry for each RAND value that lists the RAND_ID and the expiration associated with the RAND value.
Figure 13 shows the operation of the CS. For each IP packet, the transmitter determines the BAK to be used to obtain SK and determines the BAK_ID corresponding to the BAK in step 902. The BAK_ID can be any type of identifier that allows discrimination between various BAK values. 0
48/57 amount of width However, if there is
CS sends BAK and BAK_ID to individual users subscribing in step 904. Users can subscribe at different times before and during the subscription period. Steps 902 and 904 can take place before the subscription period begins. In step 906, the transmitter selects a RAND value and determines the
Matching RAND_ID. The CS can send the RAND and RAND_ID to the MS individually or send the RAND and RAND_ID to be broadcast on the broadcast channel. The RAND value does not have to be secret, so it is not encrypted. If RAND and RAND_ID are transmitted, then there should not be much time between retransmissions, so that an MS does not have to wait long before obtaining the RAND value. The transmission of RAND and RAND_ID will use a large bandwidth over time, a large number of users tuned into the channel, so a large amount of bandwidth will be required to send the RAND to each user individually. Consequently, the RAND and RAND_ID should only be transmitted if there are a large number of users tuned to the channel. In step 910, the CS chooses a random value from SPI_RAND.
Once the SPI_RAND, BAK_ID and RAND_ID are known, the transmitter combines them (as, for example, concatenating RAND_ID and BAK_ID with SPI_RAND) in order to form SPI_SK in step 912. CS uses a cryptographic function to combine SPI_RAND, BAK (identified by BAK_ID) and RAND (identified by RAND_ID) in order to form SK. The CS then encodes the broadcast message or part of the message with the SK in step 916, and transmits the encoded message in step 918. Note that the encoded broadcast message is part of an IP packet that includes the IP header and the ESP header. The ESP header includes the
49/57
SPI_SK. In decision diamond 920, CS decides whether to change SK. If the CS decides not to change the SK, then the CS proceeds to the SK stage. If the CS decides to change the SK, then the CS proceeds to decision diamond 922, where the CS decides to change the RAND. If the CS decides not to change the RAND, then the CS proceeds to step 910. If the CS decides to change the RAND, then the CS proceeds to decision diamond 924, where the CS decides to change the BAK. If the CS decides not to change the BAK, then the CS proceeds to step 906. If the CS decides to change the BAK, then the CS returns to step 902.
Figure 14 illustrates the corresponding operation on the receiver, such as, for example, an MS. Method 950 starts when the receiver receives the IP packet that includes the SPI_SK in the ESP header in step 952. Note that the receiver extracts the SPI_SK information from the IP packet. Upon receipt of the SPI_SK, the receiver first checks whether the SK corresponding to the SPI_SK value received is stored in memory in decision diamond 952. In one embodiment, the SPI_SK is stored in a SK LUT stored in unit 3 06 of the ME in figure 4 and, in another embodiment, the SPI_SK is stored in the security associations database: both of these tables are denoted in figure 14 as the SPI table. The SK LUT check is done on decision diamond 954. If the SK value is stored in memory on the receiver, the receiver can decode the payload of the content pack using the SK value stored in step 956. If the receiver does not have the SK value stored in memory, the receiver extracts the BAK_ID and SPI_RAND from the SPI_SK in step 958. In step 960, the receiver checks whether the BAK LUT has a valid BAK entry corresponding to BAK_ID. If the LUT DE BAK does in fact have a valid RAND corresponding to the BAK_ID, then the receiver selects this value and proceeds to step 964. If the LUT DE BAK does not
50/57 has a valid BAK corresponding to the BAK_ID, then (as long as the user wishes to subscribe for this period) the receiver subscribes in order to obtain the valid BAK, as shown in step 962. The new BAK is stored with the BAK_ID in the LUT DE BAK and the receiver proceeds to step 964. In step 964, the receiver then checks whether the RAND LUT has a valid BAK corresponding to the RAND_ID. If the RAND LUT does in fact have a valid BAK corresponding to the RAND_ID, then the receiver selects this value and proceeds to step 964. If the RAND LUT does not have a valid RAND corresponding to the RAND_ID, then the receiver obtains the RAND and RAND_ID by requesting the value of either CS or broadcast, as shown in step 966. The new RAND is stored with RAND_ID in RAND_LUT, and the receiver proceeds to step 968. 0 receiver combines the BAK corresponding to the BAK_ID value (that is, the BAK_ID in the received SPI_SK), the RAND corresponding to the RAND_ID (that is, the RAND_ID in the received SPI_SK) and the SPI_RAND value (also in the received SPI_SK) in order to compute the new SK in step 968. The receiver then uses the new SK value to decode the payload of the content pack in step 970. 0 receiver also stores this SK value indexed by the corresponding SPI_SK and possibly the destination address of the IPSec packets.
