Group key method, device therefor and recording medium recorded with group key program
Abstract
[Task] Group members record group key methods, devices and group key programs that can decrypt previously encrypted information and decrypt / encrypt lower class group information simply by holding the latest group key. Provide a recording medium.
Solution.The group key generation unit 11 of the group key generation organization 1 generates a group key, and the generated group key is transmitted from the group key transmission unit 13 to each user terminal 3, and each user terminal 3 has a group key reception unit 31. The latest group key GK received atk Using this latest group key, the encryption unit 35 encrypts the shared information of the group, and the decryption unit 37 decrypts the shared information encrypted with the group key with the group key. Also, the user's latest group key GKk Using the group key derived by the group key derivation unit 33 using the one-way function from, the decryption unit 37 decrypts the shared information encrypted with the past group key.

Term
Term ended
Projected expiry passed 18 February 2019, 7.6 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
27 claims: 21 independent, 6 dependent
- 1【特許請求の範囲】 【請求項1】 複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するグループ鍵方法であって、 グループ鍵は、共通鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数fを用いて作成されるn個の各値t n =f(S),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )から導出される鍵(GK n ,...,GK k+1 ,GK k ,...,GK 1 )であり、 該グループ鍵を更新する度に、鍵(GK 1 ,...,GK k+1 ,GK k ,...,GK n )の順に利用し、 グループ鍵GK k の更新時には、新たなグループ鍵GK k+1 を生成し、 利用者は、更新された最新のグループ鍵GK k のみを保持し、この最新のグループ鍵を用いて、グループの共有情報を暗号化し、 グループ鍵で暗号化された共有情報をグループ鍵で復号化し、 過去のグループ鍵で暗号化された共有情報は、利用者自身が保持する最新のグループ鍵GK k から一方向性関数を用いて導出したグループ鍵を用いて復号化することを特徴とするグループ鍵方法。
- 2【請求項2】 複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するグループ鍵方法であって、 グループ鍵は、公開鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数fを用いて作成されるn個の各値t n =f(S),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )から導出される秘密鍵(SGK n ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK n ,...,PGK k+1 ,PGK k ,...,PGK 1 )のペアであり、 該グループ鍵を更新する度に、鍵(SGK k ,PGK 1 ),...,(SGK k+1 ,PGK k+1 ),(SGK k ,PGK k ),...,(SGK n ,PGK n )の順に利用し、 グループ鍵(SGK k ,PGK k )の更新時には、新たなグループ鍵(SGK k+1 ,PGK k+1 )を生成し、 利用者は、更新された最新のグループ鍵(SGK k ,PGK k )のみを保持し、この最新のグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、 グループ鍵の公開鍵PGK k で暗号化された共有情報をグループ鍵の秘密鍵SGK k で復号化し、 過去のグループ鍵で暗号化された共有情報は、最新のグループ鍵の秘密鍵SGK k から一方向性関数を用いて導出した秘密鍵を用いて復号化することを特徴とするグループ鍵方法。
- 3【請求項3】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵方法であって、 グループ鍵は、共通鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数gを用いて作成されるm個の各値y m =g(S),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される鍵(GK m ,...,GK k+1 ,GK k ,...,GK 1 )であり、 階級毎に上位から各階級のグループ鍵として、(GK 1 ,...,GK k+1 ,GK k ,...,GK m )の順に利用者に割り当て、 利用者は、割り当てられた最新のグループ鍵GK k のみを保持し、このグループ鍵を用いて、グループの共有情報を暗号化するとともに自身の階級のグループ鍵で暗号化された共有情報を復号化し、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するには、利用者自身が自身のグループ鍵GK k から一方向性関数を用いて導出された鍵を用いることを特徴とするグループ鍵方法。
- 4【請求項4】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵方法であって、 グループ鍵は、公開鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数gを用いて作成されるm個の各値y m =g(S),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される秘密鍵(SGK m ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK m ,...,PGK k+1 ,PGK k ,...,PGK 1 )であり、 階級毎に上位から各階級のグループ鍵として、(SGK 1 ,PGK 1 ),...,(SGK k+1 ,PGK k+1 ),(SGK k ,PGK k ),...,(SGK m ,PGK m )のペアを順に利用者に割り当て、 利用者は、割り当てられたグループ鍵(SGK k ,PGK k )のみを保持し、このグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、秘密鍵SGK k を用いて、自身の階級のグループ鍵の公開鍵PGK k で暗号化された共有情報を復号化し、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するには、利用者自身が自身の秘密鍵SGK k から一方向性関数を用いて導出された鍵を用いることを特徴とするグループ鍵方法。
- 5【請求項5】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵方法であって、 グループ鍵は、共通鍵暗号方式の鍵であって、秘密情報S1から公開された一方向性関数fを用いて作成されるn個の各値t n =f(S1),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )および秘密情報S2から公開された一方向性関数gを用いて作成されるm個の各値y m =g(S2),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される鍵(GK r ,...,GK k+1 ,GK k ,...,GK 1 )であり、 グループ鍵GK k の更新時には、新たなグループ鍵GK k+1 を生成し、 利用者は、更新された最新のグループ鍵GK k のみを保持し、この最新のグループ鍵を用いて、グループの共有情報を暗号化するとともに自身の階級のグループ鍵で暗号化された共有情報を復号化し、 過去のグループ鍵で暗号化された共有情報は、利用者自身が保持する最新のグループ鍵GK k から一方向性関数fを用いて導出したグループ鍵を用いて復号化され、 自身より下位の階級のグループ鍵で暗号化された情報は、利用者自身が自身のグループ鍵から一方向性関数gで導出した鍵を用いて復号化されることを特徴とするグループ鍵方法。
- 6【請求項6】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵方法であって、 グループ鍵は、公開鍵暗号方式の鍵であって、秘密情報S1から公開された一方向性関数fを用いて作成されるn個の各値t n =f(S1),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )および秘密情報S2から公開された一方向性関数gを用いて作成されるm個の各値y m =g(S2),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される秘密鍵(SGK r ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK r ,...,PGK k+1 ,PGK k ,...,PGK 1 )のペアであり、 グループ鍵(SGK k ,PGK k )の更新時には、新たなグループ鍵(SGK k+1 ,PGK k+1 )を生成し、 利用者は、更新された最新のグループ鍵(SGK k ,PGK k )のみを保持し、この最新のグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、 グループ鍵の公開鍵PGK k で暗号化された共有情報をグループ鍵の秘密鍵SGK k で復号化し、 過去のグループ鍵で暗号化された共有情報は、最新のグループ鍵の秘密鍵SGK k から一方向性関数fを用いて導出した秘密鍵を用いて復号化し、 自身より下位の階級のグループ鍵で暗号化された情報は、利用者自身が自身のグループ鍵から一方向性関数gで導出した秘密鍵を用いて復号化されることを特徴とするグループ鍵方法。
- 7【請求項7】 前記グループ鍵は、階層組織を表す公開情報Y 1 ,Y 2 ,...,Y m を用いて、前記一方向性関数gで作成されるm個の各値y m =g(S∥Y m ),...,y k+1 =g(y′ k+1 ∥Y k+1 ),y k =g(y′ k ∥Y k ),...,y 1 =g(y′ 1 ∥Y 1 )から導出され、ここでy′ k はy k の上位階層の値であることを特徴とする請求項3乃至6のいずれかに記載のグループ鍵方法。
- 8【請求項8】 共有情報を利用者が生成した任意の鍵で暗号化し、当該鍵をグループ鍵で暗号化したものを添付情報として暗号化された共有情報に添付することを特徴とする請求項1乃至7のいずれかに記載のグループ鍵方法。
- 9【請求項9】 グループ鍵が更新される度に、前記添付情報を最新のグループ鍵で暗号化することを特徴とする請求項8記載のグループ鍵方法。
- 10【請求項10】 複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するグループ鍵装置であって、 共通鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数fを用いて作成されるn個の各値t n =f(S),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )から導出されるグループ鍵(GK n ,...,GK k+1 ,GK k ,...,GK 1 )を生成するグループ鍵生成手段と、 この生成されたグループ鍵を更新する度に、鍵(GK 1 ,...,GK k+1 ,GK k ,...,GK n )の順に利用し、グループ鍵GK k の更新時には、新たなグループ鍵GK k+1 を生成するグループ鍵更新手段と、 利用者端末に設けられ、更新された最新のグループ鍵GK k のみを利用者自身のグループ鍵として保持するグループ鍵保持手段と、 このグループ鍵保持手段に保持された最新のグループ鍵を用いて、グループの共有情報を暗号化するとともに、グループ鍵で暗号化された共有情報をグループ鍵で復号化する暗号化/復号化手段と、 過去のグループ鍵で暗号化された共有情報を復号化するためのグループ鍵を前記グループ鍵保持手段に保持されている利用者自身の最新のグループ鍵GK k から一方向性関数を用いて導出する過去情報用グループ鍵導出手段とを有することを特徴とするグループ鍵装置。
- 11【請求項11】 複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するグループ鍵装置であって、 公開鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数fを用いて作成されるn個の各値t n =f(S),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )から導出される秘密鍵(SGK n ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK n ,...,PGK k+1 ,PGK k ,...,PGK 1 )のペアを生成するグループ鍵用秘密鍵/公開鍵生成手段と、 前記グループ鍵を更新する度に、鍵(SGK 1 ,PGK 1 ),...,(SGK k+ 1 ,PGK k+1 ),(SGK k ,PGK k ),...,(SGK n ,PGK n )の順に利用し、グループ鍵(SGK k ,PGK k )の更新時には、新たなグループ鍵(SGK k+1 ,PGK k+1 )を生成するグループ鍵更新手段と、 利用者端末に設けられ、更新された最新のグループ鍵(SGK k ,PGK k )のみを保持するグループ鍵保持手段と、 このグループ鍵保持手段に保持された最新のグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化するとともに、グループ鍵の公開鍵PGK k で暗号化された共有情報をグループ鍵の秘密鍵SGK k で復号化する暗号化/復号化手段と、 過去のグループ鍵で暗号化された共有情報を復号化するためのグループ鍵の秘密鍵を前記グループ鍵保持手段で保持されている最新のグループ鍵の秘密鍵SGK k から一方向性関数を用いて導出する過去情報用グループ鍵導出手段とを有することを特徴とするグループ鍵装置。
