Use of an encoding server for encoding information to be transmitted
Abstract
An encryption server receives a first encrypted message (105) and decrypts (403) the encrypted message using a first key, yielding a decrypted message comprising a second encrypted message (105A), an identification of a sender of the first encrypted message, and an identification of a first recipient. The second encrypted message, the identification of the sender, and the identification of the first recipient are determined (405) from the decrypted message. The second encrypted message and the identification of the sender are encrypted (409) with a second key, yielding a third encrypted message (109). The third encrypted message (109) is transmitted to the first recipient.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
9 claims: 3 independent, 6 dependent
- 1Patent claims Zastrzeżenia patentowe 1. An encryption method in a telecommunications system using the first and second encryption keys, wherein the first encryption key is a private key assigned to a user and the second encryption key is a public key assigned to the encryption server, characterized in that a digital data message is generated in the user-operated telecommunications unit. , encrypt this digital data message with a first encryption key to obtain a first encrypted message to which the user ID and the first recipient ID are added to obtain a completed first encrypted message, then encrypt this completed first encrypted message with a second encryption key to obtain a second encrypted message and it is sent to the encryption server. 1. Sposób szyfrowania w systemie telekomunikacyjnym z zastosowaniem pierwszego i drugiego klucza szyfrowania, w którym pierwszy klucz szyfrowania jest kluczem prywatnym przypisanym użytkownikowi, a drugi klucz szyfrowania jest kluczem publicznym przypisanym serwerowi szyfrowania, znamienny tym, że w zespole telekomunikacyjnym obsługiwanym przez użytkownika generuje się komunikat danych cyfrowych, szyfruje się ten komunikat danych cyfrowych za pomocą pierwszego klucza szyfrowania uzyskując pierwszy zaszyfrowany komunikat, do którego dodaj e się identyfikator użytkownika i identyfikator pierwszego odbiorcy uzyskując uzupełniony pierwszy zaszyfrowany komunikat, następnie szyfruje się ten uzupełniony pierwszy zaszyfrowany komunikat za pomocą drugiego klucza szyfrowania uzyskując drugi zaszyfrowany komunikat i wysyła się go do serwera szyfrowania.
- 6The method according to p. The method of any of claims 3, 4 or 5, characterized in that the user identifier is encrypted with the second encryption key before being added to the message. 6. Sposób według zastrz. 3 albo 4, albo 5, znamienny tym, że identyfikator użytkownika szyfruje się za pomocą drugiego klucza szyfrowania przed dodaniem go do komunikatu.
- 7Encryption method in a telecommunications system using the first and second encryption keys, characterized in that the first encrypted message is received at the encryption server, the encrypted message is decrypted with the first encryption key, the decrypted message containing the second encrypted message is obtained, the sender identifier of the first encrypted message and the ID of the first recipient, from the decrypted message, the second encrypted message, the sender's ID and the first recipient's ID are determined, the second encrypted message and the sender's ID are encrypted with the second encryption key, obtaining a third encrypted message, and sending the third encrypted message to the first recipient. 7. Sposób szyfrowania w systemie telekomunikacyjnym z zastosowaniem pierwszego i drugiego klucza szyfrowania, znamienny tym, ze w serwerze szyfrowania odbiera się pierwszy zaszyfrowany komunikat, deszyfruje się zaszyfrowany komunikat za pomocą pierwszego klucza szyfrowania, uzyskuje się odszyfrowany komunikat zawierający drugi zaszyfrowany komunikat, identyfikator nadawcy pierwszego zaszyfrowanego komunikatu oraz identyfikator pierwszego odbiorcy, z odszyfrowanego komunikatu określa się drugi zaszyfrowany komunikat, identyfikator nadawcy i identyfikator pierwszego odbiorcy, szyfruje się drugi zaszyfrowany komunikat i identyfikator nadawcy za pomocą drugiego klucza szyfrowania, uzyskując trzeci zaszyfrowany komunikat i wysyła się ten trzeci zaszyfrowany komunikat do pierwszego odbiorcy.
Independent claims3
59 paragraphs in 4 sections, as filed
The invention relates to an encryption method in a telecommunications system.
Telecommunications systems with voice and data encryption are well known. Such systems provide covert communication between two or more users by separating one or more pieces of information between them, which allows only those users who know the information to correctly decode the message. This information is known as the encryption key or in the slave key. The encryption keys can be private keys where a single key is used for encryption and decryption, or public keys where multiple keys are used for encryption and decryption.
