US20090024845A1

Method and system for encryption of messages in land mobile radio systems

Claim Score by NHIP

Read claim 11, the broadest

Abstract

A method and system for authentication of a plurality of sites in a land mobile radio (LMR) system and for encryption of messages exchanged by the sites. The plurality of sites are connected by a data network (e.g., IP network). The method includes transmitting by a first site its certificate. The certificate is created by a trusted authority by applying a selected function to the public key, the ID and other relevant information of the first site with the trusted authority's private key to generate a reduced representation and then encrypting the reduced representation with the trusted authority's private key. The method further includes receiving, by the other sites in the LMR system, the certificate transmitted by the first site. The method further includes decrypting, by the other sites, the certificate transmitted by the first site and authenticating the first site, wherein the certificate is decrypted using the trusted authority's public key. The method further includes generating a session key, encrypting the session key with the public key of the first site, and transmitting the encrypted session key to the first site. The method further includes decrypting, by the first site, the encrypted session key with the first site's private key, and transmitting, by the first site, a message encrypted with the shared session key. The method further includes multicasting the encrypted message over the data network. The method further includes receiving, by the other sites in the LMR system, the encrypted message transmitted by the first site, and decrypting the message with the session key.

US20090024845A1, drawing sheet 1
Sheet 1 of 5

Term

3.6 yearsto projected expiry

Projected expiry 13 April 2030, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

29 claims: 6 independent, 23 dependent

  1. 1
    A method for authentication of a plurality of sites in a land mobile radio (LMR) system and for encryption of messages exchanged by the sites, the plurality of sites being connected by a data network, comprising:transmitting by a first site its certificate, wherein the certificate is created by a trusted authority by encrypting the public key, the ID and other relevant information of the first site with the trusted authority's private key;receiving, by the other sites in the LMR system, the certificate transmitted by the first site;decrypting, by the other sites, the certificate transmitted by the first site and authenticating the first site, wherein the certificate is decrypted using the trusted authority's public key;generating a session key;encrypting the session key with the public key of the first site and transmitting the encrypted session key to the first site;decrypting, by the first site, the encrypted session key with the first site's private key;and transmitting, by the first site, a message encrypted with the session key.
  2. 11
    Broadest claimClaim Score 97, very broad(NHIP)The method according to claim I, wherein the session key is a secret symmetric session key.
  3. 16
    A method for authentication of a plurality of sites in a land mobile radio (LMR) system and for encryption of messages exchanged by the sites, the plurality of sites being connected by a data network, comprising:transmitting by a first site its certificate, wherein the certificate is created by a trusted authority by encrypting the public key of the first site with the trusted authority's private key;receiving, by the other sites in the LMR system, the certificate transmitted by the first site;decrypting, by the other sites, the certificate transmitted by the first site and authenticating the first site, wherein the certificate is decrypted using the trusted authority's public key;generating a session key;encrypting the session key with the public key of the first site and transmitting the encrypted session key to the first site;decrypting, by the first site, the encrypted session key with the first site's private key;and transmitting, by the first site, a message encrypted with the session key.
  4. 21
    A method for authentication of a plurality of sites in a land mobile radio (LMR) system and for encryption of messages exchanged by the sites, the plurality of sites being connected by a data network, comprising:authenticating a first site by a previously authenticated site in the LMR system: generating a session key;encrypting the session key with the public key of the first site and transmitting the encrypted session key to the first site;decrypting, by the first site, the encrypted session key with the first site's private key;and transmitting, by the first site, a message encrypted with the session key.
  5. 26
    A computer-implemented method for authentication of a plurality of sites in a land mobile radio (LMR) system and for encryption of messages exchanged by the sites, the plurality of sites being connected by an IP network, comprising:transmitting by a first site its certificate, wherein the certificate is created by a trusted authority by encrypting the public key, the ID and other relevant information of the first site with the trusted authority's private key;receiving, by the other sites in the LMR system, the certificate transmitted by the first site;decrypting, by the other sites, the certificate transmitted by the first site and authenticating the first site, wherein the certificate is decrypted using the trusted authority's public key;generating a session key;encrypting the session key with the public key of the first site and transmitting the encrypted session key to the first site;decrypting, by the first site, the encrypted session key with the first site's private key;and transmitting, by the first site, a message encrypted with the session key.
  6. 27
    A system for authentication of a plurality of sites in a land mobile radio (LMR) network and for encryption of messages exchanged by the sites, the plurality of sites being connected by an IP network, the system utilizing a plurality of method steps comprising:transmitting by a first site its certificate, wherein the certificate is created by a trusted authority by encrypting the public key, the ID and other relevant information of the first site with the trusted authority's private key;receiving, by the other sites in the LMR system, the certificate transmitted by the first site;decrypting, by the other sites, the certificate transmitted by the first site and authenticating the first site, wherein the certificate is decrypted using the trusted authority's public key;generating a session key;encrypting the session key with the public key of the first site and transmitting the encrypted session key to the first site;decrypting, by the first site, the encrypted session key with the first site's private key;and transmitting, by the first site, a message encrypted with the session key.