Device and method for secured radio transmission system
Abstract
FIELD: information technologies. SUBSTANCE: to implement a secure processing in a device, which reliably stores a secret key, multiple calls are received from the network, multiple coding keys are generated on the basis of the secret key and multiple calls, and an access key is generated on the basis of multiple coding keys. EFFECT: provision of the access key protection when it is provided from a supplier to one or more receivers. 34 cl, 6 dwg
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
34 claims: 14 independent, 20 dependent
- 1A method for secure processing at the user terminal, which securely stores the secret key, comprising the steps chtoprinimayut plurality of random call from the network generating a plurality of encryption keys based on a secret key and a set of random challenges;and generating an access key based on the plurality of encryption keys. 1. Способ защищенной обработки в терминале пользователя, который надежно хранит секретный ключ, заключающийся в том, чтопринимают множество случайных вызовов из сети;генерируют множество ключей шифрования на основании секретного ключа и множества случайных вызовов;игенерируют ключ доступа на основании множества ключей шифрования. 1. Способ защищенной обработки в терминале пользователя, который надежно хранит секретный ключ, заключающийся в том, чтопринимают множество случайных вызовов из сети;генерируют множество ключей шифрования на основании секретного ключа и множества случайных вызовов;игенерируют ключ доступа на основании множества ключей шифрования.
- 4A method according to any one of claims 1-3, wherein receiving a plurality of random call comprises receiving a plurality of random values. 4. Способ по любому из пп.1-3, в котором прием множества случайных вызовов содержит этап, на котором принимают множество случайных значений. 4. Способ по любому из пп.1-3, в котором прием множества случайных вызовов содержит этап, на котором принимают множество случайных значений.
- 9A method according to any of claims 1-8 wherein storing a secret key comprises kotoromsohranyayut 128-bit key as a secret subscriber authentication key in a subscriber identity module of a mobile phone using standard Global System for Mobile communications. 9. Способ по любому из пп.1-8, в котором сохранение секретного ключа содержит этап, на которомсохраняют 128-битный ключ аутентификации абонента как секретный ключ в модуле идентификации абонента мобильного телефона, используя стандарт глобальной системы мобильной связи. 9. Способ по любому из пп.1-8, в котором сохранение секретного ключа содержит этап, на которомсохраняют 128-битный ключ аутентификации абонента как секретный ключ в модуле идентификации абонента мобильного телефона, используя стандарт глобальной системы мобильной связи.
- 11The method according to any of claims 1-8 wherein storing a secret key comprises kotoromsohranyayut 128-bit key as a secret subscriber authentication key in a subscriber identity module, a universal mobile phone using the standard Universal Mobile Telecommunications System. 11. Способ по любому из пп.1-8, в котором сохранение секретного ключа содержит этап, на которомсохраняют 128-битный ключ аутентификации абонента как секретный ключ в универсальном модуле идентификации абонента мобильного телефона, используя стандарт универсальной системы мобильной связи. 11. Способ по любому из пп.1-8, в котором сохранение секретного ключа содержит этап, на которомсохраняют 128-битный ключ аутентификации абонента как секретный ключ в универсальном модуле идентификации абонента мобильного телефона, используя стандарт универсальной системы мобильной связи.
- 13The method according to any one of claims 1-8, wherein the generation of the access key comprises a step of generating a broadcast access key;and wherein dopolnitelnoprinimayut encrypted broadcast content;irasshifrovyvayut broadcast content based on the broadcast access key. 13. Способ по любому из пп.1-8, в котором генерация ключа доступа содержит этап, на котором генерируют ключ доступа радиопередачи;и при этом дополнительнопринимают зашифрованное содержание радиопередачи;ирасшифровывают содержание радиопередачи на основании ключа доступа радиопередачи. 13. Способ по любому из пп.1-8, в котором генерация ключа доступа содержит этап, на котором генерируют ключ доступа радиопередачи;и при этом дополнительнопринимают зашифрованное содержание радиопередачи;ирасшифровывают содержание радиопередачи на основании ключа доступа радиопередачи.
