Encrypted data transmitting apparatus, encryption key updating method, electronic device, program and recording medium
Abstract
Problem to be solved.To correctly decrypt encrypted data if an update of an encryption key occurs immediately after a transmitter transmits an encryption key to a receiver.
Solution.The next encrypted data is transmitted within a first predetermined time from the completion of transmission of the encrypted data, and authentication and key exchange are performed after a second predetermined time shorter than the first predetermined time elapses. If it is determined whether the encryption has been performed and the next encrypted data is not transmitted within the first predetermined time and the authentication and key exchange are not performed after the lapse of the second predetermined time, the end of the first predetermined time Occasionally, the encryption key is updated, and if the next encrypted data is not sent within the first predetermined time and authentication and key exchange are performed after the lapse of the second predetermined time, the time of authentication and key exchange The encryption key update means 306 for updating the encryption key is provided. Then, the updated encryption key is used when the first and second predetermined time counters 310 are authenticated and the key is exchanged when the transmission of the encrypted data is completed and after the second predetermined time has elapsed. Reset before sending. [Selection diagram] Fig. 1

Term
Term ended
Projected expiry passed 5 October 2025, 1 year ago.
- Priority and filed
- Published
- Projected expiry
- Today
8 claims: 4 independent, 4 dependent
- 1送信するコンテンツデータを暗号化するための暗号鍵を格納しておく暗号鍵格納手段と、 前記暗号鍵を用いて前記コンテンツデータを暗号化して、その暗号化データを送信する暗号化データ送信手段と、 暗号化データ受信装置との間で認証および鍵交換を行う認証・鍵交換手段と、 暗号化データの送信を完了してから第1の所定時間内に次の暗号化データが送信されたかどうか、および、暗号化データの送信を完了してから前記第1の所定時間よりも短い第2の所定時間経過した後であって前記第1の所定時間内に認証および鍵交換が行われたかどうかを判断し、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記認証および鍵交換が行われない場合には、前記第1の所定時間の終了時点で前記暗号鍵の更新を行い、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記認証および鍵交換が行われた場合には、前記認証および鍵交換の際に前記暗号鍵の更新を行う、暗号鍵更新手段とを備え、 前記第1の所定時間および前記第2の所定時間のカウンタは、暗号化データの送信が完了した際のタイミング、および、前記第2の所定時間経過した後であって前記第1の所定時間内に前記認証および鍵交換が行われた場合の前記認証および鍵交換の際の、更新された前記暗号鍵を送信する前のタイミングにリセットされる、暗号化データ送信装置。
- 2送信するコンテンツデータを暗号化するための暗号鍵、および前記暗号鍵の識別子を格納しておく暗号鍵格納手段と、 前記暗号鍵を用いて前記コンテンツデータを暗号化して、その暗号化データを送信する暗号化データ送信手段と、 暗号化データ受信装置との間で認証および鍵交換を行う認証・鍵交換手段と、 前記暗号化データ受信装置に前記識別子を送信する識別子送信手段と、 暗号化データの送信を完了してから第1の所定時間内に次の暗号化データが送信されたかどうか、および、暗号化データの送信を完了してから前記第1の所定時間よりも短い第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信されたかどうかを判断し、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信されない場合には、前記第1の所定時間の終了時点で前記暗号鍵および前記識別子の更新を行い、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信された場合には、前記識別子を送信する際に前記暗号鍵および前記識別子の更新を行う、暗号鍵更新手段とを備え、 前記第1の所定時間および前記第2の所定時間のカウンタは、暗号化データの送信が完了した際のタイミング、および、前記第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信された場合の、更新された前記識別子を送信する前のタイミングにリセットされる、暗号化データ送信装置。
- 3暗号鍵を用いてコンテンツデータを暗号化して、その暗号化データを送信する暗号化データ送信ステップと、 暗号化データ受信装置との間で認証および鍵交換を行う認証・鍵交換ステップと、 暗号化データの送信を完了してから第1の所定時間内に次の暗号化データが送信されたかどうか、および、暗号化データの送信を完了してから前記第1の所定時間よりも短い第2の所定時間経過した後であって前記第1の所定時間内に認証および鍵交換が行われたかどうかを判断し、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記認証および鍵交換が行われない場合には、前記第1の所定時間の終了時点で前記暗号鍵の更新を行い、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記認証および鍵交換が行われた場合には、前記認証および鍵交換の際に前記暗号鍵の更新を行う、暗号鍵更新ステップと、 暗号化データの送信が完了した際のタイミング、および、前記第2の所定時間経過した後であって前記第1の所定時間内に前記認証および鍵交換が行われた場合の前記認証および鍵交換の際の、更新された前記暗号鍵を送信する前のタイミングに、前記第1の所定時間および前記第2の所定時間のカウンタをリセットするカウンタリセットステップとを備えた、暗号化鍵更新方法。
- 4暗号鍵を用いてコンテンツデータを暗号化して、その暗号化データを送信する暗号化データ送信ステップと、 暗号化データ受信装置との間で認証および鍵交換を行う認証・鍵交換ステップと、 前記暗号化データ受信装置に前記暗号鍵の識別子を送信する識別子送信ステップと、 暗号化データの送信を完了してから第1の所定時間内に次の暗号化データが送信されたかどうか、および、暗号化データの送信を完了してから前記第1の所定時間よりも短い第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信されたかどうかを判断し、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信されない場合には、前記第1の所定時間の終了時点で前記暗号鍵の更新を行い、前記第1の所定時間内に前記次の暗号化データが送信されない場合で前記第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信された場合には、前記識別子を送信する際に前記暗号鍵および前記識別子の更新を行う、暗号鍵更新ステップと、 暗号化データの送信が完了した際のタイミング、および、前記第2の所定時間経過した後であって前記第1の所定時間内に前記識別子が送信された場合の、更新された前記識別子を送信する前のタイミングに、前記第1の所定時間および前記第2の所定時間のカウンタをリセットするカウンタリセットステップとを備えた、暗号化鍵更新方法。
- 5請求項1または2に記載の暗号化データ送信装置を備えた電子機器。
- 6請求項3に記載の暗号化鍵更新方法の、コンテンツデータを暗号化して送信する前記暗号化データ送信ステップ、認証および鍵交換を行う前記認証・鍵交換ステップ、前記暗号鍵の更新を行う前記暗号鍵更新ステップ、前記第1の所定時間および前記第2の所定時間のカウンタをリセットする前記カウンタリセットステップ、をコンピュータに実行させるためのプログラム。
- 7請求項4に記載の暗号化鍵更新方法の、コンテンツデータを暗号化して送信する前記暗号化データ送信ステップ、認証および鍵交換を行う前記認証・鍵交換ステップ、識別子を送信する前記識別子送信ステップ、前記暗号鍵の更新を行う前記暗号鍵更新ステップ、前記第1の所定時間および前記第2の所定時間のカウンタをリセットする前記カウンタリセットステップ、をコンピュータに実行させるためのプログラム。
- 8請求項6または7に記載のプログラムを記録した記録媒体であって、コンピュータにより処理可能な記録媒体。
Independent claims8
101 paragraphs, as filed
The present invention relates to an encrypted data transmission device, an encryption key update method, and an electronic device used when performing encrypted data transmission.
