Apparatus and method for a secure broadcast system
Abstract
Devices and methods for supplying access keys used for controlled access broadcast services are disclosed. In one respect, a method for secure processing in a device that securely stores a private key is to receive multiple challenges from the network and generate multiple encryption keys based on the private key and multiple challenges. Includes generating access keys based on multiple encryption keys.

Term
Term ended
Projected expiry passed 8 July 2024, 2.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
34 claims: 10 independent, 24 dependent
- 1下記を具備する、秘密鍵を安全に記憶する装置における安全な処理のための方法:ネットワークから複数のチャレンジを受信する;秘密鍵および複数のチャレンジに基づいて複数の暗号化鍵を発生する;および前記複数の暗号化鍵に基づいて秘密鍵を発生する。
- 2さらに下記を具備する請求項1の方法:前記複数のチャレンジおよび前記秘密鍵を用いて複数の認証応答を発生する;および少なくとも1つの認証応答を前記ネットワークに送信する。
- 3前記ネットワークに送信されなかった任意の認証応答を破棄することをさらに具備する、請求項2の方法。
- 4複数のチャレンジを受信することは複数のランダム値を受信することを具備する、請求項1乃至3のいずれか1つの方法。
- 5前記アクセス鍵は暗号化鍵より長い、請求項1乃至4のいずれか1つの方法。
- 6前記アクセス鍵を発生することは、複数の暗号化鍵を連結することを具備する、請求項5の方法。
- 7前記アクセス鍵を発生することは、前記複数の暗号化鍵にハッシュ関数を使用することを具備する、請求項5の方法。
- 8前記ハッシュ関数は、前記複数の暗号化鍵を混合するためにSHA-1を具備する、請求項7の方法。
- 9前記秘密鍵を記憶することは、モバイル通信規格のためのグローバルシステムを用いて携帯電話の加入者アイデンティティモジュールに、秘密鍵として128ビットの加入者認証鍵を記憶することを具備する、請求項1乃至8のいずれか1つの方法。
- 10前記複数の暗号化鍵を発生することは64ビットの暗号化鍵を発生することを具備し;および 前記アクセス鍵を発生することは、2つの暗号化鍵を用いて128ビットのブロードキャストアクセス鍵を具備する、請求項9の方法。
- 11前記安全鍵を記憶することは、ユニバーサルモバイル通信システム規格を用いた携帯電話のユニバーサル加入者アイデンティティモジュールに、秘密鍵として128ビットの加入者認証鍵を記憶することを具備する、請求項1または請求項2乃至8のいずれか1つの方法。
- 12前記複数の暗号化鍵を発生することは、64ビットの暗号化鍵を発生することを具備し;および 前記アクセス鍵を発生することは、2つの暗号化鍵を用いて128ビットのブロードキャストアクセス鍵を発生することを具備する、請求項11の方法。
- 13前記アクセス鍵を発生することは、ブロードキャストアクセス鍵を発生することを具備し;前記方法はさらに、 暗号化されたブロードキャストコンテンツを受信し;および 前記ブロードキャストアクセス鍵に基づいて前記ブロードキャストコンテンツを復号することを具備する、請求項1乃至12のいずれか1つの方法。
- 14前記コンテンツを復号することは、 各チャレンジおよび前記ブロードキャストアクセス鍵に基づいて一時的な復号鍵を発生する;および 前記一時的な復号鍵を用いて前記ブロードキャストコンテンツを復号する;ことを具備する、請求項13の方法。
- 15下記を具備する携帯電話に使用するための装置:秘密鍵を安全に記憶し、前記秘密鍵およびネットワークから受信した複数のチャレンジに基づいて複数の暗号化キーを発生するように構成された集積回路カード(ICC);および 前記ICCと接続され、前記複数の暗号化鍵に基づいてアクセス鍵を発生するように構成されたプロセッサー。
- 16前記ICCに接続された送信機をさらに具備し、前記ICCは前記複数のチャレンジおよび前記秘密鍵を用いて複数の認証応答を発生し;および 前記送信機は、少なくとも1つの認証応答を前記ネットワークに送信するように構成される、請求項15の装置。
- 17前記チャレンジはランダム値を具備する、請求項15または請求項16の装置。
- 18前記ICCはモバイル通信規格のためのグローバルシステムを用いた携帯電話の加入者アイデンティティモジュール(SIM)である、請求項15または請求項16乃至17のいずれか1つの装置。
