Method and apparatus for security in a data processing system
Abstract
The present invention discloses a method and apparatus for secure transmission. Provide a registration key to each user. A long-updated broadcast key is encrypted using the registration key and provided to a user on a regular basis. A short-term updated key is encrypted using the broadcast key and provided to a user on a regular basis. The broadcast is then encrypted with the short-term key, wherein the user decrypts the broadcast message using the short-term key. An embodiment provides link layer content encryption. Another embodiment provides end-to-end encryption.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
37 claims: 22 independent, 15 dependent
- 11380661 十、宇請專利範®:第093120523號專利t請案 t文申請專利範園替換本年8月汉0 一種用於將加密多媒體由# 琛體内今自一内容提供者無線廣播至 複數個授權終端機之方法,包括·· 每-授權終端機無線轉寄一唯一公開密錄至該内容提 供者,其t -· 每一授權終端機具有一行動設備及具有一安全處 理單元’該安全處理單元安全地儲存對應於該唯一 公開密瑜之-唯—私人麵,使得該唯—私人密瑜 並非可由該個別授權終端機之該行動設備存取, 該安全處理單元比該行動設備提供更多的安全密 錄儲存, 該文全處理單元具有足夠解密一廣播存取密餘及 產生一短期密鑰之處理功率,及 該安全處理#元不具有足夠解密多㈣内容之處 理功率,及 該廣播存取密鑰係由該内容提供者使用該個別授 權終端機之每-者之該唯一公開密鑰而被加密以授 權該個別終端機以接收加密多媒體内容; 每一授權終端機自該内容提供者無線接收該個別經加 密之廣播存取密鑰及提供該個別經加密之廣播存取密鑰 至該授權終端機的安全處理單元,其中該授權終端機的 該安全處理單元使用該安全處理單元的唯一私人密鑰來 解密該加密廣播存取密鑰及安全地儲存該廣播存取 鑰; 9468M010808.doc 每—授權終端機自該内容提供者無線接收短期密餘資 訊及加密多媒體内容廣播至該複數個授權終端機,其中 該多媒體内容係以一短期密餘加密,及其中該短期密錄 係使用該廣播存取密錄及該短期密錄資訊所產生; 每-授權終端機提供該短期密錄資訊至該授權終端機 s安王處理單元’ 該授權終端機的該安全處理單 錢用該廣播存取密錄及該短期密餘資訊來產生該短期 密鑰,及提供該短期密鑰至該授權終端機的行動設備; 及 每一授權終端機的行動設備使用該短期密鑰來解密該 多媒體内容。 2.如4求項1之用於廣播加密多媒體内容之方法,其中該短 期密鑰係可由一使用者存取。 3·如請求項2之用於廣播加密多媒體内容之方法,其中該短 期密鑰係由該内容提供者以一關於一註冊成本之速^所 改變。 4·如請求項1之用於廣播加密多媒體内容之方法,其中該安 全處理單元係自該授權終端機為可移除。 5. 如請求項1之用於廣播加密多媒體内容之方法,其中嗜短 期密鑰資訊係使用該廣播存取密鑰所加密之該短期密 錄0 6. 如請求項1之用於廣播加密多媒體内容之方法,其中节短 期世錄係藉由將一选碼編譯混合應用至該短期密输資气 之一連接及該廣播存取密鑰所產生。 94681-1010808.doc i38〇661 η · 如M承項6之用 密鑰資訊為一隨機值 期 8. 如請求項1之用於廣播加密多媒體内容之方法,其中至少 一授權終端機包含一行動台。 9. -種用於一行動台之積體電路,包含· 用於無線轉寄一唯一公開愈 件; Α開在鑰至一内容提供者之構 用於安全地儲存對應於該唯一公開密錄之一唯 密鑰之構件,使得該唯一私人 人 取,其中该用於安全地儲存— ^ 史用者存 足夠解密一廣播存取密翰及產生一短期m 率,且不具有足夠解密多媒體内容之處理功率,= 该内容提供者以該唯一公開 手及其中 授權-積體電路安全地儲存播存取密鑰以 力口密多媒體内容;十應唯-私人密鑰以接收 用於自該内容提供者盔 鑰之構件;…線接收該個別加密廣播存取密 用於解密該加密廣播存取 取密鑰之構件,其中誃—’地儲存該廣播存 由-使用者存取;、“女儲存廣播存取密鑰並非可 用於自該内宏括紐土 a 多媒體内容廣播至M:無線接收短期密繪資訊及該加密 汽播至複數個行動台之摄 内容係以-翅期密餘p構件,其令該多媒體 乃《靖加密,及呈中兮 廣播存取密鑰及’ '、足功也、錄係使用該 及5亥虹期密鑰資訊所產生; 94681-I0I0808.doc 1380661 用於使用該安全地儲存廣播存取密鑰及該廣播短期密 鑰資訊產生該短期密鑰之構件;及 用於使用該短期密鑰解碼該多媒體内容之構件,其中 該用於安全地健存-_-私人密錄之構件提供比該用於 解密該多媒體内容之構件更多安全密輪儲存。 10.如請求項9之積體電路,其中該短期密鑰可由一使用者存 取。 U.如請求項9之積體電路,其中該短期密㈣訊係使用該廣 播存取密錄所加密之該短期密錄。 12.如請求項9之積體電路,其中該短期密錄係藉由將一密碼 編譯混合應用至該短期密錄資訊之一連接及該廣播存取 密输所產生。 13·如請求項12之積體電路’其中該短期密鑰資訊為 值。 14•-種用於自-内容提供者無線接收加密多媒體内容 至複數個授權裝置之裝置,包括: 一行動設備,其經組態以: 無線轉寄一唯一公開密输至該内容提供者,及 使用-短期密錄解密該多媒體内容,其中該 體内容係以該短期密鑰加密,及其中該短期密鑰係 使用一廣播存取密錄及短期密錄資訊所產生;及 一安全處理單元,其經組態以: 安全t儲存對應該唯一公開密錄之一唯-私人密 鑰使付該唯 '私人密輪並非可由該行動設備存 9468M010808.doc *4- 取’其中該安全處理單元提供比該安全處理單元更 夕的:ίτ全Φ錄儲存,其中該安全處理單元具有足夠 解密一廣播存取密鑰及產生一短期密鑰之處理功 率’且不具有足夠解密多媒體内容之處理功率,及 其中該内容提供者以該唯一公開密鑰加密該廣播存 取密鑰以授權一具有該安全處理單元之裝置安全地 儲存該對應之唯一私人密鑰以接收該加密多媒體内 容; 自該内容提供者無線接收該個別加密廣播存取密 鑰; f密該加密廣播存取㈣及安全地儲存該廣播存 去讀’其巾該安全地儲存廣播存取密输並非可由 一使用者存取; 自該内容提供者無線接收該短期㈣資訊廣播至 該複數個授權裝置; 插存取密_廣播短期密 15. 如請求項14之裝置,其 取.。 其f心讀㈣係可由-使甩者存 16. 如凊求項μ之裝詈,甘山 存取密+ 八該短期密鑰資訊係使用該廣播 仔取讀所加费之該短期密鑰。 播 17. 如請求項14之裝置,其 ♦ 譯混合應用至該短期密鎗資^讀餘係藉由將—密蜗編 鑰所產生。 5 連接及該廣播存取密 9468M010808.doc 1380661 18.如請求項17之裝置,其中該短期密鑰資訊是一隨機值。 9468M010808.doc -6 · A method for wirelessly broadcasting encrypted multimedia content from a content provider to a plurality of authorized terminals, comprising: each authorized terminal wirelessly forwarding a unique public key to the content provider, wherein: each authorized terminal The machine has a mobile device and has a security processing unit that securely stores a unique private key corresponding to one of the unique public keys such that the unique private key is not available to the mobile device of the individual authorized terminal Accessing, the secure processing unit provides more secure key storage than the mobile device, the secure processing unit having sufficient processing power to decrypt a broadcast access key and generate a short-term key, and the secure processing unit does not have Sufficient to decrypt the processing power of the multimedia content, and the broadcast access key is encrypted by the content provider using the unique public key of each of the individual authorized terminals to authorize the individual terminal to receive the encrypted multimedia Content;each authorized terminal wirelessly receives the individual encrypted broadcast access key from the content provider and The secure processing unit for the individual encrypted broadcast access key to the authorized terminal, wherein the secure processing unit of the authorized terminal uses the unique private key of the secure processing unit to decrypt the encrypted broadcast access key And securely storing the broadcast access key;Each authorized terminal wirelessly receives short-term key information and encrypted multimedia content broadcast from the content provider to the plurality of authorized terminals, wherein the multimedia content is encrypted with a short-term key, and wherein the short-term key uses the Generating an access key and the short-term key information;each authorized terminal provides the short-term key information to the secure processing unit of the authorized terminal, wherein the secure processing unit of the authorized terminal uses the broadcast save Obtaining the key and the short-term key information to generate the short-term key, and providing the short-term key to the mobile device of the authorized terminal;and the mobile device of each authorized terminal uses the short-term key to decrypt the multimedia content . 一種用於將加密多媒體內容自一內容提供者無線廣播至複數個授權終端機之方法,包括:每一授權終端機無線轉寄一唯一公開密鑰至該內容提供者,其中:每一授權終端機具有一行動設備及具有一安全處理單元,該安全處理單元安全地儲存對應於該唯一公開密鑰之一唯一私人密鑰,使得該唯一私人密鑰並非可由該個別授權終端機之該行動設備存取,該安全處理單元比該行動設備提供更多的安全密鑰儲存,該安全處理單元具有足夠解密一廣播存取密鑰及產生一短期密鑰之處理功率,及該安全處理單元不具有足夠解密多媒體內容之處理功率,及該廣播存取密鑰係由該內容提供者使用該個別授權終端機之每一者之該唯一公開密鑰而被加密以授權該個別終端機以接收加密多媒體內容;每一授權終端機自該內容提供者無線接收該個別經加密之廣播存取密鑰及提供該個別經加密之廣播存取密鑰至該授權終端機的安全處理單元,其中該授權終端機的該安全處理單元使用該安全處理單元的唯一私人密鑰來解密該加密廣播存取密鑰及安全地儲存該廣播存取密鑰; 每一授權終端機自該內容提供者無線接收短期密鑰資訊及加密多媒體內容廣播至該複數個授權終端機,其中該多媒體內容係以一短期密鑰加密,及其中該短期密鑰係使用該廣播存取密鑰及該短期密鑰資訊所產生;每一授權終端機提供該短期密鑰資訊至該授權終端機的該安全處理單元,其中該授權終端機的該安全處理單元使用該廣播存取密鑰及該短期密鑰資訊來產生該短期密鑰,及提供該短期密鑰至該授權終端機的行動設備;及每一授權終端機的行動設備使用該短期密鑰來解密該多媒體內容。
