Encryption communication system, device, method and program
Abstract
[Subject] Generating of a communication impossible state by the term-of-validity piece of an encryption key is beforehand prevented by supervising the traffic of device load and partner equipment and performing renewal of an encryption key dynamically. [Solution means] Two or more encryption communication equipment 16*1*16*4 which connected the terminal unit 18*1*18*6 is connected through the network 14, While enciphering the data received from the terminal unit 18*1 of the transmitting agency with the encryption communication equipment 16*1 and transmitting to other encryption communication equipment 16*2, the data received from other encryption communication equipment 16*2 is decrypted, and it transmits to the terminal unit 18*1 of a transmission destination. At the time of the communication start of the beginning with other encryption communication equipment 16*2*16*4, the encryption communication equipment 16*1 generates and exchanges encryption keys according to an encryption key exchange protocol, registers them into the encryption key management table 24*1 and 24*2, and sets up and manages the term of validity. If the term of validity is approached, renewal of an encryption key of the encryption key will be carried out, but even if it is during the term of validity, when a CPU load judges a low state, traffic searches the encryption key of the encryption communication equipment of little partner point, and updates an encryption key. [Selection figure] Fig. 1
Term
0.1 yearsto projected expiry
Projected expiry 19 October 2026, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
10 claims: 4 independent, 6 dependent
- 1Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the cryptographic communication system that decrypts and transmits the data to the destination terminal device, the data for the other cryptographic communication device is encrypted and transmitted to the plurality of cryptographic communication devices by using the encryption key, and the other cryptographic communication devices are transmitted. A predetermined encryption key exchange procedure that involves prior negotiation with the other device at the start of the first communication between the frame transmitter / receiver that decrypts the data received from the encryption communication device using the encryption key and the other encryption communication device. An encryption key exchange processing unit that generates and exchanges encryption keys according to the above is provided, and at least a part of the plurality of encryption communication devices includes a device load measurement unit that measures the device load and each other party's encryption communication device. Communication volume measurement unit that measures the communication volume of An expiration date is set for the encryption key generated by the encryption key exchange unit, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing unit is re-introduced. A cryptographic communication system characterized by having an expiration date management unit that instructs renewal of a cryptographic key by exchanging a cryptographic key. 端末装置を接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信システムに於いて、 前記複数の暗号通信装置に、 他の暗号通信装置に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化するフレーム送受信部と、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理部と、を設けるとともに、 前記複数の暗号通信装置の少なくとも一部に、 装置負荷を計測する装置負荷計測部と、 相手先の暗号通信装置毎の通信量を計測する通信量計測部と、 前記暗号鍵交換部で生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置の暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理部と、を設けたことを特徴とする暗号通信システム。
- 8Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the encrypted communication device that decrypts and transmits to the destination terminal device, the data to the other encrypted communication device is encrypted using the encryption key and transmitted, and the data received from the other encrypted communication device is transmitted. At the start of the first communication between the transmitter / receiver that decrypts using the encryption key and another encryption communication device, an encryption key is generated and exchanged according to a predetermined encryption key exchange procedure that involves prior negotiation with the other device. An encryption key exchange processing unit, a device load measurement unit that measures the device load, and a communication volume measurement unit that measures the communication volume of each other party's encrypted communication device. An expiration date is set for the encryption key generated by the encryption key exchange unit, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing unit is re-introduced. A cryptographic communication device characterized by having an expiration date management unit that instructs renewal of an encryption key by exchanging an encryption key. 端末装置を接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信装置に於いて、 他の暗号通信装置に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化する送受信部と、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理部と、 装置負荷を計測する装置負荷計測部と、 相手先の暗号通信装置毎の通信量を計測する通信量計測部と、 前記暗号鍵交換部で生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置の暗号鍵を検索して前記暗号鍵交換処理部に再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理部と、を備えたことを特徴とする暗号通信装置。
- 9Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the encrypted communication method of decrypting and transmitting to the destination terminal device, the data for the other encrypted communication method is encrypted using the encryption key and transmitted, and the data received from the other encrypted communication device is transmitted. When the transmission / reception step of decrypting using the encryption key and the first communication with another encryption communication device are started, the encryption key is generated and exchanged according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. An encryption key exchange processing step, a device load measurement step for measuring the device load, a communication volume measurement step for measuring the communication volume for each encryption communication device of the other party, and a communication volume measurement step. An expiration date is set for the encryption key generated in the encryption key exchange step, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing step is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing step is performed again. An encrypted communication method characterized by having an expiration date management step for instructing an encryption key renewal by exchanging an encryption key. 端末装置を接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信方法に於いて、 他の暗号通信方法に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化する送受信ステップと、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理ステップと、 装置負荷を計測する装置負荷計測ステップと、 相手先の暗号通信装置毎の通信量を計測する通信量計測ステップと、 前記暗号鍵交換ステップで生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理ステップに再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置の暗号鍵を検索して前記暗号鍵交換処理ステップに再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理ステップと、を備えたことを特徴とする暗号通信方法。
- 10Multiple cryptographic communication devices to which terminal programs are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. Is encrypted and transmitted to the destination terminal device by encrypting the data for the other encrypted communication device using the encryption key and transmitting the data received from the other encrypted communication device. When the transmission / reception step of decrypting using the encryption key and the first communication with another encryption communication device are started, the encryption key is generated and exchanged according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. An encryption key exchange processing step, a device load measurement step for measuring the device load, a communication volume measurement step for measuring the communication volume for each encryption communication device of the other party, and a communication volume measurement step. An expiration date is set for the encryption key generated in the encryption key exchange step, an expiration date is searched for the encryption key whose expiration date is approaching, and the encryption key exchange processing step is instructed to update the encryption key by generating the encryption key again. If there is no encryption key that is close to the expiration date, when it is determined that the device load is low, the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange is performed again in the encryption key exchange processing step. An encryption communication program characterized by executing an expiration date management step that instructs the encryption key update by. 端末プログラムを接続した複数の暗号通信装置をネットワークを介して接続し、送信元の端末装置から受信したデータを暗号化して他の暗号通信装置に送信すると共に、他の暗号通信装置から受信したデータを復号化して送信先の端末装置に送信する暗号通信装置のコンピュータに、 他の暗号通信装置に対するデータを暗号鍵を使用して暗号化して送信すると共に、他の暗号通信装置から受信したデータを前記暗号鍵を使用して復号化する送受信ステップと、 他の暗号通信装置との最初の通信開始時に、相手装置との事前折衝を伴う所定の暗号鍵交換手順に従って暗号鍵を生成して交換する暗号鍵交換処理ステップと、 装置負荷を計測する装置負荷計測ステップと、 相手先の暗号通信装置毎の通信量を計測する通信量計測ステップと、 前記暗号鍵交換ステップで生成した暗号鍵に有効期限を設定し、有効期限が近づいた暗号鍵を検索して前記暗号鍵交換処理ステップに再度の暗号鍵生成による暗号鍵更新を指示し、前記有効期限に近づいた暗号鍵がない場合は、前記装置負荷が低い状態を判定した際に、前記通信量が少ない相手先の暗号通信装置を検索して前記暗号鍵交換処理ステップに再度の暗号鍵交換による暗号鍵更新を指示する有効期限管理ステップと、を実行させることを特徴とする暗号通信プログラム。
Independent claims4
121 paragraphs, as filed
The present invention particularly relates to an encryption communication system, an apparatus, a method and a program for encrypting transmitted data and decrypting received data by using an encryption key exchanged between encrypted communication devices connected via a network. It relates to a cryptographic communication system, a device, a method and a program for dynamically managing an encryption key used for decryption by setting an expiration date.
Conventionally, in encrypted communication, a plurality of encrypted communication devices to which terminal devices are connected are connected via a network such as WAN, and a transmission frame received from the source terminal device is used by the encrypted communication device. It encrypts and sends it to another encrypted communication device. In addition, the received frame received from another encrypted communication device is decrypted using the encryption key and transmitted to the destination terminal device.
As such an encrypted communication protocol, in recent years, an IP security protocol (IPsec) that enables encrypted communication without depending on an application has been widely used.
