Method and system for dynamically constructing and controlling short-lived communication groups with secure transmission
15 claims: 2 independent, 13 dependent
- 1Verfahren zum dynamischen Aufbau und zur Steuerung von kurzzeitig gebildeten Kommunikationsgruppen mit gesicherter Übertragung, wobei potentiell an einer Kommunikationsgruppe teilnehmende Knoten (KN) über ein gemeinsames Übertragungsmedium (UT) verbunden sind, von welchem eine effiziente Übertragung von Broadcast- und/oder Multicast-Nachrichten (BC, MC) zwischen den Knoten (KN) ermöglicht wird, dadurch gekennzeichnet, dass der dynamische Aufbau einer Kommunikationsgruppe durch einen Initiator-Knoten (IKN) in folgenden Schritten erfolgt:- Versenden einer Broadcast-Nachricht (BC), welche zumindest eine Gruppenkennung (Group-ID), eine Kennung (ID1) des Initiator-Knotens (IKN), Information (Group-Info) über die Kommunikationsgruppe und eine Adresse (ADR1) des Initiator-Knotens (IKN) enthält, an alle mit dem Intiator-Knoten (IKN) über das gemeinsame Übertragungsmedium (UT) verbundenen Knoten (KN) (12), - Analyse der empfangenen Broadcast-Nachricht (BC) durch die über das gemeinsame Übertragungsmedium (UT) erreichbaren Knoten (KN), wobei der Initiator-Knoten (IKN) von diesen authentifiziert wird (12), - Zurücksenden einer ersten Unicast-Nachricht (UC1) durch an der Kommunikationsgruppe teilnehmende Knoten (KN) an den Initiator-Knoten (IKN), wobei die Unicast-Nachricht (UC1) zumindest eine Kennung (ID2) und eine Adresse (ADR2) des teilnehmenden Knoten (KN) enthält (13), - Empfang dieser ersten Unicast-Nachrichten (UC1) und Authentifizierung der teilnehmenden Knoten (KN) durch den Initiator-Knoten (IKN) (13), - Versand einer zweiten Unicast-Nachricht (UC2), welche zumindest eine Multicast-Kennung (MC-ID) sowie einen Sicherheitsschlüssel (SEC) umfasst, an jeden an der Kommunikationsgruppe teilnehmenden Knoten (KN) durch den Initiator-Knoten (IKN) (14).
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass für einen synchronisierten Start der Kommunikationsgruppe vom Initiator-Knoten (IKN) eine spezielle, verschlüsselte Multicast-Nachricht (MC) an alle an der Kommunikationsgruppe teilnehmenden Knoten (KN) versendet wird.
- 3Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass vom Initiator-Knoten (IKN) die Kennungen aller an der Kommunikationsgruppe teilnehmenden Knoten (KN) an alle an der Kommunikationsgruppe teilnehmenden Knoten (KN) versendet werden.
- 4Verfahren nach Anspruch 1, dadurch gekennzeichnet, - dass für eine laufende Erweiterung einer bestehenden Kommunikationsgruppe vom Initiator-Knoten (IKN) in periodischen Abständen eine Broadcast-Nachricht (BC), welche zumindest eine Gruppenkennung (Group-ID), eine Kennung (ID1) des Initiator-Knotens (IKN), Information (Group-Info) über die Kommunikationsgruppe und eine Adresse (ADR1) des Initiator-Knotens (IKN) enthält, über das gemeinsame Übertragungsmedium (UT) versandt wird, - dass von Knoten (KN), um der bestehenden Kommunikationsgruppe beizutreten, eine erste Unicast-Nachricht (UC1), welche zumindest eine Kennung (ID2) und eine Adresse (ADR2) des teilnehmenden Knoten (KN) enthält, an den Initiator-Knoten (IKN) gesendet wird - und dass dann diese Knoten (KN) vom Initiator-Knoten (IKN) authentifiziert werden und eine zweite Unicast-Nachricht (UC2), welche zumindest die Multicast-Kennung (MC-ID) sowie den Sicherheitsschlüssel (SEC) der Kommunikationsgruppe umfasst, an diese Knoten (KN) gesendet wird.
- 5Verfahren nach einem der Ansprüche 1 bis 3, dadurch gekennzeichnet, dass - von einem Knoten (KN1), von welchem die Kommunikationsgruppe verlassen wird, eine dritte spezielle Unicast-Nachricht (UC3), welche zumindest seine Kennung (ID3) umfasst, an den Initiator-Knoten (IKN) gesendet wird (21, 22), - dass dann vom Initiator-Knoten (IKN) nach Empfang dieser dritte Unicast-Nachricht (UC3) der entsprechende Knoten (KN1) authentifiziert und die zu diesem Knoten (KN1) gehörenden Informationen gelöscht werden (23), - dass dann vom Initiator-Knoten (IKN) ein neuer Sicherheitsschlüssel (nSEC1) generiert und dieser verschlüsselt mittels einer vierten Unicast-Nachricht (UC4) an jeden in der Kommunikationsgruppe verbleibenden Knoten (KN2) gesendet wird (24).
- 6Verfahren nach Anspruch 5, dadurch gekennzeichnet, dass in der vierten Unicast-Nachricht (UC4) gemeinsam mit dem neuen Sicherheitsschlüssel (nSEC1) Informationen über den Knoten (KN1), von welchem die Kommunikationsgruppe verlassen worden ist, versendet werden (24).
- 7Verfahren nach Anspruch 5, dadurch gekennzeichnet, dass beim Verlassen der Kommunikationsgruppe durch einen Knoten (KN1) neben dem Sicherheitsschlüssel (nSEC1) auch die Multicast-Kennung (MC-ID) und/oder die Gruppenkennung geändert werden.
