Key sharing method and system
Abstract
The invention claims a key sharing method and system, and method mainly comprises: Group member transmitting the key information request to the adjacent group member; The back and group member is received in the key information, request to the group member is used to the request the key information. The system mainly comprising: solicitant group member and responder group member. The method and system for using the invention, wherein current charging-discharging performance reliability and availability for implementing group key and/or the auxiliary key distribution, wherein a avoiding each group of member from the key server for acquiring key server performance and network bandwidth of bottleneck with.
Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
11 claims: 2 independent, 9 dependent
- 1The key sharing method, comprising a characterised, comprising steps:A, wherein the group member discovered of the group of keys and/or the auxiliary keys the other group of member connected with synchronize, a group member is one or more and group member transmitting the key message to request request of the adjacent assembly member end of the triggering the key message group of key and/or auxiliary key wherein the transmission;, Or with one or more with with neighborship responder group member substrate-processing of the identification and key with jurisdiction information to a request request of the responder group member to the input key and/or the auxiliary key is wherein the);Wherein the B, and group member is screwed to the key message to request or a key, request to the group member is used to the request the key information. 1. 一种密钥共享方法,其特征在于,包括步骤:A、当组成员发现其组密钥和/或辅助密钥与其它组成员不同步后,组成员向一个或多个邻居组成员发送密钥报文请求,请求所述邻居组成员向其发送携带所述组密钥和/或辅助密钥的密钥报文;或者,向一个或多个与其具有邻居关系的响应者组成员发送携带身份证明和密钥拥有权限信息的密钥请求,请求所述响应者组成员向其发送所述组密钥和/或辅助密钥;B、所述邻居组成员接收到所述密钥报文请求或密钥请求后,向所述组成员发送所述请求的密钥信息。
- 7A key sharing system, comprising a characterised, comprising:solicitant group member: In the solicitant group member discovered of the group of keys and/or the auxiliary keys the other group of member connected with synchronize, with one or more with with neighborship responder group member to transmit the key message to request request of the responder group member end of the triggering the key message group of key and/or auxiliary key wherein the transmission;, Or with one or more with with neighborship responder group member substrate-processing of the identification and key with jurisdiction information to a request request of the responder group member to the input key and/or the auxiliary key is wherein the);responder group member: For receiving to the key message of the solicitant group member is a request or a key, requests to the solicitant group member is used to the request the key information. 7. —种密钥共享系统,其特征在于,包括:请求者组成员:用于在请求者组成员发现其组密钥和/或辅助密钥与其它组成员不同步后,向一个或多个与其具有邻居关系的响应者组成员发送密钥报文请求,请求所述响应者组成员向其发送携带所述组密钥和/或辅助密钥的密钥报文;或者,向一个或多个与其具有邻居关系的响应者组成员发送携带身份证明和密钥拥有权限信息的密钥请求,请求所述响应者组成员向其发送所述组密钥和/或辅助密钥;响应者组成员:用于在接收到所述请求者组成员发送的密钥报文请求或密钥请求后,向所述请求者组成员发送所述请求的密钥信息。
Independent claims2
131 paragraphs, as filed
key sharing method and system
technical field
[0001] The invention relates to a communication field, to a key sharing method and system for transformer.
background technology
[0002] The interphone is a a communication field of two or more than two member participates, a field of without and two member in participate is a exceptional box of communication. The communication field with multiple data recipients generally, one or more data senders. May use unicast technique in the interphone or playing technology to transmit the message, and playing technology of the unicast process is easier than diameter of the communication.
[0003] Common communication field a remote multi-side conference, IP phone, IPTV and network online game and grid computing. The interphone is safely to the communication participant providing access control (authorization and authentication), providing encryption, a protecting alarm, the replay protection, the source and authentication group authentication to the communication content equal the safety service, preventing no hole group member sections and tamper with the corresponding content, or normal corner of interference way of communication, and prevents from member the safety threat.
[0004] The safe requirements of intercommunication mainly comprises:
[0005] 1st, Authorization and authentication. Without and method permits, and a prove the shape of state of arm multi-side the signal section and receiving and transmitting data, so the broadcasting group is controllable.
[0006] 2nd, Safe. Single wires with a key node is connected to explain group communication message the content.
