EP0809379B1

Authentication apparatus according to the challenge-response principle

Abstract

This record has no abstract on file.

EP0809379B1, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Expired 22 May 2017, 9.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 1 independent, 18 dependent

  1. 1
    An encryption apparatus for devices which perform challenge/response type authentication with a device in communication, distribute a data transfer key and use the data transfer key to perform encrypted communication, the encryption apparatus comprising:first random number generation means (60) for generating first random number for distributing the data transfer key;first random number storage means (62) for storing the generated first random number;second random number generation means (101) for generating a second random number to be used for challenge data that is to be transmitted to the device in communication;second random number storage means (102) for storing the generated second random number;first transmission means for transmitting combined data obtained by combining the generated first random number and second random number to the device in communication, wherein the device in communication is another device in current encrypted communication;authentication means (64,66) for judging whether response data returned from the device in communication in response to the challenge data, and the second random number stored in the second random number storage means match, and in case of a match, for authenticating the device in communication as a legitimate device;data transfer key generation means (59) for generating the data transfer key from at lest the first random number stored by the first random number storage means, transfer data encryption means (90,64,66,67) for encrypting the transfer data to be transferred in the encrypted communication through use of the data transfer key, wherein the first random number generation means, the first random number storage means, the data transfer key generation means, and the transfer data encryption means are implemented through one single-chip IC, and wherein the first random number storage means stores the first random number in an area tamper-proof from outside the single-chip IC.
  2. 3
    The encryption apparatus of Claim 2, wherein the second random number generation means and the authentication means are implemented by circuits provided outside the IC
  3. 4
    The encryption apparatus of Claim 3, further comprising:a decryption means for decrypting encrypted combined data sent from the device in communication;a separation means for separating the decrypted combined data into a first separated data which corresponds to response data and a remaining second separated data;and second transmission means for transmitting the first separated data to the device in communication, wherein the first encryption means combines first random number with the second random number, and encrypts the resulting combined data, and the data transfer key generation means generates the data transfer key by combining the first random number with the second separated data, and the decryption means and the separation means are implemented through circuits inside the IC.
  4. 5
    The encryption apparatus of Claim 4, wherein an encryption algorithm used by the transfer data encryption means is identical to an algorithm used by at least one of the first encryption means and the decryption means.
  5. 6
    The encryption apparatus of Claim 4, wherein the encryption algorithm of the transfer data encryption means differs from and is simpler than an algorithm used by either of the encryption and the decryption means.
  6. 8
    The encryption apparatus of Claim 7, wherein transfer data encryption means conducts encryption using exclusive OR on the blocks and data transfer key.
  7. 9
    The encryption apparatus of Claim 8, wherein the encryption performed by the first encryption means and the encryption performed by the second encryption means use the same conversion algorithm.
  8. 10
    The encryption apparatus of Claim 9, wherein the first encryption means and the decryption means decrypt and encrypt using key data stored in advance inside the IC, and, wherein one part of the key data is stored in a mask ROM area inside the IC, and the other part is stored in a programmable ROM area inside the IC.
  9. 11
    The encryption apparatus of Claim 3 further comprising:second transmission means for transmitting the second random number to the device in communication as challenge data;decryption means for decrypting encrypted combined data sent from the device in communication;and separation means for separating decrypted combined data into a first separated data corresponding to the response data, and a remaining second separated data, wherein the authentication means performs the judgement and authentication with the first separated data as the response data sent back from the device in communication, wherein the first encryption means combines the challenge data sent from the device in communication with the first random number, and encrypts the resulting combined data, and wherein the data transfer key generator generates the data transfer key by combining the first random number with the second separated data, and the decryption means and the separation means are implemented by circuits inside the IC.
  10. 13
    The encryption apparatus of Claim 11, wherein the encryption algorithm of the transfer data encryption means differs from and is simpler than an algorithm used by either of the encryption and the decryption means.
  11. 15
    The encryption apparatus of Claim 14, wherein transfer data encryption means conducts encryption using exclusive OR on the blocks and data transfer key.
  12. 16
    The encryption apparatus of Claim 15, wherein the encryption performed by the first encryption means and the encryption performed by the second encryption means use the same conversion algorithm.