WO2012160137A2 - System, apparatus and method for efficient multicast key distribution - Google Patents

System, apparatus and method for efficient multicast key distribution Download PDF

Info

Publication number
WO2012160137A2
WO2012160137A2 PCT/EP2012/059707 EP2012059707W WO2012160137A2 WO 2012160137 A2 WO2012160137 A2 WO 2012160137A2 EP 2012059707 W EP2012059707 W EP 2012059707W WO 2012160137 A2 WO2012160137 A2 WO 2012160137A2
Authority
WO
WIPO (PCT)
Prior art keywords
information
decryption
digital information
encryption
key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/EP2012/059707
Other languages
French (fr)
Other versions
WO2012160137A3 (en
Inventor
Joachim Jakob ROSENTHAL
Davide Mose' SCHIPANI
Juan Antonio LOPEZ-RAMOS
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Zurich Universitaet Institut fuer Medizinische Virologie
Universidad de Almeria
Original Assignee
Zurich Universitaet Institut fuer Medizinische Virologie
Universidad de Almeria
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zurich Universitaet Institut fuer Medizinische Virologie, Universidad de Almeria filed Critical Zurich Universitaet Institut fuer Medizinische Virologie
Publication of WO2012160137A2 publication Critical patent/WO2012160137A2/en
Publication of WO2012160137A3 publication Critical patent/WO2012160137A3/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)

Definitions

  • the present invention relates to an apparatus, a system and to a corresponding method to efficiently distribute cryptographic keys with security information purposes from one source to a plurality of receptors.
  • the typical approach to establish secure multicast communications is to agree on one or several symmetric encryption keys in order to encrypt messages.
  • the key, or keys must be renewed periodically to prevent outer or inner attacks.
  • Examples of secure multicast are described in EP2288072A2, EP2282442A1 or US201010318803A1.
  • the first one makes use of hash functions and the two others use public key cryptography.
  • the patent application published as WO2010020186A1 is based on unicast communication, but this can slow down the key distribution depending on the number of communicants.
  • HTA Hierarchical Tree Approach
  • the distribution by groups is in fact often beneficial and is used by most key managing protocols.
  • a first benefit is the parallelization of the process which speeds up the rekeying operations.
  • a compromised key in one of the groups does not affect the others and, finally and very important in most applications of secure multicast, the group distribution is connected with the scalability of the system, i.e., the efficiency of the communication protocols concerning the rekeying process, with particular reference to leave and join operations.
  • Groups are usually highly dynamic and the joining or the leaving of users implies a rekeying operation, and thus key refreshment due to this fact in one group does not affect the others.
  • we introduce a method and system for an efficient management of cryptographic keys offering advantages with respect to the aforementioned systems and protocols concerning key storage, key length or number of join/leave messages.
  • Figure 1 shows a first embodiment of a system according to the present invention, for efficient and secure distribution of cryptographic keys.
  • Figure 2 shows a second embodiment of an apparatus according to the present invention, for encrypting digital information, to calculate the information needed to decrypt the digital information and to send both of them to other apparatus.
  • Figure 3 shows a third embodiment of an apparatus according to the present invention, for decrypting the received digital information and to resend the digital information received to other apparatus.
  • the apparatus (101) of Figure 1 corresponds to an apparatus as described in Figure 2.
  • the above decomposition may be carried out by the means (203) included in it or calculated by other means and introduced into the storing means (202) for further calculations.
  • v and s new are stored in (202) for further calculations and/or encryption/ decryption of digital information.
  • the vector v will be used to obtain a new w from a new secret s and this will be used to encrypt some other digital information by some algorithm that could be implemented in (203) or it is communicated to some other device or apparatus, internal or external to (101) in charge of this encryption task.
  • user Ui wants to authenticate user U 2 , presumably another member of the group and knowing Snew Then:
  • v new and s new are stored in (202) for further calculations and/or encryption/ decryption of digital information.
  • the vector v new will be used to obtain a new w from a new secret s and this will be used to encrypt some other digital information by some algorithm that could be implemented in (203) or it is communicated to some other device or apparatus, internal or external to (101) in charge of this encryption task.
  • VW ViWi+V 2 W2+...+v n w n
  • the system given by Figure 1 will be able to broadcast multimedia contents such as live video streaming.
  • the apparatus given by Figure 2 will be constituted by a board comprising means for digital information reception and digital information broadcasting (201), means for storing the necessary information in order to encrypt digital information (202) and means for calculations that can be given by any programming device as a FPGA, microcontroller or similar (203).
  • This apparatus will be integrated in a computer in charge of the big calculations.
  • a second computer will be in charge of encryption of the multimedia contents using the key that (101) broadcasts and broadcasting the contents once they are encrypted.
  • a plurality of apparatus given by Figure 3 given by a board comprising means for digital information reception and digital information broadcasting (301), means for storing the necessary information in order to decrypt digital information (302) and means for calculations that can be given by any programming device as a FPGA, microcontroller or similar (303).
  • the decryption algorithm of the encrypted multimedia contents may be carried out by the same board, by a second board integrated into a computer or by a software implementation on it. We are going to assume that the system will distribute multimedia contents for a group with n users at most.
  • the board (101) After a period of time with users (102i),..., (102 r ), r ⁇ n, receiving multimedia contents using an encryption algorithm with key s, the system refreshes the key. To do so, the board (101) operates as follows:
  • step 6 It operates from step 1 to step 6 as in the refreshing message process.
  • step 3 It operates from step 1 to step 6 as in the refreshing message process.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