The RAND is changed less frequently than the SPI_RAND. The RAND value is common to all mobile stations that listen to the broadcast. Therefore, the RAND value can be transmitted to all mobile stations and is not necessarily coded specifically by the receiver. Therefore, if there are enough mobile stations listening to the stream of broadcasts, it is more efficient for the interface over the air to transmit the RAND value a few times to all
51/57 mobile stations, instead of requiring each mobile station to individually request the RAND values of the CS.
According to one modality, the SK calculation is given as:
SK = f (SPI_SK, BAK, BAND), (15) where the function is defined as the SPI_SK encoding using BAK. Since the SPI_SK consists of SPI_RAND, BAK_ID and RAND_ID, Equation (15) can be given as:
SK = f (SPI_RAND, BAK_ID, RAND_ID, RAND). (16)
Note that the use of a RAND value can introduce some blackout periods because the receiver needs to receive the RAN value on a change. However, these periods are less frequent than when SK is updated in a separate stream and the receiver expects periodic updates. The RAND is designed to change more slowly than the SK value, and therefore RAND updates are not sent as often. 0 CS would also like to reduce the likelihood of a blackout, which occurs when an MS stops listening to the channel due to a lost signal, tuning in to another channel, or responding to an interruption, such as a phone call, for example. Blackout is more likely to occur early in the life of a RAND value. To counteract this, the CS can re-broadcast (re-broadcast) the new RAND more often at approximately the time the new RAND value becomes valid. At the end of a RAND's lifetime, it may become necessary to broadcast (broadcast) both the current RAND value and the next RAND value. The RAND values must not be predictable, and the CS should start sending the RAND just before the RAND becomes valid.
52/57
As discussed above, according to the third exemplary modality, SK is obtained from BAK, system time and a random broadcast value denoted as SK_RAND. Figure 7C illustrates a method for updating keys for security encryption in a wireless communication system that supports broadcast service. Method 440 implements time periods, as shown in figure 7E. BAK is updated periodically, having a Tl time period. A tl timer is started when the BAK is calculated and expires (times out) in Tl. A variable is used to calculate the SK referred to as SK_RAND, which is updated periodically with a time period of T2. A timer t2 is started when SK_RAND is generated and expires at T2. In one modality, SK is also updated periodically with a T3 period. A timer t3 is started when each SK is generated and expires at time T3. 0 SK_RAND is generated in the CS and periodically supplied to the MS. MS and CS use SK_RAND to generate SK, as detailed below.
A first timer tl is reset when the applicable BAK value is updated. The length of time between two BAK updates is the BAK update period. In the exemplary modality, the BAK update period is a month, but alternative modalities can implement any desired period of time for optimal system functioning, or in order to satisfy several system criteria.