- 8Verfahren nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass - vom Initiator-Knoten(IKN), von welchem die Kommunikationsgruppe verlassen wird, eine spezielle Multicast-Nachricht (MC), welche zumindest seine Kennung (ID4) und eine Anfrage nach Funktionstransfer umfasst, an alle an der Kommunikationsgruppe teilnehmenden Knoten (nIKN, KN3) versendet wird (31), - dass von allen jenen Knoten (nIKN), von welchen eine Initiator-Funktion übernommen wird, eine fünfte spezielle Unicast-Nachricht (UC5), welche zumindest ihre Kennung (ID5) enthält, an den Initiator-Knoten (IKN) gesendet wird (32), - dass nach dem Empfang dieser fünften Unicast-Nachricht (UC5) und der Authentifizierung der antwortenden Knoten (nIKN) vom Initiator-Knoten (IKN) nach einer vorgegebenen Verfahrensweise aus diesen antwortenden Knoten (nIKN) ein neuer Initiator-Knoten gewählt wird (33), - dass dann mittels einer sechsten Unicast-Nachricht (UC6) Informationen über die Kommunikationsgruppe und über die teilnehmenden Knoten (KN3) vom Initiator-Knoten (IKN) an den neuen Initiator-Knoten (nIKN) übertragen werden (34), - dass dann vom neuen Initiator-Knoten (nIKN) die Initiator-Funktion übernommen und ein neuer Sicherheitsschlüssel (nSEC2) generiert wird (36), welcher mittels einer siebenten Unicast-Nachricht (UC7) verschlüsselt und gemeinsam mit Informationen über den neuen Initiator-Knoten (nIKN) an jeden in der Kommunikationsgruppe vorhandenen Knoten (KN3) gesendet wird (37).
- 9Verfahren nach einem der Ansprüche 1 bis 7, dadurch gekennzeichnet, dass während des Aufbaus und/oder beim Verlassen der Kommunikationsgruppe ein asymmetrisches Kryptosystem verwendet wird.
- 10Verfahren nach einem der Ansprüche 1 bis 7, dadurch gekennzeichnet, dass innerhalb der Kommunikationsgruppe ein symmetrisches Kryptosystem verwendet wird.
- 11Verfahren nach einem der Ansprüche 1 bis 9, dadurch gekennzeichnet, dass als gemeinsames Übertragung-medium (UT) ein Medium der Sicherungsschicht (Data Link Layer) verwendet wird.
- 12Verfahren nach einem der Ansprüche 1 bis 10, dadurch gekennzeichnet, dass als gemeinsames Übertragungs-medium (UT) ein Funkübertragungskanal verwendet wird.
- 13Verfahren nach einem der Ansprüche 1 bis 11, dadurch gekennzeichnet, dass als gemeinsames Übertragungsmedium (UT) ein Datenbus verwendet wird.
- 14Verfahren nach einem der Ansprüche 1 bis 12, dadurch gekennzeichnet, dass die Broadcast-, Multicast- und die Unicast-Nachricht unter Verwendung des Ethernet (IEEE802.3)-Standards oder des Wireless Local Area Network (WLAN, IEEE802.11)-Standards gesendet werden.
- 15Initiator-Knoten (IKN) zum dynamischen Aufbau und zur Steuerung von kurzzeitig gebildeten Kommunikationsgruppen mit gesicherter Übertragung, dadurch gekennzeichnet, dass zumindest folgende logische Komponenten vorgesehen sind:- eine zentrale Verwaltungseinrichtung (CPC) zur Interaktion mit Applikationen, Komponenten oder Benutzern des Knotens (KN) und zum Kontrollieren und Bearbeiten von Nachrichten, welche zwischen den an einer Kommunikationsgruppe teilnehmenden, über ein gemeinsames Übertragungsmedium (UT) verbundenen, Knoten (KN) ausgetauscht werden, - eine Einrichtung (PM) zum Managen und zum Speichern verschiedener Vorgehensweisen in Bezug auf Einrichten und Steuern von Kommunikationsgruppen, - eine Gruppen-Informationsmanagement-Einrichtung (GIM) zum Verwalten und Speichern aller Informationen über jene Kommunikationsgruppen, an welchen vom Initiator-Knoten (IKN) teilgenommen wird, - eine Einrichtung (KG) zum Generieren der Sicherheitsschlüssel (SEC, nSEC1, nSEC2) für eine gesicherte Übertragung von Nachrichten innerhalb der Kommunikationsgruppe, - eine Nachrichtenerzeugungseinrichtung (MB) zum Erzeugen von Broadcast-, Multicast- und Unicast-Nachrichten, - eine Nachrichtenübertragungseinrichtung (MT) zum Übertragen von Broadcast-, Multicast- und Unicast-Nachrichten, wobei - die zentrale Verwaltungseinrichtung (CPC) ausgebildet ist zur Triggerung einer Broadcast-Nachricht (BC) für die Nachrichtenerzeugungseinrichtung (MB), welche zumindest eine Gruppenkennung (Group-ID), eine Kennung (ID1) des Initiator-Knotens (IKN), Information (Group-Info) über die Kommunikationsgruppe und eine Adresse (ADR1) des Initiator-Knotens (IKN) enthält, - wobei die Nachrichtenübertragungseinrichtung (MT) die Broadcast-Nachricht (BC) an alle mit dem Initiator-Knoten (IKN) über das gemeinsame Übertragungsmedium (UT) verbundenen Knoten (KN) übertragt, - eine Nachrichtenempfangseinrichtung (MR) zum Empfangen von Broadcast-, Multicast- und Unicast-Nachrichten vom Übertragungsmedium (UT), - und eine Verarbeitungseinrichtung (IMA) zum Analysieren der ankommenden Broadcast-, Multicast- und Unicast-Nachrichten und der von diesen beinhalteten Informationen.