A system, apparatus and method are disclosed for efficient distribution of keys with security information purposes. In one aspect, one apparatus, the key server, is in charge of generating the information that is needed to encrypt the key using an orthogonal decomposition of a vector space and assign information that determine uniquely every authorized user and to distribute the key. In another aspect a plurality of apparatus receive and transmit the encrypted key and, using the information that determines them are able to get the key by means of a scalar product and that allows access to some digital information that can be sent by the key server itself or another server using the encryption key.

Description

TITLE
System, apparatus and method for efficient multicast key distribution
TECHNICAL FIELD
The present invention relates to an apparatus, a system and to a corresponding method to efficiently distribute cryptographic keys with security information purposes from one source to a plurality of receptors.
PRIOR ART
Traditional security measures are mainly applicable to a unicast environment, i.e. communications take place between two single parties. For instance, data confidentiality, one of the most important features in network security, can be offered in this environment by means of a pair of keys. However there exist many different situations where the usual secure unicast protocols cannot be used, mainly due to the nature of the information to be transmitted. This usually appears when trying to deliver data from a sender to multiple receivers, especially when a huge amount of data needs to be delivered very quickly. One of the most efficient ways to do this is the so-called multicast. In a multicast protocol a certain group of people receives the information and this group is usually highly dynamic, where users constantly join and leave the group. There are a number of exciting multimedia applications that make good use of multicast capability, such as stock quote services, video-conferencing, pay-per-view TV, Internet radio, and so on. Many of these multicast applications require security in data transmission, i.e., data can only be exchanged among an exclusive group of users. In multicast communications a situation of ^many-to-many" can also take place if several clients, or all, act as a source of data. Multiconferences are an example of this (strictly speaking, each data source establishes a one-to-many multicast communication).
The typical approach to establish secure multicast communications is to agree on one or several symmetric encryption keys in order to encrypt messages. However, the key, or keys, must be renewed periodically to prevent outer or inner attacks. Examples of secure multicast are described in EP2288072A2, EP2282442A1 or US201010318803A1. The first one makes use of hash functions and the two others use public key cryptography. The patent application published as WO2010020186A1 is based on unicast communication, but this can slow down the key distribution depending on the number of communicants.
Depending on how key distribution and management are carried out, secure multicast schemes are divided into centralized and distributed. Centralized schemes depend directly on a single entity to distribute every cryptographic key. Distributed schemes are able to manage higher audiences but on the other hand, key management involves other problems that make them more complex. In the following lines we recall some centralized schemes for key management.
A very well-known protocol is Hierarchical Tree Approach (HTA), [1]. It uses a logical tree arrangement of the users in order to facilitate key distribution. The benefit of this idea is that the storage requirement for each client and the number of transmissions required for key renewal are both logarithmic in the number of members. Other key tree approaches and extensions are LKH, [2], LKH++ , [3], OFT, [4], or ELK, [5] or the subject matter of patent application WO0103364A1.
In [6] the so-called Secure Lock protocol is introduced. The authors approach the problem in a computational manner, based in this case on the Chinese Remainder Theorem, rather than with a tree arrangement. Its main drawback is the big computational cost required at the key server side on each rekeying operation: the computing time needed becomes quickly excessive as the number of members grows. The treatment of users into small groups reveals to be necessary. Other systems that use key management by groups are described in US6195751B1 and US2007110248A1. In the first case a trusted user is used as a group manager for every group and in the second one, a hierarchy of keys is considered.
