Method and apparatus for security in a data processing system
Abstract
This record has no abstract on file.
Term
Term ended
Expired 8 October 2022, 4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
21 claims: 5 independent, 16 dependent
- 1安全な送信に関する方法、前記方法は、送信機により実行され、以下を具備する:送信のためにメッセージに関するショートタームキーを決定すること、前記ショートタームキーは、ショートタームキーアイデンティファイアを有する;前記メッセージに関するアクセスキーを決定すること、前記アクセスキーは、アクセスキーアイデンティファイアを有する;前記ショートタームキーで前記メッセージを暗号化すること;前記ショートタームキーアイデンティファイアを具備するインターネットプロトコルヘッダを形成すること;及び 受信機に対して、 前記インターネットプロトコルヘッダとともに前記暗号化されたメッセージを送信すること 、前記ショートタームキーアイデンティファイアは、アクセスキーを生成するために前記受信機によって使用され、前記アクセスキー及び前記ショートタームキーアイデンティファイアは、前記ショートタームキーを生成するために前記受信機によって使用される、方法。
- 2前記 ショートタームキーアイデンティファイアは、前記アクセスキーアイデンティファイアを具備する 請求項1記載の方法 。
- 3前記 ショートタームキーアイデンティファイアは、セキュリテキパラメータインデックス値をさらに具備する 、請求項2記載の方法 。
- 4前記 セキュリテキパラメータインデックス値は、乱数である 、請求項3記載の方法 。
- 5前記 ショートタームキーは、前記アクセスキーで前記ショートタームキーアイデンティファイアを暗号化することによって計算される 、請求項1記載の方法 。
- 6前記 インターネットプロトコルヘッダは、ESPヘッダの一部である 、請求項1記載の方法 。
- 7前記 インターネットプロトコルヘッダは、第2の乱数をさらに具備し、前記第2の乱数は、乱数アイデンティファイアを有する 、請求項6記載の方法。
- 8前記 ショートタームキーアイデンティファイアは、前記アクセスキーアイデンティファイア及び前記乱数アイデンティファイアを具備する 、請求項7記載の方法 。
- 9前記 ショートタームキーアイデンティファイアは、セキュリティパラメータインデックス値をさらに具備する 、請求項8記載の方法 。
- 10前記セキュリティパラメータインデックス値は、乱数である 、請求項9記載の方法 。
- 11前記 ショートタームキーは、前記ショートタームキーアイデンティファイア、前記第2の乱数、及び前記アクセスキーの関数として計算される 、請求項7記載の方法 。
- 12前記 ショートタームキーは、前記アクセスキーで前記ショートタームキーアイデンティファイア及び前記第2の乱数を暗号化することによって計算される 、請求項11記載の方法。
- 13送信の安全な受信に関する方法、前記方法は、受信機により実行され、以下を具備する:送信機から、 送信に固有のショートタームキーアイデンティファイアを受信すること、前記ショートタームキーアイデンティファイアは、ショートタームキーに対応する;前記ショートタームキーアイデンティファイアに基づいてアクセスキーを決定すること;前記ショートタームキーを復元するために、前記アクセスキーで前記ショートタームキーアイデンティファイアを暗号化すること;及び 前記ショートタームキーを使用して送信された情報を復号化すること。
- 14メモリ 記憶装置ユニットに前記ショートタームキーアイデンティファイア及び前記ショートタームキーを記憶すること、をさらに具備する 、請求項13記載の方法 。
- 15前記 ショートタームキーアイデンティファイアは、乱数及び前記アクセスキーに関連したアクセスキーアイデンティファイアから構成される 、請求項13記載の方法 。
- 16前記 ショートタームキーアイデンティファイアを暗号化することは、前記ショートタームキーを復元するために前記アクセスキーで前記ショートタームキーアイデンティファイア及び乱数を暗号化することをさらに具備する 、請求項13記載の方法 。
- 17放送サービスオプションをサポートするワイアレス通信システムにおいて、インフラストラクチャエレメントは、以下を具備する:送信に固有のショートタームキーアイデンティファイアを受信する 受信回路 、前記ショートタームキーアイデンティファイアは、ショートタームキーに対応する ;放送メッセージ復号化するための前記ショートタームキーを生成する ユーザ認識ユニット、前記ユーザ認識ユニット は、以 下を具備する: 前記ショートタームキーアイデンティファイアに基づいてアクセスキーを決定し、前記ショートタームキーアイデンティファイア及びアクセスキーの関数に基づいて前記ショートタームキーを生成する プロセシングユニット;及び 前記ショートタームキーを使用して前記ブロードキャストを復号する ために適合されたモービル装置ユニット、前記モービル装置ユニットは、以下を具備する: 複数のショートタームキー及びショートタームキーアイデンティファイアを記憶するためのメモリ記憶装置ユニット。
- 18前記 ユーザ認識ユニットは、複数のアクセスキー及びアクセスキーアイデンティファイアを記憶するための第2のメモリ記憶装置ユニットをさらに具備する 、請求項17記載のインフラストラクチャエレメント 。
- 19前記メモリ記憶装置ユニットは、安全なメモリ記憶装置ユニットである 、請求項17記載のインフラストラクチャエレメント。
- 20ワイアレス通信システムのためのインフラストラクチャエレメント、前記インフラストラクチャエレメントは、以下を具備する:送信に固有のショートタームキーアイデンティファイアを受信するための手段、前記ショートタームキーアイデンティファイアは、ショートタームキーに対応する;前記ショートタームキーアイデンティファイアに基づいてアクセスキーを決定するための手段;前記ショートタームキーを復元するために前記アクセスキーで前記ショートタームキーアイデンティファイアを暗号化するための手段;及び 前記ショートタームキーを使用して送信された情報を復号化するための手段。
- 21下記を具備するディジタル信号記憶装置:送信に固有のショートタームキーアイデンティファイアを受信機が受信するための命令の第1のセット、前記ショートタームキーアイデンティファイアは、ショートタームキーに対応する;前記ショートタームキーアイデンティファイアに基づいてアクセスキーを前記受信機が決定するための命令の第2のセット;前記アクセスキーで前記ショートタームキーアイデンティファイアを前記受信機が暗号化して、前記ショートタームキーを復元するための命令の第3のセット;及び 前記ショートタームキーを使用して送信された情報を前記受信機が復号化するための命令の第4のセット。
Independent claims21
107 paragraphs, as filed
The present invention generally relates to data processing systems, and more particularly to methods and devices relating to security in data processing systems.
Security in information systems, including data processing and communication systems, contributes to enforcement obligations, fairness, accuracy, confidentiality, feasibility, and a plethora of other desired criteria. Cryptography, the general field of cryptography, is used in electronic commerce, wireless communications, broadcasting, and has endless applications. In electronic commerce, encryption is used to prevent fraud and to support financial processing. In data processing systems, encryption is used to support subscriber identity. Encryption is also used to prevent hacking, protect web pages, and prevent access to confidential documents and various other confidential messages.
A system that employs encryption technology, often referred to as an encryption system, is divided into a symmetric encryption system and an asymmetric encryption system. Symmetric encryption systems use the same key (ie, private key) to encrypt and decrypt messages. In contrast, asymmetric encryption systems use a first key (ie, a public key) to encrypt a message and a second, different key (ie, private) to decrypt it. Key) is used. Asymmetric encryption systems are also called public key encryption systems. There is a problem with symmetric encryption systems in the secure supply of private keys from senders to recipients. In addition, problems exist when keys or other cryptographic mechanisms are updated frequently. In a data processing system, a secure way to update keys requires additional processing time, memory storage and other processing overhead. In wireless communication systems, updating keys use valuable bandwidth and are otherwise available for transmission.
The prior art does not provide a method for updating keys for a large group of mobile stations to allow access to encrypted broadcasts. Therefore, there is a need for a secure and efficient method of updating keys in data processing systems. In addition, there is a need for a secure and efficient method of updating keys in wireless communication systems.
[summary] The embodiments disclosed herein address the needs mentioned above by providing a security method in a data processing system. In one aspect, the method for secure transmission is to determine a short term key for the message for transmission, where the short term key has a short term key header and an access key for the message. Where the access key has an access key identifier, encrypts the message with the access key, and forms an internet protocol header with a short term key identifier. , And sending encrypted messages with Internet Protocol headers.
In another aspect, in a wireless communication system that supports broadcast service options, the infrastructure element is the receiving circuit, the user recognition unit, which effectively restores the short time key for decoding the broadcast message. And includes mobile device units adapted to apply short time keys for decrypting broadcast messages. The user recognition unit includes a processing unit that effectively decodes the key information. The mobile device unit includes a memory storage device unit for storing a plurality of short term keys and short term key identifiers.
In yet another aspect, the digital signal storage is the first set of instructions for receiving a transmission-specific short term key identifier, the short term key identifier corresponding to the short term key. And a second set of instructions to determine the access key based on the short term key identifier, the instruction to encrypt the short term key identifier with the access key to restore the short term key. Includes a third set, and a fourth set of instructions for decrypting the transmission using the short term key.
The term "exemplari" is widely used here and means "acting as an example, case, or example." It is not necessary that any of the embodiments disclosed herein as "Exemplarly" be construed as preferred or superior to other embodiments.
Wireless communication systems are widely deployed and provide various types of communications such as voice, data, and others. These systems can be based on code division multiple access (CDMA), time division multiple access (TDMA), or other modulation techniques. CDMA systems offer certain advantages over other types of systems, including increased system capacity.
The system is referred to here as the IS-95 standard "TIA / EIA-95-B Mobile Station-Base Station Compatibility Standard for Dual Mode Wideband Spread Spectrum Cellular Systems", here referred to as 3GPP "3rd A standard proposed by a consortium named "Generation Partnership Project" (3GPP), 3G TS 25.302, which is included in a set of documents including document numbers 3G TS 25.211, 3G TS 25.212, 3G TS 25.213, and 3G TS 25.214. , Cited here as the W-CDMA standard, this standard was proposed by a consortium named "3rd Generation Partnership Project 2", here cited as 3GPP2, and here as cdma2000, previously. May be designed to support one or more CDMA standards, such as TR-45.5, called IS-2000 MC. These named standards are incorporated here as references.
Each standard specifically specifies the processing of data for transmission from the base station to the mobile and vice versa. As an example implementation, the following discussion considers a diffusion spectrum communication system that is consistent with the cdma2000 system. Alternative embodiments may incorporate other standards / systems. Yet another embodiment may apply the security methods disclosed herein to any type of data processing system that uses an encryption system.