[0007] 3rd, Group member authenticate. The no hole group member is not connected to generate the efficient authentication information, which is not connected to pretend is a group member to transmitting multicast message.
[0008] 4th, Authentication supply (waterproof denying). The identification information of the group member is not connected to the generating set of member, is not then connected to pretend is other group of member to transmitting multicast clamped message. On the other side, group member is not connected to deny wherein the sending information.
[0009] 5th, Anonymous. Providing anonymous used for group member mechanism, i.e., a receiving end is not connected with the receiving to playing message to the considering emitting end of the state.
[0010] 6th, Integrity. A playing message wherein tampered method for determining a.
[0011] 7th, Internally program. Providing program detection mechanism, realizing waterproof program attack.
[0012] Usually and encryption transmission to a message interworking for security of ensuring consistency between datum communication. The system for sharing key according multi-side the encryption and decryption the is installed while the group member know of the ensuring consistency between datum the encrypted message is a group member cover explain. Group member authenticate is made of the key is realized, wherein the single wires with same group member capable of generating high-energy correctly encrypting multicast message.
[0013] Solve the communication secret key problem of the sharing system key multi-side is a production and distribution of key. The device for generating and distribution flowing is antiforeign, wherein the no hole group member is not connected to the straight the key of generating and distribution. The source, authentication integrity and anonymous service normally further flowing is two sides or multi-side antiforeign sharing of information. The communication, how is realized antiforeign sharing of key is a research category group of managing key, a wire key is a key of each group of common member, is used to the broadcast message end of the encryption and decryption the equal the safe operation. How group managing key is studies for group member for publishing, and updating group key, and solve the extension toughness, and a reliable problem that hence with.
[0014] In turn to prevent leakage key, a group flowing a on the encryption transmission. At a data transmission method is as KEK (Key Encryption Keys, auxiliary key) and (TPK Service Protection Keys, encryption group key) in order the confidentiality group of key.
[0015] KEK sharing between the key and servers group member, a different group member, the key server is different KEK, the front to realizing group key is updating,/backward encryption requirement. The Jan the Danzu the key management scheme, the key server and each group member common KEK; the initial distributing the updating method of set key; and key group and an KEK the encryption of each current group member, then transmits to the opposite party. The solution for realizing simply; the key updating, wherein the encryption and transmission and group member of medium the key server lower end is proportional, therefore the extendibility of the method of two leads, comprising at least for.
[0016] The, with connection advanced group key management scheme for tree structure to organize KEK generally, and method for IP broadcasting substrate-processing group key message, a encrypting and transmission according to the key the server lower end on, wherein obtaining a better extendibility. LKH Logic (Hierarchy Key, a logic level tree) is a field is connected with mature and standard tree structure based one group key management scheme, the LKH group key management scheme the schematic positive and shown the digital 1.
[0017] The LKH group key management scheme according to shown the digital 1, the root node (K1-8) is set key, the nodes (bough node and teeth node) are all key, a blade nodes and group member (u1 to u9) is 11 the corresponding relationships. Each user with a blade node to a node by way of all keys, group key distribution of each group of member. And a digital 1, front group member u9 engages the key according u1, comprising a key according k1, kl23 and kl-8, a u4 is k4, k456 and kl-8.
[0018] The LKH group key management scheme according to shown the digital 1, wherein a new group member is arm or a group of member of; the key server need to the upgrade key of each group of members are substrates to know or known.
[0019] For example, wherein u9 power, the key server updating key k78 and kl-8, while the other group of member signals to the u8 encryption transmission updating the key. The specific the process of: With kl-8 encryption kl-9, transmitted to a user u1), u8With k78 encryption k789, transmitted to a user and u7, u8A with k9 are kl_9 encryption and k789, transmitted to a user u9.
[0020] The u9 with, a server updating k789 and kl_9; and each group member u 1 to the u8 encryption transmission updating the key, a specific the process of: With k78 encryption k789, k7 encryption k78, transmitted to a user u7,With kl23 encryption kl-8, transmitting signals to the circuit; With k456 encryption kl_8, a to u4 to u6.