Continuing with figure 7C, method 440 initializes timer t2 in step 442 in order to start the SK_REG T2 time period. The CS generates the SK_RAND and supplies the value to the set of transmission circuits throughout the system in step 444. Timer t3 is
53/57 initialized in step 446 in order to start the SK T3 time period. The CS then encodes the BC using the current SK in step 448. The encrypted product is the EBC, where the CS supplies the EBC to the set of transmission circuits for transmission in the system. If the timer. t2 has expired at decision diamond 450, processing returns to step 442. Although t2 is less than T2, if timer t3 has expired on decision diamond 452, processing returns to step 446, otherwise processing returns to 450.
Figure 7D illustrates the operation of the MS that accesses a broadcast service. Method 460 first synchronizes timers t2 and t3 with the values in the CS in step 462. The UIM of the MS receives the SK_RAND generated by the CS in step 464. In step 466, the UIM generates the SK using SK_RAND, BAK and a time measurement. The UIM passes the SK to the ME of the MS. The UIM then decodes the received EBC using the SK in order to extract the original BC in step 4 68. When timer t2 expires at step 470, processing returns to step 462. Although timer t2 is less than T2, if timer t3 expires at step 472, timer t3 is initialized at step 474 and returns to 466.
The management and updates of the keys are illustrated in figure 8C, in which the CS applies a function, 508, in order to generate a value of SK_RAND, which is a provisional value used by the CS and the MS to calculate the SK. Specifically, function 508 applies the value of BAK, SK_RAND and a time factor. Although the modality shown in figure 8C applies a timer to determine when to update the SK, alternative modalities can use alternative measures to generate periodic updates, such as the occurrence of an error or other event.
54/57
The CS provides the value of SK_RAND to each of the subscribers, where a function 518, resident in each UIM, applies the same function, as in function 508 of the CS. Function 518 operates on SK_RAND, BAK and a timer value in order to generate an SK that is stored in a memory location on the ME, such as ΜΕΜ<sub>Χ</sub> 542 of ΜΕχ 540.
As discussed above, according to the fourth exemplary modality, SK is encoded using BAK to form SKI, and SKI is sent to MS. In an exemplary embodiment, SK is sent in an IPSec packet encoded using BAK. The CS can also broadcast a corresponding SPI that can be used to identify the data that is encoded using SK. This modality does not need to be discussed in more detail.
In the exemplary modalities presented above, the CS may choose to update the SK as the CS wishes. The more frequently the SK changes, the more the CS can deter attackers from distributing SK values. There will be times when an attacker considers the advantage of distributing SK values so that they are better at other times. This will basically be due to the nature of the content that is transmitted. For example, when an important event occurs, non-subscriber users will be more interested in receiving news on HSBS and, therefore, will be willing to pay more for illegitimate access than at other times. At these times, CS can increase the cost and inconvenience for attackers and non-subscriber users by changing SK more often than normal. The CS should keep in mind, however, the limits to the processing power of the UIM. If the CS changes the SK too often, the UIM cannot compute the values
55/57 SK in real time, so users will not be able to decode content in real time.
Those who know the technique would understand that information and signals can be represented using any of several different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols and chips referred to throughout the description above can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination of them .
Those skilled in the art would also understand that the various blocks, modules, logic circuits and illustrative algorithmic steps described in relation to the modalities described here can be implemented as electronic hardware, computer software or combinations of both. In order to clearly illustrate this interchangeability of hardware and software, several components, blocks, modules, circuits and illustrative steps have been described above generically in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and design restrictions imposed on the system as a whole. Those dealing with the technique can implement the functionality described in various ways for each specific application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present invention.
The various blocks, modules and illustrative logic circuits described in relation to the modalities presented here can be implemented or executed with a general purpose processor, a digital signal processor (DSP), an application integrated circuit
56/57 specific (ASIC), a field programmable port arrangement (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components or any combination of them designed to perform the functions described here. A general purpose processor can be a microprocessor, but, alternatively, the processor can be any conventional processor, controller, microcontroller or state machine. A processor can also be implemented as a combination of computing devices, such as, for example, a combination of DSP and microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other configuration.
