Cryptographic secret key distribution
Abstract
The present invention relates to cryptographic secret key distribution, wherein a value for a number of iterations can be individually set, so that the number of messages to be exchanged during generating a cryptographic secret key can be varied based on the set value of the iteration number.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
13 claims: 4 independent, 9 dependent
- 1一種用於使用一密碼編譯秘密金鑰(cryptographic secret key)以安全地發射或接收資料的裝置,該裝置包含:一設定單元,該設定單元提供用於設定一反覆次數(iteration number)之一設定功能,其中可個別地設定對應於該反覆次數之一反覆數量(a number of iterations)之一值;及一金鑰產生控制器,該金鑰產生控制器用以控制在產生該密碼編譯秘密金鑰期間待交換之訊息的一數量,其中係基於該反覆次數之一設定值而改變待交換之訊息的該數量,且其中該等訊息包含RSSI(T_rssi)訊息、邊緣讀數(MR)訊息、金鑰材料(KM)訊息或金鑰傳送(KT)訊息。
- 2如請求項1之裝置,其中該設定單元係經配置用以回應於一金鑰建立的一起始而產生或提供該反覆次數。
- 3如請求項1之裝置,其中該設定單元係經配置用以基於在該裝置處的一輸入操作而產生該反覆次數。
- 4如請求項1之裝置,其中該設定單元係經配置用以基於該資料之一類型而產生該反覆次數。
- 5如請求項1之裝置,其中該設定單元係經配置用以接收來自另一發射側的該反覆次數。
- 6如請求項1之裝置,其中該裝置包含一發射器,該發射器係經配置用以發射該反覆次數至另一發射側。
- 7如請求項1之裝置,其進一步包含一記憶體,該記憶體係用以儲存該反覆次數之一值。
- 8如請求項1之裝置,其進一步包含一計數器,該計數器係用於計數在該產生該密碼編譯秘密金鑰期間待交換之訊息的該數量。
- 9如請求項1之裝置,其中該裝置係經配置用以基於自待交換之該數量之訊息獲得的隨機產生數之一組合而產生該密碼編譯秘密金鑰。
- 10如請求項9之裝置,其中該組合為一互斥或(XOR)組合。
- 11一種用於使用一密碼編譯秘密金鑰發射或接收經加密之資料的方法,該方法包含:藉由一設定單元提供用於設定一反覆次數之一設定功能,其中可個別地設定對應於該反覆次數之一反覆數量之一值;藉由一金鑰產生控制器控制在產生該密碼編譯秘密金鑰期間待交換之訊息的一數量,其中係基於該反覆次數之一設定值而改變待交換之訊息的該數量,且其中該等訊息包含RSSI(T_rssi)訊息、邊緣讀數(MR)訊息、金鑰材料(KM)訊息或金鑰傳送(KT)訊息。
- 12一種用於分配一密碼編譯秘密金鑰之系統,該系統包含:至少一第一設備,該至少一第一設備具有如請求項1之裝置以用於發射該反覆次數;及至少一第二設備,該至少一第二設備係用於接收該發射之反覆次數及用於基於該接收之反覆次數而產生該密碼編譯秘密金鑰。
- 13一種包含程式碼之由一電腦程式體現的非暫態電腦可讀取媒體,該程式碼由一電腦設備在該電腦設備上執行時產生如請求項11之方法之諸步驟。
Independent claims13
121 paragraphs in 1 section, as filed
Cryptographic secret key distribution
CRYPTOGRAPHIC SECRET KEY DISTRIBUTION
The present invention generally relates to the distribution of cryptographic secret keys between a transmitting side and a receiving side.
WO 2007/031089 discloses a method for secure communication in a wireless communication system. In a key generation mode, an access point equipped with an ESPAR antenna forms a beam pattern and sends a packet for measurement. The terminal receives the packet in an omnidirectional pattern and obtains a received signal strength indicator (RSSI) value after averaging to even out the influence of the noise. Then, a regular user uses the omnidirectional pattern to transmit a packet for measurement. The access point receives the packet in the same pattern as the original pattern, and obtains the averaged RSSI value. K different RSSI values are obtained by repeating the measurement of RSSI K times and changing the beam pattern of the access point. Simply set a repeat K according to the length of the key. Next, a threshold value is set for the RSSI value of item K, and if the RSSI value is higher than a threshold value, it becomes 1 and if the RSSI value is lower than the threshold value, it becomes 0. After binarization, the same key is generated at the access point and regular users, and a key agreement can be reached.
In wireless communication systems, secret key cryptography is used because of its processing speed, which can process a large amount of data. Secret key cryptography is sometimes called symmetric cryptography. Private key cryptography is a traditional form of cryptography in which a single key can be used to encrypt and decrypt a message. Secret key cryptography not only handles cryptography, but also handles authentication. One such technology is called Message Authentication Code (MAC). The encryption key and the decryption key have no important relationship, because the encryption key and the decryption key may be the same or a simple change can be made between the two keys. In fact, the key represents a shared secret that can be used between two or more parties to maintain a private information link. One advantage of secret key cryptography is that it is generally faster than public key cryptography.
Other terms for symmetric key encryption are secret key, single key, shared key, single key, and private-key encryption. However, the use of the following term (private key) conflicts with the private key in public key cryptography.
One of the main problems with the secret key encryption system (cryptosystem) is to make the sender and receiver reach an agreement on the secret key, and no one else can find it out. This requires a method by which both the sender and the receiver can communicate without worrying about eavesdropping. Therefore, an important issue is how to achieve the initial key exchange.
A first approach is to use two-way LQI/RSSI (link quality indicator/received signal strength indicator) measurement to evaluate the attenuation variation of the signal path between the two transceivers to establish a relationship between the two nodes Share secrets. Due to the reciprocity theorem of radio wave propagation between two communicating parties, the two communicating parties can calculate common information by using the fluctuating characteristics of the frequency channel. This approach can provide a secret key agreement scheme without any key distribution process. Because this solution can provide a one-time key when needed, it is an excellent method for solving the problems of key distribution and key management.