- 15The device initialization key access in a mobile phone soderzhascheesmart card (ICC), configured to securely store the secret key and generate a plurality of encryption keys based on a secret key and a set of random challenges received from the network;iprotsessor connected to ICC and configured to generate an access key based on the plurality of encryption keys. 15. Устройство инициализации ключа доступа в мобильном телефоне, содержащеесмарт-карту (ICC), сконфигурированную с возможностью надежного хранения секретного ключа и генерирования множества ключей шифрования на основании секретного ключа и множества случайных вызовов, принятых из сети;ипроцессор, соединенный с ICC и сконфигурированный с возможностью генерации ключа доступа на основании множества ключей шифрования. 15. Устройство инициализации ключа доступа в мобильном телефоне, содержащеесмарт-карту (ICC), сконфигурированную с возможностью надежного хранения секретного ключа и генерирования множества ключей шифрования на основании секретного ключа и множества случайных вызовов, принятых из сети;ипроцессор, соединенный с ICC и сконфигурированный с возможностью генерации ключа доступа на основании множества ключей шифрования.
- 20An apparatus according to any of claims 15-17, wherein the ICC is a universal subscriber identity module (USIM) of mobile telephones using standard Universal Mobile Telecommunications System. 20. Устройство по любому из пп.15-17, в котором ICC является универсальным модулем идентификации абонента (USIM) мобильного телефона, использующего стандарт универсальной системы мобильной связи. 20. Устройство по любому из пп.15-17, в котором ICC является универсальным модулем идентификации абонента (USIM) мобильного телефона, использующего стандарт универсальной системы мобильной связи.
- 22The apparatus according to any of claims 15-21, wherein the receiver receives an encrypted broadcast content;and wherein the processor generates an access key to decrypt the broadcast content of the broadcast. 22. Устройство по любому из пп.15-21, в котором приемник принимает зашифрованное содержание радиопередачи;и при этом процессор генерирует ключ доступа радиопередачи для расшифровки содержания радиопередачи. 22. Устройство по любому из пп.15-21, в котором приемник принимает зашифрованное содержание радиопередачи;и при этом процессор генерирует ключ доступа радиопередачи для расшифровки содержания радиопередачи.
- 23An apparatus for secure processing device having means for reliable preservation of a secret key comprising:means for generating a plurality of encryption keys based on the plurality of random calls received from the network, and a private key;and means for generating an access key based on the plurality of encryption keys. 23. Устройство для защищенной обработки в устройстве, имеющем средство для надежного сохранения секретного ключа, содержащеесредство для генерации множества ключей шифрования на основании множества случайных вызовов, принятых из сети, и секретного ключа;исредство для генерации ключа доступа на основании множества ключей шифрования. 23. Устройство для защищенной обработки в устройстве, имеющем средство для надежного сохранения секретного ключа, содержащеесредство для генерации множества ключей шифрования на основании множества случайных вызовов, принятых из сети, и секретного ключа;исредство для генерации ключа доступа на основании множества ключей шифрования.
- 26The apparatus according to any one pp.23-24, wherein the means for generating comprises:an access key to associate a plurality of encryption keys. 26. Устройство по любому из пп.23-24, в котором средство для генерации ключа доступа содержитсредство для связывания множества ключей шифрования. 26. Устройство по любому из пп.23-24, в котором средство для генерации ключа доступа содержитсредство для связывания множества ключей шифрования.
- 27An apparatus according to any one pp.23-25, wherein the means for generating comprises:an access key for the hash function on the set of encryption keys. 27. Устройство по любому из пп.23-25, в котором средство для генерации ключа доступа содержитсредство для использования хеш-функции на множестве ключей шифрования. 27. Устройство по любому из пп.23-25, в котором средство для генерации ключа доступа содержитсредство для использования хеш-функции на множестве ключей шифрования.
- 28The apparatus according to any one pp.23-27, wherein the means for generating generates the access key by the broadcast access key; and the apparatus further comprises:receiving encrypted broadcast content;and means for decrypting the broadcast content based on the broadcast access key. 28. Устройство по любому из пп.23-27, в котором средство для генерации ключа доступа генерирует ключ доступа радиопередачи;и при этом устройство дополнительно содержитсредство для приема зашифрованного содержания радиопередачи;исредство для расшифровки содержания радиопередачи на основании ключа доступа радиопередачи. 28. Устройство по любому из пп.23-27, в котором средство для генерации ключа доступа генерирует ключ доступа радиопередачи;и при этом устройство дополнительно содержитсредство для приема зашифрованного содержания радиопередачи;исредство для расшифровки содержания радиопередачи на основании ключа доступа радиопередачи.