- 9An integrated circuit for a mobile station, comprising:means for wirelessly forwarding a unique public key to a content provider;for securely storing a unique private key corresponding to one of the unique public keys a component such that the unique private key is not accessible by a user, wherein the means for securely storing a unique private key has sufficient processing power to decrypt a broadcast access key and generate a short-term key, and Not having sufficient processing power to decrypt the multimedia content, and wherein the content provider encrypts a broadcast access key with the unique public key to authorize an integrated circuit to securely store a corresponding unique private key to receive the encrypted multimedia content;Means for wirelessly receiving the individual encrypted broadcast access key from the content provider;means for decrypting the encrypted broadcast access key and securely storing the broadcast access key, wherein the securely storing the broadcast memory The key is not accessible by a user;it is used to wirelessly receive short-term key information from the content provider and broadcast the encrypted multimedia content to a plurality of lines The member sets, wherein the multimedia content in a short-term key encryption system, and wherein the short-term key system using the broadcast access key and the key information generated by the short-term;Means for generating the short-term key using the securely stored broadcast access key and the broadcast short-term key information;and means for decoding the multimedia content using the short-term key, wherein the means for securely storing one The unique private key component provides more secure key storage than the component used to decrypt the multimedia content. 一種用於一行動台之積體電路,包含:用於無線轉寄一唯一公開密鑰至一內容提供者之構件;用於安全地儲存對應於該唯一公開密鑰之一唯一私人密鑰之構件,使得該唯一私人密鑰並非可由一使用者存取,其中該用於安全地儲存一唯一私人密鑰之構件具有足夠解密一廣播存取密鑰及產生一短期密鑰之處理功率,且不具有足夠解密多媒體內容之處理功率,及其中該內容提供者以該唯一公開密鑰加密一廣播存取密鑰以授權一積體電路安全地儲存一對應唯一私人密鑰以接收加密多媒體內容;用於自該內容提供者無線接收該個別加密廣播存取密鑰之構件;用於解密該加密廣播存取密鑰及安全地儲存該廣播存取密鑰之構件,其中該安全地儲存廣播存取密鑰並非可由一使用者存取;用於自該內容提供者無線接收短期密鑰資訊及該加密多媒體內容廣播至複數個行動台之構件,其中該多媒體內容係以一短期密鑰加密,及其中該短期密鑰係使用該廣播存取密鑰及該短期密鑰資訊所產生; 用於使用該安全地儲存廣播存取密鑰及該廣播短期密鑰資訊產生該短期密鑰之構件;及用於使用該短期密鑰解碼該多媒體內容之構件,其中該用於安全地儲存一唯一私人密鑰之構件提供比該用於解密該多媒體內容之構件更多安全密鑰儲存。
- 14An apparatus for wirelessly receiving an encrypted multimedia content broadcast from a content provider to a plurality of authorizing devices, comprising:a mobile device configured to: wirelessly forward a unique public key to the content provider, and use Decrypting the multimedia content with a short-term key, wherein the multimedia content is encrypted with the short-term key, and wherein the short-term key is generated using a broadcast access key and short-term key information;and a security processing unit Configuring to: securely store a unique private key corresponding to one of the unique public keys such that the unique private key is not storable by the mobile device And wherein the security processing unit provides more secure key storage than the secure processing unit, wherein the secure processing unit has sufficient processing power to decrypt a broadcast access key and generate a short-term key, and does not have sufficient decryption Processing power of the multimedia content, and wherein the content provider encrypts the broadcast access key with the unique public key to authorize a device having the secure processing unit to securely store the corresponding unique private key to receive the encrypted multimedia Content;wirelessly receiving the individual encrypted broadcast access key from the content provider;decrypting the encrypted broadcast access key and securely storing the broadcast save key, wherein the securely storing the broadcast access key is not User access;wirelessly receiving the short-term key information broadcast from the content provider to the plurality of authorizing devices;generating the short-term key by using the securely storing the broadcast access key and the broadcast short-term key information. 一種用於自一內容提供者無線接收加密多媒體內容廣播至複數個授權裝置之裝置,包括:一行動設備,其經組態以:無線轉寄一唯一公開密鑰至該內容提供者,及使用一短期密鑰解密該多媒體內容,其中該多媒體內容係以該短期密鑰加密,及其中該短期密鑰係使用一廣播存取密鑰及短期密鑰資訊所產生;及一安全處理單元,其經組態以:安全地儲存對應該唯一公開密鑰之一唯一私人密鑰,使得該唯一私人密鑰並非可由該行動設備存 取,其中該安全處理單元提供比該安全處理單元更多的安全密鑰儲存,其中該安全處理單元具有足夠解密一廣播存取密鑰及產生一短期密鑰之處理功率,且不具有足夠解密多媒體內容之處理功率,及其中該內容提供者以該唯一公開密鑰加密該廣播存取密鑰以授權一具有該安全處理單元之裝置安全地儲存該對應之唯一私人密鑰以接收該加密多媒體內容;自該內容提供者無線接收該個別加密廣播存取密鑰;解密該加密廣播存取密鑰及安全地儲存該廣播存去密鑰,其中該安全地儲存廣播存取密鑰並非可由一使用者存取;自該內容提供者無線接收該短期密鑰資訊廣播至該複數個授權裝置;使用該安全地儲存廣播存取密鑰及該廣播短期密鑰資訊產生該短期密鑰。
Independent claims3
63 paragraphs, as filed
Security method and device in data processing system
The present invention relates generally to data processing systems, and more particularly to security methods and apparatus in data processing systems.
