Systems and methods for distributing updates for a key at a maximum rekey rate
Abstract
A method for distributing updates for a key is described. One or more update requests are received per unit of time. The number of received update requests per unit of time is multiplied by a maximum update peirod to estimate the number of active nodes in a group. The total number of received update requests per unit of time is determined. An amount representing additional update requests per unit of time is obtained from the difference between the total number of received updates and a determined maximum. A minimum update period for a group of nodes is determined.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
12 claims: 10 independent, 2 dependent
- 1一種用於分配金鑰更新之方法,該方法藉由伺服器來執行,該方法包含:藉由伺服器自活動節點之群組來接收每時間單位一或多個更新請求;藉由伺服器用一最大更新週期乘以每時間單位所接收之更新請求的數目以提供一群組中之活動節點的數目之評估值,在傳送一更新請求之前,該最大更新週期表示一活動節點利用一KEK之最大時間量;藉由伺服器來確定每時間單位所接收之更新請求的一總數目;藉由伺服器來獲得一表示每時間單位之額外更新請求的量,藉由將每時間單位伺服器伺服一更新請求之已確定的最大數目減去每時間單位所接收的更新請求之確定的總數目;以及藉由伺服器來確定最小更新週期,該週期係使用最大負載藉由伺服器來重新加密活動節點的整個群組所需要的時間,藉由使每時間單位所接收之更新請求的數目與一最大更新參數相乘,並用表示每時間單位之額外更新請求的量除此乘積。
- 2如申請專利範圍第1項所述之方法,其另外包含藉由活動節點傳送在每一次最小檢查週期經過之一更新請求。
- 3如申請專利範圍第1項所述之方法,其中該更新請求包含一用以重新加密一金鑰交換金鑰(KEK)的請求。
- 4如申請專利範圍第3項所述之方法,其中該KEK用於連 接一安全群播節點群組。
- 5如申請專利範圍第1項所述之方法,其另外包含保持一針對一節點群組之最小狀態,其中該最小狀態包含可獲得該金鑰交換金鑰(KEK)且連接該群組之節點。
- 6如申請專利範圍第1項所述之方法,其中該更新請求通常在時間上被均勻分配。
- 7一種經組態以分配金鑰更新之伺服器,該伺服器包含:一處理器;與該處理器電子通訊之記憶體;儲存於該記憶體中之指令,該等指令可執行以:藉由處理器自活動節點之群組接收每時間單位一或多個更新請求;藉由處理器用一最大更新週期乘以每時間單位所接收之更新請求的數目以提供一群組中之活動節點的數目之評估值,在傳送一更新請求之前,該最大更新週期表示一節點利用一KEK之最大時間量;藉由處理器來確定每時間單位所接收之更新請求的一總數目;藉由處理器來獲得一表示每時間單位之額外更新請求的量,藉由將每時間單位伺服器伺服一更新請求之已確定的最大數目減去每時間單位所接收的更新請求之確定的總數目;以及藉由伺服器來確定最小更新週期,該週期係使用最大負載藉由伺服器來重新加密活動節點的整個群組所需要的時間,藉由使每時間單位所接收之更新請求的數目與一 最大更新參數相乘,並用表示每時間單位之額外更新請求的量除此乘積。
- 8如申請專利範圍第7項所述之伺服器,其中藉由該活動節點每一時間最小檢查週期逝去來傳送更新請求,該最小檢查週期係為了檢查該金鑰的改變之最小週期。
- 9如申請專利範圍第7項所述之伺服器,其中該更新請求包含一用以更新一金鑰交換金鑰(KEK)之請求。
- 10一種電腦可讀式媒體,其包含用於在一最小更新週期期間分配金鑰更新之可執行指令之伺服器,該等指令藉由伺服器來執行時造成該伺服器:藉由伺服器自活動節點之群組接收每時間單位一或多個更新請求;藉由伺服器用一最大更新週期乘以每時間單位所接收之更新請求的數目以提供一群組中之活動節點的數目之評估值,在傳送一更新請求之前,該最大更新週期表示一節點利用一KEK之最大時間量;藉由伺服器來確定每時間單位所接收之更新請求的一總數目;藉由伺服器來獲得一表示每時間單位之額外更新請求的量,藉由將每時間單位伺服器伺服一更新請求之已確定的最大數目減去每時間單位所接收的更新請求之確定的總數目;以及藉由伺服器來確定最小更新週期,該週期係使用最大負載藉由伺服器來重新加密活動節點的整個群組所需要的時間,藉由使每時間單位所接收之更新請求的數目與一 最大更新參數相乘,並用表示每時間單位之額外更新請求的量除此乘積。
- 11如申請專利範圍第10項所述之電腦可讀式媒體,其中該中藉由該活動節點每一時間最小檢查週期期間逝去來傳送更新請求,該最小檢查週期係為了檢查該金鑰的改變之最小週期。
- 12如申請專利範圍第10項所述之電腦可讀式媒體,其中該更新請求包含一用以更新一金鑰交換金鑰(KEK)之請求。
Independent claims12
52 paragraphs in 1 section, as filed
Method, system and computer readable medium for allocating key update
SYSTEMS AND METHODS FOR DISTRIBUTING UPDATES FOR A KEY AT A MAXIMUM RE-KEY RATE
The present invention relates to a computer and computer-related technology. In particular, it refers to a system and method for distributing key updates at a maximum re-encryption rate.
