Apparatus and method for a secure broadcast system
Abstract
"EQUIPMENT AND METHOD FOR A SAFE BROADCAST SYSTEM". Equipment and a method for providing an access key used for a controlled access broadcast service are described. In one aspect, a method for secure processing on a device (Figure 4, unit 430) that securely stores a secret key (Figure 4, Kc) comprises receiving a plurality of challenges from a network, generating a plurality of keys for encryption based on the secret key and the plurality of challenges, and generate an access key based on the plurality of keys for encryption.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
6 claims: 4 independent, 2 dependent
- 1CLAIMS REIVINDICAÇÕES 1. A method for secure processing on a device that securely stores a secret key, the method comprising:1. Um método para processamento seguro em um dispositivo que armazena de forma segura uma chave secreta, o método compreendendo: receber uma pluralidade de desafios provenientes de uma rede;receive a plurality of challenges from a network;generate a plurality of keys for encryption based on the secret key and the plurality of challenges;and generate an access key based on the plurality of keys for encryption. gerar uma pluralidade de chaves para cifragem com base na chave secreta e na pluralidade de desafios;e gerar uma chave de acesso com base na pluralidade de chaves para cifragem.
- 44/7 4/7 19. The equipment according to claim 18, in which the SIM stores a 128-bit subscriber authentication key as the secret key and generates keys for 64-bit encryption; and where the processor generates a 128-bit broadcast access key using two keys for encryption. 19. O equipamento, de acordo com a reivindicação 18, no qual o SIM armazena uma chave de autenticação de assinante de 128 bits como a chave secreta e gera chaves para cifragem de 64 bits; e em que o processador gera uma chave de acesso a broadcast de 128 bits usando duas chaves para cifragem. 20. The equipment according to claim 15 or any of claims 16 and 17 when dependent on it, in which the ICC is a universal subscriber identity module (USIM) of a mobile phone using the Universal Mobile Telecommunications System standard. 20. O equipamento, de acordo com a reivindicação 15 ou qualquer uma das reivindicações 16 e 17 quando dependentes da mesma, no qual a ICC é um módulo de identidade de assinante universal (USIM) de um telefone móvel usando o padrão Sistema de Telecomunicações Móveis Universal. 21. The equipment according to claim 20, in which the USIM stores a 128-bit subscriber authentication key as the secret key and generates keys for 64-bit encryption; and where the processor generates a 128-bit broadcast access key using two keys for encryption. 21. O equipamento, de acordo com a reivindicação 20, no qual o USIM armazena uma chave de autenticação de assinante de 128 bits como a chave secreta e gera chaves para cifragem de 64 bits; e em que o processador gera uma chave de acesso a broadcast de 128 bits usando duas chaves para cifragem. 22. The equipment according to claim 15 or any of claims 16 to 21 when dependent on it, in which the receiver receives encrypted broadcast content; and where the processor generates a broadcast access key to decrypt the broadcast content. 22. O equipamento, de acordo com a reivindicação 15 ou qualquer uma das reivindicações 16 a 21 quando dependentes da mesma, no qual o receptor recebe conteúdo de broadcast criptografado; e em que o processador gera uma chave de acesso a broadcast para decriptografar o conteúdo de broadcast. 23. Equipment for secure processing in a device having mechanisms for securely storing a secret key, the equipment comprising:23. Equipamento para processamento seguro em um dispositivo possuindo mecanismos para armazenar de forma segura uma chave secreta, o equipamento compreendendo: mecanismos para gerar uma pluralidade de chaves para cifragem com base em uma pluralidade de desafios recebidos a partir de uma rede e da chave secreta;e mecanismos para gerar uma chave de acesso com base na pluralidade de chaves para cifragem. mechanisms for generating a plurality of keys for encryption based on a plurality of challenges received from a network and the secret key;and mechanisms for generating an access key based on the plurality of keys for encryption. 24. The equipment according to claim 23, further comprising: 24. O equipamento, de acordo com a reivindicação 23, compreendendo adicionalmente:
- 55/7 mecanismos para usar a pluralidade de desafios e a chave secreta para gerar uma pluralidade de respostas de autenticação; e mecanismos para enviar pelo menos uma resposta de autenticação para a rede. 5/7 mechanisms to use the plurality of challenges and the secret key to generate a plurality of authentication responses; and mechanisms for sending at least one authentication response to the network. 25. The equipment according to claim 24, further comprising:25. O equipamento, de acordo com a reivindicação 24, compreendendo adicionalmente: mecanismos para descartar quaisquer respostas de autenticação não enviadas à rede. mechanisms to discard any authentication responses not sent to the network. 26. The equipment according to claim 23 or any of claims 24 and 25 when dependent on it, in which the mechanisms for generating the passkey include: 26. O equipamento, de acordo com a reivindicação 23 ou qualquer uma das reivindicações 24 e 25 quando dependentes da mesma, no qual os mecanismos para gerar a chave de acesso compreendem: mecanismos para concatenar a pluralidade de chaves para cifragem. mechanisms to concatenate the plurality of keys for encryption. 27. The equipment according to claim 23 or any of claims 24 and 25 when dependent on it, in which the mechanisms for generating the passkey include: 27. O equipamento, de acordo com a reivindicação 23 ou qualquer uma das reivindicações 24 e 25 quando dependentes da mesma, no qual os mecanismos para gerar a chave de acesso compreendem: mecanismos para usar uma função Hash sobre a pluralidade de chaves para cifragem. mechanisms for using a hash function on the plurality of keys for encryption. 