Method and apparatus for encoding security status information
10 claims: 10 independent, 0 dependent
- 1A method of encoding a frame counter (50) used in communication between a sender and a receiver, the frame counter (50) having a first component representing a compressed frame counter (42) and a second component representing a sequence counter (36), the method comprising the steps of:a) maintaining said sequence counter (36) and said frame counter (50) at the sender;b) establishing an updated value of the frame counter (50) in a direction of counting from a current value of the frame counter that is congruent to a value of the sequence counter (36) modulo a size of the sequence counter (36);andc) computing an encoded value of the frame counter (42) by removing from the frame counter (50) a component equal to a value of the sequence counter (36) such that the updated value of the frame counter (50) is uniquely recovered from the encoded value of the frame counter (42) and said sequence counter (36). Procédé de codage d'un compteur de trames (50) utilisé dans une communication entre un expéditeur et un récepteur, le compteur de trames (50) ayant un premier composant représentant un compteur de trames compressées (42) et un second composant représentant un compteur de séquences (36), le procédé comprenant les étapes consistant à : a) maintenir ledit compteur de séquences (36) et ledit compteur de trames (50) au niveau de l'expéditeur ;b) établir une valeur mise à jour du compteur de trames (50) dans une direction de comptage d'une valeur actuelle du compteur de trames qui est congruente à une valeur du compteur de séquences (36) modulo une taille du compteur de séquences (36) ;etc) calculer une valeur codée du compteur de trames (42) en supprimant du compteur de trames (50) un composant égal à une valeur du compteur de séquences (36) de sorte que la valeur mise à jour du compteur de trames (50) soit récupérée de manière unique à partir de la valeur codée du compteur de trames (42) et dudit compteur de séquences (36). Verfahren zum Verschlüsseln eines Rahmenzählers (50), der bei einer Kommunikation zwischen einem Sender und einem Empfänger verwendet wird, wobei der Rahmenzähler (50) eine erste Komponente, die einen komprimierten Rahmenzähler (42) darstellt, und eine zweite Komponente, die einen Folgezähler(36) darstellt, aufweist, wobei das Verfahren die Schritte umfasst: a) Aufrechterhalten des Folgezählers (36) und des Rahmenzählers (50) beim Sender;b) Bilden eines aktualisierten Wertes des Rahmenzählers (50) in eine Zählrichtung von einem aktuellen Wert des Rahmenzählers, der kongruent zu einem Wert des Folgezählers (36) ist, modulo eine Größe des Folgezählers (36);undc) Berechnen eines kodierten Wertes des Rahmenzählers (42) durch Entfernen einer Komponente, die gleich einem Wert des Folgezählers (36) ist, aus dem Rahmenzähler (50), sodass der aktualisierte Wert des Rahmenzählers (50) allein aus dem kodierten Wert des Rahmenzählers (42) und des Folgezählers (36) wiederhergestellt wird.
- 2Procédé selon la revendication 1, comprenant en outre la mise à jour de ladite valeur du compteur de séquences (36) chaque fois qu'un message (30) est envoyé. The method according to claim 1 further comprising updating said value of the sequence counter (36) each time a message (30) is sent. Verfahren nach Anspruch 1, ferner umfassend das Aktualisieren des Wertes des Folgezählers (36) jedes Mal, wenn eine Nachricht (30) gesendet wird.
- 3Procédé selon la revendication 2, dans lequel ladite mise à jour dudit compteur de séquences (36) comprend l'incrémentation de la valeur dudit compteur de séquences (36). The method according to claim 2 wherein said updating of said sequence counter (36) comprises incrementing the value of said sequence counter (36). Verfahren nach Anspruch 2, wobei das Aktualisieren des Folgezählers (36) das Inkrementieren des Wertes des Folgezählers (36) umfasst.
- 4Procédé selon la revendication 1, dans lequel le compteur de trames (50) est récupéré en concaténant la valeur codée du compteur de trames (42) avec la valeur de compteur de séquences (36). The method according to claim 1, wherein the frame counter (50) is recovered by concatenating the encoded value of the frame counter (42) with the value of sequence counter (36). Verfahren nach Anspruch 1, wobei der Rahmenzähler (50) durch Verknüpfen des kodierten Wertes des Rahmenzählers (42) mit dem Wert des Folgezählers (36) wiederhergestellt wird.
