WO2013005989A3 - 이동 기기에 대한 그룹 키 관리를 위한 방법 및 장치 - Google Patents

이동 기기에 대한 그룹 키 관리를 위한 방법 및 장치 Download PDF

Info

Publication number
WO2013005989A3
WO2013005989A3 PCT/KR2012/005312 KR2012005312W WO2013005989A3 WO 2013005989 A3 WO2013005989 A3 WO 2013005989A3 KR 2012005312 W KR2012005312 W KR 2012005312W WO 2013005989 A3 WO2013005989 A3 WO 2013005989A3
Authority
WO
WIPO (PCT)
Prior art keywords
key
group
counterpart
mobile device
group key
Prior art date
Application number
PCT/KR2012/005312
Other languages
English (en)
French (fr)
Other versions
WO2013005989A2 (ko
Inventor
서경주
박영훈
서승우
제동현
배범식
백영교
최성호
정상수
Original Assignee
삼성전자주식회사
서울대학교산학협력단
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 삼성전자주식회사, 서울대학교산학협력단 filed Critical 삼성전자주식회사
Priority to EP12807990.2A priority Critical patent/EP2731294B1/en
Priority to CN201280042987.2A priority patent/CN103918218B/zh
Priority to US14/130,829 priority patent/US9326136B2/en
Publication of WO2013005989A2 publication Critical patent/WO2013005989A2/ko
Publication of WO2013005989A3 publication Critical patent/WO2013005989A3/ko

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/083Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
    • H04L9/0833Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/065Network architectures or network communication protocols for network security for supporting key management in a packet data network for group communications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/068Network architectures or network communication protocols for network security for supporting key management in a packet data network using time-dependent keys, e.g. periodically changing keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0891Revocation or update of secret information, e.g. encryption key update or rekeying
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • H04L9/3066Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy involving algebraic varieties, e.g. elliptic or hyper-elliptic curves
    • H04L9/3073Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy involving algebraic varieties, e.g. elliptic or hyper-elliptic curves involving pairings, e.g. identity based encryption [IBE], bilinear mappings or bilinear pairings, e.g. Weil or Tate pairing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/047Key management, e.g. using generic bootstrapping architecture [GBA] without using a trusted network node as an anchor
    • H04W12/0471Key exchange
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/26Testing cryptographic entity, e.g. testing integrity of encryption key or encryption algorithm
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0442Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Algebra (AREA)
  • General Physics & Mathematics (AREA)
  • Mathematical Analysis (AREA)
  • Mathematical Optimization (AREA)
  • Mathematical Physics (AREA)
  • Pure & Applied Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

본 발명은 그룹 키에 관한 것으로 키 분배 센터의 그룹 키 관리 방법에 있어서 이동 기기로부터 키 요청을 수신하는 과정과 상기 키 요청에는 이탈 시간 정보가 포함되어 있으며 상기 이동 기기에 대한 비밀 키를 생성하는 과정과 상기 이동 기기에 대한 공개 키와 검증 키를 생성하는 과정과 생성한 키를 포함하는 적어도 하나의 키를 상기 이동 기기로 전송하는 과정과, 상대방의 이탈시간, 상대방의 퍼블릭키, 상대방의 검증키로 상대방이 같은 그룹에 속하는지 검증하는 과정과, 같은 그룹에 속한 경우 그룹키의 버전을 비교하여 최신 버전의 그룹키를 가진 기기가 상대방기기로 최신 버전의 그룹키를 세션키로 암호화하여 전송하는 과정과, 수신한 상대방 기기는 그룹키를 복호화하여 갱신하는 과정을 포함하는 것으로 그룹 키를 사용함으로 인하여 데이터 전송에 드는 통신 비용을 줄일 수 있고, 그룹 키가 업데이트되었을 때, 기지국에서 그룹 키를 받지 못한 이동 기기들도 나중에 기지국이나 같은 그룹의 다른 이동 기기로부터 그룹 키를 전송받을 수 있는 이점이 있다.
PCT/KR2012/005312 2011-07-04 2012-07-04 이동 기기에 대한 그룹 키 관리를 위한 방법 및 장치 WO2013005989A2 (ko)

Priority Applications (3)