28. The equipment according to claim 23 or any one of claims 24 to 27 when dependent on it, in which the mechanisms for generating the passkey generate a passkey for broadcasting;and where the equipment additionally comprises: 28. O equipamento, de acordo com a reivindicação 23 ou qualquer uma das reivindicações 24 a 27 quando dependentes da mesma, no qual os mecanismos para gerar a chave de acesso geram uma chave de acesso a broadcast;e em que o equipamento compreende adicionalmente: 29. An article of manufacture for use in a computer system incorporating a system that securely stores a secret key and receives a plurality of challenges from a network, the article of manufacture comprising a machine-readable medium having 29. Um artigo de manufatura para uso em um sistema de computador incorporando um sistema que armazena de forma segura uma chave secreta e recebe uma pluralidade de desafios a partir de uma rede, o artigo de manufatura compreendendo um meio legível por máquina possuindo
- 66/7 machine incorporated in code mechanisms readable by means comprising:6/7 máquina incorporados no mecanismos de código legível por meio compreendendo: machine-readable code mechanisms incorporated in the machine-readable medium to generate a plurality of keys for encryption based on the plurality of challenges and the secret key;and machine-readable code mechanisms incorporated into the machine-readable medium to generate a passkey based on the plurality of keys for encryption. mecanismos de código legível por máquina incorporados no meio legível por máquina para gerar uma pluralidade de chaves para cifragem com base na pluralidade de desafios e na chave secreta;e mecanismos de código legível por máquina incorporados no meio legível por máquina para gerar uma chave de acesso com base na pluralidade de chaves para cifragem. 30. The article of manufacture according to claim 29, further comprising: 30. O artigo de manufatura, de acordo com a reivindicação 29, compreendendo adicionalmente: machine-readable code mechanisms incorporated in the machine-readable medium to use the plurality of challenges and the secret key to generate a plurality of authentication responses;and machine-readable code mechanisms incorporated into the machine-readable medium to send at least one authentication response to the network. mecanismos de código legível por máquina incorporados no meio legível por máquina para usar a pluralidade de desafios e a chave secreta para gerar uma pluralidade de respostas de autenticação;e mecanismos de código legível por máquina incorporados no meio legível por máquina para enviar pelo menos uma resposta de autenticação à rede. 31. The article of manufacture according to claim 30, further comprising: 31. 0 artigo de manufatura, de acordo com a reivindicação 30, compreendendo adicionalmente: machine-readable code mechanisms embedded in the machine-readable medium to discard any authentication responses not sent to the network. mecanismos de código legível por máquina incorporados no meio legível por máquina para descartar quaisquer respostas de autenticação não enviadas à rede. 32. The article of manufacture, according to claim 29, in which the machine-readable code mechanisms for generating the passkey comprise: 32. O artigo de manufatura, de acordo com a reivindicação 29, no qual os mecanismos de código legível por máquina para gerar a chave de acesso compreendem: machine-readable code mechanisms incorporated in the machine-readable medium to concatenate the plurality of keys for encryption. mecanismos de código legível por máquina incorporados no meio legível por máquina para concatenar a pluralidade de chaves para cifragem. 33. The article of manufacture according to claim 29, in which machine-readable code mechanisms for generating the passkey comprise: 33. O artigo de manufatura, de acordo com a reivindicação 29, no qual mecanismos de código legível por máquina para gerar a chave de acesso compreendem: Ί / Ί machine-readable code mechanisms in the machine-readable medium to use a hash function over the plurality of keys for encryption. Ί/Ί mecanismos de código legível por máquina no meio legível por máquina para usar uma função Hash sobre a pluralidade de chaves para cifragem. 34. The manufacturing article according to claim 29, in which the system receives encrypted broadcast content, in which the machine-readable code mechanisms for generating the passkey generate a broadcast passkey;and in which the article of manufacture additionally comprises: 34. O artigo de manufatura, de acordo com a reivindicação 29, no qual o sistema recebe conteúdo de broadcast criptografado, em que os mecanismos de código legível por máquina para gerar a chave de acesso geram uma chave de acesso de broadcast;e em que o artigo de manufatura compreende adicionalmente: machine-readable code mechanisms incorporated in the machine-readable medium to decrypt broadcast content based on the broadcast access key. mecanismos de código legível por máquina incorporados no meio legível por máquina para decriptografar o conteúdo de broadcast com base na chave de acesso a broadcast. 1/6 1/6 2/6 2/6 200 200 Ο :<+.· w Ο: <+. · W 3/6 3/6 310 , _, Encrypted: 310 ,_, Criptografado:
Independent claims4
96 paragraphs in 6 sections, as filed
(54) Title: EQUIPMENT AND METHOD FOR A SAFE BROADCAST SYSTEM (30) Unionist Priority: 07/08/2003 us 60 / 485,791; 06/16/2004 US 10 / 870,303 (71) Depositor (s): Qualcomm Incorporated (US) (72) Inventor (s): Gregory G. Rose, James Semple, Roy Franklin Quick (57) Summary: EQUIPMENT AND METHOD FOR A SAFE BROADCAST SYSTEM. Equipment and a method for providing an access key used for a controlled access broadcast service are described. In one aspect, a method for secure processing on a device (Figure 4, unit 430) that securely stores a secret key (Figure 4, Kc) comprises receiving a plurality of challenges from a network, generating a plurality of keys for encryption based on the secret key and the plurality of challenges, and generate an access key based on the plurality of keys for encryption.
