Decryption-key distribution method and authentication apparatus
Abstract
A decryption key for decrypting data from an access node is distributed to an access terminal intending to receive the data. An authentication unit receives a message for terminal authentication including a terminal identifier from the terminal and authenticates the terminal. The authentication unit refers to a content registration table having stored in advance the content type of a content which the terminal can receive, in association with the terminal identifier, according to the received terminal identifier to obtain a corresponding content type. The authentication unit refers to a decryption data base having stored in advance a decryption key and its valid period in association with a content type, according to the obtained content type to obtain a corresponding decryption key and valid period. The authentication unit sends an authentication result and the decryption key and valid period to the terminal or to a packet control unit.
Claims
exact text as granted — not AI-modified1 . A decryption-key distribution method for distributing a decryption key to a radio terminal in a radio communication system where a contents server sends data encrypted with an encryption key which is received from a control unit managing the encryption key and/or the decryption key to the radio terminal through a broadcast channel, and the radio terminal decrypts the received data with the decryption key corresponding to the encryption key and distributed in advance, the decryption-key distribution method comprising:
a step, performed by an authentication unit, of receiving a content type or content identification information, and a corresponding decryption key and valid period of the decryption key from the control unit and of storing the received content type or content identification information, the decryption key, and valid period of the decryption key in a decryption-key data base in association with each other; a step, performed by the authentication unit, of receiving an authentication request that includes a terminal identifier from the radio terminal; a step, performed by the authentication unit, of authenticating the terminal in response to the received authentication request; a step, performed by the authentication unit, of referring to a content registration data base where the terminal identifier and the content type or content identification information of a content which the terminal can receive are stored in advance in association with each other, according to the terminal identifier included in the received authentication request to obtain the corresponding content type or content identification information; a step, performed by the authentication unit, of referring to the decryption-key data base according to the obtained content type or content identification information to obtain the corresponding decryption key and valid period of the decryption key; and a step, performed by the authentication unit, of sending an authentication result obtained in the step of authenticating the terminal, and the obtained decryption key and valid period of the decryption key to the radio terminal or to a packet control unit.
2 . A decryption-key distribution method according to claim 1 , wherein, in the step of sending to the radio terminal or the packet control unit, the authentication unit sends a message for reporting the authentication result which includes the obtained decryption key and valid period of the decryption key, to the radio terminal or the packet control unit.
3 . A decryption-key distribution method according to claim 1 , further comprising:
a first step, performed by the packet control unit, of sending a terminal calling signal to which information indicating that the signal is for authenticating the terminal is attached, to the radio terminal; a second step, performed by the radio terminal, of sending an authentication request that includes the terminal identifier to the authentication unit in response to the received terminal calling signal; and a third step, performed by the authentication unit, of authenticating the terminal again in response to the received authentication request, of referring to the content registration data base and the decryption-key data base to obtain a content type or content identification information, one or a plurality of decryption keys whose valid periods are later than the current time, and one or a plurality of valid periods corresponding to the one or the plurality of decryption keys, and of sending them to the radio terminal or the packet control unit.
4 . A decryption-key distribution method according to claim 3 , wherein the packet control unit sends the terminal calling signal to each radio terminal at different timing.
5 . A decryption-key distribution method according to claim 1 , further comprising:
a fourth step, performed by the authentication unit, of receiving an authentication request that includes a terminal identifier from a radio terminal which is performing data communication, by using a session established between the radio terminal and a radio base station for data communication; and a fifth step, performed by the authentication unit, of authenticating the terminal again in response to the received authentication request, of referring to the content registration data base and the decryption-key data base to obtain a content type or content identification information, one or a plurality of decryption keys whose valid periods are later than the current time, and one or a plurality of valid periods corresponding to the one or the plurality of decryption keys, and of sending them to the radio terminal or the packet control unit.
6 . A decryption-key distribution method according to claim 5 , wherein the packet control unit sends a message for requesting terminal authentication to each radio terminal at different timing, and
the authentication request sent from the radio terminal which is performing data communication, in response to the received message for requesting terminal authentication, is received in the fourth step.
7 . A decryption-key distribution method according to claim 5 , wherein the fourth and fifth steps are executed for the radio terminal which is performing data communication, and the first to third steps are executed for a radio terminal which is not performing data communication.
8 . A decryption-key distribution method according to claim 1 ,
wherein, in the step of sending to the radio terminal or the packet control unit, the authentication unit sends the authentication result, the obtained content type or content identification information, and the obtained decryption key and valid period of the decryption key to the packet control unit, and further comprising: a step, performed by the packet control unit, of sending the received content type or content identification information, decryption key and valid period of the decryption key to the radio terminal, and of storing the content type or content identification information and the valid period in a call-control data base in association with a terminal identifier for identifying the radio terminal, and a step, performed by the packet control unit, of sending a terminal calling signal or a message for requesting terminal authentication at a predetermined period before the end time of the valid period stored in the call-control data base to the radio terminal indicated by the terminal identifier corresponding to the valid period.
9 . A decryption-key distribution method according to claim 8 , wherein, when there are a plurality of terminal identifiers which are the predetermined period before the end time of the valid periods, the packet control unit sends the terminal calling signal or the message for requesting terminal authentication to one of a plurality of corresponding radio terminals, and sends the terminal calling signal or the message for requesting terminal authentication to another ratio terminal of the plurality of corresponding radio terminals after a decryption key is distributed to the one of the plurality of corresponding radio terminals or when a predetermined period elapses.
10 . An authentication unit in a radio communication system where a contents server sends data encrypted with an encryption key which is received from a control unit managing the encryption key and/or a decryption key to a radio terminal through a broadcast channel, and the radio terminal decrypts the received data with the decryption key corresponding to the encryption key and distributed in advance, the authentication unit comprising:
a decryption-key data base for storing a received content type or content identification information, decryption key, and valid period of the decryption key in association with each other; a content registration data base having stored in advance a terminal identifier and the content type or content identification information of a content which the terminal can receive, in association with each other; and a processing section for authenticating the terminal and distributing the decryption key, wherein the processing section receives a content type or content identification information, a corresponding decryption key and valid period of the decryption key from the control unit and stores them in the decryption-key data base, receives an authentication request that includes a terminal identifier from the radio terminal, authenticates the terminal in response to the received authentication request, refers to the content registration data base according to the terminal identifier included in the received authentication request to obtain a corresponding content type or content identification information, refers to the decryption-key data base according to the obtained content type or content identification information to obtain a corresponding decryption key and valid period of the decryption key, and sends an authentication result and the obtained decryption key and valid period of the decryption key to the radio terminal or to a packet control unit.Join the waitlist — get patent alerts
Track US2006291662A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.