Nova Patents
EP1547304B1

Secure broadcast/multicast service

Abstract

A method of authenticating candidate members 1 wishing to participate in an IP multicast via a communication network, where data sent as part of the multicast is to be encrypted using a Logical Key Hierarchy based scheme requiring that each candidate member submit a public key to a group controller. The method comprises, at the group controller 1, verifying that the public key received from each candidate member 1 is owned by that member and that it is associated with the IP address of that candidate member 1 by inspecting an interface ID part of the IP address.

EP1547304B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 13 September 2022, 4 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

8 claims: 5 independent, 3 dependent

  1. 1
    A method of authorising a user to participate in a secure IP multicast or broadcast and in which security keys are distributed to group members using a key revocation based mechanism, the method comprising:delivering a certificate to the user (1), the certificate verifying that a public-private key pair identified in the certificate can be validly used by the user (1) to access said secure multicast/broadcast;subsequently verifying at a control node that the certificate is owned by the user (1) using a proof-of-possession procedure based on the private key;and assuming that verification is obtained, using said public key to send a Key Encryption Key to the user (1).
  2. 4
    A method according to any one of the preceding claims, wherein said proof-of-possession procedure involves the control node sending a random number to the user in plain text, and the user sending a response to the control node containing a signature generated by applying the private key to the random number, wherein the control node is in possession of the user's certificate and can check whether or not the message is correctly signed with the user's private key.
  3. 5
    A method according to any one of the preceding claims, wherein the user to be authorised has a subscription to a first, home communication network and wishes to participate in a multicast or broadcast service via a second, foreign network in which the user is roaming, the method comprising:the visited network contacting the user's home network, upon receipt of an initial registration request from said user, to authorise the user;following authorisation by the home network, generating a certificate relating to said service and comprising generating a public-private key pair, either at the user equipment or within one of the networks, and signing the certificate;and sending the certificate to the user.
  4. 7
    A group controller comprising memory and processing means for implementing the method of any one of the preceding claims.
  5. 8
    A mobile terminal comprising memory and processing means for implementing the method of any one of the preceding claims.