System, method and computer program product for detecting a rogue member in a multicast group
Abstract
A system for multicasting data packets in a multicast group, including network entities and multiple members of the multicast group. The member may notify the network entity of the fraudulent member of the group claiming the identity of the impersonated member of the group. In response to the notification, the network entity may distribute different versions of the symmetric key related to the impersonated member to at least the group members other than the impersonated member. The member who informs the network entity of the fraudulent member can then receive the next data packet and the code for the next data packet, the code is generated at the fraudulent member using a version of the symmetric key associated with the impersonated member , So that fraudulent members can be identified based on the symmetric key version.

Term
Term ended
Projected expiry passed 22 December 2025, 0.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
28 claims: 28 independent, 0 dependent
- 1一种用于在多播组中多播数据分组的系统,所述系统包括:网络实体;以及所述多播组的多个成员,其中至少一个成员能够通知所述网络 实体所述组的成员操作为声称所述组的另 一成员的身份的欺诈成 员,所述组的该另一成员是被冒充的成员,其中,响应于被通知,所述网络实体能够向至少除所述被冒充 成员以外的所述组的成员分发与所述被冒充成员相关的对称密钥的 不同版本,以及,其中将所述欺诈成员通知给所述网络实体的所述成员还能接收 下 一 数据分组和用于所述下一 数据分组的代码,所述代码已经在所 述欺诈成员处使用与所述被冒充成员相关的对称密钥的版本生成, 使得能基于所述对称密钥的版本来识别所述欺诈成员。
- 2根据权利要求1所述的系统,其中将所述欺诈成员通知给所述网络实体的所述成员还能接收数据分组以及确定所述接收到的数据分组是否已经从操作为欺诈成员的所述 组成员多播,以及其中当并且响应于确定所述接收的数据分组已经 从所述欺诈成员多播时,相应的成员能通知所述网络实体。
- 3根据权利要求2所述的系统,其中将所述欺诈成员通知给所 述网络实体的所述成员能接收包括所述数据分组、用于所述数据分组的代码以及成员标识符的内容分组,以及其中所述相应的成员能 通过对所述内容分组中的所述成员标识符和与接收所述内容分组的 成员相关的成员标识符进行比较来确定所述接收到的数据分组是否 已经从欺诈成员多播,以及当所述比较识别出所述内容分组中的所 述成员标识符和与接收所述内容分组的成员相关的所述成员标识符 相匹配时,确定所述接收到的数据分组已经从欺诈成员多播。
- 4根据权利要求1所述的系统,其中所述网络实体以及将所述 欺诈成员通知所述网络实体的所述成员中至少其一还能基于用于生 成用于所述下 一数据分组的所述代码的所述对称密钥版本来识别所 述欺诈成员。
- 5根据权利要求4所述的系统,其中所述网络实体还能在所述欺诈成员被识别之后从所述多播组排除所述欺诈成员。
- 6根据权利要求4所述的系统,其中响应于被通知,所述网络 实体还能向所述被冒充成员分发与所述被冒充成员相关的对称密钥 的所有不同版本,所述网络实体分发所述对称密钥的所有不同版本 以有助于所述相应的成员识别所述#夂诈成员。
- 7根据权利要求1所述的系统,其中所述多播组的至少一个成 员能够操作为目的地成员以从操作为源成员的所述组的另一成员接 收数据分组和用于所述数据分组的代码,所述代码已经在所述源成 员处使用与所述源成员相关的对称密钥生成,其中所述目的地成员能够确定所述接收到的数据分组是否已经 从操作为欺诈成员的所述组成员多播,其中当所述接收到的数据分组已经从欺诈成员多播的时候,所述 目的地成员能够向所述多播组成员多播二次呼叫分组,以及基于与 所述数据分组相关的所述代码认证所述源成员,以及其中当以及响应于确定所述接收到的数据分组已经从所述欺诈 成员多播时,所述目的地成员能通知所述网络实体。
- 8—种包括多个成员的多播组的成员,其中所述成员包括: 能操作客户端的处理器,其中所述客户端能够将操作为声称所述组的另一成员身份的欺诈成员的组成员通知给网络实体,该另一 成员是被冒充成员,其中所述客户端能通知所述网络实体,使得所 述网络实体能向至少除所述被冒充成员之外的所述组的成员分发与 所述被冒充成员相关的对称密钥的不同版本,以及其中所述客户端能够接收下一数据分组和用于所述下一数据分 组的代码,所述代码已经在所述欺诈成员处使用与所述被冒充成员 相关的 一个对称密钥版本产生,使得能基于所述对称密钥版本来识 别所述欺诈成员。
- 9根据权利要求8所述的成员,其中所述客户端还能接收数据分组以及确定所述收到的数据分组是否已经从操作为欺诈成员的所 述组成员多播,以及其中当并且响应于确定所述收到的数据分组已 经所述欺诈成员多播时,所述客户端能通知所述网络实体。
- 10根据权利要求9所述的成员,其中所述客户端能接收包括 所述数据分组、用于所述数据分组的代码以及成员标识符的内容分 组,以及其中所述客户端能够通过对所述内容分组中的所述成员标 识符和与接收所述内容分组的成员相关的成员标识符进行比较来确 定所述收到的数据分组是否已经从欺诈成员多播,以及当所述比较 识别出所述内容分组中的所述成员标识符和与接收所述内容分组的 成员相关的所述成员标识符相匹配时,确定所述收到的数据分组已 经从欺诈成员多播。
- 11根据权利要求8所述的成员,其中所述客户端还能基于用 于产生用于所述下 一数据分组的所述代码的所述对称密钥版本来识 别所述欺诈成员。
- 12根据权利要求11所述的成员,其中所述客户端还能将所述 欺诈成员的身份通知给所述网络实体,使得所述网络实体能随后从 所述多播组排除所述欺诈成员。
- 13根据权利要求11所述的成员,其中所述客户端能够接收与 所述被冒充成员相关的对称密钥的所有不同版本,从而有助于所述 客户端识别所述欺诈成员。
- 14根据权利要求8所述的成员,其中所述客户端还能从操作 为源成员的所述组成员接收数据分组和用于所述数据分组的代码, 所述代码已经在所述源成员处使用与所述源成员相关的对称密钥生 成5其中所述客户端能够确定所述接收到的数据分组是否已经从操 作为欺诈成员的所述组成员多播,其中当所述接收到的数据分组已经从欺诈成员多播时,所述客 户端能够向所述多播组成员多播二次呼叫分组,以及基于与所述数 据分组相关的所述代码来认证所述源成员,以及其中当以及响应于确定所述接收的数据分组是从所述欺诈成员 多播时,所述客户端能通知所述网络实体。
- 15—种在包括多个成员的多播组中识别欺诈成员的方法,其 中,对于所述组的至少一个成员,所述方法包括:将操作为声称所述组的另 一成员身份的欺诈成员的组成员通知 给网络实体,该另一成员是被冒充成员,其中通知网络实体包括通 知网络实体使得所述网络实体能向至少除所述被冒充成员之外的所述组的成员分发与所述被冒充成员相关的对称密钥的不同版本;以 及接收下一数据分组和用于所述下一数据分组的代码,所述代码 已经在所述欺诈成员处使用与所述被冒充成员相关的一个对称密钥 版本生成,使得能基于所述对称密钥版本来识别所述欺诈成员。
- 16根据权利要求15所述的方法还包括: 接收数据分组;以及确定所述收到的数据分组是否已经从操作为欺诈成员的所述组 成员多播,其中通知网络实体包括当以及响应于确定所述接收到的数据分 组是从所述欺诈成员多播时,通知网络实体。
- 17根据权利要求16所述的方法,其中接收数据分组包括接收 包括所述数据分组、用于所述数据分组的代码以及成员标识符的内 容分组,以及其中确定所述收到的数据分组是否已经从欺诈成员多 播包括:对所述内容分组中的所述成员标识符和与接收所述内容分组的 成员相关的成员标识符进行比4交;以及当所述比较识别出所述内容分组中的所述成员标识符和与接收 所述内容分组的成员相关的所述成员标识符相匹配时,确定所述收 到的数据分组已经从欺诈成员多播。
- 18根据权利要求15所述的方法,还包括:基于用于产生所述下 一 数据分组的所述代码的所述对称密钥版 本来识别所述欺诈成员。
- 19根据权利要求18所述的方法,还包括:将所述欺诈成员的身份通知所述网络实体,使得所述网络实体 能随后从所述多播组排除所述欺诈成员。
- 20根据权利要求18所述的方法,还包括:接收与所述被冒充成员相关的对称密钥的所有不同版本,从而 有助于所述客户端识别所述欺诈成员。
- 21根据权利要求15所述的方法,还包括:从操作为源成员的所述组成员接收数据分组和用于所迷数据分 组的代码,所述代码已经在所述源成员处使用与所述源成员相关的 对称密钥生成,确定所述收到的数据分组是否已经从操作为欺诈成员的所述组 成员多播,当所述收到的数据分组已经从欺诈成员多播时,向所述多播组 成员多播二次呼叫分组;以及基于与所述数据分组相关的所述代码i人i正所述源成员;以及,基于与所述数据分组相关的所述代码来认证所述源成员,其中通知网络实体包括当以及响应于确定所述收到的数据分组已经从所述欺诈成员多播时通知网络实体。
- 22—种用于在包括多个成员的多播组中识别欺诈成员的计算 机程序产品,其中所述计算机程序产品适于被包含在所述组的至少 一个成员中,以及其中所述计算机程序产品包括其中存储有计算机 可读程序代码部分的至少一个计算机可读存储介质,所述计算机可 读程序代码部分包括:第 一可执行部分,用于将操作为声称所述组的另 一成员身份的 欺诈成员的组成员通知给网络实体,该另一个成员是被冒充成员, 其中所述第一可执行部分适于通知所述网络实体,使得所述网络实 体能向至少除所述被冒充成员之外的所述组的成员分发与所述被冒充成员相关的对称密钥的不同版本;以及第二可执行部分,用于接收下一数据分组和用于所述下一数据 分组的代码,所述代码已经在所述欺诈成员处使用与所述被冒充成 员相关的对称密钥版本生成,使得能基于所述对称密钥版本识另所 述欺诈成员。
- 23根据权利要求22所述的计算机程序产品,还包括: 第三可执行部分,用于接收数据分组;以及第四可执行部分,用于确定所述接收到的数据分组是否已经从 操作为欺诈成员的所述组成员多播,其中所述第 一 可执行部分适于当以及响应于所述第四可才丸行部 分确定所述接收到的数据分组已经从所述欺诈成员多播时通知所述 网络实体。
- 24根据权利要求23所述的计算机程序产品,其中所述第三可 执行部分适于接收包括所述数据分组、用于所述数据分组的代码以 及成员标识符的内容分组,以及其中所述第四可执行部分适于对所 述内容分组中的所述成员标识符和与接收所述内容分组的成员相关 的成员标识符进行比较,以及当所述比较识别出所述内容分组中的符相匹配时,确定所述收到的数据分组以及从欺诈成员多播。
- 25根据权利要求22所述的计算机程序产品,还包括: 第三可执行部分,基于用于产生所述下一数据分组的所述代码的所述对称密钥版本来识别所述欺诈成员。
- 26根据权利要求25所述的计算机程序产品,还包括:第四可执行部分,将所述欺诈成员的身份通知所述网络实体, 使得所述网络实体能随后从所述多播组排除所述欺诈成员。
- 27根据权利要求25所述的计算机程序产品,还包括:第四可执行部分,接收与所述被冒充成员相关的对称密钥的所 有不同版本,从而有助于所述第三可执行部分识别所述欺诈成员。
- 28根据权利要求22所述的计算机程序产品,还包括: 第三可执行部分,从操作为源成员的所述组成员接收数据分组 和用于所述数据分组的代码,所述代码已经在所述源成员处使用与 所述源成员相关的对称密钥生成;第四可执行部分,确定所述接收的数据分组是否已经从操作为 欺诈成员的所述组成员多播,第五可执行部分,当所述接收到的数据分组已经从欺诈成员多 播时,向所述多播组成员多播二次呼叫分组,以及基于与所述数据 分组相关的所述代码认证所述源成员,其中当以及响应于所述第四可4丸行部分确定所述接收的数据分 组已经从所述欺诈成员多播,所述第一可执行部分适于通知所述网 络实体。
Independent claims28
12 paragraphs, as filed
Multicast of the group to cheat member system, method and computer program product
technical field
The invention relates to a to provide playing safety system and method clamped, and more particularly, the radio is a safety providing a data pool the authentication system and method. Wherein the background technology the multimedia streaming transmission are capable of the following television application of male knowledge to the video on - demand and according to watching the number of the secondary pay or the video broadcasting, therefore which is considered of the main display and handle. The; the gateway vertical providing Internet protocol to broadcasting service, the service of substrates to transfer terminal and a service. By a service, wireless system is a wireless terminal broadcast data packet. The wireless terminal receiving and processing the same packet stream. Multicast service one of a audio and video format, and entertainment embodiments IP for information broadcasting streaming transmission. The other service length; multiple power to the wireless terminal broadcast data packet. The device for service's invention is multi-side the multimedia conference, thereby during conference session, multiple wireless terminal to each other multicast data packet. A understand for playing corresponding to typically is higher than the frequency modest efficiency of unicast communication, wherein playing communication service to a group of wireless terminal to broadcast. Wherein the spectral for wireless service is limited, and expanding is very expensive, therefore using multicast service with a attraction to the wireless service provider clamped. Multicast communication circuit use capacity, such section of a communication also added. Generally, playing with multiple goals section, a invention includes: The protection in aggregate for playing group playing communication clamped (i.e. encryption), a protecting alarm, and methods for playing automatic exchanging and method of set of elastic material. In addition, playing safety usually machine to play of the group playing corresponding to deploy one or more safety policies. Usually is a protection playing group clamped playing communication, playing safety is hope typically providing data pool authentication. A understand in a condition of point to point communication, usually automatic authentication data pool. The condition according with an point to point communication symmetrical key, protection
Wherein the single active and destination with symmetrical key for content of a and/or authentication transmission request. Comparatively, multiple conventional multicast the safety of broadcasting, the member of group of group member is composed of symmetrical key. The case, a data pool and without is externally typically to play group of member, it are the specific group member. Multicast in the corresponding to authenticate data pool in the technical substrate-processing from the supply multicast data each group of member is set of network with the digital signature. The digital signature claims above the data pool authentication and protecting alarm it deny. , A digital signature further typically for key of encrypted, wherein realizing than the symmetrical encryption key message authentication code (MAC) obviously slowly. Digital signature is usually than the RECEIVED need more data space overhead messages. For reduced and digital signature related overhead messages, developed shared with the digital signature multiple packet the technology. The invention technology's is: Star/hash technology, and one different hash of link. The although sharing technology truly reduced with the digital signature related overhead messages; the technical further typically then the communication charging, and lower usually the source and method for destination the data buffer. Intervals; and each authenticated a requirements of a timing the efficient current consumption the tolerance (TESLA) and protocol for providing and destination the time synchronization between for forming the source, the source certification process more complicated. A technique for a developed recently a title according June 14, 2004 submitted is an System, Method and Computer Program Product for Authenticating a Data Source in Multicast End of the patented Of claim. 