IP Library Granted Patent US 7,907,735
Granted Patent B2
US 7,907,735 · App. 11/763,854 · Granted Mar 15, 2011

System and method of creating and sending broadcast and multicast data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,907,735
App. No.
11/763,854
Granted
Mar 15, 2011
Kind
B2
Abstract

A method of encrypting broadcast and multicast data communicated between two or more parties, each party having knowledge of a shared key, is provided. The key is calculated using values, some of which are communicated between the parties, so that the shared key is not itself transferred. Avoiding the transfer of the key offers several advantages over existing encryption methods.

Claims (69)

1. A method of deriving at least one multiparty cryptographic key for use by at least three computing devices and encrypting data transferred between the at least three computing devices, comprising:

receiving, from the first computing device, an authentication packet comprising a first random number encrypted using the secret key for the first computing device and an identification number for the first computing device;

retrieving, from a database, a stored secret key for the first computing device using the device identification number for the first computing device;

decrypting the first random number using the stored secret key;

generating a second random number; and

generating the first base cryptographic key using the first random number and the second random number;

generating a multiparty cryptographic key;

determining a first offset between the multiparty key and the first base cryptographic key;

encrypting the first offset using the first base cryptographic key; and

communicating the encrypted first offset to the first computing device.

2. The method of claim 1 , wherein the step of generating a multiparty cryptographic key comprises:

generating a third random number and a fourth random number; and

generating the multiparty cryptographic key using the third random number and the fourth random number.

3. The method of claim 1 , wherein the step of encrypting the first offset using the first base cryptographic key comprises:

encrypting the first offset and a second random number using a secret key for the first computing device.

4. The method of claim 3 , wherein the step of communicating the encrypted first offset to the first computing device comprises:

transmitting the encrypted first offset and second random number to the first computing device.

5. The method of claim 1 , wherein the secret key for the first computing device is stored in memory.

6. The method of claim 1 , further comprising:

establishing a second base cryptographic key for a second computing device;

determining a second offset between the multiparty cryptographic key and the second base cryptographic key;

encrypting the second offset using the second base cryptographic key; and

transmitting the encrypted second offset to the second computing device.

7. The method of claim 6 , wherein the step of establishing a second base cryptographic key for a second computing device comprises:

retrieving, from a database, a stored secret key for the second computing device using the device identification number for the second computing device;

decrypting the first random number using the stored secret key;

generating a second random number; and

generating the second base cryptographic key using the first random number and the second random number.

8. The method of claim 6 , wherein the step of encrypting the second offset using the second base cryptographic key comprises:

encrypting the second offset using a secret key for the second computing device.

9. The method of claim 1 , further comprising:

using the multiparty cryptographic key to communicate among the at least three computing devices.

10. A method for deriving at least one shared cryptographic key for use by at least three computing devices and encrypting data transferred between the at least three computing devices, comprising:

generating a first random number and encrypting the first random number using a secret key for a first computing device;

sending to a second computing device a first authentication packet, the first authentication packet comprising the encrypted first random number and a device identification number for the first computing device;

receiving, from the second computing device, a packet comprising an encrypted first offset and an encrypted second random number;

decrypting the encrypted first offset and second random number;

determining a first base cryptographic key using the first random number and the second random number;

determining the multiparty cryptographic key using the first base cryptographic key and the first offset;

wherein the first offset is between the multiparty key and the first base cryptographic key.

11. The method of claim 10 , wherein the secret key for the first computing device is stored on a smart card.

12. The method of claim 10 , wherein the secret key for the first computing device is stored on a memory of the first computing device.

13. The method of claim 1 , further comprising using the multiparty cryptographic key to communicate among the at least three computing devices.

14. A method for generating a multiparty cryptographic key, comprising:

a first computing device encrypting a first random number using a secret key for the first computing device;

the first computing device sending to a host a first authentication packet, the first authentication packet comprising the encrypted first random number and an identification number for the first computing device;

a second computing device retrieving a stored secret key for the first computing device using the identification number;

the second computing device using the stored secret key to decrypt the first random number;

the second computing device generating a first base cryptographic key using the first random number and a second random number;

the second computing device generating a multiparty cryptographic key using a third random number and a fourth random number;

the second computing device determining a first offset between the multiparty cryptographic key and the first base cryptographic key;

the second computing device encrypting the first offset and second random number using the stored secret key;

the second computing device transmitting the encrypted first offset and second random number to the first computing device;

the first computing device decrypting the encrypted first offset and second random number;

the first computing device determining a first base cryptographic key using the first random number and the second random number; and

the first computing device determining the multiparty cryptographic key using the first base cryptographic key and the first offset.

15. The method of claim 14 , further comprising:

the first computing device generating an IGMP query;

the first computing device encrypting the IGMP query using the first base cryptographic key;

the first client sending the encrypted IGMP query to the second computing device;

the second computing device decrypting the IGMP query;

the second computing device sending the IGMP query to a third computing device;

the second computing device generating a multiparty cryptographic key using a fifth random number and a sixth random number;

the second computing device linking the multiparty cryptographic key to an multiparty IP address;

the second computing device determining a second offset between the multiparty cryptographic key and the first base cryptographic key;

the second computing device encrypting the second offset and the multiparty

IP address using the first base cryptographic key;

the second computing device transmitting the encrypted second offset and the multiparty IP address; and

the first second computing device determining the multiparty cryptographic key using the first base cryptographic key and the second offset.

Assignments (2)
SECURITY AGREEMENT Recorded Sep 24, 2013
From: KOOLSPAN, INC.
To: SILICON VALLEY BANK
Reel/Frame 031282/0689 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2007
From: FASCENDA, ANTHONY C.; STURNIOLO, EMIL
To: KOOLSPAN, INC.
Reel/Frame 019802/0394 →