- 5Procédé selon la revendication 1, comprenant en outre l'établissement d'une valeur initiale pour le compteur de trames (50) au niveau dudit expéditeur ;la fourniture, sur un canal sans fil (20), de la valeur initiale représentant ledit compteur de trames (50) et d'une valeur initiale dudit compteur de séquences (36) à un destinataire ;l'envoi par la suite de messages (30) incluant la valeur initiale du compteur de séquences (36) et une valeur non codée du compteur de trames (42) si des critères prédéfinis ne sont pas satisfaits, sinon l'envoi de messages (30) incluant la valeur du compteur de trames (50) si les critères prédéfinis sont satisfaits ;et la mise à jour de la valeur dudit compteur de séquences (36). The method according to claim 1 further comprising establishing an initial value for the frame counter (50) at said sender;providing, over a wireless channel 20, the initial value representing said frame counter (50) and an initial value of said sequence counter (36) to a recipient;subsequently sending messages (30) including the initial value of the sequence counter (36) and not encoded value of the frame counter (42) if predefined criteria is not satisfied, otherwise sending messages (30) including the value of the frame counter (50) if the predefined criteria is satisfied;and updating the value of said sequence counter (36) Verfahren nach Anspruch 1, ferner umfassend das Bilden eines Ausgangswertes für den Rahmenzähler (50) an dem Sender;Bereitstellen des Ausgangswertes, der den Rahmenzählers(50) darstellt, und eines Ausgangswertes des Folgezählers (36) über einen drahtlosen Kanal 20 an einen Empfänger;nachfolgend Senden von Nachrichten (30), die den Ausgangswert des Folgezählers (36) und einen nicht kodierten Wert des Rahmenzählers (42) beinhalten, falls vorbestimmte Kriterien nicht erfüllt sind, andernfalls Senden von Nachrichten (30), die den Wert des Rahmenzählers (50) beinhalten, falls die vorbestimmten Kriterien erfüllt sind;und Aktualisieren des Wertes des Folgezählers (36).
- 6Procédé selon la revendication 5, comprenant en outre la surveillance, au niveau de l'expéditeur, d'un accusé de réception, dudit message (30) par ledit destinataire, où les critères prédéfinis sont satisfaits lorsqu'aucun accusé de réception n'est reçu. The method according to claim 5 further comprising monitoring, at the sender, for an acknowledgment, of said message (30) by said recipient, wherein the predefined criteria is satisfied when no acknowledgement is received. Verfahren nach Anspruch 5, ferner umfassend das Überwachen der Nachricht (30) am Sender durch den Empfänger zwecks Bestätigung, wobei die vorbestimmten Kriterien erfüllt sind, wenn keine Bestätigung empfangen wird.
- 7Procédé selon la revendication 5, dans lequel les critères prédéfinis sont satisfaits lorsqu'un nombre prédéterminé de messages (30) incluant la valeur du compteur de séquences (36) et pas du compteur de trames compressées (42) sont envoyés. The method according to claim 5 wherein the predefined criteria is satisfied when a predetermined number of messages (30) including the value of the sequence counter (36) and not the compressed frame counter (42) are sent. Verfahren nach Anspruch 5, wobei die vorbestimmten Kriterien erfüllt sind, wenn eine vorbestimmte Anzahl von Nachrichten (30), die den Wert des Folgezählers (36) und nicht des komprimierten Rahmenzählers (42) gesendet werden.
- 8Procédé selon la revendication 7, dans lequel le nombre prédéterminé est dans la plage de 2 à 10. The method according to claim 7 wherein the predetermined number is in the range 2 to 10. Verfahren nach Anspruch 7, wobei die vorbestimmte Anzahl im Bereich von 2 bis 10 liegt.