(74) Attorney: Montaury Pimenta, Machado & Lioce (86) International Request: pct US2004 / 021850 of 07/08/2004 (87) International Publication: wo 2005/008398 of 27/01/2005
<img file="BRPI0412397A_D0001.tif" />
<img file="BRPI0412397A_D0002.tif" />
EQUIPMENT AND METHOD FOR A SAFE BROADCAST SYSTEM
CROSS REFERENCE TO RELATED ORDERS
The present patent application claims the priority of Provisional US Patent Application N<sup>2</sup> 60/485 791, entitled APPARATUS AND METHOD FOR A SECURE BROADCAST SYSTEM, filed on July 8, 2003, in
<td>name of</td><td>Applicant and</td><td>here expressly</td><td>incorporated</td><td>through the</td>
<td>gift</td><td>reference.</td><td>EMBASMATION</td><td></td><td></td>
<td>I. FIELD</td><td>THE INVENTION</td><td></td><td></td><td></td>
<td></td><td>This</td><td>invention is</td><td>a way</td><td>general</td>
related to secure communication systems and more particularly the management of access keys for irradiation service or multimedia broadcast in a mobile environment.
II. DESCRIPTION OF THE RELATED TECHNIQUE
Wireless communication systems are widely deployed to provide various types of communication, such as voice and so on. Such systems can be based on code division multiple access (CDMA), time division multiple access (TDMA) or other modulation techniques.
A system can be designed to support one or more standards, such as ο TIA / EIA-95-B Mobile Station Base Station Compatibility Standard for Dual Mode Wideband Spread Spectrum Cellular System, (the IS-95 standard); the communication standard of the Global System for Mobile Telecommunications (GSM) based on TDMA; the Universal Mobile Telecommunications System (UMTS) standard, which is a third generation wireless service based on the GSM communication standard; the communication standard of the General Packet Radio System (GPRS), which consists of a stage of evolution from GSM to UMTS; the standard proposed by a consortium called 3rd Generation Partnership Project
2/19 (3GPP) and incorporated into a set of documents including the documents N— 3G TS 25.211, 3G TS 25.212, 3G TS 25.213 and 3G TS 25.214, 3G TS 25.302 (the W-CDMA standard), the standard proposed by a consortium called 3rd Generation Partnership Project 2 (3GPP2), incorporated in the TR45.5 Physical Layer Standard for cdma2000 Spread Spectrum Systems (the IS-2000 standard). Each standard defines data processing for wireless communication between an infrastructure element, such as a base station, and an end-user device, such as a mobile device.
The growing demand for wireless data transmission and the expansion of services available through wireless communication technology have led to the development of specific data services. In one embodiment, a system can be configured to support multimedia broadcasting services (hereinafter referred to as broadcast service). Similar to television and / or radio broadcasting, the broadcast service can be used to wirelessly stream streams of multimedia content from a content provider to end user devices. In this case, a stream of content can be considered as equivalent to a television channel or radio station. Examples of streams of multimedia content include audio and / or video data such as films, sporting events, news and various other programs and / or files. Typically, a service provider indicates the availability of such a broadcast service to users. Users who wish to broadcast service can receive parameters related to the broadcast service in overhead messages transmitted by elements of the infrastructure. When a user wants to receive a certain stream of content, the user's end device reads the overhead messages and learns the
3/19 appropriate settings. The following end user device tunes to the channel or frequency containing the content stream and receives the broadcast service.
There are several possible subscription / rental models for the broadcast service, including open access, controlled access and partially controlled access. For free access, no subscription is required for users to receive the service. The content is broadcast without encryption, in such a way that the end user devices of interested users can receive and view the content. Income for the service provider can be generated through advertisements or advertisements that can also be broadcast on the broadcast channel. As an example, premiere movie clips can be streamed, for which the studios will pay the service provider.