Computer and communication technology continue to develop rapidly. In fact, computer and communication technology have been involved in many aspects of personal life. For example, many devices used by consumers today have small computers inside. These small computers exhibit a variety of size variations and levels of complexity. These small computer structures span from a single microcontroller to a complete computer system with complete functions. For example, these small computers may be single-chip computers (such as microcontrollers), single-board computers (such as controllers), typical desktop computers (such as IBM-PC compatible systems), and so on.
A computer usually has one or more processors located in the center of the computer. The processor(s) are usually interconnected to different external inputs and outputs and used to manage specific computers or devices. For example, the processor in a thermostat can be connected to a button for selecting a temperature setting, a furnace or an air conditioner for changing the temperature, and a temperature for reading the current temperature displayed on a display Sensor.
Many appliances, devices, etc. include one or more small computers. For example, thermostats, furnaces, air conditioning systems, refrigerators, telephones, typewriters, automobiles, vending machines, and many different types of industrial equipment now usually have small computers or processors inside them. Computer software runs the processors of these computers and instructs them how to perform certain tasks. For example In other words, the computer software running on the thermostat can cause the air conditioner to stop operating when a certain temperature is reached, or it can cause the heater to turn on when needed.
Small computers that are part of these types of devices, appliances, tools, etc. are usually called embedded devices or embedded systems. (The terms "embedded device" and "embedded system" will be used interchangeably in this article). Embedded systems usually refer to computer hardware and software that are part of a larger system. Embedded systems may not have typical input and output devices (such as keyboards, mice, and/or displays). Usually, one or more processors are located at the center of each embedded system.
Embedded systems can be used to supervise or control many different systems, resources, products, etc. With the development of the Internet and the World Wide Web, more and more embedded systems are connected to the Internet so that they can be remotely monitored and/or controlled. Other embedded systems can also be connected to computer networks (including local area networks, wide area networks, etc.). As used herein, the term "computer network" (or simply "network") refers to any system in which a series of nodes are interconnected by a communication path. The term "node" refers to any device that can be connected as part of a computer network.
Some embedded systems can use computer networks to provide data and/or services to other computing devices. Alternatively, a typical computer or computing device can use a computer network to provide data and/or services to other computing devices. Sometimes it is beneficial to minimize the number of key exchanges required to maintain a secure connection. Using a large number of key exchanges can generate additional throughput on the network. These situations and other situations can cause the communication via the network to be invalid. If the system and method can be used to prepare for an effective distribution key update, benefits can be realized.
A method for distributing key updates. Each time unit will receive one or more update requests. Multiply the maximum update period by the number of update requests received per time unit. Determine the total number of update requests received per time unit. Obtain an amount representing additional update requests per unit of time. Determine a minimum update period for a node group.
In one embodiment, by subtracting a determined maximum of update requests desired per unit of time from a determined maximum of update requests desired per unit of time, the total number of received update requests determined per time unit is subtracted (The determined total number of received update requests per unit of time) to obtain the amount representing additional update requests per unit of time. The minimum update period can be determined by multiplying the number of update requests received per time unit by a maximum update parameter, and dividing the product by the amount of additional update requests per time unit. An update request can be received from a single node during each minimum check period. In one embodiment, the update request includes a request to re-encrypt a key exchange key (KEK). The KEK can be used to connect to a secure multicast group of nodes.
