WO2005114901A1

Multicast key issuing scheme for large and medium sized scenarios and low user-side demands

Abstract

The system according to the invention comprises at least one sender S with key providing means (24) for providing group keys GK and address keys (Xj, Yj, Zj). A plurality of receivers r each have accessing means (42, 50) for accessing individual receiver address key sets and group keys. Group keys are identical for all receivers of the same group. Each receiver ad­dress key set is a subset of the base set of address keys. The receiver address key sets are pairwise different for all pairs of receivers of the same group. For each individual receiver, there is one or more exclusion key (X, Y, Z), which is not contained in that receivers set of address keys. The system comprises authorization storage means (30) storing authorization information about each receiver. Encryption means (24) are used to generate out of the message mk a plurality of encrypted messages mk*. Each encrypted message mk* is encrypted with a combination of keys in such a way that it can only be decrypted using all keys out of the combination of keys. Each encrypted message mk* is aimed at one group of receivers, and the combination contains group keys of that group. To exclude non-authorized receivers, the combination further contains one or more exclusion keys of non-authorized receivers of the group.

WO2005114901A1, drawing sheet 1
Sheet 1 of 22

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

19 claims: 9 independent, 10 dependent

  1. 1
    CLAIMS:1. System for selective multicast of a message, - with at least one sender (S), and key providing means (26, 52, 54) associated with said sender (S), for providing a base set of group keys (GKl, GK2, ...) and a base set of address keys (XO, XI, ... YO, Yl, ... ZO, Zl, ...), and with sending means (16) for sending an encrypted message (mk*), - said system further comprising a plurality of receivers (RO, Rl, ...) said receivers being members of a plurality of groups, and accessing means (42, 50) associated with each of said receivers for accessing individual receiver address key sets and one ore more group keys (GK), - where said one or more group keys (GK) are identical for all receivers of the same group, where each of said receiver address key sets is a subset of said base set of address keys, and said receiver address key sets are pairwise different for all pairs of receivers of the same group, - and where for each individual receiver, there is one or more exclusion key (X0, XI, ..., Y0, Yl, ..., Z0, Zl, ...) out of said base set of address keys, which is not contained in the receiver address key set of said receiver, said system further comprising authorization storage means (30) to store au- thorization information about each of said receivers, - said system further comprising encryption means (24) for generating out of said message (mk) a plurality of encrypted messages (mk*), - where each of said encrypted messages (mk*) is encrypted with a combination of keys in such a way that it can only be decrypted using all keys out of the combination of keys, - where each of said encrypted messages (mk*) is aimed at a target group (Go, Gi) out of said groups of receivers, and said combination of keys contains one or more group keys of said target group, - and where said combination further contains one or more exclusion key of non- authorized receivers of said target group.
  2. 3
    System according to one of the above claims, where said encryption means (24) are configured to recursively encrypt said message using said combination of keys.
  3. 4
    System according to one of the above claims, said system further comprising address key generating means (26) to generate said base set of address keys, - and selective key transmission means (28) for selectively transmitting said address keys to said receiver.
  4. 6
    System according to one of the above claims, where - for each receiver (R), there is only one exclusion key contained in said base set of address keys, which is not contained in the receiver address key set of said receiver, and where said exclusion key is contained in said receiver address key sets of the remaining receivers of the same group as said receiver.
  5. 9
    System according to one of claims 1-5, where - for each receiver there are at least two exclusion keys out of said base set of address keys, which are not contained in the corresponding receiver address key set, and where each combination of exclusion keys is unique within each group.
  6. 10
    System according to one of claims 1-5, or 9, where - said base set of address keys is divided into first address keys (SK1_0, SK1__1, ...) and second address keys (SK2_0, SK2_1, ...), - and where said groups (Go, Gi) are divided into a plurality of subgroups, - where said receiver address key sets comprise a receiver set of first address keys and a receiver set of second address keys, - where the receiver address key set of each receiver within the same subgroup contains the same receiver set of first address keys, and where the receiver address key set of each receiver contains a receiver set of second address keys unique within the subgroup of said receiver.
  7. 13
    System according to one of claims 10-12, where - each group contains maximally b2d receivers, where b>2 is an integer basis number and d≥l is an integer dimension number, and each group contains maximally bd subgroups with maximally bd receivers in each subgroup, - and where said selection base key set contain 2 * b * d selection keys, with b * d first selection keys (SK1_0, SK1_1, ...) and b * d second selection keys (SK2_0, SK2_1, ...), - and where the receiver selection key set of each receiver contains (b-l)*d first selection keys and (b-l)*d second selection keys, and where the first selection key set in the receiver selection key set of each re- ceiver corresponds to a representation of a receiver number r in a number system to basis b, with 0<r<bd-l, where each digit of r is represented by one of d different selection keys, and where the second selection key set in the receiver selection key set of each receiver corresponds to a representation of a subgroup number s in a number system to basis b, with o≤s<bd-l, where each digit of s is represented by one of d different selection keys.
  8. 15
    Broadcasting system with - a sender (S) for broadcasting scrambled content messages (FI*, F2*, F3*, ...) said content messages being scrambled with at least one scrambling key (ml, m2, m3, ...) - a plurality of receivers (R) for receiving said scrambled messages, - and a system (10) according to one of claims 1-14 for selectively transmitting said scrambling key (ml, m2, m3, ...) to authorized receivers.
  9. 16
    Method for selective multicast of a message in a system including at least one sender (S) and a plurality of receivers (R), where said receivers are divided into a plurality of groups (Go, Gi), comprising the steps of - providing a base set of group keys (GK), - providing a base set of address keys (Zj, Xj, Yj), - providing for each of said receivers one or more group keys, where all of the re- ceivers of the same group are provided with the same group keys, - providing a receiver address key set for each of said receivers, where each of said receiver key sets is a subset of said base set of address keys, - and where for each receiver there is at least one exclusion key (Zj, Xj, Yj) out of said base set of address keys, which is not contained in the corresponding re- ceiver address key set, - obtaining information about unauthorized receivers and authorized receivers, - processing said message (mk) to generate a plurality of encrypted messages (mk*), each of said encrypted messages (mk*) being aimed at a target group of receivers, - where each of said encrypted messages (mk*) is encrypted using a combination of keys in such a way that it can only be decrypted using all keys out of said combination of keys, - and where said combination contains one or more group keys of the target group, - and where said combination contains a plurality of exclusion keys of non- authorized receivers of said target group, - and sending said encrypted messages from said sender to said receivers.