A second approach is to send a set of random numbers (with low transmit power as needed), and combine them all together (for example, XOR (mutually exclusive or)) to generate a "key". It is impossible for an attacker to hear all the random numbers correctly.
The first approach has an optional variant in which the shared secret established is used to protect a 128-bit random key generated by one of the devices. This helps prevent future attacks on the "random" amount of signal attenuation. In addition, the first approach makes it difficult for the attacker to obtain the key because the attacker's receiver will have a different path attenuation between itself and each of the targets. Therefore, the link quality estimate (LQI, usually evaluated as received signal strength indicator, RSSI) evaluated in each direction between two nodes will be strongly correlated, and the correlation with the LQI/RSSI of a third node is usually Extremely weak.
The second approach makes it difficult for an attacker to obtain the key because the attacker will have to have a radio receiving device very close and the radio receiving device will be specifically configured to monitor the correct channel during installation. However, one of the risks of the second method (combining multiple keys) is that an attacker may keep a monitoring device running (possibly using a high-quality receiver). The attacker can then travel through the log file, and if he is lucky, he may receive all the key establishment information. This can be mitigated by launching with low transmit power as needed, hoping to reduce the risk of attack to the extent that manufacturers are willing to use it to deploy products.
However, both of these two approaches have a weakness in that they require many transactions to generate a key that is strong enough for all situations. For example, the first proposal may require the exchange of 300 messages to provide 128-bit security. This is excessive for many applications. A specific example of an application where this situation does not apply is an energy scavenging device. Devices (such as light switches) become capable of generating enough power by the action of pressing the switch to enable their transceivers and microprocessors for a short period of time. This period may not be enough to exchange tens or hundreds of messages.
Delay is also an important consideration; if a user presses a key and nothing happens within three seconds, for example, he can press another button. This may be more important for devices that need to frequently join a network (which may include point-of-sale applications).
Conversely, higher requirements for security require more messages to be sent to reduce the possibility of an attacker's success. The conflicting requirements of higher safety and low operating power/delay cannot be fully satisfied by the available systems.
One objective of the present invention is to provide an enhanced cryptographic secret key distribution scheme, which provides flexibility in terms of the conflicting requirements mentioned above. The present invention is defined by independent technical solutions. The ancillary technical solutions define advantageous embodiments. The present invention provides a system for transmitting or receiving encrypted data using a cryptographic secret key, wherein a setting function is provided to set a number of repetitions; and based on the number of repetitions, it is controlled to wait during the generation of the cryptographic secret key. Several messages exchanged.
Correspondingly, one or both of nodes, devices, transmitters, or transmitters can change, determine, or affect the number of messages transmitted during the generation of a cryptographic secret key. This makes the present invention more suitable for needs than the prior art of WO 2007/031089 (according to WO 2007/031089 iteratively is simply set according to the key length).
In the present invention, the term "setting unit" should be understood in the background content of the application text. This means that the setting unit can be any unit or functionality that effectively sets the number of iterations. It can be implemented in many ways, for example, by autonomously setting the number of repetitions (for example, by generating a number in a specific range (for example, a (pseudo) random number)); by reading a predetermined number; and /Or set the number of repetitions based on an external input (for example, by receiving a repetition number from another device).
According to a first embodiment, the number of repetitions can be provided or generated in response to the initial creation of a key. Therefore, a quick start of the key generation process can be ensured.
According to a second embodiment that can be combined with the first embodiment, the number of repetitions can be generated based on an input operation provided at the key generating device. The flexibility provided by this option to a user is that security and delay can be individually controlled based on application requirements, for example.
According to a third embodiment that can be combined with at least one of the first embodiment and the second embodiment, the number of repetitions can be generated based on a type of encrypted data. Therefore, the security and/or delay can be automatically controlled based on the requirements of the type of encrypted data.
According to a fourth embodiment that can be combined with at least one of the first to third embodiments, the number of iterations can be received from the other transmitting side. According to a fifth embodiment that can be combined with at least one of the first to fourth embodiments, the number of iterations can be transmitted to the other transmitting side. In this way, it can be ensured that both transmitting sides use the same amount of messages to generate the key.
According to a sixth embodiment that can be combined with at least one of the first to fifth embodiments, a memory can be provided to store the repetition value. This ensures that the repetition value remains available and will not be lost after being received.
According to a seventh embodiment that can be combined with at least one of the first to sixth embodiments, a counter can be provided to count the number of messages to be exchanged during the generation of the cryptographic secret key.
According to an eighth embodiment that can be combined with at least one of the first to seventh embodiments, the cryptographic secret key can be generated based on the recorded received signal strength indicator value obtained from the number of messages to be exchanged.
According to a ninth embodiment that can be combined with at least one of the first to eighth embodiments, a cryptographic secret key can be generated based on a combination of a random number obtained from the number of messages to be exchanged. According to a specific implementation example, the combination may be a logical exclusive OR (XOR) combination.
According to a tenth embodiment that can be combined with at least one of the first to ninth embodiments, a cryptographic secret key can be generated based on transmitting a subsequent cryptographic secret key protected with a previous cryptographic secret key, and The previous cryptographic secret key and the subsequent cryptographic secret key are transmitted by using the amount of messages to be exchanged. In an advantageous modification of the tenth embodiment, the cryptographic secret key can be transmitted on more than one transmission channel, thereby further enhancing the security of the key exchange.
According to an eleventh implementation that can be combined with at least one of the first to tenth implementations, the device can be configured to: concatenate several bits of the cryptographic secret key into a group; compare each Groups and a set of sample symbols; classify the groups according to which sample symbol is the closest matching sample symbol; and reject groups that cannot be reliably classified as higher than a predetermined threshold. In this way, a small number of bit errors caused by noise can be avoided, and a shared secret can be better extracted from the shared data set.
These and other aspects of the present invention will be clarified with reference to the embodiments described below, based on which a deeper understanding can be obtained.
In the following, various embodiments of the present invention are described based on a key distribution between a remote control device and a TV device.
