JP2006246543A

Cryptographic system and method with key escrow function

Abstract

Problem to be solved.To provide a commercial key escrow system that operates by a method of inspiring credit and confidence of the users by using the algorithm disclosed, and solving the problem brought up by national security and by request from the police.

Solution.A cryptographic system and method with a key escrow function that uses a method for dividing user's a secret encryption key into components and for transmitting those components to a trusted agent chosen by the specified user and a method of receiving a key escrow and an escrow authentication to be executed by a chip device for self-certification are also applied to a more generalized case of registering a trusted device 150 with a trusted third party and receiving the authorization enabling the device to communicate with other trusted devices from that party. The method comprises a step of escrowing a plurality of asymmetric encryption keys to be used by a plurality of users in a trusted escrow center 153; a step of confirming the plurality of keys in the escrow center; and a step of authenticating the authorities of the plurality of keys at the time of confirming.

Copyright (C)2006,JPO&NCIPI

Term

Term ended

Projected expiry passed 20 June 2026, 0.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

12 claims: 12 independent, 0 dependent

  1. 1
    In a method of performing trusted communication that can be confirmed between a large number of users, a step of depositing a large number of secret asymmetric encryption keys used by the large number of users to a trusted deposit center and a large number of the deposit centers. A step of confirming each of the keys, a step of proving each of the large number of keys according to the confirmation result, and a step of initiating communication between the large number of users using each of the large number of keys after the verification. And how to provide. 多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザにより使用される多数の秘密非対称暗号化キーを信用された寄託センタに寄託するステップと、 前記寄託センタで前記多数のキーの各々を確認するステップと、 確認結果に応じて前記多数のキーの各々を証明するステップと、 前記証明後前記多数のキーの各々を利用して前記多数のユーザ間の通信を開始するステップと、 を具備する方法。
  2. 2
    In a method of performing trusted communication that can be confirmed between a large number of users, a step of depositing a secret asymmetric encryption key related to the large number of users to a trusted deposit center and a step of confirming the key at the deposit center. And the step of proving the key according to the confirmation result, and the safe from the user who starts the communication according to the key proof of both the user who starts the communication and the user who receives the communication to the user who receives the communication. A step of initiating communication and a method of providing. 多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザに関連する秘密非対称暗号化キーを信用された寄託センタに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 通信を開始するユーザと通信を受信するユーザの両者のキーの証明に応じて通信を開始するユーザから通信を受信するユーザへの安全な通信を開始するステップと、 を具備する方法。
  3. 3
    A step of depositing a secret asymmetric encryption key associated with a large number of users to a trusted depository in a method of performing trusted communication that can be seen among a large number of users with selective non-party access, each of the above users. Is associated with at least one key and at least a selective first non-party to access user communications, and the step of confirming the key at the deposit center and the step of proving the key according to the confirmation result. A method comprising, initiating a credit communication from the sending user to the recipient to allow access to the communication by the first non-party. 選択的な非当事者アクセスを伴い多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザに関連する秘密非対称暗号化キーを信用された寄託センタに寄託するステップ、前記各ユーザは少なくとも1つのキーとユーザ通信にアクセスする少なくとも選択的な第1の非当事者に関連付けられ、と、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 第1の非当事者による通信へのアクセスを許可するように送信ユーザから受信者への信用通信を開始するステップと、 を具備する方法。
  4. 4
    The step of depositing the secret asymmetric encryption key associated with each of the large number of users to at least one of the large number of deposit centers in a method of making a trusted communication that can be confirmed among a large number of users with access by a third party. The communication includes a step of confirming the key at the deposit center, a step of proving the key according to the confirmation result, and information for reproducing the key of the user who starts the communication and the key of the receiving user. A method comprising:initiating a trusted communication from the initiating user to the receiving user. 第3者のアクセスを伴い多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザの各々に関連する秘密非対称暗号化キーを多数の寄託センタの少なくとも1つに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 通信を開始するユーザのキーと受信ユーザのキーを再生するための情報を含み、通信を開始するユーザから受信ユーザヘの信用された通信を開始するステップと、 を具備する方法。