Independent claims15
79 paragraphs, as filed
p0001The work that led to this invention were funded under the grant agreement no. 027 662 in the Seventh Framework Programme of the European Community (FP7 / 2007-2013).
p0002The invention relates to a method and apparatus for dynamically build and control of temporarily formed communications groups with secure transmission, potentially in a communications group participating nodes are connected via a common transmission medium. From this transfer medium then an efficient transmission of so-called broadcast and / or multicast messages is made possible.
p0003Currently, more and more different types are designed, developed and used by mobile and wireline communication networks in the telecommunications sector. It is understood a generic term for all resources by definition under a communications network, from which users services are provided with service features for communication purposes or for transmitting data.
p0004In order to provide the users of these services, regardless of their current location available, is a collaboration between communications networks such as Personal Area Networks (PAN), which, for example, devices such as PDAs or mobile phones ad hoc using wired transmission technologies (eg USB, FireWire, etc.) or by wireless techniques (eg, IrDA, Bluetooth, etc.) can be degraded and, Body Area networks (BAN), sensor Area networks (SAN), etc. necessary. formed communications networks and as well as devices such as PDAs, mobile phones, laptops, etc. so-called communication groups for various purposes - such as: when is established by a group of passengers on a train a local communications group by their PANs to an electronic game to play together; when forming a communication group for discussion purposes during a trade fair of experts with different locations on a fairground with her electronic equipment (eg, laptop, PDA, etc.); when an employee of a company, for example, from different areas with their electronic equipment (eg, laptop, PDA, etc.) form a dynamic communication group to a random event (eg expiry editors triggered by a software program, etc.) to observe and discuss or if in a departure lounge of an international airport by some passengers a communication group is formed in order to exchange information on destinations etc..
p0005All these exemplary scenarios are some characteristics in common:<ul><li>participating in a communications group nodes need each other before construction of this communication group not necessarily know (eg IDs, electronic addresses, security keys, etc. are not known beforehand), then exchange information such as within the communication group formed. The term "node" refers not only to a terminal used by a user, such as PDA, laptop, mobile phone, computer, etc. as well as a communication network such as PAN, BAN, SAN, etc., which, more than one device (eg, laptop, PDA mobile phone, etc.) includes.</li><li>A node or the equipment used for communication has only a limited range. In addition, the nodes are connected via a common transmission medium, such as through an Ethernet link or within one served by an access point to a wireless LAN area.</li><li>A presence of general infrastructure services, as they are made available, for example from the Internet, can not be assumed.</li><li>The communication group is built dynamically when needed and there for a relatively short time.</li><li>The communication within the communications group is carried out according to the peer-to-peer principle and the transmission should be backed up - ie eavesdropping taking place within the communication group communication through a non-participating in the communications group node should not be possible.</li><li>The construction and control of the communication group should be made dynamically and automatically, as in the participating users usually have little or no experience in the field of network management can be purposed.</li></ul>
p0006Furthermore, it is necessary that the transmission medium to which the nodes are connected, an efficient mechanism for the transfer of so-called broadcast and multicast messages will be provided, on the one hand can not be predicted which number attend nodes in a communications group becomes. On the other hand, the communication may take place within the communications group also from one node to all other nodes of the communication group - for example, if a node is a communication group is started to invite other nodes to a video information with discussion.
p0007Broadcast, some are known under the term "broadcast" refers to the transmission of an electronic message or content of identical copies of this message from a sending node to all nodes of a communications network or several collaborating communications networks. A so-called broadcast message is then used mainly in communications networks, if the address of the receiving node are not known yet. Also broadcast messages for easy transfer of information to all nodes of a communications network or several collaborating communications networks are used. From each node from which a broadcast message is received, then the message must be received and decide whether the message needs to be processed by it. If no jurisdiction is recognized for this message from the receiving node, the message is discarded.
p0008Multicast, which is also known under the term "group", transmitting an electronic message or content of identical copies of this message from a sending node is understood to a group of receiving nodes.
p0009When a message is point-to-point - that is transmitted from a sending node to a receiving node, then this message is also called a unicast message.
p0010The advantage of broadcast or multicast messages is that a message can be sent to all nodes of a communication network or on multiple nodes or all nodes in a group simultaneously. This means that on the side of the transmitting node as a rule only a bandwidth is required, which is identical to that when sending the electronic message to a single recipient. It is therefore in broadcast or multicast messages not necessary that the bandwidth required by the number of receiving nodes is scaled, particularly when the messages are transmitted via a common transmission medium.
p0011In general, the question arises, rapid visual communications groups with secure transmission dynamically as required, in the most efficient manner - can be built and controlled - starting from a node - a so-called initiator node.
p0012From the <patcit id="pcit0001" dnum="EP0952718A2"><text>EP-A2-0 952 718</text></patcit> is known an efficient and secure multicast method. For this purpose, a node is used to build and control of temporarily formed communications groups with secure transmission.
p0013an automatic and dynamic structure, as well as a control of temporarily formed communications groups and secure transmission of multicast messages within the communication groups are taken in the prior art does not support. The structure of communication groups is currently carried out statically, ie a corresponding registration of the nodes is necessary before the establishment of the communication group to exchange information, for example in the form of multicast messages. This registration (eg notification of identification and address of the node) must usually be performed by the user prior to participating in the communication group, often specific technical know-how is purposed.
p0014Existing methods for transmitting broadcast or multicast messages, such as from the document "<nplcit id="ncit0001" npl-type="s"><text>3GPP TS 22.146 V7.1.0 (2006-03); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Multimedia Broadcast / Multicast; Stage 1 (Release 7)</text></nplcit>"Known methods are generally based on that a so-called multicast identifier, which is also referred to as a multicast address, defined and a group is assigned to nodes. It is necessary that all the sending and receiving nodes, the information on have the multicast identifier. For this reason, a registry of all participating in a communications group node before the start of this communication group is required for transmission of multicast messages can be carried out within the group.
