Home | Links | Contact Us | More About Intellectual Property | Bookmark
Search patents:
Home Audio Signal Processing Method-and-apparatus-for-sending-secure-datagram-multicasts

 Source data compression and decompression in code symbol printing and decoding
In accordance with the teachings of the present invention, a coded symbol encoding and decoding ...


 Noise eliminating circuit
Accordingly, it is an object of the present invention to provide a noise eliminating circuit in ...


 Method for generating a random number for the encoded transmission of data upon employment of a variable starting value
What is claimed is: 1. Method for generating a random number for the encoded transmission of data ...


 High common mode relay multiplexer
I claim: 1. In a multiplexer having a plurality of signal channels, each of said channels having a ...


 Loudspeaker having a voice coil and a piezoelectric feedback transducer
What is claimed is: 1. A loudspeaker comprising, a cone-shaped vibratory diaphragm having an inner ...


 Speech recognition apparatus with means for preventing errors due to delay in speech recognition
The present invention has been made in consideration of the above conventional problem and has as ...


 Electronic musical instrument with manipulation plate
An object of this invention is to provide an electronic musical instrument capable of forming ...


 Health club audio system
In accordance with this invention, there is provided an integrated audio amplifier system ...


 Sound reproduction system
The sound system A of this invention is particularly adapted for reproducing music, irrespective ...


 Speech aid apparatus for laryngectomees
What is claimed is: 1. Speech aid apparatus for laryngectomees, comprising a sound head consisting ...


 Method and apparatus for sending secure datagram multicasts

Details
Inventors: Aziz, Ashar;
Assignee: Sun Microsystems, Inc. (Palo Alto, CA)
Primary Examiner: Swann; Tod R.
Assistant Examiner: Callahan; Paul E.
Attorney, Agent or Firm: Beyer & Weaver, LLP

A method and apparatus for generating additional implicit keys from a key [K.sub.ij ].sub.N without the necessity of generating a new Diffie-Helman (DH) certificate or requiring communication between nodes to change implicit master keys is disclosed. A first data processing device (node I) is coupled to a private network which is in turn coupled to the Internet. A second data processing device (node J) is coupled to the same, or to a different network, which is also coupled to the Internet, such that node I communicates with node J using the Internet protocol. Node I is provided with a secret value i and a public value. Data packets (referred to as "datagrams") are encrypted to enhance network security. Each node maintains an internal value of N which is incremented based on time and upon the receipt of a data packet from another node. The key [K.sub.ij ].sub.N.sbsb.i is derived from the appropriate quantity of .varies..sup.Nij by using high order key-sized bits of the respective quantity. The present invention then utilizes the key [K.sub.ij ].sub.N.sbsb.i to encrypt a transient key which is referred to as K.sub.p. Node I encrypts the IP data in K.sub.p and encrypts K.sub.p in [K.sub.ij ].sub.N.sbsb.i. Node I transmits the encrypted IP datagram packet in the encrypted key K.sub.p to the receiving node J. Node I further includes its current internal value of N.sub.i in the outgoing packet. The present invention also provides for the application of one-way functions to the shared secret to enhance security. Thus, either node I or node J may change the context such that if in the future [K.sub.ij ].sub.Ni is compromised, or is not useable by a cracker to either decrypt prior encrypted packets. The present invention discloses methods and apparatus for achieving perfect forward security for closed user groups, and for the application of the SKIP methodology to datagram multicast protocols.

DETAILED DESCRIPTION The present invention provides an improved simple key management scheme (SKIP) having particular application to datagram protocols, such as the Internet protocol (IP).
In one embodiment, the present invention discloses a method and apparatus for generating additional implicit keys from a key [K.
sub.
ij ].
sub.
N without the necessity of generating a new Diffie-Helman (DH) certificate or requiring any communication between nodes to change keys.
A first data processing device (node I) is coupled to a private network which is in turn coupled to the Internet.
A second data processing device (node J) is coupled to the same, or to a different network, which is also coupled to the Internet, such that node I communicates with node J using the Internet protocol.
Node I is provided with a secret value i and a public value which in one embodiment takes the form .
varies.
.
sup.
i mod p.
Data packets (referred to as "datagrams") are encrypted using the teachings of the present invention to enhance network security.
A source node I obtains a DH certificate for node J and obtains node J's public value .
varies.
.
sup.
j mod p from the DH certificate.
Node I then computes the value of, in one embodiment .
varies.
.
sup.
Nij mod p, and derives a key [K.
sub.
ij ].
sub.
N.
sbsb.
i from the value .
varies.
.
sup.
Nij mod p (or alternatively, .
varies.
.
sup.
(M.
spsp.
N.
sup.
)ij mod p, where M=2, 3, .
.
.
and N=0, 1, 2 .
.
.
).
Each node maintains an internal value of N which is incremented based on time and upon the receipt of a data packet from another node.
In the presently preferred embodiment, the value N is stored within the Security Association ID (SAID) field of an Internet specification of the IP Security Protocol (IPSP) defined by the Internet Engineering Task Force.
The key [K.
sub.
ij ].
sub.
N.
sbsb.
i is derived from the appropriate quantity of .
varies.
.
sup.
Nij by using low order key-sized bits of the respective quantity.
The present invention then utilizes the key [K.
sub.
ij ].
sub.
N.
sbsb.
i to encrypt a transient key which is referred to as K



Related patents
  Mounting arrangement for a position locating system
The above-stated problems and relates problems of the prior art solved with the principles of the present mounting arrangement. The rigid body having the exposed touch ...
  Amplifier device for a condenser microphone
It is an object of the invention to provide an amplifier with the above problems solved, or an amplifier capable of using even the FET common-source type buffer ...
  Multichannel matrix logic and encoding systems
What is claimed is: 1. In a UMX encoder comprising means for encoding multidirectional source signals in a plurality of at least two transmission channels with ...
  Expansion circuit for improved stereo and apparent monaural image
I claim: 1. An expander circuit for a multi-channel amplifier system including left and right amplifier channels respectively driving left and right speaker units, each ...
  Universal automotive electronic radio with display for tuning or time information
OF A PREFERRED EMBODIMENT OF THE INVENTION The invention is better understood with reference to the figures wherein common numbers for the same or similar items have ...
  Video disc encoding and decoding system providing intra-field track error correction
FIGS. 1 and 2 provide a comparison of a field-by-field track error correction method (FIG. 1) with the line-by-line correction method (FIG. 2). In FIG. 1, five adjacent ...
  Sound reproducing apparatus for use in vehicle
In consideration of the above-described problems, the present invention provides a sound reproducing apparatus for use in a vehicle which is capable of making the sound ...
  Control arrangement for electronic appliance
Accordingly, it is an object of the present invention to provide an electronic appliance that avoids the above-described disadvantages and difficulties of the prior art. ...
  Color video display for audio signals
The embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows: 1. A chrominance generator circuit for a television ...
  Desk/wall mounted telephone subset
A telephone subset embodying the invention has a desk and wall mount capability and employs an east-to-west oriented handset. The subset base has a bearing at a first ...

0.004

Archive: All patents - Links

Copyright (c)2006 Eipa-patents.org - All rights reserved