Communication device, and method and program for processing information
Abstract
Problem to be solved.To securely share an encryption key without introducing a public key certificate or PKI. A terminal device A102 generates a partial key tA and transmits it to a terminal device B103. The terminal device B generates the partial key tB, calculates the encryption key 203 using the partial key tA, applies the ID-based digital signature 204 based on the ID 13 of the terminal device B to the partial key tA and the partial key tB, and performs the partial key tB. Send the key tB and the digital signature to the terminal device A. The terminal device A verifies the electronic signature using the ID 13 of the terminal device B, and if the verification is successful, calculates the encryption key 205 using the partial key tB and uses it as the encryption key used for communication with the terminal device B. Further, the partial key tA and the partial key tB are given an ID-based electronic signature 206 based on ID 11 of the terminal device A and transmitted to the terminal device B. The terminal device B verifies the electronic signature 206 using the ID 11 of the terminal device A, and if the verification is successful, the previously generated encryption key 203 is used as the encryption key used for communication with the terminal device A. [Selection diagram] Fig. 2

Term
Projected expiry 5 October 2029.
- Priority and filed
- Published
- Today
- Projected expiry
16 claims: 4 independent, 12 dependent
- 1共有される暗号鍵の生成に用いられる部分鍵を第1の部分鍵として生成し、生成した前記第1の部分鍵を前記暗号鍵の共有先となる共有先通信装置に送信し、前記共有先通信装置により生成された部分鍵を第2の部分鍵として前記共有先通信装置から受信する通信装置であって、 前記通信装置の公開ID(Identification)に対応づけられて生成された秘密鍵を記憶する秘密鍵記憶部と、 前記第1の部分鍵と前記第2の部分鍵と前記通信装置の公開IDを用いて通信相手が前記通信装置であることを前記共有先通信装置において検証可能なIDベース電子署名を、前記第1の部分鍵と前記第2の部分鍵と前記秘密鍵を用いて生成する電子署名生成部と、 前記電子署名生成部により生成されたIDベース電子署名を前記共有先通信装置に送信する通信部とを有することを特徴とする通信装置。
- 2前記通信部は、 電子署名を受信し、 前記通信装置は、更に、 前記共有先通信装置の公開IDを記憶するID記憶部と、 前記第1の部分鍵と前記第2の部分鍵と前記共有先通信装置の公開IDを用いて前記通信部により受信された電子署名を検証し、通信相手が前記共有先通信装置であるか否かを判定する電子署名検証部とを有することを特徴とする請求項1に記載の通信装置。
- 3前記通信部は、 前記共有先通信装置において楕円曲線演算が行われて生成された前記第2の部分鍵を受信し、 前記通信装置は、更に、 所定の乱数値に対して楕円曲線演算を行って前記第1の部分鍵を生成し、 前記電子署名生成部によるIDベース電子署名の生成過程において楕円曲線演算を行い、 前記電子署名検証部による電子署名の検証過程において楕円曲線演算を行い、 前記電子署名検証部により通信相手が前記共有先通信装置であると判定された場合に、前記第1の部分鍵の生成に用いられた乱数値と前記第2の部分鍵を用いて楕円曲線演算を行って前記共有先通信装置と共有する暗号鍵を生成する演算部を有することを特徴とする請求項2に記載の通信装置。
- 4前記通信部は、 前記共有先通信装置において楕円曲線演算が行われて生成された前記第2の部分鍵を受信し、 前記通信装置は、更に、 所定の乱数値に対して楕円曲線演算を行って前記第1の部分鍵を生成し、 前記電子署名生成部によるIDベース電子署名の生成過程において楕円曲線演算を行い、 前記電子署名検証部による電子署名の検証過程において楕円曲線演算を行い、 前記電子署名検証部による電子署名の検証に先立ち、前記第1の部分鍵の生成に用いられた乱数値と前記第2の部分鍵を用いて楕円曲線演算を行って暗号鍵を生成する演算部を有し、 前記電子署名検証部は、 前記通信部により受信された電子署名を検証して通信相手が前記共有先通信装置であると判定した場合に、前記演算部により生成された暗号鍵を前記共有先通信装置と共有する暗号鍵とすることを特徴とする請求項2又は3に記載の通信装置。
- 5前記第1の部分鍵の生成時の楕円曲線演算処理と、前記IDベース電子署名の生成過程における楕円曲線演算処理と、前記電子署名の検証過程における楕円曲線演算処理と、前記暗号鍵の生成時の楕円曲線演算処理が共通の楕円曲線演算プログラムにより実現されることを特徴とする請求項3又は4に記載の通信装置。
- 6前記共有先通信装置は、 IDベース電子署名の生成及び検証に用いられる署名用パラメータを保有しており、 前記通信装置は、更に、 前記共有先通信装置が保有する署名用パラメータと同じ署名用パラメータを記憶するパラメータ記憶部を有し、 前記電子署名生成部は、 前記第1の部分鍵と前記第2の部分鍵と前記通信装置の公開IDと前記署名用パラメータを用いて通信相手が前記通信装置であることを前記共有先通信装置において検証可能なIDベース電子署名を、前記第1の部分鍵と前記第2の部分鍵と前記秘密鍵と前記署名用パラメータを用いて生成し、 前記電子署名検証部は、 前記第1の部分鍵と前記第2の部分鍵と前記共有先通信装置の公開IDと前記署名用パラメータを用いて前記通信部により受信された電子署名を検証し、通信相手が前記共有先通信装置であるか否かを判定することを特徴とする請求項2~5のいずれかに記載の通信装置。
- 7前記通信装置は、 所定の第1の署名用パラメータを用いて前記秘密鍵を生成する第1の管理装置により管理され、 前記共有先通信装置は、 前記第1の管理装置と異なる第2の管理装置により管理され、前記第1の署名用パラメータを保有しており、 前記通信装置は、更に、 前記第1の署名用パラメータを記憶する第1の署名用パラメータ記憶部を有し、 前記電子署名生成部は、 前記第1の部分鍵と前記第2の部分鍵と前記通信装置の公開IDと前記第1の署名用パラメータを用いて通信相手が前記通信装置であることを前記共有先通信装置において検証可能なIDベース電子署名を、前記第1の部分鍵と前記第2の部分鍵と前記秘密鍵と前記第1の署名用パラメータを用いて生成することを特徴とする請求項1~6のいずれかに記載の通信装置。
- 8前記共有先通信装置は、 所定の第2の署名用パラメータを用いて前記共有先通信装置の公開IDに対応づけて前記共有先通信装置の秘密鍵を生成する第2の管理装置により管理され、前記第2の署名用パラメータを保有しており、 前記通信部は、 電子署名を受信し、 前記通信装置は、更に、 前記共有先通信装置の公開IDを記憶するID記憶部と、 前記第2の署名用パラメータを記憶する第2の署名用パラメータ記憶部と、 前記第1の部分鍵と前記第2の部分鍵と前記共有先通信装置の公開IDと前記第2の署名用パラメータを用いて前記通信部により受信された電子署名を検証し、通信相手が前記共有先通信装置であるか否かを判定する電子署名検証部とを有することを特徴とする請求項7に記載の通信装置。
- 9前記通信装置は、更に、 前記共有先通信装置の公開IDを前記ID記憶部に保持したまま、前記第2の署名用パラメータ記憶部から前記第2の署名用パラメータを削除するパラメータ削除部を有することを特徴とする請求項8に記載の通信装置。
- 10前記共有先通信装置は、 前記第1の部分鍵の生成、前記第2の部分鍵の生成及び前記暗号鍵の生成に共通に用いられるパラメータとして選択された鍵生成用選択パラメータを保有し、 前記通信装置は、更に、 前記鍵生成用選択パラメータを記憶する鍵生成用選択パラメータ記憶部を有し、 前記通信部は、 前記共有先通信装置において前記鍵生成用選択パラメータが用いられて生成された前記第2の部分鍵を受信し、 前記通信装置は、更に、 所定の乱数値に対して前記鍵生成用選択パラメータを用いて前記第1の部分鍵を生成し、 前記電子署名検証部により通信相手が前記共有先通信装置であると判定された場合に、前記第1の部分鍵の生成に用いられた乱数値と前記第2の部分鍵と前記鍵生成用選択パラメータを用いて前記共有先通信装置と共有する暗号鍵を生成する演算部を有することを特徴とする請求項8又は9に記載の通信装置。
- 11前記共有先通信装置は、 前記第1の部分鍵の生成、前記第2の部分鍵の生成及び前記暗号鍵の生成に共通に用いられるパラメータとして選択された鍵生成用選択パラメータを保有し、 前記通信装置は、更に、 前記鍵生成用選択パラメータを記憶する鍵生成用選択パラメータ記憶部を有し、 前記通信部は、 前記共有先通信装置において前記鍵生成用選択パラメータが用いられて生成された前記第2の部分鍵を受信し、 前記通信装置は、更に、 所定の乱数値に対して前記鍵生成用選択パラメータを用いて前記第1の部分鍵を生成し、 前記電子署名検証部による電子署名の検証に先立ち、前記第1の部分鍵の生成に用いられた乱数値と前記第2の部分鍵と前記鍵生成用選択パラメータを用いて暗号鍵を生成する演算部を有し、 前記電子署名検証部は、 前記通信部により受信された電子署名を検証して通信相手が前記共有先通信装置であると判定した場合に、前記演算部により生成された暗号鍵を前記共有先通信装置と共有する暗号鍵とすることを特徴とする請求項8~10のいずれかに記載の通信装置。
- 12前記鍵生成用選択パラメータ記憶部は、 前記第1の管理装置で生成されたパラメータ及び前記第2の管理装置で生成されたパラメータのうちのいずれかを前記鍵生成用選択パラメータとして記憶することを特徴とする請求項10又は11に記載の通信装置。
- 13前記鍵生成用選択パラメータ記憶部は、 楕円曲線演算に用いられるパラメータを前記鍵生成用選択パラメータとして記憶し、 前記通信部は、 前記共有先通信装置において前記鍵生成用選択パラメータを用いた楕円曲線演算が行われて生成された前記第2の部分鍵を受信し、 前記演算部は、 所定の乱数値と前記鍵生成用選択パラメータを用いて楕円曲線演算を行って前記第1の部分鍵を生成し、 前記電子署名生成部によるIDベース電子署名の生成過程において楕円曲線演算を行い、 前記電子署名検証部による電子署名の検証過程において楕円曲線演算を行い、 前記第1の部分鍵の生成に用いられた乱数値と前記第2の部分鍵と前記鍵生成用選択パラメータを用いて楕円曲線演算を行って暗号鍵を生成することを特徴とする請求項10~12のいずれかに記載の通信装置。
- 14前記第1の部分鍵の生成時の楕円曲線演算処理と、前記IDベース電子署名の生成過程における楕円曲線演算処理と、前記電子署名の検証過程における楕円曲線演算処理と、前記暗号鍵の生成時の楕円曲線演算処理が共通の楕円曲線演算プログラムにより実現されることを特徴とする請求項13に記載の通信装置。
- 15共有される暗号鍵の生成に用いられる部分鍵を第1の部分鍵として生成し、生成した前記第1の部分鍵を前記暗号鍵の共有先となる共有先通信装置に送信し、前記共有先通信装置により生成された部分鍵を第2の部分鍵として前記共有先通信装置から受信する通信装置が行う情報処理方法であって、 前記通信装置が、前記通信装置の公開ID(Identification)に対応づけられて生成された秘密鍵を記憶する秘密鍵記憶ステップと、 前記第1の部分鍵と前記第2の部分鍵と前記通信装置の公開IDを用いて通信相手が前記通信装置であることを前記共有先通信装置において検証可能なIDベース電子署名を、前記通信装置が、前記第1の部分鍵と前記第2の部分鍵と前記秘密鍵を用いて生成する電子署名生成ステップと、 前記通信装置が、前記電子署名生成ステップにより生成されたIDベース電子署名を前記共有先通信装置に送信する通信ステップとを有することを特徴とする情報処理方法。
- 16共有される暗号鍵の生成に用いられる部分鍵を第1の部分鍵として生成し、生成した前記第1の部分鍵を前記暗号鍵の共有先となる共有先通信装置に送信し、前記共有先通信装置により生成された部分鍵を第2の部分鍵として前記共有先通信装置から受信する通信装置に、 前記通信装置の公開ID(Identification)に対応づけられて生成された秘密鍵を記憶する秘密鍵記憶処理と、 前記第1の部分鍵と前記第2の部分鍵と前記通信装置の公開IDを用いて通信相手が前記通信装置であることを前記共有先通信装置において検証可能なIDベース電子署名を、前記第1の部分鍵と前記第2の部分鍵と前記秘密鍵を用いて生成する電子署名生成処理と、 前記電子署名生成処理により生成されたIDベース電子署名を前記共有先通信装置に送信する通信処理とを実行させることを特徴とするプログラム。
Independent claims16
130 paragraphs, as filed
The present invention relates to a technique for sharing an encryption key between a plurality of communication devices.
In communication between a plurality of communication devices, when encrypting the communication contents, it is necessary to share the encryption key with each other. When sharing a cryptographic key, only the parties should be able to obtain the cryptographic key. For example, the DH (Diffie-Hellman) key exchange method shares a key on a public communication path, but the parties cannot obtain the shared encryption key from the information (packets) exchanged between the parties via the communication path. Key sharing can be realized so that the encryption key is not known. On the other hand, in the DH key exchange method, it is not possible to confirm that the creator and sender of the packet are the same, so the shared key may be known to the fraudster by resending or forwarding the packet by the fraudster. There is a possibility that the communication content encrypted with the shared key may be leaked to an unauthorized person.
In response to such a problem, in the technique described in Non-Patent Document 1, it is possible to detect the retransmission or transfer of a packet by an unauthorized person by giving an electronic signature by public key cryptography to the above-mentioned DH key exchange method. .. However, in order to prevent the electronic signature used in Non-Patent Document 1 from being forged by an unauthorized person, the public key is introduced by introducing a public key certificate and PKI (Public Key Infrastructure). You must ensure that the owner on the certificate and the sender of the digital signature are the same. Therefore, the verification process of the public key certificate is performed every time the key is shared, which leads to a decrease in the overall processing speed. In addition, PKI equipment, including a Certificate Authority (CA), must be prepared.
