IP Library Granted Patent US 12712712
Granted Patent B2
US 12712712 · App. 18/033,086 · Granted Aug 18, 2026

Method and device for distributing a multicast encryption key

Inventor: Oscar Garcia Morchon (Eindhoven, NL)
Assignee: Koninklijke Philips N.V.
H04L9/0833H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712712
App. No.
18/033,086
Granted
Aug 18, 2026
Kind
B2
Abstract

The present invention relates to a method for a primary station distributing an encryption key to a plurality of secondary stations. The method comprises the steps of determining whether a group key needs to be updated, said group key being used for multicast encrypted communication from the primary station to the plurality of secondary stations, upon determining that an update is required, transmit to at least one first subset of the secondary stations through an encrypted unicast message a first set key by uni-cast, transmitting in a multicast message to the first set of the secondary stations an updated group key, said multicast message being encrypted by means of the first set key, or alternatively including said updated group key in the encrypted unicast message carrying the first step key, transmitting in respective multicast messages to further respective sets of secondary station the updated group key, said multicast messages being encrypted by means of respective set keys associated with each corresponding set.

Claims (52)

1 . A method for a primary station to distribute a cryptographic key to a plurality of secondary stations, the method comprising the steps of:

determining whether a group key needs to be updated, said group key being used for multicast protected communication from the primary station to the plurality of secondary stations, and

upon determining that an update is required, transmitting to at least a subset of the secondary stations through an encrypted message an updated cryptographic key,

wherein the updated cryptographic key is a first set key shared to a first set of secondary stations that allows encrypting multicast messages addressed to the first set of secondary stations, and

wherein the encrypted message is sent in unicast.

2 . The method of claim 1 , wherein the updated cryptographic key is an updated group key, and wherein the encrypted message is encrypted by means of a user specific encryption key and sent in unicast.

3 . The method of claim 1 , wherein determining whether a group key needs to be updated includes determining whether at least one of the following conditions is satisfied: at least one of the secondary stations' access rights have been revoked, at least one of the secondary stations' access rights have expired, a validity time of the group key has expired, at least one of the secondary stations has moved away from a predetermined location.

4 . The method of claim 1 , wherein the first set key is updated upon determination that the access rights of at least one of the secondary stations belonging to the first set are not currently valid.

5 . The method of claim 4 , further comprising the step of transmitting an updated group key to each set of secondary stations by means of a message protected with a respective set key associated to each set of secondary stations.

6 . The method of claim 4 , further comprising the step of transmitting an updated group key to at least a first and a second sets of secondary stations by means of a multicast message containing at least a first and a second protected group keys, wherein the first protected group key is protected with a first set key associated to the first set of secondary stations and the second protected group key is protected with a second set key associated to the second set of secondary stations.

7 . The method of claims 4 , wherein the multicast message includes along with the protected updated group key an authentication fingerprint message that allows checking whether the integrity of the decrypted group key.

8 . The method of claim 1 , wherein multicast messages are retransmitted periodically.

9 . A program code means of a computer program stored/distributed on a non-transitory computer readable medium, the non-transitory computer-readable medium comprising instructions adapted to, when executed on a computer, cause the computer to perform the steps of the method claimed in claim 1 .

10 . A method for a primary station to distribute a cryptographic key to a plurality of secondary stations, comprising the steps of:

determining whether a group key needs to be updated, said group key being used for protected multicast communication from the primary station to the plurality of secondary stations, and

upon determining that an update is required, transmitting in respective multicast messages to respective sets of secondary station an updated group key, said multicast messages being protected by means of respective set keys associated with each corresponding set,

wherein the updated cryptographic key is a first set key shared to a first set of secondary stations that allows encrypting multicast messages addressed to the first set of secondary stations, and

wherein the updated cryptographic key is sent in unicast.

11 . The method of claim 10 , wherein determining whether a group key needs to be updated includes determining whether at least one of the following conditions is satisfied:

at least one of the secondary stations' access rights have been revoked,

at least one of the secondary stations' access rights have expired,

a validity time of the group key has expired,

at least one of the secondary stations has moved away from a predetermined location.

12 . The method of claim 10 , further comprising, upon the determination that the group key is linked to access rights of a first secondary station belonging to a first set of secondary stations not being valid, transmitting to each secondary stations of said first set through protected unicast message a new first set key by unicast.

13 . The method of claim 12 , further comprising transmitting in a multicast message to the first set of the secondary stations an updated group key, said multicast message being encrypted by means of the new first set key, and wherein the protected unicast message also includes the updated group key.

14 . The method of claim 10 , wherein the sets of secondary stations are formed based on location, and the method further comprises the primary station transmitting in at least one further multicast message the updated group key, said further multicast message being encrypted by means of a respective set key used in a neighbouring set, and wherein the neighbouring set is a set of a plurality of secondary stations camping in a cell served by another primary station.

15 . The method of claim 10 , wherein the multicast message includes along with the updated group key an authentication fingerprint message computed as the hash of updated group key.

16 . A method for a primary station to distribute a cryptographic key to a plurality of secondary stations, comprising the steps of:

determining whether a group key needs to be updated, said group key being used for protected multicast communication from the primary station to the plurality of secondary stations,

upon determining that an update is required, transmit to at least one first subset of the secondary stations through a protected unicast message a first set key by unicast,

wherein the updated cryptographic key is a first set key shared to the first set of secondary stations that allows encrypting multicast messages addressed to the first set of secondary stations,

transmitting in a multicast message to the first set of the secondary stations an updated group key, said multicast message being protected by means of the first set key, or alternatively including said updated group key in the protected unicast message, and

transmitting in respective multicast messages to further respective sets of secondary station the updated group key, said multicast messages being protected by means of respective set keys associated with each corresponding set, and

wherein the updated cryptographic key is sent in unicast.

17 . A method for a secondary station receiving a cryptographic key in a network, comprising the steps of:

receiving from the primary station through protected unicast message a first set key by unicast, said first key being associated with a first set of secondary stations, and

receiving and decrypting a multicast message to the first set of the secondary stations an updated group key, said decrypting using the first set key,

wherein the updated cryptographic key is a first set key shared to a first set of secondary stations that allows encrypting multicast messages addressed to the first set of secondary stations, and

wherein the updated cryptographic key is sent in unicast.

18 . The method of claim 17 , wherein the multicast message includes along with the protected updated group key an authentication fingerprint message, and the method further comprising the secondary station authenticating the multicast message by checking whether the hash of the decrypted group key matches the received authentication fingerprint, and the method further comprising reporting an anomaly to the primary station if the check fails.

19 . The method of claim 17 , wherein the multicast message comprises at least a first and a second protected group keys, wherein the first protected group key is protected with a first set key associated to the first set of secondary stations and the second protected group key is protected with a second set key associated to the second set of secondary stations, and wherein receiving and decrypting the multicast message comprises:

determining, by the secondary station, the set of secondary stations it belongs to,

determining, by the secondary station, the protected group key associated to the set of secondary stations the secondary station belongs to, and

decrypting, by the secondary station, the determined protected group key using the set group key.

20 . A primary station operating in a cellular network and communicating with a plurality of secondary stations, comprising:

a controller adapted to determine whether a group key needs to be updated, said group key being used for protected multicast communication from the primary station to the plurality of secondary stations, and

a transmitter coupled to the controller adapted to, upon determining that an update is required, transmit in respective multicast messages to respective sets of secondary station an updated cryptographic key, said multicast messages being protected by means of respective set keys associated with each corresponding set,

wherein the updated cryptographic key is a first set key shared to a first set of secondary stations that allows encrypting multicast messages addressed to the first set of secondary stations, and

wherein the updated cryptographic key is sent in unicast.

21 . A secondary station operating in a cellular network and communicating with a primary station, comprising a receiver adapted to receiving from the primary station through a protected unicast message a first set key by unicast, said first key being associated with a first set of secondary stations, and a controller adapted to decrypt a multicast message to the first set of the secondary stations an updated group key, said decrypting using the first set key,

wherein the updated cryptographic key is a first set key shared to a first set of secondary stations that allows encrypting multicast messages addressed to the first set of secondary stations, and

wherein the updated cryptographic key is sent in unicast.