An encryption system is a method of identifying a message that allows a particular group of users to extract the message. FIG. 1 illustrates the basic encryption system 10. Cryptographic technology is a technology that creates and uses an encryption system. Cryptanalysis is a technique that breaks a cryptographic system, that is, receiving and understanding a message when it is not in a particular group of users who are authorized to access the message. The original message is called a plain text message or plain text. The encrypted message is called cipher text. Here, encryption includes any means of converting plain text to cipher text. Decryption includes any means of converting cipher text to plain text. That is, the original message is restored. As shown in Figure 1, plaintext messages are encrypted to form cypher text. The cipher text is then received, decrypted and restored in plain text. Although the terms plain text and cipher text generally refer to data, the idea of encryption can be applied to any digital information, including audio and video data expressed in digital form. Although the description of the invention given herein uses the terms plain text and cipher text consistent in the field of cryptographic technology, these terms do not preclude other forms of digital communication.
The encryption system is based on confidentiality. A group of entities shares a secret if the entities outside this group cannot acquire the secret without a very large amount of resources.
Cryptographic systems can be a collection of algorithms. Here, each algorithm is labeled and the label is called a key. Symmetric cryptosystems, often referred to as cryptosystems, use the same key (ie, private key) to encrypt and decrypt messages. The symmetric encryption system 20 is shown in FIG. 2, where encryption and decryption utilize the same private key.
In contrast, asymmetric encryption systems use a first key (eg, a public key) to encrypt a message and a different key (eg, a private key) to decrypt it. .. Figure 3 shows an asymmetric encryption system, where one key is given for encryption and a second key is given for decryption. Asymmetric encryption systems are also called public key encryption systems. The public key is made public and can be used to encrypt any message. However, only a private key can be used to decrypt a message encrypted with a public key.
There is a problem with symmetric encryption systems in the secure supply of private keys from senders to recipients. In one solution, a courier can be used to provide information. Alternatively, a more efficient and reliable solution can use a public key cryptosystem, such as the public key cryptosystem specified by Rivest, Shamir and Adreman (RSA) described below. RSA system is Pretty Good Privacy) (PGP), which is used in a reputable security tool called, discussed in more detail below. For example, the first recorded cryptosystem transforms characters in plain text by shifting each character by n in the alphabet. Here, n is an integer value of a predetermined constant. In such schemes, "A" is replaced with "D" etc. Here, a given encryption scheme may incorporate several different values of n. In this encryption scheme, "n" is the key. The specified recipient is given an encryption scheme prior to receiving the cipher text. In this way, only those who know the key can decrypt the ciphertext and restore the plaintext. However, by calculating the key with cryptographic knowledge, an unspecified population may be able to eavesdrop and decrypt the cipher text, creating a security issue.
More complex and sophisticated cryptosystems employ strategic keys to prevent eavesdropping and decryption from unspecified populations. The classical encryption system employs encryption function E and decryption function D as follows: D_K (E_K (P)) = P, for any plain text P (1) In public key cryptosystems, E_K is easily calculated from the known "public key" Y, and Y is in turn calculated from K. Public key Y is public, and as a result, anyone can encrypt the message. The decryption function D_K can be calculated from the public key Y, but only using the knowledge of the private key K. Without the use of private key K, unspecified populations will not be able to decrypt similarly generated cipher text. In this way, only the person who generated K can decrypt the message.
RAS is a public key cryptosystem defined by Rivest, Shamir and Adreman. Where, for example, plain text is 2<sup>512</sup>Consider positive integers up to. The keys are quadruples (p, q, e, d), where p is given as a 256-bit prime, q is a 258-bit prime, and d and e are (de-1) (p-1). ) (Q-1) is a large number divisible by. In addition, define the encryption function as follows: E_K (P) = P<sup>e</sup> mod pq, D_K (C) = C<sup>d</sup> mod pq (2) E_K can be easily calculated from the set of (pq, e), but no simple method is known to calculate D_K from the set of (pq, e). Therefore, the recipient who generates K can publish (pq, e). Since the recipient is the one who can read the message, it is possible to send a secret message to the recipient.
PGP integrates the features of symmetric and asymmetric cryptography. 4 and 5 show the PGP encryption system 50. Here, the plaintext message is encrypted and restored. In Figure 4, the plaintext message is compressed, saving modem transmission time and disk space. Compression enhances the security of cryptographic techniques by adding other levels of conversion to encryption and decryption processing. Many cryptanalysis techniques utilize patterns found in plain text to unravel cyphers. Compression reduces these patterns in plain text, thereby increasing its resistance to cryptanalysis. Note that some embodiments do not compress plain text, or other messages that are too short to be compressed, or those that cannot be compressed well.
PGP then generates a session key. This is a one-time private key. This key is a random number that can be generated from any random phenomenon. For example, a random movement of a computer mouse and / or a typing keystroke. The session key works with a secure encryption algorithm to encrypt plaintext, resulting in ciphertext. Once the data is encrypted, the session key is then encrypted to the recipient's public key. The public key encrypted session key is sent to the recipient along with the cipher text.
For decryption, as shown in Figure 5, the PGP recipient copy uses the private key and restores the temporary session key. PGP then uses it to decrypt traditionally encrypted cipher text. The combination of encryption methods has the advantages of the convenience of public key encryption and the speed of symmetric encryption. Symmetric encryption is generally much faster than public key encryption. Public key encryption, in turn, provides solutions to key distribution and data transmission problems. In combination, outcomes and key distribution are improved without any security sacrifice.
A key is a value that works with cryptographic algorithms to generate a particular cipher text. The keys are basically very large numbers. The key size is measured in bits. In public key cryptography, security increases with key size, but public key size and symmetric encryption private key size are generally irrelevant. Public and private keys are mathematically related, but given the public key alone creates difficulties in deriving the private key. Derivation of a private key is possible given sufficient time and computer power, making key size selection an important security issue. The best goal is to maximize the key size from a security point of view, but minimizing the key size facilitates rapid processing. Large keys are cryptographically secure for a long period of time. Additional considerations are the expected eavesdroppers, specifically: 1) what is the importance of the message to the third party, and 2) how much resources the third party has to decrypt the message. Whether the party has it.
Note that the key is stored in encrypted form. PGP specifically stores in two files: one for the public key and one for the private key. These files are called keyrings. In application, the PGP cryptosystem adds the desired recipient's public key to the sender's public keyring. The sender's private key is stored in the sender's private key ring.
As discussed in the example above, the method of distributing the keys used in encryption and decryption can be complex. The "key exchange problem" is primarily with respect to ensuring that the keys are exchanged and, as a result, both the sender and the receiver can perform encryption and decryption, respectively, and bidirectional communication. As a result, the sender and receiver can both encrypt and decrypt the message. In addition, key exchanges are preferably performed to eliminate eavesdropping by third parties and undesignated groups.
Finally, an additional consideration is authentication, which gives the recipient a guarantee that the message is encrypted by the specified sender and is not a third party. In a private key exchange system, keys are exchanged secretly, providing improved security in good key exchange and valid authentication. Note that the private key encryption scheme explicitly provides authentication. The underlying assumption in a private key encryption system is that only the specified sender has a key that can encrypt the message delivered to the specified recipient. A method of public key cryptography solves the critical aspect of the'key exchange problem', specifically resistance to decryption in the presence of passive eavesdroppers during key exchange, but still , It does not solve all the problems related to key exchange. In particular, some other mechanism is preferred to give authentication, as the key takes into account'public knowledge'(especially in RSA). Authentication is sufficient to encrypt the message, but it is preferable to own the key alone, there is no proof of a particular unique identity of the sender, and it is itself to establish the identity of the recipient. You also don't have enough corresponding decryption keys.
One solution is that the listed keys are actually those of a given entity, sometimes a trusted authority, a certificate authority, and a third party escrow. It is to develop a key distribution mechanism that guarantees that it is called agent). The authority typically does not actually generate the key, but is kept for reference by the sender and receiver, ensuring that the published key and associated list of identities are correct and flawless. .. Another way is to rely on users to distribute and track each other's keys, and to trust the informally distributed form. Under RSA, the signature is encrypted with a private key if the user wishes to send proof of identity in addition to the encrypted message. The recipient can conversely use the RSA algorithm to demonstrate that the information has been decrypted. As a result, only the sender can encrypt the plaintext with the user's private key. Typically, an encrypted'sign'is a'message digest' with a unique mathematical'summary' of a secret message (if the sign doesn't change across multiple messages, once you know it). Recipients can use it illegally). In this way, in theory, only the sender of the message should be able to generate a legitimate signature for the message, thereby proving to the recipient.
Message digests are often calculated using cryptographic hash functions. Cryptographic hash functions calculate a value (having a certain number of bits) from any input, regardless of the length of the input. One property of a cryptographic hash function is: a given output value, and it is difficult to computationally determine the input that should produce that output. An example of a cryptographic hash function is SHA-1, which is described in the "Secret Hash Standard", FIPS PUB 180-1. It was published by Federal Information Processing Standards Publications (FIPS PUBS) and published by the National Institute of Standards and Technology.
FIG. 6 serves as an example of the communication system 100. It supports a large number of users and is capable of implementing at least some aspects and embodiments of the present invention. Any of a variety of algorithms and methods can be used in system 100 to plan transmissions. System 100 provides communication for a large number of cells 102A to 102G. Each of the cells is serviced by the corresponding base stations 104A through 104G. In an exercising embodiment, some of the base stations 104 have a plurality of receiving antennas and others have only one receiving antenna. Similarly, some of the base stations 104 have multiple transmitting antennas and others have one transmitting antenna. There are no restrictions on the combination of the transmitting antenna and the receiving antenna. Therefore, the base station 104 may have multiple transmit antennas and one receive antenna, or may have multiple receive antennas and one transmit antenna, or both may have one or more transmit and receive antennas. It is possible to have.
Terminal 106 in the communication area<u style="single">A, 106B, 106C, 106D, 106E, 106F, 106G, 106H and 106I</u>Can be fixed (ie, stationary) or moving. As shown in FIG. 6, the various terminals 106 are distributed throughout the system. Each terminal 106 depends, for example, on whether soft handoff is employed or whether the terminal is designed and operates to receive multiple transmissions (simultaneously or continuously) from multiple base stations. It communicates with at least one, and perhaps more, base station 104 on the downlink or uplink at any given moment. Soft handoffs in CDMA communication systems are well known in the art and are described in detail in US Pat. No. 5,101,501, entitled "Methods and Systems of Providing Soft Handoffs in CDMA Cellular Telephone Systems." This has been assigned to the assignee of the present invention.