- 12【請求項12】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵装置であって、 共通鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数gを用いて作成されるm個の各値y m =g(S),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される鍵(GK m ,...,GK k+1 ,GK k ,...,GK 1 )を生成するグループ鍵生成手段と、 階級毎に上位から各階級のグループ鍵として、(GK 1 ,...,GK k+1 ,GK k ,...,GK m )の順に利用者に割り当てるグループ鍵割当手段と、 利用者端末に設けられ、利用者に割り当てられた最新のグループ鍵GK k のみを保持するグループ鍵保持手段と、 このグループ鍵保持手段に保持されたグループ鍵を用いて、グループの共有情報を暗号化するとともに自身の階級のグループ鍵で暗号化された共有情報を復号化する暗号化/復号化手段と、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するための鍵を前記グループ鍵保持手段に保持されている利用者自身のグループ鍵GK k から一方向性関数を用いて導出する下位階級情報用鍵導出手段とを有することを特徴とするグループ鍵装置。
- 13【請求項13】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵装置であって、 公開鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数gを用いて作成されるm個の各値y m =g(S),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される秘密鍵(SGK m ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK m ,...,PGK k+1 ,PGK k ,...,PGK 1 )を生成するグループ鍵用秘密鍵/公開鍵生成手段と、 階級毎に上位から各階級のグループ鍵として、(SGK 1 ,PGK 1 ),...,(SGK k+1 ,PGK k+1 ),(SGK k ,PGK k ),...,(SGK m ,PGK m )のペアを順に利用者に割り当てるグループ鍵割当手段と、 利用者端末に設けられ、利用者に割り当てられたグループ鍵(SGK k ,PGK k )のみを保持するグループ鍵保持手段と、 このグループ鍵保持手段に保持されたグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、秘密鍵SGK k を用いて、自身の階級のグループ鍵の公開鍵PGK k で暗号化された共有情報を復号化する暗号化/復号化手段と、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するための鍵を前記グループ鍵保持手段に保持された利用者自身の秘密鍵SGK k から一方向性関数を用いて導出する下位階級情報用鍵導出手段とを有することを特徴とするグループ鍵装置。
- 14【請求項14】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵装置であって、 共通鍵暗号方式の鍵であって、秘密情報S1から公開された一方向性関数fを用いて作成されるn個の各値t n =f(S1),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )および秘密情報S2から公開された一方向性関数gを用いて作成されるm個の各値y m =g(S2),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出されるグループ鍵(GK r ,...,GK k+1 ,GK k ,...,GK 1 )を生成し、グループ鍵GK k の更新時には、新たなグループ鍵GK k+1 を生成するグループ鍵生成手段と、 利用者端末に設けられ、更新された最新のグループ鍵GK k のみを利用者自身のグループ鍵として保持するグループ鍵保持手段と、 このグループ鍵保持手段に保持されている最新のグループ鍵を用いて、グループの共有情報を暗号化するとともに自身の階級のグループ鍵で暗号化された共有情報を復号化する暗号化/復号化手段と、 過去のグループ鍵で暗号化された共有情報を復号化するためのグループ鍵を前記グループ鍵保持手段に保持されている利用者自身の最新のグループ鍵GK k から一方向性関数fを用いて導出する過去情報用グループ鍵導出手段と、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するための鍵を前記グループ鍵保持手段に保持されている利用者自身のグループ鍵から一方向性関数gで導出する下位階級情報用グループ鍵導出手段とを有することを特徴とするグループ鍵装置。
- 15【請求項15】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で暗号して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵装置であって、 公開鍵暗号方式の鍵であって、秘密情報S1から公開された一方向性関数fを用いて作成されるn個の各値t n =f(S1),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )および秘密情報S2から公開された一方向性関数gを用いて作成されるm個の各値y m =g(S2),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される秘密鍵(SGK r ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK r ,...,PGK k+1 ,PGK k ,...,PGK 1 )のペアを生成し、グループ鍵(SGK k ,PGK k )の更新時には、新たなグループ鍵(SGK k+1 ,PGK k+ 1 )を生成するグループ鍵用秘密鍵/公開鍵生成手段と、 利用者端末に設けられ、更新された最新のグループ鍵(SGK k ,PGK k )のみを利用者自身のグループ鍵として保持するグループ鍵保持手段と、 このグループ鍵保持手段に保持された最新のグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、グループ鍵の公開鍵PGK k で暗号化された共有情報をグループ鍵の秘密鍵SGK k で復号化する暗号化/復号化手段と、 過去のグループ鍵で暗号化された共有情報を復号化するための秘密鍵を前記グループ鍵保持手段に保持されている利用者自身の最新のグループ鍵の秘密鍵SGK k から一方向性関数fを用いて導出する過去情報用秘密鍵導出手段と、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するための秘密鍵を前記グループ鍵保持手段に保持されている利用者自身のグループ鍵から一方向性関数gで導出する下位階級情報用秘密鍵導出手段とを有することを特徴とするグループ鍵装置。
- 16【請求項16】 前記グループ鍵は、階層組織を表す公開情報Y 1 ,Y 2 ,...,Y m を用いて、前記一方向性関数gで作成されるm個の各値y m =g(S∥Y m ),...,y k+1 =g(y′ k+1 ∥Y k+1 ),y k =g(y′ k ∥Y k ),...,y 1 =g(y′ 1 ∥Y 1 )から導出され、ここでy′ k はy k の上位階層の値であることを特徴とする請求項12乃至15のいずれかに記載のグループ鍵装置。
- 17【請求項17】 共有情報を利用者が生成した任意の鍵で暗号化し、当該鍵をグループ鍵で暗号化したものを添付情報として暗号化された共有情報に添付することを特徴とする請求項10乃至16のいずれかに記載のグループ鍵装置。
- 18【請求項18】 グループ鍵が更新される度に、前記添付情報を最新のグループ鍵で暗号化することを特徴とする請求項17記載のグループ鍵装置。
- 19【請求項19】 複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するグループ鍵プログラムを記録した記録媒体であって、 グループ鍵は、共通鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数fを用いて作成されるn個の各値t n =f(S),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )から導出される鍵(GK n ,...,GK k+1 ,GK k ,...,GK 1 )であり、 該グループ鍵を更新する度に、鍵(GK 1 ,...,GK k+1 ,GK k ,...,GK n )の順に利用し、 グループ鍵GK k の更新時には、新たなグループ鍵GK k+1 を生成し、 利用者は、更新された最新のグループ鍵GK k のみを保持し、この最新のグループ鍵を用いて、グループの共有情報を暗号化し、 グループ鍵で暗号化された共有情報をグループ鍵で復号化し、 過去のグループ鍵で暗号化された共有情報は、利用者自身が保持する最新のグループ鍵GK k から一方向性関数を用いて導出したグループ鍵を用いて復号化することを特徴とするグループ鍵プログラムを記録した記録媒体。
- 20【請求項20】 複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するグループ鍵プログラムを記録した記録媒体であって、 グループ鍵は、公開鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数fを用いて作成されるn個の各値t n =f(S),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )から導出される秘密鍵(SGK n ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK n ,...,PGK k+1 ,PGK k ,...,PGK 1 )のペアであり、 該グループ鍵を更新する度に、鍵(SGK 1 ,PGK 1 ),...,(SGK k+1 ,PGK k+1 ),(SGK k ,PGK k ),...,(SGK n ,PGK n )の順に利用し、 グループ鍵(SGK k ,PGK k )の更新時には、新たなグループ鍵(SGK k+1 ,PGK k+1 )を生成し、 利用者は、更新された最新のグループ鍵(SGK k ,PGK k )のみを保持し、この最新のグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、 グループ鍵の公開鍵PGK k で暗号化された共有情報をグループ鍵の秘密鍵SGK k で復号化し、 過去のグループ鍵で暗号化された共有情報は、最新のグループ鍵の秘密鍵SGK k から一方向性関数を用いて導出した秘密鍵を用いて復号化することを特徴とするグループ鍵プログラムを記録した記録媒体。
- 21【請求項21】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵プログラムを記録した記録媒体であって、 グループ鍵は、共通鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数gを用いて作成されるm個の各値y m =g(S),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される鍵(GK m ,...,GK k+1 ,GK k ,...,GK 1 )であり、 階級毎に上位から各階級のグループ鍵として、(GK 1 ,...,GK k+1 ,GK k ,...,GK m )の順に利用者に割り当て、 利用者は、割り当てられた最新のグループ鍵GK k のみを保持し、このグループ鍵を用いて、グループの共有情報を暗号化するとともに自身の階級のグループ鍵で暗号化された共有情報を復号化し、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するには、利用者自身が自身のグループ鍵GK k から一方向性関数を用いて導出された鍵を用いることを特徴とするグループ鍵プログラムを記録した記録媒体。
- 22【請求項22】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵プログラムを記録した記録媒体であって、 グループ鍵は、公開鍵暗号方式の鍵であって、秘密情報Sから公開された一方向性関数gを用いて作成されるm個の各値y m =g(S),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される秘密鍵(SGK m ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK m ,...,PGK k+1 ,PGK k ,...,PGK 1 )であり、 階級毎に上位から各階級のグループ鍵として、(SGK 1 ,PGK 1 ),...,(SGK k+1 ,PGK k+1 ),(SGK k ,PGK k ),...,(SGK m ,PGK m )のペアを順に利用者に割り当て、 利用者は、割り当てられたグループ鍵(SGK k ,PGK k )のみを保持し、このグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、秘密鍵SGK k を用いて、自身の階級のグループ鍵の公開鍵PGK k で暗号化された共有情報を復号化し、 自身より下位の階級のグループ鍵で暗号化された情報を復号化するには、利用者自身が自身の秘密鍵SGK k から一方向性関数を用いて導出された鍵を用いることを特徴とするグループ鍵プログラムを記録した記録媒体。
- 23【請求項23】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵プログラムを記録した記録媒体であって、 グループ鍵は、共通鍵暗号方式の鍵であって、秘密情報S1から公開された一方向性関数fを用いて作成されるn個の各値t n =f(S1),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )および秘密情報S2から公開された一方向性関数gを用いて作成されるm個の各値y m =g(S2),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される鍵(GK r ,...,GK k+1 ,GK k ,...,GK 1 )であり、 グループ鍵GK k の更新時には、新たなグループ鍵GK k+1 を生成し、 利用者は、更新された最新のグループ鍵GK k のみを保持し、この最新のグループ鍵を用いて、グループの共有情報を暗号化するとともに自身の階級のグループ鍵で暗号化された共有情報を復号化し、 過去のグループ鍵で暗号化された共有情報は、利用者自身が保持する最新のグループ鍵GK k から一方向性関数fを用いて導出したグループ鍵を用いて復号化され、 自身より下位の階級のグループ鍵で暗号化された情報は、利用者自身が自身のグループ鍵から一方向性関数gで導出した鍵を用いて復号化されることを特徴とするグループ鍵プログラムを記録した記録媒体。
- 24【請求項24】 複数の階級からなる階層構造を持ち、複数の利用者からなるグループの共有情報をグループ鍵で暗号化してグループで共有し、利用者は暗号化された共有情報をグループ鍵で復号化して利用するとともに、各利用者は自身の階級および自身の階級より下位の階級の情報を暗号化/復号化することができるグループ鍵プログラムを記録した記録媒体であって、 グループ鍵は、公開鍵暗号方式の鍵であって、秘密情報S1から公開された一方向性関数fを用いて作成されるn個の各値t n =f(S1),...,t k+1 =f(t k+2 ),t k =f(t k+1 ),...,t 1 =f(t 2 )および秘密情報S2から公開された一方向性関数gを用いて作成されるm個の各値y m =g(S2),...,y k+1 =g(y k+2 ),y k =g(y k+1 ),...,y 1 =g(y 2 )から導出される秘密鍵(SGK r ,...,SGK k+1 ,SGK k ,...,SGK 1 )および公開鍵(PGK r ,...,PGK k+1 ,PGK k ,...,PGK 1 )のペアであり、 グループ鍵(SGK k ,PGK k )の更新時には、新たなグループ鍵(SGK k+1 ,PGK k+1 )を生成し、 利用者は、更新された最新のグループ鍵(SGK k ,PGK k )のみを保持し、この最新のグループ鍵の公開鍵PGK k を用いて、グループの共有情報を暗号化し、 グループ鍵の公開鍵PGK k で暗号化された共有情報をグループ鍵の秘密鍵SGK k で復号化し、 過去のグループ鍵で暗号化された共有情報は、最新のグループ鍵の秘密鍵SGK k から一方向性関数fを用いて導出した秘密鍵を用いて復号化し、 自身より下位の階級のグループ鍵で暗号化された情報は、利用者自身が自身のグループ鍵から一方向性関数gで導出した秘密鍵を用いて復号化されることを特徴とするグループ鍵プログラムを記録した記録媒体。
