Communication apparatus, communication method and program
Abstract
Problem to be solved.To provide a communication technology capable of making a combination of each encryption piece distributed in a content distribution system unique for each communication device and improving the degree of freedom in system construction. When a node 51 receives a node ID string, a random number string, and an encryption piece from other nodes 50, 51, the node 51 stores them in association with each other. When a piece request is received from another node 51, the node 51 generates a temporary symmetric key using a random number and a private key, determines an encryption part that is a part of the encryption piece, and temporarily determines the encryption part. The encrypted part is further encrypted using the symmetric key. Then, the node 51 has its own node ID in addition to the node ID string associated with the encryption piece and stored, and the random number generated by itself in addition to the random number string associated with the encryption piece and stored. , Sends a new encryption piece, part of which it encrypts, to the other node 51. [Selection diagram] Fig. 1

Term
2.2 yearsto projected expiry
Projected expiry 11 December 2028, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
24 claims: 7 independent, 17 dependent
- 1データの一部であるピースを暗号化して送信する通信装置であって、 他の通信装置によって暗号化されたピースである第1暗号化ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置が暗号化する際に生成した第1一時情報とを受信する受信手段と、 前記第1暗号化ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶する第1記憶手段と、 当該通信装置に割り当てられた第2装置識別情報を記憶する第2記憶手段と、 その生成毎に異なり得る第2一時情報を生成する第1生成手段と、 前記第2一時情報を用いて一時対称鍵を生成する第2生成手段と、 前記第1暗号化ピースのうち暗号化する第1部分を決定する第1決定手段と、 前記一時対称鍵を用いて前記第1部分を更に暗号化して、第2暗号化ピースを出力する暗号化手段と、 前記第2暗号化ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信手段とを備えることを特徴とする通信装置。
- 2前記第1暗号化ピースを複数に分割する分割手段を更に備え、 前記第1決定手段は、分割された前記第1暗号化ピースのうちいずれかの部分である前記第1部分を決定することを特徴とする請求項1に記載の通信装置。
- 3前記第1決定手段は、前記第1暗号化ピースと対応付けられて記憶された前記第1装置識別情報の個数及び前記第1暗号化ピースが分割された数に応じて、前記第1部分を決定することを特徴とする請求項2に記載の通信装置。
- 4前記受信手段は、前記第1暗号化ピースと、前記第1装置識別情報と、前記第1一時情報と、当該第1暗号化ピースのうち暗号化する前記第1部分を指定する第1指定情報とを受信し、 前記第1決定手段は、前記第1指定情報によって指定された前記第1部分を判別することにより、前記第1部分を決定し、 前記送信手段は、前記第2暗号化ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報と、前記第1指定情報と、前記第2暗号化ピースのうち次に暗号化する第2部分を指定する第2指定情報とを送信することを特徴とする請求項1に記載の通信装置。
- 5前記第2暗号化ピースのうち次に暗号化する第2部分を決定する第2決定手段と、 前記第2部分を指定する第2指定情報を生成する生成手段とを更に備えることを特徴とする請求項4に記載の通信装置。
- 6前記受信手段は、前記第1暗号化ピースと、前記第1装置識別情報と、前記第1一時情報と、前記第1部分を決定する手順又は前記第1暗号化ピースに対して行なう暗号化の手順を示す手順情報とを受信し、 前記第1決定手段は、前記手順情報によって指定された前記手順に従って、前記第1部分を決定し、 前記送信手段は、前記第2暗号化ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報と、前記手順情報とを送信することを特徴とする請求項1に記載の通信装置。
- 7前記暗号化手段は、 前記一時対称鍵を用いて前記第1部分を更に暗号化する部分暗号化手段と、 前記第1暗号化ピースのうち前記第1部分以外の全部又は一部である第3部分に対して可逆な変換を行う変換手段と、 暗号化された前記第1部分及び可逆な変換が行なわれた前記第3部分を含む第2暗号化ピースを出力する出力手段とを有することを特徴とする請求項1乃至6のいずれか一項に記載の通信装置。
- 8前記変換手段は、前記第1暗号化ピースのうち前記第1部分以外であって、当該第3部分自体に対する暗号化は行なわれていない第3部分に対して可逆な変換を行うことを特徴とする請求項7に記載の通信装置。
- 9前記変換手段は、前記第3部分に対して前記第1部分を用いて可逆な変換を行うことを特徴とする請求項7又は8に記載の通信装置。
- 10前記第2記憶手段は、当該通信装置に割り当てられている秘密情報を更に記憶し、 前記第2生成手段は、前記第2一時情報と前記秘密情報とを用いて前記一時対称鍵を生成することを特徴とする請求項1乃至9のいずれか一項に記載の通信装置。
- 11前記第2生成手段は、前記第2一時情報と前記秘密情報とを用いて一方向性関数、共通鍵暗号、あるいは擬似乱数生成器により前記一時対称鍵を生成することを特徴とする請求項10に記載の通信装置。
- 12前記ピースを要求するピース要求を受信する要求受信手段を更に備え、 前記第1生成手段は、前記ピース要求が受信された場合に、前記第2一時情報を生成することを特徴とする請求項1乃至11のいずれか一項に記載の通信装置。
- 13データの一部であるピースを受信する通信装置であって、 他の通信装置によって暗号化されたピースである暗号化ピースと、当該他の通信装置に割り当てられている装置識別情報と、当該他の通信装置がピースを暗号化する際に生成した一時情報とを受信する第1受信手段と、 受信された前記暗号化ピース、前記装置識別情報及び前記一時情報を対応付けて記憶する記憶手段と、 前記暗号化ピースを復号するための復号鍵を要求すると共に、当該暗号化ピースと対応付けられて記憶された前記装置識別情報及び前記一時情報を対応付けて含む鍵要求を鍵サーバへ送信する送信手段と、 前記鍵要求に応じて前記鍵サーバから、前記ピースについて行われた暗号化を復号するための各復号鍵を受信する第2受信手段と、 受信された各前記復号鍵と、前記暗号化ピースのうち当該各復号鍵を用いて復号可能な各第1部分との対応関係を判別する判別手段と、 前記判定手段の判定の結果に応じて、各前記復号鍵を用いて前記暗号化ピースの各第1部分を復号する復号手段とを備えることを特徴とする通信装置。
- 14前記暗号化ピースは、前記他の通信装置が各前記一時情報を少なくとも用いて生成した一時対称鍵によって各々暗号化されており、 前記第2受信手段は、前記一時対称鍵である前記復号鍵を前記鍵サーバから受信し、 前記復号手段は、前記判定手段の判定の結果に応じて、各前記一時対称鍵である各前記復号鍵を用いて前記暗号化ピースの各第1部分を復号することを特徴とする請求項13に記載の通信装置。
- 15前記装置識別情報は、前記一時情報と共に順序付けられて前記記憶手段に記憶されており、 前記第2受信手段は、前記装置識別情報に各々対応する前記復号鍵を受信し、 前記判定手段は、 前記暗号化ピースを複数に分割する分割手段と、 前記装置識別情報の順序及び前記暗号化ピースが分割された数に応じて、前記復号鍵を用いて復号可能な各前記第1部分を判別し、 前記復号手段は、前記判定手段の判定の結果に応じて、各前記復号鍵を用いて各前記第1部分を復号することを特徴とする請求項13又は14に記載の通信装置。
- 16前記第1受信手段は、前記暗号化ピースと、前記装置識別情報と、前記一時情報と、前記暗号化ピースのうち暗号化された部分を指定する指定情報とを受信し、 前記記憶手段は、前記暗号化ピース、前記装置識別情報、前記一時情報及び前記指定情報を対応付けて記憶し、 前記判別手段は、前記指定情報を用いて、各前記復号鍵と、前記暗号化ピースのうち当該各復号鍵を用いて復号可能な各前記第1部分との対応関係を判別することを特徴とする請求項13又は14に記載の通信装置。
- 17前記第1受信手段は、前記暗号化ピースと、前記装置識別情報と、前記一時情報と、前記第1暗号化ピースのうち暗号化する前記第1部分を決定する手順又は前記第1暗号化ピースに対して行なう暗号化の手順を示す手順情報とを受信し、 前記記憶手段は、受信された前記暗号化ピース、前記装置識別情報、前記一時情報及び前記指定情報を対応付けて記憶し、 前記判別手段は、前記手順情報を用いて、各前記復号鍵と、前記暗号化ピースのうち当該各復号鍵を用いて復号可能な各前記第1部分との対応関係を判別することを特徴とする請求項13又は14に記載の通信装置。
- 18前記暗号化ピースは、前記暗号化ピースのうち前記第1部分に対する暗号化と共に当該第1部分以外の全部又は一部である第2部分に対して可逆な変換が行われており、 前記復号手段は、 前記判定手段の判定の結果に応じて、各前記復号鍵を用いて各前記第1部分を復号する部分復号手段と、 前記第1部分に対する暗号化と共に共に可逆な変換が行なわれた前記第2部分に対して逆変換を行う逆変換手段とを有することを特徴とする請求項13乃至17のいずれか一項に記載の通信装置。