A minimum state for a node group can be maintained, where the minimum state includes nodes that can obtain KEK and connect to the group. The maximum update period may represent the maximum amount of time a node can apply the same KEK, and an update request must be sent before the maximum amount of time is exceeded. Multiplying the number of update requests received per time unit by a maximum update period can provide an estimate of the number of active nodes in a group. This can evenly distribute update requests.
It also describes a computer system configured to distribute key updates. The electricity The brain system includes a processor and a memory for electronic communication with the processor. The command is stored in the memory. Receive one or more update requests per time unit. Multiply the number of update requests received per time unit by a maximum update period. Determine the total number of update requests received per time unit. Obtain an amount representing additional update requests per unit of time. Determine a minimum update period for a node group.
A computer-readable medium is also described, which contains executable instructions for allocating key updates during a minimum update period. Receive one or more update requests per time unit. Multiply a maximum update period by the number of update requests received per time unit. Determine the total number of update requests received per time unit. Obtain an amount representing additional update requests per unit of time. Determine a minimum update period for a node group.
In order to have a better understanding of the technology, means and effects adopted by the present invention to achieve the intended purpose, please refer to the following detailed description and drawings of the present invention. I believe that the purpose, features and characteristics of the present invention can be obtained from this in depth and For specific understanding, however, the accompanying drawings are only provided for reference and illustration, and are not intended to limit the present invention. Exemplary embodiments of the present invention will be described in detail and in detail with reference to the accompanying drawings.
Various embodiments of the present invention will now be described with reference to the figures, in which similar reference numerals represent elements with the same or similar functions. As generally described and illustrated in the figures in this document, the embodiments of the present invention can be configured and designed in a wide variety of different configurations. Therefore, as shown in the figure, the following implementations of several exemplary embodiments of the present invention are not intended to limit the scope of the present invention as claimed, but merely represent embodiments of the present invention.
The term "exemplary" in this text means "serving as an example, instance, or illustration". Any embodiment described herein as "exemplary" need not be construed as favored or advantageous over other embodiments.
Many of the features of the embodiments disclosed herein can be implemented as computer software, electronic hardware, or a combination of both. In order to clearly illustrate this interchangeability of hardware and software, various components will generally be described in terms of their functions. Whether this function is implemented as hardware or software depends on the specific application and design constraints imposed on the entire system. Skilled technicians can implement the described functions in varying ways for each specific application, but these implementation decisions should not be construed as causing a departure from the scope of the present invention.
In the case of implementing the described functions as computer software, this software may include any type of computer instructions or computer executable code located in a memory device and/or as an electronic signal via a system bus or network Way to transmit. The software that implements the functionality associated with the components described herein can include a single command or many commands, and can be distributed across several different code segments, among different programs, and across several memory devices.
As used herein, unless expressly stated otherwise, the terms "an embodiment", "an embodiment", "a number of embodiments", "the embodiment", "the embodiments", "an or "Multiple embodiments", "some embodiments", "certain embodiments", "one embodiment", "another embodiment" and the like mean "one or more of the disclosed invention(s) Multiple (but not necessarily all) embodiments".
The term "determining" (and its grammatical variants) is used in a very broad sense. The term "determine" covers a wide variety of actions And therefore "determining" can include accounting, calculation, processing, obtaining, investigating, checking (for example, checking in a table, database, or another data structure), finding out, and the like. Furthermore, "determining" may include receiving (for example, receiving information), accessing (for example, accessing data in a memory), and the like. again. "Determining" can include solving, selecting, selecting, establishing, and the like.
Unless specifically stated otherwise, the phrase "based on" does not mean "based on only." In other words, the phrase "based on..." describes both "based only on..." and "based at least on...".
When a centralized server (such as an authentication server) is used to manage a secure multicast group, each member (or node) of the group can periodically verify a distribution from the server The key has not changed. The key can enable the node to connect to the multicast group and receive a group key. The key can be referred to as a key exchange key (KEK). Each group can have a different KEK. Periodic verification of KEK may cause problems between timely update (ie, frequent use of checks) and network usage (ie, use of more frequent checks). In one embodiment, the less frequent checks are sent to the server until the assigned key is changed. When a KEK change occurs, the server may want to re-encrypt each active node belonging to the group as quickly as possible.
In one embodiment, an authentication server maintains a minimum state for the multicast group. For example, the server may maintain nodes that can be authenticated as group members, and the server may maintain KEK. The KEK can be used by the nodes to connect to the actual group. This keeps the minimum state, allowing the system to avoid the risk of the authentication server being shut down or switched to a redundant authentication server (in which there may be little or no shared authentication server status) due to overload. risk.