p0015Such methods are therefore suitable essentially only for static applications, such as television or radio broadcasts, which also require a medium to long-term membership of nodes for communication group. In such applications, it is for a transmitting node normally not necessary to have information about the properties of the receiving node. Furthermore, in these applications, it is also not necessary to make sure from the perspective of a transmitting node, all receiving nodes can actually receive a transmitted multicast message and that the transmission of this message is carried out in a secure manner.
p0016For these reasons, the method described above in its application for the automatic and dynamic configuration and control of temporarily formed communications groups are unsuitable, within which is to be the transmission of messages in a secure manner and these messages are also safely received by the participating nodes , Through the need for prior registration of which also an existence of general infrastructure services and is possibly provided by specific technical know-how, it is not possible to form a communication group spontaneously and, if necessary for a short time in a simple manner.
p0017The present invention is therefore an object to provide an efficient method and apparatus by which a short time communication can be set up automatically and dynamically with secure transmission in an efficient and simple manner when required.
p0018The object is achieved by a method of the initially defined type, wherein the dynamic structure of a communication group is performed by an initiator node in the following steps:<ul><li>Sending a broadcast message which contains at least one group identifier, an identifier of the initiator node, information about the communications group and an address of the initiator node to all connected with the FlexMax node via the common transmission medium node</li><li>Analysis of the received broadcast message by the reachable via the common transmission medium node, the initiator node is authenticated by these,</li><li>Returning a unicast message by participating in the communications group node to the initiator node, wherein the Unicast message includes at least one identifier and an address of the participating nodes,</li><li>Receiving this unicast messages and authenticate the participating nodes by the initiator node,</li><li>Sending a unicast message, which includes at least one multicast identification and a security key, to each participating in the communications group nodes by the initiator node.</li></ul>
p0019The main aspect of the inventively proposed solution is that the structure of the communication group is performed dynamically and automatically. It is not assumed that node, from which participated in the communication group, must be informed of group-specific information such as multicast identification or security keys before the assembly and launch of the communication group, whereby no complicated registration, in which not infrequently specific know-how is assumed to be performed by the user. In addition, multicast messages can be sent through the common multicast identifier and the common security key within the communications group in a simple manner and in a secure manner.
p0020It is advantageous if a special encrypted multicast message to all participating in the communications group node will be shipped for a synchronized start of the communication group from the initiator node. In certain applications, such as transmission of video information or discussion groups with determinate time frame, can thus in a simple manner by all group members are informed about the start of the communication group.
p0021It is advantageous if the initiator node identifiers of all participating in the communications group nodes are sent to all participating in the communications group nodes, hence unicast messages are sent selectively and easily to other participating nodes of participating nodes.
p0022Further recommended if for an ongoing expansion of an existing communication group from the initiator node at periodic intervals a broadcast message containing at least one group identifier, an identifier of the initiator node, information about the communications group and an address of the initiator node, will be sent via the common transmission medium, then from node to join the existing communications group, a unicast message, which contains at least one identifier and an address of the participating node is sent to the initiator node and then authenticates these nodes from the initiator node be and a unicast message, which includes at least the multicast identification and the security key of the communication group, is sent to this node. In this simple way you can take part in the communications group by an interested user or node without big expenses anytime.
p0023An important aspect of the invention also is that is left from a node from which the communication group, a special unicast message which includes at least its identification, is sent to the initiator node that then the initiator node upon reception unicast message authenticates the corresponding node and the associated information is deleted and that then generated by the initiator node, a new security key and then encrypts this by means of a unicast message to everyone in the communication group remaining nodes is sent. On the one hand by each participating node communication group always rely on simple and efficient manner. On the other hand is ensured by the generation and distribution of a new security key that was left of that node from which the communication group communication within the communication group and can not be overheard.
p0024It is advantageous if the ship unicast message together with the new security key information on the node from which the communications group has been left. Thus, the remaining nodes will be informed of which node communication group has been abandoned, and it will prevent, for example, messages are sent to this node.
p0025It is furthermore suitable if after leaving the communications group by a node next to the security key and the multicast identification and / or the group ID to be changed. In this way it is ensured that no more multicast messages are sent to the node from which the communications group has been abandoned, and thus the transmission medium is unnecessarily burdened.
p0026An expedient development of the invention provides that the initiator node, is left by which the communication group, a special multicast message, which includes at least its identifier and a request for function transfer, will be sent to all participating in the communications group node that of all those nodes that can be adopted by which the initiator function, a special unicast message, which includes at least its identifier, is sent to the initiator node that after receiving this unicast messages and the authentication of the responding node from the initiator node after a predetermined procedure from those responding node, a new initiator node is selected that then means unicast message information about the communications group and the participating nodes from the initiator node is transferred to the new initiator node, and that then the new initiator node over the initiator function and a new security key is generated, which is encrypted using a unicast message and, together with information about the new initiator node to each node present in the communication group is transmitted.
p0027This procedure is easily ensured that the communication group can be managed and controlled, even after the communication group from the initiator node has been abandoned. In addition, a procedure for the election of the new initiator node are predetermined - eg new initiator node is the first node from which a corresponding unicast message is received or has what certain defined characteristics, etc.
p0028It is also advantageous if an asymmetric cryptosystem is used during the construction and / or when leaving the communication group, as this cryptosystem can not only be used for encryption, but also for authentication. In addition, can be used in the presence of a general security services in the communication network or the cooperating communications networks, this security service. If unavailable this security service, such as the public key of FlexMax node can be sent with the broadcast message and the public key of each participating node with the respective unicast message.