<p><nplcit num="1"><text>Simon Blake-Wilson and Alfred Menezes. Authnticated Diffie-Hellman key agreement protocols. In S. Tavares et al., Editors, Selected Areas in Cryptography, 5th International Workshop, pages 339-361. Springer-Verlag, 1999. Lecture Notes in Computer Science Volume 1556.</text></nplcit></p>
<p> In the technology described in Non-Patent Document 1 above, by introducing a public key certificate and PKI (Public Key Infrastructure), it is possible to realize sharing of cryptographic keys without being subject to fraud such as forgery by fraudsters. There is. On the other hand, it is necessary to perform the verification process of the public key certificate every time the key is shared with a new communication partner. In order to perform the efficient verification process, additional equipment such as a verification server used in PKI is required. There is a problem such as</p><p> One of the main purposes of the present invention is to solve the above problems, and sharing of cryptographic keys without introducing a public key certificate and PKI and without being subject to fraud such as forgery by a fraudster. The main purpose is to realize.</p>
<p> The communication device according to the present invention is A partial key used to generate a shared encryption key is generated as a first partial key, and the generated first partial key is transmitted to a sharing destination communication device that is a sharing destination of the encryption key, and the sharing destination. A communication device that receives a partial key generated by the communication device as a second partial key from the shared destination communication device. A secret key storage unit that stores a private key generated in association with the public ID (Identification) of the communication device, and a secret key storage unit. Using the first partial key, the second partial key, and the public ID of the communication device, the ID-based digital signature that can be verified by the shared destination communication device that the communication partner is the communication device is the first. An electronic signature generator generated by using the partial key of 1, the second partial key, and the private key, It is characterized by having a communication unit that transmits an ID-based electronic signature generated by the electronic signature generation unit to the shared destination communication device.</p>
<p> According to the present invention, it is possible to authenticate a communication partner using an ID-based digital signature, and the encryption key can be used without introducing a public key certificate and PKI and without being forged by an unauthorized person. Sharing can be achieved.</p>
<figref num="1">The figure which shows the outline of the network which concerns on Embodiment 1.</figref><figref num="2">Schematic diagram of the system at the time of key sharing according to the first embodiment.</figref><figref num="3">The processing flow diagram at the time of communication which concerns on Embodiment 1.</figref><figref num="4">Schematic diagram of the system at the time of parameter distribution according to the first embodiment.</figref><figref num="5">FIG. 5 is a processing flow diagram relating to parameter distribution according to the first embodiment.</figref><figref num="6">Schematic diagram of the system at the time of delivery of the private key according to the first embodiment.</figref><figref num="7">The processing flow diagram about the private key delivery which concerns on Embodiment 1.</figref><figref num="8">The functional block diagram of the terminal apparatus which concerns on Embodiment 1. FIG.</figref><figref num="9">FIG. 5 is a flow chart of a partial key generation unit according to the first embodiment.</figref><figref num="10">The flow chart of the encryption key generation part which concerns on Embodiment 1.</figref><figref num="11">The flow chart of the electronic signature generation part which concerns on Embodiment 1. FIG.</figref><figref num="12">The flow chart of the electronic signature verification part which concerns on Embodiment 1.</figref><figref num="13">The functional block diagram of the management server apparatus which concerns on Embodiment 1.</figref><figref num="14">The flow diagram of the secret generation part which concerns on Embodiment 1.</figref><figref num="15">The figure which shows the outline of the network which concerns on Embodiment 2.</figref><figref num="16">Schematic diagram of the system at the time of key sharing according to the second embodiment.</figref><figref num="17">The processing flow diagram at the time of communication which concerns on Embodiment 2.</figref><figref num="18">The system schematic diagram at the time of parameter transmission which concerns on Embodiment 2.</figref><figref num="19">FIG. 5 is a processing flow diagram relating to parameter transmission according to the second embodiment.</figref><figref num="20">The functional block diagram of the management server apparatus which concerns on Embodiment 2.</figref><figref num="21">Schematic diagram of the system at the time of parameter distribution according to the second embodiment.</figref><figref num="22">FIG. 5 is a processing flow diagram relating to parameter distribution according to the second embodiment.</figref><figref num="23">FIG. 5 is a processing flow diagram relating to parameter distribution according to the second embodiment.</figref><figref num="24">FIG. 5 is a processing flow diagram relating to parameter deletion according to the second embodiment.</figref><figref num="25">The functional block diagram of the terminal apparatus which concerns on Embodiment 2. FIG.</figref><figref num="26">The figure which shows the example of the parameter table which concerns on Embodiment 2.</figref><figref num="27">The figure which shows the hardware configuration example of the terminal apparatus and management server apparatus which concerns on Embodiment 1 and 2.</figref>
Embodiment 1. In this embodiment, by using ID-based cryptography technology (ID-based signature) for digital signature, the encryption key is not introduced and is not subject to fraud such as forgery by an unauthorized person without introducing a public key certificate and PKI. Explain the technology that realizes the sharing of. Further, in the above-mentioned technique of Non-Patent Document 1, key exchange is performed by the DH key exchange method using the remainder group, but in the present embodiment, the key exchange is performed by the ECDH (Elliptic Curve Diffie-Hellman) key exchange method. Explain the technique to be performed. The ECDH key exchange method is composed of operations on the body defined by the elliptic curve, and the ID-based signature can also be configured by the same operation. Therefore, the elliptic curve operation in the ID-based signature and the elliptic in the key exchange An example of implementing curve calculation as a common module will be described. When the function of performing elliptic curve calculation is implemented as a program, the data size occupied by the program can be reduced. Furthermore, since the ECDH key exchange method can keep the size of the partial key smaller than the DH key exchange by the surplus group while maintaining the confidentiality of the shared key, it is possible to keep the amount of communication data between the parties small. it can.