Downlink refers to transmission from a base station to a terminal, and uplink refers to transmission from a terminal to a base station. In its exemplary embodiment, some of the terminals 106 have multiple receiving antennas and others have only one receiving antenna. In FIG. 6, base station 104A transmits data to terminals 106A and 106J on the downlink, base station 104B transmits data to terminals 106B and 106J on the downlink, and base station 104C transmits data to terminals 106C and 106C on the downlink. Data is sent to, and so on.
The increasing demand for wireless data transmission and the expansion of services available through wireless communication technology have led to the development of certain data services. One such service is called High Data Rate (HDR). The exercising HDR service is proposed in the "EIA / TIA-IS856 cdma2000 high-rate packet data air interface specification" and is called the "HDR specification". HDR services are generally overlays on voice communication systems and provide an efficient way to send packets of data in wireless communication systems. As the amount of data transmission and the number of transmissions increase, the limited bandwidth available for high frequency transmission becomes a critical resource. Therefore, there is a need for an efficient and equitable method of transmission scheduling in communication systems that optimizes the use of available bandwidth. In an exercising embodiment, the system 100 shown in FIG. 6 is consistent with a CDMA type system having HDR service.
According to one embodiment, the system 100 supports a high-speed multimedia broadcasting service called a high-speed broadcasting service (HSBS). One application of HSBS is video streaming for movies, sporting events, etc. The HSBS service is a packet data service based on the Internet Protocol (IP). According to its exercising embodiment, the service provider indicates the availability of such a high-speed broadcast service to the user. Users wishing for HSBS services can sign up to receive the service and find broadcast service schedules through advertising, short management systems (SMS), wireless application protocols (WAP), etc. Mobile users are referred to as mobile stations (MS). The base station (BS) sends HSBS-related parameters in overhead messages. If the MS wants to receive a broadcast session, the MS reads the overhead message and learns the proper configuration. The MS then tunes to the frequency containing the HSBS channel and receives the broadcast service content.
The service considered is a high-speed multimedia broadcasting service. This service is referred to in this document as the High Speed Broadcast Service (HSBS). One such example is video streaming of movies, sporting events, etc. This service may be a packet data service based on the Internet Protocol (IP).
The service provider indicates to the user the availability of such a high-speed broadcast service. Mobile station users who desire such a service should apply to receive this service and can find the broadcast service schedule through advertisements, SMS, WAP, etc. The base station transmits parameters related to the broadcasting service in the overhead message. A mobile wishing to listen to a broadcast session should read these messages, determine the appropriate configuration, tune to the frequency containing the high-speed broadcast channel, and begin receiving broadcast service content.
There are several possible subscription / revenue models for HSBS services, including free access, controlled access, and partially controlled access. For free access, non-subscription is required for mobiles to receive the service. BS broadcasts the content unencrypted, and interested mobiles receive the content. Revenues for service providers can be generated through advertising and can also be transmitted over broadcast channels. For example, a movie clip to be shown may be transmitted, for which the production company pays the service provider.
For controlled access, MS users subscribe to the service and pay for the broadcast service they receive. Users who have not subscribed to the service cannot receive the HSBS service. Managed access can be achieved by encrypting HSBS transmissions / content so that only subscribed users can decrypt the content. It may use a radio broadcast encryption key exchange procedure. This scheme provides strong security and prevents services from being stolen.
The hybrid access scheme, called Partially Managed Access, provides HSBS services as a service based on encrypted applications, along with intermittent unencrypted promotional transmissions. These promotions may be intended to facilitate subscriptions to encrypted HSBS services. Scheduling of such unencrypted segments is known through external means.
The wireless communication system 200 is shown in FIG. Here, the video and audio information is provided to the data service network (PDSN) 202 packetized by the content server (CS) 201. Video and audio information may come from programming or wireless transmission broadcast on television. The information is provided as packetized data, such as in an IP packet. PDSN202 processes IP packets for distribution within the access network (AN). As illustrated, AN is defined as part of the system that includes BS204 communicating with multiple MS206s. PDSN202 is connected to BS204. For the HSBS service, the BS204 receives a stream of information from the PDSN202 and provides the information on the channel designated to the subscriber in the system 200. To control access, the content is encrypted by CS201 before being provided to PDSN202. The subscribed user is provided with a decryption key, which allows the IP packet to be decrypted.
FIG. 8 describes the MS300 in detail and is similar to the MS206 in FIG. The MS300 has an antenna 302 connected to the receiving circuit 304. The MS300 receives transmissions from a BS (not shown) similar to BS204 in FIG. The MS300 includes a user identification module (UIM) 308 and a mobile device (ME) 306. The receiving circuit is connected to UIM308 and ME306. UIM308 applies verification procedures to the security of HSBS transmissions and provides various keys to ME306. The ME306 may be connected to the processing unit 312. The ME306 performs substantial processing, including, but not limited to, decoding the HSBS content stream. ME306 includes a memory storage unit, MEM310. In an exercising embodiment, the data in the ME306 processing unit (not shown) and the data in the ME memory storage unit, MEM310, may be easily accessed by non-subscribers due to the use of limited resources. And therefore the ME306 is said to be unsafe. Any information passed to or processed by ME306 will be kept confidential for a short period of time. Therefore, any confidential information, such as keys, shared with ME306 is desired to be changed frequently.
UIM308 is trusted to store and process confidential information (such as encryption keys) that should be kept secret for extended periods of time. Since the UIM308 is a secure unit, the secrets stored there do not require the system to frequently change the secret information. The UIM308 includes a processing unit called the Safe UIM Processing Unit (SUPU) 316 and a memory storage unit called the Safe UIM Memory Unit (SUMU) 314, which is trusted to be safe. Within UIM308, SUMU314 stores confidential information in a way that prevents unauthorized access to the information. If confidential information is obtained from UIM308, access requires a huge amount of resources. Among UIM308, SUPU316 performs calculations of values that are not essential to UIM308 and / or may be essential to UIM308. The result of the calculation can be stored in SUMU314 or passed to ME306. Calculations performed using SUPU316 can only be obtained from UIM308 by entities with vast amounts of resources. Similarly, the output from SUPU316 (but not the output to ME306) specified to be stored in SUMU314 is designed so that unjust eavesdropping requires a huge amount of resources. In one embodiment, the UIM308 is a fixed unit in the MS300. In addition to secure memory and processing in UIM308, UIM308 is an insecure memory for storing information including phone numbers, e-mail address information, web page or URL address information, and / or scheduling functions, etc. And processing (not shown) can also be included.
An alternative embodiment provides a removable and / or reprogrammable UIM. In an exercising embodiment, SUPU316 does not have significant processing capabilities for functions beyond security and key procedures. Here, security and key procedures can typically be used to enable encryption of HSBS broadcast content. An alternative embodiment may implement a UIM with stronger processing capabilities.
UIM308 is used to primarily authenticate that the MS300 is associated with a particular user and names the rights granted to the user, such as accessing a mobile telephone network. Therefore, some users are associated with UIM308 rather than MS300. The same user may be associated with multiple UIM308s.
Broadcast services face the problem of deciding how to distribute keys to subscribed users. In order to decrypt the broadcast content at a particular time, the ME needs to know the current decryption key. To avoid eavesdropping on services, decryption keys change frequently, for example, one service updates the key every minute. These decryption keys are called short term keys (SK). The SK is used to decode the broadcast content in a short period of time, and it can be assumed that the SK has a certain amount of intrinsic momentary value for the user. For example, this intrinsic momentary value may be part of the registration cost. It is assumed that the cost of a non-subscriber to acquire SK from the subscriber's memory storage unit MEM310 exceeds the intrinsic momentary value of SK. That is, the cost of illegally acquiring SK outweighs the rewards, and as a result, there is no ultimate benefit. As a result, the need to protect the SK in the memory storage unit MEM310 is reduced. However, if the private key has a lifetime longer than the SK lifetime, the cost of illegally acquiring this private key may actually be less than in return. In this situation, there is a final benefit to illegally obtaining such a key from the memory storage unit MEM310. Therefore, ideally the memory storage unit MEM310 should not store secrets that have a lifetime longer than the SK lifetime.
The channels used by CS (not shown) to distribute SK to various subscriber units are assumed to be insecure. In other words, the optimal design assumes that the channel is unsafe and the SK is designed accordingly. Therefore, when distributing a given SK, CS wants to use a technique that hides the SK value from non-subscribers. In addition, CS distributes SK to each of the large number of potential subscribers for processing in each ME within a relatively short time frame. Well-known secure methods of key transmission are traditionally slow and require the transmission of a large number of keys. Key transmission methods are generally not feasible for the desired combination of security and efficiency criteria. In an exercising embodiment, it is a viable way to distribute a decryption key to a large set of subscribers in a short time frame in such a way that non-subscribers cannot obtain the decryption key.
An exercising embodiment is described as transmitting information in packets compatible with the Internet Protocol. For example, something like "IPSec" as described below. And therefore, the following description gives a brief introduction to the terms used in connection with IPSec. Although the term is valid to describe an exemplary embodiment, the use of this term does not mean limiting the exemplary embodiment for communicating using IPSec.
The basis of IPSec is RFC1825, entitled "Security System for Internet Protocols" by Earl Atkinson in August 1995, RFC1826, entitled "IP Authentication Header" by Earl Atkinson in August 1995, and August 1995. Earl It is described in detail in RFC 1827 entitled "IP Encapsulating Security Payload (ESP)" by Atkinson. Authentication headers are a mechanism for giving reliability to IP datagrams. Here, an IP datagram is a collection of useful information, generally referred to as a payload, integrated with network control information and IP headers. The network router uses the IP header to direct the packet to the appropriate network node. In some environments, the authentication header can also provide authentication for IP datagrams. ESP is a mechanism that provides confidentiality and reliability for IP datagrams and may be used with authentication headers. IPSec utilizes "security associations" to describe parameters, such as encryption keys and encryption algorithms, used to encrypt and / or authenticate communications between group entities. The concept of security associations is also valid when applied to cryptographic systems that are not based on IPSec.
The IPSec packet contains a 32-bit parameter called the Security Parameter Index (SPI). The SPI, along with the destination address, is used to recognize the security association used to encrypt and / or authenticate the content of the IP datagram. One entity can store security associations in the security association database and search for security associations according to the destination address and SPI. The encrypted content of IPSec packets is often referred to as the payload.