p0029From an asymmetric cryptosystem, which is also known as public-key method, different keys for encryption and decryption are - so-called public (Public) and secret (private) key (Keys) - used, wherein the public key made generally available becomes. The basic idea of the asymmetric cryptosystem is that the encryption is performed using the public key and a known algorithm, which are provided by the receiving node to the sending node over as publicly accessible channels or by means of a publicly available security services available. The decryption as a message is then performed by the receiving node with a matching public key secret key that is known only to the receiving node.
p0030In a reversal of the process of the asymmetric cryptosystem can be used for authentication, ie, for a determination or verification of authenticity of a transmitting node. Here, a content (for example, the identification of the respective sending node, such as the initiator node participating node) is encrypted a message with the secret key. By the receiving node is then checked by the decryption with the public key, if a source of a message matches the presumed transmitting node.
p0031Alternatively, a symmetric cryptosystem can also be used within the communications group, as in the symmetric cryptosystem only one key (security key) is used to encrypt and decrypt messages to protect communication within the communication group from unauthorized access. This security key, which by all participating in the communications group node is used for encryption and decryption, for example, is generated to establish communications group from FlexMax node and then provided to the participating nodes together with the multicast identification available. If communication group leaving from a node, it is only necessary to generate a new security key and distribute. Also needs to be set up by using a symmetric cryptosystem for the period of existence of the current communication group no elaborate general security service.
p0032In a preferred embodiment, the inventive method is designed such that a common transmission medium is a medium of the data link layer (Data Link Layer) is used as implemented in the (Open System Interconnection) model commonly used, for example, according to the OSI protocol stacks the data link layer (layer designated 2, also known as data link layer or link layer) is usually in the form of a common transmission medium is realized.
p0033It is also advantageous if a radio transmission channel is used as the common transmission medium because the inventive method for dynamically setting up and control of temporarily formed communications groups with secure transmission even in the case of wirelessly over a mobile network interconnected nodes can be used.
p0034Preferably, the inventive method may also be configured such that a data bus is used as the common transmission medium. In a data bus is in case of wired nodes interconnected by a common and powerful common transmission medium.
p0035For the transmission of broadcast, multicast and unicast messages to any existing or future protocol standards wireless or wireline technologies, in particular the data link layer, are used, which use a common transmission medium. Examples include GSM (Global System for Mobile Communications), WCDMA (Wideband Code Division Multiple Access), TD-SCDMA (Time Division Synchronous Code Division Multiple Access) and WiMAX (Worldwide Interoperability for Microwave Access) called. In a particularly preferred development of the method, the broadcast, multicast and unicast messages (IEEE802.3) standards or the Wireless Local Area Network (WLAN, IEEE802.11) standards are sent using the Ethernet as it is these two standards is widespread protocol standards the data link layer in wired or wireless communication networks.
p0036In addition, the object is achieved by a device or node to dynamically build and control of short-term and secure communication groups, at which node at least the following logical components are provided:<ul><li>a central management device to interact with applications, components or users of the node and to control and handle messages, which are exchanged between participating in a communications group nodes</li><li>a means for managing and storing of different approaches is provided in terms of setting up and controlling of communication groups,</li><li>a group information management means for managing and storing all information on those communications groups, will participate in what the node,</li><li>means to generate the security key for a secure transmission of messages within the communication group,</li><li>a message generating means for generating broadcast, multicast and unicast messages, </li><li>the manager is formed (CPC) to trigger a broadcast message (BC) for message generation means (MB), which at least one group ID (Group ID), an identifier (ID1) of the initiator node (IKN), information (Group- information) about the communications group and an address (ADR1) of the initiator node (IKN) contains,</li><li>a communication means for transmitting broadcast, multicast and unicast messages,</li><li>a message receiving means for receiving broadcast, multicast and unicast messages from the transmission medium,</li><li>and processing means for analyzing the incoming broadcast, multicast and unicast messages and the information contained by this.</li></ul>
p0037This device comprises at least those logical components over which a node must have in order to easily and efficiently on the one hand a communication group can be set up automatically and dynamically and controlled by him and thus from this node on the other hand or at such a communication group with no effort of a registration can be part of general infrastructure services without precondition.
p0038The invention will now be described by way of example with reference to the accompanying figures. Show it:<dl id="dl0001" compact="compact"><dt>Fig. 1</dt><dd>a schematic representation of the logical components of a node for carrying out the method of the invention</dd><dt>FIG. 2</dt><dd>the schematic sequence of the dynamic structure of a communication group briefly formed with secure transmission</dd><dt>Fig. 3</dt><dd>the schematic sequence of leaving the communications group temporarily formed by a participating node</dd><dt>Fig. 4</dt><dd>the schematic sequence of leaving the communications group temporarily formed by an initiator node</dd></dl>
p0039<figref idrefs="f0001">figure 1</figref> exemplifies a schematic illustration of a node KN for performing the method according to the invention, wherein both a node from which a communication group is started, as well as a in the communications group only participating nodes should have the basic logic functions exemplified.
p0040The node KN comprises, among other components or applications K1, K2, K3, which are not required in a sequence of the method according to the invention, a central management device CPC. From the central management device CPC interactions with the other components or applications K1, K2, K3, and users of the node KN are controlled on the one hand. On the other hand is also the control and processing of messages that are exchanged within the communications group, carried out by the central management device CPC and communicates with the necessary for the establishment and control of a communication group, logical functions of the node.
p0041Furthermore, the node KN comprises a means for managing and storing various approaches (models) for building and managing short-term communication groups - a so-called Policy Manager PM.
p0042In addition to the Policy Manager PM, a group information management device GIM is provided, from which specific information - are managed and stored by different communication groups - such as group identifiers, multicast identifiers, identifiers of participating nodes, etc.. From a device to generate security keys - the so-called key generator KG - the group information management device GIM made group-specific security keys. These security keys are then used for example for a symmetric cryptosystem for secure transmission of multicast or unicast messages within the communications group. In principle, the key generator KG is only one node KN for use, is from which a communications group started and controlled. However, since each node CN should be able to initiate and manage a communication group, the Key Generator KG can also be provided at participating only in the communication group node CN.