Conventionally, as a method of updating this type of encryption key, there is an update of the encryption key (Kx) defined in the DTCP standard (Digital Transmission Content Protection standard), for example, the one described in Patent Document 1. there were.
FIG. 5 shows a block diagram of the encrypted data transmission / reception system described in Patent Document 1.
The encrypted data transmitting device 400 is connected to the encrypted data receiving device 401 via Ethernet (registered trademark) 419. From the encrypted data receiving device 401, the authentication / key exchange request, the encryption key identifier request, and the content transmission request are transmitted to the request analysis control unit 416 via the interface unit 412 of the encrypted data transmitting device 400. The request analysis control unit 416 manages the generation / update of the encryption key Kx415 used for encrypting the content data, controls the authentication and key exchange in response to the request from the encrypted data receiving device 401, and also encrypts. Controls the return of the encryption key identifier in response to the same request from the encrypted data receiving device 401.
Hereinafter, the operation when the encrypted data transmitting device 400 receives various requests from the encrypted data receiving device 401 will be described.
The encryption key generation unit 425 of the request analysis control unit 416 generates the encryption key Kx415, destroys / updates the encryption key Kx415, and assigns the encryption key identifier 413 in synchronization with the destruction / update. These encryption key Kx415 and encryption key identifier 413 are stored in the encryption key register 414.
When the request analysis control unit 416 receives a request for content data from the encrypted data receiving device 401, the analysis unit 421 analyzes the request content and instructs the data transmission control unit 422 to control the encrypted data transmission. The data transmission control unit 422 issues a read request for plaintext content data to the hard disk 410 in which the content data is stored, and at the same time instructs the data encryption transmission unit 411 to encrypt the data. The data encryption transmission unit 411, which receives the encryption instruction from the data transmission control unit 422, encrypts the plain text content data read from the hard disk 410 using the encryption key Kx415 read from the encryption key register 414. , The encrypted content data is returned to the encrypted data receiving device 401 via the interface unit 412.
When the request analysis control unit 416 receives an authentication / key exchange request from the encrypted data receiving device 401, the analysis unit 421 analyzes the request contents and controls the authentication and key exchange to the authentication control unit 424. To instruct. The authentication control unit 424 instructs the authentication / key exchange unit 417 to perform authentication and key exchange with the encrypted data receiving device 401, and the authentication / key exchange unit 417 receives the encrypted data receiving device 401. If successful, the encryption key Kx415 and the encryption key identifier 413 read from the encryption key register 414 are transmitted to the encryption data receiving device 401 through the authentication control unit 424.
When the request analysis control unit 416 requests the encryption key identifier 413 from the encrypted data receiving device 401, the analysis unit 421 analyzes the request contents and instructs the identifier transmission control unit 423 to control the identifier transmission. The identifier transmission control unit 423 gives the encryption key identifier 413 read from the encryption key register 414 to the encryption key identifier request processing unit 418, and instructs the encryption data receiving device 401 to return the encryption key identifier 413. Upon receiving this instruction, the encryption key identifier request processing unit 418 returns the encryption key identifier 413 to the encrypted data receiving device 401 via the interface unit 412.
Next, a method of updating the encryption key in the conventional encrypted data transmission device 400 will be described with reference to FIGS. 5 and 6.
FIG. 6 shows a method of updating the encryption key in the conventional encrypted data transmitting device 400 shown in FIG. 5, and the data encrypted by the encrypted data transmitting device 400 with the encryption key Kx is encrypted by the encrypted data receiving device. It is the figure which showed the procedure received by 401 in chronological order.
In FIG. 6, the encrypted data transmission device 400 generates the first encryption key Kx [1] at time 500. When the encrypted data receiving device 401 requests the encrypted data transmitting device 400 for authentication / key exchange, the encrypted data transmitting device 400 performs the authentication / key exchange and if the authentication is successful, the encryption is performed. The encryption key Kx [1] is transmitted to the encrypted data receiving device 401 (501).
Next, the encrypted data receiving device 401 transmits a content data transmission request 502 to the encrypted data transmitting device 400, and the encrypted data transmitting device 400 that receives this transmits the requested content with the encryption key Kx [. Encrypt in 1] and send the encrypted data 503. The encrypted data receiving device 401 repeats the request for these content data as many times as necessary like the content requests 502 and 504, and the encrypted data transmitting device 400 repeats the content data requested for these requests. It encrypts with the encryption key Kx [1] and sends the encrypted data 503 and 505.
The data transmission control unit 422 of the requirements analysis control unit 416 counts the time from the time when the transmission of the encrypted data is completed by the Kx update timer 420. When the transmission of the encrypted data is completed from the encrypted data transmission device 400 and a predetermined time (here, 2 hours) elapses without the encrypted data being transmitted, the encryption of the request analysis control unit 416 is performed. The key generator 425 considers that a series of encrypted data transmissions has been completed, discards and updates the encryption key Kx [1] used up to that point for the security of encrypted data transmission, and newly at time 506. Generate the encryption key Kx [2] in.
After time 506, the encryption key Kx [1] has already been destroyed and is invalid. Therefore, if the encrypted data receiving device 401 wants to receive data from the encrypted data transmitting device 400 again, it is newly authenticated. -By requesting a key exchange, it is necessary to reacquire the new encryption key Kx [2] from the encrypted data transmitter 400 (507).