10/867,150 Base, wherein content through a quotation with the. To process of the developed recently, multiple destination member for playing group comprises a broadcasting supply member and method for data packet the data packets, wherein each playing member and symmetrical key of group is related; the key for playing of each other member is set to know. The operation, the source plate which is connected with the source member and symmetrical key is a data packet code generating, and multicast the data packet and coding then. Wires; and destination member to receiving data packet code and. When the destination member by the source plate is declare in corresponding destination state member (i.e. pretended is connected to the corresponding destination member state); and destination member can play group of member to play two calls to group, the source plate of the condition to play group of cheat member. Additionally, destination member cover on the authentication code supply member. ' 150 Publicize applications of radio in the corresponding to the authenticate supply technology to overcome the other an shortcomings. On the surface, and point-multipoint multicast the communication, 'the technologies of 150 applications of the destination member is authenticate the source member does not set between the digital signature or the source and destination the synchronous. And the technical field to provide understand easily is generally the expectation further comprises (' technologies of applications 150) is covered on the existing technology. The invention content the lower an of the background, the embodiment of this invention claims a broadcast data packet and authentication data packet supply further improvement system, method and computer program product clamped. The embodiment of this invention, the playing of the group; the destination member is capable of ' to the technologies of 150 applications the authenticate supply member for playing communication. Additionally, wherein the embodiment of this invention, the playing of the corresponding to declare the cheat part of the pretended is group member state hood is externally. Through the recognition cheat member, wherein the cheats member be isolation or playing from the group to remove, to prevent the cheated the member is casing to pretend is more than a broadcasting group member state. To the diaphragm surface, claims a to play the set of broadcast data packet the system. The system comprises: The network entity, a group of the key/server, and said multiple playing of member set. At least part of the inform member of network entity group is installed to declare the other group member state the cheat member, the other pretended member is a. The response is informed, network entity to at least an is pretended is member the member is of set is arranged on pretends is the member and keys are different versions. Additionally, network entity is arranged as is pretended is the member is arranged on pretended is the related member are key full different versions. The network entity symmetrically distributed key collection, cheats the member the member is connected to the network entity receiving notice second data packet code and a second data packets, wherein the code in the cheats the member is made of the pretends is a related member are key generation thereof. A to playing different member of group arranged above the keys are different versions, a base on the symmetrical key an identification cheat member, for example and/or is the network entity a members group of. Connector
The network entity capable of the identification the cheated the member in the cheat member of broadcast in set to be removed clamped. More particularly, wherein cheat member to inform to the network entity member arranged on the data to set and determine data packet is received a to cheat member group member playing from the operation clamped. For example, a corresponding part of receiving a data packet and content of grouping code and a identifier for data packet. The corresponding member and is connected in content packet the identifier member and a receiving content packet the member and a identifier of compares to determine data packet is received from wherein the cheating member playing clamped. The case; and compares is sleeved in content packet the identifier member and a member and member identifier for receiving content distribution packets, and corresponding member can determine of data packet for receiving and cheating the member playing clamped. How no matter the corresponding part by a data packet is received from cheating the member playing clamped, a corresponding part of respond then in such and informs the network entity. The invention, the other side, one or more member can authenticate the other member group of. The case, playing at least a group of operation setting for destination part of the operation receiving data packet code and source plate and a group of for data packets, the code in the source plate is made source and related member are key generation. The destination member which can determine data packet is received a to cheat member group member playing from the operation clamped. Data packets in a received from cheating the member playing clamped; and destination member can play group of member to play secondary to call (memory) packet. Additionally, destination member a base and a data packet and authentication code supply member. , A data packet for determining a front cheating member of radio time and in response, a destination member is further cheat existence of member to the network entity informing. To the aspects of the invention, providing playing group of member method, and computer program product. Therefore the embodiment of this invention claims a radio is a set of broadcasting data to set and a cheat member improved system, group member method, and computer program product clamped clamped. Is similar to groove (150 ' publicize applications, the member for playing group of member is in based on service data packet and generating code for authenticating a source member and symmetrical key multicast data packet. Is similar to the groove (150 ' publicize applications, wherein the part of cheating the plate receiving data packets, the member can is further configured to playing group multiple playing of two calls, packet data packet is known and delivers excellent member oneself, wherein multiple member is not and data packet to group. , And according to the embodiment of this invention, one or more of member is sleeved with the cheat member, so cheat to the member be removed hereafter is radio of the group. Therefore, the diaphragm the example's system, group member method, and computer program product solved the problem of the existing technology has a pointed and provided with the extra coefficients. The brief description for drawings where the invention claims a universal sense, now is fixed to the auxiliary shape, the gasket digital no need to be of the ratio: Digital 1 profiting the invention embodiment a terminal and system, diagram Digital 2 to embodiment of this invention can use of the terminal, the original server, a user processor and/or group controller/key unit entity hint, diagram Digital 3 to the invention embodiment a hint diagram of terminal; Digital 4 to one embodiment of this invention is playing group member is arranged symmetrically same group controller/key function unit; diagramImage 5a according to one embodiment of this invention is playing supply member function of diagram group of destination members and content, packetImage 5b according to one embodiment of this invention on condition according to the position 5a fixing schematic drawing of; multi-broadcastingImage 6a according to one embodiment of this invention, bullies blesses the member to play content packet to the destination member, and a response from the cheating member for content packets in a destination member; the destination member is playing other member of set of broadcasting function diagram of two calls group clamped clamped; Image 6b according to one embodiment of this invention displaying the two calls of the condition to position 6a set as the positive schematic of; multi-broadcastingDigital 7 to one embodiment of this invention, responded is informed the cheat member, group controller key/server to provide functional keys is diagram the member of group; aImage 8a according to one embodiment of this invention, the shown the digital 7 GCKS is connected to a group of member and key, a position 6a cheat member to the destination member playing while
Content packets, a to cheat member function based diagram on content, packetImage 8b according to one embodiment of this invention on condition according to the position 8a fixing schematic drawing of; multi-broadcastingDigital 9 to one embodiment of this invention, GCKS to group member is externally cheat member a key function diagram once; multipleAnd digital 10 and image lla- image llf according to one embodiment of this invention, comprising a radio the set of authenticate the source plate and a to cheat member method for current charts of each step of the group. The lower detailed description of illustrated embodiments is fixed to the digital attached to explain the invention comprehensively, of the invention The embodiment preferred. Further, the invention can or more of different form of a transversely symmetrically distributed understood for embodiment is restricted claims here; On the top, providing the embodiments to make the base is integrated and alarm, and a sending the invention to the technical field comprehensively provide the range. The invention claims a same number unit the same element. See the digital 1, wherein a fixed with profited from the invention the position of the system. A combined comprising a mobile communication equipment the Ming dynasty printed books invention embodiment system, method and computer program product. Further, the understand the invention the embodiment system, method and computer program product and mobile communication industry of mobile communication industry of with an or more of application combined for. For example, wherein for example's system, method and computer program product with a wire and/or a wireless network (. e.g) and application with a. The fixing position, the may include a terminal 10, terminal capable IO with the base