Nodes in a group may not trust each other's KEK. In one embodiment, the destroyed node can mislead the KEK of the remaining nodes in the group. The authentication server can be trusted to allocate or verify the KEK, which puts a heavy load on the authentication server. However, the authentication server may not have an exact count of the number of active nodes in a group at any given time. The authentication server does not know the number of active nodes in the group. This factor increases so that the authentication server determines how to best allocate update requests to check the updated KEK (if it needs the nodes in the group to send requests as quickly as possible) Difficulties. For example, a group with ten active nodes can be re-encrypted by changing the KEK within a few seconds. However, a group with 10,000 active nodes may not be able to re-encrypt quickly. If all 10,000 nodes in the group send a re-encryption request to the authentication server within a few seconds, the server or network may not be able to handle the large throughput load.
The first figure is a block diagram illustrating an embodiment of the server 102 that communicates a key exchange key (KEK) 104 to one or more nodes in the group A 106. In this embodiment, the server 102 is an authentication server. An authentication server can be a server that authenticates nodes that want to connect to group A 106. In one embodiment, the server 102 authenticates a node and the node receives KEK 104. A node can use KEK 104 to connect to group A 106 to prove its ability to connect to group A 106 to other local nodes that belong to group A 106. In one embodiment, the server 102 maintains a minimum state for each node of the group A 106. For example, the server 102 may maintain information for authenticating that a specific node N 116 can connect to the group A 106. In one embodiment, the server 102 Keep the minimum state for each group A 106. For example, the server 102 can simply maintain the state of the KEK 104. The server 102 can communicate the changes of the KEK 104 to the nodes of the group A 106.
As illustrated, group A 106 includes node A 108, node B 110, and node C 112. Although group A 106 is illustrated as having only three nodes, understand that group A 106 may include more or fewer nodes. Group A 106 can be referred to as a secure multicast group, because nodes in group A 106 can multicast information to each other in a secure manner. For example, a shared group A key 114 can be used to encrypt the information grouped among the nodes of the group A 106. The nodes can use KEK 104 to receive the group A key 114 associated with the group A 106. For example, node N 116 may request to become a member of group A 106 by sending a group request 118 to one or more nodes of group A 106. The member or members of group A 106 can determine whether node N 106 includes KEK 104. If the node N 116 includes the KEK 104, the node or nodes can assign the group A key 114 to the node N 116. The group A key 114 can enable a node to transmit information to and receive information from other nodes in the group A 106. The node can use the group A key 114 to encrypt and decrypt the information broadcasted among the nodes of the group A 106.
If the node N 116 does not include the KEK 104, the node N 116 can send a KEK request 120 to the server 102 and request the server 102 to allocate the KEK 104 to the node N 116. The server 102 can authenticate the node N 116 and allocate the KEK 104. However, if the KEK 104 is not allocated to the node N 116, the node N 116 may not connect to the group A 106 and receive the group A key 114.
The communication between server 102, group A 106 and node N 116 can be via A network 122 is performed. The network 122 may include the Internet, a telephone network, a pager network, and so on. In one embodiment, the server 102 can manage multiple node groups and communicate with the multiple node groups via the network 122. The server 102 can allocate a KEK specific to the node group to each node group.
The second figure is a block diagram illustrating another embodiment of the server 202 communicating with a node group via a network 222. The node group may include group A 206. For the sake of clarity, only node A 208 is illustrated in group A 206. However, each node in group A 206 is similar to node A 208. In one embodiment, the node A 208 can determine a maximum update period 224. The maximum update period 224 may indicate how long the maximum amount of time the KEK 204 can be trusted without checking whether the server 202 has changed the KEK 204. For example, group A 206 may include a maximum update period 224 with twenty-four hours as the maximum update period, which implies that each node belonging to group A 206 can change every twenty-four hours for KEK 204. A request will be sent to the server 202 once every hour. In one embodiment, the server 202 may first determine the maximum update period 224 and then respond to the KEK request 120 to deliver the maximum update period 224 to the node. In another embodiment, the node 208 may obtain the maximum update period 224 from another node in the group A 206.