In an exercising embodiment, the MS300 supports HSBS in a wireless communication system. To gain access to HSBS, the user must register for the service and then subscribe. Once the application is enabled, the various keys will be updated as needed. In the registration process, CS and UIM308 negotiate a security association and agree on the registration key (RK) and other parameters required for the security association between the user and CS. The CS can then send subsequent RK-encrypted confidential information to the UIM308. RK is kept secret in UIM308, but other parameters may be kept in ME306. RK is unique to a given UIM308. That is, each user is assigned a different RK. The registration process alone does not give users access to HSBS.
As mentioned above, after registration, the user subscribes to the service. In the application process, CS sends the value of the common broadcast access key (BAK) to UIM308. Note that while RK is specific to UIM308, BAK is used to encrypt broadcast messages to multiple users. The CS sends the BAK value encrypted using the UIM308's unique RK to the MS300, and especially the UIM308. UIM308 can restore the original BAK value from the encrypted version using RK. Along with other parameters, BAK forms a security association between CS and a group of subscribed users. BAK is kept secret in UIM308. On the other hand, other parameters of the security association may be retained in ME306. The CS then broadcasts data called SK information (SKI). SKI is integrated with BAK in UIM308 to derive SK. UIM308 then passes SK to ME306. In this way, CS can efficiently distribute the new value of SK to the ME of the subscribed user. The following are some examples of how SK is derived from SKI and the forms that SKI may take. The registration and application process will be discussed in detail, followed by SKI and SK.
Regarding registration, UIM308 and CS (not shown) set up a security association when the user registers with a given CS. That is, UIM308 and CS agree on the secret registration key RK. RKs are unique to each UIM308, although if the user has multiple UIMs, these UIMs may share the same RK depending on the CS approach. This registration may occur when the user subscribes to the broadcast channel applied for by CS, or may occur before the application. One CS can apply for multiple broadcasting channels. CS chooses to connect users with the same RK for all channels, or require users to register for each channel, and connect the same users with different RKs for different channels. it can. Multiple CSs can choose to use the same registration key, or the user can request each CS to register and acquire different RKs.
And 3) Broadcast service provisioning (OTASP). In either case, the UIM memory unit SUMU314 contains a private key, which is referred to here as the A-key. For example, using the AKA method, the A-key is a secret known only to UIMs and trusted third parties (TTPs). Here, the TTP can consist of one or more entities. TTP is typically a mobile service provider with users registered there. All communications between CS and TTP are secure, and CS trusts that TTP should not assist in illegal access to broadcast services. When the user registers, the CS informs the TTP that the user wants to register for the service and gives confirmation of the user's request. TTP uses a function similar to the hash function of cryptography to calculate RK from additional data called A-key and registration key information (RKI). TTP passes RK and / or RKI along with other data to CS over a secure channel. CS sends RKI to MS300. The receiver circuit 304 can pass the RKI to the UIM308 and the RKI to the ME306. UIM308 calculates RK from the A-key stored in RKI and UIM memory unit SUMU314. RK is stored in the UIM memory unit SUMU314 and is not given directly to ME306. An alternative embodiment can use an IKE scenario or some other method and sets the RK. Other parameters of the security association between CS and UIM308 are also negotiated. RK is kept secret in UIM308, while other parameters of the security association may be kept in ME306. In an exercising embodiment, the BAK is transmitted to the UIM308 as an IPSec packet encrypted using RK. CS and MS300 are SPI values used to point to security associations Arrange. And this SPI is expressed as SPI_RK.
Under the AKA method, RK is a secret shared between CS, UIM and TTP. Therefore, as used here, the AKA method implies that any security association between CS and UIM implies TTP. What TTP includes in any security association does not consider security breaches, as CS trusts that TTP does not assist in illegal access to broadcast channels. As mentioned above, if the key is shared with ME306, it is preferable that the key be changed frequently. This is due to the risk of non-subscribers accessing the information stored in the memory storage unit MEM310. And in this way, it allows access to managed or partially managed services. The ME306 stores the SK, that is, the key information used for decoding the broadcast content, in the memory storage device unit MEM310. CS sends enough information to the users who subscribed to calculate the SK. If the subscribed user's ME306 can calculate the SK from this information, the additional information required to calculate the SK need not be confidential. In this case, it is assumed that the non-subscriber ME306 can calculate the SK from this information. Therefore, the value of SK is calculated in SUPU316 using the private key shared by CS and SUMU314. CS and SUMU314 share the value of RK. However, each user has a unique value of RK. There is not enough time for CS to encrypt each value of RK and send these encrypted values to each subscriber user.
Regarding the application, CS will regularly distribute the Common Broadcast Access Key (BAK) to each subscriber UIM308 to ensure the efficient distribution of Confidential Information SK. For each subscriber, CS uses the corresponding RK to encrypt the BAK and obtain a value called BAKI Information (BAKI). CS sends the corresponding BAKI to the subscribed user's MS300. For example, the BAK may be sent as an IP packet encrypted using the RK that corresponds to each MS. In an exercising embodiment, the BAKI is an IPSec packet containing a BAK encrypted using RK as the key. Since RK is the key for each user, CS needs to send BAK to each subscriber individually. Therefore, BAK is not transmitted over the broadcast channel. MS300 passes BAKI to UIM308. SUPU316 calculates BAK using the RK value and BAKI value stored in SUMU314. The BAK value is then stored in SUMU. In an exercising embodiment, BAKI contains an SPI value expressed as SPI_RK. SPI_RK supports security associations including RK. The MS300 knows that the UIM308 can decrypt the payload if the IPSec packet is encrypted according to this security association. Therefore, when the MS300 receives an IPSec packet encrypted according to this security association, the MS300 passes BAKI to the UIM308, instructing the UIM308 to use the RK to decrypt the payload.
The period for updating the BAK is preferably sufficient to allow the CS to send the BAK to each individual subscriber without incurring significant overhead. UIM308 does not provide BAK to ME306 because it is not trusted to keep confidential for a long time. Other parameters of the security association between the CS and the group of subscribers are also negotiated. In some embodiments, these parameters are fixed, but in other embodiments, these parameters may be transmitted to the MS as part of BAKI. While BAK is kept secret in UIM308, other parameters of the security association may be kept in ME306. In one embodiment, there the SK sends to the MS300 as an IPSec packet encrypted using the BAK, and the CS provides the subscriber with the SPI used to index the security association. And SPI is expressed as SPI_BAK.
The following paragraph discusses how SK is updated following a good application process. Within each period of updating the BAK, short term intervals will be provided while the SK is distributed on the broadcast channel. CS uses cryptographic functions to determine two values, SK and SKI (SK information). As a result, SK can be determined from BAK and SKI. For example, SKI could be SK encryption using BAK as a key. In one exemplary embodiment, the SKI is an IPSec packet, where the payload contains a value of SK encrypted using BAK as a key. Alternatively, SK may be the result of applying a cryptographic hash function to the concatenation of blocks SKI and BAK. CS ideally guarantees that the value of SK is unpredictable. If the SK is predictable in advance, an attacker, i.e. an illegally accessing entity, can send the predicted SK value to an unsubscribed user.
As an example, assume that the N value of SK is used for 24 hours. If the SK is predicted with 100% accuracy, the attacker only needs to ask the UIM to calculate the N key. The attacker then creates an N key that can be used by unsubscribed users. Unsubscribed users can download the key at the beginning of each day and access the HSBS service at no cost or inconvenience. If the attacker can predict the SK with 50% accuracy, the attacker needs to send almost 2N keys. As the accuracy of the prediction decreases, the number of keys to be generated by the attacker increases. Attackers discourage distributing forecasts to SK by ensuring that the costs of generating, remembering, and distributing forecasts outweigh the benefits of giving illegal access. Can be done. By ensuring that the accuracy of any prediction by the attacker is small enough, the attacker can be disappointed, and therefore as the number of keys increases, the attacker costs to give illegal access. Generates to the point where the profit exceeds the profit. As a result, any scheme that produces SK ideally ensures that the attacker's best predictions have sufficiently small accuracy. That is, the calculation of SK includes some random values that can be predicted in advance with little accuracy.
In some exercising embodiments where the SK exists in an encrypted form, the CS can select the SK using a random or pseudo-random function. In an alternative embodiment, here the SK is derived by applying cryptographic functions to the SKI and BAK, the CS introduces unpredictable values when forming the SKI. Some parts of the SKI may be predictable. For example, a portion of the SKI may be derived from the system time, which is the period during which this SKI is valid. This part, represented as SKI_PREDICT, may not be sent to the MS300 as part of the broadcast service. SKI's reminder, SKI_RANDOM, can be unpredictable. That is, SKI_RANDOM is predicted with low accuracy. SKI_RANDOM is sent to the MS300 as part of the broadcast service. The MS300 reproduces the SKI from SKI_PREDICT and SKI_RANDOM and supplies the SKI to the UIM308. SKI may be reproduced in UIM308. The value of SKI changes for each new SK. In this way, either SKI_PREDICT and / or SKI_RANDOM changes when calculating a new SK.
CS sends SKI_RANDOM to BS for broadcast transmission. BS broadcasts SKI_RANDOM. This is detected by the antenna 302 and passed to the receiving circuit 304. The receiving circuit 304 supplies SKI_RANDOM to the MS300. Here, the MS300 reproduces SKI. MS300 supplies SKI to UIM308. Here, UIM308 uses the BAK stored in SUMU314 to acquire SK. SK is then supplied to UIM308 by ME306. ME306 stores SK in the memory storage device unit, MEM310. ME306 uses SK to decode the broadcast transmission received from CS.
CS and BS agree on some criteria for when SKI_RANDOM is transmitted. The CS may wish to reduce the temporary values inherent in each SK by changing the SKs frequently. In this situation, the desire to change the SKI_RANDOM data is balanced against optimizing the available bandwidth. In some exemplary embodiments, SKI_RANDOM is transmitted with encrypted content. This allows the MS300 to generate an SK and start decrypting it immediately. In many situations this wastes bandwidth. One exception is the scheme in which SKI_RANDOM is sent as a communication parameter. For example, the SPI value in IPSec can change and can be leveraged to include the SKI_RANDOM value, as discussed in more detail below.
In other embodiments, SKI_RANDOM is transmitted independently of the encrypted content. SKI_RANDOM may even be transmitted on channels other than the broadcast channel. When the user "tunes" to the broadcast channel, the receiving circuit 304 acquires information for finding the position of the broadcast channel from the "control channel". It may be preferable to allow fast access when the user "tunes" to the broadcast channel. This requires the ME306 to acquire SKI in a short amount of time. ME306 may already know SKI_PREDICT, but BS supplies SKI_RANDOM to ME300 in this short time. For example, the BS may frequently transmit SKI_RANDOM on the control channel, or may frequently transmit SKI_RANDOM on the broadcast channel, along with information for locating the broadcast channel. The more often the BS "refreshes" the value of SKI_RANDOM, the faster the MS300 can access the broadcast message. The request to refresh the SKI_RANDOM data optimizes the available bandwidth, as sending SKI_RANDOM data too often may use an unacceptable amount of bandwidth in the control or broadcast channel. Balanced for what you do.