In [7], a divide-and-conquer extension of the Secure Lock is proposed. It combines the Hierarchical Tree Approach and the Secure Lock: members are arranged in a HTA fashion, but the Secure Lock is used to refresh keys on each tree level. Therefore, the number of computations required by the Secure Lock is reduced. Another computational approach is introduced in [8] with the particular application on Pay-TV but extendable to any other secure multicast application. The idea is to use polynomials over a finite field interpolating hashes of secret values belonging to the authorized users. The main drawbacks are the big size of the polynomials involved and that the hash function must be renewed with any rekeying operation, due to security concerns.
The distribution by groups is in fact often beneficial and is used by most key managing protocols. A first benefit is the parallelization of the process which speeds up the rekeying operations. Secondly a compromised key in one of the groups does not affect the others and, finally and very important in most applications of secure multicast, the group distribution is connected with the scalability of the system, i.e., the efficiency of the communication protocols concerning the rekeying process, with particular reference to leave and join operations. Groups are usually highly dynamic and the joining or the leaving of users implies a rekeying operation, and thus key refreshment due to this fact in one group does not affect the others. In this patent we introduce a method and system for an efficient management of cryptographic keys offering advantages with respect to the aforementioned systems and protocols concerning key storage, key length or number of join/leave messages.
REFERENCES
[1] D. Wallner, E. Harder and R. Agee, Key management for multicast: Issues and architectures, RFC 2627, 1999.
[2] C. K. Wong, M. Gouda, and S. S. Lam, Secure group communications using key graphs, IEEE/ACM Transactions on Networking 8(1) (2000) 16-30.
[3] R. Di Pietro and L. V. Mancini, Efficient and Secure Keys Management for Wireless Mobile Communications, Proceedings of the second ACM international workshop on Principles of mobile computing, 2002, 66-73. [4] A. T. Sherman and D. A. McGrew, Key establishment in large dynamic groups using one-way function trees, IEEE Transactions on Software Engineering 29 (2003) 444-458.
[5] A. Perrig, D. Song, and J. D. Tygar, ELK, a new protocol for efficient large-group key distribution, Proceedings of IEEE Symposium on Security and Privacy (S\& P), 2001, 247-262.
[6] G. Chiou and W. Chen, Secure broadcasting using the secure lock, IEEE Trans. Softw. Eng. 15(8) (1989) 929-934.
[7] O. Scheikl, J. Lane, R. Boyer and M. Eltoweissy, Multi-level secure multicast: the rethinking of secure locks, Parallel Processing Workshops, 2002. Proceedings. International Conference on, 2002, 17-24.
[8] B. Liu, W. Zhang and T. Jiang, A Scalable Key Distribution Scheme for Conditional Access System in Digital Pay-TV System, IEEE Consumer Electronics 50(2) (2004) 632-637.
SUMMARY OF THE INVENTION
In a first aspect, it is an object of the present invention to provide a method for distributing digital information efficiently and in a secure form. This object is achieved by a method having the features of claim 1.
In a second aspect, it is an object of this invention to provide an apparatus to encrypt digital information and to calculate the necessary information to recover the encrypted digital information. This object is achieved by an apparatus having the features of claim 6.
It is a further object of the present invention to provide an apparatus for decryption of information received from an apparatus as that of claim 1. This object is achieved by an apparatus having the features of claim 8.
In a third and final aspect, it is an object of this invention to provide a system to distribute securely and efficiently encrypt/decrypt digital information. This object is achieved by a system having the features of claim 11.
Further embodiments of the invention are stated in the dependent claims.
BRIEF DESCRIPTION OF THE EMBODIMENTS
Preferred embodiments of the invention are described in the following with reference to the drawings, which are for the purpose of illustrating the present preferred embodiments of the invention and not for the purpose of limiting the same. In the drawings,
Figure 1 shows a first embodiment of a system according to the present invention, for efficient and secure distribution of cryptographic keys.
Figure 2 shows a second embodiment of an apparatus according to the present invention, for encrypting digital information, to calculate the information needed to decrypt the digital information and to send both of them to other apparatus.
Figure 3 shows a third embodiment of an apparatus according to the present invention, for decrypting the received digital information and to resend the digital information received to other apparatus.
GENERAL DESCRIPTION OF THE INVENTION
The general description of the present invention is described in the following with reference to Figure 1, Figure 2 and Figure 3. All the apparatus that form the system may be implemented either in hardware or in software as a program for a general-purpose computer or for a dedicated digital signal processor, the program carrying out a method as described herein when being executed on the computer. The usefulness of the system and method described is the secure and efficient distribution of secrets that allow encrypt/decrypt digital information.
Setting up step: In order to detail a general description, let us assume that we are considering a vector space V over a field K of dimension n endowed with a scalar product given by the matrix A.
The first step is to calculate an orthogonal decomposition V=Vi+...+Vm such that dim(Vi)+...+dim(Vm)=n.
The apparatus (101) of Figure 1 corresponds to an apparatus as described in Figure 2. The above decomposition may be carried out by the means (203) included in it or calculated by other means and introduced into the storing means (202) for further calculations. The matrix A should be also stored in the apparatus (101) in (202) and in every apparatus (102j) j=l, r in (302). The apparatus (101) calculates a random vector Vj in Vj j=l,..., r (r<m) and assigns it to each apparatus (102j), j=l,..., r. Every vector Vj j= 1 , ... , r is then communicated to its corresponding apparatus ( 102j), j= 1 , ... , r individually and this is stored in (302).
Joining the system:
Once a user with an apparatus (102i) as that appearing in Figure 3 wishes to join the system given by Figure 1, that up to that moment is sharing a secret s0id, it sends a message to the apparatus (101) using (301) communicating its wish to join the system. Then the apparatus (101) operates as follows using the means (203):
1. It randomly chooses a new secret snew in K to be distributed.
2. It selects a subspace V; i=l,..., m, that is not being used by any other user.
3. It randomly selects a vector v; in Vi and sends v; to this new user in a secure way via (201).
4. It calculates the vector v=vi+...+v;+...+vr where each vector Vj is in Vj (j=l,..., r) and corresponds to an apparatus (102j) , for j=l,..., r.
5. It calculates the vector w=snewV and then w is broadcasted via (201 ).
6. v and snew are stored in (202) for further calculations and/or encryption/ decryption of digital information. The vector v will be used to obtain a new w from a new secret s and this will be used to encrypt some other digital information by some algorithm that could be implemented in (203) or it is communicated to some other device or apparatus, internal or external to (101) in charge of this encryption task.
Recovering the secret s:
After (101) broadcasts w, then every apparatus (102j) receives w via (301) and stores it in (302). Then it broadcasts w to any other apparatus (102 ) in the system via (301). To recover snew from w, (102j) operates as follows using (303):
1. It calculates the scalar product
Figure imgf000008_0001
2. It calculates c(vjAvj)"1= snew.
3. snew is stored in (302) and used to decrypt the information received and that was encrypted with snew by some algorithm that could be implemented in (303) or it is communicated to some other device or apparatus, internal or external to (102j) j=l , ... , r in charge of this decryption task.
After recovering the secret snew, the vector d= snew w=v lets every user to authenticate any other user in the group by a means of a unicast communication. Suppose user Ui wants to authenticate user U2, presumably another member of the group and knowing Snew Then:
1. Ui selects a random element in K, say k.
2. Ui calculates h=k_1 in K.
3. Ui sends hd to U2.
4. U2 recovers h and calculates h"1=k in K.
5. U2 sends back kd to Ui .
Leaving the system:
When a user with an apparatus (102i) as that appearing in Figure 3 leaves the system given by Figure 1, that up to that moment is sharing a secret s0id, it sends a message to the apparatus (101) using (301) communicating that it is leaving the system. Then the apparatus (101) operates as follows:
1. It extracts the vectors v0id used up to that moment to encrypt s0id and v; that determines apparatus (102i) from the storing means (202).
2. It calculates the vector v= v0id- v;.
3. Depending on the chosen implementation, the calculating means (203) select a new vector u; in V; and then calculates vnew =v+Ui (in this case u; does not determine any user) or defines vnew =v.
4. It randomly chooses a new secret snew in K to be distributed by means of (203)
5. It calculates the vector
Figure imgf000009_0001
and then w is broadcasted via (201).
6. vnew and snew are stored in (202) for further calculations and/or encryption/ decryption of digital information. The vector vnew will be used to obtain a new w from a new secret s and this will be used to encrypt some other digital information by some algorithm that could be implemented in (203) or it is communicated to some other device or apparatus, internal or external to (101) in charge of this encryption task.
DESCRIPTION OF PREFERRED EMBODIMENTS
Preliminary considerations.
