Network system and device for delivery of a data item to a set of devices

The scheme allocates device keys to optimize secure data item delivery in passive wireless communication devices, addressing the challenges of energy scarcity and secure communication in ambient IoT environments.

WO2025114514A1PCT designated stage expired Publication Date: 2025-06-05KONINK KPN NV +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/084053
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-01
Filing Date
2024-11-29
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing technologies face challenges in efficiently managing and securely communicating with passive wireless communication devices, particularly in ambient IoT scenarios where energy is scarce and low-cost, secure authentication and key distribution are difficult to achieve.

Method used

A scheme for smartly allocating device keys to passive wireless communication devices, allowing for secure and low-complexity distribution of data items, such as cryptographic keys, using a network system that configures device keys differently between the network and the devices, enabling efficient delivery with minimal transmissions.

Benefits of technology

This approach enables secure and efficient delivery of data items to selected devices with a single or few transmissions, optimizing energy use and reducing computational complexity, while maintaining security by limiting access to device keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024084053_05062025_PF_FP_ABST
    Figure EP2024084053_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure pertains to a network system configured for delivering a data item to a first subset of devices from a set of devices. The set of devices may also contain at least a second subset of devices. The first subset and second subset of devices may have an empty intersection. The network system may have access to one or more first device keys associated with devices of the first subset of devices and one or more second device keys associated with devices of the second subset of devices. The network system may be configured to obtain an encrypted data item by encrypting the data item using at least one second device key associated with devices of the second subset of devices. The network system may further be configured to transmit the encrypted data item in a transmission to the set of devices for decryption of the encrypted data item only by the devices of the first subset of devices. The disclosure also relates to a device for use with such a network system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Network system and device for delivery of a data item to a set of devices

[0002] TECHNICAL FIELD

[0003] The present disclosure relates to a network system and device for delivery of a data item, such as a cryptographic key, to a set of devices. In particular, the disclosure relates to a network system and passive wireless communication device wherein a wireless transmission may contain a data item for delivery to a set of devices.

[0004] BACKGROUND

[0005] Future networks are expected to host sizable numbers of passive wireless transmission devices that store and / or collect data that should be uploaded via a network infrequently or in small amounts. Such devices should be managed efficiently in a network.

[0006] For example, 3GPP recently issued a study on ambient power-enabled Internet of Things, loT, devices in Technical Recommendation 3GPP TR 22.840. The document discloses use cases and requirements for ambient power-enabled loT devices, hereinafter also referred to as ambient loT devices, zero energy devices, energy harvesting devices, or passive wireless communication devices, being battery-less devices with limited energy storage capability (a capacitor may be included) wherein the energy is provided through the harvesting of radio waves, light, motion, heat or any other power source that could be suitable. Thus, energy is a very scarce resource in this context, and its usage is preferably optimized by limiting computations and / or the number and size of exchanged messages. Additionally, an ambient loT device may remain passive for extended periods of time before receiving a wake-up signal and starting to send data.

[0007] In view of the limited capabilities of these devices and low-cost requirements for these devices, it is a challenge or even not possible to conduct a substantial series of steps of transmissions, for example as currently standardized under 3GPP TS 33.501 , for authentication and secure association in order to obtain a session key for secure transfer of data items. Still, in some applications using passive wireless communication devices, a certain degree of security is desired when communicating with such devices.

[0008] SUMMARY

[0009] The inventors have invented a scheme of smartly allocating device keys to passive wireless communication devices that are deployed in the field wherein a network system is configured to communicate with these devices. The scheme may be used for secure and low-complexity distribution of data items requiring only one or only a few transmissions. Such a scheme may, for example, be useful when a common data item needs to be updated, for example when one or a few devices of a large set of devices are no longer authorized to receive the data item and / or to participate in a message exchange with the network system.

[0010] The inventors have further envisaged that the smart allocation of device keys is also applicable outside the field of ambient loT devices, for example in wired networks, such as cable networks, wherein some devices of a large set of devices are no longer authorized to receive a data item. One aspect of the disclosure pertains to a network system configured for delivering a data item, such as a cryptographic key (for example a common session key or a common message decryption key), to a first subset of devices from a set of devices. The set of devices may also contain at least a second subset of devices. The first subset and second subset of devices may have an empty intersection, i.e. there are no devices belonging to both the first and second subset.

[0011] The network system may have access to one or more first device keys associated with devices of the first subset of devices and one or more second device keys associated with devices of the second subset of devices. The network system may be configured to obtain an encrypted data item by encrypting the data item using at least one second device key associated with devices of the second subset of devices. The network system may further be configured to transmit the encrypted data item in a transmission to the set of devices for decryption of the encrypted data item only by the devices of the first subset of devices.

[0012] Another aspect of the invention amounts to a device for use with such a network system.

[0013] The network system may associate the device with a first device key of the one or more first device keys if the device is a member of the first subset of devices. In this case, the device may store or be configured to store at least the second device key and receive the transmission from the network system containing the data item encrypted under at least the second device key. The device may decrypt the data item when received using at least the stored second device key. The device may also store or be configured to store some or all of the first device keys, except for the first device key to which it is associated in the network system. These first device keys may also be used for encryption and decryption, if necessary

[0014] The network system may associate the device with a second device key of the one or more second device keys if the device is a member of the second subset. In this case, the device may store or be configured to store at least one of the first device keys and not the second device key and receive the transmission from the network system containing the data item encrypted under at least the second device key. The device may then fail to decrypt the data item when received in the absence of access to the second device key to which it is associated in the network system.

[0015] It should be appreciated that the device keys stored in the network system and in the devices may be symmetric keys.

[0016] The network system and device benefit from an asymmetry in storing and allocating device keys in the network system and in the device. Whereas the network system stores associations of devices and corresponding device keys, the devices themselves may store any device key except for the device key to which it is associated in the network system. This allows delivery of the data item with a single message to selected devices. The following case may exemplify this benefit. If the network system associates three devices D1 , D2 and D3 with corresponding device keys k1 , k2 and k3, whereas the devices themselves store all device keys except from the one to which it is associated in the network system (i.e. D1 stores k2 and k3; D2 stores k1 and k3; D3 stores k1 and k2), a data item encrypted under device key k3 will be decryptable by devices D1 and D2, but not D3. In this case, devices D1 and D2 are in the first subset of devices and device D3 in the second subset of devices. In this example, the data item is conveyed to two devices at once, whereas delivering the data item to D3 can be purposefully omitted by selecting its device key for encryption of the data item. In other words, the network system selects the device key corresponding to the device that should not have delivered the data item to it.

[0017] Substantial benefits from this symmetric key scheme arise when the size of the first subset of devices is considerably larger than the second subset of devices. The first subset of devices and second subset of devices may together form the set of devices.

[0018] In one embodiment, the network system is configured to transmit to the device via wireless transmissions, that contain the data item encrypted under the second device key and, possibly, an identifier of the second device key. The device may be a passive wireless communication device, i.e. a device that is to be energized externally and has limited capabilities. Such a device may contain the device keys of other devices in the system except for its own device key to which it is associated in the network system, such as the second device key mentioned above. In this manner, a device can simply be selected to not receive the data item by encrypting the data item with the device key of that device.