Application Number Priority Date Filing Date Title
EP12807990.2A EP2731294B1 (en) 2011-07-04 2012-07-04 Method and apparatus for managing group key for mobile device
CN201280042987.2A CN103918218B (zh) 2011-07-04 2012-07-04 用于管理移动设备的群密钥的方法和装置
US14/130,829 US9326136B2 (en) 2011-07-04 2012-07-04 Method and apparatus for managing group key for mobile device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020110066137A KR101808188B1 (ko) 2011-07-04 2011-07-04 이동 기기에 대한 그룹 키 관리를 위한 방법 및 장치
KR10-2011-0066137 2011-07-04

Publications (2)

Publication Number Publication Date
WO2013005989A2 WO2013005989A2 (ko) 2013-01-10
WO2013005989A3 true WO2013005989A3 (ko) 2013-04-04

Family

ID=47437564

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2012/005312 WO2013005989A2 (ko) 2011-07-04 2012-07-04 이동 기기에 대한 그룹 키 관리를 위한 방법 및 장치

Country Status (5)

Country Link
US (1) US9326136B2 (ko)
EP (1) EP2731294B1 (ko)
KR (1) KR101808188B1 (ko)
CN (1) CN103918218B (ko)
WO (1) WO2013005989A2 (ko)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
ES2759428T3 (es) * 2014-01-28 2020-05-11 Huawei Tech Co Ltd Método de cambio de clave de seguridad y equipo de usuario
CN105516055B (zh) * 2014-09-23 2020-07-14 腾讯科技(深圳)有限公司 数据访问方法、访问设备、目标设备及管理服务器
CN104270516B (zh) * 2014-09-23 2019-05-24 中兴通讯股份有限公司 解密方法和移动终端
CN106452736B (zh) * 2016-08-12 2019-05-17 数安时代科技股份有限公司 密钥协商方法和系统
US11025596B1 (en) * 2017-03-02 2021-06-01 Apple Inc. Cloud messaging system
US10819701B2 (en) 2018-03-14 2020-10-27 Microsoft Technology Licensing, Llc Autonomous secrets management for a managed service identity
US10965457B2 (en) 2018-03-14 2021-03-30 Microsoft Technology Licensing, Llc Autonomous cross-scope secrets management
US10691790B2 (en) 2018-03-14 2020-06-23 Microsoft Technology Licensing, Llc Autonomous secrets management for a temporary shared access signature service
US11762980B2 (en) * 2018-03-14 2023-09-19 Microsoft Technology Licensing, Llc Autonomous secrets renewal and distribution
WO2021212413A1 (zh) * 2020-04-23 2021-10-28 华为技术有限公司 一种密钥的传输方法及装置
EP3920499A1 (en) * 2020-06-05 2021-12-08 FIMER S.p.A. Secure group communication in a cluster of devices
CN112653552B (zh) * 2020-11-23 2023-01-10 北京思特奇信息技术股份有限公司 采用分组方式的密钥管理系统和方法
CN113037485B (zh) * 2021-05-24 2021-08-03 中国人民解放军国防科技大学 一种群组会话密钥建立方法及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20040105064A (ko) * 2003-06-04 2004-12-14 학교법인 성균관대학 무선 통신 환경을 위한 키 분배 프로토콜 방법
US20050144439A1 (en) * 2003-12-26 2005-06-30 Nam Je Park System and method of managing encryption key management system for mobile terminals
US20070019807A1 (en) * 2005-07-23 2007-01-25 Samsung Electronics Co., Ltd. Method for generating group key
KR20090092509A (ko) * 2008-02-27 2009-09-01 삼성전자주식회사 멀티캐스트 서비스를 위한 그룹 키 관리 방법