In controlled access, users are required to subscribe and be authorized to receive the broadcast service by paying a fee or subscription. Such controlled access can be achieved by encrypting the transmission of the broadcast service or content with cryptographic access keys in such a way that only subscribing users can decrypt and view the content. In this case, the encryption of broadcast content can be based on symmetric or asymmetric encryption systems. In symmetric encryption systems, the same keys are used for encryption / decryption and in asymmetric encryption systems, different keys are used for encryption / decryption.
Cryptography is well known to technicians in the field and will not be described in more detail here. A hybrid access or partial controlled access scheme provides broadcast service in the form of a subscription-based service that is encrypted with intermittent transmissions of unencrypted advertisements. Such announcements
4/19 may be intended to encourage subscriptions to the encrypted broadcast service.
For controlled or partially controlled broadcast service, there is a problem with the secure provisioning of the access key from a content provider to one or more receivers. Therefore, there is a demand for a secure way to provide an access key for end user devices. More particularly, the provision of the access key must conform to existing standards and their corresponding infrastructures, as well as to developing standards and their corresponding infrastructures.
ABSTRACT
The modalities described here meet the demand mentioned above for allowing a secure provision of the access key for the end user devices.
In one embodiment, a method for securely processing a device that securely stores a secret key comprises receiving a plurality of challenges from a network; generate a plurality of keys for encryption based on the secret key and the plurality of challenges; and generate an access key based on the plurality of keys for encryption. The method may also comprise using the plurality of challenges and the secret key to generate a plurality of authentication responses; and send at least one authentication response to the network. The generation of the access key may include generating a broadcast access key; and wherein the method further comprises: receiving encrypted broadcast content; and decrypting broadcast content based on the broadcast access key. The decryption of the content can comprise: generate a temporary decryption key based on each challenge and the broadcast access key; and decrypt the
5/19 broadcast content using the temporary decryption key.
In another embodiment, an equipment for secure processing in a device having devices for securely storing a secret key comprises devices for generating a plurality of keys for encryption based on a plurality of challenges received from a network and the secret key; and devices for generating an access key based on the plurality of keys for encryption.
In yet another embodiment, a machine-readable medium for use in a device that securely stores a secret key and receives a plurality of challenges from a network is described. The machine-readable medium comprises codes for generating a plurality of keys for encryption based on the plurality of challenges and the secret key; and codes for generating an access key based on the plurality of keys for encryption.
In the above modalities, a 128-bit subscriber authentication key can be stored as the secret key in a mobile phone's subscriber identity module using the Global System for Mobile Telecommunications communication standard. A 128-bit subscriber authentication key can also be stored as the secret key in a mobile phone's universal subscriber identity module using the Universal Mobile Telecommunications System standard. In addition, keys for 64-bit encryption can be generated and a 128-bit broadcast access key can be generated using two keys for encryption.
In another embodiment, equipment for use on a mobile phone comprises: an integrated circuit board (ICC) configured to securely store a secret key and to generate a plurality of keys for encryption based on the secret key and a password.
6/19 plurality of challenges received from a network; and a processor coupled to the ICC and configured to generate an access key based on the plurality of keys for encryption. The ICC can be a subscriber identity module (SIM) of a mobile phone using the communication standard of the Global System for Mobile Telecommunications. The SIM can store a 128-bit subscriber authentication key as the secret key and generate keys for 64-bit encryption. The ICC can also be a universal subscriber identity module (USIM) for a mobile phone using the Universal Mobile Telecommunications System standard. USIM can store a 128-bit subscriber authentication key as the secret key and generate keys for 64-bit encryption in a mode that is backward compatible with the SIM. The processor can generate a 128-bit broadcast access key using two keys for encryption.
BRIEF DESCRIPTION OF THE DRAWINGS
Various modalities will be described in detail with reference to the following drawings, in which similar numerical references identify corresponding items and in which:
Figure 1 is an example of wireless communication capable of supporting the broadcast service;
Figure 2 shows a simplified network for implementing MBMS;
Figure 3 shows a terminal capable of subscribing to MBMS to receive multimedia content;
Figure 4 is a simplified example of a GSM system;
Figure 5 is an example of a system with a network that performs authentication and a terminal for broadcast service; and
7/19
Figure 6 presents a method for secure processing on a device that securely stores a secret key.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
In the description that follows, specific details are presented to provide a complete understanding of the modalities. However, it will be noted by technicians in the field that the modalities can be practiced without such specific details. As an example, circuits can be presented in block diagrams so as not to obscure the modalities with unnecessary details. In other cases, well-known circuits, structures and techniques can be presented in detail so as not to obscure the modalities.
