Management device for content distribution system, method for updating encryption keys, and program
By classifying content and using a key update function to notify subscribers and publishers about affected topics, the system minimizes the transmission of encryption key updates, addressing the inefficiency in existing systems and contributing to sustainable development goals.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- KDDI CORP
- Filing Date
- 2023-05-29
- Publication Date
- 2026-05-26
Smart Images

Figure 0007865921000001 
Figure 0007865921000002 
Figure 0007865921000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a technique for updating an encryption key in a content distribution system that classifies content into a plurality of topics, encrypts the content belonging to a topic with an encryption key of the topic, and distributes the encrypted content.
Background Art
[0002] Non-Patent Documents 1 and 2 disclose a publish / subscribe type content distribution system. In a publish / subscribe type content distribution system, a node (device) that issues content is called a publisher. For example, each publisher issues content of a predetermined "topic". A "topic" is, for example, something that specifies approximately the content of the content, and is determined by an operator of the content distribution system. For example, when the content is news, topics can be determined such as "domestic", "overseas", "sports", etc. In such a content distribution system, a node (device) that subscribes (acquires) content is called a subscriber. Subscribers subscribe to content in units of topics.
[0003] Furthermore, in a publish / subscribe type content distribution system, the nodes that relay content are defined as brokers. Publishers send the content they publish to one or more brokers. Each broker stores the content it receives from each publisher. Subscribers obtain the content of the topics they subscribe to from one or more brokers. Note that instead of configuring a broker to store the content it receives from each publisher, it is also possible to configure a broker to simply relay the content to subscribers who subscribe to that content. In a client / server type content distribution system, the server that publishes the content must always be online. On the other hand, in a publish / subscribe type content distribution system, if the content is stored at the broker, it is not necessary for the publisher that publishes the content to always be online. In the following explanation, a publish / subscribe type content distribution system will also be simply referred to as a "content distribution system".
[0004] In a content distribution system, it is necessary to control access so that only nodes with legitimate access rights can access the content. For this reason, as described in Non-Patent Document 3, the operator of the content distribution system (hereinafter simply referred to as "operator") distributes the encryption key associated with a topic to both the publisher that issues the content of that topic and the subscribers that subscribe to the content of that topic. The publisher encrypts the content of the topic with the encryption key associated with that topic and sends the encrypted content (encrypted content) to the broker. This configuration makes it possible to restrict the subscribers who can decrypt the encrypted content of a topic obtained from the broker to only those subscribers that subscribe to that topic. [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] Macenski,Steven,et al."Robot Operating System 2:Design,architecture,and uses in the wild",Science Robotics 7.66 (2022):eabm6074. [Non-Patent Document 2] Desbiens,Frederic.zenoh.,Building Enterprise IoT Solutions with Eclipse IoT Technologies:An Open Source Approach to Edge Computing.Berkeley,CA:Apress,2022.155-185. [Non-Patent Document 3] Markus Dahlmanns, Jan Pennekamp, Ina Berenice Fink, Bernd Schoolmann, Klaus Wehrle, and Martin Henze. 2021.Transparent End-to-End Security for Publish / Subscribe Communication in Cyber-Physical Systems.In Proceedings of the 2021 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems(SAT-CPS 21).Association for Computing Machinery,New York, NY, USA, 78-87. [Overview of the project] [Problems that the invention aims to solve]
[0006] For example, suppose there are M different topics (where M is an integer greater than or equal to 1), and each of the first to Nth subscribers (where N is an integer greater than or equal to 2) subscribes to all M topics. In this case, each of the first to Nth subscribers has obtained M encryption keys from the operator corresponding to the M topics. If the Nth subscriber stops subscribing to the M topics, the operator must update the M encryption keys and send each of the updated M encryption keys to the first to (N-1)th subscribers so that the Nth subscriber cannot decrypt the encrypted content of each of the M topics newly issued after the subscription is stopped. In other words, the operator needs to distribute M × (N-1) encryption keys to the subscribers.
[0007] Generally, encryption keys are large in size. Therefore, when one subscriber cancels their subscription, the amount of information sent to other subscribers to update the encryption key is also large.
