Communication system, and communication method
Abstract
[Subject] It improves so that possibility of a decipherment of communication according the communications system containing two communication apparatus to a third party may be made smaller. [Solution means] Including the 1st communication apparatus and the 2nd communication apparatus, a communications system transmits the encoded data which enciphered and generated transmission object data with one communication apparatus to the communication apparatus of another side, and decrypts the encoded data which is a communication apparatus of the another side and was received. Whenever each communication apparatus performs encryption or decryption, it generates the algorithm used for encryption. In this case, by substituting the solution to past, each communication apparatus substitutes the solution to past for the algorithm for solution generation which can generate a new algorithm, and generates an algorithm. The solution to past is eliminated when used no longer. [Selection figure] Fig. 4
Term
Term ended
Projected expiry passed 7 January 2025, 1.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
9 claims: 4 independent, 5 dependent
- 1The first communication device, which is two communication devices that can encrypt the plain text transmission target data and then send it to the other party's communication device as encrypted data, and decrypt the received encrypted data into the transmission target data. And the second communication device, both the first communication device and the second communication device cut the transmission target data by a predetermined number of bits to obtain a plurality of transmission target disconnection data, and the encrypted data. A cutting means that cuts the encrypted data for each number of bits that was cut when the encrypted data was encrypted to make a plurality of encrypted cut data, which is common to the first communication device and the second communication device. An algorithm generation means for sequentially generating the encrypted algorithms, the transmission target disconnection data is encrypted with the algorithm and a predetermined key to obtain encrypted data, and the encrypted disconnection data is encrypted with the encrypted disconnection data. An encryption / decryption means that decrypts with the algorithm used at the time and the same key as the key to make the transmission target disconnection data, and a connection that connects the decrypted transmission target disconnection data to the transmission target data. Means, transmission / reception means for transmitting / receiving the encrypted data, and The algorithm generation means is adapted to generate the algorithm each time the transmission target data is encrypted or the encrypted data is decrypted, and when the algorithm is generated, a past solution is used. A communication system in which a predetermined solution obtained by substituting at least one of the above into a solution generation algorithm is used, and the past solution is deleted when there is no need to newly substitute. .. 平文である送信対象データを暗号化し暗号化データとしてから相手側の通信装置に送るとともに、受付けた暗号化データを復号化して送信対象データにすることができる2つの通信装置である第1通信装置及び第2通信装置を含み、 前記第1通信装置及び前記第2通信装置が共に、 前記送信対象データを所定のビット数毎に切断して複数の送信対象切断データにするとともに、前記暗号化データをその暗号化データが暗号化されたときに切断されたのと同じビット数毎に切断して複数の暗号化切断データにする切断手段、 前記第1通信装置と前記第2通信装置で共通とされたアルゴリズムを順次生成するアルゴリズム生成手段、 前記送信対象切断データを、前記アルゴリズムと所定の鍵によって暗号化して暗号化データとするとともに、前記暗号化切断データをその暗号化切断データを暗号化するときに用いられたアルゴリズムと前記鍵と同一の鍵によって復号化して送信対象切断データにする暗号化・復号化手段、 復号化された前記送信対象切断データを接続して前記送信対象データにする接続手段、 前記暗号化データを送受信する送受信手段、 を備えているとともに、 前記アルゴリズム生成手段は、前記送信対象データの暗号化、又は前記暗号化データの復号化が行われるたびに前記アルゴリズムを生成させるようになっているとともに、前記アルゴリズムを生成させる場合に、過去の解の少なくとも一つを解生成用アルゴリズムに代入することによって得られる所定の解を用いるようにされ、且つ新たに代入する必要がなくなった時点で過去の解を消去するようになっている、 通信システム。
- 4The first communication device, which is two communication devices that can encrypt the transmission target data in plain text and send it to the other party's communication device as encrypted data, and decrypt the received encrypted data to make the transmission target data. And a method executed in a communication system including a second communication device, in which one of the first communication device and the second communication device cuts the data to be transmitted by a predetermined number of bits and a plurality of data are cut. The process of converting the transmission target disconnection data into the data, the process of sequentially generating the algorithm, the process of encrypting the transmission target disconnection data by the algorithm to obtain the encrypted data, the process of converting the encrypted data into the first communication device and the second communication device. In the process of transmitting to the other of the communication device, the same bit as the encrypted data received by the other of the first communication device and the second communication device was disconnected when the encrypted data was encrypted. The process of cutting every number to make a plurality of encrypted cut data, the process of sequentially generating the same algorithm as that generated on one side of the first communication device and the second communication device, The process of decrypting the encrypted disconnection data by the algorithm used when encrypting the encrypted disconnection data to make the transmission target disconnection data, and connecting the decrypted transmission target disconnection data to the transmission target data. The first communication device and the other one and the other of the first communication device and the second communication device each time the data to be transmitted is encrypted or the encrypted data is decrypted. The algorithm is generated, and when the algorithm is generated, a predetermined solution obtained by substituting at least one of the past solutions into the solution generation algorithm is used and newly substituted. A communication method that erases past solutions when they are no longer needed. 平文である送信対象データを暗号化し暗号化データとしてから相手側の通信装置に送るとともに、受付けた暗号化データを復号化して送信対象データにすることができる2つの通信装置である第1通信装置及び第2通信装置を含んでいる通信システムで実行される方法であって、 前記第1通信装置及び前記第2通信装置の一方が、 前記送信対象データを所定のビット数毎に切断して複数の送信対象切断データにする過程、 アルゴリズムを順次生成する過程、 前記送信対象切断データを、前記アルゴリズムによって暗号化して暗号化データとする過程、 前記暗号化データを前記第1通信装置及び前記第2通信装置の他方に送信する過程、 前記第1通信装置及び前記第2通信装置の他方が、 受付けた前記暗号化データを、その暗号化データが暗号化されたときに切断されたのと同じビット数毎に切断して複数の暗号化切断データにする過程、 前記第1通信装置及び前記第2通信装置の前記一方で生成されたのと同じアルゴリズムを順次生成する過程、 前記暗号化切断データをその暗号化切断データを暗号化するときに用いられたアルゴリズムによって復号化して送信対象切断データにする過程、 復号化された前記送信対象切断データを接続して前記送信対象データにする過程、 を含んでいるとともに、 前記第1通信装置及び前記第2通信装置の前記一方及び前記他方は、 前記送信対象データの暗号化、又は前記暗号化データの復号化が行われるたびに前記アルゴリズムを生成させるようになっているとともに、前記アルゴリズムを生成させる場合に、過去の解の少なくとも一つを解生成用アルゴリズムに代入することによって得られる所定の解を用い、且つ新たに代入する必要がなくなった時点で過去の解を消去する、 通信方法。