- 19前記暗号化ピースは、前記暗号化ピースのうち前記第1部分に対する暗号化と共に当該第1部分以外の全部又は一部である第2部分に対して前記第1部分を用いて可逆な変換が行われており、 前記逆変換手段は、復号された前記第1部分を用いて前記第2部分に対して逆変換を行うことを特徴とする請求項18に記載の通信装置。
- 20前記暗号化ピースは、前記ピースの全部が暗号化された後に、各前記第1部分が各々暗号化されており、 前記復号手段は、前記判定手段の判定の結果に応じて、各前記復号鍵を用いて、各前記第1部分及び前記暗号化ピースの全部を復号することを特徴とする請求項13乃至19のいずれか一項に記載の通信装置。
- 21前記暗号化ピースは、前記他の通信装置が前記一時情報及び当該他の通信装置に割り当てられた秘密情報を用いて生成した一時対称鍵により暗号化されており、 前記第2受信手段は、前記一時対称鍵である復号鍵を前記鍵サーバから受信することを特徴とする請求項14に記載の通信装置。
- 22データの一部であるピースを暗号化して送信する通信装置で実行される通信方法であって、 前記通信装置は、受信手段と、記憶制御手段と、第1生成手段と、第2生成手段と、第1決定手段と、暗号化手段と、送信手段とを備え、 前記受信手段が、他の通信装置によって暗号化されたピースである第1暗号化ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置が暗号化する際に生成した第1一時情報とを受信する受信ステップと、 前記記憶制御手段が、前記第1暗号化ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶手段に記憶させる記憶制御ステップと、 前記第1生成手段が、その生成毎に異なり得る第2一時情報を生成する第1生成ステップと、 前記第2生成手段が、前記第2一時情報を用いて一時対称鍵を生成する第2生成ステップと、 前記第1決定手段が、前記第1暗号化ピースのうち暗号化する第1部分を決定する第1決定ステップと、 前記暗号化手段が、前記一時対称鍵を用いて前記第1部分を更に暗号化して、第2暗号化ピースを出力する暗号化ステップと、 前記送信手段が、前記第2暗号化ピースと、前記第1装置識別情報と、当該通信装置に割り当てられた第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信ステップとを含むことを特徴とする通信方法。
- 23データの一部である複数のピースを暗号化して送信する通信装置の有するコンピュータを、他の通信装置によって暗号化されたピースである第1暗号化ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置が暗号化する際に生成した第1一時情報とを受信する受信手段と、 前記第1暗号化ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶手段に記憶させる記憶制御手段と、 その生成毎に異なり得る第2一時情報を生成する第1生成手段と、 前記第2一時情報を用いて一時対称鍵を生成する第2生成手段と、 前記第1暗号化ピースのうち暗号化する第1部分を決定する第1決定手段と、 前記一時対称鍵を用いて前記第1部分を更に暗号化して、第2暗号化ピースを出力する暗号化手段と、 前記第2暗号化ピースと、前記第1装置識別情報と、当該通信装置に割り当てられた第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信手段として機能させるためのプログラム。
- 24データの一部であるピースを受信する通信装置の有するコンピュータを、 他の通信装置によって暗号化されたピースである暗号化ピースと、当該他の通信装置に割り当てられている装置識別情報と、当該他の通信装置がピースを暗号化する際に生成した一時情報とを受信する第1受信手段と、 受信された前記暗号化ピース、前記装置識別情報及び前記一時情報を対応付けて記憶手段に記憶させる記憶制御手段と、 前記暗号化ピースを復号するための復号鍵を要求すると共に、当該暗号化ピースと対応付けられて記憶された前記装置識別情報及び前記一時情報を対応付けて含む鍵要求を鍵サーバへ送信する送信手段と、 前記鍵要求に応じて前記鍵サーバから、前記ピースについて行われた暗号化を復号するための各復号鍵を受信する第2受信手段と、 受信された各前記復号鍵と、前記暗号化ピースのうち当該各復号鍵を用いて復号可能な各第1部分との対応関係を判別する判別手段と、 前記判定手段の判定の結果に応じて、各前記復号鍵を用いて前記暗号化ピースの各第1部分を復号する復号手段として機能させるためのプログラム。
Independent claims24
80 paragraphs, as filed
The present invention relates to communication devices, communication methods and programs.
For example, a distribution method (called P2P distribution) that distributes data using P2P (peer to peer) does not require a data distribution server with a huge storage and a large communication bandwidth, and is a distribution method with great cost merit. is there. Further, since the node that receives the data distribution is expected to supply data from a plurality of nodes, high-speed data acquisition that makes use of the bandwidth in download and upload is expected. In this way, P2P data distribution has great merits, but on the other hand, there were concerns about safety from the viewpoint of data security such as copyright protection. Not limited to P2P distribution, the following are assumed as general assumptions when considering data security such as copyright protection. This means that not all terminal devices or nodes will be hacked. If this premise is denied, the terminal device will not be able to hold data that should be kept secret or perform processing that should be kept secret, and most security technologies and ingenuity for ensuring security will not be established.
By the way, in P2P distribution, there is a content distribution system in which encrypted data is distributed and a node that receives the data distribution acquires a decryption key for decrypting the data (referred to as distribution data). A major problem in data security in P2P distribution of such a system is that the combination of the distribution data and the decryption key for decrypting the distribution data is single or few in number. In this case, suppose a node is hacked and the decryption key is exposed. In this case, this decryption key can be used to decrypt most of the distribution data. One way to solve this problem is to individualize the distribution data for each node.
As a technique for individualizing distribution data for each node in P2P distribution, for example, the Marking method shown in Patent Document 1 is known. In this method, the distribution data is divided into pieces and then encrypted with a key matrix to generate an encrypted piece. As a result, a group of pieces consisting of encrypted pieces encrypted in a matrix is generated. And such a group of pieces is delivered via the P2P network. One node connected to the P2P network obtains one encryption piece from a plurality of encryption pieces encrypted in a matrix for each piece. As a result, it is expected that the combination of encryption pieces in which each piece constituting the distribution data is encrypted is statistically unique for each node.