- 9A wireless device for receiving communications from other wireless devices in a wireless network (20), each of the wireless devices comprising:a) storage (24) for a frame counter (42);b) a receiver (29) for obtaining a message over the wireless network (20), the message including a sequence counter (36) and data encrypted via an encryption using a secret key and an updated value of the frame counter (50) as input to the encryption;c) a decryptor configured to perform decryption complementary to the encryption used in the message (30), the decryptor having access to the secret key;andd) a processor (22) connected to the message receiver and configured to recover the value of the frame counter (50) from a sequence counter (36) in the message and provide the frame counter (50) and encrypted data from the message to the decryptor, wherein the device is configured to: e) establish an updated value of the frame counter (50) in a direction of counting from a current value of the frame counter that is congruent to a value of the sequence counter (36) modulo a size of the sequence counter (36);andf) compute an encoded value of the frame counter (42) by removing from the frame counter (50) a component equal to a value of the sequence counter (36) such that the updated value of the frame counter (50) is uniquely recovered from the encoded value of the frame counter (42) and said sequence counter (36). Dispositif sans fil pour recevoir des communications d'autres dispositifs sans fil dans un réseau sans fil (20), chacun des dispositifs sans fil comprenant : a) un stockage (24) pour un compteur de trames (42) ;b) un récepteur (29) pour obtenir un message sur le réseau sans fil (20), le message incluant un compteur de séquences (36) et des données chiffrées via un chiffrement utilisant une clé secrète et une valeur mise à jour du compteur de trames (50) en tant qu'entrée pour le chiffrement ;c) un déchiffreur configuré pour effectuer un message (30), le déchiffreur ayant accès à la clé secrète ;etd) un processeur (22) connecté au récepteur de message et configuré pour récupérer la valeur du compteur de trames (50) à partir d'un compteur de séquences (36) dans le message et fournir le compteur de trames (50) et des données chiffrées du message au déchiffreur, où le dispositif est configuré pour : e) établir une valeur mise à jour du compteur de trames (50) dans une direction de comptage d'une valeur actuelle du compteur de trames qui est congruente à une valeur du compteur de séquences (36) modulo une taille du compteur de séquences (36) ;etf) calculer une valeur codée du compteur de trames (42) en supprimant du compteur de trames (50) un composant égal à une valeur du compteur de séquences (36) de sorte que la valeur mise à jour du compteur de trames (50) soit récupérée de manière unique à partir de la valeur codée du compteur de trames (42) et dudit compteur de séquences (36). Drahtlose Vorrichtung zum Empfangen von Mitteilungen von anderen drahtlosen Vorrichtungen in einem drahtlosen Netzwerk (20), jede der drahtlosen Vorrichtungen umfassend: a) Speicher (24) für einen Rahmenzähler (42);b) einen Empfänger (29) zum Erhalten einer Nachricht über das drahtlose Netzwerk (20), wobei die Nachricht einen Folgezähler (36) und Daten beinhaltet, die über eine Verschlüsselung verschlüsselt sind, die einen geheimen Schlüssel und einen aktualisierten Wert des Rahmenzählers (50) als Eingabe in die Verschlüsselung verwendet;c) eine Entschlüsselungsvorrichtung, die konfiguriert ist, um eine Entschlüsselung komplementär zu der Verschlüsselung, die in der Nachricht (30) verwendet wird, durchzuführen, wobei die Entschlüsselungsvorrichtung Zugriff auf den geheimen Schlüssel hat;undd) einen Prozessor (22), der mit dem Nachrichtenempfänger verbunden und konfiguriert ist, um den Wert des Rahmenzählers (50) aus einem Folgezähler (36) in der Nachricht wiederherzustellen und dem Rahmenzähler (50) und verschlüsselte Daten aus der Nachricht der Entschlüsselungsvorrichtung bereitzustellen, wobei die Vorrichtung konfiguriert ist, um: e) einen aktualisierten Wert des Rahmenzählers (50) in eine Zählrichtung von einem aktuellen Wert des Rahmenzählers, der kongruent zu einem Wert des Folgezählers (36) ist, modulo eine Größe des Folgezählers (36), zu bilden;undf) einen kodierten Wert des Rahmenzählers (42) durch Entfernen einer Komponente, die gleich einem Wert des Folgezählers (36) ist, aus dem Rahmenzähler (50) zu berechnen, sodass der aktualisierte Wert des Rahmenzählers (50) allein aus dem kodierten Wert des Rahmenzählers (42) und des Folgezählers (36) wiederhergestellt wird.
