Systems and methods for distributing key updates with maximum key change intensity
Abstract
FIELD: information technology. SUBSTANCE: number of key changes required for maintaining secure connections is minimised by multiplying the number of received update requests by the maximum update period in order to estimate the number of active nodes in a group, determining the total number of update requests received per unit time, determining additional update requests per unit time as the difference between the total number of the received update requests and the determined maximum number of requests expected per unit time, and determining the minimum update period for the group of nodes, which enables to prevent extra load on the communication line in the network. EFFECT: high efficiency of using a communication network. 13 cl, 7 dwg
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
13 claims: 3 independent, 10 dependent
- 1A method for distributing updates for a key, wherein the method is performed server, the method comprising the steps of:receiving at the server, one or more update requests per unit of time from the group of active nodes on the server multiplies the number of received update requests per unit of time a maximum update period to derive a number of active nodes in the group, determining a server total number of received update requests per unit of time is prepared on the server amount representing additional update requests per unit of time by subtracting the determined total number of received update requests per unit time from a certain maximum number of update requests expected per unit of time is determined on the server the minimum update period, which is the time it takes the server to change the keys of the entire group of active nodes using a maximum load by multiplying the number of received requests refresh per unit time by the maximum update parameter and dividing this product by the amount representing additional update requests per unit of time;iotpravlyayut server a certain minimum period of updating the active node. 1. Способ распределения обновлений для ключа, при этом способ осуществляется сервером, причем способ содержит этапы, на которых:принимают на сервере один или более запросов на обновление за единицу времени от группы активных узлов;умножают на сервере количество принятых запросов на обновление за единицу времени на максимальный период обновления для получения оценки количества активных узлов в группе;определяют на сервере общее количество принимаемых запросов на обновление за единицу времени;получают на сервере величину, отображающую дополнительные запросы на обновление за единицу времени, путем вычитания определенного общего количества принимаемых запросов на обновление за единицу времени из определенного максимального количества запросов на обновление, ожидаемых за единицу времени;определяют на сервере минимальный период обновления, который представляет собой время, необходимое серверу для того, чтобы сменить ключи всей группы активных узлов, используя максимальную нагрузку, путем умножения количества принятых запросов на обновление за единицу времени на максимальный параметр обновления, и деления этого произведения на величину, отображающую дополнительные запросы на обновление за единицу времени;иотправляют на сервере определенный минимальный период обновления активному узлу. 1. Способ распределения обновлений для ключа, при этом способ осуществляется сервером, причем способ содержит этапы, на которых:принимают на сервере один или более запросов на обновление за единицу времени от группы активных узлов;умножают на сервере количество принятых запросов на обновление за единицу времени на максимальный период обновления для получения оценки количества активных узлов в группе;определяют на сервере общее количество принимаемых запросов на обновление за единицу времени;получают на сервере величину, отображающую дополнительные запросы на обновление за единицу времени, путем вычитания определенного общего количества принимаемых запросов на обновление за единицу времени из определенного максимального количества запросов на обновление, ожидаемых за единицу времени;определяют на сервере минимальный период обновления, который представляет собой время, необходимое серверу для того, чтобы сменить ключи всей группы активных узлов, используя максимальную нагрузку, путем умножения количества принятых запросов на обновление за единицу времени на максимальный параметр обновления, и деления этого произведения на величину, отображающую дополнительные запросы на обновление за единицу времени;иотправляют на сервере определенный минимальный период обновления активному узлу.