FIG. 1 is a schematic diagram of a network system to which the key exchange method according to the first embodiment can be applied. A plurality of terminal devices A102 to B103 and a management server device 104 are connected to a network 101 such as the Internet. In the following, an example of performing key exchange between the terminal device A102 and the terminal device B103 will be described. The terminal device A102 and the terminal device B103 are examples of communication devices and shared destination communication devices, respectively. In FIG. 1, for convenience, the terminal device A102 is shown as an example of a communication device, and the terminal device B103 is shown as an example of a shared destination communication device. However, when the terminal device B103 is used as an example of a communication device, the terminal Device A102 is an example of a shared destination communication device.
First, an outline of the operation when the terminal devices share the key for encrypting the communication will be described. FIG. 2 shows an outline of the operation when the terminal device A102 and the terminal device B103 share the key.
In preparation for key sharing, the terminal device A102 and the terminal device B103 have an elliptic curve function E and a point P on the elliptic curve, which are parameters used in ECDH key exchange, respectively (in FIG. 2, parameters E and P are collectively parameters (E). , P) 15) and the ID-based signature parameter (signature) 16 (signature parameter) are shared by the method described later. The ID-based signature parameter is also called the system public key. The parameter (E, P) 15 possessed by the terminal device A102 and the parameter (E, P) 15 possessed by the terminal device B103 have the same information. Further, the parameter (signature) 16 held by the terminal device A102 and the parameter (signature) 16 held by the terminal device B103 are the same information. In addition, the terminal device A102 acquires the private key 12 for ID-based signature corresponding to its own public ID (hereinafter, also simply referred to as ID) 11 from the management server device 104 by the method described later, and is a terminal. The device B103 also obtains the private key 14 for ID-based signature corresponding to its own public ID 13 from the management server device 104 by the method described later. Further, the terminal device A102 holds the public ID 13 of the terminal device B103, and the terminal device B103 holds the public ID 11 of the terminal device A102. The public ID is, for example, the e-mail address of the user of the terminal device.
First, the terminal device A102 performs an elliptic curve operation on a predetermined random number value to generate a partial key tA201, and transmits the partial key tA201 to the terminal device B103. After receiving the partial key tA201, the terminal device B103 performs an elliptic curve calculation on a predetermined random number value to generate the partial key tB202, and then performs an elliptic curve calculation on the random number value used for generating the partial key tB202 and the partial key tA201. Go and calculate the encryption key Z_AB203. Further, the terminal device B103 applies an electronic signature (= Sign_B (tA, tB)) 204 by the private key 14 to the partial key tA201 and the partial key tB202. Elliptic curve calculation is also performed in the process of generating the electronic signature 204. Further, the terminal device B103 transmits the partial key tB202 and the electronic signature 204 to the terminal device A102. For each terminal device, the partial key generated by the own device and transmitted to the terminal device to which the encryption key is shared corresponds to the first partial key, and the partial key received from the terminal device to which the encryption key is shared is Corresponds to the second partial key. For example, for the terminal device A102, the partial key tA201 is the first partial key and the partial key tB202 is the second partial key.
When the terminal device A102 receives the partial key tB202 and the digital signature 204, the terminal device A102 verifies the digital signature 204 by using the public ID 13 of the terminal device B103. Elliptic curve calculation is also performed in the verification process of the electronic signature 204. Here, if the electronic signature 204 is incorrect, it is considered that an illegal process has been performed and the process is terminated. Further, if it can be confirmed that the electronic signature 204 is correctly created by the terminal device B103 (the communication partner is the terminal device B103), the terminal device A102 is a random number value used for generating the partial key tA201. And the partial key tB202 is subjected to an elliptic curve calculation to calculate the encryption key Z_BA205. Further, the terminal device A102 applies an electronic signature (= Sign_A (tB, tA)) 206 with the private key 12 to the partial key tA201 and the partial key tB202. Elliptic curve calculation is also performed in the process of generating the electronic signature 206. Further, the terminal device A102 transmits the electronic signature 206 to the terminal device B103.
The terminal device B103 receives the electronic signature 206, and uses the public ID 11 of the terminal device A102 to verify the electronic signature 206. Elliptic curve calculation is also performed in the verification process of the electronic signature 206. If it can be confirmed that the electronic signature 206 is correctly created by the terminal device A102 (the communication partner is the terminal device A102), the terminal device B103 has completed the process normally. If not, it is considered that an illegal process has been performed and the process is terminated. If it cannot be confirmed that the digital signature 206 was created correctly by the terminal device A102, the encryption key Z_AB203 is considered to be insecure and is not used.
Since Z_AB203 = Z_BA205 as described later, if the electronic signature verification is successful in both the terminal device A102 and the terminal device B103, Z_AB203 (= Z_BA205) is used as the shared encryption key, or it is used as the encryption key. Sharing of the encryption key is completed by using the one that can be generated from Z_AB203 (= Z_BA205) as the sharing encryption key.
Next, with reference to FIG. 3, in the first embodiment, for example, a process when the terminal device A102 and the terminal device B103 share the encryption key will be described. FIG. 3 is a flow chart of processing performed in relation to the communication processing of FIG. Hereafter, "*" means the multiplication defined by the field on the elliptic curve function E.
The terminal device A102 generates a random number rA (step 301), calculates the partial key tA201 = (rA * P) from the parameters (E, P) 15 (step 302), and transmits the partial key tA201 to the terminal device B103 (step 302). Step 303).
The terminal device B103 receives the partial key tA201 from the terminal device A102 (step 304), generates a random number rB (step 305), and calculates the partial key tB202 = (rB * P) from the parameters (E, P) 15 (step 305). Step 306), calculate the encryption key Z_AB203 = (rB * tA) (step 307). Further, the terminal device B103 applies a digital signature (= Sign_B (tA, tB)) 204 with the parameter (signature) 16 and the private key 14 to the partial key tA201 and the partial key tB202 (step 308), and gives the terminal device A102. Send the partial key tB202 and the digital signature 204 (step 309).
The terminal device A102 receives the partial key tB202 and the digital signature 204 from the terminal device B103 (step 310), and verifies the digital signature 204 using the parameter (signature) 16 and the ID 13 of the terminal device B103 (step 311). If it can be confirmed that the digital signature 204 is invalid, the process ends. If the digital signature 204 is legitimate, the encryption key Z_BA205 = (rA * tB) is calculated. (Step 312) Then, the terminal device A102 is a key that shares the encryption key Z_BA205 with the terminal device B103. Further, the terminal device A102 applies a digital signature (= Sign_A (tB, tA)) 206 with the parameter (signature) 16 and the private key 12 to the partial key tA201 and the partial key tB202 (step 313), and the terminal device B103. Send the digital signature 206 to (step 314).
The terminal device B103 receives the digital signature 206 from the terminal device A102 (step 315), and verifies the digital signature 206 using the parameter (signature) 16 and the ID 11 of the terminal device A102 (step 316). If it can be confirmed that the digital signature 206 is invalid, the process is terminated. If the digital signature 206 is legitimate, the encryption key Z_AB203 (= Z_BA205) generated in step 307 is used as the shared key used between the terminal device A102 and the terminal device B103.
Next, based on FIG. 4, in the first embodiment, for example, the management server device 104 sets the terminal devices A102 to B103 with the elliptic curve function E and the point P on the elliptic curve, which are parameters used in ECDH key exchange. , The outline of the operation when distributing the parameter of ID-based signature will be explained. In the following description, for convenience, when the ECDH key exchange parameter and the ID-based signature parameter are treated as a set, they are collectively referred to as parameter 401.
The management server device 104 distributes the parameter 401 to the managed terminal devices A102 to B103. At this time, the distribution method may be multicast communication or one-to-one communication. Further, the communication may be encrypted if necessary. Also, due to the terminal device that could not receive the parameters in the first distribution, such as an accident on the communication path or the terminal device was not connected at the time of distribution, the distribution is not only once, but regular or irregular depending on the situation. You may repeat it on a regular basis.
Next, with reference to FIG. 5, in the first embodiment, for example, a process in which the parameter 401 is distributed from the management server device 104 to the terminal device A102 will be described. The same applies to the processing for the terminal device B103.
The management server device 104 generates an elliptic curve function E and a point P on the elliptic curve, which are parameters used in ECDH key exchange, by the ECDH key sharing parameter generator described later (step 501), and ID-based signature parameters are generated by an ID described later. It is generated by the base signature parameter generator (step 502), and the parameter 401 is transmitted to the terminal device A102 (step 503).
The terminal device A102 receives the parameter 401 (step 504) and holds it in the parameter storage unit (step 505).
If the parameters are not changed and the distribution is repeated, the process is started from step 503. When changing the parameters, the process is started from step 501.
Here, the management server device 104 is supposed to send the parameter 401 to the terminal device A102, but the parameter of the ID-based signature is a safe method other than sending from the management server device 104 to the terminal device A102 (system introduction). Occasionally, ID-based signature parameters may be pre-embedded in the managed terminal device).
Next, based on FIG. 6, in the first embodiment, for example, an operation outline when the terminal device A102 acquires the private key of the ID-based signature generated in association with its own public ID from the management server device 104. Will be described. The same applies to the processing for the terminal device B103.
The management server device 104 periodically or in response to a request from the administrator, transmits the private key 12 corresponding to the ID 11 of the terminal device A102 to the terminal device A102. At this time, if necessary, the communication from the management server device 104 to the terminal device A102 may be encrypted.
Next, with reference to FIG. 7, in the first embodiment, for example, a process when the terminal device A102 acquires the private key of the ID-based signature corresponding to the ID of the terminal device from the management server device 104 will be described. The same applies to the processing for the terminal device B103.