Safe in data processing and information systems (including communication systems), providing descriptive, fair, accurate, confidential, operational, and other requirements. Encryption, or the general field of cryptography, is used in e-commerce, wireless communications, broadcasting, and unlimited applications. In the case of e-commerce, encryption is used to prevent fraudulent financial transactions and to check financial transactions. In a data processing system, encryption is used to verify the identity of a participant. Encryption is also used to prevent hackers, protect web pages, and prevent access to confidential files.
A symmetric encryption system, commonly referred to as a cryptosystem, uses the same key (ie, the secret key) to encrypt and decrypt a message. Conversely, an asymmetric encryption system uses a first key (i.e., the public key) to encrypt a message and a second key (i.e., the private key) to decrypt the message. Asymmetric cryptosystems are also known as public key cryptosystems. A symmetric cryptosystem has a problem with the security of the sender providing the key to the recipient.
Thus, a secure and efficient key provision is required between a sender and a recipient.
Embodiments disclosed herein provide a method of security in a data processing system to meet the needs described above.
In one aspect, in a terminal for storing a private key, one is provided A method of accessing a key to receive a broadcast service, comprising: assigning a pair of public keys that should be a private key; receiving a secret key encrypted with the public key; decrypting the secret key with the private key; receiving the key The secret key encryption access key; and decrypting the access key with the secret key. An alternative method for providing an access key to receive a broadcast service in a terminal for storing a private key, comprising: assigning a pair of public keys that should be private keys; and receiving access encrypted by the public key a key; and decrypting the access key with the private key. Another alternative method for providing an access key to receive a broadcast service in a terminal for storing a private key, comprising: receiving a public key corresponding to a private key; encrypting the secret with the public key a key; transmitting the encrypted key; receiving an access key encrypted with the secret key; and decrypting the access key with the secret key.
In another aspect, a method for allocating an access key to provide a content provider's broadcast service includes: receiving a public key corresponding to a private key; and encrypting the secret key using the public key; Transmitting the encrypted key; encrypting the access key using the secret key; and transmitting the encrypted access key. An alternative method for assigning an access key to provide a content provider's broadcast service, comprising: receiving a public key corresponding to a private key; encrypting the access key using the public key; and transmitting The encrypted access key. Another alternative method for assigning an access key to provide a content provider's broadcast service for storing a private key includes: assigning a pair of public keys that should be private keys; receiving encryption with the public key a secret key; decrypting the secret key using the private key; encrypting the access key using the secret key; and transmitting the encrypted access key.
In still another aspect, in a terminal for storing a private key, an apparatus for providing an access key to receive a broadcast service includes: means for allocating a public key of a private key a means for receiving a secret key encrypted with the public key; means for decrypting the secret key with the private key; means for receiving an access key encrypted with the secret key; and for The secret key decrypts the component of the access key. An apparatus for providing an access key for receiving a broadcast service in a terminal for storing a private key, comprising: means for assigning a public key of a private key; for receiving a component of an access key for public key encryption; and means for decrypting the access key with the private key. Another alternative means for providing an access key for receiving a broadcast service in a terminal for storing a private key, comprising: means for receiving a public key corresponding to a private key; The public key encrypts the component of the secret key; means for transmitting the encrypted secret key; means for receiving an access key encrypted with the secret key; and for decrypting the access key with the secret key The components.
In a further aspect, an apparatus for allocating an access key to provide a content provider's broadcast service includes: means for receiving a public key corresponding to a private key; for using the disclosure a component of a key encryption key; a means for transmitting the encryption key; a means for encrypting the access key using the key; and means for transmitting the encrypted access key. An alternative means for allocating an access key to provide a content provider's broadcast service, comprising: means for receiving a public key corresponding to a private key; for encrypting the deposit using the public key a component of the key; and means for transmitting the encrypted access key. Used to allocate a deposit Another alternative means for obtaining a broadcast service for a content provider storing a private key, comprising: means for assigning a public key to a private key; for receiving the public key a component of the encrypted key; a means for decrypting the secret key using the private key; a means for encrypting the access key using the secret key; and means for transmitting the encrypted access key.