- 8A server that is configured to distribute updates for a key, wherein the server comprises:a processor, memory in electronic communication with the processor, instructions stored in the memory, the instructions executed to: receive via the processor, one or more requests updated per unit time from a group of active nodes;multiply by the processor number of received update requests per unit time to a maximum update period to derive a number of active nodes in the group, identify by processor total number of received update requests per unit of time is obtained with the a processor amount representing additional update requests per unit of time by subtracting the determined total number of received update requests per unit of time from a determined maximum number of update requests expected per unit time, determined by means of the processor the minimum update period, which is the time it takes the server to change the keys of the entire group of active nodes using a maximum load by multiplying the number of received update requests per unit time to a maximum update parameter and dividing this product by the amount representing additional update requests per unit of time;iotpravlyat by the processor a certain minimum period of updating the active node. 8. Сервер, который выполнен с возможностью распределения обновлений для ключа, при этом сервер содержит:процессор;запоминающее устройство в электронной связи с процессором;инструкции, хранящиеся в запоминающем устройстве, причем инструкции выполняются, чтобы:принимать с помощью процессора один или более запросов на обновление за единицу времени от группы активных узлов;умножать с помощью процессора количество принятых запросов на обновление за единицу времени на максимальный период обновления для получения оценки количества активных узлов в группе;определять с помощью процессора общее количество принимаемых запросов на обновление за единицу времени;получать с помощью процессора величину, отображающую дополнительные запросы на обновление за единицу времени, путем вычитания определенного общего количества принимаемых запросов на обновление за единицу времени из определенного максимального количества запросов на обновление, ожидаемых за единицу времени;определять с помощью процессора минимальный период обновления, который представляет собой время, необходимое серверу для того, чтобы сменить ключи всей группы активных узлов, используя максимальную нагрузку, путем умножения количества принятых запросов на обновление за единицу времени на максимальный параметр обновления, и деления этого произведения на величину, отображающую дополнительные запросы на обновление за единицу времени;иотправлять с помощью процессора определенный минимальный период обновления активному узлу. 8. Сервер, который выполнен с возможностью распределения обновлений для ключа, при этом сервер содержит:процессор;запоминающее устройство в электронной связи с процессором;инструкции, хранящиеся в запоминающем устройстве, причем инструкции выполняются, чтобы:принимать с помощью процессора один или более запросов на обновление за единицу времени от группы активных узлов;умножать с помощью процессора количество принятых запросов на обновление за единицу времени на максимальный период обновления для получения оценки количества активных узлов в группе;определять с помощью процессора общее количество принимаемых запросов на обновление за единицу времени;получать с помощью процессора величину, отображающую дополнительные запросы на обновление за единицу времени, путем вычитания определенного общего количества принимаемых запросов на обновление за единицу времени из определенного максимального количества запросов на обновление, ожидаемых за единицу времени;определять с помощью процессора минимальный период обновления, который представляет собой время, необходимое серверу для того, чтобы сменить ключи всей группы активных узлов, используя максимальную нагрузку, путем умножения количества принятых запросов на обновление за единицу времени на максимальный параметр обновления, и деления этого произведения на величину, отображающую дополнительные запросы на обновление за единицу времени;иотправлять с помощью процессора определенный минимальный период обновления активному узлу.
- 11The computer-readable medium comprising executable instructions server for distributing updates for a key during a minimum update period, the instructions when performing server prompt said server:receive one or more update requests per unit of time from a group of active nodes;multiply the number of received update requests per unit time to a maximum update period to derive a number of active nodes in the group, identify the total number of received update requests per unit of time to obtain an amount representing additional update requests per unit of time by subtracting the determined total number of received update requests per unit time from a determined maximum number of update requests expected per unit of time to determine a minimum update period, which is the time it takes the server to change the keys of the entire group of active nodes using a maximum load by multiplying the number of received update requests per unit time to maximum update parameter and dividing this product by the amount representing additional update requests per unit of time;iotpravlyat a certain minimum period of updating the active node. 11. Машиночитаемый носитель, содержащий выполняемые сервером инструкции для распределения обновлений для ключа в течение минимального периода обновления, причем инструкции при выполнении сервером побуждают упомянутый сервер:принимать один или более запросов на обновление за единицу времени от группы активных узлов;умножать количество принятых запросов на обновление за единицу времени на максимальный период обновления для получения оценки количества активных узлов в группе;определять общее количество принимаемых запросов на обновление за единицу времени;получать величину, отображающую дополнительные запросы на обновление за единицу времени, путем вычитания определенного общего количества принимаемых запросов на обновление за единицу времени из определенного максимального количества запросов на обновление, ожидаемых за единицу времени;определять минимальный период обновления, который представляет собой время, необходимое серверу для того, чтобы сменить ключи всей группы активных узлов, используя максимальную нагрузку, путем умножения количества принятых запросов на обновление за единицу времени на максимальный параметр обновления, и деления этого произведения на величину, отображающую дополнительные запросы на обновление за единицу времени;иотправлять определенный минимальный период обновления активному узлу. 11. Машиночитаемый носитель, содержащий выполняемые сервером инструкции для распределения обновлений для ключа в течение минимального периода обновления, причем инструкции при выполнении сервером побуждают упомянутый сервер:принимать один или более запросов на обновление за единицу времени от группы активных узлов;умножать количество принятых запросов на обновление за единицу времени на максимальный период обновления для получения оценки количества активных узлов в группе;определять общее количество принимаемых запросов на обновление за единицу времени;получать величину, отображающую дополнительные запросы на обновление за единицу времени, путем вычитания определенного общего количества принимаемых запросов на обновление за единицу времени из определенного максимального количества запросов на обновление, ожидаемых за единицу времени;определять минимальный период обновления, который представляет собой время, необходимое серверу для того, чтобы сменить ключи всей группы активных узлов, используя максимальную нагрузку, путем умножения количества принятых запросов на обновление за единицу времени на максимальный параметр обновления, и деления этого произведения на величину, отображающую дополнительные запросы на обновление за единицу времени;иотправлять определенный минимальный период обновления активному узлу.