The IP security protocol is located at the IP network layer, does not require security settings for each application, and can unify security functions. In addition, shared encryption key encryption is used for encryption with the IP security protocol to enable high-speed communication processing, and by generating an encryption key prior to communication with the encryption key exchange protocol and handing it over to the other party. Share the encryption key. The shared encryption key encryption method is a method in which the same encryption key is used for encryption and decryption.
Furthermore, in encrypted communication, an expiration date is set for the encryption key in order to prevent an attacker from analyzing the encryption key, and the encryption key is changed regularly. When this expiration date is reached, the encryption key is also updated by the encryption key exchange protocol.
FIG. 14 is a block diagram of a conventional cryptographic communication system. In FIG. 14, the cryptographic communication device 106-1 is arranged at the center base 100, and the terminal devices 108-1 to 108-3 are connected to the cryptographic communication device 106-1 by LAN or the like. The cryptographic communication device 106-1 is connected to the cryptographic communication devices 106-2 to 106-4 located at the local bases 102-1 to 102-3 via a network 104 such as a WAN.
Cryptographic key management tables 114-1 to 114-4 are provided for each of the cryptographic communication devices 106-1 to 106-4. In addition, terminal devices 108-4 to 108-6 are connected to the encrypted communication devices 106-2 to 106-4 of the local bases 102-1 to 102-3, respectively.
FIG. 15 is a block diagram of a functional configuration realized by executing a program of the encrypted communication device 106-1 arranged at the center base 100 of FIG. In FIG. 15, the cryptographic communication device 106-1 is provided with a frame transmission / reception unit 110-1, an encryption key exchange processing unit 112-1, an encryption key management table 114-1, and an expiration date management unit 116-1.
The frame transmission / reception unit 1102-1 transmits / receives a frame (packet data) passing through the encryption communication device 106-1 and a frame issued by the device itself for encryption key exchange. For the frame passing through the device, the encryption key management table 114-1 is searched and the encryption key is taken out, the transmission frame is encrypted, and the reception frame is decrypted.
The encryption key exchange processing unit 112-1 exchanges encryption key information with a partner device that performs encrypted communication according to the encryption key exchange protocol by prior negotiation (negotiation) to generate an encryption key . The expiration date management unit 116-1 periodically scans the encryption key management table 114-1 and instructs the encryption key exchange processing unit 112-1 to update the encryption key that is about to expire. As shown in FIG. 16A, the encryption key management table 114-1 registers the generation time, expiration date, remote device, and encryption key of the encryption key.
To generate an encryption key, when the frame transmission / reception unit 110-1 receives a frame to be transferred to another encryption communication device, the encryption key management table 114-1 is referred to to search for an encryption key suitable for the other device. If the required encryption key does not exist, the encryption key exchange processing unit 112-1 is instructed to generate the encryption key. The encryption key exchange processing unit 112-1 negotiates with the other device to determine the encryption key exchange protocol, generates an encryption key, registers it in the encryption key management table 114-1, and registers the encryption key in the other device. Encrypt a frame of information and send it, and share the encryption key.
16 (B) to 16 (D) are the encryption key management tables 114-2 to 114-4 of the encryption communication devices 106-2 to 106-4 located at the local bases 102-1 to 102-3 in FIG. , The encryption key information generated by the encryption key exchange process with the encryption communication device 106-1 of the center base 100 is also registered.
The encryption key in the encryption key exchange process may be generated on either the sending side or the receiving side, and in either case, the generating side needs to hand over the encryption key to the other side in order to share the encryption key. There is.
To update the encryption key, in the system shown in FIG. 14, the expiration date management unit 116-1 provided in the encryption communication device 106-1 of the center base 100 shown in FIG. 15 periodically scans the encryption key management table 114-1. Then, instruct the encryption key exchange processing unit 112-1 to update the encryption key whose remaining time until the expiration date is approaching within a certain time. The encryption key exchange processing unit 112-1 generates an encryption key as in the case of the first encryption key exchange, registers it in the encryption key management table 114-1 and updates it, and encrypts the frame of the encryption key information on the other device. And update the encryption key of the other device at the same time.<patcit num="1"><text>Japanese Patent Application Laid-Open No. 62-181543</text></patcit><patcit num="2"><text>Japanese Unexamined Patent Publication No. 2004-023237</text></patcit>
<p> However, in such a conventional cryptographic communication system, the cryptographic key information of a large number of remote devices is registered in the cryptographic key management table 114-1 of the cryptographic communication device 106-1 at the center base to manage the expiration date. , If the operation start time with multiple remote devices is set to the same time and the operation is started with the same validity period set, the expiration date is approaching because the encryption key generation time is approaching. If the encryption key exchange process is started sequentially with the other party's encryption communication devices 106-4, 106-2, 106-3 near the expiration date, the load on the encryption communication device 106-1 will increase. There is a problem that a new encryption key cannot be generated before the old encryption key expires.</p><p> If a new encryption key cannot be generated by the expiration date, communication with the remote device will not be possible until a new encryption key can be generated after the expiration date.</p><p> In order to solve this problem, in order to prevent the concentration of encryption key updates, there is also a method of using random numbers to change the expiration date for each site. However, since the fluctuation range due to the random number of the expiration date is suppressed to a constant width, the encryption keys are sequentially updated with a plurality of partner devices within the fluctuation range time, and at this time, normal frame encryption communication is performed and the device load is applied. If the value is high, it takes time to update the encryption key, and there is a risk that a new encryption key cannot be generated before the old encryption key expires.</p><p> The present invention provides an encrypted communication device that monitors the device load and the amount of communication between the other device and dynamically updates the encryption key to prevent the occurrence of a communication failure state due to the expiration of the encryption key. The purpose is to provide.</p>
<p>(System) The present invention provides a cryptographic communication system. The present invention connects a plurality of cryptographic communication devices to which terminal devices are connected via a network, encrypts data received from the source terminal device and transmits the data to another cryptographic communication device, and another cryptographic communication device. In the cryptographic communication system that decrypts the data received from and sends it to the destination terminal device, the data for other cryptographic communication devices is encrypted using the encryption key and transmitted to multiple cryptographic communication devices. , A predetermined encryption that involves prior negotiation with the other device at the start of the first communication between the frame transmitter / receiver that decrypts the data received from the other encrypted communication device using the encryption key and the other encrypted communication device. An encryption key exchange processing unit that generates and exchanges encryption keys according to the key exchange procedure is provided, and at least a part of a plurality of encryption communication devices has a device load measurement unit that measures the device load and the other party's encryption communication. A communication volume measurement unit that measures the communication volume of each device, An expiration date is set for the encryption key generated by the encryption key exchange unit, the encryption key whose expiration date is approaching is searched, and the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again, and the expiration date is approaching. If there is no new encryption key, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for, and the encryption key exchange processing unit re-exchanges the encryption key. It is characterized by having an expiration date management unit that instructs renewal.</p><p> Here, the expiration date management unit includes an encryption key management table, and registers and manages the encryption key generation date and time, the expiration date, the remote device, the communication amount, and the encryption key in the encryption key management table.</p><p> As a form of a cryptographic communication system, when a plurality of local cryptographic communication devices are connected to a specific center cryptographic communication device for cryptographic communication, the center cryptographic communication device is connected to a frame transmission / reception unit, an encryption key exchange processing unit, and a device load measurement unit. , A communication volume measurement unit and an expiration date management unit are provided, and a frame transmission / reception unit and an encryption key exchange processing unit are provided in each of the local encryption communication devices.</p><p> Further, in the form of a cryptographic communication system, when cryptographic communication is performed between a plurality of cryptographic communication devices, a frame transmission / reception unit, an encryption key exchange processing unit, a device load measurement unit, and a communication amount measurement unit are used for each of the plurality of cryptographic communication devices. And an expiration date management department will be established.</p><p> When the encryption key exchange processing unit receives the first reception connection from another encryption communication device, the encryption key exchange processing unit generates and exchanges the encryption key, and instructs the expiration date management unit to manage the expiration date of the encryption key.</p><p> When the encryption key exchange processing unit first transmits and connects to another encryption communication device, the encryption key may be generated and exchanged, and the expiration date management unit may be instructed to manage the expiration date of the encryption key. ..</p><p> In the cryptographic communication system of the present invention, the device load measuring unit measures the CPU load, and the expiration date management unit determines that the encryption key update timing is when the average value of the CPU load for a certain period of time falls below a predetermined value. Then, the encryption communication device of the other party whose communication amount is equal to or less than a predetermined value is searched, and the encryption key exchange unit is instructed to update the encryption key by generating the encryption key again.