The steps of a method or algorithm described in connection with the modalities presented here can be embodied directly in hardware, in a software module executed by a processor, or a combination of the two. A software module can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium can be integrated with the processor. The processor and storage medium can reside in an ASIC. The ASIC can reside on a user terminal. Alternatively, the processor and the storage medium can reside as discrete components in a user terminal.
57/57
The foregoing description of the embodiments presented is provided to allow anyone skilled in the art to create or make use of the present invention. Several changes in these modalities will become readily apparent to those dealing with the technique, and the generic principles defined here can be applied to other modalities without departing from the spirit or scope of the invention. Thus, the present invention is not intended to be limited to the modalities shown here, but it should receive the broadest scope compatible with the principles and unpublished aspects presented here.
Contents5
24 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24
37 members in 15 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 97330101 | United States of America | A | |
| 0232054 | United States of America | W |
Members37
| Document | Office | Kind | |
|---|---|---|---|
| US2003070092A1 | United States of America | A1 | |
| CA2463542A1 | Canada | A1 | |
| WO03032573A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03032573A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MXPA04003335A | Mexico | A | |
| EP1436939A2 | European Patent Office (EPO) | A2 | |
| IL161312A0 | Israel | A0 | |
| KR20050034607A | Republic of Korea | A | |
| CN1633778A | China | A | |
| RU2004114212A | Russian Federation | A | |
| JP2005537689A | Japan | A | |
| HK1076553A1 | Hong Kong, China | A1 | |
| BR0213214AThis record | Brazil | A | |
| TWI256223B | Taiwan Province of China | B | |
| AU2002342014B2 | Australia | B2 | |
| US7352868B2 | United States of America | B2 | |
| RU2333608C2 | Russian Federation | C2 | |
| US2008226073A1 | United States of America | A1 | |
| AU2002342014C1 | Australia | C1 | |
| CN100481762C | China | C | |
| CN101515851A | China | A | |
| KR100967323B1 | Republic of Korea | B1 | |
| EP2204939A2 | European Patent Office (EPO) | A2 | |
| EP2204940A2 | European Patent Office (EPO) | A2 | |
| HK1137269A | Hong Kong, China | A | |
| HK1137269A1 | Hong Kong, China | A1 | |
| JP4732687B2 | Japan | B2 | |
| EP2204939A3 | European Patent Office (EPO) | A3 | |
| EP2204940A3 | European Patent Office (EPO) | A3 | |
| CA2463542C | Canada | C | |
| CN101515851B | China | B | |
| US8983065B2 | United States of America | B2 | |
| EP2204939B1 | European Patent Office (EPO) | B1 | |
| EP2204940B1 | European Patent Office (EPO) | B1 | |
| EP1436939B1 | European Patent Office (EPO) | B1 | |
| ES2791681T3 | Spain | T3 | |
| ES2796115T3 | Spain | T3 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent or certificate of addition of invention granted [chapter 16.1 patent gazette]GrantedB16A | B16A | |
| Decision: intention to grant [chapter 9.1 patent gazette]B09A | B09A | |
| Patent application procedure suspended [chapter 6.1 patent gazette]B06A | B06A | |
| Patent application procedure suspended [chapter 6.1 patent gazette]B06A | B06A | |
| Application suspended after technical examination (opinion) [chapter 7.1 patent gazette]B07A | B07A |
Numbers
- Application
- 213214
Titles2
- Portuguese
- método e equipamento de segurança em um sistema de processamento de dados
- English
- security method and equipment in a data processing system
Classification
- CPC, 8
- H04L63/04
- H04L9/08
- H04L9/0891
- H04L2209/601
- H04W4/06
- H04W12/04
- H04W12/0433
- H04W12/041
- IPC, 4
- G06F21 60
- G06F21 62
- H04L9 08
- H04L29 06