- 19前記SIMは、秘密鍵として128ビットの加入者認証鍵を記憶し、64ビットの暗号化鍵を発生する;および 前記プロセッサーは、2つの暗号化鍵を用いて128ビットのブロードキャストアクセス鍵を発生する、請求項18の装置。
- 20前記ICCは、ユニバーサルモバイル通信システム規格を用いた携帯電話のユニバーサル加入者アイデンティティモジュール(USIM)である、請求項15または請求項16乃至17のいずれか1つの装置。
- 21前記USIMは前記秘密鍵として128ビットの加入者認証鍵を記憶し、64ビットの暗号化鍵を発生し;および 前記プロセッサーは、2つの暗号化鍵を用いて128ビットのブロードキャストアクセス鍵を発生する。
- 22前記受信機は暗号化されたブロードキャストコンテンツを受信し;および前記プロセッサーは、ブロードキャストコンテンツを復号するためにブロードキャストアクセス鍵を発生する、請求項15、または請求項16乃至21の装置。
- 23下記を具備する、秘密鍵を安全に記憶する手段を有する装置における安全処理のための装置:ネットワークから受信した複数のチャレンジと前記秘密鍵に基づいて、複数の暗号化鍵を発生する手段;および 前記複数の暗号化鍵に基づいてアクセス鍵を発生する手段。
- 24前記複数のチャレンジと前記秘密鍵を用いて複数の認証応答を発生する手段;および少なくとも1つの認証応答を前記ネットワークに送信する手段をさらに具備する、請求項23の装置。
- 25前記ネットワークに送信されなかった任意の認証応答を破棄する手段をさらに具備する、請求項24の装置。
- 26前記アクセス鍵を発生する手段は、前記複数の暗号化鍵を連結する手段を具備する、請求項23または請求項24乃至25のいずれか1つの装置。
- 27前記アクセス鍵を発生する手段は、前記複数の暗号化鍵にハッシュ関数を使用する手段を具備する、請求項23、または請求項24乃至25のいずれか1つの装置。
- 28前記アクセス鍵を発生する手段は、ブロードキャストアクセス鍵を発生し;前記装置は、 暗号化されたブロードキャストコンテンツを受信する手段;および 前記ブロードキャストアクセス鍵に基づいて前記ブロードキャストコンテンツを復号する手段をさらに具備する、請求項23または請求項24乃至27のいずれか1つの装置。
- 29秘密鍵を安全に記憶し、ネットワークから複数のチャレンジを受信するシステムを具現化するコンピューターシステムに使用する製品であって、前記製品は、前記媒体に具現化された機械読み出し可能なコード手段を有する機械読み出し可能な媒体を具備し、下記を具備する製品:複数のチャレンジおよび秘密鍵に基づいて複数の暗号化鍵を発生するための、前記機械読み出し可能媒体に具現化された機械読み出し可能なコード手段;および 前記複数の暗号化鍵に基づいてアクセス鍵を発生するための、前記機械読み出し可能な媒体に具現化された機械読み出し可能なコード手段。
- 30前記複数のチャレンジと前記秘密鍵を用いて複数の認証応答を発生するための、前記機械読み出し可能な媒体に具現化された機械読み出し可能なコード手段;および 少なくとも1つの認証応答を前記ネットワークに送信するための、前記機械読み出し可能な媒体に具現化された機械読み出し可能なコード手段をさらに具備する、請求項29の製品。
- 31前記ネットワークに送信されなかった任意の認証応答を破棄するための、前記機械読み出し可能な媒体に具現化された機械読み出し可能なコード手段をさらに具備する、請求項30の製品。
- 32前記アクセス鍵を発生するための機械読み出し可能なコード手段は、前記複数の暗号化鍵を連結するための、前記機械読み出し可能な媒体に具現化された機械読み出し可能なコード手段。
- 33前記アクセス鍵を発生するための機械読み出し可能コード手段は、前記複数の暗号化鍵にハッシュ関数を使用するための、前記機械読み出し可能媒体に具現化された機械読み出し可能なコード手段を具備する、請求項29の製品。
- 34前記システムは暗号化されたブロードキャストコンテンツを受信し、前記アクセス鍵を発生するための前記機械読み出し可能なコード手段はブロードキャストアクセス鍵を発生し;および前記製品はさらに、前記ブロードキャストアクセス鍵に基づいて前記ブロードキャストコンテンツを復号するための、前記機械読み出し可能媒体に具現化された機械読み出し可能なコード手段を具備する、請求項29の製品。
Independent claims34
51 paragraphs, as filed
Cross-reference to related applications This patent application is assigned to the assignee of this patent application and is expressly incorporated herein by reference, filed on July 8, 2003, "Secure Broadcast". Claims priority over US Provisional Application No. 60 / 485,791 entitled "Apparatus and Method for a Secure Broadcast System".