Independent claims3
59 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
The present invention relates generally to computers and computer technology. More particularly, the present invention relates to systems and methods for distributing updates for a key with a maximum intensity change of key.
BACKGROUND
Computer and communication technologies continue to evolve rapidly. Indeed, computer and communication technologies are involved in many aspects of everyday life. For example, many devices being used today by consumers have a small computer inside. These small computers come in different sizes and levels of complexity. These small computers include everything possible from one microcontroller to a fully functional complete computer system. For example, these small computers may be a one-chip computer, such as a microcontroller, a computer on a single circuit board, such as a controller, a typical desktop computer, such as an IBM-PC compatible, etc.
Computers typically have one or more processors at the heart of the computer. The processor (s) usually are interconnected (s) with various external input and output devices and perform (s) the function of controlling a specific computer or device. For example, a processor in a thermostat may be connected to buttons used to select the temperature, the furnace or air conditioning device to change the temperature, and to temperature sensors to read and display the current temperature on a display.
Many appliances, devices, etc. They include one or more small computers. For example, thermostats, furnaces, air conditioning systems, refrigeration devices, telephones, printers, automobiles, vending machines, and most different types of industrial equipment now typically have small computers inside or processors. Computer software runs the processors of these computers and indicates the processors how to carry out certain tasks. For example, the computer software running on a thermostat may cause the device to stop the air conditioning operation when it reaches a specific temperature, or can cause the heating device switched if necessary.
These types of small computers that are a part of the device, device, tool, etc., are often referred to as embedded devices or embedded systems. (The terms "embedded device" and "embedded system" will be used interchangeably herein). The embedded system usually refers to computer hardware and software that is part of a larger system. Embedded systems may not have typical input and output devices such as a keyboard, a mouse pointing device and / or display device. Usually, at the heart of each embedded system has one or more processors.
Embedded systems may be used to monitor or control many different systems, resources, outcomes, etc. With the proliferation of the Internet and the World Wide embedded systems are increasingly connected to the Internet so that they can be remotely monitored and / or controlled. Other embedded systems may be connected to computer networks include local area networks, wide area networks, etc. As used herein, the term "computer network" (or simply "network") refers to any system in which a series of nodes connected through a communication channel. The term "node" refers to any device that can be connected as part of a computer network.
Some embedded systems may provide data and / or services to other computing devices using a computer network. Alternatively, it may be conventional computers or computing devices that provide data and / or services to other computing devices using a computer network. Sometimes it is useful to minimize the number of key exchanges necessary to maintain secure communications. Using a large number of key exchanges can cause additional stress on the link in the network. These situations, as well as others, may cause inefficiencies interaction over a network. Benefits may be realized if available to systems and methods for efficiently distributing updates for a key.
DISCLOSURE OF INVENTION
Discloses a method for distributing updates for a key. Receive one or more update requests per unit of time. Number of per unit time update requests is multiplied by a maximum update period. Specifies the total number per unit time received update requests. It turns out the value of showing additional update requests per unit of time. It specifies the minimum update period for the group of nodes.
In one embodiment, a value representing additional update requests per unit of time is obtained by subtracting the determined total number of received update requests per unit of time from a determined maximum number of update requests per unit of time expected. The minimum update period may be determined by multiplying the number of received update requests per unit time to a maximum update parameter and dividing this product by the amount representing additional update requests per unit of time. During each minimum check period can be received update request from a single node. In one embodiment, the update request comprises a request for changing a key exchange key (KEK). KEK may be used to attach to secure multicast group of nodes.
Minimum characteristics can be maintained with respect to a group of nodes, the nodes contain the minimum characteristics that may KEK and join the group. The maximum renewal period may be a maximum time within which the host uses KEK before sending the update request. Multiplying the number of received update requests per unit time to a maximum update period may provide an estimate of the number of active nodes in a group. Update requests may be normally distributed evenly through time.
Also describes a computer system that is configured to distribute updates for a key. The computer system includes a processor and a memory coupled to the electronic communication with the processor. Instructions are stored in the memory. Receive one or more update requests per unit of time. The number of received update requests per unit of time is multiplied by a maximum update period. Specifies the total number per unit time received update requests. It turns out the value of showing additional update requests per unit of time. It specifies the minimum update period for the group of nodes.
Also disclosed is a computer-readable medium comprising executable instructions for distributing updates for a key during a minimum update period. Receive one or more update requests per unit of time. The number of received update requests per unit of time is multiplied by a maximum update period. Specifies the total number per unit time received update requests. It turns out the value of showing additional update requests per unit of time. It specifies the minimum update period for the group of nodes.