- 5The first communication device, which is two communication devices that can encrypt the plain text transmission target data and then send it to the other party's communication device as encrypted data, and decrypt the received encrypted data into the transmission target data. And the second communication device, both the first communication device and the second communication device cut the transmission target data by a predetermined number of bits to obtain a plurality of transmission target disconnection data, and the encrypted data. A cutting means that cuts the encrypted data for each number of bits that was cut when the encrypted data was encrypted to make a plurality of encrypted cut data, which is common to the first communication device and the second communication device. A key generation means for sequentially generating the keys, the transmission target disconnection data is encrypted with the key and a predetermined algorithm to obtain encrypted data, and the encrypted disconnection data is encrypted with the encrypted disconnection data. An encryption / decryption means that decrypts the key used at the time and the same algorithm as the above algorithm to make the transmission target disconnection data, and a connection that connects the decrypted transmission target disconnection data to the transmission target data. Means, transmission / reception means for transmitting / receiving the encrypted data, and The key generation means is adapted to generate the key each time the transmission target data is encrypted or the encrypted data is decrypted, and when the key is generated, a past solution is used. A communication system in which a predetermined solution obtained by substituting at least one of the above into a solution generation algorithm is used, and the past solution is deleted when there is no need to newly substitute. .. 平文である送信対象データを暗号化し暗号化データとしてから相手側の通信装置に送るとともに、受付けた暗号化データを復号化して送信対象データにすることができる2つの通信装置である第1通信装置及び第2通信装置を含み、 前記第1通信装置及び前記第2通信装置が共に、 前記送信対象データを所定のビット数毎に切断して複数の送信対象切断データにするとともに、前記暗号化データをその暗号化データが暗号化されたときに切断されたのと同じビット数毎に切断して複数の暗号化切断データにする切断手段、 前記第1通信装置と前記第2通信装置で共通とされた鍵を順次生成する鍵生成手段、 前記送信対象切断データを、前記鍵と所定のアルゴリズムによって暗号化して暗号化データとするとともに、前記暗号化切断データをその暗号化切断データを暗号化するときに用いられた鍵と前記アルゴリズムと同一のアルゴリズムによって復号化して送信対象切断データにする暗号化・復号化手段、 復号化された前記送信対象切断データを接続して前記送信対象データにする接続手段、 前記暗号化データを送受信する送受信手段、 を備えているとともに、 前記鍵生成手段は、前記送信対象データの暗号化、又は前記暗号化データの復号化が行われるたびに前記鍵を生成させるようになっているとともに、前記鍵を生成させる場合に、過去の解の少なくとも一つを解生成用アルゴリズムに代入することによって得られる所定の解を用いるようにされ、且つ新たに代入する必要がなくなった時点で過去の解を消去するようになっている、 通信システム。
- 9The first communication device, which is two communication devices that can encrypt the plain text transmission target data and then send it to the other party's communication device as encrypted data, and decrypt the received encrypted data into the transmission target data. And a method executed in a communication system including a second communication device, wherein one of the first communication device and the second communication device cuts the transmission target data at a predetermined number of bits and a plurality of them. The process of converting the transmission target disconnection data into the transmission target disconnection data, the process of sequentially generating the key, the process of encrypting the transmission target disconnection data with the key and a predetermined algorithm to obtain encrypted data, the process of converting the encrypted data into the first communication device. And the process of transmitting to the other of the second communication device, the other of the first communication device and the second communication device disconnected the received encrypted data when the encrypted data was encrypted. The process of cutting for the same number of bits as the above to make a plurality of encrypted cut data, the process of sequentially generating the same key generated by the one of the first communication device and the second communication device, The process of decrypting the encrypted disconnection data with the key used when encrypting the encrypted disconnection data and the same algorithm as the algorithm to make the transmission target disconnection data, and the decrypted transmission target disconnection data. The process of connecting to the transmission target data is included, and the one and the other of the first communication device and the second communication device are encrypted of the transmission target data or of the encrypted data. The key is generated each time decoding is performed, and when the key is generated, a predetermined solution obtained by substituting at least one of the past solutions into the solution generation algorithm is obtained. A communication method that erases past solutions when they are used and no longer need to be newly substituted. 平文である送信対象データを暗号化し暗号化データとしてから相手側の通信装置に送るとともに、受付けた暗号化データを復号化して送信対象データにすることができる2つの通信装置である第1通信装置及び第2通信装置を含んでいる通信システムで実行される方法であって、 前記第1通信装置及び前記第2通信装置の一方が、 前記送信対象データを所定のビット数毎に切断して複数の送信対象切断データにする過程、 鍵を順次生成する過程、 前記送信対象切断データを、前記鍵と所定のアルゴリズムによって暗号化して暗号化データとする過程、 前記暗号化データを前記第1通信装置及び前記第2通信装置の他方に送信する過程、 前記第1通信装置及び前記第2通信装置の他方が、 受付けた前記暗号化データを、その暗号化データが暗号化されたときに切断されたのと同じビット数毎に切断して複数の暗号化切断データにする過程、 前記第1通信装置及び前記第2通信装置の前記一方で生成されたのと同じ鍵を順次生成する過程、 前記暗号化切断データをその暗号化切断データを暗号化するときに用いられた鍵及び前記アルゴリズムと同一のアルゴリズムによって復号化して送信対象切断データにする過程、 復号化された前記送信対象切断データを接続して前記送信対象データにする過程、 を含んでいるとともに、 前記第1通信装置及び前記第2通信装置の前記一方及び前記他方は、 前記送信対象データの暗号化、又は前記暗号化データの復号化が行われるたびに前記鍵を生成させるようになっているとともに、前記鍵を生成させる場合に、過去の解の少なくとも一つを解生成用アルゴリズムに代入することによって得られる所定の解を用い、且つ新たに代入する必要がなくなった時点で過去の解を消去する、 通信方法。
Independent claims4
42 paragraphs, as filed
The present invention includes two communication devices capable of encrypting plain text transmission target data and then sending it to the other party's communication device, and decrypting the received encrypted data into transmission target data. Regarding communication systems.
The communication system as described above is used in a situation where the data to be transmitted transmitted between two communication devices needs to be kept secret from a third party. Various encryption techniques have been proposed and used to conceal the data to be transmitted, but it is difficult to completely prevent the decryption of the encryption.
Generally, in communication performed by encrypting the data to be transmitted, the data to be transmitted is cut by a predetermined number of bits by the transmitting / receiving device on the sender side, and each of the cut data is encrypted and sent to the communication device on the other side. The procedure is to decrypt the data received by the transmitting / receiving device on the receiving side. When performing such encryption, a predetermined algorithm and key are generally used. The algorithm is very complex to prevent cryptanalysis, and the key is often changed at a given time. However, no matter how complex the algorithm is, or even if the key is changed, once the algorithm and key are known, the decryption of the data encrypted using the algorithm and key is relatively It's easy.
On the other hand, the inventor of the present application has repeatedly studied encryption technology, and has provided a common means for continuously generating at least one of an algorithm and a key for encryption and decryption on a transmitting side and a receiving side communication device. We have developed a technology for performing encrypted communication while continuously changing at least one of the algorithm and the key used for encryption and decryption. This technique continuously generates at least one of an algorithm and a key for encryption and decryption, and even if the algorithm or key is known once, then the algorithm or key, or the key thereof. Since both are changing, its strength is much higher than that of conventional encryption technology. However, even with this technology, if some algorithms or keys in the past are known, it may be predicted how the algorithms and / or keys will change in the future. , It cannot be said that the possibility of being deciphered by a third party is zero.
<p> The present invention includes two communication devices capable of encrypting plain text transmission target data and then sending it to the other party's communication device, and decrypting the received encrypted data into transmission target data. The object is to improve the communication system so as to reduce the possibility of decryption of the communication by a third party.</p>
<p> In order to solve such a problem, the inventor of the present application proposes the first invention and the second invention described below.</p><p> The first invention of the present application is as follows. The first invention is two communication devices that can encrypt plain text transmission target data and then send it to the other party's communication device, and decrypt the received encrypted data to make transmission target data. It is a communication system including a first communication device and a second communication device. Then, both the first communication device and the second communication device in this communication system cut the transmission target data for each predetermined number of bits to obtain a plurality of transmission target disconnection data, and the encrypted data is used as the encrypted data. A cutting means that cuts the encrypted data for each number of bits that was cut when the encrypted data was encrypted to make a plurality of encrypted cut data, which is common to the first communication device and the second communication device. An algorithm generation means for sequentially generating algorithms, the algorithm used when the transmission target disconnection data is encrypted by the algorithm to be encrypted data, and the encrypted disconnection data is encrypted with the encrypted disconnection data. It is provided with an encryption / decryption means for decrypting the data to be transmitted, a connection means for connecting the decrypted data to be transmitted, and a transmission / reception means for transmitting / receiving the encrypted data. ing. The algorithm generation means in this communication system is adapted to generate the algorithm each time the transmission target data is encrypted or the encrypted data is decrypted, and when the algorithm is generated. , The predetermined solution obtained by substituting at least one of the past solutions into the solution generation algorithm is used, and the past solution is deleted when it is no longer necessary to substitute a new one. There is. In this communication system, the algorithms used for encryption and decryption are continuously generated by the algorithm generation means, but the algorithm generation means uses a "solution" when generating the algorithm. ing. This solution has come to be generated using past solutions, as described above. Moreover, this solution is eliminated after it is no longer needed to generate a new solution. Therefore, in this communication system, past solutions are erased one after another, so even if the current solution can be known, a third party cannot know how it was generated. .. For the above reasons, the encrypted communication by this communication system is less likely to be decrypted by a third party. The above solution may result in a pseudo-random number.</p><p> In this communication system, the algorithm is updated at a timing so that encryption and decryption can be performed by using the same algorithm in the first communication device and the second communication device. The algorithm generation means may be such that the algorithm is generated each time the transmission target data is encrypted or the encrypted data is decrypted, and further, the transmission target disconnection data is encrypted. Alternatively, the algorithm may be generated each time the decryption data is decrypted. In the latter case, since encryption is performed by a different algorithm for each transmission target disconnection data, the possibility of decryption is further reduced.</p><p> The algorithm generation means generates a new solution from a past solution, but the solution may be obtained by substituting a plurality of past solutions into the solution generation algorithm. That is, the number of past solutions assigned to the solution generation algorithm to generate a new solution may be one or more.</p><p> The first invention can also be realized by the following method. This method is two communication devices that can encrypt plain text transmission target data and then send it to the other party's communication device, and decrypt the received encrypted data to make transmission target data. It is a method performed in a communication system including a first communication device and a second communication device. Then, in this method, one of the first communication device and the second communication device sequentially generates an algorithm in a process of cutting the transmission target data by a predetermined number of bits to obtain a plurality of transmission target cut data. A process, a process of encrypting the transmission target disconnection data by the algorithm to obtain encrypted data, a process of transmitting the encrypted data to the other of the first communication device and the second communication device, the first communication device. And the other of the second communication device cuts the received encrypted data for each number of bits that was cut when the encrypted data was encrypted into a plurality of encrypted cut data. It was used in the process, the process of sequentially generating the same algorithm as that generated in one of the first communication device and the second communication device, and in encrypting the encrypted breaking data. It includes a process of decoding by an algorithm to make transmission target disconnection data, and a process of connecting the decoded transmission target disconnection data to make transmission target data. Further, in this method, the one and the other of the first communication device and the second communication device generate the algorithm each time the transmission target data is encrypted or the encrypted data is decrypted. In addition, when generating the algorithm, it is no longer necessary to use a predetermined solution obtained by substituting at least one of the past solutions into the solution generation algorithm and to newly substitute the solution. At that point, erase the past solution.</p><p> The second invention according to the present application is as follows. The second invention is two communication devices that can encrypt plain text transmission target data and then send it to the other party's communication device, and decrypt the received encrypted data to make it transmission target data. A first communication device and a second communication device are included, and both the first communication device and the second communication device cut the transmission target data by a predetermined number of bits to obtain a plurality of transmission target disconnection data. A cutting means for cutting the encrypted data for each number of bits that was cut when the encrypted data was encrypted to obtain a plurality of encrypted cut data, the first communication device and the second communication device. A key generation means for sequentially generating a key common to communication devices, the transmission target disconnection data is encrypted by the key and a predetermined algorithm to obtain encrypted data, and the encryption disconnection data is encrypted and disconnected. The key used when encrypting the data and the encryption / decryption means for decrypting by the same algorithm as the above-mentioned algorithm to obtain the transmission target disconnection data, and the above-mentioned transmission by connecting the decrypted transmission target disconnection data. It is a communication system including a connection means for making target data and a transmission / reception means for transmitting / receiving the encrypted data. Then, the key generation means in this communication system is adapted to generate the key each time the transmission target data is encrypted or the encrypted data is decrypted, and the key is generated. In some cases, the predetermined solution obtained by substituting at least one of the past solutions into the solution generation algorithm is used, and the past solution is deleted when it is no longer necessary to substitute a new one. It has become. This communication system according to the second invention shares the basic idea with the first invention. In the communication system according to the second invention, instead of continuously generating the algorithm in the first invention, the key is continuously generated. The key in the second invention is generated by the key generation means, but when the key is generated, the past solution is used and the solution is used as in the case of the generation of the algorithm in the first invention. When it disappears, the past solution is erased. Therefore, even in the communication system according to the second invention, the possibility of decoding the communication by a third party is small. The solution in this case may also result in a pseudo-random number.</p><p> The key generation means in the second invention may generate a key solution at any timing. For example, the key generation means may be configured to generate the key each time the transmission target disconnection data is encrypted or the encrypted disconnection data is decrypted.</p><p> The key generation means obtains the solution by substituting the past solution into the solution generation algorithm, and the number of solutions assigned to the solution generation algorithm may be one or a plurality. The second invention can also be realized by the following method. The second invention is two communication devices that can encrypt plain text transmission target data and then send it to the other party's communication device, and decrypt the received encrypted data to make transmission target data. It is a method performed in a communication system including a first communication device and a second communication device. In the second invention, one of the first communication device and the second communication device cuts the transmission target data at a predetermined number of bits to obtain a plurality of transmission target cut data, and a process of sequentially generating a key. , The process of encrypting the transmission target disconnection data with the key and a predetermined algorithm to obtain encrypted data, the process of transmitting the encrypted data to the other of the first communication device and the second communication device, the first. One communication device and the other of the second communication device cut the received encrypted data for each number of bits that was cut when the encrypted data was encrypted, and a plurality of encryption cuts are performed. The process of converting data, the process of sequentially generating the same key that was generated on one side of the first communication device and the second communication device, and when encrypting the encrypted disconnection data. It includes a process of decoding the key used and the same algorithm as the algorithm to obtain the transmission target disconnection data, and a process of connecting the decoded transmission target disconnection data to the transmission target data. Further, the first communication device and the one and the other of the second communication device generate the key each time the transmission target data is encrypted or the encrypted data is decrypted. At the same time, when the key is generated, the predetermined solution obtained by substituting at least one of the past solutions into the solution generation algorithm is used, and when it is no longer necessary to newly substitute the past solution. Erase the solution.</p>
Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the drawings.
The communication system according to this embodiment is roughly configured as shown in FIG. The communication system includes a first communication device 11 and a second communication device 12 connected to each other via a network 13. The first communication device 11 and the second communication device 12 perform encrypted communication with each other. The network 13 connecting the first communication device 11 and the second communication device 12 is, for example, the Internet. However, instead of this, the network 13 may be configured by other means such as an intranet or a dedicated line.
The configurations of the first communication device 11 and the second communication device 12 will be described. Since the first communication device 11 and the second communication device 12 have the same configuration in this embodiment, only the configuration of the first communication device 11 will be described as a representative.
Figure 2 shows the hardware configuration of the first communication device 11. In this embodiment, the first communication device 11 includes a CPU (central processing unit) 21, a ROM (read only memory) 22, an HDD (hard disk drive) 23, a RAM (random access memory) 24, an input device 25, and a display device. The configuration includes 26, a communication device 27, and a bus 28. Data can be exchanged between the CPU 21, ROM 22, HDD 23, RAM 24, input device 25, display device 26, and communication device 27 via the bus 28. The ROM 22 or the HDD 23 contains a predetermined program and predetermined data (which may include data to be transmitted, which is the case in the present embodiment, and the predetermined data includes data. Contains the data necessary to execute the above program) is recorded. The CPU 21 controls the entire first communication device 11, and executes a process described later based on a program or data stored in the ROM 22 or the HDD 23. The RAM 24 is used as a work storage area when processing is performed by the CPU 21. The input device 25 is composed of a keyboard, a mouse, and the like, and is used for inputting commands and data. The display device 26 is composed of an LCD (liquid crystal display), a CRT (cathode ray tube), and the like, and is used for displaying commands, input data, and the status of processing described later. The communication device 27 executes communication with the second communication device 12 via the network 13. The communication device 27 of the second communication device 12 executes communication with the first communication device 11 via the network 13.
Next, the configuration of the communication device 27 will be described. FIG. 3 shows a block configuration diagram of the communication device 27. The communication device 27 is composed of an interface unit 31, a preprocessing unit 32, an encryption / decryption unit 33, a common data generation unit 34, an algorithm generation unit 35, a key generation unit 36, a communication unit 37, and a connection unit 38. The algorithm.
The interface unit 31 exchanges data between the bus 28 and the encryption / decryption unit 33. The interface unit 31 also has a function of sending data from the bus 28 to the common data generation unit 34 and sending data from the connection unit 38 to the bus 28. The preprocessing unit 32 cuts the transmission target data or the encrypted data received from the bus 28 via the interface unit 31 for each predetermined number of bits to generate the transmission target disconnection data or the encryption disconnection data. It has a function of sending this to the encryption / decryption unit 33. How to disconnect the transmission target data or the encrypted data will be described later. In this embodiment, the preprocessing unit 32 has a function of including dummy data, which is data unrelated to the transmission target data, in the transmission target data by a method as described later. When the encryption / decryption unit 33 receives the transmission target disconnection data or the encryption disconnection data from the preprocessing unit 32, encrypts the transmission target disconnection data when it is received, and receives the encryption disconnection data. Has the ability to decrypt it. The encryption / decryption unit 33 in this embodiment has a fixed number of reference bits, which is a processing unit when performing encryption / decryption processing. The reference bit number in this embodiment is 8 bits, but is not limited to this. Details of the encryption and decryption process will be described later. The common data generation unit 34 sequentially generates common data, which is data common to the first communication device 11 and the second communication device 12. In this embodiment, the common data generation unit 34 in the first communication device 11 and the second communication device 12 sequentially generates common data by making the common data in the same order the same. Also, the common data in this embodiment is a pseudo-random number, although not necessarily so. The generated common data is sent to the preprocessing unit 32, the algorithm generation unit 35, and the key generation unit 36. The algorithm generation unit 35 generates an algorithm based on the common data received from the common data generation unit 34. This algorithm is used when the encryption / decryption unit 33 performs the encryption process and the decryption process. The key generation unit 36 generates a key based on the common data received from the common data generation unit 34. The key is used by the encryption / decryption unit 33 when performing the encryption process and the decryption process. The communication unit 37 exchanges data with the network 13. The encrypted disconnection data generated by encrypting the transmission target disconnection data in the encryption / decryption unit 33 is connected by the connection unit 38 and sent to the communication device on the other side via the communication unit 37. Become. Further, the communication unit 37 receives the encrypted data from the communication device on the other side. This encrypted data will be sent from the communication unit 37 to the preprocessing unit 32. The connection unit 38 has a function of connecting the transmission target disconnection data generated by decrypting the encrypted disconnection data by the encryption / decryption unit 33 in the original order to form a set of transmission target data. ing. The data to be transmitted is sent to the interface unit 31, and is sent to the HDD 23, the CPU 21, or the like via the bus 28 as needed. The connection unit 38 also has a function of connecting the encryption disconnection data generated by encrypting the transmission target disconnection data by the encryption / decryption unit 33 to form a set of encrypted data. .. This encrypted data is sent to the communication unit 37, and is sent from the communication unit 37 to the communication device on the other side. The connection unit 38 does not have to have a function of connecting the encrypted disconnection data generated by encrypting the transmission target disconnection data by the encryption / decryption unit 33. In this case, the encrypted disconnection data is sequentially sent to the communication device on the other side in the order of encryption. When the connection unit 38 is such, the encrypted disconnect data can be sent directly to the communication unit 37 without passing through the connection unit 38.
Next, the flow of processing performed in this communication system will be described. Briefly explaining with reference to FIG. 4, the flow of processing performed in this communication system is as follows. First, the first communication device 11 encrypts the data to be transmitted to generate the encrypted data (S110). The first communication device 11 then sends the encrypted data to the second communication device 12 (S120). Next, the second communication device 12 that has received the encrypted data decrypts the encrypted data and returns it to the data to be transmitted (S130). As described above, in the following description, the encrypted data is sent from the first communication device 11 to the second communication device 12, but the encrypted data is sent from the second communication device 12 to the first communication device 11 as described above. It is self-evident that the content of the process does not change even if the process is the opposite of the case.
First, the process of the above-mentioned S110 in which the first communication device 11 encrypts the data to be transmitted to generate the encrypted data will be described in detail with reference to FIG.