In the authentication / key exchange 507, the encrypted data receiving device 401 that has acquired the new encryption key Kx [2] sends the encrypted content data to the encrypted data transmitting device 400 in the same manner as the content requests 502 and 504. When the transmission request 508 is transmitted, the encrypted data transmitting device 400 encrypts the requested content with the encryption key Kx [2] in response to the transmission request 508, and transmits the encrypted data 509 to the encrypted data receiving device 401.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 11-289326</text></patcit>
<p> However, in the above-mentioned conventional method of updating the encryption key, it is stipulated that the encryption key Kx is destroyed / updated after a predetermined time (2 hours in the above example) after the last transmission of the encrypted data is completed. Therefore, if there is a request for authentication and key exchange from the encrypted data receiving device 401 at the timing immediately before the lapse of this predetermined time, the encrypted data receiving device 401 sends the encryption after that. There was a problem that the encrypted data could not be decrypted.</p><p> Hereinafter, this problem will be described by taking the case of the above-mentioned conventional method of updating the encryption key as an example.</p><p> In the case of this conventional method of updating the encryption key, the timing of discarding / updating the encryption key Kx is set to be 2 hours after the last transmission of the encrypted data is completed, and then the encrypted data of the encrypted data. This 2-hour progress is not initialized until transmission is started.</p><p> Here, consider the case where the authentication / key exchange 507 of FIG. 6 occurs immediately before the time 506 when the encryption key Kx is updated.</p><p> FIG. 7 shows a method of updating the encryption key in the conventional encrypted data transmission device 400 shown in FIG. 5 when authentication and key exchange occur immediately before the time 506 when the encryption key Kx is updated. The same reference numerals are used for the parts having the same timing as in FIG. The timing of the authentication / key exchange 510 is different from the timing of the authentication / key exchange 507 in FIG.</p><p> In the case of FIG. 7, the time 506 comes immediately after the encrypted data receiving device 401 receives the encryption key Kx [1] in the authentication / key exchange 510, and the encryption key update event in the encrypted data transmitting device 400 occurs. Then, when the encrypted data transmitting device 400 receives the content transmission request 511 from the encrypted data receiving device 401 after the encryption key is updated at time 506, the encrypted data transmitting device 400 is updated. The content is encrypted with the encryption key Kx [2], and the encrypted data 512 is transmitted.</p><p> That is, in this case, the content data is encrypted with the encryption key Kx [2] different from the encryption key Kx [1] received by the encrypted data receiving device 401 from the encrypted data transmitting device 400. The encrypted data receiving device 401 cannot correctly decrypt the encrypted data 512 received in response to the content request 511.</p><p> Further, in the configuration of the conventional encrypted transmission / reception system, the encrypted data receiving device 401 can request the encrypted data transmitting device 400 to refer to the unique identifier given to the encryption key. This identifier reference request is used by the encrypted data receiving device 401 to know whether or not the encryption key Kx has been updated on the encrypted data transmitting device 400 side without performing an authentication / key exchange process. Be done.</p><p> That is, when it becomes necessary for the encrypted data receiving device 401 to receive the content from the encrypted data transmitting device 400, it is necessary to perform an authentication / key exchange process to reacquire the encryption key Kx. In order to know whether the encryption key Kx previously obtained from the encryption data transmission device 400 is still valid and the authentication / key exchange process does not need to be performed again, the encryption data transmission device 400 is used. On the other hand, the reference of the identifier of the encryption key Kx is requested.</p><p> As a result of acquiring the encryption key Kx identifier, the encrypted data receiving device 401 is newly used when it is found that the encryption key Kx obtained from the encrypted data transmitting device 400 in the previous authentication / key exchange process is still valid. The content data request is transmitted to the encrypted data transmission device 400 without re-performing the authentication / key exchange process. On the contrary, if it is found that the previously acquired encryption key Kx has already been destroyed / updated, the authentication / key exchange process is performed prior to the content data request to acquire the updated encryption key Kx. After that, the content data transmission request is transmitted to the encrypted data transmission device 400.</p><p> Here, consider a case where the time 506 shown in FIG. 7 occurs immediately after the encrypted data receiving device 401 acquires the identifier of the encryption key Kx, and the encryption key update event occurs in the encrypted data transmitting device 400.</p><p> It is assumed that the response obtained as a result of requesting the encryption key identifier from the encryption data transmission device 400 indicates that the encryption key Kx held by the encryption data reception device 401 has not been updated. Next, it is assumed that an encryption key update event in the encrypted data transmitting device 400 occurs immediately after the result of the identifier request is returned to the encrypted data receiving device 401. In this case, the encrypted data receiving device 401 requests the encrypted data transmitting device 400 to transmit the content data on the assumption that the encryption key Kx has not been updated. As the encryption key when performing encryption in response to the transmission request of the content data from the encrypted data receiving device 401, a new encryption key after being updated is used, and this encrypted data is received. In the encrypted data receiving device 401, the received encrypted data cannot be decrypted correctly.</p><p> The present invention solves the above-mentioned conventional problems, and an object of the present invention is to provide an encrypted data transmission device, an encryption key update method, and an electronic device capable of reliably decrypting the received encrypted data by the receiving device. And.</p>
<p> In order to solve the above-mentioned problems, the first invention relates to an encryption key storage means for storing an encryption key for encrypting the content data to be transmitted, and the content data is encrypted by using the encryption key. An encrypted data transmitting means that encrypts and transmits the encrypted data, and an authentication / key exchange means that performs authentication and key exchange between the encrypted data receiving device. Whether or not the next encrypted data is transmitted within the first predetermined time after the transmission of the encrypted data is completed, and the first time shorter than the first predetermined time after the transmission of the encrypted data is completed. When it is determined whether authentication and key exchange have been performed within the first predetermined time after the lapse of the predetermined time of 2 and the next encrypted data is not transmitted within the first predetermined time. If the authentication and key exchange are not performed within the first predetermined time after the second predetermined time has elapsed, the encryption key is updated at the end of the first predetermined time. When the next encrypted data is not transmitted within the first predetermined time and the authentication and key exchange are performed within the first predetermined time after the second predetermined time has elapsed. Is provided with an encryption key updating means for updating the encryption key at the time of the authentication and the key exchange. The counters for the first predetermined time and the second predetermined time are the timing when the transmission of the encrypted data is completed, and after the second predetermined time has elapsed, within the first predetermined time. This is an encrypted data transmission device that is reset at a timing before transmitting the updated encryption key at the time of the authentication and the key exchange when the authentication and the key exchange are performed.</p><p> Further, in the second invention, the content data is encrypted by using the encryption key for encrypting the content data to be transmitted, the encryption key storage means for storing the identifier of the encryption key, and the encryption key. An encrypted data transmitting means for encrypting and transmitting the encrypted data, an authentication / key exchange means for performing authentication and key exchange between the encrypted data receiving device, and transmitting the identifier to the encrypted data receiving device. Identification transmission means and Whether or not the next encrypted data is transmitted within the first predetermined time after the transmission of the encrypted data is completed, and the first time shorter than the first predetermined time after the transmission of the encrypted data is completed. It is determined whether or not the identifier is transmitted within the first predetermined time after the elapse of the predetermined time of 2, and the next encrypted data is not transmitted within the first predetermined time. If the identifier is not transmitted within the first predetermined time after the lapse of the predetermined time of 2, the encryption key and the identifier are updated at the end of the first predetermined time, and the first is performed. If the next encrypted data is not transmitted within the predetermined time of 1 and the identifier is transmitted within the first predetermined time after the second predetermined time has elapsed, the identifier is used. It is provided with an encryption key updating means for updating the encryption key and the identifier at the time of transmission. The counters for the first predetermined time and the second predetermined time are the timing when the transmission of the encrypted data is completed, and after the second predetermined time has elapsed, within the first predetermined time. This is an encrypted data transmission device that is reset at a timing before transmitting the updated identifier when the identifier is transmitted to the data.