In still further aspects, in a terminal for storing a private key, an access key is provided to receive machine readable media of the broadcast service, including: for distributing a pair of private keys to be disclosed a code of a key; a code for receiving a secret key encrypted by the public key; a code for decrypting the secret key with the private key; and receiving an access key encrypted by the secret key a code; and a code for decrypting the access key with the secret key. An alternative machine readable medium for providing a broadcast service for receiving a private key in a terminal for storing a private key, comprising: a code for assigning a public key of a private key; a code for receiving an access key encrypted with the public key; and a code for decrypting the access key with the private key. An alternative machine readable medium for providing an access key for receiving a broadcast service, in a terminal for storing a secret key, comprising: a code for receiving a public key of a private key a code for encrypting the secret key with the public key; a code for transmitting the encryption key; a code for receiving an access key encrypted with the secret key; and for using the secret The key decrypts the code of the access key.
In still another aspect, a machine readable medium for distributing an access key to provide a content provider's broadcast service, comprising: for receiving a code of a public key corresponding to a private key; a code for encrypting the secret key using the public key; a code for transmitting the encrypted key; and for encrypting the access secret using the secret key a code of the key; and a code for transmitting the encrypted access key. An alternate machine readable medium for assigning an access key to provide a content provider's broadcast service, comprising: a code for receiving a public key corresponding to a private key; for using the disclosure The key encrypts the code of the access key; and the code for transmitting the encrypted access key. Another alternative machine readable medium for assigning an access key to provide a content provider's broadcast service for storing a private key, including: a program for assigning a public key to a private key a code for receiving a secret key encrypted with the public key; a code for decrypting the secret key using the private key; and a code for encrypting the access key using the secret key; A code for transmitting the encrypted access key.
In the following embodiments, the secret key may be a registration key or a temporary key.
In the following description, specific details are set forth to provide a comprehensive understanding of the embodiments. However, those skilled in the art will appreciate that such embodiments can be practiced without such specific description. For example, the circuits are shown in block diagrams in order to avoid obscuring the embodiments. In other instances, well known circuits, structures, and techniques have been shown in detail in order not to obscure the embodiments.
Moreover, please note that the embodiments may be described as a process, depicted as a flowchart, a flowchart, a structural diagram, or a block diagram. Although flow The process describes the jobs as continuous processing, but many of the jobs in the jobs can be executed in parallel or simultaneously. In addition, the order of the jobs can be reconfigured. When a processed job is completed, the process is terminated. A process can be equivalent to a method, a function, a program, a subroutine, a subroutine, and the like. When a process is equivalent to a function, its termination is equivalent to the function returning the call function or the main function.
Wireless communication systems are widely utilized to provide various types of communication, such as sound, data, and the like. These systems can be based on coded multi-directional proximity (CMDA), time-of-flight proximity (TDMA), or other modulation techniques.
A system that supports one or more standards can be designed, for example, "TIA/EIA-95-B Mobile Station-Base Station Compatibility Standard for Dual-Mode Wideband Spread Spectrum Cellular System" (for dual-mode broadband spread spectrum mobile phones) System TIA/EIA-95-B mobile base station standard) (this IS-95 standard); TDMA-based "Global System for Mobile" (GSM); "Universal Mobile Telecommunications Service" ( The Global Mobile Telephone Service System (UMTS) standard is a third-generation wireless service system based on the GSM communication standard; the General Packet Radio System (GRPS) communication standard is a development step of GSM to UMTS; The standards provided by the 3rd Generation Partnership Project (3GPP) are included in a set of documents including the file numbers: 3G TS 25.211, 3G TS 25.212, 3G TS 25.213, and 3G. TS 25.214, 3G TS 25.302; named by a joint "3rd Generation Partnership Project 2" The standard provided by 2) (3GPP2) is included in the "TR-45.5 Physical Layer Standard for cdma2000 Spread Spectrum System" (TR-45.5 physical layer standard for cdma2000 spread spectrum system) (IS-2000 standard).
Each standard defines a public construction component, such as a mobile device, and a device at the user end, such as a mobile device, for data processing for wireless communication. For purposes of illustration, the following discussion considers the use of a spread spectrum communication system consistent with a CDMA 2000 system. However, alternative embodiments may include another standard/system.
The cryptosystem is a method of disguising a message, thereby enabling a particular group of users to obtain the message. Figure 1A illustrates a basic cryptosystem. Cryptography is the technology that creates and uses cryptosystems. When you are not part of a specific user group that can access the message, cryptography is the technique of deciphering the cryptosystem, that is, receiving and understanding the message. The original message is called a plaintext message or plaintext. The encrypted message is referred to as a ciphertext, where the encryption includes any method of converting the plaintext into ciphertext. Decryption includes any method of converting ciphertext into plaintext, ie, retrieving the original message. As illustrated in Figure 1A, the plaintext message is encrypted to form a ciphertext. The ciphertext is then received and decrypted to retrieve the plaintext. The terms plaintext and ciphertext are usually related to data, and the concept of encryption can be applied to any digital information, including sound and video data in digital form. While the invention has been described herein, the terms plaintext and ciphertext are used consistent with cryptographic techniques, and such terms do not exclude other forms of digital communication.
The cryptosystem is based on confidentiality. a group of entities sharing a secret in the group Entities other than this, if there are not many resources, can not get the secret. Assume that the secret servo acts as a security association between the group of entities. A cryptosystem can be a collection of algorithms, where each algorithm is tagged and the tags are so-called keys. A symmetric encryption system uses the same key to encrypt and decrypt a message. A symmetric encryption system 20 is illustrated in FIG. 1B, wherein both encryption and decryption utilize the same private key.
In contrast, an asymmetric encryption system uses a first key called a public key to encrypt a message and uses a different key called a private key to decrypt the encrypted message. Figure 1C illustrates an asymmetric encryption system 30 in which a secret key for encryption and a second key for decryption are provided. Asymmetric cryptosystems are also known as public key cryptosystems. The public key is disclosed and can be used to encrypt any message, however, only the private key can be used to decrypt the message encrypted by the public key.
In a symmetric cryptosystem, there is a problem in providing a key to a recipient from a sender. One solution is to use a courier to provide this information, or a more efficient and reliable solution is to use a public key cryptosystem, such as the public key cryptosystem defined by Rivest, Shamir, and Adleman (RSA). Discussed below. The RSA system is used called Pretty Good Privacy (Pretty Good Privacy) (PGP) by the joy of confidentiality of the tool welcome.
PGP combines the characteristics of symmetric and asymmetric encryption. Figures 1D and 1E illustrate a PGP cryptosystem 50 in which a plaintext message is encrypted and received. In Figure 1D, the plaintext message can be compressed to save data transfer time and disk space. Since compression adds another degree of change to the encryption and decryption process, Therefore, the security of the password is enhanced. Most cryptanalysis techniques use the pattern obtained in the plaintext to crack the password. Compression reduces these patterns in the plaintext, thereby increasing resistance to cryptanalysis.
The PGP then establishes a session key, which is a unique key. The key is a random number that can be generated by any random event, such as random movement of the mouse and input of the keyboard when inputting. The session key works in conjunction with a secure encryption algorithm to encrypt the plaintext and generate ciphertext. Once the material is encrypted, the session key is then encrypted into the recipient's public key. The session key encrypted into a public key is transmitted to the recipient along with the ciphertext.