<patcit num="1"><text>USP 7165050</text></patcit>
<p> However, in the technique of Patent Document 1 described above, it is only statistically expected that the combination of each encryption piece is unique for each node. For example, the following two methods can be considered to realize that the combination of each encryption piece is unique for each node. One is to devise a distribution method for the encrypted piece. One is a method in which the key server holding the decryption key for decrypting each encryption piece restricts the distribution of the decryption key. For example, in order for a node to decrypt a delivered piece group, there is a system that declares a combination of each encryption piece to a key server and obtains a decryption key. In this system, in order to prevent a replay attack due to redistribution of the decryption key, there is a method in which the key server rejects the combination of the decryption key that has already been acquired and the encryption piece that is often duplicated. However, with either method, the distribution efficiency of the encryption piece is sometimes significantly reduced, and the advantages of the P2P network may not be fully utilized. In addition, the former method impairs the independence between data protection and data distribution method, which may be a major constraint on system construction.</p><p> The present invention has been made in view of the above, and it is possible to make the combination of each encryption piece distributed in the content distribution system unique for each communication device, and to increase the degree of freedom in system construction. It is an object of the present invention to provide an improveable communication device, communication method and program.</p>
<p> The present invention solves the above-mentioned problems, and the present invention includes a first encryption piece, which is a communication device that encrypts and transmits a piece that is a part of data, and is a piece encrypted by another communication device. A receiving means for receiving the first device identification information assigned to another communication device and the first temporary information generated when the other communication device encrypts, the first encryption piece, and the first. 1 The first storage means for storing the device identification information in association with the first temporary information and the second storage means for storing the second device identification information assigned to the communication device are different for each generation. The first generation means for generating the second temporary information to be obtained, the second generation means for generating the temporary symmetric key using the second temporary information, and the first part to be encrypted in the first encryption piece are determined. The first determination means to be used, the encryption means for further encrypting the first part using the temporary symmetric key and outputting the second encryption piece, the second encryption piece, and the first device identification. It is characterized by including a transmission means for transmitting information, the second device identification information, the first temporary information, and the second temporary information.</p><p> Further, the present invention is a communication device that receives a piece that is a part of data, and is an encryption piece that is a piece encrypted by another communication device and a device assigned to the other communication device. The first receiving means for receiving the identification information and the temporary information generated when the other communication device encrypts the piece is associated with the received encryption piece, the device identification information, and the temporary information. A key request that requests a storage means to be stored and a decryption key for decrypting the encryption piece, and also includes the device identification information and the temporary information stored in association with the encryption piece. To the key server, a second receiving means for receiving each decryption key for decrypting the encryption performed on the piece from the key server in response to the key request, and each received. Each of the above-mentioned decryption means according to the determination means for determining the correspondence relationship between the decryption key and each first portion of the encryption piece that can be decrypted using the respective decryption keys, and the determination result of the determination means. It is characterized by comprising a decryption means for decrypting each first portion of the encryption piece using a key.</p>
<p> According to the present invention, it is possible to make the combination of each encryption piece distributed in the content distribution system unique for each communication device, and it is possible to improve the degree of freedom in system construction.</p>
The best embodiments of the communication device, communication method and program according to the present invention will be described in detail with reference to the accompanying drawings.
[First Embodiment] (1) Configuration <Content distribution system configuration> FIG. 1 is a diagram showing a configuration of a data distribution system according to the present embodiment. In the data distribution system according to the present embodiment, a plurality of nodes 50, 51A to 51B are connected via the P2P network NT. Other nodes, not shown, may also be connected via P2P network NT. In addition, each node 50, 51A to 51B is connected to the key server 53. Each node 50, 51A to 51B holds a secret key as device identification information uniquely assigned to each node and allocation information uniquely assigned to each node. The device identification information is information assigned to each node in the data distribution system, and may be any information as long as each node can be identified, such as a node ID. Here, the node IDs assigned to the nodes 50, 51A to 51B are ID # 0, ID # 1, ID # 2, respectively, and the private keys are s_0, s_1, s_2, respectively. Of the nodes 50, 51A to 51B, the node 50 is a distribution start node that is a base point for data distribution, and holds data to be distributed (referred to as distribution data). The delivery data may be plaintext or already encrypted ciphertext. For example, the distribution data may be video data protected by some DRM (Digital Rights Management) System as encryption . The key server 53 holds a private key assigned to each of the nodes 50, 51A to 51B. Hereinafter, when it is not necessary to distinguish between the nodes 51A to 51B, the node 51 is simply described.
Here, the hardware configuration of each device of each node 50, 51 and the key server 53 will be described. Each device has a control device such as a CPU (Central Processing Unit) that controls the entire device, and a storage device such as a ROM (Read Only Memory) or RAM (Random Access Memory) that stores various data and various programs. It is equipped with an external storage device such as an HDD (Hard Disk Drive) or CD (Compact Disk) drive device that stores data and various programs, and a bus that connects them, and has a hardware configuration that uses a normal computer. ing. In addition, each device has a display device that displays information, an input device such as a keyboard or mouse that accepts user's instruction input, and a communication I / F (interface) that controls communication of an external device, either wired or wireless. Connected by.
<Configuration of distribution start node> Next, in the above-mentioned hardware configuration, various functions realized by executing various programs stored in the storage device or the external storage device by the CPU of the node 50, which is the distribution start node, will be described. FIG. 2 is a diagram illustrating the functional configuration of the node 50. The node 50 includes a unique information storage unit 500, a random number generation unit 501, a temporary symmetric key generation unit 502, a piece encryption unit 503, a piece encryption unit 504, a data transmission unit 505, and a transmission request reception unit 506. Has. The unique information storage unit 500 is secured as a storage area in an external storage device such as the HDD of the node 50. The random number generation unit 501, the temporary symmetric key generation unit 502, the piece conversion unit 504, the piece encryption unit 503, the data transmission unit 505, and the transmission request reception unit 506 are actually the program execution of the CPU of the node 50. It is sometimes generated on a storage device such as RAM. The distribution data is stored in advance in the external storage device of the node 50.
The unique information storage unit 500 stores the node ID and the private key assigned to the node 50. The piece-forming unit 504 divides the distribution data into a plurality of pieces. The data size at the time of division is not particularly limited, but it is assumed to be predetermined. The transmission request receiving unit 506 receives a piece request from another node 51 requesting the divided pieces by the piece forming unit 504. When the transmission request reception unit 506 receives a piece request, the random number generation unit 501 generates a random number which is temporary information that may differ each time the request is generated. The temporary information may be a value that can be different each time it is generated by the node, and is, for example, a random number, a time stamp, a communication sequence number, a value of a counter unique to the node, or a Time Variant Parameter. The Time Variant Parameter is described in, for example, Document ISO9798-1.
The temporary symmetric key generation unit 502 generates a temporary symmetric key by the function F using the random number generated by the random number generation unit 501 and the secret key stored in the unique information storage unit 500. This is expressed by an equation as follows. k_0 = F (s_0, r_0)
Note that the function F is a one-way function, symmetric key cryptography, or pseudo-random number generator, and even if it knows the secret key or random number that is the input value, the temporary symmetric key that is the output value cannot be inferred from them. is there. The symmetric key is a function F, and the relationship between the input value and the output value of the function F may be uniquely defined. For example, a hash function such as SHA-1 or SHA256 may be used, and AES or Herocrypt. It may be a common key cryptosystem such as, or a pseudo random number generator such as Mersenne twister. A value obtained by combining a random number and a private key may be input to the hash function. In the common key encryption method, a random number may be encrypted with a private key, or the private key may be encrypted with a random number. In the common key cryptosystem, a random number may be decrypted with a private key, or the secret key may be decrypted with a random number. A value obtained by combining a random number and a secret key may be input to the pseudo-random number generator.
The piece encryption unit 503 encrypts the piece using the temporary symmetric key generated by the temporary symmetric key generation unit 502, and outputs the encrypted piece. The temporary symmetric key is also an encryption key used for encryption, and also serves as a decryption key for decrypting the encryption performed on the encryption piece.
The data transmission unit 505 outputs the node ID stored in the unique information storage unit 500, the random number generated by the random number generation unit 501, and the piece encryption unit 503 to the other node 51 that has transmitted the piece request. Send with the encrypted piece.
<Configuration of nodes other than the distribution start node> Next, various functions realized by executing various programs stored in the storage device or the external storage device by the CPU of the node 51 other than the distribution start node will be described. FIG. 3 is a diagram illustrating the functional configuration of the node 51. The node 51 includes a unique information storage unit 510, a random number generation unit 511, a temporary symmetric key generation unit 512, a piece encryption unit 513, a data reception unit 514, a data transmission unit 515, and a transmission request reception unit 516. , A data storage unit 517, a transmission request transmission unit 518, a key request transmission unit 519, a piece decryption unit 520, and an encryption portion determination unit 521. The unique information storage unit 510 and the data storage unit 517 are secured as storage areas in an external storage device such as an HDD of the node 51, for example. Random number generation unit 511, temporary symmetric key generation unit 512, piece encryption unit 513, data transmission unit 515, transmission request reception unit 516, data reception unit 514, key request transmission unit 519, and piece decryption unit. The substance of the 520 and the encryption partial determination unit 521 is generated on a storage device such as RAM when the program of the CPU of the node 51 is executed.