The embodiments are aimed at modifying either or both of the two initially described methods (and/or variants thereof) to allow one or both of the participating nodes to change the number of messages delivered. However, the present invention is not limited to these methods and can be applied to any key distribution mechanism.
As an example of implementation, a TV remote controller powered by a small solar panel may allow the exchange of, for example, up to 5 messages during key establishment. This will provide lower security than a typical device, but will allow the exchange to be completed before the power runs out.
As an example of a further implementation, a TV and a digital versatile disc (DVD) player that establish a security relationship may exchange, for example, 1,000 messages, because power efficiency is less important, and the resistance to a security compromise may be greater. important.
An implementation based on a wireless protocol can define the effective value range of the N messages to be transmitted. The typical value of N can be between 0 and 1000.
For the first approach based on RSSI above, setting N=0 will cause the "shared secret" to be NULL. Using this shared secret to send a 128-bit key is equivalent to sending the key explicitly.
For the second method based on XOR, setting N=1 is functionally equivalent to sending the key explicitly.
The first embodiment is directed to an implementation that uses RSSI to generate a shared secret.
FIG. 1 shows a signaling diagram of an RSSI-based key establishment mechanism according to a first embodiment. A first node or device A (such as a remote controller) initiates communication with a second node or device B (such as a TV). Allow each device to implement a key exchange protocol through some user interaction. For example, a user presses a button on the second device B and then presses a button on the first device A, or vice versa. In a first step, the first device A sends an initial message INI (including an indication of the number N of messages exchanged). Then, in a second step, the second device B sends an acknowledgement Ack, and in a third step, the first device A sends a test RSSI message T_rssi without any payload. In a fourth step, the second device B records the RSSI of the received test RSSI message T_rssi received from the first device A and sends an acknowledgement Ack. In a fifth step, the second device B sends a test RSSI message T_rssi without any payload. In a sixth step, the first device A records the RSSI of the received test RSSI message T_rssi and sends an acknowledgement Ack. Then, after a short delay D, repeat the third to sixth steps until each node has sent and received N messages.
Readings above a predetermined threshold T are classified as "1", and readings below the threshold T are classified as "0". Next, identify the "edge" RSSI reading and create a one-bit field of edge bits. In a seventh step, the first device A constructs and sends an edge reading message MR of the bit field containing the edge bit. In an eighth step, the second device B sends an acknowledgement Ack. Then, in a ninth step, the second device B constructs and sends an edge reading message MR containing a bit field of the edge bit. In a final tenth step, the first device A sends an acknowledgement Ack.
Now, both devices A and B combine the two bit fields of the marginal bit by, for example, a logical OR (OR) combination, and both devices reject all RSSI samples that are considered marginal. Concatenating the remaining non-marginal bits is a shared secret. If necessary, the shared secret can be used to transmit a random number from the first device A to the second device B. The key can be confirmed according to other key exchange algorithms.
If the message is not received as expected, the transmitter may time out and abort the processing procedure, and the user may need to try again later.
The feasible frame format for the above message exchange can be configured as follows: Format of the initial message INI:
<img file="TWI491237B_D0001.tif" he="280" id="i0001" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="2011" />
The format of the acknowledgement message Ack:
<img file="TWI491237B_D0002.tif" he="257" id="i0002" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="1396" />
Format of test RSSI message T_rssi:
<img file="TWI491237B_D0003.tif" he="252" id="i0003" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="1355" />
Format of marginal bit message:
<img file="TWI491237B_D0004.tif" he="298" id="i0004" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="2076" />
After the short delay D, both devices A and B have a set of RSSI values. The two sets of RSSI values are related, but generally not the same, as illustrated below.
FIG. 2 shows a schematic diagram indicating typical RSSI values received at different transmitting sides (for example, at devices A and B). Each RSSI sample is classified as "1" (if higher than the threshold T) and classified as "0" (if lower than the threshold T). The samples in the edge region MR are marked as "edge". These labeled RSSI samples are depicted as hatched circles, while the black circles indicate the RSSI samples received at the second device B, and the white circles indicate the RSSI samples received at the first device A. The agreement rejects all samples marked as marginal by either device A or B. In the above example of FIG. 2, both device A and device B have reached an agreement on all non-rejected samples, and they have a common secret with a value of "0b110".
It should be noted that multiple other algorithms can be used to extract a common secret from two related data sets. The above is given as a simple example.
Another example can be the use of signal changes, for example: 1=becomes stronger, 0=becomes weaker. Some algorithms can extract more than one data bit from each message exchanged, for example, by having three threshold lines between high, high, low, and bottom levels. A further algorithm that can be applied includes concatenating a number of bits into groups, and comparing each group with a set of sample "symbols". The group can be classified according to which sample symbol is the closest matching sample symbol. Groups with edge classification on either side (that is, groups that cannot be classified as being above a predetermined threshold with certainty) are rejected by both sides in a manner similar to bit classification. This helps to avoid a small number of bit errors caused by noise, and allows a shared secret to be extracted more effectively from the shared data set.
These and other algorithms will also benefit from the ability to change the number N of messages exchanged in the same way.
FIG. 3 shows a signal diagram of one of multiple keys using subsequent combination (such as XOR) to be transmitted according to a second embodiment. In the second embodiment, a first device A (such as a remote control device) initiates communication with a second device B (such as a TV). Each device is allowed to implement a key exchange protocol through some user interaction (for example, the user presses a button on the second device B, and then presses a button on the first device A, or vice versa).
In a first step, the first device A sends an initial message INI (including an indication of the number N of messages exchanged). Then, in a second step, the second device B sends an acknowledgement Ack. In a third step, the first device A generates a 128-bit random number, constructs a key material message KM containing the 128-bit random number, and sends the key material message KM to the second device B (as required Use one to reduce the transmit power). In a fourth step, the second device B records the random number in the message received from the first device A and sends an acknowledgement Ack. Repeat the third and fourth steps until the first device A has sent N messages.
Then, devices A and B sequentially combine a number "0" with each random number sent and received in a logical XOR manner. Therefore, the two devices A and B now share a common secret. Then, the obtained key can be confirmed according to other key exchange algorithms.
