EP2471211B1

Secure key management in conferencing system

Abstract

This record has no abstract on file.

EP2471211B1, drawing sheet 1
Sheet 1 of 17

Term

3.9 yearsleft in the term

Expires 23 August 2030.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

10 claims: 5 independent, 5 dependent

  1. 1
    A method for managing a conference between two or more parties in a communication system, the method comprising steps of:performing an identity based authenticated key exchange operation between a conference management element of the communication system and each of the two or more parties seeking to participate in the conference, wherein messages exchanged between the conference management element and the two or more parties are encrypted based on respective identities of recipients of the messages, and further wherein the conference management element receives from each party during the key authentication operation a random key component that is computed based on a random number selected by the party;sending from the conference management element to each party a set comprising the random key components computed by the parties;receiving at the conference management element from each party a random group key component, wherein the random group key component is computed by each party via a computation based on the random number used by the party during the key authentication operation and the random key components computed by a subset of others of the two or more parties seeking to participate in the conference;and sending from the conference management element to each party a set comprising the random group key components computed by the parties such that each party can compute the same group key for use in communicating with each other party through the conference management element.
  2. 7
    The method of the claim 1, wherein a functional element imitates a tainted party seeking to participate in the conference such that the functional element can intercept conference messages to and from the tainted party.
  3. 8
    Apparatus for managing a conference between two or more parties in a communication system, the apparatus comprising:a memory;and at least one processor coupled to the memory and configured to: perform an identity based authenticated key exchange operation between a conference management element of the communication system and each of the two or more parties seeking to participate in the conference, wherein messages exchanged between the conference management element and the two or more parties are encrypted based on respective identities of recipients of the messages, and further wherein the conference management element receives from each party during the key authentication operation a random key component that is computed based on a random number selected by the party;send from the conference management element to each party a set comprising the random key components computed by the parties;receive at the conference management element from each party a random group key component, wherein the random group key component is computed by each party via a computation based on the random number used by the party during the key authentication operation and the random key components computed by a subset of others of the two or more parties seeking to participate in the conference;and send from the conference management element to each party a set comprising the random group key components computed by the parties such that each party can compute the same group key for use in communicating with each other party through the conference management element but wherein the conference management element is unable to compute the group key.
  4. 9
    A method for use in participating in a conference between parties in a communication system, the method at a given party comprising steps of:performing an identity based authenticated key exchange operation between a conference management element of the communication system and the given party, wherein the conference management element also performs the identity based authenticated key exchange operation with the other parties seeking to participate in the conference, wherein messages exchanged between the conference management element and the parties are encrypted based on respective identities of recipients of the messages, and further wherein the conference management element receives from each party during the key authentication operation a random key component that is computed based on a random number selected by the party;receiving at the given party from the conference management element a set comprising the random key components computed by the parties;sending from the given party to the conference management element a random group key component, wherein the conference management element also receives a random group key component from each of the other parties, wherein the random group key component is computed by each party via a computation based on the random number used by the party during the key authentication operation and the random key components computed by a subset of others of the parties seeking to participate in the conference;receiving at the given party from the conference management element a set comprising the random group key components computed by the parties;and computing at the given party a group key which is the same group key computed by the other parties for use in communicating with each other party through the conference management element.
  5. 10
    Apparatus for use in participating in a conference between parties in a communication system, the apparatus at a given party comprising:a memory;and at least one processor coupled to the memory and configured to: perform an identity based authenticated key exchange operation between a conference management element of the communication system and the given party, wherein the conference management element also performs the identity based authenticated key exchange operation with the other parties seeking to participate in the conference, wherein messages exchanged between the conference management element and the parties are encrypted based on respective identities of recipients of the messages, and further wherein the conference management element receives from each party during the key authentication operation a random key component that is computed based on a random number selected by the party;receive at the given party from the conference management element a set comprising the random key components computed by the parties;send from the given party to the conference management element a random group key component, wherein the conference management element also receives a random group key component from each of the other parties, wherein the random group key component is computed by each party via a computation based on the random number used by the party during the key authentication operation and the random key components computed by a subset of others of the parties seeking to participate in the conference;receive at the given party from the conference management element a set comprising the random group key components computed by the parties;and compute at the given party a group key which is the same group key computed by the other parties for use in communicating with each other party through the conference management element.