[0008] This disclosure provides a technology that reduces the amount of information transmitted for updating cryptographic keys. [Means for solving the problem]
[0009] According to one aspect of the present disclosure, a management device for a content distribution system is provided that classifies content into a plurality of topics and distributes the content belonging to a topic after encrypting it with the encryption key of that topic. Here, a subscription node that subscribes to a subscription topic among the plurality of topics has the encryption key of the subscription topic and a key update function for updating the encryption key of the subscription topic. The management device includes a notification means that, when a first subscription node stops subscribing to the first subscription topic, notifies a second subscription node that subscribes to the first subscription topic to update the first encryption key of the first subscription topic and to provide numerical information to be used to update the first encryption key by the first key update function of the first subscription topic. [Effects of the Invention]
[0010] According to this disclosure, the amount of information transmitted for updating cryptographic keys can be reduced. [Brief explanation of the drawing]
[0011] [Figure 1] A diagram illustrating the configuration of the content distribution system. [Figure 2] A diagram showing an example of topic structure. [Figure 3] A diagram showing the topics that subscribers are subscribed to. [Figure 4] Sequence diagram of the encryption key update method. [Figure 5] Sequence diagram of the encryption key update method. [Figure 6] A flowchart of the processes performed by the management server. [Figure 7] Functional block diagram of the management server. [Modes for carrying out the invention]
[0012] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims, and not all combinations of features described in the embodiments are essential to the invention. Two or more features from the multiple features described in the embodiments may be arbitrarily combined. Furthermore, identical or similar configurations will be given the same reference numeral, and redundant descriptions will be omitted.
[0013] Figure 1 is a diagram illustrating the configuration of a content distribution system used to describe an embodiment. The management server 1, publisher 2, subscriber 3, and broker 5 are configured to communicate with each other via network 4. In Figure 1, for the sake of simplification, the management server 1, publisher 2, and subscriber 3 are shown connected to network 4, and the broker 5 is shown as being within network 4, but all of these are devices connected to network 4. The content distributed by the content distribution system is classified into real-time content such as live video streaming and non-real-time content such as news articles. In the following explanation, the content to be distributed will be described as non-real-time content. Furthermore, because the content to be distributed is non-real-time content, broker 5 stores encrypted content received from publisher 2 and transmits the content to subscriber 3 based on content acquisition requests from subscriber 3.
[0014] Management Server 1 is a device operated by the content distribution system operator or a business operator under the operator's supervision, and is also referred to as a management device. The operator classifies the content to be distributed into topics and sets them in Management Server 1. Management Server 1 stores the topic's encryption key and key update function. The topic's key update function is used to update the topic's encryption key. Figure 2 shows the topics used to describe this embodiment. According to Figure 2, topics are broadly classified into "A", "B", and "C". For example, if the topic is about travel, "A", "B", and "C" could be countries or regions. Topic A is further classified into "X" and "Other than X". For example, "X" is useful information for travel destination A, and "Other than X" is general information for travel destination A. For example, the operator can set a higher subscription fee for useful information for travel destination A (i.e., X) than for general information (i.e., Other than X). Furthermore, as shown in Figure 2, topic B remains a single topic without being divided, while topic C is divided into three parts: "X", "Y", and "other than X and Y". As a result, in the example in Figure 2, a total of six topics, T#1 to T#6, are set up.
[0015] As shown in Figure 3, the current encryption keys for T#1 to T#6 are K#1_v to K#6_v. The letter "v" in the encryption key indicates the version number of the encryption key, which is incremented by 1 each time the encryption key is updated. Note that not all of T#1 to T#6 are updated simultaneously, so the current version numbers of the encryption keys for each topic are not necessarily the same. Also, as shown in Figure 3, the key update functions for T#1 to T#6 are H#1 to H#6. The key update function is a one-way function such as a hash function.
[0016] Subscriber 3 is a device operated by a person (subscriber) who subscribes to one or more topics, and is also referred to as a subscription node. When Subscriber 3 starts subscribing to a topic, Management Server 1 sends the encryption key of that topic at that time and the key update function of that topic to Subscriber 3. Figure 3 shows the subscription status of topics for six Subscribers 3 (SUB#1 to SUB#6). In Figure 3, a circle indicates that the topic is subscribed, and a cross indicates that it is not subscribed. For example, SUB#1 subscribes to all of T#1 to T#6. On the other hand, SUB#4 subscribes only to T#2 and T#3.
[0017] Publisher 2 is a device operated by a person (publisher) who publishes the content of a topic, and is also referred to as a publishing node. Publisher 2 acquires and holds the encryption key and key update function of the topic to which the content to be published belongs from Management Server 1. When the publisher publishes content, Publisher 2 encrypts the content with the current encryption key of the topic to which the content belongs and sends it to each Broker 5. In Figure 1, there is one Publisher 2, but the number of Publishers 2 can be one or more. Hereinafter, it is assumed that Publisher 2 publishes the content of T#1 to T#6.
[0018] Each Broker 5 stores the encrypted content and distributes the encrypted content in response to requests from Subscriber 3. Note that Broker 5 does not have information about which Subscriber 3 subscribes to which topic. Therefore, Broker 5 distributes the content to any terminal in response to a request from that terminal. However, since the content is encrypted, Subscriber 3 that has acquired the encryption key from Management Server 1, that is, Subscriber 3 other than the one that subscribes to the content, cannot decrypt the content.
[0019] Figures 4 and 5 are sequence diagrams of the key update method started when SUB#3 stops subscribing to all of T#1 and T#3 to T#5 in the subscription status of Figure 3.
[0020] The management server 1 needs to update the encryption keys of T#1 and T#3 to T#5 so that it cannot decrypt the content of T#1 and T#3 to T#5 for which SUB#3 has stopped subscribing. For this reason, in S1, the management server 1 determines, for each subscriber 3 other than SUB#3, which of the topics in T#1 and T#3 to T#5 for which SUB#3 has stopped subscribing are being subscribed. For example, from FIG. 3, the management server 1 determines that SUB#1 subscribes to all of T#1 and T#3 to #5, SUB#4 and SUB#5 subscribe only to T3, and SUB#6 subscribes to T#4 and T#5. Further, the management server 1 determines that SUB#2 subscribes to none of T#1 and T#3 to T#5.
[0021] In S2 to S5, the management server 1 notifies SUB#1 and SUB#4 to SUB#6, which subscribe to at least one of T#1 and T#3 to T#5 for which SUB#3 has stopped subscribing, of the value N and information indicating the topics for which key update is necessary. Specifically, in S2, the management server 1 notifies SUB#1 of the value N and T#1 and T#3 to T#5 as the topics for which key update is necessary. Also, in S3, the management server 1 notifies SUB#4 of the value N and T#3 as the topic for which key update is necessary. Further, in S4, the management server 1 notifies SUB#5 of the value N and T#3 as the topic for which key update is necessary. Further, in S5, the management server 1 notifies SUB#6 of the value N and T#4 and T#5 as the topics for which key update is necessary.
[0022] The subscriber 3 notified of the value N and the topics for which key update is necessary updates the encryption key of the notified topic in S6. For example, if the notified topic is T#k (k is an integer from 1 to 6), the current encryption key of topic T#k is K#k_v, and the key update function of topic T#k is H#k, the subscriber #3 calculates the updated encryption key K#k_v+1 by the following formula. K#k_v+1 = H#k(N, K#k_v) Thus, in this embodiment, instead of the management server 1 sending the updated encryption key for each topic to each subscriber 3, it sends the identification information of the topic whose encryption key is to be updated and the numerical information (value N) used to update the encryption key to each subscriber 3. Note that there is only one numerical piece of information regardless of the number of topics whose encryption keys are to be updated. In other words, the same numerical information is used to update the encryption keys of multiple topics. Since the number of bits (amount of information) for the topic identification information and numerical information is less than that for the encryption key, the configuration of this embodiment can reduce the amount of information sent to subscribers for updating the encryption key.
[0023] Next, as shown in Figure 5, in S10, management server 1 notifies publisher 2 of the value N and topics T#1 and T#3~#5 which require key updates. In S11, publisher 2 updates the encryption key in the same way as subscriber 3. Subsequently, in S12, publisher 2 encrypts the content previously published for topics T#1 and T#3~#5 with the updated encryption key and sends it to each broker 5 in S13. The encrypted content is associated with version information indicating the version of the encryption key used for encryption. When broker 5 receives encrypted content associated with the new version information, it deletes the encrypted content associated with the old version information and stores the encrypted content associated with the new version information.
[0024] Generally, content distribution systems have a set expiration date for content distribution. Therefore, in S12, the content that Publisher 2 encrypts and transmits to each Broker 5 can be limited to content that has been published in the past and whose distribution expiration date has not yet expired.
[0025] With the above configuration, it is possible to restrict subscriber 3 who can decrypt encrypted content to only subscriber 3 who have subscribed to that content.
[0026] Furthermore, if the content to be distributed is real-time content such as live video streaming, Publisher 2 encrypts the real-time content and distributes it to each Broker 5, and each Broker 5 relays the content to the Subscriber 3 that requested the content distribution. In this case, the content is stored in Broker 5 and will not be distributed again, so processing S12 and S13 is unnecessary. After updating the encryption key, Publisher 2 uses the updated encryption key to distribute subsequent real-time content.
[0027] Figure 6 is a flowchart of the process executed by the management server 1 in this embodiment. The process in Figure 6 is executed when subscriber 3 stops subscribing to at least one topic (subscribed topic). In S20, the management server 1 determines the affected topics. An affected topic is a topic that subscriber 3 has stopped subscribing to. For example, in the example in Figure 4, the affected topics are T#1 and T#3 to T#5. In S21, the management server 1 determines the affected subscribers, which are subscriber 3 that subscribe to the affected topics. For example, in the example in Figure 4, the affected subscribers are SUB#1 and SUB#4 to SUB#6.
[0028] In S22, the management server 1 determines the value N. The value N is, for example, a random number. That is, the management server 1 can determine the value N to be a randomly generated value. Alternatively, the operator can store a sequence of numbers in the management server 1, and the management server 1 can determine the value N to be the next value in the sequence that was used in the previous S22 process. In S23, the management server 1 notifies each affected subscriber of the affected topic that the affected subscriber subscribes to and the value N. Each affected subscriber updates the encryption key of the affected topic using the value N. In S24, the management server 1 notifies the publisher 2 that publishes the content of the affected topic of the affected topic and the value N. The publisher 2 that publishes the content of the affected topic updates the encryption key of the affected topic using the value N. Although not shown in the diagram, the management server 1 also updates the encryption key of the affected topic.
[0029] Figure 7 is a block diagram of the management server 1 according to this embodiment. The storage unit 11 stores the identifier of each topic, the current encryption key of each topic, the key update function of each topic, and information of the subscribers 3 that subscribe to each topic. The determination unit 12 determines the affected topic and the affected subscriber when a subscriber 3 stops subscribing to a topic. Furthermore, the determination unit 12 also determines the publisher 2 that issued the affected topic. The generation unit 13 determines the value N to be used for key updates. The generation unit 13 determines the value N by, for example, randomly generating the value N. Alternatively, the generation unit 13 stores a sequence of numbers, and the generation unit 13 determines the value N by sequentially selecting numbers from the sequence. The notification unit 14 notifies the subscriber 3 of the encryption key and key update function of the topic when the subscriber 3 starts subscribing to the topic. Furthermore, when subscriber 3 stops subscribing to a topic, the notification unit 14 notifies the affected subscribers and publisher 2, which issued the affected topic, of the affected topic and the value N.
[0030] Furthermore, the management server 1 described in this disclosure may be implemented not as a single device, but as multiple devices capable of communicating with each other. The management server 1 may also be configured to manage only the key update process. In this case, another device is provided to manage the encryption key and key update function for each topic, and to notify subscriber 3 of the encryption key and key update function for a topic when subscriber 3 begins subscribing to that topic. In this configuration, subscription information indicating the topics currently subscribed to by each subscriber 3 may be stored in another device, and when subscriber 3 stops subscribing to a topic, the management server 1 may retrieve the subscription information from the other device and perform the processing shown in Figure 6. Alternatively, the subscription information may be stored in a synchronized state in both the management server 1 and the other device.