</p><p> The communication volume measuring unit measures the bit rate (bps) per unit time as the communication volume.</p><p> The expiration date management unit prohibits the update of the encryption key for a predetermined time after the update of the encryption key.</p><p> The encryption key exchange processing unit generates and exchanges an encryption key of a shared key cryptosystem that uses the same encryption key for encryption and decryption.</p><p>(Device) The present invention provides a cryptographic communication device. The present invention encrypts the data received from the source terminal device and transmits it to another encrypted communication device, and at the same time, decrypts the data received from the other encrypted communication device and transmits it to the destination terminal device. In the device, a transmission / reception unit that encrypts data to another encrypted communication device using an encryption key and transmits the data, and decrypts data received from the other encrypted communication device using the encryption key, and a transmission / reception unit. At the start of the first communication with another encrypted communication device, the encryption key exchange processing unit that generates and exchanges the encryption key according to the predetermined encryption key exchange procedure that involves prior negotiation with the other device, and the device load that measures the device load. Set the expiration date for the measurement unit, the communication volume measurement unit that measures the communication volume for each encryption communication device of the other party, and the encryption key generated by the encryption key exchange unit, and search for the encryption key whose expiration date is approaching. If the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again and there is no encryption key that is approaching the expiration date, when it is determined that the device load is low, the encryption of the other party with a small amount of communication It is characterized by having an expiration date management unit that searches for a communication device and instructs an encryption key exchange processing unit to update the encryption key by exchanging the encryption key again.</p><p>(Method) The present invention provides a cryptographic communication method. The present invention connects a plurality of cryptographic communication devices to which terminal devices are connected via a network, encrypts data received from the source terminal device and transmits the data to another cryptographic communication device, and another cryptographic communication device. In the encrypted communication method that decrypts the data received from and sends it to the destination terminal device, the data for other encrypted communication methods is encrypted using the encryption key and transmitted, and also from the other encrypted communication device. At the transmission / reception step of decrypting the received data using the encryption key and the start of the first communication with another encryption communication device, an encryption key is generated according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. A cryptographic key exchange processing step for exchanging data, a device load measurement step for measuring the device load, and a communication volume measurement step for measuring the communication volume for each cryptographic communication device of the other party. Set an expiration date for the encryption key generated in the encryption key exchange step, search for the encryption key whose expiration date is approaching, instruct the encryption key exchange processing step to update the encryption key by generating the encryption key again, and approach the expiration date. If there is no new encryption key, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for and the encryption key exchange processing step is performed again by encryption key exchange. It is characterized by having an expiration date management step for instructing key renewal.</p><p>(Program) The present invention provides a cryptographic communication program. The cryptographic communication program of the present invention connects a plurality of cryptographic communication devices to which terminal devices are connected via a network, encrypts data received from the source terminal device and transmits the data to another cryptographic communication device, and also other Decrypts the data received from the encryption communication device of the above and sends it to the destination terminal device. The data for the other encryption communication device is encrypted using the encryption key and transmitted to the computer of the encryption communication device. According to the transmission / reception step of decrypting the data received from the encryption communication device using the encryption key and the predetermined encryption key exchange procedure involving prior negotiation with the other device at the start of the first communication with the other encryption communication device. An encryption key exchange processing step for generating and exchanging an encryption key, a device load measurement step for measuring the device load, and a communication volume measurement step for measuring the communication volume for each encryption communication program of the other party. Set an expiration date for the encryption key generated in the encryption key exchange step, search for the encryption key whose expiration date is approaching, instruct the encryption key exchange processing step to update the encryption key by generating the encryption key again, and approach the expiration date. If there is no new encryption key, when it is determined that the device load is low, the encryption key of the other party's encryption communication device with a small amount of communication is searched for and the encryption key exchange processing step is performed again by encryption key exchange. It is characterized by executing an expiration date management step that instructs key renewal.</p><p>(Device) The present invention is connected to another cryptographic communication device via a network, the terminal device is connected, the data received from the terminal device is encrypted and transmitted to the other cryptographic communication device, and other In a cryptographic communication device that decrypts data received from a cryptographic communication device and sends it to a terminal device, the data to be transmitted to another cryptographic communication device is encrypted using an encryption key and transmitted, and other cryptographic communication is performed. A transmission / reception unit that decrypts data received from the device using an encryption key, an encryption key processing unit that generates an encryption key used for data transmission / reception between other encryption communication devices according to an encryption key exchange procedure, and an encryption key processing unit. When the device load measurement unit that measures the load of the own device, the communication amount measurement unit that measures the communication volume of other encrypted communication devices, and the device load measurement unit determines that the load is low, the communication amount measurement unit measures it. It is characterized by having a management unit that searches for another encryption communication device with a small amount of communication based on the result and instructs the encryption key exchange processing unit to update the encryption key with the other encryption communication device. And.</p><p>(Information Processing Device) The present invention is an information processing device that is connected to another device and transmits / receives information to / from another device, in which transmission information encrypted by an encryption key is transmitted to the other device and at the same time. When the transmission / reception unit that decrypts the received information from other devices with the encryption key, the device load measurement unit that measures the load of the own device, and the device load measurement unit determine that the load is low, the amount of communication is small. It is characterized by including a management unit that searches for another device and updates the encryption key used for transmitting / receiving information to / from the other device.</p><p> Here, the information processing device is connected to a plurality of other devices, and the encryption key processing unit generates a different encryption key corresponding to each of the plurality of other devices.</p>
<p> According to the present invention, in addition to the management of the encryption key for which the expiration date is set, the encryption key is updated by searching for the encryption key of the other device having a low communication volume while the CPU load is low during the validity period of the encryption key. Therefore, even if the operation of a plurality of encrypted communication devices is started at the same time and the management of the encryption key update is started by setting the same expiration date, the encryption key updates with the plurality of remote devices are concentrated near the expiration date. Therefore, it is possible to reliably avoid a state in which communication is temporarily disabled without updating the encryption key within the expiration date, and it is possible to improve the security of encrypted communication.</p><p> In addition, the update timing of the encryption key with multiple remote devices changes dynamically according to the CPU load of the device itself and the amount of communication with the remote device, so it is valid even if the expiration date is approaching immediately after the start of operation. By dynamically updating the encryption key during the period, the expiration date after the update is shifted from each other and dispersed in time, and the expiration date is surely distributed compared to the conventional method using random numbers. Can be done.</p>
FIG. 1 is a block diagram showing an embodiment of the cryptographic communication system according to the present invention. In this embodiment, the expiration date of the cryptographic key is centrally managed at the center base.
In FIG. 1, in the cryptographic communication system of the present embodiment, local bases 12-1, 12-2, 12-3 are connected to the center base 10 via a network such as a WAN.
Cryptographic communication devices 16-1, 16-2, 16-3, 16-4 according to the present invention are provided in each of the center base 10 and the local bases 12-1 to 12-3, and the encryption key management table 24-1 is provided, respectively. , 24-2,24-3,24-4 are provided.
Terminal devices 18-1, 18-2, 18-3 are connected to the encrypted communication device 16-1 at the center base 10 by LAN or the like. For local bases 12-1 to 12-3, terminal devices 18-4 to 18-6 are connected to each encrypted communication device 16-2 to 16-4 by LAN or the like.
As a cryptographic communication system in which the center base 10 and the local bases 12-1 to 12-3 are connected by a network 14, the center base 10 is, for example, the head office of a company, and the local bases 12-1 to 12-3 are like its branches. This is the case.
In the cryptographic communication system of the present embodiment, the expiration date is set for the cryptographic key used for cryptographic communication between the local bases 12-1 to 12-3 in the cryptographic communication device 16-1 of the center base 10. , Manages the expiration date of this encryption key.
