Claims
- 1. A method for distributing group secrets, said method comprising the steps of:
encrypting a first user group record containing at least one group secret using a first user secret associated with a first of a plurality of users; and distributing said encrypted first user group record to a first communication device associated with said first user for decryption using said first user secret.
- 2. The method of claim 1, wherein said at least one group secret comprises a plurality of group secrets.
- 3. The method of claim 1, further comprising at least the steps of:
encrypting a second user group record containing at least one group secret using a second user secret associated with a second of a plurality of users; and distributing said encrypted second user group record to a second communication device associated with said second user for decryption using said second user secret.
- 4. The method of claim 1, wherein said first user group record is encrypted at an administrator.
- 5. The method of claim 1, further comprising at least the step of:
storing said encrypted first user group record at a distribution facility prior to said distributing step.
- 6. The method of claim 1, wherein said user secret includes at least a user ID and password combination and said at least one group secret includes at least one group ID and password combination.
- 7. The method of claim 1, further comprising at least the steps of:
receiving said encrypted first user group record at said first communication device; and decrypting said encrypted first user group record at said first communication device using said first user secret to obtain said at least one group secret, said first user secret supplied to said first communication device by said first user.
- 8. The method of claim 7, wherein a first of said at least one group secret is used to encrypt a group traffic key, said method further comprising at least the steps of:
extracting said first group secret from said decrypted user group record; and decrypting said group traffic key at said first communication device using said extracted first group secret.
- 9. A method for distributing group secrets in a communication system, said method comprising the steps of:
encrypting a user group record for a user at an administrator using a user secret known to said administrator and to said user, said user group record including at least one group secret for a group to which said user belongs; passing said encrypted user group record to a distribution system for storage and distribution; distributing said encrypted user group record from said distribution system to a communication device associated with said user; decrypting said encrypted user group record at said communication device using said user secret to obtain said at least one group secret, said user secret supplied to said communication device by said user.
- 10. The method of claim 9, wherein said at least one group secret comprises a plurality of group secrets.
- 11. The method of claim 9, wherein said user secret includes at least a user ID and password combination and said at least one group secret includes at least one group ID and password combination.
- 12. The method of claim 9, wherein a first of said at least one group secret is used to encrypt a group traffic key, said method further comprising at least the step of:
extracting said first group secret from said decrypted user group record; and decrypting said group traffic key at said communication device using said extracted first group secret.
- 13. A method for distributing group secrets in a communication system, said method comprising the steps of:
storing an encrypted user group record associated with a user, said encrypted user group record including at least one group secret, said user group record encrypted using a user secret known to said user; and distributing said encrypted user group record to a communication device associated with said user.
- 14. The method of claim 13, wherein said distributing step comprises at least the steps of:
receiving said user secret from said communication device; and passing said encrypted user group record to said communication device responsive to receipt of said user secret from said communication device.
- 15. The method of claim 13, wherein said distributing step comprises at least the steps of:
monitoring when said user accesses the communication system, said user accessing the communication system by entering said user secret into said communication device, said communication device passing said user secret to the communication system; passing said encrypted user group record to said communication device when said encrypted user group record is updated and said user is accessing the communication system; and passing said encrypted user group record to said communication device when said user accesses the communication system if the user was not accessing the communication system when said encrypted user group record was updated.
- 16. A method for distributing group secrets, said method comprising the steps of:
receiving a user secret at a communication device from a user; accessing a communication system with said communication device using said user secret; receiving from said communication system an encrypted user group record including at least one group secret at said communication device, said encrypted user group record encrypted using said user secret.
- 17. The method of claim 16, further comprising at least the steps of:
decrypting said encrypted user group record using said user secret; and extracting a first of said at least one group secret.
- 18. An encrypted communication system comprising:
an administrator for encrypting a user group record using a user secret associated with a user, said user group record including at least one group secret, each of said at least one group secret associated with said user; a distribution facility for storing and distributing said encrypted user group record; and at least one device for receiving said encrypted user group record from said distribution system, said at least one device configured to decrypt said encrypted user group record using said user secret.
- 19. The system of claim 18, wherein the encrypted communication system is a trunked radio communication system.
- 20. The system of claim 18, wherein said at least one device is a mobile radio.
- 21. A method for distributing group secrets in a communication system having a plurality of groups, each of said plurality of groups having a plurality of users, some users belonging to multiple groups, wherein each of said users has a unique user secret, said method comprising the steps of:
generating a plurality of user group records, each of said user group records corresponding to a different one of said plurality of users, each of said user group records having one or more group secrets; encrypting each of said plurality of user group records with the user secret of the corresponding user; and distributing each of said plurality of encrypted user group records to communication devices associated with the user associated with the user group record for decryption using the user's user secret.
- 22. The method of claim 21, wherein said plurality of user group records are encrypted at an administrator.
- 23. The method of claim 21, further comprising at least the step of:
storing said plurality of encrypted user group records at a distribution facility prior to said distributing step.
- 24. The method of claim 21, wherein each of said user group records contain a group secret for each group to which said corresponding user belongs.
- 25. The method of claim 21, further comprising at least the steps of:
receiving each of said plurality of encrypted user group records at said communication devices associated with the user associated with the user group record; and decrypting said encrypted user group records at said communication devices using the user's user secret to obtain said one or more group secrets, said user secrets supplied to said communication devices by said users.
RELATED APPLICATIONS
[0001] The present application is related to commonly assigned, co-pending U.S. patent application Ser. No. ______ entitled SECURE ENCRYPTION KEY DISTRIBUTION filed on Aug. 27, 2002 Ser. ______ (Attorney Docket No. 17838).