In some situations, CS can choose to use the values of SKI_PREDICT and SKI_RANDOM. Here, both are changed for each generated SK value. In other situations, CS may want to reduce the number of times SKI_RANDOM changes, so the MS300 does not acquire SKI_RANDOM less often. For example, if the user changes frequently between multiple HSBS channels, then the value of SKI_RANDOM is even more if it is unlikely to change to, for 5 minutes, during which the user tunes to another channel. Should be good. If you change SKI_RANDOM, the user must wait for the new value of SKI_RANDOM to be broadcast, and if SKI_RANDOM remains constant for as long as possible, such a scheme is more "user friendly". Indicates that it should be. CS may wish to use multiple values of SK during the lifetime of the SKI_RANDOM value by using the value for SKI_PREDICT. SKI_PREDICT is changed whenever CS wants to change SK. One example uses system time. However, using system time introduces additional problems with synchronization.
For broadcast content encryption and transmission, CS will use the current SK to encrypt the broadcast content. The Exemplary embodiment employs an encryption algorithm such as the Advanced Encryption Standard (AES) Cipher Algorithm. In an exercising embodiment, the encrypted content is then carried by an IPSec packet according to the Encapsulating Security Payload (ESP) carrying mode discussed below. The IPSec packet also contains the SPI value. The SPI value indicates that ME306 should decrypt the broadcast content received using the current SK. The encrypted content is transmitted over the broadcast channel.
The receiving circuit 304 directly supplies RKI and BAKI to UIM308. Furthermore, if CS calculates SK from SKI_RANDOM and SKI_PREDICT, the receiving circuit 304 supplies SKI_RANDOM to the appropriate part of the MS300. There, it is integrated with SKI_PREDICT to get SKI. In one embodiment, the SKI is attached to an encrypted message and extracted by ME306. SKI is supplied to UIM308 by the relevant part of MS300. UIM308 calculates RK from RKI, decrypts BAKI using RK to obtain BAK, and calculates SK using SKI and BAK to generate SK for use by ME306. ME306 uses SK to decrypt broadcast content. The UIM308 in its exercising embodiment may not be powerful enough to decrypt the broadcast content in real time, therefore the SK is passed to the ME306 to decrypt the broadcast.
<u style="single">Figure 9 and</u>FIG. 10 shows the transmission and processing of a key containing RK, BAK and SK according to an exemplary embodiment. As illustrated, at registration, the MS300 receives the RK information (RKI) and passes it to the UIM308. Here, SUPU316 calculates RK using the RKI and A-keys, and stores RK in the UIM memory storage device SUMU314. The MS300 periodically receives BAK information (BAKI), including a BAK encrypted with a specific RK value on the UIM308. The encrypted BAKI is decrypted by SUPU316 and restores the BAK. The BAK is stored in the UIM memory storage device SUMU314. The MS300 also earns SKI on a regular basis. In one exercising embodiment, the MS300 receives SKI_RANDOM. SKI_RANDOM is integrated with SKI_PREDICT to form SKI. SUPU316 calculates SK from SKI and BAK. The SK is supplied to the ME306 to decrypt the broadcast content.
In an exercising embodiment, the CS key is encrypted and does not need to be sent to the MS. CS can use an alternative method. The key information generated by the CS for transmission to each MS provides sufficient information for the MS to calculate the key. As shown in system 350 in Figure 11, RK is generated by CS, but RK information (RKI) is sent to MS. The CS provides enough information for the UIM to derive the RK. Here, a predetermined function is used to derive RK from the information sent from CS. RKI uses a pre-determined public function named d1 that contains enough information for the MS to determine the original RK from the A-key and other values, such as system time. here: RK = d1 (A-key, RKI) (3) In an exercising embodiment, the function d1 defines a cryptographic technique type function. According to an embodiment, the RK is determined as follows: RK = SHA (A-key TheRKI) (4) Where represents the combination of the block containing the A-key and RKI, and SHA (X) represents the last 128-bit of the output of the safe hash algorithm SHA-1 for the given input X. .. In an alternative embodiment, the RK is determined as follows: RK = AES (A-key, RKI) (5) Here, AES (X, Y) represents the encryption of the 128-bit block RKI using the 128-bit A-key. In the next embodiment based on the AKA protocol, RK is determined as the output of the 3GPP key generation function f3. Here, RKI includes the value of RAND and the appropriate value of AMF and SQN as specified by the standard.
BAK is processed differently because multiple users with different values of RK must calculate the same value of BAK. CS can use any technique for determining BAK. However, the value of BAKI associated with a particular UIM308 is the BAK encryption under the unique RK associated with that UIM308. SUPU316 decrypts BAKI using the RK stored in SUMU314 according to the function expressed as d2, and follows the following equation: BAK = d2 (BAKI, RK) (6) In an alternative embodiment, CS can calculate BAKI by applying a decryption process to BAK using RK, and SUPU316 can calculate BAKI by applying an encryption process to BAKI using RK. Earn BAK. This is considered to be equivalent to CS encrypting BAK and SUPU316 decrypting BAKI. An alternative embodiment may perform any number of key combinations in addition to or instead of those shown in FIG.
SK is processed in the same way as RK. In some embodiments, SKI is first derived from SKI_PREDICT and SKI_RANDOM. Here, SKI_RANDOM is the information transmitted from CS to MS. A predetermined function, represented by d3, is then used to derive SK from SKI and BAK (stored in SUMU314), according to the following equation: SK = d3 (BAK, SKI) (7) In one embodiment, the function d3 defines a cryptographic technique type function. In one exemplary embodiment, the SK is calculated as: SK = SHA (BAKTheSKI) (8) However, in other embodiments, SK is calculated as: SK = AES (BAK, SKI) (9) Figures 12-15 show how to provide security for broadcast messages. FIG. 12 shows the registration process 400. Here, the subscriber negotiates registration with CS in step 402. The registration in step 404 gives the UIM a unique RK. The UIM stores the RK in the safety memory unit (SUMU) in step 406. FIG. 13 shows application processing 420 between CS and MS. In step 422, CS generates a BAK during the BAK time period T1. BAK is valid throughout the BAK time period T1. Here, BAK is updated regularly. At step 424, the CS authorizes the UIM to access the broadcast content (BC) during the BAK timer period T1. In step 426, CS encrypts the BAK with each individual RK for each subscriber. The encrypted BAK is called BAKI. The CS then sends a BAKI to the UIM in step 428. The UIM receives the BAKI and uses the RK in step 430 to perform the decryption. The decrypted BAKI results in the originally generated BAK. The UIM stores the BAK in SUMU in step 432.
If the user subscribes to the broadcast service during a particular BAK update period, CS will send the appropriate information BAKI. Here, BAKI corresponds to BAK encrypted with RK. This typically occurs before the beginning of this BAK update period, or when the MS first tunes to a broadcast channel during this BAK update period. This can be initiated by MS or CS according to various criteria. Multiple BAKIs can be transmitted and decrypted at the same time.
Note that if the BAK update period is about to expire, the MS can request an updated BAK from CS if the MS is subscribed to the next BAK update period. In an alternative embodiment, the first timer t1 is used by the CS. Here, due to the expiration of the timer, that is, the satisfaction of the BAK update period, the CS transmits the BAK. CS changes the value of BAK faster than originally intended. This may be preferable, for example, if the current value of BAK is publicly available.
For example, if the BAK update is performed monthly, the subscriber notes that subscribing to the service in the middle of the month will allow the user to receive the BAK during the BAK update period. In addition, the time periods for BAK and SK updates may be synchronized so that all subscribers are updated at the given time.
FIG. 17 shows the registration process in the wireless communication system 500 according to the Exemplarly embodiment. The CS502 negotiates with each subscriber, the MS512, and produces a specific RK for each of the subscribers. RK is supplied to the SUMU unit in the UIM of each MS. As shown, CS502 is RK<sub>1</sub>To generate and RK<sub>1</sub>Is UIM<sub>1</sub>SUMU in 512<sub>1</sub>It is stored in 510. Similarly, CS502 is RK<sub>2</sub>And RK<sub>N</sub>Generate, each of these is a UIM<sub>2</sub>SUMU in 522<sub>2</sub>520 and UIM<sub>N</sub>SUMU in 532<sub>N</sub>It is stored in 530.
FIG. 18 shows the enrollment process in System 500. The CS502 further includes a plurality of encoders 504. Each of the encoders 504 receives one of a plurality of unique RK and BAK values generated by the CS502. The output of each encoder 504 is a specific BAKI encrypted for the subscriber. BAKI is UIM<sub>1</sub>Received in each MS UIM such as 512. Each UIM is a UIM<sub>1</sub>512 SUPU<sub>1</sub>514 and SUMU<sub>1</sub>510<u style="single">And UIM</u><sub><u style="single">N</u></sub><u style="single">532 SUPU</u><sub><u style="single">N</u></sub><u style="single">534 and SUMU</u><sub><u style="single">N</u></sub><u style="single">530</u>Includes SUPU and SUMU such as. SUPU is a decoder that restores BAK by applying UIM RK 516<u style="single">Or decoder 536</u>Includes decoders such as. The process is repeated for each subscriber.
FIG. 20 shows BC processing after registration and application. The CS502 includes an encoder 560. The encoder uses the current SK to encode the BC and generate the EBC. The EBC is then sent to the subscriber. Each MS is an encoder 544<u style="single">Or encoder 554</u>Includes encoders like. The encoder uses SK to extract BC from EBC.
The following description considers four exemplary embodiments. Exemplary embodiments may be used to update SK and broadcast content. In the first exemplary embodiment, the SK is derived from the SPI value in the header of the IPSec packet containing the BAK and broadcast content. In the second exemplary embodiment, the SK is derived from the broadcast random values represented as BAK, RAND and the SPI value in the header of the IPSec packet containing the broadcast content. In the third igzenpular embodiment, SK is derived from broadcast random values expressed as BAK, system time and SK_RAND. In a fourth ixemrary embodiment, the SK is transmitted as an IPSec packet encrypted using BAK. Yet other embodiments may give SK as a combination of embodiments listed above, or use other mechanisms to prevent unauthorized access to broadcast services. Give the MS SK, which is sufficient in the case of.