FIG. 2 is a block diagram of a functional configuration showing an embodiment of the cryptographic communication device 16-1 according to the present invention arranged at the center base of FIG. 1, and this functional configuration is made by a computer constituting the cryptographic communication device 16-1. This is a function realized by executing the encrypted communication program of the present embodiment.
In Fig. 2, the cryptographic communication device 16-1 at the center base includes a frame transmission / reception unit 20-1, an encryption key exchange processing unit 22-1, an encryption key management table 24-1, an expiration date management unit 26-1, and a CPU load. A measurement unit 28-1 and a communication volume measurement unit 30-1 are provided.
The frame transmission / reception unit 20-1 uses an encryption key for frames (packet data) passing through the encryption communication device 16-1, specifically, transmission frames from the terminal devices 18-1 to 18-3 in FIG. And decrypts the received frames from the cryptographic communication devices 16-2 to 16-4 of other local bases 12-1 to 12-3 received via the network 14 using the encryption key. The decrypted frame is output to the terminal devices 18-1 to 18-3.
The encryption key exchange processing unit 22-1 generates an encryption key according to a predetermined encryption key exchange protocol that involves prior negotiation (negotiation) at the start of the first communication with another encryption communication device, and the encryption key management table of the device itself. Register with 24-1 and hand it over to the other device to share the encryption key.
As the cryptographic communication method of this embodiment, for example, IPSec (IP security protocol), which is a standard of the cryptographic communication method being standardized by the IETF, is used. IPSec employs a shared encryption key encryption method that uses the same encryption key for encryption and decryption as an encryption method, and is a shared encryption key compared to a public encryption key encryption method that uses a public encryption key and a private encryption key. Since the encryption method has a higher processing speed for encryption and decryption, it is used.
The encryption algorithms used in IPSec include multiple encryption algorithms, but the implementation of DES (Data Encryption Standard) is essential.
In IPSec, the encryption algorithm and encryption key actually used during encrypted communication are dynamically determined and exchanged by negotiation (pre-negotiation) with the other device immediately before the start of communication. That is, in the process of negotiation, encryption algorithms that can be used with each other are presented, and encryption algorithms that can be used by both parties are determined. In this case, even if there is a difference between the two encryption algorithms, at least an agreement by DES is possible.
Once the encryption algorithm used in the encrypted communication is determined, the encryption key used for the determined encryption algorithm is subsequently exchanged. This encryption key exchange is executed by the encryption key exchange processing unit 22-1. In the case of IPSec, IKE (Internet Key Exchange) is specified as the encryption key exchange protocol of the encryption key exchange processing unit 22-1.
Cryptographic key exchange protocol IKE consists of two stages of processing, and the first stage determines the encryption algorithm used only for cryptographic key exchange. In the next second stage, cryptographic communication limited to the cryptographic key exchange protocol IKE will be possible, negotiations for cryptographic communication by IPSec will be started, the encryption algorithm will be determined, and the encryption key will be generated and exchanged. It will be.
Further, the generation and exchange of the encryption key by the encryption key exchange protocol IKE may be performed on the transmitting side or the receiving side of the two encrypted communication devices that perform the encrypted communication. In either case, when the encryption key is generated, the encryption key is handed over to the other device and shared.
In the encryption key management table 24-1, the encryption key generated by the encryption key exchange processing unit 22-1 and shared with the remote device is registered, and the expiration date is set and managed. The encryption key management table 24-1 has the contents shown in FIG. 4 (A), for example. The encryption key management table 24-1 in FIG. 4A registers and manages the encryption key generation time, expiration date, remote device, communication volume, and encryption key.
Corresponding to the encryption key management table 24-1 provided in the encryption communication device 16-1 of the center base 10 in Fig. 4 (A), the encryption communication device 16 of the local bases 12-1 to 12-3, which is the other device. The contents of the encryption key management tables 24-2,24-3,24-4 provided in -2 to 16-4 are as shown in Figures 4 (B) (C) and (D).
For example, the management record in the first row of the encryption key management table 24-1 at the center base 10 in Fig. 4 (A) shows that the remote device is the encryption communication device 16-4 at the local base 12-3, and the encryption key generation time is It is "2006/4/1 3:00:45", and since the validity period is set to 24 hours in this case, the expiration date is "2006/4/2 3:00:45". .. The validity period of the encryption key can generally be set to 8 hours or 24 hours, and one of them is selected and set as necessary.
On the other hand, in the encryption key management table 24-4 of Fig. 4 (D) of the cryptographic communication device 16-4, which is the other device of this management record, the encryption key generation time and expiration date are 1 in Fig. 4 (A). It is the same as the management record in the line, and the remote device is the encrypted communication device 16-1 at the center base.
In the second and third rows of the cryptographic management table 24-1 at the center base 10 in Fig. 4 (A), the cryptographic communication of the cryptographic communication device 16-2 and the local base 12-2 whose counterpart device is the local base 12-1 In device 16-3, the encryption key generation time is almost the same as the management record on the first line, and the first line is 45 seconds at the same time, while the second line is 47 seconds after 2 seconds. , The third line is 56 seconds after 11 seconds, and the encryption key is generated at about the same time.
Specifically, in the cryptographic communication system shown in FIG. 1, for example, at the start of system operation, terminal devices 18- provided at local bases 12-1 to 12-3 at a predetermined operation start time. The first frame is transmitted from 4,18-5,18-6 to, for example, the terminal device 18-1 at the center base 10. Therefore, among the encrypted communication devices 16-2, 16-3, 16-4 provided at the local bases 12-1 to 12-3, the encryption key exchange process is performed in the device that first receives the frame transmission from the terminal device side. It starts up and shares the encryption key by generating and exchanging the encryption key with the encryption communication device 16-1 of the center base 10 by negotiation according to the encryption key exchange protocol IKE.
Of course, as another operation mode in the cryptographic communication system, the terminal devices 18-1 to 18-3 at the center base to the terminal devices 18-4 on the local bases 12-1, 12-2, 12-3 side at a predetermined operation time. Even if the first frame is transmitted to, 18-5, 18-6 and the encryption key exchange processing unit on the encryption communication device 16-1 side generates and distributes the encryption key, the encryption communication is started. good.
With reference to Fig. 2 again, the expiration date management unit 26-1 sets the expiration date when the encryption key is registered in the encryption key management table 24-1, as shown in Fig. 4 (A), and the set validity period is set. Manage deadlines. That is, when the expiration date management unit 26-1 searches the encryption key management table 24-1 and searches for an encryption key whose remaining time for the expiration date is less than or equal to a predetermined time, the encryption key exchange processing unit 22- Instruct 1 to update the encryption key. Upon receiving the update of the encryption key, the encryption key exchange processing unit 22-1 generates and exchanges the encryption key by the same encryption key exchange protocol as at the start of communication, and updates the encryption key of the device itself and the other device.
Here, the expiration date management unit 26-1 instructs the renewal of the encryption key. The remaining time until the expiration date is sufficient for the management exchange protocol to complete the renewal by generating and exchanging the encryption key before the expiration date. Is set.
In addition to updating the encryption key using such an expiration date, in the present embodiment, even if the expiration date management unit 26-1 does not have an encryption key that is approaching the expiration date, the encryption communication device 16-1 When the CPU load, which is the device load, is measured and the state in which the average value of the CPU load over a certain period of time is determined to be less than or equal to a predetermined threshold value, the communication amount becomes less than or equal to the predetermined value. Searches for the encryption key with, and instructs the encryption key exchange processing unit 22-1 to update the encryption key.
For this reason, the CPU load measurement unit 28-1 and the communication volume measurement unit 30-1 are provided for the expiration date management unit 26-1. The CPU load measuring unit 28-1 measures and outputs the load of the CPU that executes the program of the encrypted communication device 16-1. Further, the communication amount measurement unit 30-1 measures the communication amount of encrypted communication by the frame transmission / reception unit 20-1, specifically, the bit rate (bps), and outputs it to the expiration date management unit 26-1.