[0021] When the LKH group key management scheme, the key server updating group key encryption value of times of O (IogN), N is a group of. A message transmission, the LKH default for I the p-type to play to transmit the key is updating the short clamped, and suggested used to transmit the mode of group; soon the key information of the encrypting method based on a sealed in a message, in the manner of multi- radio each group of members, wherein, the key updating the transmission device of times and maintain is a constant.
[0022] Is the LKH group key management scheme, the tree structure based one group key management scheme - comprising a OFT, LKH++.
[0023] When the upper LKH group key management scheme, the key server to the group member transmitting the key message, flowing ensuring consistency between datum of the key message the reliability conductor, a to the legitimate group member configured of the terminal group key message, which is not connected to the upgrade group key and/or the auxiliary key, which is not connected with the ACK/NAK for continuously end of the group communication. Power of power key message reliably transmitting comprises: Voltage and a group of node fault and group member node short offline the network failure and a network congestion for equal. With a mainly comprises the following method and is used for ensuring consistency between datum to the key message distribution the reliability.
[0024] The existing technology the reliable method of first of ensuring consistency between datum key message distribution of: Repeatedly transmit the key message method. When the method, a server to the group member transmitting the key message, each key message a transmission of multiple. Group member is allocated the key message for processing first convex part, discards a message of repetition of the transmission line by. The method suitable for a key distributing method of unicast and radio multi-, and simply, can enhance to a multiple has densely
Reliability 5 of the key message updating, and between the group member a to the probability of the key without synchronize, suitable for the group communication field of the partial range time.
[0025] The existing technology first of ensuring consistency between datum key message distribution's the shortcoming reliability of realizing is:
[0026] 1st, It fundamentally solve the reliable problem of the group key distribution. The condition that a network measurement the jam, a condition of very possibly with a texts of all a transmission is discarded, a group member - circuit for obtaining group key message via another method.
[0027] 2nd, Then the bandwidth consumption. Repeatedly transmit the key message to the waste network bandwidth, an AC bandwidth restricted field.
[0028] The existing technology the reliable method of second of ensuring consistency between datum key message distribution of: Based on reliable unicast/group key distributing method of multi- broadcast. The method introduces the overtime retransmission and receiving data transmission mechanism is a key and servers group member, fundamentally realizing group reliable key message transmission. For IP broadcasting is filled with a message distribution of LKH the same the capacitor is reliably playing technology.
[0029] The existing process and device for ensuring consistency between datum key message distribution's the shortcoming reliability of realizing is:
[0030] 1st, The forward authentication mechanism and method for with the phenomenon for data message firing. A door (ACK acknowledge), which is not NAK (a) response authentication mechanism, a group member of each receiving group key message in transmitting the data message. Wherein the group member and a group key message the time is closed; each group member medium is big, a magnetism group of member almost relative to the unidirection transmitting data message, wherein the pulling network information of sudden bulge of the short - time, worsens the network the jam state, a server further possibly wherein the network processing burden is a overweight, which is not connected with an alarm receiving data message.
[0031] 2nd, Then the burden key of server. Can make the key service processing burden is a data message quantity arc overweight, the key server need to maintain the overtime retransmission timer of each group member, a increasing the burden key of server, and a group member medium of each server that can serve is not connected to the oversized.
[0032] The existing technology the reliable method of third of ensuring consistency between datum key message distribution of: FECO^orward for Error Correction, forward error correction) group key distributing method of technology. The method for increasing through the multiple ratio of the key message the de-repeated information, for example, duplicates increase the front message in the following message the information, causing the is originating no need to receiving the complete message, only need to receiving the multiple ratio is a message to a withdraw the alarm information message. The capacitor is in with good, relative universal device, and methods of scenes further can be applied in streaming media.
[0033] The existing technology third of ensuring consistency between datum key message distribution's the shortcoming reliability of realizing is: Is transmission, wherein then the transmission burden key of server. Cottons, then the de-repeated information in message, a message transmission burden key of server is correspondingly aggravates.
[0034]
invention content
[0035] The problem of the view of the fact of the existing technology, comprising An objective of the present invention claims a key distribution method and, wherein current charging-discharging performance reliability of the key distribution.