The node A 208 may also include a request generator 226. The request generator 226 can generate an update request to query the server 202 for the change of the KEK 204. For example, the server 202 can change the KEK 204, and the node A 208 can generate an update request for discovering the change of the KEK 204. The request generator 226 may also include a random time selector 228. In one embodiment, the random time selector 228 randomly selects a time for sending the update request to the server 202. The selector 228 can randomly select a value smaller than the maximum The time of the big update cycle 224. For example, if the maximum update period 224 is twenty-four hours, the update request can be randomly sent to the server 202 during the tenth hour. Node A 208 may transmit an update request at the tenth hour and then transmit another update request at the end of the maximum update period 224 (ie, twenty-four hours). In one embodiment, the nodes in the group A 206 evenly distribute the update requests they generate to the server 202. For example, if group A 206 includes twenty-four nodes, a first node can transmit an update request in the first hour (and then transmit another update request after the maximum update period 224); The two nodes may transmit an update request in the second hour (and then transmit another update request after the maximum update period 224), and so on.
In one embodiment, the server 202 includes a size determiner 230. The size determiner 230 facilitates the server 202 to determine approximately how many nodes are active in a particular group (such as group A 206). An active node may include a node that generates an update request for the KEK 204 and transmits it to the server 202. The server 202 can use the size determiner 230 to determine the approximate number of active nodes in the group A 206. In one embodiment, the size determiner 230 multiplies the maximum update period 224 with a request rate associated with group A 206. The request rate may indicate the number of KEK 204 update requests received by the server 202 from nodes in the group A 206 per time unit. For example, the maximum update period 224 associated with each node may include twenty-four hours, and the server 202 may receive ten requests from nodes in group A 206 every hour. Therefore, the size determiner 230 may estimate that the group A 206 includes two hundred and forty active nodes (ten requests divided by hours and then multiplied by twenty-four hours).
In one embodiment, the server 202 includes a re-encryption determiner 232. The re-encryption determiner 232 can determine a minimum update period 240. The minimum update period 240 represents the minimum time required for the server 202 to re-encrypt all active nodes in a group. A maximum load. In one embodiment, re-encrypting each active node in a group includes changing the KEK 204 stored on each node. The re-encryption determiner 232 may use all the number of requests in a certain time to determine its current load. In one embodiment, this can be done using a floating average. The re-encryption determiner 232 can then determine the number of additional requests per second that the server 202 can satisfy by subtracting its 202 current load from a determined maximum load. The re-encryption determiner 232 may also use the size determiner 230 to obtain the estimated number of active nodes in a specific group. In one embodiment, the re-encryption determiner 232 can divide the determined additional request per time unit by the number of active nodes in a group to obtain the minimum update period 240, which is required by the server 202 It is used to re-encrypt the entire active node group with a maximum load. For example, the server 202 may determine that it currently serves ten update requests per time unit. The maximum load can be determined as twenty update requests per time unit. The size determiner 230 may divide the group A One estimate of the size of 206 is determined to be two hundred and forty active nodes. Therefore, the re-encryption determiner 232 can determine that the server 202 needs about twenty-four time units to re-encrypt the KEK 204 stored on each active node in the group A 206 (with 10 additional requests per time unit possible Divide by two hundred and forty nodes). In one embodiment, the minimum update period 240 is assigned to the node 208 along with the KEK 204. In another embodiment, the minimum update period 240 and the maximum update period 224 together with the KEK 204 are allocated to the node A 208.
The third diagram is a block diagram illustrating an embodiment of a single node A 308 that uses a minimum check period 344 to send an update request to a server 302 to check the change of the KEK 304. As previously explained, the server 302 may include the KEK 304 that is allocated to the nodes in a group (such as the group A 306) via the network 322. The KEK 304 can enable a node to obtain a group A key 314 that allows the node to communicate securely with other nodes in the group A 306. The server 302 also includes a size determiner 330 that enables the server 302 to estimate the number of active nodes in the group A 306 as explained previously. In one embodiment, the server 302 includes a re-encryption determiner 332, and the re-encryption determiner 332 may include a minimum update period 340. The minimum update period 340 can be determined as previously explained and can indicate the minimum time required by the server 302 to allocate the KEK 304 to each active node of the group A 306 using a maximum load.
In one embodiment, the re-encryption determiner 332 may also include a minimum check period 344. The minimum check period 344 may indicate the minimum time (maximum rate) between requests, and the server 302 may favor serving ordinary update requests from a single node to check the update of the KEK 304 under the minimum time. In one embodiment, the minimum inspection period 344 may be predetermined by the system administrator. In another embodiment, the minimum check period 344 may be determined in a manner similar to the minimum update period 340. Therefore, the minimum check period 344 and the minimum update period 340 may be similar. In one embodiment, the minimum check period 344 may only serve as a guide to the nodes in the group A 306, and may not be forced by the node 308 or the server 302.