The management server device 104 generates the private key 12 by inputting the ID 11 of the terminal device A102 into the private key generator described later (step 701) on a regular basis or in response to a request from the administrator, and the generated secret. Send key 12 to terminal device A102 (step 702). The terminal device A102 receives the private key 12 (step 703) and holds the private key 12 in the storage unit (step 704) (private key storage step). At this time, the past private key held in the storage unit may be deleted.
Next, the functions of the terminal devices A102 to B103 in the first embodiment will be described with reference to FIG. FIG. 8 is a functional block diagram illustrating the functional configurations of the terminal devices A102 to B103. Here, for convenience, the terminal device is designated by reference numeral 801.
The terminal device 801 includes a communication interface 802, an elliptic curve calculation unit 803, a partial key generation unit 804, an encryption key generation unit 805, an electronic signature verification unit 806, an electronic signature generation unit 807, a parameter acquisition unit 808, and a private key acquisition unit 809. It is composed of a parameter storage unit 810, an encryption key storage unit 811 and a private key storage unit 812.
The communication interface 802 is a communication unit that communicates with an external device. More specifically, the communication interface 802 receives from the management server device 104 the parameters used in the ECDH key exchange, the elliptic curve function E, the point P on the elliptic curve, and the parameters used in the ID-based signature. Further, as shown in FIG. 2, an electronic signature with a partial key and an ID-based signature is transmitted to the terminal device to which the encryption key is shared, and the partial key and ID-based are transmitted from the terminal device to which the encryption key is shared. Receive a digital signature by signature.
The elliptic curve calculation unit 803 performs calculations on the elliptic curve in response to requests from the partial key generation unit 804, the encryption key generation unit 805, the electronic signature verification unit 806, and the electronic signature generation unit 807. More specifically, the elliptic curve calculation unit 803 generates a partial key by performing an elliptic curve calculation on a predetermined random value based on the request of the partial key generation unit 804, and the encryption key generation unit 805. Based on the request, an elliptic curve calculation is performed on the above random value and the partial key from the terminal device to which the encryption key is shared to generate the encryption key. Further, the elliptic curve calculation unit 803 performs an elliptic curve calculation in the ID-based electronic signature generation process based on the request of the electronic signature generation unit 807, and the electronic signature verification process based on the request of the electronic signature verification unit 806. Performs an elliptic curve calculation in. The elliptic curve calculation unit 803 is an example of the calculation unit.
The partial key generation unit 804 generates a random number and supplies the generated random number, the elliptic curve function E, and the point P on the elliptic curve to the elliptic curve calculation unit 803 to obtain the partial key.
The encryption key generation unit 805 supplies the random number generated by the partial key generation unit 804, the elliptic curve function E, and the partial key from the terminal device to which the encryption key is shared to the elliptic curve calculation unit 803 to obtain the encryption key. Further, the encryption key generation unit 805 stores the generated encryption key in the encryption key storage unit 811. The encryption key held in the encryption key storage unit 811 is, for example, the encryption key Z_BA205 in the case of the terminal device A102 in FIG.
The electronic signature verification unit 806 verifies the electronic signature received by the communication interface 802 and determines whether or not the communication partner is the terminal device of the encryption key sharing destination. More specifically, the partial key (first partial key) generated by the partial key generation unit 804, the partial key (second partial key) received from the terminal device of the encryption key sharing destination, and the encryption key sharing destination The received electronic signature is verified using the public ID of the terminal device and the parameters for the ID-based signature in the parameter storage unit 810. As mentioned above, elliptic curve calculation is performed in the verification process.
The digital signature generator 807 generates an ID-based digital signature using the first partial key, the second partial key, the private key in the private key storage unit 812, and the parameters for the ID-based signature in the parameter storage unit 810. To do. As mentioned above, the elliptic curve operation is performed in the process of generation. The ID-based signature is a combination of two partial keys (a partial key tB generated by the terminal device B103 and a partial key tA generated by the terminal device A102) and a terminal device (for example, the terminal device B103) in which the encryption key is shared. It is an electronic signature that can determine whether or not the communication partner is a legitimate terminal device (terminal device A102) by performing verification using the public ID of the terminal device A102) and the parameters for ID-based signing.
The parameter acquisition unit 808 inputs the elliptic curve function E, which is the parameter used in the ECDH key exchange generated by the management server device 104, the point P on the elliptic curve, and the parameter used in the ID-based signature from the communication interface 802, and stores the parameter. Store in part 810.
The private key acquisition unit 809 inputs the private key generated by the management server device 104 from the communication interface 802 and stores it in the private key storage unit 812. The private key held in the private key storage unit 812 is an ID-based signature private key corresponding to the ID of the terminal device 801. For example, the terminal device A102 holds the private key 12 corresponding to the ID 11 of the terminal device A102 in the secret key storage unit 812.
The ID storage unit 813 stores the public ID of the terminal device to which the encryption key is shared.
FIG. 9 is a flow chart of the partial key generation unit 804 of the terminal device 801. The partial key generation unit 804 generates a random number rA (step 821), and acquires parameters E and P from the parameter storage unit 810 (step 822). Then, the random numbers rA, parameters E, and P are transmitted to the elliptic curve calculation unit 803, and the partial key tA (r times the parameter P) of the ECDH key exchange is acquired from the elliptic curve calculation unit 803 (step 823), and the communication interface 802. To another terminal device via (step 824). Further, the random number rA is transmitted to the encryption key generator 805 (step 825).
FIG. 10 is a flow chart of the encryption key generation unit 805 of the terminal device 801. The encryption key generation unit 805 receives the random number rA from the partial key generation unit 804 (step 826), acquires the parameter E from the parameter storage unit 810 (step 827), and receives the ECDH key from another terminal device via the communication interface 802. Receive the exchange partial key tB (step 828). Then, the random number rA, the parameter E, and the partial key tB are transmitted to the elliptic curve calculation unit 803, and the encryption key (r times tB) is obtained from the elliptic curve calculation unit 803 (step 829). Further, the generated encryption key is stored in the encryption key storage unit 811 (step 830).
FIG. 11 is a flow chart of the electronic signature generation unit 807 of the terminal device 801. The digital signature generator 807 acquires the ECDH key exchange partial key tA from the partial key generator 804 (step 831) (electronic signature generation step), and the ECDH key exchange partial key from another terminal device via the communication interface 802. Receive tB (step 832) (electronic signature generation step) and acquire the private key S from the private key storage unit 812 (step 833) (electronic signature generation step). Next, the parameters of the ID-based signature are acquired from the parameter storage unit 810 (step 834) (electronic signature generation step). Then, a digital signature SignA is generated using the parameters of the partial key tA, the partial key tB, the private key S, and the ID-based signature (step 835) (electronic signature generation step), and the other terminal device is connected via the communication interface 802. Send (step 836) (communication step). When generating the electronic signature SignA, it is necessary to perform calculations on the elliptic curve, and the elliptic curve calculation unit 803 performs these calculation processes.
FIG. 12 is a flow chart of the electronic signature verification unit 806 of the terminal device 801. The digital signature verification unit 806 receives the ECDH key exchange partial key tB and the digital signature Sign B from another terminal device via the communication interface 802 (step 837), and receives the ECDH key exchange partial key tA from the partial key generator 804. Obtain (step 838) and obtain the ID-based signature parameter from the parameter storage 810 (step 839). Then, the digital signature SignB is verified using the ID of the terminal device that is the source of the digital signature SignB and the parameters of the partial key tA, the partial key tB, and the ID-based signature (step 840). When verifying the electronic signature SignB, it is necessary to perform calculations on the elliptic curve, and the elliptic curve calculation unit 803 performs those calculation processes. Further, as a result of the verification of the electronic signature SignB in step 840, if it is confirmed that the electronic signature SignB is legitimate, and if the terminal device 801 corresponds to the terminal device A102 in FIG. 3, step 311 in FIG. As shown in step 312, the digital signature verification unit 806 instructs the encryption key generation unit 805 to generate the encryption key. The encryption key generation unit 805 generates an encryption key according to the flow shown in FIG. Further, as a result of the verification of the electronic signature SignB in step 840, if it is confirmed that the electronic signature is legitimate, and if the terminal device 801 corresponds to the terminal device B103 in FIG. 3, the step 316 in FIG. 3 is performed. As shown, the digital signature verification unit 806 uses the encryption key generated in step 307 as an encryption key to be shared with the sharing destination terminal device. On the other hand, if, as a result of the verification of the electronic signature SignB in step 840, it cannot be confirmed that the electronic signature SignB is legitimate, and the terminal device 801 corresponds to the terminal device A102 in FIG. 3, in step 311 in FIG. , The digital signature verification unit 806 stops the subsequent processing and does not instruct the generation of the encryption key. If, as a result of the verification of the electronic signature Sign B in step 840, it cannot be confirmed that the electronic signature Sign B is legitimate, and the terminal device 801 corresponds to the terminal device B 103 in FIG. 3, in step 316 in FIG. , The digital signature verification unit 806 does not use the encryption key generated in step 307 as the encryption key to be shared with the sharing destination terminal device. The encryption key generated in step 307 may be destroyed.
Further, the parameter acquisition unit 808 acquires the parameters E and P of ECDH key exchange and the parameters used in the ID-based signature from the management server device 104 via the communication interface 802. Further, the private key acquisition unit 809 acquires the private key S corresponding to the ID of the terminal device from the management server device 104 via the communication interface 802.
Next, the function of the management server device 104 according to the first embodiment will be described with reference to FIG. FIG. 13 is a functional block diagram illustrating the functional configuration of the management server device 104. Here, for convenience, the verification server device is designated by reference numeral 901.
The management server device 901 includes a communication interface 902, an ECDH key sharing parameter generation unit 903, a secret key generation unit 904, an ID-based signature parameter generation unit 905, a parameter delivery unit 906, and a parameter storage unit 907. The communication interface 902 has the same function as that constituting the terminal device 801 of FIG.
The parameters stored in the parameter storage unit 907 are the parameters generated by the ID-based signature parameter generation unit 905 and the parameters generated by the ECDH key sharing parameter generation unit 903.