[0036] An objective of the present invention approves the following technical solution is realized:
[0037] The key sharing method, comprises steps:
[0038] A, wherein the group member discovered of the group of keys and/or the auxiliary keys the other group of member connected with synchronize, a group member is one or more and group member transmitting the key message to request request of the adjacent assembly member end of the key set to the transmission and/or the key message of auxiliary key; , Or with one or more with with neighborship responder group member substrate-processing of the identification and key with jurisdiction information to a request request of the responder group member to the key set to wherein the) and/or the auxiliary key;
[0039] Wherein the B, and group member is screwed to the key message to request or a key, request to the group member is used to the request the key information.
[0040] The pedal B is specifically comprising:
[0041] Wall; the adjacent group member is screwed to the key request message, a command to the group member of the key request message end of the identification authentication, and identification authentication failure; and fixing flexible to the key message, requestOtherwise, operating order B2,
[0042] B2, a on the adjacent group member to exist to the request the key message, the group member is used for transmitting key message request to the request the key message; The key message of otherwise, informs to the transmitting key message to a request group member of wherein an request to exist.
[0043] Front - Bl of; the farther comprising:
[0044] The B10, wherein neighbour group member is screwed to the key request message, a command to the group member of the key request message to for defending attack inspection; and defending attack inspection failure; and fixing flexible to the key message, requestOtherwise, operating order wall.
[0045] The pedal B is specifically comprising:
[0046] B3, wherein neighbour group member to act according to the key request to the identification information of terminal, the transmitting group member of the key request end of the identification authentication; The identification authentication, and according to the key request to the button is disposed in the jurisdiction information, the transmitting group member of the key request to a a jurisdiction inspection, wherein the jurisdiction inspection are, operating order; B4
[0047] B4, a on the adjacent group member to exist to the request group key and/or the auxiliary key, the transmitting group member is used for key request to the request group key and/or the auxiliary key; Group key and/or the auxiliary key according otherwise, informs to the transmitting key message to a request group member of wherein request without exist.
[0048] Front - B3 of; the farther comprising:
[0049] The B30, wherein neighbour group member is screwed to the key request, a command to the group member of the key request to method for defending attack inspection; and defending attack inspection failure; and fixing flexible to the key; requestOtherwise, operating order B3.
[0050] The B farther of comprising: a
[0051] When the adjacent group member to discover when the key message or the key according group member request is not the newest key message or a key, wherein the adjacent group member to the group member to the position corresponding, reportOr the group member to transmit the newest key message or the key by.
[0052] The key sharing system, comprising:
[0053] solicitant group member: In the solicitant group member discovered of the group of keys and/or the auxiliary keys the other group of member connected with synchronize, with one or more with with neighborship responder group member to transmit the key message to request request of the responder group member end of the triggering the key message group of key and/or auxiliary key wherein the transmission; , Or with one or more with with neighborship responder group member substrate-processing of the identification and key with jurisdiction information to a request request of the responder group member to the input key and/or the auxiliary key is wherein the station.
[0054] responder group member: For receiving to the key message of the solicitant group member is a request or a key, requests to the solicitant group member is used to the request the key information.
[0055] The responder group member comprises:
[0056] Key message buffer: moduleThe key message for transmitting key and server for sending end and buffer;
[0057] Identification authentication: moduleIs a key message back receiving solicitant group member a request, disposed on the identification authentication to the solicitant group member; The identification authentication failure, stopping processing to the key message, request
[0058] Key message transmission module: In the back solicitant group member the identification authentication function, and key message buffer module for obtaining to the key message of the solicitant group member request, charges to the solicitant group member and.
[0059] The responder group member farther comprising:
[0060] Defending attack inspection: moduleIs a key message back receiving solicitant group member a request or the key requests, using the defending attack according to the solicitant group member; For defending attack inspection, failure protection processing to the key request message or the key request.
[0061] The responder group member comprises:
[0062] Key buffer: moduleGroup key and/or the auxiliary key according information for transmitting key and server for sending and buffer;
[0063] Identification authentication and jurisdiction inspection: moduleThe identity information of the key request for according to receiving end, and solicitant group member end of the identification authentication, the identification authentication failure fixing flexible to the key; requestThe key in the key request according to receive an with jurisdiction, information to the solicitant group member is a a jurisdiction inspection, wherein jurisdiction inspection failure fixing flexible to the key; request
[0064] key transmission module: In the back solicitant group member the identification authentication and jurisdiction inspection are, which the key module buffer obtaining to the input key and/or the auxiliary key for solicitant group member request, charges to the solicitant group member and.