The present invention relates generally to secure communication systems, especially access key management for multimedia broadcasting services in a mobile environment.
Wireless communication systems are widely deployed to provide various types of communication such as voice, data, etc. These systems may be based on code division multiple access (CDMA), time division multiple access (TDMA) or other modulation techniques.
The system is "TIA / EIA-95-B Mobile Station-Base Station Compatible Standard for Dual Mode Wide Wide Spectrum Cellular System" (IS-95 Standard), a third generation wireless service based on the GSM communication standard "Universal". Mobile Communications Services (UMTS); General Packet Radio Systems (GPRS) Communications Standard, an evolutionary step from GSM towards UMTS; Reference Numbers 3G TS 25.211, 3G TS 25.212, 3G TS 25.213, and 3G TS 25.214, 3G TS A standard provided by a community named "Third Generation Partnership Project" embodied in a set of literature including 25.302 (W-CDMA standard); in "TR-45.5 Physical Layer Standard for cdma2000 Spectral Diffusion System". It may be designed to support one or more standards, such as the standard provided by the community named "Third Generation Partnership Project 2" (3PP2) that is embodied (IS-2000 standard). Each standard defines the processing of data for wireless communication between infrastructure elements such as base stations and user-end devices such as mobile devices.
The increasing demand for wireless data transmission and the expansion of services available through wireless communication technologies have resulted in the development of specific data services. In one embodiment, the system may be configured to support a multimedia broadcasting service (broadcast service). As with television and / or radio broadcasts, broadcast services may be used for wireless transmission of multimedia streams from content providers to user end devices. Here, the content stream can be thought of as the equivalent of a television channel or radio station. Examples of multimedia content streams include audio and / or video data such as movies, sporting events, news and various other programs and / or files. Typically, service providers indicate to users the availability of such broadcast services. Users who desire a broadcast service may receive broadcast service-related parameters in overhead messages sent from infrastructure elements. When the user wants to receive a content stream, the user end device reads the overhead message to know the proper configuration. The user-end device then tunes to the channel or frequency containing the content stream and receives the broadcast service.
There are several possible subscription / revenue models for broadcast services, including free access, controlled access, and partially controlled access. Free access does not require a user subscription to receive the service. The content is broadcast unencrypted so that the user end device of the interested user can receive and view the content. Revenues for service providers can be generated through advertisements that may be sent over broadcast channels. For example, you can send a cut-out scene of an upcoming movie that the studio will pay the service provider.
With controlled access, the user must subscribe and will be empowered to receive broadcast services for a fee. This controlled access can be achieved by encrypting the broadcast service transmission so that only the subscriber can decrypt and view the content, or by content with an encrypted access key. Here, the encryption of broadcast content may be based on a symmetric or asymmetric cryptosystem. Symmetric cryptosystems use the same key for encryption / decryption, and asymmetric cryptosystems use different keys for encryption / decryption.
Cryptography is well known to those skilled in the art and will not be described in more detail. Hybrid access schemes or partially controlled access provide broad services as subscription-based services that are encrypted with intermittent unencrypted ad transmission. These advertisements may be intended to encourage subscription to encrypted broadcast services.
For controlled or partially controlled broadcast services, there is a problem with the secure supply of access keys from content providers to one or more recipients. Therefore, there is a need for a secure method for supplying access keys to end-user devices. In particular, the supply of access keys must comply with existing standards and corresponding infrastructure as well as evolving standards and corresponding infrastructure.
Outline of the invention
The embodiments disclosed herein address the above-mentioned need by allowing the secure supply of access keys to end-user devices.
In one embodiment, a method for secure processing in a device that securely stores a private key receives multiple challenges from the network; generates multiple encryption keys based on the private key and multiple challenges; And include generating access keys based on multiple encryption keys. This method further involves generating multiple authentication responses with multiple challenges and private keys; sending at least one authentication response to the network. Generating an access key may include generating a broadcast access key, which method further includes receiving encrypted broadcast content; and decrypting the broadcast content based on the broadcast access key. .. Decryption of content may include generating a temporary decryption key based on each challenge and broadcast access key; and decrypting the broadcast content using the temporary decryption key.
In another embodiment, the device for secure processing in a device having means for securely storing the private key generates multiple encryption keys based on multiple challenges and private keys received from the network. Means and; Includes means to generate access keys based on multiple encryption keys.