- 29A computer readable medium including stored thereon instructions that when executed protsessorompredpisyvayut processor to execute security processing method in a system that securely stores the private key and receives a plurality of random call from the network, said method comprising the steps kotoryhgeneriruyut plurality of encryption keys based on a set of random challenges and the secret key;and generating an access key based on the plurality of encryption keys. 29. Машиночитаемый носитель информации, содержащий сохраненные на нем команды, которые при исполнении процессоромпредписывают процессору выполнять способ защищенной обработки в системе, которая надежно хранит секретный ключ и принимает множество случайных вызовов из сети, причем упомянутый способ содержит этапы, на которыхгенерируют множество ключей шифрования на основании множества случайных вызовов и секретного ключа;игенерируют ключ доступа на основании множества ключей шифрования. 29. Машиночитаемый носитель информации, содержащий сохраненные на нем команды, которые при исполнении процессоромпредписывают процессору выполнять способ защищенной обработки в системе, которая надежно хранит секретный ключ и принимает множество случайных вызовов из сети, причем упомянутый способ содержит этапы, на которыхгенерируют множество ключей шифрования на основании множества случайных вызовов и секретного ключа;игенерируют ключ доступа на основании множества ключей шифрования.
Independent claims14
52 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
The invention relates generally to secure communication systems, and more particularly, to management of access keys to multimedia communication services in the mobile environment.
BACKGROUND
Wireless communication systems are widely deployed to provide various types of communication such as voice, data, and the like. These systems may be based on code division multiple access channels (CDMA), multiple access with time division (TDMA), or other modulation techniques.
The system can be designed to support one or more standards such as «TIA / EIA-95-B Mobile Station-Base Station Compatibility Standard for Dual-Mode Wideband Spread Spectrum Cellular System» (IS-95 standard); communication standard «Global System for Mobile» (GSM), based on the TDMA; Standard «Universal Mobile Telecommunications Service» (UMTS), which is the third generation of wireless services based on the communication standard GSM; Standard communications General Packet Radio System (GPRS), which is an evolutionary step from GSM to UMTS; the standard offered by a consortium named «3rd Generation Partnership Project» (3GPP), which is embodied in a set of documents including Document No. 3G TS 25.211, 3G TS 25.212, 3G TS 25.213 and 3G TS 25.214, 3G TS 25.302 (W-CDMA standard); the standard offered by a consortium named «3rd Generation Partnership Project 2» (3GPP2), which is embodied in a «TR-45.5 Physical Layer Standard for cdma 2000 Spread Spectrum Systems» (IS-2000 standard). Each standard defines the processing of data for wireless communication between the infrastructure element, such as a base station and end-user devices such as mobile device.
Increasing demands for wireless data transmission and the expansion of services available via wireless communication technology, leading to the development of specific data services. In one embodiment, the system can be configured to support the broadcast service (broadcast) media (hereinafter, "broadcast service"). Like the television and / or radio broadcast services, radio can be used for wireless streaming of multimedia content from the content provider to the end user device. Here, the flow of the content can be viewed as the equivalent of a TV channel or radio station. Examples of multimedia content streams include audio and / or video data, movies for example, sporting events, news, and other various programs and / or files. As a rule, the service provider indicates the availability of such services to broadcast to users. Customers wishing to use the service the radio, can receive parameters associated with the service broadcast in the overhead message transmitted infrastructure elements. When a user wants to get some flow of content, the user end device reads the overhead messages and learns the appropriate configurations. Customer target device then tunes to the channel or frequency containing stream content, and receives the broadcast service.
There are several possible models of subscription / revenue for broadcast services, including free access, controlled access, and partially controlled access. For free access by users do not need any subscription for the service. The content on the radio without coding so that the user end devices of interested users can receive and view the contents. Revenue for the service provider can be generated through advertisements that may also be transmitted in the broadcast channel. For example, they can be transferred to the new video clips for which the studios will pay the service provider.
The control user access are required to sign, and they are authorized to provide services to the broadcast, making a charge. This controlled access may be achieved by encrypting the broadcast transmission service or content by cryptographic keys to access so that only the subscribed users can decrypt and view the content. There encoding broadcast content may be based on symmetric or asymmetric cryptosystem. In symmetric cryptosystems the same key is used for encryption / decryption, and asymmetric cryptosystems for encoding / decoding use different keys.
Encryption is well known to those skilled in the art and will not be further described in detail. A hybrid access scheme or partial controlled access provide a broadcast service as a service on a subscription basis, which is encrypted, interspersed with the unencrypted transmission of advertising. These advertisements may be intended to encourage subscriptions to the encrypted broadcast service.