BRIEF DESCRIPTION OF THE DRAWINGS
Exemplary embodiments of the present invention will be fully understood from the following description and appended claims when taken in conjunction with the accompanying drawings. With the understanding that these drawings depict only illustrative embodiments of the present embodiment and therefore should not be construed as limiting the scope of the present invention, exemplary embodiments of the present invention will be described with additional specificity and detail through use of the accompanying drawings, in which:
1 is a block diagram illustrating one embodiment of a server, informing the key exchange key (KEK) to one or more nodes within a group;
2 is a block diagram illustrating a further embodiment of the server that interacts with a group of nodes on the network;
3 is a block diagram illustrating one embodiment of a single node, sends a request to update the server by using a minimum period of inquiry, to check for changes to the KEK;
4 is a flowchart of a method illustrating one embodiment of a method for determining a minimum update period for a group of nodes;
5 is a flowchart of a method illustrating one embodiment of a method for determining whether a node may join a group of nodes;
6 is a flowchart of a method illustrating one embodiment of a method for alerting of additional nodes in a group about changes to a KEK; and
7 is a block diagram of hardware components that may be used in the integrated apparatus according to the embodiment.
THE INVENTION
Next will be described various embodiments of the present invention with reference to the drawings, wherein like reference numerals refer to identical or functionally similar elements. Embodiments of the present invention, as generally described and shown in the figures herein, could be arranged and designed in a wide variety of different configurations. Therefore, the following more detailed description of several exemplary embodiments of the present invention are reflected in the drawings are not intended to limit the scope of the claimed invention, but simply reflects the embodiments of the present invention.
The word "exemplary" is used exclusively herein to mean "serving as an example, instance, or illustration." Any embodiment described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments.
Many features of the embodiments disclosed herein may be implemented in software, electronic hardware, or combinations thereof. To clearly illustrate this interchangeability of hardware and software, various components will be described generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present invention.
In the case where the described functionality is implemented as computer software, such software may include any type of computer instruction or computer executable code located in the memory and / or transmitted as electronic signals over a system bus or network. Software that implements the functionality that is correlated with the components described herein may comprise a single instruction, or many instructions, and may be distributed over several different code segments, among different programs and across multiple storage devices.
As used herein, the terms "any embodiment", "an embodiment", "an embodiment", "this embodiment", "this embodiment", "one or more embodiments," "some embodiments", " certain embodiments, "" one embodiment "," another embodiment "and the like mean" one or more (but not necessarily all) embodiments of the disclosed invention (s) ", unless expressly specified otherwise.
The term "determining" (and its grammatical forms) is used in the broadest sense. The term "determining" encompasses a wide variety of actions and, therefore, "determining" may include calculating, computing with the computer processing, deriving, investigating, looking up (e.g., lookup table, a database or another data structure), ascertaining and the like. Also, "determining" may include receiving (e.g., receiving information), accessing an organization (e.g., accessing data in a memory) and the like. Also, "determining" may include a decision, selecting, choosing, justification, and the like.
The phrase "based on" does not mean "based only on," unless expressly specified otherwise. In other words, the phrase "based on" describes both "based only on" and "based at least on."
As for the organization of the security of multicast groups used a centralized server, such as an authentication server, each member of the group (or node) may periodically check that the key is distributed by the server has not changed. The key may enable the node to join the multicast group and receive a group key. The key may be referred to as a key exchange key (KEK). Each group can be a particular KEK. Periodic validation of KEK could cause differences between the timely updating (ie use frequent checks) and network congestion (ie less use of checks). In one embodiment, the server less frequent checks are sent until change the allocation of the KEK. When there is a change to the KEK, seek to change the key server for each active node belonging to the group as soon as possible.
In one embodiment, an authentication server maintains minimal characteristics (states) relative to multicast groups. For example, the server can support the nodes that can be identified as members of the group, and the server can support KEK. KEK may be used by nodes for connection to the active group. Maintaining the minimum characteristics allows the system to be protected from failure of the authentication server or failover authentication server, which can be characteristic of the authentication server with limited access or no joint without it.
Nodes within a group may not trust each other regarding KEK. In one embodiment, the node that has been corrupted may mislead the remaining nodes within the group about the KEK. The authentication server may be trusted to distribute or confirmation KEK, which may place a heavy load on the authentication server. However, the authentication server may not possess an exact count of the number of active nodes in a group at any time. Ignorance of the number of active nodes in the group increases the difficulty for the authentication server in deciding how to best distribute the update requests to check for updates KEK, if it needs to access them in a group to send the requests as soon as possible. For example, a group with ten active nodes may change keys with changes to the KEK in a few seconds. However, a group with 10,000 active nodes can not change the keys so quickly. If all 10,000 nodes in the group sent a request to the authentication server, which is to change the key for a few seconds, the server or the network may not be able to handle large information load.