In yet another embodiment, a machine-readable medium is disclosed that is used in a device that securely stores a private key and receives multiple challenges from a network. Machine-readable media include codes for generating multiple encryption keys based on multiple challenges and private keys; and codes for generating access keys based on multiple encryption keys.
In other embodiments, the 128-bit subscriber authentication key may be stored as a private key in the subscriber identity module of a mobile phone using a global system for mobile communication standards. The 128-bit subscriber authentication key may also be stored as a private key in the universal subscriber identity module of a mobile phone using the universal mobile communication system standard. In addition, two encryption keys may be used to generate a 64-bit encryption key or a 128-bit broadcast access key.
In a further embodiment, the device for use in a mobile phone is configured to securely store the private key and generate multiple encryption keys based on the private key and multiple challenges received from the network. Includes an integrated circuit card (ICC) and; and a processor that is connected to the ICC and is configured to generate access keys based on multiple encryption keys. The ICC may be a mobile phone subscriber identity module (SIM) with a global system for mobile communication standards. The SIM may store the 128-bit subscriber authentication key as a private key or generate a 64-bit encryption key. The ICC may be a universal subscriber identity module (USIM) for mobile phones using the universal mobile communication system standard. USIM may store the 128-bit subscriber authentication key as a private key and may generate a 64-bit encryption key in a SIM-backward compatible mode. The processor may generate a 128-bit broadcast access key using two encryption keys.
Various embodiments will be described in detail with reference to the following drawings in which similar reference numbers point to similar elements.
In the following description, specific details are given to provide a complete understanding of the embodiments.
However, it will be appreciated by those skilled in the art that embodiments may be implemented without these particular details. For example, the circuit may be shown on a block diagram so as not to obscure the embodiments unnecessarily in detail. In other instances, well-known circuits, structures and techniques may be shown in detail so as not to obscure the embodiments.
It should also be noted that embodiments may be described as processes drawn as flowcharts, flow diagrams, structural diagrams or block diagrams. Flowcharts may describe actions as sequential processes, but many of the actions can be performed in parallel or simultaneously. Further, the order of operations may be rearranged. The process ends when the operation is complete. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, or the like. When a process corresponds to a function, its termination corresponds to the return of the function to the calling function or the main function.
Further, as disclosed herein, the storage medium is for storing read-only memory (ROM), random access memory (RAM), magnetic disk storage medium, optical storage medium, flash memory device, and / or information. It may represent one or more devices for storing data, including other machine-readable media. The term "machine readable medium" is, but is not limited to, storing, including, and owning portable or fixed storage devices, optical storage devices, radio channels and instructions (s) and / or data. Includes various other media capable of.
Figure 1 shows an example of a wireless communication network 100 that can support broadcast services. Network 100 may include one or more communication systems that support different standards. In particular, network 100 includes multiple service areas 102A-102G. Each of the service areas is serviced by the corresponding infrastructure element 104A-104G. Infrastructure elements 104A-104G communicate with user end devices (hereinafter "terminals") 106A-106J within the service area 102A-102G of infrastructure elements 104A-104G, respectively. Depending on the type of communication system, infrastructure elements 104A-104G may include base stations, base transceiver stations, gateways, or other devices that communicate with terminals 106A-106J. The terminals 106A-106J are not limited to these, but are mobile phones (including cellular and personal communication services), wired phones, wireless handsets, personal digital assistants (PDAs), various computer devices (including laptops and desktops) or It may be another data transceiver. As shown in FIG. 1, the terminals 106A-106J can be portable or fixed (stationary) as seen in handheld, mobile, in-vehicle (including automobiles, trucks, boats, and airplanes).
In one embodiment, the network 100 supports a broadcast service, sometimes referred to as a multimedia broadcast / multicast service (MBMS), or sometimes a broadcast / multimedia service (BCMCS). In general, MBMS is a packet data service based on the Internet Protocol (IP). The service provider may indicate the availability of such MBMS to the user. Users who desire MBMS may receive the service and discover the broadcast service via broadcasts such as Advertising, Short Message System (SMS), and Wireless Application Protocol (WAP). Infrastructure elements send MBMS-related parameters in overhead messages. When the user wants to receive a broadcast session, terminal 106 reads an overhead message to know the proper configuration. The terminal 106 then tunes to the frequency including the MBMS channel and receives the broadcast service content.
Figure 2 shows a simplified network 200 for implementing MBMS. In network 200, video and / or audio information is supplied to data service network (PDSN) 230 packetized by content source (CS) 210. Video and audio information may come from television broadcast programs or wireless transmissions. The information is supplied as packetized data such as an IP packet. The PDSN220 processes IP packets for delivery within the access network (AN). As illustrated, the AN is defined as part of the network 200 that contains the infrastructure element 240 that communicates with multiple terminals 250.
