EP1557973A1

Communication apparatus, digital signature issuance method and apparatus, and digital signature transmission method

Abstract

An initiator shares y_ir with a responder, calculates HASH_I on the basis of y_ir, and sends HASH_I to an IKE proxy server. The initiator receives a digital signature SIG_S generated for HASH_I and the address of the initiator from the IKE proxy server and sends the digital signature SIG_S to the responder.

EP1557973A1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Projected expiry passed 20 January 2025, 1.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

15 claims: 7 independent, 8 dependent

  1. 1
    A communication apparatus comprising    generation means (303) for generating data, characterized by    communication means (301) for sending the generated data to a digital signature issuance apparatus,    wherein said communication means receives a digital signature issued by the digital signature issuance apparatus for the generated data and an address used by said communication means and sends the issued digital signature to a communication partner.
  2. 3
    A digital signature issuance method comprising    a reception step (S123, S623) of receiving data from a second apparatus which executes cryptographic communication with a first apparatus, characterized by    a generation step (S111, S611) of generating, using a private key, a digital signature for the received data and an address used by the second apparatus;and    a transmission step (S112, S612) of sending a certificate of a public key corresponding to the private key and the generated digital signature to the second apparatus.
  3. 9
    A digital signature issuance apparatus which issues a digital signature to a second apparatus that executes cryptographic communication with a first apparatus, comprising    communication means (302) for communicating with the second apparatus, characterized by    generation means (303) for generating a digital signature for data received from the second apparatus and an address used by the second apparatus, using a private key,    wherein said communication means sends a certificate of a public key corresponding to the private key, and the generated digital signature to the second apparatus.
  4. 10
    A transmission method for a communication apparatus to send a digital signature to a communication partner, comprising    a calculation step (S131, S631) of sharing secret data with the communication partner and calculating a hash value on the basis of the secret data, characterized by    a hash value transmission step (S110, S610) of sending the hash value to a digital signature issuance apparatus;a reception step (S112, S612) of receiving a digital signature generated for the hash value and an address of the communication apparatus from the digital signature issuance apparatus;and    a digital signature transmission step (S113, S613) of sending the digital signature to the communication partner.
  5. 11
    A public-key certificate which includes, as contents of the certificate, an IP address used by an apparatus having a public key and private key, and the public key, further including information defining that the apparatus is a signature generation apparatus in a digital signature issuance method defined in claim 3.
  6. 12
    A digital signature issuance program comprising    a reception step (S123, S623) of receiving data from a second apparatus which executes cryptographic communication with a first apparatus, characterized by    a generation step (S111, S611) of generating, using a private key, a digital signature for the received data and an address used by the second apparatus;and    a transmission step (S112, S612) of sending a certificate of a public key corresponding to the private key and the generated digital signature to the second apparatus.
  7. 13
    A transmission program for a communication apparatus to send a digital signature of a communication partner, comprising    a calculation step (S131, S631) of sharing secret data with the communication partner and calculating a hash value on the basis of the secret data, characterized by    a hash value transmission step (S110, S610) of sending the hash value to a digital signature issuance apparatus;a reception step (S112, S612) of receiving a digital signature generated for the hash value and an address of the communication apparatus from the digital signature issuance apparatus;and    a digital signature transmission step (S113, S613) of sending the digital signature to the communication partner.