[0019] The inventors have realized that the disclosed key distribution especially facilitates delivery of the data item, such as a cryptographic key, to passive wireless communication devices since the number of transmissions is only one or only a few, as will be illustrated in further detail in the detailed description. Moreover, while a passive wireless communication device may store many device keys, for example virtually all device keys except for its own device key, the security risk is limited since these devices are configured to not provide easy access to these device keys for other devices.

[0020] In one embodiment, the wireless transmissions from the network system are configured to energize the passive wireless communication device to decrypt the data item from the wireless transmission using the second device key. In this manner, activation and data transmission are efficiently combined.

[0021] In one embodiment, the network system is configured to select at least one device for the second subset of devices to which the data item should not be delivered. The network system may be configured to apply the at least one second device key associated with said at least one device of the second subset of devices for encrypting the data item. The embodiment allows the network system to identify the device that should not have the data item and find the corresponding device key to achieve this in a simple manner. In one example, the selection is based on a determination that the at least one device of the second subset of devices is not authorized to have the data item. The first subset may contain the devices that are authorized to have the data item.

[0022] In one embodiment, the data item is a cryptographic key, such as a session key. The network system may be configured to determine that the one or more devices of the second subset of devices are not authorized to decrypt a broadcast message or multicast message with the cryptographic key. In this manner, while transmitting as a broadcast or multicast to the set of devices, delivery of the common session key, for example, can be achieved to the first subset of devices having the second device key while avoiding delivery of this session key to the second subset of devices, for example in a single transmission.

[0023] In one embodiment, the network system is configured to transmit an identifier of the at least one second device key used for encrypting the data item in the transmission to the set of devices. In one embodiment, the device may be configured to receive an identifier of the at least one second device key used for encrypting the data item. The device may further be configured to use the identifier to trace the second device key amongst a plurality of device keys stored in the device when the device is a member of the first subset of devices. Since the device may contain many device keys (but not its own device key), the identifier assists in quickly tracing the applicable device key which reduces processing time and / or energy. This is particularly relevant for passive wireless communication devices as disclosed herein.

[0024] In one embodiment, the network system may be configured to detect one or more acknowledgement messages corresponding to one or more devices of the first subset of devices. In the absence of an acknowledgement message or in the event of a negative acknowledgement message, the network system may optionally also be configured to retransmit the data item.

[0025] In one embodiment, the device may be configured to transmit an acknowledgement message to the network system upon decrypting the data item using the second device key. The embodiment is advantageous to inform the network system which devices of the first subset of devices, i.e. the devices to which the data item should be delivered, have actually not received the data item for whatever reason. The network system may decide to retransmit the data item, either in a new broadcast or multicast message or as a unicast message to the specific device.

[0026] In one embodiment, the device may be configured to transmit a negative acknowledgement message dependent on detecting an identifier of the second device key when the device is not capable of decrypting the data item. The embodiment enables the device to only transmit a negative acknowledgement in case the device is not capable of decrypting the data item while this was intended. This can be achieved by detecting that the device possesses the device key identifier. In one embodiment, the network system may be configured to transmit an encrypted message as a transmission for the first subset of devices, wherein the message is decryptable using a previously received cryptographic key, for example a message decryption key, as the data item.

[0027] In one embodiment, the device is further configured to receive an encrypted message and to decrypt the message using a cryptographic keys, such as a message decryption key, previously received as the data item.

[0028] The embodiment makes use of the cryptographic key, for example a common session key such as a message decryption key, previously delivered as a data item to authorized devices using the disclosed device key allocation scheme. The encrypted message may be a broadcast message or a multicast message containing data, such as instructions for the devices.

[0029] In one embodiment, the message may contain at least one device key corresponding to a device added to the set of devices. The device may be configured to store the device key of the added device. The device key of the added device may be decrypted using the previously obtained cryptographic key.

[0030] The embodiment facilitates adding of (new) devices to the set of devices and informing the other devices of its device key. As before, the added device does not store its own device key, whereas the network system does associate the added device with this own device key. The inventors have considered that storage of a large number of device keys by each device would not be problematic in general, since the device keys may be of limited size. For example, a symmetric key encryption scheme like AES may use keys of 128 or 256 bits only. This would allow storage of many device keys, even for passive wireless communication devices with limited storage capabilities.

[0031] However, the inventors have considered that the key distribution scheme may be organized in a layered fashion, for example using a two- or three-layer scheme. The scheme may apply group keys wherein devices are gathered into groups having a common group key, for example.

[0032] In one embodiment, the set of devices may be divided into groups of devices. The network system may associate each of the groups of devices with a group key. Devices may have the group keys of all groups except for the group key to which the network system associates them.

[0033] The network system may further be configured to obtain an encrypted data item by encrypting the data item using at least one group key of one or more groups containing one or more devices of the second subset. The network system may further be configured to transmit the encrypted data item in a transmission to the set of devices for decryption of the encrypted data item by one or more groups of devices possessing the group key.

[0034] In one embodiment, the network system is configured to transmit one instance of the encrypted data item encrypted under the at least one group key and one instance of the encrypted data item encrypted under the at least one second device key in a single message. In one embodiment, the device is configured to store the plurality of group keys except for the group key to which it is associated in the network system.

[0035] The result of the embodiment is that the data item is delivered to devices of all groups possessing the group key. Devices in the remaining group would not have the data item at this stage if the transmission under the group key precedes the transmission for the first subset of devices and devices from the first subset within the remaining group require a subsequent transmission using at least one second device key or vice versa.

[0036] The embodiments result in a reduction of the number of keys to be stored in the device as will be clarified further in the detailed description.

[0037] In one embodiment, the network system may comprise a core network system having a dedicated entity for connection-less messaging. Although existing entities in a network, such as an HSS / UDM for storing device keys and / or group keys and an MME / AMF for signaling messages in 3GPP compliant 4G / 5G telecommunications network may be used for executing the disclosed data item delivery, a dedicated entity may offload some of the tasks from these existing entities. The dedicated entity may interface with the existing entities or store all keys and perform all tasks itself. Wireless communication with the devices may occur via a base station of the telecommunications network, for example.

[0038] The disclosure further pertains to a method in a network system configured for delivering a data item, such as a cryptographic key, to a first subset of devices from a set of devices. The set of devices also contains at least a second subset of devices and the first subset and second subset have an empty intersection. The network system may have access to one or more first device keys associated with devices of the first subset of devices and one or more second device keys associated with devices of the second subset of devices. The method may involve the step of obtaining an encrypted data item by encrypting the data item using at least one second device key associated with devices of the second subset of devices. The method may further involve the step of transmitting the encrypted data item in a transmission to the set of devices for decryption of the encrypted data item only by the devices of the first subset of devices.

[0039] The disclosure further relates to a computer program comprising one or more software code portions that are configured to, when run on a computer system, to execute the method.

[0040] Furthermore, the disclosure defines a method in a device for use with the disclosed network system. The network system may associate the device with a first device key of the one or more first device keys if the device is a member of the first subset. In this case, the device may store or be configured to store at least the second device key. The method may involve the step of receiving the transmission from the network system containing the data item encrypted under at least the second device key. The method may further comprise the step of decrypting the data item when received using at least the stored second device key. The device may also store or be configured to store some or all of the first device keys, except for the first device key to which it is associated in the network system. These first device keys may also be used for encryption and decryption, if necessary.

[0041] The disclosure further relates to a computer program comprising one or more software code portions that are configured to, when run on a computer system, to execute the method.

[0042] The disclosure also involves a method in a device for use with the disclosed network system. The network system may associate the device with a second device key of the one or more second device keys if the device is a member of the second subset. In this case, the device may store or be configured to store at least one of the first device keys and not the second device key. The method may involve receiving the transmission from the network system containing the data item encrypted under at least the second device key. The method may further comprise the step of failing to decrypt the data item when received in the absence of access to the second device key to which it is associated in the network system.

[0043] The disclosure further relates to a computer program comprising one or more software code portions that are configured to, when run on a computer system, to execute the method.

[0044] The disclosure also pertains to a data item delivery system, such as a cryptographic key delivery system comprising a network system and a set of devices. The set of devices may contain a first subset of devices and a second subset of devices wherein the first subset and second subset have an empty intersection, i.e. there are no devices belonging to both the first and second subset.

[0045] The network system of the data item delivery system may have access to one or more first device keys associated with devices of the first subset of devices and one or more second device keys associated with devices of the second subset of devices. Each device of the set of devices may have many device keys, but not the device key to which it is associated in the network system. The network system of the data item delivery system may be configured to obtain an encrypted data item by encrypting the data item using at least one second device key associated with devices of the second subset of devices. The network system may further be configured to transmit the encrypted data item in a transmission to the set of devices for decryption of the encrypted data item only by the devices of the first subset of devices.

[0046] If the device is a member of the first set of devices, the device may store or be configured to store at least the second device key and receive the transmission from the network system containing the data item encrypted under at least the second device key. The device may decrypt the data item when received using at least the stored second device key. The device may also store or be configured to store some or all of the first device keys, except for the first device key to which it is associated in the network system. These first device keys may also be used for encryption and decryption, if necessary

[0047] If the device is a member of the second set of devices, the device may store or be configured to store at least one of the first device keys and not the second device key and receive the transmission from the network system containing the data item encrypted under at least the second device key. The device may then fail to decrypt the data item when received in the absence of access to the second device key to which it is associated in the network system.

[0048] It should be appreciated that the device keys stored in the network and in the devices are symmetric keys.

[0049] The network system and devices, i.e. the data item delivery system, benefit from an asymmetry in storing and allocating device keys in the network system and in the device. Whereas the network system stores associations of devices and corresponding device keys, the devices themselves may store any device key except for the device key to which it is associated in the network system. This allows delivery of the data item with a single message to selected devices. The following case may exemplify this benefit. If the network system associates three devices D1 , D2 and D3 with corresponding device keys k1 , k2 and k3, whereas the devices themselves store all device keys except from the one to which it is associated in the network system (i.e. D1 stores k2 and k3; D2 stores k1 and k3; D3 stores k1 and k2), a data item encrypted under device key k3 will be decryptable by devices D1 and D2, but not D3. In this case, devices D1 and D2 are in the first subset of devices and device D3 in the second subset of devices. In this example, the data item is conveyed to two devices at once, whereas delivering the data item to D3 can be purposefully omitted by selecting its device key for encryption of the data item. In other words, the network system selects the device key corresponding to the device that should not have delivered the data item to it.

[0050] Substantial benefits from this symmetric key scheme arise when the size of the first subset of devices is considerably larger than the second subset of devices. The first subset of devices and second subset of devices may together form the set of devices.

[0051] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as a system, a method or a computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a "circuit," "module" or "system." Functions described in this disclosure may be implemented as an algorithm executed by a processor / microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied, e.g., stored, thereon.

[0052] Any combination of one or more computer readable medium(s) may be utilized. The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer readable storage medium may include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present invention, a computer readable storage medium may be any tangible medium that can contain, or store, a program for use by or in connection with an instruction execution system, apparatus, or device.

[0053] A computer readable signal medium may include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium may be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0054] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber, cable, RF, etc., or any suitable combination of the foregoing. Computer program code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code may execute entirely on the person's computer, partly on the person's computer, as a stand-alone software package, partly on the person's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the person's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0055] Aspects of the present invention are described below with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor, in particular a microprocessor or a central processing unit (CPU), of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer, other programmable data processing apparatus, or other devices create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0056] These computer program instructions may also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.

[0057] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0058] The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.

[0059] Moreover, a computer program for carrying out the methods described herein, as well as a non- transitory computer readable storage-medium storing the computer program are provided.

[0060] Elements and aspects discussed for or in relation with a particular embodiment may be suitably combined with elements and aspects of other embodiments, unless explicitly stated otherwise. Embodiments of the present invention will be further illustrated with reference to the attached drawings, which schematically will show embodiments according to the invention. It will be understood that the present invention is not in any way restricted to these specific embodiments.

[0061] BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Aspects of the invention will be explained in greater detail by reference to exemplary embodiments shown in the drawings, in which:

[0063] FIG. 1 is a schematic illustration of a data item delivery system comprising a network system and a plurality of devices according to an embodiment of the present disclosure; FIGS. 2A and 2B are schematic illustrations of a network system and a device according to embodiments of the present disclosure;

[0064] FIG. 3 is a schematic illustration of an embodiment of the data item delivery system according to FIG. 1 ;

[0065] FIGS. 4A-4E depict time diagrams illustrating embodiments for operating the data item delivery system according to FIG. 3 from the perspective of the network system and devices according to FIGS. 2A and 2B, respectively,

[0066] FIG. 5A and 5B are schematic illustrations of embodiments of a multi-layer key scheme;

[0067] FIGS. 5C and 5D depict embodiments of time diagrams showing operation of the data item delivery system when applying the multi-layer key scheme of FIG. 5A.

[0068] FIG. 6 depicts an embodiment for an implementation of a network system in a 5G core network;

[0069] FIG. 7 depicts an example of a processing system according to an embodiment of a network system or a device for use with such a network system or a part thereof.

[0070] DETAILED DESCRIPTION OF THE DRAWINGS

[0071] FIG. 1 is a schematic illustration of a data item delivery system 1 comprising a network system 10 and a plurality of devices 20 according to an embodiment of the present disclosure. In FIG. 1 , the network system 10 is implemented in a core network CN of a telecommunications network, for example a 3GPP standard compliant telecommunications network. Communication between the network system 10 and devices 20 may be conducted wirelessly via a plurality of base stations, as shown in FIG. 1 . In FIG. 1 , the data delivery system 1 is connected to a data collecting entity DCE over a further network NW. Data collecting entity DCE may be the operator or user of devices 20, for example to gather data sensed by devices 20.

[0072] It should be noted that other implementations of network system 10, for example as a standalone system or an implementation in an enterprise network, and wired communications between the network system 10 and devices 20, for example over a cable network, have been envisaged by the inventors.

[0073] Embodiments for the network system 10 and a device 20 are shown in FIGS. 2A and 2B, respectively.

[0074] In FIG. 2A, it is schematically shown that network system 10 comprises a processor 11 and a storage 12 for storing information, such as one or more device keys of the devices 20 as will be explained in further detail below. Network system 10 is configured to communicate with the devices 20 over communication interface 13 and with one or more backend systems, such as the DCE, over communication interface 14. Communications between the network system 10 and device 20 may involve broadcast transmissions or multicast transmissions, for example. Network system 10 may use a separate broadcast channel or messages can be sent with an indication that assists a device 20 to identify the message type or purpose.

[0075] Device 20 may be any kind of device, such as a 3GPP standard compliant User Equipment, UE, a wireless communication device or a wired communication device, such as a device for cable television. However, the disclosed embodiments are particularly suitable for low complexity, low-cost devices for which a certain degree of security is still desirable. An example of such a device is a passive wireless communication device 20 as shown in FIG. 2B. Such devices may include ambient loT devices, zero energy devices, energy harvesting devices, being battery-less devices with limited energy storage capability (a capacitor may be included) wherein the energy is provided through the harvesting of radio waves, light, motion, heat or any other power source that could be suitable. For example, in FIG. 1 , devices 20 may be energized from transmissions from the base stations and / or from a power source W, being a source of heat, vibrations, electromagnetic radiation or otherwise, to name a few examples. These devices may be referred to as passive wireless communication devices in general.

[0076] FIG. 2B is a schematic illustration of a passive wireless communication device 20. The passive wireless communication device 20 may be configured to receive and process a wireless transmission, such as radio signal RS. The device 20 comprises a power harvesting part 21 , a processing part 22 and a storage part 23 configured to store data, such as device keys and device key identifiers. Other data that may be stored include a sensor data. The device 20 may also comprise a transceiver part 24 for wireless transmissions. The device 20 may comprise further parts or functions, such as at least one sensor 25 (or a connector therefore). It should be appreciated that device 20 may comprise a plurality of sensors 25 or connectors therefore. Examples of sensors include a location sensor, a temperature sensor, a humidity sensor, a light sensor, a pressure sensor, a motion sensor etc.

[0077] The device 20 is configured to harvest power to activate at least the processing part 22 and, optionally, the other parts, such as at least one of the storage part 23, transceiver part 24 and sensor 25. Power supply lines to these parts are indicated by the solid lines in FIG. 2B. The processing part 22 is configured to process wireless transmissions received from the network system 10, for example to detect the device key identifier and to retrieve the appropriate corresponding device key as will be explained in further detail below. Signal lines for such action(s) are indicated by the dashed-dotted lines in FIG. 2B. It should be appreciated that devices 20 may comprise more or fewer parts. Essentially, the device 20 is a battery-less device with limited, if any, energy storage capability. In one embodiment, the energy harvesting part 21 and transceiver part 24 may be integrated, at least in part, when the device 20 gathers energy from wireless radio transmissions and receives data items or other messages via such transmissions as well. Transmissions of data or other messages, including acknowledgements, may also be performed in this manner.

[0078] FIG. 3 is a schematic illustration of an embodiment of the data item delivery system 1 . Network system 10 is configured for delivering a data item, as shown, encrypted under a second device key SDK. The data item may comprise a cryptographic key, for example a common session key or a common message decryption key, or any other common data item. The data item may be delivered in a wirelessly (shown by the arrow) or wired fashion, the latter embodiment being shown by the dashed lines in FIG. 3. The transmission of the data item may be a broadcast or multicast transmission.

[0079] The network system 10 has access to device keys, generally referred to as keys ‘k’ herein, for example from an internal database as an implementation of storage 12 as shown in FIG. 2A. It should be noted that the keys k may also be stored in another location to which the network system 10 has access. The network system 10 stores the device keys k in association with the devices. For example, network system 10 stores device key k1 for device 20(1), device key k2 for device 20(2) .... device key k5 for device 20(5).

[0080] Whereas the network system 10 stores the device keys k in association with the devices 20, the device keys k are allocated differently in the devices 20 as shown in FIG. 3. Generally, the devices 20 themselves may store any device key k except for the device key k(i) to which a particular device 20(i) is associated in the network system 10. It should be appreciated that the device keys k stored in the network system 10 and in the devices 20 may be symmetric keys.

[0081] Accordingly, in the embodiment of FIG. 3, device 20(1) stores device keys k2-k5 (but not k1), device 20(2) stores device keys k1 and k3-k5 (but not k2), device 20(3) stores device keys k1 , k2, k4 and k5 (but not k3), device 20(4) stores device keys k1-k3 and k5 (but not k4) and device 20(5) stores device keys k1-k4 (but not k5). It will be appreciated by the skilled person that a data item delivery system 1 may contain more or fewer devices 20, wherein the device keys are allocated according to this scheme.

[0082] In the embodiment of FIG. 3, it is assumed that network system 10 desires to deliver a data item to all devices 20 except to device 20(4). This may be defined as that devices 20(1), 20(2), 20(3) and 20(5) are associated with a first subset, SET 1 , of devices to which the data item should be delivered and device 20(4) is associated with a second subset, SET 2, of devices that is not authorized to have the data item. The devices 20 in SET 1 are in the possession of the second device key, SDK, and the device 20(4) is not, but may possess one or more first device keys FDK. To deliver the data item to the first subset, SET 1 , of devices, the network system 10 is configured to obtain an encrypted data item by encrypting the data item using at least device key k4, i.e. a second device key SDK associated with devices 20 of the second subset, SET 2, of devices. The network system 10 is further configured to transmit the encrypted data item in a transmission to the set of devices 20 for decryption of the encrypted data item only by the devices of the first subset, SET 1 , of devices, i.e. devices 20(1), 20(2), 20(3) and 20(5) as intended. This is achieved by the allocation of the device keys k in the devices 20 in deviation of the association of these keys to the devices in the network system 10.

[0083] In particular, for a device 20 in the first subset, SET 1 , such a device may decrypt the data item when received using at least the stored second device key k4. The device may also store or be configured to store some, or all of the first device keys of devices associated with the first subset of devices, except for the first device key to which it is associated in the network system 10, as shown in FIG. 3. For example, device 20(1) not only stores device key k4, but also device keys k2, k3 and k5 (but not k1). This is advantageous in case such other devices are to be left out for decrypting a data item. For a device in the second subset, SET 2, the device 20(4) stores the first device keys k1 -3 and k5, but not device key k4 under which the data item is encrypted. When receiving the data item, device 20(4) would fail to decrypt the data item because of lacking the device key k4 to which it is associated in the network system 10.

[0084] In FIG. 3, the network system 10 may be configured to transmit to the devices 20 via wireless transmissions, as shown by the bidirectional bold arrow in FIG. 3. Devices 20 may be passive wireless communication devices i.e. devices that are to be energized externally and are low cost and have limited capabilities, for example as shown in FIG. 2B. Such a device may contain the device keys k of other devices 20 in the system except for its own device key as associated to it in the network system 10, such as the second device key k4 mentioned above. In this manner, a device 20 can simply be selected to not have delivered the data item by encrypting the data item with the device key of that device 20.

[0085] The disclosed key distribution especially facilitates delivery of the data item to passive wireless communication devices 20, since the number of transmissions is only one or only a few as shown in FIG. 3 and further with reference to FIGS. 4A-4E, as will be illustrated in further detail below. The wireless transmissions from the network system 10, sent via the base stations in FIG. 1 , for example, may be configured to energize the passive wireless communication device 20 to decrypt the data item from the wireless transmission using the second device key k4. In this manner, activation and data item transmission are efficiently combined.

[0086] In the embodiment of FIG. 3, the network system 10 may use processor 11 executing software code to select at least one device 20, here device 20(4), to which the data item should not be delivered. The network system 10 is then configured to apply the at least one second device key k4 associated with said at least one device 20(4) for encrypting the data item. The embodiment allows the network system 10 to identify the device 20(4) that should not have the data item and find the corresponding device key k4 to achieve this in a simple manner. In one example, the selection is based on a determination that the at least one device 20(4) of the second subset, SET 2, of devices is not authorized to have the data item.

[0087] The network system 10 may be configured to determine that the one or more devices 20 are not authorized to decrypt a broadcast message or multicast message, as mentioned above, containing a cryptographic key. In this manner, while transmitting as a broadcast or multicast to the set of devices 20, delivery of the cryptographic key can be achieved to the first subset, SET 1 , of devices having the second device key k4 while avoiding delivery of the cryptographic key to the second subset, SET 2, of devices (here device 20(4), for example in a single transmission.

[0088] The devices 20 in FIG. 3 may also store one or more session keys for decrypting messages. Initial session keys may either be preconfigured in the devices 20 or be shared with the devices using a secure unicast mechanism, if necessary.

[0089] FIGS. 4A-4E depict time diagrams illustrating embodiments for operating the data item delivery system 1 according to FIG. 3 from the perspective of the network system 10 and devices 20 according to FIGS. 2A and 2B, respectively. Time runs in the downward direction. Like for FIG. 3, each of these embodiments comprises devices 20(1), 20(2), 20(3), 20(4) and 20(5) which store device keys k as in FIG. 3 at some point in time. In addition, each of these devices 20 and the network system 10 contains a session key SK1 . Session key SK1 may be an initial session key preconfigured in the devices 20, for example.

[0090] FIG. 4A is a basic embodiment for delivery of a data item, here common session key SK2, to devices 20(1), 20(2), 20(3) and 20(5) as described above.

[0091] The embodiment starts to show transmission of a message encrypted under session key SK1 . Each of the devices 20(1), 20(2), 20(3), 20(4) and 20(5) can decrypt the message, as shown by the sign, since each of these devices contains the session key SK1 . Session key SK1 may, for example be stored in storage 23 of the passive wireless communication device as shown in FIG. 2B. The transmission may be a wireless transmission energizing the devices 20 to perform this task.

[0092] In response to an event detected by the network system 10, for example an indication from the data collection entity DCE as shown in FIG. 1 , the network system 10 may find that device 20(4) is no longer authorized to receive messages from, for example, the network system 10. Since the network system 10 stores the device keys k4 in association with the devices, the network system 10 can identify and obtain this device key k4 easily. This process is indicated by step S1 in FIG. 4A.

[0093] To avoid delivery of further messages to device 20(4), the network system 10 transmits a second session key SK2 as a data item to the devices 20 in a broadcast message or multicast message, for example. The session key SK2 is intended to enable the devices 20 to decrypt future messages encrypted under SK2. By encrypting the SK2 with device key k4, devices 20(1), 20(2), 20(3) and 20(5) can successfully decrypt this session key SK2 and store it, while device 20(4) cannot (as illustrated by the sign in FIG. 4), since device 20(4) is the only device lacking device key k4 in its local storage as explained also with reference to FIG. 3. Hence, in a next message that is encrypted under the session key SK2, all devices except device 20(4) can successfully decrypt this next message as shown in FIG. 4A.

[0094] FIG. 4B is a schematical illustration of a more advanced operation of the network system 10 as compared to FIG. 4A, wherein the network system 10 once again detects that device 20(4) is not authorized to have the data item SK2. In addition to encrypting SK2 with device key k4 associated with the device 20(4) that should not have SK2, network system 10 also includes an identifier ID4 of this device key k4 in the transmission. Network system 10 may contain an identifier ID for each of the device keys k (not shown in FIG. 4B).

[0095] The devices 20 are configured to receive the identifier ID4 of the second device key k4 used for encrypting the data item SK2. Any device 20 is configured to use the identifier ID4 to obtain the device key k4 from a plurality of device keys k stored in each device 20. The devices 20 have stored device key identifiers of each of the device keys in their storage. In the embodiment of FIG. 4B, devices 20(1), 20(2), 20(3) and 20(5) each have device key k4 stored in association with device key identifier ID4 as shown in FIG. 4B. Likewise, device 20(1), for example, also stores device key k2 in association with identifier ID2 (not shown), device key k3 in association with device key identifier ID3 (not shown) and device key k5 in association with device key identifier ID5. The same applies to the other devices 20, with the note that device 20(4) does not store ID4 in the absence of device key k4. Since each device 20 may contain many device keys k (but not its own device key), the identifier ID assists in quickly tracing the applicable device key k, as shown for device key k4 association with identifier ID4, which reduces processing time and / or energy. This is particularly relevant for passive wireless communication devices 20 as shown in FIG. 2B.

[0096] As explained with reference to FIG. 3 and FIG. 4A, device 20(4) cannot decrypt the data item SK2 for lack of the appropriate device key k4. Devices 20(1), 20(2), 20(3) and 20(5) can decrypt the data item SK2 and store SK2, for example in storage 23 as shown in FIG. 2B. In addition, or alternatively, the latter devices may report back to the network system 10 on the successful decryption of the data item as shown by the acknowledgement messages ACK in FIG. 4B. The acknowledgement messages ACK may include an identifier of the devices, as shown between parentheses in FIG. 4B, so that network system 10 may determine which devices 20 have successfully decrypted the data item SK2.

[0097] If a device could not decrypt the data item, such as device 20(1) in FIG. 4B, it may transmit a negative acknowledgement, NACK, message optionally also including the device identifier. It is noted that device 20(4) would not transmit a NACK message since it was intended that this device 20(4) could not decrypt the data item SK2. Device 20(4) may determine that it should not send a NACK based on the identifier ID4 in the transmission.