For MBMS, the CS210 supplies unencrypted content. Infrastructure element 240 receives a stream of information from PDSN 230 and supplies that information to subscriber terminals in network 200 over a designated channel. To control access, the content from the CS210 is encrypted by a content encrypter (not shown) using an encryption key before being supplied to the PDSN220. Content ciphers and CS210s will be referred to below as content providers, although content ciphers may be implemented with or separately from CS210. A decryption key is provided to the subscriber so that the IP packet can be decrypted.
In particular, FIG. 3 shows a terminal 300 that can subscribe to MBMS to receive multimedia content. The terminal 300 includes an antenna 310 connected to the receiving circuit 320.
Terminal 300 receives a transmission from a content provider (not shown) via an infrastructure element (not shown). The terminal 300 includes a mobile device 340 connected to the receiving circuit 320 and a universal integrated circuit card (UICC) 330. It should be noted that on some terminals, UICC330 and ME340 may be implemented together in one secure processor. Also, although embodiments are described using UICCs, other integrated circuits and / or secure processing devices such as user identification modules (UIMs), subscriber identity modules (SIMs) or universal SIMs are implemented within the terminal. You may.
In general, UICC330 applies verification procedures for the security of MBMS transmission and supplies various keys to ME340. The ME340 uses the key provided by the UICC 330 to perform substantial processing, including, but not limited to, decrypting the MBMS content stream. UICC330 is entrusted with the secure storage and processing of confidential information (such as cryptographic keys) that must remain confidential for extended periods of time. Since the UICC330 is a secure device, the secrets stored in it do not necessarily require the system to change the secret information often. The UICC 330 may include a processor called a secure UICC processor (SUPU) 332 and a secure memory storage unit called a secure UICC memory unit (SUMU) 334. Within UICC330, SUMU334 stores confidential information in a way that blocks unauthorized access to the information. If confidential information could be obtained from the UICC 330, access would require a significant amount of resources. Also, within the UICC330, the SUPU332 performs calculations on values that may be outside the UICC330 and / or inside the UICC330. The result of the calculation may be stored in SUMU334 or passed to ME340.
In one embodiment, the UICC 330 is either a stationary device or integrated within a terminal 300. The UICC330 may also include insecure memory and processing (not shown) for storing information including telephone numbers, email address information, web page or URL address information, and / or scheduling functions. Alternative embodiments may provide removable and / or reprogrammable UICCs. Typically, SUPU332 does not have significant processing power for features that go beyond secure and key procedures, such as allowing encryption of MBMS broadcast content. However, an alternative embodiment may implement a UICC with higher processing power.
Although the UICC330 is a secure unit, the data in the ME340 may be accessed by non-subscribers and is said to be unsafe. Any information passed to or processed by ME340 is kept confidential for a short period of time. Therefore, it is often desirable that any confidential information, such as the key (s) shared with the ME340, be changed.
In particular, MBMS content is encrypted using a unique, frequency-changing temporary encryption key called a short-term key (SK). In order to decrypt the broadcast content at a particular time, the ME340 must know the current SK. SK is used to decrypt short broadcast content so that SK can assume that it has some inherent monetary value to the user. For example, this inherent monetary value may be part of the registration cost. Here, different content types may have different inherent monetary values. Assuming that the cost of a non-subscriber to obtain SK from subscriber ME340 exceeds the inherent monetary value of SK, the cost of obtaining SK illegally exceeds the reward and is not profitable. Therefore, it is not necessary to protect SK in ME340. However, if the broadcast has a real value that is greater than the cost of illegally obtaining this private key, it would be beneficial to non-subscribers to obtain such a key from the ME340. Therefore, the ME340 would ideally not remember secrets that had a lifetime longer than that of the SK.
In addition, the channels used by content providers (not shown) to transmit data are considered insecure. Therefore, SK is not transmitted wirelessly. It is derived by UICC330 or ME340 from an access key called a broadcast access key (BAK) and SK information (SKI) that is broadcast with the encrypted content. BAK may be used for a period of time, eg, one day, one week, or one month, and is renewed. Within each period for updating the BAK, a shorter interval is provided and the SK is changed during that period. Content providers may use cryptographic capabilities to determine two values, SK and SKI, so that SK can be determined from BAK and SKI. In one embodiment, the SKI may include an SK that is encrypted using BAK as a key. Alternatively, SK may be the result of applying a cryptographic hash function to the concatenation of SKI and BAK. Here, SKI may be a random value.
