Encrypted data transmitting apparatus, encryption key updating method, electronic device, program and recording medium
2 claims: 2 independent, 0 dependent
- 1コンテンツを暗号処理により符号化して、データ受信装置へ送信する暗号化データ送信装置であって、 前記暗号処理 に用いる 暗号鍵を保持する暗号鍵格納手段と、 第1の所定時間の経過を カウント する第1のカウンタと、 前記第1のカウンタと同じ時刻を起点とし、前記第1の所定時間よりも短い第2の所定時間 の経過 を カウント する第2のカウンタと、 前記暗号処理 に用いる 暗号鍵を生成する暗号鍵更新手段と、 前記データ受信装置からの認証要求を受けると認証を行い、前記認証が成功した場合に前記暗号鍵格納手段に格納された暗号鍵を該データ受信装置へ送信する認証・鍵交換手段と、 前記暗号鍵を用いた暗号処理により符号化されたコンテンツを、前記データ受信装置へ送信する暗号化データ送信手段と、を備え、 前記暗号鍵更新手段は、前記第1のカウンタにより前記第1の所定時間の経過を カウント すると、前記暗号鍵格納手段に保持されている暗号鍵を破棄し、 前記第1のカウンタによる前記第1の所定時間の経過前であって、前記第2のカウンタによる前記第2の所定時間経過後に、前記認証・鍵交換手段が前記データ受信装置からの認証要求を受けると、前記暗号鍵更新手段は新たな暗号鍵を生成し、前記暗号鍵格納手段は保持する暗号鍵を該生成された暗号鍵で更新し、前記認証・鍵交換手段は該生成された暗号鍵を前記データ受信装置へ送信し、前記第1のカウンタ及び第2のカウンタはともにリセットされ、 前記第2のカウンタによる前記第2の所定時間経過前に、前記認証・鍵交換手段が前記データ受信装置からの認証要求を受けると、前記認証・鍵交換手段は前記鍵格納手段に保持された暗号鍵を前記データ受信装置へ送信し、 前記暗号化データ送信手段が暗号処理により符号化したコンテンツを前記データ受信装置へ送信する度に、前記第1のカウンタ及び第2のカウンタはリセットされる、 暗号化データ送信装置。
- 2コンテンツを暗号処理により符号化して、データ受信装置へ送信する暗号化データ送信装置であって、 前記暗号処理 に用いる 暗号鍵と、該暗号鍵を識別する暗号鍵識別子と、を保持する暗号鍵格納手段と、 第1の所定時間の経過を カウント する第1のカウンタと、 前記第1のカウンタと同じ時刻を起点とし、前記第1の所定時間よりも短い第2の所定時間 の経過 を カウント する第2のカウンタと、 前記暗号処理 に用いる 暗号鍵を生成する暗号鍵更新手段と、 前記暗号鍵格納手段に保持された暗号鍵識別子を前記データ受信装置へ送信する識別子送信手段と、 前記暗号鍵格納手段に保持された暗号鍵を用い た 暗号処理により符号化されたコンテンツを、前記データ受信装置へ送信する暗号化データ送信手段と、を備え、 前記第1のカウンタにより前記第1の所定時間の経過を カウント すると、前記暗号鍵格納手段に保持されている暗号鍵識別子は破棄され、 前記第1のカウンタによる前記第1の所定時間の経過前であって、前記第2のカウンタによる前記第2の所定時間経過後に、前記データ受信装置から識別子参照要求を受けると、前記暗号鍵更新手段は新たな暗号鍵と該新たな暗号鍵に対応する新たな暗号鍵識別子とを生成し、前記暗号鍵格納手段は保持する暗号鍵と暗号鍵識別子とを、該新たな暗号鍵と暗号鍵識別子とで更新し、前記識別子送信手段は前記暗号鍵格納手段に保持された該新たな暗号鍵識別子を前記データ受信装置へ送信し、前記第1のカウンタ及び第2のカウンタはともにリセットされ、 前記第2のカウンタによる前記第2の所定時間経過前に、暗号鍵識別子の要求を受けると、前記識別子送信手段は前記鍵格納手段に保持された暗号鍵識別子を前記データ受信装置へ送信し、 前記暗号化データ送信手段が暗号処理により符号化したコンテンツを前記データ受信装置へ送信する度に、前記第1のカウンタ及び第2のカウンタはリセットされる、 暗号化データ送信装置。
Independent claims2
90 paragraphs, as filed
The present invention is an encrypted data transmission device used when transmitting encrypted data.<u style="single">In place</u>It is related.