[0098] The network system 10 may process the ACK and NACK message(s) as shown in step S2 and decide whether or not to retransmit the data item. The embodiment is advantageous to inform the network system 10 which devices of the first subset of devices, i.e. the devices to which the data item should be delivered, could not decrypt the data item SK2. The network system 10 may decide to retransmit the data item, either in a new broadcast or multicast message or as a unicast to the specific device, as shown in FIG. 4B for device 20(1).

[0099] It should be appreciated that, when devices 20 are passive wireless communication devices, these devices may be energized from the first transmission of the data item to transmit the ACK or NACK message. Furthermore, it should be noted that the data item delivery system 1 may be configured such that either ACK or NACK messages are transmitted and wherein the absence of the one message, for example a NACK message, is interpreted by the network system 10 as the other message, the ACK message in this example, to save resources.

[0100] Substantial benefits from the key allocation scheme may arise when the size of the first subset of devices (i.e. the set of devices 20 authorized to have the data item, for example) is considerably larger than the second subset of devices (i.e. the set of devices 20 not authorized to have the data item, for example). However, the second subset of devices 20 not authorized to have the data item may be larger than one device 20.

[0101] An example of such an embodiment is schematically shown in FIG. 4C. In FIG. 4C, the network system 10 determines in step S1 that devices 20(1) and 20(4) are not authorized to decrypt the data item, i.e. session key SK2. In this case, the network system 10 is configured to trace the associated device keys k1 and k4 from the device identities ID and encrypt SK2 with a combination of device keys k1 and k4, noted as k1 ® k4 in FIG. 4C. The network system 10 may then broadcast or multicast data item SK2 under the combined device keys k1 and k4, optionally also including device key identities ID1 and ID4 to assist the device to obtain keys k1 and k4 from their local storage, such as storage part 23 shown in FIG. 2B. The skilled person should appreciate that both network system 10 and the device 20 are configured to perform the same encryption / decryption algorithm for the combination of device keys k. Devices 20(2), 20(3) and 20(5) possess both device keys k1 and k4 and are therefore capable to decrypt SK2 from the transmission (and store SK2, for example in storage part 23), while devices 20(1) and 20(4) fail to decrypt the message since one of the keys k1 , k4 is not available to these devices from the local storage. The skilled person will also appreciate that the same approach can be followed when more than two devices are to be excluded from successfully decrypting the data item.

[0102] Devices 20(2), 20(3) and 20(5) having successfully decrypted SK2 from the transmission may transmit ACK messages as shown and explained with reference to FIG. 4B.

[0103] As an option, devices 20(1) and 20(4), having received the broadcast message from the network system 10 but failed to decrypt the message as explained above, may transmit NACK messages, NACK(1) and NACK(4), as shown in FIG. 4C. This may be used to assist the network system 10 as an indication that the correct devices 20(1) and 20(4) do not possess SK2 in step S2.

[0104] As shown in FIG. 4C, a next message encrypted under SK2 can only be decrypted by devices 20(2), 20(3) and 20(5).

[0105] FIGS. 4D and 4E schematically depict operational embodiments wherein a device 20(2) is added to the set of devices 20 at some stage. Such an added device 20(2) is associated in the network system 10 with a device key k2. The device 20(2) itself can be provisioned with the device keys of other devices in the field (in this case, device keys k1 ,k3, k4 and k5) except for its own device key k2 and optionally a session key SK2. However, the devices 20 in the field need to be provisioned with the device key k2.

[0106] In FIG. 4D, in step S3, network system 10 is informed that device 20(2) is to be added and stores its device key k2 in association with the device 20(2). Since the devices 20(1), 20(3), 20(4) and 20(5) have stored a session key SK1 , as shown, network system 10 may transmit a message encrypted under this session key SK1. The message may contain the device key k2, and optionally the device key identifier ID2 and new session key SK2 to all devices 20 as shown in FIG. 4D. Devices 20(1), 20(3), 20(4) and 20(5) may then decrypt the message and store device key k2, and ID2, if present, in the local storage. This is shown by step S4 for each device 20(1), 20(3), 20(4) and 20(5) in FIG. 4D.

[0107] A next message may then be sent, encrypted under session key SK2, and may be decrypted by devices 20(1), 20(3), 20(4) and 20(5) as well as by added device 20(2).

[0108] Alternatively, as shown in FIG. 4E, the added device 20(2) is deployed in the field before transmission of the device key k2 to the other devices. Since device 20(2) is provisioned with session key SK2, and not SK1 , device 20(2) will not be able to decrypt the message containing device key k2 (and, optionally, ID2) encrypted under SK1 as shown in FIG. 4E. Devices 20(1), 20(3), 20(4) and 20(5) store device key k2 in step S4. In the embodiment of FIG. 4E, session key SK2 is transmitted from the network system 10 in a different transmission from the device key k2, again encrypted under SK1 . Devices 20(1), 20(3), 20(4) and 20(5) store session key SK2 in step S5. The skilled person will appreciate that, like in FIG. 4D, transmission of device key k2 and session key SK2 may also be combined in FIG. 4E.

[0109] The embodiments of FIG. 4D and 4E facilitate adding of (new) devices 20 to the set of devices and informing the other devices of its device key k. As before, the added device 20(i) does not store its own device key k(i), whereas the network system 10 does associate the added device 20(i) with this own device key k(i). It should be appreciated that a device 20 may be added because it is an entirely new device or because it was previously not authorized while being deployed in the field and now should be authorized again.

[0110] The inventors have considered that storage of many device keys k by each device 20 would not be problematic in general since the device keys k may be of limited size. For example, a symmetric key encryption scheme like AES may use keys of 128 or 256 bits only. This would allow storage of many device keys k, even for passive wireless communication devices with limited storage capabilities as shown in FIG. 2B.

[0111] However, the inventors have considered that the key distribution scheme may be organized in a layered fashion, for example using a two- or three-layer scheme. The scheme applies group keys gk wherein devices 20 are gathered into groups G having a common group key gk, for example. An embodiment of such a key scheme is shown in FIG. 5A, wherein a set of 100 devices 20 is considered.

[0112] Network system 10 may store a group key gk and a device key k for each device 20. In FIG. 5A, it is assumed that the set of 100 devices is divided in 10 groups, each group having assigned a group key gk and each group consisting of 10 devices 20. For example, group G1 is assigned group key gk1 , group G2 is assigned group key gk2, ... group G10 is assigned group key gk10. Within each group G, each device has been allocated a device key k as described above. However, device keys k can be reused between different groups G of devices 20. Accordingly, each group G may have a device 20(i) with the same set of device keys k. For example, group G1 has a device 20(1) with device keys k2-k10 and group G10 has a device 20(1) also has a device 20(1) with device keys k2-k10. Likewise, groups G2, G3...G9 also have such devices 20(1) (not shown in FIG. 5A).

[0113] Devices 20 also need to store both the group keys gk (except for the group to which they are assigned) and device keys k (except for the device key k allocated to the device). As shown in FIG. 5A, device 20(1) of group G1 stores group keys gk2-gk10 and device keys k2-k10. Device 20(1) in group G10 also stores device keys k2-k9, but stores group key gk1 (and not group key gk10) in addition to group keys gk2-gk9. This approach for a set of 100 devices only requires storage of only 18 keys in total instead of 99 device keys k for a single layer scheme.

[0114] Alternatively, as shown in FIG. 5B, all devices 20 have their own individual device key k irrespective of the group to which they are associated (i.e. devices have keys k1-k100 and devices are numbered 20(1)-20(100) as shown). The network system 10 may store device keys k1-k100 instead of k1-k10, but the devices 20 still only need to store the device keys k of the other devices in the same group G, so that devices 20 still need to store only 18 keys, viz. 9 group keys gk and 9 device keys of the devices 20 in the same group (assuming that each group consists of 10 devices in this example). Using individual device keys k for each device provides the advantage that more flexibility in group definition can be used. For example, using the groups of devices can be omitted or devices can be grouped differently without a need to change device keys.

[0115] FIG. 5C depicts an embodiment of a time diagram showing operation of the data item delivery system 1 when applying the multi-layer key scheme of FIG. 5A. FIG. 5C only shows two devices 20(1), 20(2) of groups G1 and G10 to illustrate how a data item, such as session key SK, can be delivered selectively with only a few transmissions. In step S1 , network system 10 is informed that device 20(1) of group G10 should not have a new session key SK. Network system 10 obtains the device key k1 and group key gk10 since the device 20(1) is associated with these keys in the network system 10.

[0116] A first transmission, for example a broadcast transmission, may be sent from network system 10 with session key SK encrypted under group key gk10. The devices 20 of groups G1-G9 are able to decrypt the message and store the session key SK by virtue of the storage of group key gk10, whereas the devices 20 of group G10 cannot decrypt the message in the absence of access to group key gk10.

[0117] In a second transmission, the session key SK can be sent encrypted under device key k1 . All devices 20(1) cannot decrypt this second transmission for lacking device key k1 , but devices 20(1) of groups G1 , G2 ...G9 already decrypted the session key SK from the first transmission. The result of the scheme is that only device 20(1) of group G10 does not have the session key SK, as intended.

[0118] The order of the transmissions may be reversed, i.e. a first transmission under device key k1 followed by a second transmission under group key gk10.

[0119] It is noted that a single transmission may be used wherein one instance of the session key SK is encrypted with device key k1 and another instance of the session key is encrypted with group key gk10. This is shown in FIG. 5D

[0120] It should be appreciated that the embodiments as shown in FIGS. 4A-4E may also apply to a multi-layer scheme, including the use of a device key identifier ID, possibly combined with a group key identifier GID, and the possibility of sending positive acknowledgement messages, ACK and / or negative acknowledgement messages NACK. Multiple devices 20 from the same group (using the same concept as in FIG. 4C of device key combinations) or from different groups (using group key combinations) have also been envisaged. Addition of a device 20 can be performed in the same way as in FIG. 4D and 4E. Addition of a new group requires transmission and storing of the new group key gk in the devices of the existing groups, which may be performed in the similar manner.

[0121] The embodiments of FIGS. 5A-5D achieve a reduction of the number of keys to be stored in the device 20. This may be particularly relevant for low cost, low capability devices, such as passive wireless communication device 20 in FIG. 2B.

[0122] Existing entities or functions in a 5GC, such as a unified data management, UDM, entity or function and / or an access and mobility management entity or function, AMF, may be used for storing device keys and / or group keys, resp. signaling messages in the 5G telecommunications network to devices 20 may be used for executing the disclosed data item delivery.

[0123] In one embodiment, as depicted in FIG. 6, network system 10 may be implemented through a dedicated entity or function in a 5G core network, 5GC having a user plane UP and a control plane CP. Such a network system 10 is indicated in FIG. 6 as a collection-less messaging function, CLMF. As shown in FIG. 6, the CLMF entity may interface with the existing entities or functions in the 5G core network, known to the skilled person, or store the one or more device and / or group keys and perform some or all tasks itself. Wireless communication with the devices may occur via a base station of the telecommunications network, for example. An external application function, AF, may be used to interact with the core network. The application function may be hosted in the data collection entity, DCE, as shown in FIG. 1 .

[0124] The application function, AF, may perform one or more functions, such as to provide an indication to the CLMF, such as information in which area to send the broadcast message with the data item, a group identifier and / or device identifier of the device that is not authorized to decrypt the data item and / or the contents of the message. The group identifier and / or device identifier may correspond to the group key identifier GID and / or device key identifier ID as discussed above.

[0125] For example, the AF may provide area information or network information used for the various broad cast / multicast messages. The AF may provide the message content for normal broadcast / multicast (encrypted with SK1). Then it may indicate that changes are needed, e.g. remove authorization, adding new devices and provide an indication to the network system 10. For these operations it will exchange information such as gk, k of the device(s) that need their authorization removed or gk, k and SK2 of new device(s). It should be appreciated that either the AF or CLMF, or both, may generate this information and, optionally, inform the other entity.

[0126] It should be appreciated that network system 10 may also be implemented in previous network generations, such as a 4G 3GPP standard compliant network or a 6G 3GPP standard compliant network.

[0127] FIG. 7 depicts a block diagram illustrating an exemplary processing system according to a disclosed embodiment, e.g. a (part of a) network system 10 or device 20 as described above for use in a data item deliver system 1 . As shown in FIG. 7, the processing system 70 may include at least one processor 71 coupled to memory elements 72 through a system bus 73. As such, the processing system may store program code within memory elements 72. Further, the processor 71 may execute the program code accessed from the memory elements 72 via a system bus 73. In one aspect, the processing system may be implemented as a computer system that is suitable for storing and / or executing program code. It should be appreciated, however, that the processing system 70 may be implemented in the form of any system including a processor and a memory that is capable of performing the functions described within this specification.

[0128] The memory elements 72 may include one or more physical memory devices such as, for example, local memory 74 and one or more bulk storage devices 75. The local memory may refer to random access memory or other non-persistent memory device(s) generally used during actual execution of the program code. A bulk storage device may be implemented as a hard drive or other persistent data storage device. The processing system 70 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the number of times program code must be retrieved from the bulk storage device 75 during execution.

[0129] Input / output (I / O) devices depicted as an input device 76 and an output device 77 optionally can be coupled to the processing system. Examples of input devices may include, but are not limited to, a space access keyboard, a pointing device such as a mouse, or the like. Examples of output devices may include, but are not limited to, a monitor or a display, speakers, or the like. Input and / or output devices may be coupled to the processing system either directly or through intervening I / O controllers. In an embodiment, the input and the output devices may be implemented as a combined input / output device (illustrated in FIG. 7 with a dashed line surrounding the input device 76 and the output device 77). An example of such a combined device is a touch sensitive display, also sometimes referred to as a “touch screen display” or simply “touch screen” that may be provided with the UE. In such an embodiment, input to the device may be provided by a movement of a physical object, such as e.g. a stylus or a finger of a person, on or near the touch screen display.

[0130] A network adapter 78 may also be coupled to the processing system to enable it to become coupled to other systems, computer systems, remote network devices, and / or remote storage devices through intervening private or public networks. The network adapter may comprise a data receiver for receiving data that is transmitted by said systems, devices and / or networks to the processing system 70, and a data transmitter for transmitting data from the processing system 70 to said systems, devices and / or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapter that may be used with the processing system 70.

[0131] As pictured in FIG. 7, the memory elements 72 may store an application 79. In various embodiments, the application 79 may be stored in the local memory 74, the one or more bulk storage devices 75, or apart from the local memory and the bulk storage devices. It should be appreciated that the processing system 70 may further execute an operating system (not shown in FIG. 7) that can facilitate execution of the application 79. The application 79, being implemented in the form of executable program code, can be executed by the processing system 70, e.g., by the processor 71 . Responsive to executing the application, the processing system 70 may be configured to perform one or more operations or method steps described herein.

[0132] In one aspect of the present invention, one or more components of the base station selection support system and / or user device for use with such a base station selection support system, as disclosed herein may represent processing system 70 as described herein.

[0133] Various embodiments of the invention may be implemented as a program product for use with a computer system, where the program(s) of the program product define functions of the embodiments (including the methods described herein). In one embodiment, the program(s) can be contained on a variety of non-transitory computer-readable storage media, where, as used herein, the expression “non-transitory computer readable storage media” comprises all computer-readable media, with the sole exception being a transitory, propagating signal. In another embodiment, the program(s) can be contained on a variety of transitory computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media (e.g., read-only memory devices within a computer such as CD-ROM disks readable by a CD-ROM drive, ROM chips or any type of solid-state non-volatile semiconductor memory) on which information is permanently stored; and (ii) writable storage media (e.g., flash memory, floppy disks within a diskette drive or hard-disk drive or any type of solid-state random-access semiconductor memory) on which alterable information is stored. The computer program may be run on the processor 71 described herein.

[0134] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of embodiments of the present invention has been presented for purposes of illustration but is not intended to be exhaustive or limited to the implementations in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the claims. The embodiments were chosen and described in order to best explain the principles and some practical applications of the present invention, and to enable others of ordinary skill in the art to understand the present invention for various embodiments with various modifications as are suited to the particular use contemplated.

Claims

CLAIMS1 . A network system configured for delivering a data item, such as a cryptographic key, to a first subset of devices from a set of devices, wherein the set of devices also contains at least a second subset of devices and wherein the first subset and second subset have an empty intersection, wherein the network system has access to one or more first device keys associated with devices of the first subset of devices and one or more second device keys associated with devices of the second subset of devices, wherein the network system is configured to: select at least one device for the second subset of devices to which the data item should not be delivered; obtain an encrypted data item by encrypting the data item using at least one second device key associated with devices of the second subset of devices and apply the at least one second device key associated with said at least one device for encrypting the data item; transmit the encrypted data item in a transmission to the set of devices for decryption of the encrypted data item only by the devices of the first subset of devices.

2. The network system according to claim 1 , wherein the selection is based on a determination that the at least one device of the second subset of device is not authorized to have the decrypted data item.

3. The network system according to claim 1 , wherein the data item is a cryptographic key, such as a session key, and wherein the network system is configured to: determine that the one or more devices of the second subset of devices is not authorized to decrypt a broadcast message or multicast message with the cryptographic key.

4. The network system according to claim 1 or 2, wherein the network system is configured to: transmit an identifier of the at least one second device key used for encrypting the data item in the transmission to the set of devices.

5. The network system according to one or more of the preceding claims, wherein the network system is configured to: detect one or more acknowledgement messages corresponding to one or more devices of the first subset of devices, and wherein, optionally, in the absence of an acknowledgement message or in the event of a negative acknowledgement message, the network system is configured to retransmit the data item.

6. The network system according to one or more of the preceding claims, wherein the network system is configured to: transmit an encrypted message as a transmission for the first subset of devices, wherein the message is decryptable using a previously received cryptographic key as the data item; and wherein the message optionally contains at least one device key corresponding to at least one device added to the set of devices.

7. The network system according to one or more of the preceding claims, wherein the set of devices is divided into groups of devices, wherein the network system associates each of the groups of devices with a group key, and wherein the network system is configured to: obtain an encrypted data item by encrypting the data item using at least one group key of one or more groups containing one or more devices of the second subset; transmit the encrypted data item to the set of devices for decryption of the encrypted data item by one or more groups of devices possessing the group key; wherein, optionally, the network system is configured to transmit one instance of the encrypted data item encrypted under the at least one group key and one instance of the encrypted data item encrypted under the at least one second device key in a single message.

8. The network system according to one or more of the preceding claims, wherein the network system comprises a core network system having a dedicated entity for connectionless messaging.

9. A device for use with a network system according to one or more of the claims 1-8, wherein the network system associates the device with either a first device key of the one or more first device keys if the device is a member of the first subset of device or a second device key of the one or more second device keys if the device is a member of the second subset of devices, wherein the device is configured to: for the device being a member of the first subset of devices: store at least the second device key; receive the transmission from the network system containing the data item encrypted under at least the second device key, and decrypt the data item using the stored second device key; for the device being a member of the second subset of devices: store the first device key and not the second device key; receive the transmission from the network system containing the data item encrypted under at least the second device key; and fail to decrypt the data item.

10. The device according to claim 9, wherein the device is configured to receive an identifier of the at least one second device key used for encrypting the data item and wherein the device is further configured to use the identifier to trace the second device key amongst a plurality of device keys stored in the device when the device is a member of the first subset of devices.11 . The device according to claim 9 or claim 10, wherein the device is configured to transmit an acknowledgement message to the network system upon decrypting the data item using the second device key, wherein, optionally, the device is configured to transmit a negative acknowledgement message dependent on detecting an identifier of the second device key when the device is not capable of decrypting the data item.

12. The device according to one or more of the claims 9-11 , wherein the device is further configured to receive an encrypted message and to decrypt the message using a cryptographic key previously received as the data item, wherein, optionally, the message contains at least one device key corresponding to a device added to the set of devices, wherein the device is configured to store the device key of the added device.

13. The device according to one or more of the claims 9-12, wherein the set of devices is divided into groups of devices and wherein the network system associates each of the groups of devices with a plurality of group keys, wherein the device is configured to store the plurality of group keys except for the group key to which it is associated in the network system.

14. The network system according to one or more of the claims 1 -8 or device according to one or more of the claims 9-13, wherein transmissions exchanged between the network system and device are wireless transmissions, wherein the device is a passive wireless communication device and wherein the wireless transmission contains at least one of the data item encrypted under the second device key and an identifier of the second device key according to claims 4 and 10.

15. The network system according to claim 14 or the device according to claim 14, wherein the wireless transmissions from the network system are configured to energize the passive wireless communication device to decrypt the data item from the wireless transmission using the second device key.

Citation Information

Patent Citations

  • Local area network

    EP1516474B1

  • A method for updating encryption keys, an encryption key update device, and an encryption key update program.

    JP5234307B2

  • Conditional access

    US20020090090A1

  • System and method for digital rights management with authorized device groups

    US8578157B2