To gain access to MBMS, users register and subscribe to the service. In one embodiment of the registration process, the content provider and UICC330 agree on a registration key or a root key (RK) that acts as a security association between the user and the content provider. Registration may occur when a user subscribes to a broadcast channel provided by a content provider, or may occur prior to subscription. A single content provider may provide multiple broadcast channels. Content providers may choose to associate users with the same RK for all channels, or register each channel and require users to associate different RKs on different channels with the same user. May be good. Multiple content providers may choose to use the same registration key, or may require users to register and obtain different RKs.
Therefore, if possible, RK is kept secretly in UICC330. RK is specific to a given UICC. That is, each user is assigned a different RK. However, if the user has multiple UICCs, these UICCs may be configured to share the same RK depending on the content provider's policy. Therefore, the content provider may send the UICC 330 additional confidential information, such as RK-encrypted BAK. UICC330 can use RK to recover the value of the original BAK from the encrypted BAK. Since the ME340 is not a secret device, the UICC330 does not supply the BAK to the ME340.
The content provider also broadcasts the SKI combined with the BAK on the UICC 330 to derive the SK. The UICC330 then passes the SK to the ME340, which uses the SK to decrypt the encrypted broadcast transmission received from the content provider. In this way, the content provider can efficiently deliver the new value of SK to the subscribed users.
As described, controlled access may be achieved by supplying SUMU334 of UICC330 with RK consent. However, in the existing infrastructure of some systems, the proper value of RK is due to the cost and / or inconvenience of existing UICCs, SIMs, UIMs or other integrated circuit cards, to a secure device like UICC330. Cannot be maintained.
For example, in a GSM system, a subscriber identification module (SIM) is a secure device that contains subscriber identification data about a user that can be used to access the network. For purposes of illustration, FIG. 4 shows a simplified example of a GSM system 400 for authenticating subscribers to allow access to the network. System 400 includes terminals such as Home Location Register (HLR) 410, Visitor Location Register (VLR) 420 and Mobile Device 430. It should be noted that the system 400 contains additional elements, but the GSM system is well known to those of skill in the art and will not be described in detail.
HLR410 is a subscriber database for mobile systems. The HLR410 is maintained by the terminal's home carrier and contains important user information for billing and authentication to the network. The VLR420 is also a database and contains temporary user information, such as the current location of the terminal, to manage requests from subscribers outside the area covered by the home system. When the user initiates a call and the user's terminal is outside the home area, the VLR420 is called HLR410 to get the information needed to process the call, including the information needed to authenticate the subscriber. connect.
Terminal 430 includes a SIM module 432 that reliably contains a subscriber authentication key (K) used to authenticate the subscriber. Here, a challenge-handshake authentication protocol known as Authenticated Key Agreement (AKA) is typically used for GSM authentication. In AKA, the network sends a challenge message to the subscriber terminal. The subscriber terminal responds to the value obtained using the one-way hash function. Here, the challenge message may be a random value. The network checks the response by comparing it with its own expected hash value. If the values match, the authentication is acknowledged. While generating this response, a key that can be used to guarantee the next communication is also generated.
Especially in GSM systems, the VLR420 requires authentication parameters from the HLR410. The HLR410 sends a 128-bit random number RAND, signed response (RES) and encryption key (Kc) to the VLR. Both RES and Kc are generated from the subscriber authentication keys K and RAND using different algorithms. Using this set of three authentications (RAND, RES, Kc), the challenge message is generated by sending a random number RAND to the terminal 430. The received RAND is passed to SIM432. SIM432 uses RAND and k to generate RES and Kc. The generated RES is returned to VLR420. VLR420 checks that the two values of RES match. If they match, the subscriber is authenticated and both the terminal and the network initiate encryption / decryption using Kc.
GSM SIM certainly contains the subscriber authentication key (K) used to authenticate the subscriber, but does not allow the supply of additional keys like RK. That is, existing GSM SIMs cannot be modified. Therefore, one way to deliver BAK for broadcast services may be to use Kc rather than RK to encrypt BAK. The content provider will send a message containing RAND and a Kc-encrypted BAK. The terminal receives the message and sends the RAND to the SIM as if it were normal GSM authentication. Therefore, RES and Kc are generated by SIM using RAND and K. Here, the RES generated by the SIM may be discarded. This protects against an attacker who may send a RAND and may record the RES returned for unauthorized access. Kc may be used to decrypt the encrypted BAK.
However, Kc is a 64-bit key. On the other hand, some broadcast services like MBMS are designed to provide 128-bit security. Therefore, you need to use a key longer than 64-bit to encrypt the BAK. As a result, multiple triads are used for BAK encryption.