The unique information storage unit 510 stores the node ID and private key assigned to the node 51. The configuration of the transmission request reception unit 516 is the same as the configuration of the transmission request reception unit 506 of the node 50 described above. Transmission request The transmission unit 518 transmits a piece request requesting a piece to node 50 or another node 51. The data receiving unit 514 mediates the transmission of the encrypted piece whose piece is encrypted and the transmission of the encrypted piece from the node 50 or another node 51 to which the transmission request transmitting unit 518 has transmitted the piece request. It receives a node ID string containing each node ID assigned to one other node 50,51 and a random number sequence containing each random number generated by the other node 50,51. The data storage unit 517 stores the node ID string, the random number string, and the encryption piece received by the data reception unit 514 in association with each other. The random number generator 511 generates a random number. The temporary symmetric key generation unit 512 generates a temporary symmetric key by the above-mentioned function F using the random number generated by the random number generation unit 511 and the secret key stored in the unique information storage unit 510.
The encryption part determination unit 521 determines a part (referred to as an encryption part) to be encrypted in the encryption piece to be transmitted. Here, the encryption portion is any portion in which the piece encryption unit 513 described below divides the encryption piece to be transmitted into a plurality of parts. Specifically, the encryption partial determination unit 521 determines the number of times of encryption (referred to as the number of times of encryption) performed on all or a part of the encryption pieces to be transmitted, and the number of times of encryption and the number of times of encryption are used. The encrypted part is determined according to the number of divisions. Here, since the number of encryptions is the same as the number of node IDs included in the node ID column stored in the data storage unit 517 in association with the encryption piece to be transmitted, this number can be calculated. Desired. The piece encryption unit 513 divides the encryption piece to be transmitted into a plurality of pieces, and uses the temporary symmetric key generated by the temporary symmetric key generation unit 512 to use the encryption part determination unit 521 of the encryption pieces to be transmitted. Further encrypts the encrypted part determined by, and performs reversible conversion on a part of the encryption piece to be transmitted other than the encrypted part according to the number of times of encryption, and a new encryption piece is performed. Is output.
The data transmission unit 515 transmits the following data to the other node 51 that has transmitted the piece request received by the transmission request reception unit 516. The data is stored in the encryption piece with a new node ID column including the node ID column stored in the data storage unit 517 in association with the encryption piece and the node ID stored in the unique information storage unit 510. In addition to the random number sequence stored in the data storage unit 517 in association with each other, a new random number sequence including a random number generated by the random number generation unit 511 and a new encryption piece output by the piece encryption unit 513. If the encryption piece is not stored in the data storage unit 517, the piece encryption unit 513 does not output the encryption piece even if the transmission request reception unit 516 receives the piece request, and the data transmission unit 513 does not output the encryption piece. 515 does not send the encryption piece.
Here, the node ID string, the random number string, and the encryption piece transmitted from the nodes 50 and 51 will be specifically described. The node ID and the random number transmitted from the node 50 to one encryption piece are one each, but for convenience of explanation, these may be described as a node string and a random number sequence, respectively. .. As a distribution path of the encryption piece, a case where the encryption piece is transmitted from the node 50 to the node 51A, further from the node 51A to the node 51B, and the key request is transmitted from the node 51B to the key server 53 will be described. For example, in response to a piece request from node 51A for a piece P, node 50 uses a random number r_0 and a private key s_0 to generate a temporary symmetric key k_0, which is used to encrypt and encrypt piece P. Suppose that piece E (k_0) P is output. Then, it is assumed that the node 50 transmits the encryption piece E (k_0) P to the node 51A together with the node ID ID # 0 and the random number r_0. FIG. 4 is a diagram schematically showing information transmitted from node 50 to node 51A. The node 51A is the node ID ID of these nodes. # 0, the random number r_0, and the encryption piece E (k_0) P are associated and stored in the data storage unit 517. The data storage unit 517 holds the correspondence between the node ID and the random number generated by the node to which the node ID is assigned, and keeps the order of distribution, and each node ID string and each random number string. Remember.
Then, when the node 51A transmits an encrypted piece to the piece P in response to the piece request from the node 51B, a random number r_1 is generated, and a temporary symmetric key k_1 is generated using this and the private key s_1. It is assumed that this is used to further encrypt the encryption part that is a part of the encryption piece E (k_0) P and output a new encryption piece. E (k_1) E (k_0) P are the temporary symmetric keys k_0, in order. It is assumed that k_1 indicates that all or part of piece P is encrypted in multiple ways. At this time, the node 51A is assigned to the node 51B, which is stored in the unique information storage unit 510 in addition to the node ID ID # 0 assigned to the node 50, which is stored in the data storage unit 517. In addition to the node ID ID # 1 and the random number r_0 stored in the data storage unit 517, the random number r_1 generated by itself and the encryption piece E (k_1) E (k_0) P are transmitted. FIG. 5 is a diagram schematically showing information transmitted from node 51A to node 51B. The node 51B stores these node ID strings ID # 0, ID # 1, random number strings r_0, r_1, and encryption pieces E (k_1) E (k_0) P in association with each other in the data storage unit 517.
Return to the description in Figure 3. The key request transmission unit 519 transmits a key request requesting a decryption key for decrypting the encryption piece stored in the data storage unit 517 to the key server 53. Here, the key request transmission unit 519 includes the node ID string and the random number string stored in the data storage unit 517 corresponding to the encryption piece in the key request and transmits the key server 53. For example, node 51B has a key request that requests a decryption key for decrypting the encryption piece E (k_1) E (k_0) P shown in FIG. 5, which is output when node 51A encrypts. When sending to the server 53, the key request transmission unit 519 of the node 51B has the node ID column ID # 0, ID. Send a key request containing # 1 and random numbers r_0, r_1. FIG. 6 is a diagram schematically showing information transmitted from the node 51B to the key server 53. As described above, when the node 51 requests the key server 53 for the decryption key for decrypting the encryption piece, the node 51 indicates the distribution path of the encryption piece with the node 50 as the distribution start node as a base point. A node ID string including each node ID of each node 50, 51 that mediates the distribution of the encryption piece and a random number sequence including each random number generated by each of the nodes 50, 51 are transmitted to the key server 53. At the time of these transmissions, the key request transmission unit 519 transmits in a state of maintaining the correspondence between each node ID and the random number generated by the node to which each node ID is assigned.
The piece decryption unit 520 receives the temporary symmetric key transmitted from the key server 53 in response to the key request transmitted by the key request transmission unit 519 as a decryption key, and decrypts the encryption piece using the temporary symmetric key. Node 51B receives the temporary symmetric keys k_0 and k_1 transmitted from the key server 53 in response to the key request including the node ID string and the random number string shown in FIG. FIG. 7 is a diagram schematically showing information transmitted from the key server 53 to the node 51B. The temporary symmetric key k_0 shown in the figure is used by the node 50 when encrypting the piece, and the temporary symmetric key k_1 is used by the node 51 to encrypt the encrypted part of the encrypted piece. It was used in the event. Therefore, the piece decryption unit 520 decrypts the encrypted portion using the temporary symmetric key k_1, and decrypts the entire encrypted piece using the temporary symmetric key k_0. The details of this decoding will be described later. Also, how the key server 53 generates a temporary symmetric key will be described later.
It should be noted that the order and timing from which the node 51 acquires each of the plurality of pieces is not particularly limited, but as described above, each of the plurality of pieces of the node 51 is encrypted. Each encrypted piece is obtained from other nodes 50,51 by piece request. Further, the node 51 receives each temporary symmetric key from the key server 53 by a key request for each encryption piece, and decrypts each encryption piece to obtain the above-mentioned distribution data.
<Key server configuration> Next, various functions realized by the CPU of the key server 53 executing various programs stored in the storage device or the external storage device will be described. FIG. 8 is a diagram illustrating a functional configuration of the key server 53. The key server 53 includes a private key storage unit 530, a data reception unit 531, a temporary symmetric key generation unit 533, and a data transmission unit 534. The private key storage unit 530 is secured as a storage area in an external storage device such as the HDD of the key server 53. The data receiving unit 531, the temporary symmetric key generating unit 533, and the data transmitting unit 534 are actually generated on a storage device such as RAM when the program of the CPU of the key server 53 is executed.
The private key storage unit 530 stores the private key assigned to each node 50,51 in association with the node ID assigned to each node 50,51. The data receiving unit 531 requests a decryption key for decrypting the encryption piece, and receives a key request including the above-mentioned node ID string and random number string from the node 51.