The server 302 can allocate the minimum inspection period 344 to the node A 308. Node A 308 may include a request generator 326, which 326 can generate an update request for querying the server 302 for the change of the KEK 304. In one embodiment, the request generator 326 transmits the update request at a rate specified by the minimum check period 344. The node A 308 may be the only node in the group A 306 that transmits the update request at the rate specified by the minimum check period 344. In another embodiment, group A 306 includes a small group of nodes, each of which includes a request generator 326 that transmits update requests to the server 302 at a rate specified by the minimum check period 344. In another embodiment, the group A 306 may include a large group of nodes, each of which includes a request generator 326 that transmits update requests to the server 302 at a rate specified by the maximum update period 224.
The benefit of using a minimum check period 344 on a small group of nodes is that a single node can then notify other nodes in a group of KEK changes, thereby enabling it to update KEK using the determined minimum update period 340. When the KEK is unchanged, this logic minimizes the load on the server 302 and also minimizes the time required to allocate a changed KEK to all nodes in the group. In one embodiment, node A 308 includes a notification generator 342. When there is a change in the KEK 304, the notification generator 342 can generate a notification to signal to other nodes in the group A 306. In one embodiment, node A 308 safely multicasts these notifications to additional nodes in group A 306. These additional nodes may also include KEK 304. These additional nodes can generate update requests and send these update requests to the server 302 to re-encrypt the KEK 304. The notification generator 342 may also include a minimum update period 340 that informs additional nodes of the minimum period during which an update request can be sent to the server 302 to retrieve the updated KEK 304. In another embodiment, the additional nodes can use a random time selector to determine when to obtain updated updates within the minimum update period 340. The new KEK 304.
The fourth figure is a flowchart illustrating an embodiment of a method 400 for determining a minimum update period 240 for a group of nodes. In one embodiment, the method 400 may be implemented by a server 102 (such as an authentication server). The minimum update period 240 may indicate the time during which the server can re-encrypt the nodes in a group. Re-encrypting nodes may include updating the KEK 104 stored on each active node in the group.
In one embodiment, one or more update requests are received per time unit (402). The update request may include a query on whether the KEK 104 stored on the server 102 has changed. The number of update requests received per time unit is multiplied by a maximum update period 224 (404). The maximum update period 224 represents the maximum amount of time that the KEK 104 can be trusted without transmitting an update request for the change of the KEK 104. The product of the received update request multiplied by the maximum update period 224 can generate an estimate of the active nodes in a group. In one embodiment, the total number of update requests received per time unit is determined (406). The total number of update requests received per time unit may represent the number of update requests that the server 102 serves all groups at any time. In one embodiment, an amount representing additional update requests per unit time is obtained (408). This (408) represents the amount of additional update requests that can be obtained by subtracting the total number of received requests from a determined maximum value. As explained previously, the determined maximum value may include the maximum number of update requests that the server 102 can service per unit time. A minimum update period 240 for a node group is determined (410). In one embodiment, the minimum update period 240 indicates the time required for the server 102 to re-encrypt each active node in the group A 206. Re-encrypting each active node can include updating group A 206 Every job within KEK 104 on the moving node. As previously explained, the minimum update period 240 can be determined by dividing the estimated value of the active nodes in the group A 206 by the amount representing the additional update request per unit of time.
The fifth figure is a flowchart illustrating an embodiment of a method 500 for determining whether a node can connect to a node group. In one embodiment, the method 500 may be implemented by an individual node belonging to the group. A request to connect to the node group can be received (502). The request may include a parameter determined by a KEK. It is determined whether the parameters included in the request are generated by the KEK 104 associated with each node in the group (504). For example, node A 108 may receive a request from node N 116 for node N 116 to become a member of group A 106 (502). The request may include a parameter determined by a KEK. Node A 108 may determine (504) whether the KEK associated with the request matches the KEK 104 associated with node A 108. If it is determined (504) that the KEK associated with the request does not match the KEK 104 associated with node A 108, or if node N 116 does not own a KEK, then method 500 ends. If it is determined (504) that the KEKs match, a group key 114 is allocated (506) to the node N 116. In one embodiment, the group key 114 allows a node to receive security data from other nodes belonging to the group. The group key can also allow a node to safely transmit data to other nodes in the group.