For controlled or partially controlled radio services is a problem in providing a secure access key from the content provider to one or more recipients. Therefore, there exists a need for secure key delivery path access end-user device. For more details, delivery passkey must comply with existing standards and related infrastructure, as well as developing standards and related infrastructure.
SUMMARY OF THE INVENTION
Embodiments disclosed herein relate to the above stated requirements that enable the secure transfer of the key access to the end-user device.
In one embodiment, a method for secure processing device that securely stores the secret key is receiving a plurality of calls from the network, generating a plurality of encryption keys based on a secret key and a set of calls and generating an access key based on the plurality of encryption keys. The method may further comprise the steps of providing a set of challenges and the secret key to generate a plurality of the authentication response, and send at least one authentication response to the network. Generation of the access key may comprise the step of generating a broadcast access key, and wherein the method further comprises the steps of: receiving encrypted broadcast content and decrypt broadcast content based on the broadcast access key. Explanation of content can include the steps of generating temporary key decryption on the basis of each call and the broadcast access key and decrypt the broadcast content using the temporary decryption key.
In another embodiment, an apparatus for secure processing device having means for secure storage of a secret key comprising: means for generating a plurality of encryption keys based on the plurality of calls received from the network, and the private key and means for generating an access key based on the plurality of encryption keys.
In yet another embodiment, a machine-readable medium for use in a device, which securely stores the private key and receives a plurality of calls from the network. The computer readable medium comprises code for generating a plurality of encryption keys based on a variety of challenges and the secret key codes to generate an access key based on the plurality of encryption keys.
In the above embodiments, the 128-bit authentication key of the called party may be maintained as a secret key in a subscriber identity module, a mobile phone using standard Global System for Mobile communications. 128-bit key subscriber authentication can also be saved as a secret key in a universal subscriber identity module with the mobile phone using a standard Universal Mobile Telecommunications System. Furthermore, there may be generated a 64-bit encryption keys, and 128-bit key access radio may be generated by using two encryption keys.
In a further embodiment, an apparatus for use in a mobile phone comprising a smart card (ICC), configured to securely store the secret key and generating a plurality of encryption keys based on a secret key and a plurality of calls received from the network, and a processor coupled with the ICC and configured to generate an access key based on the plurality of encryption keys. ICC can be a subscriber identity module (SIM) mobile phone that uses the Global System for Mobile communications. SIM can store a 128-bit key as a subscriber authentication and secret key to generate a 64-bit encryption keys. ICC can also be a universal subscriber identity module (USIM) mobile phone, using a standard Universal Mobile Telecommunications System. USIM may store a 128-bit key as a subscriber authentication and secret key to generate a 64-bit encryption keys in a mode that is backward compatible from SIM. The processor can generate a 128-bit key access broadcast using two encryption keys.
BRIEF DESCRIPTION OF THE DRAWINGS
Various embodiments will be described in detail with reference to the following drawings in which like reference numerals refer to similar elements and in which:
Figure 1 is an example of a wireless communication network, adapted to support the broadcast services;
Figure 2 shows a simplified network for MBMS;
3 shows a terminal configured to subscribe to the MBMS to receive multimedia content;
4 is a simplified example of a GSM system;
Figure 5 is an example of a network which performs authentication and a terminal for broadcast services, and
Figure 6 shows a method for secure processing device that securely stores the secret key.
DETAILED DESCRIPTION
In the following description specific details are given to provide a thorough understanding of the embodiments. However, one skilled in the art will recognize that embodiments may be practiced without these specific details. For example, circuits may be shown in block diagrams in order not to obscure the embodiments in unnecessary detail. In other implementations can show details well-known circuits, structures and techniques that do not obscure the embodiments.
Note also that the embodiments may be described as a process which is depicted as a flowchart diagram flowchart or block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of operations can be rebuilt. The process is completed when its operations are completed. A process may correspond to a method, functions, procedures, routines, programs, etc. When a process corresponds to a function, its termination corresponds to a return of the function to the request or the main function.
Moreover, as disclosed herein, a storage medium may represent one or more devices for storing data, including read only memory (ROM), random access memory (RAM), storage media, a magnetic disk media on the optical disk, flash memory devices and / or other machine-readable media to store the information. The term "computer readable medium" includes, but is not limited to, portable or fixed storage devices, optical storage devices, wireless channels and various other media capable of storing, containing or carrying instruction (s) and / or data.