The ECDH key sharing parameter generation unit 903 generates an elliptic curve function E and a point P on the elliptic curve, which are parameters for ECDH key exchange, and stores the generated parameters in the parameter storage unit 907.
The ID-based signature parameter generation unit 905 generates ID-based signature parameters, and stores the generated parameters in the parameter storage unit 907.
The private key generation unit 904 generates a private key in association with the public ID of the terminal device 801.
The parameter delivery unit 906 delivers the ID-based signature parameters and the ECDH key exchange parameters E and P stored in the parameter storage unit 907 to the distribution target terminal device 801.
FIG. 14 is a flow chart of the private key generation unit 904 of the management server device 901. The private key generator 904 acquires the ID-based signature parameter from the parameter storage unit 907 (step 911), generates the private key from the ID and parameters of the terminal device to be distributed (step 912), and uses the communication interface 902. The private key is delivered to the terminal device 801 to be distributed (step 913).
In the terminal devices A102 to B103 and the management server device 104 configured in this way, ECDH key exchange and electronic signature by ID-based signature are used together to perform public key certificate verification processing and PKI. It is possible to realize the sharing of cryptographic keys that are not subject to fraud such as counterfeiting by fraudsters without the need for additional equipment.
That is, in the key sharing method according to the first embodiment, in order for the terminal devices A102 to B103 to share the encryption key between the two devices, ECDH key exchange is performed and an electronic signature by ID-based signature is transmitted to each other. That, and the ECDH key exchange method parameters are distributed from the management server device 104 to the terminal devices A102 to B103, and from the management server device 104 to the terminal devices A102 to B103, respectively. It distributes the private key of ID-based signature.
Further, in the present embodiment, the key is exchanged by the ECDH key exchange method, and the ECDH key exchange method is composed of the calculation on the body defined by the elliptic curve, and the ID-based signature is also the elliptic curve calculation. Since it can be configured by, it is possible to implement the elliptic curve calculation as a common part. Therefore, for example, by implementing the elliptic curve calculation unit 803 as a program, the data size occupied by the program can be reduced.
Furthermore, since the ECDH key exchange method can keep the size of the partial key smaller than the DH key exchange by the surplus group while maintaining the confidentiality of the shared key, it is possible to keep the amount of communication data between the parties small. it can.
As described above, in the present embodiment, when the encryption key used for encrypted communication or the like is shared between terminals, the public key is verified by using the ID-based signature as the electronic signature given to authenticate the key sharing partner. A communication system that shares a key with an intended sharing partner without processing is explained.
Further, in the present embodiment, a communication system in which an encryption key is shared by an ECDH key exchange method and an ID-based signature is implemented by an operation on an elliptic curve has been described.
Further, in the present embodiment, a communication system that implements the ECDH key exchange method and the arithmetic processing on the elliptic curve in the ID-based signature as a common module has been described.
Further, in the present embodiment, the ECDH key exchange method and the public parameters of the ID-based signature are the same for the terminals in the same organization, and the management server delivers the above public parameters to the terminals in the organization. Described the system.
Further, in the present embodiment, when the public parameter is delivered from the management server to the terminal in the organization, the management server assigns an electronic signature to the public parameter to the public parameter, and the receiving terminal verifies the electronic signature. Explained.
Embodiment 2. FIG. 15 is a schematic diagram of a network system to which the key exchange method according to the second embodiment can be applied. A plurality of management server devices 1002 to 1003 and a plurality of terminal devices A1004 to 1005 and 1006 to 1007 are connected to a network 1001 such as the Internet under the control of each of the management server devices. For example, in FIG. 15, the management server device 1002 manages the terminal devices A1004 to 1005, and the management server device 1003 manages the terminal devices B1006 to 1007. In the following, an example of performing key exchange between the terminal device A1004 and the terminal device B1006 will be described. The terminal device A1004 and the terminal device B1006 are examples of communication devices and shared destination communication devices, respectively. In FIG. 15, for convenience, the terminal device A1004 is shown as an example of a communication device, and the terminal device B1006 is shown as an example of a shared destination communication device. However, when the terminal device B1006 is used as an example of a communication device, the terminal is shown. Device A1004 is an example of a shared destination communication device. Further, in FIG. 15, the management server device 1002 that manages the terminal device A1004, which is an example of the communication device, is an example of the first management device, and the management server device 1003 that manages the terminal device B1006, which is the shared destination communication device, is the first. This is an example of the management device of 2. On the contrary, when the terminal device B1006 is used as an example of the communication device, the management server device 1003 is an example of the first management device, and the management server device 1002 that manages the terminal device A1004 which is the shared destination communication device is the second. This is an example of a management device.
In the second embodiment, the key sharing between the terminal devices under the control of the same management server device, for example, between the terminal devices A1004 and the terminal device 1005 in FIG. 15, is performed by the same method as in the first embodiment. Will be.
Next, key sharing between terminal devices under the control of different management server devices will be described. In FIG. 16, when key sharing is performed between terminal devices under the control of different management server devices, for example, the terminal device A1004 under the control of the management server device 1002 and the terminal device B1006 under the control of the management server device 1003 A schematic diagram of the system for key sharing is shown.
In preparation for key sharing, the terminal device A1004 has the ECDH key exchange parameters (E, P) 1101 and the ID-based signature parameter (signature) 1102 generated by the management server device 1002 from the management server device 1002 by the method described later. , The ECDH key exchange parameter (E, P) 1103 generated by the management server device 1003 and the ID-based signature parameter (signature) 1104 have been acquired. When the terminal device A1004 is taken as an example of a communication device, the ID-based signature parameter (signature) 1102 acquired from the management server device 1002, which is the first management device, becomes the first signature parameter and the second. The ID-based signature parameter (signature) 1104 obtained from the management server device 1003, which is the management device of the above, is the second signature parameter. In preparation for key sharing, the terminal device B1006 uses the ECDH key exchange parameters (E, P) 1103 and the ID-based signature parameters (signature) generated by the management server device 1003 from the management server device 1003 by the method described later. Acquired 1104, the ECDH key exchange parameter (E, P) 1101 generated by the management server device 1002, and the ID-based signature parameter (signature) 1102. In addition, the terminal device A1004 acquires the ID-based signature private key 1106 corresponding to its own ID 1105 from the management server device 1002, and the terminal device B1006 also obtains the ID-based signature private key 1108 corresponding to the ID 1107 from the management server device 1003. Obtained from. Further, the terminal device A1004 possesses the ID1107 of the terminal device B1006, and the terminal device B1006 also possesses the ID1105 of the terminal device A1004.
First, the terminal device A1004 and the terminal device B1006 select the ECDH key exchange parameters (E, P) from either the parameter (E, P) 1101 or the parameter (E, P) 1103. Here, for convenience, the selected parameter is set as parameter (E, P) 1109. The selection method may be any. The selected parameters (E, P) 1109 are examples of key generation selection parameters.
In the present embodiment, the parameters (E, P) 1109 selected at the time of partial key key generation and encryption key generation are commonly used between the terminal devices, and the parameters at the time of digital signature generation and digital signature verification. The only difference is that (signature) 1102 and parameter (signature) 1104 are used, and the processing procedure itself for key exchange is the same as that shown in 1 in the embodiment.
First, the terminal device A1004 performs an elliptic curve operation using a predetermined random number value and parameters (E, P) 1109 to generate a partial key tA1201 and transmits it to the terminal device B1006. After receiving the partial key tA1201, the terminal device B1006 performs an elliptic curve operation using a predetermined random number value and parameters (E, P) 1109 to generate the partial key tB1202. In addition, the random number used to generate the partial key tB1202 and the partial key tA1201 are subjected to elliptic curve calculation to calculate the encryption key Z_AB1203. Further, the terminal device B1006 digitally signs (= Sign_B) the partial key tA1201 and the partial key tB1202 by using the parameter (signature) 1104 generated by the management server device 1003 and the private key 1108 generated by the management server device 1003. (tA, tB)) Apply 1204. Further, the terminal device B1006 transmits the partial key tB1202 and the electronic signature 1204 to the terminal device A1004.
When the terminal device A1004 receives the partial key tB1202 and the digital signature 1204, the terminal device A1004 verifies the digital signature 1204 by using the parameter (signature) 1104 generated by the management server device 1003 and the public ID 1107 of the terminal device B1006. If it can be confirmed that the digital signature is legitimate (the communication partner is the terminal device B1006), the random value used to generate the partial key tA1201 and the partial key tB1202 are subjected to elliptic curve calculation to obtain the encryption key Z_BA1205. calculate. This encryption key Z_BA1205 is a key shared with the terminal device B1006. Further, the terminal device A1004 applies a parameter (signature) 1102 and an electronic signature (= Sign_A (tB, tA)) 1206 with the private key 1106 to the partial key tA1201 and the partial key tB1202. Further, the terminal device A1004 transmits the electronic signature 1206 to the terminal device B1006.
The terminal device B1006 receives the digital signature 1206, and verifies the digital signature 1206 by using the parameter (signature) 1102 and the public ID 1105 of the terminal device A1004. If it can be confirmed that the electronic signature 1206 is correctly created by the terminal device A1004 (the communication partner is the terminal device A1004), the processing of the terminal device B1006 is completed normally. If not, it is considered that an illegal process has been performed and the process is terminated. If you cannot verify that the digital signature 1206 was created correctly by the terminal device A1004, then the encryption key Z_AB1203 is considered insecure and should not be used.
Since Z_AB1203 = Z_BA1205 will be described later, if the electronic signature verification is successful in both the terminal device A1004 and the terminal device B1006, the encryption key that shares Z_AB1203 (= Z_BA1205) is used, or Sharing of the encryption key is completed by using the one that can be generated from Z_AB1203 (= Z_BA1205) as the sharing encryption key.
Next, based on FIG. 17, in the second embodiment, for example, a process when the terminal device A1004 and the terminal device B1006 share the encryption key will be described. FIG. 17 is a diagram showing a flow chart of processing performed with respect to the communication processing of FIG.