The sixth figure is a flowchart illustrating an embodiment of a method 600 for notifying additional nodes in a group of changes to KEK. In one embodiment, the method 600 is implemented by a single node. In another embodiment, the method 600 is implemented by a small node group.
A minimum check period can be used to send (602) an update request to a server 102. The update request may include The query of KEK 104 changes. The server 102 may include an authentication server. The server 102 can respond to the request. In one embodiment, the response includes the KEK 104 associated with the group identified by the node that sent the request. It is determined (604) whether the KEK 104 included in the response matches the KEK 104 on the node. If the KEKs match (604), the node continues to transmit (602) another update request after the minimum check period 344 has elapsed. If the KEKs do not match (604), the KEK 104 on the node is updated (606) to match the KEK 104 on the server 102. In one embodiment, the server 102 may periodically change the KEK 104 to protect the integrity of the node group. An update KEK can be notified to the group broadcast (608) to one or more nodes in the group. In one embodiment, the notification is multicast to the group from the node that sends (602) the update request to the server 102. The notification may also include a minimum update period 240. In one embodiment, the node or nodes may send an update request to the server 102 after receiving the notification. These update requests can be transmitted within the minimum update period 240.
The seventh diagram is a block diagram of hardware components in a node or server 702 that can be configured according to an embodiment. The node or server 702 can be embodied in an embedded device/computing device; in turn, it can be designated as the embedded device/computing device 702. A central processing unit (CPU) 704 or processor may be provided to control the operation of the embedded device 702 (including other elements coupled to the CPU 704 via a bus 710). The CPU 704 can be implemented as a microprocessor, microcontroller, digital signal processor, or other device known in the art. The CPU 704 executes logic and arithmetic operations based on the code stored in the memory. In some embodiments, the memory 706 may include on-board memory included in the CPU 704. For example, a microcontroller usually includes a certain amount of on-board memory. The embedded device 702 can also include a network interface 708. The network interface 708 facilitates communication between the embedded device 702 and other devices connected to the network 122, which can be a pager network, a cellular network, a global communication network, the Internet, a computer network , Telephone network, etc. The network interface 708 operates in accordance with standard protocols for the applicable network 122.
The embedded device 702 may also include a memory 706. The memory 706 may include random access memory (RAM) for storing temporary data. Alternatively or additionally, the memory 706 may include a read-only memory (ROM) for storing more permanent data (such as fixed codes and configuration data). The memory 706 can also be implemented as a magnetic storage device (such as a hard disk drive). The memory 706 can be any type of electronic device capable of storing electronic information.
The embedded device 702 may also include one or more communication ports 712, which facilitate communication with other devices. The embedded device 702 may also include an input/output device 714 (such as a keyboard, a mouse, a joystick, a touch screen, a display screen, a speaker, a printer, etc.).
Of course, the seventh figure only illustrates one possible configuration of an embedded device 702. It can utilize various other architectures and components.
Any of a variety of different processes and technologies can be used to represent information and signals. For example, the data, instructions, commands, information, signals, bits, symbols, and chips referred to throughout the above description can be represented by voltage, current, electromagnetic waves, magnetic fields or particles, light fields or particles, or any combination thereof.
Various illustrative logic blocks, modules, circuits, and algorithm steps described in conjunction with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, various descriptive components, blocks, modules, circuits, and steps have been listed above The text is usually described in terms of its functionality. Whether this functionality is implemented as hardware or software depends on the specific application and design constraints imposed on the entire system. Skilled artisans can implement the described functionality in varying ways for each specific application, but these implementation determinations should not be construed as causing a departure from the scope of the present invention.
General-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices designed to perform the functions described in this article can be used. Discrete gates or transistors, discrete hardware components, or any combination thereof implement or execute various illustrative logic blocks, modules, and circuits described in conjunction with the embodiments disclosed herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices (for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration ). The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be directly embodied by hardware, a software module executed by a processor, or a combination of the two. A software module can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, scratchpad, hard disk, removable disk, CD-ROM or any known in the art In other forms of storage media. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. In the alternative, the storage medium may be an integral part of the processor. The processor and storage medium may reside in an ASIC. The ASIC can reside in a user terminal. In the alternative, the processor and storage medium can be used as discrete components and reside in a user terminal middle.