Here, SK is because the short term key (SK) is used to encrypt and decrypt broadcast content, and is stored in memory that may be vulnerable to unauthorized access. Typically, it changes frequently. There is a problem of how to change SK frequently while balancing with the following four purposes. 1) Minimize SK update latency or blackout period for mobile stations recently tuned to broadcast; 2) Minimize the amount of bandwidth used to update SK values; 3 ) To increase the level of security; and 4) To increase the ease with which SK can be incorporated into IPSec. Frequent updates can reduce the blackout period, except at the expense of requiring more bandwidth to send frequent updates.
One solution provides a way to provide sufficient information to perform a SK update on each encrypted broadcast content packet without using any additional bandwidth. Therefore, the blackout period can be minimized without having to bear the additional bandwidth requirements. In order to carry out the SK update, the four Exemplarative embodiments described here have various advantages and disadvantages. All four embodiments provide a sufficiently secure method. The first embodiment removes the blockout period and does not use additional bandwidth to update the SK value. Other embodiments may bear a blackout period during periods of high use. The first embodiment is also easily incorporated into IPSec.
According to the first embodiment for performing the SK update, the above problem is solved by defining the SK. SK encrypts a given IPSec packet as a function of SPI in the broadcast access key (BAK) and ESP header. In this way, SK is calculated from the content stream, rather than giving SK in another stream. Assuming the MS has already received the BAK as described above, the MS can immediately calculate the SK for each content packet without having to wait for some additional SK update information. This can effectively remove any SK update latency for new broadcast reception. As soon as the MS receives the content packet, the MS can immediately determine the SK and decrypt the content.
Sufficient information is provided in the IPSec packet to calculate the SK in the MS. IPSec packets utilize the IP Encapsulation Security Payload (ESP) and were described in detail in RFC 1827 entitled IP Encapsulation Security Payload (ESP) by Earl Atkinson in August 1995, as described above. ing. ESP is a mechanism for providing integrity and security to IP datagrams. Authentication for IP datagrams can also be given in some environments. FIG. 21 shows an IPSec packet 600 containing an IP header 602, an ESP header 604, and a payload 606 according to one embodiment. The Encapsulating Security Payload (ESP) can appear anywhere after the IP header and before the last transport layer protocol. In general, ESP consists of encrypted data following an unencrypted header.
ESP header field 604 contains a security association identifier called SPI. According to the first embodiment described above, the IPSec packet containing the broadcast content includes an SK-related SPI, named SPI_SK. Figure 22 shows the corresponding 32-bit SPI_SK610 format. SPI_SK610 is decomposed into two parts: SPI_RAND612 and BAK_ID614. SPI_RAND612 is a statistically random random number that is also used to calculate SK. SK is used to encrypt and decrypt the corresponding broadcast content or payload. The SPI_RAND parameter allows the Content Server (CS) to frequently change the effective SK value for content by changing the SPI_RAND value. In this way, the parameters needed to immediately calculate the SK value are supplied to the MS. In addition, SPI_RAND plays the role of SKI_RANDOM discussed above. The randomness of SPI_RAND ensures that the attacker cannot predict the value of SK with high accuracy. Since SPI is already a standard parameter in IPSec encrypted packets, i.e. specified for ESP, this embodiment is typically associated with sending SK as a separate stream. Does not bear the bandwidth of. BAK_ID indicates which BAK value to use for calculating the SK value. In some embodiments, the BAK_ID is a 4-bit tag. Here, each tag is associated with a BAK value. When the MS executes the application, the MS stores each received BAK_ID and the corresponding BAK value in the memory storage device unit. According to certain embodiments, the MS includes a look-up table (LUT) that stores the BAK values associated with each corresponding BAK_ID. The BAK LUT is contained in the secure memory in the UIM.
FIG. 24 shows the BAK LUT 630. Each entry in the LUT630 reveals the invalidity of the BAK_ID, the corresponding BAK value, and the combination. Revocation is introduced because the value of BAK_ID is a small number. Alternative embodiments can avoid using expired values in the BAK LUT. In some embodiments, only the 16 values of BAK_ID are used. If a new BAK is issued monthly, the BAK_ID value will be repeated after 16 months. At that time, it can be confusing as to which BAK value is valid. Expiration gives a timeout period after a new entry replaces an expired entry. The BAK LUT may need to store a BAK value of 1 or greater. One reason for this is that the CS may want to send the BAK value to the MS before the BAK value is valid. In addition, CS may want to have multiple BAK values valid at the same time. Here, different BAK values may be used to calculate different SK values. BAK If the LUT does not contain the current BAK corresponding to the BAK_ID, the MS may carry out the application and regain the legitimate BAK.
After extracting SPI_RAND and BAK_ID from SPI_SK and regaining the BAK corresponding to BAK_ID, UIM uses the cryptographic function g to calculate the value of SK from BAK and SPI_RAND: SK = g (BAK, SPI_RAND) (10) In one embodiment, the function g (BAK, SPI_RAND) supports encryption of SPI_RAND padded on 128-bit bits with zeros and uses an encryption algorithm that uses BAK as the key: SK = AES (BAK, SPI_RAND) (11) In other embodiments, the function g (BAK, SPI_RAND) corresponds to computing the 128 least important bits of the SHA-1 output applied to the concatenation of BAK and SPI_RAND: SK = SHA (BAK, SPI_RAND) (12) It is not necessary for the UIM to calculate the value of SK for each packet received by the MS in this way. The MS stores each of the SPI_SK values along with the SK value corresponding to the memory storage unit, such as a look-up table (LUT). The MS can store SPI_SK and SK values as security associations in the Security Association Database (SAD). SAD is one LUT, in which MS stores typical security associations required for other applications. Security associations are indexed according to destination address and SPI. If a new SK is generated from a new value for SPI_SK, the old security association is replaced by a new security association that contains the new values for SPI_SK and SK. Alternatively, the MS can store the SPI_SK and SK values in the SK_LUT along with one SK_LUT assigned to each broadcast channel. FIG. 23 shows SK_LUT620. Each entry in LUT620 reveals SPI_SK and the corresponding SK value. When the MS receives a broadcast content packet, the ME first checks the SAD or SK LUT to see if the table contains a value of SPI_SK equal to the SPI of the received packet. If the table contains such a value, the ME will use this value, otherwise the UIM will calculate a new value for the SK. CS can also have a BAK LUT, SDA or SK_LUT.
25 and 26 show one embodiment for performing a SK update. FIG. 25 shows a method 700 of CS operation. For each IP packet, CS determines the BAK that should be used to derive the SK, and in step 702 determines the BAK_ID that corresponds to the BAK. BAK_ID can be any type of identifier that allows identification among multiple BAK values. The CS sends the BAK and BAK_ID to the individual users by making the application in step 706. The user can apply at various times before and during the application period. Steps 702 and 706 can occur before the application period begins. In step 710, CS selects a random value for the SPI_RAND value. If BAK_ID is represented using bits b, SPI_RAND is represented using bits (32-b). The SPI_RAND value must not be repeated during the lifetime of one BAK. Once SPI_RAND and BAK_ID are known, CS integrates them (ie, concatenates BAK_ID to SPI_RAND) and generates SPI_SK in step 712. In step 714, CS generates a SK by using a cryptographic function and integrates SPI_RAND with the BAK corresponding to the BAK_ID to generate the SK. The CS then uses SK in step 716 to encrypt the broadcast message or part of the message. Then, in step 718, the encrypted message is transmitted. Note that the encrypted broadcast message is part of an IP packet that contains an IP header and an ESP header. The ESP header contains SPI_SK. Judgment In Diamond 720, CS decides whether to change SK. If CS determines that it does not change SK, CS proceeds to step 716. If CS decides to change SK, CS decides Proceed to Mondo 724. There, CS decides whether to change the BAK. If CS determines that it does not change the BAK, CS proceeds to step 710. If CS determines that the BAK will change, CS proceeds to step 702.
FIG. 26 shows the corresponding operation in a receiver such as the MS. Method 750 begins in step 752 when the receiver receives an IP packet containing SPI_SK in the ESP header. Note that the receiver extracts SPI_SK information from the IP packet. Upon receiving SPI_SK, the receiver first checks to see if the SK corresponding to the received SPI_SK value is stored in memory.
In one embodiment, SPI_SK is stored in the SK LUT stored in the ME306 unit of FIG. 8, and in other embodiments, SPI_SK is stored in the security association database. Both of these tables are represented in FIG. 26 by the SPI table. A check of the SPI table is performed at Judgment Diamond 754. If the SK value is stored in the receiver's memory, the receiver can use the stored SK value to decrypt the payload of the content packet in step 756. If the receiver does not have the SK value stored in memory, the receiver extracts BAK_ID and SPI_RAND from SPI_SK in step 758. At step 760, check if the BAK LUT has a valid BAK corresponding to the BAK_ID. If the BAK LUT has a valid BAK corresponding to the BAK_ID, the receiver selects this value and proceeds to step 764. BAK, as if the user wants to subscribe during this period If the LUT does not have a valid BAK corresponding to the BAK_ID, the receiver performs the application and obtains a valid BAK, as shown in step 762. The new BAK is stored with the BAK_ID in the BAK LUT, and the receiver proceeds to step 764. In step 764, the receiver integrates the BAK corresponding to the BAK_ID, that is, the BAK_ID in the received SPI_SK, and the SPI_RAND value (also in the received SPI_SK) to calculate the new SK. The receiver then uses the new SK value in step 766 to decode the payload of the content packet. The receiver also remembers this SK value indexed by the corresponding SPI_SK and possibly the destination address of the IPSec packet.
SK is calculated directly from the knowledge of BAK and the SPI_SK value in the content packet. BAK does not change more often than SK. For example, BAK may change once a month. Therefore, the receiver can determine the SK value immediately from the content packet without additional delay and without requiring more bandwidth to send the SK update.
According to an embodiment, the SK calculation is given as follows: SK = f (SPI_SK, BAK) (13) Here, this function is defined as the encryption of SPI_SK using BAK. Since SPI_SK consists of SPI_RAND and BAK_ID, equation (13) can also be given as: SK = f (SPI_RAND, BAK_ID) (14) The second ixempular embodiment of performing the SK update introduces an additional aspect of randomness to the calculation of SK. Here, SK is defined as a function of BAK, SPI_RAND, and additional parameters, RAND. The RAND parameter is kept constant for some SK values. RAND allows for even more different values of SK derived from a single BAK value by modifying both SPI_RAND and RAND. At most 2 if RAND is not used<sup>32</sup>There is a value of SK, which can be derived from a single BAK by changing the SPI. However, if 96-bit RAND is used, 2<sup>218</sup>There may be values of SK up to, which can be derived from one BAK by changing both SPI_RAND and RAND. (These numbers are not related to the SPI bits used to represent BAK_ID). Now, rather than SPI_SK recognizing only BAK, SPI_SK contains information for recognizing RAND. To execute the RAND value, SPI_SK can be formulated in three parts: 1) BAK_ID to recognize and use the BAK value; 2) RAND_ID; and 3) to recognize and use the RAND value. SPI_RAND value to give randomness that changes frequently in SPI_SK.