First, the data to be transmitted is read out. The data to be transmitted may be any data that needs to be transmitted from the first communication device 11 to the second communication device 12. In this embodiment, it is assumed that the data to be transmitted is recorded in the HDD 23. For example, when a command is input from the input device 25 to send the transmission target data to the second communication device 12, the CPU 21 reads the transmission target data from the HDD 23 and temporarily records it in, for example, the RAM 24. This data to be transmitted is transmitted from the RAM 24 to the preprocessing unit 32 via the bus 28 and the interface unit 31 in the communication device 27 (S1101).
In the preprocessing unit 32, the transmission target data is cut every predetermined number of bits and converted into transmission target cut data (S1102). The preprocessing unit 32 includes dummy data in the transmission target disconnection data as necessary. There may be one method of generating the transmission target disconnection data from the transmission target data, but in this embodiment, the transmission target disconnection data is generated from the transmission target data by one of the following three methods. It has become. A) The transmission target data is cut into a fixed number of bits shorter than the reference bit number to make the transmission target disconnection data, and all of the transmission target disconnection data whose number of bits is shorter than the reference bit number. When dummy data is included at a certain position B) The data to be transmitted is cut into a certain number of bits shorter than the reference number of bits to make the data to be transmitted, and all of them have more bits than the reference number of bits. When dummy data is included in each different position of the transmission target disconnection data that is shortened C) The transmission target data is cut to the same number of bits as or shorter than the reference bit number to make the transmission target disconnection data, and When dummy data is included in each of the transmission target disconnection data whose number of bits is shorter than the reference number of bits
Which of the three methods described above is used to generate the transmission target disconnection data from the transmission target data is determined by the common data generated by the common data generation unit 34.
Therefore, how the common data generation unit 34 generates the common data will be described first. When the interface unit 31 receives the data to be transmitted from the bus 28, the common data generation unit 34 receives the information from the interface unit 31. With this as an opportunity, the common data generation unit 34 starts generating common data. In this embodiment, the common data generation unit 34 generates common data each time the transmission target data is received by the interface unit 31. Although not limited to this, the common data in this embodiment is an 8-by-8 matrix (X).
The common data generation unit 34 does not necessarily have to do so, but in this embodiment, the common data is continuously generated as a non-linear transition. In order to continuously generate common data so as to make a non-linear transition, for example, (1) the process of generating common data includes the operation of the power of the past common data, and (2) the process of generating common data. , Including the multiplication of two or more common data in the past, or combining (1) and (2).
In this embodiment, the common data generation unit 34 uses the 01st solution (X) as the initial matrix.<sub>01</sub>) And the 02nd solution (X)<sub>02</sub>) As a predetermined one (for example, the 01st solution and the 02nd solution are recorded in a predetermined memory). The common data generation unit 34 substitutes this initial matrix into the solution generation algorithm and substitutes the first solution (X).<sub>1</sub>) Is generated as follows. First solution (X<sub>1</sub>) = X<sub>02</sub>X<sub>01</sub>+ α (α = 8-by-8 matrix) This is the first common data generated. Next, when the interface unit 31 receives the data to be transmitted from the bus 28, the common data generation unit 34 receives the second solution (X).<sub>2</sub>) Is generated as follows. Second solution (X<sub>2</sub>) = X<sub>1</sub>X<sub>02</sub>+ α Similarly, every time the interface unit 31 receives the data to be transmitted from the bus 28, the common data generation unit 34 sets the third solution, the fourth solution, ... the Nth solution as follows. Generate in. Third solution (X<sub>3</sub>) = X<sub>2</sub>X<sub>1</sub>+ α 4th solution (X<sub>4</sub>) = X<sub>3</sub>X<sub>2</sub>+ α: Nth solution (X<sub>N</sub>) = X<sub>N-1</sub>X<sub>N-2</sub>+ α The solution (that is, common data) generated in this way is sent to the preprocessing unit 32 and the algorithm generation unit 35, and is held by the common data generation unit 34. In this embodiment, the Nth solution (X)<sub>N</sub>) To generate the N-1th solution (X)<sub>N-1</sub>) And N-2 solution (X)<sub>N-2</sub>), In short, use the two solutions generated just before that. Therefore, the common data generator 34 must hold the two most recent solutions generated in the past (or if someone else does not hold these two solutions) in order to generate a new solution. (Do not). Conversely, solutions older than the last two solutions generated in the past are no longer used to generate new solutions. Therefore, in this embodiment, the past two solutions are always held by the common data generation unit 34, but the new solution is generated and becomes the latest third solution. The solution that was the solution is deleted from a predetermined memory or the like in which the solution was recorded. The solution generated in this way becomes a chaotic one with a non-linear transition and becomes a pseudo-random number.
To cause a non-linear transition, when finding the Nth solution, the above-mentioned Nth solution (X)<sub>N</sub>) = X<sub>N-1</sub>X<sub>N-2</sub>In addition to using the formula + α, it is conceivable to use the following formula. For example, (a) Nth solution (X)<sub>N</sub>) = (X<sub>N-1</sub>)<sup>P</sup>(b) Nth solution (X<sub>N</sub>) = (X<sub>N-1</sub>)<sup>P</sup>(X<sub>N-2</sub>)<sup>Q</sup>(X<sub>N-3</sub>)<sup>R</sup>(X<sub>N-4</sub>)<sup>S</sup>(c) Nth solution (X<sub>N</sub>) = (X<sub>N-1</sub>)<sup>P</sup>+ (X<sub>N-2</sub>)<sup>Q</sup>And so on. Note that P, Q, R, and S are predetermined constants, respectively. Further, the common data generation unit 34 has two initial matrices when the mathematical formula (a) or (c) is used, and four initial matrices when the mathematical formula (b) is used. Further, although the above-mentioned α is a constant, it can also be used as specific changing environmental information. This environmental information is information that naturally occurs one after another with the passage of time and can be commonly acquired even at remote locations. For example, information determined based on the weather in a specific region or broadcast at a specific time. Information that is determined based on the content of the television broadcast of a certain television station, information that is determined based on the results of a specific sport, and so on. If the above-mentioned α is created one after another from such environmental information to generate common information, the confidentiality of communication can be further enhanced. Of course, it is also possible to add α (which may be generated from environmental information) to the right side of the above-mentioned mathematical expressions (a) to (c).