There are known methods of encryption using the public key. Typically, such a method is that a single message is encrypted with the sender's private key and then the receiver's public key. The recipient decrypts the message using the recipient's private key and then the sender's public key. Typically public keys are 512 bits long, although some public keys are only 256 bits long. Some encryption experts recommend using 1024-bit keys. Longer keys provide better security as the computing power needed to break a key increases exponentially with the length of the key. Moreover, since two keys are needed to decrypt a message, the two longer keys are more difficult to decrypt when neither of them is known.
Secured communication systems are used to transmit data in an encrypted form. If a user wants to send the same message to five different recipients, he has to encrypt it five times, each time using a different recipient's public key. The user then sends five messages to five recipients. This process is troublesome when the user wants to send a message to, for example, one hundred or more recipients. In this case, the user must encrypt each message individually one hundred or more times, one for each recipient. If a user has a portable telecommunication device such as a laptop, the battery may run out before all messages are encrypted and sent. Moreover, the encryption and transmission process consumes a lot of processing time and power of the mobile device, making it unavailable for other activities at that time. Such transmissions are therefore impractical for users of mobile devices.
What is needed is a method for transmitting the encrypted data messages to a plurality of users that does not block the user's communication device in time or energy.
An encryption method in a telecommunications system using the first and second encryption keys, wherein the first encryption key is a private key assigned to a user and the second encryption key is a public key assigned to the encryption server, according to the invention, it is characteristic that the user-operated telecommunications unit generates digital data message, encrypt this digital data message with a first encryption key to obtain a first encrypted message, to which are added the user ID and the first recipient ID to obtain a completed first encrypted message, then encrypt this completed first encrypted message with a second encryption key to obtain a second encrypted message, and it is sent to the encryption server.
Preferably, the identifier of the second recipient is also added to the first scrambled message to obtain a completed first scrambled message.
Preferably, the encryption server receives the completed second encrypted message, on the basis of which the second encrypted message, the user ID and the first recipient ID are determined, then the second encrypted message is decrypted with the third encryption key, obtaining the first encrypted message which is encrypted with the fourth an encryption key to obtain a third encrypted message which is sent to the first recipient.
182 910
Preferably, the identifier of the second recipient is also added to the second encrypted message, thereby obtaining a completed second encrypted message.
Preferably, the first encryption key is a private key assigned to a user, the second encryption key is a public key assigned to the encryption server, the third encryption key is a private key assigned to the encryption server, and the fourth encryption key is the public key assigned to the first recipient.
Preferably, the user identifier is scrambled with the second encryption key before being added to the message.
The method of encryption in a telecommunications system using the first and second encryption keys according to the invention is characterized in that the first encrypted message is received at the encryption server, the encrypted message is decrypted with the first encryption key, a decrypted message containing the second encrypted message, the sender's identifier is obtained the first encrypted message and the identifier of the first recipient, from the decrypted message, the second encrypted message, the sender's ID and the first recipient's ID are determined, the second encrypted message and the sender's ID are encrypted with the second encryption key, obtaining a third encrypted message, and sending the third encrypted message to the first recipient.
Preferably, the first encryption key is a private key assigned to the encryption server and the second encryption key is a public key assigned to the first recipient.
Preferably, when part of the decrypted message in the encryption server is the second identifier of the second recipient, the second decrypted message and the sender's identifier are encrypted with the third encryption key, obtaining the fourth encrypted message and sent to the second recipient.
The use of an encryption server to encrypt data messages sent by the user to multiple recipients makes the telecommunications system more efficient and secure. The encryption server has more computing power at its disposal than an individual telecommunications team and may encrypt and send the message multiple times to many different recipients. Individual telecommunications teams do not need to store all possible public keys of the recipients, only the public key of the encryption server. Encrypting recipient IDs helps ensure the identity of recipients and eliminates the source of information for unwanted parties.
In an embodiment, the subject matter of the invention is reproduced in the drawing in which Fig. 1 shows a telecommunication system using an encryption server in a block diagram; Fig. 2 shows an encryption server in a block diagram; Fig. 3 is a flowchart of sending a digital data message from a user to a scrambling server and Fig. 4 is a flowchart of sending an encrypted message through the encryption server.
