发明名称 Network key update system, a server, a network key update method and a recording medium
摘要 In order to reduce the frequency with which communication occurs when updating a network key is reduced and minimize the deterioration in performance due to updating without relying on a key tree, a server is provided with an address key allocation unit which generates identifiers for identifying clients by the combination of addresses on a plurality of address spaces and allocates address keys to respective addresses included in the generated identifier, and a network key ciphering unit which generates a network key update key which cannot be generated from the address keys allocated to a client to be disconnected, ciphers a new network key using the network key update key, and delivers the new network key to the clients.
申请公布号 US9049181(B2) 申请公布日期 2015.06.02
申请号 US201013496842 申请日期 2010.09.14
申请人 NEC CORPORATION 发明人 Noda Jun
分类号 H04L29/06;G06F21/60;G06F21/72;G06F21/73;H04L9/08 主分类号 H04L29/06
代理机构 Sughrue Mion, PLLC 代理人 Sughrue Mion, PLLC
主权项 1. A server which, when a client is disconnected from a network, updates a network key which is used in order to participate in said network, and the server comprising: an address key allocation unit which generates an identifier for identifying said client by a combination of addresses extracted from each of a plurality of any address spaces, one by one optionally, and allocates an address key respectively to each said address which said generated identifier includes; and a network key encryption unit which: generates a network key update key, to disconnect the client corresponding to said any address of said plurality of any address spaces, which is impossible to generate from the address key which said address key allocation unit allocated to each address which is an identifier of said client, which is targeted to be disconnected, is included based on said address key allocated to each address included in said identifier of a client which is not the target to be disconnected,encrypts a new network key using said generated network key update key; anddistributes said encrypted new network key to the client via the network, wherein: a group of clients which include an address in one address space in one's own identifier is an element group and a group of clients which are specified by an intersection of the element group corresponding to an address which is extracted, one each from a plurality of different address spaces respectively, is a structured group;said network key encryption unit selects, among the structured groups which do not include a client n which is a target to be disconnected, one structured group G with a largest number of elements, and generates said network key update key by a predetermined method from the address key which is made to correspond to the address corresponding to each element group respectively whose intersection is said selected structured group G; andsaid network key encryption unit distributes said encrypted new network key to a client included in said structured group G.
地址 Tokyo JP