If a device does not receive an acknowledgement Ack for a given frame, it can retry, for example, according to a media access control (MAC) protocol. If all retries of any frame fail, the transmitter can abort the processing procedure and the receiver may eventually time out and also abort the processing procedure. The user can try again later.
The feasible frame format for the above message exchange can be configured as follows: Format of the initial message INI:
<img file="TWI491237B_D0005.tif" he="268" id="i0005" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="2021" />
The format of the acknowledgement message Ack:
<img file="TWI491237B_D0006.tif" he="268" id="i0006" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="1370" />
Format of key material message KM:
<img file="TWI491237B_D0007.tif" he="280" id="i0007" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="2021" />
The above procedure of the second embodiment can be modified in that an initial key is explicitly sent, and after that, the next key is sent under the protection of the previous key. Repeat this a fixed number of times or a variable number of times. Again, an attacker who missed any single message will not be able to obtain the final key.
As a further modification, the channel can be changed between the transmission of the separate key. This makes it more difficult for an attacker to capture all the necessary keys when they are equipped with only a simple radio monitor device, because these transmissions usually operate on a single channel.
4 shows a signalling diagram of transmitting a key protected with a previous key on more than one channel according to a third embodiment. Third, a first device A (such as a remote controller) initiates communication with a second device B (such as a TV). Allow each of devices A and B to achieve a gold through some user interaction (for example, the user presses a button on the second device B, and then presses a button on the first device A, or vice versa) Key exchange agreement.
In a first step, the first device A sends an initial message INI (including an indication of the number N of messages exchanged). Then, in a second step, the second device B sends an acknowledgement Ack. In a third step, the first device A generates a 128-bit random key k<sub>n</sub>, Randomly select a new channel, construct the key k<sub>n</sub>And a key of the number ch1 of the new channel to send the message KT, and send the message to the second device B (if necessary, use a reduced transmission power). Then it waits for an Ack and switches to the new channel.
In a fourth step, the second device B records the key in the message received from the first device A, sends an acknowledgement Ack, and switches to the new channel. In a fifth step, the first device A generates another 128-bit random key, randomly selects another new channel, constructs a key containing the key and the number ch2 of the new channel to send the message KT, and uses The previously transmitted key protects the message, and sends the message to the second device B (use a reduced transmit power if necessary). Then the first device A waits for an acknowledgement Ack and switches to the new channel.
In a sixth step, the second device B sends an acknowledgement Ack and then checks whether the received command is properly protected. If the received command is properly protected, the second device B removes security from the message and then extracts a new key from the message and records the new key. Then the second device B switches to the new channel.
Repeat the fifth and sixth steps until the first device A has sent N key transmission messages. The current key can be confirmed according to other key exchange algorithms and used for future communications. If a device does not receive an acknowledgement Ack for a given frame, it can retry according to the MAC protocol. If all retries of any frame fail, the transmitter can abort the processing procedure and the receiver may eventually time out and also abort the processing procedure. The user can try again later.
The feasible frame format for the above message exchange can be configured as follows: Format of the initial message INI:
<img file="TWI491237B_D0008.tif" he="269" id="i0008" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="2015" />
The format of the acknowledgement message Ack:
<img file="TWI491237B_D0009.tif" he="270" id="i0009" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="1376" />
Format of key transmission message KT:
<img file="TWI491237B_D0010.tif" he="480" id="i0010" img-content="drawing" img-format="tif" inline="yes" orientation="portrait" wi="1980" />
Other implementation plan changes are feasible. For example, the channel can be changed according to a certain pre-configured schedule (such as a continuous channel or a pseudo-random sequence).
In addition, key confirmation can be achieved by sending a message protected by the key between two devices A and B and checking whether the message from the other is properly protected after receiving.
FIG. 5 is a schematic block diagram of a television (TV) device in which one of the key distribution systems of the embodiments of the present invention can be implemented. The TV device includes a screen or display (such as a liquid crystal display (LCD) or the like) 10, a display driver 11, a front panel keypad 12 with a number of control buttons, other audio and video inputs 14, a tuner 15, A power supply 16, a volatile memory (such as random access memory (RAM)) 17, a non-volatile memory (such as flash memory) 18, a central processing unit (CPU) 19, and an antenna 21 is connected to a transceiver 20. An interconnection between the above various components is achieved by a communication line (such as a system bus) 13.
In operation, media data is accessed via the tuner 15 and other audio/video inputs 14. The media data is output to the display 10 via the display driver 11. The interface between the display 10 and the display driver 11 can also be used for the control and configuration of TV settings. The CPU 19 executes control software and can provide the mechanism of the embodiments of the present invention. The transceiver 20 may perform, for example, the IEEE 802.15.4 MAC protocol. It can also implement the IEEE 802.15.4 PHY layer protocol. The front panel keypad 12 may have a button as mentioned in the embodiment of initial key establishment. Memory 17 and 18 can be used to store control software and can also be used to implement IEEE 802.15.4 stacking.
6 is a schematic block diagram of a remote control device of the key distribution system in which the embodiments of the present invention can be implemented.
The remote control device includes a keypad 22 with a number of control buttons, a power supply 24, a volatile memory (such as random access memory (RAM)) 25, and a non-volatile memory (such as flash). Memory) 26, a central processing unit (CPU) 27, and a transceiver 28 to which an antenna 29 is connected. An interconnection between the above various components is achieved by a communication line (such as a system bus) 23.
The keypad 22 represents buttons that the user can press. It may include a button for initiating key creation, as described in the embodiments of the present invention. The CPU 27 executes control software and can provide the mechanism of the embodiments of the present invention. The transceiver 28 can perform the IEEE 802.15.4 MAC protocol. It can also implement the protocol 802.15.4 PHY layer protocol. The memories 25 and 26 can be used to store control software and can also be used to implement IEEE 802.15.4 stacking.