  5. 5
    In a method of performing trusted communication that can be confirmed among a large number of users, a step of depositing a secret asymmetric encryption key associated with each of the large number of users to a deposit center and a step of confirming the key at the deposit center. , The step of proving the key according to the confirmation result, and the step of starting the communication from the user who starts the communication to the receiving user when the credit device of the user who starts the communication confirms the key proof of the transmitting user and the receiving user. How to provide ,. 多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザの各々に関連する秘密非対称暗号化キーを寄託センタに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 通信を開始するユーザの信用装置が送信ユーザと受信ユーザのキーの証明を確認すると通信を開始するユーザから受信ユーザヘの通信を開始するステップと、 を具備する方法。
  6. 6
    In a method of performing trusted communication that can be confirmed between a large number of users, a step of depositing a secret asymmetric encryption key associated with each of the large number of users to a trusted deposit center and confirming the key at the deposit center. Communication from the user who starts communication to the receiving user when the key used for communication including access information that allows access to communication by a third party is proved, and the step of proving the key according to the confirmation result. Steps to start and how to provide. 多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザの各々に関連する秘密非対称暗号化キーを信用された寄託センタに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 第3者による通信へのアクセスを許可するアクセス情報を含む通信に使われるキーを証明すると通信を開始するユーザから受信ユーザヘの通信を開始するステップと、 を具備する方法。
  7. 7
    In a method of performing trusted communication that can be confirmed between a large number of users, a step of depositing a secret asymmetric encryption key associated with each of the large number of users to a trusted deposit center and confirming the key at the deposit center. Steps to certify the key according to the confirmation result and certify the trusted device associated with each user, and after certifying the key used for communication, and the trusted related to the user who initiates the communication. A method of starting communication from the user who starts communication to the receiving user after confirming the attributes of the device. 多数のユーザ間で確認できる信用された通信を行う方法において、 前記多数のユーザの各々に関連する秘密非対称暗号化キーを信用された寄託センタに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明し、各ユーザに関連する信用された装置を証明するステップと、 通信に使われるキーの証明後、および通信を開始するユーザに関連する信用された装置の属性の確認後、通信を開始するユーザから受信ユーザヘの通信を開始する方法。
  8. 8
    In a method of performing trusted stream-oriented communication that can be confirmed among a large number of users, a step of depositing an asymmetric encryption key associated with each of the large number of users to a trusted deposit center and the key at the deposit center. A confirmation step, a step of proving the key according to the confirmation result, and an encrypted stream-oriented communication from the user who starts the communication to the receiving user by using the encryption key of the user who starts the communication are started. The communication comprises (a) an initial packet containing access information permitting a third party's stream decryption and (b) a subsequent packet stream having information identifying a packet associated with the stream. However, a communication method in which at least one packet of the following and subsequent packets does not include the access information. 多数のユーザ間で確認できる信用されたストリーム指向通信を行う方法において、 前記多数のユーザの各々に関連する非対称暗号化キーを信用された寄託センタに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 通信を開始するユーザの暗号化キーを使用して通信を開始するユーザから受信ユーザヘの暗号化されたストリーム指向通信を開始するステップとを具備し、 前記通信は(a)第3者のストリーム復号を許可するアクセス情報を含む初期パケットと(b)ストリームに関連するパケットを識別する情報を有する次以降のパケットストリームとを有し、前記次以降のパケットの少なくとも1つのパケットは前記アクセス情報を含まない通信方法。
  9. 9