- 25【請求項25】 前記グループ鍵は、階層組織を表す公開情報Y 1 ,Y 2 ,...,Y m を用いて、前記一方向性関数gで作成されるm個の各値y m =g(S∥Y m ),...,y k+1 =g(y′ k+1 ∥Y k+1 ),y k =g(y′ k ∥Y k ),...,y 1 =g(y′ 1 ∥Y 1 )から導出され、ここでy′ k はy k の上位階層の値であることを特徴とする請求項21乃至24のいずれかに記載のグループ鍵プログラムを記録した記録媒体。
- 26【請求項26】 共有情報を利用者が生成した任意の鍵で暗号化し、当該鍵をグループ鍵で暗号化したものを添付情報として暗号化された共有情報に添付することを特徴とする請求項19乃至25のいずれかに記載のグループ鍵プログラムを記録した記録媒体。
- 27【請求項27】 グループ鍵が更新される度に、前記添付情報を最新のグループ鍵で暗号化することを特徴とする請求項26記載のグループ鍵プログラムを記録した記録媒体。
Independent claims27
255 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a group key method and device for sharing information by sharing a key for encrypting / decrypting shared information with a group consisting of a plurality of users. The shared information is encrypted with a group key and shared by the group, and the user decrypts the encrypted shared information with the group key and uses the group key method and the recording medium in which the device and the group key program are recorded.
【0002】
[Conventional technology]
Businesses and workflows within a company are often performed by groups of organizations or businesses. For example, the department to which the information belongs, the position, etc. determine whether or not the confidential information can be operated and viewed. To protect such confidential information that is confidential to the group, create a group for each business, department, and job title, assign an encryption key (hereinafter referred to as the group key) to each group, and perform encryption. Is an effective method.
【0003】
Arai et al. Attach a destination list to the shared document of the group, compare this with the attribute information (name, department name, etc.) of the user stored in the IC card, etc., and perform access control for the shared information. We are proposing a method (see Masato Arai, Tadashi Forge, Hiromichi Ito, Toshiyuki Shibata: Group Cryptographic System for Corporate Information, Computer Security 1-3, p.11-16, May 29.1998). The name or department name of the user who can access the shared document is described in the destination list. However, in the workflow, groups can be created for each detailed business other than the department name, and it is generally easy to add / delete groups.
【0004】
In addition, Matsuzaki et al. Have proposed a method for updating the key of a new group on all the remaining terminals except the terminal specified by the center in the mobile communication system (Natsume Matsuzaki, Jun Ansai: For mobile communication). Suitable group key update method (II), suitable group key update method for mobile communication (III), see ISEC 97-73, p.51-62, Mar. 1998).
【0005】
[Problems to be Solved by the Invention]
In the method of Mr. Arai et al. Above, in order to add a new group, the IC card is collected and the attribute information is changed, or the names of the members of the group are listed in the destination list of the shared information of the newly added group. There is a problem that you have to do.
【0006】
Further, when the above-mentioned method of Mr. Matsuzaki et al. Is applied to encryption of shared information in a group, there are the following problems.
【0007】
In the case of the method of paying out the group key for each group, when the member X of the group leaves at a certain time t, the group key GK of that group<sub>old </sub>A new group key GK that member X does not know<sub>new </sub>Need to be updated to. The remaining members of the group are GK<sub>new </sub>And after t, GK<sub>new </sub>Encrypt with. However, to decrypt documents encrypted before time t, GK<sub>old </sub>The remaining members of the group are GK<sub>old </sub>, GK<sub>new </sub>Must be retained. In this way, the number of keys held by the members remaining in the group increases each time the key is updated. In addition, the members who newly joined the group are the latest group key GK<sub>new </sub>Besides the past group key GK<sub>old </sub>There is also the problem of having to obtain it.
【0008】
On the other hand, in a plurality of groups having a hierarchical structure, the group members of the upper class generally have the authority to encrypt / decrypt the information of the lower class group. For example, in the model in which a department manager group, a section manager group, and a section chief group exist in a corporate organization as shown in Fig. 6, the members of the department manager group encrypt / decrypt the information of the department manager group, the section manager group, and the section chief group, and are members of the section manager group. Is generally able to encrypt / decrypt information in the section chief group and the chief group. In the case of the method of paying out the key for each group, there is a problem that the members of each group must hold the group key of the lower class in addition to their own group key.
【0009】
As described above, in the conventional method of issuing a group key for each group, (1) when the group key is updated, the past group key must be retained in addition to the latest group key (2). ) Members who newly join the group must obtain the past group key in addition to the latest group key. (3) Each member of multiple groups with a hierarchical structure has its own group key in addition to its own group key. There is a problem that the lower class group key must also be retained.
【0010】
The present invention has been made in view of the above, and an object of the present invention is to decrypt information encrypted in the past and information of a lower class group only by holding the latest group key. It is an object of the present invention to provide a group key method capable of decryption / encryption and a recording medium on which a device and a group key program are recorded.
【0011】
[Means for solving problems]
In order to achieve the above object, the present invention according to claim 1 encrypts the shared information of a group consisting of a plurality of users with a group key and shares the encrypted shared information with the group key. It is a group key method that is decrypted and used in, and the group key is a key of the common key cryptosystem, and each of n values created by using the unidirectional function f disclosed from the secret information S. t<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2</sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the key (GK)<sub>n </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And every time the group key is updated, the key (GK)<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n </sub>), Group key GK<sub>k</sub>When updating, a new group key GK<sub>k + 1 </sub>The latest group key GK that has been updated by the user<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group, decrypts the shared information encrypted with the group key with the group key, and the shared information encrypted with the past group key , The latest group key GK held by the user himself<sub>k </sub>The gist is to decrypt using the group key derived from the one-way function.