FIG. 7 is a schematic block diagram of a hardware implementation of an RSSI-based random number generation system at two transmitting ends according to a fourth embodiment. The blocks depicted in FIG. 7 can be implemented as discrete hardware circuits implemented in a module, configured on a circuit board, or integrated on a single or multiple chip device. A control logic (CTRL) 33 that can be implemented as a software-controlled CPU or as a discrete logic circuit can access a counter (C) 30 and a memory (MEM) 31, and can be controlled by a start button ( IB)32. The control logic 33 stores the transmission value of the allowed number of repetitions N in the memory 31 and controls the counter 30 to count the number of messages received or transmitted during the key establishment period. Based on the comparison between the count value at the counter 30 and the value of the number N stored in the memory 31, the control logic 33 can determine when the allowable number of iterations has been reached. In addition, the control logic 33 controls an RSSI classification circuit or block (RSSI-C) 34 and a key generation circuit or block (KG) 35 that receives information from the RSSI classification block 34. The input/output signal is received/transmitted via a transceiver (TRX) 36 and an antenna 38. An RSSI measurement circuit or block (RSSI-M) 37 receives RSSI samples from the transceiver 36, measures the samples, and forwards the measurement results to the RSSI classification block 34. The RSSI classification block 34 compares the RSSI samples received by the transceiver with a predetermined threshold value T. The RSSI classification block 34 classifies the measurement results, similar to those described above in conjunction with FIGS. 1 and 2 program. Based on the classification of the N RSSI samples, the key generation block 35 generates a shared secret.
FIG. 8 shows a flowchart of a key distribution procedure at a remote control side of an RSSI-based key establishment system according to a fifth embodiment. The program of FIG. 8 can be implemented as a software routine for controlling (for example) the CPU 27 of FIG. 6.
In step S100, the start button for key establishment on the remote control device is pressed. Then, in step S101, a value of the number of repetitions or the number of messages N used to generate the encryption key or the secret key is selected. This can be achieved based on the type of data to be encrypted (for example, the specific application of protected transmission), or the setting of a separate user, manufacturer, or operator. In step S102, an initial message including the selected value of the number N is sent to a TV to be controlled by the remote control device, and then the remote control device waits for an approval from the TV. In the subsequent step S103, the remote control device sends a test RSSI (for example, "T_rssi" in FIG. 1) message to the controlled TV and waits for an approval. Then, in step S104, the remote control device waits for a test RSSI message from the controlled TV. Thereafter, in step S105, the remote control device records the received RSSI samples and sends an approval. After a short delay in step S106, in step S107, the remote control device checks whether the signaled N messages have been received. If N messages have not been received, the procedure jumps back to step S103 to send the next test RSSI message. Otherwise, if N messages have been received, the recorded RSSI samples or values are classified and edge bits are identified in step S108. Then, in step S109, send an edge reading message to the controlled TV and wait for an approval. In the subsequent step S110, the remote control device waits for an edge reading message from the controlled TV and sends an approval after receiving the edge reading message. In step S111, OR combine the edge bit fields and reject all edge bits. In addition, the remaining non-marginal bits are concatenated to form a shared secret. In step S112, a random key is generated, the random key is protected by using the shared secret, and the shared secret is sent to the controlled TV. In step S113, the remote control device generates a certain message, uses the random key to protect the message, and sends the message to the controlled TV. Then, in step S114, the remote control device waits for a security message from the controlled TV, and checks whether the security of the received message is good. If it is determined in step S115 that the security is not good, the procedure jumps back to step S102 to send a new initial message. Otherwise, if it is determined that the security is good in step S115, it is concluded that the key establishment is completed in step S116.
FIG. 9 shows a flowchart of a key distribution procedure at a TV side of the RSSI-based key establishment system according to the fifth embodiment. The procedure of FIG. 9 can be implemented as a software routine for controlling (for example) the CPU 19 of FIG. 5.
In step S200, the start button for key establishment at the TV device is pressed. Next, in step S201, the TV device waits for an initiation message from the remote control device, and sends an approval after receiving the initiation message. In step S202, a received value of the number of repetitions or the number of messages N is recorded to set the number of repetitions for key generation. In the subsequent step S203, the TV device waits for a test RSSI message, records an RSSI value after receiving the test RSSI message, and waits for an approval. In step S204, the TV device sends a test RSSI message to the remote control device and waits for an approval. Next, in step S205, the TV device checks whether it has received N signals sent by the signal. If N messages have not been received, the procedure jumps back to step S203 to wait for the next test RSSI message. Otherwise, if N messages have been received, the recorded RSSI samples or values are classified and edge bits are identified in step S206. Then, in step S207, the TV device waits for an edge reading message sent by the remote control device and sends an approval after receiving the edge reading message. In the subsequent step S208, the TV device sends an edge reading message to the remote control device and waits for an approval. In step S209, OR combine the edge bit fields and reject all edge bits. In addition, the remaining non-marginal bits are concatenated to form a shared secret. In step S210, the TV device waits for a message protected by the shared secret from the remote controller, removes the security, and records the transmitted key. In step S211, the TV device waits for a message protected by the recorded key from the remote control device, and checks whether the security of the received message is good. If it is determined in step S212 that the security is not good, the procedure jumps back to step S201 to wait for a new start message. Otherwise, if it is determined that the security is good in step S212, the TV device generates a certain message in step S213, uses the recorded key to protect the message, and sends the message to the remote control device. Then, in step S214, it is concluded that the key establishment is completed.
10 is a schematic block diagram of a hardware implementation of a multiple key combination system at a remote control side according to a sixth embodiment. The blocks depicted in FIG. 10 can be implemented as discrete hardware circuits implemented in a module, configured on a circuit board, or integrated on a single or multiple chip device. A control logic (CTRL) 43 that can be implemented as a software-controlled CPU or as a discrete logic circuit can access a counter (C) 40 and a memory (MEM) 41, and can be controlled by a start button (IB ) 42. The control logic 43 stores the transmission value of the allowed number of repetitions N in the memory 41 and controls the counter 40 to count the number of messages received or transmitted during the key establishment period. Based on the comparison between the count value at the counter 40 and the value of the number N stored in the memory 41, the control logic 43 can determine when the allowable number of iterations has been reached. In addition, the control logic 43 controls a random number generation circuit or block (RNG) 44, a key storage or key memory (KMEM) 45 for key building materials, and an XOR combination circuit for key generation Or box 47. The input/output signal is received/transmitted via a transceiver (TRX) 46 and an antenna 48. The random number generating block 44 generates random numbers and supplies the random numbers to the transceiver 46 for transmission to the controlled TV equipment. The generated and signaled random numbers are memorized or recorded in the key memory 45 and XOR combined at the XOR combination block 47 to generate a shared secret.
11 is a schematic block diagram of a hardware implementation of the multiple key combination system at a TV side according to the sixth embodiment. The blocks depicted in FIG. 11 can be implemented as discrete hardware circuits implemented in a module, configured on a circuit board, or integrated on a single or multiple chip device. A control logic (CTRL) 53 that can be implemented as a software-controlled CPU or as a discrete logic circuit can access a counter (C) 50 and a memory (MEM) 51, and can be controlled by a start button (IB )52. The control logic 53 stores the received value of the allowable number of iterations N in the memory 51 and controls the counter 50 to count the number of messages received or transmitted during the key establishment period. Based on the comparison of the count value at the counter 50 and the value of the number N stored in the memory 51, the control logic 53 can determine when the allowable number of iterations has been reached. In addition, the control logic 53 controls a key storage or key memory (KMEM) 55 used for key building materials and an XOR combination circuit or block 57 used for key generation. The input/output signal is received/transmitted via a transceiver (TRX) 56 and an antenna 58. The random number received by the transceiver 56 from the remote control device is memorized or recorded in the key memory 55 and XOR combined at the XOR combination block 57 to generate a shared secret.
FIG. 12 shows a flowchart of a key distribution procedure at a remote control side of a multiple key combination system according to a seventh embodiment. The program of FIG. 12 can be implemented as a software routine for controlling (for example) the CPU 27 of FIG. 6.
In step S300, the start button for key establishment on the remote control device is pressed. Then, in step S301, a value of the number of repetitions or the number of messages N used to generate the encryption key or the secret key is selected. This can be achieved based on the type of data to be encrypted (for example, the specific application of protected transmission), or the setting of a separate user, manufacturer, or operator. In step S302, an initial message including the selected value of the number N is sent to a TV to be controlled by the remote control device, and then the remote control device waits for an approval from the TV. In the subsequent step S303, the remote control device generates a 128-bit random number, and in step S304 sends the random number in a key material message to the controlled TV and waits for an approval. Next, in step S305, the remote control device checks whether the signaled N messages have been transmitted. If N messages have not been transmitted, the procedure jumps back to step S303 to generate a new random number. Otherwise, if N messages have been transmitted, in step S306, the transmitted random numbers are XOR combined to form a shared secret key. In step S307, the remote control device generates a certain message, uses the generated key to protect the message, and sends the message to the controlled TV. Then, in step S308, the remote control device waits for a security message from the controlled TV, and checks whether the security of the received message is good. If it is determined in step S309 that the security is not good, the procedure jumps back to step S302 to send a new initial message. Otherwise, if it is determined that the security is good in step S309, it is concluded that the key establishment is completed in step S310.
FIG. 13 shows a flowchart of a key distribution procedure at a TV side of the multiple key combination system according to the seventh embodiment. The procedure of FIG. 13 can be implemented as a software routine for controlling (for example) the CPU 19 of FIG. 5.
In step S400, the start button for key establishment at the TV device is pressed. Next, in step S401, the TV device waits for an initial message from the remote control device. In step S402, a received value of the number of repetitions or the number of messages N is recorded to set the number of repetitions for key generation. In the subsequent step S403, the TV device waits for a key material message from the remote control device, and sends an approval after receiving the key material message. Next, in step S404, the TV device records a 128-bit random number received from the remote control device. In step S405, the TV device checks whether it has received N signaled messages. If N messages have not been received, the procedure jumps back to step S403 to wait for the next new key material message. Otherwise, if N messages have been received, the received random numbers are XOR combined to form a shared secret key in step S406. In step S407, the TV device waits for a security message protected by the generated key from the remote control device, and checks whether the security of the received message is good. If it is determined in step S408 that the security is not good, the procedure jumps back to step S401 to wait for a new start message. Otherwise, if it is determined that the security is good in step S408, the TV device generates a certain message in step S409, uses the generated key to protect the message, and sends the message to the remote control device. Then, in step S410, it is concluded that the key establishment is completed.
14 is a schematic block diagram of a hardware implementation of a protected multi-channel multi-key transmission system at a remote control side according to an eighth embodiment. The blocks depicted in FIG. 14 can be implemented as discrete hardware circuits implemented in a module, configured on a circuit board, or integrated on a single or multiple chip device. A control logic (CTRL) 73 that can be implemented as a software-controlled CPU or as a discrete logic circuit can access a counter (C) 70 and a memory (MEM) 71, and can be controlled by a start button (IB ) 72. The control logic 73 stores the transmission value of the allowed number of repetitions N in the memory 71 and controls the counter 70 to count the number of messages received or transmitted during the key establishment period. Based on the comparison of the count value at the counter 70 with the value of the number N stored in the memory 71, the control logic 73 can determine when the allowable number of iterations has been reached. In addition, the control logic 73 controls a random number generating circuit or block (RNG) 74 and a working key storage or working key memory (WKMEM) 75 for a working key. The input/output signal is received/transmitted via a transceiver (TRX) 76 and an antenna 78. The random number generation block 74 generates random numbers and supplies the random numbers to the transceiver 76 for transmission to the controlled TV equipment. The generated and signaled random number is memorized or recorded in the working key memory 75 to generate a shared secret. In addition, the control logic 73 controls a channel changing circuit or block 77, which controls the channel used by the transceiver 76 to transmit/receive output/input signals.