station or the base station BS (14) command signal and from the BS 14 received antenna signal 12. The base station is one or more cellular or mobile network a part; each network comprises a device for operation network, need for of mobile switching centre 16. And the technical field of the further ^^ knowledge, mobile network is capable of called base station /MSC/ interactive function (BMI). The operation, wherein the terminal in carrier) and receiving call, an MSC from the routing terminal calling or calling is a terminal. When the terminal participates the call, an MSC also provides the connection of the electric wire framework. In addition, an MSC control message to retransmit and retransmit the terminal of the terminal, and a control message to retransmit from the terminal comprises a message centre and retransmits the terminal from a message centre, and communicates of the SMS body (SMSC 18) short message service () sending information. MSC16 of the coupled to the data network, for of the local area network, metropolitan area network and/or Wide area network . MSC of the conductive coupled to the data network. The, wherein a typical embodiment, an MSC is coupled with GTW20, and GTW is coupled with WAN, to 22 Internet. , Then for example processing unit (device. e.g, personal computer server and computer equal) can via a network coupled to the terminal 10. For example, is as follows, processing unit comprises with one or more original server 23, user processor 24, group controller key/server 25 equal and one or more processing unit, and each shown the digital 1 and invention as follows. BS14 of the is coupled to a signal GPRS (general packet radio service) support node SGSN (26). And the technical field of the provide male knowledge, SGSN of the frame and MSC16 typically for packet - switched service function same. Similar to MSC SGSN, a coupled to the data network, to 22 Internet. SGSN of the conductive connecting inclined to the data network. The, wherein a typical one embodiment, SGSN coupled to packet-switched network core, the GPRS network core 28. Packet-switched network core and coupled to the GTW, a invention GTWGPRS support node GGSN (30), and GGSN coupled to the Internet. An outer GGSN, a packet-switched network core of the is coupled to GTW20. GGSN of the is coupled to a messaging centre, for of the multimedia messaging service (MMS) centre 32. On, an MSC have type, GGSN and SGSN a control message forwarding, a invention claims AN information. GGSN and SGSN and control information to retransmit from the terminal is a messaging centre and retransmit the terminal from a messaging centre. By SGSN 24 couplings to the core network and 26, GGSN28 for of the service provider 22 device of via Internet 20, SGSN and GGSN couplings to the terminal 10. On, a of the service provider's device capable of connecting SGSN GPRS, and GGSN and communication terminal. The region; the SGSN26 coupled to the core network and 28, GGSN30 for of the original server, 23 and 24 processors and/or the GCKS25 device of via Internet 22, SGSN and GGSN couplings to the terminal 10. On, a of the original server, a user processor and/or the GCKS device capable of connecting SGSN and GPRS
Corresponding to GGSN and terminal. Is directly or connected (e.g. original server, user processor equal) connected with the output end and device, and other end and device of columns are, for example according to any broadcastings multimedia broadcast services (MBMS) clamped playing communication. Of MBMS multiple information, see - third generation partnership project (3GPP) process standard 3GPP TS 22.146, wherein the title is a Multimedia Broadcast Multicast Service (MBMS'), wherein merges content by a quotation the. Although here is not shown and explains each possibility each set of network, further understand the IO terminal is in a connecting is any one or more to multiple different networks. On, mobile network shaft hood according to multiple kinds of the generator (of 1G), and generator (2G), 2.5G and/or a third generation (3G) mobile communication protocol equal to or with multiple member housing. The joint or capable of replacing seat, mobile network is connected to act according to any one or more supporting communication between different digital broadcast network, for example (DVB- the running) and/or DVB-H (DVB- hand-held) and a digital video playing (DVB) network and said isdb-t comprising a DVB-T (ISDB- the running) and composite service digital broadcast (ISDB) network. More particularly, for example, IO terminal capable coupled to act according to 2G wireless communication protocol IS-136 (TDMA), AND and one or more network is-95 (CDMA) support communication. Additionally, for example, one or more network to act according to 2.5G wireless communication protocol GPRS and an data AND environment and supporting housing. In addition, for example, one or more network to act according to the 3G wireless communication protocol, a of the universal mobile telephone system and network communication with wideband code division multiple access (WCDMA) wireless access technology. Fractional narrowband AMPS (NAMPS) and a TACS network is further profit from the embodiment of this invention, the dual mode or multi-mode the telephone is further provided with (e.g., digital analogue/or TDMA/CDMA/simulation telephone). The terminal capable 10) for connecting with one or more of wireless access point (AP 34). AND a i 殳 jacket for switches such as for example radiofrequency and Bluetooth and an infrared (IrDA) technique or comprising a WLAN technique or more of different wireless internet of things technology to a corresponding to a terminal. AP34 of the coupling to 22 Internet. To a MSC16- type, AND capable conductive coupled to the Internet. , Further in one embodiment, AND via the GTW20 indirectly coupled to the Internet. Capable of understand is directly or indirectly the terminal and original server
23rd, User processor 24, GCKS25 and/or the other device are connected in Internet, a terminal capable are corresponding, a user communication processor; therefore realizing and a functions of terminal, to the data transmission and content wait till the user processor, and/or a user processor and content data, equal. In a quarter using, terminology of the data and content” and information and a same terminology of AC using to indicate for automatically according to the invention embodiment is transmitted, a data of receiving and/or memory. Therefore, the made of any and a terminology is not be regarded as and range of the limit to the invention the spirit. Digital although 1 is not shown, further connected in terminal IO solution for or a polymeric the Internet 22 couplings to a user processor 24, wherein the terminal and user processor of the mutual connecting shaft and according to for example RF, and BT IrDA or an LAN and/or WLAN technology to a different wired or wireless communication technique for on the communication. The joint or capable of replacing base; one or more user processor is connected to a energy-accumulating the content storage removable memory, the content can be transmitted the terminal then. Now reference diagram 2, pores with air according to the invention embodiment of part of the terminal 10, original server, 23 and 24 processors and/or the GCKS entity diagram. Although display is a entity, further in some embodiments, one or more provided with supporting the terminal, the original server and/or a user processor one or more, logically independent, and which is arranged on the entity. For example, single entity capable of supporting logically the independent, a terminal and server original located at the same. Further for example, single entity capable of supporting logically the independent, a terminal and user processor located at the same. The fixing position, which is a IO terminal and server original 23, user 24 processors and/or the GCKS25 entity and a connecting the memory 39 processors generally 37. The processor is TCP/IP connected at least 41 interface or other are used for transmitting and/or receiving the data, a content for device. Memory may include a volatilizing and/or a nonvolatile memory, and typically layer, content data. For example, a memory storing typically from the entity and transmission/or a content for entity is received. Further for example, according to the invention embodiment, wherein the memory unit the soft to apply, the typically equal, and systems operation and processor for operating. For example, when the entity comprising GCKS, a memory can save energy for entity broadcast group the key management device of each other member and symmetrical keys' multiple. The, when entity used as entity playing group of member, a memory can save of the symmetrical key according GCKS providing. In addition, the memory can save playing is a common keys are set of. Moreover, the memory can save and corresponding entity related public key/private key is the. Now reference diagram 3, wherein a are to profit from the invention embodiment of type 10 terminal. Further, the understand, pores terminal according and lower invention is profiting the invention embodiment a terminal of; and is not considered of the illuminating to 50-160v of the invention, the types' terminal, to the portable pdas (PDA), beepers, the laptop computer and types' electronic system, and easy using the invention. The fixing position, except for antenna 12, terminal capable IO 40 and 42 controller or other signal transmitter and a receiver received signal processor to the sending a transmitter 38, receivers are. The signals is suitable for honeycomb system containing standard connector signalling message comprising a base, collection module and user voice and/or a user with. On, a terminal and uses a or a space connector standard, communication protocol and modulation type and access type and operation. More particularly, the terminal shaft hood according to multiple kinds of the generator (of 1G), and generator (2G), and 2.5G/or a third generation (3G) communication protocol equal to the device for operation. For example, a terminal and realizes the operation according to 2G wireless communication protocol IS-136 (TDMA), and GSM IS-95 (CDMA). Further for example, a terminal can be tightly equal end of the operation according to 2.5G wireless communication protocol GPRS and an data AND environment. For example, a terminal shaft hood according to use wideband code division multiple access (WCDMA) wireless access technology universal mobile telephone system and (UMTS) 3G wireless communication protocol and operation. Fractional narrowband AMPS (NAMPS) and a TACS mobile terminal capable further profit from a method of this invention, the dual mode or the multimode multimedia telephone further yes (e.g., digital analogue/or TDMA/CDMA/simulation telephone). A understand with the controller (42) is dynamically switching circuit according with the 10 audio frequencies and logical functions circuit. For example, wherein the controller is connected to the processor device and detecting device, and each ADCs, a digital-to-analog converters and supporting circuit. Terminal and control signal processing shaft function according to the width power to the methods and apparatus. The controller is a comprises a sound encoder (VC) 42a, and may include a data modem42b. Moreover, the controller comprises an operating one or more software device function, and program of latching a memory (a) emitter. For example, wherein the controller is a connective program, the normal Web browser. The connective program and capable of the terminal to transmitting and receiving the content Network, for example according to HTTP and/or wireless application protocol. Terminal IO - comprising user interface, the user interface on a rare earphone speaker or 44, 46 of the microphone, 48, 50 monitoring and user interface, which are coupled to the controller 42. Allows the terminal receiving user data input interface is connected with multiple licence the terminal receiving data to a device, to a keyboard 52, a monitoring (is not shown) or the input devices. The comprising a keyboard embodiment, a keyboard comprises in digital (0-9) and related key (#, *) and for operating other keys of terminal. Although is not shown, terminal and may include a battery; and vibration battery, a power supply is the circuit for operation terminal need, and a line providing a mechanical vibrations used is in the output of the detection. The terminal capable 10 further comprises for obtaining and/or the data one or more device. For example, a terminal comprises a short distance radiofrequency transceiver or the interrogator-responder 54, wherein according to the RF technology, the data can be shared and/or obtaining from electronic device. The joint or a line, a terminal capable comprises the short distance transceiver, such as for of the infrared transceiver 56, and/or is a Bluetooth brand wireless technology operation Bluetooth transceiver of the Bluetooth special interest (58 develops. Therefore, the joint or a line, according to the technologies, a terminal and electronic data transmission and/or an electronic receiving data. Although is not shown; the head or a line, according to different wireless internet of things technology, comprising a of the IEEE802.il technology's WLAN technology, a terminal and electronic data transmission and/or an electronic receiving data. IO terminal capable further comprises a memory, a of user distinguishing module SIM (60), removable user distinguishing module (R-UIM), wherein the memory and mobile user related information element. Solution for SIM, a terminal capable comprises an removable and/or the fixing memory. On the; the terminal of the volatile memory 62, is of a cache area volatilizing random access memory is interim data. The terminal can further comprises an nonvolatile storages 64, wherein can be inserted and/or removable. The joint or a line, a nonvolatile memory may include, EEPROM memory. Memory can save of multiple software of terminal is applied, any two indicating, the information section and data, is realized by function. For example, a memory can save the identifier, a of the international mobile device comprises a (IMEI code) and international mobile user to the RF (IMSI code) and mobile station composite service network digital combining information (MSISDN) code (mobile phone number), the Internet protocol address and Session starting Protocol address equal, which uniquely mark the terminal, for example in aggregate of MSC16. And the background part of the recently a developed for authenticating broadcasting process of group member is June 14, 2004 voltage of the connecting title is an System, Method and Computer Program Product for Authenticating a Data Source in Multicast End of the patented claim No.l0/867,150 is respectively. The thunder, the source plate of broadcast data packet is energy source and related member key are allocated with a code for data, and multicast the data packet and coding then. The receiving data packet and coding, a destination member of broadcasting group of cheat member based on authentication code source or member for determining supply member. To additionally background part of the although ' the technologies of 150 overcame applications has been radio in the corresponding to the authenticate data pool clamped in the technical shortcoming, further hopes usually is further improved the existing technology. Now reference diagram 4 to charts 11, wherein more particularly of the embodiment of this invention. As follows, 7 and 9 is in the shape of 4, for example, GCKS25 can use the key management unit 68) comprises N members and group of members arranged above the symmetrical key, a part of 1 70a and a i70b and a j 70c and a n70d. The briefly as follows, and member each group is connected with the broadcasting each other member known symmetrical key K of group is related. The key management unit for playing group of members arranged above the symmetrical key in one or multiple probable of situations, is of a square or irregular gap, possibly phase from a condition to the lower condition with one or more member and buttons are. Further to the edge position; 5a 6a and 8a, and playing group of source member (72) comprises one or more data packet one or more contents to group (CP 73) (see further and image 5b and 8b), transmitting multicast or transmitting broadcast multiple destination member of group (74) are of destination member 74a, 74b and 74c). The source plate and ride of application, a of the source client 76, wherein a coming from the memory source (e.g., memory 39) and a data memory 78 one or more data packet to broadcasting destination member. And then each destination member can use the destination client 80, wherein the client and receiving the information source authentication part of the content groups and based on content packet. For and source plate is authenticated; and destination agent can save data packets in a corresponding destination member and content storage 82. A lower invention claims a detail according to the embodiment of this invention, the destination member 74 clients destination 80 and authenticate the source plate (72) is allocated to the digital signature or; the part between multi-spots multicast the communication the source and destination synchronization. In turn to licence the source plate multicast data packet to destination member, and is supply part of the destination member can authenticate data packets, the source member supply client 7 and 6 based on device 73 and source plate and are key generation content; the content packet a data packet. More particularly, the source client and a content packets, the content packet comprises a code of data packet and supply state member and a source and related member are with key. And maintain the circuit, the source client and a wherein symmetrical key or group are key enciphered data packet and/or supply member OF. A destination member 74 clients destination 80 and with the source member and symmetrical key to the authenticate member source based on content 72 packet. More particularly, the destination client and a decryption and authentication code of the source member are key authentication supply member. Adhesive; each supply state member is authenticated; and client destination of the once which is used for enciphered data packet) deciphering data packet by supply are key or group are key, and data packet is then transfers a storing the data memory 82. By using source and related member are key, and authentication member source based on which are key, the invention relates example's destination client and authenticate and playing an external communication source and member. And a understand, wherein playing member each group to know of the group the symmetrical keys of each other members', the cheat part of the group of the group the symmetrical key and state of other member multicast data packets, therefore pretends is or declares the other units member state. Thus, a group of operation member is a cheat member, playing member each group of relate to arranged, and receiving part is a known from which a data packet in the multiple member is not broadcast data packet to the group (supposition, a of the member is wherein multi-broadcasting of knowledge data packet or no wherein receiving data packet of multi-broadcasting), a playing group multiple playing of two calls to a group RP (83), image to 6a cooling. Adhesive; at pretending is the plate receiving content packet the destination member 74 clients destination 80) is connected to the two call and packet/of the two call packet by content packet is received from no emitted out from the content group connection member in fact. Then front destination client treatment, content packet is received, is similar to a supply for playing the content (packet. i.e, group member according pretends is) (iU layer is an anode. In turn to perform a damage identification pretended is or declared of the group the cheat part of the member status's, responded the receiving is a known from which data packets, the pretended is destination member 74 clients destination 80 is further provided and set of exist to cheat the member to inform is electrically connected with GCKS25. , And responded in the receiving notice, a front of the same; the key management