In addition, it should be noted that the modalities can be described as a process that is presented in the form of a flow chart, a flow diagram, a structure diagram, or a block diagram. Although a flowchart can describe operations as a sequential process, many operations can be carried out in parallel or concurrently. Additionally, the order of operations can be rearranged. A process is terminated when its operations are completed. A process can correspond to a method, a function, a procedure, a subroutine, a sub-program, etc. When a process corresponds to a function, its termination corresponds to a return of the function to the calling function or the main function.
In addition, as described herein, a storage medium can represent one or more data storage devices, including a read-only memory (ROM), random access memory (RAM), magnetic disk storage media, storage media optical devices, flash memory devices and / or other machine-readable means for storing information.
8/19
The term machine-readable means includes, but is not limited to, portable or fixed storage devices, optical storage devices, wireless channels and various other media capable of storing, containing, or carrying instructions and / or data.
Figure 1 shows an example of a wireless communication network 100 capable of supporting the broadcast service. Network 100 can comprise one or more communication systems that support different standards. More particularly, network 100 comprises a plurality of service areas 102a to 102g, each of which is served by a corresponding infrastructure element 104a to 104g, respectively. Infrastructure elements 104a to 104g communicate with end-user devices (hereinafter terminals) 106a to 106j that are within service areas 102a to 102g of infrastructure elements 104a to 104g, respectively. Depending on the type of communication system, infrastructure elements 104a to 104g can include base stations, a base station transceiver, gateways or other devices that communicate with terminals 106a to 106j. Terminals 106a to 106j can be, but are not limited to, a mobile phone (including cellular and personal communication service), a corded phone, a wireless device, a personal data assistant (PDA), various computer devices (including laptop and desktop) or other data transceiver. As shown in Figure 1, terminals 106a to 106j can be manual, mobile, portable, as mounted on a vehicle (including cars, trucks, boats, trains and aircraft) or fixed (stationary).
In one embodiment, network 100 supports a broadcast service designated as broadcast / multicast multimedia service (MBMS), sometimes referred to as broadcast / multimedia service (BCMCS). In general, MBMS is a packet data service based on the
9/19 Internet Protocol (IP). A service provider can indicate the availability of such an MBMS to users. Users wishing to MBMS can receive the service and discover the broadcast service program through radiations such as advertisements, short message services (SMS) and wireless application protocol (WAP). The infrastructure elements transmit parameters related to MBMS in overhead messages. When a user wishes to receive a broadcast session, a terminal 106 reads the overhead messages and learns the appropriate settings. Terminal 106 below tunes to the frequency containing the MBMS channel and receives the broadcast service content.
Figure 2 shows a simplified network 200 for implementing the MBMS. In network 200, video and / or audio information is provided to the packet data services network (PDSN) 230 by a content source (CS) 210. The video and audio information can come from televised programs or broadcasts radio. The information is provided in the form of packet data, such as IP packets. PDSN 220 processes IP packets for distribution within an access network (AN). As illustrated, the access network is defined as portions of network 200 including an infrastructure element 240 in communication with a plurality of terminals 250.
For MBMS, CS 210 provides encrypted content. The infrastructure element 240 receives the information stream from the PDSN 230 and provides the information through a channel designated for subscriber terminals within the network 200. To control access, the content coming from the CS 210 is encrypted by a content encryption (not shown) using a key for encryption before being provided to the PDSN 220. Although the content encryption can be implemented together or separately from the CS 210, the content encryption and CS 210 will hereinafter be referred to as a
10/19 content provider. Subscribing users receive the decryption key so that IP packets can be decrypted.
More particularly, Figure 3 shows a terminal 300 capable of subscribing to the MBMS to receive multimedia content. Terminal 300 comprises an antenna 310
<td>coupled</td><td>together</td><td>of circuits</td><td>in</td><td>reception</td><td> 320 .</td><td> 0</td>
<td>terminal</td><td>300 receives</td><td>transmissions</td><td colspan="2">from</td><td>in</td><td>one</td>
<td>provider</td><td>of content</td><td colspan="2">(not shown)</td><td>through</td><td>in</td><td>one</td>
infrastructure element (not shown). The terminal 300 includes a mobile device 340 and a universal integrated circuit board (UICC) 330 coupled to the receiving circuitry 320. It should be noted that in some terminals, the UICC 330 and the ME 340 can be implemented together in one secure processing unit. In addition, although the modality is described using the UICC, other integrated circuits and / or secure processing units, such as a user identification module (UIM), a subscriber identity module (SIM) or universal SIM, can be implemented in a terminal.