FIG. 27 shows the SPI_SK800 portion of an IP packet containing SPI_RAND802, BAK_ID804, and RAND_ID806. SPI_RAND802 and BAK_ID804 are as described above. To keep SPI_SK at a given or specified bit length, SPI_RAND802 can use fewer bits than SPI_RAND612, as shown in Figure 22, allowing bits for RAND_ID806. RAND_ID806 corresponds to the RAND value used to calculate the SK and may be a 4-bit tag or other identifier. The RAND_ID and the corresponding RAND value are stored in the LUT at the receiver. FIG. 28 shows the RAND LUT 820. The RAND LUT820 contains an entry for each RAND value listing the RAND_ID and the revocation associated with the RAND value.
Figure 29 shows the operation of CS.<u style="single">900</u>Is shown. For each IP packet, the transmitter determines the BAK used to derive the SK and in step 902 determines the BAK_ID corresponding to the BAK. BAK_ID can be any type of identifier that allows discrimination between multiple BAK values. The CS sends the BAK and BAK_ID to the individual user by making the application in step 904. The user can make an application before and at various times during the application period. Steps 902 and 904 may occur before the application period begins. In step 906, the transmitter selects a RAND value and determines the corresponding RAND_ID.<u style="single">In step 908</u>The CS can transmit RAND and RAND_ID separately to the MS, or can transmit RAND and RAND_ID and is broadcast on the broadcast channel. The value of RAND is not encrypted because it does not need to be kept secret. If the RAND and RAND_ID are broadcast, the time between retransmissions should not be long and the MS does not have to wait a long time before getting the RAND value. Broadcasting RAND and RAND_ID will use a large amount of bandwidth over a long period of time. However, if a large number of users tune in to that channel, a large amount of bandwidth is needed to send the RAND to each user separately. Therefore, if a large number of users tune in to that channel, then RAND and RAND_ID will only be broadcast. In step 910, CS selects a random value for SPI_RAND.
Once SPI_RAND, BAK_ID and RAND_ID are known, the transmitter integrates them (eg, connects RAND_ID and BAK_ID to SPI_RAND) to form SPI_SK in step 912. CS uses cryptographic functions to integrate SPI_RAND, BAK (recognized by BAK_ID) and RAND (recognized by RAND_ID).<u style="single">In step 914</u>Form SK. The CS then encrypts the broadcast message or part of the message with SK in step 916 and sends the encrypted message in step 918. Note that the encrypted broadcast message is part of an IP packet that contains an IP header and an ESP header. The ESP header contains SPI_SK. Judgment In Diamond 920, CS decides whether to change SK. If CS decides not to change SK, CS proceeds to step 916. If CS decides to change SK, CS proceeds to Judgment Diamond 922. There, CS decides whether to change the RAND. If CS decides not to change the RAND, CS proceeds to step 910. If CS decides to change the RAND, CS proceeds to Judgment Diamond 924. There, CS decides whether to change the BAK. If CS decides not to change the BAK, CS proceeds to step 906. If CS decides to change the BAK, CS returns to step 902.
FIG. 30 shows the corresponding behavior in a receiver such as the MS. Method 950 begins when the receiver receives an IP packet containing SPI_SK in the ESP header in step 952. Note that the receiver extracts SPI_SK information from the IP packet. When SPI_SK is received, the receiver first checks in the determination diamond 952 whether the SK corresponding to the received SPI_SK value is stored in the memory. In one embodiment, SPI_SK is the SK stored in ME unit 306 of FIG. Stored in the LUT. And in other embodiments, SPI_SK is stored in the security association database. Both tables are represented in FIG. 30 as SPI tables. The SK_LUT check is performed in Judgment Diamond 954. If the SK value is stored in memory at the receiver, the receiver can use the SK value stored in step 956 to decrypt the payload of the content packet. If the receiver does not store the SK value in memory, the receiver extracts BAK_ID and SPI_RAND from SPI_SK in step 958. At step 960, the receiver then checks if the BAK LUT has a valid BAK entry corresponding to the BAK_ID. If the BAK LUT has a valid RAND corresponding to the BAK_ID, the receiver selects this value and proceeds to step 964. BAK If the LUT does not have a valid BAK corresponding to the BAK_ID (provided the user wishes to join during this period), the receiver will make an application as shown in step 962. And get a valid BAK. The new BAK is stored with the BAK_ID in the BAK LUT and the receiver proceeds to step 964. At step 964, the receiver then checks if the RAND LUT has a valid RAND entry corresponding to the RAND_ID. If the RAND LUT has a valid BAK corresponding to the RAND_ID, the receiver selects this value and proceeds to step 964. If the RAND LUT does not have a valid RAND corresponding to the RAND_ID, the receiver can request either this value from the CS or from the broadcast as shown in step 966 to make the RAND and RAND_ID. To win. The new RAND is RAND Stored with RAND_ID in the LUT, the receiver proceeds to step 968. In step 968, the receiver has a BAK corresponding to the BAK_ID value (that is, BAK_ID in the received SPI_SK), a RAND corresponding to the RAND_ID (that is, RAND_ID in the received SPI_SK), and an SPI_RAND value (also in the received SPI_SK). There is) and a new SK is calculated. The receiver then uses the new SK value in step 970 to decrypt the payload of the content packet. The receiver also remembers this SK value indexed by the corresponding SPI_SK and possibly the destination address of the IPSec packet.
RAND does not change as often as SPI_RAND. The RAND value is common to all mobile stations listening to the broadcast. Therefore, the RAND value can be broadcast to all mobile stations and does not need to be specified and encrypted for each receiver. Therefore, if there are enough mobile stations listening to the broadcast stream, for all these mobile stations, rather than requiring each mobile station to request a RAND value from the CS individually. It is more efficient for the air interface to broadcast the RAND value several times.
According to one embodiment, the calculation of SK is given by: SK = f (SPI_SK, BAK, RAND) (15) Here, this function is specified as SPI_SK encryption using BAK. Since SPI_SK consists of SPI_RAND, BAK_ID, and RAND_ID, equation (15) could also be given as: SK = f (SPI_RAND, BAK_ID, RAND_ID, RAND) (16) Note that the use of a RAND value may introduce some "blackout period", as the receiver is required to receive the RAND value upon change. However, these periods are less frequent and the receiver waits for regular updates than if the SK were updated in separate streams. RAND is designed to change more slowly than the SK value, and therefore updates to RAND are not sent frequently. Probability of "blackout" resulting when MS stops listening to a channel by losing sight of the signal, tuning to another channel, or responding to interference such as a phone call. However, CS is about to decrease. Blackouts are most likely to occur at the beginning of the RAND value lifetime. To address this, CS may rebroadcast the new RAND more frequently, around the time before and after the new RAND value becomes effective. At the end of the RAND lifetime, it may be necessary to broadcast both the current RAND value and the next RAND value. The value of RAND should be unpredictable and CS will only start sending RAND just before RAND is enabled.
As discussed above, according to the third igzenpular embodiment, SK is derived from broadcast random values expressed as BAK, system time and SK_RAND. Figure 14 shows how to update the security encryption key in a wireless communication system that supports broadcast services. Method 440 performs a time period as given in FIG. BAK is updated regularly with time period T1. Timer t1 starts when BAK is calculated and ends at T1. One variable is used to calculate the SK called SK_RAND. SK_RAND is updated regularly with time period T2. Timer t2 starts when SK_RAND is generated and ends at T2. In some embodiments, the SK is updated more regularly during the T3 period. Timer t3 starts when SK is generated and ends at T3. SK_RAND is generated in CS and given to MS on a regular basis. As described in detail below, MS and CS use SK_RAND to generate SK.
The first timer t1 is reset when the applicable value of BAK is updated. The length of time between two BAK updates is the BAK update period. In some exemplary embodiments, the BAK update period is one month, however, in alternative embodiments, any time period desired for optimal operation of the system or to meet various system criteria. May be executed.
Continuing with FIG. 14, method 440 initializes timer t2 in step 442 and initiates the SK_REG time period T2. CS generates SK_RAND and supplies its value to the transmit circuit for transmission throughout the system in step 444. The timer t3 is initialized in step 446 and starts the SK time period T3.<u style="single">CS generates SK from SK_RAND, BAK, and time in step 448.</u>Then step<u style="single">450</u>In, CS uses the current SK to encrypt BC. The encrypted product is EBC. Here, the CS supplies the EBC to the transmit circuit for transmission in the system. Judgment diamond<u style="single">452</u>In, if the timer t2 expires, the processing returns to step 442. Timer t3 judges diamond while t2 is less than T2<u style="single">454</u>If expired at, processing returns to step 446, otherwise processing returns to step 450.
FIG. 15 shows the operation of the MS accessing the broadcasting service. Method 460 first synchronizes timers t2 and t3 with the values in CS in step 462. The MS UIM receives the SK_RAND generated by CS in step 464. In step 466, the UIM uses SK_RAND, BAK and time measurement to generate the SK. UIM passes SK to ME of MS. Then, in step 468, the UIM uses the SK to decode the received EBC and extract the original BC. If timer t2 expires in step 470, processing returns to step 462. If timer t3 expires in step 472 while timer t2 is less than T2, timer t3 is initialized in step 474 and returns to 466.<u style="single">FIG. 16 is a timing diagram of the key update period of the security option in the wireless communication system that supports broadcast transmission.</u>
Key management and updates are shown in Figure 19. Here, CS applies the function 508 to generate the value of SK_RAND. SK_RAND is a tentative value used by CS and MS to calculate SK. Specifically, function 508 applies the BAK value, SK_RAND and time factor. In the embodiment shown in FIG. 19, the SK applies a timer to determine when to update, while alternative embodiments may use alternative methods and provide periodic updates. For example, the occurrence of an error or other event. CS supplies each of the subscribers with an SK_RAND value. Here, the function 518 that exists in each UIM<u style="single">Or 538</u>Apply the same function as in function 508 of CS. Function 518 operates with SK_RAND, BAK and timer values to generate SK. SK is ME<sub>1</sub>540 MEM<sub>1</sub>542<u style="single">And ME</u><sub><u style="single">N</u></sub><u style="single">550 MEM</u><sub><u style="single">N</u></sub><u style="single">552</u>It is stored in the memory location in ME, such as.