Regarding decryption, as illustrated in FIG. 1E, the recipient's PGP replica uses a private key to reacquire the temporary session key, which is then used to decrypt the conventionally encrypted ciphertext. The combination of encryption methods yields the advantages of the convenience of public key encryption and the speed of symmetric encryption. Symmetric encryption is usually much faster than public key encryption. Public key encryption provides a solution to the problem of key distribution and data transmission in turn. In combination, improved performance and key distribution, there is no notable sacrifice in terms of confidentiality.
The PGP stores the keys in two files: one for the public key and one for the private key. These files are so-called key rings. In an application, a PGP encryption system adds the public key of the target recipient to the public key ring of the sender. The sender's private key is stored in the sender's private key ring.
As described above, the method of allocating the keys for encryption and decryption is complicated. The "key exchange problem" first involves ensuring that the key is handed over. Therefore, the transmitter and the receiver can perform encryption and decryption separately, and for two-way communication, the transmitter and receiver can encrypt and decrypt the message. Furthermore, it is desirable to perform a key exchange to prevent interception by unintended third parties.
2 provides an example of a communication system 200 that supports some users and that is capable of implementing at least some of the aspects and embodiments of the present invention. System 200 provides communication for units 202A through 202G, each unit being serviced by a respective base station 204A through 204G.
The terminal 206 can be fixed (i.e., not moved) or moved within the coverage area. As shown in Figure 2, various terminals 206 are placed throughout the system. Each terminal 206 receives, depending on, for example, whether the soft handoff is utilized, or whether the terminal is designed and operated (simultaneously or continuously) to receive multiple transmissions from the multi-base station, at any particular time, with the downlink Or an upstream route, communicating with at least one or possibly more base stations 204. In the art, soft handoff in a CDMA communication system is well known and described in detail in U.S. Patent No. 5,101,501 entitled "Method and system for providing a Soft Handoff in a CDMA Cellular Telephone System", Assignment to the assignee of the present invention. The downlink route is transmitted from the base station to the terminal, and the uplink is transmitted from the terminal to the base station. Please note that other public building components other than the base station can be implemented according to a system configuration and/or standards supported by a system. Furthermore, when a terminal device may be a mobile phone, a personal data assistant, or some other mobile or fixed station, for purposes of illustration, a mobile station (MS) will be used to describe the embodiments.
The increased demand for wireless data transmission using wireless communication technology, as well as the expansion of effective services, has led to the development of specific data services. According to an embodiment, the system 200 supports a high speed multimedia broadcast service, hereinafter referred to as a high speed broadcast service (HSBS). The demonstration applications of HSBS are video streaming of movies, entertainment projects, and so on. The HSBS service is a packet data service based on the Internet Protocol (IP). A service provider can indicate the available high speed broadcast service to such users. The user of the HSBS service is required to subscribe to receive the service, and the list of broadcast services can be found through advertisements, a Short Message Management System (SMS), a Wireless Application Protocol (WAP), and the like. The base station (BS) transmits HSBS related parameters with management messages. When an MS wishes to receive the broadcast session, the MS reads the management messages and learns about the appropriate configuration. The MS then goes to the frequency containing the HSBS channel and receives the broadcast service content.
Several possible subscription/revenue models for HSBS services, including free access, control access, and special control access. With regard to free access, such mobile devices can receive the service without a subscription. The BS broadcasts that the content is not encrypted, and the mobile device of interest can receive the content. The service provider earns revenue through advertisements transmitted on the broadcast channel. For example, a movie studio pays a service provider for the upcoming movie.
Regarding the control access, the MS user subscribes to the service and pays a relative fee to receive the broadcast service. Users who have not subscribed should not access the content broadcast by HSBS. Thus, by encrypting the transmission/content of the HSBS to achieve control access, only the users of the order can decrypt, View and/or process the content. The above can use a wireless encryption key exchange program. The program provides robust security and prevents services from being stolen.
A hybrid access scheme, called partial access, is transmitted as an intermittent unencrypted advertisement that provides the HSBS service as an order-based encryption service. It is intended to facilitate the ordering of the encrypted HSBS service with such advertisements. The MS can know the list of such encrypted portions through an external device.
In one embodiment, system 200 supports a particular broadcast service, referred to as Broadcast/Multiple Propagation Service (BCMCS), sometimes referred to as Multimedia Broadcast/Multicast Service (MBMS). A detailed description of BCMCS is disclosed in U.S. Patent Application Serial No. 10/233,188, filed on August 28, 2002. Typically, BCMCS is a data packet service based on the Internet Protocol (IP). Figure 3 shows a simplified network 300 implementing BCMCS. In the network 300, video and/or voice information is provided to a packet data service network (PDSN) 330 by a content source (CS) 310. The video and audio information can be from a television broadcast program or a radio transmission. This information is provided as a packet of data, such as in the form of an IP packet. For an access within an access network (AN), PDSN 320 processes the IP packets. As illustrated, the AN is defined as part of the network 300 and includes a public building component 340, such as a base station, in communication with a plurality of terminals 350, such as a mobile station.
For BCMCS, CS 310 provides unencrypted material. The public construction component 340 receives the information stream from the PDSN 330 and provides the information to the subscriber terminal within the network 300 over a designated channel. For control access, the content from the CS 310 is encrypted by a content encryptor (for display) using an encryption key before being provided to the PDSN 320. However, the content encryptor can be combined with the CS 310. Or separately, the content encryptor and CS 310 are referred to below as content providers. Note that the content provider may also include other components and/or entities, such as a subscription manager, a key generator and a key manager. The subscriber of the subscription then has the decryption key so that the IP packets can be decrypted.
In particular, Figure 4 shows a terminal 400 having the ability to subscribe to a BCMCS to receive broadcast content. The terminal 400 includes an antenna 410 coupled to the receiving circuit 420. Terminal 400 receives transmissions from a content provider (not shown) via a common building component (not shown). The terminal 400 includes a mobile device (ME) 440 coupled to the receiving circuit 420 and a user identification module (UIM) 430. Note that here, for purposes of illustration, UIM 430 has been separated from ME 440, but in some embodiments, UIM 430 and ME 440 can be integrated together as a secure processing unit. Furthermore, although the embodiment is described in terms of a related UIM, other integrated circuit cards or secure processing units may be implemented, such as a Universal Integrated Circuit Card (UICC), a Subscriber Identity Module (SIM) or a Universal SIM (USIM). .
Typically, UIM 430 applies a validation procedure for the security of the BCMCS transmission and provides various keys to the ME 440. The ME 440 performs a number of processing including, but not limited to, decrypting the BCMCS content stream using the keys provided by the UIM 430. UIM 430 relies on secure storage and processing of confidential information (such as encryption keys) to keep it secret for a long time. The UIM 430 is a security unit, and the secrets stored therein do not necessarily require the system to change the confidential information from time to time.