unit 68 to broadcasting group member arranged above the symmetrical key. , A front of the automatic with a key distribution, the key management unit to an is pretended is the member group member is arranged between the pretend is the member and keys are different versions, and shown the digital 7. , Namely key management unit to an is pretended is the member each group member is arranged between the pretend is the member and keys are different versions. , And the cheating the playing member is a known of a pretended is a content of member is set and 73 second condition; the destination member is not possibly connected to the authenticate cheat member, wherein for producing the content packet pretended is member are key thereof is different from pretends is member are key pole of the group of other member know, image to 8a cooling. And wherein each member receiving the keys are different versions, therefore a based on is used to generate the content packet the symmetrical key thereof is sleeved to the cheat member. The capable of broadcasting is set to be removed of externally cheat member, a through the invention claims a key is a group member the once, and removes the cheat member, so cheat to the member and longer with the group of the members' symmetrical relative keys, or the symmetrical key, knowledge and shown the digital 9. In a quarter fixing and describes, the key management unit 68, clients supply 76 and client destination 80) are respectively comprise a software according GCKS25 source and member 72 and destination member is 74. And the understand, wherein there is deviate the invention the lower spirit and range, the key management unit, the source client and/or a destination in a line is connected to the firmware or hardware. Moreover, although the key management unit, a client and destination client and fixing description is respectively arranged GCKS and source plate and destination member the local, the key management unit, a client and destination client any one or more of the line from GCKS source, and destination distributing with corresponding, a bridged of the Internet 22. In a quarter fixing and describes, the content and packet data information, equal between GCKS and source member and/or destination transmission member or transmission. And the understand according terminology the transmission rod and playing " and transmission clamped with the AC using here, and no deviate the invention the lower spirit and range, a transmission, and multicast transmission data packet clamped may include for example from the source member to the destination mobile member or a duplication content. Now more than 72, wherein broadcast or a sending one or more data to the destination member 74 transmission the light of the source plate is set to the invention embodiment system, method and computer program product the detail. In a quarter the according to or more of different broadcasting communication rope, the source and destination member playing group of member, and each comprising an upper end and a or/receiving data packets, a content of random entity (e.g., 10 terminal, server original 23, user processor, 24) GCKS25. Multicast of the group; according to the embodiment of this invention, the source of member comprises is connected to a random group member are multiple destination members and one or more data packet. On the other side, according to the embodiment of this invention, the destination member comprises an is connected to the data packet from the source plate, and authentication supply member then random group member. Is a understand, although time filler the operation of different groove; and entity; the different time operable as GCKS and source plate, a destination member or GCKS, the source plate and destination member one or more. Now reference diagram IO and image lla- llf current position, wherein the light of digital 4-9 a explain according to the automatically according to the invention one embodiment, and playing a set of authenticate the source plate and a to cheat member each of the method in the group. Digital 4 and digital 10 and 84 are, the method may comprise GCKS 25, or more particularly, comprising a GCKS25 key management unit 68, through which the symmetrical key collecting to receive to play group member 70a-70d to each member providing key, a cover part and a key and a wherein the corresponding data memory (82) see image 5a). May include a key are collecting of each member is received with the corresponding member and symmetrical key, with the group of each other member and symmetrical keys, as to is group member 1 70a and a i70b and a j 70c and a n70d key Kq, Kj, Kj and Kn are. In addition, although is not shown; the symmetrical key collecting can also comprises broadcasting group are key according member each group of knows, a group of current capacity encryption key (GTEK). The GCKS25 key management unit 68 is in any one or more according to the different manner of the symmetrical key and distributes the symmetrical key to play group member 70a-70d. For example, key management unit capable of generating symmetrical key from the same or different key supply material, which comprises a broadcasting identifier or a group of each member. And the key are separately sending playing group; each according to the technical field male further Diffie-Hellman knowledge key are protocol. A on pointed out of the GCKS 25 key management unit (68) is arranged as broadcast group of member 70a-70d providing key one or more situations, wherein the according to one or more rectangular or irregular gaps, or according to the circuit. Although the key management unit can makes the same via providing key and member each condition; however, wherein one distributed key centralized one or more symmetrical key in the ACK/NAK distributed be different from the corresponding key in the ACK/NAK distributed. Therefore, wherein one or more switches in the form of different condition distributed, the invention relates example's key management unit is a are the key or distributed the same key to provide a better safety each condition than a key management unit in single situation. In addition, a pressing gap of the keys, the key management unit is a device for increasing and reduction of group member. To play group member 70a-70d providing key or in one ACK/NAK the key, a supply member 72 clients source (76 e.g member. i70b) and is started to send one or more content fragments to; 5a position and shape 10 and 86 are. The starting supply client 78, the source is in form of the content format one or more data packet. For example, client supply capable of changing into the content format the Ethernet frame and Internet protocol packets, section of the data an equal. A source, a client, it has no need enciphered data packets, a block are 88. The source plate of shaft according to or more of different a random a enciphered data packet. For example, in one embodiment, the source in a shaft according to playing sealing safety load (MESP) process enciphered data packet. On, according to one embodiment, the source of client for playing each known group are key of group (e.g. GTEK,) enciphered data packet. The enciphered data packets, the source member 72 clients source (76 e.g member. i70b) for increasing for data packet of encrypted or is connected to an and other member of set is sleeved to the source member identifier, a block are 90. On, playing member each of 70a-70d group is connected with a storage to respectively connected to a relative to the different identifier to the other member group of. For example, when playing member comprises a mobile terminal
10:00, The member identifier may include a IMEI code, the IMSI code, a MSISDN decoding and IP address, an SIP address. A identifier is no consider and enciphered data packets, connected source member 76 clients source (76). e.g, a i70b) and then packet and code a source member and symmetrical key of can be connected; each block are 92. And the pointed device for playing member each of 70a-70d group is connected with the broadcasting to each other member known symmetrical keys of set and related. Therefore the destination member and authentication supply member then based on code and a supply member and symmetrical key. Source is a 72 clients source (76). e.g, a i70b) is code for producing a comprises multiple different any codes. The typical one embodiment, a code of a message authentication code (MAC) . Of MAC comprising a cryptographic the sum of connection packet for example using supply member are with key. A line, a of MAC of a connection packet a cryptographic the sum of hash using supply member are with key. The case, although is not shown, packet of the capable of generating MAC a hash, so MAC is smaller than of MAC packets of hash connected with an state. The, which is consider how the source client generating MAC, a client supply capable to the source plate then playing multiple destination member group of more than 74 to broadcasting content to 73), a block are 94. Is a packet is RECEIVED of connecting a content packet of source member of broadcasting (is supply member are key generation). In turn to explain content packet for example, see the position 5b (Ki to generate MAC group member i are keys is supply member is behalf of operation). Now reference diagram lla-llf, providing a authentication to a supply members and multiple destination member 74 playing group multiple broadcast data packet the source member 72 method, is a radio is in set is sleeved to cheat method for member. The fixing position, the method for 73) destination member comprises a receiving content; the content 73 paths comprises packet is RECEIVED of, packet of the connecting a data packet and source of member identifier encryption, image to 11a block are 96. Then; each destination member, or more particularly, each destination client of each destination member 80 a based on supply member identifier determine whether content packet columns from pretends is or declares the corresponding destination member state cheat member. More particularly, the destination client and determine in content packet the source plate contains identifier and corresponding destination member
(Which is not leads for transmitting packet supply member) destination member identifier matching, a block are 98. In turn to explain, a group of member j 70c pretends is group member i70b state cheat member, group member j operation of the source plate, 72 to points as 6a. The case, group member j supply client 76 with a content to 73), image to 5b pores; the content 73 paths comprises: Packet of, packet connected with a data packet of encrypted; With a i member; identifiersAnd use with MAC for plate i and symmetrical keys (i.e. Ki) is generated. A group member j to playing group of destination member more than 74 to play content packets, the playing group comprises group member 1 70a and group member i70b and group member n 70d. The receiving content packets, destination member 74a and 74b (. i.e, group member l and group member n) is destination client 80 determining in content packet the source plate (identifier. i.e, plate i identifiers) connected with a matching methods of member identifiers. On the other side, destination member (74c. i.e, group member i) destination the client truly in content packet the source plate identifier with a second member identifier matching, indicated according cheats the member to pretend is a destination member 74c state. Therefore, a destination member (74). e.g, group member i70b) is destination client 80 are the source plate identifier and corresponding destination member the matching between identifiers member; and client destination cover with multiple and 4 calls two groups RP (83) to inform to play the other member of group (e.g., group member 1 70a and group member j and group member n70d) supply member 72 cheats the member, a corresponding destination member does not know for at the time cheats member, working position to llb block are 112. The other testing, destination, client cover with two calls is set to inform to play a group of a content packet the member identifier and transmitting packet content supply member is non-correlated, and a playing destination member are two calls set and related. Two calls group is in comprises multiple different information fragments are, such as for example to play other group member (e.g., group member 1 70a and group member j and group member n70d) informing. In turn to respond groups of 73 to reduce the destination member 74 to successes broadcasting according possibility from the contents of source member 72 correcting transmission two calls group; the corresponding destination member destination client 80) is filled on the digital signature to two calls, a invention uses and destination member related joint/private key of private key, a to 112 are. On, playing member each group of is further connected with male/private key is related, wherein the common key to play other member and GCKS group is clamped knows. A groups of the digital signature to two calls see, and image 6b. The groups the digital signature the two calls, corresponding destination member (74). e.g, group member i70b) is destination client of 80 to play group multiple broadcasting two calls digital signature to group; the playing group comprises an destination member (74). e.g, group member 170a and group member n70d) and initial playing content to group 73 supply member (72). e.g, group member j70c) and a a destination member are two calls group), image to 6a and image lib block are 114. Additionally, client destination of inform GCKS more than 25) and a group comprises a cheat member, and is fixed playing two calls digital signature is set to GCKS. Intervals; the distinguishing supply member identifier and matched between corresponding target i is a identifiers, comprising a radio two call packet typically, a destination client and discard data packet of encrypted, wherein the destination client it authenticate the source plate, a block are 116. A destination member (74). e.g, group member 1, 70a group member n70d) is destination client 80 is not respectively supply identifier member (e.g., plate i 70b identifiers) matching with destination identifiers member; and client destination available (e.g. Ki) for generating a source member identifier symmetrical relative key compares MAC, is composed of a supply member (72). e.g, a j) 70b supply client 76 productions, comprising a content 73 groups of MAC are respectively, image to lla block are 100. More particularly, for example, a client destination is made of grouping connected with the generating MAC compare a group member and symmetrical key of the source plate identifier is marked. On, a base and source plate identifier selecting corresponding symmetrical key, a example, wherein the destination member saving in aggregate of a group member rate identifier group member are key. A line; and client of generating MAC packets of hash connected; the destination client capable of generating MAC packets of hash connection, and then generating MAC from a hash. A block are 102, wherein the compares generating MAC, destination member (74). e.g, group member 1 70a and group member n70d) is destination client 80 of comparing MAC and content groups of MAC 73 to compare. And the client destination is not externally matched; and source plate (. e.g, a j70b) is not authenticated. The case, client destination of discard packet of encrypted, and a circuit, which can inform the source plate destination to authenticate the source plate, a block are 104. On the other side, and client destination truly comprises a matching; and source plate is authenticated, and destination client can save data packets in a destination member data memory 82 interim data annular, a block are 106. The storing the data packet front interim data forming; each set, and destination client and a data packets, for example to encrypt to the data packet opposite manner and source plate (. e.g, group are key or supply member are key). Destination member (74). e.g, group member 1 70a and group member n) 70d the destination client 80 and a group the data to the data and maintaining waiting time interval to licence other destination member (e.g., a i70b) destination client determining supply member identifier and matched between corresponding destination member identifiers, and a comprises a matching, comprising a corresponding destination client's destination playing group multiple broadcasting two calls digital signature to set, and upper (see is the position lla device 98 and image lib block 112-116). And the client destination the standby for time interval is not received two calls to group, while the destination client and a data packet (, only and connected in front interim data and associated decryption), a invention is a supply member enciphered data packet opposite groove (e.g., group are key or supply member are key); and device 108 and 110 are. The destination client and a piece of data from the data packet of a destination with multiple lasting position of the data memory, block to 110 are. , And a destination member (74). e.g, group member 1 70a and group member n70d) is destination client 80 in standby for time interval truly and two calls to group; and client destination a digital signature attempt digital authentication signature-based two calls group, then to the position llc device 118 and 120 are. On the destination, client and is a playing pretended is group member are two calls group (the presentation of the source plate of two calls group) destination client and private/key of a common authentication key two calls to set. And two calls group is authenticated; and destination client and interpretation two call packet to inform, and realizes the data packet of a came from the cheating the member, and without converts the source plate of the content for 73 to symbol, discards from the destination a data memory 82 and data packet data of decryption; and device 122 and 124 are. The; and two calls group is not authenticated; and client destination a data packet is a casing to a balanced the waiting time interval (see is a position 11a block of the data forming 108); and client destination the standby for time interval is not received and authentication two calls to group, while data packet of a mobile (see block is IIO). Intervals; and informs GCKS25 to play of the group comprises a cheat member, is of a receiving GCKS the two calls digital signature groups; and GCKS can also authenticate two calls to group based on digital signature, attempt to the position lld device 126 and 128 are. Is the same as the destination client, GCKS can use and multicast is pretended is a group member are two calls group (further ends of the source plate of two calls group now) destination client and private/key of a common authentication key two calls to set. And two calls group is authenticated; and GCKS and interpretation two call packet to inform, and realizing multiple groups l comprising a cheat member, and methods for group member key condition lower side, or a authenticating the time of two call packets, providing a key or a a key management unit for group member 70a-70d plugged 68 providing key; and device 130 and 132 are. Connected to the pointed supply according to compares the key distribution, the key management unit of the group member except pretended is a distributed on the pretended is member related key are different versions, and shown the digital 7. For example, when group member pretended i is member, the key management unit is arranged with a i related keys are different versions Ku, Kij and Kin, a thereof is distributed member 1, member j member and n is. Therefore, for example destination member (74a i.e. group member 1) and receiving the symmetrical collecting key, comprising Ki (with which buttons), (Ku with the pretended is group member i related key first pole), (Kj and group member j related key) and KJ and group member and n key). , The source plate (72). i.e, cheat group member j) is connected to the symmetrical the key collecting similar, comprising K. Kij (with pretended is group member i related key j versions), (Kj and related which keys and); KnAnd destination member (74b i.e. group member n) and receiving the symmetrical collecting key, comprising & (with group member 1 