    In a method of performing trusted stream-oriented communication that can be confirmed among a large number of users, a step of depositing an asymmetric encryption key associated with each of the large number of users to a trusted depository center and the key at the depository center. The communication comprises a step of confirming, a step of proving the key according to the confirmation result, and a step of receiving the first encrypted stream-oriented communication from the user who starts the communication at the receiving user. Encrypted using the encryption key of the user initiating the communication, the communication identifies (a) initial packets containing access information permitting stream decryption by a third party and (b) packets associated with the stream. A communication method in which the next and subsequent packet streams having information are included, and at least one packet of the subsequent and subsequent packets of the first stream does not include the access information. 多数のユーザ間で確認できる信用されたストリーム指向通信を行う方法において、 前記多数のユーザの各々に関連する非対称暗号化キーを信用された寄託センタに寄託するステップと、 前記寄託センタで前記キーを確認するステップと、 確認結果に応じて前記キーを証明するステップと、 通信を開始するユーザからの第1の暗号化されたストリーム指向通信を受信ユーザにおいて受信するステップとを具備し、 前記通信は前記通信を開始するユーザの暗号化キーを用いて暗号化され、前記通信は(a)第3者のストリーム復号を許可するアクセス情報を含む初期パケットと(b)ストリームに関連するパケットを識別する情報を有する次以降のパケットストリームとを有し、前記第1のストリームの次以降のパケットの少なくとも1つのパケットは前記アクセス情報を含まない通信方法。
  10. 10
    In a method of performing trusted communication that can be confirmed among a large number of users, a step of performing secure communication within the hardware of the first user, the communication provides access information that allows a third party to access the communication. Including, and the step of signing the secure communication with a secret signature key unique to the signature chip of the first user's hardware, the signature key is the first before the hardware is passed to the first user. Embedded in the tamper-resistant memory associated with one user's signature chip, the step of certifying the secure communication, the proof corresponds to the secret signature key of the first user's signature chip. A method that includes a public signing key signed with a private signing key of a trusted authority, and a step of sending a secure communication to a second user. 多数のユーザ間で確認できる信用された通信を行う方法において、 第1のユーザのハードウェア内で安全な通信を行うステップ、該通信は該通信への第3者のアクセスを許可するアクセス情報を含む、と、 前記安全な通信に前記第1のユーザのハードウェアの署名チップに固有な秘密署名キーで署名するステップ、前記署名キーは前記ハードウェアが前記第1のユーザに渡される前に第1のユーザの署名チップに関連する耐タンパーメモリ内に埋め込まれている、と、 前記安全な通信に証明を付すステップ、該証明は前記第1のユーザの署名チップの秘密署名キーに対応し、信用された権威の秘密署名キーで署名された公開署名キーを含む、と、 安全な通信を第2のユーザに送信するステップと、 を具備する方法。
  11. 11
    In a method of secure communication in a system having at least one communicator and a message key played by a person who is not involved in the communication, the steps of giving each user a computer hardware device and the device user A step of registering a hardware device in a center according to control information determined by a separate device owner, and a step of certifying the hardware device and generating a certificate associated with the center, user, and hardware device. And a method of providing a step of initiating secure communication from a user who initiates communication using a message key to the receiving user so that the owner can access the communication. 少なくとも1つの通信者と、通信に関与する者ではない者によって再生されるメッセージキーとを有するシステムで安全な通信を行う方法において、 各ユーザにコンピュータハードウェア装置を与えるステップと、 装置ユーザとは別個の装置所有者により決定される制御情報に応じてハードウェア装置をセンタに登録するステップと、 前記ハードウェア装置を証明し、前記センタ、ユーザ、ハードウェア装置に関連する証明書を発生するステップと、 所有者が通信にアクセスできるようにメッセージキーを利用して通信を開始するユーザから受信ユーザへ安全な通信を開始するステップと、 を具備する方法。
  12. 12
    In a method of encrypting a communication in a system having a communicator and a message key played by a person who is not involved in the communication, a step of giving each user a computer hardware device having at least one device-related key. , The step of registering the hardware device in at least one selected center among many centers, the step of certifying the hardware device and generating the device certificate, and the communication using the message key. The communication start step comprises the step of initiating a secure communication from the initiating user to the receiving user, the communication including an access portion encrypted by the center key to reproduce the message key, and the communication initiating step is the first. An encryption method including a step of encrypting access information using a center key and a step of encrypting access information using a second center key. 通信者と、通信に関与する者ではない者によって再生されるメッセージキーとを有するシステムで通信を暗号化する方法において、 各ユーザに少なくとも1つの装置関連キーを有するコンピュータハードウェア装置を与えるステップと、 ハードウェア装置を多数のセンタの中の少なくとも1つの選択されたセンタに登録するステップと、 前記ハードウェア装置を証明し、装置の証明書を発生するステップと、メッセージキーを利用して通信を開始するユーザから受信ユーザへ安全な通信を開始するステップ、該通信はメッセージキーを再生するためにセンタのキーにより暗号化されたアクセス部分を含む、とを具備し、 該通信開始ステップは第1センタのキーを用いてアクセス情報を暗号化するステップと、第2センタのキーを用いてアクセス情報を暗号化するステップとを具備する暗号化方法。