In the communication system shown in Fig. 1, the user of the first telecommunication unit 103 transmits a digital data message which, in the preferred embodiment of the invention, is encrypted in two steps. First, the digital data message is encrypted with a first encryption key which preferably is the private key of the user of the first telecommunications unit 103. The result of this encryption is the message encrypted in the first step. In an alternative embodiment, the digital data message may not be encrypted with the first key. The user identifier and one or more identifiers of the recipients to whom the message is directed are added to the message encrypted in the first step to form a padded message. The completed message is encrypted with the second key, creating a message 105 encrypted in the second step. In the preferred embodiment, the second key is a public key assigned to the encryption server 101. The telecommunications unit 103, over the wireless communication link, transmits a message 105 encrypted in the second step to a wireless receiver / transmitter device 107, which may be an RF base station, repeater, or any other radio or radio frequency telecommunications device
182 910 infrared. From there, the second step encrypted message 105 is forwarded to the encryption server 101.
The encryption server 101 decrypts the message 105 encrypted in the second step with the appropriate key. In a preferred embodiment, the respective key is the private key of the encryption server 101. Based on the decrypted message, the encryption server 101 determines the user ID and the identifiers of all recipients that the user has indicated as recipients of the encrypted message in the first step. The encryption server 101 then encrypts, with the public key of the first recipient, the user ID together with the message encrypted in the first step. The completed scrambled message 109 is sent to the first receiver using the second telecommunications unit 111. Then the encryption server 101 encrypts, with the public key of the second recipient, the first step encrypted message together with the user ID and sends the completed encrypted message 113 to the second recipient using the third telecommunications unit 115. This process continues until the encryption server 101 reaches the last recipient ID in the user list and encrypts, with the last recipient's public key, the first step encrypted message along with the user ID and sends the completed encrypted message 117 to the last recipient using the fourth recipient. telecommunications team 119.
The encryption server 101 may also receive encryption orders from users of wired telecommunication devices 121 over wired channels. As with wireless transmission, the encryption server 101 decrypts the received message 123 from the wired communication device 121 with the private key of the encryption server 101, then encrypts the completed message separately for each recipient using the recipient's respective individual public key. These recipients may be wired devices 127 and 131 that receive messages 125 and 129 over wired communication channels.
The above examples apply to radio-radio and wire-wire transmission of encrypted messages. However, the same encryption method may well be used when wired communication device 121 requests transmission to wireless telecommunications units 111, 115 and 119. Likewise, wireless communication unit 103 may request transmission from the encryption server 101 to wired communication devices 127 and 131. . In addition, recipients may combine both wireless and wired telecommunications units 111, 115, 119, 127 and 131, whether the sender uses wireless telecommunications unit 103 or wired telecommunications device 121.
After receiving the encrypted message from the encryption server 101, each recipient decrypts this message with the recipient's own private key and, after determining the user ID that sent the message, decrypts the completed message with the user's public key, obtaining the original digital data message. The user is also the sender of the message 105 encrypted in the second step.
Figure 2 shows a block diagram of an encryption server 101 and its input 105 and outputs 109, 113, 117, and 125. The encryption server 101 may be a Sun SparcServer 2000 in a multiprocessor chip from Sun Microsystems. The encryption server 101 includes one or more processors 201, such as known microprocessors or digital signal processors. The processors 201 access the encryption and decryption algorithms 203, the public key database 205, and the memory 211. The encryption and decryption algorithms 203 include public key algorithms, private algorithms, and other algorithms as used in the art. The public key database 205 lists the identifiers used by the senders (users) and recipients, and the public keys associated with these identifiers. Memory 211 contains programming data and other data necessary to support the operation of the encryption server 101. The processors 201 also include a wired and wireless receive block 207 and a wired and wireless transmit block 209.
182 910 and wireless 207 implement the appropriate demodulation techniques on the received messages 105 and 123. The wired and wireless communications transmit block 209 implements the appropriate modulation techniques on the messages 109, 113, 117, 125 and 129 to be sent. In addition, the encryption server 101 may be equipped with hardware and / or software that provide the encryption server 101 with radio-broadcasting capabilities.
The message 105 (Fig. 2) encrypted in the second step with the public key of the encryption server 101 comprises: the digital data message 105A encrypted in the first step with the private key of the user (sender), user ID, and a number of recipient IDs 1 ID, 2 ID, 3 ID, ..., N ID. Alternatively, the user message 105 may include an unencrypted digital data message 105A, user ID Π), and one or more recipient IDs 1 ID, 2 Π), 3 ID, ..., N ID.
The user message 105 is input into a wired and wireless receive block 207, the output of which is the input of processor 201. The processor 201 uses an encryption and decryption algorithm 203 and a public key database 205 to decrypt the user message 105 with the private key of the encryption server 101. Then, the processor 201 determines from the decrypted message the message 105A encrypted in the first step, the user ID and the user ID of the first recipient 1 ID. From the public key database 205, the processor 201 determines the public key of the first recipient and decrypts the first-step encrypted message 105A and the user ID using the encryption and decryption algorithms 203 and the public key of the first recipient. Finally, processor 201 adds the first receiver's ID 1 to form a message 109 which it sends to the wired and wireless communications uplink 209. From there, message 109 is transmitted to the first receiver's telecommunications unit 111 (FIG. 1). A similar process is performed in the case of transmitting the message 105A, encrypted or unencrypted in the first step, and the user ID ID for each of the recipients specified in the user message 105.
In an alternative embodiment, the encryption server 101 may be physically distributed among several servers. The encryption server 101 then encrypts the message with a second set of private and public keys assigned to the second server. The message thus encrypted is sent to the second encryption server. The second server decrypts the message and then encrypts it with the recipient's public key. In heavy traffic, the encryption server 101 optimizes its throughput by performing the calculations necessary to transmit directly to each recipient or to send a transmit request to separate servers. The process is transparent to the user.
The flowchart of FIG. 3 shows the transmission by the telecommunications unit of a digital data message to the encryption server 101. In step 301, a digital data message is generated. If it is determined in step 303 that this message is not intended to be encrypted, it proceeds to step 307. If in step 303 it is determined that the digital data message is to be encrypted, step 305 follows, in which the digital data message is encrypted with the private key of the user sending the message. In step 307, it is determined whether the user and / or recipient identifiers are to be encrypted. If so, the process proceeds to step 309. In step 309, a user identifier and recipient ids are added to the unencrypted message from step 301 or to the message scrambled in step 305. In step 311, the message containing the added identifiers is encrypted with the public key of the encryption server 101. The process proceeds to step 317, where the encrypted message is sent to the encryption server 101.
If the identifiers were not to be encrypted, the process of step 307 proceeds to step 313, where the message not encrypted in step 301 or the message scrambled in step 305 is encrypted with the public key of the encryption server 101. Then, in step 315, it adds the message encrypted in step 313. the user ID and the recipient ids are replaced and the process proceeds to step 317.
182 910
In an alternative embodiment of the method, i.e. when it is determined in step 303 that the digital data message is not intended to be encrypted, the sender or user may decrypt the digital data message and, if desired, the recipient's identifiers only once, by means of the encryption server's public key. . Then, the encryption server decrypts the message with the private key of the encryption server and encrypts the message individually for each recipient with the recipient's public key. The recipient only decrypts the message using the recipient's private key.
This method requires the user to store only one public key, that is, the public key of the encryption server. A single symmetric key may be used to encrypt and decrypt messages between the user and the encryption server 101, and one or more keys may be used to encrypt messages between the encryption server 101 and the recipient. However, for better security, the encryption server 101 used in this embodiment should be physically secured, e.g. locked with restricted access, since there is unencrypted information inside the encryption server 101. The advantage of such a system is that it allows authorized persons to read the decrypted message available on the encryption server 101.
The flowchart of Fig. 4 shows the encryption and sending by the encryption server 101 of the received message. In step 401, the encryption server 101 receives the encrypted message sent by the telecommunications unit 103. In step 403, the encryption server 101 decrypts the message received in step 401 with the private key of the encryption server 101. In step 405, the encryption server 101 determines the user ID, recipient IDs and the encrypted (generated at step 305 of Fig. 3) or a non-encrypted (generated in step 301 in Fig. 3) data message. In an alternate embodiment, the encryption server 101 may be provided with appropriate keys to decrypt the digital data message 105A (if message 105A is encrypted). In this way, authorized authorities can have full access to all information transmitted in the system.
In step 407 it is determined whether the user ID and / or recipient IDs are to be encrypted prior to transmission. If the identifiers are to be encrypted, the process proceeds to step 409, where the encryption server 101 encrypts the encrypted data message with the recipient's public key together with the user ID and recipient IDs, if required. In step 411, the encryption server 101 transmits the encrypted message to the recipient whose public key was used in step 409. If in step 413 it is determined that there are more user-specified recipients for which the encryption server 101 has not yet encrypted the message and has not sent it, the process proceeds to step 407. If in step 413 it is determined that there are no more customers, the process is terminated. If in step 407 it is determined that the identifiers are not to be encrypted, the process proceeds to step 415 where the encrypted data message is encrypted with the recipient's public key and the user ID and recipient ID are added to this encrypted message without further encryption and the process goes to step 411.
Alternatively, all messages may be encrypted simultaneously and then sent sequentially, instead of encrypting the first message with one public key, then sending the encrypted first message, then encrypting the second message with the second public key and sending the second encrypted message, etc.
The method described above relates to encryption with a public key. Private key encryption, where the same key is used to encrypt and decrypt the message, may also be used. For example, the key used to encrypt the message sent to the encryption server may be identical to the key used to decrypt the encrypted message at the encryption server. In addition, encryption of the original digital data message 105A by the user may also be with a private key rather than a public key. Additionally, in the first encryption step, the user may use a different encryption algorithm than in the second encryption step, and the result of this encryption is sent to the encryption server.
182 910
In summary, the method for encrypting messages according to the invention is that, before being transmitted to the encryption server, the messages are encrypted twice: once with the private key of the sender and then with the public key of the encryption server. The encryption server uses its private key to decrypt the received messages, obtaining the encrypted message, the user ID, and the ID of one or more recipients. The encryption server encrypts the encrypted message and user ID individually with the public keys of each recipient and sends the resulting messages to the respective recipients. Each recipient decrypts the messages using the recipient's private key and the sender's public key. In this way, a secured communication system is obtained in which the portable telecommunication devices are neither blocked nor depleted of energy when sending one encrypted message to multiple recipients.
Transmission may be via wireless radio frequency communication or wired communication means such as standard telephone lines or fiber optic cables.
ID- USER ID
<img file="PL182910B1_D0001.tif" />
FIG. 2
182 910
<img file="PL182910B1_D0002.tif" />
313
315
<img file="PL182910B1_D0003.tif" />
182 910
<img file="PL182910B1_D0004.tif" />
<img file="PL182910B1_D0005.tif" />
ENCRYPTION SERVER
<img file="PL182910B1_D0006.tif" />
<img file="PL182910B1_D0007.tif" />
<sup>1</sup> oooonoaaoona Innaaooooaaoa
<img file="PL182910B1_D0008.tif" />
131
121 naQQQQQQQQQQ aoaiMMiiQQMQ | QQQMQMQQQQ | ooaoottoooaoca
<img file="PL182910B1_D0009.tif" />
127
FIG. 1
Publishing Department of the UP RP. Circulation of 50 copies
Price PLN 2.00.
Contents4
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
17 members in 11 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 63945796 | United States of America | A | |
| 63945796 | United States of America | A | |
| 9706161 | United States of America | W | |
| 9706161 | United States of America | W | |
| 96639457 | – | – | – |
| 97US9706161 | – | – | – |
| US19960639457 | – | – | – |
| WO1997US06161 | – | – | – |
Members17
| Document | Office | Kind | |
|---|---|---|---|
| CA2224661A1 | Canada | A1 | |
| WO9741661A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU3877997A | Australia | A | |
| WO9741661A3 | World Intellectual Property Organization (WIPO) | A3 | |
| PL324266A1 | Poland | A1 | |
| US5751813A | United States of America | A | |
| IL122438A0 | Israel | A0 | |
| CN1189949A | China | A | |
| EP0882340A1 | European Patent Office (EPO) | A1 | |
| BR9702187A | Brazil | A | |
| JPH11509075A | Japan | A | |
| RU2147792C1 | Russian Federation | C1 | |
| EP0882340A4 | European Patent Office (EPO) | A4 | |
| IL122438A | Israel | A | |
| CA2224661C | Canada | C | |
| PL182910B1This record | Poland | B1 | |
| CN1098581C | China | C |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Decisions on the lapse of the protection rightsLapsedLAPS | LAPS |
Numbers
- Publication, DOCDB
- 182910
- Publication, EPODOC
- PL182910B
- Application
- 97324266
- Application, DOCDB
- 32426697
- Application, EPODOC
- PL19970324266
Titles2
- English
- USE OF AN ENCODING SERVER FOR ENCODING INFORMATION TO BE TRANSMITTED
- Polish
- Sposób szyfrowania w systemie telekomunikacyjnym
Classification
- CPC, 6
- H04L63/0442
- H04L9/0822
- H04L63/0464
- H04L9/0825
- H04L2463/102
- H04L2209/805
- IPC, 6
- H04L9 00
- H04L9 14
- G09C1 00
- H04L9 30
- H04L9 36
- H04L29 06