JP2003143128A

Communication system and communication method

Abstract

[Task] High security communication is possible with a simple configuration.

Solution.Share the ID of the client terminal 11 and PWD offline (S11, S12). Generate a random number value R on the client terminal 11, calculate Kreg: = h (PWD), encrypt R with Kreg to obtain eKreg (R), and give the access point 21 an ID, h (ID | PWD). , Send eKreg (R) (S13, S14). The access point 21 finds the PWD corresponding to the received ID (S15), finds h (ID | PWD) (S16), calculates Kreg if it matches the received value (S17), and eKreg with Kreg. (R) is decoded to extract R (S18), and the hash value of R is transmitted to the client terminal 11 (S19). When the hash value of R matches the received value, the client terminal 11 notifies the access point 21 that the authentication is OK. After that, KCL: = h (PWD | R) is used as the encryption key.

JP2003143128A, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Projected expiry passed 5 November 2021, 4.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

11 claims: 4 independent, 7 dependent

  1. 1
    [Claims] 1. Between a first device (11) and a second device (21) that communicate with each other. The identifier ID of the first device and the confidential information PWD are shared by the first and second devices, and the secret information PWD is shared. In the first device, a predetermined value R is generated, the one-way function value Kreg:= h (PWD) of the secret information PWD is obtained, and the obtained one-way function value Kreg of the secret information is used as an encryption key for authentication. Then, the predetermined value R is encrypted to calculate the encrypted data eKreg (R), and the identifier ID and the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD are connected to the second device. And the encrypted predetermined value eKreg (R), The second device searches for the secret information PWD corresponding to the received identifier ID, calculates the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD, and receives this. It is compared with the direction function value h (ID | PWD), and if it matches, the authentication encryption key Kreg: = h (PWD) is calculated, and a predetermined value encrypted using this authentication encryption key Kreg. eKreg (R) is decoded, a predetermined value R is extracted, and the value h (R) converted by a one-way function is transmitted to the first device. The first device obtains the one-way function value h (R) of the predetermined value R, compares this with the received one-way function value H (R) of the predetermined value R, and if they match, Notify the second device that the authentication has been established, and The first device obtains the one-way function value KCL: = h (PWD | R) of the concatenation of the secret information PWD and the predetermined value R as the common key KCL for encryption. The second device calculates the common key KCL: = h (PWD | R) and The first device and the second device communicate with each other using the common key KCL as an encryption key. A communication method characterized by that. 【特許請求の範囲】 【請求項1】相互に通信を行う第1の装置(11)と第2の装置(21)との間で、 前記第1の装置の識別子IDと秘密情報PWDとを前記第1と第2の装置で共有し、 前記第1の装置において、所定値Rを生成し、秘密情報PWDの一方向関数値Kreg:=h(PWD)を求め、求めた秘密情報の一方向関数値Kregを認証用の暗号鍵として用いて、所定値Rを暗号化して暗号データeKreg(R)を計算し、前記第2の装置に、識別子IDと、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)と、暗号化された所定値eKreg(R)とを送信し、 前記第2の装置は、受信した識別子IDに対応する秘密情報PWDを検索し、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)を計算し、これと受信した一方向関数値h(ID|PWD)と比較し、一致した場合に、認証用の暗号鍵Kreg:=h(PWD)を計算し、この認証用の暗号鍵Kregを用いて暗号化された所定値eKreg(R)を復号して、所定値Rを抽出し、これを一方向性関数で変換した値h(R)を前記第1の装置に送信し、 前記第1の装置は、所定値Rの一方向性関数値h(R)を求め、これと受信した所定値Rの一方向性関数値h(R)とを比較し、一致する場合に、認証が成立したことを前記第2の装置に通知し、 前記第1の装置は、秘密情報PWDと所定値Rの連結の一方向関数値KCL:=h(PWD|R)を暗号用の共通鍵KCLとして求め、 前記第2の装置は、共通鍵KCL:=h(PWD|R)を計算し、 前記第1の装置と前記第2の装置とは、共通鍵KCLを暗号鍵として用いて相互に通信を行う、 ことを特徴とする通信方法。
  2. 6