For this description of preferred embodiments we will assume a finite field K and the vector space Kn endowed with the usual scalar product given by the matrix A=In where In denotes the identity matrix of order n. Thus the scalar product of any two vectors v=(vi , ... ,vn) and w=(wi , ... ,wn) in Kn is given by the formula
VW=ViWi+V2W2+...+vnwn
The system given by Figure 1 will be able to broadcast multimedia contents such as live video streaming. The apparatus given by Figure 2 will be constituted by a board comprising means for digital information reception and digital information broadcasting (201), means for storing the necessary information in order to encrypt digital information (202) and means for calculations that can be given by any programming device as a FPGA, microcontroller or similar (203). This apparatus will be integrated in a computer in charge of the big calculations. A second computer will be in charge of encryption of the multimedia contents using the key that (101) broadcasts and broadcasting the contents once they are encrypted. A plurality of apparatus given by Figure 3 given by a board comprising means for digital information reception and digital information broadcasting (301), means for storing the necessary information in order to decrypt digital information (302) and means for calculations that can be given by any programming device as a FPGA, microcontroller or similar (303). The decryption algorithm of the encrypted multimedia contents may be carried out by the same board, by a second board integrated into a computer or by a software implementation on it. We are going to assume that the system will distribute multimedia contents for a group with n users at most.
Setting up and refreshing messages processes:
The computer containing (101) calculates a basis of Kn B= {bi , b2, ... , bn} , from which it can get an orthogonal basis of Kn Bi={ei, e2, ..., en} in a standard way. Then it gets the orthogonal decomposition Kn=Kei+Ke2+...+Ken. In this way, each user is assigned a different V;= Ke; for i=l,...,t < n and to do so, the computer chooses a random lq in K i=l,..., t <n and sends independently to each user (102i).
After a period of time with users (102i),..., (102r), r<n, receiving multimedia contents using an encryption algorithm with key s, the system refreshes the key. To do so, the board (101) operates as follows:
1. It chooses randomly a new secret snew in K to be distributed and to encrypt/decrypt the video contents by means of (203).
2. It stores snew in (202), checking that it is different from the previous one s.
3. It gets the vector v=ui+...+ur from (202) and then, by means of (203) it calculates the vector w= snewv=(wi,...,wn).
4. It stores w in (203).
5. It sends snew to the computer in charge of encrypting and broadcasting the multimedia contents in a secure form.
6. It broadcasts w to users (102j), j=l,..., r<n.
Decrypting the refreshed key: When the vector w is received by one user (102j), an apparatus as that given in Figure 2 operates in the following manner to get the new key snew:
1. It receives w via the means of information reception (201).
2. It stores w in (202).
3. It broadcasts w to any other user (102i) by means of (201).
4. It gets Uj=(uj,i , . . . ,Uj,n) from (202) and calculates the scalar product
C=WUj=WiUj,i + . .
Figure imgf000011_0001
. .+U2j,„).
5. It gets (u2j,i+...+u2j,n)_1 by calculating in (203) each time or by computing it previously when Uj is communicated for the first time and storing this value in (202).
6. It calculates snew =c(u2j,i+...+u2 j,n)_1.
7. It stores snew in (202) in order to be used by the corresponding decryption algorithm or device when receiving multimedia information encrypted with snew.
Joining the group process:
Once a user with an apparatus (102i) as that appearing in Figure 3 wishes to join the system given by Figure 1, that up to that moment is sharing a secret s, it sends a message to the apparatus (101) using (301) communicating its wish to join the system. Then the apparatus (101) operates as follows:
1. It selects, from the storing means, (202), a subspace V;= Ke;, i=r,..., n, that is not being used by any other user, say r+1.
2. It randomly selects a value kr+i in K and calculates the vector
Figure imgf000011_0002
and communicates it to the new user in a secure manner.
3. It stores ur+i in the storing means.
4. It calculates the vector v=ui+...+ur+ ur+i .
5. It randomly chooses a new secret snew in K to be distributed using (203).
6. It operates from step 1 to step 6 as in the refreshing message process.
Leaving the message process: When a user with an apparatus (102i) as that appearing in Figure 3 leaves the system given by Figure 1 , that up to that moment is sharing a secret s, it sends a message to the apparatus (101) using (301) communicating it is leaving the system. Then the apparatus (101) operates as follows:
1. It extracts the vectors v used up to that moment to encrypt s and v; that determines apparatus (102i) from the storing means (202).
2. It calculates the vector vnew = v- v; and defines v=vnew.
3. It operates from step 1 to step 6 as in the refreshing message process.

