EP1793525A1

Method for changing the group key in a group of network elements in a network

Abstract

The method involves joining a new network unit to a group of network units (P 1-P 4) during changing a configuration of the group of network units. A renewal of a group key is implemented, where a network unit selected from the group of network units generates a new group key, which is transmitted to network units of the group in an altered configuration. The selected network unit with the network units executes a key exchange according to the Diffie-Hellman principle for transmitting the new key group.

EP1793525A1, drawing sheet 1
Sheet 1 of 35

Term

Term ended

Projected expiry passed 1 December 2025, 0.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

16 claims: 5 independent, 11 dependent

  1. 1
    Method for changing a group key GK for secure data exchange in a group of network elements P 1 ... P n ( n = 2, 3, ...) in a network system having a closed peer-to-peer configuration and a virtual synchronity-supporting group communication protocol in a communication layer of a system architecture of the network system, wherein when a composition of the group of network elements changes P 1 ... P n . by adding a new network element P n + 1 to the group of network elements P 1 ... P n added or by adding a network element P v (1 ≤ ν ≤ n) the group of network elements P 1 ... P n a group key renewal is performed, in which one of the group of network elements P 1 ... P n selected network element P i * (1 ≤ i ≤ n) a new group key GK New generated and the new group key GK New from the selected network element P i to all other network elements P k (1 ≤ k ≤ n + 1, 1 ≤ k ≤ n, k ≠ i, k ≠ v) the group of network elements P 1 ... P n in the modified composition is transmitted by the selected network element P i * with all other network elements P k a key exchange according to the Diffie-Hellman principle for transmitting the new group key GK New performs.
  2. 6
    Method according to one of the preceding claims, characterized in that Group key renewal is performed using the IKEv2 (Internet Key Exchange Protocol) protocol.
  3. 8
    Method according to one of the preceding claims, characterized in that on the addition of the new network element P n + 1 to the group of network elements P 1 ... P n authentication of the new network element before the group key renewal P n + 1 is carried out.
  4. 14
    Method according to one of the preceding claims, characterized in that when leaving the network element P v the group key renewal in a similar way as when the new network element is added P n + 1 is carried out.
  5. 16
    Method according to one of the preceding claims, characterized in that the new group key GK New in a data communication between the plurality of network elements P i in the network system for exchanging video and / or audio and / or text data.