    A communication system for communicating between a first device (11) and a second device (21). The identifier ID of the first device and the confidential information PWD are shared by the first and second devices, and the secret information PWD is shared. The first device generates a predetermined value R, calculates the one-way function value Kreg:= h (PWD) of the secret information PWD, and uses the calculated one-way function value Kreg of the secret information as an authentication encryption key. Using, the predetermined value R is encrypted to calculate the encrypted data eKreg (R), and the identifier ID and the one-way function value h (ID | PWD) of concatenating the identifier ID and the secret information PWD are connected to the second device. ) And the encrypted predetermined value eKreg (R), The second device searches for the secret information PWD corresponding to the received identifier ID, calculates the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD, and receives this. The directional function value h (ID | PWD) is compared, and if they match, the authentication encryption key Kreg: = h (PWD) is calculated, and the predetermined value encrypted using this authentication encryption key Kreg. The value eKreg (R) is decoded, the predetermined value R is extracted, and the value h (R) converted by the one-way function is transmitted to the first device. The first device obtains the one-way function value h (R) of the predetermined value R, compares this with the received one-way function value H (R) of the predetermined value R, and if they match, Notify the second device that the authentication has been established, and The first device obtains and stores the one-way function value KCL: = h (PWD | R) of the concatenation of the secret information PWD and the predetermined value R as the common key KCL for encryption, and stores it. The second device calculates and stores the common key KCL: = h (PWD | R) and stores it. The first device and the second device communicate with each other using the common key KCL as an encryption key. A communication system characterized by that. 【請求項6】第1の装置(11)と第2の装置(21)との間で通信を行う通信システムであって、 前記第1の装置の識別子IDと秘密情報PWDとを前記第1と第2の装置で共有し、 前記第1の装置は、所定値Rを生成し、秘密情報PWDの一方向関数値Kreg:=h(PWD)を計算し、計算した秘密情報の一方向関数値Kregを認証用の暗号鍵として用いて、所定値Rを暗号化して暗号データeKreg(R)を計算し、前記第2の装置に、識別子IDと、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)と、暗号化された所定値eKreg(R)とを送信し、 前記第2の装置は、受信した識別子IDに対応する秘密情報PWDを検索し、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)を計算し、これと受信した一方向関数値h(ID|PWD)とを比較し、一致した場合に、認証用の暗号鍵Kreg:=h(PWD)を計算し、この認証用の暗号鍵Kregを用いて暗号化された所定値eKreg(R)を復号して、所定値Rを抽出し、これを一方向性関数で変換した値h(R)を前記第1の装置に送信し、 前記第1の装置は、所定値Rの一方向性関数値h(R)を求め、これと受信した所定値Rの一方向性関数値h(R)とを比較し、一致する場合に、認証が成立したことを前記第2の装置に通知し、 前記第1の装置は、秘密情報PWDと所定値Rの連結の一方向関数値KCL:=h(PWD|R)を暗号用の共通鍵KCLとして求めて保存し、 前記第2の装置は、共通鍵KCL:=h(PWD|R)を計算して保存し、 前記第1の装置と前記第2の装置とは、共通鍵KCLを暗号鍵として用いて相互に通信を行う、 ことを特徴とする通信システム。
  3. 7
    Between a first device (11) and a second device (21) that communicate with each other. The private key KCL of the first device is generated, and the address of the first device and the pair of this private key KCL are notified offline to the second device and registered. The second device generates its own private key KAP when idle and The second device receives the connection request from the first device, searches the private key KCL of the first device from the address of the first device of the request source, and generates the session key K. , The concatenation of the predetermined value R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device to generate encrypted data eKCL (R | K | KAP), and the first Send to the device and The first device decrypts the encrypted data eKCL (R | K | KAP) addressed to itself with its own private key KCL, and uses the predetermined value R, the session key K, and the secret key KAP of the second device. Is extracted, and the extracted predetermined value R is encrypted with the private key KAP of the second device to generate encrypted data eKAP (R), and the generated encrypted data eKAP (R) is used in the second device. Send and The second device receives the encrypted data eKAP (R), decrypts it with the private key KAP of the second device, extracts a