FIG. 3 is a block diagram of a functional configuration showing an embodiment of the cryptographic communication device according to the present invention arranged at the local bases 12-1 to 12-3 in Fig. 1 for the cryptographic communication device 16-2 at the local base 12-1. ..
The cryptographic communication device 16-2 installed at the local site in Fig. 3 is equipped with a frame transmission / reception unit 20-2, an encryption key exchange processing unit 22-2, and an encryption key management table 24-2. In the form, since the expiration date management of the encryption key is performed only by the encryption communication device 16-1 at the center base, the expiration date management unit provided in the encryption communication device 16-1 at the center base in Fig. 2 Since the functions corresponding to 26-1, CPU load measurement unit 28-1 and communication volume measurement unit 30-1 are disabled and do not operate, this is indicated by a dotted line.
FIG. 5 is a block diagram of the hardware environment of the computer that executes the encrypted communication program of the present embodiment. In FIG. 5, the computer that realizes the encrypted communication device is equipped with a CPU 32, and the RAM 36, ROM 38, the hard disk drive 40, the keyboard 44, the mouse 46, and the device interface 42 that connects the display 48 to the bus 34 of the CPU 32, and the external network. The WAN network adapter 50 to be connected and the LAN network adapter 52 to be connected to the internal terminal device are connected.
The hard disk drive 40 stores a program for executing the encrypted communication according to the present invention. When the computer is started, the OS is read and arranged in the RAM 36 by boot-up, and then the encrypted communication program of the present invention as an application program is stored. Reads and arranges it in RAM36, and executes it by CPU32.
FIG. 6 is a flowchart of encrypted communication processing by the encrypted communication device 16-1 provided at the center base 10 of FIG. 1, and the procedure of this flowchart is the encrypted communication device 16 of the center base that realizes the functional configuration shown in FIG. It becomes the contents of the encrypted communication program of -1.
In FIG. 6, in the center base encrypted communication process, first, in step S1, the presence or absence of reception from the local base encrypted communication device at the start of operation is checked. In the encryption communication system shown in Fig. 1, since the frame is transmitted from the local base to the center base at the start of operation, the encryption key exchange process is activated at the start of communication accompanying this frame transmission, and the encryption key exchange process is performed. The accompanying negotiation communication connection is received in step S1.
Then, in step S2, it is checked whether or not it is an encryption key exchange processing request, and if it is an encryption key exchange processing request, the process proceeds to step S3 to execute the encryption key exchange processing. This encryption key exchange process generates and exchanges an encryption key by the encryption key exchange protocol IKE in the encryption algorithm IPSec already described, and the encryption key is used between the encryption communication device 16-1 at the center base and the other device at the local base side. Share.
Subsequently, in step S4, the encryption key generated by the encryption key exchange process is registered in the encryption key management table 24-1, and as shown in FIG. 4 (A), the validity period is, for example, 24 hours with respect to the encryption key generation time. Set the expiration date.
On the other hand, if the received frame from the local base is not the encryption key exchange processing request in step S2, the process proceeds to step S5, the encryption key management table 24-1 is searched, and the encryption key corresponding to the remote device is acquired. , The received frame is decrypted using the acquired encryption key and transmitted to the destination terminal device. Subsequently, in step S6, the communication volume in the frame communication at this time is measured, and the communication volume value is updated as shown in the encryption key management table 24-1 of FIG. 4 (A).
On the other hand, if the reception is not received from the encryption communication device of the local base in step S1, the process proceeds to step S7 to check whether or not the transmission is to the encryption communication device of the local base. At this time, when the transmission frame from the terminal device side of the transmission source is received, the process proceeds to step S8, the encryption key management table 24-1 is searched, the encryption key with the other device is searched, and the presence / absence of registration is checked. If the encryption key is not registered, the process proceeds to step S9, the encryption key exchange process is executed, the encryption key is generated and exchanged with the other device, and the encryption key generated in step S10 is registered in the encryption key management table and is valid. Set a deadline.
If the registration of the encryption key with the other party device is determined in step S8, the process proceeds to step S11, and the transmission frame is encrypted with the corresponding encryption key and transmitted to the other party's encryption communication device. Then, in step S12, the amount of communication by the transmission frame at this time is measured, and the amount of communication in the encryption key management table 24-1 of FIG. 4 (A) is updated.
Subsequently, the expiration date management process is executed in step S13, and the details are shown in the flowchart of FIG. The processing of steps S1 to S13 is repeated until a stop instruction is given in step S14.
FIG. 7 is a flowchart of the local base cryptographic communication processing performed by each of the local base cryptographic communication devices 16-2, 16-3, 16-4 in Fig. 1, and the local base cryptographic communication device 16 shown in FIG. -Represents the processing content of the program that realizes the functional configuration of 2.
In FIG. 7, when the encryption communication process of the local base determines the reception from the encryption communication device 16-1 of the center base in step S1, the process proceeds to step S2, and it is determined that this reception is the encryption key exchange request at the start of communication. Once determined, the encryption key exchange process is executed in step S3, the encryption key generated in step S4 is registered in the encryption key management table of the device itself, and the expiration date is set.
Here, in the encryption communication system shown in FIG. 1, since the operation is started by frame transmission from the local bases 12-1 to 12-3, the steps associated with the encryption key exchange request from the center base side. The processing of S3 and S4 will be skipped.
If it is determined in step S1 that an encrypted frame has been received from the encryption communication device at the center base during operation, it is determined in step S2 that it is not an encryption key exchange request, and the process proceeds to step S5 to perform the corresponding encryption. The received frame is decrypted by the key and transmitted to the destination terminal device.
If the transmission frame for the encryption communication device 16-1 at the center site is determined from the terminal device connected to the device itself in step S6, the process proceeds to step S7, the encryption key management table of the device itself is searched, and the encryption key is used. Check if there is any registration.
Here, at the start of operation, frames are transmitted from the local bases 12-1 to 12-3 to the center base 10, so even if the encryption key management table is searched in step S7 at the start of operation, it will be the other device. In this case, the process proceeds to step S8 to execute the encryption key exchange process, for example, the encryption key is generated on the local base side, and the encryption key is handed over to the center base side for sharing. Then, in step S9, the generated encryption key is registered in the encryption key management table, and the expiration date is set.
If the frame transmission to the center base is determined in step S6 after the encryption key has been registered after the start of operation, the encryption key is registered with the other device in step S7, so the process proceeds to step S10. The transmission frame is encrypted with the corresponding encryption key and transmitted to the encryption communication device 16-1 at the center base, which is the destination. Such processing of steps S1 to S10 is repeated until a stop instruction is given in step S11.
Further, in the local site encryption communication processing shown in FIG. 7, since the center site manages the expiration date of the encryption key registered in the encryption key management table, the encryption communication process at the center site shown in FIG. 12 is performed. The communication volume update in steps S6 and S12 and the expiration date management process in step S13 are excluded.
FIG. 8 is a flowchart showing the details of the expiration date management process at the center base in step S13 of FIG. In FIG. 8, in the expiration date management process, the expiration date management unit 26-1 of FIG. 2 scans the encryption key management table 24-1 and searches for an encryption key that is about to expire. Specifically, an encryption key whose remaining time with respect to the expiration date is less than a predetermined time is searched as an encryption key whose expiration date is about to expire.
When the corresponding encryption key whose expiration date is approaching is determined in step S2 by this search, the process proceeds to step S9, and the encryption key exchange processing unit 22-1 is instructed to update the searched encryption key. As a result, the encryption key exchange processing unit 22-1 generates and exchanges the encryption key with the other device sharing the encryption key to be updated through negotiation according to the encryption key exchange protocol IKE. By registering each in the encryption key management table, the encryption key will be updated and the expiration date will be reset accordingly.
On the other hand, if there is no encryption key that is about to expire in step S2, proceed to step S3, read the average value of the CPU load for the past fixed time measured by the CPU load measurement unit 28-1, and in step S4. Check if the CPU load is below the threshold.
If the CPU load is below the threshold value, it is judged that the CPU load is small, and the process proceeds to step S5, and among the registered encryption keys in the encryption key management table 24-1, the encryption key whose communication volume is below the predetermined threshold value is selected. search for.