The UIM 430 can include a processing unit, referred to as a secure UIM processing unit (SUPU) 432, and a memory unit, referred to as a secure UIM memory unit. (SUMU) 434. Within UIM 430, SUMU 434 stores confidential information in a manner that does not allow access to this information without permission. If the confidential information is obtained from the UIM 430, the access will require a large amount of resources. Again, within UIM 430, SUPU 432 performs calculations based on values internal and/or external to UIM 430. The result of the calculation can be stored in SUMU 434 or passed to ME 440.
The UIM 430 can be a resident unit or integrated into the terminal 400. Note that the UIM 430 may also include non-secure memory and a processor (not shown) for storing information including phone numbers, email address information, web or RUL address information, and/or scheduling functions. and many more. Alternate embodiments may provide a movable and/or reprogrammable UIM. In general, SUPU 432 has no significant processing power and functionality, such as decrypting BCMCS broadcast content beyond security and key procedures. However, alternative embodiments may implement a UIM with powerful processing capabilities.
When the UIM 430 is a secure unit, the data in the ME 440 can be accessed by non-subscribers and is considered unsafe. Because any information is only passed to the ME 440 in the short term or processed by the ME 440, it is still confidential. It is therefore desirable to be able to change any confidential information shared with the ME 440, such as a key, from time to time.
In particular, BCMCS content, commonly referred to as short-term key (SK), is typically encrypted using a unique and frequently changing temporary encryption key. In order to decrypt the broadcast content at a particular time, the ME 440 must know the current SK. The SK is used to decrypt the broadcast content in a short time, so it can be assumed that the SK has some inherent financial value to a user. For example, the inherent financial value can be a portion of the registration cost. Here, different content types can have Different inherent financial values. If the non-subscriber's cost of obtaining SK from a subscriber's ME 440 exceeds the inherent financial value of SK, then the cost of illegally obtaining SK exceeds the compensation and there is no benefit. Therefore, there is no need to protect the SK in the ME 440. However, if the inherent value of a broadcast is greater than the cost of illegally obtaining the key, it is advantageous for the non-subscriber to obtain the key from the ME 440. Therefore, the ideal is that the ME 440 storage secret will not be longer than SK.
In addition, it is considered unsafe for a content provider to use these channels to transmit data. Therefore, in BCMCS, SK is not transmitted wirelessly. The UIM 430 or ME 44 is obtained by playing one of the access keys, the so-called broadcast access key (BAK), and the SK information (SKI) together with the encrypted content. The BAK can be used for a specific period of time, for example, one day, one week or one month, and is updated. During each period in which the BAK is updated, a shorter interval is provided during the period in which the SK is changed. The content provider can use a cryptographic function to determine the values of SK and SKI, so SK can be determined by BAK and SKI. In an embodiment, the SKI may include an SK that uses BAK encryption as the key. Alternatively, SK can be the result of applying a cryptographic compilation hybrid function to the connection between the SKI and the BAK. Here, the SKI can be some random value.
In order to gain access to BCMCS, a user registers and subscribes to the service. In an embodiment of the registration process, a content provider and the UIM 430 agree on a registration key or source key (RK), and the server acts as a security association between the user and the content provider. The registration may occur when a user subscribes to a broadcast channel provided by the content provider or prior to the subscription. A single content provider can offer multiple broadcast channels. The content provider can choose to combine with the same RK user of all channels, or ask the user to One channel is registered, and the same user with different RKs on different channels is combined. Most content providers may choose to use the same registration key or require the user to register to obtain a different RK.
If possible, RK is still a secret in UIM 430. RK is unique to a particular UIM, ie, each user is assigned a different RK. However, if a user has multiple UIMs, then these UIMs can be configured to share the RK according to the content provider's policies. The content provider can then transmit further confidential information of the UIM 430, such as a BAK encrypted in RK. The UIM 430 can regain the original BAK value using the RK encrypted BAK. Since the ME 440 is not a confidential unit, the UIM 430 typically does not provide a BAK to the ME 440.
The content provider also broadcasts the SKI in combination with the BAK in UIM 430 to get the SK. The UIM 430 then passes the SK to the ME 440, and the ME 440 uses the SK to decrypt the encrypted broadcast program received from a content provider. In this method, the content provider can efficiently allocate new SK values to the ordering user.
As described, control access can be achieved by providing a BAK to the UIM 430. However, the broadcast service faces a problem in deciding how to provide BAK in UIM 430. In one embodiment, a public cryptosystem is implemented to supply the BAK of the UIM 430. The above assumes that a terminal or a content provider has a private key KPI and is able to assign a pair of public keys KPU that should be private keys.
For example, FIG. 5A shows that if a terminal has a private key, the supply of RK in UIM 430, and FIG. 5B shows if a content provider has a private secret. Key, the supply of RK in UIM 430. Here, various known algorithms and/or communication protocols can be used to establish a private key and assign a public key corresponding to the private key. If a terminal is established with a private key, the private key is stored securely and processed within a secure processing unit such as UIM 430. Furthermore, various encryption functions E and decryption functions D can be used to implement the disclosed cryptosystem.
In FIG. 5A, the content provider encrypts RK using KPU and transmits the encrypted RK.<img file="TWI380661B_D0001.tif" />(<i>RK</i>) to UIM 430. UIM 430 uses, for example<img file="TWI380661B_D0002.tif" />(<img file="TWI380661B_D0003.tif" />(<i>RK</i>))=<i>RK</i>The KPI decrypts the encrypted RK. The retrieved RK can then be safely stored in SUMU 434. In FIG. 5B, UIM 430 encrypts RK using KPU and transmits the encrypted RK.<img file="TWI380661B_D0004.tif" />(<i>RK</i>) to a content provider. Here, the SUPU 432 of the UIM 430 can perform the decryption and encryption when needed. Furthermore, UIM 430 can generate an RK value for safe storage in SUMU 434. Alternatively, RK can be provided in advance to SUMU 434, such as at the time of manufacture. The content provider uses, for example<img file="TWI380661B_D0005.tif" />(<img file="TWI380661B_D0006.tif" />(<i>RK</i>))=<i>RK</i>The KPI decrypts the encrypted RK. Once the description RK is provided, the BAK can be encrypted using RK as described above and transmitted from a content provider to a terminal.
In an alternate embodiment, a temporary key (TK) instead of RK can be used to encrypt the BAK. The temporary key can be used to further deprive the unprivileged user of the desire to access the broadcast content. If RK is provided to UIM 430, a content provider can transmit TK to UIM 430 before using RK to encrypt TK. The content provider then transmits the BAK encrypted using the current value of TK. Therefore, UIM 430 can decrypt the encrypted BAK using only the current value of the TK. However, in some cases, RK may be valid and/or a temporary key is required. For example, if a user wants to order in a short or regular time to receive a particular broadcast service, the temporary key is better. Thus, a public cryptosystem can be used to provide the TK.