Conventionally, as a method of updating this type of encryption key, there is an update of the encryption key (Kx) defined in the DTCP standard (Digital Transmission Content Protection standard), for example, the one described in Patent Document 1. there were.
FIG. 5 shows a block diagram of the encrypted data transmission / reception system described in Patent Document 1.
The encrypted data transmitting device 400 is connected to the encrypted data receiving device 401 via Ethernet (registered trademark) 419. From the encrypted data receiving device 401, the authentication / key exchange request, the encryption key identifier request, and the content transmission request are transmitted to the request analysis control unit 416 via the interface unit 412 of the encrypted data transmitting device 400. The request analysis control unit 416 manages the generation / update of the encryption key Kx415 used for encrypting the content data, controls the authentication and key exchange in response to the request from the encrypted data receiving device 401, and also encrypts. Controls the return of the encryption key identifier in response to the same request from the encrypted data receiving device 401.
Hereinafter, the operation when the encrypted data transmitting device 400 receives various requests from the encrypted data receiving device 401 will be described.
The encryption key generation unit 425 of the request analysis control unit 416 generates the encryption key Kx415, destroys / updates the encryption key Kx415, and assigns the encryption key identifier 413 in synchronization with the destruction / update. These encryption key Kx415 and encryption key identifier 413 are stored in the encryption key register 414.
When the request analysis control unit 416 receives a request for content data from the encrypted data receiving device 401, the analysis unit 421 analyzes the request content and instructs the data transmission control unit 422 to control the encrypted data transmission. The data transmission control unit 422 issues a read request for plaintext content data to the hard disk 410 in which the content data is stored, and at the same time instructs the data encryption transmission unit 411 to encrypt the data. The data encryption transmission unit 411, which receives the encryption instruction from the data transmission control unit 422, encrypts the plain text content data read from the hard disk 410 using the encryption key Kx415 read from the encryption key register 414. , The encrypted content data is returned to the encrypted data receiving device 401 via the interface unit 412.
When the request analysis control unit 416 receives an authentication / key exchange request from the encrypted data receiving device 401, the analysis unit 421 analyzes the request contents, and the authentication control unit 424 controls the authentication and key exchange. To instruct. The authentication control unit 424 instructs the authentication / key exchange unit 417 to perform authentication and key exchange with the encrypted data receiving device 401, and the authentication / key exchange unit 417 receives the encrypted data receiving device 401. If successful, the encryption key Kx415 and the encryption key identifier 413 read from the encryption key register 414 are transmitted to the encryption data receiving device 401 through the authentication control unit 424.
When the request analysis control unit 416 requests the encryption key identifier 413 from the encrypted data receiving device 401, the analysis unit 421 analyzes the request contents and instructs the identifier transmission control unit 423 to control the identifier transmission. The identifier transmission control unit 423 gives the encryption key identifier 413 read from the encryption key register 414 to the encryption key identifier request processing unit 418, and instructs the encryption data receiving device 401 to return the encryption key identifier 413. Upon receiving this instruction, the encryption key identifier request processing unit 418 returns the encryption key identifier 413 to the encrypted data receiving device 401 via the interface unit 412.
Next, a method of updating the encryption key in the conventional encrypted data transmission device 400 will be described with reference to FIGS. 5 and 6.
FIG. 6 shows a method of updating the encryption key in the conventional encrypted data transmitting device 400 shown in FIG. 5, and the data encrypted by the encrypted data transmitting device 400 with the encryption key Kx is encrypted by the encrypted data receiving device. It is the figure which showed the procedure received by 401 in chronological order.
In FIG. 6, the encrypted data transmission device 400 generates the first encryption key Kx [1] at time 500. When the encrypted data receiving device 401 requests the encrypted data transmitting device 400 for authentication / key exchange, the encrypted data transmitting device 400 performs the authentication / key exchange and if the authentication is successful, the encryption is performed. The encryption key Kx [1] is transmitted to the data receiver 401 (501).