- 10A wireless device for sending communications from other wireless devices in a wireless network (20), each of the wireless devices comprising:a) storage (24) for a frame counter and a sequence counter;b) a processor (22) for: i) establishing an updated value of the frame counter (50) in a direction of counting from a current value of the frame counter that is congruent to a value of the sequence counter (36) modulo a size of the sequence counter (36);ii) computing an encoded value of the frame counter (42) by removing from the frame counter (50) a component equal to the value of the sequence counter (36) such that the updated value of the frame counter (50) is uniquely recovered from said encoded value of the frame counter (42) and said sequence counter (36);andc) a transmitter for sending a message over the wireless network (20), the message including a sequence counter (36) and data encrypted via an encryption using a secret key and the updated value of the frame counter (50) as input to the encryption. Dispositif sans fil pour envoyer des communications à partir d'autres dispositifs sans fil dans un réseau sans fil (20), chacun des dispositifs sans fil comprenant : a) un stockage (24) pour un compteur de trames et un compteur de séquences ;b) un processeur (22) pour : i) établir une valeur mise à jour du compteur de trames (50) dans une direction de comptage d'une valeur actuelle du compteur de trames qui est congruente à une valeur du compteur de séquences (36) modulo une taille du compteur de séquences (36) ;ii) calculer une valeur codée du compteur de trames (42) en supprimant du compteur de trames (50) un composant égal à la valeur du compteur de séquences (36) de sorte que la valeur mise à jour du compteur de trames (50) soit récupérée de manière unique à partir de ladite valeur codée du compteur de trames (42) et dudit compteur de séquences (36) ;etc) un émetteur pour envoyer un message sur le réseau sans fil (20), le message incluant un compteur de séquences (36) et des données chiffrées via un chiffrement utilisant une clé secrète et la valeur mise à jour du compteur de trames (50) en tant qu'entrée pour le chiffrement. Drahtlose Vorrichtung zum Senden von Mitteilungen von anderen drahtlosen Vorrichtungen in einem drahtlosen Netzwerk (20), jede der drahtlosen Vorrichtungen umfassend: a) Speicher (24) für einen Rahmenzähler und einen Folgezähler;b) einen Prozessor (22) zum: i) Bilden eines aktualisierten Wertes des Rahmenzählers (50) in eine Zählrichtung von einem aktuellen Wert des Rahmenzählers, der kongruent zu einem Wert des Folgezählers (36) ist, modulo eine Größe des Folgezählers (36);ii) Berechnen eines kodierten Wertes des Rahmenzählers (42) durch Entfernen einer Komponente, die gleich dem Wert des Folgezählers (36) ist, aus dem Rahmenzähler (50), sodass der aktualisierte Wert des Rahmenzählers (50) allein aus dem kodierten Wert des Rahmenzählers (42) und des Folgezählers (36) wiederhergestellt wird;undb) einen Sender zum Senden einer Nachricht über das drahtlose Netzwerk (20), wobei die Nachricht einen Folgezähler (36) und Daten beinhaltet, die über eine Verschlüsselung verschlüsselt sind, die einen geheimen Schlüssel und den aktualisierten Wert des Rahmenzählers (50) als Eingabe in die Verschlüsselung verwendet.
Independent claims10
26 paragraphs in 6 sections, as filed
BACKGROUND OF THE INVENTION
FIELD OF THE INVENTION
The present invention relates to a method and apparatus for encoding security status information.
DESCRIPTION OF THE PRIOR ART
Low rate personal wireless networks are used with small devices with transmission speeds of up to 250 kilobits per second. These devices typically have severe power constraints as they are operated on batteries. In many of these devices, such as battery-operated sensors, remote controls, car door openers and light switches, it is necessary to have long battery life. If the batteries die too quickly then the replacement cost can be equal to the cost of the product itself.
It is also desirable to have secure communications between such constrained devices to prevent abuse of the system. One technique is to encrypt data being sent between the devices. Encryption mathematically transforms the transmitted information using a secret key known only to the two parties who are communicating. Without the key, the message is unintelligible. However, this requires overhead in the message structure in order to allow the recipient to decrypt the data. The sender must indicate which key it has used, which algorithm it has used to encrypt, and input parameters of the encryption algorithm such as a counter.
Usually, a frame counter is used as one of the input parameters for freshness in the encryption. Freshness means that the parameters change for each communication and are thus not reused. One type of encryption called a block cipher breaks up a message into parts (blocks) of a fixed size. Various block ciphers are known such as DES (Data Encryption Standard) and AES (Advanced Encryption Standard). Block ciphers often use an input block as a seed when used in stream-cipher mode. This input block should not repeat in order to maintain data freshness and data confidentiality. In one approach, a frame counter and a key identifier are used as the input block and are indicated in the message that is sent. In addition, each message usually includes a sequence counter that is not used for security but rather to match the sending of a message with the acknowledgement thereof by the recipient. These messages typically include a data portion referred to as the payload which is about 20 bytes. Accordingly, a five byte overhead for security information represents a 25% overhead.