The temporary symmetric key generation unit 533 reads the private key stored in the private key storage unit 530 associated with each node ID included in the node ID column included in the key request received by the data reception unit 531. , A decryption key is generated by the function F using each random number included in the random number string included in the key request. For example, each node ID included in the node ID column is ID # 0, ..., ID # (j), and each node ID ID # m (0 m j) corresponds to r_m, s_m, respectively. It shall be. In this case, for m, the decryption key k_m is expressed by an equation as follows. k_m = F (s_ m, r_ m) The function F is the same as that used by the above-mentioned node 51 when generating the temporary symmetric key. Therefore, here, the temporary symmetric key is restored as the decryption key by the function F using the temporary information and the private key.
The data transmission unit 534 transmits the temporary symmetric key generated by the temporary symmetric key generation unit 533 as the decryption key to the node 51 that has transmitted the key request received by the data reception unit 531. For example, in the above example, the key server 53 responds to a key request including the node ID sequence and the random number sequence shown in FIG. 6, and as shown in FIG. 7, a temporarily symmetric key for each random number r_0, r_1. Obtain k_0 and k_1 and send them to node 51B. In this way, each temporary symmetric key for decrypting each of all the encryptions performed on all or part of one piece is transmitted to node 51B, so that node 51B is concerned. The encryption of the encryption piece can be completely decrypted.
(2) Operation <Distribution start node: Distribution processing> Next, the procedure of the processing performed by the data distribution system according to the present embodiment will be described. First, the procedure of the distribution process performed by the node 50, which is the distribution start node, will be described with reference to FIG. Node 50 divides the distribution data into multiple pieces (step S1). Then, when the node 50 receives a piece request requesting a piece from another node 51 (step S2: YES), the node 50 generates a random number r_0 (step S3). Next, the node 50 generates a symmetric key k_0 by the function F using the random number r_0 and the secret key s_0 stored in the unique information storage unit 500 (step S4). Then, the node 50 encrypts the piece P to be transmitted by using the symmetric key generated in step S4, and outputs the encrypted piece E (k_0) P (step S5). It should be noted that how to determine the piece to be transmitted is not particularly limited.
FIG. 10 is a conceptual diagram of a piece and an encrypted piece encrypted by the node 50. As shown in the figure, the piece encryption unit 503 encrypts the entire piece P and outputs the encrypted piece E (k_0) P.
Then, the node 50 sets the node ID ID # 0 stored in the unique information storage unit 500 to the other node 51 that transmitted the piece request received in step S2, for example, as shown in FIG. The random number r_0 generated in step S4 and the encryption piece E (k_0) P output in step S5 are transmitted (step S6). After that, the process returns to step S2, and the node 50 waits for the reception of a new piece request. The piece request received in step S2 is not necessarily the same node 51, and the piece P requested by the piece request is not necessarily the same piece. Also, the random numbers generated in step S3 are basically different for each process in step S3.
<Reception processing> Next, the procedure of the reception process in which the node 51 receives the encryption piece from the node 50 or another node 51 will be described with reference to FIG. Node 51 sends a piece request requesting a piece to node 50 or another node 51 (step S10). Next, the node 51 receives the node ID string, the random number string, and the encryption piece from the node 50 or another node 51 to which the piece request is transmitted in step S10 (step S11). Then, the node 51 stores the node ID string, the random number string, and the encryption piece received in step S11 in association with each other (step S12).
When the node 51 sends a piece request to the node 50, in step S11, the node ID string, the random number string, and the encryption piece shown in FIG. 4 are received for the piece P. Here, although not shown, a node connected to the P2P network NT, where f is an integer of 1 or more and receives the piece P at the fth position, will be generalized and described. For convenience of explanation, the node ID of the node is ID # f. The node to which node ID ID # f is assigned is the node ID column ID # for piece P, as shown in FIG. 12, from the node to which the (f -1) th node ID ID # (f-1) is assigned. 0, ..., ID # (f-1), random number r_0, ..., r_ {f-1}, and encryption piece E (k_ {f-1}) ... E (k_0) P And receive. This means that the node to which node ID # f is assigned receives an encryption piece that has been encrypted (f-1) times for a part of it, and part of it is encrypted by itself. Means to send an encrypted piece that has been encrypted f times. Note that node ID column ID # 0, ..., Since ID # (f-1) identifies which node the encryption piece was encrypted and transmitted by, the distribution route of the encryption piece is indicated.
<Nodes other than the distribution start node: Distribution processing> Next, the procedure of the distribution process performed by the node 51 other than the distribution start node will be described with reference to FIG. When the node 51 receives a piece request requesting a certain piece P from another node 51 (step S21: YES), the node 51 first generates a random number (step S22). Next, the node 51 generates a temporary symmetric key by the function F using the random number generated in step S22 and the secret key stored in the unique information storage unit 510 (step S23). Next, the node 51 divides the encryption piece recorded in the data storage unit 517 into a plurality of pieces (step S24).
FIG. 14 is a diagram conceptually showing the encryption piece and the processing performed on the encryption piece. The encryption piece EP shown in the first row of the figure is divided into n pieces (integers of n: 2 or more), and as shown in the second row, multiple parts SP # 1, SP # 2, .. .., SP # n is obtained. For convenience of explanation, these are referred to as subpieces, and the numbers 1, 2, ..., N assigned to them are referred to as subpiece numbers.
Next, the node 51 determines the number of times of encryption by using the number of node IDs included in the node ID string stored in the data storage unit 517 in association with the encryption piece to be transmitted. Assuming that the node 51 is the node 51 to which the above-mentioned node ID ID # f is assigned, the node ID included in the node ID column is ID # 0, ..., When ID # (f-1), the number of node IDs is "f-1", so the number of encryptions is "f-1". In this case, the node 51 determines whether or not the number of times of encryption "f-1" is equal to or less than the number of divisions n of the encryption pieces (step S25). When the number of encryptions "f-1" is less than or equal to the number of divisions n (step S25: YES), the whole piece is encrypted by node 50, which is the distribution start node, but is larger than "f-1". It means that each subpiece SP # f, ..., SP # n of the subpiece number has never been encrypted by the node 51 or another node 51. In this case, the node 51 adds "1" to the number of encryptions "f-1" and determines the subpiece SP # f of the subpiece number f corresponding to the value f as the encryption part (step S26). Further, the node 51 is for each subpiece SP # (f + 1), ..., SP # n of the subpiece number (f + 1), ..., n larger than the subpiece number f of the subpiece SP # f. Reversible conversion is performed for each (step S27).
Here, a detailed procedure of the process in which the node 51 performs the reversible conversion in step S27 will be described with reference to FIG. Here, it is assumed that the node 51 performs an XOR (exclusive OR) operation as a reversible conversion. Node 51 uses the subpiece SP # f determined as the encrypted part in step S25 as the first input of the XOR operation (step S40), and sets the index l for setting the subpiece to be the second input to "f + 1". Set (step S41). Next, the node 51 determines whether or not the index l is the number of divisions n or less (step S42), and if the index l is the number of divisions n or less (step S42: YES), the subpiece SP # is used as the second input. Set (f + 1) and perform an XOR operation between the second input and the subpiece SP # f which is the first input (step S43). Then, the node 51 adds "1" to the index l (step S44) and returns to step S42. By repeating the processing of steps S43 to S44 until the index l becomes larger than the number of divisions n (step S42: NO), the node 51 sets each subpiece SP # {f + 1}, ..., SP # n. Each is set as a second input and an XOR operation is performed on the second input and the first input. As a result of performing an XOR operation on each subpiece SP # {f + 1}, ..., SP # n using the subpiece SP # f, as shown in the third row of FIG. 14, the subpiece SP # {f + 1} XOR SP # f, ..., SP # n XOR SP # f is obtained.
Return to the description of FIG. After step S27, node 51 uses the temporary symmetric key generated in step S23 to encrypt the subpiece SP # f determined as the encryption part in step S25, and outputs a new encryption piece (step S28). ). As a result of encrypting the subpiece SP # f using a temporary symmetric key (let's call it k_f), the encrypted subpiece E (k_f) SP # f is shown in the fourth row of FIG. Is obtained. In addition, encryption and reversibility for each subpiece SP # 1, ..., SP # {f-1} of subpiece number 1, ..., {f-1} smaller than subpiece number f of subpiece SP # f. No conversion is done. Here, these SP # 1, ..., SP # {f-1}, the encrypted subpiece E (k_f) SP # f, and the reversibly converted subpiece SP # {f + 1} XOR The one including SP # f, ..., SP # n XOR SP # f is output as a new encryption piece. Then proceed to step S29.