When the encryption key whose communication volume is below the threshold is determined in step S6 by this encryption key search, the process proceeds to step S7, checks whether or not a plurality of encryption keys are applicable, and if it is single, proceeds to step S9. , Instruct the encryption key exchange processing unit 22-1 to update the encryption key, as in the case of the expiration date.
If it is determined that a plurality of encryption keys are applicable in step S7, the encryption key having the minimum communication time is searched for in step S8, and the same procedure proceeds to step S9 to the encryption key exchange processing unit 22-1. Instruct to update the encryption key.
Due to such an expiration date management process, at the start of operation, for example, as shown in the encryption key management table 24-1 at the center base in FIG. 4 (A), the encryption key generation time of the encryption key of the remote device is almost the same. Since they are the same, the expiration dates are also concentrated at the same time, but the state of the CPU load of the encrypted communication device 16-1 at the center base 10 and the local bases 12-1 to 12 which are the other devices during the subsequent operation. Based on the amount of communication with the -3 device, the encryption key update process is dynamically executed for the encryption key that satisfies the conditions for updating the encryption key according to the CPU load and the amount of communication before the expiration date is reached, and as a result, the encryption key update process is executed. The encryption key generation time is appropriately distributed depending on the CPU load and communication usage, and the expiration date associated therewith is also distributed.
Therefore, even if the communication start time is the same and the expiration date of the encryption key for multiple devices is managed with the same expiration date, the expiration date is distributed throughout the system operation, so that the encryption key of a specific device becomes the expiration date. When it reaches, the probability that the encryption key of another device will expire before and after that will be greatly reduced, and the encryption key update processing will be concentrated, so the encryption key cannot be updated by the expiration date. It is possible to reliably prevent the occurrence of a state in which communication becomes impossible.
FIG. 9 is a flowchart showing another embodiment of the expiration date management process in step S13 of FIG. 6, and in this embodiment, the expiration date management is performed by setting the encryption key renewal prohibition period within the validity period. It is characterized by having to do.
The expiration date of the encryption key in the present embodiment is set by a fixed expiration time such as 24 hours or 8 hours from the encryption key generation date and time, but is based on the CPU load and the communication amount in the embodiment of FIG. According to the encryption key update, if these two conditions are met, the encryption key will be updated even at the initial stage of the validity period.
However, since the once generated encryption key is meaningless unless it is used for a certain period of time, in the embodiment of FIG. 9, it is constant from the start time of the validity period, that is, the generation time of the encryption key. A time encryption key update prohibition period is set, and the encryption key cannot be updated even if the conditions for encryption key update due to CPU load and communication volume are satisfied for this encryption key update prohibition period.
As a result, even if the encryption key is updated based on the CPU load and communication volume, the encryption key update is prohibited for a certain period of time from the encryption key update to the encryption key update prohibition period, and the usage period of the generated encryption key is extended. It is possible to prevent it from becoming unnecessarily short.
In the expiration date management process of FIG. 9 in which the encryption key update prohibition period is set, steps S1 to S8 are the same as the expiration date management process of FIG. 8, but from the current encryption key generation time in step S9. Checks whether the elapsed time of is the preset prohibition period for encryption key update, and if it is the prohibition period, skips the encryption key update process in step S10 and updates the encryption key during the encryption key update prohibition period. I try not to do it.
Here, it is desirable to statistically determine how long the encryption key update prohibition period is set for the validity period from the operation history of the encryption communication system shown in FIG. Specifically, the default encryption key renewal prohibition period is set to, for example, 50% of the validity period, and if the encryption key updates are concentrated, the default encryption key renewal prohibition period is shortened, while the default encryption key renewal prohibition period is shortened. If the encryption key updates are sufficiently distributed, the default encryption key update prohibition period may be adjusted to be longer.
FIG. 10 is a block diagram showing another embodiment of the cryptographic communication system according to the present invention. In this embodiment, the expiration date of the cryptographic key is managed at each of the bases. ..
In Fig. 10, for example, four bases 10-1 to 10-4 are connected via network 14, and cryptographic communication devices 16-11, 16-12, are connected to each of the bases 10-1 to 10-4. 16-13, 16-14 are arranged, two each, terminal device 18-11, 18-12, terminal device 18-21, 18-22, terminal device 18-31, 18-32 and terminal device 18-41. , 18-42 are connected.
Cryptographic key management tables 24-11, 24-12, 24-13, 24-14 are provided for each of the cryptographic communication devices 16-11 to 16-14.
The functional configuration associated with the program execution of the cryptographic communication devices 16-11 to 16-14 in the embodiment of FIG. 10 is the same as that of the cryptographic communication device 16-1 at the center base 10 in the cryptographic communication system of FIG. 1 shown in FIG. Equipped with frame transmission / reception unit 20-1, encryption key exchange processing unit 22-1, encryption key management table 24-1, expiration date management unit 26-1, CPU load measurement unit 28-1, and communication volume measurement unit 30-1. There is.
In addition, the expiration date management using the encryption key management tables 24-11 to 24-14 is performed by each encrypted communication device 16-11 to 16-14, but in order to avoid the management of duplicate expiration dates, this book is used. In the embodiment, for example, the device that generated the encryption key manages the expiration date.
FIG. 11 shows the contents of the encryption key management tables 24-11,24-12,24-13,24-14 provided in the encryption communication devices 16-11 to 16-14 of FIG. It is shown in (B), FIG. 11 (C), and FIG. 11 (D), respectively.
In the encryption key management tables 24-11 to 24-14, the encryption key generation time, expiration date, remote device, communication volume, and encryption key are registered as in the case of the encryption communication system shown in FIG. A new encryption key generation flag is provided for management.
The encryption key generation flag is set to "1" on the device side that generated the encryption key, and is reset to "0" on the device side that was handed over without generating the encryption key. Will be managed for the encryption key whose generation flag is set to "1".
In the encryption key management table 24-11 provided in the encryption communication device 16-11 of the base 10-1 in Fig. 11 (A), the other device in the first and third lines is the encryption communication of the base 10-4. Device 16-14 and cryptographic communication device 16-13 at base 10-3 are set to "1", and the expiration date is managed for these two encryption keys.
On the other hand, for the encryption keys managed by the encryption communication devices 16-11 and 16-13 at the bases 10-1, 10-3, the encryption of the encryption communication device 16-3 in Fig. 11 (C) that generated the encryption key The generation flag of the key management table 24-13 is set to "1", and the expiration date is managed by the cryptographic communication device 16-3.
FIG. 12 is a flowchart of the encrypted communication process performed by each of the encrypted communication devices 16-11 to 16-14 at each base of FIG. The cryptographic communication processing performed at each of these bases is basically the same as the cryptographic communication processing of the cryptographic communication device 16-1 of the center base 10 in FIG. 1 shown in FIG. 6, and the differences are step S1 and step S2. The only point is that it checks for reception or transmission from other interconnected cryptographic communication devices, not from the local cryptographic communication device.
FIG. 13 is a flowchart showing the details of the expiration date management process in step S13 of FIG. This expiration date management process is the same as the expiration date management process at the center base in FIG. 1 shown in FIG. 9, but the difference is that each encryption key management table 24-11 ~ as shown in FIG. 11 in step S1. The point is that the encryption key whose generation flag in 24-14 is set to "1" is searched for whether or not it is an encryption key that is about to expire, and the other points are the same processing.
Further, in the embodiment of FIG. 13, the encryption key update prohibition period is set and whether or not the encryption key update prohibition period is determined in step S9, but the expiration date of FIG. 8 is excluded except for the processing of step S9. It may be the same process as the management process.
The present invention also provides a recording medium in which the encrypted communication programs shown in FIGS. 6 to 7 and 12 are stored. This recording medium includes portable recording media such as CD-ROMs, floppy disks (R), DVD disks, magneto-optical disks, and IC cards, storage devices such as hard disk drives installed inside and outside the computer system, and lines. It includes a database that holds programs via the disk, as well as other computer systems and their databases, as well as transmission media on the line.