For example, XP-02280534 and XP-02280537 ("<nplcit id="ncit0001" npl-type="s" url="URL:http://grouper.ieee.org/groups/802/15/pub/2001/Jan01/0 1034r0P802-15_TG3-MAC-Clause7-Draft-Text.doc"><text>Draft of Clause 7 for TG3-MAC" PROJECT: IEEE P802.15 WIRELESS PERSONAL AREA NETWORKS, 'Online! January (2001-01), pages 1-24, XP-02280534 retrieved from the Internet: <URL:http://grouper.ieee.org/groups/802/15/pub/2001/Jan01/0 1034r0P802-15_TG3-MAC-Clause7-Draft-Text.doc</text></nplcit>) both teach wireless Personal Area Network message formats which include a sequence control numbers denoting the message sequence.
The amount of data transferred between such constrained devices is one of the principal factors in their battery life. Accordingly, it is desirable to reduce the amount of information transferred.
However, in order to maintain the security of the underlying encryption methods, the number of bits in the frame counter should not be reduced.
SUMMARY OF THE INVENTION
The invention is defined by the appended claims.
In a further aspect, there is provided a wireless device as defined in claim 9.
In a yet further aspect, there is provided a wireless device as defined in claim 10.
BRIEF DESCRIPTION OF THE DRAWINGS
These and other features of the preferred embodiments of the invention will become more apparent in the following detailed description in which reference is made to the appended drawings wherein: <ul id="ul0001" list-style="none" compact="compact"><li><figref idref="f0001">Figure 1</figref> is a schematic representation of a communication system.</li><li><figref idref="f0001">Figure 2</figref> is a more detailed view of a correspondent in the communication system of <figref idref="f0001">Figure 1</figref>.</li><li><figref idref="f0002">Figure 3</figref> is a schematic representation of a message packet used by the correspondents of <figref idref="f0001">Figure 1</figref>.</li><li><figref idref="f0002">Figure 4</figref> is a schematic representation of another embodiment of a message packet.</li><li><figref idref="f0003">Figure 5</figref> is a schematic representation of an information exchange by the correspondents of <figref idref="f0001">Figure 1</figref>.</li><li><figref idref="f0003">Figure 6</figref> is a schematic representation of an information interchange among the corespondents of <figref idref="f0001">Figure 1</figref>.</li><li><figref idref="f0004">Figure 7</figref> is a schematic representation of the method used in <figref idref="f0003">Figure 6</figref>.</li><li><figref idref="f0005">Figure 8</figref> is a schematic representation of an information exchange between the correspondents of <figref idref="f0001">Figure 1</figref>.</li><li><figref idref="f0006">Figure 9</figref> is a schematic representation of the method used in <figref idref="f0005">Figure 8</figref>.</li><li><figref idref="f0007">Figure 10</figref> is a schematic representation of the method used in <figref idref="f0006">Figure 9</figref>.</li><li><figref idref="f0008">Figure 11</figref> is a schematic representation of another information exchange between the correspondents of <figref idref="f0001">Figure 1</figref>.</li></ul>
DESCRIPTION OF THE PREFERRED EMBODIMENTS
As may be seen in <figref idref="f0001">Figures 1 and 2</figref>, a communication system 10 consists of correspondents 12, 14, 16, and 18 communicating over a wireless network 20. Correspondent 12 includes a processor 22, a storage medium 24, a frame counter 26, a user interface 28. The processor 22 and storage 24 may be provided in an integrated circuit. The frame counter 26 is used as input to an encryption method in the processor 22. The user interface 28 may be provided by a simple switch and an LED or by more sophisticated means such as a keyboard and a monitor or other display. Each correspondent includes a wireless network interface 29 which sends and receives signals at a predetermined radio frequency such as 2.4GHz or 868 MHz/915 MHz. The correspondents can communicate directly with each other when they are in close enough proximity. The network 20 also provides wireless interfaces linked to routers, bridges, and other network hardware to provide connectivity beyond the range of wireless signals and to assist in establishing connections between physically close correspondents.
The correspondents exchange messages using packets in the format shown in <figref idref="f0002">Figure 3</figref> by the numeral 30. The packet consists of three portions: a header 32, a payload 40, and a footer 48. The header 32 contains a frame control portion 34, a sequence counter 36 which is notated as DSN and addressing fields 38. The payload portion 40 contains the actual content of the message, and includes security status information and data 46. The security status information 42, 44 includes a compressed frame counter 42 and a key identifier 44. The footer portion 48 of the packet 30 includes an error control sequence. As shown in <figref idref="f0001">Figure 2</figref>, the compressed frame counter 42 and the sequence counter 36 together form the frame counter 50.
