EP0784392A2

Key distribution for communication network

Abstract

In a cryptosystem, communication terminals and encryptors can be grouped physically and logically. The communication mode can be switched by the encryptor between ciphertext communication and plaintext communication. The encryptor includes the session key memorizing unit for memorizing the session key and the mode switch for switching the communication mode between ciphertext communication and plaintext communication. The key manager distributes the session key generated by the session key generating unit and the valid/invalid information set by the valid/invalid setting unit to each encryptor. The valid/invalid judging unit judges whether the communication data should be sent in ciphertext or plaintext using the mode switch and the valid/invalid information.

EP0784392A2, drawing sheet 1
Sheet 1 of 38

Term

Term ended

Projected expiry passed 8 January 2017, 9.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

13 claims: 6 independent, 7 dependent

  1. 1
    A cryptosystem comprising:a plurality of groups of communication terminals (20 - 29, 2a - 2m);a plurality of encryptors (41, 41a, 42a, 42b, 43 - 46, 49, 51 - 54, 81, 81a, 81b, 82, 82a, 82b, 83 - 88, 501 - 503), each of which corresponds to at least one of communication terminals, and each of which comprises: (a) a session key memorizing unit (711, 721) for memorizing at least one session key for encrypting/decrypting communication data sent/received by the communication terminal which belongs to each of the plurality of groups;(b) a cipher processing unit (413, 423) for encrypting/decrypting the communication data using the session key;and (c) a data sending/receiving unit (414, 424) for sending/receiving the communication data processed by the cipher processing unit.
  2. 7
    The cryptosystem of any one of claims 1 - 6, wherein the encryptor includes:(a) an encryption condition memorizing unit (811, 821) for memorizing an encryption condition for encrypting the communication data;and (b) a condition judging unit (812, 822) for judging the communication data is to be encrypted/decrypted based on the encryption condition.
  3. 10
    The cryptosystem of any one of claims 7 - 9, wherein the encryption condition includes at least one special pass condition for indicating the encryption condition for a special communication data, and a basic pass condition for all communication data except the special communication data matching the special pass condition.
  4. 11
    The cryptosystem of any one of claims 7 - 10, wherein the encryption condition is set based on one of an application program which processes the communication data, a communicating direction, and at least one communication terminal of a communicating partner.
  5. 12
    The cryptosystem of any one of claims 7 - 11,    where in the encryptor memorizes the plurality of session keys in the session key memorizing unit, and    wherein the encryption condition indicates which session key to be used.
  6. 13
    The cryptosystem of any one of claims 10 - 12, wherein the encryptor includes:(a) at least one port for connecting one of the communication terminals or the key manager;(b) a port condition memorizing unit for memorizing the basic pass condition and the special pass condition as a port condition for each port.