1 is a block diagram illustrating one embodiment of a server 102 informing key exchange key (KEK) 104 to one or more nodes within group A 106. In one embodiment, the server 102 is the authentication server. The authentication server may be a server that authenticates nodes wishing to join group A 106. In one embodiment, the server 102 authenticates a node and the node receives the KEK 104. A node may join group A 106 by using the KEK 104 to verify its possibility to join the group A 106 to the other nodes already belonging to group A 106. In one embodiment, the server 102 maintains a minimum characteristic with respect to each group node A 106. For example, server 102 may maintain information used to authenticate a particular node N 116 which is able to join group A 106. In one embodiment, the server 102 maintains a minimum characteristic regarding each group A 106. For example, the server 102 may simply maintain the characteristic KEK 104. The server 102 may communicate changes to the KEK 104 to the nodes of group A 106.
As illustrated, group A 106 includes node A 108, node B 110 and node C 112. While group A 106 shown with only three nodes, it is understood that group A 106 may include more or less nodes. Group A 106 may be referred to as a secure multicast group because nodes within group A 106 may carry multicast information to each other safe manner. For example, information which multicast is performed between the nodes of group A 106 may be encrypted with a shared key 114 of A. Nodes may use the KEK 104 to receive the group A key 114, which are assigned to group A 106. For example, node N 116 may implement the request to become a member of group A 106 by sending a request 118 to join the group to one or more nodes of group A 106. The one or more nodes of group A 106 may determine if node N 116 a KEK 104. If node N 116 includes the KEK 104, the one or more nodes 114 may receive a key group 116. A node N A key group 114 may enable a node to send information to other nodes within group A 106 and receive information from them. Nodes can use the key 114 of A, to encrypt and decrypt the information, which the multicast between the nodes of group A 106.
If node N 116 does not include the KEK 104, node N 116 may send a KEK request 120 to the server 102, requesting that the server 102 provides the KEK 104 to node N 116. The server 102 may authenticate node N 116 and output the KEK 104. However, if the KEK 104 is not issued to node N 116, node N 116 can not join the group A 106 and take the key 114 of A.
Exchange of information between the server 102, group A 106 and node N 116 may be over a network 122. Network 122 may include the Internet, a telephone network, a paging network, etc. In one embodiment, the server 102 may manage and communicate with multiple groups of nodes over the network 122. The server 102 may distribute the KEK, which is specific to each group of nodes.
2 is a block diagram illustrating a further embodiment of the server 202 interacting with a group of nodes over the network 222. The group of nodes may include group A 206. For simplicity within group A 206 is shown only node A 208. In addition, each node in the within group A 206 may be similar to node A 208. In one embodiment, node A 208 may determine a maximum update period 224. The maximum update period 224 may represent the maximum time during which a node may trust the KEK 204 without carrying out any changes to the KEK by 204 on the server 202. For example, group A 206 may include a maximum update period 224 of twenty-four hours, which implies each node belonging to the group A 206 may send a request to the server 202 for changes to the KEK 204 once every twenty-four hours. In one embodiment, the maximum update period 224 can first be determined by the server 202, and then to cross the node in response to a request for 120 KEK. In a further embodiment, node 208 may obtain the maximum update period 224 from another node already in the group A 206.
Node A 208 may also include a device 226 for generating the request. Generating apparatus 226 may generate a request for update requests that request the server 202 for changes to the KEK 204. For example, the server 202 may change the KEK 204, and node A 208 may generate an update request to discover the changes to the KEK 204. The apparatus 226 also generate a query may include a selection device 228 random time. In one embodiment, the random selection unit 228 randomly selects a time period for sending update requests at the server 202. The device 228 may select a random time randomly select a time that is less than the maximum update period 224. For example, if the maximum update period 224 includes twenty-four hours, the update request may be randomly sent to the server 202 for the tenth hour. Node 208 may send an update request at the tenth hour and then another update request at the end of the maximum update period 224 (i.e., twenty-four hours). In one embodiment, the nodes within group A 206 evenly distribute their generated update requests to the server 202. For example, if group A 206 includes twenty-four nodes, a first node may send an update request in the first hour (and then another update request after the maximum update period 224); a second node may send an update request in the second hour (and then another update request after the maximum update period 224), etc.