In operation, the header is used to direct the packet to its intended address using the addressing fields. At the recipient, the footer is used to perform error correction and to ensure that the message has been received intact. In addition, the recipient may acknowledge the message. The acknowledgement will include the sequence counter DSN. The sequence counter is used to match sent messages with their acknowledgements. The security status information includes a frame counter which is used as input to a decryption method at the recipient. The decryption method is then used to decode the data and recover the original data sent by the sender.
In order to reduce the amount of information transferred, the frame counter is specially encoded. This encoding is accomplished by updating the frame counter N to a value of <i>N</i><sub>0</sub><i>≥ N</i> such that N<sub>0</sub> = min{N'≥ <i>N</i> such that <i>N'</i>= <i>DSN</i> mod 256}. The frame counter can then be represented as 3 byte encoded frame counter portion with the sequence counter DSN appended thereto. Accordingly, it is only necessary to transmit 3 bytes in the payload portion to communicate the frame counter rather than the full length of 4 bytes.
In another embodiment, further reduction in the information transferred may be achieved by omitting the frame counter altogether from the payload as seen in <figref idref="f0002">Figure 4</figref>. The sequence counter DSN is then used to recover the new value of the frame counter by combining the previous value of the frame counter 42 in storage 24 with the value of the sequence counter. In this embodiment, the message is compressed by removing the frame counter entirely.
Referring therefore to <figref idref="f0003">Figure 5</figref>, a simplified information exchange between one sender and one recipient is shown. The sender begins with a frame counter of 270. The sender transmits the frame counter 270 to the recipient. The recipient is then initialised to the beginning value of 270. For each further communication, the sequence counter is incremented. Accordingly, the next message has a sequence counter of 15 and a frame counter of 271. The sender sends the value of the sequence counter, which is 15 and equal to 271 mod 256, to the recipient. The recipient then updates the frame counter with the integer next larger to 270 which is congruent to 15 mod 256, in this case the value 271. Each sequential communication proceeds similarly with the sequence counter being incremented. Accordingly, the next transmission of a frame counter 272 is accomplished by transmitting the sequence counter of 16. The recipient may then recover the value 272 of the frame counter from the sequence counter 16 and the previous frame counter 271.
In typical use, the sender will be communicating with several recipients and accordingly the messages may be spaced out in time. There may be intervening messages to other recipients which necessitate incrementing the sequence control DSN between messages to any given recipient. Accordingly, the consecutive structure shown in <figref idref="f0003">Figure 5</figref> may not always be present. The communication may proceed as shown in <figref idref="f0003">Figure 6</figref> by the numeral 70. In this case, the frame counter begins at 7, which is sent to the first recipient which sets its frame counter to 7. In this example some time passes before the next message is transmitted to the first recipient. In this case, the next message is transmitted with a frame counter of 258 indicating that 250 other messages have been transmitted to other recipients by the sender in the interim. The value 258 is transmitted by sending the sequence counter, which is 258 mod 256 = 2. The recipient then recovers 258 as the integer next larger than 7 which is congruent to 2 mod 256. The next message is transmitted with a frame counter of 289 which is transmitted by sending the sequence counter of 33. However, in this case, the recipient does not acknowledge receipt of this message. The non-acknowledgement may occur for a number of reasons including simply not receiving the message or a failure in the error control. Accordingly, the recipient's frame counter remains at 258. Since the message is not acknowledged, the sender retransmits the full value 289 of the frame counter. This retransmission resets the frame counter at the recipient to the value 289 and the recipient acknowledges with the value 33 = 289 mod 256. The final message sent immediately following the third message is 290, which is communicated by sending the sequence counter of 34 which is 290 mod 256. The recipient updates its frame counter to 290 and acknowledges receipt of the value 34.
In the above example, the recipient always acknowledges messages from the sender. Accordingly, the sender is immediately notified that a message has not been received because it does not receive an acknowledgement. In this case, the sender can send a full message to resynchronise transmission.
Referring to <figref idref="f0004">Figure 7</figref>, the steps of the above method are shown generally by the numeral 80. The sender first sends a compressed message at step 82. The compressed message includes the value of the sequence counter and not the frame counter. Upon receipt of the compressed message, the recipient updates its frame counter as the minimum value larger than the current frame counter which is congruent to the sequence counter modulo 256. If the message is acknowledged at step 84 then execution continues. Otherwise, the sender repeatedly sends uncompressed messages at step 86 until one of these is acknowledged. The uncompressed messages include the frame counter. Upon receipt of the uncompressed message, the recipient updates its frame counter to the value of the frame counter in the uncompressed message. Once the message is acknowledged, the sender increments the sequence counter for the next message at step 88. It is particularly expedient to increment the sequence counter by 1, however it will be recognized that other method of updates the sequence counter may be used by the sender. The sender then establishes the frame counter for the next message as the minimum value larger then the current frame counter which is congruent to the sequence counter modulo 256.