The methods disclosed herein include one or more steps or actions for achieving the described methods. These method steps and/or actions can be interchanged with each other without departing from the scope of the present invention. In other words, unless a specific step or sequence of actions is required for proper operation of the embodiment, the order and/or use of specific steps and/or actions can be modified without departing from the scope of the present invention.
Although the specific embodiments and applications of the present invention have been illustrated and described, please understand that the present invention is not limited to the precise configurations and components disclosed herein. Various modifications, changes and changes that will be obvious to those skilled in the art can be made in the configuration, operation and details of the method and system of the present invention disclosed herein without departing from the spirit and scope of the present invention.
<p>102Server</p><p>104Key Exchange Key (KEK)</p><p>106Group A</p><p>108Node A</p><p>110Node B</p><p>112Node C</p><p>114Group A Key</p><p>116Node N</p><p>118Group request</p><p>120KEK request</p><p>122Internet</p><p>202Server</p><p>204KEK</p><p>206Group A</p><p>208Node A</p><p>222Internet</p><p>224Maximum update cycle</p><p>226Request Generator</p><p>228Random Time Picker</p><p>230Size Determiner</p><p>232Re-encryption determiner</p><p>240Minimum update cycle</p><p>302Server</p><p>304KEK</p><p>306Group A</p><p>308node</p><p>314Group A Key</p><p>322Internet</p><p>326Request Generator</p><p>330Size Determiner</p><p>332Re-encryption determiner</p><p>340Minimum update cycle</p><p>342Notification Generator</p><p>344Minimum inspection cycle</p><p>702node or server</p><p>704Central Processing Unit (CPU)</p><p>706Memory</p><p>708Network interface</p><p>710Bus</p><p>712Communication port</p><p>714Input/Output Device</p>
The first figure is a block diagram that illustrates an embodiment of a server that transmits a key exchange key (KEK) to one or more nodes in a group; the second figure is a block diagram that illustrates Another embodiment of a server that communicates with a node group via a network; the third figure is a block diagram, which illustrates the use of a minimum check period to send update requests to a server to check KEK changes An embodiment of a single node; the fourth figure is a flowchart illustrating an embodiment of a method for determining a minimum update period for a group of nodes; the fifth figure is a flowchart illustrating An embodiment of a method for determining whether a node can be connected to a node group; Figure 6 is a flowchart illustrating a method for determining whether a node can be connected to a node group; An embodiment of the method of changing notification of additional nodes in a group; and the block diagram of the hardware components in Fig. 7 which can be used for an embedded device assembled according to an embodiment.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US7007040B1 | Cites | United States of America |
| A secure group key management framework: design and rekey issues^&rn^^&rn^ Ghanem, S.M.; Abdel-Wahab, H.; ^&rn^Computers and Communication, 2003. (ISCC 2003). Proceedings. Eighth IEEE International Symposium on ^&rn^Digital Object Identifier: 10.1109/ISCC.2003.1214215^&rn^Publication Year: 2003 , Page(s): 797 - 802 vol.2 | Non-patent | – |
16 members in 8 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 11624147 | United States of America | – | |
| 62414707 | United States of America | A |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| US2008170692A1 | United States of America | A1 | |
| WO2008088081A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW200840300A | Taiwan Province of China | A | |
| WO2008088081A8 | World Intellectual Property Organization (WIPO) | A8 | |
| KR20090106577A | Republic of Korea | A | |
| EP2122898A1 | European Patent Office (EPO) | A1 | |
| CN101636964A | China | A | |
| JP2010517332A | Japan | A | |
| RU2009131030A | Russian Federation | A | |
| RU2420893C2 | Russian Federation | C2 | |
| US8059819B2 | United States of America | B2 | |
| KR101092291B1 | Republic of Korea | B1 | |
| JP5033189B2 | Japan | B2 | |
| CN101636964B | China | B | |
| EP2122898A4 | European Patent Office (EPO) | A4 | |
| TWI389531BThis record | Taiwan Province of China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- I389531
- Application
- 97101738
Titles2
- English
- SYSTEMS AND METHODS FOR DISTRIBUTING UPDATES FOR A KEY AT A MAXIMUM RE-KEY RATE
- Chinese
- 用以分配金鑰更新的方法、系統及電腦可讀式媒體
Classification
- CPC, 4
- H04L9/0833
- H04L9/08
- H04L9/0891
- H04L9/16
- IPC, 1
- H04L9 16