1 shows an example wireless communication network 100 capable of supporting broadcast services. Network 100 may comprise one or more communication systems that support different standards. More particularly, network 100 includes a plurality of service areas 102A-102G, each of which serves a respective infrastructure element 104A-104G, respectively. Infrastructure elements 104A-104G communicate with the user end devices (hereinafter "terminal») 106A-106J, are within service areas 102A-102G are infrastructure elements 104A-104G, respectively. Depending on the type of communications system infrastructure elements 104A-104G may include base stations, base transceiver stations, gateways, or other devices that communicate with terminals 106A-106J. The terminals 106A-106J may be, but are not limited to, mobile (including cellular and personal communications service) phones, wired phone, a wireless handset, a personal assistant (PDA), a variety of computer devices (including portable and desktop computers) or other data transceiver . As shown in Figure 1, the terminals 106A-106J may be hand-held, mobile, portable, installed in the vehicle (including cars, trucks, boats, trains and planes) or fixed.
In one embodiment, network 100 supports the broadcast service (broadcast), called services broadcast / multicast media (MBMS), or sometimes called service broadcast / multimedia (BCMCS). MBMS is a general packet service based on the Internet Protocol (IP). The service provider may indicate the availability of a MBMS users. Customers who wish to receive MBMS, can get service and explore the graph of services broadcast via the radio-type advertisements, Short Message System (SMS) and interactive communication protocol mobile Internet (WAP). Infrastructure elements transmit MBMS-related parameters in overhead messages. When a user wants to receive the broadcast session, the terminal 106 reads the overhead messages and learns the appropriate configurations. The terminal 106 then tunes to the frequency containing the MBMS channel, and receives the broadcast service content.
2 shows a simplified network 200 for implementing MBMS. In the network 200 the video and / or audio information is provided to the network packet data service (PDSN) 230 via content source 210 (CS). Video and audio information may be from televised programs or radio transmissions. The information is provided as packet data, such as in IP packets. PDSN 220 processes the IP packets for distribution within an access network (AN). As illustrated, AN is defined as part of the network 200, including 240 infrastructure element in communication with a plurality of terminals (mobile stations (MS)) 250.
For MBMS CS 210 provides unencrypted content. Infrastructure element 240 receives a stream of information from PDSN 230 and provides information for the determined channel to subscriber terminals within network 200. To control access, the content from CS 210 is encrypted content encryption circuit (not shown here) using an encryption key before transmission to the PDSN 220. While the content of the encryption scheme may be implemented together or separately from CS 210, content encryption scheme and CS 210 are hereinafter referred to as a content provider. Subscribed users are provided with the decryption key, so that the IP packets can be decrypted.
In more detail, Figure 3 shows the terminal 300 configured to subscribe to the MBMS, to receive multimedia content. The terminal 300 includes an antenna 310 coupled to receive circuitry 320. Terminal 300 receives transmissions from a content provider (not shown here) through an infrastructure element (not shown here). The terminal 300 includes a mobile equipment (ME, ME) 340 and a universal smartcard 330 (UICC), coupled to receive circuitry 320. Note that in some terminals UICC 330 and ME 340 may be implemented together in one secure processing unit . Also, although the embodiment will be described using UICC, other integrated circuits, and / or secure processor modules, such as user identity module (UIM), a subscriber identity module (SIM) or Universal SIM, may be implemented in the terminal.
Generally UICC 330 uses the verification procedure to protect the MBMS transmission and provides various keys to ME 340. ME 340 The compensation nyaet substantial processing, including, but not limited to, streams decoding MBMS content, using clues provided by the UICC 330. UICC 330 is trusted and reliable storage treatment of classified information (eg encryption keys) that must remain secret for a long time. Since the UICC 330 is a secure unit, the secrets stored therein do not necessarily require frequent change of classified information. UICC 330 may include a processing unit referred to as the secure UICC processing unit 332 (SUPU) and secure the memory module, referred to as the secure UICC 334 memory module (SUMU). Within UICC 330 SUMU 334 saves, to a certain extent, secret information, which prevents unauthorized access to information. If the classified information received from the UICC 330, the access will require significantly more resources. Also within the UICC 330 SUPU 332 performs calculations on the values which may be external and / or internal to the UICC 330. The results of calculations can be stored in SUMU 334 or transferred to the ME 340.