【0012】
In the present invention according to claim 1, the group key is a key of a common key cryptosystem, and n each value t created by using the one-way function f disclosed from the secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the key (GK)<sub>n </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And every time the group key is updated, the key (GK)<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n</sub>), Group key GK<sub>k </sub>New group key GK when updating<sub>k + 1 </sub>Is generated and the user has the latest group key GK<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group, decrypts the shared information encrypted with the group key with the group key, and the shared information encrypted with the past group key The latest group key GK held by the user himself<sub>k </sub>Since the decryption is performed using the group key derived from the one-way function, the user does not have to keep the past group key as in the past, and the newly joined member is also the latest. You only need to get the group key, not the past group key.
【0013】
Here, the group key is, for example, a key for encrypting / decrypting shared information, and is a key shared by a group.
【0014】
Further, in the present invention according to claim 2, the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the user decrypts the encrypted shared information with the group key and uses it. The group key method is a public key cryptosystem key, and each value t of n created by using the unidirectional function f disclosed from the secret information S<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k +</sub><sub>1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the private key (SGK)<sub>n </sub>, ..., SGK<sub>k + 1</sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>n </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And every time the group key is updated, the key (SGK)<sub>1</sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>n </sub>, PGK<sub>n </sub>), And the group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user can update the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k</sub>For shared information decrypted with and encrypted with the past group key, the latest group key private key SGK<sub>k </sub>The gist is to decrypt using the private key derived from the one-way function.
【0015】
In the present invention according to claim 2, the group key is a key of public key cryptography, and each of n values t created by using the one-way function f disclosed from the secret information S.<sub>n</sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the private key (SGK)<sub>n </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>n </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And every time the group key is updated, the key (SGK)<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>n </sub>, PGK<sub>n </sub>), And the group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user is updated with the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret key SGK of the latest group key.<sub>k </sub>Since the decryption is performed using the private key derived from the one-way function, the user does not have to keep the past group key as in the past, and the newly joined member is also the latest. You only need to get the group key, not the past group key.
【0016】
Further, the present invention according to claim 3 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. The group key is a group key method that allows each user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while decrypting and using the shared information with the group key. , A key of the common key encryption method, and each value y of m created by using the unidirectional function g disclosed from the secret information S.<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>m </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1</sub>), And as a group key for each class from the top to each class, (GK<sub>1 </sub>, ..., GK<sub>k +</sub><sub>1 </sub>, GK<sub>k </sub>, ..., GK<sub>m </sub>), And the user is assigned the latest group key GK.<sub>k </sub>Only is retained, and this group key is used to encrypt the shared information of the group, decrypt the shared information encrypted with the group key of its own class, and encrypt it with the group key of the lower class. To decrypt the information, the user himself / herself has his / her own group key GK.<sub>k </sub>The gist is to use the key derived from the one-way function.
【0017】
In the present invention according to claim 3, the group key is a key of the common key cryptosystem in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S. Each value of m that is y<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2</sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>m </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And as a group key for each class from the top to each class, (GK<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>m </sub>), And the user has the latest group key GK.<sub>k </sub>Only retained, the shared information of the group was encrypted using this group key, the shared information encrypted with the group key of its own class was decrypted, and it was encrypted with the group key of the lower class than itself. To decrypt the information, the user himself has his own group key GK<sub>k </sub>Since the key derived from the one-way function is used, the user does not have to keep the past group key as in the past, and the members of each group are lower class in addition to their own group key. There is no need to hold the group key of.
【0018】
The present invention according to claim 4 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users share the encrypted shared information. Is a group key method that allows the user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while decrypting and using the group key, and the group key is the public key. Each of m values y, which is a cryptographic key and is created using the unidirectional function g disclosed by the secret information S.<sub>m</sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>m </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>m </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And as a group key for each class from the top to each class, (SGK<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>m </sub>, PGK<sub>m </sub>) Pairs are assigned to users in order, and the user assigns the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only, the public key PGK for this group key<sub>k </sub>Encrypts the shared information of the group using the private key SGK<sub>k </sub>Use the public key PGK of your class's group key<sub>k </sub>In order to decrypt the shared information encrypted with, and to decrypt the information encrypted with the group key of the lower class than itself, the user himself / herself has his / her own private key SGK.<sub>k </sub>The gist is to use the key derived from the one-way function.
【0019】
In the present invention according to claim 4, the group key is a public key cryptosystem key in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S. Each value of m that is y<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2</sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>m </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>m </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And as a group key for each class from the top to each class, (SGK<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>m </sub>, PGK<sub>m </sub>) Pairs are assigned to users in order, and users are assigned the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only, the public key PGK for this group key<sub>k </sub>Encrypts the shared information of the group using the private key SGK<sub>k </sub>Use the public key PGK of your class's group key<sub>k </sub>In order to decrypt the shared information encrypted with, and to decrypt the information encrypted with the group key of the lower class than itself, the user himself / herself has his / her own private key SGK.<sub>k </sub>Since the key derived from the one-way function is used, the user does not have to keep the past group key as in the past, and the members of each group are lower class in addition to their own group key. There is no need to hold the group key of.
【0020】
Further, the present invention according to claim 5 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. The group key is a group key method that allows each user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while decrypting and using the shared information with the group key. , A common key encryption key, each of n values t created using the unidirectional function f published from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>r </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) And the group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>The latest group key GK that has been updated by the user<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group and decrypt the shared information encrypted with the group key of its own class, and the shared encrypted with the past group key For information, the latest group key GK held by the user himself<sub>k </sub>For information that is decrypted using the group key derived from the one-way function f and encrypted with the group key of a lower class than itself, the user himself / herself is the one-way function from his / her own group key. The gist is that it is decrypted using the key derived in g.
【0021】
In the present invention according to claim 5, the group key is a key of the common key cryptosystem in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S1. Each of n values t<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>r </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) And the group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>Is generated and the user has the latest group key GK<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group and decrypt the shared information encrypted with the group key of its own class, and the shared encrypted with the past group key The information is the latest group key GK held by the user himself.<sub>k </sub>The information decrypted from the group key derived from the unidirectional function f using the group key and encrypted with the group key of the lower class is the user himself / herself using the unidirectional function g from his / her own group key. Since it is decrypted using the derived key, the user does not need to keep the past group key as in the past, and the newly joined member only needs to obtain the latest group key. It is not necessary to obtain the past group key, and the members of each group do not need to hold the group key of the lower class in addition to their own group key.
【0022】
Further, the present invention according to claim 6 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. The group key is a group key method that allows each user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while decrypting and using the shared information with the group key. , Public key Cryptographic key, n each value t created using the unidirectional function f published from secret information S1<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>r </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>r </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Pair and group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user can use the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>For shared information decrypted with and encrypted with the past group key, the private key SGK of the latest group key<sub>k </sub>For information that is decrypted using the private key derived from the one-way function f and encrypted with a group key of a lower class than itself, the user himself / herself is one-way from his / her own group key. The gist is that it is decrypted using the private key derived by the function g.
【0023】
In the present invention according to claim 6, the group key is a key of public key cryptography, and each of n values t created by using the one-way function f disclosed from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1</sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>r </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>r </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k</sub>, ..., PGK<sub>1 </sub>) Pair and group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated, and the user can use the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret key SGK of the latest group key.<sub>k </sub>Decrypted using the private key derived from the unidirectional function f, and the information encrypted with the group key of the lower class than itself is derived by the user himself from his own group key with the unidirectional function g. Since it is decrypted using the private key, the user does not need to keep the past group key as in the past, and new members who join the group only need to obtain the latest group key. It is not necessary to obtain the past group key, and the members of each group do not need to hold the group key of the lower class in addition to their own group key.
【0024】
The present invention according to claim 7 is the invention according to any one of claims 3 to 6, wherein the group key represents a hierarchical organization.<sub>1 </sub>, Y<sub>2 </sub>, ..., Y<sub>m </sub>Each of the m values y created by the one-way function g using<sub>m </sub>= g (STheY<sub>m </sub>), ..., y<sub>k + 1 </sub>= g (y <sub>k + 1 </sub>TheY<sub>k + 1 </sub>), Y<sub>k </sub>= g (y <sub>k </sub>TheY<sub>k </sub>), ..., y<sub>1 </sub>= g (y <sub>1 </sub>TheY<sub>1 </sub>), Where y <sub>k </sub>Is y<sub>k </sub>The gist is that it is a value in the upper hierarchy of.
【0025】
In the present invention according to claim 7, the group key is public information Y representing a hierarchical organization.<sub>1</sub>, Y<sub>2 </sub>, ..., Y<sub>m </sub>Each of m values y created by the one-way function g using<sub>m </sub>= g (STheY<sub>m </sub>), ..., y<sub>k + 1 </sub>= g (y <sub>k + 1 </sub>TheY<sub>k + 1 </sub>), Y<sub>k </sub>= g (y <sub>k </sub>TheY<sub>k </sub>), ..., y<sub>1 </sub>= g (y <sub>1 </sub>TheY<sub>1 </sub>) Derived from.
【0026】
Further, the present invention according to claim 8 is the invention according to any one of claims 1 to 7, wherein the shared information is encrypted with an arbitrary key generated by the user, and the key is encrypted with a group key. The gist is to attach to the encrypted shared information as attached information.
【0027】
In the present invention according to claim 8, the shared information is encrypted with an arbitrary key generated by the user, and the key encrypted with the group key is attached to the encrypted shared information as attached information.
【0028】
Furthermore, the gist of the present invention according to claim 9 is that the attached information is encrypted with the latest group key each time the group key is updated in the invention according to claim 8.