</p><p> Further, in the third invention, the content data is encrypted by using the encryption key, and the encrypted data transmission step of transmitting the encrypted data and the encrypted data receiving device perform authentication and key exchange. After completing the authentication / key exchange step and the transmission of the encrypted data, whether or not the next encrypted data has been transmitted within the first predetermined time, and after completing the transmission of the encrypted data, the first After the lapse of the second predetermined time shorter than the predetermined time of, it is determined whether the authentication and the key exchange have been performed within the first predetermined time, and the next encryption is performed within the first predetermined time. If the encryption data is not transmitted and the authentication and key exchange are not performed within the first predetermined time after the second predetermined time has elapsed, at the end of the first predetermined time. When the encryption key is updated and the next encrypted data is not transmitted within the first predetermined time, the authentication and the authentication are performed within the first predetermined time after the second predetermined time has elapsed. When the key exchange is performed, the encryption key update step of updating the encryption key at the time of the authentication and the key exchange, and the encryption key update step. The timing when the transmission of the encrypted data is completed, and the authentication and key exchange when the authentication and key exchange are performed within the first predetermined time after the second predetermined time has elapsed. In the encryption key update method, which includes a counter reset step for resetting the counters of the first predetermined time and the second predetermined time at the timing before transmitting the updated encryption key at the time of is there.</p><p> Further, in the fourth aspect of the present invention, content data is encrypted using an encryption key, and authentication and key exchange are performed between an encrypted data transmission step of transmitting the encrypted data and an encrypted data receiving device. The authentication / key exchange step, the identifier transmission step of transmitting the encryption key identifier to the encrypted data receiving device, and the next encrypted data within the first predetermined time after the transmission of the encrypted data is completed. Whether or not the data has been transmitted, and after a second predetermined time shorter than the first predetermined time has elapsed since the transmission of the encrypted data is completed, the identifier is transmitted within the first predetermined time. If the next encrypted data is not transmitted within the first predetermined time, the identifier is not transmitted within the first predetermined time even after the second predetermined time has elapsed. In this case, the encryption key is updated at the end of the first predetermined time, and after the second predetermined time elapses when the next encrypted data is not transmitted within the first predetermined time. When the identifier is transmitted within the first predetermined time, the encryption key and the identifier are updated when the identifier is transmitted, and the encryption key update step. The updated identifier is transmitted when the transmission of the encrypted data is completed and when the identifier is transmitted within the first predetermined time after the second predetermined time has elapsed. This is an encryption key update method including a counter reset step for resetting the counters of the first predetermined time and the second predetermined time at the timing before the operation.</p><p> Further, the fifth invention is an electronic device provided with the encrypted data transmitting device of the first or second invention.</p><p> Further, the sixth invention is the encryption data transmission step of the encryption key update method of the third invention, in which the content data is encrypted and transmitted, and the authentication / key exchange step for performing authentication and key exchange. This is a program for causing a computer to execute the encryption key update step of updating the encryption key, and the counter reset step of resetting the counters of the first predetermined time and the second predetermined time.</p><p> Further, the seventh aspect of the present invention is the encrypted data transmission step of encrypting and transmitting the content data, and the authentication / key exchange step of performing authentication and key exchange, according to the fourth method of the encryption key update method of the present invention. Have the computer execute the identifier transmission step of transmitting the identifier, the encryption key update step of updating the encryption key, and the counter reset step of resetting the counters of the first predetermined time and the second predetermined time. It is a program for.</p><p> The eighth invention is a recording medium on which the program of the sixth or seventh invention is recorded, and is a recording medium that can be processed by a computer.</p>
<p> INDUSTRIAL APPLICABILITY According to the present invention, it is possible to provide an encrypted data transmission device, an encryption key update method, and an electronic device capable of reliably decrypting the received encrypted data by the receiving device.</p>
Hereinafter, embodiments of the present invention will be described with reference to the drawings.
(Embodiment 1) FIG. 1 shows a block diagram of an encrypted data transmission / reception system of the first embodiment that realizes the method of updating the encryption key of the present invention.
The encrypted data transmitting device 110 is connected to the encrypted data receiving device 111 via Ethernet 309. From the encrypted data receiving device 111, the authentication / key exchange request, the encryption key identifier request, and the content transmission request are transmitted to the request analysis control unit 306 via the interface unit 302 of the encrypted data transmitting device 110. The request analysis control unit 306 manages the generation / update of the encryption key Kx305 used for encrypting the content data, controls the authentication / key exchange in response to the request from the encrypted data receiving device 111, and also encrypts. Controls the return of the encryption key identifier 303 in response to the same request from the data receiving device 111.
Hereinafter, the configuration of the encrypted data transmitting device 110 will be described together with the operation when the request analysis control unit 306 receives various requests from the encrypted data receiving device 111.
The encryption key generation unit 315 of the request analysis control unit 306 generates the encryption key Kx305, destroys / updates the encryption key Kx305 according to the conditions described later, and assigns the encryption key identifier 303 in synchronization with the destruction / update. These encryption keys Kx305 and encryption key identifier 303 are stored in the encryption key register 304. The encryption key generation unit 315 corresponds to an example of the encryption key updating means of the present invention, and the encryption key register 304 corresponds to an example of the encryption key storage means of the present invention.
When the request analysis control unit 306 receives a request for content data from the encrypted data receiving device 111, the analysis unit 311 analyzes the request content and instructs the data transmission control unit 312 to control the encrypted data transmission. The data transmission control unit 312 issues a plaintext content data read request to the hard disk 300 in which the content data is stored, and at the same time instructs the data encryption transmission unit 301 to encrypt the data.
Upon receiving an encryption instruction from the data transmission control unit 312, the data encryption transmission unit 301 encrypts the plain text content data read from the hard disk 300 using the encryption key Kx305 read from the encryption key register 304. , The encrypted content data is returned to the encrypted data receiving device 111 via the interface unit 302. The data encryption transmission unit 301 corresponds to an example of the encrypted data transmission means of the present invention.
When the request analysis control unit 306 receives an authentication / key exchange request from the encrypted data receiving device 111, the analysis unit 311 analyzes the request contents, and the authentication control unit 314 controls the authentication and key exchange. To instruct.
The authentication control unit 314 instructs the authentication / key exchange unit 307 to perform authentication / key exchange with the encrypted data receiving device 111, and the authentication / key exchange unit 307 instructs the encrypted data receiving device 111. If successful, the encryption key Kx305 and the encryption key identifier 303 read from the encryption key register 304 are transmitted to the encryption data receiving device 111 through the authentication control unit 314. The authentication / key exchange unit 307 corresponds to an example of the authentication / key exchange means of the present invention.
When the request analysis control unit 306 is requested by the encrypted data receiving device 111 to transmit the encryption key identifier, the analysis unit 311 analyzes the request contents and instructs the identifier transmission control unit 313 to control the identifier transmission. ..
The identifier transmission control unit 313 gives the encryption key identifier 303 read from the encryption key register 304 to the encryption key identifier request processing unit 308, and instructs the encryption data receiving device 111 to return the encryption key identifier 303. Upon receiving this instruction, the encryption key identifier request processing unit 308 returns the encryption key identifier 303 to the encrypted data receiving device 111 via the interface unit 302. The encryption key identifier request processing unit 308 corresponds to an example of the identifier transmission means of the present invention.
The data transmission control unit 312, the identifier transmission control unit 313, and the authentication control unit 314 each start counting the Kx update timer 310, and the encryption key generation unit 315, the identifier transmission control unit 313, and the authentication control unit 314 respectively start Kx update. The encryption key Kx305 and the encryption key identifier 303 are updated according to the count value of the timer 310. The timing for starting the counting of the Kx update timer 310 and the timing for updating the encryption key Kx305 and the encryption key identifier 303 will be described later. The Kx update timer 310 corresponds to an example of the counter of the first predetermined time and the second predetermined time of the present invention.
Next, a method of updating the encryption key in the encrypted data transmission device 110 of the first embodiment will be described with reference to FIGS. 1 and 2.