In general, UICC 330 applies verification procedures for the security of MBMS transmission and provides several keys for the ME 340. The ME 340 provides substantial processing, including, but not limited to, decryption of the MBMS content streams using the keys provided by UICC 330. UICC 330 is entrusted with the secure storage and processing of secret information (such as encryption keys) that must remain secret for a long time. As UICC 330 is a secure unit, the secrets stored there do not necessarily require the system to change information
<td>secret with</td><td>frequency.</td><td>The UICC</td><td> 330</td><td colspan="2">can</td><td>include</td><td>an</td>
<td colspan="2">processing unit</td><td>designated</td><td colspan="2">as</td><td>an</td><td>unity</td><td>in</td>
<td>processing</td><td>Secure UICC</td><td>(SUPU)</td><td> 332</td><td>and</td><td>an</td><td>unity</td><td>in</td>
<td>storage</td><td>from memory</td><td>designated</td><td colspan="2">as</td><td>an</td><td>unity</td><td>in</td>
11/19 secure UICC memory (SUMU) 334. Within UICC 330, SUMU 334 stores secret information in a way that discourages unauthorized access to information. If secret information is obtained from UICC 330, access will require a significantly large amount of resources. In addition, inside UICC 330, SUPU 332 computes values that can be external and / or internal to UICC 330. The computation results can be stored in the SUMU 334 or passed to the
ME '340.
In one embodiment, UICC 330 is a stationary or integrated unit inside terminal 300. Note that UICC 330 may also include non-secure memory and processing (not shown) for storing information including telephone numbers, email addresses, web pages or URL address information, and / or programming functions, etc. Alternative modalities can provide a removable and / or re-programmable UICC. Typically, the SUPU 332 does not have significant processing power for functions other than security procedures and keys, in order to allow encryption of the broadcast content of the MBMS. However, alternative modalities can implement a UICC having stronger processing power.
Although the UICC 330 is a secure unit, the data on the ME 340 can be accessed by a non-subscriber and is considered non-secure. Any information passed to the ME 340 or processed by the ME 340 remains securely secret for only a short time. It is therefore desired that any secret information, such as keys, stored with the ME 340 be modified frequently.
More particularly, MBMS content is encrypted using unique and frequently modified temporary encryption keys, designated as
12/19 short-term keys (SK). To decrypt the broadcast content at a specific time, the ME 340 must know the current SK. SK is used to decrypt broadcast content for a short time in such a way that SK can be presumed to have a certain amount of intrinsic monetary value for a user. As an example, such intrinsic monetary value may be a part of the registration costs. In this case, different types of content may have different intrinsic monetary values. Assuming that the cost for a non-subscriber to obtain SK from a subscriber's ME 340 exceeds SK's intrinsic monetary value, the cost of illegitimately obtaining SK outweighs the reward and there is no benefit. Consequently, there is no need to protect the SK in the ME 340. However, if a broadcast has an intrinsic value higher than the cost of illegitimately obtaining such a secret key, there is a benefit to the non-subscriber in obtaining such a key from the ME 340. Therefore, the ME 340 ideally will not store secrets with a lifetime longer than that of an SK.
In addition, channels used by a content provider (not shown) for transmitting data are considered unsafe. Therefore, SK is not transmitted by air. It is derived by UICC 330 or ME 340 from a passkey called a broadcast passkey (BAK) and SK (SKI) information disseminated along with the encrypted content. BAK can be used for a certain period of time, for example a day, a week, or a month, and is updated. Within each BAK update period, a shorter interval is provided during which the SK is modified. The content provider can use a cryptographic function to determine two SK and SKI values, such that SK can be determined from BAK and SKI. In one embodiment, SKI
13/19 can contain the SK which is encoded using BAK as the key. Alternatively, SK may be the result of applying a cryptographic hash function to the concatenation
<td>in</td><td>SKI and</td><td>BAK. In this</td><td>case,</td><td>at</td><td>SKI can</td><td>own a certain</td>
<td colspan="3">random value.</td><td></td><td></td><td></td><td></td>
<td></td><td></td><td>To get</td><td>access</td><td>to</td><td colspan="2">MBMS, a user registers</td>
<td>and</td><td>sign</td><td>the service</td><td>In</td><td>an</td><td>modality</td><td>of the process</td>
registration, a content provider and UICC 330 agree on a registry key or root key (RK) that serves as a security association between the user and the content provider. Registration can occur when a user subscribes to a broadcast channel offered by the content provider, or it can occur before subscription. A single content provider can offer multiple broadcast channels. The content provider can choose to associate users with the same RK for all channels, or require users to register for each channel and associate the same user with different RKs on different channels. Multiple content providers can choose to use the same registration keys or require the user to register and obtain a different RK.
If possible, the RK is then kept a secret in UICC 330. The RK is exclusive for a given UICC, that is, each user receives a different RK. However, if a user has multiple UICCs, then such UICCs can be configured to share the same RK depending on the content provider's policies. The content provider can then send other secret information to UICC, such as BAK encoded with RK. The UICC 330 is able to retrieve the value of the original BAK from the BAK encoded using the RK. Since the ME 340 is not a secret unit, UICC 330 does not provide BAK for the ME 340.
The content provider also broadcasts the SKI that is combined with BAK on UICC 330 to derive SK. THE
14/19
UICC 330 then passes SK to ME 340 and ME 340 uses SK to decrypt encrypted broadcast transmissions received from a content provider. In this way, the content provider can efficiently distribute new SK values to subscribing users.