15 is a schematic block diagram of a hardware implementation of the protected multi-channel multi-key transmission system at a TV side according to the eighth embodiment. The blocks depicted in FIG. 15 can be implemented as discrete hardware circuits implemented in a module, configured on a circuit board, or integrated on a single or multiple chip device. A control logic (CTRL) 83 that can be implemented as a software-controlled CPU or as a discrete logic circuit can access a counter (C) 80 and a memory (MEM) 81, and can be controlled by a start button (IB ) 82. The control logic 83 stores the received value of the allowed number of iterations N in the memory 81 and controls the counter 80 to count the number of messages received or transmitted during the key establishment period. Based on the comparison of the count value at the counter 80 with the value of the number N stored in the memory 81, the control logic 83 can determine when the allowable number of iterations has been reached. In addition, the control logic 83 controls a key storage or key memory (WKMEM) 85 for a working key. The input/output signal is received/transmitted via a transceiver (TRX) 86 and an antenna 88. The random number or key received by the transceiver 86 from the remote control device is memorized or recorded in the working key memory 85 to generate a shared secret. In addition, the control logic 83 controls a channel changing circuit or block 87 that controls the channel used by the transceiver 86 to transmit/receive output/input signals.
16 shows a flowchart of a key distribution procedure at a remote control side of a protected multi-channel multi-key transmission system according to a ninth embodiment. The program of FIG. 16 can be implemented as a software routine for controlling (for example) the CPU 27 of FIG. 6.
In step S500, the start button for key establishment on the remote control device is pressed. Then, in step S501, a value of the number of repetitions or the number of messages N used to generate the encryption key or the secret key is selected. This can be achieved based on the type of data to be encrypted (for example, the specific application of protected transmission), or the setting of a separate user, manufacturer, or operator. In step S502, an initial message including the selected value of the number N is sent to a TV to be controlled by the remote control device, and then the remote control device waits for an approval from the TV. In the subsequent step S503, the remote control device generates a 128-bit random number, and in step S504, the remote control device generates a random channel number. Then, in step S505, the remote control device sends a key transmission message protected by a working key to the controlled TV and waits for an approval. In the next step S506, the remote control device changes to the previously selected new channel. In step S507, the remote control device sets the work key to the value or pattern of the received random number, and then checks in step S508 whether N messages to be signaled have been transmitted. If N messages have not been transmitted, the procedure jumps back to step S503 to generate a new random number. Otherwise, if N messages have been transmitted, the working key is stored as a key shared with this TV in step S509. Then, in step S510, the remote control device generates a certain message, uses the stored key to protect the message, and sends the message to the controlled TV. Then, in step S511, the remote control device waits for a security message from the controlled TV, and checks whether the security of the received message is good. If it is determined in step S512 that the security is not good, the procedure jumps back to step S502 to send a new initial message. Otherwise, if it is determined that the security is good in step S512, it is concluded that the key establishment is completed in step S513.
FIG. 17 shows a flowchart of a key distribution procedure at a TV side of the protected multi-channel multi-key transmission system according to the ninth embodiment. The procedure of FIG. 17 can be implemented as a software routine for controlling (for example) the CPU 19 of FIG. 5.
In step S600, the start button for key establishment at the TV device is pressed. Next, in step S601, the TV device waits for an initial message from the remote control device. In step S602, a received value of the number of repetitions or the number of messages N is recorded to set the number of repetitions for key generation. In the subsequent step S603, the TV device waits for a key transmission message from the remote control device, sends an approval after receiving the key transmission message, and removes security from the received message. Then, in step S604, the TV device records a 128-bit random number extracted from the received message, and in step S605, the TV device records a channel number extracted from the received message. Next, in step S606, the TV device changes to the new channel signaled from the remote control device, and sets the working key to the value of the transmitted random number in step S607. In step S608, the TV device checks whether it has received N signaled messages. If N messages have not been received, the procedure jumps back to step S603 to wait for a new key to send a message. Otherwise, if N messages have been received, the working key is stored as the key shared with the remote control device in step S609. In step S610, the TV device waits for a security message protected by the stored key from the remote control device, and checks whether the security of the received message is good. If it is determined that the security is not good in step S611, the procedure jumps back to step S601 to wait for a new start message. Otherwise, if the security is determined to be good in step S611, the TV device generates a certain message in step S612, uses the stored key to protect the message, and sends the message to the remote control device. Then, in step S613, it is concluded that the key establishment is completed.
In summary, an apparatus and a method for performing cryptographic secret key distribution have been described, in which a value of the number of iterations can be individually set, so that it can be changed based on the set value of the number of iterations when generating a cryptographic secret. The number of messages to be exchanged during the key period.
It should be noted that the present invention is not limited to the above embodiments and can be used in any key distribution scheme in any type of application (not only between a remote control device and a TV device) to provide a link between devices in the network. Secure transmission mechanism. Key management can be kept simple and transparent-thus minimizing the impact on user experience.
In an LQI-based modification of the above RSSI-based embodiment, for example, a dummy packet exchanged on a wireless or radio frequency (RF) link after the proposed signalling number of repetitions N can generate the same on both devices Key. Exchange (minimum data) approved packets between devices, and measure the link quality for each packet exchange. The key can be generated from the change of LQI over time. Changes in link quality over time can be "enhanced" by moving at least one of the nodes or by changing the physical environment between two devices.
From the study of the schema, the disclosure content, and the scope of the attached patent application, those familiar with the technology can understand and implement changes to the disclosed embodiments. In the scope of patent application, the word "include" does not exclude other elements or steps, and the indefinite article "a" or "one" does not exclude plural elements or steps. A single processor or other unit can implement the functions of FIGS. 7-17 and several items described in the scope of the patent application. The mere fact that certain measures are described in mutually different subsidiary claims does not indicate that a combination of these measures cannot be used to advantage. A computer program for controlling a processor to perform the claimed method features is stored/distributed on an appropriate medium, such as an optical storage medium or a solid-state medium supplied with or as part of other hardware , But can also be distributed in other forms, such as via the Internet or other wired or wireless telecommunication systems. Any reference signs in the scope of the patent application should not be construed as limiting its scope.