As described above, the preprocessing unit 32 that has received the common data (that is, the above-mentioned solution) determines which of the above-mentioned A), B), and C) to generate the transmission target disconnection data accordingly. decide. In this embodiment, although not limited to this, the sum of the numbers constituting the 8-by-8 matrix, which is common data, is divided by 3, and when the remainder is 0, the method A) is used. When the remainder is 1, the method B) is used, and when the remainder is 2, the method C) is used to generate the disconnection data to be transmitted. When generating the transmission target disconnection data by the method of A), the preprocessing unit 32 processes the transmission target data received from the interface unit 31 in order from the beginning, and has a fixed number of bits shorter than the reference bit number (this implementation). In the form, the transmission target disconnection data is generated by disconnecting at 7 bits). Further, the preprocessing unit 32 embeds dummy data at a fixed position of the transmission target disconnection data. The position in the transmission target disconnection data in which the dummy data is embedded may be changed or may be fixed. In the latter case, the position where the dummy data is embedded can be, for example, the beginning or end of the cut data to be transmitted, or a predetermined intermediate position such as the second bit or the third bit. This dummy data may be any data as long as it is irrelevant to the data to be transmitted. For example, processing such as always embedding the data 0, embedding the data 1 or alternately embedding the data 1 and 0 can be considered. As yet another example, it is possible to determine what kind of dummy data is to be embedded based on the above-mentioned common data. For example, divide the sum of the numbers that make up the 8-by-8 matrix, which is common data, by 9, and when the remainder is 0, 0, 0, 0, 0 ... and 0 are continuous, and that When the remainder is 1, insert 1 every other 0, 1, 0, 1 ..., and when the remainder is 2, 0, 0, 1, 0, 0, 1 ... and 2 Insert 1 every other, and similarly, when the remainder is 3, every 3th, when the remainder is 4, every 4th, ... When the remainder is 9, it can be like inserting 1 every 9th. When generating the transmission target disconnection data by the method B), the preprocessing unit 32 cuts the transmission target data into a fixed number of bits (for example, 7 bits) shorter than the reference bit number and transmits the data. In addition to making the target disconnection data, dummy data is included at different positions of the transmission target disconnection data in which the number of bits is shorter than the reference bit number. In this case, the position where the dummy data is embedded may be fixed, or the 1st bit, the 2nd bit, the 3rd bit ... the 8th bit, the 1st bit, the 2nd bit, respectively, for each of the cut data to be transmitted. It may change regularly, such as moving in the order of ..8th bit, or it may change randomly. When the position where the dummy data is embedded changes randomly, for example, the position where the dummy data is embedded may be determined based on the common data. As a method of determining the reference number of bits to be embedded in the dummy data based on the common data, for example, the sum of the numbers constituting the 8-by-8 matrix, which is the common data, is divided by 8 and the remainder is 0. When, dummy data is embedded alternately at the beginning and end of every other disconnection data to be transmitted. When the remainder is 1, dummy data is embedded at the beginning and dummy data is embedded at the end. Make sure that the transmission target disconnection data is every two. When the remainder is 2, there are three transmission target disconnection data with dummy data embedded at the beginning and three transmission target disconnection data with dummy data embedded at the end. Try to be every other, ... When the remainder is 7, the transmission target disconnection data with dummy data embedded at the beginning and the transmission target disconnection data with dummy data embedded at the end should be processed so that they are every eight. Can be done. It is also possible to move the position where the dummy data is embedded without fixing the position as in the beginning and the end. When the transmission target data is generated by the method of C), the transmission target data is cut to the same number of bits as or shorter than the reference bit number. This cutting can be performed by cutting the data to be transmitted to a random length shorter than 8 bits. For example, the sum of the numbers constituting the 8-by-8 matrix, which is common data, is added. Divide by 8, and when the remainder is 0, the beginning part of the data to be transmitted at that time is cut by 8 bits, and when the remainder is 1, the beginning part of the data to be transmitted at that time is cut by 1 bit. When the remainder is 2, the beginning part of the data to be transmitted at that time is cut by 2 bits, and when the remainder is 7, the beginning part of the data to be transmitted at that time is cut by 7 bits. can do. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation. When the remainder is 7, the beginning part of the data to be transmitted at that time can be cut by 7 bits. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation. When the remainder is 7, the beginning part of the data to be transmitted at that time can be cut by 7 bits. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation. When the remainder is 7, the beginning part of the data to be transmitted at that time can be cut by 7 bits. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation. When the remainder is 7, the beginning part of the data to be transmitted at that time can be cut by 7 bits. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation. When the remainder is 7, the beginning part of the data to be transmitted at that time can be cut by 7 bits. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation. When the remainder is 7, the beginning part of the data to be transmitted at that time can be cut by 7 bits. Further, the preprocessing unit 32 embeds dummy data in each of the transmission target disconnection data generated by this, in which the transmission target disconnection data has a bit number shorter than the reference bit number. In this case, the embedding position of the dummy data may be a specific position such as the beginning or the end, or may be a changing predetermined position specified by the common data, for example. In any case, the transmission target disconnection data generated in this way is streamed to the encryption / decryption unit 33 in the order of generation.
In parallel with the generation of the transmission target disconnection data, the algorithm generation unit 35 generates an algorithm used when encrypting the transmission target disconnection data. The algorithm generation unit 35 generates an algorithm based on common data. In this embodiment, the algorithm generation unit 35 generates the algorithm as follows. The algorithm in this embodiment is "when the transmission target disconnection data, which is 8-bit data, is a matrix Y of 1 row and 8 columns, the matrix X of 8 rows and 8 columns, which is common data, is raised to the ath power, and then the clock. It is calculated by multiplying a matrix rotated by n × 90 ° around it by Y. Here, a may be a predetermined constant, but in this embodiment, it is a number that changes based on common data. That is, the algorithm in this embodiment changes based on common data. For example, a is the remainder when the number obtained by adding all the elements of the matrix included in the common data, which is a matrix of 8 rows and 8 columns, is divided by 5 (however, if the remainder is 0). It can be defined as (a = 1). Further, n mentioned above is a predetermined number determined by the key. If the number of keys is constant, n is fixed, but as explained below, the keys change based on common data. That is, in this embodiment, this n also changes based on the common data. However, the algorithm can be determined as something else. In this embodiment, the algorithm generation unit 35 generates an algorithm each time it receives common data from the common data generation unit 34, and sends it to the encryption / decryption unit 33.
In parallel with the generation of the transmission target disconnection data, the key generation unit 36 generates the key used when encrypting the transmission target disconnection data. The key generation unit 36 generates a key based on common data. In this embodiment, the key generation unit 36 generates the key as follows. The key in this embodiment is a number obtained by adding all the elements of the matrix included in the common data, which is a matrix of 8 rows and 8 columns. Therefore, the key changes based on common data in this embodiment. The key can also be determined as something else. In this embodiment, the key generation unit 36 generates a key each time it receives common data from the common data generation unit 34, and sends the key to the encryption / decryption unit 33.
The encryption / decryption unit 33 encrypts the transmission target disconnection data received from the preprocessing unit 32 based on the algorithm received from the algorithm generation unit 35 and the key received from the key generation unit 36 (S1103). As described above, the algorithm is "when the transmission target disconnection data, which is 8-bit data, is a matrix Y of 1 row and 8 columns, the matrix X of 8 rows and 8 columns, which is common data, is multiplied by a to the power of a. It is calculated by multiplying a matrix rotated clockwise by n × 90 ° by Y. The key n is the number as described above. For example, when a is 3 and n is 6, the 8-by-8 matrix obtained by squaring X is rotated clockwise by 6 × 90 ° = 540 °, which is 8 obtained. Encryption is performed by multiplying the row / 8-column matrix by the transmission target disconnection data. The data generated by this is the encrypted disconnection data.