In one embodiment, the UICC 330 is a constant modulus or integrated in the terminal 300. Note that the UICC 330 may also include non-secure memory and processing (not shown here) for storing information including telephone numbers, e-mail address information, web page or address information URL, and / or function of the schedule, etc. Alternate embodiments may provide a removable and / or reprogrammable UICC. Typically, SUPU 332 does not have sufficient processing power for functions beyond security procedures and key so as to provide the ability to encode broadcast MBMS content. However, alternative embodiments may implement UICC, having a greater processing power.
Since the UICC 330 is a secure unit, data in ME 340 may not contact the subscriber and it shows insecurity. Any information passed to ME 340 or processed ME 340 remains securely secret for only a short time. It is therefore desirable that any sensitive information, such as key (s), shared with ME 340, was often changed.
For more information, MBMS content is encrypted using a unique and frequently changing temporary encryption keys, called the short-term key (SK). To decrypt the broadcast content at a particular time, ME 340 must know the current SK. SK is used to decrypt the broadcast content for a short time such that SK can be expected to have a number of internal monetary values to the user. For example, this internal monetary value may be part of the costs of registration. There are different types of content can have different internal monetary value. Assuming that cost is not the subscriber receiving the SK from ME 340 subscriber exceeds domestic monetary value SK, the cost of obtaining SK illegitimately exceeds the reward and has no benefits. Consequently, there is no need to protect SK in ME 340. However, if the broadcast has built a value greater than the value of the illegal receipt of the secret key without the subscriber has the benefit in obtaining such a key from ME 340. Hence, ME 340 ideally will not store secrets on Throughout life longer than the duration of the SK.
In addition, the channels used by the content provider (not shown here) for data transmission are unprotected. Therefore SK is not transmitted over the air. It is produced by the UICC or 330 or ME 340 from an access key called a broadcast access key (BAK) and information SK (SKI), transmitted by radio, along with the encrypted content. BAK can be used for some time, eg one day, one week or a month, and modified. Within each period for updating the BAK is provided a shorter interval during which SK is changed. The content provider may use a cryptographic function to determine two values SK and SKI such that SK can be determined from BAK and SKI. In one embodiment, SKI may contain SK, which is encrypted using BAK as the key. Alternatively, SK may be the result of applying a cryptographic hash function to the concatenation of SKI and BAK. Here, SKI may be some random value.
To gain access to the MBMS, a user registers and subscribes to the service. In one embodiment, the process of registering the content provider 330 and the UICC agree registration key or the root key (RK), which serves as a security association between the user and the content provider. Registration can occur when a user has subscribed to a channel radio, the proposed content provider or may occur prior to subscription. The only content provider to offer multiple channels broadcast. The content provider can select the association members with the same RK for all channels, or require users to be recorded for each channel and to associate the same user with different RK on different channels. Multiple content providers may choose to use the same registration keys or require users to register and received a variety of RK.
If possible, RK then saved as a secret information UICC 330. RK is unique to a given UICC, i.e. each user is assigned a different RK. However, if the user has many UICC, the UICC can then be configured to share the same RK depending on the policy of a content provider. The content provider can then send the UICC 330 further secret information, such as BAK, encrypted with RK. UICC 330 is able to recover the value of the original BAK from the encrypted BAK, using the RK. Since the ME 340 is not a secret unit, UICC 330 does not provide BAK to ME 340.
The content provider also broadcasts SKI radio, which is combined with the BAK in the UICC 330 to get SK. UICC 330 then passes SK to ME 340 and ME 340 uses the SK to decrypt the encrypted radio transmission received from the content provider. In this way, the content provider can efficiently distribute new values of SK to subscribed users.
As described, controlled access may be achieved by initializing the coherent RK in SUMU 334 of the UICC 330. However, in some systems, existing infrastructure appropriate value RK can be stored in a protected module such UICC 330 due to cost and / or inconvenience of replacing existing UICC, SIM, UIM cards or other integrated circuits.
For example, in GSM systems, a Subscriber Identity Module (SIM) is a secure module and includes identification information about the user of the called party, which can be used to gain access to the network. For purposes of explanation, Figure 4 shows a simplified example of the GSM system 400 to authenticate the subscriber to enable access to the network. The system 400 comprises a home location register 410 (home location register) (HLR), the visitor location register 420 (guest register) (VLR) and the terminal, such as mobile device 430. Note that the system 400 comprises additional elements, but the GSM system are known to those skilled in the art and will not be described in detail.