On the other hand, in step S25, when the number of encryptions f is larger than the number of divisions n (step S25: NO), each subpiece SP # 1, ..., SP # {f-1} is the node 51 or another node. It means that it has already been encrypted more than once by 51. In this case, the node 51 determines the subpiece SP # {f mod n} of the subpiece number having the same value as "f mod n", which is the remainder obtained by dividing the number of encryptions f by the number of divisions n, as the encryption part (step). S30). Then, the node 51 uses the temporary symmetric key generated in step S23 to encrypt the subpiece SP # {f mod n} determined as the encryption part in step S28, and outputs a new encryption piece (step). S31). Neither encryption nor reversible conversion is performed on subpieces other than subpiece SP # {f mod n}, and here, subpieces other than subpiece SP # {f mod n} and encrypted subpiece E ( k_f) The one containing SP # {f mod n} is output as a new encryption piece. Then proceed to step S29.
In step S29, the node 51 sets the node ID stored in the data storage unit 517 in association with the encryption piece to be transmitted to the other node 51 that transmitted the piece request received in step S21. In addition, a new node ID string including the node ID stored in the unique information storage unit 510, a random number sequence associated with the encryption piece and stored in the data storage unit 517, and the random number generated in step S22 are included. The new random number sequence and the new encryption piece output in step S27 or S29 are transmitted.
When the new encryption piece output in step S28 or S31 is represented by E (k_f) ... E (k_0) P, the node 51 to which the node ID ID # f is assigned is the (f + 1) th. For node 51 to which node ID ID # (f + 1) is assigned, node ID column ID # 0, ..., ID # (f-1), ID for piece P, as shown in FIG. Send #f, random number strings r_0, ..., r_f, and encryption piece E (k_f) ... E (k_0) P.
As described above, the node 51 determines and encrypts the encryption part according to the number of times of encryption and the number of divisions, and performs a reversible conversion on a part other than the encrypted part. Send. As a result, until the number of encryptions reaches n times, each time the encryption piece is encrypted in the distribution process, the subpieces divided into n pieces are encrypted in order, and the node 51 or the like is encrypted. A state in which a reversible conversion is performed on a subpiece that has not been partially encrypted by the node 51 of the above. Further, when the number of times of encryption becomes n times or more, each time the encryption piece is encrypted in the process of distribution, the encryption pieces are sequentially encrypted for each subpiece that has already been partially encrypted. It will be in the state where it was done.
<Decryption process> Next, the procedure of the decryption process in which the node 51 acquires the decryption key from the key server 53 and decrypts the encryption piece using the decryption key will be described with reference to FIG. The node 51 reads the node ID string and the random number string associated with the encryption piece stored in the data storage unit 517 (step S50), requests a decryption key for decrypting the encryption piece, and requests a decryption key. A key request including the node ID string and the random number string is transmitted to the key server 53 (step S51). Next, the node 51 receives the temporary symmetric key transmitted from the key server 53 as the decryption key in response to the key request transmitted in step S30 (step S52), and decrypts the encryption piece using the temporary symmetric key. (Step S53).
Here, a detailed procedure of the process in which the node 51 decrypts the encryption piece in step S53 will be described with reference to FIG. Here, it is assumed that the node 51 is a node to which the node ID ID # (f + 1) is assigned, and for the key server 53, as shown in FIG. 19, for the piece P, the node ID column ID # It is assumed that 0, ..., ID # (f-1), ID # f and the random number sequence r_0, ..., r_ {f-1}, r_f are transmitted. Then, the node 51 receives the temporary symmetric key k_0, ..., from the key server 53 with respect to the piece P as shown in FIG. Suppose you are receiving k_f. First, the node 51 determines the correspondence between each received temporary symmetric key and an encrypted part of the encryption piece that can be decrypted using each temporary symmetric key, and decrypts each encrypted part. That is, in order to determine which encryption part of the encryption piece to be decrypted can be decrypted by using each temporary symmetric key, the following processing is performed. Node 51 divides the encryption piece to be decrypted into n subpieces as described above, and sets the index l for setting the subpiece to be decrypted to "f" in order to decrypt each subpiece. Step S60), it is determined whether or not the index l is less than or equal to the number of divisions n (step S61). When the index l is less than or equal to the number of divisions n (step S61: YES), the node 51 uses the subpiece SP # l as the encryption part of the temporary symmetric key received in step S32 that can be decrypted using the temporary symmetric key k_l. It is determined that there is, and the subpiece SP # l is decrypted using the temporary symmetric key k_l (step S62). On the other hand, when the index l is larger than the number of divisions n (step S61: NO), the node 51 has the subpiece SP # (the encrypted part that can be decrypted using the temporary symmetric key k_l among the temporary symmetric keys received in step S32). It is determined that l mod n), and the subpiece SP # (l mod n) is decrypted using the temporary symmetric key k_l (step S63). Node 51 then subtracts "1" from the value of index l ́ (step S64) to determine if the value of index l ́ is greater than or equal to 1 (step S65), and index l ́ If the value of is greater than or equal to "1" (step S65: YES), the process returns to step S61. Node 51 repeats the process of step S62 or S63 until the value of index l becomes smaller than "1".
If the value of the index l is less than "1" (step S65: NO), node 51 sets the index l ́ to "0" to set the subpiece to be XORed (step S66). , Set the first input of the XOR operation to the subpiece SP # l ́ (step S67). The encryption for the subpiece SP # l ́ has already been decrypted in steps S62 or S63. Then, the node 51 sets the first input of the XOR operation to the subpieces SP # (l ́ + 1), ..., SP # n, respectively, and performs the XOR operation of each of the second input and the first input, respectively. Do (step S68). Node 51 then adds "1" to the value of index l ́ (step S69), determines if the value of index l ́ is less than or equal to n-1 (step S70), and index l ́. If the value of ́ is less than or equal to n-1 (step S70: YES), the process returns to step S67. Node 51 repeats the processing of steps S67 to S69 until the value of the index l ́ becomes larger than n-1. As a result, the node 51 performs the inverse conversion of the conversion performed in step S27. And index l If the value of ́ is greater than n-1 (step S70: NO), node 51 uses the temporary symmetric key k_0 to decrypt the entire encryption piece. As a result, as shown in the second row of FIG. 14, each sub-piece is decrypted and a piece in which the first decryption is performed for the whole is obtained.
After that, the node 51 uses the temporary symmetric key k_0 of the temporary symmetric keys received in step S32 in order to decrypt the encryption performed by the node 50 which is the distribution start node for the entire encryption piece, and uses the temporary symmetric key k_0 in step S60. Decrypt the encryption piece obtained as a result of ~ 70 to obtain the piece (step S71). In this way, each node 51 can decrypt the encryption performed on each piece and reverse the conversion by obtaining all the temporary symmetric keys for decrypting the encryption performed on each piece. It is possible to completely restore the encryption piece. Therefore, each node 51 receives each temporary symmetric key from the key server 53 by a key request for each encryption piece encrypted by each of the plurality of pieces, and restores each encryption piece to deliver the above-mentioned distribution. You can get the data.
<Key server: key transmission process> Next, the procedure of the key transmission process in which the key server 53 transmits the decryption key in response to the key request from the node 51 will be described with reference to FIG. When the key server 53 requests a decryption key for decrypting the encryption piece and receives a key request including a node ID string and a random number string from the node 51 (step S80: YES), the key server 53 is included in the received key request. The private key stored in the private key storage unit 530 associated with each node ID included in the node ID column is read out for each node ID (step S81). Then, the key server 53 uses the random numbers for all the node IDs and the private key read in step S81 to generate a temporary symmetric key as a decryption key by the function F for each node ID (step S82). Next, the key server 53 transmits the temporary symmetric key generated as the decryption key in step S82 to the node 51 that transmitted the key request received in step S80 (step S83).
