JP2008125064A

Encrypted tape access control method and system via challenge-response protocol

Abstract

[Subject] While offering data security, the encryption and the decryption method of being easy to operate the data on the medium for computers are offered. [Solution means] Access to the encoded data on [like a computer tape / which can be removed] a computer medium is controlled by asymmetrical encipherment through the header structurized peculiar [on the medium which has the symmetrical key by which the lap was carried out, and a public key relevant to asymmetrical encipherment]. The data on a medium is enciphered using a symmetrical key. That is, it acts as Ann Rapp of the symmetrical key using a secret key, and the symmetrical key which acted as Ann Rapp is used in order to decrypt the data on a medium. [Selection figure] Fig. 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 4 independent, 16 dependent

  1. 1
    A header located on a removable computer-readable medium containing a symmetric key wrapped by asymmetric encryption and a public key associated with the asymmetric encryption, and placed on a removable computer-readable medium and encrypted using the symmetric key. Receives the encrypted data and the medium, generates a challenge including the public key to the automatic host, receives a response from the host signed by the private key associated with the public key, and receives the signed response. In response to confirmation of the signed response with a reader configured to confirm, the private key is used to unwrap the symmetric key, and the unwrapped symmetric key is used to unwrap the encrypted data. A system that includes a data decryption device that is configured to decrypt. 取外し可能コンピュータ可読媒体に配置され、非対称暗号化によってラップされた対称鍵および前記非対称暗号化に関連した公開鍵を含むヘッダと、 取外し可能コンピュータ可読媒体に配置され、前記対称鍵を使って暗号化された暗号化データと、 前記媒体を受取り、前記公開鍵を含むチャレンジを自動ホストに発生し、前記公開鍵に関連した秘密鍵によってサインされた前記ホストからの応答を受取り、前記サインされた応答を確認するように構成された読取装置と、 前記サインされた応答の確認に応答して、前記秘密鍵を使って前記対称鍵をアンラップし、前記アンラップされた対称鍵を使って前記暗号化データを復号化するように構成されたデータ復号化装置と、 を含むシステム。
  2. 7
    In the step of receiving a removable computer-readable medium by a reader, the medium is placed with a symmetric key wrapped by asymmetric encryption and a public key associated with the asymmetric encryption and encrypted using the symmetric key. The receiving step, the step of generating a challenge including the public key from the reader to the automatic host, and the response signed by the private key associated with the public key, which have a coded version of the symmetric encrypted data. In response to the confirmation of the signed response, the step of unwrapping the symmetric key using the private key, and the step of decrypting the encrypted data using the unwrapped symmetric key. And how to include. 取外し可能コンピュータ可読媒体を読取装置によって受取るステップであって、前記媒体は非対称暗号化によってラップされた対称鍵および前記非対称暗号化に関連した公開鍵を配置され、前記対称鍵を使って暗号化された対称暗号化データを符号化したものを有する、前記受取るステップと、 前記公開鍵を含むチャレンジを前記読取装置から自動ホストに発生するステップと、 前記公開鍵に関連した秘密鍵によってサインされた応答を前記ホストから受取るステップと、 前記サインされた応答の確認に応答して、前記秘密鍵を使って前記対称鍵をアンラップするステップと、 前記アンラップされた対称鍵を使って前記暗号化データを復号化するステップと、 を含む方法。
  3. 13
    In the step of receiving a removable computer-readable medium by a reader, the medium is placed with a symmetric key wrapped by asymmetric encryption and a public key associated with the asymmetric encryption and encrypted using the symmetric key. The receiving step, the step of generating a challenge including the public key from the reader to the automatic host, and the response signed by the private key associated with the public key, which have a coded version of the symmetric encrypted data. The step of receiving the data from the host, the step of unwrapping the symmetric key using the private key in response to the confirmation of the signed response, and the decryption of the encrypted data using the unwrapped symmetric key. A computer program that is configured to perform the steps of cryptography. 取外し可能コンピュータ可読媒体を読取装置によって受取るステップであって、前記媒体は非対称暗号化によってラップされた対称鍵および前記非対称暗号化に関連した公開鍵を配置され、前記対称鍵を使って暗号化された対称暗号化データを符号化したものを有する、前記受取るステップと、前記公開鍵を含むチャレンジを前記読取装置から自動ホストに発生するステップと、 前記公開鍵に関連した秘密鍵によってサインされた応答を前記ホストから受取るステップと、 前記サインされた応答の確認に応答して、前記秘密鍵を使って前記対称鍵をアンラップするステップと、 前記アンラップされた対称鍵を使って前記暗号化データを復号化するステップと、 を行うように構成されたコンピュータ・プログラム。
  4. 19
    A symmetric key encoded on a removable computer-readable medium and wrapped by asymmetric encryption, a coded public key associated with the asymmetric encryption on the medium, and an encoded on the medium. Also, a computer program containing symmetric encrypted data encrypted using the symmetric key. 取外し可能コンピュータ可読媒体上に符号化された、非対称暗号化によってラップされた対称鍵と、 前記媒体上の符号化された、前記非対称暗号化に関連する公開鍵と、 前記媒体上の符号化された、前記対称鍵を使って暗号化された対称暗号化データと、 を含む、コンピュータ・プログラム。