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020154782A1 (en) 2001-03-23 2002-10-24 Chow Richard T. System and method for key distribution to maintain secure communication
US7231664B2 (en) 2002-09-04 2007-06-12 Secure Computing Corporation System and method for transmitting and receiving secure data in a virtual private group
US20050036623A1 (en) * 2003-08-15 2005-02-17 Ming-Jye Sheu Methods and apparatus for distribution of global encryption key in a wireless transport network
EP1549010B1 (en) * 2003-12-23 2008-08-13 Motorola Inc. Rekeying in secure mobile multicast communications
KR20080004165A (ko) * 2006-07-05 2008-01-09 삼성전자주식회사 브로드캐스트 암호화를 이용한 디바이스 인증 방법
CN101645870B (zh) 2008-08-07 2013-04-17 赵运磊 一类高效、公平的密钥交换方法
ES2449790T3 (es) 2008-02-22 2014-03-21 Security First Corp. Sistemas y métodos para la gestión y la comunicación seguras en un grupo de trabajo
KR100957121B1 (ko) * 2008-02-22 2010-05-13 성균관대학교산학협력단 키 분배 방법 및 인증 서버
CN102164125A (zh) * 2011-03-17 2011-08-24 武汉大学 基于asgka协议的安全通信系统及方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20040105064A (ko) * 2003-06-04 2004-12-14 학교법인 성균관대학 무선 통신 환경을 위한 키 분배 프로토콜 방법
US20050144439A1 (en) * 2003-12-26 2005-06-30 Nam Je Park System and method of managing encryption key management system for mobile terminals
US20070019807A1 (en) * 2005-07-23 2007-01-25 Samsung Electronics Co., Ltd. Method for generating group key
KR20090092509A (ko) * 2008-02-27 2009-09-01 삼성전자주식회사 멀티캐스트 서비스를 위한 그룹 키 관리 방법

Also Published As

Publication number Publication date
KR101808188B1 (ko) 2017-12-13
KR20130004841A (ko) 2013-01-14
US9326136B2 (en) 2016-04-26
CN103918218B (zh) 2017-02-08
US20140149745A1 (en) 2014-05-29
WO2013005989A2 (ko) 2013-01-10
EP2731294A2 (en) 2014-05-14
CN103918218A (zh) 2014-07-09
EP2731294B1 (en) 2019-09-04
EP2731294A4 (en) 2015-07-08

Similar Documents

Publication Publication Date Title
WO2013005989A3 (ko) 이동 기기에 대한 그룹 키 관리를 위한 방법 및 장치
WO2010017281A3 (en) Device manager repository
WO2007092588A3 (en) Secure digital content management using mutating identifiers
WO2012094205A3 (en) Methods and systems for providing a signed digital certificate in real time
WO2012077999A3 (en) Traffic encryption key management for machine to machine multicast group
WO2009145495A3 (en) Method and apparatus for providing broadcast service using encryption key in a communication system
GB2528226A (en) Method performed by at least one server for processing a data packet from a first computing device to a second computing device to permit end-to-end
SG10201803986RA (en) Method and system for secure transmission of remote notification service messages to mobile devices without secure elements
GEP20094692B (en) Method of encrypting and transferring data between sender and receiver using network
GB2514055A (en) Bluetooth pairing system, method, and apparatus
WO2014208033A3 (en) Secure discovery for proximity based service communication
NO20091199L (no) Fremgangsmate, system og anordning for synkronisering mellom tjener og mobil anordning
WO2012141555A3 (en) Method and apparatus for providing machine-to-machine service
ES2546283T3 (es) Aparato de comunicación por línea eléctrica, método de confirmación de estado de registro y sistema de comunicación por línea eléctrica
MX2015016228A (es) Protocolos de cifrado de datos para comunicaciones por satelites moviles.
WO2013067601A3 (en) Secure messaging
WO2018016713A3 (ko) 무선 통신 시스템에서의 단말의 접속 식별자 보안 방법 및 이를 위한 장치
IN2014KN02750A (ko)
EP2394452A4 (en) APPARATUS AND METHOD FOR PROTECTING A PRIMER MESSAGE IN A NETWORK
EP2629448A4 (en) PROXY-BASED ENCRYPTION AND DECOMPOSITION PROCESS, NETWORK DEVICE, NETWORK DEVICE AND SYSTEM THEREFOR
WO2011122912A3 (ko) 방송 서비스의 암호화 키 관리 방법 및 시스템
WO2012087692A3 (en) System and method for secure communications in a communication system
WO2013167043A3 (zh) 数据安全验证方法和装置
WO2012087572A8 (en) Wireless communication system and method
WO2012093900A3 (en) Method and device for authenticating personal network entity

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 2012807990

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 14130829

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE