Sign In to Follow Application
View All Documents & Correspondence

Communication System Node Device Communication Terminal Key Management Method And Non Temporary Computer Readable Medium In Which Program Is Stored

Abstract: A communication system (1) comprises a plurality of communication terminals (10_1 10_n) that form a communication group (100) and a node device (20) that performs authentication processing on each of the communication terminals (10_1 10_n). The node device (20) derives first keys unique to the respective communication terminals (10_1 10_n) using information shared among the communication terminals in the authentication processing derives a second key common to the communication group (100) calculates exclusive ORs of the respective first keys and the second key and transmits respective XOR values obtained by the calculation to the communication terminals (10_1 10_n). Each of the communication terminals (10_1 10_n) calculates the exclusive OR of the first key that is unique to the communication terminal and derived using the information and the XOR value received from the node device (20) to thereby regenerate the second key. Consequently the key used for group communication is more securely managed.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
02 August 2017
Publication Number
39/2017
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
Parent Application

Applicants

NEC CORPORATION
7 1 Shiba 5 chome Minato ku Tokyo 1088001

Inventors

1. ZHANG Xiaowei
c/o NEC Corporation 7 1 Shiba 5 chome Minato ku Tokyo 1088001
2. PRASAD Anand Raghawa
c/o NEC Corporation 7 1 Shiba 5 chome Minato ku Tokyo 1088001

Specification

Technical field
[0001]
 The present invention relates to a communication system, the node device, a communication terminal, relates to a key management method and a program, to a technology for particular manage keys used for group communication.
Background technique
[0002]
 Recently, mobile phones and communication terminals such as a smartphone can spread rapidly, sometimes one user holding a plurality of communication terminals. In the future, in addition to the user holds, the increase in M2M (Machine to Machine) terminal for autonomously communicate with another communication device is predicted. M2M terminal, in 3GPP (3rd Generation Partnership Project) has, MTC (Machine Type Communication) is referred to as the device. M2M terminal, for example, be a vending machine equipped with a communication function may be a sensor device or the like having a communication function. Moreover, M2M terminal, like the mobile phone or the like, needs to be authenticated when performing communication using a network. It should be noted that, in addition to the increase of the M2M terminal, the future, increase or wearable terminals, spread of network appliances in the home are also expected. Wearable devices is considered a number are possessed by one user. In addition, as the network home appliances, for example, air conditioning, robot vacuum cleaners and refrigerators, and the like.
[0003]
 Such procedures for authentication (procedure) is disclosed, for example, in Non-Patent Documents 1 and 2. Non-patent Document 1 defines the authentication procedure in the LTE (Long Term Evolution) system, non-patent document 2 defines the authentication procedure in the 3G system.
[0004]
 Incidentally, In 3GPP, a plurality of communication terminals has been studied by performing grouped group communication. In group communication, keys for communicating securely with the communication group and the network to which the communication terminal belongs (hereinafter, sometimes referred to as "group key") must be used.
[0005]
 Non-Patent Document 3, a technique for managing such a group key is disclosed. Non-Patent Document 3, generally, the network generates a group key is distributed to each communication terminal.
CITATION
Non-patent literature
[0006]
非特許文献1 : 3GPP TS 33.401、“3GPP System Architecture Evolution (SAE); Security architecture (Release 12)”、V12.13.0、6章及び7章、2014年12月
非特許文献2 : 3GPP TS 33.102、“3G Security; Security architecture (Release 12)”、V12.2.0、6章、2014年12月
非特許文献3 : 3GPP TR 33.833、“Study on Security issues to support Proximity Services (ProSe) (Release 13)”、V1.2.0、節6.3.2~6.3.5、2014年11月
Summary of the Invention
Problems that the Invention is to Solve
[0007]
 However, the inventors have, in the technique disclosed in Non-Patent Document 3, it was found that the problem of security for the group key management is insufficient there. Specifically, in Non-Patent Document 3, a group key itself itself, are delivered from the network to the communication terminal. For example, when the group key is leaked to malicious third parties, there is a possibility that the group communication from being eavesdropped not protected.
[0008]
 Accordingly, an object of the present invention is a key to be used for group communication, to more safely manage.
Means for Solving the Problems
[0009]
 To achieve the above object, a communication system according to the first aspect of the present invention includes a plurality of communication terminals forming a communication group, the node device performs an authentication process for each communication terminal. Said node device, the deriving the first key specific to each communication terminal using information shared between the communication terminal by the authentication processing, to derive a common second key to the communication group calculates the exclusive OR of the second key and the first key, and transmits the respective XOR (exclusive OR) values ​​obtained by the calculation to each communication terminal addressed. Each communication terminal includes a first key specific to the own communication terminal derived using the information, calculates the exclusive OR of the XOR value received from the node device, reproducing the second key to.
[0010]
 The node device according to the second aspect of the present invention is a node device which performs an authentication process for a plurality of communication terminals each forming a communication group. The node device using the information shared between the communication terminal by the authentication process, to derive the first key unique to each communication terminal, derives a common second key to the communication group transmitting unit and a deriving unit that, a calculation unit for calculating an exclusive OR of the second key and the first key, each XOR values ​​obtained by the calculation unit, and transmits to the communication terminal addressed and, including the.
[0011]
 The communication terminal according to the third aspect of the present invention is a communication terminal that forms a communication group with another communication terminal. The communication terminal includes a lead portion by using the information shared between the node device by the authentication processing for the self communication terminal, to derive the first key specific to the own communication terminal, from the node device, XOR value a receiving unit that receives the first key and calculates the exclusive OR of the XOR value, including a reproducing unit for reproducing the common second key to the communication group. The XOR value, the node device, is obtained by calculating the exclusive OR of the first key and the second key.
[0012]
 Further, the key management method according to the fourth aspect of the present invention is a method executed in a node device which performs an authentication process for a plurality of communication terminals each forming a communication group. The key management method, deriving a second key common to each communication terminal derives the first key specific, the communication group with the information that is shared between the communication terminal by the authentication processing and calculates the exclusive OR of the second key and the first key, and transmits the respective XOR value obtained by the calculation to each communication terminal addressed involves.
[0013]
 Further, the key management method according to a fifth aspect of the present invention is a method executed in a communication terminal to form a communication group with another communication terminal. The key management method derives a first key unique to the communication terminal using the information shared between the node device by the authentication processing for the communication terminal, from the node device, receives the XOR value the first key and calculates the exclusive OR of the XOR value, to reproduce the common second key to the communication group comprises. The XOR value, the node device, is obtained by calculating the exclusive OR of the first key and the second key.
[0014]
 Further, the program according to a sixth aspect of the present invention is a program to be executed by a node device which performs an authentication process for a plurality of communication terminals each forming a communication group computer. The program, in the computer, using the information shared between the communication terminal by the authentication process, a process of deriving the first key specific to each communication terminal, the common to the communication group a process of deriving a second key, the process for calculating the exclusive OR of the second key and the first key, each XOR value obtained by the calculation, is transmitted to each communication terminal addressed processing and, to the execution.
[0015]
 Furthermore, the program according to a seventh aspect of the present invention is a program for causing a computer to execute a communication terminal to form a communication group with another communication terminal. The program, in the computer, using the information shared between the node device by the authentication processing for the communication terminal, the process of deriving the first key unique to the communication terminal, from the node device, a process of receiving an XOR value, the first key and calculates the exclusive OR of the XOR value, a process of reproducing the common second key to said communication group, is executed. The XOR value, the node device, is obtained by calculating the exclusive OR of the first key and the second key.
Effect of the Invention
[0016]
 According to the present invention, it is possible to manage keys used for group communication more securely, can solve the problems described above Te following.
BRIEF DESCRIPTION OF THE DRAWINGS
[0017]
FIG. 1 is a block diagram showing a configuration example of a communication system according to the first embodiment.
It is a block diagram showing a configuration example of a node device according to [2] Embodiment 1.
3 is a diagram showing an example of a calculation process in the node device according to the first embodiment.
4 is a block diagram showing a configuration example of a communication terminal according to the first embodiment.
5 is a diagram showing an example of processing in the communication terminal according to the first embodiment.
6 is a block diagram showing a configuration example of a communication system according to the second embodiment.
7 is a sequence diagram showing an operation example of the communication system according to the second embodiment.
8 is a block diagram showing a configuration example of a communication system according to a third embodiment.
9 is a sequence diagram showing an operation example of the communication system according to a third embodiment.
FIG. 10 is a block diagram showing a configuration example of a communication system according to the fourth embodiment.
11 is a sequence diagram showing an operation example of the communication system according to the fifth embodiment.
12 is a sequence diagram showing an operation example of the communication system according to the sixth embodiment.
DESCRIPTION OF THE INVENTION
[0018]
 Hereinafter, the first to sixth embodiments of the present invention will be described with reference to the drawings. In the drawings, the same components are denoted by the same reference numerals, for clarity of description, repeated explanation is omitted as appropriate.
[0019]

 As shown in FIG. 1, a communication system according to the present embodiment, a plurality of communication terminals 10_1 ~ 10_n (n is an integer of 2 or more) containing a, a node device 20.
[0020]
 Communication terminal 10_1 ~ 10_n form a communication group 100, enjoy a variety of services using the group communication Te or more. Communication terminals 10_1 ~ 10_n, for example, a cellular phone, a smart phone or M2M terminal, or a communication function may be a computer device or the like having a. Terminals forming the communication group 100, for example, a plurality of wearable devices that the user has worn, the network home appliances such installed in the home, the sensor and the meters in the building, the communication terminals in familial and certain groups , it may be a vending machine or the like by the manufacturer to manage. The communication terminal 10_1 ~ 10_n communicates with the node apparatus 20 via the base station 300. Communication terminals 10_1 ~ 10_n is predominantly connected wirelessly to the base station 300 may be connected to the base station 300 by wire. On the other hand, the base station 300 will be primarily connected wired in to the node device 20 may be connected wirelessly to the node device 20. In the following description, the communication terminal 10_1 ~ 10_n, occasionally represented by a reference numeral 10.
[0021]
 Here, the service using a group communication, for example, include broadcasting services for members of the communication group 100 is. That is, the communication terminal 10_1 ~ 10_n belonging to the communication group 100 may receive the same information simultaneously. Alternatively, the communication group 100 belongs smartphones and wearable devices such that the user holds the same information to the smart phone and the wearable device or the like may be transmitted. Alternatively, the communication terminal 10_1 ~ 10_n may be present at positions remote from each other, it is also possible to receive the same information in such a remote location.
[0022]
 Node device 20 performs an authentication process to the communication terminal 10. Node device 20, for example, there in UE (User Equipment) is defined as a device that performs the authentication processing for, MME (Mobility Management Entity) or SGSN (Serving GPRS (General Packet Radio Service) Support Node) or the like in the 3GPP and it may be.
[0023]
 Also, the node device 20 as an operation unique to the present embodiment, to perform various processes so as to securely manage keys used for group communication.
[0024]
 Specifically, as shown in FIG. 2, the node device 20 includes a derivation unit 21, a calculating unit 22, a transmission unit 23.
[0025]
 Derivation unit 21, information shared between the communication terminal 10_1 ~ 10_n each the node device 20 by the authentication processing (hereinafter, "shared information" and designation) using a unique key to the communication terminal 10_1 ~ 10_n each (hereinafter, referred to as a "group device key") to derive. In addition, the derivation unit 21, a common key to the communication group 100 (hereinafter referred to as "group key" and called) to derive.
[0026]
 Here, the shared information, when the node device 20 is the MME can be used Kasme (Key Access Security Management Entity), when the node device 20 is the SGSN CK (Cipher Key), and IK (Integrity Key) can be used. The group device key may if derived differently for each communication device, and its derivation can be applied various algorithms. An example of such an algorithm, KDF defined by 3GPP (Key Derivation Function) and the like. Furthermore, the group key may if unique communication group 100, can be used, for example random numbers.
[0027]
 Calculation unit 22 calculates the exclusive OR of the group device keys and group keys. This calculation process is performed for each communication terminal. For example, as shown in FIG. 3, for a certain communication terminal by deriving unit 21, a group device key 201 composed of a bit string "0011 ...", the group key 202 composed of a bit string "0101" has been derived. In this case, the calculating unit 22 obtains a calculation result of the exclusive, the XOR (Exclusive OR or Exclusive disjunction) value 203 composed of a bit string "0110 ...". The group device key 201, group key 202 and XOR value 203 each bit length is arbitrary and may be set according to a communication standard such as to apply.
[0028]
 Transmitter 23, each XOR value calculated for each communication terminal, and transmits to the communication terminal 10_1 ~ 10_n each addressed.
[0029]
 Incidentally, these deriving unit 21, calculation unit 22 and the transmitter 23 can be configured by at least the hardware. Such hardware, for example, a transceiver and communicating with the communication terminal 10 includes a controller such as a CPU for controlling the transceiver (Central Processing Unit).
[0030]
 On the other hand, as shown in FIG. 4, the communication terminal 10 includes a derivation unit 11, a receiving unit 12, a reproduction portion 13.
[0031]
 Deriving unit 11 uses the shared information described above to derive a unique group device key to the own communication terminal 10. At this time, deriving unit 11 applies the same algorithm as that node 20 is applied to derive the same group device key to that node device 20 is derived Te following. Incidentally, in a case like the candidates of applicable algorithms or information there are multiple, it may instruct the algorithm or information to be applied from the node device 20. Such an indication may be performed using, for example KSI (Key Set Identifier) ​​or the like.
[0032]
 Receiver 12 from the node device 20, receives the XOR value calculated for the own communication terminal 10.
[0033]
 Reproducing unit 13, and group device key derived by the derivation unit 11 calculates the exclusive OR of the received XOR value by the receiving unit 12, reproduces the common group key to the node device 20 Te than (derived ,get. Now, as shown in FIG. 5, the deriving unit 11, the group device key 201 composed of the same bit sequence "0011 ..." as shown in FIG. 3 is derived, identical to that shown by the receiving section 12, FIG. 3 the XOR value 203 composed of a bit string of "0110 ..." has been received. In this case, the playback unit 13, a calculation result of the exclusive OR obtained bit string "0101 ...". The bit string "0101" is the same as the group key 202 shown in FIG.
[0034]
 Incidentally, these deriving unit 11, receiving unit 12 and the playback unit 13 can be constituted by at least hardware. Such hardware, for example, a transceiver and for communication with the node device 20 includes a controller such as a CPU for controlling the transceiver.
[0035]
 Above-described above, in this embodiment, the group key, Without being distributed from the node device 20 to the communication terminal 10 is shared between the communication terminal 10 and the node device 20. For this reason, also that the group key is leaked to a third party, in due group communication It would also be no monkey eavesdropping. Therefore, according to this embodiment, as compared with the technology disclosed in Non-Patent Document 3, it is possible to manage a group key safer.
[0036]
 In addition, even if if the XOR value is leaked, as described above, only XOR value, able to play the group key has become impossible. For this reason, to play for a third party, a group key is extremely difficult. Incidentally, as described later, from the node device 20 encrypts the XOR value may be transmitted to the communication terminal 10. In this case, the reproduction of the group key by a third party becomes more difficult.
[0037]

 This embodiment, generally, the concepts described in the first above-described embodiment is intended to apply to the LTE system.
[0038]
 As shown in FIG. 6, the communication system according to the present embodiment, a plurality of devices 30 _ 1 ~ 30_N (hereinafter, occasionally represented by a reference numeral 30) and a type of the radio base station eNB (evolved Node B) 40, and a MME 50. Here, the device 30 _ 1 ~ 30_N corresponds to the communication terminal 10_1 ~ 10_n shown in FIG. 1, except that executes processes related signaling conforming to the LTE standard, similar to the communication terminal 10 shown in FIG. 4 It can be configured to. MME 50 corresponds to the node device 20 shown in FIG. 1, except that executes processes related signaling conforming to the LTE standard, can be configured similarly to the node device 20 shown in FIG. Traffic between the device 30 and MME 50 is transmitted through the backhaul (backhaul) link between the radio link, and eNB 40 and MME 50 between the device 30 and eNB 40. In the example shown in FIG. 6, but the device 30 _ 1 ~ 30_N are dealing with cases of wireless connection to the same eNB 40, the device 30 _ 1 ~ 30_N may be wirelessly connected to a different eNB mutually.
[0039]
 In operation, as shown in FIG. 7, the device 30 _ 1 ~ 30_N each, the Attach Request message, and transmits to the MME 50 via the eNB 40, requesting to attach to MME 50 Te following (step S11). Then, in MME 50 led authentication process for the device 30 _ 1 ~ 30_N each, that AKA as disclosed in Non-Patent Document 1 (Authentication and Key Agreement) Procedure is performed (step S12). The success of this AKA Procedure provides that the device 30 _ 1 ~ 30_N each and MME 50 share the Kasme. For example, the device 30_1 to share the MME 50 a Kasme_1 device 30_2 shares with MME 50 a (different from the Kasme_1) Kasme_2.
[0040]
 Device 30_1 ~ 30_n is, Kasme_1 from ~ Kasmen_n, device-specific group device key 201_1 ~ 201_n to derive, respectively (step S13).
[0041]
 On the other hand, MME 50 is a device 30 _ 1 ~ 30_N each verifies whether it can receive the service using the group communication (step S14). Such verification may, for example, may be performed based on the contract information of the device 30_1 ~ 30_n (subscription information) and a network policy, or the like. Upon successful verification, MME 50 is configured to derive each unique group device keys 201_1 ~ 201_n to the device 30 _ 1 ~ 30_N from Kasme_1 ~ Kasmen_n, common group key 202 to the communication group 110 that the device 30 _ 1 ~ 30_N belongs (e.g., random number) to derive (step S15).
[0042]
 Furthermore, MME 50 is the exclusive OR of the group device keys 201_1 ~ 201_n and group key 202 respectively calculated to obtain the XOR value 203_1 ~ 203_n Te following (step S16).
[0043]
 Then, MME 50 is a Attach Response message including the XOR value 203_1 ~ 203_n, respectively transmit to the device 30 _ 1 ~ 30_N via the eNB 40 (step S17).
[0044]
 In this case, MME 50 encrypts the XOR values ​​203_1 ~ 203_n, including Attach Response message. During encryption, can be used NAS (Non Access Stratum) security context shared between the device 30 _ 1 ~ 30_N each and MME 50 in AKA Procedure. The NAS security context contains NAS keys, these NAS keys, and is used to protect the integrity of the traffic between the UE and the MME (integrity) and confidentiality (confidentiality). Incidentally, MME 50 is an XOR value 203_1 ~ 203_n encrypted, Attach Response message different from the message (e.g., new message) may be included in.
[0045]
 Device 30 _ 1 ~ 30_N are, Attach the Response receiving the message, the exclusive OR of the the XOR value 203_1 ~ 203_n with decoded using the NAS security context of the above, the group device key 201_1 ~ 201_n and XOR values ​​203_1 ~ 203_n the calculated respectively. Thus, the group key 202, are reproduced by the device 30 _ 1 ~ 30_N respectively, and be shared between the devices 30 _ 1 ~ 30_N each and MME 50 Te following (step S18). Incidentally, the principle of group key is played on the device is similar to the principle described above with reference to FIGS. 3 and 5.
[0046]
 According to this embodiment, in the LTE system, a group key can be similarly safely manage the above-mentioned first embodiment. Further, the encryption of XOR values, the security of the group key management can be further improved.
[0047]

 This embodiment, generally, the concepts described in the first above-described embodiment is intended to apply to the 3G system.
[0048]
 As shown in FIG. 8, a communication system according to this embodiment, a plurality of devices 30 _ 1 ~ 30_N, and NB (Node B) 60 is a kind of radio base station, RNC for controlling the NB 60 (Radio Network and Controller) 70, and a SGSN 80. Here, the device 30 _ 1 ~ 30_N corresponds to the communication terminal 10_1 ~ 10_n shown in FIG. 1, except that executes processes related signaling conforming to 3G standards, similar to the communication terminal 10 shown in FIG. 4 It can be configured to. SGSN 80 corresponds to the node device 20 shown in FIG. 1, except that executes processes related signaling conforming to 3G standards, it can be configured similarly to the node device 20 shown in FIG. Traffic between the device 30 and SGSN 80, the wireless link between the device 30 and NB 60, and transmitted over the backhaul link between the NB 60, RNC 70 and SGSN 80. In the example shown in FIG. 8, although the device 30 _ 1 ~ 30_N are dealing with cases of wireless connection to the same NB 60, the device 30 _ 1 ~ 30_N may be wirelessly connected to a different NB each other.
[0049]
 In operation, as shown in FIG. 9, first, the device 30 _ 1 ~ 30_N each, the Attach Request message, via the RNC 70 (and NB 60 not shown) transmits to the SGSN 80, of the SGSN 80 Te than requesting an attach (step S21). Then, in SGSN 80 led authentication process for the device 30 _ 1 ~ 30_N each, that AKA Procedure as disclosed in Non-Patent Document 2 is performed (step S22). The success of this AKA Procedure provides that the device 30 _ 1 ~ 30_N each and SGSN 80 share the CK and IK. For example, the device 30_1 to share CK_1 and IK_1 the SGSN 80, the device 30_2 is CK_2 and IK_2 (CK_1 and IK_1 different from each) to share the SGSN 80.
[0050]
 Device 30 _ 1 ~ 30_N are, CK_1 from ~ CK_n and IK_1 ~ IK_n, device-specific group device keys 201_1 ~ 201_n the deriving respectively (step S23).
[0051]
 Meanwhile, SGSN 80, the device 30 _ 1 ~ 30_N each verifies whether it can receive the service using the group communication (step S24). Such verification may, for example, may be performed based on the contract information of the device 30_1 ~ 30_n (subscription information) and a network policy, or the like. Upon successful verification, SGSN 80 may, CK_1 ~ CK_n and thereby derive each unique group device keys 201_1 ~ 201_n to IK_1 ~ IK_n from the device 30 _ 1 ~ 30_N, common group key to the communication group 110 that the device 30 _ 1 ~ 30_N belongs 202 (e.g., random number) to derive (step S25).
[0052]
 Further, SGSN 80 is the exclusive OR of the group device keys 201_1 ~ 201_n and group key 202 respectively calculated to obtain the XOR value 203_1 ~ 203_n Te following (step S26).
[0053]
 Then, SGSN 80 is the Attach Response message including the XOR value 203_1 ~ 203_n, respectively transmit to the device 30 _ 1 ~ 30_N through the RNC 70 (step S27).
[0054]
 At this time, SGSN 80 encrypts the XOR values ​​203_1 ~ 203_n, including Attach Response message. During encryption, can be used UMTS (Universal Mobile Telecommunications System) security context shared between the device 30 _ 1 ~ 30_N each and SGSN 80 in AKA Procedure. The UMTS security context contains UMTS keys, these UMTS keys, and is used to protect the integrity and confidentiality of traffic between the UE and SGSN. Incidentally, SGSN 80 is the XOR value 203_1 ~ 203_n encrypted, Attach Response message different from the message (e.g., new message) may be included in.
[0055]
 Device 30 _ 1 ~ 30_N are, Attach the Response receiving the message, the exclusive OR of the the XOR value 203_1 ~ 203_n with decoded using the UMTS security context of the above, the group device key 201_1 ~ 201_n and XOR values ​​203_1 ~ 203_n the calculated respectively. Thus, the group key 202, are reproduced by the device 30 _ 1 ~ 30_N respectively, and be shared between the devices 30 _ 1 ~ 30_N each and SGSN 80 Te following (step S28). Incidentally, the principle of group key is played on the device is similar to the principle described above with reference to FIGS. 3 and 5.
[0056]
 According to this embodiment, in the 3G systems, the group key may be similarly safely manage the above-mentioned first embodiment. Further, the encryption of XOR values, the security of the group key management can be further improved.
[0057]

 As shown in FIG. 10, the communication system according to this embodiment, in addition to the configuration of the communication system shown in FIG. 1, the master device (also base unit and the parent device or the like is referred) 90 in that is provided, different from the first embodiment described above.
[0058]
 Master device 90 is one of a communication terminal representing the communication group 100. Master device 90, for example, a cellular phone, a smart phone or M2M terminal, or a communication function may be a computer device or the like having a. Alternatively, the master device 90 may be a mobile router. Master device 90 is a mobile router, mobile phone, when a smart phone or a M2M terminal or the like, but is connected to the base station 300 by radio as shown in FIG. 10, when fixed is such a wireless router, etc., wired in being connected to the base station 300.
[0059]
 In operation, the master device 90 from the node device 20, the communication terminal (with handset and expansion devices such as are referred) 10_1 ~ 10_n receives XOR values ​​calculated for each of the communication terminals 10_1 ~ 10_n the XOR value received to distribute to. On the other hand, the communication terminal 10_1 ~ 10_n is authenticated individually by Embodiment 1 similarly to the node device 20 of the above-described communication terminal 10_1 ~ 10_n each derivation portion 11 (see FIG. 4), using the shared information of the to derive the group device key Te. Then, the receiving unit 12 receives the XOR values ​​distributed by the master device 90, the reproduction unit 13, and group device key derived by the deriving unit 11, exclusive of the received XOR value by the receiving section 12 to calculate the sum, to play the group key Te or more.
[0060]
 Thus, in the present embodiment, the master device 90, on behalf of the communication group 110 receives the XOR value from the node device 20. Thus, the signaling amount required for the transmission of the XOR value, can be reduced as compared with the above-mentioned first embodiment. Of course, similarly to the first embodiment described above, the group key because it is not delivered from the node device 20 to the communication terminal 10 can be securely manage the group key.
[0061]
 The communication between the communication terminal 10 with the master device 90 may if performed with reference to any communication system. Master device 90, for example, may be in communication with the communication terminal 10 using a wireless LAN (Local Area Netwrok) communication, using the short-range wireless communication such as Bluetooth (registered trademark) or NFC (Near Field Communication) it may be in communication with the communication terminal 10 Te. When the communication terminal 10 is located in the distance, the master device 90 may communicate with the communication terminal 10 via the mobile network.
[0062]

 This embodiment, generally, both concepts described in the fourth concept and the embodiment described with reference to the above-mentioned first embodiment is to apply to the LTE system.
[0063]
 Although not shown, a communication system according to the present embodiment, except that the master device 90 between the device 30 _ 1 ~ 30_N and eNB 40 is interposed, can be configured similarly to the communication system shown in FIG.
[0064]
 In operation, as shown in FIG. 11, the first master device 90 and the MME 50 Prefecture, in order to perform an authentication process for performing normal communication through the mobile network, MME 50 is, the master device 90 the Authentication Request message sending to (step S31). In this case, MME 50 is, AV a (Authentication Vector), included in Authentication Request message.
[0065]
 Master device 90, AV received from the MME 50, and using the self-device SIM (Subscriber Identity Module) information and key information, execute the operation predetermined, MME 50 including the operation result to the Authentication Response message to send to (step S32). MME 50 may use the calculation result received from the master device 90, and a calculation result in the own device, performs an authentication process related to the master device 90.
[0066]
 Then, the master device 90 in order to perform an authentication process regarding communication group 110, sends a Group Authentication Request message to the MME 50 (Step S33). At this time, the master device 90, for example, sets the information for identifying the communication group 110 to Group Authentication Request message. Furthermore, the master device 90, the identification information of all the devices 30 _ 1 ~ 30_N belonging to the communication group 110 may be set to Group Authentication Request message.
[0067]
 MME 50 belongs device to the communication group 110 (with handset and expansion devices such as are referred) to 30 _ 1 ~ 30_N, checks by using the information contained in the Group Authentication Request message (step S34).
[0068]
 Furthermore, MME 50 is similar to step S15 in FIG. 7, Kasme_1 with derives each unique group device keys 201_1 ~ 201_n to the device 30 _ 1 ~ 30_N from ~ Kasmen_n, common to communication group 110 that the device 30 _ 1 ~ 30_N belong group key 202 (e.g., random number) to derive (step S35).
[0069]
 Furthermore, MME 50 is the exclusive OR of the group device keys 201_1 ~ 201_n and group key 202 respectively calculated to obtain the XOR value 203_1 ~ 203_n Te following (step S36).
[0070]
 Then, MME 50 is a Group Authentication Response message including the XOR value 203_1 ~ 203_n, and transmits to the master device 90 (step S37). In this case, MME 50, in the same manner as the above-described Embodiment 2, by encrypting the XOR values ​​203_1 ~ 203_n, may be included in the Group Authentication Response message. In such cases, increased confidentiality, the safety is ensured. Furthermore, MME 50 is a Group AV associated with communication group 110, it may be included in the Group Authentication Response message. Such Group AV, for example, can be subjected to applications where the master device 90 authenticates the device 30 _ 1 ~ 30_N.
[0071]
 Master device 90, the XOR value 203_1 ~ 203_n received from MME 50, distributes to the device 30 _ 1 ~ 30_N (step S38). Further, the master device 90 transmits a Group Authentication Confirmation message to the MME 50 (Step S39). Master device 90 to authenticate the device 30 _ 1 ~ 30_N, transmitted to MME 50, including the authentication result to the Group Authentication Confirmation message, the MME 50 Te than, be allowed to recognize the device 30 _ 1 ~ 30_N belonging to the communication group 110 good.
[0072]
 Meanwhile, although not shown, the device 30 _ 1 ~ 30_N is authenticated individually by MME 50 in AKA Procedure shown in FIG. 7, share a Kasme_1 ~ Kasmen_n the MME 50. Thus, the device 30 _ 1 ~ 30_N are, Kasme_1 from ~ Kasmen_n, device-specific group device keys 201_1 ~ 201_n derived respectively (step S40).
[0073]
 Then, the device 30 _ 1 ~ 30_N receives the XOR value 203_1 ~ 203_n from the master device 90 in step S38 described above, the exclusive OR of the group device keys 201_1 ~ 201_n and XOR values ​​203_1 ~ 203_n respectively calculated, Te following Play group key 202 (step S41). Incidentally, if the XOR value 203_1 ~ 203_n is encrypted, the device 30 _ 1 ~ 30_N can be decrypted using the above-described NAS security context.
[0074]
 According to this embodiment, it is possible in the LTE system, to reduce the signaling amount required for the transmission of the XOR value. Moreover, a group key can be similarly safely manage the above-described Embodiment 2. Further, the encryption of the XOR value, can be further improve the security of the group key management.
[0075]

 This embodiment, generally, both concepts described in the fourth concept and the embodiment described with reference to the above-mentioned first embodiment is to apply to the 3G system.
[0076]
 Although not shown, a communication system according to the present embodiment, except that the master device 90 between the device 30 _ 1 ~ 30_N and NB 60 are interposed, can be configured similarly to the communication system shown in FIG.
[0077]
 In operation, as shown in FIG. 12, the first master device 90 and the SGSN 80 Prefecture, in order to perform an authentication process for performing normal communication through the mobile network, SGSN 80 is the master device 90 the Authentication Request message to send to (step S51). At this time, SGSN 80 is included in the AV to the Authentication Request message.
[0078]
 Master device 90, AV received from the SGSN 80, and by using the SIM information and key information of its own device, it performs operations defined in advance, and sends the calculation result to the SGSN 80 included in the Authentication Response message (step S52). SGSN 80, using the calculation result received from the master device 90, and a calculation result in the own device, performs an authentication process related to the master device 90.
[0079]
 Then, the master device 90 in order to perform an authentication process regarding communication group 110, sends a Group Authentication Request message to the SGSN 80 (step S53). At this time, the master device 90, for example, sets the information for identifying the communication group 110 to Group Authentication Request message. Furthermore, the master device 90, the identification information of all the devices 30 _ 1 ~ 30_N belonging to the communication group 110 may be set to Group Authentication Request message.
[0080]
 SGSN 80 is a device 30 _ 1 ~ 30_N belonging to the communication group 110 is checked using information included in Group Authentication Request message (step S54).
[0081]
 Further, SGSN 80 is similar to step S25 in FIG. 9, CK_1 ~ CK_n and IK_1 with deriving each unique group device keys 201_1 ~ 201_n from ~ IK_n device 30 _ 1 ~ 30_N, communication group device 30 _ 1 ~ 30_N belong 110 deriving a common group key 202 (e.g., random number) (step S55).
[0082]
 Furthermore, SGSN 80 is the exclusive OR of the group device keys 201_1 ~ 201_n and group key 202 respectively calculated to obtain the XOR value 203_1 ~ 203_n Te following (step S56).
[0083]
 Then, SGSN 80 is a Group Authentication Response message including the XOR value 203_1 ~ 203_n, and transmits to the master device 90 (step S57). At this time, SGSN 80, in the same manner as the above third embodiment, by encrypting the XOR values ​​203_1 ~ 203_n, may be included in the Group Authentication Response message. In such cases, increased confidentiality, the safety is ensured. Further, SGSN 80 is a Group AV associated with communication group 110, it may be included in the Group Authentication Response message. Such Group AV, for example, can be subjected to applications where the master device 90 authenticates the device 30 _ 1 ~ 30_N.
[0084]
 Master device 90, the XOR value 203_1 ~ 203_n received from SGSN 80, is distributed to the devices 30 _ 1 ~ 30_N (step S58). Further, the master device 90 transmits a Group Authentication Confirmation message to SGSN 80 (step S59). Master device 90 to authenticate the device 30 _ 1 ~ 30_N, transmits to the SGSN 80 including the authentication result to the Group Authentication Confirmation message to SGSN 80 Te than, be allowed to recognize the device 30 _ 1 ~ 30_N belonging to the communication group 110 good.
[0085]
 Meanwhile, although not shown, the device 30 _ 1 ~ 30_N is individually authenticated by MME 50 in AKA Procedure shown in FIG. 9, share a CK_1 ~ CK_n and IK_1 ~ IK_n the SGSN 80. Thus, the device 30 _ 1 ~ 30_N are, CK_1 from ~ CK_n and IK_1 ~ IK_n, device-specific group device keys 201_1 ~ 201_n the deriving respectively (step S60).
[0086]
 Then, the device 30 _ 1 ~ 30_N receives the XOR value 203_1 ~ 203_n from the master device 90 in step S58 described above, the exclusive OR of the group device keys 201_1 ~ 201_n and XOR values ​​203_1 ~ 203_n respectively calculated, Te following Play group key 202 (step S61). Incidentally, if the XOR value 203_1 ~ 203_n is encrypted, the device 30 _ 1 ~ 30_N can be decrypted using the above-described UMTS security context.
[0087]
 According to this embodiment, it is possible in a 3G system, to reduce the signaling amount required for the transmission of the XOR value. Moreover, a group key can be managed safely as in the aforementioned third preferred embodiment. Further, the encryption of the XOR value, can be further improve the security of the group key management.
[0088]
 In the embodiment described above, the invention has been described as a hardware configuration, the present invention is not limited thereto. The present invention is a process in the communication terminal 10 and the node device 20 can also be implemented by executing a computer program to the CPU.
[0089]
 In this case, the program may be stored using a non-transitory computer readable media of various types (non-transitory computer readable medium), it can be supplied to the computer. Non-transitory computer readable media include with various types of entities (tangible storage medium). Examples of non-transitory computer readable media include magnetic storage media (such as floppy disks, magnetic tape, hard disk drive), magneto-optical recording medium (e.g. optical disk), CD-ROM (Read Only Memory), CD-R, CD-R / W, a semiconductor memory (e.g., a mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access memory)) includes a. The program may be provided to a computer using a temporary computer readable media of various types (transitory computer readable medium). Examples of transitory computer readable media include electric signals, optical signals, and electromagnetic waves. Transitory computer readable media, wired communication path such as electrical wires and optical fibers, or via a wireless communication path can provide the program to a computer.
[0090]
 Note that the present invention by the above-described embodiment is not intended to be limited, based on the description of the claims, it is clear that various modifications may be made by those skilled in the art.
[0091]
 This application claims priority based on Japanese Patent Application No. 2015-027356, filed on February 16, 2015, the entire disclosure of which is incorporated herein.
DESCRIPTION OF SYMBOLS
[0092]
 10 the communication terminal
 11, 21 deriving unit
 12 receiving unit
 13 playback unit
 20 node device
 22 calculating unit
 23 transmission unit
 30 the device
 40 eNB
 50 MME
 60 NB
 70 RNC
 80 SGSN
 90 master device
 100, 110 communication group
 201 Group device key
 202 group key
 203 XOR value

The scope of the claims
[Claim 1]
 A plurality of communication terminals forming a communication group,
 and a node apparatus that performs authentication processing for each communication terminal,
 the node device,
 by using the information shared between the communication terminal by the authentication process, deriving a first key specific to each communication terminal,
 derives a second key common to the communication group,
 calculates the exclusive OR of the second key and the first key,
 the each XOR (Exclusive OR) values obtained by the calculation, and transmitted to each communication terminal addressed,
 each communication terminal,
 the first key specific to the own communication terminal derived using the information, received from the node device and it calculates the exclusive OR of the the XOR value, reproducing the second key,
 the communication system.
[Claim 2]
 According to claim 1,
 wherein the node device, each XOR values, via a first communication terminal representing the communication group, distributes to each communication terminal,
 communication system, wherein the.
[Claim 3]
 According to claim 1 or 2,
 wherein the node device, each XOR value, the encrypt and send using the security context shared between the communication terminal by the authentication processing,
 the communication terminal is the encrypted each XOR values are decoded using the security context, the
 communication system, wherein the.
[Claim 4]
 In any one of claims 1 to 3,
 said node device and each communication device uses Kasme (Key Access Security Management Entity) as the information,
 communication system, wherein the.
[Claim 5]
 In any one of claims 1 to 3,
 said node device and the respective communication devices, using the CK (Cipher Key), and IK (Integrity Key) as the information,
 communication system, wherein the.
[Claim 6]
 A node device performs an authentication process for a plurality of communication terminals each forming a communication group,
 using the information shared between the communication terminal by the authentication processing, the first key specific to each communication terminal It derives a deriving unit for deriving a common second key to the communication group,
 a calculation unit for calculating an exclusive OR of the second key and the first key,
 obtained by the calculation unit each XOR value that is, a transmission unit for transmitting to the communication terminal addressed to
 the node device provided with.
[Claim 7]
 According to claim 6,
 wherein the transmission section, each XOR values, via a first communication terminal representing the communication group, distributes to each communication terminal,
 the node device characterized by.
[8.]
 According to claim 6 or 7,
 wherein the transmission section, each XOR value, encrypted and transmitted using the security context shared between the communication terminal by the authentication processing,
 the node device characterized by.
[Claim 9]
 According to any one of claims 6-8,
 wherein the deriving unit uses Kasme as the information,
 the node device characterized by.
[Claim 10]
 According to any one of claims 6-8,
 wherein the deriving unit uses a CK and IK as the information,
 the node device characterized by.
[Claim 11]
 A communication terminal that forms a communication group with another communication terminal,
 using the information shared between the node device by the authentication processing for the self communication terminal, to derive the first key specific to the own communication terminal a deriving unit,
 from the node device, a receiving unit that receives the XOR value,
 reproducing the first key and calculates the exclusive OR of the XOR value, a second key common to the communication group It includes a reproducing unit that, the,
 the XOR value, the node device, is obtained by calculating the exclusive OR of the first key and the second key,
 the communication terminal.
[Claim 12]
 According to claim 11,
 wherein the receiving unit, the XOR value, received via the first communication terminal representing the communication group,
 the communication terminal characterized by.
[Claim 13]
 According to claim 11 or 12,
 wherein the XOR value is encrypted using the security context to be shared between said node device by the authentication processing,
 the reproducing unit, the encrypted XOR value , wherein the decoded using a security context,
 the communication terminal characterized by.
[Claim 14]
 According to any one of claims 11 to 13,
 wherein the deriving unit uses Kasme as the information
 communication terminal, wherein the.
[Claim 15]
 According to any one of claims 11 to 13,
 wherein the deriving unit uses a CK and IK as the information,
 communication terminal characterized in that.
[Claim 16]
 A key management method executed in a node device which performs an authentication process for a plurality of communication terminals each forming a communication group,
 using the information shared between the communication terminal by the authentication process, the communication terminals to derive the first key unique,
 to derive a second key common to the communication group,
 it calculates the exclusive OR of the second key and the first key,
 obtained by the calculation each of the XOR value, transmits to each communication terminal addressed to
 key management method comprising.
[Claim 17]
 A key management method executed in a communication terminal to form a communication group with another communication terminal,
 using the information shared between the node device by the authentication processing for the communication terminal, specific to the communication terminal deriving a first key,
 from the node device, it receives the XOR value,
 the first key and calculates the exclusive OR of the XOR value, a second key common to the communication group play, said method comprising,
 the XOR value, the node device, is obtained by calculating the exclusive OR of the first key and the second key,
 the key management method.
[Claim 18]
 The non-transitory computer readable medium storing a program to be executed by the a node device which performs an authentication process for a plurality of communication terminals each forming a communication group computer,
 the computer,
 each by the authentication processing using the information shared between the communication terminal, the process of deriving the first key specific to each communication terminal,
 a process of deriving a common second key to the communication group,
 the first a process for calculating an exclusive OR of key and said second key,
 each XOR value obtained by the calculation, a process of transmitting to the communication terminal addressed,
 non-transitory which stores a program for executing the a computer-readable media.
[Claim 19]
 The non-transitory computer readable medium storing a program to be executed by the a communication terminal computer forming a communication group with another communication terminal,
 the computer,
 and the node device by the authentication processing for the communication terminal using the information shared between the process of deriving the first key unique to the communication terminal,
 from the node device, and a process of receiving the XOR value,
 and the first key and the XOR value and calculating an exclusive OR, a process of reproducing the common second key to said communication group, is executed,
 the XOR value, the node device, and the first key and the second it is obtained by calculating the exclusive OR of the key,
 a non-transitory computer readable medium which stores a program.

Documents

Application Documents

# Name Date
1 201717027498-STATEMENT OF UNDERTAKING (FORM 3) [02-08-2017(online)].pdf 2017-08-02
2 201717027498-REQUEST FOR EXAMINATION (FORM-18) [02-08-2017(online)].pdf 2017-08-02
3 201717027498-PRIORITY DOCUMENTS [02-08-2017(online)].pdf 2017-08-02
4 201717027498-POWER OF AUTHORITY [02-08-2017(online)].pdf 2017-08-02
5 201717027498-FORM 18 [02-08-2017(online)].pdf 2017-08-02
6 201717027498-FORM 1 [02-08-2017(online)].pdf 2017-08-02
7 201717027498-DRAWINGS [02-08-2017(online)].pdf 2017-08-02
8 201717027498-DECLARATION OF INVENTORSHIP (FORM 5) [02-08-2017(online)].pdf 2017-08-02
9 201717027498-COMPLETE SPECIFICATION [02-08-2017(online)].pdf 2017-08-02
10 201717027498.pdf 2017-08-03
11 abstract.jpg 2017-08-04
12 201717027498-RELEVANT DOCUMENTS [10-08-2017(online)].pdf 2017-08-10
13 201717027498-MARKED COPIES OF AMENDEMENTS [10-08-2017(online)].pdf 2017-08-10
14 201717027498-AMMENDED DOCUMENTS [10-08-2017(online)].pdf 2017-08-10
15 201717027498-Amendment Of Application Before Grant - Form 13 [10-08-2017(online)].pdf 2017-08-10
16 201717027498-Verified English translation (MANDATORY) [11-08-2017(online)].pdf 2017-08-11
17 201717027498-Proof of Right (MANDATORY) [11-08-2017(online)].pdf 2017-08-11
18 201717027498-certified copy of translation (MANDATORY) [11-08-2017(online)].pdf 2017-08-11
19 201717027498-Power of Attorney-080817.pdf 2017-08-16
20 201717027498-Correspondence-080817.pdf 2017-08-16
21 201717027498-OTHERS-160817.pdf 2017-08-22
22 201717027498-OTHERS-160817-.pdf 2017-08-22
23 201717027498-OTHERS-160817--.pdf 2017-08-22
24 201717027498-Correspondence-160817.pdf 2017-08-22
25 201717027498-FORM 3 [30-01-2018(online)].pdf 2018-01-30
26 201717027498-FER.pdf 2020-02-25

Search Strategy

1 SearchPattern201717027498_19-02-2020.pdf