Nova Patents
EP1762080A1

Access control over multicast

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 22 June 2025, 1.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

1 claim: 1 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2006000566 A1 Claims [001] 1. A multicast host for communicating information published about any one of a set of topics to one or more authorised subscribers to those topics, the set of topics being partitioned into one or more partition elements, each partition element having a partition element encryption key associated therewith, wherein each of the one or more partition elements is a disjoint proper subset of the set of topics, the host comprising:means for receiving information relating to a topic;means for determining a partition element for the topic;means for retrieving a partition element encryption key associated with the partition element;means for encrypting the information with the retrieved partition element encryption key;and means for communicating the information to the one or more authorised subscribers. [002] 2. The multicast host of claim 1 wherein each disjoint proper subset of the set of topics is defined in accordance with an access control list. [003] 3. The multicast host of claim 2 wherein the access control list includes a definition of a plurality of roles. [004] 4. The multicast host of claim 3 wherein each of the plurality of roles is a subset of the set of topics. [005] 5. The multicast host of claim 4 wherein each disjoint proper subset of the set of topics is defined to be one of a set difference and an intersect of the plurality of roles. [006] 6. The multicast host of claim 1 further comprising means for securely com¬ municating the partition element encryption key to the one or more subscribers. [007] 7. The multicast host claim 6 wherein the partition element encryption key is securely communicated by encrypting the partition element encryption key. [008] 8. The multicast host of claim 7 wherein the partition element encryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more authorised subscribers. [009] 9. The multicast host of claim 1 further comprising means for securely com¬ municating a partition element decryption key to the one or more authorised subscribers, wherein the partition element decryption key corresponds to the partition element encryption key. [010] 10. The multicast host of claim 9 wherein the partition element decryption key is securely communicated by encrypting the partition element decryption key. [011] 11. The multicast host of claim 10 wherein the partition element decryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more authorised subscribers. [012] 12. The multicast host of claim 1 further comprising: means for receiving a new subscription to a topic in a partition element;and means for generating a new partition element encryption key for a partition element. [013] 13. The multicast host of claim 12 further comprising means for generating a new partition element decryption key corresponding to the new partition element encryption key. [014] 14. The multicast host of claim 1 further comprising: means for receiving a cancelled subscription to a topic in a partition element;and means for generating a new partition element encryption key for a partition element. [015] 15. The multicast host of claim 14 further comprising means for generating a new partition element decryption key corresponding to the new partition element encryption key. [016] 16. A multicast system comprising: a multicast host according to claim 1 ;andone or more multicast subscribers for receiving information communicated by the multicast host. [017] 17. The multicast system of claim 16 further comprising: one or more publishers for publishing information about any one of a plurality of topics. [018] 18. A method for communicating information published about any one of a set of topics to one or more authorised subscribers to those topics, the set of topics being partitioned into one or more partition elements, each partition element having a partition element encryption key associated therewith, wherein each of the one or more partition elements is a disjoint proper subset of the set of topics, the host comprising: receiving information relating to a topic;determining a partition element for the topic;retrieving a partition element encryption key associated with the partition element;encrypting the information with the retrieved partition element encryption key;and communicating the information to the one or more authorised subscribers. [019] 19. The method of claim 18 wherein each disjoint proper subset of the set of topics is defined in accordance with an access control list. [020] 20. The method of claim 19 wherein the access control list includes a definition of a plurality of roles. [021] 21. The method of claim 20 wherein each of the plurality of roles is a subset of the set of topics. [022] 22. The method of claim 21 wherein each disjoint proper subset of the set of topics is defined to be one of a set difference and an intersect of the plurality of roles. [023] 23. The method of claim 18 further comprising securely communicating the partition element encryption key to the one or more subscribers. [024] 24. The method claim 23 wherein the partition element encryption key is securely communicated by encrypting the partition element enciyption key. [025] 25. The method of claim 24 wherein the partition element encryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more authorised subscribers. [026] 26. The method of claim 18 further comprising securely communicating a partition element decryption key to the one or more authorised subscribers, wherein the partition element decryption key corresponds to the partition element encryption key. [027] 27. The method of claim 26 wherein the partition element decryption key is securely communicated by encrypting the partition element decryption key. [028] 28. The method of claim 27 wherein the partition element decryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more authorised subscribers. [029] 29. The method of claim 18 further comprising: receiving a new subscription to a topic in a partition element;and generating a new partition element encryption key for a partition element. [030] 30. The method of claim 29 further comprising means for generating a new partition element decryption key corresponding to the new partition element encryption key. [031] 31. The method of claim 18 further comprising: receiving a cancelled sub¬ scription to a topic in a partition element;and generating a new partition element encryption key for a partition element. [032] 32. The method of claim 31 further comprising means for generating a new partition element decryption key corresponding to the new partition element encryption key. [033] 33. A computer program comprising computer program code which, when executed on a data processing system, instructs the data processing system to carry out the method as claimed in claim 18. [034] 34. A computer program product stored on a computer usable medium, the