p0043Furthermore, the node KN comprises a message generator or a Message Builder MB, which is controlled by the central management device. Using the message builder MB broadcast, multicast and unicast messages are generated. From Message Builder MB a communication device or a message transmitter MT is driven, from which then the broadcast, multicast and unicast messages to a transmission medium UT.
p0044Furthermore, the node CN also includes a message receiving device or a MessageReceiver MR, which are received by broadcast, multicast and unicast messages via the transmission medium UT. From MessageReceiver MR are received messages to a processing means for analyzing the incoming messages - passed a so-called incoming message analyzer IMA. From incoming message analyzer IMA information contained in the incoming message (eg group IDs, identifiers and addresses of other nodes KN, profile and / or purpose of communication groups, etc.) are analyzed and forwarded to the central management device CPC.
p0045<figref idrefs="f0002">figure 2</figref> shows the schematic sequence of an automatic and dynamic configuration of a communication group briefly formed with secure transmission. It is from a node - a so-called initiator node IKN - tried a new communication group for a specific purpose - such as for a discussion group for an electronic game with multiple play along to provide video information available to build etc.. To this end, in a first step 11 - triggered by the central management device CPC of the initiator node IKN - of the group information management device GIM of the initiator node IKN data for a new communications group such as a group ID Group ID, a group profile , etc., but also a safety bowl SEC, which is generated by the Key generator KG for the new communications group created and forwarded to the central management device CPC of the initiator node.
p0046From the central management device CPC of the initiator node IKN then all you need to know, such as the group identifier Group-ID, a group profile, etc. continue to accompany the Message Builder MB of initiator node from which then a broadcast message BC is generated. The broadcast includes not only the group identifier Group-ID and information Group-Info about the communications group such as group profiles, purpose, etc., at least an identifier ID1 and an address ADR1 of the initiator node IKN. As address ADR1 example IP or MAC address of the initiator node IKN can be used.
p0047The identifier ID1 of the initiator node can be generated for example by means of an asymmetric cryptosystem by encrypting the group identifier Group-ID with a secret key of the initiator node IKN. In this example, an existing security service in a communication network or in cooperating communication networks can be used. For example, if no security service available, must be transmitted in the broadcast message BC for an authentication of the initiator node IKN also a public key.
p0048In a second process step 12, then the broadcast message BC by the message transmitter MT - triggered by the Message Builder MB transmitted to the transmission medium UT by which the broadcast message BC is provided to all nodes can be reached via this transmission medium UT CN available.
p0049From Incoming Message Analyzer IAM in the <figref idrefs="f0002">figure 2</figref> Node exemplified CN, which has been triggered by the central management device CPC of the node KN, the contents of all incoming messages, such as also those of the broadcast message BC, analyzed after they have been received by MessageReceiver MR. The information of the broadcast message BC are then passed in the node KN of Incoming Message Analyzer IAM to the central management device CPC of the node CN. There, the authentication of the initiator node ICS is performed - for example, using a corresponding public key of the initiator node IKN, if an asymmetric cryptosystem is used. In addition, sent along in the broadcast message BC Information Group-Info about the communications group such as group profiles, purpose, etc. are analyzed and decided whether competition from node CN in the communications group or not. In this case also the user of the node CN as contacted by a dialog box on the display of a terminal and to enter a decision prompted.
p0050Will not take part from the node in the communications group, the broadcast message BC is made of nodes KN simply discarded. If the node KN however participants in the communication group, so be - triggered by a central management device CPC of its group information management device GIM the information communication group such as the group identifier Group-ID, the group profile, etc. stored and then his Message Builder MB activated. From Message Builder then a first unicast message UC1 to the initiator node IKN is created, comprising at least one identifier ID2 and an address ADR2 of nodes. As address ADR2 example IP or MAC address of the node IK can be used. The identifier ID2 of the node CN, for example, are produced with a private key of the node CN as the initiator node by encrypting the group identifier Group-ID.
p0051This first unicast message UC1, which may be encrypted for security purposes, for example with the public key of the initiator node IKN, is then sent via message transmitter MT of the node KN and via the transmission medium UT in a third method step 13 to the initiator node IKN ,
p0052From MessageReceiver MR of the initiator node IKN the first unicast message UC1 received, decrypted and forwarded to the incoming message analyzer IMA of the initiator node IKN for analysis. From incoming message analyzer IMA of the initiator node IKN then the contents of the first unicast message UC1 be transmitted to the central management device CPC of the initiator node IKN. There, the authentication of the node KN is performed - for example, using a corresponding public key of the node CN, if an asymmetric cryptosystem is used. According to the filed in the Policy Manager procedures for communication groups the node KN is taken as a new participating node in the communication group and the information stored by the group information management device GIM updated communication group.
p0053After that, the message will Builder MB of initiator node enabled and created by this second unicast message UC2 for transporting the necessary details about the communications group. This second unicast message UC2 includes at least the multicast identifier MC-ID of the communication group and the security key SEC reliable transfer of messages already generated by the Key Generator KG within the communications group.
p0054This second unicast message UC2, which may be encrypted for security purposes, for example with the public key of the node KN is then transmitted to node CN via message transmitter MT of the initiator node IKN and the transmission medium UT in a fourth method step 14th
p0055From MessageReceiver MR of the node CN then the second unicast message UC2 is received, decrypted and forwarded to the incoming message analyzer IMA of the node KN for analysis. From incoming message analyzer IMA then the contents of the second unicast message UC2 to the central management device CPC of the node CN are received, from which then the group information management device GIM the node KN is triggered to update the information stored on the communication group and as the multicast identifier MC-ID and secret key SEC to store the communications group.