FIG. 2 shows a method of updating the encryption key in the encrypted data transmission device 110 of the first embodiment shown in FIG. 1, and the data encrypted by the encryption data transmission device 110 with the encryption key Kx is encrypted. It is a figure which showed the procedure which the encryption data receiving apparatus 111 receives in time series. FIG. 2 shows the same timing as that shown in FIG. 7 in which the encrypted data received by the encrypted data receiving device 401 shown in FIG. 5 could not be correctly decrypted in the conventional encrypted data transmission / reception system described above. It is a thing. That is, the timing when an authentication / key exchange request is made from the encrypted data receiving device 111 immediately before a predetermined time (2 hours) elapses from the time when the transmission of the last encrypted data is completed is shown. There is.
In FIG. 2, the encrypted data transmission device 110 generates the first encryption key Kx [1] at time 100. When the encrypted data receiving device 111 requests the encrypted data transmitting device 110 for authentication / key exchange, the encrypted data transmitting device 110 performs the authentication / key exchange, and if the authentication is successful, the encryption is performed. Send the encryption key Kx [1] to the data receiver 111 (101).
Next, the encrypted data receiving device 111 transmits a content data transmission request 102 to the encrypted data transmitting device 110, and the encrypted data transmitting device 110 that receives this transmits the requested content data with the encryption key Kx. It is encrypted in [1] and the encrypted data 103 is transmitted. The encrypted data receiving device 111 repeats the request for these content data as many times as necessary as in the content requests 102 and 104, and the encrypted data transmitting device 110 requests the content data requested for these requests. It is encrypted with the encryption key Kx [1] and the encrypted data 103 and 105 are transmitted.
The data transmission control unit 312 of the request analysis control unit 306 causes the Kx update timer 310 to count the time from the time when the transmission of the encrypted data is completed. When the transmission of the encrypted data is completed from the encrypted data transmission device 110 and a predetermined time (here, 2 hours) elapses without the encrypted data being transmitted, the request analysis control unit The encryption key generation unit 315 of 306 considers that a series of encrypted data transmissions have been completed, discards / updates the encryption key Kx [1] used up to that point for the security of encrypted data transmission, and sets the time. A new encryption key Kx [2] is generated in 106.
When the encrypted data receiving device 111 wants to receive data from the encrypted data transmitting device 110 again, it newly requests authentication / key exchange, but here, the request is issued immediately before time 106.
Here, when the authentication control unit 314, which receives a new authentication / key exchange request from the encrypted data receiving device 111, refers to the count value of the Kx update timer 310 and completes the transmission of the last encrypted data. It is determined whether the time is 5 minutes immediately before the time when the predetermined time (2 hours) elapses from, that is, whether 1 hour 55 minutes or more has passed from the time when the transmission of the last encrypted data is completed.
The predetermined time (2 hours) set for destroying / updating the encryption key when the encrypted data has not been transmitted is an example of the first predetermined time of the present invention. Further, a time set as 1 hour 55 minutes from the time when the transmission of the last encrypted data, which is shorter than the first predetermined time, is completed corresponds to an example of the second predetermined time of the present invention.
If 1 hour and 55 minutes have not passed since the last transmission of the encrypted data was completed, the authentication control unit 314 does not update the encryption key, and the encryption key Kx305 stored in the encryption key register 304 is used. And the encryption key identifier 303 is instructed to the authentication / key exchange unit 307 to be transmitted to the encrypted data receiving device 111 at the time of authentication and key exchange.
On the other hand, if more than 1 hour 55 minutes have passed since the last transmission of the encrypted data was completed, the authentication control unit 314 causes the encryption key generation unit 315 to update the encryption key Kx305, and then the authentication control unit 314 updates the encryption key Kx305. Instruct the authentication / key exchange unit 307 to perform authentication and key exchange, and to send the updated new encryption key Kx305. In this case, the authentication control unit 314 counts the Kx update timer 310 after the encryption key generation unit 315 updates the encryption key Kx305 and before the authentication / key exchange unit 307 performs authentication and key exchange. Reset and start counting again.
In the case of FIG. 2, since the request for authentication / key exchange from the encrypted data receiving device 111 is received after 1 hour 55 minutes have passed from the time when the transmission of the last encrypted data is completed, the authentication is performed. At the time 120 when the request is received, the control unit 314 discards / updates the encryption key Kx [1] used up to that point, generates a new encryption key Kx [2], and stores the encryption key Kx [2] in the encryption key register 304. Rewrite the encryption key Kx305 and the encryption key identifier 303. Then, the authentication control unit 314 passes the new encryption key Kx [2] to the authentication / key exchange unit 307, and the authentication / key exchange 107 transmits the new encryption key Kx [2] to the encrypted data receiving device 111. Let me.
Immediately after this authentication / key exchange 107, it is time 106, which is two hours after the completion of the transmission of the last encrypted data. However, when the authentication control unit 314 performs authentication / key exchange 107, the Kx update timer 310 Since the count of is reset, at this time 106, 2 hours have not passed since the time when the transmission of the last encrypted data was completed, so the processing of discarding / updating the encryption key Kx is performed. I can't.
Following the authentication / key exchange 107, after the time 106, the encrypted data receiving device 111 issues a content transmission request 108. At this time, the encrypted data transmission device 110 encrypts the content with the encryption key Kx [2] updated at time 120, and transmits the encrypted data 109.
On the other hand, the encrypted data receiving device 111 decrypts the received encrypted data 109 by using the encryption key Kx [2] acquired at the time of the authentication / key exchange 107, so that the encrypted data 109 can be decrypted correctly.
Next, the operation when the encrypted data receiving device 111 refers to the unique identifier given to the encryption key will be described with reference to FIGS. 1 and 3.
FIG. 3 shows a method of updating the encryption key in the encrypted data transmitting device 110 of the first embodiment when the encrypted data receiving device 111 refers to the identifier of the encryption key. FIG. 3 shows the timing when an identifier transmission request is made from the encrypted data transmission device 110 immediately before a predetermined time (2 hours) elapses from the time when the transmission of the last encrypted data is completed. .. In FIG. 3, the same reference numerals as those in FIG. 2 are used for the similarly corresponding parts in FIG.
When referring to the identifier of the encryption key, the encrypted data receiving device 111 issues a reference request for the identifier to the encrypted data transmitting device 110 when it becomes necessary to receive the content from the encrypted data transmitting device 110. , It is determined whether or not it is necessary to perform authentication / key exchange according to the identifier returned from the encrypted data transmission device 110. That is, the identifier returned from the encrypted data transmitting device 110 is compared with the identifier previously obtained from the encrypted data transmitting device 110, and whether the previously obtained encryption key Kx is still valid or updated. Judge. Then, if the previously acquired encryption key Kx is still valid, a content request is sent to the encrypted data transmission device 110 without authentication / key exchange, and if the encryption key Kx is updated. After performing authentication and key exchange to obtain a new encryption key Kx, request the content.
Therefore, in FIG. 3, when issuing the content request 102, the encrypted data receiving device 111 first transmits the identifier reference request 121 to the encrypted data transmitting device 110.