If a terminal has the private key, a content provider can encrypt the TK using the KPU and transmit the encrypted TK.<img file="TWI380661B_D0007.tif" />(<i>TK</i>) to UIM 430, and the UIM 430 decrypts the encrypted TK, so<img file="TWI380661B_D0008.tif" />(<img file="TWI380661B_D0009.tif" />(<i>TK</i>))=<i>TK</i>. The re-acquired RK can be safely stored in the SUMU 434. If a content provider has the private key, the UIM 430 encrypts the TK using the KPU and transmits the encrypted TK.<img file="TWI380661B_D0010.tif" />(<i>TK</i>) to a content provider, and the content provider decrypts the encrypted TK, so<img file="TWI380661B_D0011.tif" />(<img file="TWI380661B_D0012.tif" />(<i>TK</i>))=<i>TK</i>. Here, the SUPU 432 of the UIM 430 can perform the decryption and encryption when needed. Furthermore, if a terminal has the private key, the content provider can generate a TK, and if the content provider has the private key, the UIM 430 can generate a TK. Once the TK value is provided, the BK is encrypted using TK in a manner similar to RK encryption and transmitted to a terminal by a content provider.
Figure 6 shows an embodiment in which a BAK is provided directly using a public cryptosystem. Here, a terminal device can have the private key, and a content provider can encrypt the BAK using the KPU and transmit the encrypted BAK.<img file="TWI380661B_D0013.tif" />(BAK) to UIM 430. UIM 430 can decrypt the encrypted BAK, so<img file="TWI380661B_D0014.tif" />(<img file="TWI380661B_D0015.tif" />(<i>BAK</i>))=<i>BAK</i>. The SUPU 432 of the UIM 430 can perform this decryption when needed.
Therefore, at UIM 430, BAK can be provided by a variety of different methods. In particular, Figure 7 shows an exemplary method 700 for providing a BAK for use in a terminal if a terminal has a private key. Method 700 begins with UIM of the terminal A pair of public keys (710) that should be private keys are assigned. After receiving the public key (715), the content provider encrypts the RK using the public key (725). The encrypted RK is transmitted to the UIM (735). The UIM receives the encrypted RK (740) and then uses the private key to decrypt the encrypted RK (750). The retrieved RK is stored in a secure memory, such as SUMU 434. In terms of the content provider, the RK is used to encrypt the BAK (745), and then the encrypted BAK (E BAK) is transmitted to the terminal (755). The UIM then receives the resulting E BAK (760) and decrypts E BAK (770) using RK.
Figure 8 shows another exemplary method 800 for providing a BAK in a terminal when a content provider has a private key. The method 800 begins with a content provider assigning a public key (805) corresponding to the private key. After receiving the public key (810), the UIM of the terminal uses the public key to encrypt RK (820). The RK will be stored in a secure memory such as SUMU 434. The encrypted RK is transmitted to a content provider (830). The content provider receives the encrypted RK (835) and uses the private key to decrypt RK (845). The content provider encrypts the BAK (855) using RK and then transmits the encrypted BAK (EBAK) to the terminal (865). The UIM then receives the EBAK (870) and then uses RK to decrypt the EBAK (880).
Figure 9 shows another exemplary method 900 for providing a BAK when a terminal has a private key. The method 900 begins with the UIM assigning a pair of public keys (910) that should be private keys. After receiving the public key (915), the content provider encrypts the BAK (925) using the public key. The encrypted BAK (EBAK) is transmitted to the UIM (935). The UIM receives the resulting EBAK (940) and then decrypts the EBAK (770) using the private key.
Once the BAK is provided at a terminal, the content can be encrypted with SK, and a terminal can obtain SK according to BAK to view/process the encrypted broadcast content.
In methods 700 and 800, in a UIM, more than one RK value may be provided because the content provider may choose to combine the user with the same RK of all channels, or require the user to register for each channel, and will be the same The user is combined with a different RK. Moreover, although the methods are described as being related to RK, RK-like methods can also be used to provide other keys such as TK. Furthermore, as described, RK and TK can be used to provide access keys other than BAK. Likewise, method 900 can also be used to provide an access key other than BAK.
The use of the disclosed cryptosystem provides an access key such as a BAK, as described, excluding the need to provide a previously shared secret key, such as RK or TK, often involving complex procedures. Furthermore, a user wants to convert a legacy SIM card or a removable UIM (R-UIM) into a new broadcast capable terminal. The legacy SIM/R-UIM can still be used for general mobile services, and the functions required for broadcasting can be incorporated into the terminal. BAK's public cryptosystem is provided to make it easy for new terminals to share a key with the network.
In addition, the distribution of a public key is easier than the distribution of a symmetric key. It should be understood that the public key is combined with the first entity and does not have the ability to decrypt the message for the second entity for the entity. The above-mentioned public key for distribution/transmission is not encrypted. Moreover, when communicating with the first entity, all other entities are able to use a single public key corresponding to the private key that the first entity has. Similarly, the first entity only needs to store a key to decrypt messages from the other entities. If using a symmetric key, when transferring data When the first entity is given (e.g., BAK), other different entities must (or at least preferably) use other different symmetric keys, requiring the first entity to store a symmetric key for each entity with which it communicates.
In addition, it is known that a first entity has a public key corresponding to a private key, making the first entity less likely to compromise. However, it is obvious that a first entity has a symmetric key that makes the first entity easy to compromise. Therefore, it is possible to assign a single public key of a terminal/UIM to a plurality of content providers, sharing a symmetric key such as RK, with no noticeable influence.
Finally, please note that these embodiments can be implemented using hardware, software, firmware, mediation software, microcode, or any combination thereof. When implemented in software, firmware, mediation software or microcode, the code or code segments that perform such tasks may be stored on machine readable media such as SUMU 434, or other media (not shown). These necessary tasks can be performed by a processor such as SUPU 434 or other processor (not shown). A code segment can represent a program, a function, a subroutine, a program, a program, a subroutine, a module, a software package, a classification, or any instruction, data structure or A combination of program statements. A code segment can be combined with another code segment or a hardware circuit by passing and/or receiving information, data, arguments, parameters or memory contents. Information, arguments, parameters, data, etc. can be communicated, forwarded, or transmitted by any suitable method including memory sharing, messaging, token passing, network transmission, and the like.
Accordingly, the above embodiments are merely illustrative and are not to be construed as limiting the invention. The description of the embodiments is intended to be illustrative, and not to limit the scope of the application. Therefore, those skilled in the art understand that such instructions are easily applied. Other types of devices, as well as many alternatives, modifications and variations.
