JP2008103988A

Encryption communication system, device, method and program

Abstract

[Subject] Generating of a communication impossible state by the term-of-validity piece of an encryption key is beforehand prevented by supervising the traffic of device load and partner equipment and performing renewal of an encryption key dynamically. [Solution means] Two or more encryption communication equipment 16*1*16*4 which connected the terminal unit 18*1*18*6 is connected through the network 14, While enciphering the data received from the terminal unit 18*1 of the transmitting agency with the encryption communication equipment 16*1 and transmitting to other encryption communication equipment 16*2, the data received from other encryption communication equipment 16*2 is decrypted, and it transmits to the terminal unit 18*1 of a transmission destination. At the time of the communication start of the beginning with other encryption communication equipment 16*2*16*4, the encryption communication equipment 16*1 generates and exchanges encryption keys according to an encryption key exchange protocol, registers them into the encryption key management table 24*1 and 24*2, and sets up and manages the term of validity. If the term of validity is approached, renewal of an encryption key of the encryption key will be carried out, but even if it is during the term of validity, when a CPU load judges a low state, traffic searches the encryption key of the encryption communication equipment of little partner point, and updates an encryption key. [Selection figure] Fig. 1

Term

0.1 yearsto projected expiry

Projected expiry 19 October 2026, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

10 claims: 4 independent, 6 dependent

  1. 1
    Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the cryptographic communication system that decrypts and transmits the data to the destination terminal device, the data for the other cryptographic communication device is encrypted and transmitted to the plurality of cryptographic communication devices by using the encryption key, and the other cryptographic communication devices are transmitted. A predetermined encryption key exchange procedure that involves prior negotiation with the other device at the start of the first communication between the frame transmitter / receiver that decrypts the data received from the encryption communication device using the encryption key and the other encryption communication device. An encryption key exchange processing unit that generates and exchanges encryption keys according to the above is provided, and at least a part of the plurality of encryption communication devices includes a device load measurement unit that measures the device load and each other party's encryption communication device. Communication volume measurement unit that measures the communication volume of An expiration date is set for the encryption key generated by the encryption key exchange unit, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing unit is re-introduced. A cryptographic communication system characterized by having an expiration date management unit that instructs renewal of a cryptographic key by exchanging a cryptographic key. 端末装置を接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信システムに於いて、 前記複数の暗号通信装置に、 他の暗号通信装置に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化するフレーム送受信部と、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理部と、を設けるとともに、 前記複数の暗号通信装置の少なくとも一部に、 装置負荷を計測する装置負荷計測部と、 相手先の暗号通信装置毎の通信量を計測する通信量計測部と、 前記暗号鍵交換部で生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置の暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理部と、を設けたことを特徴とする暗号通信システム。
  2. 8
    Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the encrypted communication device that decrypts and transmits to the destination terminal device, the data to the other encrypted communication device is encrypted using the encryption key and transmitted, and the data received from the other encrypted communication device is transmitted. At the start of the first communication between the transmitter / receiver that decrypts using the encryption key and another encryption communication device, an encryption key is generated and exchanged according to a predetermined encryption key exchange procedure that involves prior negotiation with the other device. An encryption key exchange processing unit, a device load measurement unit that measures the device load, and a communication volume measurement unit that measures the communication volume of each other party's encrypted communication device. An expiration date is set for the encryption key generated by the encryption key exchange unit, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing unit is re-introduced. A cryptographic communication device characterized by having an expiration date management unit that instructs renewal of an encryption key by exchanging an encryption key. 端末装置を接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信装置に於いて、 他の暗号通信装置に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化する送受信部と、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理部と、 装置負荷を計測する装置負荷計測部と、 相手先の暗号通信装置毎の通信量を計測する通信量計測部と、 前記暗号鍵交換部で生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置の暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理部と、を備えたことを特徴とする暗号通信装置。
  3. 9
    Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the encrypted communication method of decrypting and transmitting to the destination terminal device, the data for the other encrypted communication method is encrypted using the encryption key and transmitted, and the data received from the other encrypted communication device is transmitted. When the transmission / reception step of decrypting using the encryption key and the first communication with another encryption communication device are started, the encryption key is generated and exchanged according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. An encryption key exchange processing step, a device load measurement step for measuring the device load, a communication volume measurement step for measuring the communication volume for each encryption communication device of the other party, and a communication volume measurement step. An expiration date is set for the encryption key generated in the encryption key exchange step, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing step is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing step is performed again. An encrypted communication method characterized by having an expiration date management step for instructing an encryption key renewal by exchanging an encryption key. 端末装置を接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信方法に於いて、 他の暗号通信方法に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化する送受信ステップと、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理ステップと、 装置負荷を計測する装置負荷計測ステップと、 相手先の暗号通信装置毎の通信量を計測する通信量計測ステップと、 前記暗号鍵交換ステップで生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理ステップに再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置の暗号鍵を検索して前記暗号鍵交換処理ステップに再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理ステップと、を備えたことを特徴とする暗号通信方法。
  4. 10
    Multiple cryptographic communication devices to which terminal programs are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. Is encrypted and transmitted to the destination terminal device by encrypting the data for the other encrypted communication device using the encryption key and transmitting the data received from the other encrypted communication device. When the transmission / reception step of decrypting using the encryption key and the first communication with another encryption communication device are started, the encryption key is generated and exchanged according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. An encryption key exchange processing step, a device load measurement step for measuring the device load, a communication volume measurement step for measuring the communication volume for each encryption communication device of the other party, and a communication volume measurement step. An expiration date is set for the encryption key generated in the encryption key exchange step, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing step is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange is performed again in the encryption key exchange processing step. An encryption communication program characterized by executing an expiration date management step that instructs the encryption key update by. 端末プログラムを接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信装置のコンピュータに、 他の暗号通信装置に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化する送受信ステップと、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理ステップと、 装置負荷を計測する装置負荷計測ステップと、 相手先の暗号通信装置毎の通信量を計測する通信量計測ステップと、 前記暗号鍵交換ステップで生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理ステップに再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置を検索して前記暗号鍵交換処理ステップに再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理ステップと、を実行させることを特徴とする暗号通信プログラム。