When the request analysis control unit 306 receives the request for the identifier reference from the encrypted data receiving device 111, the analysis unit 311 analyzes the request contents and instructs the identifier transmission control unit 313 to control the identifier transmission. Then, according to the instruction from the identifier transmission control unit 313, the encryption key identifier 303 stored in the encryption key register 304 is transmitted to the encrypted data receiving device 111 by the encryption key identifier request processing unit 308.
Since the encryption key was updated at time 100 immediately before the identifier reference request 121, the encrypted data receiving device 111 was previously used from the identifier received by the encrypted data receiving device 111 for the identifier reference request 121. Judge that the acquired encryption key Kx has been updated. Since the encryption key Kx acquired last time has been updated, the encrypted data receiving device 111 then requests the encrypted data transmitting device 110 for authentication / key exchange.
Then, by the authentication / key exchange 101, the encrypted data receiving device 111 acquires the encryption key Kx [1], and the encrypted data 103 and 105 received in the subsequent content requests 102 and 104 are received by the received encryption key Kx. Decrypt with [1].
Then, in FIG. 3, the encrypted data receiving device 111 issues an identifier reference request 122 to the encrypted data transmitting device 110 immediately before the time 106.
Here, the identifier transmission control unit 313, which receives the reference request for the new identifier from the encrypted data receiving device 111, refers to the count value of the Kx update timer 310 and starts from the time when the last encrypted data transmission is completed. It is determined whether the time is 5 minutes immediately before the time when the predetermined time (2 hours) elapses, that is, whether 1 hour 55 minutes or more has passed from the time when the transmission of the last encrypted data is completed.
In addition, also in FIG. 3, as in FIG. 2, the predetermined time (2 hours) set for discarding / updating the encryption key when the encrypted data has not been transmitted has passed. This is an example of the first predetermined time of the invention. Further, a time set as 1 hour 55 minutes from the time when the transmission of the last encrypted data, which is shorter than the first predetermined time, is completed corresponds to an example of the second predetermined time of the present invention.
If 1 hour and 55 minutes have not passed since the last transmission of the encrypted data was completed, the identifier transmission control unit 313 does not update the encryption key, and the encryption key stored in the encryption key register 304 is stored. Instructs the encryption key identifier request processing unit 308 to return the identifier 303 to the encrypted data receiving device 111.
On the other hand, if 1 hour 55 minutes or more has passed since the last transmission of the encrypted data was completed, the identifier transmission control unit 313 updates the encryption key Kx305 and the encryption key identifier 303 to the encryption key generation unit 315. Instructs the encryption key identifier request processing unit 308 to return the new encryption key identifier 303 after the update. In this case, the identifier transmission control unit 313 causes the encryption key generation unit 315 to update the encryption key Kx305 and the encryption key identifier 303, and then causes the encryption key identifier request processing unit 308 to return the encryption key identifier 303. , Resets the count of the Kx update timer 310 and starts counting again.
In the case of FIG. 3, since the identifier reference request from the encrypted data receiving device 111 is received after 1 hour and 55 minutes have passed from the time when the transmission of the last encrypted data is completed, the identifier transmission control is performed. At the time 126 when the request is received, the unit 313 discards / updates the encryption key Kx [1] used up to that point, generates a new encryption key Kx [2], and stores the encryption key Kx [2] in the encryption key register 304. Rewrite the existing encryption key Kx305 and encryption key identifier 303. Then, the identifier transmission control unit 313 passes the identifier of the new encryption key Kx [2] to the encryption key identifier request processing unit 308, and the encryption key identifier request processing unit 308 transfers the identifier of the new encryption key Kx [2]. It is transmitted to the encrypted data receiving device 111.
Immediately after this identifier reference request 122, at time 106, which is two hours after the completion of the transmission of the last encrypted data, the identifier transmission control unit 313 receives the identifier reference request 122 and the encryption key generation unit 315. Since the count of the Kx update timer 310 is reset when the encryption key Kx305 and the encryption key identifier 303 are updated, 2 hours have passed since the last transmission of the encrypted data was completed. Therefore, at this time 106, the process of destroying / updating the encryption key Kx is not performed.
Following the transmission of the identifier reference request 122 and the identifier of the encryption key Kx [2], after time 106, the encrypted data receiving device 111 issues a request for authentication / key exchange, and the authentication / key exchange is performed (authentication / key exchange). one two Three). In the authentication / key exchange 123, the encrypted data receiving device 111 acquires a new encryption key Kx [2].
Further, following the authentication / key exchange 123, the content transmission request 124 is issued from the encrypted data receiving device 111. At this time, the encrypted data transmission device 110 encrypts the content with the encryption key Kx [2] updated at time 126, and transmits the encrypted data 125.
On the other hand, the encrypted data receiving device 111 decrypts the received encrypted data 125 by using the encryption key Kx [2] acquired at the time of the authentication / key exchange 123, so that the encrypted data 125 can be correctly decrypted.
Next, when the encrypted data receiving device 111 shown in FIG. 3 refers to the unique identifier given to the encryption key, the encrypted data transmitting device 110 updates the encryption key Kx305 and the encryption key identifier 303. The algorithm will be described with reference to FIGS. 1 and 4.
FIG. 4 shows a processing flow when the requirements analysis control unit 306 of the encrypted data transmission device 110 updates the encryption key Kx305 and the encryption key identifier 303.
At the time of initialization, the encryption key generation unit 315 of the request analysis control unit 306 generates the initial value of the encryption key Kx305 and the encryption key identifier 303 corresponding to this initial value with random numbers and stores them in the encryption key register 304 (S200). ). At this time, the encryption key generation unit 315 starts counting the Kx update timer 310 (S201), and the analysis unit 311 enters the request waiting state from the encrypted data receiving device 111 (S202).
The analysis unit 311 that received some request from the encrypted data receiving device 111 notifies the encryption key generation unit 315, and the encryption key generation unit 315 that received the notification has the count value of the Kx update timer 310 exceeding 2 hours. Determine if it is (S203). Then, when the count value exceeds 2 hours, the encryption key generation unit 315 generates a new encryption key Kx305 value with a random number and reads the value of the encryption key identifier 303 from the encryption key register 304. It increments and writes back to the encryption key register 304 (S204), resets the count value of the Kx update timer 310, and starts from zero again (S205).
Next, the analysis unit 311 analyzes the request content from the encrypted data receiving device 111 (S206), and branches the processing to S210, S207, and S214 according to the received request content, respectively.
When the content of the request received from the encrypted data receiving device 111 is an authentication / key exchange request, the analysis unit 311 instructs the authentication control unit 314 to execute the authentication / key exchange request.
The authentication control unit 314 determines whether the count value of the Kx update timer 310 exceeds the time 5 minutes before the time (2 hours) when the value of the encryption key Kx305 is updated in S204, that is, 1 hour 55 minutes. However, if it exceeds (S210), the encryption key generator 315 is instructed to update the encryption key Kx305. Upon receiving the instruction, the encryption key generator 315 generates a new encryption key Kx305 value with a random number, reads the value of the encryption key identifier 303 from the encryption key register 304, increments it, and writes it back to the encryption key register 304 again ( S211), reset the count value of the Kx update timer 310 and start from zero again (S212).