The encrypted disconnection data is sent to the connection unit 38. The connection unit 38 connects the encrypted disconnection data in a batch and generates the encrypted data (S1104). The order of the encrypted cut data at this time corresponds to the order of the original cut data to be transmitted.
As described above, first, the process of S110 in which the first communication device 11 encrypts the data to be transmitted and generates the encrypted data is completed.
The encrypted data is sent to the communication unit 37, and is sent to the second communication device 12 via the network 13.
The second communication device 12 that has received the encrypted data executes the process of S130 that decrypts the encrypted data and returns it to the data to be transmitted. Hereinafter, the decoding process will be described in detail.
The encrypted data sent to the second communication device 12 is received by the communication unit 37 of the second communication device 12 (S1201). The communication unit 37 sends this encrypted data to the preprocessing unit 32.
The preprocessing unit 32 cuts the received encrypted data for each predetermined number of bits to generate the encrypted cut data (S1202). When the encrypted data is disconnected and the encrypted data is generated, the preprocessing unit 32 performs the reverse processing performed by the connection unit 38 of the first communication device 11. That is, the encrypted data is cut every 8 bits from the beginning and divided into a plurality of encrypted cut data.
Next, the encrypted disconnection data is sent to the encryption / decryption unit 33, where it is decrypted and used as the transmission target disconnection data (S1203). Decryption is executed as the reverse process performed by the encryption / decryption unit 33 in the first communication device 11. Therefore, the second communication device 12 requires the algorithm and the key required for encryption by the first communication device 11.
The algorithm and key used for decryption are generated in the second communication device 12. The mechanism will be explained. The information that the communication unit 37 of the second communication device 12 has received the encrypted data is sent from the communication unit 37 to the common data generation unit 34. The common data generation unit 34 generates common data each time it receives this information, triggered by receiving this information. The common data generation performed by the common data generation unit 34 of the second communication device 12 is performed through the same process as that performed by the common data generation unit 34 of the first communication device 11. The common data generation unit 34 of the second communication device 12 has the same initial matrix and solution generation algorithm as those of the common data generation unit 34 of the first communication device 11. Therefore, the common data generated by the second communication device 12 is the same as the common data generated by the first communication device 11 when compared with each other in the same order of generation. The generated common data is sent from the common data generation unit 34 to the preprocessing unit 32, the algorithm generation unit 35, and the key generation unit 36. The algorithm generation unit 35 generates an algorithm each time it receives common data based on the received common data. The process in which the algorithm generation unit 35 of the second communication device 12 generates an algorithm is the same as the process in which the algorithm generation unit 35 of the first communication device 11 generates an algorithm. The generated algorithm is sent from the algorithm generation unit 35 to the encryption / decryption unit 33. Each time the key generation unit 36 receives the common data, the key generation unit 36 generates a key based on the received common data. The process in which the key generation unit 36 of the second communication device 12 generates the key is the same as the process in which the key generation unit 36 of the first communication device 11 generates the key. The generated key is sent from the key generation unit 36 to the encryption / decryption unit 33. By the way, in this communication system, new common data is generated in the first communication device 11 every time encryption is performed in the first communication device 11, and second communication is performed every time decryption is performed in the second communication device 12. New common data is generated in device 12. Further, as described above, the common data generated by the second communication device 12 is the same as the common data generated by the first communication device 11 when compared with each other in the same order of generation. .. Therefore, the common data generated when encrypting the transmission target data of the first communication device 11 and the algorithms and keys generated based on the common data all use the common data and the common data. When decrypting the encrypted data generated using the algorithm and key generated in the above, the common data generated by the second communication device 12 and the algorithm and key generated based on the common data , Always match. This situation is the same when the second communication device 12 performs encryption and the first communication device 11 performs decryption.
As described above, the encryption / decryption unit 33 performs the decryption process using the algorithm received from the algorithm generation unit 35. More specifically, the encryption / decryption unit 33 uses common data when the algorithm received from the algorithm generation unit 35 (When the transmission target disconnection data, which is 8-bit data, is a matrix Y of 1 row and 8 columns, Based on the definition), what is obtained by multiplying a matrix of 8 rows and 8 columns to the power of a and then rotated clockwise by n × 90 ° by Y is the encrypted cut data. Then, the algorithm for performing the decryption process (when the encrypted cut data is viewed as the 1-by-8 matrix Z, the 8-by-8 matrix X, which is the common data, is raised to the a-th power, and then clockwise. The definition) is generated by multiplying the inverse matrix of the matrix rotated by n × 90 ° by Y to obtain the data to be transmitted, and the key is used to perform the operation according to the above definition. By doing so, the decryption process is performed. In this way, the encryption / decryption unit 33 decrypts the encryption disconnection data streamed from the preprocessing unit 32 one after another, and generates the transmission target disconnection data.
Next, the encryption / decryption unit 33 removes dummy data from the transmission target disconnection data, if necessary (S1204). As described above, the common data generated by the common data generation unit 34 is sent to the preprocessing unit 32. This common data was used by the preprocessing unit 32 of the first communication device 11 to determine how the dummy data was embedded in the transmission target disconnection data. That is, the common data held by the preprocessing unit 32 of the second communication device 12 at that time has been decrypted (or decrypted) by the encryption / decryption unit 33 of the second communication device 12. Or, to show how the dummy data was embedded in the encrypted disconnection data (more accurately, the transmission target disconnection data before the encryption disconnection data was encrypted). It is a thing. The preprocessing unit 32 sends information to the encryption / decryption unit 33 about where the dummy data is embedded in the transmission target disconnection data decrypted by the encryption / decryption unit 33. Using this, the encryption / decryption unit 33 removes the dummy data from the transmission target disconnection data.
The transmission target disconnection data generated in this way is sent to the connection unit 38. The connection unit 38 connects the received transmission target disconnection data together and returns the transmission target data in the original state before being encrypted by the first communication device 11 (S1205). In this way, the process of S130 in which the second communication device 12 decrypts the encrypted data and returns it to the data to be transmitted is completed.
The generated data to be transmitted is sent from the connection unit 38 to the interface unit 31, is sent to, for example, the HDD 23 via the bus 28, and is stored there.
<< Modification example >> In the communication system described above, the common data generation unit 34 generates common data every time the interface unit 31 receives the data to be transmitted and every time the communication unit 37 receives the encrypted data. It was supposed to be. In this case, all the transmission target disconnection data generated from one transmission target data are encrypted by the same algorithm. Instead, the common data generation unit 34 receives every time the encryption / decryption unit 33 receives the transmission target disconnection data, and every time the encryption / decryption unit 33 receives the encryption disconnection data. It may be designed to generate common data. In this case, the transmission target disconnection data generated from one transmission target data is encrypted by a different algorithm and key.