HLR 410 is a database for the mobile subscriber system. HLR 410 is supported by the home carrier frequency terminal and contains important user information for billing and network authentication. VLR 420 is also a database, and includes a temporary user information, such as current location of the terminal by managing requests from subscribers who are out of the area covered by their home system. When the user initiates a call and the user terminal is in its home area, VLR 420 communicates with the HLR 410 to obtain the information required for processing the request, including the information required to authenticate the subscriber.
Terminal 430 includes a module 432 SIM, which securely contains a subscriber authentication key (K), is used to authenticate the subscriber. Here, the authentication protocol to establish a call connection, known as authenticates the key agreement (AKA), typically used to authenticate GSM. The AKA, the network sends the call message to the subscriber station, which corresponds to the value obtained using one-way hash function. Here the challenge message may be a random value. The network checks the response by comparing it with its own expected hash value. If the values match, the authentication is acknowledged. When generating this response is also generated key that can be used for subsequent communication.
In more detail, the system requires a GSM VLR 420 requests authentication parameters from HLR 410. HLR 410 sends the VLR 128-bit random number RAND, a signed response (RES) and an encryption key (Kc). RES and Kc are generated from the subscriber authentication key K and RAND by using different algorithms. Using this authentication triplet (RAND, RES, Kc), a call message is issued by sending a random number RAND to the terminal 430. The resultant RAND transmitted SIM 432 that generates RES and Kc using RAND and RES K. generated returns to the VLR 420, which It verifies that the two values coincide RES. If they match, the user is authenticated and the terminal and the network are beginning to encrypt / decrypt using Kc.
Since GSM SIM reliably contains subscriber authentication key (K), used to authenticate a subscriber, it does not permit initialization of additional key type RK. Namely, the existing GSM SIM can not be changed. Therefore, one way to deliver broadcast services to BAK may be composed to use the Kc, instead of RK to encrypt BAK. The content provider has to send a message containing RAND and BAK, encrypted with Kc. The terminal receives the message and transmits the RAND SIM, as though it would have been the normal GSM authentication. Accordingly, RES and Kc generated by the SIM, using RAND and RES K. Here, the generated SIM, can be rejected. It protects against the attacker who could send the same RAND and RES record returned to unauthorized access. Kc can be used to decrypt the encrypted BAK.
However Kc is generally 64-bit key, whereas some broadcast services, for example MBMS, designed to protect the 128 bits. It is therefore necessary to use a key longer than 64 bits to encrypt BAK. As a result, BAK used for encoding a plurality of triplets.
5 shows an example of a system 500 with a network 510, which performs authentication and a terminal 520 for broadcast services. Network 510 includes one or more content providers, and other elements of the infrastructure required for broadcast services. Terminal 520 includes ICC 522 coupled to the processor 524. In GSM network 510 may include a VLR and HLR, and ICC 522 should be a module SIM, as described in Figure 4. Generally, the network 510 sends a call message to perform authentication. Call message using a terminal 520 to generate BAK for controlled access. Namely, ICC 522 of the terminal 510 securely stores the secret key used to generate BAK. Operation of the system 500 will be explained with reference to Figure 6 below.
6 shows a method 600 for secure processing device such as terminal 620, which securely stores the secret key, such as a subscriber authentication key in the secure module such as ICC 622. The process unit 600 receives a plurality of calls from the network (610). Calls may be set in a single message or multiple messages. The set of encryption keys is generated based on a secret key and a set of calls (620). Access Key then generated based on the plurality of encryption keys (630). The system 500, for example, ICC 522 is configured to generate encryption keys, because the secret key must remain within the ICC 522. The processor 524 is configured to generate an access key based on the encryption key.
The access key is generated using a plurality of encryption keys, as an access key is typically longer than the encryption key. For example, in GSM for MBMS encryption key is a 64-bit, while the access key is 128 bits. In this case, the passkey may be generated by using two encryption keys. Any known method may be used to generate the access key of the plurality of encryption keys. In one embodiment, an access key is generated by associating a plurality of encryption keys. In an alternative embodiment, an access key is generated using a hash function on the set of encryption keys. A hash function can include SHA-1 for mixing a plurality of encryption keys.
For authentication, the method 600 may further comprise providing a plurality of call message and the secret key to generate a plurality of authentication responses, as described with reference to Figure 4. After at least one of the authentication response is returned to the network using a transmitter (not shown here), carried out in the terminal 520, and any authentication responses are not sent to the network, it may be rejected.