As described, controlled access can be obtained by providing an RK agreed on UICC 330 SUMU 334. However, in the existing infrastructure of some systems, an appropriate RK value cannot be maintained in a secure unit such as UICC 330 due to the cost and / or inconvenience of replacing existing UICCs, SIMs, UIMs or other integrated circuit boards.
As an example, in GSM systems, a subscriber identity module (SIM) is the secure unit and contains subscriber identifier data about a user that can be used to gain access to a network. For explanatory purposes, Figure 4 shows a simplified example of a GSM 400 system for subscriber authentication to allow access to a network. 0 system 400 comprises a home location register (HLR) 410, a visitor location register (VLR) 420 and a terminal such as a mobile device 430. Note that system 400 comprises additional elements, however GSM systems are well known to technicians in the field and will not be described in detail.
The HLR 410 is a subscriber database for a mobile system. The HLR 410 is maintained by the home carrier of a terminal and contains important user information for billing and authentication for a network. The VLR 420 is also a database and contains temporary user information, such as the current location of a terminal, to manage requests from subscribers who are outside the area covered by their home system. When a user initiates the call and the terminal
15/19 subscriber case, one of the user is outside the home or home area, the VLR 420 communicates with the HLR 410 to obtain information required to process a call, including the information required for subscriber authentication.
Terminal 430 comprises a SIM module 432 that securely contains an authentication key (K) used to authenticate a subscriber. This handshake challenge authentication protocol, known as an authenticated key agreement (AKA) is typically used for GSM authentication. At AKA, a network sends a challenge message to a subscriber terminal, which responds with a value obtained using a one-way hash function. In this case, the challenge message can be a random value. The network checks the response against its own expected hash value. If the values are in agreement, authentication is confirmed. When generating such a response, a key is also generated that can be used to secure subsequent communications.
More particularly, in the GSM system, the VLR 420 requests authentication parameters from the HLR 410. The HLR 410 sends a random 128-bit RAND number, a signed response (RES) and an encryption key (Kc) to the VLR. RES and Kc are both generated from the K and RAND subscriber authentication key, using different algorithms. Using such an authentication trio (RAND, RES, Kc), a challenge message is sent by sending the random RAND number to terminal 430. The received RAND is passed to SIM 432, which generates RES and Kc using RAND and K. The generated RES is returned to VLR 420, which checks whether the two RES values are in agreement. If so, the subscriber is authenticated and both the terminal and the network initiate encryption / decryption using
Kc.
16/19
Although GSM SIM securely contains a subscriber authentication key (K) used to authenticate a subscriber, it does not allow the provision of an additional key such as the RK. That is, the existing GSM SIMs cannot be modified. Therefore, one way of transporting BAK for broadcast service may be to use Kc instead of RK to encrypt BAK. A content provider would send a message containing Kc-encoded RAND and BAK. A terminal receives the message and passes the RAND to the SIM as if it were a normal GSM authentication. Therefore, RES and Kc are generated by SIM using RAND and K. In this case, the RES generated by SIM can be discarded. This provides protection against an attacker who could send the same RAND and record the returned RES for unauthorized access. The Kc can be used to decrypt the encoded BAK.
However, Kc is typically a 64-bit key, while some broadcast services, such as MBMS, are designed to provide 128-bit security. Therefore, it is necessary to use a key longer than 64 bits to encrypt the BAK. As a result, a plurality of trios are used for BAK encryption.
Figure 5 shows an example of a system 500 with a 510 network that performs authentication and a terminal 520 for broadcast service. The 510 network comprises one or more content providers and other infrastructure elements required for broadcast service. The terminal 520 comprises the ICC 522 coupled to a processor 524. In GSM systems, the network 510 can comprise a VLR and an HLR and the ICC 522 would be a SIM module as described in Figure
4. In general, network 510 sends challenge messages to perform authentication. Challenge messages are used by terminal 520 to generate the BAK for controlled access. In other words, ICC 522 on terminal 510 securely stores a secret key used in the generation of BAK. THE
17/19 System 500 operation will be explained with reference to Figure 6 below.
Figure 6 presents a method 600 for secure processing on a device, such as terminal 620, which securely stores a secret key, such as a subscriber authentication key, in a secure unit. Like ICC 622. In method 600, the device receives a plurality of challenges from a network (610). The plurality of challenges can be in a message or in a plurality of messages. A plurality of keys for encryption is generated based on the secret key and the plurality of challenges (620). The access key is then generated based on the plurality of encryption keys (630). In system 500, for example, ICC 522 is configured to generate the keys for encryption, since the secret key must be kept within ICC 522. Processor 524 is configured to generate the access key based on the keys for encryption .