[0065] The responder group member farther comprising:
[0066] Defending attack inspection: moduleA key request back receiving solicitant group member, a conducts the defending attack according to the request group member; For defending attack inspection, failure protection processing to the key request.
[0067] The invention claims a see of the technical solution of the invention is connected with neighborship group member share group key message or the share group key and/or the auxiliary key, wherein current charging-discharging performance reliability and availability for implementing group key and/or the auxiliary key are, wherein a avoiding each group of member from the key server for acquiring key the server performance and a network bandwidth of bottleneck with enhanced, a rectifying group system resource (for example network bandwidth and processing capacity) is factor enhanced, the safety full group communication system data.
brief description fo the drawings
[0068] Digital 1) is set LKH key management scheme schematic drawing;
[0069] Digital 2 is the invention the key message sharing to a key distribution method embodiment the specific action flow, image
[0070] Digital 3 is the invention the key sharing to a key distribution method embodiment the specific action flow, image
[0071] Digital 4 is the invention the key message sharing to a key distribution system embodiment the specific structure schematic drawing;
[0072] Digital 5 is the invention the key sharing to a key distribution system embodiment the specific structure schematic drawing.
Performing is specifically
[0073] The invention claims a key sharing method and system, and a core is: A a neighborship group member share group key message or the share group key and/or the auxiliary key, a component abnormal group member a normal group member is set acquiring key and/or the auxiliary key, avoiding without synchronize with the normal group members' group keys and/or the auxiliary keys.
[0074] The invention the method comprises realizing - based on key message sharing and a share one of two.
[0075] Based on key for realizing - comprising: aGroup member for receiving the request confirm group member body causing the support
8, Inspect group member key according causing request to the jurisdiction. , And group member for receiving the request fixedly connected to the support member set transmit group key and/or the auxiliary key for encrypting transmission method.
[0076] Based on key message for realizing - comprising: aGroup member for receiving the request it confirm group member state of the support, the group member for receiving the request can only to the request the group member retransmit the key message from a server.
[0077] A method detailed description invention claims a light of the auxiliary shape, the invention the key message sharing to a key sharing method embodiment the specific action current and shown the digital 2. Comprising the following steps:
[0078] The pedal 2-1), the neighborship between the group member.
[0079] First lower is arranged on the neighborship between the group member, which is arranged between the neighborship group member is a corresponding to each. The invention the other group member does not installed on two neighborships, containing the neighborship without with part is set between the member to exist.
[0080] Arranged between the group member the neighborship through the key server is provided, which is connected with the method.
[0081] The damage, group member transmitting the key message request to the adjacent group member.
[0082] When the group member is arranged on the neighborship, wherein all group member, wherein network failure, thereof, short offline and other end is not received group key message of the key a server, and a discovered for group key and/or the auxiliary key the other group of member connected with synchronize, the adjacent group member transmit the key message to request request of the adjacent assembly member transmitting to oneself end of the key message of corresponding set key and/or auxiliary key.
[0083] The group of member capable of transmitting the key message to request to the adjacent group member, may send a key message request to the adjacent group member in sequence.
[0084] The invention claims 2-3, and adjacent group member of key request message to for defending attack inspection and identification authentication.
[0085] The adjacent assembly member and key request message, for preventing malicious group member by request message to the group of member emitting the DOS attack, first conducts the DOS preventing attack according to the group member for transmitting the key request message. The DOS preventing attack inspection failure; and fixing processing the key request message.
[0086] The back of the DOS attack polling successfully, and identification authentication to the group member for transmitting the key message, requestThe identification authentication failure; and fixing formed on the key message, requestOtherwise, operating claims 2-4.
[0087] The invention claims 2-4, and adjacent group member of key message request to transmit the key message to a group member of the transmitting key request message.
[0088] The DOS preventing attack polling successfully, and receiving and group member of the key request message searching the local buffer the key message of the preserves with a transmitting key message to a request group member of request.