FIG. 5 shows an exemplary system 500 with a network 510 for authentication and a terminal 520 for a broadcast service. Network 510 contains one or more content providers and other infrastructure elements required for broadcast services. Terminal 520 includes ICC522 connected to processor 524. In a GSM system, network 510 may include VLR and HLR, and ICC522 will be a SIM module as described in Figure 4. Generally, network 510 sends a challenge message to authenticate. The challenge message is used by terminal 520 to generate a BAK for controlled access. That is, the ICC522 of the terminal 510 securely stores the private key used in the occurrence of BAK. The operation of System 500 will be described with reference to Figure 6 below.
FIG. 6 shows a method 600 for secure processing in a device such as terminal 620, which securely stores a private key such as a subscriber authentication key in a security device such as ICC622. In method 600, the device receives multiple challenges from the network (610). Multiple challenges may be in one message or in multiple messages. Multiple encryption keys are generated based on the private key and multiple challenges (620). The access key is then generated based on multiple encryption keys (630). In system 500, for example, the private key must be kept in the ICC522, so the ICC522 is configured to generate an encryption key. Processor 524 is configured to generate an access key based on the encryption key.
Since the access key is typically longer than the encryption key, the access key is generated using multiple encryption keys. For example, in GSM for MBMS, the encryption key is 64 bits and the access key is 128 bits. In such cases, the access key can be generated using two encryption keys. Access keys may be generated from multiple encryption keys using any well-known technique. In one embodiment, the access key is generated by concatenating a plurality of encryption keys. In another embodiment, the access key is generated using a hash function on a plurality of encryption keys. The hash function may include SHA-1 to mix multiple encryption keys.
In the case of authentication, method 600 may further include using multiple challenge messages and private keys to generate the multiple authentication responses described with reference to FIG. At least one of the authentication responses may then be returned to the network using a transmitter (not shown) implemented within the terminal 520, and any authentication response not sent to the network may be discarded.
Therefore, after generating the access key, the method 600 may further comprise receiving the encrypted broadcast content and decrypting the broadcast content based on the access key. For example, in MBMS, the access key would be BAK. And SKI will be used to generate SK. In such cases, Method 600 may further include generating a temporary encryption / decryption key such as SK based on each challenge message and the current BAK. Therefore, the current SK can be used to decrypt and view / process encrypted content.
Therefore, the described embodiments allow a secure supply of access keys for broadcast services. Although embodiments have been described with reference to MBMS, it should be noted here that the scope of the invention applies to broadcast services other than MBMS and applies to various systems that require controlled access. There is. Similarly, the access key may be shorter or longer than 128 bits. Further, the present embodiment may be applied to a system other than the GSM system. For example, a UMTS system has a USIM that is similar to a GSM SIM and has a backward compatibility mode that allows it to operate as a GSM SIM.
Further, the embodiment may be implemented by hardware, software, firmware, middleware, microcode or any combination thereof. When implemented in software, firmware, middleware, or microcode, program code or code segments to perform the required tasks may be stored on machine readable media (not shown). The processor may perform the required tasks. A code segment may represent any combination of procedure, function, subprogram, program, routine, subroutine, module, software package, class, or instruction, data structure, or program statement. Code segments may connect to other code segments or hardware circuits by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. can be shared by memory, message passing, token passing (token). It may be passed, sent, and transmitted via any suitable means, including passing), network transmission, and the like. Further, the machine-readable medium may be implemented in a product used for a computer system, or may have a machine-readable code means embodied in the product.
Finally, it should be noted that the above embodiments are merely examples and should not be construed as limiting the invention. The description of the embodiments is intended to be exemplary and not to limit the scope of the claims. As such, this teaching is readily applicable to other types of equipment and many alternatives, modifications, and modifications will be readily available to those of skill in the art.