The terminal device A1004 generates a random number rA (step 1301), calculates the partial key tA1201 = (rA * P) from the parameters (E, P) 1109 (step 1302), and transmits the partial key tA1201 to the terminal device B1006 (step 1302). Step 1303).
The terminal device B1006 receives the partial key tA1201 from the terminal device A1004 (step 1304), generates a random number rB (step 1305), and calculates the partial key tB1202 = (rB * P) from the parameters (E, P) 1109 (step 1304). Step 1306), calculate the encryption key Z_AB1203 = (rB * tA) (step 1307). In addition, the terminal device B1006 applies a digital signature (= Sign_B (tA, tB)) 1204 with the parameter (signature) 1104 and the private key 1108 to the partial key tA1201 and the partial key tB1202 (step 1308), and attaches the terminal device A1004 to the terminal device A1004. Send the partial key tB1202 and the digital signature 1204 (step 1309).
The terminal device A1004 receives the partial key tB1202 and the digital signature 1204 from the terminal device B1006 (step 1310), and verifies the digital signature 1204 using the parameter (signature) 1104 and the ID 1107 of the terminal device B1006 (step 1311). If it can be confirmed that the digital signature 1204 is invalid, the process is terminated. If the digital signature 1204 is legitimate, the encryption key Z_BA1205 = (rA * tB) is calculated (step 1312). Further, the terminal device A1004 applies a parameter (signature) 1102 and an electronic signature (= Sign_A (tB, tA)) 1206 with the parameter (signature) 1102 and the private key 1106 to the partial key tA1201 and the partial key tB1202 (step 1313), and the terminal device B1006 Send the digital signature 1206 to (step 1314).
The terminal device B1006 receives the digital signature 1206 from the terminal device A1004 (step 1315), and verifies the digital signature 1206 using the parameter (signature) 1102 and the ID 1105 of the terminal device A1004 (step 1316). If it can be confirmed that the digital signature 1206 is invalid, the process is terminated. If the digital signature 1206 is legitimate, the encryption key Z_AB1203 (= Z_BA1205) generated in step 1307 is used as the shared key used between the terminal device A1004 and the terminal device B1006.
Next, based on FIG. 18, in the second embodiment, in order to enable key sharing between terminal devices under the control of different management server devices, for example, ECDH key exchange from the management server device 1002 to the management server device 1003. The outline of the operation when the parameter 91 of the above and the parameter 92 of the ID-based signature are transmitted will be described.
The management server device 1002 transmits the ECDH key exchange parameter 91 and the ID-based signature parameter 92 used in the managed terminal device to the management server device 1003. At this time, the management server device 1002 assigns its own electronic signatures to the parameters 91 and 92. Upon receiving the parameter 91 and the parameter 92, the management server device 1003 transmits the parameter 91 and the parameter 92 to the managed terminal device by the method described later.
Next, based on FIG. 19, in the second embodiment, in order to enable key sharing between terminal devices under the control of different management server devices, for example, ECDH key exchange from the management server device 1002 to the management server device 1003. The processing when the parameter 91 of the above and the parameter 92 of the ID-based signature are transmitted will be described.
The management server device 1002 acquires the elliptic curve function E and the point P on the elliptic curve, which are the parameters 91 used in the ECDH key exchange, and the parameter 92 of the ID-based signature from the parameter storage unit described later (step 1401), and the parameter 91. And parameter 92 to management server device 1003 (step 1402).
The management server device 1003 receives the parameter 91 and the parameter 92 (step 1403), and verifies the electronic signature given to the parameter 92. If the digital signature is legitimate, parameter 91 and parameter 92 are stored in the parameter storage along with the digital signature (step 1404). If the electronic signature is not correct, the process ends without changing the information in the parameter storage unit.
Next, the functions of the management server device 1002 and the management server device 1003 in the second embodiment will be described with reference to FIG. FIG. 20 is a functional block diagram illustrating the functional configurations of the management server device 1002 and the management server device 1003. Here, for convenience, reference numeral 1501 is attached to the management server device.
The management server device 1501 includes a communication interface 1502, an ECDH key sharing parameter generation unit 1503, a private key generation unit 1504, an ID-based signature parameter generation unit 1505, a parameter transmission unit 1506, a parameter reception unit 1507, an electronic signature generation unit 1508, and parameter delivery. It is composed of a unit 1509 and a parameter storage unit 1510. The communication interface 1502, the ECDH key sharing parameter generation unit 1503, the private key generation unit 1504, and the ID-based signature parameter generation unit 1505 have the same functions as those constituting the terminal device 801 in FIG.
The parameters held in the parameter storage unit 1510 are the parameters generated by the ECDH key sharing parameter generation unit 1503 and the ID-based signature parameter generation unit 1505 and the parameters received by the parameter reception unit 1507 from other management server devices.
The parameter transmission unit 1506 obtains the elliptic curve function E, which is the parameter of the ECDH key exchange generated by the management server device 1501, and the parameters of the point P and the ID-based signature on the elliptic curve from the parameter storage unit 1510, and its own electronic signature. Is given and sent to other management server devices.
The parameter receiver 1507 receives the elliptic curve function E, which is the parameter of ECDH key exchange, the point P on the elliptic curve, and the parameter of the ID-based signature from another management server device, verifies the electronic signature, and then verifies the electronic signature. If the electronic signature is legitimate, the corresponding parameter and the electronic signature are stored in the parameter storage unit 1510.
The electronic signature generation unit 1508 assigns the electronic signature of the management server device 1501 to the parameters generated by either or both of the ECDH key sharing parameter generation unit 1503 and the ID-based signature parameter generation unit 1505.
The parameter delivery unit 1509 extracts the parameters of the ID-based signature and the parameters E and P of the ECDH key exchange stored in the parameter storage unit 1510 that are permitted to be delivered to the terminal device to be distributed. The extracted parameters and the attached electronic signature are delivered to the terminal device to be distributed.
Next, based on FIG. 21, in the second embodiment, for example, when the management server device 1002 distributes the parameter 1601 generated by itself or received from the management server device 1003 to the terminal devices A1004 to 1005. The outline of the operation of is explained. Here, the parameter 1601 is composed of the elliptic curve function E, which is a parameter used in ECDH key exchange, the point P on the elliptic curve, and the parameter used in the ID-based signature.
The management server device 1002 distributes the parameter 1601 to the managed terminal devices A1004 to 1005. At this time, the distribution method may be multicast communication or one-to-one communication. Further, the communication may be encrypted if necessary. Also, due to the terminal device that could not receive the parameters in the first distribution, such as an accident on the communication path or the terminal device was not connected at the time of distribution, the distribution is not only once, but regular or irregular depending on the situation. You may repeat it on a regular basis.
Next, based on FIG. 22, in the second embodiment, for example, a process in which the management server device 1002 generates the parameter 1601 and distributes it to the terminal device A1004 will be described.
The management server device 1002 generates an elliptic curve function E and a point P on the elliptic curve, which are parameters used in ECDH key exchange, by the ECDH key sharing parameter generator 1503 described later (step 1701), and ID-based signature parameters are generated by ID-based. It is generated by the signature parameter generation unit 1505 (step 1702). The combination of the above two parameters corresponds to the above-mentioned parameter 1601. The management server device 1002 assigns a digital signature 1711 to the parameter 1601 (step 1703). The management server device 1002 also transmits the parameter 1601 and the digital signature 1711 to the terminal device A1004 (step 1704).
Terminal device A1004 receives parameter 1601 and digital signature 1711 (step 1705) and verifies the digital signature 1711 (step 1706). If the digital signature 1711 is confirmed to be correct, the parameter 1601 is stored in the parameter table in the parameter storage (step 1707). Here, in the parameter table, the ID of the management server device that generated the parameter and the electronic signature of the parameter and the management server device for the parameter are written together. In the case of FIG. 22, the ID of the management server device 1002, the parameter 1601, and the electronic signature 1711 are described in the parameter table. If you want to distribute repeatedly without changing the parameters, start the process from step 1704. When changing the parameters, the process is started from step 1701.
Here, the management server device 1002 transmits the parameter 1601 and the electronic signature 1711 to the terminal device under control, but the ID-based signature parameter is transmitted from the management server device 1002 to the terminal device A1004. In addition to this, a separate secure method (such as incorporating ID-based signature parameters into the managed terminal device in advance at the time of system introduction) may be used.
Next, with reference to FIG. 23, in the second embodiment, for example, a process in which the parameter 1601 generated by the management server device 1003 is distributed from the management server device 1002 to the terminal device A1004 will be described. Here, it is assumed that the parameter 1601 and the digital signature 1711 have already been transmitted from the management server device 1003 to the management server device 1002.
First, the management server device 1002 confirms whether the terminal device A1004 is permitted to share the key with the terminal device under the control of the management server device 1003 (step 1751). If it is confirmed that it is permitted, the parameter 1601 and the digital signature 1711 are sent to the terminal device A1004 (step 1752).
Terminal device A1004 receives parameter 1601 and digital signature 1711 (step 1753) and verifies the digital signature 1711 (step 1754). If the digital signature 1711 is confirmed to be correct, the parameter 1601 is stored in the parameter table in the parameter storage (step 1755). For example, the ID and parameter 1601 of the management server device 1003 and the electronic signature 1711 will be listed in the parameter table. If it is to be distributed repeatedly, the process is started from step 1751.
In the example of FIG. 23, the management server device 1002 transmits the electronic signature 1711 received from the management server device 1003 as it is to the terminal device A1004 together with the parameter 1601, but the management server device 1002 sends a new electronic signature. You may use it. That is, the management server device 1002 uses the electronic signature parameters (the electronic signature parameters used by the organization to which the management server device 1002 and the terminal device A1004 belong) possessed by both the management server device 1002 and the terminal device A1004. A new electronic signature may be generated, and the generated new electronic signature may be transmitted instead of the electronic signature 1711 from the management server device 1003.