[0089] The key message of each of the local buffer with transmitting key message to a request group member of request, transmitting the key message to a group member for transmitting the key request message. A command to the key message to request group member for receiving the key message, deciphers group key and/or the auxiliary key, disposed on corresponding processing and.
[0090] The key message of each of the local buffer there is no transmitting key message to a request group member of request, the key message of the group member of a advising transmitting key request message wherein request which is exist.
[0091] The invention claims a key sharing to a key sharing method embodiment the specific action current and shown the digital 3. Comprising the following steps:
[0092] The pedal 3-1), the neighborship between the group member.
[0093] First lower is arranged on the neighborship between the group member, which is arranged between the neighborship group member is a corresponding to each. The invention the other group member does not installed on two neighborships, containing the neighborship without with part is set between the member.
[0094] Arranged between neighborship group member through the key server is provided, which is connected with the method.
[0095] The pedal 3-2, group member transmitting the key request to the adjacent group member.
[0096] When the group member is arranged on the neighborship, wherein all group member, wherein network failure, thereof, short offline and other end is not received group key message of the key a server, and a discovered for group key and/or the auxiliary key the other group of member connected with synchronize, with a neighborship other group of member to transmit the key request to the request the other group of member themselves close to the sending set corresponding key and/or the auxiliary key. And the upper key request indicator method for identifying and key with jurisdiction information.
[0097] The group of member capable of neighborship with other group of member to transmit the key is a request to multiple, and a neighborship other group of member to transmit the key request with is provided with a.
[0098] The pedal 3-3, and adjacent group member of the key request to method for defending attack inspection.
[0099] The other group of member and key request, for preventing malicious group member by request message to the group of member emitting the DOS attack, first conducts the DOS preventing attack inspection. A DOS preventing attack inspection failure; and fixing processing the key; requestOtherwise, operating order 3-4.
[0100] The pedal 3-4, and adjacent group member of the key request end of the identification authentication and jurisdiction inspection.
[0101] The DOS preventing attack polling successfully, the identification information of the adjacent assembly member shaft according to receiving the key request of, and identification authentication to the group member for transmitting the key request, and identification authentication failure; and fixing processing the key according request; aA identification authentication successfully, the key according and continuously to act according to receiving the key request device for with jurisdiction information, a group member of the inspection transmitting key request with a key upper-stage access.
[0102] A key and access upper-stage inspection failure, the key according and receiving the key request to the adjacent assembly member baffle is formed of said request to informed according to transmit the group member of the key request to flow wherein jurisdiction is insufficient; And the key access upper-stage polling successfully, and execution claims 3-5.
[0103] The invention claims 3-5, and adjacent group member of the key request to transmit the key a group member for transmitting the key request.
[0104] And receiving and group member of the key request searching the local buffer the key and/or the auxiliary key of the preserves with a transmitting key request to the group member of request.
[0105] The key and/or the auxiliary key according and local buffer exists to transmitting key request to the group member of request, used for encrypting the via the transmitting key and/or the auxiliary key a group member for transmitting the key request. A command to the key request to the group member for receiving the key and/or the auxiliary key, based on corresponding processing.
[0106] The key and/or the auxiliary key according and local buffer without exist to transmit the key request to the group member of request, the key and/or the auxiliary key for group member of a advising transmitting key request wherein request which is exist.
[0107] The key on share one or based on key message the sharing image processing of embodiment, to prevent between the group member with the phenomenon for implementing group key without synchronize, and safety consideration; the limiting the adjacent group member is request associated the key message of eliminated group key and/or the auxiliary key or communication. Therefore, the lower manager to the conducting corresponding policy; each group member discovered of the adjacent assembly member request associated group key message of eliminated group key and/or the auxiliary key or communication, no matter and a sending a group key message of the group of key and/or the auxiliary key or corresponding to the opposite party, wherein inform group key message of group and a group of key and/or the auxiliary key or communication is eliminated, a inform the opposite party is further provided with a request group key message of the newest group key and/or the auxiliary key or communication. In turn to assure the safety, the broadcast message and ensuring consistency between datum the safety of some of authentication mechanism.
[0108] The invention claims a method is connected with reliable method for ensuring consistency between datum prior key message distribution and light of use, wherein the enhanced reliability of the key is distributed.