<figref num="1">Figure 1 is an example of wireless communication that can support broadcast services.</figref><figref num="2">Figure 2 shows a simplified network for implementing MBMS.</figref><figref num="3">Figure 3 shows a terminal that can subscribe to MBMS to receive multimedia content.</figref><figref num="4">Figure 4 is a simplified example of a GSM system.</figref><figref num="5">Figure 5 is an exemplary system with a network that performs authentication and terminals for broadcast services.</figref><figref num="6">FIG. 6 shows a method for secure processing in a device that securely stores a private key.</figref>
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2011135464A | Cited by | Japan | Search report |
| JP2011135464A | Cited by | Japan | Search report |
| JP2008259183A | Cited by | Japan | Examiner |
| JP2011135464A | Cited by | Japan | Examiner |
| JP2015506131A | Cited by | Japan | Search report |
| JP2015506131A | Cited by | Japan | Search report |
| WO02080449A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO02096150A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2001500327A | Cites | Japan | Search report |
| JP2001500327A | Cites | Japan | Search report |
| JP2001510970A | Cites | Japan | Search report |
| US2002091931A1 | Cites | United States of America | Search report |
| US2002091931A1 | Cites | United States of America | Search report |
| JP2002175505A | Cites | Japan | Search report |
| JP2002232962A | Cites | Japan | Search report |
| JP2002502204A | Cites | Japan | Search report |
| JP2002514024A | Cites | Japan | Search report |
| JP2002514024A | Cites | Japan | Search report |
| JP2002541685A | Cites | Japan | Search report |
| JP2003503896A | Cites | Japan | Search report |
| JP2003503896A | Cites | Japan | Search report |
| JP2004080663A | Cites | Japan | Search report |
| JP2004080663A | Cites | Japan | Search report |
| JP2004343764A | Cites | Japan | Search report |
| JP2004343764A | Cites | Japan | Search report |
| JP2004533174A | Cites | Japan | Search report |
| JP2004533174A | Cites | Japan | Search report |
| JPH10191459A | Cites | Japan | Search report |
| JPH11513853A | Cites | Japan | Search report |
| H. HAVERINEN ET AL: "EAP SIM Authentication draft-haverinen-pppext-eap-sim-11.txt", ONLINE, JPN6010050169, June 2003 (2003-06-01), ISSN: 0001711334 | Non-patent | – | Search report |
| DAN BROWN: "Techniques for Privacy and Authentication in Personal Communication Systems", IEEE PERSONAL COMMUNICATIONS, JPN6011013860, August 1995 (1995-08-01), pages 6 - 10, ISSN: 0001874278 | Non-patent | – | Search report |
21 members in 13 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 48579103 | United States of America | P | |
| 48579103 | United States of America | P | |
| 60485791 | United States of America | – | |
| 10870303 | United States of America | – | |
| 87030304 | United States of America | A | |
| 87030304 | United States of America | A | |
| 2004021850 | United States of America | W | |
| 2004021850 | United States of America | W | |
| 2003485791 | – | – | – |
| 2004870303 | – | – | – |
| 2004021850 | – | – | – |
| US20030485791P | – | – | – |
| US20040870303 | – | – | – |
| WO2004US21850 | – | – | – |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| US2005010774A1 | United States of America | A1 | |
| AU2004258561A1 | Australia | A1 | |
| CA2531590A1 | Canada | A1 | |
| WO2005008398A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2005008398A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200518543A | Taiwan Province of China | A | |
| MXPA06000274A | Mexico | A | |
| KR20060031852A | Republic of Korea | A | |
| EP1649630A2 | European Patent Office (EPO) | A2 | |
| IL173021A0 | Israel | A0 | |
| BRPI0412397A | Brazil | A | |
| CN1846395A | China | A | |
| RU2006103624A | Russian Federation | A | |
| JP2007529147AThis record | Japan | A | |
| AU2004258561B2 | Australia | B2 | |
| AU2004258561C1 | Australia | C1 | |
| EP1649630A4 | European Patent Office (EPO) | A4 | |
| RU2419223C2 | Russian Federation | C2 | |
| TWI386004B | Taiwan Province of China | B | |
| CA2531590C | Canada | C | |
| US8718279B2 | United States of America | B2 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Re-examination (zenchi) completed and case transferred to appeal boardAppealJAPANESE INTERMEDIATE CODE: A912A912 | A912 | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written submission of copy of amendment under section 19 (pct)JAPANESE INTERMEDIATE CODE: A524A524 | A524 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 2007529147
- Publication, DOCDB
- 2007529147
- Publication, EPODOC
- JP2007529147
- Application
- 2006518894
- Application, DOCDB
- 2006518894
- Application, EPODOC
- JP20060518894
Titles2
- Japanese
- 安全なブロードキャストシステムのための装置および方法
- English
- Equipment and methods for secure broadcast systems
Classification
- CPC, 13
- H04W12/08
- H04L9/0844
- H04L63/0428
- H04L63/06
- H04L2463/101
- H04W84/12
- H04L9/14
- H04L2209/601
- H04L2209/80
- H04W12/0431
- H04L9/0643
- H04L9/0877
- H04L9/0894
- IPC, 3
- H04L9 08
- H04L12 28
- H04L29 06
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo