Method and apparatus for security in a data processing system
Abstract
This record has no abstract on file.
Term
Term ended
Expired 8 October 2022, 4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
23 claims: 4 independent, 19 dependent
- 1Способ защищенной передачи сообщения, содержащий этапы, на которых определяют краткосрочный ключ для передаваемого сообщения, причем краткосрочный ключ имеет идентификатор краткосрочного ключа, содержащий значение индекса параметров защиты;определяют ключ доступа для сообщения, причем ключ доступа имеет идентификатор ключа доступа, при этом краткосрочный ключ вычисляют как функцию идентификатора краткосрочного ключа и ключа доступа;шифруют сообщение с помощью краткосрочного ключа;формируют заголовок Интернет-протокола (IP), содержащий идентификатор краткосрочного ключа;и передают зашифрованное сообщение вместе с заголовком Интернет-протокола.
- 2Способ по п.1, в котором идентификатор краткосрочного ключа содержит идентификатор ключа доступа.
- 3Способ по п.1, в котором значение индекса параметров защиты является случайным числом.
- 4Способ по п.1, в котором краткосрочный ключ вычисляют путем шифрования идентификатора краткосрочного ключа с помощью ключа доступа.
- 5Способ по п.1, в котором заголовок Интернет-протокола является частью заголовка инкапсуляции полезной нагрузки IP-пакета с целью защиты (ESP).
- 6Способ по п,5, в котором заголовок Интернет-протокола дополнительно содержит второе случайное число, причем второе случайное число имеет идентификатор случайного числа.
- 7Способ по п.6, в котором идентификатор краткосрочного ключа содержит идентификатор ключа доступа и идентификатор случайного числа.
- 8Способ по п.7, в котором идентификатор краткосрочного ключа дополнительно содержит значение индекса параметров защиты.
- 9Способ по п.8, в котором значение индекса параметров защиты является случайным числом.
- 10Способ по п.6, в котором краткосрочный ключ вычисляют как функцию идентификатора краткосрочного ключа, второго случайного числа и ключа доступа.
- 11Способ по п.10, в котором краткосрочный ключ вычисляют путем шифрования идентификатора краткосрочного ключа и второго случайного числа с помощью ключа доступа.
- 12Способ защищенного приема контента, содержащий этапы, на которых принимают пакет протокола защиты графика на уровне Интернет-протокола (IPSec), включающий в себя зашифрованный контент и индекс параметров защиты, относящийся к краткосрочному ключу, восстанавливают ключ доступа с использованием индекса параметров защиты, вычисляют краткосрочный ключ с использованием индекса параметров защиты и ключа доступа и дешифруют контент с использованием краткосрочного ключа.
- 13Способ по п.12, в котором индекс параметров защиты содержит значение ключа доступа, при этом ключ доступа восстанавливают с использованием этого значения ключа доступа.
- 14Способ по п.13, в котором значение ключа доступа показывает, какой ключ доступа должен быть использован для вычисления краткосрочного ключа, и хранится в таблице соответствия.
- 15Способ по п.12, в котором индекс параметров защиты содержит случайное число, при этом краткосрочный ключ вычисляют с использованием этого случайного числа и ключа доступа.
- 16Мобильная станция для защищенного приема контента, содержащая средство для приема пакета протокола защиты графика на уровне Интернет-протокола (IPSec), включающего в себя зашифрованный контент и индекс параметров защиты, относящийся к краткосрочному ключу, средство для восстановления ключа доступа с использованием индекса параметров защиты, средство для вычисления краткосрочного ключа с использованием индекса параметров защиты и ключа доступа и средство для дешифрования контента с использованием краткосрочного ключа.
- 17Мобильная станция по п.16, в которой индекс параметров защиты содержит значение ключа доступа, при этом ключ доступа восстанавливается средством для восстановления ключа доступа с использованием этого значения ключа доступа.
- 18Мобильная станция по п.17, в которой значение ключа доступа показывает, какой ключ доступа должен быть использован для вычисления краткосрочного ключа, при этом мобильная станция дополнительно содержит средство для хранения значений ключа доступа.
- 19Мобильная станция по п.16, в которой индекс параметров защиты содержит случайное число, при этом краткосрочный ключ вычисляется средством для вычисления краткосрочного ключа с использованием этого случайного числа и ключа доступа.
- 20Мобильная станция для защищенного приема контента, содержащая схему приема, выполненную с возможностью приема пакета протокола защиты графика на уровне Интернет-протокола (IPSec), включающего в себя зашифрованный контент и индекс параметров защиты, относящийся к краткосрочному ключу, модуль идентификации пользователя, выполненный с возможностью восстановления ключа доступа с использованием индекса параметров защиты, при этом модуль идентификации пользователя дополнительно выполнен с возможностью вычисления краткосрочного ключа с использованием индекса параметров защиты и ключа доступа, и блок оборудования мобильной связи, выполненный с возможностью дешифрования контента с использованием краткосрочного ключа.
- 21Мобильная станция по п.20, в которой модуль идентификации пользователя содержит блок обработки, выполненный с возможностью восстановления ключа доступа.
- 22Мобильная станция по п.21, в которой модуль идентификации пользователя дополнительно содержит запоминающее устройство для хранения ключа доступа.
- 23Мобильная станция по п.21, в которой блок обработки дополнительно выполнен с возможностью вычисления краткосрочного ключа.
Independent claims23
158 paragraphs in 4 sections, as filed
TECHNICAL FIELD OF THE INVENTION
The present invention relates generally to data processing systems and particularly to methods and devices for providing protection in a data processing system.
BACKGROUND
Protecting information systems and data processing systems, including communications systems, contributes identifiability fairness faultlessness, confidentiality, operability, as well as a variety of other criteria. Encryption, or the total area of cryptography, used in e-commerce, wireless, in broadcasting, and has a very wide range of applications. The e-commerce encryption is used to prevent fraud and verification of financial transactions. In data processing systems, encryption is used to verify the authenticity of the parties. Encryption is also used to prevent hacking, protect Web-pages, and prevent access to confidential documents, as well as the implementation of other security measures.
Systems employing cryptography, often referred to as cryptosystems, can be divided into symmetric cryptosystems and asymmetric cryptosystems. Systems with symmetric encryption using the same key (ie secret key) to encrypt and decrypt messages. Meanwhile, asymmetric encryption system uses a first key (i.e. public key) to encrypt a message and uses a second, different key (i.e. private key) to decrypt the message. The asymmetric cryptosystems are often called public-key cryptosystems. In symmetric cryptosystems problem exists secure secret key from a transmission source to the receiver. In addition, in symmetric cryptosystems there is a problem with frequent updating of keys or other encryption mechanisms. In data processing systems secure key update methods have the effect of increasing processing time, memory, and other overhead costs in processing. In wireless communication systems update key occupies valuable bandwidth resources, which otherwise could be available for transmission.
The prior art has not provided a method for updating keys to a large group of mobile stations to enable them to access an encrypted broadcast. Thus, there exists a need for a secure and efficient method of updating keys in a data processing system. In addition there is a need for a secure and efficient method of updating keys in a wireless communication system.
SUMMARY OF THE INVENTION
Embodiments of the invention disclosed herein is intended to meet the above described need by providing a method for providing protection in data processing systems. In one aspect, a method of secure transmission includes determining a short-term key for the message to be transmitted, and the short key has an ID key short-term; determining an access key for this message, the access key is the access key ID; encrypting messages using the access key; the formation of the Internet protocol header, containing identifier of the key short-term, and the transfer of the encrypted message with the title Internet Protocol.
In another aspect, in a wireless communication system, supporting a broadcast infrastructure element includes a circuit receiving a subscriber identity module performing the recovery of short-term key for decrypting a broadcast message, and a block of mobile communication equipment, adapted to use a short key for decrypting a broadcast message . User identity module includes a processing unit that performs the decryption of the key information. The block of mobile communication equipment includes a memory for storing a plurality of short term keys and short term key identifiers.
In yet another aspect, storage of digital signals includes a first set of instructions for receiving the identifier short key specific for the transmission, the identifier of the short-term key corresponds to the short-term key, a second set of instructions for determining an access key based on the identifier the short-term key, the third set of instructions for encryption key identifier via short access key to recover the short-term key, and a fourth set of instructions for decrypting the transmission using the short key.
LIST OF FIGURES
1A - diagram of the cryptosystem.
1B - diagram of a symmetric cryptosystem.
1C - scheme of asymmetric cryptosystems.
1D - diagram of encryption PGP.
1E - diagram of decrypting PGP.
2 - scheme of spread spectrum communications, supporting a number of users.
Figure 3 - a block diagram of a communication system supporting broadcast transmissions.
4 - block diagram of a mobile station in a wireless communication system.
5A and 5B - illustrate models describing the updating of keys in a mobile station, used to control access to the multicast.
6 - a model that describes the cryptographic operations in the IIP.
7A-7D - illustration of a method for realizing the secure encryption in a wireless communication system supporting broadcast transmissions.
7E - timing chart update periods key security option in a wireless communication system supporting broadcast transmissions.
8A-8D - illustrate the application of a secure encryption method in a wireless communication system supporting broadcast transmissions.
9A - illustrates the format of IPSec packet for transmission over the Internet Protocol.
9B - illustration ID Protection Association, or SPI, applicable in the packet IPSec.
9C - illustration of memory to store the SPI mobile station.
9D - illustration memory storage access keys to the broadcasting (KDSH, HAC) in the mobile station.
10 and 11 - illustrates a method for protecting a broadcast message in a wireless communication system.
12A - illustration ID Protection Association, or SPI, applicable in the packet IPSec.
12B - illustration of memory to store the SPI mobile station.
13 and 14 - illustrates a method for protecting a broadcast message in a wireless communication system.
Detailed description
The word "exemplary" as used herein is used exclusively to mean "serving as an example, a demonstration, or illustration." Any embodiment described herein as "exemplary" is not to be construed as preferred or advantageous over other embodiments.
Wireless communication systems are widely deployed to provide various types of communication such as voice, data, etc. Such systems may be based on code division multiple access (CDMA, CDMA), multiple access, time division multiple access (TDMA, IDMA), or other modulation techniques. A CDMA system provides certain advantages over other types of systems, including increased system capacity.
The system can be designed to support one or more standards such as the standard "TIA / EIA / IS-95-B Mobile Station-Base Station Compatibility Standard for Dual-Mode Wideband Spread Spectrum Cellular System", which is herein referred to as the IS -95, the standard offered by a consortium "3rd Generation Partnership Project" (partnership project communication systems of the 3rd generation), which is herein referred to as the 3GPP standard, and the standard, embodied in a set of documents including Document №№ 3G TS 25.211, 3G TS 25.212, 3G TS and 25.213, 3G TS 25.214, 3G TS 25.302, which is herein referred to as standard W-CDMA, the standard offered by a consortium "3rd Generation Partnership Project 2" (Partnership Project 2 in communication systems 3rd Generation), which is herein referred to as a standard of 3GPP2, and the standard TR-45.4, which is herein referred to as a standard cdma2000, originally called the IS-2000 MC. The standards listed above are incorporated herein in their entirety by reference.
Each standard specifically defines the processing of data for transmission from base station to mobile station, and vice versa. The following discussion considers an exemplary embodiment communication system with the spread spectrum system compatibility standard cdma2000. Alternate embodiments may incorporate another standard / system. Other embodiments may apply the methods of protection described herein, other types of data processing systems using cryptosystems.
Cryptosystem is a method for concealing messages, allowing a certain group of users to remove the specified message. 1A illustrates a basic cryptosystem 10. Cryptography is the art, associated with the creation and use of cryptosystems. Cryptanalysis is the art, associated with breaking cryptosystems, ie, reception and recognition of communications, provided that you are not part of a specific group of users who are allowed access to the message. The original message is called a message in plain text, or plain text. The encrypted message is called a ciphertext, wherein encryption includes any means for converting plaintext into ciphertext. Decryption includes any means for converting ciphertext into plaintext, for example, restoring the original message. As illustrated in Figure 1A, the message in plain text is encrypted to form ciphertext. Then the ciphertext is received and decoded to recover the plaintext. Although the terms "clear" and "ciphertext" generally refer to data, the concepts of encryption may be applied to any digital information, including audio and video data presented in digital form. Although the invention as set forth herein, the terms "clear" and "ciphertext" are used, respectively, the art related to cryptography, these terms do not exclude other forms of digital communication.
Cryptosystem based on secrets (numerical values, the actual participants known cryptosystems, but unknown to others). Group objects together using a secret if an entity outside this group can not get this secret is not having a very significant resource.
A cryptosystem may be a collection of algorithms, wherein each algorithm is labeled and the labels are called keys. Symmetric encryption system, often called a cryptosystem uses the same key (for example, a secret key) to encrypt and decrypt messages. Symmetric encryption system 20 is illustrated in Figure 1B, and for encrypting and decrypting the same secret key is used.
In contrast, the asymmetric encryption system uses the first key (eg, a public key) to encrypt a message and uses a different key (for example, the private key) to decrypt it. 1C illustrates an asymmetric encryption system 30 wherein one key is provided for encryption and a second key for decryption. Asymmetric cryptosystems also called public-key cryptosystems. The public key is available in an open letter, and becomes available to encrypt any message, but only the private key can be used for decrypting messages encrypted with the public key.
In symmetric cryptosystems the problem exists of providing a secure secret key from the source to the receiver. In one of the solutions for the provision of information can be used by a courier or a more efficient and reliable solution would be to use public-key cryptosystems, such as riptosistema public key developed Rivert, Shamir, and Adelman (RSA), discussed below. The RSA is used in the popular security tools, called Pretty Good Privacy (PGP), described in more detail below. For example, the originally recorded cryptosystem replaces characters in the plaintext by shifting each letter by n in the alphabet, wherein n is a predetermined integer constant. In this scheme, "A" is replaced with "D", etc., and this encryption scheme may include several values of n. In this encryption scheme "n" is the key. Provided the recipient is given encryption scheme before taking the ciphertext. In this case, only knowing the key should be able to decrypt the ciphertext to obtain the plaintext. However, by calculating a known encryption key, unintended parties may be able to intercept and decrypt ciphertext, creating a security problem.
The more complex and sophisticated cryptosystem using the strategic keys that are resistant to interception and decryption by unintended parties. Classical cryptosystem uses encryption functions E and decryption function D, such as:
D_K (E_K (P)) = P, for any plaintext P. (1)
In public-key cryptosystems E_K easily calculated based on the known "public key" Y, which is in turn calculated based on the public key K Y is discharged into the open circulation, so that anyone can encrypt messages. D_K decryption function is calculated based on a public key Y, but only know the secret key K. Without the private key unintended recipient is not able to decrypt the ciphertext generated thus. In this case, only a recipient who has generated K can decrypt messages.
RSA is a public-key cryptosystem developed Rivert, Shamir and Adelman, in which, for example, the plaintext is viewed as positive integers up to 2512. The keys are the four (p, q, e, d), with a number of 256-bit simple number q in the form of 258-bit prime number, and d and e in large numbers with (de-1) divisible by (p-1) (q-1). Next, define the encryption function as:
E_K (P) = Pemod (pq), D_K (C) = Cdmod (pq). (2)
While E_K easily computed from the pair (pq, e), there is no simple method of calculating D_K pair (pq, e). Consequently, the recipient that generated K can be released in an open letter (pq, e). Is it possible to send a secure message to the recipient, and only he has the ability to read the communication.
PGP combines features of symmetric and asymmetric encryption. 1D and 1E illustrate the cryptosystem 50 PGP, where a message in plain text is encrypted and restored. 1D message in plaintext is compressed to save modem transmission time and disk space. Compression strengthens cryptographic security by adding another level of conversion to the processing for encryption and decryption. Most cryptanalysis techniques to crack the cipher uses a combination found in plain text. Compression reduces the amount of such combinations in the plaintext, thereby enhancing resistance to cryptanalysis. It should be noted that one embodiment does not compress: plaintext, or other connection, is too short to compress, or not very good compressible.
PGP then creates a session key, which is a one-time secret key. This key is a random number that can be generated by any accidental event (s), such as the random movement of a computer mouse and / or keystrokes when you print. The session key is used to secure encryption algorithm to encrypt the plaintext, resulting in ciphertext. After encryption session key is encrypted using the recipient's public key. Session key encrypted by the public key is transmitted along with the ciphertext to the recipient.
For decryption, as illustrated in Figure 1, the recipient uses PGP copy of the secret key to recover the temporary session key, which PGP then uses to decrypt the cipher text encrypted in the usual way. The combination of encryption methods offers advantages convenience of public key encryption and the speed of symmetric encryption. Symmetric encryption is generally much faster than public key encryption. Public key encryption in turn provides a solution to problems of key distribution and data transmission. The combination of performance and key distribution are improved without compromising security.
The key is the value used in the cryptographic algorithm to produce a specific ciphertext. Typically, the keys are very large numbers. Key size is measured in bits. In public key cryptography, security increases with key size, however, public key size and the size of the secret symmetric key encryption is generally not related. While the public and private keys are mathematically related, a problem arises in the determination of a private key known only with the public key. Determination of the private key is possible with enough time and computing power that makes the choice of the key size of an issue while providing protection. The optimum goal is to maximize the size of the key in terms of protection and minimizing the size of the key in terms of rapid processing. Longer keys are cryptographically secure for a longer period of time. An additional consideration is the alleged interceptor, more specifically: 1) what is the importance of the message to a third party; and 2) how many resources are available to a third party to decrypt the message.
It should be noted that the keys are stored in encrypted form. Specifically, PGP stores the keys in two files: one for the public keys and one for private keys. These files are called 'key-ring'. In the application, the PGP encryption system adds the public keys of the target recipient in the ring for the sender's public key. Sender's private key is stored in the ring for the secret key of the sender.
As discussed in the examples cited above, the method of distributing the keys used for encryption and decryption can be complicated. "The problem of key exchange" includes, firstly, providing assurance that the key exchange is carried out so that both the sender and receiver can perform encryption and decryption, respectively, for bidirectional communication, that both sender and the recipient can encrypt and decrypt messages. Besides this requires that the key exchange is done in a way to prevent the interception of the third and unintended party.
Finally, the subject of a separate authentication (authentication), which guarantees the recipient that the message was encrypted by the sender provided, and not a third party. The system of exchange secret keys, key exchange takes place securely, providing improved security in a successful key exchange and authentication faithful. It should be noted that the circuit with secret encryption key implicitly provides authentication. The basic assumption in the secret key cryptosystem is that only the sender has provided the key that can encrypt a message delivered to the recipient provided. Although cryptographic techniques of public key decide critical aspect "key exchange problem ', in particular their resistance to analysis even with the presence a passive eavesdropping during the exchange of keys, still, they do not solve all problems associated with key exchange. More specifically, since the keys are considered as 'public information' (especially in the case of RSA), authentication is required to provide a different mechanism. It is desirable that authentication was enough only to possession of keys, and although it is enough to encrypt messages, it is no guarantee of a unique authentication of the sender, and the possession of the appropriate decryption key is not in itself sufficient to establish the identity of the recipient.
One solution is to provide a mechanism for key distribution, ensures that the keys in the list are in fact owned by the specified object, sometimes referred to as a trusted authority, the certifying authority or the depositary of a third party. Normally, the body does not generate keys myself, but ensures that the list of keys and associated identification data stored and advertised for information senders and recipients are true and not discredited. Another method is based on the fact that users distribute and track each other's keys and trust in an informal way of organizing distributed. In the case of RSA, if a user wishes to send evidence of their identity in addition to an encrypted message, a signature is encrypted with a secret key. The recipient may use the RSA algorithm converts a way as to ensure that the information stands, because only the sender can encrypt the plaintext using the private key. Normally encrypted 'signature' is a 'message digest' that contains a unique mathematical 'resume' secret message (if the signature was constant for multiple messages, then knowing the previous recipients could use it correctly). Thus, theoretically, only the sender of the message can generate a correct signature for that message, thereby authenticating it for the receiver.
The message digest is often computed using a cryptographic hash function. A cryptographic hash function computes a value (with a fixed number of bits) from any input value, regardless of the length of the input variable. One property of a cryptographic hash function is this: for a given output value is difficult to determine by calculating the input value, which gave the specified output value. An example of a cryptographic hash function is SHA-1, described in "Secure Hash Standard", FIPS PUB 180-1, published Federal Information Processing Standards Publications (FIPS PUBS) and issued by National Institute of Standards and Technology.
Figure 2 shows an example of a communications system 100 that supports a number of users and capable of implementing at least some aspects and embodiments of the present invention. To arrange the system 100 may be any of a variety of algorithms and methods. System 100 provides communication for a number of cells 102A on 102G, each of which is serviced by a corresponding base station 104A at 104G, respectively. In the exemplary embodiment, some of base stations 104 have multiple receive antennas and others have only one receive antenna. Similarly, some of base stations 104 have multiple transmit antennas, and others have single transmit antennas. There are no restrictions on the combinations of transmit antennas and receive antennas. Thus it is possible that the base station 104 has multiple transmit antennas and a single receive antenna, or a plurality of receive antennas and a single transmit antenna, or is as one or a plurality of transmit antennas and receive antennas.
Terminals 106 in the coverage area may be fixed (i.e., stationary) or mobile. As shown in Figure 2, the system is allocated to different terminals 106. Each terminal 106 at any given time is in communication with at least one and possibly more base stations 104 on the uplink and downlink Communication that depends on, for example, whether soft handoff mode or whether the terminal is designed to (concurrently or sequentially) receive multiple transmissions from multiple base stations, and if it is working in this mode. Soft handoff mode in CDMA communications systems is well known in this art and are described in detail in U.S. Patent number 5,101,501 entitled "Method and system for providing a Soft Handoff in CDMA Cellular Telephone System", assigned to the assignee of the present invention.
The downlink refers to transmission from the base station to the terminal, and the uplink refers to transmission from the terminal to the base station. In the exemplary embodiment, some of terminals 106 have multiple receive antennas and others have only one receive antenna. In Figure 2, the base station 104A transmits data to terminals 106A and 106J, base station 104C transmits data to terminal 106C, and so on
The increasing demand for wireless data transmission and the expansion of services available via wireless communication technology have led to the creation of specific data services. One such service is called a high-speed data (VPD, HDR). Examples of services offered in the specification of the CPA "EIA / TIA-IS856 cdma2000 High Rate Packet Data Air Interface Specification", called "PEP specification" ("HDE Specification"). Hauling CPA is generally more comprehensive in respect to voice communication systems that provides an efficient method of transmitting packets of data in a wireless communication system. When the volume of data transmitted and the number of channels, limited bandwidth available for radio transmissions becomes a critical resource. Consequently, a need exists for an efficient and accurate method to transmissions in communication systems, optimizes the use of available bandwidth. In an exemplary embodiment, the system 100 shown in Figure 2, is consistent with a CDMA type system having PEP service.
In an exemplary embodiment, the system 100 supports a high-speed multimedia broadcasting service, called a high-speed broadcast service (UVSSH, HSBS). Examples UVSSH applications may include generating streams movies, sports, news, etc. UVSSH service is a packet data service based on Internet Protocol (IP). In an exemplary embodiment, the service provider informs the user about the availability of such high-speed broadcast. Users who wish to use the service UVSSH, subscribe to a service and can be found with the program broadcast service through advertising, short message service (SMS), Wireless Application Protocol (WAP), etc. Mobile users are referred to as mobile stations (MS, MS). Base stations (BS) transmit parameters relating to UVSSH for official communications. If the MS is willing to accept a broadcast session, the MS reads the overhead messages and determines the appropriate configuration. The MS then tunes to the frequency containing UVSSH channel, and receives the broadcast service content.
The service in question is a high-speed multimedia broadcasting service. This service is referred to herein as a high-speed broadcast service (UVSSH). One example is the formation of streams movies, sports, news, etc. This service is probably a packet data service based on Internet Protocol (IP).
Service Provider notifies users about the availability of such high-speed broadcast. Users of mobile stations wishing to use such a service, subscribe to a service and can be found with the program broadcast service through advertising, SMS, WAP, etc. The base stations transmit parameters relating to the broadcasting service in the official reports. Mobile stations wishing to listen to the broadcast session, reads the overhead messages and determine the appropriate configuration, tuned to the frequency containing high broadcast channel and starts receiving content broadcast service.
For UVSSH service models, there are several possible subscription / payment, which include access-controlled access, and partially controlled access. For free access does not require a subscription for the service. BS produces broadcast content without encryption and interested mobiles devices can receive this content. Thus, the service provider can earn revenue by means of advertising, which may also be transmitted over a broadcast channel. For example, can be transmitted clips produced films in the near future, for which the studio paid provider.
In the case of controlled access, in order to receive a broadcasting service, the MS user subscribes to the service and pay the relevant amount. Unsigned user will not be able to receive the service UVSSH. Controlled access can be achieved by encrypting the transmission / content UVSSH so that only subscribed users can decrypt the content. In this procedure can be used for encryption key exchange radio interface. This scheme provides a high level of security and prevents theft of services.
A hybrid access scheme called partial controlled access, provides a service UVSSH as a subscription-based service that is being encrypted with intermittent unencrypted advertising programs. These advertisements may be intended to encourage subscriptions to the encrypted service UVSSH. Schedule of these unencrypted segments could be known to the MS through a third-party tools.
3 is a wireless communication system 200 in which video and audio information is available in the service network packet data (PDSN) 202, a content server (SC, CS) 201. The source of the video and audio information may be broadcast and radio broadcast. The information is provided as packetized data, such as IP-packets. PDSN 202 processes the IP-packets for distribution in the access network (AN, AN). As shown, the AN is defined as part of a system including a BS 204 in communication with multiple MS 206. PDSN 202 associated with the BS 204. For UVSSH service, the BS 204 transmits a stream of information from PDSN 202 and provides the information on a particular channel to subscribers in the system 200. To control access, content is encrypted before granting SC 201 in the PDSN 202. subscribed users are provided with the decryption keys that allow to decrypt the IP-packets.
Figure 4 shows in detail the MS 300, similar to MS 206 of Figure 3. The MS 300 has an antenna 302 connected to a receiving circuit 304. MS 300 receives transmissions from a BS (not shown) similar to BS 204 of Figure 3. MS 300 includes a User Identity Module (UIM, UIM) 308 and mobile communication equipment (CHI ME) 306. The circuit 304 is connected to receive the IIP 308 and 306. MLA IIP 308 applies verification procedures for the protection of transmission UVSSH and provides various keys in CHI CHI 306. 306 can be connected to the processing unit 312. OMC 306 performs the main processing that includes, but is not limited to, decryption of content flows UVSSH. MLA 306 includes a memory storage 310. In an exemplary embodiment, the data processing unit in the OMC 306 (not shown) and the data in the memory MLA memory 310 can easily be accessed by the subscriber is not using limited resources, and so say the OMC 306 is unprotected. Any information that falls within the MLA or processed 306 in MLA 306, the secret remains secure and only for a short period of time. Therefore it is required that any confidential information such as key (s) used in conjunction with the MLA 306, part of me.
UIM 308 is trusted to store and process secret information (such as encryption keys) that should be protected for a long time. Since IIP 308 is a secure unit for secrets stored in it is not necessary that the system often changed sensitive information. UIM 308 includes a processing unit, called the secure processing unit IIP (ZBOM, SUPU) 316 and a storage device called the protected memory IIP (ZZUM, SUMU) 314, which are entrusted to protect. Inside IIP 308 ZZUM 314 stores secret information in such a way as to prevent unauthorized access to information. If the secret information obtained from UIM 308, the access should require a relatively large amount of resources. Also inside the IIP 308 ZBOM 316 performs calculations on the values which may be external to the UIM 308 and / or internal relative IPI 308. The calculation results can be stored in or transmitted ZZUM 314 in MLA 306. Calculations performed ZBOM 316 can be obtained Only 308 of the IIP objects with a significant amount of resources. Similarly, the output ZBOM 316 intended to be stored in ZZUM 314 (but not output to the OMC 306), arranged so that unauthorized interception requires substantial resources. In one embodiment, the UIM 308 is a constant unit within the MS 300. Note that in addition to the secure memory and processing in UIM 308, UIM 308 may also include non-secure memory and processing (not shown) for storing information , including phone numbers, information about the e-mail address information of Web-pages or uniform resource locator (URL), and / or function organizer, etc.
Alternate embodiments may provide a removable and / or reprogrammable UIM. In an exemplary embodiment ZBOM 316 has no significant processing power for functions in addition to the procedures related to the protection and keys, the keys are usually protection and can be used to allow the encryption of content broadcast UVSSH. Alternate embodiments may implement a UIM with greater computing power.
UIM 308 is associated with a particular user and is used mainly to verify that the MS 300 has a right to enjoy the privileges granted to that user, such as access to a mobile telephone network. Thus, the user is likely associated with the UIM 308 rather than the MS 300. The same user may be associated with multiple UIM 308.
Broadcasting service is faced with the problem of determining the method of distribution of keys the user has subscribed. To decrypt the broadcast content at a specific time, the MLA should know the current decryption key. To prevent theft of services, the decryption key must be changed frequently, for example, one key service updates every minute. These decryption keys are called short-term keys (CK, SK). QC is used to decrypt the broadcast content for a short period of time, therefore, the spacecraft can be considered as having some value to the user in monetary terms. For example, the value in monetary terms can be part of the cost of registration. Assume that the subscriber is not the cost of getting spacecraft from the memory storage 310 subscriber exceeds the value in monetary terms, QC. That is the cost of obtaining illegitimate QC exceeds the remuneration, which results in the absence of net profit. Consequently, the need for the protection of spacecraft in the memory storage 310 decreases. However, if the private key has a lifetime of greater than the lifetime of the spacecraft, the cost of obtaining illegitimate QC can actually be less than the reward. In such a situation there is a net profit in the illegitimate receipt of the CC storage memory 310. Hence, in the ideal case, the storage device memory 310 does not store secrets with a lifetime exceeding the lifetime of the spacecraft.
It is assumed that the channels used by the IC (not shown) for distribution to various devices QC subscribers are unprotected. In other words, in the optimum design channels must rely unprotected and QC must be designed accordingly. Thus, the propagation of the CC, SC requires ways of hiding from unsigned value CC members. Besides QC SC it distributes each of a potentially large number of subscribers for processing in respective OMC in a relatively short period of time. Known methods of secure key distribution are traditionally slow and require the transmission of large amounts of keys. Key transmission methods are generally not suitable for the desired combination of security and efficiency criteria. An exemplary embodiment of the invention is useful way of distributing decryption keys among a plurality of subscribers in a short time in such a way that no subscribers can not obtain the decryption keys.
An exemplary embodiment is described as transmitting the information in the packets that are compatible with the Internet protocol, such as described below packets "IPSec" (protocol traffic protection level IP), and thus, the following description provides a brief introduction to terminology used in connection with IPSec. This terminology is useful for describing exemplary embodiments, but the use of this terminology is not meant to limit the exemplary embodiment, communication using IPSec.
IPSec main provisions are described in RFC 1825, entitled "Security Architecture for Internet Protocol", R. Atkinson, August 1995, RFC 1826 entitled "IP Autentification Header", R. Atkinson, August 1995, and RFC 1827 entitled "IP Encapsulating Security Payload ( ESP) ", R. Atkinson, August 1995. The authentication header is a mechanism for ensuring the integrity of the IP-datagrams, wherein IP-datagrams are generally a collection of useful information, called payload, combined with network control information and IP header. Network routers use IP headers to route packets to the desired node. In some situations, the authentication header may also provide authentication to IP-datagrams. Encapsulation Payload IP-packet for the protection (ESP) is a mechanism for providing confidentiality and integrity of IP-datagrams, and may be used in conjunction with the authentication header. IPSec uses a "security association" (data structures associated with the secure transmission and defining its security parameters) to describe the parameters, such as the encryption key and the encryption algorithm used in the encryption and / or authenticate communications between a group of objects. It should be noted that the concept of security association is also applicable to cryptosystems not based on IPSec.
IPSec packet includes a 32-bit parameter, called the security parameters index (SPI), which is used in conjunction with the destination address to identify the security association used for the encryption and / or authentication of content IP-datagrams. Any object can maintain security association database protection associations and associations index of protection according to the destination address and SPI. The encrypted content IPSec packets are often called the payload.
In an exemplary embodiment, MS 300 supports UVSSH in a wireless communication system. To access UVSSH user must register and then subscribe to the service. After subscribing various keys are updated as required. During the registration process, and IC UIM 308 agree on the association of protection and come to an agreement on the registration key (RK, RK) and other parameters required for the security association between the user and the UK. Then SK can be sent to the UIM 308 further secret information encrypted using the RK. RK is kept as a secret in the UIM 308, while other parameters may be stored in the OMC 306. The RK is unique to a given UIM 308, i.e. Each user is assigned a separate Kazakhstan. By itself, the registration process does not give the user access to UVSSH.
As mentioned above, after registration the user subscribes to the service. During the subscription SC 308 sends a MIP value of public key access to multicast (KDSH, WAC). It should be noted that while the RK is specific to the UIM 308 KDSH used to encrypt broadcast to multiple users. SC sends the MS 300, and more specifically, the IIP 308, the value KDSH, encrypted using the RK unique to UIM 308. UIM 308 has the ability to recover the value of the original KDSH encrypted version using RC. KDSH, together with other parameters of the forms of protection association between the UK and the band signed a user. KDSH kept as a secret in the UIM 308, while other parameters of the security association may be stored in the OMC 306. Then the SC sends data, called the short key information (CQI, SKI), which are combined with KDSH in UIM 308 to produce QC. Then IIP 308 passes QC OMS 306. In this case, the IC can efficiently distribute new values of QC OMS subscribed users. Below are some examples of preparation of QC CQI, and CQI forms. Discussed in detail the processes of registration and subscription, and then describes the CQI, and QC.
With regard to registration, when a user logs using this IC, UIM 308 and IC (not shown) installed security association. That is 308 MIP and the UK come to an agreement about the secret registration key RK. Kazakhstan is unique to each UIM 308, but if a user has a plurality of MIP, then the IIP may jointly possess the same RK depending on the policy of the UK. The registration may occur when the user subscribes to a broadcast channel offered by the SC, or may occur before the subscription. One IC can provide a plurality of broadcast channels. SC may select associating the user with the same RK for all channels or require the user to register for each channel and associate the same user with different RK for each channel. Many SC may choose to apply the same registration keys or require user registration and receipt of the RK differs for each IC.
Three common scenarios to establish security association include: 1) a method of the keys to authenticate the Agreement (AKA), used in systems 3GPP; 2) method of Internet Key Exchange (IKE), used in IPSec; and 3) the provision of services through the ether (OTASP). In either case, storage device IIP ZZUM 314 contains a secret key, referred to herein as the A-key. For example, using the method of AKA, A-key is a secret known only to the IIP and the trusted third party (TTP, TTP), the TPA can include several objects. Typically, TPA is a provider of mobile services, which registered users. Any link between the UK and TPA is protected, and the SC believes that the TPA does not contribute to unauthorized access to broadcasting services. When a user logs SK inform TPA that the user wants to sign up for the service, and provides verification of the user's request. TPA uses a function similar to a cryptographic hash function to compute the RK based on the A-key and additional data refers to information about registration keys (IGC, RKI). DTS reports of Kazakhstan and / or the IGC in the UK via a secure channel, along with other data. SC sends the IGC to the MS 300. The circuit 304 receiving reports IGC in UIM 308, and can transmit the IGC in the OMC 306. UIM 308 calculates the Republic of Kazakhstan on the basis of the IGC and the A-key, stored in the memory IIP ZZUM 314. RK is stored in the memory of IPI , ZZUM 314 and not provided directly to the OMS 306. Alternate embodiments may use a script IKE, or any other means of establishing the Republic of Kazakhstan. Must also be other parameters agreed security association between the CS and UIM 308. The RK is kept as a secret in the UIM 308, while other parameters of the security association may be stored in the OMC 306. In an exemplary embodiment, wherein KDSH sent to the UIM 308 as an IPSec packet encrypted using the RK, the UK and agree on the value of the MS 300 SPI, used to index the Association for the Protection and the SPI is designated SPI_RK.
In the process of AKA, Kazakhstan is a secret shared between the UK, IIP and TPA. Thus, as is assumed herein AKA method implies that any association between the protection IC and UIM implicitly includes the TTP. The inclusion of DTS any association of protection is not seen as a security hole because SC trusts in the sense that the TPA does not facilitate unauthorized access to a broadcast channel. As indicated above, if a key is shared with the MLA 306, then it requires frequent replacement. This occurs due to the risk that a subscriber does not have access to the information stored in the memory storage 310, and thus gain access to the service, with a controlled or partially controlled access. QC OMS 306 stores, ie the key information used in decrypting broadcast content, in a memory IC 310. The memory sends the subscribed users to compute necessary information QC. If OMS 306 signatory user can calculate the spacecraft based on this information, the additional information required to calculate the CC can not be secret. In this case, assume that the user unsigned OMC 306 may also compute the CK based on this information. Therefore, the value should be calculated in QC ZBOM 316 using a secret key shared between the SC and the SC 314. ZZUM ZZUM and 314 share the value of RK, but each user has a unique value of RK. SK requires little time to encrypt QC with each value of the Republic of Kazakhstan and to transfer the encrypted values to each user is subscribed.
With regard to the subscription, to ensure the effective dissemination of information about the protected QC SK periodically distributes the public key access to multicast (KDSH) for each subscriber UIM 308. For each subscriber IC encrypts KDSH using the appropriate Kazakhstan, to get the value, called the information about KDSH (IKDSH, BAKI). SC sends the appropriate IKDSH in the MS 300 subscribed users. For example, KDSH may be transmitted as IP-packet encrypted using the RK corresponding to each MS. In an exemplary embodiment, IKDSH a package containing KDSH encrypted using Kazakhstan as a key. Since Kazakhstan is a private key for each user, the UK should send KDSH each subscriber individually; so KDSH not sent via a broadcast channel. MS 300 transmits IKDSH in UIM 308. ZBOM KDSH 316 calculates, using the value of RK stored in ZZUM 314, and the value IKDSH. Then, the value stored in ZZUM KDSH. In an exemplary embodiment, has a value IKDSH SPI, referred SPI_RK, which corresponds to the security association comprising Kazakhstan. MS 300 knows that the UIM 308 can decrypt the payload when the IPSec packet is encrypted according to said security association. Consequently, if the MS 300 receives a packet IPSec, encrypted according to said security association, MS 300 transmits IKDSH in UIM 308 to use the RK at decrypted payload.
It is desirable that the refresh period KDSH was sufficient to provide an opportunity to send SC KDSH each subscriber individually, without a significant amount of overhead messages. Since OMS 306 is not trusted to store secrets for a long time, the IIP does not provide 308 KDSH in MLA 306. There should also be agreed upon other parameters Protection Association between the UK and a group of subscribers. In one embodiment, these parameters are fixed, while in another embodiment, these parameters may be sent as part of the IC IKDSH. Whereas KDSH kept as a secret in the UIM 308, other parameters of the security association may be stored in the OMC 306. In one embodiment, in which KK is sent to the MS 300 as a packet IPSec, encrypted using KDSH, SC provides subscribers SPI, used indexing Protection Association, and said designated SPI SPI_BAK.
The next section discusses how after the successful registration process is updated QC. Within each update period KDSH, it provides a short interval, during which the CC applies the BCH. SC uses a cryptographic function to determine two values and CQI QC (QC information) so that the KK may be determined based on the CQI and KDSH. For example, CQI may be a QC KDSH encrypted using as a key. In one exemplary embodiment, CQI is an IPSec packet, wherein the payload contains the value QC KDSH encrypted using as a key. Alternatively, QC may be the result of applying a cryptographic hash function to a sequence of combined (concatenation) blocks a CQI and KDSH. Ideally, the IC ensures that the values of CC can not be predicted in advance. If the QC can be predicted in advance, then the attacking side, ie object performs illegitimate access can send the predicted values unsigned QC users.
As an example, assume that for a period of 24 hours should be used N CS values. If CC is predicted with an accuracy of 100%, the attacker only needs to request the IIP compute N keys. Then the attacker makes N unsigned keys available to users. Unsigned users can download keys at the beginning of each day and have access to the service UVSSH at low cost or inconvenience. If an attacker is able to predict the spacecraft only up to 50%, the attacker need to send about 2N keys. With a decrease in the accuracy of predictions of the required amount of generated keys increases. The attacking side can be without interest to the spread of QC, convinced that the cost of generation, storage and distribution exceeds the predictions of the profit from illegitimate access. The attacking side can be without interest, convinced that the accuracy of any predictions made by the attacking side is relatively small, thereby increasing the number of keys that are attacking side must generate, to a level at which the cost of more than profit illegitimate access. Consequently, in the ideal case, any generation circuit CC ensures that the best prediction attacker have sufficiently small accuracy. Thus, QC computation should include some random value that can only be predicted in advance with small accuracy.
In an exemplary embodiment, in which KK is encrypted CK CS may select using random or pseudorandom function. In alternative embodiments, in which KK is the result of applying a cryptographic function to the CQI and KDSH, SC when forming CQI introduces unpredictable values. Some of the CQI can be predictable. For example, a part of the CQI may be derived from the system time during which CQIs remains valid. This part, called SKI_PREDICT, can not be transmitted to the MS 300 as part of the broadcast service. The residue CQI, SKI_RANDOM, can be unpredictable. That is SKI_RANDOM predictable with low accuracy. SKI_RANDOM transmitted to the MS 300 as part of a broadcasting service. MS 300 recovers from KIC SKI_PREDICT and SKI_RANDOM and provides CQI IIP 308. CQI can be reduced in UIM 308. CQI value changes for each new CC. Thus, SKI_PREDICT and / or SKI_RANDOM vary with each new computation of QC.
SKI_RANDOM SC sends to the BS for broadcast transmission. BS performs broadcast SKI_RANDOM, which is received by antenna 302 and transmitted to the receiving circuit 304. The circuit 304 receiving offers SKI_RANDOM in the MS 300, MS 300 and restores the KIC. MS 300 provides the CQI MIP 308 and MIP 308 receives CC using KDSH stored in ZZUM 314. Then IIP 308 provides QC OMS 306. The OMS 306 CC retains in the memory storage 310. OMC 306 CC uses to decrypt broadcasts received from the SC.
SC and BS come to an agreement on some of the criteria under which SKI_RANDOM be transmitted. SC may demand a reduction in the value of its own spacecraft in monetary terms by the frequent changes in the spacecraft. In such a situation, the requirement information changes SKI_RANDOM balanced by the requirement optimize the available bandwidth. In some exemplary embodiments, SKI_RANDOM sent with the encrypted content. This allows the MS 300 to generate a QC and decryption start immediately. In many situations, it is unnecessary bandwidth consumption. An exception is a scheme in which SKI_RANDOM sent as communication parameters. For example, the SPI value in IPSec can vary, and can be used to enable SKI_RANDOM values, as more fully described below.
In another embodiment, SKI_RANDOM sent separately from the encrypted content. SKI_RANDOM may even be transmitted on a channel other than the broadcast channel. When the user "tunes" to the broadcast channel reception circuit 304 receives information about the position of the broadcast channel "control channel". It may be desirable to provide quick access when "tuning" by the broadcast channel. Thus from OMC 306 is required to receive a CQI in a short period of time. OMC 306 may already know SKI_RANDOM, however, the BS provides a SKI_RANDOM OMC 306 for a short period of time. For example, the BS may send often SKI_RANDOM control channel with information on the status of a broadcast channel or send often SKI_RANDOM on a broadcast channel. The more BS "update" value SKI_RANDOM, the faster the MS 300 can access the broadcast message. The requirement for balanced SKI_RANDOM update requirement optimizing available bandwidth, because too frequent SKI_RANDOM data transfer may take an unacceptable amount of bandwidth resources in the control channel or broadcast channel.
In some situations, the UK can choose to use the values and SKI_PREDICT SKI_RANDOM, changing the values obtained for each CC. In other situations, the IC may require reducing the number of times changes SKI_RANDOM, to the MS is not required to receive SKI_RANDOM frequently. For example, if the user often changes channels UVSSH in many of them, then it will be better if the value SKI_RANDOM likely will not change for five minutes, during which the user switches to another channel. If SKI_RANDOM change, the user is forced to wait for the broadcast SKI_RANDOM new value that indicates that the circuit is more "user friendly" if SKI_RANDOM remains constant as long as possible. SC may wish to use a set of values of QC during the lifetime value SKI_RANDOM, using the value SKI_PREDICT, which changes if the UK wishes to change the spacecraft. In one example, the system time is used; however, using system time creates additional problems associated with synchronization.
As for encryption and transmission of content broadcast, SC encrypts the broadcast content using the current CC. The exemplary embodiment employs an encryption algorithm, encryption algorithm such as the Advanced Encryption Standard (AES). In an exemplary embodiment, the encrypted content is then transmitted in packets according to the IPSec transport mode encapsulation payload IP-packet for the protection (ESP), discussed below. IPSec packet also contains the value of the SPI, prescribing OMS 306 to use the current CC to decrypt the received broadcast content. The encrypted content is sent via a broadcast channel.
The circuit 304 provides reception and IGC IKDSH directly IIP 308. In addition, if the IC calculates QC based SKI_RANDOM and SKI_PREDICT, then circuit 304 receiving offers SKI_RANDOM in the relevant part of the MS 300, where it is combined with SKI_PREDICT for KIC. In one embodiment, the CQI is attached to the encrypted message and the extracted OMC 306. The CQI is provided in UIM 308 corresponding part of the MS 300. The UIM 308 computes RK based on CRFs and the A-key, decrypts IKDSH using the RK to obtain KDSH and calculates QC using CQI and KDSH to generate QA to apply to CHI CHI 306 306 decrypts the broadcast content using CC. UIM 308 of an exemplary embodiment may not be sufficiently powerful for decryption of broadcast content in real-time and therefore is transmitted in the KK OMC 306 for decrypting the broadcast.
5B illustrates the transmission and processing of keys, including RK, KDSH and CK according to an exemplary embodiment. As illustrated, at registration, the MS 300 receives information about the RC (KFM), and transmits it to UIM 308, wherein ZBOM 316 computes RK using IRC and A-key, and stores the RK in UIM memory, ZZUM 314. The MS 300 periodically receives information about KDSH (IKDSH) containing KDSH encrypted using pK values specific for MIP 308. The encrypted decrypted in ZBOM IKDSH 316 KDSH recovery, which is stored in the memory IIP ZZUM 314. In addition, the MS 300 periodically receives the CQI. In some exemplary embodiments, the MS 300 receives SKI_RANDOM, which it combines with SKI_PREDICT, forming CQI. ZBOM 316 calculates the QC-based CQI and KDSH. QC OMS is available in 306 to decrypt the content broadcast.
In an exemplary embodiment, the key SC must not necessarily encrypted and transmitted to the MS; IC may use an alternative method. Key information generated by the IC to transmit to each MS, the MS provides sufficient information to calculate the key. As illustrated in the system 350 of Figure 6, RK SK generated, but MS is transmitted information about the Republic of Kazakhstan (IGC). SC sends the information sufficient to IIP to obtain RK and RK to obtain the information from the transmitter IC using a predetermined function. IGC provides sufficient information for the MS to determine the source of the RK on the basis of the A-key and other values, such as system time, using a predetermined open the function indicated by d1, wherein:
RC = d1 (A-key, IGC). (3)
In an exemplary embodiment, the function d1 defines a cryptographic-type function. According to one embodiment, RK is determined as:
RC = SHA '(A key || IGC) (4)
where "||" denotes a sequence of combined (concatenation) blocks containing A-key and KFM, SHA '(X) indicates the last 128 bits of output data secure hash algorithm SHA-1 having an inlet X. In an alternative embodiment, RK is determined as:
RC = AES (A-key, IGC), (5)
wherein AES (X, Y) denotes the encryption of 128-bit block KFM, using 128-bit A-key. In another embodiment based on the AKA protocol, RK is determined as the output key generation function f3 in 3GPP, and KFM contains the value RAND and appropriate values of AMF and SQN, as determined by the standard.
KDSH treated in another way, since many users with different values of Kazakhstan, must calculate the same value KDSH. SC may use any method for determining KDSH. However, the value IKDSH associated with a particular IIP 308 must be KDSH encrypted with a unique RC associated with this UIM 308. ZBOM IKDSH 316 decrypts, using the RK stored in ZZUM 314, according to the function, denoted d2, as:
KDSH = d2 (IKDSH, Kazakhstan). (6)
In an alternative embodiment, the IC can calculate IKDSH applying to KDSH decryption process using RC and ZBOM 316 receives KDSH applying to IKDSH encryption process using RC. This is considered equivalent to SC KDSH encryption and decryption in IKDSH ZBOM 316. Alternate embodiments may use any number of key combinations in addition to or instead of 6A.
QC treated similarly RK. In some embodiments, the CQI is determined based on the first and SKI_PREDICT SKI_RANDOM, wherein SKI_RANDOM is information transmitted from the SC to the MS. It then uses the predetermined function labeled d3, for the determination of CK and CQI KDSH (ZZUM stored in 314) for:
CC = d3 (KDSH, ICC). (7)
In one embodiment, the function d3 is a function of a cryptographic type. In an exemplary embodiment, the CS is calculated as:
CC = SHA (KDSH || ICC), (8)
whereas in another embodiment, QC is calculated as
CC = AES (KDSH, ICC). (9)
7A-7D illustrates a method for protecting a broadcast message. 7A illustrates the process 400 registration in which the subscriber agrees to the registration of SC in step 402. In step 404, registration provides a unique SIE RK. In step 406, UIM keeps RK protected memory (ZZUM). 7B illustrates the processing in the IC 420 and the MS during the subscription process. In step 422 generates KDSH SC for the time period T1. KDSH is valid for a time period T1 for KDSH, and KDSH updated periodically. In step 424 authorizes the SC to IIP access to the content broadcast (CS, CS) for a time period T1 for KDSH. In step 426 SC KDSH encrypts using a separate Kazakhstan for each subscriber. Encrypted KDSH called IKDSH. Then, in step 428, SC transmits IKDSH in IIP. In step 430, the IIP takes IKDSH and performs decryption using the RK. Decrypt IKDSH results in KDSH initially generated. IPI maintains KDSH ZZUM in step 432.
If a user subscribes to a broadcast service for a specific period of renovation KDSH, the SC sends the relevant information IKDSH, and IKDSH corresponds KDSH encrypted via Kazakhstan. This usually occurs before the update period of KDSH, or when the MS first tunes to the broadcast channel during this update period KDSH. This may be initiated by the MS or SC according to a variety of criteria. At the same time can be transmitted and decrypt a lot IKDSH.
It should be noted that if the end of the renewal period KDSH a close, the MS may request an updated KDSH at SC if MS has a subscription on the next renewal period KDSH. In an alternate embodiment the first timer t1 is used in the SC, and after expiration of the timer, i.e. meet the requirements for a period of renovation KDSH, SC transmits KDSH. SC can change the KDSH earlier than originally anticipated. This may be necessary if, for example, the current value KDSH disclosed.
It should be noted that it is possible for the user for reception KDSH KDSH update period, wherein, for example, a subscriber to use the service started in the middle of the month then, as update KDSH performed monthly. Additionally, time periods and QC KDSH update can be synchronized so that all subscribers update performed at the scheduled time.
8A illustrates the registration process in a wireless communication system 500 according to an exemplary embodiment. SC 502 agree with each subscriber, ie, MS 512, the generation of the Republic of Kazakhstan, specific for each subscriber. RK is provided in the device in the IIP ZZUM each MS. As shown, the IC 502 generates RK1 that is stored in ZZUM1 510 MIP1 512. Similarly IC 502 generates RK2 and RKN which are stored in ZZUM2 MIP2 520 to 522 and 530 to ZZUMN MIPN 532, respectively.
8B illustrates the subscription process in the system 500. SC 502 further includes a plurality of encoders 504. Each of the encoders 504 receives one of the unique keys RK and BAK value generated in the IC 502. The output of each encoder 504 are IKDSH encrypted specifically for the subscriber. IKDSH is taken from the IIP each MS, such as MIP1 512. Each UIM includes ZBOM and ZZUM such as ZBOM1 ZZUM1 514 and 510 to 512. MIP1 ZBOM includes a decoder, such as decoder 516 that recovers KDSH using RC of the IIP. This process is repeated for each subscriber.
8D illustrates the processing of CABG after registration and subscription. IC 502 includes an encoder 560, which encodes CABG using the current QC for generating encrypted content broadcast (SHKSH EBU). SHKSH then transmitted to subscribers. Each MS includes a decoder, such as decoder 544 that extracts from CABG SHKSH using QC.
The following description considers four exemplary embodiments that may be used to update the CC and broadcast content. In the first exemplary embodiment, KK is calculated based on KDSH and SPI value in IPSec packet header, containing the broadcast content. In the second exemplary embodiment, KK is calculated based on KDSH transmitted broadcast manner random value denoted RAND, and the SPI value in IPSec packet header, containing the broadcast content. In the third exemplary embodiment, KK is calculated based on KDSH, system time and a broadcast transmitted way random value denoted SK_RAND. In the fourth exemplary embodiment is sent to QA IPSec packet form, encrypted with App olzovaniem KDSH. Other embodiments may provide QC as a combination of the above embodiments, or using another mechanism to provide QC MS with sufficient frequency for a loss of interest in unauthorized access to the broadcast service.
As a short-term key (CK) is used to encrypt and decrypt the broadcast content and stored in the memory, which may be subject to unauthorized access, it is usually KK changes frequently. The problem is how often to change the spacecraft while at the same time maintaining a balance with the following four objectives: 1) minimization of the waiting time update QC or blackout period for the mobile station that has recently tuned to the broadcast; 2) to minimize the amount of bandwidth that is used to update the QC; 3) increasing the level of protection; and 4) to simplify integration QC IPSec. Frequent updates can reduce the blackout period, but demand a greater share of the cost of bandwidth to send frequent updates.
One solution provides a way to provide sufficient information to perform updates QC in each packet broadcast content without the use of additional bandwidth. Thus, the blackout period may be minimized without requiring additional bandwidth. Described herein four illustrative embodiment of the upgrade CC have different advantages and disadvantages. All four embodiments provide methods that are largely protected. The first embodiment eliminates the blackout period and uses no additional bandwidth to update the value of KK. Other embodiments may allow the emergence blackout period during periods of heavy use. The first embodiment is also easy to integrate with IPSec.
According to a first embodiment of the update QC, the above problems are solved by defining QA, which encrypts predetermined IPSec packet, as a function key to access the multicast (KDSH) and SPI in the ESP header. In this case, instead of providing a separate flow QA, QC is calculated from the content stream. Assuming that MS has already adopted KDSH, as described above, the MS has the ability to immediately calculate the CC for each packet content without having to wait for any further information about the update QC. This effectively eliminates any waiting time for a new update QC host the broadcast. Once the MS receives a packet of content, MS can immediately identify QC and decrypt the content.
Sufficient information to calculate the spacecraft in MS is provided in the package IPSec. IPSec packet payload encapsulation uses IP-packet for the protection (ESP) and is described in RFC 1827 entitled "IP Encapsulating Security Payload (ESP)", R.Atkinson, August 1995, as mentioned above. ESP is a mechanism to ensure the integrity and confidentiality of IP-datagrams. In some circumstances it can also provide authentication to IP-datagrams. 9A illustrates an IPSec packet 600, including the IP header 602, ESP header 604 and a payload 606, according to one embodiment. Encapsulation payload IP-package in order to protect (ESP) can be located anywhere after the IP header and before the final transport-layer protocol header. Generally ESP contains unencrypted header followed by encrypted data.
ESP header field 604 includes the security association identifier called SPI. In the first embodiment set forth above, the IPSec packets, comprising the broadcast content include SPI, related to QC denoted SPI_SK. 9B illustrates the format of the corresponding 32-bit SPI_SK 610. SPI_SK 610 is divided into two parts: SPI_RAND 612 and BAK_ID 614. SPI_RAND 612 is a random number that is statistically random, and is also used to calculate the spacecraft, which is used to encrypt and decrypt the corresponding broadcast content or payload. SPI_RAND parameter allows the server content (IC) often change the effective value of the QC for the content by changing the value SPI_RAND, thereby providing MS parameters required to calculate the value of immediate QC. Besides SPI_RAND acts SKI_RANDOM, discussed above. Chance SPI_RAND ensures that the attacker would not be able to predict the value of QC with high accuracy. Because SPI is already a standard option in encrypted packets IPSec, ie is set for the ESP, the present embodiment requires no additional bandwidth typically associated with transmitting QC as a separate stream. BAK_ID indicates how important KDSH used to calculate the value of KK. In one embodiment BAK_ID represents 4-bit descriptor, each descriptor is associated with a value KDSH. When the MS performs a subscription, the MS stores each received BAK_ID KDSH and the corresponding value in the memory. In one embodiment the MS includes a mapping table (TC, LUT) for storing the value (s) KDSH identified relevant BAK_ID. TC KDSH placed in secure memory in the IIP.
9D illustrates the TC 630 KDSH. Each item in the TC 630 identifies BAK_ID, the corresponding value KDSH and time of expiry of the combination. The expiry time is introduced due to the small number of values BAK_ID. Alternate embodiments may not use the values of the expiration time in the TS KDSH. In one embodiment, only 16 values are used BAK_ID. If the new KDSH produced every month, while the value BAK_ID be repeated after 16 months. At this point, it may be confusion as to what value KDSH is valid. The expiry time provides the delay period (timeout), after which a new entry replaces the overdue account. TC KDSH may be required to maintain multiple values KDSH. One reason for this is that the SC may decide to send the value in KDSH MS before they become valid. Further, the IC can be solved KDSH set of values that are valid at the same time, with different values KDSH can be used for calculating various values QC. If the vehicle does not contain the current KDSH KDSH corresponding BAK_ID, while the MS can carry out the procedure for obtaining a valid subscription KDSH.
After removing SPI_RAND and BAK_ID of SPI_SK and recovery KDSH corresponding BAK_ID, UIM calculates the value QC based KDSH and SPI_RAND, using a cryptographic function g:
CC = g (BAK, SPI_RAND). (10)
In one embodiment, the function g (BAK, SPI_RAND) corresponds to the encrypted value SPI_RAND, the complement to 128 bits with zeroes, using the AES encryption algorithm with key KDSH as:
CC = AES (BAK, SPI_RAND). (eleven)
In another embodiment, the function g (BAK, SPI_RAND) corresponds to the calculation of the 128 most significant bits of the output of the SHA-1, applied to a sequence of combined (concatenation) and KDSH SPI_RAND:
CC = SHA (BAK, SPI_RAND). (12)
In this case, from the IIP is not required to calculate the value of QC for each packet received by the MS. MS stores each of the values with the corresponding values SPI_SK QC in a memory device such as a correspondence table (TC). MS can store values SPI_SK and QA as an association to protect the database security associations (BAZ, SAD): the vehicle in which the MS maintains the usual security association is required for other applications. Association for Protection of indexed according to the destination address and SPI. When the new CC is generated from the new value SPI_SK, old Protection Association is replaced with the new security association, containing new values SPI_SK and QC. Alternatively, the MS can store values SPI_SK TC and QC QC (SK_LUT), one TC CC allocated to each broadcast channel. 9C illustrates the TS 620 CC. Each item in the TC 620 identifies SPI_SK and the corresponding value QC. When the MS receives a packet of content broadcast OMC first checks BASES or QC TS in order to determine whether the table of values SPI_SK, coinciding with SPI the received packet. If the table contains such a value, the CHI uses this value, otherwise the UIM computes the new value of KK. Insurance can also be the vehicle KDSH BAZ CU or KK.
10 and 11 illustrate one embodiment of the upgrade KK. 10 illustrates a method 700 to perform operations SC. In step 702, for each IP-packet SC determines KDSH to be used in the determination of CK and determines BAK_ID, corresponding KDSH. BAK_ID identifier can be any type that allows to distinguish KDSH values in their set. SC sends KDSH BAK_ID individual users and when the subscription procedure in step 706. The users may perform subscription procedure at various times before and during the subscription period. Steps 702 and 706 may occur before the start of the subscription period. In step 710 SC selects a random value as the value SPI_RAND. If BAK_ID represented using b bits, then SPI_RAND represented using a (32-b) bits. SPI_RAND value should not be repeated during the lifetime of a KDSH. After SPI_RAND and BAK_ID become known, SC unites them (that attaches to BAK_ID SPI_RAND), forming SPI_SK in step 712. In step 714, the UK generates QC, using a cryptographic function for combining with SPI_RAND KDSH corresponding BAK_ID, forming KK . Next, in step 716, the IC encrypts the broadcast message or portion of the message using a CS and sends the encrypted message at step 718. Note that the encrypted broadcast message is part of the IP-packet, which includes the IP header and the ESP header. The ESP header includes SPI_SK. At 720 SC decides whether to change the spacecraft. If the SC decides not to change the spacecraft, while the UK continues to step 716. If the SC decides to change the spacecraft, while the UK continues to step 724 where the SC decides whether to change KDSH. If SC decides not to change KDSH whereas SC proceeds to step 710. If SC decides to change KDSH whereas SC proceeds to step 702.
11 illustrates the corresponding operation at the receiver, such as MS. The method 750 starts when the receiver receives the IP-packet including an ESP header SPI_SK at step 752. Note that the receiver extracts information from SPI_SK IP-packet. Having SPI_SK, the receiver first checks whether the stored in the memory QC corresponding to the received value SPI_SK.
In one embodiment, stored in the TS SPI_SK QC situated in block 306 of Figure 4 OMC and in another embodiment SPI_SK stored security associations database: both of these tables are denoted in this 11 as the SPI table. In step 754, a check table SPI. If the value of KK is stored in the memory of the receiver, the receiver has the option at step 756 to decrypt the payload of the content packet using the stored value of KK. If the receiver does not matter CK stored in the memory, the receiver extracts and BAK_ID SPI_RAND of SPI_SK in step 758. Then, in step 760, the receiver checks whether the actual vehicle KDSH element KDSH corresponding BAK_ID. If the vehicle has a valid KDSH KDSH corresponding BAK_ID, then the receiver selects this value and proceeds to step 764. If the vehicle has no actual KDSH KDSH corresponding BAK_ID, for example, in the case where the user wishes to subscribe for this period, then the receiver performs a to obtain a valid subscription KDSH as shown in step 762. The new KDSH saved together with the TS KDSH BAK_ID and receiver proceeds to step 764. The receiver combines KDSH BAK_ID corresponding value, ie BAK_ID adopted in SPI_SK, and the value SPI_RAND (also contained in the received SPI_SK) to calculate the new CC in step 764. The receiver then uses the new value of KK to decrypt the packet payload content in step 766. The receiver also stores the value QC, indexed appropriately SPI_SK, and possibly the destination address of packets IPSec.
QC is calculated directly from data on KDSH SPI_SK and values in the package content. KDSH changed less often than QC, for example, can vary KDSH once a month. Thus, the receiver has to immediately determine the value QC of the content packets without additional delay and without requiring more bandwidth to send the update KK.
In one embodiment, the QA calculation as follows:
RC = f (SPI_SK, KDSH), (13)
where the function is defined as using encryption SPI_SK KDSH. Since SPI_SK includes SPI_RAND and BAK_ID, equation (13) can also be written as:
RC = f (SPI_RAND, BAK_ID). (14)
The second exemplary embodiment of the update introduces an additional aspect of QC randomness calculation QC and QC is determined as a function KDSH, SPI_RAND RAND and an additional parameter. RAND parameter remains constant for several values of QC. RAND allows to calculate more different values from one value QC KDSH by changing how SPI_RAND, and RAND. Without using RAND, then there is at most 232 values of CC, which can be calculated from one KDSH by changing SPI. However, if a 96-bit RAND, then there is a CC to 2218 values that can be calculated from one KDSH by changing both SPI_RAND, and RAND. (These numbers do not include bits of SPI, which are used to represent BAK_ID.) Now, in addition to being SPI_SK identifies only KDSH, SPI_SK should also contain information identifying the RAND. In order to obtain the value of RAND, SPI_SK is formed of three parts: 1) BAK_ID, identifying value KDSH; 2) RAND_ID, identifying the value of RAND; and 3) the value SPI_RAND, providing changes often random nature SPI_SK.
12 illustrates the corresponding SPI_SK 800 of the IP-packet including a SPI_RAND 802, 804 and BAK_ID RAND_ID 806. SPI_RAND BAK_ID 802 and 804 similar to those described above. SPI_SK for maintaining a predetermined or specified bit length, SPI_RAND 802 may use fewer bits than 612 SPI_RAND 9B, leaving bits for RAND_ID 806. RAND_ID 806 corresponds to the RAND, used for calculating QA and can be 4- bit descriptor or other identifier. RAND_ID and the corresponding value (s) stored in the TS RAND at the receiver. 12B illustrates the TC 820 RAND. RAND TC 820 includes an element for each value of RAND, containing RAND_ID and expiry time associated with the value of RAND.
13 illustrates the operation of SC. For each IP-packet transmitter determines in step 902 KDSH to be used for calculating QA and determines BAK_ID, corresponding KDSH. BAK_ID may be any type of identifier that allows values KDSH distinguish among multiple. SC sends KDSH BAK_ID individual users and when the subscription procedure in step 904. The users may perform subscription procedure at various times before and during the subscription period. Steps 902 and 904 may occur before the start of the subscription period. In step 906, the transmitter selects a value RAND and determines the appropriate RAND_ID. SC may send RAND and RAND_ID in MS on an individual basis or to send RAND and RAND_ID, to be broadcast on a broadcast channel. It is not required that the value of RAND was secret, so it is not encrypted. If RAND_ID RAND and sends a broadcast, should not be a large gap of time between retransmissions so that MS did not have to wait for a long time to get the value of RAND. During the broadcast RAND and RAND_ID uses a large amount of bandwidth. However, if a channel is set up a large number of users, while a large amount of bandwidth required to transmit RAND every user on an individual basis. Therefore, RAND and RAND_ID broadcast to be transmitted unless the channel is set to a large number of users. In step 910, SK chooses a random value SPI_RAND.
After determining SPI_RAND, BAK_ID RAND_ID transmitter and unites them (for example, consistently combines BAK_ID and RAND_ID with SPI_RAND), forming SPI_SK at step 912. The IC uses a cryptographic function for combining SPI_RAND, KDSH (identified BAK_ID) and RAND (identified RAND_ID), forming KK . Then IC encrypts the broadcast message or portion of the broadcast message in step 916 and transmits the encrypted message at step 918. Note that the encrypted broadcast message is part of the IP-packet, which includes the IP header and the ESP header. The ESP header includes SPI_SK. At 920 SC decides whether to change the spacecraft. If SC decides not to change CC, then SC proceeds to step 916. If the CS decides to change SK, then the SC proceeds to step 922, where SC decides whether to change RAND. If SC decides not to change RAND, then SC proceeds to step 910. If SC decides to change RAND, then SC proceeds to step 924, where the IC determines whether to change KDSH. If SC decides not to change KDSH whereas SC proceeds to step 906. If SC decides to change KDSH whereas SC proceeds to step 902.
14 illustrates the corresponding operation at the receiver, such as MS. The method 950 starts when the receiver receives the IP-packet including an ESP header SPI_SK at step 952. Note that the receiver extracts information from SPI_SK IP-packet. Upon receiving SPI_SK, in step 952 the receiver first checks whether stored in a storage device QC corresponding to the received value SPI_SK. In one embodiment, stored in the TS SPI_SK QC situated in block 306 of Figure 4 OMC and in another embodiment SPI_SK stored security associations database: both of these tables are denoted in Figure 14 as the SPI table. In step 954, a check TC QC. If the value of KK is stored in the memory of the receiver, the receiver has the option at step 956 to decrypt the payload of the content packet using the stored value of KK. If the receiver does not matter CK stored in the memory, the receiver extracts and BAK_ID SPI_RAND of SPI_SK in step 958. Then, in step 960, the receiver checks whether the actual vehicle KDSH element KDSH corresponding BAK_ID. If the vehicle has a valid KDSH KDSH corresponding BAK_ID, then the receiver chooses the value and proceeds to step 964. If the vehicle does not have a valid KDSH KDSH corresponding BAK_ID, then (assuming that the user wishes to subscribe to this period), the receiver performs the procedure for subscription KDSH valid, as shown at step 962. The new KDSH saved together with the TS KDSH BAK_ID and receiver proceeds to step 964. Then, in step 964, the receiver checks whether the actual vehicle RAND element RAND, corresponding RAND_ID. If the vehicle has a valid RAND RAND, corresponding RAND_ID, then the receiver selects this value and proceeds to step 964. If the vehicle does not have a valid RAND RAND, corresponding RAND_ID, then the receiver obtains RAND and RAND_ID or by requesting this value in SC, or from the broadcast transmission, as shown in step 966. The new RAND is stored together with the TS RAND_ID RAND, and the receiver proceeds to step 968. The receiver combines KDSH corresponding BAK_ID value (i.e. the received SPI_SK BAK_ID), RAND corresponding RAND_ID (m. e. RAND_ID adopted in SPI_SK), and the value SPI_RAND (also contained in the received SPI_SK) to calculate the new CC in step 968. The receiver then uses the new value of KK to decrypt the packet payload content in step 970. The receiver also stores the value QC indexed accordingly SPI_SK, and possibly the destination address of packets IPSec.
RAND changes less frequently than SPI_RAND. RAND value is common to all mobile stations listening broadcast. Thus, the RAND value may broadcast to all mobile stations, and it does not require encryption individually for each receiver. Thus, if there are enough mobile stations listening on the broadcast stream, if the air interface is a more efficient broadcast RAND value a few times to all these mobile stations rather than the requirement that each mobile station individually requests the value of RAND in the UK.
In one embodiment, QA calculation as follows:
RC = f (SPI_SK, KDSH, RAND), (15)
where the function is defined as using encryption SPI_SK KDSH. Since SPI_SK includes SPI_RAND, BAK_ID and RAND_ID, equation (15) can also be written as:
RC = f (SPI_RAND, BAK_ID, RAND_ID, RAND). (16)
It should be noted that the use of RAND values could lead to some of the "blackout period" since the receiver is required to accept a replacement value of RAND. However, these periods are less frequent than when you upgrade CC through a separate thread, and waiting for the receiver periodic updates. RAND provides for less frequent replacement than the value QC, and thus does not update RAND transmitted frequently. For IC may also be desirable to reduce the likelihood of "full off" as a result of termination of MS listening to the channel due to loss of signal, the settings for another channel, or responding to an interrupt, such as a telephone call. Blackout is most likely to occur in the early period of time of existence in the value of RAND. Given this, the IC may conduct retransmission broadcast new RAND more frequently in the vicinity of the point in time when the new RAND value becomes valid. At the end of the lifetime of the RAND may be necessary to perform a broadcast transmission the values of the current RAND, and the importance of follow-RAND. The values of RAND should not be predictable, and the SC shall begin transmission RAND only a short time before RAND becomes valid.
As discussed above, according to the third exemplary embodiment of KK is calculated based on KDSH, system time and a broadcast transmitted way random value denoted SK_RAND. 7C illustrates a method of updating keys for security encryption in a wireless communication system supporting broadcast service. The method 440 implements time periods as shown in Figure 7. KDSH updated periodically through the time interval T1. Timer t1 is started when each generation of spacecraft and expire after a time T1. A variable used to calculate the spacecraft, called SK_RAND and updated periodically over the time interval T2. T2 timer is started when the generated SK_RAND, and expire after T2. In one embodiment, KK is further updated periodically over a time interval T3. Timer t3 starts when each generation of spacecraft and expire after a time T3. SK_RAND generated in the UK and regularly available in the MS. MC and SC SK_RAND used to generate CK as described in more detail below.
The first timer t1 is reset when updating the applied value KDSH. The length of the interval between two updates KDSH is a period of renewal KDSH. In an exemplary embodiment, the refresh period is KDSH month, however, alternate embodiments may use any time interval required for optimal system performance, or to meet a variety of criteria.
Further along the way to 7C 440 starts the timer t2 at step 442, giving rise to a time interval T2 SK_RAND. SK_RAND IC generates and provides this value to a transmission scheme for transmission in the system at step 444. The timer t3 is started at step 446, giving rise to a time interval T3 KK. Then, in step 448, IC encrypts CABG using the current CC. The encrypted result is SHKSH, the SC provides SHKSH a transmission scheme for transmission in the system. If the timer t2 at step 450 has expired, the process returns to step 442. As t2 is not greater than T2, if the timer t3 has expired at step 452, then the processing returns to step 446, otherwise processing returns to step 450.
7D illustrates the MS to access the broadcast service. The method 460 in step 462 first synchronizes the timers t2 and t3 with the values in the NC. IIP MS receives SK_RAND, generated in the UK in step 464. In step 466 generates QC IIP using SK_RAND, KDSH and the result of measurement of time. IIP QC OMS transmits the MS. UIM then decrypts the received SHKSH using CC for extracting source CS at step 468. If the timer t2 expires at step 470, then the processing returns to step 462. Since the timer t2 does not exceed T2, if the timer t3 expires at step 472, the timer t3 is initialized at step 474 and processing returns to step 466.
8C shows key management and updating, and the IC uses a functional means 508 to generate values SK_RAND, which is an intermediate value used by the UK and the MS for calculating spacecraft. More precisely, the functional agent (F) 508 uses the KDSH, SK_RAND and the time factor. Although the embodiment illustrated in 8C, uses a timer to determine when to update QC, alternate embodiments may use alternate measures to provide periodic updates, for example occurrence of an error or other event. SC value SK_RAND offered to each subscriber, wherein the operating means (F) 518, residing in each UIM, realizes the same function as the operating means 508 in the UK. Functional means 518 performs a SK_RAND, KDSH timer value and generating QC, which is stored in the memory of the MLA, for example, positions M1 542 540 OMS1.
As discussed above, according to the fourth embodiment, QC is encrypted using KDSH to generate CQI, and CQI is transmitted to the MS. In one illustrative embodiment, QC is transmitted in a packet IPSec, encrypted using KDSH. SC can also broadcast the corresponding SPI, which can be used to identify data that is encrypted using CK. This embodiment does not require a more detailed discussion.
In an exemplary embodiment, the above, the UK can choose upgrade CC at its discretion. The more frequently changes QC, the more IC can reduce the interest in attacking side to spread the values of CC. There are times when the attacker decides that profits from the dissemination of the values of CC should be higher than at other times. Mostly this is due to the nature of the content broadcast. For example, if there is an important event, unsigned, users will be more interested in getting news on UVSSH and therefore are willing to pay more for illegitimate access than at other times. At these times the UK may increase the cost and create a greater disadvantage the attacker and unsubscribe users, changing QC more frequently than usual. However, the SC should consider the limits of computing power IIP. If CS changes SK too often, then the UIM will be unable to compute the values of CS in real time, and thus the users will not be able to decrypt the content in real time.
Those skilled in the art would understand that information and signals may be represented using any of a variety of known technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips (code PN sequences) that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
Those skilled in the art will also appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or combination. In order to clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in varying ways for each particular application, but such solutions can not be regarded as a departure from the scope of the present invention.
The various illustrative logical blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed with a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable matrix logic elements (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
The steps of a method or algorithm described in connection with the embodiments disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or a combination thereof. A software module may reside in RAM memory, flash memory, ROM, erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any type of media, It is known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may be arranged in a user terminal. In the alternative, the processor and the storage medium may reside in a user terminal in the form of discrete components.
The previous description of the disclosed embodiments is intended to enable any person skilled in the art to make or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the generic principles defined herein may be applied to other embodiments without departing from the spirit and scope of the present invention. Thus, the present invention is not limited to the embodiments shown herein but is to be according the broadest scope consistent with the principles and novel features set forth herein.
Contents4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| RU2718217C1 | Cited by | Russian Federation | Search report |
| US11182490B2 | Cited by | United States of America | Applicant |
| RU2689308C2 | Cited by | Russian Federation | Search report |
| RU2764393C2 | Cited by | Russian Federation | Search report |
| US11544402B2 | Cited by | United States of America | Applicant |
| US11138335B2 | Cited by | United States of America | Applicant |
| RU2614369C2 | Cited by | Russian Federation | Search report |
| RU2768196C2 | Cited by | Russian Federation | Search report |
37 members in 15 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 97330101 | United States of America | A | |
| 97330101 | United States of America | A | |
| 09973301 | – | – | – |
| US20010973301 | – | – | – |
Members37
| Document | Office | Kind | |
|---|---|---|---|
| US2003070092A1 | United States of America | A1 | |
| CA2463542A1 | Canada | A1 | |
| WO03032573A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03032573A3 | World Intellectual Property Organization (WIPO) | A3 | |
| MXPA04003335A | Mexico | A | |
| EP1436939A2 | European Patent Office (EPO) | A2 | |
| IL161312A0 | Israel | A0 | |
| KR20050034607A | Republic of Korea | A | |
| CN1633778A | China | A | |
| RU2004114212A | Russian Federation | A | |
| JP2005537689A | Japan | A | |
| HK1076553A1 | Hong Kong, China | A1 | |
| BR0213214A | Brazil | A | |
| TWI256223B | Taiwan Province of China | B | |
| AU2002342014B2 | Australia | B2 | |
| US7352868B2 | United States of America | B2 | |
| RU2333608C2This record | Russian Federation | C2 | |
| US2008226073A1 | United States of America | A1 | |
| AU2002342014C1 | Australia | C1 | |
| CN100481762C | China | C | |
| CN101515851A | China | A | |
| KR100967323B1 | Republic of Korea | B1 | |
| EP2204939A2 | European Patent Office (EPO) | A2 | |
| EP2204940A2 | European Patent Office (EPO) | A2 | |
| HK1137269A | Hong Kong, China | A | |
| HK1137269A1 | Hong Kong, China | A1 | |
| JP4732687B2 | Japan | B2 | |
| EP2204939A3 | European Patent Office (EPO) | A3 | |
| EP2204940A3 | European Patent Office (EPO) | A3 | |
| CA2463542C | Canada | C | |
| CN101515851B | China | B | |
| US8983065B2 | United States of America | B2 | |
| EP2204939B1 | European Patent Office (EPO) | B1 | |
| EP2204940B1 | European Patent Office (EPO) | B1 | |
| EP1436939B1 | European Patent Office (EPO) | B1 | |
| ES2791681T3 | Spain | T3 | |
| ES2796115T3 | Spain | T3 |
Numbers
- Publication, DOCDB
- 2333608
- Publication, EPODOC
- RU2333608
- Application
- 200411421209
- Application, DOCDB
- 2004114212
- Application, EPODOC
- RU20040114212
Titles2
- Russian
- СПОСОБ И УСТРОЙСТВО ДЛЯ ОБЕСПЕЧЕНИЯ ЗАЩИТЫ В СИСТЕМЕ ОБРАБОТКИ ДАННЫХ
- English
- METHOD AND DEVICE FOR PROVIDING PROTECTION IN THE DATA PROCESSING SYSTEM
Classification
- CPC, 8
- H04L63/04
- H04L9/08
- H04L9/0891
- H04L2209/601
- H04W4/06
- H04W12/04
- H04W12/0433
- H04W12/041
- IPC, 4
- H04L9 08
- G06F21 60
- G06F21 62
- H04L29 06