Next, the encrypted data receiving device 401 transmits a content data transmission request 502 to the encrypted data transmitting device 400, and the encrypted data transmitting device 400 that receives this transmits the requested content with the encryption key Kx [. Encrypt in 1] and send the encrypted data 503. The encrypted data receiving device 401 repeats the request for these content data as many times as necessary, such as the content requests 502 and 504, and the encrypted data transmitting device 400 requests the content data requested for these requests. It encrypts with the encryption key Kx [1] and sends the encrypted data 503 and 505.
The data transmission control unit 422 of the request analysis control unit 416 counts the time from the time when the transmission of the encrypted data is completed by the Kx update timer 420. When the transmission of the encrypted data is completed from the encrypted data transmission device 400 and a predetermined time (here, 2 hours) elapses without the encrypted data being transmitted, the encryption of the request analysis control unit 416 is performed. The key generation unit 425 considers that a series of encrypted data transmissions has been completed, discards and updates the encryption key Kx [1] used up to that point for the security of encrypted data transmission, and newly at time 506. Generate the encryption key Kx [2] in.
After time 506, the encryption key Kx [1] has already been destroyed and is invalid. Therefore, if the encrypted data receiving device 401 wants to receive data from the encrypted data transmitting device 400 again, it is newly authenticated. -By requesting a key exchange, it is necessary to reacquire the new encryption key Kx [2] from the encrypted data transmitter 400 (507).
In the authentication / key exchange 507, the encrypted data receiving device 401 that has acquired the new encryption key Kx [2] sends the encrypted content data to the encrypted data transmitting device 400 in the same manner as the content requests 502 and 504. When the transmission request 508 is transmitted, the encrypted data transmitting device 400 encrypts the requested content with the encryption key Kx [2] in response to the transmission request 508, and transmits the encrypted data 509 to the encrypted data receiving device 401.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 11-289326</text></patcit>
<p> However, in the above-mentioned conventional method of updating the encryption key, it is stipulated that the encryption key Kx is destroyed / updated after a predetermined time (2 hours in the above example) after the last transmission of the encrypted data is completed. Therefore, if there is a request for authentication and key exchange from the encrypted data receiving device 401 at the timing immediately before the lapse of this predetermined time, the encrypted data receiving device 401 sends the encryption after that. There was a problem that the encrypted data could not be decrypted.</p><p> Hereinafter, this problem will be described by taking the case of the above-mentioned conventional method of updating the encryption key as an example.</p><p> In the case of this conventional method of updating the encryption key, the timing of discarding / updating the encryption key Kx is set to be 2 hours after the last transmission of the encrypted data is completed, and then the encrypted data of the encrypted data. This 2-hour progress is not initialized until transmission is started.</p><p> Here, consider the case where the authentication / key exchange 507 of FIG. 6 occurs immediately before the time 506 when the encryption key Kx is updated.</p><p> FIG. 7 shows a method of updating the encryption key in the conventional encrypted data transmission device 400 shown in FIG. 5 when authentication and key exchange occur immediately before the time 506 when the encryption key Kx is updated. The same reference numerals are used for the parts having the same timing as in FIG. The timing of the authentication / key exchange 510 is different from the timing of the authentication / key exchange 507 in FIG.</p><p> In the case of FIG. 7, the time 506 comes immediately after the encrypted data receiving device 401 receives the encryption key Kx [1] in the authentication / key exchange 510, and the encryption key update event in the encrypted data transmitting device 400 occurs. Then, when the encrypted data transmitting device 400 receives the content transmission request 511 from the encrypted data receiving device 401 after the encryption key is updated at time 506, the encrypted data transmitting device 400 is updated. The content is encrypted with the encryption key Kx [2], and the encrypted data 512 is transmitted.</p><p> That is, in this case, the content data is encrypted with the encryption key Kx [2] different from the encryption key Kx [1] received by the encrypted data receiving device 401 from the encrypted data transmitting device 400. The encrypted data receiving device 401 cannot correctly decrypt the encrypted data 512 received in response to the content request 511.</p><p> Further, in the configuration of the conventional encrypted transmission / reception system, the encrypted data receiving device 401 can request the encrypted data transmitting device 400 to refer to the unique identifier given to the encryption key. This identifier reference request is used by the encrypted data receiving device 401 to know whether or not the encryption key Kx has been updated on the encrypted data transmitting device 400 side without performing an authentication / key exchange process. Be done.</p><p> That is, when it becomes necessary for the encrypted data receiving device 401 to receive the content from the encrypted data transmitting device 400, it is necessary to perform an authentication / key exchange process to reacquire the encryption key Kx. In order to know whether the encryption key Kx previously obtained from the encryption data transmission device 400 is still valid and the authentication / key exchange process does not need to be performed again, the encryption data transmission device 400 is used. On the other hand, the reference of the identifier of the encryption key Kx is requested.