EP1045585A1

Method of and apparatus for providing secure communication of digital data between devices

Abstract

The present invention provides a method of providing secure communication of digital data between devices, said method comprising the steps of communicating from one device an identifier of a device to an independent security module and performing device validation depending on the identity of the received identifier. <IMAGE>

EP1045585A1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 13 April 2019, 7.4 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

46 claims: 19 independent, 27 dependent

  1. 1
    A method of providing secure communication of digital data between devices, said method comprising the steps of communicating from one device an identifier of a device to an independent security module and performing device validation depending on the identity of the communicated identifier.
  2. 6
    A method of providing secure communication of digital data between devices, said method comprising the steps of comparing an identifier communicated from one device with at least one stored identifier, each stored identifier being associated with a respective valid device, and validating the device if the communicated identifier is identical to the or one of the stored identifiers.
  3. 9
    A method according to any of Claims 1 to 6 and 8, wherein certificates are passed between the device and the security module to validate the device.
  4. 20
    A method of providing secure communication of digital data between a device and a security module, said method comprising the steps of transferring to the security module a random number and an identifier of the device encrypted by a public key of the security module, the security module decrypting the random number and device identifier using a private key of the security module, validating the device using the device identifier and, upon validation of the device, using the random number to encrypt and decrypt data communicated between the security module and the device.
  5. 23
    A method according to any of Claims 17 to 19 or 21, wherein the random number and the certificate containing the identifier of the device are randomised by the device prior to encryption, the randomisation being reversed by the security module following decryption of the random number and certificate.
  6. 24
    A method according to any of Claims 19 to 23, wherein the security module communicates to the device a random key (SK) generated in the security module and encrypted using the random number (X), the device decrypting said key (SK) using the random number (X) and thereafter using said key (SK) to encrypt data sent to the security module.
  7. 29
    A method according to any of Claims 19 to 28, wherein data is communicated between first and second devices, and upon validation of each device by the security module, the security module communicates to the first device a random key (SK) generated in the security module and encrypted using the random number (X) generated by the first device, the first device decrypting said key (SK) using the random number (X) generated thereby, and communicates to the second device said key (SK) encrypted using the random number (Y) generated by the second device, the second device decrypting said key (SK) using the random number (Y) generated thereby, said key (SK) thereafter being used to encrypt data communicated between the security module and the devices and data communicated between the devices.
  8. 30
    A method of providing secure communication of digital data between devices, said method comprising the step of providing a security module, generating a random key (SK) in the security module and encrypting data communicated between the devices using the random key.
  9. 35
    A method according to any of Claims 30 to 34, wherein the security module validates each device before communicating said key (SK) to each device.
  10. 37
    A method according to any of Claims 28 to 36, wherein said key (SK) is periodically changed by the security module.
  11. 38
    A method according to any of Claims 29 to 37 as applied to a home network system, the devices corresponding to first and second consumer electronic devices adapted to transfer data therebetween via a communication link.
  12. 39
    Apparatus for providing secure communication of digital data between devices, said apparatus comprising a security module comprising means for receiving an identifier of a device and means for performing device validation depending on the identity of the received identifier.
  13. 40
    A security module for providing secure communication of digital data between devices and arranged to receive an identifier of a device and to perform device validation depending on the identity of the received identifier.
  14. 41
    Apparatus for providing secure communication of digital data between devices, said apparatus comprising means for storing at least one identifier, each stored identifier being associated with a respective valid device, means for comparing an identifier of a device with said at least one stored identifier, and means for validating the device if the identifier of the device is identical to the or one of the stored identifiers.
  15. 42
    A security module for providing secure communication of digital data between devices and arranged to store at least one identifier, each stored identifier being associated with a respective valid device, to compare an identifier of a device with said at least one stored identifier, and to validate the device if the identifier of the device is identical to the or one of the stored identifiers.
  16. 43
    A system for providing secure communication of data between a device and a security module, said device comprising means for communicating to the security module a random number and an identifier of the device encrypted by a public key of the security module, the security module comprising means for decrypting the random number and device identifier using a private key of the security module, means for validating the device using the device identifier, and means for using the random number to encrypt and decrypt data communicated between the security module and the device.
  17. 44
    A security module arranged to receive a random number and an identifier of a device encrypted by a public key of the security module, decrypt the random number and device identifier using a private key of the security module, validate the device using the device identifier, and, upon validation of the device, use the random number to encrypt and decrypt data communicated between the security module and the device
  18. 45
    Apparatus for providing secure communication of digital data between devices, said apparatus comprising the devices and a security module comprising means for generating a random key and means for communicating the random key to the devices, each device being arranged to encrypt data communicated between the devices using the random key.
  19. 46
    A security module for providing secure communication of digital data between devices and arranged to generate a random key (SK) for encrypting data communicated between the devices and to communicate the random key to the devices.
Independent claims19