p0056In a fifth method step 15 then multicast and / or unicast messages can be exchanged with the help of the security key in a safe SEC form from node KN within the communications group.
p0057The in <figref idrefs="f0002">figure 2</figref> shown node KN exemplifies each node of a communications network or several collaborating communications networks, which can be reached from the broadcast message BC. The recording of each node CN in the communication group by means of unicast messages UC1 and UC2, which are exchanged between nodes CN and initiator node IKN or corresponding to the two process steps. 13 and 14
p0058For a synchronization of a starting time - as it is useful for example for the transmission of video information - can be sent from the initiator node IKN a special encrypted multicast message to all participating in the communications group node CN. For some applications, such as discussion forums, it may also be useful if, for example, the identifiers, the addresses or information on all participating in the communications group node CN by the initiator node IKN are distributed by multicast message.
p0059To extend an existing communication group continuously, a broadcast message BC can be sent, for example, at periodic intervals from the initiator node IKN. Creating and sending this broadcast message BC, which should include at least the group identifier Group-ID, information Group-Info about the communications group such as group profiles, purpose, etc., the identifier ID1 and an address ADR1 of the initiator node IKN , is performed as described 11 and 12 as in the two process steps. If then participated because this broadcast message BC from a node CN in the communications group, as are also the in<figref idrefs="f0002">figure 2</figref> Described process steps 13 and 14 pass through.
p0060is simplicity in the further exemplary embodiments, the in <figref idrefs="f0003">figure 3</figref> or. <figref idrefs="f0004">figure 4</figref> Sequences shown on a detailed presentation of the proceeding within the node IKN, nIKN, KN1 KN 2, KN 3 operations - detailed involvement of the logical components of the node IKN, nIKN, KN1 KN 2, KN 3 - given, as these do not differ from the procedures already described.
p0061From <figref idrefs="f0003">figure 3</figref> describes when an existing communication group of an exemplary node KN1 is exited by way of example the flow. In a sixth method step 21 a third special unicast message from a node KN1, departing from which the communication group, sent UC3 to the initiator node IKN. This third unicast message UC3 here comprises at least one identifier ID3 of the node KN 1, wherein ID3 example, a secret key of the node can be KN1 used to generate this ID. In a seventh step 22, the communication group will then leave the node KN1.
p0062After receiving the third unicast message UC3 by the initiator node IKN, in an eighth step 23, the node KN1 is authenticated - for example using a corresponding public key - and deleted all belonging to this node KN1 information. For this is triggered by the central management device CPC of the initiator node IKN the group information management device GIM, to update the information stored to the communication group, and using the Key Generator KG, a new security key nSEC1 created for the communications group.
p0063In a ninth step 24, a fourth unicast message UC4 is then the initiator node IKN to each still participating in the communications group node KN 2 shipped. This fourth unicast message UC4 includes at least the new security key nSEC1 the communications group. With this fourth unicast message UC4 but can also be sent information (eg identifier ID3, address, etc.) of the node KN1, of which the communication group has been abandoned. In addition it is also possible that, for example, for security reasons, the group identifier and / or the multicast identifier to be changed and the new identifiers to the fourth unicast message UC4 the remaining in the communication group node KN 2 are communicated. For security reasons, the respective fourth unicast message UC4 is eg also encrypted with a public key of each node KN 2, to which this fourth unicast message UC4 is sent.
p0064In a tenth step 25 then KN 2 can from the remaining in the communication group node back within the communication group multicast and / or unicast messages in a secure manner - but replaced with the new security key nSEC1. Were also the group ID and / or the multicast identification of the communication group is changed, these new identifiers for the exchange of multicast and / or unicast messages will now be used from.
p0065<figref idrefs="f0004">figure 4</figref> describes an example of the sequence when the communication group from the initiator node IKN will leave.
p0066Here is the initiator node IKN in an eleventh Verfahrenssch rode 31 a special multicast message MC to all participating in the communications group node nIKN, KN 3 sent, through which requested from the initiator node IKN a transfer of a function as the initiator node IKN. This multicast message comprises at least one identifier ID4 of the initiator node ICS, wherein ID4 for example a secret key of the initiator node ICS can be used to produce this identifier.
p0067Upon receipt of this multicast message MC and the authentication of the initiator node IKN can be decided by a node nIKN whether the function is taken as the initiator node. For this purpose of this node nIKN in a twelfth step 32, a fifth special unicast message UC5, which receives at least one identifier ID5 of the node nIKN, for example, has been generated using a secret key of the node nIKN transmitted to the initiator node. After waiting from that node nIKN a response from the initiator node IKN. If the node nIKN not contacted within a predefined time period from the initiator node IKN, the process is simply discarded.
p0068In a thirteenth step 33 of all the responses received to the multicast message MC from the initiator node IKN evaluated - ie responding node nIKN be authenticated and then selected a new initiator node, where different approaches are retrieved from the Policy Manager PM which eg can, may be employed. For example, the function of the initiator node IKN be transmitted to node nIKN, obtained from the first to answer. It can, however, as well as the users of the initiator node IKN as contacted by a dialog box on the display of a terminal and to enter a decision prompted.
p0069When a decision on the transfer of the initiator function has been taken, in a fourteenth step is to 34 with a sixth special unicast message UC6 necessary for control of the communication group information (eg, group ID, group profile, identifiers of the participating nodes, etc.) node nIKN, to be adopted by which the initiator function transmitted. can this sixth unicast message UC6 eg if necessary be encrypted for security with for example a public key of the node nIKN.
p0070From initiator node in its group information management device GIM all members of the communication group submitted information will be deleted. In a fifteenth step 35 the communication group of the initiator node is then exited.