computer program product for communicating information published about any one of a set of topics to one or more authorised subscribers to those topics, the set of topics being partitioned into one or more partition elements, each partition element having a partition element encryption key associated therewith, wherein each of the one or more partition elements is a disjoint proper subset of the set of topics, the computer program product comprising: computer readable program means for receiving information relating to a topic;computer readable program means for determining a partition element for the topic;computer readable program means for retrieving a partition element encryption key associated with the partition element;computer readable program means for encrypting the in¬ formation with the retrieved partition element encryption key;and computer readable program means for communicating the information to the one or more authorised subscribers. [035] 35 A multicast host for communicating information published about any one of a plurality of topics to subscribers to those topics, each topic having a topic encryption key associated therewith, the host comprising: means for receiving in¬ formation relating to a topic;means for accessing subscriber data representing one or more users subscribed to the topic;means for retrieving a topic encryption key associated with the topic;means for encrypting the information with the retrieved topic encryption key;and means for communicating the information to the one or more users. [036] 36 The multicast host of claim 35 further comprising means for securely com¬ municating the topic encryption key to the one or more subscribers. [037] 37.The multicast host claim 36 wherein the topic key is securely communicated by encrypting the topic encryption key. [038] 38 The multicast host of claim 37 wherein the topic encryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more users. [039] 39 The multicast hostrof claim 35 further comprising means for securely com- !.r- municating a topic decryption key to the one or more subscribers, wherein the topic decryption key corresponds to the topic encryption key. [040] 40 The multicast host of claim 39 wherein the topic decryption key is securely communicated by encrypting the topic decryption key. [041] 41 The multicast host of claim 40 wherein the topic decryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more users. [042] 42 The multicast host of claim 35 further comprising: means for receiving a new subscription to a topic;and means for generating a new topic encryption key for the topic. [043] 43 The multicast host of claim 42 further comprising means for generating a new topic decryption key corresponding to the new topic encryption key. [044] 44 The multicast host of claim 35 further comprising: means for receiving in¬ formation relating to a new topic;and means for generating a topic encryption key for the new topic. [045] 45 The multicast host of claim 44 further comprising means for generating a topic decryption key corresponding to the topic encryption key for the new topic. [046] 46 The multicast host of claim 35 further comprising: means for receiving a cancelled subscription to a topic;and means for generating a new topic encryption key for the topic. [047] 47 The multicast host of claim 46 further comprising means for generating a new topic decryption key corresponding to the new topic encryption key. [048] 48 A multicast system comprising: a multicast host according to claim 35;and one or more multicast subscribers for receiving information communicated by the multicast host. [049] 49 The multicast system of claim 48 further comprising: one or more publishers for publishing information about any one of a plurality of topics. [050] 50 A method for communicating information published about any one of a plurality of topics to subscribers to those topics, each topic having a topic encryption key associated therewith, the method comprising: receiving in¬ formation relating to a topic;accessing subscriber data representing one or more users subscribed to the topic;retrieving a topic encryption key associated with the topic;encrypting the information with the retrieved topic encryption key;and communicating the information to the one or more users. [051 ] 51 The method of claim 150 further comprising securely communicating the topic encryption key to the one or more subscribers. [052] 52 The method of claim 50 wherein the topic key is securely communicated by in* encrypting the topic encryption key. ιρ [053] 53 The method of claim 52 wherein the topic encryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more users. [054] 54 The method of claim 50 further comprising securely communicating a topic decryption key to the one or more subscribers, wherein the topic decryption key corresponds to the topic encryption key. [055] 55 The method of claim 54 wherein the topic decryption key is securely com¬ municated by encrypting the topic decryption key. [056] 56 The method of claim 55 wherein the topic decryption key is encrypted using a logical key hierarchy in which a logical key corresponds to the one or more users. [057] 57 The method of claim 50 further comprising: receiving a new subscription to a topic;and generating a new topic encryption key for the topic. [058] 58 The method of claim 57 further comprising generating a new topic decryption key corresponding to the new topic encryption key. [059] 59. The method of claim 50 further comprising: receiving information relating to a new topic;and generating a topic encryption key for the new topic. [060] 6O.The method of claim 59 further comprising means for generating a topic decryption key corresponding to the topic encryption key for the new topic. [061] 61. The method of claim 50 further comprising: receiving a cancelled sub¬ scription to a topic;and generating a new topic encryption key for the topic. [062] 62 The method of claim 61 further comprising means for generating a new topic decryption key corresponding to the new topic encryption key. [063] 63 A computer program product comprising computer program code stored on a computer readable storage medium which, when executed on a data processing system, instructs the data processing system to carry out the method as claimed in claim 50. [064] 64 A computer program product stored on a computer usable medium, the computer program product for communicating information published about any one of a plurality of topics to subscribers to those topics, each topic having a topic encryption key associated therewith, the computer program product comprising: computer readable program means for receiving information relating to a topic;computer readable program means for accessing subscriber data rep¬ resenting one or more users subscribed to the topic;computer readable program means for retrieving a topic encryption key associated with the topic;computer readable program means for encrypting the information with the retrieved topic encryption key;and computer readable program means for communicating the information to the one or more users.