As discussed above, according to the fourth embodiment, the SK is encrypted using the BAK to form the SKI. Then SKI is sent to MS. In one embodiment, the SK is transmitted in an IPSec packet encrypted using BAK. The CS may also broadcast the corresponding SPI, which can be used to recognize data encrypted using SK. This embodiment does not need to be discussed in any further detail.
In the example given above, the CS can be selected to update the SK as the CS desires. The more often the SK changes, the more CS can discourage attackers from distributing SK values. There are times when attackers consider the benefits of distributing SK values better than at other times. This is inherent due to the nature of the content that is about to be broadcast. For example, when a significant event occurs, unsubscribed users should be more interested in receiving news on HSBS and therefore willing to pay more for illegal access than at other times. Is. At such times, CS can increase costs and inconveniences for attackers and non-subscribers by changing SKs more often than usual. However, CS must be aware that UIM processing capabilities are limited. If the CS changes the SK more often than necessary, the UIM will not be able to calculate the SK value in real time, and as a result, the user will not be able to decrypt the content in real time. Become.
Those knowledgeable in this field should understand that information and signals can be represented using any of a wide variety of different techniques and techniques. For example, data, instructions, commands, information, signals, symbols, and chips that may be referenced in the overall description above are voltage, current, electromagnetic waves, magnetic or magnetic particles, light fields or light particles, or It is effectively represented by any combination of these.
It is this area that the various explanatory logical blocks, modules, circuits, and algorithmic steps described in connection with the embodiments disclosed herein can be performed as electronic hardware, computer software, or a combination thereof. Those who are knowledgeable about it should appreciate it even more. To articulate this compatibility of hardware and software, various descriptive components, blocks, modules, circuits, and steps have generally been described in terms of functionality. Whether such functionality is performed as hardware or software depends on the unique application and design constraints imposed on the entire system. Skilled craftsmen can perform the described functionality in different ways for each unique application. However, such a decision of practice is not explained beyond the scope of the present invention.
The various explanatory logic blocks, modules, and circuits described in connection with the embodiments disclosed herein include general purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), and field programmable gates. It can be performed or implemented in an array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware elements, or any combination of these designed to perform the functions described herein. it can. A general purpose processor can be a microprocessor, but in an alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. The processor can be executed as a combination of arithmetic units. For example, it could be a combination of DSP and microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.
The steps of methods or algorithms described in connection with the embodiments disclosed herein can be implemented directly in hardware, in software modules executed by a processor, or in combination of both. Software modules reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disks, removable disks, CD-ROMs, or any other storage medium known in the art. it can. An exempt storage medium is connected to a processor, which allows the processor to read information from the storage medium and write information to it. Alternatively, the storage medium can be integrated into the processor. The processor and storage medium can be in the ASIC. The ASIC can be in the user terminal. Alternatively, the processor and storage medium can exist as a single element in the user terminal.
The previous description of the preferred embodiment allows anyone with knowledge of the art to create and use the present invention. Various variations of these embodiments will be readily realized by those who are knowledgeable in the art. And the general principles defined here can be applied to other embodiments without using the inventive capabilities of the present invention. Therefore, the present invention is not intended to be limited to the embodiments presented herein, but is to be applied in a wide range consistent with the principles and outstanding properties disclosed herein.
<figref num="1">FIG. 1 is a diagram of an encryption system.</figref><figref num="2">FIG. 2 is a diagram of a symmetric encryption system.</figref><figref num="3">FIG. 3 is a diagram of an asymmetric encryption system.</figref><figref num="4">FIG. 4 is a diagram of a PGP encryption system.</figref><figref num="5">FIG. 5 is a diagram of a PGP decoding system.</figref><figref num="6">FIG. 6 is a diagram of a diffusion spectrum communication system that supports a large number of users.</figref><figref num="7">FIG. 7 is a block diagram of a communication system that supports broadcast transmission.</figref><figref num="8">FIG. 8 is a block diagram of a mobile station in a wireless communication system.</figref><figref num="9">FIG. 9 is a diagram of a model illustrating updating keys in a mobile station used to control broadcast access.</figref><figref num="10">FIG. 10 is a diagram of a model illustrating updating keys in a mobile station used to control broadcast access.</figref><figref num="11">FIG. 11 is a model explaining the operation of the encryption technology in UIM.</figref><figref num="12">FIG. 12 shows how to perform security encryption in a wireless communication system that supports broadcast transmission.</figref><figref num="13">FIG. 13 shows how to perform security encryption in a wireless communication system that supports broadcast transmission.</figref><figref num="14">FIG. 14 shows how to perform security encryption in a wireless communication system that supports broadcast transmission.</figref><figref num="15">FIG. 15 shows how to perform security encryption in a wireless communication system that supports broadcast transmission.</figref><figref num="16">FIG. 16 is a timing diagram of the key update period of the security option in the wireless communication system that supports broadcast transmission.</figref><figref num="17">FIG. 17 shows the application of a security encryption method in a wireless communication system that supports broadcast transmission.</figref><figref num="18">FIG. 18 shows the application of security encryption methods in wireless communication systems that support broadcast transmission.</figref><figref num="19">FIG. 19 shows the application of a security encryption method in a wireless communication system that supports broadcast transmission.</figref><figref num="20">FIG. 20 shows the application of security encryption methods in wireless communication systems that support broadcast transmission.</figref><figref num="21">FIG. 21 shows the format of an IPSec packet for Internet Protocol transmission.</figref><figref num="22">FIG. 22 shows a Security Association Identifier or SPI as applicable to IPSec packets.</figref><figref num="23">FIG. 23 shows a memory storage device for storing SPI information in a mobile station.</figref><figref num="24">FIG. 24 shows a memory storage device for storing a broadcast access key (BAK) in a mobile station.</figref><figref num="25">FIG. 25 shows a method of providing security for broadcast messages in a wireless communication system.</figref><figref num="26">FIG. 26 shows a method of providing security for broadcast messages in a wireless communication system.</figref><figref num="27">Figure 27 shows the Security Association Identifier or SPI as applicable to IPSec packets.</figref><figref num="28">FIG. 28 shows a memory storage device for storing SPI information in a mobile station.</figref><figref num="29">FIG. 29 shows how to provide security for broadcast messages in a wireless communication system.</figref><figref num="30">FIG. 30 shows a method of providing security for broadcast messages in a wireless communication system.</figref>
Code description
10 ... Basic encryption system, 20 ... Symmetric encryption system, 100 ... Communication system, 200 ... Wireless communication system, 300 ... MS, 400 ... Registration process, 500 .. .Exemplified communication system, 600 ... IPSec packet, 700 ... CS operation method.
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office |
|---|---|---|
| JP05216411A | Cites | Japan |
| JP2001136507A | Cites | Japan |
| 忠海 均 Hitoshi TADAUMI,通信インフラとしてのIP技術 IP Networking Technologies for Communication Infrastructure,電子情報通信学会誌 第83巻 第4号 THE JOURNAL OF THE INSTITUTE OF ELECTRONICS,INFORMATION AND COMMUNICATION ENGINEERS,日本,社団法人電子情報通信学会 The Institute of Electronics,Information and Communication Engineers,2000年 4月,第83巻,p.286-294 | Non-patent | – |
| JNSA,相互接続性実証実験レポート付き セキュリティプロトコル「IPsec」の今を知る,NETWORK MAGAZINE 第6巻 第6号,日本,株式会社アスキー,2001年 6月,第6巻,p.86-93 | Non-patent | – |
37 members in 15 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 09973301 | United States of America | – | |
| 97330101 | United States of America | A | |
| 97330101 | United States of America | A | |
| 0232054 | United States of America | W | |
| 0232054 | United States of America | W | |
| 2001973301 | – | – | – |
| 2002032054 | – | – | – |
| US20010973301 | – | – | – |
| WO2002US32054 | – | – | – |
Members37
| Document | Office | Kind | |
|---|---|---|---|
| US2003070092A1 | United States of America | A1 | |
| CA2463542A1 | Canada | A1 | |
| WO03032573A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03032573A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MXPA04003335A | Mexico | A | |
| EP1436939A2 | European Patent Office (EPO) | A2 | |
| IL161312A0 | Israel | A0 | |
| KR20050034607A | Republic of Korea | A | |
| CN1633778A | China | A | |
| RU2004114212A | Russian Federation | A | |
| JP2005537689A | Japan | A | |
| HK1076553A1 | Hong Kong, China | A1 | |
| BR0213214A | Brazil | A | |
| TWI256223B | Taiwan Province of China | B | |
| AU2002342014B2 | Australia | B2 | |
| US7352868B2 | United States of America | B2 | |
| RU2333608C2 | Russian Federation | C2 | |
| US2008226073A1 | United States of America | A1 | |
| AU2002342014C1 | Australia | C1 | |
| CN100481762C | China | C | |
| CN101515851A | China | A | |
| KR100967323B1 | Republic of Korea | B1 | |
| EP2204939A2 | European Patent Office (EPO) | A2 | |
| EP2204940A2 | European Patent Office (EPO) | A2 | |
| HK1137269A | Hong Kong, China | A | |
| HK1137269A1 | Hong Kong, China | A1 | |
| JP4732687B2This record | Japan | B2 | |
| EP2204939A3 | European Patent Office (EPO) | A3 | |
| EP2204940A3 | European Patent Office (EPO) | A3 | |
| CA2463542C | Canada | C | |
| CN101515851B | China | B | |
| US8983065B2 | United States of America | B2 | |
| EP2204939B1 | European Patent Office (EPO) | B1 | |
| EP2204940B1 | European Patent Office (EPO) | B1 | |
| EP1436939B1 | European Patent Office (EPO) | B1 | |
| ES2791681T3 | Spain | T3 | |
| ES2796115T3 | Spain | T3 |
28 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4732687
- Publication, DOCDB
- 4732687
- Publication, EPODOC
- JP4732687B
- Application
- 2003535411
- Application, DOCDB
- 2003535411
- Application, EPODOC
- JP20030535411
Titles2
- Japanese
- データプロセシングシステムにおけるセキュリティに関する方法及び装置
- English
- Security methods and equipment in data processing systems
Classification
- CPC, 8
- H04L63/04
- H04L9/08
- H04L9/0891
- H04L2209/601
- H04W4/06
- H04W12/04
- H04W12/0433
- H04W12/041
- IPC, 5
- H04L9 08
- G06F21 24
- G06F21 60
- G06F21 62
- H04L29 06