For example, the key server 53 responds to the key request including the node ID string and the random number string as shown in FIG. 19 for the piece P for the node to which the above-mentioned node ID ID # (f + 1) is assigned. , Send the temporary symmetric keys k_0, ..., k_f as shown in Figure 20.
According to the above configuration, the combination of the encryption pieces acquired by a certain node is unique to the delivery route and the delivery time, and can be surely unique. With such a configuration, it is possible to surely enhance the uniqueness of each node for each combination of encryption pieces acquired by each node without any special device regarding the distribution method in P2P distribution, and it is safe. Can be improved. Furthermore, it becomes possible to maintain independence between data protection and the data distribution method, and it becomes possible to improve the degree of freedom in system construction.
For example, suppose that each node 51 acquires all the encrypted pieces in which each of the plurality of pieces is encrypted. The distribution route of each encryption piece is various. Therefore, if the encryption piece is different, the distribution route is likely to be different, so that the combination of node IDs associated with each encryption piece is likely to be different. Further, when the distribution paths of different encryption pieces are the same, the combination of node IDs associated with each encryption piece is the same, but the random numbers corresponding to each node are different.
For example, it is assumed that the distribution data is divided into N pieces (integers of N: 2 or more) of P1 to PN. At this time, it is assumed that the node to which the above-mentioned node ID ID # f is assigned stores, for example, the piece P1 in association with the following data. Node ID column: ID # 0, ID # 1, ..., ID # (f-1) Random number sequence: r_0, r_1, ..., r_ {f-1} Encryption piece: E (k_t) ... E (k_0) P1
Further, it is assumed that the node receives the encryption piece at the i-th place instead of the f-th place for another piece P2, and stores the following data in association with each other. Node ID column: ID # 0, ID'# 1, ..., ID' # (i-1) Random number sequence: r_0, r ́_1, ..., r ́_ {i-1} Encryption piece: E ({k ́_ (i-1)}) ... E (k ́_1) E (k_0) P2 Note that ID'# 1, ..., ID'# (i-1) is a series of node IDs different from ID # 1, ..., ID # (j-1). In addition, r_0, r ́_1, ..., r ́_ {i-1} were generated by each node to which each node ID of ID'# 1, ..., ID'# (i-1) was assigned. It is a random number, and each one is different. In addition, k_0 is a temporary symmetric key generated by node 50, and k ́_1, ..., k ́_ (i-1) is assigned to each node ID ID # 1, ..., ID # (i-1). It is a temporary symmetric key generated by each node.
In this way, even in the same node, the temporary symmetric key required to decrypt the encryption piece is different for each piece. Also, different nodes require different temporary symmetric keys to decrypt each encryption piece, even if they are the same piece. Therefore, if the node is different, the combination of the encryption pieces is different for each of the plurality of pieces. That is, the combination of the encryption pieces in which all the pieces constituting the distribution data are encrypted can be surely different for each node. Therefore, according to the present embodiment, the uniqueness of each node can be surely enhanced for the combination of each encryption piece acquired by each node.
Further, when the node 51 transmits an encryption piece to another node 51, the processing load when decrypting the encryption piece is reduced by encrypting not all but a part of the encryption piece. Can be done. For example, the effect is remarkable when the moving image content is played back in real time.
[Modification example] The present invention is not limited to the above-described embodiment as it is, and at the implementation stage, the components can be modified and embodied within a range not deviating from the gist thereof. In addition, various inventions can be formed by an appropriate combination of the plurality of components disclosed in the above-described embodiment. For example, some components may be removed from all the components shown in the embodiments. In addition, components across different embodiments may be combined as appropriate. In addition, various modifications as illustrated below are possible.
<Modification example 1> In the above-described embodiment, various programs executed by each node 50 may be stored on a computer connected to a network such as the Internet and provided by downloading via the network. In addition, the program is recorded on a computer-readable recording medium such as a CD-ROM, flexible disk (FD), CD-R, or DVD (Digital Versatile Disk) in an installable or executable format. It may be configured to provide. In this case, the program is loaded on the main storage device (for example, RAM) by reading from the recording medium and executing the program at each node 50, and each part described in the above functional configuration is generated on the main storage device. To. The same applies to various programs executed on the key server 53.
Further, in the above-described embodiment, all or a part of each part described in the functional configuration of each node 50 may be configured by hardware. The same applies to all or part of each part described in the functional configuration of the key server 53.
<Transformation example 2> In the above-described embodiment, the node ID may be any information that can uniquely identify each node, and may be, for example, an IP address, a MAC address, a URL, or the like of each node.
<Modification example 3> In the data distribution system of the above-described embodiment, the number of distribution start nodes may be a plurality. In addition, the number of other nodes connected to the P2P network NT is not particularly limited.
<Modification example 4> In the above-described embodiment, a plurality of pieces may be required by one piece request. In this case, the nodes 50 and 51 may transmit the set of the encryption piece, the node ID string, and the random number string for each of the plurality of pieces to the other node 51 that has sent the piece request.
Further, in the above-described embodiment, the nodes 50 and 51 are configured to transmit the encrypted piece in response to the piece request, but the present invention is not limited to this, and the node 51 does not have to receive the piece request to the other nodes 51. The ID node sequence and the random number sequence may be transmitted together with the encryption piece.
<Modification example 5> In the above-described embodiment, when the encryption pieces are acquired for all the pieces constituting the distribution data and stored in the data storage unit 517, the node 51 requests a key for decrypting each encryption piece. It may be sent to the key server 53. Alternatively, the node 51 makes a key request for decrypting the encryption piece stored in the data storage unit 517 even if the encryption piece has not been acquired for all the pieces constituting the distribution data. It may be sent to 53. Further, the node 51 may request a decryption key for decrypting one encryption piece by one key request, or request each decryption key for decrypting a plurality of encryption pieces. You may do so.
<Modification example 6> In the above-described embodiment, a temporary symmetric key, which is both an encryption key and a decryption key for decrypting the encryption, is used for encrypting the piece. However, the encryption key used for encrypting the piece and the decryption key for decrypting the encryption performed on the encryption piece may be different from each other. For example, the public key may be used as the encryption key.
Further, in the above-described embodiment, the nodes 50 and 51 generate a random number each time the encryption piece stored in the data storage unit 517 is transmitted to another node 51. However, the nodes 50 and 51 may generate random numbers according to the number of transmissions of the encryption piece, for example, instead of generating random numbers each time. For example, the nodes 50 and 51 may generate a new random number every time the encryption piece is transmitted a predetermined number of times (for example, 5 times). Further, the timing at which the nodes 50 and 51 generate random numbers may be when a piece request is received from another node 51, or may be at predetermined time intervals.
<Modification 7> In the above-described embodiment, the node ID sequence and the random number sequence that the node 51 transmits to the other node 51 together with the encryption piece are not limited to the modes shown in FIGS. 4 to 5, 12, 16. For example, (ID # 0, r_0), (ID # 1, r_1) ... (ID # f, r_f), etc., a set of a node ID and a random number corresponding to the node ID is set for each node ID. It may be in the form shown.
<Modification example 8> In the above-described embodiment, the secret key is used as the secret information uniquely assigned to each of the nodes 50 and 51, but the present invention is not limited to this.
Further, in the above-described embodiment, the private key is uniquely assigned to each node 50, 51, but the present invention is not limited to this. For example, the same private key may be assigned to some of the nodes 50 and 51.
<Modification example 9> In the above-described embodiment, the encryption piece is configured so that each time the encryption piece is encrypted in the process of distribution, the sub-pieces to be the encryption part are encrypted in order from the left, but the present invention is limited to this. Instead, it may be encrypted in order from the right or in a random order.
Further, in the above-described embodiment, the node 51 divides the encryption piece into a plurality of subpieces when encrypting the encryption piece, but the method of division may be equally divided. However, it does not have to be divided equally, and the number of divisions n may be variable rather than fixed. Further, each node 51 may select a part of the data range of the data of the encryption piece as the encryption part and encrypt the encryption piece without dividing the encryption piece.
Further, in the above-described embodiment, when the node 51 encrypts a part of the encryption piece stored in the data storage unit 517 and sends it to another node 51, the encryption that the node 51 encrypts. The part is prevented from overlapping with the encrypted part encrypted by the node 51 transmitted to the node 51, but it may be duplicated.
