US2015074417A1PendingUtilityA1

Apparatus and method for access control of content in distributed environment network

Assignee: SAMSUNG ELECTRONICS CO LTDPriority: Mar 2, 2011Filed: Nov 17, 2014Published: Mar 12, 2015
Est. expiryMar 2, 2031(~4.6 yrs left)· nominal 20-yr term from priority
Inventors:Dae-Youb Kim
H04L 9/50H04L 63/061H04L 63/101H04L 9/008H04L 2209/60H04L 2463/062H04L 9/0861H04L 9/088H04L 9/3247H04L 9/0825H04L 9/0643
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An apparatus for generating a key for access control of content in a distributed environment network is provided. The apparatus includes a first key distributor configured to generate first encrypted keys by encrypting a first key corresponding to a key for write authorization using each public key of members having write authorization among members included in an access control list including information of at least one user and distribute the access control list and information about access authorization and the first encrypted keys to the members having write authorization, and a second key distributor configured to generate second encrypted keys by encrypting a second key corresponding to a key for read authorization using the first key using each public key of members having read authorization among members included in the access control list and distribute the access control list and second encrypted keys to the members having read authorization.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An apparatus for generating content for an access control of content in a distributed environment network, the apparatus comprising:
 a key decryption unit configured to secure a first key by decrypting a first encrypted key, encrypted by using a public key, using a secret key corresponding to the public key;   an encryption key generator configured to generate an encryption key using a second key generated using the first key;   a content encryption unit configured to generate an encrypted content by encrypting content using the encryption key;   a signature generator configured to generate a signature using the first key, a content and a signature key in response to members included in an access control list having write authorization as a result of checking access authorization of the members; and   a distributor configured to distribute the encrypted content and the signature through a network.   
     
     
         2 . The apparatus of  claim 1 , wherein the encryption key generator generates the encryption key using information of the content and the second key. 
     
     
         3 . The apparatus of  claim 1 , wherein the first key corresponds to a key for write authorization and is neither generated nor predicted using the second key. 
     
     
         4 . The apparatus of  claim 1 , wherein the second key corresponds to a key for read authorization and is a result obtained by hashing the first key n times, the value of n being an integer greater than 0. 
     
     
         5 . The apparatus of  claim 1 , wherein:
 the signature generator generates the signature using a value obtained by hashing the first key m times, a value obtained by hashing the content, and the signature key,   the distributor distributes a value of the m in addition to the encrypted content and the signature and   the value m corresponds to a random value less than n corresponding to a number of times the first key is hashed to generate the second key.   
     
     
         6 . The apparatus of  claim 1 , wherein the signature generator generates the signature using an algorithm having a one-way homomorphic characteristic. 
     
     
         7 . The apparatus of  claim 1 , wherein the signature key is generated based on a Rivest Shamir Adleman (RSA) encryption scheme. 
     
     
         8 . An apparatus for verification of content for an access control of content in a distributed environment network, the apparatus comprising:
 a receiver configured to receive an encrypted content, a signature of the encrypted content, and an access control list, and to receive a second encrypted key from a network in response to the apparatus being determined to have read authorization as a result of checking the access control list;   a key decryption unit configured to secure a second key by decrypting the second encrypted key, encrypted by using a public key, using a secret key corresponding to the public key in response to the apparatus being determined to have read authorization as a result of checking the access control list;   a signature verification unit configured to verify the signature using the second key and the encrypted content;   a decryption key generator configured to generate a decryption key using the second key in response to the signature verification being successful; and   a content decryption unit configured to decrypt the encrypted content using the decryption key.   
     
     
         9 . The apparatus of  claim 8 , further comprising:
 a second key generator configured to generate the second key using a first key,   wherein the receiver receives a first encrypted key from the network, and   the key decryption unit secures the first key by decrypting the first encrypted key using the secret key in response to the apparatus being determined to have write authorization as a result of checking the access control list.   
     
     
         10 . The apparatus of  claim 9 , wherein the first key corresponds to a key for write authorization and is neither generated nor predicted using the second key. 
     
     
         11 . The apparatus of  claim 9 , wherein the second key corresponds to a key for read authorization and is a result obtained by hashing the first key n times, the value of n being an integer greater than 0. 
     
     
         12 . A method for an access control of content in an apparatus for generating content of a distributed environment network, the method comprising:
 requesting and receiving an access control list and a first encrypted key from a network;   securing a first key corresponding to a key for write authorization by decrypting the first encrypted key, encrypted by using a public key, using a secret key corresponding to the public key in response to the apparatus being determined to have write authorization as a result of checking the access control list;   generating an encryption key using information of a content and a second key corresponding to a key for read authorization using the first key;   generating an encrypted content by encrypting content using the encryption key;   generating a signature using the first key, the content, and a signature key; and   distributing the encrypted content and the signature through the network.   
     
     
         13 . The method of  claim 12 , wherein:
 the generating of the signature comprises generating the signature using a value obtained by hashing the first key m times, a value obtained by hashing the content and the signature key,   the distributing comprises distributing a value of the m in addition to the encrypted content and the signature, and   the value m corresponds to a random value less than n corresponding to a number of times the first key is hashed to generate the second key, the value of n being an integer greater than 0.   
     
     
         14 . The method of  claim 12 , wherein the generating of the signature comprises generating the signature using an algorithm having a one-way homomorphic characteristic. 
     
     
         15 . A method for an access control of content in an apparatus for verification of content of a distributed environment network, the method comprising:
 checking access authorization of an encrypted content in an access control list to verify access requirements are satisfied;   securing a second key corresponding to a key for read authorization in response to the encrypted content being determined to be accessible as a result of the verification;   verifying a signature of the encrypted content using the second key and the encrypted content;   generating a decryption key using the second key in response to the signature verification being successful; and   decrypting the encrypted content using the decryption key.   
     
     
         16 . The method of  claim 15 , wherein the securing comprises:
 receiving a second encrypted key from the network in response to the apparatus being determined to have read authorization as a result of checking the access control list; and   securing a second key by decrypting the second encrypted key, encrypted by using a public key, using a secret key corresponding to the public key.   
     
     
         17 . The method of  claim 15 , wherein the securing comprises:
 receiving a first encrypted key from the network in response to the apparatus being determined to have write authorization as a result of checking the access control list;   securing a first key by decrypting the first encrypted key, encrypted by using a public key, using a secret key corresponding to the public key; and   generating the second key using the first key.

Join the waitlist — get patent alerts

Track US2015074417A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.