The internal configuration of the terminal devices A1004 to 1007 is the same as that shown in FIG. The operation flow of the partial key generation unit 804 is also shown in FIG. In the present embodiment, the parameters E and P acquired in step 822 are the parameters (E, P) 1109 selected between the terminals. Further, the operation of the elliptic curve calculation unit 803 at the time of partial key generation is the same as that of the first embodiment, but the parameters E and P used for the elliptic curve calculation are the parameters (E, P) 1109 selected between the terminals. .. The operation flow of the encryption key generation unit 805 is also shown in FIG. In the present embodiment, the parameter E acquired in step 827 is E of the parameters (E, P) 1109 selected between the terminals. Further, the operation of the elliptic curve calculation unit 803 at the time of cryptographic key generation is the same as that of the first embodiment, but the parameter E used for the elliptic curve calculation is E of the parameters (E, P) 1109 selected between the terminals. Is. The operation flow of the electronic signature generation unit 807 is also shown in FIG. In the present embodiment, the ID-based signature parameter acquired in step 834 and used in step 835 is the parameter of the own device. That is, in the present embodiment, the terminal device A1004 digitally signs using the parameter (signature) 1102 generated by the management server device 1002. The operation flow of the electronic signature verification unit 806 is also shown in FIG. In the present embodiment, the ID-based signature parameter acquired in step 839 and used in step 840 is a parameter of another terminal device. That is, in the present embodiment, the terminal device A1004 verifies the electronic signature using the parameter (signature) 1104 generated by the management server device 1003.
Next, for example, when the terminal device A1004 is no longer permitted to share the key with the terminal device under the control of the management server device 1003 belonging to another organization by the judgment of the administrator, the management server device 1002 and The process in which the terminal device A1004 deletes the ID-based signature parameter will be described.
When using ID-based signature, the verifier's ID is used as the public key. Therefore, in order to invalidate the public key, the signer deletes the verifier's ID from his / her own storage device. However, this ID may be an ID used for other purposes such as an e-mail address. Therefore, it may not be possible to delete the ID itself due to the invalidation of the public key. Therefore, in the following, the ID-based signature parameter is deleted as a method for invalidating the public key. As a result, the ID cannot be used as the public key, so that the public key can be invalidated without deleting the ID.
FIG. 24 shows the procedure for removing the identity-based signature parameter. First, the management server device 1002 confirms whether the parameter 1601 of the management server device 1003 is held in the parameter storage unit of the terminal device A1004 (step 1761). For example, refer to the parameter log previously sent from the management server device 1002 to the terminal device A1004. If parameter 1601 is not retained, processing ends. If the retention is confirmed, the management server device 1002 sends a parameter deletion command to the terminal device A1004 (step 1762). The parameter deletion instruction includes information indicating the parameter to be deleted and the electronic signature of the management server device 1002.
The terminal device A1004 receives the parameter deletion instruction (step 1763) and verifies the digital signature given (step 1764). If it is confirmed that the digital signature is correct, the parameter described in the information indicating the deletion target is deleted from the parameter table in the parameter storage unit (step 1765). In the case of FIG. 24, the parameters and digital signatures described in the ID section of the management server device 1003 in the parameter table are deleted.
Next, the functions of the terminal devices A1004 to 1005 and 1006 to 1007 in the second embodiment will be described with reference to FIG. 25. FIG. 25 is a functional block diagram illustrating the functional configurations of the terminal devices A1004 to 1005 and 1006 to 1007. Here, for convenience, reference numeral 1801 is attached to the terminal device.
The terminal device 1801 includes a communication interface 1802, an elliptical curve calculation unit 1803, a partial key generation unit 1804, an encryption key generation unit 1805, an electronic signature verification unit 1806, an electronic signature generation unit 1807, a parameter acquisition unit 1808, and a private key acquisition unit 1809. It is composed of a parameter deletion unit 1810, an encryption key storage unit 1811, a secret key storage unit 1812, a parameter storage unit 1813, and an ID storage unit 1814. Communication interface 1802, Elliptical curve calculation unit 1803, Partial key generation unit 1804, Encryption key generation unit 1805, Digital signature verification unit 1806, Digital signature generation unit 1807, Private key acquisition unit 1809, Encryption key storage unit 1811, Private key storage unit The 1812 and the ID storage unit 1814 have the same functions as those constituting the terminal device 801 of FIG.
The parameter storage unit 1813 manages and holds the parameters used when sharing the key for each management server device that generated the parameters. For example, it is held in the form of the table shown in FIG. 26, and the ID and parameters of the management server device and the electronic signature are written together. In addition, the fields corresponding to the management server device for which parameters have not been acquired are blank except for the ID. In the second embodiment, the parameter storage unit 1813 is an example of the first signature parameter storage unit, the second signature parameter storage unit, and the key generation selection parameter storage unit.
The parameter acquisition unit 1808 acquires parameters and electronic signatures given to them from the management server device that manages the terminal device 1801 via the communication interface 1802. Here, the parameters are composed of the ECDH key exchange parameters E and P and the parameters used in the ID-based signature. The digital signature is verified by the digital signature verification unit 1806, and only when the digital signature is confirmed to be correct, the parameter and the digital signature are the management server device that created the parameter and the digital signature in the table in the parameter storage unit 1813. It is described in the ID column of. At this time, if the corresponding ID does not exist in the table, create a new one.
The parameter deletion unit 1810 receives a parameter deletion command from the management server device via the communication interface 1802. The received parameter deletion instruction includes information indicating the parameter to be deleted and the electronic signature of the management server device. The digital signature is verified by the digital signature verification unit 1806, and only when the digital signature is confirmed to be correct, the corresponding parameter is deleted from the table in the parameter storage unit 1813 based on the information indicating the parameter to be deleted. To do. For example, if the information indicating the parameter to be deleted states "Disable the parameter of the management server device Serv_C", the parameter and digital signature in the column where the ID in the table is described as "Serv_C". To delete. If it says "Delete the management server device Serv_C", delete all the fields in the table where the ID is "Serv_C". If the corresponding parameter is not in the table, the process ends.
In the management server device and the terminal device configured in this way, even between the terminal devices under the control of different management server devices, the public key certificate is the same as the processing between the terminal devices in the first embodiment. It is possible to share an encryption key that is not subject to fraud such as forgery by a fraudulent person, without the need for additional equipment for verification processing and PKI.
In addition, ID-based signature is a method of realizing electronic signature using ID as a public key, but it is premised that parameters are shared with each other. To invalidate the public key, the signer would remove the verifier's ID from his storage. However, the ID may be used for other purposes, and it may not be possible to delete the ID due to invalidation of the public key. Therefore, in the present embodiment, as a method of invalidating the public key, the management server device sends a parameter deletion command to the managed terminal device as in the above method, and the terminal device sends the parameter of the ID-based signature. delete. Since the ID cannot be used as the public key due to the deletion of the parameter, the public key is invalidated without deleting the ID, and the management server device can restrict the key sharing between the terminal devices.
That is, in the key sharing method according to the second embodiment, in addition to the operation of the key sharing method according to the first embodiment, ECDH key exchange parameters and ID-based signature parameters are transmitted and received between the management server devices, and different management is performed. In order to share the encryption key between the terminal devices under the control of the server device, ECDH key exchange is performed and the electronic signature by the ID-based signature is transmitted to each other, and the management server device is intended from the terminal device under the control. Key sharing between terminal devices is restricted by deleting the specified parameters.
As described above, in the present embodiment, when key sharing is performed between terminals belonging to different organizations, the management servers of each organization exchange the public parameters of each organization and the digital signatures given to each other, and electronically exchange each other. After verifying the signature, the management server of each organization delivers the public parameters of the other party to the terminals in the organization, thereby explaining the communication system in which the above key sharing can be realized even between terminals between different organizations.
Further, in the present embodiment, when the management server delivers the public parameters received from the management servers of different organizations to the terminals in the organization, the electronic signatures of the management servers of different organizations given to the public parameters are also within the organization. We explained the communication system that delivers to the terminal of the above and the receiving terminal verifies the electronic signature.
Further, in the present embodiment, when the management server delivers the public parameters received from the management servers of different organizations to the terminals in the organization, the public parameters are given their own electronic signatures and delivered to the terminals in the organization. The communication system in which the receiving terminal verifies the electronic signature has been described.
Further, in the present embodiment, when the public parameter of an external organization has already been delivered to the terminal in the organization and the terminal in the organization holds the public parameter of the external organization described above. , By instructing the management server to delete the above-mentioned external organization parameters to the terminal in the organization, the ID should not function as a public key without deleting the ID corresponding to the public key in the ID-based signature. The communication system that enables the above is explained.
Finally, a hardware configuration example of the terminal device and the management server device shown in the first and second embodiments will be described. FIG. 27 is a diagram showing an example of hardware resources of the terminal device and the management server device shown in the first and second embodiments. Note that the configuration shown in FIG. 27 is merely an example of the hardware configuration of the terminal device and the management server device, and the hardware configuration of the terminal device and the management server device is not limited to the configuration shown in FIG. 27. It may be a configuration.
In FIG. 27, the terminal device and the management server device include a CPU 1911 (also referred to as a central processing unit, a processing device, an arithmetic unit, a microprocessor, a microprocessor, or a processor) that executes a program. The CPU 1911 is connected to, for example, a ROM (Read Only Memory) 1913, a RAM (Random Access Memory) 1914, a communication board 1915, a display device 1901, a keyboard 1902, a mouse 1903, and a magnetic disk device 1920 via a bus 1912. Control your hardware device. Further, the CPU 1911 may be connected to an FDD1904 (Flexible Disk Drive), a compact disk device 1905 (CDD), a printer device 1906, and a scanner device 1907. Further, instead of the magnetic disk device 1920, a storage device such as an optical disk device or a memory card (registered trademark) reading / writing device may be used. RAM1914 is an example of volatile memory. The storage media of ROM1913, FDD1904, CDD1905, and magnetic disk device 1920 are examples of non-volatile memory. These are examples of storage devices. The "~ storage unit" such as the parameter storage unit 810 and the secret key storage unit 812 described in the first and second embodiments is realized by the RAM 1914, the magnetic disk device 1920, and the like. The communication board 1915, keyboard 1902, mouse 1903, scanner device 1907, FDD1904, etc. are examples of input devices. The communication board 1915, the display device 1901, the printer device 1906, and the like are examples of output devices.