In an alternative embodiment, the recipient does not acknowledge messages received. The sender continues to transmit regardless of whether the messages are actually received. Accordingly, it is necessary for the sender to occasionally send uncompressed messages containing the value of the frame counter in case a loss of synchronisation has occurred. Referring therefore to <figref idref="f0005">Figure 8</figref>, the messages transmitted by the sender are shown generally by the numeral 100. The first message reaches the recipient and accordingly both the sender and the recipient have frame counters of 7. However, the second message is lost during transmission. Accordingly, the recipient's frame counter is not updated. The third message is an uncompressed message and accordingly, updates the recipient's frame counter to 288, regardless of the earlier loss of synchronisation. The fourth message 289 is sent with the sequence counter of 33 and not the frame counter. This updates the recipient's frame counter to 289. The fifth message 547 is lost during the transmission, and accordingly the recipient's frame counter is incorrect. The next message 601 is transmitted as the sequence counter of 89, which results in an incorrect frame counter at the recipient since the computation yields the value 345 which is congruent to 89 modulo 256 but differs by 256 from the value of the frame counter in the sender. The incorrect frame counter results in a failure of decryption. Upon discovering the failure, the recipient maintains its frame counter of 289 rather than updating the frame counter to the incorrect value. The final message 805 is sent as an uncompressed message which updates the recipient's frame counter to the correct value again.
The steps performed in the example of <figref idref="f0005">Figure 8</figref> are shown schematically in <figref idref="f0006">Figure 9</figref> by the numeral 10. The sender first sends a compressed message at step 12. The sender then increments the sequence control at step 114 then updates the frame counter at step 116. The sender then checks to see if it is time for resynchronisation at step 118. Resynchronisation can be performed at periodic intervals such as every 2, 3, 4...., 10 transmissions. When the resync is required, the sender sends an uncompressed message at step 120, otherwise the sender proceeds to send compressed messages at step 112. It will be recognized that the sender independently decides which messages to send uncompressed. The sender cannot be guided by the recipient in this choice since there is no feedback from the recipient.
In a further embodiment, the recipient occasionally acknowledges messages. Furthermore, the sender may indicate in the header of a sent message that this message should be acknowledged. The recipient can therefore use such messages to indicate that a loss of synchronisation has occurred. Referring therefore to <figref idref="f0007">Figure 10</figref>, a transmission is shown by the numeral 130. The first message 7 is sent and is acknowledged by the recipient. Both the sender and the recipient have frame counters of 7. The second frame counter 258 is communicated by sending the sequence counter of 2 and is lost during transmission. The third message 288 is sent as the sequence counter of 32. The recipient acknowledges receipt of the sequence counter 32 however, during the subsequent decryption, the recipient has an error since its frame counter is out of sync with the sender since the reconstructed value is 32 rather than 288. Accordingly, the recipient enables an error flag. The next message 289 is sent as the sequence counter of 33, but is rejected by the recipient due to the error flag. Another message with a frame counter of 290 is sent to the recipient as the sequence counter of 34 and with a request for acknowledgement embedded in the message. When a recipient receives this message, it does not acknowledge since the error flag is set. Therefore, the sender resends the message with the frame counter of 290 as an uncompressed message which resynchronizes the frame counters of the sender and the recipient again. The recipient then acknowledges receipt of the message with frame counter 290. The error flag indicates that a decryption error occurred and that synchronization must be established by received an uncompressed message including the frame counter, rather than a compressed message without the frame counter. It will be recognized that loss of synchronization may occur in this embodiment, but the synchronization is re-established with a delay of at most one acknowledged message.
Referring to <figref idref="f0008">Figure 11</figref>, the steps of this embodiment are shown schematically by the numeral 140. The sender first sends a compressed message at step 142. The recipient then acknowledges receipt of the uncompressed message at step 144. The recipient attempts to decrypt the message at step 146. If there is a failure during decryption at step 148, then the recipient sets an error flag at step 150. If there is no failure and the error flag is set, then the recipient clears the error flag at step 152. The sender then sends another compressed message at step 154. When the recipient receives the message, it checks to see if the error flag is set at step 156. If the error flag is not set, then the recipient acknowledges the message at step 158 and proceeds with decryption by steps 146 onward. If the flag is set, then the recipient does not acknowledge the message at step 160. If the message was sent with an acknowledgement request at step 162, then the sender detects this and sends an uncompressed message at step 164, and execution returns to the decryption step 146. If no acknowledgement request was sent, then the sender proceeds to send compressed messages at step 154.
