EP2124381B1

Method, system and device for generating group key

Abstract

This record has no abstract on file.

EP2124381B1, drawing sheet 1
Sheet 1 of 170

Term

1.7 yearsleft in the term

Expires 27 May 2028.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

15 claims: 4 independent, 11 dependent

  1. 1
    A method for generating a group key, wherein system parameters are selected based on an elliptic curve, the method comprising:forming (201), by group members, a star-shaped structure, and selecting an organizer from the group members;randomly selecting (203), by the group members, DH secret values according to the system parameters individually, generating DH public values individually according to the system parameters and the selected DH secret values, and broadcasting the DH public values in the group;selecting (204), by the organizer, a secret exponent after receiving the DH public values of the other group members, computing an intermediate message DH value according to the secret exponent, generating an intermediate message carrying the intermediate message DH value, broadcasting the intermediate message in the group, and generating a group key according to the DH secret value selected by the organizer and the DH public values of the other group members;and computing (205), by the other group members, the DH secret value selected by the organizer according to the intermediate message after receiving the intermediate message and the DH public value of the organizer, verifying (206) the computed DH secret value selected by the organizer to be correct according to the received DH public value of the organizer, and generating (207) a group key according to the DH secret value selected by the organizer and the DH public values of the other group members.
  2. 12
    A system for generating a group key, comprising:a communication device as an organizer and a communication device as members;wherein the communication device as the organizer is configured to select a DH secret value according to system parameters, generate a DH public value according to the system parameters and the selected DH secret value, and broadcast the DH public value in the group;and after receiving DH public values of other devices, the communication device as the organizer is further configured to select a secret exponent, compute an intermediate message DH value according to the secret exponent, generate an intermediate message carrying the intermediate message DH value, broadcast the intermediate message in the group, and generate a group key according to the DH secret value selected by the organizer and DH public values of all devices in the group;and the communication device as the members is configured to select DH secret values according to the system parameters, generate DH public values according to the system parameters and the selected DH secret values, and broadcast the DH public values;and after receiving the DH public value and the intermediate message broadcasted by the communication device as the organizer, the communication device as the members is further configured to compute the DH secret value selected by the organizer according to the intermediate message, verify the computed DH secret value selected by the organizer to be correct, and generate a group key according to the DH secret value selected by the organizer and the DH public values of all devices in the group.
  3. 13
    A communication device, comprising:a system parameter selecting module, configured to select system parameters based on an elliptic curve;a DH public value generating and broadcasting module, configured to select a DH secret value according to the system parameters selected by the system parameter selecting module, generate a DH public value according to the system parameters and the selected DH secret value, and broadcast the DH public value;an intermediate message generating and broadcasting module, configured to select a secret exponent after receiving DH public values broadcasted by other communication devices, compute an intermediate message DH value according to the secret exponent, generate an intermediate message carrying the intermediate message DH value according to the DH secret value selected by the DH public value generating and broadcasting module, and broadcast the intermediate message;and an organizer group key generating module, configured to receive the DH public values broadcasted by other communication devices, and generate a group key according to the DH secret value selected by the DH public value generating and broadcasting module and the DH public values broadcasted by other communication devices.
  4. 14
    A communication device, comprising:a system parameter selecting module, configured to select system parameters based on an elliptic curve;a DH public value generating and broadcasting module, configured to select DH secret values according to the system parameters selected by the system parameter selecting module, generate DH public values according to the system parameters and the selected DH secret values, and broadcast the DH public values;and a member group key generating module, configured to receive a DH public value and an intermediate message broadcasted by another communication device, compute a DH secret value selected by an organizer according to the intermediate message, verify the computed DH secret value selected by the organizer to be correct according to the DH public value broadcasted by the communication device that broadcasts the intermediate message, and then generate a group key according to the DH secret value selected by the organizer and DH public values broadcasted by the other communication devices except the communication device that broadcast the intermediate message.