[0031] Furthermore, the management server 1 described herein can be implemented by a computer program that, when executed on one or more processors of a device having one or more processors, causes the device to operate as the management server 1. These computer programs are stored on a computer-readable storage medium or can be distributed via a network.
[0032] The invention is not limited to the embodiments described above, and various modifications and changes are possible within the scope of the gist of the invention.
[0033] This configuration reduces the amount of information sent to subscribers for updating encryption keys. Therefore, it becomes possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs): "Build resilient infrastructure, promote sustainable industrialization and foster innovation." [Explanation of Symbols]
[0034] 11: Storage section, 14: Notification section
Claims
1. A management device for a content distribution system that classifies content into multiple topics, encrypts the content belonging to each topic using the encryption key of that topic, and distributes it, A subscription node that subscribes to a subscription topic among the aforementioned multiple topics has the encryption key of the subscription topic and a key update function for updating the encryption key of the subscription topic. The aforementioned control device is A management device comprising a notification means for notifying a second subscription node that is subscribed to the first subscription topic, when the first subscription node stops subscribing to the first subscription topic, that the first encryption key of the first subscription topic be updated, and numerical information to be used to update the first encryption key by the first key update function of the first subscription topic.
2. The management device according to claim 1, wherein the second subscription node updates the first encryption key by using the first encryption key and the numerical information as inputs to the first key update function.
3. If the first subscription node stops subscribing to the first and second subscription topics, and the second subscription node is subscribing to the first and second subscription topics, the notification means notifies the second subscription node to update the first encryption key, update the second encryption key for the second subscription topic, and provide the numerical information. The management device according to claim 1, wherein the numerical information is used to update both the first encryption key and the second encryption key.
4. The management device according to claim 3, wherein the second subscription node updates the first encryption key by using the first encryption key and the numerical information as inputs to the first key update function, and updates the second encryption key by using the second encryption key and the numerical information as inputs to the second key update function of the second subscription topic.
5. The aforementioned content distribution system is The system further comprises a publishing node having the first encryption key and the first key update function, and publishing content belonging to the first subscription topic, The management device according to claim 1, wherein the notification means notifies the issuing node that the first encryption key should be updated and the numerical information when the first subscription node stops subscribing to the first subscription topic.
6. The management device according to claim 1, wherein the notification means notifies the subscription node of the encryption key and key update function of the one or more topics when the subscription node requests to subscribe to one or more of the plurality of topics.
7. A program that, when executed on one or more processors of a device having one or more processors, causes the device to function as a management device according to any one of claims 1 to 6.
8. A method for updating the encryption key in a content distribution system that classifies content into multiple topics and distributes content belonging to a topic using the encryption key of that topic, The aforementioned content distribution system is Management device and A subscription node that subscribes to one or more topics from the plurality of topics, each of the subscription nodes having the encryption key and key update function of the subscription topic it is subscribed to, The aforementioned update method is If the first subscription node stops subscribing to the first subscription topic, the management device shall notify the second subscription node, which is subscribed to the first subscription topic, of the first subscription topic and numerical information. The second subscription node updates the first encryption key by using the first encryption key and the numerical information of the first subscription topic as inputs to the first key update function of the first subscription topic, Update methods, including those mentioned above.
9. If the first subscription node stops subscribing to the first and second subscription topics, and the second subscription node is still subscribing to the first and second subscription topics, The management device notifies the second subscription node of the first subscription topic, the second subscription topic, and the numerical information. The second subscription node updates the first encryption key by using the first encryption key and the numerical information as inputs to the first key update function, and updates the second encryption key by using the second encryption key and the numerical information of the second subscription topic as inputs to the second key update function of the second subscription topic, The renewal method according to claim 8, including the method described in claim 8.
10. The content distribution system further comprises a publishing node that has the first encryption key and the first key update function, and publishes content belonging to the first subscription topic. The aforementioned update method is The update method according to claim 8, further comprising notifying the publishing node of the first subscription topic and the numerical information when the first subscription node stops subscribing to the first subscription topic.