</p><p> As a result of acquiring the encryption key Kx identifier, the encrypted data receiving device 401 is newly used when it is found that the encryption key Kx obtained from the encrypted data transmitting device 400 in the previous authentication / key exchange process is still valid. The content data request is transmitted to the encrypted data transmission device 400 without re-performing the authentication / key exchange process. On the contrary, if it is found that the previously acquired encryption key Kx has already been destroyed / updated, the authentication / key exchange process is performed prior to the content data request to acquire the updated encryption key Kx. After that, the content data transmission request is transmitted to the encrypted data transmission device 400.</p><p> Here, consider a case where the time 506 shown in FIG. 7 occurs immediately after the encrypted data receiving device 401 acquires the identifier of the encryption key Kx, and the encryption key update event occurs in the encrypted data transmitting device 400.</p><p> It is assumed that the response obtained as a result of requesting the encryption key identifier from the encryption data transmission device 400 indicates that the encryption key Kx held by the encryption data reception device 401 has not been updated. Next, it is assumed that the encryption key update event in the encrypted data transmitting device 400 occurs at the timing immediately after the result of the identifier request is returned to the encrypted data receiving device 401. In this case, the encrypted data receiving device 401 requests the encrypted data transmitting device 400 to transmit the content data on the assumption that the encryption key Kx has not been updated. As the encryption key when performing encryption in response to the transmission request of the content data from the encrypted data receiving device 401, a new encryption key after being updated is used, and this encrypted data is received. In the encrypted data receiving device 401, the received encrypted data cannot be decrypted correctly.</p><p> The present invention solves the above-mentioned conventional problems, and is an encrypted data transmission device capable of reliably decrypting received encrypted data by a receiving device.<u style="single">Place</u>The purpose is to provide.</p>
<p> In order to solve the above-mentioned problems, the first invention of the present invention An encrypted data transmitting device that encodes content by encryption processing and transmits it to a data receiving device. The encryption process<u style="single">Used for</u>An encryption key storage means that holds the encryption key, The passage of the first predetermined time<u style="single">count</u>The first counter to do, A second predetermined time shorter than the first predetermined time, starting from the same time as the first counter.<u style="single">Progress of</u>To<u style="single">count</u>The second counter to do, The encryption process<u style="single">Used for</u>An encryption key update method that generates an encryption key, An authentication / key exchange means that authenticates when an authentication request is received from the data receiving device and transmits the encryption key stored in the encryption key storage means to the data receiving device when the authentication is successful. An encrypted data transmission means for transmitting content encoded by an encryption process using the encryption key to the data receiving device is provided. The encryption key renewal means uses the first counter to check the elapse of the first predetermined time.<u style="single">count</u>Then, the encryption key held in the encryption key storage means is destroyed, and the encryption key is destroyed. The authentication / key exchange means makes an authentication request from the data receiving device before the lapse of the first predetermined time by the first counter and after the lapse of the second predetermined time by the second counter. Upon receipt, the encryption key updating means generates a new encryption key, the encryption key storage means updates the held encryption key with the generated encryption key, and the authentication / key exchange means uses the generated encryption. The key is transmitted to the data receiving device, and both the first counter and the second counter are reset. When the authentication / key exchange means receives an authentication request from the data receiving device before the lapse of the second predetermined time by the second counter, the authentication / key exchange means is held by the key storage means. Send the encryption key to the data receiving device and Each time the encrypted data transmitting means transmits the content encoded by the encryption process to the data receiving device, the first counter and the second counter are reset. It is an encrypted data transmission device.</p><p> In addition, the second invention of the present invention An encrypted data transmitting device that encodes content by encryption processing and transmits it to a data receiving device. The encryption process<u style="single">Used for</u>An encryption key storage means that holds an encryption key, an encryption key identifier that identifies the encryption key, and The passage of the first predetermined time<u style="single">count</u>The first counter to do, A second predetermined time shorter than the first predetermined time, starting from the same time as the first counter.<u style="single">Progress of</u>To<u style="single">count</u>The second counter to do, The encryption process<u style="single">Used for</u>An encryption key update method that generates an encryption key, An identifier transmitting means for transmitting the encryption key identifier held in the encryption key storage means to the data receiving device, and Using the encryption key held in the encryption key storage means<u style="single">Ta</u>It is provided with an encrypted data transmission means for transmitting the content encoded by the encryption process to the data receiving device. The first predetermined time elapses by the first counter.<u style="single">count</u>Then, the encryption key identifier held in the encryption key storage means is destroyed. When an identifier reference request is received from the data receiving device before the elapse of the first predetermined time by the first counter and after the elapse of the second predetermined time by the second counter, the encryption key is updated. The means generates a new encryption key and a new encryption key identifier corresponding to the new encryption key, and the encryption key storage means holds the encryption key and the encryption key identifier in the new encryption key and the encryption key. Updated with an identifier, the identifier transmitting means transmits the new encryption key identifier held in the encryption key storage means to the data receiving device, and both the first counter and the second counter are reset. When the request for the encryption key identifier is received by the second counter before the lapse of the second predetermined time, the identifier transmission means transmits the encryption key identifier held in the key storage means to the data receiving device. Each time the encrypted data transmitting means transmits the content encoded by the encryption process to the data receiving device, the first counter and the second counter are reset. It is an encrypted data transmission device.</p>
<p> According to the present invention, an encrypted data transmission device that allows the receiving device to reliably decrypt the received encrypted data.<u style="single">Place</u>Can be provided.</p>
Hereinafter, embodiments of the present invention will be described with reference to the drawings.
(Embodiment 1) FIG. 1 shows a block diagram of an encrypted data transmission / reception system according to the first embodiment that realizes the method of updating the encryption key of the present invention.
The encrypted data transmitting device 110 is connected to the encrypted data receiving device 111 via Ethernet 309. From the encrypted data receiving device 111, the authentication / key exchange request, the encryption key identifier request, and the content transmission request are transmitted to the request analysis control unit 306 via the interface unit 302 of the encrypted data transmitting device 110. The request analysis control unit 306 manages the generation / update of the encryption key Kx305 used for encrypting the content data, controls the authentication / key exchange in response to the request from the encrypted data receiving device 111, and also encrypts. Controls the return of the encryption key identifier 303 in response to the same request from the data receiving device 111.
Hereinafter, the configuration of the encrypted data transmitting device 110 will be described together with the operation when the request analysis control unit 306 receives various requests from the encrypted data receiving device 111.
The encryption key generation unit 315 of the request analysis control unit 306 generates the encryption key Kx305, destroys / updates the encryption key Kx305 according to the conditions described later, and assigns the encryption key identifier 303 in synchronization with the destruction / update. These encryption key Kx305 and encryption key identifier 303 are stored in the encryption key register 304. The encryption key generation unit 315 corresponds to an example of the encryption key updating means of the present invention, and the encryption key register 304 corresponds to an example of the encryption key storage means of the present invention.
When the request analysis control unit 306 receives a request for content data from the encrypted data receiving device 111, the analysis unit 311 analyzes the request content and instructs the data transmission control unit 312 to control the encrypted data transmission. The data transmission control unit 312 issues a plaintext content data read request to the hard disk 300 in which the content data is stored, and at the same time instructs the data encryption transmission unit 301 to encrypt the data.
Upon receiving an encryption instruction from the data transmission control unit 312, the data encryption transmission unit 301 encrypts the plain text content data read from the hard disk 300 using the encryption key Kx305 read from the encryption key register 304. , The encrypted content data is returned to the encrypted data receiving device 111 via the interface unit 302. The data encryption transmission unit 301 corresponds to an example of the encrypted data transmission means of the present invention.
When the request analysis control unit 306 receives an authentication / key exchange request from the encrypted data receiving device 111, the analysis unit 311 analyzes the request contents, and the authentication control unit 314 controls the authentication and key exchange. To instruct.
The authentication control unit 314 instructs the authentication / key exchange unit 307 to perform authentication / key exchange with the encrypted data receiving device 111, and the authentication / key exchange unit 307 instructs the encrypted data receiving device 111. If successful, the encryption key Kx305 and the encryption key identifier 303 read from the encryption key register 304 are transmitted to the encryption data receiving device 111 through the authentication control unit 314. The authentication / key exchange unit 307 corresponds to an example of the authentication / key exchange means of the present invention.
When the request analysis control unit 306 is requested by the encrypted data receiving device 111 to transmit the encryption key identifier, the analysis unit 311 analyzes the request contents and instructs the identifier transmission control unit 313 to control the identifier transmission. ..
The identifier transmission control unit 313 gives the encryption key identifier 303 read from the encryption key register 304 to the encryption key identifier request processing unit 308, and instructs the encryption data receiving device 111 to return the encryption key identifier 303. Upon receiving this instruction, the encryption key identifier request processing unit 308 returns the encryption key identifier 303 to the encrypted data receiving device 111 via the interface unit 302. The encryption key identifier request processing unit 308 corresponds to an example of the identifier transmission means of the present invention.
The data transmission control unit 312, the identifier transmission control unit 313, and the authentication control unit 314 each start counting the Kx update timer 310, and the encryption key generation unit 315, the identifier transmission control unit 313, and the authentication control unit 314 respectively start Kx update. The encryption key Kx305 and the encryption key identifier 303 are updated according to the count value of the timer 310. The timing for starting the counting of the Kx update timer 310 and the timing for updating the encryption key Kx305 and the encryption key identifier 303 will be described later. The Kx update timer 310 corresponds to an example of the counter of the first predetermined time and the second predetermined time of the present invention.
Next, a method of updating the encryption key in the encrypted data transmission device 110 of the first embodiment will be described with reference to FIGS. 1 and 2.
FIG. 2 shows a method of updating the encryption key in the encrypted data transmission device 110 of the first embodiment shown in FIG. 1, and the data encrypted by the encryption data transmission device 110 with the encryption key Kx is encrypted. It is the figure which showed the procedure which the encryption data receiving apparatus 111 receives in time series. FIG. 2 shows the same timing as that shown in FIG. 7 in which the encrypted data received by the encrypted data receiving device 401 shown in FIG. 5 could not be correctly decrypted in the conventional encrypted data transmission / reception system described above. It is a thing. That is, the timing when an authentication / key exchange request is made from the encrypted data receiving device 111 immediately before a predetermined time (2 hours) elapses from the time when the transmission of the last encrypted data is completed is shown. There is.
In FIG. 2, the encrypted data transmission device 110 generates the first encryption key Kx [1] at time 100. When the encrypted data receiving device 111 requests the encrypted data transmitting device 110 for authentication / key exchange, the encrypted data transmitting device 110 performs the authentication / key exchange, and if the authentication is successful, the encryption is performed. Send the encryption key Kx [1] to the data receiver 111 (101).
Next, the encrypted data receiving device 111 transmits a content data transmission request 102 to the encrypted data transmitting device 110, and the encrypted data transmitting device 110 that receives this transmits the requested content data with the encryption key Kx. It is encrypted in [1] and the encrypted data 103 is transmitted. The encrypted data receiving device 111 repeats the request for these content data as many times as necessary as in the content requests 102 and 104, and the encrypted data transmitting device 110 requests the content data requested for these requests. It is encrypted with the encryption key Kx [1] and the encrypted data 103 and 105 are transmitted.
The data transmission control unit 312 of the request analysis control unit 306 causes the Kx update timer 310 to count the time from the time when the transmission of the encrypted data is completed. When the transmission of the encrypted data is completed from the encrypted data transmission device 110 and a predetermined time (here, 2 hours) elapses without the encrypted data being transmitted, the request analysis control unit The encryption key generation unit 315 of 306 considers that a series of encrypted data transmissions have been completed, discards / updates the encryption key Kx [1] used up to that point for the security of encrypted data transmission, and sets the time. A new encryption key Kx [2] is generated in 106.
When the encrypted data receiving device 111 wants to receive data from the encrypted data transmitting device 110 again, it newly requests authentication / key exchange, but here, the request is issued immediately before time 106.
Here, when the authentication control unit 314, which receives a new authentication / key exchange request from the encrypted data receiving device 111, refers to the count value of the Kx update timer 310 and completes the transmission of the last encrypted data. It is determined whether the time is 5 minutes immediately before the time when the predetermined time (2 hours) elapses from, that is, whether 1 hour 55 minutes or more has passed from the time when the transmission of the last encrypted data is completed.