Claims

1. Encryption/decryption information method comprising:
a) a step of calculating digital information based on a orthogonal system of vectors in a vector space V and such that allows to encrypt the information to be transmitted via a linear combination of the vectors in the above system and then, be recovered by a group of users at a certain time t within a period of time h using the scalar product defined on the vector space V.
b) a step of calculating digital information based in that of section a) that allows to assign information relative to a vector subspace of V to each user and that allows to decrypt the digital transmitted information.
2. Method according to claim 1 characterized in the fact that the transmitted information before the time t cannot be decrypted by an unauthorized user.
3. Method according to claims 1 and 2, characterized in that the transmitted information after the period of time h is expired cannot be decrypted by an unauthorized user.
4. Method according to any of the preceding claims, characterized in that it calculates the information given to the authorized users randomly.
5. Method according to any of the preceding claims, characterized in that it allows changing the information held by the authorized users.
6. Apparatus for encryption of digital information including means for digital information reception and digital information broadcasting (201), means for storing the necessary information in order to encrypt digital information (202) and means for the execution of the method according to claims 1 to 5, including means for information encryption and means for calculating the information needed to decrypt the broadcasted messages (203).
7. The apparatus according to claim 6, characterized in that it assigns digital information that is unique for every authorized user.
8. Apparatus for decryption of digital information including means for digital information reception and digital information broadcasting (301), means for storing the necessary information in order to decrypt the received information (302) and means for the execution of the method according to claims 1 to 5, including means for information decryption (303).
9. The apparatus according to claim 8 and capable of resending the encrypted information received from the apparatus according to claim 6 or the apparatus according to claim 8.
10. The apparatus according to claims 6 and 7, characterized in being capable of storing the information that allows decryption of information broadcasted by every apparatus according to claims 8 and 9.
11. System of information encryption/decryption and generator of the corresponding keys for encryption/decryption including a plurality of decryption apparatus according to claims 8 and 9 (102i to 1027); one encryption apparatus (101), at least, according to claims 6, 7 and 9, and means of transmitting digital information between the encryption apparatus and the decryption apparatus or between two any decryption apparatus.
12. The system according to claim 11, characterized in that the means of transmitting information are means selected from wireless, cable or a combination of both of them.
13. The system according to claims 11 and 12, characterized in that the transmitted information can be made from one to many or from many to many by considering it a plurality of systems "one to many" as that of claim 11.
PCT/EP2012/059707 2011-05-25 2012-05-24 System, apparatus and method for efficient multicast key distribution Ceased WO2012160137A2 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CH889/11 2011-05-25
CH8892011 2011-05-25

Publications (2)

Publication Number Publication Date
WO2012160137A2 true WO2012160137A2 (en) 2012-11-29
WO2012160137A3 WO2012160137A3 (en) 2013-01-24