【0029】
In the present invention according to claim 9, the attached information is encrypted with the latest group key each time the group key is updated.
【0030】
The present invention according to claim 10 is a group in which shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the user decrypts the encrypted shared information with a group key and uses it. Each of n values t, which is a key device, a key of a common key cryptosystem, and is created by using a unidirectional function f disclosed from secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the group key (GK)<sub>n </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) Is generated, and the key (GK) is updated every time this generated group key is updated.<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n </sub>), Group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>Group key update means to generate, and the latest group key GK provided and updated on the user terminal<sub>k </sub>The group key holding means that holds only the user's own group key and the latest group key held in this group key holding means are used to encrypt the shared information of the group and are encrypted with the group key. A user whose encryption / decryption means for decrypting shared information with a group key and a group key for decrypting shared information encrypted with a past group key are held in the group key holding means. Own latest group key GK<sub>k </sub>The gist is to have a group key derivation means for past information derived from from using a one-way function.
【0031】
In the present invention according to claim 10, the group key is a key of a common key cryptosystem, and n each value t created by using the one-way function f disclosed from the secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the key (GK)<sub>n </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And every time the group key is updated, the key (GK)<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n</sub>), Group key GK<sub>k </sub>New group key GK when updating<sub>k + 1 </sub>Is generated and the user has the latest group key GK<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group, decrypts the shared information encrypted with the group key with the group key, and the shared information encrypted with the past group key The latest group key GK held by the user himself<sub>k </sub>Since the decryption is performed using the group key derived from the one-way function, the user does not have to keep the past group key as in the past, and the newly joined member is also the latest. You only need to get the group key, not the past group key.
【0032】
Further, in the present invention according to claim 11, the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the user decrypts the encrypted shared information with the group key and uses it. A group key device that is a public key cryptosystem key, and n values t created by using a unidirectional function f disclosed from secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the private key (SGK)<sub>n </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>n </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Private key / public key generation means for generating a pair, and a key (SGK) every time the group key is updated.<sub>k </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1</sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>n </sub>, PGK<sub>n </sub>), And the group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) And the latest group key (SGK) provided on the user terminal and updated.<sub>k </sub>, PGK<sub>k </sub>) Only the group key holding means and the latest group key public key PGK held in this group key holding means<sub>k</sub>Encrypts the shared information of the group and uses the public key PGK of the group key.<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The encryption / decryption means for decrypting with, and the latest group key held by the group key holding means with the private key of the group key for decrypting the shared information encrypted with the past group key. Private key SGK<sub>k </sub>The gist is to have a group key derivation means for past information derived from from using a one-way function.
【0033】
In the present invention according to claim 11, the group key is a key of public key cryptography, and each of n values t created by using the one-way function f disclosed from the secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the private key (SGK)<sub>n </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>n </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And every time the group key is updated, the key (SGK)<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>n </sub>, PGK<sub>n </sub>), And the group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user is updated with the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k</sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret key SGK of the latest group key.<sub>k </sub>Since the decryption is performed using the private key derived from the one-way function, the user does not have to keep the past group key as in the past, and the newly joined member is also the latest. You only need to get the group key, not the past group key.
【0034】
Further, the present invention according to claim 12 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. It is a group key device that can decrypt / decrypt shared information with a group key, and each user can encrypt / decrypt information of his / her own class and classes lower than his / her own class, and is a common key encryption. Each value y of m, which is the key of the method and is created by using the unidirectional function g published from the secret information S.<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2</sub>) Derived from the key (GK)<sub>m </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>As a group key generation means to generate) and as a group key for each class from the top for each class, (GK<sub>1</sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>m </sub>), And the latest group key GK provided on the user terminal and assigned to the user.<sub>k </sub>The group key holding means that holds only and the group key held by this group key holding means are used to encrypt the shared information of the group and decrypt the shared information encrypted by the group key of the own class. The user's own group key GK whose encryption / decryption means and the key for decrypting the information encrypted by the group key of the lower class than itself are held in the group key holding means.<sub>k </sub>The gist is to have a key derivation means for lower class information derived from the above using a one-way function.
【0035】
In the present invention according to claim 12, the group key is a key of the common key cryptosystem in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S. Each value of m that is y<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k +</sub><sub>2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>m </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And as a group key for each class from the top to each class, (GK<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>m </sub>), And the user has the latest group key GK.<sub>k </sub>Only retained, the shared information of the group was encrypted using this group key, the shared information encrypted with the group key of its own class was decrypted, and it was encrypted with the group key of the lower class than itself. To decrypt the information, the user himself has his own group key GK<sub>k </sub>Since the key derived from the one-way function is used, the user does not have to keep the past group key as in the past, and the members of the group are in the lower class in addition to their own group key. There is no need to hold a group key.
【0036】
The present invention according to claim 13 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users share the encrypted shared information. Is a group key device that can encrypt / decrypt information of its own class and classes lower than its own class while decrypting and using it with a group key, and is a key of public key cryptography. And each of m values y created using the unidirectional function g published from the secret information S<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>m </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>m </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Is generated as a private key / public key generation means for the group key, and as a group key for each class from the upper level to each class, (SGK<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>m </sub>, PGK<sub>m </sub>) Pairs are assigned to users in order, and a group key (SGK) provided on the user terminal and assigned to the user.<sub>k </sub>, PGK<sub>k </sub>) Only the group key holding means and the public key PGK of the group key held by this group key holding means<sub>k </sub>Encrypts the shared information of the group using the private key SGK<sub>k </sub>Use the public key PGK of your class's group key<sub>k </sub>The group key holding means holds an encryption / decryption means for decrypting the shared information encrypted in the above and a key for decrypting the information encrypted with the group key of the lower class than itself. The user himself is the private key SGK<sub>k </sub>The gist is to have a key derivation means for lower class information derived from the above using a one-way function.
【0037】
In the present invention according to claim 13, the group key is a key of public key cryptography in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S. Each value of m that is y<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k +</sub><sub>2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>m </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>m </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And as a group key for each class from the top to each class, (SGK<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>m </sub>, PGK<sub>m </sub>) Pairs are assigned to the users in order, and the users are assigned the group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only, the public key PGK for this group key<sub>k </sub>Encrypts the shared information of the group using the private key SGK<sub>k </sub>Use the public key PGK of your class's group key<sub>k </sub>In order to decrypt the shared information encrypted with, and to decrypt the information encrypted with the group key of the lower class than itself, the user himself / herself has his / her own private key SGK.<sub>k </sub>Since the key derived from the one-way function is used, the user does not have to keep the past group key as in the past, and the members of each group are lower class in addition to their own group key. There is no need to hold the group key of.
【0038】
Further, the present invention according to claim 14 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. It is a group key device that can decrypt / decrypt shared information with a group key, and each user can encrypt / decrypt information of his / her own class and classes lower than his / her own class, and is a common key encryption. Each of n values t, which is the key of the method and is created using the unidirectional function f published from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the group key (GK)<sub>r </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) And the group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>The latest group key GK provided and updated on the user terminal and the group key generation means to generate<sub>k </sub>The group key holding means that holds only as the user's own group key and the latest group key held in this group key holding means are used to encrypt the shared information of the group and the group key of the own class. Utilization in which the encryption / decryption means for decrypting the shared information encrypted in the above and the group key for decrypting the shared information encrypted with the past group key are held in the group key holding means. Person's own latest group key GK<sub>k </sub>The group key derivation means for past information derived from the unidirectional function f and the key for decrypting the information encrypted by the group key of the lower class than itself are held in the group key holding means. The gist is that it has a group key derivation means for lower class information that is derived from the user's own group key with a unidirectional function g.
【0039】
In the present invention according to claim 14, the group key is a key of the common key cryptosystem in a plurality of groups having a hierarchical structure, and is created by using the one-way function f disclosed from the secret information S1. Each of n values t<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>r </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) And the group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>Is generated and the user has the latest group key GK<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group and decrypt the shared information encrypted with the group key of its own class, and the shared encrypted with the past group key The information is the latest group key GK held by the user himself.<sub>k </sub>The information decrypted from the group key derived from the unidirectional function f using the group key and encrypted with the group key of the lower class is the user himself / herself using the unidirectional function g from his / her own group key. Since it is decrypted using the derived key, the user does not need to keep the past group key as in the past, and the newly joined member only needs to obtain the latest group key. It is not necessary to obtain the past group key, and the members of each group do not need to hold the group key of the lower class in addition to their own group key.
【0040】
The present invention according to claim 15 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users share the encrypted shared information. Is a group key device that can encrypt / decrypt information of its own class and classes lower than its own class while decrypting and using it with a group key, and is a public key cryptosystem. Each of n values t that is a key and is created using the unidirectional function f exposed from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>r </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>r </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Pairs and group keys (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated as a private key / public key generation means for the group key, and the latest group key (SGK) provided and updated on the user terminal.<sub>k</sub>, PGK<sub>k </sub>A group key holding means that holds only) as the user's own group key, and the public key PGK of the latest group key held by this group key holding means.<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The latest group key of the user whose own encryption / decryption means and the private key for decrypting the shared information encrypted by the past group key are held in the group key holding means. Private key SGK<sub>k </sub>The group key holding means holds a secret key derivation means for past information derived from the unidirectional function f and a secret key for decrypting information encrypted with a group key of a lower class than itself. The gist is that it has a secret key derivation means for lower class information that is derived from the user's own group key by a unidirectional function g.