<p>20Symmetric Encryption System</p><p>30Asymmetric encryption system</p><p>50PGP cryptosystem</p><p>100Communication system</p><p>102A, 102B, 102C, 102D, 102E, 102F, 102G units</p><p>104A, 104B, 104C, 104D, 104E, 104F, 104G base station</p><p>106A, 106B, 106C, 106D, 106E, 106F, 106G, 106H, 106I, 106J Terminals</p><p>300BCMCS simplified network</p><p>310Content source</p><p>330 Packet Data Service Network</p><p>340Public construction components</p><p>350,400 Terminal</p><p>410Antenna</p><p>420 receiving circuit</p><p>422Safe UIM Processing Unit</p><p>424Safe UIM memory unit</p><p>430User Identification Module</p><p>440Mobile equipment</p>
The various embodiments have been described in detail with reference to the accompanying drawings, in which FIG. 1A is an illustration of a cryptographic system; FIG. 1B is an illustration of a cryptographic system; 1C is an illustration of an asymmetric cryptosystem; FIG. 1D is a diagram of a PGP encryption system; FIG. 1E is a diagram of a PGP decryption system; and FIG. 2 is a diagram of a spread spectrum communication system supporting some users; Figure 3 shows a simplified system for implementing BCMCS; Figure 4 shows a terminal that can order BCMCS to receive multimedia content; Figures 5A and 5B are shown in a UIM, providing a key; Figure 6 is shown in a UIM, provided An access key; Figure 7 shows an exemplary method for providing a secret key in a UIM; Figure 8 shows another exemplary method for providing a secret key in a UIM; and Figure 9 shows a UIM for use in a UIM An exemplary method of providing an access key is provided.
3 sheets
Sheet 1 Sheet 2 Sheet 3
258 members in 19 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 93397201 | United States of America | A | |
| 10615882 | United States of America | – | |
| 61588204 | United States of America | A | |
| 10615882 | – | – | – |
| US20010933972 | – | – | – |
| US20040615882 | – | – | – |
Members258
| Document | Office | Kind | |
|---|---|---|---|
| US2002141365A1 | United States of America | A1 | |
| US2002141371A1 | United States of America | A1 | |
| US2002141391A1 | United States of America | A1 | |
| US2002141447A1 | United States of America | A1 | |
| US2002141591A1 | United States of America | A1 | |
| US2002142730A1 | United States of America | A1 | |
| US2002142757A1 | United States of America | A1 | |
| CA2442378A1 | Canada | A1 | |
| CA2442383A1 | Canada | A1 | |
| CA2442503A1 | Canada | A1 | |
| CA2442622A1 | Canada | A1 | |
| CA2442625A1 | Canada | A1 | |
| CA2442641A1 | Canada | A1 | |
| CA2442650A1 | Canada | A1 | |
| CA2442655A1 | Canada | A1 | |
| CA2442656A1 | Canada | A1 | |
| WO02080401A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080449A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO02080454A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080488A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080489A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080490A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080588A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080589A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080590A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO02080609A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002252545A1 | Australia | A1 | |
| AU2002252546A1 | Australia | A1 | |
| AU2002252547A1 | Australia | A1 | |
| AU2002252548A1 | Australia | A1 | |
| AU2002306978A1 | Australia | A1 | |
| US2002181423A1 | United States of America | A1 | |
| US2003039361A1 | United States of America | A1 | |
| WO02080588A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02080589A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02080590A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02080401A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02080454A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2003134655A1 | United States of America | A1 | |
| TW550926B | Taiwan Province of China | B | |
| NO20034316D0 | Norway | D0 | |
| NO20034339D0 | Norway | D0 | |
| NO20034340D0 | Norway | D0 | |
| NO20034341D0 | Norway | D0 | |
| KR20030086334A | Republic of Korea | A | |
| KR20030086616A | Republic of Korea | A | |
| KR20030086617A | Republic of Korea | A | |
| NO20034316L | Norway | L | |
| NO20034340L | Norway | L | |
| KR20030087036A | Republic of Korea | A | |
| WO02080489A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02080490A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20030088046A | Republic of Korea | A | |
| KR20030088048A | Republic of Korea | A | |
| KR20030088049A | Republic of Korea | A | |
| KR20030088050A | Republic of Korea | A | |
| KR20030088051A | Republic of Korea | A | |
| KR20030088052A | Republic of Korea | A | |
| NO20034339L | Norway | L | |
| NO20034341L | Norway | L | |
| US2003228861A1 | United States of America | A1 | |
| WO02080488A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW569579B | Taiwan Province of China | B | |
| EP1374440A2 | European Patent Office (EPO) | A2 | |
| EP1374477A1 | European Patent Office (EPO) | A1 | |
| EP1374483A2 | European Patent Office (EPO) | A2 | |
| EP1374506A2 | European Patent Office (EPO) | A2 | |
| EP1374528A2 | European Patent Office (EPO) | A2 | |
| EP1374529A2 | European Patent Office (EPO) | A2 | |
| EP1378145A1 | European Patent Office (EPO) | A1 | |
| TW571535B | Taiwan Province of China | B | |
| TW571596B | Taiwan Province of China | B | |
| EP1382177A2 | European Patent Office (EPO) | A2 | |
| EP1382178A2 | European Patent Office (EPO) | A2 | |
| EP1389386A2 | European Patent Office (EPO) | A2 | |
| TW577204B | Taiwan Province of China | B | |
| CA2496677A1 | Canada | A1 | |
| TW579629B | Taiwan Province of China | B | |
| TW579630B | Taiwan Province of China | B | |
| WO2004021153A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US6707801B2 | United States of America | B2 | |
| AU2003270024A1 | Australia | A1 | |
| AU2003270024A8 | Australia | A8 | |
| IL158130D0 | Israel | D0 | |
| IL158161D0 | Israel | D0 | |
| IL158162D0 | Israel | D0 | |
| IL158164D0 | Israel | D0 | |
| BR0208432A | Brazil | A | |
| MXPA03008871A | Mexico | A | |
| MXPA03008872A | Mexico | A | |
| MXPA03008876A | Mexico | A | |
| MXPA03008878A | Mexico | A | |
| MXPA03008880A | Mexico | A | |
| MXPA03008881A | Mexico | A | |
| TW591961B | Taiwan Province of China | B | |
| CN1507730A | China | A | |
| US2004120527A1 | United States of America | A1 | |
| MXPA03008923A | Mexico | A | |
| CN1511387A | China | A | |
| BR0208735A | Brazil | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Expiration of patent term of an invention patentMK4A | MK4A |
Numbers
- Publication
- I380661
- Publication, DOCDB
- I380661
- Publication, EPODOC
- TWI380661B
- Application
- 93120523
- Application, DOCDB
- 93120523
- Application, EPODOC
- TW20040120523
Titles4
- English
- Method and apparatus for security in a data processing system
- Chinese
- 在資料處理系統中之保密方法及裝置
- Unlabeled
- 在資料處理系統中之保密方法及裝置
- Unlabeled
- Security method and device in data processing system
Classification
- CPC, 13
- H04L63/0442
- H04L9/0822
- H04L9/0825
- H04L9/083
- H04L9/0891
- H04L9/14
- H04L63/062
- H04L63/08
- H04L2209/601
- H04L2209/80
- H04L2463/062
- H04W12/02
- H04W12/0013
- IPC, 3
- H04L9 30
- H04L9 08
- H04L29 06