[0109] The invention claims a key message sharing to a key distribution system embodiment the specific structure and shown the digital 4. Comprises the following modules:
[0110] solicitant group member: A key request message transmission module; the solicitant group member discovered of the group of keys and/or the auxiliary keys the other group of member connected with synchronize, with one or more with with neighborship responder group member to transmit the key message to request request of the responder group member end of the triggering the key message group of key and/or auxiliary key wherein the transmission.
[0111] responder group member: Is a key message back receiving solicitant group member a request, wherein the solicitant group member using the defending attack inspection and identification authentication, to the solicitant group member for transferring message key according wherein request. Comprising: Key message buffer module and defending attack inspection module and identification authentication module and a message transmission module.
[0112] , A message buffer: moduleThe key message for transmitting key and server for sending end and buffer.
[0113] , Defending attack inspection: moduleIs a key message back receiving group member a request, for preventing malicious group member launched the DOS attack to by request message, using the DOS preventing attack according to the group of member. The DOS preventing attack inspection failure; and fixing formed on the key request message.
[0114] , Identification authentication: moduleIs a key message back receiving solicitant group member a request, disposed on the identification authentication to the solicitant group member; The identification authentication failure, stopping processing to the key request message.
[0115] , A message transmission module: For group member of the sealing transmitting the key request message in the DOS preventing attack inspection and identification authentication part, which the key message buffer module for obtaining to the key message of the solicitant group member request, is connected to the solicitant group member and.
[0116] The invention claims a key sharing to a key distribution system embodiment the specific structure and shown the digital 5. Comprises the following modules:
[0117] solicitant group member: A key request transmission module; the solicitant group member discovered of the group of buttons and/or the auxiliary key the other group of member connected with synchronize, with one or more with with neighborship responder group member substrate-processing of the identification and key with jurisdiction information to a request request of the responder group member to the input key and/or the auxiliary key is wherein the station.
[0118] responder group member: A key request back receiving solicitant group member, transmitting time of the solicitant group member for defending attack inspection, the identification authentication and jurisdiction, inspect to the solicitant group member the transmitting key according wherein request. Comprising: Cache key module and defending attack inspection module, identification authentication and jurisdiction inspection module and a transmission module.
[0119] , A buffer: moduleGroup key and/or the auxiliary key according information for transmitting key and server for sending and buffer.
[0120] , Defending attack inspection: moduleA key request back receiving solicitant group member, for preventing malicious group member emitting the DOS attack to by request message thereof, the DOS preventing attack according to the solicitant group member. The DOS preventing attack inspection failure; and fixing formed on the key request.
[0121] , Identification authentication and jurisdiction inspection: moduleThe identity information of the key request for according to receiving end, and identification authentication to the solicitant group member, and identification authentication failure; and fixing processing the key according request; a A identification authentication successfully, the key according and continuously to act according to receiving the key request device for with jurisdiction information, the inspection solicitant group member whether a key upper-stage access. A jurisdiction inspection failure; and said processing the key according to a request according informs solicitant group member wherein jurisdiction is insufficient.
[0122] , A transmission module: For solicitant group member of the sealing transmitting the key request in the defending attack inspection, the identification authentication and jurisdiction inspection, through which the key module buffer obtaining to the key group of the solicitant group member and request/or the auxiliary key, is connected to the solicitant group member and.
[0123] The periphery of that is only the invention good specifically embodiment, and has a protection of this invention are not to limit, any of familiar with a provide the technical field in a range of the invention exposition, the exchanger or the alternative capable of think easily, and covered on the has a protection of this invention. Therefore, has a protection of this invention the is a claim the has a protection and standard.
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200610152283 | China | A | |
| CN20061152283 | – | – | – |
Numbers
- Publication
- 101155027
- Publication, DOCDB
- 101155027
- Publication, EPODOC
- CN101155027B
- Application
- 101522837
- Application, DOCDB
- 200610152283
- Application, EPODOC
- CN20061152283
Titles2
- English
- Key sharing method and system
- Chinese
- 密钥共享方法和系统
Classification
- CPC, 2
- H04L9/0833
- H04L9/3271
- IPC, 2
- H04L9 08
- H04L9 30