Therefore, after the access key generation method 600 may further comprise obtaining the encrypted content, and decrypt the broadcast content based on the broadcast access key. For example, in the MBMS access key BAK would, and for generating a SK to be used SKI. In this case, the method 600 may further comprise generating temporary key encryption / decryption SK type based on each call message flow and BAK. SK stream can then be used to decrypt and view / treat the encrypted content.
Accordingly, the described embodiments allow the secure initialization of an access key to the broadcast service. It should be noted that although the embodiments have been described with reference to the MBMS, the possibility of the invention relate to other broadcast services, other than MBMS, and various systems that require controlled access. Similarly, an access key may be shorter or longer than 128 bits. Furthermore, embodiments may relate to other systems besides GSM system. For example, the UMTS have USIM, which is like a SIM GSM and has a backward compatibility mode, which allows it to act as a SIM GSM.
Furthermore, embodiments may be implemented in hardware, software, firmware, middleware, firmware, or any combination thereof. When implemented in software, firmware, middleware or microcode, or program code portion of the code to perform the necessary tasks may be stored on a computer readable medium (not shown here). A processor may perform the necessary tasks. Some code may represent a procedure, a function, a subprogram, a program, a routine, program, module, a software package, a class, or any combination of instructions, data structures, or program instructions. Section can be connected to another piece of code or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or sent via any suitable means including memory sharing, message passing, token passing, network transmission, etc. Also, the computer readable medium may be implemented in an article of manufacture for use in a computer system and can embody computer-readable code means.
Finally, it should be noted that the foregoing embodiments are merely examples and should not be construed as limiting the invention. Description of the embodiments is intended to be illustrative, and not to limit the possibility of the appended claims. Also existing doctrine can be readily applied to other types of apparatuses and many alternatives, modifications and variations that will be apparent to those skilled in the art.
Contents5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| MD4511C1 | Cited by | Republic of Moldova | Search report |
| WO9715161A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| RU2169437C1 | Cites | Russian Federation | – |
| EP0675615A1 | Cites | European Patent Office (EPO) | – |
| EP1075123A1 | Cites | European Patent Office (EPO) | – |
21 members in 13 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 48579103 | United States of America | P | |
| 48579103 | United States of America | P | |
| 60485791 | United States of America | – | |
| 10870303 | United States of America | – | |
| 87030304 | United States of America | A | |
| 87030304 | United States of America | A | |
| 10870303 | – | – | – |
| 60485791 | – | – | – |
| US20030485791P | – | – | – |
| US20040870303 | – | – | – |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| US2005010774A1 | United States of America | A1 | |
| AU2004258561A1 | Australia | A1 | |
| CA2531590A1 | Canada | A1 | |
| WO2005008398A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2005008398A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200518543A | Taiwan Province of China | A | |
| MXPA06000274A | Mexico | A | |
| KR20060031852A | Republic of Korea | A | |
| EP1649630A2 | European Patent Office (EPO) | A2 | |
| IL173021A0 | Israel | A0 | |
| BRPI0412397A | Brazil | A | |
| CN1846395A | China | A | |
| RU2006103624A | Russian Federation | A | |
| JP2007529147A | Japan | A | |
| AU2004258561B2 | Australia | B2 | |
| AU2004258561C1 | Australia | C1 | |
| EP1649630A4 | European Patent Office (EPO) | A4 | |
| RU2419223C2This record | Russian Federation | C2 | |
| TWI386004B | Taiwan Province of China | B | |
| CA2531590C | Canada | C | |
| US8718279B2 | United States of America | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A |
Numbers
- Publication
- 2419223
- Publication, DOCDB
- 2419223
- Publication, EPODOC
- RU2419223
- Application
- 200610362409
- Application, DOCDB
- 2006103624
- Application, EPODOC
- RU20060103624
Titles3
- English
- DEVICE AND METHOD FOR SECURED RADIO TRANSMISSION SYSTEM
- Russian
- УСТРОЙСТВО И СПОСОБ ДЛЯ ЗАЩИЩЕННОЙ СИСТЕМЫ РАДИОПЕРЕДАЧИ
- Russian
- ?????????? ? ?????? ??? ?????????? ??????? ?????????????
Classification
- CPC, 14
- H04W12/08
- H04L9/0844
- H04L63/0428
- H04L63/06
- H04L9/14
- H04L2463/101
- H04W84/12
- H04L2209/601
- H04L2209/80
- H04W12/04031
- H04W12/0431
- H04L9/0643
- H04L9/0877
- H04L9/0894
- IPC, 4
- H04L9 00
- H04L9 08
- H04L12 28
- H04L29 06