The communication board 1915 is connected to the network as shown in FIG. 1 and the like. For example, the communication board 1915 may be connected to a LAN (local area network), the Internet, a WAN (wide area network), a SAN (storage area network), or the like.
The magnetic disk device 1920 stores an operating system 1921 (OS), a window system 1922, a program group 1923, and a file group 1924. The programs of the program group 1923 are executed by CPU 1911 using the operating system 1921 and the window system 1922.
In addition, RAM 1914 temporarily stores at least a part of operating system 1921 programs and application programs to be executed by CPU 1911. In addition, various data required for processing by the CPU 1911 are stored in the RAM 1914.
A BIOS (Basic Input Output System) program is stored in the ROM 1913, and a boot program is stored in the magnetic disk device 1920. When the terminal device and the management server device are started, the BIOS program of ROM 1913 and the boot program of the magnetic disk device 1920 are executed, and the operating system 1921 is started by the BIOS program and the boot program.
In the program group 1923, a program that executes the function described as "~ part" (other than "~ storage part", the same applies hereinafter) in the description of the first and second embodiments is stored. The program is read and executed by CPU 1911.
In the file group 1924, in the description of the first and second embodiments, "judgment of ~", "judgment of ~", "calculation of ~", "calculation of ~", "comparison of ~", and verification of "~" , "Generate ~", "Update ~", "Set ~", "Register ~", "Select ~", etc. Information, data, signal values, and variables that indicate the result of the process. Values and parameters are stored as each item of "~ file" and "~ database". The "~ file" and "~ database" are stored in a recording medium such as a disk or a memory. Information, data, signal values, variable values, and parameters stored in a storage medium such as a disk or memory are read out by the CPU 1911 into the main memory or cache memory via a read / write circuit, and are extracted, searched, referenced, compared, and calculated. -Used for CPU operations such as calculation, processing, editing, output, printing, and display. During CPU operation of extraction / search / reference / comparison / calculation / calculation / processing / editing / output / printing / display, information, data, signal values, variable values and parameters are stored in main memory, registers, cache memory and buffers. It is temporarily stored in a memory or the like. Further, the part of the arrow in the flowchart described in the first and second embodiments mainly indicates the input / output of data and signals, and the data and signal values are the memory of RAM1914, the flexible disk of FDD1904, the compact disk of CDD1905, and the magnetic field. It is recorded on a magnetic disk of the disk device 1920 and other recording media such as an optical disk, a minidisc, and a DVD. In addition, data and signals are transmitted online by bus 1912, signal lines, cables and other transmission media.
Further, what is described as "~ part" in the description of the first and second embodiments may be "~ circuit", "~ device", "~ device", and "~ step", It may be "~ procedure" or "~ processing". That is, what is described as "~ part" may be realized by the firmware stored in ROM1913. Alternatively, it may be implemented only by software, only hardware such as elements, devices, boards, and wiring, or a combination of software and hardware, or a combination of firmware. The firmware and software are stored as programs on a recording medium such as a magnetic disk, a flexible disk, an optical disk, a compact disk, a mini disk, or a DVD. The program is read by CPU 1911 and executed by CPU 1911. That is, the program causes the computer to function as the "~ part" of the first and second embodiments. Alternatively, the computer is made to execute the procedure or method of "~ part" of the first and second embodiments.
As described above, the terminal device and the management server device shown in the first and second embodiments are a display device such as a CPU as a processing device, a memory as a storage device, a magnetic disk, a keyboard as an input device, a mouse, a communication board, and the like. , A computer including a communication board, etc., which realizes the functions indicated as "~ parts" as described above by using these processing devices, storage devices, input devices, and output devices.
101 Network, 102 Terminal device A, 103 Terminal device B, 104 Management server device, 801 Terminal device, 802 communication interface, 803 Elliptical curve calculation unit, 804 Partial key generator, 805 Cryptographic key generator, 806 Digital signature verification unit, 807 Digital signature generator, 808 Parameter acquisition unit, 809 Private key acquisition unit, 810 Parameter storage unit, 811 Encryption key storage unit, 812 Private key storage unit, 813 ID storage unit, 901 Management server device, 902 Communication interface, 903 ECDH Key sharing parameter generator, 904 secret key generator, 905 ID-based signature parameter generator, 906 parameter delivery unit, 907 parameter storage unit, 1001 network, 1002 management server device, 1003 management server device, 1004 terminal device A, 1006 terminal Device B, 1501 Management server device, 1502 communication interface, 1503 ECDH key sharing parameter generator, 1504 secret key generator, 1505 ID-based signature parameter generator, 1506 parameter transmitter, 1507 Parameter receiver, 1508 digital signature generation unit, 1509 parameter delivery unit, 1510 parameter storage unit, 1801 terminal device, 1802 communication interface, 1803 elliptical curve calculation unit, 1804 partial key generation unit, 1805 encryption key generation unit, 1806 digital signature verification unit. Department, 1807 Digital signature generation unit, 1808 Parameter acquisition unit, 1809 Private key acquisition unit, 1810 Parameter deletion unit, 1811 Encryption key storage unit, 1812 Private key storage unit, 1813 Parameter storage unit, 1814 ID storage unit.
28 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28
Every citation, both waysCites: the store holds 4 of 5
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR20180114182A | Cited by | Republic of Korea | Search report |
| US11606219B2 | Cited by | United States of America | Applicant |
| US12314379B2 | Cited by | United States of America | Applicant |
| US11194898B2 | Cited by | United States of America | Applicant |
| US11410145B2 | Cited by | United States of America | Applicant |
| US11347838B2 | Cited by | United States of America | Applicant |
| US12321930B2 | Cited by | United States of America | Applicant |
| US12367468B2 | Cited by | United States of America | Applicant |
| US11455378B2 | Cited by | United States of America | Applicant |
| US11126976B2 | Cited by | United States of America | Applicant |
| US10659223B2 | Cited by | United States of America | Applicant |
| US12248539B2 | Cited by | United States of America | Applicant |
| US11308486B2 | Cited by | United States of America | Applicant |
| JP2020532928A | Cited by | Japan | Search report |
| US11373152B2 | Cited by | United States of America | Applicant |
| US10652014B2 | Cited by | United States of America | Applicant |
| US11349645B2 | Cited by | United States of America | Applicant |
| JP2019511855A | Cited by | Japan | Search report |
| US11755718B2 | Cited by | United States of America | Applicant |
| US12217224B2 | Cited by | United States of America | Applicant |
| US10715336B2 | Cited by | United States of America | Applicant |
| US12032677B2 | Cited by | United States of America | Applicant |
| US11120437B2 | Cited by | United States of America | Applicant |
| US11727501B2 | Cited by | United States of America | Applicant |
| US11972422B2 | Cited by | United States of America | Applicant |
| US11182782B2 | Cited by | United States of America | Applicant |
| US12294661B2 | Cited by | United States of America | Applicant |
| US11936774B2 | Cited by | United States of America | Applicant |
| US12254452B2 | Cited by | United States of America | Applicant |
| US12271466B2 | Cited by | United States of America | Applicant |
| US12107952B2 | Cited by | United States of America | Applicant |
| US11625694B2 | Cited by | United States of America | Applicant |
| US11621833B2 | Cited by | United States of America | Applicant |
| US12182805B2 | Cited by | United States of America | Applicant |
| US11356280B2 | Cited by | United States of America | Applicant |
| JP2002108208A | Cites | Japan | Search report |
| JP2005521323A | Cites | Japan | Examiner |
| WO2007080633A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JP2009218991A | Cites | Japan | Search report |
| JPN6013058698; 原田 俊治 他: '機器組込みソフトウェア' Matsushita Technical Journal 第45巻 第2号, 19990218, p.43〜50, 松下電器産業株式会社 | Non-patent | – | Search report |
| JPN6013058694; Katrin Hoeper et al: 'Identity-Based Key Exchange Protocols for Ad Hoc Networks' [online] , 2005, [平成25年11月20日検索],インター | Non-patent | – | Examiner |
| JPN6013058695; 今本 健二 他: '耐タンパ性を備えたユニークデバイスに基づく暗号認証基盤の検討' 電子情報通信学会技術研究報告 Vol.106 No.176, 20060714, p.223〜228, 社団法人電子情報通信学会 The Institute of Electro | Non-patent | – | Examiner |
| JPN6013058696; K. Hoeper et al: 'Preventing or Utilizing Key Escrow in Identity-Based Schemes Employed in Mobile Ad Hoc' [online] , 2007 | Non-patent | – | Examiner |
| CSNG200600913026; 今本 健二 他: '耐タンパ性を備えたユニークデバイスに基づく暗号認証基盤の検討' 電子情報通信学会技術研究報告 Vol.106 No.176, 20060714, p.223〜228, 社団法人電子情報通信学会 The Institute of Electro | Non-patent | – | Examiner |
| CSNH199900076008; 原田 俊治 他: '機器組込みソフトウェア' Matsushita Technical Journal 第45巻 第2号, 19990218, p.43〜50, 松下電器産業株式会社 | Non-patent | – | Examiner |
1 member in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2009231492 | Japan | A | |
| JP20090231492 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| JP2011082662AThis record | Japan | A |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2011082662
- Publication, DOCDB
- 2011082662
- Publication, EPODOC
- JP2011082662
- Application
- 231492
- Application, DOCDB
- 2009231492
- Application, EPODOC
- JP20090231492
Titles2
- Japanese
- 通信装置及び情報処理方法及びプログラム
- English
- Communication equipment and information processing methods and programs
Classification
- IPC, 3
- H04L9 08
- H04L9 32
- G09C1 00