In one embodiment, the server 202 includes means 230 for determining the amount. Apparatus 230 helps determine the size of the server 202 to determine approximately how many nodes may be active within a particular group, such as group A 206. An active node may include a node which generates and sends update requests to the server 202 regarding KEK 204. The server 202 may use size determination unit 230 to determine the approximate number of active nodes in group A 206. In one embodiment, the size determinator 230 multiplies the maximum update period 224 requests the intensity correlated with the intensity of the band 206. A query may reflect the number of requests to update KEK 204 that the server 202 receives from nodes within group A 206 per unit time. For example, the maximum update period 224, correlated with each node may include twenty-four hours, and the server 202 may receive ten requests per hour from nodes within group A 206. Hence, the size determination unit 230 may estimate that group A 206 It includes two hundred and forty active nodes (ten requests per hour multiplied by twenty-four hours).
In one embodiment, the server 202 includes a device 232 rekey determinator. Apparatus rekey determinator 232 may determine a minimum update period 240 that represents the minimum time required for the server 202 to rekey all active nodes within a group, causing a maximum load for the server 202. In one embodiment, the shift key each active node within group It includes changing the KEK 204 stored on each node. Apparatus rekey determinator 232 may determine its current load using all requests over a certain time interval. In one embodiment, this may be done using a floating average. The device then rekey determinator 232 may determine the number of additional requests per second that the server 202 may satisfy by subtracting the current load of server 202 of the specified maximum load. Apparatus rekey determinator 232 may also access the device 230 for determining the amount to obtain the estimated number of active nodes in a particular group. In one embodiment, the device 232 rekey determinator may divide the number of active nodes in the group to certain additional requests per unit time to obtain the minimum update period 240, which represents the time it takes the server 202 to rekey the entire group of active nodes using maximum load. For example, the server 202 may determine that it currently serves ten update requests per unit of time. The maximum load may be defined as the twenty update requests per unit of time. The device 230 can determine the size of the assessment to determine the size of the group A 206 as the two hundred and forty active nodes. For this reason, the device 232 rekey determinator may determine that the server 202 requires approximately twenty-four units of time to replace the key KEK 204 stored on each active node within group A 206 (two hundred and forty nodes divided by the 10 additional requests possible per unit time). In an embodiment, the minimum update period 240 is distributed node A 208 along with the KEK 204. In a further embodiment, both the minimum update period 240 and the maximum update period 224 is distributed node A 208 along with the KEK 204.
3 is a block diagram illustrating one embodiment of a single node A 308 sends a request to update the server 302, using a minimum period of 344 inspections to check for changes to the KEK 304. As explained above, the server 302 may include the KEK 304, which distributed nodes within the group, such as group A 306, over the network 322. KEK 304 may enable a node to receive the group A key 314, which allows that node to establish a secure connection to other nodes within group A 306. The server 302 also includes sizing device 330, which may enable the server 302 to estimate the number of active nodes within group A 306 as previously explained. In one embodiment, the server 302 includes a device rekey determinator 332 which may include a minimum update period 340. The minimum update period 340 may be determined in the same manner as explained earlier, and may reflect the minimum time required for the server 302 to distribute the KEK 304 to each active node of group A 306 using a maximum load.
In one embodiment, the rekey determinator 332 may also include a minimum check period 344. The minimum check period 344 may reflect the minimum time between requests (maximum intensity), at which the server 302 may prefer to service normal update requests from a single node to check for updates to the KEK 304. In one embodiment, the minimum check period 344 may be pre-specified by the system administrator. In another embodiment, the minimum check period 344 may be determined similarly to the minimum update period 340. Thus, the minimum check period 344 and the minimum update period 340 may be similar. In one embodiment, the minimum check period 344 may serve only as a guide to nodes within group A 306, and can not perform its required audio unit 308, audio server 302.
The server 302 can allocate a minimum period of 344 check node A 308. Node A 308 may include a device 326 for generating queries, which can generate update requests, which requests the server 302 on the changes to the KEK 304. In one embodiment, the device 326 sends a query generation update requests to the rate specified minimum period of 344 checks. Node A 308 may be a single unit within group A 306 sends a request to update a rate given a minimum period of 344 checks. In another embodiment, the group A 306 includes a small set of nodes, each of which includes a device 326 for generating queries that sends update requests to the server 302 at a rate specified minimum period of 344 checks. In another embodiment, the group A 306 may include a large set of nodes, each of which includes a device 326 for generating queries that sends update requests to the server 302 at a rate specified maximum period of 224 upgrade.