Note that the above embodiment takes as an example a shared key encryption method in which the same encryption key is used for encryption and decryption as the encryption key for encrypted communication, but different encryption keys are used for encryption and decryption. It can also be applied to the public key method, which is the method used.
Further, in the above embodiment, IPSec (IP security protocol) is taken as an example of the encryption protocol, but other application-dependent SSL, SSH, S / MIME, PGP, etc. may be used.
Further, the present invention includes appropriate modifications that do not impair its purpose and advantages, and is not further limited by the numerical values shown in the above embodiments.
Here, the features of the present invention can be summarized as follows. (Appendix) (Appendix 1) (System) Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the cryptographic communication system that decrypts and transmits the data to the destination terminal device, the data for the other cryptographic communication devices is encrypted and transmitted by using the encryption key to the plurality of cryptographic communication devices, and the data is transmitted to the other cryptographic communication devices. A predetermined encryption key exchange procedure that involves prior negotiation with the other device at the start of the first communication between the frame transmitter / receiver that decrypts the data received from the encryption communication device using the encryption key and the other encryption communication device. An encryption key exchange processing unit that generates and exchanges encryption keys according to the above is provided, and at least a part of the plurality of encryption communication devices includes a device load measurement unit that measures the device load, and each other party's encryption communication device. An expiration date is set for the communication volume measurement unit that measures the communication volume and the encryption key generated by the encryption key exchange unit, the encryption key whose expiration date is approaching is searched, and the encryption key is re-encrypted in the encryption key exchange processing unit. When an instruction is given to update the encryption key by generation and there is no encryption key that has approached the expiration date, when the device load is determined to be low, the encryption key of the other party's encryption communication device with a small amount of communication is searched. A cryptographic communication system characterized in that the encryption key exchange processing unit is provided with an expiration date management unit for instructing an encryption key update by another encryption key exchange. (1)
(Appendix 2) (Encryption key management table) In the encryption communication system described in Appendix 1, the expiration date management unit includes an encryption key management table, and the encryption key management table includes the encryption key generation date and time, the expiration date, and the other party. An encryption communication system characterized by registering and managing a device, communication volume, and encryption key.
(Appendix 3) (1: n Cryptographic Communication System) In the cryptographic communication system described in Appendix 1, when a plurality of local cryptographic communication devices are connected to one center cryptographic communication device for cryptographic communication, the center cryptographic communication device is used. The communication device is provided with the frame transmission / reception unit, the encryption key exchange processing unit, the device load measurement unit, the communication amount measurement unit, and the expiration date management unit, and each of the local encryption communication devices is provided with the frame transmission / reception unit and the encryption key exchange processing. A cryptographic communication system characterized by having a unit. (2)
(Appendix 4) (Mutual Cryptographic Communication System) In the cryptographic communication system described in Appendix 1, when cryptographic communication is performed between a plurality of cryptographic communication devices, the frame transmitter / receiver is used in each of the plurality of cryptographic communication devices. A cryptographic communication system characterized by providing an encryption key exchange processing unit, a device load measurement unit, a communication volume measurement unit, and an expiration date management unit. (3)
(Appendix 5) (Cryptographic key is generated and exchanged at the first reception connection to manage the expiration date) In the encryption communication system described in Appendix 1, the encryption key exchange processing unit makes the first reception connection from another encryption communication device. A cryptographic communication system characterized in that, when received, the encryption key is generated and exchanged, and the expiration date management unit is instructed to manage the expiration date of the encryption key. (Four)
(Appendix 6) (Cryptographic key is generated and exchanged at the first transmission connection to manage the expiration date) In the encryption communication system described in Appendix 1, the encryption key exchange processing unit first transmits and connects to another encryption communication device. A cryptographic communication system characterized in that, at the same time, the encryption key is generated and exchanged, and the expiration date management unit is instructed to manage the expiration date of the encryption key. (Five)
(Appendix 7) (Details of device load) In the cryptographic communication system described in Appendix 1, the device load measurement unit measures the CPU load, and the expiration date management unit measures the average value of the CPU load over a certain period of time in the past. Is less than the predetermined value, it is determined that the encryption key update timing is performed, the encryption communication device of the other party whose communication volume is less than or equal to the predetermined value is searched for, and the encryption key exchange unit is encrypted by generating the encryption key again. A cryptographic communication system characterized by instructing a key update. (6)
(Appendix 8) (Details of communication charge measurement bps) In the encrypted communication system described in Appendix 1, the communication volume measuring unit measures a bit rate per unit time as the communication volume. system.
(Appendix 9) (Prohibition Period for Encryption Key Renewal) In the encryption communication system described in Appendix 1, the expiration date management unit is characterized in that the encryption key update is prohibited for a predetermined time from the update of the encryption key. Cryptographic communication system. (7)
(Appendix 10) (Shared Key Encryption Method) In the encryption communication system described in Appendix 1, the encryption key exchange processing unit generates an encryption key of a shared key encryption method that uses the same encryption key for encryption and decryption. A cryptographic communication system characterized by being exchanged.
(Appendix 11) (Device) Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the encrypted communication device that decrypts and transmits to the destination terminal device, the data to the other encrypted communication device is encrypted using the encryption key and transmitted, and the data received from the other encrypted communication device is transmitted. At the start of the first communication between the transmitter / receiver that decrypts using the encryption key and another encryption communication device, an encryption key is generated and exchanged according to a predetermined encryption key exchange procedure that involves prior negotiation with the other device. The expiration date of the encryption key exchange processing unit, the device load measurement unit that measures the device load, the communication volume measurement unit that measures the communication volume of each other party's encryption communication device, and the encryption key generated by the encryption key exchange unit. Is set, the encryption key whose expiration date is approaching is searched, and the encryption key exchange processing unit is instructed to update the encryption key by generating the encryption key again. When it is determined that the load is low, the expiration date management is performed by searching for the encryption key of the other party's encryption communication device with a small amount of communication and instructing the encryption key exchange processing unit to update the encryption key by exchanging the encryption key again. A cryptographic communication device characterized by having a unit and. (8)
(Appendix 12) (Encryption key management table) In the encryption communication system described in Appendix 11, the expiration date management unit includes an encryption key management table, and the encryption key management table includes an encryption key generation date and time, an expiration date, and a partner. An encrypted communication device characterized by registering and managing a device, communication volume, and encryption key.
(Appendix 13) (Cryptographic key is generated and exchanged at the first reception connection to manage the expiration date) In the encryption communication device described in Appendix 11, the encryption key exchange processing unit makes the first reception connection from another encryption communication device. A cryptographic communication device characterized in that when it is received, the encryption key is generated and exchanged, and the expiration date management unit is instructed to manage the expiration date of the encryption key.
(Appendix 14) (Cryptographic key is generated and exchanged in the first transmission connection to manage the expiration date) In the encryption communication device described in Appendix 11, the encryption key exchange processing unit first transmits and connects to another encryption communication device. An encrypted communication device, characterized in that, at the same time, the encryption key is generated and exchanged, and the expiration date management unit is instructed to manage the expiration date of the encryption key.
(Appendix 15) (Details of device load) In the encrypted communication device described in Appendix 11, the device load measuring unit measures the CPU load, and the expiration date management unit measures the average value of the CPU load over a certain period of time in the past. Is less than the predetermined value, it is determined that the encryption key update timing is performed, the encryption communication device of the other party whose communication volume is less than or equal to the predetermined value is searched for, and the encryption key exchange unit is encrypted by generating the encryption key again. An encrypted communication device characterized by instructing a key update.
(Appendix 16) (Prohibition Period for Encryption Key Renewal) In the encrypted communication device described in Appendix 11, the expiration date management unit is characterized in that the encryption key update is prohibited for a predetermined time from the update of the encryption key. Cryptographic communication device.