【0041】
In the present invention according to claim 15, the group key is a key of public key cryptography, and each of n values t created by using the one-way function f disclosed from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1</sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k +</sub><sub>1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>r </sub>, ..., SGK<sub>k + 1</sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>r </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Pair and group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated, and the user can use the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret key SGK of the latest group key.<sub>k </sub>Decrypted using the private key derived from the unidirectional function f, and the information encrypted with the group key of the lower class than itself is derived by the user himself from his own group key with the unidirectional function g. Since it is decrypted using the private key, the user does not need to keep the past group key as in the past, and new members who join the group only need to obtain the latest group key. It is not necessary to obtain the past group key, and the members of each group do not need to hold the group key of the lower class in addition to their own group key.
【0042】
The present invention according to claim 16 is the invention according to any one of claims 12 to 15, wherein the group key represents a hierarchical organization.<sub>1 </sub>, Y<sub>2 </sub>, ..., Y<sub>m </sub>Each of the m values y created by the one-way function g using<sub>m </sub>= g (STheY<sub>m </sub>), ..., y<sub>k + 1 </sub>= g (y <sub>k + 1 </sub>TheY<sub>k + 1 </sub>), Y<sub>k </sub>= g (y <sub>k </sub>TheY<sub>k </sub>), ..., y<sub>1 </sub>= g (y <sub>1 </sub>TheY<sub>1 </sub>), Where y <sub>k </sub>Is y<sub>k </sub>The gist is that it is a value in the upper hierarchy of.
【0043】
In the present invention according to claim 16, the group key is public information Y representing a hierarchical organization.<sub>1 </sub>, Y<sub>2 </sub>, ..., Y<sub>m </sub>Each of m values y created by the one-way function g using<sub>m </sub>= g (STheY<sub>m </sub>), ..., y<sub>k + 1 </sub>= g (y <sub>k + 1 </sub>TheY<sub>k + 1 </sub>), Y<sub>k </sub>= g (y <sub>k </sub>TheY<sub>k</sub>), ..., y<sub>1 </sub>= g (y <sub>1 </sub>TheY<sub>1 </sub>) Derived from.
【0044】
Further, the present invention according to claim 17 is the invention according to any one of claims 10 to 16, wherein the shared information is encrypted with an arbitrary key generated by the user, and the key is encrypted with a group key. The gist is to attach to the encrypted shared information as attached information.
【0045】
In the present invention according to claim 17, the shared information is encrypted with an arbitrary key generated by the user, and the key encrypted with the group key is attached to the encrypted shared information as attached information.
【0046】
Further, the present invention according to claim 18 is the gist of the invention according to claim 17, wherein the attached information is encrypted with the latest group key each time the group key is updated.
【0047】
In the present invention according to claim 18, the attached information is encrypted with the latest group key each time the group key is updated.
【0048】
The present invention according to claim 19 is a group in which shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the user decrypts the encrypted shared information with a group key and uses the group. A recording medium on which a key program is recorded, a group key is a key of a common key cryptosystem, and n respective values t created by using a unidirectional function f disclosed from secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k +</sub><sub>2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the key (GK)<sub>n </sub>, ..., GK<sub>1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And every time the group key is updated, the key (GK)<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n </sub>), Group key GK<sub>k</sub>When updating, a new group key GK<sub>k + 1 </sub>The latest group key GK that has been updated by the user<sub>k </sub>Only hold and use this latest group key to encrypt the shared information of the group, decrypt the shared information encrypted with the group key with the group key, and convert it to the shared information encrypted with the past group key. If there is, the latest group key GK held by the user himself<sub>k </sub>The gist is to record a group key program to be decrypted using a group key derived from the above using a one-way function on a recording medium.
【0049】
In the present invention according to claim 19, the group key is a key of a common key cryptosystem, and n each value t created by using the one-way function f disclosed from the secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the key (GK)<sub>n </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And every time the group key is updated, the key (GK)<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n</sub>), Group key GK<sub>k </sub>New group key GK when updating<sub>k + 1 </sub>Is generated and the user has the latest group key GK<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group, decrypts the shared information encrypted with the group key with the group key, and the shared information encrypted with the past group key The latest group key GK held by the user himself<sub>k </sub>Since the group key program to be decoded using the group key derived from the above using the one-way function is recorded on the recording medium, the distribution medium can be improved by using the recording medium.
【0050】
Further, in the present invention according to claim 20, the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the user decrypts the encrypted shared information with the group key and uses it. Group key A recording medium on which a program is recorded, in which the group key is a public key cryptographic key, and n each created by using a public unidirectional function f consisting of secret information S. Value t<sub>n </sub>= f (S), ..., t<sub>k + 1</sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the private key (SGK)<sub>n </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>n </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And every time the group key is updated, the key (SGK)<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1</sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>n </sub>, PGK<sub>n </sub>), And the group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user can update the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret secret key SGK of the latest group key.<sub>k </sub>The gist is to record a group key program to be decrypted using a private key derived from the above using a one-way function on a recording medium.
【0051】
In the present invention according to claim 20, the group key is a key of public key cryptography, and n each value t created by using the one-way function f disclosed from the secret information S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) Derived from the private key (SGK)<sub>n </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>n </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And every time the group key is updated, the key (SGK)<sub>k </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>n </sub>, PGK<sub>n </sub>), And the group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user is updated with the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k</sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret key SGK of the latest group key.<sub>k </sub>Since the group key program to be decrypted using the secret key derived from the above using the one-way function is recorded on the recording medium, the recording medium can be used to improve its circulation.
【0052】
Further, the present invention according to claim 21 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. It is a recording medium that records a group key program that allows each user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while decrypting and using the shared information with a group key. The group key is a key of the common key encryption method, and each value y of m created by using the unidirectional function g disclosed from the secret information S.<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>m </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And as a group key for each class from the top to each class, (GK<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>m </sub>), And the user is assigned the latest group key GK.<sub>k </sub>Only is retained, and this group key is used to encrypt the shared information of the group, decrypt the shared information encrypted with the group key of its own class, and encrypt it with the group key of the lower class. To decrypt the information, the user himself / herself has his / her own group key GK.<sub>k </sub>The gist is to record a group key program using a key derived from a one-way function on a recording medium.
【0053】
In the present invention according to claim 21, the group key is a key of the common key cryptosystem in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S. Each value of m that is y<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k +</sub><sub>2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>m </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>), And as a group key for each class from the top to each class, (GK<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>m </sub>), And the user has the latest group key GK.<sub>k </sub>Only retained, the shared information of the group was encrypted using this group key, the shared information encrypted with the group key of its own class was decrypted, and it was encrypted with the group key of the lower class than itself. To decrypt the information, the user himself has his own group key GK<sub>k </sub>Since a group key program using a key derived from a one-way function is recorded on a recording medium, the recording medium can be used to improve its circulation.
【0054】
The present invention according to claim 22 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users share the encrypted shared information. Is a recording medium that records a group key program that allows the user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while decrypting and using the group with a group key. The key is a public key encryption key, and each of m values y created by using the unidirectional function g disclosed from the secret information S.<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>m </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>m </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And as a group key for each class from the top to each class, (SGK<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>m </sub>, PGK<sub>m </sub>) Pairs are assigned to users in order, and the user assigns the assigned group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only, the public key PGK for this group key<sub>k </sub>Encrypts the shared information of the group using the private key SGK<sub>k </sub>Use the public key PGK of your class's group key<sub>k </sub>In order to decrypt the shared information encrypted with, and to decrypt the information encrypted with the group key of the lower class than itself, the user himself / herself has his / her own private key SGK.<sub>k </sub>The gist is to record a group key program using a key derived from a one-way function on a recording medium.
【0055】
In the present invention according to claim 22, the group key is a key of public key cryptography in a plurality of groups having a hierarchical structure, and is created by using the one-way function g disclosed from the secret information S. Each value of m that is y<sub>m </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k +</sub><sub>2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>m </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>m </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>), And as a group key for each class from the top to each class, (SGK<sub>1 </sub>, PGK<sub>1 </sub>), ..., (SGK<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>), (SGK<sub>k </sub>, PGK<sub>k </sub>), ..., (SGK<sub>m </sub>, PGK<sub>m </sub>) Pairs are assigned to the users in order, and the users are assigned the group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only, the public key PGK for this group key<sub>k </sub>Encrypts the shared information of the group using the private key SGK<sub>k </sub>Use the public key PGK of your class's group key<sub>k </sub>In order to decrypt the shared information encrypted with, and to decrypt the information encrypted with the group key of the lower class than itself, the user himself / herself has his / her own private key SGK.<sub>k </sub>Since a group key program using a key derived from a one-way function is recorded on a recording medium, the recording medium can be used to improve its circulation.
【0056】
Further, the present invention according to claim 23 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. It is a recording medium that records a group key program that allows each user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while encrypting the shared information with a group key. The group key is a key of the common key encryption method, and each of n values t created by using the unidirectional function f disclosed from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1</sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>r </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) And the group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>The latest group key GK that has been updated by the user<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group and decrypt the shared information encrypted with the group key of its own class, and the shared encrypted with the past group key For information, the latest group key GK held by the user himself<sub>k </sub>For information that is decrypted using the group key derived from the one-way function f and encrypted with the group key of a lower class than itself, the user himself / herself is one-way from his / her own group key. The gist is to record a group key program decrypted using the key derived by the sex function g on a recording medium.
【0057】
In the present invention according to claim 23, the group key is a key of a common key cryptosystem in a plurality of groups having a hierarchical structure, and is created by using the one-way function f disclosed from the secret information S1. Each of n values t<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the key (GK)<sub>r </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>) And the group key GK<sub>k </sub>When updating, a new group key GK<sub>k + 1 </sub>Is generated and the user has the latest group key GK<sub>k </sub>Only keeps and uses this latest group key to encrypt the shared information of the group and decrypt the shared information encrypted with the group key of its own class, and the shared encrypted with the past group key The information is the latest group key GK held by the user himself.<sub>k </sub>Information that is decrypted using the group key derived from the one-way function f and encrypted with the group key of the lower class than itself is the information that the user himself uses from his own group key with the one-way function g. Since the group key program decrypted using the derived key is recorded on the recording medium, the recording medium can be used to improve its circulation.
【0058】
Further, the present invention according to claim 24 has a hierarchical structure composed of a plurality of classes, and the shared information of a group composed of a plurality of users is encrypted with a group key and shared by the group, and the users are encrypted. It is a recording medium that records a group key program that allows each user to encrypt / decrypt information of his / her own class and classes lower than his / her own class while encrypting the shared information with a group key. The group key is a public key encryption key, and each of n values t created by using the unidirectional function f published from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1</sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>r </sub>, ..., SGK<sub>k + 1 </sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>r </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Pair and group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated and the user can update the latest group key (SGK).<sub>k </sub>, PGK<sub>k</sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>For shared information decrypted with and encrypted with the past group key, the private key SGK of the latest group key<sub>k </sub>For information that is decrypted using the private key derived from the one-way function f and encrypted with a group key of a lower class than itself, the user himself / herself is one-way from his / her own group key. The gist is to record the group key program decrypted using the private key derived by the function g on the recording medium.
【0059】
In the present invention according to claim 24, the group key is a key of public key cryptography, and each of n values t created by using the one-way function f disclosed from the secret information S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1</sub>= f (t<sub>2 </sub>) And m each value y created using the one-way function g exposed from the secret information S2<sub>m </sub>= g (S2), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k +</sub><sub>1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>) Derived from the private key (SGK)<sub>r </sub>, ..., SGK<sub>k + 1</sub>, SGK<sub>k </sub>, ..., SGK<sub>1 </sub>) And public key (PGK)<sub>r </sub>, ..., PGK<sub>k + 1 </sub>, PGK<sub>k </sub>, ..., PGK<sub>1 </sub>) Pair and group key (SGK)<sub>k </sub>, PGK<sub>k </sub>When updating), a new group key (SGK)<sub>k + 1 </sub>, PGK<sub>k + 1 </sub>) Is generated, and the user can use the latest group key (SGK).<sub>k </sub>, PGK<sub>k </sub>) Only keeps this latest group key public key PGK<sub>k </sub>Encrypts the shared information of the group using, and the public key PGK of the group key<sub>k </sub>The shared information encrypted with the group key private key SGK<sub>k </sub>The shared information decrypted with and encrypted with the past group key is the secret key SGK of the latest group key.<sub>k </sub>Decrypted using the private key derived from the one-way function f, and the information encrypted with the group key of the lower class than itself is derived by the user himself from his own group key with the one-way function g. Since the group key program decrypted using the private key is recorded on the recording medium, the recording medium can be used to improve its circulation.
【0060】
The present invention according to claim 25 is the invention according to any one of claims 21 to 24, wherein the group key represents a hierarchical organization.<sub>1 </sub>, Y<sub>2 </sub>, ..., Y<sub>m </sub>Each of the m values y created by the one-way function g using<sub>m </sub>= g (STheY<sub>m </sub>), ..., y<sub>k + 1 </sub>= g (y <sub>k + 1 </sub>TheY<sub>k + 1 </sub>), Y<sub>k </sub>= g (y <sub>k </sub>TheY<sub>k </sub>), ..., y<sub>1 </sub>= g (y <sub>1 </sub>TheY<sub>1 </sub>), Where y <sub>k </sub>Is y<sub>k </sub>The gist is to record the group key program, which is the value of the upper layer of, on the recording medium.
【0061】
In the present invention according to claim 25, the group key is public information Y representing a hierarchical organization.<sub>1 </sub>, Y<sub>2 </sub>, ..., Y<sub>m </sub>Each of m values y created by the one-way function g using<sub>m </sub>= g (STheY<sub>m </sub>), ..., y<sub>k + 1 </sub>= g (y <sub>k + 1 </sub>TheY<sub>k + 1 </sub>), Y<sub>k </sub>= g (y <sub>k </sub>TheY<sub>k</sub>), ..., y<sub>1 </sub>= g (y <sub>1 </sub>TheY<sub>1 </sub>) Is recorded on a recording medium, so that the recording medium can be used to improve its circulation.
【0062】
Further, the present invention according to claim 26 is the invention according to any one of claims 19 to 25, in which the shared information is encrypted with an arbitrary key generated by the user, and the key is encrypted with a group key. The gist is to record the group key program attached to the encrypted shared information as the attached information on the recording medium.
【0063】
In the present invention according to claim 26, a group in which shared information is encrypted with an arbitrary key generated by a user, and the key encrypted with a group key is attached to the encrypted shared information as attached information. Since the key program is recorded on a recording medium, the recording medium can be used to improve its circulation.
【0064】
Further, in the invention of claim 27, in the invention of claim 26, every time the group key is updated, a group key program for encrypting the attached information with the latest group key is recorded on a recording medium. Is the gist.
【0065】
In the present invention according to claim 27, since the group key program that encrypts the attached information with the latest group key is recorded on the recording medium each time the group key is updated, the recording medium is used. Therefore, its distribution can be enhanced.
【0066】
BEST MODE FOR CARRYING OUT THE INVENTION
In the group key method of the present invention, the group key is derived from each of n values created by using the one-way function disclosed from the secret information to generate the group key, which is shown in FIG. The value obtained by applying the one-way function f to the initial value S k + 1 times is calculated as h.<sub>nk</sub>Then, due to the characteristics of the one-way function, h<sub>nk </sub>From h<sub>nk-1 </sub>Is easy to calculate, but h<sub>n-k + 1 </sub>Is difficult to calculate.
【0067】
In the present invention, the above-mentioned features are utilized to facilitate the management of the group key for the user. As the unidirectional function, any method may be used as long as it is a unidirectional function having the above characteristics.
【0068】
First, an apparatus configuration for implementing the group key method according to the first embodiment of the present invention will be described. FIG. 1 is a diagram showing a configuration of a group key device that implements the group key method of the present embodiment, and the group key device shown in the figure encrypts shared information of a group composed of a plurality of users with a group key. The encrypted shared information is decrypted and used by the group key, and the group key generator 1 that generates the group key and this generated group key are used. It is composed of a plurality of user terminals 3a to 3n that encrypt / decrypt the shared information of the group and use it.
【0069】
The group key generation organization 1 is composed of a group key generation unit 11 that generates a group key and a group key transmission unit 13 that transmits the generated group key to each user terminal 3a to 3n. In addition, each of the plurality of user terminals 3a to 3n is a group key receiving unit 31 that receives the group key transmitted from the group key transmitting unit 13 of the group key generating organization 1, and the latest group held by the user himself / herself. Group key derivation unit 33 that derives the group key for decrypting the shared information encrypted with the past group key using a one-way function from the key, and the encryption unit that encrypts the shared information with the group key It consists of 35 and a decryption unit 37 that decrypts the shared information encrypted with the group key.
【0070】
Next, a group key method using the group key device of the present embodiment configured as described above will be described. In this embodiment, a group key is issued for each group, and the group members only hold the latest key, which enables decryption of a document encrypted in the past.
【0071】
Confidential information S is generated for each group, and n values (t) are used using the one-way function f published by S.<sub>n </sub>= f (S), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1 </sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>)) Is generated. GK with each value converted by the function G1<sub>n </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>Is used as the group key, and GK is used every time the group key is updated.<sub>1 </sub>, ..., GK<sub>k + 1 </sub>, GK<sub>k </sub>, ..., GK<sub>n </sub>Use in the order of. The function G1 may be an identity function.
【0072】
The group key at a certain point is GK<sub>k </sub>If so, the group key generator will newly update the GK when the group key is updated.<sub>k + 1 </sub>To generate. On the other hand, the user is the latest group key GK<sub>k + 1 </sub>And keep only that key. GK<sub>k </sub>To decrypt a past document encrypted with, do the following:
【0073】
(1) GK<sub>k + 1 </sub>From function G1 by t<sub>k + 1 </sub>Convert to.
【0074】
(2) t by the one-way function f<sub>k </sub>Ask for (t<sub>k </sub>= f (t<sub>k + 1 </sub>))。
【0075】
(3) t<sub>k </sub>From the function G1<sup>-1</sup>By GK<sub>k </sub>Convert to.
【0076】
(4) GK<sub>k </sub>Decrypt using.
【0077】
GK<sub>1 </sub>, ..., GK<sub>k-1 </sub>The document encrypted in is also decrypted by the same process.
【0078】
Next, the group key method according to the second embodiment of the present invention will be described. In this embodiment, in a group having a hierarchical structure, it is possible to encrypt / decrypt information of a lower class group only by holding its own group key.
【0079】
Generate secret information S and use n values (y) using the one-way function g exposed from S.<sub>n </sub>= g (S), ..., y<sub>k + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>)) Is generated. GK with each value converted by the function G2<sub>n </sub>, ..., GK<sub>k + 1</sub>, GK<sub>k </sub>, ..., GK<sub>1 </sub>Is assigned to each class as a group key for each class from the top. The function G2 may be an identity function.
【0080】
A class of users has their own group key (GK)<sub>k </sub>GK to keep only) and encrypt / decrypt your group shared information<sub>k </sub>To use. Also, GK<sub>k-1 </sub>To decrypt the information of the group lower than yourself encrypted in, do as follows.
【0081】
(1) GK<sub>k </sub>From the function G2 by y<sub>k </sub>Convert to.