In such a modification, when performing encryption, common data, an algorithm, and a key are generated as follows. First, a case where encryption is performed will be described. When the interface unit 31 receives the data to be transmitted, the information to that effect is transmitted from the interface unit 31 to the common data generation unit 34. The common data generation unit 34 that has received this generates common data in the same manner as in the case of the above-described embodiment. This common data is sent to the preprocessing unit 32, the algorithm generation unit 35, and the key generation unit 36. The preprocessing unit 32 that has received the common data cuts the transmission target data and starts generating the transmission target disconnection data as in the case of the above-described embodiment. On the other hand, the algorithm generation unit 35 generates an algorithm based on the received common data, and sends the generated algorithm to the encryption / decryption unit 33. Further, the key generation unit 36 generates a key based on the received common data, and sends the generated key to the encryption / decryption unit 33. The encryption / decryption unit 33 encrypts the received transmission target disconnection data with the received algorithm and key, and generates the first encryption disconnection data. Next, the common data generation unit 34 generates common data before the second transmission target disconnection data from the preprocessing unit 32 is sent to the encryption / decryption unit 33, and generates the key with the algorithm generation unit 35. Send to department 36. The algorithm generation unit 35 receives this and generates an algorithm different from the one used to generate the first encrypted decryption data, and sends this to the encryption / decryption unit 33. Similarly, the key generation unit 36 also generates a key different from the first key and sends this to the encryption / decryption unit 33. The encryption / decryption unit 33 uses this algorithm and the key to generate the second encrypted disconnection data using the second transmission target disconnection data. By repeating this, different encryption is performed on each transmission target disconnection data. In this modification, the second and subsequent common data are sent only to the algorithm generation unit 35 and the key generation unit 36, but the second and subsequent common data are also sent to the preprocessing unit 32. You can also do it. In this case, the method of generating the transmission target disconnection data can be changed for each transmission target disconnection data. Next, a case where decoding is performed will be described. When the communication unit 37 receives the encrypted data, information to that effect is sent from the communication unit 37 to the common data generation unit 34. The common data generation unit 34 that has received this generates common data in the same manner as in the case of the above-described embodiment. This common data is sent to the preprocessing unit 32, the algorithm generation unit 35, and the key generation unit 36. The preprocessing unit 32 that has received the common data generates information about how the transmission target disconnection data is generated in the same manner as in the above embodiment, and sends this to the encryption / decryption unit 33. And send. On the other hand, the algorithm generation unit 35 generates an algorithm based on the received common data, and sends the generated algorithm to the encryption / decryption unit 33. The key generation unit 36 generates a key based on the received common data, and sends the generated key to the encryption / decryption unit 33. This algorithm and key are the same as the algorithm and key used to encrypt the cut data to be transmitted. Further, the preprocessing unit 32 sends the encryption / decryption data generated by cutting the encrypted data to the encryption / decryption unit 33, as in the case of the above-described embodiment. The encryption / decryption unit 33 decrypts the received encryption disconnection data by the decryption algorithm generated by using the accepted algorithm, and generates the first transmission target disconnection data. In addition, the encryption / decryption unit 33 removes dummy data from the generated transmission target disconnection data based on the above-mentioned information on how the received transmission target disconnection data is generated. Next, the common data generation unit 34 generates the next common data before the second transmission target disconnection data is sent from the preprocessing unit 32 to the encryption / decryption unit 33, and sends it to the algorithm generation unit 35. send. The algorithm generation unit 35 receives this and generates an algorithm different from the one used to generate the first transmission target disconnection data, and sends this to the encryption / decryption unit 33. This algorithm is the same as the algorithm used when encrypting the transmission target disconnection data. The key generation unit 36 generates a key different from the one used for receiving the common data and generating the first transmission target disconnection data, and sends this to the encryption / decryption unit 33. This key is the same as the key used to encrypt the transmission target disconnection data. The encryption / decryption unit 33 decrypts the second encrypted disconnection data by using this algorithm and the key, and generates the second transmission target disconnection data. Also, dummy data is removed in the same manner as in the above case. By repeating this, each encrypted disconnection data is decrypted with a different algorithm and key to generate transmission target disconnection data one after another. When encrypting, if the method of generating the transmission target disconnection data is changed for each transmission target disconnection data by sending the second and subsequent common data to the preprocessing unit 32, decryption is performed. Even when doing so, the second and subsequent common data are also sent to the preprocessing unit 32. As a result, the preprocessing unit 32 generates information about how the transmission target disconnection data is generated for each of the encrypted disconnection data. The above-mentioned information about how the transmission target disconnection data generated in this way is generated is encrypted / decrypted each time the encryption / decryption unit 33 decrypts the encrypted disconnection data. It is sent to the conversion department 33. Using this information, the encryption / decryption unit 33 reliably removes the dummy data embedded in each of the transmission target disconnection data by different methods.
<figref num="1">The figure which shows the whole structure of the communication system of embodiment.</figref><figref num="2">The figure which shows the hardware configuration of the 1st communication apparatus and the 2nd communication apparatus included in the communication system shown in FIG.</figref><figref num="3">The block diagram which shows the structure of the communication device of the 1st communication device and the 2nd communication device included in the communication system shown in FIG.</figref><figref num="4">The flow chart which shows the flow of processing executed in the communication system shown in FIG.</figref><figref num="5">The flow chart which shows the flow of the encryption processing executed by the 1st communication device of the communication system shown in FIG.</figref><figref num="6">The flow chart which shows the flow of the decoding process executed by the 2nd communication device of the communication system shown in FIG.</figref>
Code description
11 1st communication device 12 2nd communication device 13 Network 31 Interface part 32 Preprocessing part 33 Encryption / decryption part 34 Common data generation part 35 Algorithm generation part 36 Key generation part 37 Communication part 38 Connection part
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2020120297A | Cited by | Japan | Search report |
| WO2008126913A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2020153480A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2013236397A | Cited by | Japan | Examiner |
| JP2009177684A | Cited by | Japan | Examiner |
| WO2009096588A1 | Cited by | World Intellectual Property Organization (WIPO) | Search report |
| JP2000261427A | Cites | Japan | Search report |
| JPH0575596A | Cites | Japan | Examiner |
| JPH06216897A | Cites | Japan | Search report |
| JPH09116532A | Cites | Japan | Examiner |
| JPH0918469A | Cites | Japan | Examiner |
| JPH10242956A | Cites | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2005003259 | Japan | A | |
| JP20050003259 | – | – | – |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Transfer of reconsideration by examiner before appeal (zenchi)AppealA911 | A911 | |
| Written amendmentA521 | A521 | |
| Notification of change in applicantA711 | A711 | |
| Decision of refusalA02 | A02 | |
| Notification of reasons for refusalA131 | A131 | |
| Notification of resignation of power of attorneyRD04 | RD04 | |
| Notification of acceptance of power of attorneyRD02 | RD02 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2006191508
- Publication, DOCDB
- 2006191508
- Publication, EPODOC
- JP2006191508
- Application
- 3259
- Application, DOCDB
- 2005003259
- Application, EPODOC
- JP20050003259
Titles2
- Japanese
- 通信システム、通信方法
- English
- Communication system, communication method
Classification
- CPC, 4
- H04L9/0891
- H04L9/08
- H04L2209/08
- G09C1/04
- IPC, 1
- H04L9 10