It will be recognised that in these embodiments, a reduction in the amount of data transferred is achieved. The reduction is realized by maintaining frame counters at both the sender and the recipient. The inventor has recognized that the recipient can reconstruct the correct value of the frame counter from partial information received from the sender in combination with the recipient's local copy of the information. Furthermore, a recovery mechanism is provided which re-synchronizes frame counters that end up out-of-synchronization. It will be recognized that the recovery mechanism allows the compression technique to be applied in a robust manner.
It will be recognized that the above techniques are not limited to use with integers but rather may be used with counters that are elements of a finite set with a partial ordering. Furthermore, although the technique has been described in the particularly advantageous setting of a cryptographic system, it may be applied in other settings where counters are used and where a reduction in communication cost is at a premium. One example of such a setting is the inclusion of frame counters to facilitate detection of duplicate transmission.
Contents6
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
19 members in 5 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 431078P | United States of America | – | |
| 43107802 | United States of America | P | |
| 43107802 | United States of America | P | |
| 431645P | United States of America | – | |
| 43164502 | United States of America | P | |
| 43164502 | United States of America | P | |
| 0301879 | Canada | W | |
| 0301879 | Canada | W | |
| 431078P | – | – | – |
| 431645P | – | – | – |
| CA2003001879 | – | – | – |
| US20020431078P | – | – | – |
| US20020431645P | – | – | – |
| WO2003CA01879 | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| CA2508485A1 | Canada | A1 | |
| WO2004051956A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003287811A1 | Australia | A1 | |
| US2004136527A1 | United States of America | A1 | |
| WO2004051956A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1570623A2 | European Patent Office (EPO) | A2 | |
| US7600038B2 | United States of America | B2 | |
| US2009316902A1 | United States of America | A1 | |
| CA2508485C | Canada | C | |
| US8855308B2 | United States of America | B2 | |
| US2016366103A1 | United States of America | A1 | |
| US10063524B2 | United States of America | B2 | |
| US2018367512A1 | United States of America | A1 | |
| EP1570623B1This record | European Patent Office (EPO) | B1 | |
| EP3525416A1 | European Patent Office (EPO) | A1 | |
| US10673829B2 | United States of America | B2 | |
| US2020274857A1 | United States of America | A1 | |
| EP3525416B1 | European Patent Office (EPO) | B1 | |
| US11323421B2 | United States of America | B2 |
79 legal events, as 8 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20240530 AND 20240605732E | 732E | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Patent expired because of reaching the maximum lifetime of a patentExpiredMK | MK | NL | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0029060000R079 | R079 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20200206 AND 20200212732E | 732E | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Change of ownershipPD | PD | NL | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Deletion acc. to par. 5 (withdrawal of the translation of the ep patent)MK05 | MK05 | AT | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Translation for ep filed (entry of ep into country)FP | FP | NL | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Change of applicant/patenteeR081 | R081 | DE | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1570623
- Publication, DOCDB
- 1570623
- Publication, EPODOC
- EP1570623
- Application
- 37796083
- Application, DOCDB
- 03779608
- Application, EPODOC
- EP20030779608
Titles3
- German
- METHOD UND GERÄT ZUR VERSCHLÜSSELUNG VON SICHERHEITSSTATUSINFORMATION
- English
- METHOD AND APPARATUS FOR ENCODING SECURITY STATUS INFORMATION
- French
- PROCEDE ET APPAREIL DE CODAGE D'INFORMATIONS D'ETAT DE SECURITE
Classification
- CPC, 20
- H04L63/0428
- H04L1/1803
- H04L1/1812
- H04L1/1867
- H04L47/34
- H04W56/0015
- H04W12/033
- H04L9/40
- H04L63/0435
- H04W4/12
- H04W12/02
- H04W24/00
- H04W28/04
- H04W28/06
- H04L67/04
- H04L67/12
- H04L69/329
- H04L63/06
- H04L2209/80
- H04W12/04
- IPC, 5
- H04L29 06
- H04L1 18
- H04L12 801
- H04W56 00
- H04L29 08
Designated states27
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye
