Methods, systems and devices for managing transmission of data in a media network

WO2026161924A1PCT designated stage Publication Date: 2026-08-06AUDINATE HLDG PTY LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
AUDINATE HLDG PTY LTD
Filing Date
2025-10-21
Publication Date
2026-08-06

Smart Images

  • Figure AU2025051189_06082026_PF_FP_ABST
    Figure AU2025051189_06082026_PF_FP_ABST
Patent Text Reader

Abstract

A method for managing transmission of data within a system of endpoints. The method comprising determining one or more communication policies for the system of endpoints, each of the one or more communication policies specifying a communication requirement that is conditional on a respective endpoint characteristic. In response to receiving, from a first endpoint of the system of endpoints, a request to participate in a communication flow within a group of endpoints of the system of endpoints, determining at least one endpoint characteristic associated with the one or more endpoints in the group of endpoints. Processing the one or more communication policies and the at least one endpoint characteristic to determine applicable communication requirements for the group of endpoints and providing, to the first endpoint, the applicable communication requirements for the group of endpoints.
Need to check novelty before this filing date? Find Prior Art

Description

Methods, systems and devices for managing transmission of data in a media networkCross-Reference to Related Application

[0001] The present application claims priority from Australian Provisional Patent Application No. 2025900276 filed on 3 February 2024, the contents of which are incorporated herein by reference in their entirety.Technical Field

[0002] Aspects of the disclosure relate generally to systems and methods for managing transmission of data in a media network and, more specifically, to managing transmission of data in a media network in accordance with specified communication policies.Background

[0003] Achieving secure data communication between endpoints of a media network relies on considerations of key management, access management and capabilities management, across the network of media device endpoints. Key management techniques, which provide cryptographic keys for cryptographically processing data transmitted in a media network, may be utilised to maintain confidentiality and prevent unauthorised tapping of media signals. However, existing media key management solutions do not scale, do not provide policy management.

[0004] Some management solutions rely on factory programmed keys for the media devices; however, such protocols often fail to incorporate considerations of access management and lack the flexibility to accommodate the changing shape of a media network. Existing dynamic key distribution solutions most commonly require a user entering a shared passphrase into each audio / visual device. This method does not scale well and is prone to user error.

[0005] Accordingly, there is a desire to provide a method of managing the secure transmission of data in a media network that ameliorates one or more of these difficulties, or other difficulties, of the prior art, or at least provides a useful alternative.

[0006] Any discussion of documents, acts, materials, devices, articles or the like which has been included in the present specification is solely for the purpose of providing a context for the present invention. It is not to be taken as an admission that any or all of these matters formpart of the prior art base or were common general knowledge in the field relevant to the present invention as it existed before the priority date of each claim of this application.Summary

[0007] In accordance with an aspect of the present disclosure, there is provided a method for managing transmission of data within a system of endpoints, each endpoint of the system of endpoints configured to receive data from, or transmit data to, another endpoint of the system of endpoints. The method comprises, determining one or more communication policies for the system of endpoints, each of the one or more communication policies specifying a communication requirement that is conditional on a respective endpoint characteristic. The method further comprises in response to receiving, from a first endpoint of the system of endpoints, a request to participate in a communication flow within a group of endpoints of the system of endpoints, the group of endpoints comprising a subset of the systemof endpoints, determining at least one endpoint characteristic associated with the one or more endpoints in the group of endpoints. The method further comprises processing the one or more communication policies and the at least one endpoint characteristic to determine applicable communication requirements for the group of endpoints, and providing, to the first endpoint, the applicable communication requirements for the group of endpoints.

[0008] In some embodiments, determining the one or more communication policies for the system of endpoints comprises obtaining, via a user interface, one or more user defined policies, and deriving a derived policy from one or more preconfigured policies and the one or more user defined policies.

[0009] In some embodiments, if an endpoint satisfies the derived policy, the endpoint also satisfies the one or more user defined policies and satisfies the one or more preconfigured policies. In some embodiments, determining the at least one endpoint characteristic of an endpoint comprises one or more of receiving from the endpoint, the endpoint characteristic, and retrieving, from a data storage medium, the endpoint characteristic.

[0010] In some embodiments, the method further comprises one or more of transmitting, by the first endpoint, to a second endpoint of the group of endpoints, data in accordance with the communication requirements, and receiving, from the first endpoint, from a second endpoint of the group of endpoints, data in accordance with the communication requirements. In someembodiments, the communication requirements satisfy the one or more communication policies.

[0011] In some embodiments, the method further comprises providing, to each endpoint of the group of endpoints, the communication requirements of the group of endpoints.

[0012] In some embodiments, the method further comprises, in response to receiving, from a first endpoint of the group of endpoints, a request to participate in a communication flow within the group of endpoints, and in response to processing the plurality of communication policies and at least one of the sets of endpoint characteristics to determine that the first endpoint’s participation in the communication flow within the group of endpoints does not satisfy one or more communication policies of the plurality of communication policies, rejecting the first endpoint’s request to participate in the communication flow within the group of endpoints.

[0013] In some embodiments, the group of endpoints comprises at least one transmitter endpoint and at least one receiver endpoint. In some embodiments, processing the one or more communication policies and the at least one endpoint characteristics to determine applicable communication requirements for the group of endpoints comprises determining communication requirements for the group of endpoints that satisfy the communication policies defined for the system of endpoints.

[0014] In some embodiments, the one or more communication policies define one or more of: data transmission restrictions which are applicable based on endpoint characteristics of a transmitter endpoint; data transmission restrictions which are applicable based on endpoint characteristics of a receiver endpoint; and data cryptographic processing requirements.

[0015] In some embodiments, the at least one endpoint characteristic defines one or more of: a communication capability of the endpoint; a communication limitation of the endpoint; a data transmission restriction of the endpoint; a data transmission permission of the endpoint; a data reception restriction of the endpoint; a data reception permission of the endpoint; a physical location of the endpoint; and an indication of one or more groups to which the endpoint belongs. In some embodiments, the applicable communication requirements for the group of endpoints satisfy the communication policies defined for the system of endpoints.

[0016] In some embodiments, the applicable communication requirements comprise one or more of: a master key; a master key identifier; a data encryption algorithm; a data decryption algorithm;; a key rotation scheme; a packet size restriction; a data signing mechanism; a data authentication mechanism; and a policy restriction for transmitting data.

[0017] In some embodiments, receiving, from the first endpoint, the request to participate in a communication flow within the group of endpoints comprise receiving, from the first endpoint, a group identifier identifying the group of endpoints.

[0018] In some embodiments, the method further comprises verifying, that the first endpoint belongs to a group of endpoints identified by the group identifier and in response to verifying that the first endpoint belongs to the group of endpoints, provide, to the first endpoint the communication requirements.

[0019] In some embodiments, the communication requirements comprise a master key associated with the group of endpoints.

[0020] In some embodiments, the first endpoint comprises a transmitter endpoint, and wherein the request to participate in a communication flow within the group of endpoints comprises a request to transmit data. In some embodiments, the first endpoint is configured to cryptographically apply the master key to data to determine cryptographically processed data, and transmit the cryptographically processed data to the at least one receiver endpoint.

[0021] In some embodiments, applying the master key to data to determine cryptographically processed data comprises determining a generator identifier, applying a generator identified by the generator identifier to the master key to generate a session key, and assigning a session key identifier to the session key. In some embodiments, the method further comprises: transmitting, to at least one receiver endpoint of the group of endpoints, the master key identifier, the generator identifier, the session key identifier, and cryptographically apply session key to the data to produce the cryptographically processed data.

[0022] In some embodiments, transmitting the cryptographically processed data to the at least one receiver endpoint comprises transmitting, to the at least one receiver endpoint, the session key identifier, and the cryptographically processed data.

[0023] In some embodiments, the first endpoint is further configured to, in response to an occurrence of a session key rotation trigger, determine a second generator identifier, apply a second generator identified by the second generator identifier to the flow key to generate a second session key, assign a second session key identifier to the second session key, apply the second session key to second data to produce a cryptographically processed second data. In some embodiments, the first endpoint is further configured to transmit, to the at least one receiver endpoint: the second generator identifier; the second session key identifier; and the cryptographically processed second data. In some embodiments, determining the secondgenerator identifier comprises selecting the second generator identifier from a list of generator identifiers.

[0024] In some embodiments, the communication requirements comprise a session key rotation period. In some embodiments, the session key rotation trigger comprises determining an elapse of the session key rotation period.

[0025] In some embodiments, in response to determining an occurrence of a security trigger, the domain manager is configured to transmit a new master key to one or more endpoints in the group of endpoints. In some embodiments, the security trigger comprises one or more of determining the addition of a new endpoint to the group of endpoints; determining the removal of a third endpoint from the group of endpoints; determining an interruption in the communication to at least one of the endpoints of the group of endpoints; determining a loss of power; and receiving a security trigger instruction from the controller.

[0026] In some embodiments, the security trigger comprises determining the removal of a third endpoint from the group of endpoints, and wherein the domain manager is configured to not transmit the new master key to the third endpoint. In some embodiments, the domain manager is configured to receive a periodic heartbeat signal from the third endpoint within a heartbeat interval. In some embodiments, determining the removal of the third endpoint from the group of endpoints comprises determining that a heartbeat signal from the third endpoint has not been received by the domain manager within the heartbeat interval.

[0027] In some embodiments, the method further comprises, in response to adding a new endpoint to the group of endpoints: processing the one or more communication policies and at least one of the sets of endpoint characteristics, including the endpoint characteristics of the new endpoint, to determine revised communication requirements of the group of endpoints; and providing, to the first endpoint, the revised communication requirements of the group of endpoints.

[0028] In some embodiments, the first endpoint comprises a receiver endpoint, and wherein the request to participate in a communication flow within the group of endpoints comprises a request to receive data from at least one transmitter endpoint of the group of endpoints. In some embodiments, the receiver endpoint is configured to receive cryptographically processed data from the at least one transmitter endpoint of the group of endpoints, and cryptographically apply the master key to the cryptographically processed data.

[0029] In some embodiments, the cryptographically processed data comprises clock distribution data signed with the session key.

[0030] In accordance with another aspect of the present disclosure, there is provided a domain manager comprising one or more processors, configured to, individually or in combination perform a method described herein.

[0031] In accordance with another aspect of the present disclosure, there is provided a system for controlling transmission of data within a system of endpoints, each endpoint configured to receive data from, or transmit data to, another endpoint in the system of endpoints. The system comprises a storage medium configured to store a plurality of communication policies for the system of endpoints, and a plurality of communication requirements, each communication requirement associated with a group of endpoints. The system further comprises a domain manager, comprising one or more processors, configured to, individually or in combination, perform a method as described herein.Brief Description of Drawings

[0032] The embodiments of the disclosure will now be described with reference to the accompanying drawings, in which:Figure 1 illustrates a media network, in accordance with an embodiment;Figure 2 is a diagram illustrating the functional blocks of a domain manager, in accordance with an embodiment;Figure 3 is a flowchart illustrating a method to provide communication requirements to an endpoint of a system of endpoints, in accordance with an embodiment;Figure 4 illustrates the endpoints of a media network, wherein the endpoints are distributed in locations of a physical installation, in accordance with an embodiment; Figure 5 illustrates a message sequence performed by components of a media network to establish a multicast communication flow, in accordance with an embodiment; Figure 6 illustrates a message sequence performed by components of a media network to establish a unicast communication flow, in accordance with an embodiment;Figure 7 illustrates flow groups of endpoints, in accordance with an embodiment; andFigure 8 is a flowchart illustrating the process by which an endpoint determines a session key based on a master key, in accordance with an embodiment.Description of Embodiments

[0033] Methods and systems described herein provide for the centralisation of communication policy management and distribution within a domain manager of a media network, such that communication policies for a media network may be readily managed at a single point of management by an administrator. Endpoints, arranged into a flow group, may be configured to transmit and receive data in accordance with communication requirements established by the domain manager. Advantageously, communication requirements may be automatically revised in response to changes to a flow group, and the revised communication requirements are automatically distributed to the relevant endpoints to satisfy the communication policies set by the administrator.

[0034] The security of a media network is enhanced through the application of communication policies by a domain manager. The domain manager, as described herein, centralises policy definition and deployment, based on the characteristics of the participating endpoints.

[0035] Methods provided herein seek to ameliorate the need to configure communication policy management directly for each endpoint. Methods provided herein seek to ameliorate the need to distribute communication policies to the endpoints of a media network in response to receiving new or revised communication policy from a user.

[0036] Additionally, the methods provided herein seek to ameliorate the complexity and computational burden on an endpoint to continuously manage communication requirements to satisfy a plurality of dynamically changing communication policies, which may or may not be applicable to the endpoint. The methods provided herein provide the endpoint with a concise list of communication requirements to which the endpoint is obligated to follow, without the endpoint being burdened with analysis or evaluation of the communication requirements with regard to the communication policies of the media network.

[0037] Advantageously, the domain manager described herein allows a user with administrator privileges to set network-wide, or conditional communication policies (based on metadata that is provided by or inferred from an endpoint) which are subsequently enforced though automatically generated, highly granular, communication requirements inside the domain manager.Media network

[0038] Figure 1 illustrates a media network 100, in accordance with an embodiment. The media network comprises a plurality of components in networked communication. In particular, the media network comprises a system of endpoints 102, which are configured to transmit and / or receive media data across the media network. Media data may comprise audio data, video data, or a combination thereof. Some or all of the endpoints in the system of endpoints 102 may also be configured to transmit and / or receive clocking data across the media network.

[0039] The system 100 comprises a controller 110, which is configured to manage the transmission of media data and clocking data within the system of endpoints. The controller may comprise software, hardware, firmware or a combination thereof. The controller comprises one or more processors configured to, individually or in combination, execute instructions stored in storage medium 120. Storage medium 120 may comprise a transitory or non-transitory storage medium. The one or more processors may include one or more integrated electronic circuits that perform the operations of the controller. In some embodiments, the controller may be implemented as a distributed system comprising multiple server systems configured to communicate over a network to provide, individually or in combination, the functionality of the controller 110.

[0040] Storage medium 120 may comprise both volatile and non-volatile memory for storing executable program code (not shown) which, when executed by the one or more processors of the controller, individually or in combination, provides the various computational and management capabilities of the controller 110. The controller may comprise a plurality of submodules, wherein the submodules comprise: software; hardware; firmware; or a combination thereof.

[0041] The submodules of the controller comprise a domain manager 112 and a user interface 114. In other embodiments, the controller may comprise additional, fewer or a different arrangement of submodules. The functionality described herein as being provided by the controller or a submodule of the controller, may, in other embodiments, be provided by another submodule of the controller or another component of the media network.

[0042] Storage medium 120 may comprise both volatile and non-volatile memory for storing data, such as, but not limited to, policy repository 122, endpoint characteristics 124 and system parameters 126, for use by the controller 110.

[0043] The devices of the system 100 are configured to communicate via a communication network 150. The communication network may comprise a plurality of subnets.System of endpoints

[0044] A media network may comprise a system of endpoints. The system of endpoints may comprise one or more transmitter endpoints (TX), which are devices or modules configured to transmit data to other endpoints in the system. A system of endpoints may further comprise one or more receiver endpoints (RX), which are devices or modules configured to receive data from other endpoints in the system. A system of endpoints may further comprise one or more transceiver endpoints (RX / TX), which are devices or modules capable of receiving and / or transmitting data within the system of endpoints.Domains

[0045] In some embodiments, it may be desirable to sub-divide large media systems into logically separate sub-systems called administrative domains, which consist of groups of endpoints. An administrative domain may contain one or more endpoints. An administrative domain may comprise an administrative grouping to facilitate the application of a communication policy (e.g., access rights for users can be managed on a per domain basis). An administrative domain is also referred to herein as merely a ‘domain’. A domain of an endpoint may comprise a characteristic of the endpoint.

[0046] The system of endpoints 102 comprises three domains: domain 160; domain 180 and domain 190. An endpoint may belong to more than one domain simultaneously. For example, transmitter endpoint 182 belongs to domain 180 as well as to domain 190. In some embodiments, endpoints within a domain support audio routing within and across subnets to other devices in the same domain. Label-based routing may be used to route media data. In some embodiments, multiple domains can co-exist within a media network, but devices in one domain do not interact with devices in a different domain.Clock domains

[0047] Media networks may also be sub-divided into logically separate sub-systems call clock domains, which consisting of groups of endpoints configured with a distinct clock signal. Each clock domain may comprise its own master clock and changes to clocking in one clock domain may not interfere with the endpoints of another clock domain.

[0048] Endpoints within a domain (e.g., an administrative domain) may also be in the same clock domain, and may therefore be synchronized to the same clock. The clock domain of an endpoint may differ from the administrative domain of the endpoint. The clock domain of an endpoint may comprise a characteristic of the endpoint.

[0049] Clocking data may be transferred between endpoints in the media network to enable management of clock domains. In some embodiments, the domain manager 112 may be configured to manage the transfer of clocking data as well as the transfer of media data. When transferring clocking data, security keys are distributed to endpoints in the clock domain such that they can validate the clock data is sent by the authorised clock master for that domain. Domain manager

[0050] The domain manager 112 may comprise a submodule of the controller 100, as is shown in Figure 1. Alternatively, the domain manager 112 may comprise a module that is separate to the controller, but is in communication with the controller. The domain manager 112 is configured to manage the media networks and provide networked media distribution between the endpoints 102, over routed networks.

[0051] In some embodiments, the domain manager 112 described herein may be implemented in software, hardware, and / or a combination of hardware and / or software. Additionally, the domain manager 112 may be part of a local computer (e.g., laptop or rack mounted computer), it may be installed on a virtual machine, or it may reside as hardware / software in the cloud. The domain manager 112 may be a set of services that operate in the control plane of the network. The domain manager 112 may be virtualized or implemented as a "cloud" service.

[0052] As described herein, a domain manager 112 is configured to manage the domains of endpoints (including administrative domains and clock domains). The endpoints selected for a particular domain may not be limited to a particular subnet but may instead come from a more expansive wide area network (WAN), this administrative grouping by the domain manager 112 may enable more complex features to be implemented within the network.

[0053] The domain manager 112 provides one or more beneficial features to the media network, including enabling effective communication within large scale networked media systems.Domain manager architecture

[0054] Figure 2 is a diagram illustrating the functional blocks of the domain manager 112, in accordance with an embodiment. The storage medium 120 is the memory of the domain manager 112. The other modules are able to update / query the data stored in the storage medium 120 based on messages received and processed from endpoints and the controller 110. The endpoint manager 250 is responsible for setting up and maintaining secure encrypted connections to / from media endpoints and the domain manager 112.

[0055] In some embodiments, the endpoint directory module 220 manages the discovery of endpoint information by other endpoints and the domain manager 112. In some embodiments, when an endpoint (endpoint A) is powered on, the endpoint registers its endpoint information or metadata by sending one or more messages to the domain manager 112. These messages contain descriptive information about the endpoint: e.g., network interface information such as IP address, media information such as number of channels, channel labels, sample rates, supported encoding types; and / or product information such as versions, manufacturer, model, supported capabilities etc. The endpoint directory module 220 processes these messages and stores the endpoint information in the storage medium 120. Another endpoint (endpoint B) that wishes to configure a media flow from endpoint A, issues a query to the endpoint directory 220 for relevant information such as address and channel information so it can request a flow from endpoint A.

[0056] The domain services module 210 manages the creation and deletion of domains, generation of credentials and grouping of endpoints into domains. The domain services module 210 may maintain an endpoint directory, which is responsible for managing endpoint registrations and lookups by endpoints and controllers. The domain services module 210 may maintain a list of current connected and / or enrolled endpoints and may update a domain database to reflect this information. The endpoint directory may track device service advertisements on behalf of the endpoint. These advertisements may be tracked by the device directory or by a separate advertisement manager. This module could then provide advertisement information to controllers and other endpoints. Controllers may discover endpoints in a domain using this information.Access controller

[0057] The domain manager 112 further comprises an access controller 230. The access controller 230 is responsible for access control policy management and evaluation, includingmanagement of cryptographic keys to enable encrypted and / or authenticated communication between the domain manager 112 and the endpoints.Key distribution infrastructure

[0058] The domain manager 112 further comprises key distribution infrastructure module 260. The key distribution infrastructure module 260 is responsible for generating and distributing keys to endpoints.User interface

[0059] The controller 110 further comprises a user interface 114. A user 172, such as an administrator, may engage with the user interface 114 via a user device 170. The user interface 114 may comprise a system dashboard that shows alerts and statistics for various system health and performance metrics of the system of endpoints. The dashboard can be used for general performance monitoring and for detailed event auditing. Information available on the dashboard may include domain statistics, clocking alerts, security alerts, and device firmware notifications. Domain manager 112 may comprise a web server 240, configured to interface with user interface 114 to provide access to the domain manager 112 by a user 172.Secure communications

[0060] In some embodiments, the domain manager 112 may use public key infrastructure (PKI) to setup authenticated communication between the domain manager 112 and the endpoints. In some embodiments, when a domain manager 112 is installed and licensed, a public / private key pair is generated and the public key is signed by an authorising entity. When a domain manager 112 creates a domain of endpoints, the domain manager 112 generates a public / private key pair to be used for communication between the domain manager 112 and endpoints within the domain. The domain manager 112 signs the public key by the domain manager’s private key, and provides the signed public key to the one or more endpoints in the domain. When an endpoint is added to a domain, the domain manager 112 provides the signed public key to the endpoint. Accordingly, a chain of trust is created and an endpoint can be authenticated as being cryptographically associated with a particular domain and domain manager 112.

[0061] When creating a domain of endpoints, a domain manager 112 may assign a domain identifier for the domain, and communicate the domain identifier to the endpoints within the domain. The endpoints and the domain manager 112 may include the domain identifier in communications, to identify which domain the communication belongs to. The domainmanager 112 stores the public / private key pair created for the domain, in association with the domain identifier.Flows and flow groups

[0062] A plurality of endpoints in a domain may form a flow group, comprising at least one transmitter endpoint and at least one receiver endpoint. A communication flow (also known as a flow) comprises the transfer of data (media data or clocking data) from an endpoint to one or more other endpoints in a flow group. An endpoint participates in a communication flow of a flow group by: transmitting data to another endpoint in the flow group; or by receiving data from another endpoint in the flow group. An endpoint may participate in more than one communication flows. Accordingly, an endpoint may belong to more than one flow group.

[0063] A flow may comprise a unicast flow or a multicast flow. Unicast routing creates flows to a single receiving endpoint. A unicast flow may assign space for 4 channels of audio, or 1 channel of video. Unicast flows are set up when a receiver subscribes to an available media channel.

[0064] Multicast flow creates a flow of data that can be received by multiple receivers. Multicast flows are assigned flow identifiers, enabling them to be identified by the domain manager 112. In contrast to unicast flows, multicast flows are set up on the transmitting endpoint before receiver endpoints can subscribe to these flows. A transmitter endpoint in the flow group can request the domain manager 112 to start a multicast flow of media data.

[0065] Media routing facilitates the transfer of data from an endpoint to another endpoint in the flow group. A flow may comprise multiple channels of audio. A flow may comprise one or more channels of video.Determining communication requirements

[0066] Figure 3 is a flowchart illustrating a method 300 to provide communication requirements to an endpoint of a system of endpoints 102, in accordance with an embodiment. In some embodiments, method 300 may be performed by a domain manager 112 in response to receiving a request from an endpoint (e.g., transmitter or receiver) to participate (e.g., transmit or receive data) in a communication flow (e.g., a multicast or unicast flow).

[0067] In response to receiving this request, the domain manager 112 determines the one or more communication policies that may apply to the endpoint, and determines the one or more endpoint characteristics of the endpoints in the group of endpoints. In some embodiments, thegroup of endpoints comprises a flow group of endpoints. In some embodiments, the group of endpoints comprises a domain group of endpoints. In some embodiments, the group of endpoints comprises a clock domain group of endpoints.

[0068] The domain manager 112 considers both the communication policies (also referred to as ‘policies’) and the endpoint characteristics to determine communication requirements that the endpoint are configured to adhere to when participating in the communication flow.Multicast flow

[0069] A non-limiting example implementation of method 300 is described with reference to the domain of endpoints 160, illustrated in Figure 1 and Figure 4, and with reference to the message sequence illustrated in Figure 5. It is to be understood that other implementations of method 300 may comprise operations that differ from, or are in addition to, the operations described herein in relation to this non-limiting example.

[0070] Figure 4 illustrates the endpoints 160 of media network 100, wherein the endpoints are distributed in a physical installation, in accordance with an embodiment. In particular, a transmitter endpoint 162 and a transceiver endpoint 164 are located in the boardroom 402. Each of these two endpoints are configured to record audio and transmit the recorded audio from the boardroom. The reception area 410 includes a receiver endpoint 412, configured to receive audio data and play audio in the reception area. Guest meeting room 420 includes a receiver endpoint 422, configured to receive audio data and play audio in the guest meeting room. Remote meeting room 430 is located in a different city to the boardroom, and includes a receiver endpoint 168, configured to receive audio data and play audio in the remote meeting room.

[0071] In anticipation of a meeting of a company’s board, an administrator of the media network 100 may desire to set up a flow of audio / visual media data from the transmitter endpoint 162, located in the boardroom. To allow the board meeting to be remotely attended by employees located in a different city, the administrator intends for the flow of media data to be received by a receiver endpoint 168, physically located in the remote meeting room 430.

[0072] Figure 5 illustrates a message sequence performed by components of a media network to establish a multicast communication flow, in accordance with an embodiment. The administrator engages with user interface 114 to create a flow of media data from transmitter endpoint 162. The message sequence of Figure 5 may be performed in response to the administrator engaging with user interface to create a flow of media data.

[0073] In response to the administrator engaging with the user interface, the controller issues an instruction, via message 502, to the transmitter endpoint 162 in the boardroom to create a flow of media data.

[0074] In operation 503, the transmitter 162 defines the transmitter flow. Defining the transmitter flow may comprise initiating a process, executed on the transmitter, to manage the flow of media data from the transmitter. Defining the transmitter flow may comprise defining a flow group identifier 505, wherein the flow group identifier uniquely identifies (within the system of endpoints 102) the group of endpoints participating in the flow from transmitter 162.

[0075] The endpoints participating in a flow may comprise: one or more transmitter endpoints, transmitting data to receiver endpoints of the flow group; and one or more receiver endpoints, receiving data from a transmitter endpoint of the flow group.Request to participate

[0076] Via message 504, the transmitter 162 requests that the domain manager 112 register the communication flow identified by the flow group identifier. The request to register the communication flow may be considered to be a request from the transmitter endpoint 162 to participate in a communication flow. The participation of the endpoint in a communication flow may comprise the transmission of data to another endpoint in the domain, or the reception of data from another endpoint in the domain.

[0077] In response to receiving message 504, the domain manager 112 may take steps to verify that the endpoint 162 belongs to the flow group identified by the flow group identifier, by performing one or more of: verifying the authentication signature on message 504, verifying the record of the transmitter endpoint 162 in the flow group in the endpoint directory 220.

[0078] Accordingly, in operation 304 of the method 300 performed by the domain manager 112, the domain manager receives, from transmitter endpoint 162 of the system of endpoints 102, a request to participate in a communication flow within a group of endpoints of the system of endpoints. The group of endpoints being identified by the flow group identifier. The request to participate 504 includes the flow group identifier ‘XYZ’ 505.

[0079] At this stage, the group of endpoints identified by the flow group identifier may only include the transmitter 162 itself. As detailed herein, one or more other endpoints may subsequently request to participate in the flow group, and therefore also be identifiable by the flow group identifier.

[0080] In some embodiments, the administrator may assign a plurality of endpoints to a flow group (e.g., via the user interface), before the controller instructs 502 the transmitter endpoint 162 to create a flow. The controller 110 may record the details of the flow group in storage medium 120, wherein the details of the flow group may comprise the identities of the member endpoints and the flow group identifier.Policy engine

[0081] The domain manager 112 further comprises a policy engine 270. The policy engine 270 manages the transmission of data within a system of endpoints in accordance with a set of one or more policies defined in the policy repository 122. Each policy of the set of policies comprises a conditional rule to be adhered to by the endpoints of the system of endpoints 102.

[0082] A policy may be defined by an administrator 172 or other authorised user, via an administrator user interface accessible via a user device 170 used by the administrator. The administrator user interface may comprise a dashboard or graphical depiction of the media network, via which the administrator can identify endpoints of the media network, and define policies applicable to the media network.

[0083] The policies may be stored, in a policy repository 122, such that they are accessible to the controller and other entities within the system 100. Each policy may be individually identifiable (e.g., by a policy number).

[0084] A policy may be applicable to all endpoints within a system of endpoints. A policy may be applicable to one or more flow groups within a system of endpoints. In some embodiments, policies are conditionally applicable to an endpoint or a flow group. Accordingly, a policy may comprise a policy condition, which when TRUE with regard to an endpoint characteristic of an endpoint, indicates that the policy is applicable to that endpoint.

[0085] A policy may define one or more of: data transmission restrictions which are applicable based on endpoint characteristics of a transmitter endpoint; data transmission restrictions which are applicable based on endpoint characteristics of a receiver endpoint; and data cryptographic processing requirements.Policy types

[0086] A policy stored in the policy repository 122 may be categorised in terms of its origin. For example, the policy repository 122 may be configured to store built-in policies, which comprise a base set of standard policies that are preconfigured into the policy repository 122for management by the policy engine 270. The built-in policies may be preconfigured by baseline parameters for the policy engine 270. The built-in policies may be preconfigured by an administrator 172 of the policy engine 270. A built-in policy may be referred to as a preconfigured policy.

[0087] The policy repository 122 may be configured to store end user defined policies, which comprise policies that are provided to the policy repository 122 by a user 172. A user 172 may input an end user policy via the user interface 114.

[0088] The policy repository 122 may be configured to store endpoint defined policies. An endpoint defined policy comprises a policy that is defined by, or on behalf of, the endpoint for enforcement by the policy engine 270. An endpoint defined policy may comprise a proprietary policy, defined by the manufacturer of the endpoint. For example, an endpoint defined policy may define a proprietary encryption scheme, key rotation scheme, security parameters or other policy that is relevant to the endpoint.

[0089] In some embodiments, built-in policies, endpoint defined policies and end user policies are layered together and used to derive policies for flows between endpoints. The policy engine 270 may be configured to automatically derive policies from one or more built-in policies, endpoint defined policies and / or end user policies. Accordingly, a derived policy comprises a policy that is automatically derived from one or more of: a built-in policy; an endpoint defined policy; a end user defined policy; an endpoint characteristic; another derived policy; or a combination thereof.

[0090] The policy engine is configured to derive policies such that, if an endpoint satisfies the derived policy, the endpoint also satisfies the policies from which the derived policy was derived.

[0091] Advantageously, the policy engine 270 may be configured to automatically derive a derived policy without user input. This may reduce the administrative burden on a user, such as an administrator.Policy derivation example 1

[0092] In some embodiments, the policy engine 270 is configured to consider built-in policies and stored endpoint characteristics 124 to derive policies for transport flows between endpoints.

[0093] In one example, the policy repository 122 comprises a built-in policy, which specifies that:WHEN: An audio flow is requested between an audio transmitter and an audio receiver, and both the audio transmitter and the audio receiver support media confidentiality. THEN: Issue a new key group from the domain manager.

[0094] Additionally, the endpoint characteristics repository 124 comprises endpoint characteristics, which specify:Endpoint A: Location-’boardroom”, security level-’sensitive”Endpoint B: Location=”CTO office”, security level-’sensitive”

[0095] These endpoint characteristics may be provided to the domain manager 112 by a user 172 via the user interface 114. For example, the user 172 may select a checkbox, in association with an endpoint, to indicate that the endpoint is located in a sensitive location. A user 172 may be required to have particular access permissions to be able to indicate that an endpoint is located in a sensitive location (or not located in a sensitive location). For example, in some embodiments, only an administrator user has permission to provide endpoint characteristics.

[0096] In response to the built-in policy and the endpoint characteristics, the policy engine 270 determines the following derived policies.Derived policy 1 : If an endpoint is not located in the ‘boardroom’ or ‘CTO office’, flows should be encrypted if both the transmitter and receiver support encryption.Derived policy 2: All endpoints located in the ‘boardroom’ or ‘CTO office’ must only transmit encrypted flows.Derived policy 3 : For all endpoints located in the ‘boardroom’ or ‘CTO office’, transmit media flows to endpoints not in the ‘boardroom’ or ‘CTO office’ are denied (e.g. blocked).Derived policy 4: For all endpoints not located in the ‘boardroom’ or ‘CTO office’, transmit media flows to all other endpoints are allowed.Policy derivation example 2

[0097] In one example, the policy repository 122 comprises built-in policies, which specify:Built-in policy 1 : Any key for an active key group must be rotated every 30 days. Built-in policy 2: When an endpoint that is part of a key group with multiple endpoints, is off-boarded or un-enrolled, the flow keys for key groups that the endpoint was part of must be rotated.

[0098] The policy repository 122 further comprises an endpoint defined policy. An endpoint defined policy may be defined by a manufacturer of the endpoint. In this example, the endpoint defined policy comprises a proprietary control protocol, defined by the manufacturer of the endpoint to ensure manufacturer-specific data is transmitted confidentially over the network. The endpoint defined policy may be provided, to the policy engine 270, from an endpoint, or may be provided to the policy engine 270 by an administrator user.Endpoint defined policy 1 : Proprietary control protocol for endpoints with the endpoint characteristic endpoint_manufacturer=’ ACME’ :key rotati on durati on= ’7 day s ’ ;key_protocol=’ AES-256 symmetric key’;encryption_protocol=’ ACME OEM encry ption’ ; andprovide key on J oining=TRUE.

[0099] The policy repository 122 further comprises an end user defined policy, which specifies:End user defined policy 1 : The maximum tolerable downtime for an internet connection to an endpoint is 1 day (based on the organisation’s business continuity policy). Once the maximum tolerable downtime has occurred for an endpoint, then the endpoint is considered to be off-boarded or unenrolled.

[0100] The policy engine 270 is configured to automatically derive one or more communication policies based on the built-in policies, the endpoint defined policy, and the end user defined policy.

[0101] The policy engine 270 determines that the endpoint defined policy 1 overrides the rotation duration of 30 days as specified in the built-in policy 1. Accordingly, the policy engine determines derived policy 1.Derived policy 1: When a flow group comprises an endpoint with the endpoint characteristic endpoint_manufacturer=’ACME’, any key for the flow group must be rotated every 7 days.

[0102] The policy engine 270 determines that the end user defined policy 2 defines a condition in which the built-in policy 2 is applicable. Accordingly, the policy engine determines derived policy 2.Derived policy 2: When an endpoint is offline for over 1 day, rotate the key for any flow group that the offline endpoint was a member of.Policy derivation example 3

[0103] In one example, the policy repository 122 comprises built-in policies, which specify:Built-in policy 1 : Any key for an active flow group must be rotated every 30 days. Built-in policy 2: When an endpoint that is part of a multicast flow is off-boarded or unenrolled, then the flow keys for any multicast flow that the endpoint was part of must be rotated.

[0104] The policy repository 122 further comprises end user defined policies, which specify:End user defined policy 1: Any key for an active flow group must be rotated every 7 days.End user defined policy 2: The maximum tolerable downtime for an internet connection to an endpoint is 1 day (based on the organisation’s business continuity policy). Once the maximum tolerable downtime has occurred for an endpoint, then the endpoint is considered to be off-boarded or unenrolled.

[0105] The policy engine 270 is configured to automatically derive one or more communication policies based on the built-in policies and the end user defined policies. In this example, the policy engine 270 derives the following derived policies.

[0106] The policy engine 270 determines that the end user defined policy 1 overrides the built-in policy 1. Accordingly, the policy engine determines derived policy 1.Derived policy 1 : Any key for an active flow group must be rotated every 7 days.

[0107] The policy engine 270 determines that the end user defined policy 2 defines a condition in which the built-in policy 2 is applicable. Accordingly, the policy engine determines derived policy 2.Derived policy 2: When an endpoint is offline for over 1 day, rotate the key for any flow group that the offline endpoint was a member of.

[0108] In some embodiments, the policy engine 270 is configured to determine a redundant policy in the policy repository 122. A redundant policy may comprise a policy that is fully covered by one or more other policies in the policy repository. For example, as end user defined policy 1 overrides built-in policy 1, built-in policy 1 is considered redundant by the policyengine 270. A policy that is considered redundant, may be marked as redundant in the policy repository 122. Advantageously, marking policies as redundant may reduce the number of policies considered by the policy engine 270 during operation of the policy engine 270. The policy engine 270 may mark a redundant policy as no longer redundant in response to the addition, removal or alteration of a policy.Policy derivation example 4

[0109] In some embodiments, an administrator may desire to ensure that the system of endpoints is protected from denial-of-service attacks, or misconfigured clock devices, by cryptographically controlling which endpoints can be a clock leader. A clock leader is configured to provide a master clock for a clock domain. Accordingly, the administrator 172 may set a plurality of end user defined policies.End user defined policy 1 : secure_clocking=TRUEEnd user defined policy 2: Clock leaders for clock domain X = endpointA, endpointB, endpointCEnd user defined policy 3 : Clock leaders for clock domain Y = endpointD, endpointE, endpointF

[0110] In response to the policy engine 270 receiving the end user defines policies (1, 2 and 3), the policy engine is configured to determine a derived policy that implements the secure clocking as parametrised by the end user defines policies (1, 2 and 3). The policy engine 270 automatically determines the following, multi-part, derived policy.Derived policy 1: Create an asymmetric (public + private) clock signing key. For all clock followings in a clock domain, provide the public signing key. For all clock leaders, provide the private signing key. Enforce secure clocking on all devices in a clock domain.Example policies

[0111] Table 1, below, comprises an example set of policies, defined in the policy repository 122, for the system of endpoints 102, in accordance with an embodiment. In particular, Table 1 comprises 6 policies, identified by labels Policy 1 to Policy 6. The policies in Table 1 may comprise one or more built-in policies, end user defines policies, endpoint defined policies, derived policies, or a combination thereof.Table 1 - Example set of policies, defined in the policy repository 122, for the system of endpoints 102<Sensitive location

[0112] An administrator may set a policy which is conditional on an endpoint characteristic that defines the physical location of an endpoint. For example, transmitter endpoint 404 comprises a microphone, located in a boardroom of an organisation. The boardroom is considered, by the administrator, to be a sensitive location, due to the sensitive nature of audio that may be picked up by the microphone of transmitter endpoint 404 in the boardroom.

[0113] In one embodiment, the set of endpoint characteristics associated with transmitter endpoint 162 comprises a ‘location type’ characteristic, which indicates that transmitter is located in a sensitive location.

[0114] In one embodiment, the set of endpoint characteristics associated with transmitter endpoint 162 comprises a characteristic that the transmitter endpoint is located in the boardroom 402, and the system parameters 126 comprises an indication that the boardroom comprises a sensitive location. The domain manager 112 is configured to determine, by considering the transmitter endpoint’s characteristics and the installation parameters, that the transmitter endpoint is located in a sensitive location.

[0115] In this example, the administer sets a policy (Policy 1) which specifies that transmissions of media data (audio or video data) from transmitter endpoints located in sensitive locations must be encrypted in accordance with specific communication requirements, which relate to encryption algorithm and session key rotation.Determining policies

[0116] Referring again to method 300 and the message sequence of Figure 5, in response to receiving, from transmitter endpoint 162, a request to transmit data in a flow group identified by flow group identifier ‘XYZ’ 505, the domain manager 112 determines, in operation 302, one or more policies for the system of endpoints.

[0117] Determining the one or more policies may comprise determining all the policies pertaining to the system of endpoints 102. In some embodiments, the domain manager 112 may filter the policies to identify a subset of the policies. The subset of policies may be applicable to the flow group of endpoints, as identified by the flow group identifier ‘XYZ’ 505. The subset of policies may be applicable to a domain (e.g., domain 160) of endpoints.Endpoint characteristics

[0118] In operation 306, the domain manager 112 determines the one or more endpoints in the flow group of endpoints identified by the flow group identifier ‘XYZ’ 505. The domain manager 112 may determine the one or more endpoints by referring to the system parameters 126, to determine a list of endpoints in the flow group of endpoints.

[0119] Each endpoint is associated with one or more endpoint characteristics. Accordingly, in operation 306, the domain manager 112 is further configured to determine at least oneendpoint characteristic associated with the one or more endpoints in the flow group of endpoints.

[0120] An endpoint characteristic may include, but is not limited to, one or more of: an indicated physical location of the endpoint; an inferred physical location of the endpoint; the permitted use of the endpoint (e.g., for sensitive content, adult content, public content); the capabilities of the endpoint (e.g., firmware version, supported cryptographic algorithms, bandwidth capability, clocking capability); the performance configuration of the endpoint (e.g., reduced performance capability to reduce power usage); media routing configuration; audio proximity to other endpoints; whether the endpoint is a transmitter, receiver or transceiver; the clock domain of the endpoint; endpoint identifiers (e.g. product ID, manufacturer ID, developer ID); licensed features (e.g. audio, video, media CODEC’s, media formats, channel count); regulatory declarations, compliance, conformance or certification (e.g. handling of personal data [e.g., GDPR]; content protection configuration; a data reception permission of the endpoint; data reception restriction of the endpoint; a data transmission permission of the endpoint; a data transmission restriction of the endpoint; a communication capability of the endpoint; a communication limitation of the endpoint; a current connection status of the endpoint; a model of the endpoint; media metadata provided by the endpoint; or any combination thereof.

[0121] In some embodiments, some or all of the endpoint characteristics of an endpoint are stored in storage medium 120, and may be accessible for reading by the domain manager 112. The domain manager 112 or controller may store an endpoint characteristic in response to receiving the endpoint characteristic of an endpoint via a user entering the endpoint characteristic in the user interface.

[0122] A user (e.g., an administrator) may utilise the user interface 114 to add a new endpoint to the media network. For example, the user may indicate, via interaction with the user interface, the physical location of the endpoint and the intended role of the endpoint.

[0123] In some embodiments, the domain manager 112 may determine one or more of the endpoint characteristics of an endpoint via communication from the endpoint itself. For example, an endpoint characteristic of an endpoint may comprise endpoint metadata that may be transmitted to the domain manager 112 as header fields of packets.

[0124] In some embodiments, the domain manager 112 may determine a default characteristic for an endpoint, in lieu of an actual value for the endpoint characteristic.

[0125] In some embodiments, the domain manager 112 may be configured to verify an endpoint characteristic provided by a endpoint. In some embodiments, the domain manager 112 may verify an endpoint characteristic by consulting reference data defining verifies endpoint characteristics.Communication requirements

[0126] In operation 308, the domain manager 112 is configured to process one or more of the policies identified in operation 302, and at least one of the sets of endpoint characteristics identified in operation 306, to determine the communication requirements for the group of endpoints defined by the flow group identifier. These communication requirements may be referred to as applicable communication requirements.

[0127] In some embodiments, the domain manager 112 is configured to process the one or more of the policies, and at least one of the sets of endpoint characteristics, to determine the applicable communication requirements for the group of endpoints that satisfy each of the one or more policies.

[0128] Processing the one or more communication policies and the at least one endpoint characteristic to determine applicable communication requirements for the group of endpoints may comprise identifying one or more of the communication policies that are conditional on the at least one endpoint characteristic. Processing the one or more communication policies may comprise evaluating each of the communication policies in the policy repository 122 to determine whether the communication policy defines a communication requirement that is conditional on the at least one endpoint characteristic.

[0129] In some embodiments, the communication requirements of a group of endpoints satisfies a set of policies ifa. each transmitting endpoint in the group of endpoints, in transmitting data to another endpoint in the group of endpoints, in accordance with the communication requirements, does not violate any policy of the set of policies; andb. each receiving endpoint in the group of endpoints, in receiving data from another endpoint in the group of endpoints, in accordance with the communication requirements, does not violate any policy of the set of policies.

[0130] A communication requirement for a group of endpoints defines an obligation on the each endpoint in the flow group’s participation in a communication flow in the flow group. In some embodiments, a communication requirement may define a conditional obligation on each endpoint (e.g., an obligation that only applies to the transmission of data).

[0131] Communication requirements for the endpoints of a flow group are determined based on policies set for the whole system of endpoints, and based on the specific endpoint characteristics of one or more of the endpoints in the flow group.

[0132] A communication requirement may comprise, but is not limited to, one or more of: a master cryptography key (e.g., a master key, also known as a flow key) to be cryptographically applied to data; a master key identifier; a cryptographic algorithm or protocol with which to apply the master key; a session key generation algorithm or protocol; or any combination thereof.

[0133] A communication requirement may comprise session key rotation instructions, comprising: a session key rotation protocol; a session key rotation period; and a session key rotation trigger. A communication requirement may comprise a data transmission requirements, such as: a bandwidth restriction; a packet size restriction.Processing policies

[0134] Referring again to the message sequence of Figure 5, at step 300, the domain manager 112 is configured to process the policies of Table 1, and the endpoint characteristics of transmitter endpoint 162, to determine applicable communication requirements to provide to transmitter endpoint 162.

[0135] Policy 1 is conditional on the transmitter endpoint 162 being located in a sensitive location. In processing the endpoint characteristics and the policies, the domain manager 112 determines that the endpoint characteristics of transmitter endpoint 162 indicate that the endpoint is located in the Boardroom, which is considered by Policy 1 to be a sensitive location. Accordingly, the domain manager 112 determines that the communication requirements of Policy 1 are applicable to transmitter endpoint 162.

[0136] Policy 2 is conditional on a receiver endpoint, in the flow group identified by flow group identifier ‘XYZ’ 505, being located in the guest meeting room. In processing the endpoint characteristics, the domain manager 112 determines that, at this stage, there is no receiver endpoint in the flow group identified by flow group identifier ‘XYZ’ 505. Accordingly, the domain manager 112 determines that Policy 2 is not applicable to the transmitter endpoint 162.

[0137] Policy 3 is conditional on the transmitter endpoint 162 being used for a guest. In processing the endpoint characteristics and the policies, the domain manager 112 determines that the endpoint characteristics of endpoint 162 indicate that the defined use of this endpoint is not for guest use. Accordingly, the domain manager 112 determines that Policy 3 is not applicable to the transmitter endpoint 162.

[0138] Policy 4 is applicable to all endpoints in the system of endpoint 102, unconditionally. Accordingly, in processing the endpoint characteristics and the policies, the domain manager 112 determines that communication requirements of Policy 4 are applicable to transmitter endpoint 162.

[0139] Policy 5 is applicable to endpoints in the “ACME domain”. In processing the endpoint characteristics and the policies, the domain manager 112 determines that the transmitter endpoint 162 is not in the “ACME domain”. Accordingly, the domain manager 112 determines that the communication requirements of Policy 5 are not applicable to transmitter endpoint 162.

[0140] Policy 6 is applicable to endpoints in the clock domain “clock_domain_A3Fl”. The domain manager 112 determines that the transmitter endpoint 162 is not in the “clock_domain_A3Fl”. Accordingly, the domain manager 112 determines that the communication requirements of Policy 6 are not applicable to transmitter endpoint 162.

[0141] The domain manager 112 determines that the combined communication requirements for Policy 1 and Policy 4 are:Encry pti on=TRUE,Encry pti on_algorithm= AES -256Session key rotation = TRUESession_key_rotation_period = 24 hoursSession key_rotation_period <= 1 weekwhich can be simplified to:Encry pti on=TRUE,Encry pti on_algorithm= AES -256Session key rotation = TRUESession_key_rotation_period = 24 hours

[0142] As the simplified communication requirements specify encrypted communication, the domain manager 112 includes a master key, and master key identifier to the simplified communication requirements. The domain manager 112 then provides the simplified communication requirements 506 to the transmitter endpoint 162, as applicable communication requirements.Adding a receiver endpoint

[0143] In response to receiving message 506, the transmitter endpoint 162 creates a communication flow in accordance with the communication requirements 506, and publishes flow information for receiver endpoints.

[0144] On instruction 508 from the controller, the receiver endpoint 168 defines a communication flow. In particular, the receiver endpoint 166 transmits, to the domain manager 112, a request 510 to participate in a communication flow within a group of endpoints of the system of endpoints. The group of endpoints being identified by the flow group identifier ‘XYZ’ 505. The request to participate 510 includes the flow group identifier ‘XYZ’ 505.

[0145] In response to receiving message 510, the domain manager 112 again performs method 300 to determine communication requirements for the endpoints of the flow group. The domain manager 112 determines, based on the endpoint characteristics of the receiver endpoint 168, that no additional policies are applicable due to the addition of receiver endpoint 168 to the flow group. Accordingly, the simplified communication requirements 506 are applicable to receiver endpoint 168 and transmitter endpoint 162. The domain manager 112 transmits the communication requirements 506 (including the master key and master key identifier) to the receiver endpoint 168.

[0146] A communication flow 520 is created between the transmitter endpoint 162 and the receiver endpoint 168.Scenarios

[0147] In an example scenario, the receiver endpoint 166 transmits, to the domain manager 112, a request to participate in the “XYZ” flow group. Receiver endpoint 166 is located in the guest meeting room. In performing operation 308, the domain manager 112 processes the endpoint characteristics of receiver endpoint 166, and the endpoint characteristics of the other endpoints in flow group ‘XYZ’ (e.g., transmitter endpoint 162 and receiver endpoint 168). The domain manager 112 determines, based on the endpoint characteristics of receiver endpoint 162, that Policy 2 is applicable. However, the communication requirements of Policy 2 forbidthe inclusion of a receiver endpoint in a guest meeting room being in a flow group with a transmitter located in a sensitive location. In other words, the inclusion of the receiver endpoint 166 in the flow group ‘XYZ’ would not satisfy the set of policies, defined in the policy repository 122.

[0148] Accordingly, based on the endpoint characteristics of the transmitter endpoint 162, the receiver endpoint 166 is forbidden from joining flow group ‘XYZ’. In this case, the domain manager 112 transmits an error message to receiver endpoint 166, and may issue an error report to an administrator.

[0149] Considering another example scenario in which the transceiver endpoint 164 transmits, to the domain manager 112, a request to participate in the “XYZ” flow group. This may occur in the event of a guest providing a backup microphone in the boardroom, for example. In performing operation 308, the domain manager 112 processes the endpoint characteristics of transmitter endpoint 164, and the endpoint characteristics of the other endpoints in flow group ‘XYZ’ (e.g., transmitter endpoint 162 and receiver endpoint 168). The domain manager 112 determines, based on the endpoint characteristics of transmitter endpoint 164, that Policy 3 is applicable.

[0150] Accordingly, the domain manager 112 revises the communication requirements 506 to incorporate the additional communication requirements specified by Policy 3 - being ‘Maximum packet size = packet size small’ .

[0151] The revised communication requirements are:Encry pti on=TRUE,Encry pti on_algorithm= AES -256Session key rotation = TRUESession_key_rotation_period = 24 hoursMaximum packet size = packet size small

[0152] The domain manager 112 transmits the revised communication requirements to all endpoints in flow group ‘XYZ’ . The revised communication requirements include a new master key and master key identifier.

[0153] Notably, the revised communication requirements that are received by the transmitter endpoint 162 (and the other endpoints in flow group ‘XYZ’) have been determined, at least ine part, based on endpoint characteristics of an endpoint other than transmitter endpoint 162 itself.Further applications

[0154] In some embodiments, policies may be conditional on owner or manufacturer characteristics of the endpoint. For example, the manufacturer of the endpoint (e.g. manufacturer X or software developer Y) may desire secure communication of their own manufacturer specified data (e.g., proprietary networked video, signal processing metadata, specified communication protocols, metadata, headers, product identifiers) between endpoints of that manufacturer / developer. Access to the manufacturer specified data may be provided to the other endpoints by the domain manager 112, via communication requirements. Advantageously, the provision of the manufacturer specified data by the domain manager 112, in response to the endpoint’ s manufacturer charactertistics, may ameliorate the need for manual user configuration at the endpoints, to setup the manufacturer’s policy group.

[0155] In some embodiments, policies may be conditional on licensing characteristics of the endpoint. For example, an endpoint user may decide purchase access to audio, but not video, for an endpoint. Accordingly, in response to the endpoint requesting to participate in a flow group, the policies that are conditional on the endpoint;s licensing characteristics will be applicable to the endpoint, and the other endpoints in the group. Advantageously, centralling managing licensing via applicable policies managed by the domain manager 112, may ameliorate the need for management of licensing mechanisms at the endpoint.

[0156] In some embodiments, the network data will contain data from different policy groups (e.g. video from group X, object location metadata from group Y, person identification metadata from group Z). Advantageously, this reduces the multicast flows needed to transmit the same data to endpoints with heterogeneous access to these policy groups, and if an endpoints policy changes to remove or add access to data in the multicast flow, no changes to the multicast flow are required.

[0157] Media flows may contain a variety of data / metadata. For example, metadata may comprise data from a ‘smart sensor’ that contains the image data along with classification labels of objects and their respective locations. It can be desirable to be able to limit access to this data individually. For example, the metadata may be proprietary from a manufacture / developer and, or the metadata could be a licensable extension to the media stream. The advantage of having the metadata within the same flow is that if policies change, the network flows remain static.

[0158] Advantages of the described embodiments may comprise reducing networking complexity, and the time for policy changes to take effect on an endpoint.Clocking data

[0159] In some embodiments, the endpoints of a media network are configured to transmit and receive clocking data as well as media data. Endpoints may belong to clock domains, as well as to domains for media data transfer. Master keys may be utilised by endpoints for cryptographically securing media data. Similarly, master keys may be utilised by endpoints for securely transmitting clocking data to endpoints that belong to a clock domain.

[0160] In some embodiments, the domain manager 112 is configured determining a set of policies pertaining to clocking data transfer in the system of endpoints. Furthermore, the domain manager 112 is configured to apply process 300, or similar, to determine communication requirements for clocking data transfer. The domain manager 112 is configured to determine communication requirements for clocking data transfer by processing the communication requirements for clocking data transfer and the endpoint characteristics of the endpoints in the clock domain.

[0161] The communication requirements for clocking data transfer may be similar to the communication requirements for media data transfer. In particular, the communication requirements for clocking data transfer may comprise one or more of: a clocking data master key, and associated master key identifier; an authentication algorithm for signing the clocking data; a clock session key generation algorithm; a clock session key rotation trigger; and data transfer requirements.

[0162] Accordingly, the “clock domain” of an endpoint may be considered to be a characteristic of an endpoint, and the domain manager 112 may be configured to automatically generate, distribute and rotate keys for signing clock messages to secure the clocking data from tamper and / or malicious attacks.Centralised policy management

[0163] Advantageously, even when new transmitters are added to the boardroom (for example, an additional microphone), the administrator does not need to take action to apply the applicable policy Policy 3 to the new transmitter endpoint 164. Upon the new transmitter endpoint 164 requesting, to the domain manager 112, to transmit data within flow group ‘XYZ’ the domain manager 112 will automatically provide the communication requirements of Policy 3 to the new transmitter endpoint 164 (and the other endpoints of flow group ‘XYZ’) to satisfy the policy Policy 3.

[0164] Accordingly, the systems and methods provided herein can provide a ‘secure by default’ arrangement, whereby the domain manager 112 is configured to automatically determine applicable policies for a new endpoint that is added to the system of endpoints, without a user having to determine and apply applicable policies when adding the new endpoint. This approach can reduce the administrative burden placed on the user, and can ameliorate the risk of human error in determining and applying policies for the new endpoint.Unicast flow

[0165] Figure 6 illustrates a message sequence performed by components of a media network to establish a unicast communication flow, in accordance with an embodiment. Although the establishment of the unicast communication flow differs in sequence to the establishment of a multicast flow, the domain manager still receives a request 602 from an endpoint to participate in a communication flow in a flow group, and in response to receiving this request, the domain manager performs method 300 to determine communication requirements for the endpoints in the flow group. If the domain manager identifies communication requirements that satisfy the policies, the domain manager provides the communication requirements 606 to the endpoint and thus allows the endpoint to join the flow group.Master key regeneration

[0166] In some embodiments, the communication requirements provided from the domain manager 112 to an endpoint (e.g., in message 506) may comprise a master key. The same master key may be provided to all endpoints in a domain of endpoints. A master key may be unique to a domain of endpoints, such that the master key is not provided to endpoints outside the domain of endpoints.

[0167] The endpoints may cryptographically apply the master key to data to produce cryptographically processed data, by performing one or more cryptographic operations, including, but not limited to: encryption; decryption; signing; authentication; key generation; and hashing.

[0168] For example, the communication requirements provided to a transmitter endpoint may specify that data to be transmitted by the transmitter endpoint is to be encrypted by application of the master key in accordance with a specified encryption protocol. Similarly, a receiver endpoint may be configured to decrypt received data using the master key to produce plaintext data.

[0169] In some embodiments, it may be desirable for the domain manager 112 to generate a new a master key for a domain of endpoints, periodically, or in response to the occurrence of a security trigger.

[0170] In some systems, to ameliorate security risks, it is desirable to generate a new master key for the endpoints in a domain, in response to the security trigger. A security trigger may comprise one or more of; an endpoint being removed from the domain; an endpoint being added to the domain; a change in permission setting for an endpoint (e.g., a previously unsecure endpoint is now considered to be secure, or a previously secure endpoint is now considered to be unsecure); a determination that the security of an endpoint may be compromised; change in licensing characteristics of the endpoint; a change in a policy, such that the policy is now applicable to an endpoint in the group of endpoints; a change in a policy, such that the policy is no longer applicable to an endpoint in the group of endpoints; failure to receive timely communication from an endpoint of the domain; receiving an instruction (e.g., a security trigger instruction) from the controller 110 to generate a new master key; determining a connectivity loss (e.g., loss of network connection) to the domain manager 112; or determining a power loss to the domain manager 112. Failure to receive timely communication from an endpoint of the domain may be an indication that the endpoint has experienced a failure, a power loss or the security of the endpoint has been compromised.

[0171] In one embodiment, the domain manager 112 is configured to receive heartbeat signals from a receiver endpoint in a domain. The domain manager 112 may be configured to receive heartbeat signals periodically, for example hourly. The heartbeat signal may comprise a dedicated heartbeat packet transmitted from the receiver endpoint to the domain manager 112. In some embodiments, the domain manager 112 may be configured to consider any packet transmitted from the receiver to the domain manager 112 to comprise a heartbeat signal.

[0172] For example, with reference to Figure 1, in response to the domain manager 112 failing to receive a heartbeat signal from receiver 184 endpoint for a period exceeding a predetermined heartbeat period (e.g., 1 hour), the domain manager 112 considers a security trigger has occurred. The domain manager 112 adjusts the domain 180 to remove the receiver endpoint 184 from the domain 180, thus creating adjusted domain 190.

[0173] In response to the occurrence of the security trigger, the domain manager 112 generates a new master key and provides the new master key to the endpoints of the adjusted domain 190. In response to receiving the new master key, the endpoints may be configured to generate a new session key with which to cryptographically apply to subsequent flow communications.Session keys

[0174] In some embodiments, an endpoint is configured to apply a session key, that is generated deterministically from a master key, rather than the master key itself, for cryptographic operations.

[0175] The session key may be cryptographically applied to data to produce cryptographically processed data, by to performing one or more cryptographic operations, including, but not limited to: encryption; decryption; signing; authentication; key generation; and hashing. Advantageously, the use of a session key, rather than the master key, to perform cryptographic operations avoids the transmission of the applied cryptographic key from one device in the system 100 to another device in the system, as the session key is generated locally, by each entity that utilises the session key, and the session key is not transmitted between devices.

[0176] Figure 8 is a flowchart illustrating the process 800 by which an endpoint determines a session key based on a master key, in accordance with an embodiment.

[0177] In operation 802, the endpoint receives a master key. The master key may be provided by the domain manager 112. For example, the master key may be provided as a communication requirement in message 506.

[0178] The master keys are assigned a master key identifier, that uniquely identifies the master key. The domain manager 112 assigns a master key identifier (such as “master key ID 752”) to a master key. The communication requirements comprise the master key identifier.

[0179] In operation 804, the endpoint determines session key generation instructions. The session key generation instructions instruct the endpoint to generate a session key from the master key. The key generation instructions may further indicate a method via which to generate the session key from the master key.

[0180] The endpoint may be preconfigured with the key generation instructions, for example as part of the firmware of the endpoint. Alternatively, the domain manager 112 may provide the session key generation instructions to the endpoint. The session key generation instructions may be provided as a communication requirement in message 506.Session key generation

[0181] In operation 806, the endpoint generates a session key, based on the master key, in accordance with the session key generation instructions.

[0182] For example, a transmitter endpoint selects a generator number and uses this number to generate a session key from the master key. A session key may be cryptographically generated by the transmitter endpoint, by applying a deterministic cryptographic algorithm, known to the endpoints of the flow group, to the generator number and the master key.

[0183] Once the session key is generated, the transmitter assigns a session key identifier to the session key (e.g., “session key ID 1025”), that uniquely identifies the session key within the flow group.

[0184] So that the receiver endpoints in the flow group can also generate the same session key, the transmitter endpoint provides the generator number, or an indication thereof, to the receiver endpoints in the flow group. The transmitter endpoint also indicates the master key identifier (assigned by the domain manager 112) and the session key identifier (assigned by the transmitter endpoint).

[0185] The transmitter endpoint may provide the generator number, master key identifier and session key identifier in a dedicated transmission to the other endpoints in the flow group. Alternatively, the transmitter endpoint may provide the generator number, master key identifier and session key identifier as metadata (or header data) in a media data transmission that has been encrypted using the previous session key. Advantageously, the session key is not transmitted from one endpoint to another endpoint.

[0186] In some embodiments, each packet transmitted in a flow group comprises an indication of the session key identifier, so that the receiving endpoint knows which session key to cryptographically apply to the packet.

[0187] In operation 808, if the endpoint is a transmitter endpoint, the endpoint applies the session key to data to produce encrypted data. The transmitter endpoint transmits the encrypted data to one or more receiver endpoints.

[0188] In operation 808, if the endpoint is a receiver endpoint, the endpoint receives encrypted data from a transmitter endpoint and applies the session key to the encrypted data to produce decrypted data.

[0189] An endpoint may store a plurality of session keys (e.g., for use with different flow groups, or during the transition from a current session key to a new session key). When a receiver endpoint receives an encrypted packet, it confirms that the session key in the packet is known to it by comparing the session key identifier to the identifiers of stored session keys. If so, it can decrypt the packet using that key. If not, the receiver can send a message to thetransmitter endpoint requesting that it re-send the session key generation information. In response, to such a request, the transmitter endpoint may re-send the session key generation information, comprising the master key identifier, generator number and session key identifier. In some cases, this process might continue several times until receiver has the right key. The most usual reason for the process repeating is that receiver has not yet received the master key from the domain manager 112 and thus cannot generate the session key. To avoid overwhelming the transmitter, a receiver may be configured to wait for a time period between sending successive requests for the session key generation information from the transmitter. Session key rotation

[0190] In operation 812, in response to the occurrence of a key rotation trigger 810, the endpoint is configured to rotate the session key. Session key rotation comprises the generation of a new session key to replace the current session key, for using in communication within the flow group. Session key rotation may be performed periodically to ensure that an attacker cannot accumulate sufficient data about an encrypted communication in order to break the communication.

[0191] To rotate a session key, a transmitter endpoint selects a new generator number and uses this new generator number to generate a new session key from the master key. The new session key may be cryptographically generated by the transmitter endpoint, by applying a deterministic cryptographic algorithm, known to the endpoints of the flow group, to the new generator number and the master key.

[0192] Once the new session key is generated, the transmitter assigns a session key identifier to the new session key (e.g., “session key ID 1026”), that uniquely identifies the new session key within the flow group.

[0193] So that the receiver endpoints in the flow group can also perform session key rotation (e.g., generate the same new session key), the transmitter endpoint provides the new generator number, or an indication thereof, to the receiver endpoints in the flow group. The transmitter endpoint also indicates the master key identifier (assigned by the domain manager 112) and the new session key identifier (assigned by the transmitter endpoint).

[0194] The transmitter endpoint may provide the new generator number, master key identifier and new session key identifier in a dedicated transmission to the other endpoints in the flow group. Alternatively, the transmitter endpoint may provide the new generator number, master key identifier and new session key identifier as metadata (or header data) in a media datatransmission that has been encrypted using the previous session key. Advantageously, the new session key is not transmitted from one endpoint to another endpoint.

[0195] Preferably, a domain of endpoints rotate a session key without disrupting communication within the domain of endpoints. In some embodiments, a transmitter endpoint transmits a key rotation signal to the receiver endpoints in the domain. The transmitter endpoint may include the key rotation signal in a header of a packet transmitted to the receiver endpoints in the domain.

[0196] In some embodiments, each endpoint maintains the concept of a “current” and “next” session key. Each audio packet can indicate which key it is encrypted with. After generating a new session key and signalling the new session key generation information to the other endpoints in the flow group, a transmitter can continue to apply the current session key for a preparation period (as defined in terms of time, numbers of packets, or data size) before transitioning to applying the new session key. The preparation period allows the receiver endpoints to generate the new session key themselves, and be prepared to receive packets encrypted with the new session key.

[0197] In some embodiments, the key rotation signal provides forewarning of an imminent change to the session key. For example, the key rotation signal may indicate that a new session key will be applied to data after x more packets transmitted from the transmitter endpoint. Accordingly, in response to receiving the key rotation signal, the receiver endpoint performs key rotation, so that the new session key is available for use upon receipt of the the x+1 packet from the transmitter endpoint.Flow group example

[0198] Figure 7 illustrates flow groups of endpoints, in accordance with an embodiment. In particular, Figure 7 illustrates flow group 702 and flow group 704. Flow group 702 comprises three endpoints, including a transmitter endpoint 706, a receiver endpoint 708 configured to receive data from transmitter endpoint 706, and a transceiver endpoint 710 configured to receive data from transmitter endpoint 706.

[0199] Flow group 704 comprises three endpoints, two receiver endpoints 712 and 714, and the transceiver endpoint 710, which is configured to transmit data to the receiver endpoints 712 and 714. Each of flow group 702 and flow group 704 are associated with a different session key. Accordingly, transceiver endpoint 710 has a session key for flow group 702 and a different session key for flow group 704.

[0200] Transceiver endpoint 710 may receive separate session key rotation instructions from the controller 110 for each of flow group 702 and flow group 704. Accordingly, the transceiver endpoint 710 may be configured to perform separate session key rotation operations for flow group 702 and flow group 704.Session key rotation trigger

[0201] The communication requirements 506 may comprise instructions to rotate the session key in response to a session key rotation trigger. The session key rotation trigger may comprise, but is not limited to, one or more of: receiving a session key rotation signal from another endpoint in the group of endpoints; the elapse of a period of time; the transmission or reception of a set amount of data (e.g. an amount of bytes); the transmission or reception of a set number of packets; an explicit session key rotation signal from the domain manager 112 or controller; a change in the master key; the transition in an endpoint’s state (e.g. being removed from the policy group, disconnecting from the domain manager 112); detection of instability or anomalies of an endpoint or the system (e.g. loss of clock synchronisation, network packet loss, high latency media); or a combination thereof.

[0202] In response to the occurrence of the session key rotation trigger 810, the endpoint is configured to rotate the session key. Advantageously, if the security parameters of the receiver endpoint 166 in the guest room were compromised during a meeting, a new session key will issue within the hour, thus the compromised keys will not longer be effective and usable.

[0203] Flowcharts provided herein illustrate steps performed in an illustrative method, and may not recite the complete process or all steps of the method. Although various steps of methods 300 and 800 are described herein, the steps need not necessarily all be performed, and in some cases may be performed simultaneously or in a different order than the order shown.

[0204] To avoid obscuring the inventive subject matter with unnecessary detail, various functional components (e.g., modules, devices, databases, etc.) that are not germane to conveying an understanding of the inventive subject matter have been omitted from the figures. However, a skilled artisan will readily recognize that various additional functional components may be supported by the system 100 to facilitate additional functionality that is not specifically described herein. Furthermore, the various functional components depicted in the figures may reside on a single computing device or may be distributed across several computing devices in various arrangements such as those used in cloud-based architectures.

[0205] It will be appreciated by persons skilled in the art that numerous variations and / or modifications may be made to the above-described embodiments, without departing from the broad general scope of the present disclosure. Furthermore, it will be appreciated by persons skilled in the art that embodiments disclosed herein can be combined with one or more other embodiment disclosed herein, without departing from the broad general scope of the present disclosure. The present embodiments are, therefore, to be considered in all respects as illustrative and not restrictive.

[0206] It will be appreciated by persons skilled in the art that any suitable distribution of functionality between different functional units may be used without detracting from the invention. For example, functionality illustrated to be performed by separate computing devices may be performed by the same computing device. Likewise, functionality illustrated to be performed by a single computing device may be distributed amongst several computing devices. Hence, references to specific functional units are only to be seen as references to suitable means for providing the described functionality, rather than indicative of a strict logical or physical structure or organization.

[0207] It will be appreciated by persons skilled in the art that, for processes and methods disclosed herein, the operations performed in the processes and methods may be implemented in differing order. Furthermore, the outlined steps and operations are only provided as examples, and some of the steps and operations can be optional, combined into fewer steps and operations, or expanded into additional steps and operations without detracting from the essence of the disclosed embodiments.

[0208] References herein to software or executable instructions are to be understood as referring to executable instructions stored in volatile or non-volatile memory. The memory can include any data storage device that can store data which can thereafter be read by a processor. Examples of memory include read-only memory (ROM), random-access memory (RAM), magnetic tape, optical data storage device, flash storage devices, or any other suitable storage devices.

[0209] Throughout this specification the word ‘comprise’, or variations such as ‘comprises’ or ‘comprising’, will be understood to imply the inclusion of a stated element, integer or step, or group of elements, integers or steps, but not the exclusion of any other element, integer or step, or group of elements, integers or steps.

[0210] As used herein, any reference to “one embodiment” or “an embodiment” means that a particular element, feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. The appearances of the phrase “in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment. Similarly, use of “a” or “an” preceding an element or component is done merely for convenience. This description should be understood to mean that one or more of the element or component is present unless it is obvious that it is meant otherwise.

[0211] Unless expressly stated to the contrary, “or” refers to an inclusive or and not to an exclusive or. For example, a condition A or B is satisfied by any one of the following: A is true (or present) and B is false (or not present), A is false (or not present) and B is true (or present), and both A and B are true (or present).

[0212] Unless expressly stated to the contrary, the terms “first,” “second,” and “third,” etc. are used merely as labels, and are not intended to impose numerical requirements on their objects. The use of a numerical label for an object does not necessarily imply an requirements regarding the number of objects in the embodiment. In particular, the use of a numerical label for an object, wherein the numerical label indicates a number does not necessarily imply that there is that number of objects present in the embodiment.

[0213] Provided herein are additional aspects and features of this disclosure, presented without limitation as a series of paragraphs, some or all of which may be alphanumerically designated for clarity and efficiency. Each of these paragraphs can be combined with one or more other paragraphs, and / or with disclosure from elsewhere in this disclosure, in any suitable manner. Some of the paragraphs below expressly refer to and further limit other paragraphs, providing without limitation examples of some of the suitable combinations.Al. A method for securely transmitting data, via a communication network, to a data receiver, the method performed by a data transmitter, the method comprising:transmitting, to a controller, a group identifier;receiving, from the controller: a master key associated with the group identifier; and a master key identifier, the master key being identified by the master key identifier; determining a generator identifier;applying a generator identified by the generator identifier to the master key to generate a session key;assigning a session key identifier to the session key;transmitting, to at least one data receiver: the master key identifier; the generator identifier; and the session key identifier;cryptographically apply the session key to the data, to produce cryptographically processed data; andtransmitting, to the at least one data receiver: the session key identifier; and the cryptographically processed data.A2. The method of Al, further comprising, in response to a session key rotation trigger:determining a second generator identifier;applying a second generator identified by the second generator identifier to the flow key to generate a second session key;assigning a second session key identifier to the second session key; cryptographically apply the second session key to the data, to produce a second cryptographically processed data; andtransmitting, to the at least one data receiver: the second generator identifier; the second session key identifier; and the second cryptographically processed data.A3. The method of A2, wherein determining the second generator identifier comprises selecting the second generator identifier from a list of generator identifiers.A4. The method of A2 or A3, wherein the session key rotation trigger comprises one or more of: determining an elapse of a key rotation period; and the receipt of a key rotation instruction from the controller.A5. The method of any of Al to A4, further comprising, in response to receiving, from the controller a second master key and a second master key identifier, the second master key being identified by the second master key identifier:determining a third generator identifier;applying a third generator identified by the third generator identifier to the second master key to generate a third session key;assigning a third session key identifier to the third session key; andtransmitting, to at least one data receiver: the second master key identifier; the third generator identifier; and the third session key identifier.A6. The method of any of Al to A5, wherein transmitting, to the at least one data receiver, the session key identifier, and the cryptographically processed data comprises, transmitting, to the at least one data receiver, the session key identifier, and the cryptographically processed data in a single packet.A7. The method of any of Al to A6, further comprising determining, based on the group identifier, the at least one data receiver from a plurality of data receivers.A8. The method of A7, wherein the at least one data receiver comprises a plurality of data receivers.A9. The method of any of Al to A8, wherein the data transmitter and the data receiver are associated with a clock domain, and wherein the group identifier identifies the clock domain. A10. The method of A9, wherein the cryptographically processed data comprises clock distribution data signed with the session key.Bl. A method for securely receiving data from a data transmitter, via a network, the method performed by a data receiver, the method comprising:providing, to a controller, a group identifier;receiving, from the controller:a master key associated with the group identifier; anda master key identifier, the master key being identified by the master key identifier; receiving, from the data transmitter, a first packet comprising:the master key identifier; a key generator identifier; and a session key identifier; generating a session key, by applying a key generator, identified by the key generator identifier, to the master key identified by the master key identifier;identifying the session key with the session key identifier;receiving, from the transmitter, a second packet comprising: the session key identifier; and cryptographically processed data; anddecrypting the cryptographically processed data, by applying the session key identified by the session key identifier to the cryptographically processed data, to produce unencrypted data.Cl. A method for controlling the secure transmission of data, from a data transmitter to a data receiver, the method performed by a controller, the method comprising:receiving, from each of the data transmitter and the data receiver, a group identifier; in response to verifying that the data transmitter is in a group identified by the group identifier, and in response to verifying that the data receiver is in a group identified by the group identifier, provide, to each of the data transmitter and the data receiver: a master key associated with the group identifier; anda master key identifier, the master key being identified by the master key identifier. C2. The method of Cl, further comprising, in response to determining a security trigger:determine a second master key associated with the group identifier; andprovide, to each of the data transmitter and the data receiver:the second master key; and a second master key identifier, the second master key being identified by the second master key identifier.C3. The method of C2, wherein determining the security trigger comprises one or more of:determining an elapse of a period of time since receiving a transmission from the data receiver;determining that the data receiver is no longer associated with the group identifier; determining that the data transmitter is no longer associated with the group identifier; anddetermining, based on a predefined policy, that the data receiver is no longer permitted to receive data from the data transmitter.C4. The method of C2, wherein the at least one data receiver comprises a plurality of data receivers, and determining the security trigger comprises determining at a data receiver of the plurality of data receivers is no longer associated with the group identifier.C5. The method of Cl, wherein receiving, from each of the data transmitter and the data receiver, a group identifier, comprises:receiving, from the receiver via a first communication network, a first group identifier; receiving, from the transmitter, via a second communication network, a second group identifier; anddetermining that the first group identifier is the same as the second group identifier. DI . A method for managing transmission of data within a system of endpoints, each endpoint of the group of endpoints configured to receive data from, or transmit data to, another endpoint of the group of endpoints, the method comprising:determining one or more communication policies for the system of endpoints; determining a group of endpoints in the system of endpoints, wherein, each endpoint of the group of endpoints is defined by a respective set of endpoint characteristics; processing the one or more communication policies and at least one of the sets of endpoint characteristics to determine communication requirements of the group of endpoints; andin response to receiving, from a first endpoint of the group of endpoints, a request to participate in a communication flow within the group of endpoints,providing, to the first endpoint, the communication requirements of the group of endpoints.El . A machine-readable storage medium storing instructions which, when executed by one or more processors, individually or in combination, cause the one or more processors to perform a method described herein.Fl. A system comprising:one or more processors; andmemory comprising computer executable instructions, which when executed by the one or more processors, individually or in combination, cause the system to perform a method described herein.