related key), (Kin with pretended is group member i related key n versions), Kj and Kn. In turn to licence the pretended is member (. i.e, playing two calls to group 83) member identification cheat member; the GCKS 25 key management device of 68 to group is pretended is the member is arranged with a related which are all keys are versions key collections, and shown the digital 7. Continuous the invention, and destination member (74c i.e. group member i70b) and receiving the symmetrical collecting key, comprising Kp Ku, Kjj and Kin, (distributed to the other member, a pretended is group member i and key versions group of), Kj and Kn. A understand, by means of a pretended is group member (e.g., plate i) are different versions of related key (e.g. Ku, Kjj, and Kin) are different front group member 70a-70d the key; and at least thereof is different front group member 70a-70d key for providing, each group of a receiving and corresponding group member and are symmetrical key (e.g. Ki) is see digital 4). Connected with the other member and buttons are of group; one or a key front group member is a are different; although the keys are in the embodiment of truly different from providing key. Image 8a pores; the GCKS25 key management unit 68 to play group of member 70a-70d driving part of the key, cheats the member (e.g., front part j70c) to be, such communicating with pretending is the same group member (e.g., a i70b) state the same in multicast content to group 73 once the clamped sees (6a image 10) and. , And compared with two, wherein providing key is a group member, and code of the cheat member generating based on a pretended is related member are different key generation. On the front, a cheating content packet part of multiple a radio based on playing group member are known pretended is members' symmetrical buttons (e.g. Ki) is code for producing, wherein the invention also fixing position of 5b. , Further now of cheating content packet part of multiple a radio based on single cheats the code for member and pretended is a known pretended is member are key pole (e.g. Kij) is generated. And the presentation of cheating member of simulcasting of such content packet see, further 8b points (compares the content packet of image 5b) as. A front same; each destination part of the operation to cheat member supply member (72). e.g, a j 70c) and lower more than content of radio groups 73, image to lle block are 134. The case, content packet of multi-broadcasting and pretended is the member comprises a data packet of encrypted (e.g., a i70b) is a identifier, and use with pretended is the member and version the symmetrical key (e.g. Kij) generating MAC; the key thereof is mounted providing key is distributed for cheating the member. A front same; each destination member, or more particularly, each destination client of each destination member of 80 to determine content packet the source plate identifier with the corresponding destination member (, which is not leads for transmitting packet supply member) is destination member identifier matched; each block are 136. A for supply member 72 once in operations are cheat members, pretended is destination member (e.g., a i70b) beside destination member (74). e.g, group member 1 70a and group member n) 70d the destination client 80 is not respectively supply identifier member (e.g., plate i identifiers) and is matched destination member identifiers. Therefore, according to compares to a casing front 73 MAC. On the destination, a client and symmetrical key is used for based on supply member identifier to generate the compare MAC. , Which are the same to cheat supply member; the destination member destination client with a content packet is now marked for supply pretends member is member are key version, wherein an adhesive is a corresponding destination member and pretended is a oneself knows. Therefore which is consider for destination member 74, wherein the corresponding destination client 80) is pretends is member are key version to generate compares MAC; the thereof is different from being used to generate content packet the version of MAC. Continuous to provide keys is of a group member 70a-70d, and when group member j is cheats the members and group member i are pretended is the member; and thinks of group member j in content packet comprising a group member i and are the same j (versions i.e. Kjj) is RECEIVED generating device. On the other side, including (i.e. Kn) generating MAC compares a wiring plate i and symmetrical key first pole is a group member 1 destination client made of destination member 74a. , Including similar for destination member 74b the destination client made of group member (n i.e. Kin) generating MAC compares a wiring plate i related keys are n versions. Connected to the position 11a block as 102, wherein the generation to the industrial MAC special, destination member (74). e.g, group member 1 70a and group member n70d) is destination client 80 of comparing MAC and content groups of MAC 73 to compare. The, wherein the destination client for pretends is the symmetrical key version production of member is compare MAC; and version with for generating in content MAC packets the version are different; therefore the destination client typically distinguishing not to match. Therefore, a front same; the destination client it authenticate the source plate
(E.g., a j70b), and therefore the discards packet of encrypted, block to 104 are. A destination member (74). e.g, group member 1 70a and group member n70d) destination part of the destination client 80, relativities the voltage pretends layer is 74 ). e.g, group member i70b) is destination client and are the source plate and identifiers destination member the seal between a identifiers. Front, a client destination production of pretended is destination member and multicast two calls to group (RP 83) is clamped inform to play the other member group of clamped (e.g., group member 1 70a and group member j and group member n70d) supply member 72 cheats the member. The, wherein the box; the destination client no need to play two calls to group, wherein and, and playing other destination member of group according to authenticate the source member in operation. Otherwise, pretended is destination member destination client and are the cheat member source based on MAC 72. More particularly, pretended is destination member (e.g., a i70b) is destination client and 80 are corresponding destination member and symmetrical key (e.g., Ku, Kij or Ki). The pole, the thereof is distributed to the cheat supply member is used for generating MAC (e.g. Kij). The destination client of the cheats member based on are externally key an identification (e.g member. j70c), image to two block are 138, wherein the is connected to the cheat member and corresponding pretended is destination member receiving the symmetrical key thereof. The destination client and a any one or more according to different are respectively RF each pole of symmetrical key. For example, client destination of the ^f government official with corresponding destination member and keys are different versions different generating MAC images, respectively to compare MAC and content is a client destination 73 groups of a matched and MAC. , And one group of member is knowing receiving and pretends is destination related member which are versions key, a destination client and is sleeved to the cheat member is for generating matching said MAC symmetrical key pole group member. Which is consider pretended is destination member (e.g., a i70b) how the destination client are 80 to cheat the specifically member (e.g member. j70c), a destination client and cheating then member state informs GCKS25. The destination client capable of any according to the different respectively inform GCKS, a through of generating and informing transmitting packet
NP (85) is at GCKS, packet informing a cheating member, working position to 8a and is 140 to 11e points as. Informing a packet in random productions according to the different respectively, and a to different fragment information. In one embodiment, for informing of grouping according to be 83) similar groove productions with two calls, comprising distinguishing to cheat member informing. Is allocated with two calls similar, providing a safety according to the device for informing packet gain; the destination client a set of network with the digital signature to advising, a invention uses and corresponding destination member related joint/private key private key is. The sealing informing set to 85 signatures digital, corresponding destination member (74). e.g, a i70b) is destination client of 80 to informing packet of GCKS25 digital transmission signature, image to 8a and is 142 to 11e points as. A receiving calls two groups similar, GCKS capable of receiving of informing packet digital signature, and is based on digital authentication signature informing packets, to the position llf device 144 and 146 are. On, GCKS can use and corresponding destination member destination client and private/public key of key is authentication informing packet. And two calls group is authenticated; and GCKS and interpretation two call packet to inform, and cheats recognizes the member (e.g member. j70c), authentication providing key or a a key management unit 68 providing key is a group member, a back of cheats recognizing member state or the time of authentication informing packet based on plugged; and device 148 and 150 are. Multicast group of member is connected to the different groove is provided with a key, a invention according to the same as shown the digital 4. The ACK/NAK capable, a shown the digital compares 4, GCKS of 6 to 8 and other group member through the guide key management unit, which is distributed the new symmetrical key collecting slicer converts broadcast is externally cheat member group to remove the cheat member, and shown the digital 9. Therefore, to the fixing position, and a judging member j 70c to cheat member, condition for example, the key management unit of which the new symmetrical key collecting part (1 70a and a i70b and a n70c, wherein the )is no broadcasting fixing member group of) is a j symmetrically