predetermined value R, and extracts the extracted predetermined value R and the first first device. It is compared with the predetermined value R transmitted to the device, and if they match, it is determined that the authentication has been established, and it is determined. The first device and the second device store the secret key KCL of the first device and the secret key KAP of the second device, respectively. Hereinafter, the first device and the second device execute encrypted communication using the secret key KCL of the first device and the secret key KAP of the second device. A communication method characterized by that. 【請求項7】相互に通信を行う第1の装置(11)と第2の装置(21)との間で、 前記第1の装置の秘密鍵KCLを生成し、前記第1の装置のアドレスとこの秘密鍵KCLのペアを、前記第2の装置にオフラインで通知して登録し、 前記第2の装置は、アイドル時に、自己の秘密鍵KAPを生成し、 前記第2の装置は、前記第1の装置からの接続要求を受信し、要求元の前記第1の装置のアドレスから前記第1の装置の秘密鍵KCLを検索し、セッション鍵Kを生成し、所定値Rとセッション鍵Kと自己の秘密鍵KAPとの連結を前記第1の装置の秘密鍵KCLにて暗号化して暗号データeKCL(R|K|KAP)を生成して、前記第1の装置に送信し、 前記第1の装置は、自己宛の暗号データeKCL(R|K|KAP)を自己の秘密鍵KCLにて復号して、所定値Rとセッション鍵Kと前記第2の装置の秘密鍵KAPとを抽出し、さらに、抽出した所定値Rを前記第2の装置の秘密鍵KAPで暗号化して暗号データeKAP(R)を生成し、生成した暗号データeKAP(R)を前記第2の装置に送信し、 前記第2の装置は、暗号データeKAP(R)を受信し、これを前記第2の装置の秘密鍵KAPにて復号して所定値Rを抽出し、抽出した所定値Rと前記第1の装置に送信した所定値Rとを比較し、一致していれば、認証成立と判別し、 前記第1の装置と前記第2の装置は、それぞれ、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを保存し、 以後、前記第1の装置と前記第2の装置は、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを用いて、暗号通信を実行する、 ことを特徴とする通信方法。
  4. 10
    A communication system that communicates between a first device (11) and a second device (21). The private key KCL of the first device is generated, the address of the first device and the pair of this private key KCL are notified offline to the second device, and this is registered in the storage unit. The second device generates and stores its own private key KAP when idle. The second device receives the connection request from the first device, searches the private key KCL of the first device from the address of the first device of the request source, and generates the session key K. , The concatenation of the predetermined value R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device to generate encrypted data eKCL (R | K | KAP), and the first Send to the device and The first device decrypts the encrypted data eKCL (R | K | KAP) addressed to itself with its own private key KCL, and uses the predetermined value R, the session key K, and the secret key KAP of the second device. Is extracted, and the extracted predetermined value R is encrypted with the private key KAP of the second device to generate encrypted data eKAP (R), and the generated encrypted data eKAP (R) is used in the second device. Send and The second device receives the encrypted data eKAP (R), decrypts it with the private key KAP, extracts a predetermined value R, and transmits the extracted predetermined value R to the first device. Compare with the predetermined value R, and if they match, it is determined that the authentication has been established, and The first device and the second device store the secret key KCL of the first device and the secret key KAP of the second device, respectively. Hereinafter, the first device and the second device are characterized in that encrypted communication is executed by using the secret key KCL of the first device and the secret key KAP of the second device. Communications system. 【請求項10】第1の装置(11)と第2の装置(21)との間で通信を行う通信システムであって、 前記第1の装置の秘密鍵KCLを生成し、前記第1の装置のアドレスとこの秘密鍵KCLのペアを、前記第2の装置にオフラインで通知し、これを記憶部に登録し、 前記第2の装置は、アイドル時に、自己の秘密鍵KAPを生成し格納し、 前記第2の装置は、前記第1の装置からの接続要求を受信し、要求元の前記第1の装置のアドレスから前記第1の装置の秘密鍵KCLを検索し、セッション鍵Kを生成し、所定値Rとセッション鍵Kと自己の秘密鍵KAPとの連結を前記第1の装置の秘密鍵KCLにて暗号化して暗号データeKCL(R|K|KAP)を生成して、前記第1の装置に送信し、 前記第1の装置は、自己宛の暗号データeKCL(R|K|KAP)を自己の秘密鍵KCLにて復号して、所定値Rとセッション鍵Kと前記第2の装置の秘密鍵KAPとを抽出し、さらに、抽出した所定値Rを前記第2の装置の秘密鍵KAPで暗号化して暗号データeKAP(R)を生成し、生成した暗号データeKAP(R)を前記第2の装置に送信し、 前記第2の装置は、暗号データeKAP(R)を受信し、これを秘密鍵KAPにて復号して所定値Rを抽出し、抽出した所定値Rと前記第1の装置に送信した送った所定値Rと比較し、一致していれば、認証成立と判別し、 前記第1の装置と前記第2の装置は、それぞれ、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを保存し、 以後、前記第1の装置と前記第2の装置は、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを用いて、暗号通信を実行する、ことを特徴とする通信システム。