p0071By obtaining the sixth unicast message UC6 is assumed the initiator function of nodes nIKN - ie is from this node nIKN in a sixteenth step 36 with the help of its group information management device GIM the received information about the communications group and the participating nodes KN 3 stored and generated by means of its key generator KG, a new security key nSEC2 for communication group.
p0072In a seventeenth step 37, a seventh unicast message UC7 for those remaining in the communication group node KN 3 is created and sent from node nIKN as the new initiator node. This seventh unicast message UC7 includes at least the new security key nSEC2 the communications group. This seventh unicast message UC7 but can also be sent information (eg identifier ID4, address, etc.) of the initiator node IKN, of which the communication group has been abandoned. For security reasons, the respective seventh unicast message UC7 eg be encrypted with a public key of each node KN 3.
p0073In addition, it is also likely to be changed by the node nIKN as the new initiator node, for example, for security reasons, the group identifier and / or the multicast identification and the new identifiers to the seventh unicast message UC7 the remaining in the communication group node KN 3 are communicated.
p0074If a communication group as abandoned by all participating nodes or remains only one node or the initiator node IKN in the communications group, this communication group is automatically disbanded. To ensure the existence of a communications group with secure transmission, a special request (eg in the form of a multicast message), for example, periodically from the initiator node CN are sent to all participating nodes to this to the existence of an initiator node IKN inform. In addition, for example, in order to ensure the existence of the participating nodes, a response to this request will be requested by the initiator node IKN.
p0075The sending of broadcast, multicast and unicast messages BC, MC, UC, for example, using Ethernet (IEEE802.3) and / or wireless LAN (WLAN, IEEE802.11) technology can be realized.
p0076Of these technologies (Ethernet, WLAN) is a transmission of these messages on the so-called security layer (Data Link Layer), for example, according to the OSI (Open System Interconnection) model implemented protocol stacks the data link layer (layer 2, also known as Data Link Layer or link layer refers), allows a common transmission medium UT. In this example, a transport of these messages via different network elements such as repeaters or bridges on the same layer 2 or the same link layer is performed.
p0077In particular, the transmission of the unicast and broadcast messages UC BC used by methods of the invention can be implemented in these technologies (Ethernet, WiFi) in a simple and direct way.
p0078The transfer of the next used in the method according to the invention multicast messages MC - such as for taking place within the communication group communication - can always be used when using Ethernet or Wi-Fi technology in a simple way, when a so-called multicast address has been corresponding to the already mentioned multicast identification MC ID, distributed by eg encrypted unicast message to each individual participating in a communications group node CN of an initiator node IKN.
p0079The basic structure of the broadcast, multicast and unicast messages BC, MC, UC when using Ethernet or Wi-Fi technology in principle corresponds to the structure of a data packet to Ethernet (IEEE802.3) or WLAN (IEEE802.11).
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP1562322A | Cites | European Patent Office (EPO) |
| EP0952718A2 | Cites | European Patent Office (EPO) |
| EP1331755A2 | Cites | European Patent Office (EPO) |
| YINGJIC WANG ET AL: "An efficient method of group rekeying for multicast communication" EMERGING TECHNOLOGIES: FRONTIERS OF MOBILE AND WIRELESS COMMUNICATION, 2004. PROCEEDINGS OF THE IEEE 6TH CIRCUITS AND SYSTEMS SYMPOSIUM ON SHANGHAI, CHINA MAY 31-JUNE 2, 2004, 31. Mai 2004 (2004-05-31), Seiten 273-276, XP010716071 | Non-patent | – |
| 3RD GENERATION PARTNERSHIP PROJECT (3GPP): "3GPP TS 22.146 V7.1.0, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Multimedia Broacast/Multicast Service; Stage 1 (Release 7)" 3GPP TS 22.146 V7.1.0, März 2006 (2006-03), XP002385907 | Non-patent | – |
| 3GPP GROUP SERVICES AND SYSTEM ASPECTS: "3GPP TS 23.246 V.6.5.0: Multimedia Broadcast/Multicast Service (MBMS); Architecture and functional description Release 6" 3GPP TS 23.246 V6.5.0, Dezember 2004 (2004-12), XP002333585 | Non-patent | – |
10 members in 6 offices; this record represents the family
Members10
| Document | Office | Kind | |
|---|---|---|---|
| EP1860819A1 | European Patent Office (EPO) | A1 | |
| WO2007134970A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20090018661A | Republic of Korea | A | |
| CN101536405A | China | A | |
| US2009290522A1 | United States of America | A1 | |
| US8130689B2 | United States of America | B2 | |
| CN101536405B | China | B | |
| EP1860819B1This record | European Patent Office (EPO) | B1 | |
| ES2436184T3 | Spain | T3 | |
| KR101403625B1 | Republic of Korea | B1 |
76 legal events, as 10 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Change of applicant/patenteeR081 | R081 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Change of name or company nameCD | CD | FR | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Transfer of patentPC2A | PC2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Discontinued in the netherlands as no translation has been filedVDEP | VDEP | NL | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Party data changed (patent owner data changed or rights of a patent transferred)RAP2 | RAP2 | EP | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent enters austrian national phase)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Designation fees paidAKX | AKX | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1860819
- Application
- 61144044
Titles3
- German
- Verfahren und Vorrichtung zum dynamischen Aufbau und zur Steuerung von kurzzeitig gebildeten Kommunikationsgruppen mit gesicherter Übertragung
- English
- Method and system for dynamically constructing and controlling short-lived communication groups with secure transmission
- French
- Procédé et système pour la construction et la gestion des groupes de communication de courte durée avec transmission securisée
Classification
- CPC, 6
- H04W4/08
- H04L12/18
- H04L12/185
- H04L12/189
- H04W8/186
- H04L12/28
- IPC, 1
- H04L12 18
Designated states31
- Contracting states, 31
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Netherlands (Kingdom of the)
and 7 moreShow fewer
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