Claims

CLAIMS:

1. A method for managing transmission of data within a system of endpoints, each endpoint of the system of endpoints configured to receive data from, or transmit data to, another endpoint of the system of endpoints, the method comprising:determining one or more communication policies for the system of endpoints, each of the one or more communication policies specifying a communication requirement that is conditional on a respective endpoint characteristic;in response to receiving, from a first endpoint of the system of endpoints, a request to participate in a communication flow within a group of endpoints of the system of endpoints, the group of endpoints comprising a subset of the system of endpoints: determining at least one endpoint characteristic associated with the one or more endpoints in the group of endpoints;processing the one or more communication policies and the at least one endpoint characteristic to determine applicable communication requirements for the group of endpoints; andproviding, to the first endpoint, the applicable communication requirements for the group of endpoints.

2. The method of claim 1, wherein determining the one or more communication policies for the system of endpoints comprises:obtaining, via a user interface, one or more user defined policies; andderiving a derived policy from one or more preconfigured policies and the one or more user defined policies.

3. The method of claim 2, wherein if an endpoint satisfies the derived policy, the endpoint also satisfies the one or more user defined policies and satisfies the one or more preconfigured policies.

4. The method of any of claims 1 to 3, wherein determining the at least one endpoint characteristic of an endpoint comprises one or more of:receiving from the endpoint, the endpoint characteristic; andretrieving, from a data storage medium, the endpoint characteristic.

5. The method of any of claims 1 to 4, further comprising one or more of:transmitting, by the first endpoint, to a second endpoint of the group of endpoints, data in accordance with the communication requirements; andreceiving, from the first endpoint, from a second endpoint of the group of endpoints, data in accordance with the communication requirements.

6. The method of any of claims 1 to 5, wherein the communication requirements satisfy the one or more communication policies.

7. The method of any of claims 1 to 6, further comprising, providing, to each endpoint of the group of endpoints, the communication requirements of the group of endpoints.

8. The method of any of claims 1 to 7, further comprising:in response to receiving, from a first endpoint of the group of endpoints, a request to participate in a communication flow within the group of endpoints, andin response to processing the plurality of communication policies and at least one of the sets of endpoint characteristics to determine that the first endpoint’s participation in the communication flow within the group of endpoints does not satisfy one or more communication policies of the plurality of communication policies,rejecting the first endpoint’s request to participate in the communication flow within the group of endpoints.

9. The method of any of claims 1 to 8, wherein the group of endpoints comprises at least one transmitter endpoint and at least one receiver endpoint.

10. The method of any of claims 1 to 9, wherein processing the one or more communication policies and the at least one endpoint characteristic to determine applicable communication requirements for the group of endpoints comprises:determining applicable communication requirements for the group of endpoints that satisfy the communication policies defined for the system of endpoints.

11. The method of any of claims 1 to 10, wherein the one or more communication policies define one or more of:data transmission restrictions which are applicable based on endpoint characteristics of a transmitter endpoint;data transmission restrictions which are applicable based on endpoint characteristics of a receiver endpoint; anddata cryptographic processing requirements.

12. The method of any of claims 1 to 11, wherein the at least one endpoint characteristic defines one or more of:a communication capability of the endpoint;a communication limitation of the endpoint;a data transmission restriction of the endpoint;a data transmission permission of the endpoint;a data reception restriction of the endpoint;a data reception permission of the endpoint;a physical location of the endpoint; andan indication of one or more groups to which the endpoint belongs.

13. The method of any of claims 1 to 12, wherein the applicable communication requirements for the group of endpoints satisfy the communication policies defined for the system of endpoints.

14. The method of any of claims 1 to 13, wherein the applicable communication requirements comprise one or more of:a master key;a master key identifier;a data encryption algorithm;a data decryption algorithm;;a key rotation scheme;a packet size restriction;a data signing mechanism;a data authentication mechanism; anda policy restriction for transmitting data.

15. The method of any of claims 1 to 14, wherein receiving, from the first endpoint, the request to participate in a communication flow within the group of endpoints comprises: receiving, from the first endpoint, a group identifier identifying the group of endpoints.

16. The method of claim 13, further comprising,verifying, that the first endpoint belongs to a group of endpoints identified by the group identifier; andin response to verifying that the first endpoint belongs to the group of endpoints, provide, to the first endpoint the communication requirements.

17. The method of any of claims 1 to 16, wherein the first endpoint comprises a transmitter endpoint, and wherein the request to participate in a communication flow within the group of endpoints comprises a request to transmit data.

18. The method of claim 17, wherein the first endpoint is configured to:cryptographically apply the master key to data to determine cryptographically processed data; andtransmit the cryptographically processed data to the at least one receiver endpoint.

19. The method of claim 18, wherein applying the master key to data to determine cryptographically processed data comprises:determining a generator identifier;applying a generator identified by the generator identifier to the master key to generate a session key;assigning a session key identifier to the session key;transmitting, to at least one receiver endpoint of the group of endpoints:the master key identifier;the generator identifier; andthe session key identifier; andcryptographically apply session key to the data to produce the cryptographically processed data.

20. The method of claim 19, wherein transmitting the cryptographically processed data to the at least one receiver endpoint comprises:transmitting, to the at least one receiver endpoint:the session key identifier; andthe cryptographically processed data.

21. The method of any of claim 1 to 20, wherein the first endpoint is further configured to, in response to an occurrence of a session key rotation trigger:determine a second generator identifier;apply a second generator identified by the second generator identifier to the flow key to generate a second session key;assign a second session key identifier to the second session key;apply the second session key to a second data, to produce a cryptographically processed second data; andtransmitting, to the at least one receiver endpoint:the second generator identifier;the second session key identifier; andthe cryptographically processed second data.

22. The method of claim 21, wherein determining the second generator identifier comprises selecting the second generator identifier from a list of generator identifiers.

23. The method of claim 22,wherein the communication requirements comprise a session key rotation period, and wherein the session key rotation trigger comprises determining an elapse of the session key rotation period.

24. The method of any of claims 1 to 23, wherein, in response to determining an occurrence of a security trigger, the domain manager is configured to transmit a new master key to one or more endpoints in the group of endpoints.

25. The method of claim 24, wherein the security trigger comprises one or more of: determining the addition of a new endpoint to the group of endpoints; determining the removal of a third endpoint from the group of endpoints; determining an interruption in the communication to at least one of the endpoints of the group of endpoints;determining a loss of power; andreceiving a security trigger instruction from the controller.

26. The method of claim 25, wherein the security trigger comprises determining the removal of a third endpoint from the group of endpoints, and wherein the domain manager is configured to not transmit the new master key to the third endpoint.

29. The method of claims 25 to 26, wherein the domain manager is configured to receive a periodic heartbeat signal from the third endpoint within a heartbeat interval, and wherein determining the removal of the third endpoint from the group of endpoints comprises determining that a heartbeat signal from the third endpoint has not been received by the domain manager within the heartbeat interval.

28. The method of any of claims 1 to 27, further comprising, in response to adding a new endpoint to the group of endpoints:processing the one or more communication policies and at least one of the sets of endpoint characteristics, including the endpoint characteristics of the new endpoint, to determine revised communication requirements of the group of endpoints; and providing, to the first endpoint, the revised communication requirements of the group of endpoints.

29. The method of any of claims 1 to 28, wherein the first endpoint comprises a receiver endpoint, and wherein the request to participate in a communication flow within the group of endpoints comprises a request to receive data from at least one transmitter endpoint of the group of endpoints.

30. The method of claim 29, wherein the receiver endpoint is configured to:receive cryptographically processed data from the at least one transmitter endpoint of the group of endpoints; andcryptographically apply the master key to the cryptographically processed data.

31. The method of any of claims 18 or 30, wherein the cryptographically processed data comprises clock distribution data signed with the session key.

33. A domain manager compri sing :one or more processors, configured to, individually or in combination perform the method as defined in any of claims 1 to 31.

34. A system for controlling transmission of data within a system of endpoints, each endpoint configured to receive data from, or transmit data to, another endpoint in the system of endpoints, the system comprising:a storage medium configured to store:a plurality of communication policies for the system of endpoints; anda plurality of communication requirements, each communication requirement associated with a group of endpoints; anda domain manager, comprising one or more processors, configured to, individually or in combination, perform the method as defined in any of claims 1 to 31.

35. A non-transitory computer-readable storage medium storing instructions, which when executed by one or more processors, individually or in combination, perform the method as defined in any of claims 1 to 31.