The authentication control unit 314 causes the encryption key generation unit 315 to update the encryption key Kx305, and then causes the authentication / key exchange unit 307 to perform authentication / key exchange with the encrypted data receiving device 111. Instruct. Then, when the authentication / key exchange is completed, the authentication control unit 314 reads the encryption key Kx305 and the encryption key identifier 303 from the encryption key register 304 and passes them to the authentication / key exchange unit 307 to perform the authentication / key exchange unit. It is transmitted to the encrypted data receiving device 111 by 307 (S213).
On the other hand, in S206, when the request content received from the encrypted data receiving device 111 is a reference request for the encryption key identifier, the analysis unit 311 instructs the identifier transmission control unit 313 to transmit the identifier. put out.
The identifier transmission control unit 313 determines whether or not the count value of the Kx update timer 310 exceeds the time 5 minutes before the time (2 hours) when the value of the encryption key Kx305 is updated in S204, that is, 1 hour 55 minutes. Judgment (S214), and if it exceeds, instruct the encryption key generator 315 to update the encryption key Kx305. Upon receiving the instruction, the encryption key generator 315 generates a new encryption key Kx305 value with a random number, reads the value of the encryption key identifier 303 from the encryption key register 304, increments it, and writes it back to the encryption key register 304 again ( S215), reset the count value of the Kx update timer 310 and start from zero again (S216).
The identifier transmission control unit 313 causes the encryption key generation unit 315 to update the encryption key Kx305, and then gives the encryption key identifier 303 to the encryption key identifier request processing unit 308, and gives the encryption key identifier 303 to the encryption data receiving device 111. Instruct to send. Upon receiving this instruction, the encryption key identifier request processing unit 308 returns the requested encryption key identifier 303 to the encrypted data receiving device 111.
On the other hand, in S206, when the request content received from the encrypted data receiving device 111 is a content transmission request, the analysis unit 311 instructs the data transmission control unit 312 to transmit the encrypted content data. put out.
The data transmission control unit 312 gives an instruction to read the plaintext content data to the hard disk 300 and an instruction to encrypt the plaintext content data to the data encryption transmission unit 301. Upon receiving this instruction, the data encryption transmitter 301 reads the encryption key Kx305 stored in the encryption key register 304, encrypts the plain text content data using the encryption key Kx305 (S207), and interfaces the encrypted content data. It is sent back to the encrypted data receiving device 111 via unit 302 (S208). Further, the data transmission control unit 312 resets the count value of the Kx update timer 310 after the transmission of the encrypted data is completed, and starts from zero again (S209).
The processes of S213 and S217 correspond to an example of the authentication / key exchange step and the identifier transmission step of the present invention, respectively. Further, the combined processing of S207 and S208 corresponds to an example of the encrypted data transmission step of the present invention. Further, the processes of S204, S211 and S217 all correspond to an example of the encryption key update step of the present invention.
Further, when the encryption key Kx305 is not updated in S211 and S215 and the encryption key Kx305 is updated in S204, the second case where the next encrypted data is not transmitted within the first predetermined time of the present invention is the second case. This is an example of a case where authentication and key exchange are not performed within the first predetermined time after the lapse of a predetermined time. Further, the case where the encryption key Kx305 is updated in S211 before the encryption key Kx305 is updated in S204 is the case where the next encrypted data is not transmitted within the first predetermined time of the present invention. This is an example of a case where authentication and key exchange are performed within the first predetermined time after the lapse of the predetermined time. Further, the case where the encryption key Kx305 is updated in S215 before the encryption key Kx305 is updated in S204 is the case where the next encrypted data is not transmitted within the first predetermined time of the present invention. This is an example of the case where the identifier is transmitted within the first predetermined time after the lapse of the predetermined time.
The request analysis control unit 306 updates the encryption key Kx305 and the encryption key identifier 303 with S211 or S215 according to the algorithm described above, so that the encryption data transmission device 110 performs an authentication / key exchange request or an encryption key identifier information request. If the count value of the Kx update timer 310 exceeds 1 hour 55 minutes at the time of receiving the above, each request is executed after the encryption key Kx305 and the encryption key identifier 303 are updated. As a result, the encryption key Kx305 is updated immediately after the encryption data receiving device 111 acquires the encryption key Kx305 by authentication / key exchange, and the encryption data receiving device 111 also acquires the encryption key identifier 303. Since there is no possibility that the encryption key Kx305 will be updated immediately afterwards, it is possible to provide an encryption data transmission device and an encryption key update method that can reliably decrypt the encrypted content data received by the encryption data reception device 111. It will be possible.
Further, by equipping the electronic device for transmitting the encrypted data with the encrypted data transmission device 110 of the first embodiment, it is possible to provide an electronic device capable of reliably decrypting the received encrypted content data. For example, it can be applied to electronic devices that transmit encrypted content data, such as AV devices connected to a LAN, personal computers, and STBs.
In the first embodiment, the time for updating the encryption key Kx is set to be 2 hours and 1 hour 55 minutes after the completion of the transmission of the last encrypted data. Even if the time is set to any other predetermined value, the same effect can be obtained if the time updated by S211 and S215 in FIG. 4 is earlier than the time updated by S204. Needless to say.
Further, in the first embodiment, the plaintext content data is encrypted with the encryption key Kx, but the content data is not directly encrypted with the encryption key Kx, but the content is indirectly derived from the encryption key Kx. It goes without saying that the same effect can be obtained by encrypting the data.
Further, in the first embodiment, the configuration in which only one encrypted data receiving device 111 is connected to the encrypted data transmitting device 110 has been described, but a plurality of encrypted data receiving devices are encrypted by one unit. It may be connected so as to receive the encrypted content data from the encrypted data transmission device.
Further, in the first embodiment, the encrypted data transmitting device 110 and the encrypted data receiving device 111 are connected by Ethernet 309, but any connection method capable of transmitting and receiving encrypted data is wired or wireless. Regardless of, it may be connected in any way.
The program of the present invention includes the encrypted data transmission step of encrypting and transmitting content data, the authentication / key exchange step of performing authentication and key exchange, and the encryption of the above-mentioned encryption key update method of the present invention. To cause the computer to perform all or part of the operation of the encryption key update step for updating the key, the counter reset step for resetting the counters for the first predetermined time and the second predetermined time. It is a program that operates in cooperation with a computer.
Further, the recording medium of the present invention is the encrypted data transmission step of the above-described encryption key update method of the present invention for encrypting and transmitting content data, the authentication / key exchange step for performing authentication and key exchange, and the above. All or part of the operation of the encryption key update step for updating the encryption key, the counter reset step for resetting the counters for the first predetermined time and the second predetermined time, all or part of the steps. It is a recording medium on which a program to be executed by a computer is recorded, and is a recording medium that can be read by the computer and the read program is used in cooperation with the computer.
Further, the program of the present invention includes the encrypted data transmission step of encrypting and transmitting the content data, the authentication / key exchange step of performing authentication and key exchange, and the identifier of the above-mentioned encryption key update method of the present invention. All or part of the identifier transmission step for transmitting data, the encryption key update step for updating the encryption key, and the counter reset step for resetting the counters for the first predetermined time and the second predetermined time. It is a program for causing a computer to execute a step operation, and is a program that operates in cooperation with the computer.