The advantage of using a minimum check period 344 on a small set of nodes is that the single node may then notify the other nodes in the group that the KEK has changed, enabling them to use certain minimum update period 340 to update the KEK. This logic minimizes the load on the server 302 when the KEK has not changed, and also minimizes the time required to distribute a changed KEK to all nodes in the group. In one embodiment, node A 308 includes a device 342 for generating alerts. Generating apparatus 342 may generate a warning alert that signal other nodes within group A 306, that there are changes to the KEK 304. In one embodiment, node A 308 performs secure multicast notification additional nodes within group A 306. Additional nodes may also include a KEK 304. Additional nodes can generate update requests and to send those requests to the update server 302 to change the key KEK 304. The device 342 can also generate alerts include a minimum period of 340 upgrade that notifies other nodes on the minimum period in during which update requests can be sent to the server 302 to receive an updated KEK 304. In another embodiment, additional nodes can use the random selection device time to determine when to receive updates KEK 304 within a minimum period of 340 upgrade.
4 is a flowchart of a method illustrating one embodiment of a method 400 for determining a minimum update period 240 for a group of nodes. In one embodiment, the method 400 may be implemented by the server 102, such as an authentication server. The minimum update period 240 may represent the time during which the server can change the keys for the nodes within the group. Rekeying nodes may include updating the KEK 104 stored on each active node within the group.
In one embodiment, in step 402 receives one or more update requests per unit of time. Update requests may include requesting that changed whether the KEK 104 stored on the server 102. In step 404, the number of received update requests per unit time may be multiplied by a maximum update period 224. The maximum update period 224 may represent the maximum time during which a node may trust the KEK 104 before sending an update request regarding changes to the KEK 104. The result of multiplying the received update requests and the maximum update period 224 may assess active nodes within the group.
In one embodiment, at step 406 determined total number of received update requests per unit of time. The total number of received update requests per unit of time may be the total number of update requests that the server 102 services at any time in all groups. In one embodiment, in step 408, the value is obtained, showing additional update requests per unit of time. A value representing additional update requests may be obtained in step 408 by subtracting the total number of received requests from a determined maximum. As previously explained, the determined maximum may include the maximum number of update requests that the server 102 can serve per time unit. In step 410 is determined minimum update period 240 for a group of nodes. In one embodiment, the minimum update period 240 indicates the time it takes the server 102 to rekey each active node within group A 206. Rekeying each active node may include updating the KEK 104 on each active node within group A 206 . As previously explained, the minimum update period 240 may be determined by dividing the evaluation of active nodes within group A 206 by the amount representing additional update requests per unit of time.
5 is a flowchart of a method illustrating one embodiment of a method 500 for determining whether a node may join a group of nodes. In one embodiment, the method 500 may be implemented separate node belonging to the group. In step 502 may receive a request to join the group of nodes. The request may include a parameter determined by KEK. In step 504, it is determined whether caused parameter included with the request, KEK 104 correlated to each node within the group. For example, node A 108 may receive at block 502 a request from node N 116 requesting that node N 116 to become a member of group A 106. The request may include a parameter determined by the KEK. Node A 108 may determine at step 504 whether the same KEK, correlated with the request to the KEK 104 to node A correlated 108. If at step 504 it is determined that the KEK, correlated with the request does not match the KEK 104 to node A correlated 108, or if node N 116 does not possess the KEK, the method 500 terminates. If at step 504 it is determined that the KEK match, a group key 114 is issued at step 506 node N 116. In one embodiment, the group key 114 allows a node to receive secure data from other nodes belonging to the group. The group key may also allow a node to securely send data to other nodes in the group.
6 is a flowchart of a method illustrating one embodiment of a method 600 to notify other nodes in a group about changes to a KEK. In one embodiment, method 600 is implemented by a single node. In a further embodiment, the method 600 is implemented by a small group of nodes.
Update request may be sent at step 602 the server 102 using a minimum check period. Update request may include a query regarding changes to the KEK 104, correlated with the group. The server 102 may include an authentication server. The server 102 may respond to the request. In one embodiment, the response includes the KEK 104, correlated with the group identified by the node that sent the request. In step 604, it is determined whether match the KEK 104 included in the response to the KEK 104 on the node. If at step 604 the same KEK, the node continues to send in step 602 another update request after the minimum check period 344. If at step 604 KEK do not coincide, the KEK 104 on the node is updated in step 606 to match the KEK 104 on the server 102. In one embodiment, the server 102 may change the KEK 104 periodically to protect the integrity of the group of nodes. In step 608 may be multicast KEK change notification to one or more nodes within the group. In one embodiment, the notification is made multicast group from the node that sent the request in step 602 to update the server 102. Notification may also include the minimum update period 240. In one embodiment, one or more nodes may send an update request to the server 102 after receiving the notification. Update requests may be sent within the minimum update period 240.