The passkey is generated using a plurality of keys for encryption as the passkey is typically longer than an encryption key. As an example, in GSM for MBMS, the encryption key has 64 bits, while the access key has 128 bits. In this case, the access key can be generated using two keys for encryption. Any known technique can be used to generate an access key from the plurality of keys for encryption. In one embodiment, the access key is generated by concatenating the plurality of keys for encryption. In an alternative mode, the access key is generated using a hash function over the plurality of keys for encryption. The hash function can comprise SHA-1 to mix the plurality of keys for encryption.
For authentication, method 600 can also understand the use of the plurality of challenge messages and
18/19 of the secret key to generate a plurality of authentication responses, as described with reference to Figure 4. Next, at least one of the authentication responses is returned to the network using a transmitter (not shown) implemented in the terminal 520 and any authentication responses not sent to the network can be discarded.
Therefore, after generating the passkey, method 600 can also understand the receipt of encrypted broadcast content and decrypt the broadcast content based on the passkey. As an example, in MBMS, the passkey would be BAK and SKI would be used to generate SK. In this case, method 600 may also comprise the generation of a temporary encryption / decryption key, such as SK, based on each challenge message and the current BAK. The current SK can then be used to decrypt and view / process the encrypted content.
Therefore, the described modalities allow a secure provision of an access key for broadcast service. It should be noted here that although the modalities have been described with reference to the MBMS, the scope of the invention applies to broadcast services other than MBMS and to various systems that require controlled access. Similarly, the passkey can be shorter or longer than 128 bits. In addition, the modalities may apply to systems other than the GSM system. As an example, UMTS systems have a USIM that is analogous to GSM SIM and has a backward compatible mode that allows it to act as a GSM SIM.
Additionally, the modalities can be implemented through hardware, software, firmware, middleware, micro code, or any combination thereof. When implemented in software, firmware, middleware or micro code, the program code or code segments to perform the necessary tasks can be stored
19/19 in a machine-readable medium (not shown). A processor can perform the necessary tasks. A code segment can represent a procedure, a function, a sub-program, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or statements of program. A code segment can be coupled to another code segment or to a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., can be passed on, passed on, or transmitted through any suitable means, including memory sharing, message passing, token passing, network transmission, etc. In addition, the machine-readable medium can be implemented in a manufacturing article for use in a computer system and may have machine-readable code mechanisms incorporated into it.
Finally, it should be noted that the above modalities are merely examples and should not be considered as limiting the invention. The description of the modalities is intended to be illustrative and not to limit the scope of the claims. Therefore, the present teachings can be readily applied to other types of equipment and various alternatives, modifications and variations will become clear to technicians in the field.
Contents6
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
21 members in 13 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 48579103 | United States of America | P | |
| 87030304 | United States of America | A | |
| 2004021850 | United States of America | W |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| US2005010774A1 | United States of America | A1 | |
| AU2004258561A1 | Australia | A1 | |
| CA2531590A1 | Canada | A1 | |
| WO2005008398A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2005008398A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200518543A | Taiwan Province of China | A | |
| MXPA06000274A | Mexico | A | |
| KR20060031852A | Republic of Korea | A | |
| EP1649630A2 | European Patent Office (EPO) | A2 | |
| IL173021A0 | Israel | A0 | |
| BRPI0412397AThis record | Brazil | A | |
| CN1846395A | China | A | |
| RU2006103624A | Russian Federation | A | |
| JP2007529147A | Japan | A | |
| AU2004258561B2 | Australia | B2 | |
| AU2004258561C1 | Australia | C1 | |
| EP1649630A4 | European Patent Office (EPO) | A4 | |
| RU2419223C2 | Russian Federation | C2 | |
| TWI386004B | Taiwan Province of China | B | |
| CA2531590C | Canada | C | |
| US8718279B2 | United States of America | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent lapsed as no evidence of payment of the annual fee has been furnished to inpi [chapter 8.11 patent gazette]LapsedEM VIRTUDE DO ARQUIVAMENTO PUBLICADO NA RPI 2314 DE 12-05-2015 E CONSIDERANDO AUSENCIA DE MANIFESTACAO DENTRO DOS PRAZOS LEGAIS, INFORMO QUE CABE SER MANTIDO O ARQUIVAMENTO DO PEDIDO DE PATENTE, CONFORME O DISPOSTO NO ARTIGO 12, DA RESOLUCAO 113/2013.B08K | B08K | |
| Application dismissed because of non-payment of annual fees [chapter 8.6 patent gazette]REFERENTE A 11A ANUIDADE.B08F | B08F |
Numbers
- Application
- 4123972
Titles2
- Portuguese
- equipamento e método para um sistema de broadcast seguro
- English
- equipment and method for a secure broadcast system
Classification
- CPC, 13
- H04W12/08
- H04L9/0844
- H04L63/0428
- H04L63/06
- H04L2463/101
- H04W84/12
- H04L9/14
- H04L2209/601
- H04L2209/80
- H04W12/0431
- H04L9/0643
- H04L9/0877
- H04L9/0894
- IPC, 3
- H04L9 08
- H04L12 28
- H04L29 06