【0082】
(2) y by the one-way function g<sub>k-1 </sub>Ask for (y<sub>k-1 </sub>= g (y<sub>k </sub>))。
【0083】
(3) y<sub>k-1 </sub>From the function G2<sup>-1</sup>By GK<sub>k-1 </sub>Convert to.
【0084】
(4) GK<sub>k-1 </sub>Decrypt using.
【0085】
GK<sub>1 </sub>, ..., GK<sub>k-2 </sub>The shared information encrypted in is also decrypted by the same process.
【0086】
Next, the group key method according to the third embodiment of the present invention will be described. In this embodiment, in a group having a hierarchical structure, group members only hold their own latest key, and can encrypt / decrypt information of lower class groups and documents encrypted in the past. Is what you do.
【0087】
Confidential information S1 is generated for each class, and n values (t) are generated using the one-way function f published from S1.<sub>n </sub>= f (S1), ..., t<sub>k + 1 </sub>= f (t<sub>k + 2 </sub>), t<sub>k </sub>= f (t<sub>k + 1</sub>), ..., t<sub>1 </sub>= f (t<sub>2 </sub>)) Is generated.
【0088】
Furthermore, secret information S2 is generated, and m values (y) are used using the one-way function g published from S2.<sub>m </sub>= g (S2), ..., y<sub>K + 1 </sub>= g (y<sub>k + 2 </sub>), Y<sub>k </sub>= g (y<sub>k + 1 </sub>), ..., y<sub>1 </sub>= g (y<sub>2 </sub>)) Is generated.
【0089】
It is assumed that the group key of each class is converted by the function G3 by combining the values obtained from the one-way functions f and g. The function G3 may be an identity function. In the case of the model of FIG. 6, the group key is calculated from the intersection shown in FIG. The group key of the manager group at a certain point is GK<sub>1 </sub>If so, the members of the department manager group GK the document encrypted with the group key in the shaded area.<sub>1 </sub>Decrypt with the key generated from.
【0090】
Repeated updates of the group key in a particular group may result in holding a group key that cannot be derived from a group above that group (see the group key for the section chief group in Figure 4). This process always includes allocating a group key so that the upper group can derive the group key of the lower group.
【0091】
Next, a specific example will be described. The following cases will be described here.
【0092】
(1) It is possible to decrypt past ciphertext with only the latest group key.
【0093】
(2) The group key shall be public key cryptography (described using the ElGamal method as an example).
【0094】
(3) The shared document is encrypted with the temporary key SK, and the SK is further encrypted with the group key and attached to the ciphertext.
【0095】
The group key generator applies the one-way function f n times from the secret information (S), and t<sub>1</sub>To calculate.
【0096】
t<sub>1 </sub>= f<sup>n </sup>(S) Next, the prime number p and the multiplicative group Zp<sup>* </sup>Produces the primitive element g of, t<sub>1 </sub>Is the private key of the group key, and (g<sup>t1</sup>Let (mod p), p, g) be the public key of the group key. The private key may be distributed to the group members, or may be stored in the group key generator instead of being distributed every time the update is made, and may be distributed to the members when the group member requests the acquisition of the group key.
【0097】
When updating the group key due to the group member leaving, the group key generator again applies the one-way function f from the secret information (S) n-1 times, and t.<sub>2</sub>Calculate and t<sub>2 </sub>= f<sup>n-1 </sup>(S) Private key t<sub>2 </sub>, Public key (g<sup>t2</sup>Create (mod p), p, g).
【0098】
The private key of the group key at a certain point is t<sub>k </sub>, The public key is (g<sup>tk</sup>If it is (mod p), p, g), the group members perform the cryptographic operation as follows.
【0099】
encryption: (1) Create a temporary key SK and encrypt the document.
【0100】
(2) Obtain the public key of the group key from the group key generator.
【0101】
(3) Encrypt SK with the public key of the group key and attach it to the ciphertext.
【0102】
Decryption: (1) If necessary, the private key of the group key t<sub>k </sub>Is obtained from the group key generator.
【0103】
(2) SK in the attached information is g<sup>tk</sup>If encrypted with, the private key of the group key t<sub>k </sub>Decrypt using. g<sup>tk</sup>Earlier g<sup>tk -r</sup>If encrypted with, the private key of the group key t<sub>k </sub>By applying the one-way function f r times to t<sub>kr </sub>Calculate and t<sub>kr </sub>Decrypt using.
【0104】
Also, when a group member is added, only the latest group key is assigned to the new member.
【0105】
Next, as another specific example, a diagram shows a case where a group having a hierarchical structure only holds its own group key to decrypt a document encrypted by a lower group and the group key is a common key cryptosystem. This will be explained with reference to 5.
【0106】
In FIG. 5, the group key generator applies the one-way function g from the secret information S, and the group key y of each class.<sub>1 </sub>, ..., y<sub>5 </sub>To generate.
【0107】
Development Department Group Key: y<sub>1 </sub>= g (S Development Department ) Lesson 1 Group Key: y<sub>2 </sub>= g (y<sub>1 </sub> Lesson 1 ) Lesson 2 Group Key: y<sub>3 </sub>= g (y<sub>2 </sub> Lesson 2 ) Group 1 key: y<sub>4 </sub>= g (y<sub>2 </sub> 1st clerk ) 2nd group key: y<sub>5 </sub>= g (y<sub>2 </sub> 2nd clerk ) Character strings such as "Development Department" are public information representing a hierarchical organization.
【0108】
Assign a group key to users who belong to each department. At this time, it may be distributed to the group members, or it may be stored in the group key generator instead of being distributed every time the update is made, and distributed to the members when the group member requests the acquisition of the group key.
【0109】
Group members perform cryptographic operations as follows.
【0110】
encryption: (1) Encrypt the text with your own group key.
【0111】
Decryption: (1) If necessary, obtain the group key from the group key generator.
【0112】
(2) If the ciphertext is encrypted with the group key to which it belongs, decrypt it using its own group key.
【0113】
When encrypted with a lower class group key, the lower group key is calculated and decrypted based on the public information representing the hierarchical structure.
【0114】
By recording the process of the above embodiment as a program on a recording medium, the recording medium can be used to improve its circulation.
【0115】
[Effect of the invention]
As described above, according to the present invention, the user is the latest group key GK.<sub>k </sub>Only keep only, encrypt the shared information of the group with this latest group key, decrypt the shared information encrypted with the group key with the group key, and use the shared information encrypted with the past group key The latest group key GK held by the person himself / herself<sub>k </sub>Since the decryption is performed using the group key derived from the one-way function, the user does not have to keep the past group key as in the past, and the newly joined member is also the latest. You only need to get the group key, not the past group key.
【0116】
Further, according to the present invention, the user is the latest group key GK.<sub>k </sub>Only the group key is retained, the shared information of the group is encrypted using this group key, and the shared information encrypted with the group key of the own class is decrypted, and the user's own group key GK<sub>k </sub>Using the key derived from the one-way function, the information encrypted with the group key of the lower class than itself is decrypted, so that the user retains the past group key as before. It is not necessary, and members of each group do not need to hold a lower class group key in addition to their own group key.
【0117】
Further, according to the present invention, the user is the latest group key GK.<sub>k </sub>Keep only, use this latest group key to encrypt the shared information of the group, decrypt the shared information encrypted with the group key of your own class, and share encrypted with the past group key Information is the latest group key GK held by the user himself<sub>k </sub>The information decrypted from the group key derived from the group key using the unidirectional function f and encrypted with the group key of the lower class is the unidirectional function g from the group key held by the user. Since it is decrypted using the derived key, the user does not need to keep the past group key as in the past, and the newly joined member only needs to obtain the latest group key. It is not necessary to obtain the past group key, and the members of each group do not need to hold the group key of the lower class in addition to their own group key.
[Simple explanation of drawings]
[Figure 1]
It is a figure which shows the structure of the group key device which carries out the group key method which concerns on 1st Embodiment of this invention.
[Figure 2]
It is explanatory drawing for demonstrating the property of the one-way function used in the group key method of this invention.
[Fig. 3]
It is a figure which shows the range which a director in 3rd Embodiment of this invention can decode.
[Fig. 4]
It is a figure for demonstrating the group key which cannot be derived from a higher group when the group key is updated repeatedly in the 3rd Embodiment of this invention.
[Fig. 5]
It is explanatory drawing which shows the structure of the group which has a hierarchical structure as a specific example of the 2nd Embodiment of this invention.
[Fig. 6]
It is explanatory drawing which shows a plurality of groups having a hierarchical structure consisting of a department manager, a section manager, and a section chief.
[Explanation of symbols]
1 Group key generator 3a ~ 3n User terminal 11 Group key generator 13 Group key transmitter 31 Group key receiver 33 Group key derivation unit 35 Encryption Department 37 Decoding section
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2014034018A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2005539423A | Cited by | Japan | Examiner |
| US12388800B2 | Cited by | United States of America | Applicant |
| WO2023162232A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2008199639A | Cited by | Japan | Search report |
| JP2002366030A | Cited by | Japan | Examiner |
| US9455828B2 | Cited by | United States of America | Applicant |
| JP7358659B1 | Cited by | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 4031999 | Japan | A | |
| JP19990040319 | – | – | – |
Numbers
- Publication
- 2000-244474
- Publication, DOCDB
- 2000244474
- Publication, EPODOC
- JP2000244474
- Application
- 11040319
- Application, DOCDB
- 4031999
- Application, EPODOC
- JP19990040319
Titles2
- Japanese
- グループ鍵方法および装置とグループ鍵プログラムを記録した記録媒体
- English
- PROBLEM TO BE SOLVED: To record a group key method, an apparatus, and a group key program.
Classification
- IPC, 2
- H04L9 08
- H04L9 14