7 is a block diagram of hardware components that may be used in a node or server 702 that is configured according to an embodiment. Node or server 702 may be implemented in an embedded device / computing device 702. There may be a central processing unit (CPU) 704 or processor for controlling the operation of the embedded device 702, including the other components thereof, which are connected to the CPU 704 via a bus 710. The CPU 704 may be implemented in the form of a microprocessor, microcontroller, digital signal processor or other device known in the art. The CPU 704 performs logical and arithmetic operations based on program code stored in the memory. In some embodiments, memory 706 may be on-board memory included in the CPU 704. For example, microcontrollers often include on-board memory of a volume.
The embedded device 702 may also include a network interface 708. Network interface 708 provides for establishing communication between the embedded device 702 and other devices connected to the network 122, which may be a paging network, cellular network, a global communications network, the Internet, computer network, telephone network, etc. The network interface 708 operates according to standard protocols for the respective network 122.
The embedded device 702 may also include memory 706. The memory 706 may include random access memory (RAM) for storing temporary data. Alternatively or in addition, the memory 706 may include read only memory (ROM) for storing more permanent data, such as fixed code and configuration data. The memory 706 may also be embodied in the form of a magnetic storage device such as a hard disk. The storage device 706 may be any type of electronic device configured to store information in electronic form.
The embedded device 702 may also include one or more communication ports 712, that provide the establishment of communication with other devices. The embedded device 702 may also include devices 714, input / output devices such as a keyboard, a mouse pointing device, a joystick, a touch screen device for display, speakers, printer apparatus, etc.
Of course, Figure 7 illustrates only one possible configuration of an embedded device 702 may be used various other architectures and components.
Information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination.
The various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, software, or a combination thereof. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present invention.
The various illustrative logical blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed with a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA ) or other programmable logic device, discrete gate element or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, a control unit, a microprocessor control unit, or state machine. In addition, the processor may be implemented as a combination of computing devices, eg, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
Stages methods or algorithms described in connection with the embodiments disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of two components. A software module may reside in RAM memory, EEPROM memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a compact optical disk or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, wherein said processor can read information from the storage medium and write information. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. Alternatively, the processor and the storage medium may reside in a user terminal in the form of separate components.
The methods disclosed herein comprise one or more steps or actions for successful implementation of the described method. The method steps and / or actions may be used interchangeably without departing from the scope of the present invention. In other words, if for proper operation of the embodiment does not require a specific order of steps or actions, the order and / or use of specific steps and / or actions may be modified without departing from the scope of the present invention.
Although the above shown and described specific embodiments and applications of the present invention, it is understood that the present invention is not limited to the individual configuration and components disclosed herein. Various modifications, changes and variations which will be apparent to those skilled in the art may be made in the arrangement, operation and details of the methods and systems of the present invention disclosed herein without departing from the spirit and scope of the present invention.
Contents5
16 members in 8 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 11624147 | United States of America | – | |
| 62414707 | United States of America | A | |
| 11624147 | – | – | – |
| US20070624147 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| US2008170692A1 | United States of America | A1 | |
| WO2008088081A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW200840300A | Taiwan Province of China | A | |
| WO2008088081A8 | World Intellectual Property Organization (WIPO) | A8 | |
| KR20090106577A | Republic of Korea | A | |
| EP2122898A1 | European Patent Office (EPO) | A1 | |
| CN101636964A | China | A | |
| JP2010517332A | Japan | A | |
| RU2009131030A | Russian Federation | A | |
| RU2420893C2This record | Russian Federation | C2 | |
| US8059819B2 | United States of America | B2 | |
| KR101092291B1 | Republic of Korea | B1 | |
| JP5033189B2 | Japan | B2 | |
| CN101636964B | China | B | |
| EP2122898A4 | European Patent Office (EPO) | A4 | |
| TWI389531B | Taiwan Province of China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A |
Numbers
- Publication
- 2420893
- Publication, DOCDB
- 2420893
- Publication, EPODOC
- RU2420893
- Application
- 200913103009
- Application, DOCDB
- 2009131030
- Application, EPODOC
- RU20090131030
Titles3
- English
- SYSTEMS AND METHODS FOR DISTRIBUTING KEY UPDATES WITH MAXIMUM KEY CHANGE INTENSITY
- Russian
- СИСТЕМЫ И СПОСОБЫ ДЛЯ РАСПРЕДЕЛЕНИЯ ОБНОВЛЕНИЙ ДЛЯ КЛЮЧА С МАКСИМАЛЬНОЙ ИНТЕНСИВНОСТЬЮ СМЕНЫ КЛЮЧА
- Russian
- ??????? ? ??????? ??? ????????????? ?????????? ??? ????? ? ???????????? ?????????????? ????? ?????
Classification
- CPC, 2
- H04L9/0833
- H04L9/0891
- IPC, 1
- H04L9 08