<p>10. . . Display/screen</p><p>11. . . Display driver</p><p>12. . . Front panel keypad</p><p>13. . . Communication line</p><p>14. . . Other video/audio input</p><p>15. . . tuner</p><p>16. . . Power Supplier</p><p>17. . . Volatile memory</p><p>18. . . Non-volatile memory</p><p>19. . . Central processing unit</p><p>20. . . transceiver</p><p>twenty one. . . antenna</p><p>twenty two. . . Keyboard</p><p>twenty three. . . Communication line</p><p>twenty four. . . Power Supplier</p><p>25. . . Volatile memory</p><p>26. . . Non-volatile memory</p><p>27. . . Central processing unit</p><p>28. . . transceiver</p><p>29. . . antenna</p><p>30. . . counter</p><p>31. . . Memory</p><p>32. . . Start button</p><p>33. . . Control logic</p><p>34. . . RSSI classifies circuits or blocks</p><p>35. . . Key generation circuit or block</p><p>36. . . transceiver</p><p>37. . . RSSI measurement circuit or block</p><p>38. . . antenna</p><p>40. . . counter</p><p>41. . . Memory</p><p>42. . . Start button</p><p>43. . . Control logic</p><p>44. . . Random number generating circuit or block</p><p>45. . . Key Storage/Key Memory</p><p>46. . . transceiver</p><p>47. . . XOR combination circuit or block</p><p>48. . . antenna</p><p>50. . . counter</p><p>51. . . Memory</p><p>52. . . Start button</p><p>53. . . Control logic</p><p>55. . . Key Storage/Key Memory</p><p>56. . . transceiver</p><p>57. . . XOR combination circuit or block</p><p>58. . . antenna</p><p>70. . . counter</p><p>71. . . Memory</p><p>72. . . Start button</p><p>73. . . Control logic</p><p>74. . . Random number generating circuit or block</p><p>75. . . Work Key Storage/Work Key Memory</p><p>76. . . transceiver</p><p>77. . . Channel change circuit or block</p><p>78. . . antenna</p><p>80. . . counter</p><p>81. . . Memory</p><p>82. . . Start button</p><p>83. . . Control logic</p><p>85. . . Key Storage/Key Memory</p><p>86. . . transceiver</p><p>87. . . Channel change circuit or block</p><p>88. . . antenna</p><p>A. . . First device/remote control device</p><p>B. . . Second device/TV</p>
Fig. 1 shows a signalling diagram based on RSSI random number generation according to a first embodiment;
Figure 2 shows a schematic diagram of a typical RSSI value indicating reception at different transmitting sides;
FIG. 3 shows a signal diagram of transmitting one of multiple keys using subsequent combinations according to a second embodiment;
4 shows a signaling diagram of transmitting a key protected by a previous key on more than one channel according to a third embodiment;
5 shows a schematic block diagram of a television (TV) device in which the key distribution system of one of the embodiments can be implemented;
6 shows a schematic block diagram of a remote control device of the key distribution system in which the embodiments can be implemented;
FIG. 7 shows a schematic block diagram of a hardware implementation of an RSSI-based random number generation system at two transmitting ends according to a fourth embodiment;
FIG. 8 shows a flowchart of a key distribution procedure at a remote control side of an RSSI-based random number generation system according to a fifth embodiment;
9 shows a flowchart of a key distribution procedure at a TV side of the RSSI-based random number generation system according to the fifth embodiment;
10 shows a schematic block diagram of a hardware implementation of a multiple key combination system at a remote control side according to a sixth embodiment;
11 shows a schematic block diagram of a hardware implementation of the multiple key combination system at a TV side according to the sixth embodiment;
12 shows a flowchart of a key distribution procedure at a remote control side of a multiple key combination system according to a seventh embodiment;
FIG. 13 shows a flowchart of a key distribution procedure at a TV side of the multiple key combination system according to the seventh embodiment;
14 is a schematic block diagram of a hardware implementation of a protected multi-channel multi-key transmission system at a remote control side according to an eighth embodiment;
15 is a schematic block diagram of a hardware implementation of the protected multi-channel multi-key transmission system at a TV side according to the eighth embodiment;
16 shows a flowchart of a key distribution procedure at a remote control side of a protected multi-channel multi-key transmission system according to a ninth embodiment;
FIG. 17 shows a flowchart of a key distribution procedure at a TV side of the protected multi-channel multi-key transmission system according to the ninth embodiment.
27 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2006067533A1 | Cites | United States of America | Examiner |
| US5341427A | Cites | United States of America | Examiner |
| US6487660B1 | Cites | United States of America | Examiner |
| US7177424B1 | Cites | United States of America | Examiner |
| US20060067533A1 | Cites | United States of America | – |
21 members in 11 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 081623969 | European Patent Office (EPO) | – | |
| 08162396 | European Patent Office (EPO) | A |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| EP2154814A1 | European Patent Office (EPO) | A1 | |
| WO2010018493A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201025983A | Taiwan Province of China | A | |
| MX2011001574A | Mexico | A | |
| EP2314016A1 | European Patent Office (EPO) | A1 | |
| KR20110056507A | Republic of Korea | A | |
| US2011135088A1 | United States of America | A1 | |
| CN102132520A | China | A | |
| JP2011530924A | Japan | A | |
| RU2011109211A | Russian Federation | A | |
| US8542828B2 | United States of America | B2 | |
| RU2517408C2 | Russian Federation | C2 | |
| TWI491237BThis record | Taiwan Province of China | B | |
| BRPI0912073A2 | Brazil | A2 | |
| KR101576861B1 | Republic of Korea | B1 | |
| EP2314016B1 | European Patent Office (EPO) | B1 | |
| JP2016174419A | Japan | A | |
| PL2314016T3 | Poland | T3 | |
| JP6069778B2 | Japan | B2 | |
| CN102132520B | China | B | |
| BRPI0912073B1 | Brazil | B1 |
Numbers
- Publication
- I491237
- Application
- 98127170
Titles2
- English
- CRYPTOGRAPHIC SECRET KEY DISTRIBUTION
- Chinese
- 密碼編譯祕密金鑰分配
Classification
- CPC, 2
- H04L9/0841
- H04L9/08
- IPC, 1
- H04L9 08