Family

ID=47217819

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2012/059707 Ceased WO2012160137A2 (en) 2011-05-25 2012-05-24 System, apparatus and method for efficient multicast key distribution

Country Status (1)

Country Link
WO (1) WO2012160137A2 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112236974A (en) * 2018-06-11 2021-01-15 三菱电机株式会社 Decryption device, encryption device and cryptographic system

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
JING WANG ET AL: "An Efficient Hierarchical Group Key Management Scheme Based on Orthogonal Vectors", INFORMATION ASSURANCE AND SECURITY, 2009. IAS '09. FIFTH INTERNATIONAL CONFERENCE ON, IEEE, PISCATAWAY, NJ, USA, 18 August 2009 (2009-08-18), pages 681-684, XP031544765, ISBN: 978-0-7695-3744-3 *
JOHN PRAKASH A ET AL: "Secure Authenticated Key Establishment Protocol for Ad Hoc Networks", NETWORK AND SYSTEM SECURITY, 2009. NSS '09. THIRD INTERNATIONAL CONFERENCE ON, IEEE, PISCATAWAY, NJ, USA, 19 October 2009 (2009-10-19), pages 87-94, XP031561691, ISBN: 978-1-4244-5087-9 *
PRAKASH A J ET AL: "Multicrypt: A Provably Secure Encryption Scheme for Multicast Communication", NETWORKS AND COMMUNICATIONS, 2009. NETCOM '09. FIRST INTERNATIONAL CONFERENCE ON, IEEE, PISCATAWAY, NJ, USA, 27 December 2009 (2009-12-27), pages 246-253, XP031612957, ISBN: 978-1-4244-5364-1 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112236974A (en) * 2018-06-11 2021-01-15 三菱电机株式会社 Decryption device, encryption device and cryptographic system
CN112236974B (en) * 2018-06-11 2024-02-23 三菱电机株式会社 Decryption devices, encryption devices and cryptographic systems

Also Published As

Publication number Publication date
WO2012160137A3 (en) 2013-01-24

Similar Documents

Publication Publication Date Title
Veltri et al. A novel batch-based group key management protocol applied to the Internet of Things
EP0952718B1 (en) Efficient, secure multicasting with minimal knowledge
Lin et al. A collaborative key management protocol in ciphertext policy attribute-based encryption for cloud data sharing
US20050204161A1 (en) Method and apparatus for hybrid group key management
Xie et al. New ciphertext-policy attribute-based access control with efficient revocation
Naranjo et al. A suite of algorithms for key distribution and authentication in centralized secure multicast environments
Dutta et al. Efficient self-healing key distribution with revocation for wireless sensor networks using one way key chains
Vijayakumar et al. An effective key distribution for secure internet pay‐TV using access key hierarchies
Kumar et al. A computationally efficient and scalable key management scheme for access control of media delivery in digital pay-TV systems
Pal et al. Efficient and secure key management for conditional access systems
Tian et al. Self-healing key distribution schemes for wireless networks: A survey
Lin et al. Multicast key management without rekeying processes
Tseng et al. Towards scalable key management for secure multicast communication
Kumar et al. Computation and storage efficient key distribution protocol for secure multicast communication in centralized environments
WO2012160137A2 (en) System, apparatus and method for efficient multicast key distribution
Wuu et al. Group key management based on (2, 2) secret sharing.
Bohio et al. Self-healing Group Key Distribution.
Hsu et al. A novel group key transfer protocol
Thomas et al. A novel decentralized group key management using attribute based encryption
Rial A conditional access system with revocation for mobile pay-TV systems revisited
Balaji et al. Enhanced approximate topology generality and identity-related broadcast encryption methodology for improving the security
Dutta Access polynomial based self-healing key distribution with improved security and performance
Naranjo et al. An updated view on centralized secure group communications
Antequera et al. Remarks and countermeasures on a cryptoanalysis of a secure multicast protocol
Akkus et al. Secure transmission of video on an end system multicast using public key cryptography

Legal Events

Date Code Title Description
NENP Non-entry into the national phase in:

Ref country code: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12727806

Country of ref document: EP

Kind code of ref document: A2

122 Ep: pct application non-entry in european phase

Ref document number: 12727806

Country of ref document: EP

Kind code of ref document: A2