Further, the recording medium of the present invention includes the encrypted data transmission step of encrypting and transmitting content data, the authentication / key exchange step of performing authentication and key exchange, and the above-mentioned authentication / key exchange step of the above-mentioned encryption key update method of the present invention. All or part of the identifier transmission step of transmitting an identifier, the encryption key update step of updating the encryption key, and the counter reset step of resetting the counters of the first predetermined time and the second predetermined time. A recording medium on which a program for executing all or a part of the operations of the above steps by a computer is recorded, which is readable by the computer and the read program is used in cooperation with the computer. is there.
The above-mentioned "partial steps" of the present invention means one or several steps among the plurality of steps.
Further, the above-mentioned "step operation" of the present invention means the operation of all or a part of the step.
Further, one usage form of the program of the present invention may be a mode in which the program is recorded on a recording medium readable by a computer and operates in cooperation with the computer.
The recording medium includes a ROM and the like.
Further, the computer of the present invention described above is not limited to pure hardware such as a CPU, and may include firmware, an OS, and peripheral devices.
As described above, the configuration of the present invention may be realized by software or hardware.
As described above, the encrypted data transmission device, the encryption key update method, and the electronic device of the present invention have the original encryption key destruction / update time (the last in the present embodiment) in the encrypted data transmission device. The second key update time (1 hour 55 from the time when the last encrypted data transmission in the present embodiment) is slightly smaller than the time when 2 hours have passed from the time when the transmission of the encrypted data of If the time when the encrypted data receiving device sends the authentication / key exchange request to the encrypted data transmitting device is after the second key update time has elapsed. , The encryption key is updated earlier than the original key update timing, and the updated new encryption key is transmitted to the encrypted data receiving device.
By using the encrypted data transmission device, the encryption key update method, and the electronic device of the present invention, when the encrypted data transmission device receives an authentication / key exchange request, the time is shorter than the original encryption key update time. If the encryption key update time of 2 has already passed, authentication / key exchange is performed by transmitting the encryption key Kx to the encrypted data receiving device after updating the encryption key. It is possible to avoid the problem that the encryption key is updated between the time when the content data is requested and the encrypted data received by the encrypted data receiving device is not correctly decrypted.
Further, the encrypted data transmitting device, the encryption key updating method and the electronic device of the present invention are used in the encrypted data transmitting device when the encrypted data receiving device requests the identifier given to the encryption key in the encrypted data transmitting device. Is a second key renewal time (this implementation) that is slightly smaller than the original encryption key destruction / renewal time (in the present embodiment, two hours after the completion of transmission of the last encrypted data). 1 hour 55 minutes after the completion of the transmission of the last encrypted data) is provided, and the encrypted data receiving device requests the encryption key identifier from the encrypted data transmitting device. If the timing is after this second key update time has elapsed, the encryption key is updated earlier than the original key update timing, and the updated new encryption is applied to the encrypted data receiving device. It sends the key identifier.
By using the encrypted data transmitting device, the encryption key updating method, and the electronic device of the present invention, when the encrypted data receiving device requests the encrypted data transmitting device for the encryption key identifier, the original encryption key If the second encryption key update time, which is shorter than the update time, has already passed, the encrypted data transmitter sends the encryption key identifier after updating the encryption key. It is possible to avoid the problem that the encryption key is updated between the time when the inquiry is made and the time when the content data is requested, and the encrypted data received by the encrypted data receiving device is not decrypted correctly. ..
The encrypted data transmission device, the encryption key update method, and the electronic device according to the present invention have the effect that the receiving device can reliably decrypt the received encrypted data, and are used when transmitting the encrypted data. It is useful for encrypted data transmission devices, encryption key update methods, electronic devices, and the like.
<figref num="1">Block diagram of the encrypted data transmission / reception system according to the first embodiment of the present invention</figref><figref num="2">The figure which shows the method of updating the encryption key in the encrypted data transmission apparatus of Embodiment 1 of this invention.</figref><figref num="3">The figure which shows the method of updating the encryption key in the encryption data transmission device when the encryption data receiving device refers to the identifier of the encryption key in Embodiment 1 of this invention.</figref><figref num="4">The figure which shows the processing flow when the encrypted data transmission apparatus of Embodiment 1 of this invention updates an encryption key and an encryption key identifier.</figref><figref num="5">Block diagram of a conventional encrypted data transmission / reception system</figref><figref num="6">The figure which shows the update method of the encryption key in the conventional conventional encrypted data transmission device.</figref><figref num="7">The figure which shows the method of updating the encryption key in the conventional encrypted data transmission device when the authentication and the key exchange occur just before the time when the encryption key is updated.</figref>
Code description
110 Encrypted data transmitter 111 Encrypted data receiver 100, 106, 120, 126 Time 101, 107, 123 Authentication / key exchange 102, 104, 108, 124 Content request 103, 105, 109, 125 Encrypted data 121 122 Identifier reference request 300 Hard disk 301 Data encryption transmitter 302 Interface section 303 Cryptographic key identifier 304 Cryptographic key register 305 Cryptographic key Kx 306 Request analysis control section 307 Authentication / key exchange section 308 Cryptographic key identifier Request processing section 309 Ethernet 310 Kx Update timer 311 Analysis unit 312 Data transmission control unit 313 Identifier transmission control unit 314 Authentication control unit
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8300827B2 | Cited by | United States of America | Applicant |
| US9031240B2 | Cited by | United States of America | Applicant |
| JP2010147768A | Cited by | Japan | Examiner |
| US10999065B2 | Cited by | United States of America | Applicant |
| US9871944B2 | Cited by | United States of America | Search report |
| US8144877B2 | Cited by | United States of America | Applicant |
| JP5601368B2 | Cited by | Japan | Search report |
| US10057769B2 | Cited by | United States of America | Applicant |
| KR101503581B1 | Cited by | Republic of Korea | Search report |
| US8023658B2 | Cited by | United States of America | Applicant |
| US9143322B2 | Cited by | United States of America | Applicant |
| WO2009043294A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2011151924A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2016150122A1 | Cited by | United States of America | Pre-grant |
| JP2001230769A | Cites | Japan | Search report |
| JP2001345798A | Cites | Japan | Search report |
| JP2002217896A | Cites | Japan | Examiner |
| JP2003244131A | Cites | Japan | Search report |
| JP2004229114A | Cites | Japan | Search report |
| JP2004302846A | Cites | Japan | Search report |
| JP2005136870A | Cites | Japan | Search report |
| JPH11289326A | Cites | Japan | Search report |
2 members in 1 office
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2007104430AThis record | Japan | A | |
| JP4907944B2 | Japan | B2 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: A7422RD02 | RD02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2007104430
- Application
- 292805
Titles2
- Japanese
- 暗号化データ送信装置、暗号化鍵更新方法、電子機器、プログラムおよび記録媒体
- English
- Encrypted data transmitter, encryption key update method, electronic device, program and recording medium
Classification
- IPC, 1
- H04L9 14