distributed key collecting. The invention on distributed, the symmetrical key collecting comprises a playing each group member and new symmetrical key (. i.e, K, p Ends; I, or aluminium plate, RECTIFIER, it does not comprises a front member j symmetrical relative key (. i.e, K, J). Although and playing one or more member and symmetrical key of set possibly is provided with a key to change the time, and a member are symmetrical relative keys of the distinguishing to cheat the member to provide the key truly during member typically to exchange, wherein to cheat the member is provided with a playing group member and symmetrical key knowledge. The supposition description the GCKS 25 key management unit 68 to play group member 70a-70d driving part of the key, cheats the member (e.g., a j70c) according to pretending with is the same group member (e.g., a i70b) state same in multicast content to group 73 the once. And the understand in each situations, cheats the member possibly once not more to pretend is the same group member state to play content packets, possibly or single-pole pretends is the same group member is very long time. Therefore, GCKS is provided wait is a time to 85) from the pretended is destination 74 destination client and 80 notices. For example, GCKS is provided wait is a time, the time interval from a time of key to provide the next time of key is a group member is a group member. Adhesive; and GCKS is not received informing packet elapsed time, and GCKS capable of providing a to respond for group member, and once pretended is destination member and are symmetrical key comprises two symmetrical key centralized (see the digital 4 and 10 digital block 84). Therefore playing set of machine to the operation mode, probably the cheats the formerly member is made pretend is connected to the other part of the group is the same. And, and source member 72 to 76 clients can be added with supply member and identifier or more data packet (encryption or other). The destination member and may use supply member identifier of determining the source plate is a pretending is a corresponding destination member state, and selecting with the source member and symmetrical key, and based on corresponding symmetrical authentication key source plate (. i.e, generated by using corresponding symmetrical key compares MAC). And the socket of a client supply without with an supply member identifier capacity or more data packet. The case, destination member is a based on broadcast with other group member each and buttons are to generate a comparing MAC compares, is used MAC and MAC matching of content packets, determining supply member identifier. Each destination member is further connected compare MAC based on destination member are key generation and a compare MAC and content MAC packets compares to determine whether the source plate is pretending is a destination member state. And the destination member comprises a matching; and source plate with pretended is a destination member state. And further arranged above, the source member 72 to 76 clients is connected through enciphered data packet and packet data packet the source of member identifier and hash connection and based on generating MAC to generate according to supply member identifier hash packet of the content packet. The further understand, a circuit, a occurrence of which the step for producing content packet a or multiple probable capable of the according to a. For example, supply capable member, and based on generating MAC to generate according to supply member identifier of grouping via a hash data packets, hash data packet and source of member identifier connected content packet. Further, to the types of the two pair of events, the source of client and no need or packet data packet of hash connection. In a quarter fixing and describes, playing group comprises the source plate more than 72 and destination member 74. And the understand according to any time of distribution, is more than one group member (70) is connected 喿 is the source plate is realized the multi-senders to broadcast. Such condition, playing group is in comprises multiple source members and at least destination member (; and multiple not). Intervals; and, wherein the GCKS25 key management unit 68 to playing group is pretended is the member (i.e. to play two calls to group 83) members are symmetrical key collection, the symmetrical key collecting comprises a wherein symmetrical relative key are versions, therefore containing is pretended is the member is respectively # cheats the large member. The understand multiple other network entities any one or more of equate on arranged on the versions of symmetrical key and a to cheat the member. For example, GCKS of the versions of for receiving or operating key are. Such condition, wherein pretended is destination member (74). e.g, group member i70b) of the destination client 80 are the source plate identifier and a matching identifier of corresponding destination member, (see block (136), a front of the same; the destination client capable of advising set to 85 and a digital wherein signature. The content capable, wherein the shell, a cheating member state, informing packet is received comprising a destination user terminal groups 73 MAC. MAC identification cheat member according GCKS and a base on content packets, a of communication the same way of the pretended is destination member destination the client. To the invention of handle, the invention system or completely part, a invention GCKS 25, supply member (72) and/or destination member 74 or completely part in usually computer program product (e.g., key management unit 68, client supply 76, clients destination 80 equal) for controlling on. For carrying out the invention embodiment method and computer program product comprises: The function adding the storage medium, for of the non-volatile storage medium, and a function adding method for coding component, for example, comprising a computer is connected to an of the storage medium a series of the computer. On, image IO and image lla-llf according to the current of image method, system and program product the invention. A understand of each block or the damage and image current flow image the combination of block capable of a computer program indicating. The computer program instructions can be mounted to the computer or programmable device to generate machine, so that the operation or programmable device in instructions on the computer is of a function and apparatus for flow image block or the invention assigns. The computer program instructions further can save; the function adding the memory, and communication computer or programmable device of the wire groove with, so the memory; the function adding the instruction memory to generate the article for processing; the article includes a function command device for realizing the current image block or the invention assigns. The computer program indicating can be mounted to the computer or programmable device to generate a series of capable of sequence operation executing on the computer or programmable device, to generate a method for realizing computer, so that the operation or programmable device in instructions on the computer for providing the function of for realizing the current image block or the invention assigns. Function the combination and a function of the combination of the therefore, the current image block or the invention support for carrying out methods for carrying out to methods, and is a function program directive device for carrying out to methods. The understand further comprises a current image each block or, and current image the block or the combination of; a through the function or the invention special hardware based on computer system or the special hardware and combination of computer indication the operating assigns realizing. The technical field of provide with a description and related attached digital for guiding the invention of coefficients relates to think of the plurality revisions and embodiments of this invention. Therefore the understand of the invention is interposed between adjacent a specific embodiment of publicizes, and revisions and embodiments are capable of a, wherein at least one of claims a range. Although here with a specific terminology, they are is provided with a generally and descriptive significance, which is not used for limiting the target.
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN107148788A | Cited by | China | Search report |
| US12284164B2 | Cited by | United States of America | Applicant |
| CN113439414A | Cited by | China | Search report |
| CN103119634A | Cited by | China | Search report |
9 members in 5 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 11027274 | United States of America | – | |
| 2727404 | United States of America | A | |
| 2727404 | United States of America | A | |
| 2005003878 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 2005003878 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 11027274 | – | – | – |
| US20040027274 | – | – | – |
| WO2005IB03878 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| US2006149965A1 | United States of America | A1 | |
| WO2006070256A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW200637318A | Taiwan Province of China | A | |
| EP1832041A1 | European Patent Office (EPO) | A1 | |
| CN101124770AThis record | China | A | |
| US7434047B2 | United States of America | B2 | |
| TWI324006B | Taiwan Province of China | B | |
| EP1832041A4 | European Patent Office (EPO) | A4 | |
| CN101124770B | China | B |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Termination of patent right due to non-payment of annual feeCF01 | CF01 | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 101124770
- Publication, DOCDB
- 101124770
- Publication, EPODOC
- CN101124770
- Application
- 80048342
- Application, DOCDB
- 200580048342
- Application, EPODOC
- CN2005848342
Titles2
- Chinese
- 在多播组中检测欺诈成员的系统、方法和计算机程序产品
- English
- System, method and computer program product for detecting fraudulent members in multicast group
Classification
- CPC, 5
- H04L12/18
- H04L63/065
- H04L63/08
- H04L63/104
- H04W12/122
- IPC, 2
- H04L9 32
- H04L9 08