(Appendix 17) (Method) Multiple cryptographic communication devices to which terminal devices are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. In the encrypted communication method of decrypting and transmitting to the destination terminal device, the data for the other encrypted communication method is encrypted using the encryption key and transmitted, and the data received from the other encrypted communication device is transmitted. At the transmission / reception step of decrypting using the encryption key and the start of the first communication with another encryption communication device, an encryption key is generated and exchanged according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. The expiration date of the encryption key exchange processing step, the device load measurement step for measuring the device load, the communication amount measurement step for measuring the communication amount for each encryption communication device of the other party, and the encryption key generated in the encryption key exchange step. Is set, the encryption key whose expiration date is approaching is searched, and the encryption key exchange processing step is instructed to update the encryption key by generating the encryption key again. When it is determined that the load is low, the expiration date management is performed by searching for the encryption key of the other party's encryption communication device with a small amount of communication and instructing the encryption key exchange processing step to update the encryption key by another encryption key exchange. A cryptographic communication method characterized by having steps and. (9)
(Appendix 18) (Details of device load) In the encrypted communication method described in Appendix 17, the device load measurement step measures the CPU load, and the expiration date management step is the average value of the CPU load over a certain period of time in the past. Is less than the predetermined value, it is determined that the encryption key update timing is performed, the encryption communication device of the other party whose communication volume is less than or equal to the predetermined value is searched for, and the encryption is performed by generating the encryption key again in the encryption key exchange step. An encrypted communication method characterized by instructing a key update.
(Appendix 19) (Program) Multiple cryptographic communication devices to which terminal programs are connected are connected via a network, data received from the source terminal device is encrypted and transmitted to other cryptographic communication devices, and data received from other cryptographic communication devices. Is encrypted and transmitted to the destination terminal device by encrypting the data for the other encrypted communication device using the encryption key and transmitting the data received from the other encrypted communication device. When the transmission / reception step of decrypting using the encryption key and the first communication with another encryption communication device are started, the encryption key is generated and exchanged according to a predetermined encryption key exchange procedure involving prior negotiation with the other device. The expiration date of the encryption key exchange processing step, the device load measurement step for measuring the device load, the communication amount measurement step for measuring the communication amount for each encryption communication device of the other party, and the encryption key generated in the encryption key exchange step. Is set, the encryption key whose expiration date is approaching is searched, and the encryption key exchange processing step is instructed to update the encryption key by generating the encryption key again. When it is determined that the load is low, the expiration date management step is performed by searching for the encryption communication device of the other party with a small amount of communication and instructing the encryption key exchange processing step to update the encryption key by exchanging the encryption key again. A cryptographic communication program characterized by executing. (Ten)
(Appendix 20) (Details of device load) In the encrypted communication program described in Appendix 19, the device load measurement step measures the CPU load, and the expiration date management step is the average value of the CPU load over a certain period of time in the past. Is less than the predetermined value, it is determined that the encryption key update timing is performed, the encryption communication device of the other party whose communication volume is less than or equal to the predetermined value is searched for, and the encryption is performed by generating the encryption key again in the encryption key exchange step. A cryptographic communication program characterized by instructing a key update.
(Appendix 21) While being connected to another cryptographic communication device via a network, the terminal device is connected, the data received from the terminal device is encrypted and transmitted to the other cryptographic communication device, and other cryptographic communication is performed. In the encryption communication device that decrypts the data received from the device and transmits it to the terminal device, the data to be transmitted to the other encryption communication device is encrypted by using the encryption key and transmitted, and the other encryption communication device is transmitted. A transmission / reception unit that decrypts data received from the above using the encryption key, an encryption key processing unit that generates an encryption key used for data transmission / reception between another encryption communication device according to an encryption key exchange procedure, and an encryption key processing unit. When the device load measuring unit that measures the load of the own device, the communication amount measuring unit that measures the communication amount of another encrypted communication device, and the device load measuring unit determine a low load state, the communication amount measuring unit It is provided with a management unit that searches for another encryption communication device with a small amount of communication based on the measurement result by the above and instructs the encryption key exchange processing unit to update the encryption key with the other encryption communication device. A cryptographic communication device characterized by the fact that.
(Appendix 22) In an information processing device that is connected to another device and transmits / receives information to / from another device, the transmission information encrypted by the encryption key is transmitted to the other device and received from the other device. When the transmission / reception unit that decrypts information with the encryption key, the device load measurement unit that measures the load of the own device, and the device load measurement unit determine that the load is low, a search for another device with a small amount of communication is performed. An information processing device including a management unit that updates an encryption key used for transmitting and receiving information to and from the other device.
(Appendix 23) In the information processing apparatus described in Appendix 22, the information processing apparatus is connected to a plurality of other devices, and the encryption key processing unit is different corresponding to each of the plurality of other devices. An information processing device characterized by generating an encryption key.
<figref num="1">A block diagram showing an embodiment of a cryptographic communication system according to the present invention in which the expiration date is centrally managed at a center base.</figref><figref num="2">A block diagram of a functional configuration showing an embodiment of an encrypted communication device according to the present invention arranged at the center base in FIG.</figref><figref num="3">A block diagram of a functional configuration showing an embodiment of an encrypted communication device according to the present invention arranged at a local base in FIG.</figref><figref num="4">Explanatory drawing of the encryption key management table provided in the encryption communication device of the embodiment of FIG.</figref><figref num="5">Block diagram of the hardware environment of the computer that executes the program that realizes the functions of the encrypted communication device of this embodiment.</figref><figref num="6">Flowchart of encrypted communication processing at the center base in Fig. 1.</figref><figref num="7">Flowchart of encrypted communication processing at the local site in Fig. 1.</figref><figref num="8">A flowchart showing the details of the expiration date management process in step S13 of FIG.</figref><figref num="9">A flowchart showing the details of the expiration date management process in step S13 of FIG. 6 when the encryption key update prohibition period is set.</figref><figref num="10">A block diagram showing another embodiment of the cryptographic communication system according to the present invention that manages the expiration date at each of the bases.</figref><figref num="11">Explanatory drawing of the encryption key management table provided in the encryption communication device of the embodiment of FIG.</figref><figref num="12">Flowchart of encrypted communication processing at the center base in Fig. 10.</figref><figref num="13">A flowchart showing the details of the expiration date management process in step S13 of FIG.</figref><figref num="14">Block diagram of a conventional cryptographic communication system</figref><figref num="15">Block diagram of the functional configuration of the encrypted communication device shown in FIG.</figref><figref num="16">Explanatory drawing of the encryption key management table provided in the encryption communication device of the conventional system of FIG.</figref>
Code description
10: Center base 10-1 ~ 10-4: Base 12-1 ~ 12-3: Local base 14: Network 16-1 ~ 16-4: Cryptographic communication device 18-1 ~ 18-6, 18-11 ~ 18 -42: Terminal device 20-1, 20-2: Frame transmission / reception unit 22-1, 22-2: Encryption key exchange processing unit 24-1 to 24-4: Encryption key management table 26-1: Expiration date management unit 28 -1: CPU load measurement unit 30: -1: Traffic measurement unit 32: CPU 34: Bus 36: RAM 38: ROM 40: Hard disk drive 42: Device interface 44: Keyboard 46: Mouse 48: Display 50: WAN network adapter 52: LAN network adapter
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2015144373A | Cited by | Japan | Search report |
| JP2021501358A | Cited by | Japan | Search report |
| JP2013026840A | Cited by | Japan | Examiner |
| JP2010056852A | Cited by | Japan | Search report |
| JP2011507318A | Cited by | Japan | Search report |
| US8515073B2 | Cited by | United States of America | Applicant |
| JP2011507318A | Cited by | Japan | Examiner |
| JP2011223603A | Cited by | Japan | Search report |
| US8413254B2 | Cited by | United States of America | Applicant |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2006284817 | Japan | A | |
| JP20060284817 | – | – | – |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Withdrawal of application because of no request for examinationA300 | A300 |
Numbers
- Publication
- 2008103988
- Publication, DOCDB
- 2008103988
- Publication, EPODOC
- JP2008103988
- Application
- 284817
- Application, DOCDB
- 2006284817
- Application, EPODOC
- JP20060284817
Titles3
- Japanese
- 暗号通信システム、装置、方法及びプログラム
- English
- Cryptographic communication systems, devices, methods and programs
- English
- ENCRYPTION COMMUNICATION SYSTEM, DEVICE, METHOD AND PROGRAM
Classification
- CPC, 2
- H04L9/0891
- H04L9/0838
- IPC, 1
- H04L9 08