<Modification example 10> In the above-described embodiment, each node 51 determines the number of encryptions using the number of node IDs included in the node ID column, and determines the encryption portion according to the number of encryptions. However, the present invention is not limited to this, for example, the node 50 that transmits the encryption piece, 51 (called a source node) may specify an encryption part to be encrypted for a node 51 (called a destination node) that receives the encryption piece. The specification of the encryption part may be, for example, the subpiece number when the encryption piece is divided into n subpieces as described above, or in the data range of a part of the data of the encryption piece. There may be. In this way, the designated information that specifies the encrypted portion is transmitted from the source node to the destination node together with the node ID string, the random number string, and the encryption piece. Then, the destination node stores the designated information together with the node ID string, the random number string, and the encryption piece. When transmitting the encryption piece to a new destination node, the encrypted part specified by the specified information is encrypted with the above-mentioned temporary symmetric key, and then the destination node to be the next destination encrypts the encrypted part. The encryption part to be output is determined, the specified information that specifies the encrypted part is generated, and the specified information and the specified information received from the source node (referred to as the specified information string) are the node ID including its own node ID. Sends to a new destination node with a column, a random sequence containing a random number generated by itself, and a new encryption piece. The designated information received from the source node is information for designating the already encrypted encrypted portion of the encryption piece for the new destination node. When the new destination node receives the designated information string, the node ID string, the random number string, and the new encryption piece, it stores them in association with each other. Then, when decrypting the encryption piece, the node acquires a temporary symmetric key from the key server 53 in the same manner as described above, and applies each temporary symmetric key to each encryption portion specified by each specified information. Decrypt using. Since the part encrypted by the node 50, which is the distribution start node, is the entire piece as described above, the node 51 uses the temporary symmetric key corresponding to the node 50 without using the specified information. The whole can be decrypted. Even with the above configuration, the piece can be restored correctly and the processing load required for decryption can be reduced.
Further, as the specified information, for example, a VM code that describes the encryption procedure itself to be performed on the encryption piece to be transmitted, or a procedure to determine the encryption part of the encryption piece to be transmitted. Procedure information such as VM code that describes itself may be used. In this case, when transmitting the encryption piece to another node 51, the node 51 determines the encryption part according to the procedure shown in the procedure information stored in association with the encryption piece, and encrypts the encryption piece. The new encryption piece after the encryption may be transmitted to the other node 51 together with the above-mentioned node ID string and random number string with the procedure information added. Further, when decrypting the encryption piece, the node 51 uses the procedure shown in the procedure information stored in association with the encryption piece to obtain each temporary symmetric key received from the key server 53. It suffices to determine the correspondence relationship with the encryption part which can be decrypted by using each temporary symmetric key of the encryption piece, and decrypt each encryption part.
<Modification example 11> In the above-described embodiment, an XOR operation using the encrypted part as the first input is performed as a reversible conversion performed on a part of the encrypted piece to be transmitted other than the encrypted part according to the number of times of encryption. I tried to do. However, the present invention is not limited to this, and it is not necessary to use the encrypted part as the first input, and the conversion method is a reversible conversion that can be restored by performing an inverse conversion on the performed conversion. , It does not have to be an XOR operation.
Alternatively, reversible conversion may not be performed on a part of the encryption piece to be transmitted other than the encrypted part.
<Modification example 12> In the above-described embodiment, the above-mentioned encryption piece, node ID string, and random number string may be configured to be distributed in the form of packaged package data. In this case, the package data may be recorded on a computer-readable recording medium and provided to the node, or may be configured to be downloaded to the node via the server. In response to the piece request, the node that has acquired the package data can use the encryption piece that encrypts the encryption piece included in the package data and the package data in the same manner as in the above embodiment. The included node ID and its own node ID, and the random number sequence included in the package data and the random number generated by itself may be transmitted to other nodes.
<figref num="1">It is a figure which shows the structure of the data distribution system which concerns on 1st Embodiment.</figref><figref num="2">It is a figure which illustrates the functional configuration of the node 50 which concerns on the embodiment.</figref><figref num="3">It is a figure which illustrates the functional configuration of the node 51 which concerns on the embodiment.</figref><figref num="4">It is a figure which shows typically the information transmitted from the node 50 to the node 51A which concerns on the embodiment.</figref><figref num="5">It is a figure which shows typically the information transmitted from the node 51A to the node 51B which concerns on the embodiment.</figref><figref num="6">It is a figure which shows typically the information which is transmitted from the node 51B which concerns on this embodiment to a key server 53.</figref><figref num="7">It is a figure which shows typically the information transmitted from the key server 53 to the node 51B which concerns on this embodiment.</figref><figref num="8">It is a figure which illustrates the functional configuration of the key server 53 which concerns on this embodiment.</figref><figref num="9">It is a flowchart which shows the procedure of the distribution processing performed by the node 50 which is the distribution start node which concerns on this embodiment.</figref><figref num="10">It is the figure which conceptually represented the piece and the encryption piece which node 50 encrypted this piece.</figref><figref num="11">It is a flowchart which shows the procedure of the reception process which the node 51 which concerns on this embodiment receives the encryption piece from a node 50 or another node 51.</figref><figref num="12">It is a figure which shows typically the information received by the node which concerns on the embodiment.</figref><figref num="13">It is a flowchart which shows the procedure of the distribution processing performed by the node 51 other than the distribution start node which concerns on this embodiment.</figref><figref num="14">It is a figure which conceptually represented the encryption piece and the processing performed on the encryption piece.</figref><figref num="15">It is a flowchart which shows the detailed procedure of the process which the node 51 which concerns on the same embodiment perform a reversible conversion in step S27 of FIG.</figref><figref num="16">It is a figure which shows typically the information transmitted by the node which concerns on the embodiment.</figref><figref num="17">FIG. 5 is a flowchart showing a procedure of a decryption process in which the node 51 according to the embodiment acquires a decryption key from the key server 53 and decrypts the encryption piece using the decryption key.</figref><figref num="18">It is a flowchart which shows the detailed procedure of the process which the node 51 which concerns on the same embodiment in step S53 of FIG. 17 decrypts the encryption piece.</figref><figref num="19">It is a figure which shows typically the information transmitted by the node which concerns on the embodiment.</figref><figref num="20">It is a figure which shows typically the symmetric key received by the node which concerns on the embodiment.</figref><figref num="21">FIG. 5 is a flowchart showing a procedure of a key transmission process in which the key server 53 according to the embodiment transmits a decryption key in response to a key request from the node 51.</figref>
Code description
50,51,51A, 51B nodes 53 key server 500 Unique information storage 501 Random number generator 502 Temporary symmetric key generator 503 piece encryption part 504 Pieces 505 data transmitter 506 Transmission request reception department 510 Unique information storage 511 Random number generator 512 Temporary symmetric key generator 513 piece encryption part 514 Data receiver 515 Data transmitter 516 Transmission request reception department 517 Data storage 518 Transmission request transmitter 519 Key request transmitter 520 piece decoding unit 521 Encryption part determination part 530 Private key storage 531 Data receiver 533 Temporary symmetric key generator 534 Data transmitter NT P2P network
22 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11374854B2 | Cited by | United States of America | Applicant |
| US9736236B2 | Cited by | United States of America | Applicant |
| US12107757B2 | Cited by | United States of America | Applicant |
| JP2012151546A | Cited by | Japan | Examiner |
| US9438669B2 | Cited by | United States of America | Applicant |
| CN111355656A | Cited by | China | Search report |
| JP2015222982A | Cited by | Japan | Examiner |
| JP2012151849A | Cited by | Japan | Examiner |
2 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2008315611 | Japan | A | |
| JP20080315611 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| WO2010067660A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2010141567AThis record | Japan | A |
Numbers
- Publication
- 2010141567
- Publication, DOCDB
- 2010141567
- Publication, EPODOC
- JP2010141567
- Application
- 315611
- Application, DOCDB
- 2008315611
- Application, EPODOC
- JP20080315611
Titles2
- Japanese
- 通信装置、通信方法及びプログラム
- English
- Communication equipment, communication methods and programs
Classification
- CPC, 2
- H04W12/033
- H04W12/041
- IPC, 3
- H04L9 08
- H04W12 02
- H04L12 22