The predetermined time (2 hours) set for destroying / updating the encryption key when the encrypted data has not been transmitted is an example of the first predetermined time of the present invention. Further, a time set as 1 hour 55 minutes from the time when the transmission of the last encrypted data, which is shorter than the first predetermined time, is completed corresponds to an example of the second predetermined time of the present invention.
If 1 hour and 55 minutes have not passed since the last transmission of the encrypted data was completed, the authentication control unit 314 does not update the encryption key, and the encryption key Kx305 stored in the encryption key register 304 is used. And the encryption key identifier 303 is instructed to the authentication / key exchange unit 307 to be transmitted to the encrypted data receiving device 111 at the time of authentication and key exchange.
On the other hand, if more than 1 hour 55 minutes have passed since the last transmission of the encrypted data was completed, the authentication control unit 314 causes the encryption key generation unit 315 to update the encryption key Kx305, and then the authentication control unit 314 updates the encryption key Kx305. Instruct the authentication / key exchange unit 307 to perform authentication and key exchange, and to send the updated new encryption key Kx305. In this case, the authentication control unit 314 counts the Kx update timer 310 after the encryption key generation unit 315 updates the encryption key Kx305 and before the authentication / key exchange unit 307 performs authentication and key exchange. Reset and start counting again.
In the case of FIG. 2, since the request for authentication / key exchange from the encrypted data receiving device 111 is received after 1 hour 55 minutes have passed from the time when the transmission of the last encrypted data is completed, the authentication is performed. At the time 120 when the request is received, the control unit 314 discards / updates the encryption key Kx [1] used up to that point, generates a new encryption key Kx [2], and stores the encryption key Kx [2] in the encryption key register 304. Rewrite the encryption key Kx305 and the encryption key identifier 303. Then, the authentication control unit 314 passes the new encryption key Kx [2] to the authentication / key exchange unit 307, and the authentication / key exchange 107 transmits the new encryption key Kx [2] to the encrypted data receiving device 111. Let me.
Immediately after this authentication / key exchange 107, the time is 106, which is two hours after the completion of the transmission of the last encrypted data. However, when the authentication control unit 314 performs the authentication / key exchange 107, the Kx update timer 310 Since the count of is reset, at this time 106, 2 hours have not passed since the time when the transmission of the last encrypted data was completed, so the processing of discarding / updating the encryption key Kx is performed. I can't.
Following the authentication / key exchange 107, after the time 106, the encrypted data receiving device 111 issues a content transmission request 108. At this time, the encrypted data transmission device 110 encrypts the content with the encryption key Kx [2] updated at time 120, and transmits the encrypted data 109.
On the other hand, the encrypted data receiving device 111 decrypts the received encrypted data 109 by using the encryption key Kx [2] acquired at the time of the authentication / key exchange 107, so that the encrypted data 109 can be decrypted correctly.
Next, the operation when the encrypted data receiving device 111 refers to the unique identifier given to the encryption key will be described with reference to FIGS. 1 and 3.
FIG. 3 shows a method of updating the encryption key in the encrypted data transmitting device 110 of the first embodiment when the encrypted data receiving device 111 refers to the identifier of the encryption key. FIG. 3 shows the timing when an identifier transmission request is made from the encrypted data transmission device 110 immediately before a predetermined time (2 hours) elapses from the time when the transmission of the last encrypted data is completed. .. In FIG. 3, the same reference numerals as those in FIG. 2 are used for the similarly corresponding parts in FIG.
When referring to the encryption key identifier, the encrypted data receiving device 111 issues a reference request for the identifier to the encrypted data transmitting device 110 when it becomes necessary to receive the content from the encrypted data transmitting device 110. , It is determined whether or not it is necessary to perform authentication / key exchange according to the identifier returned from the encrypted data transmission device 110. That is, the identifier returned from the encrypted data transmitting device 110 is compared with the identifier previously obtained from the encrypted data transmitting device 110, and whether the previously obtained encryption key Kx is still valid or updated. Judge. Then, if the previously acquired encryption key Kx is still valid, a content request is sent to the encrypted data transmission device 110 without authentication / key exchange, and if the encryption key Kx is updated. After performing authentication and key exchange to obtain a new encryption key Kx, request the content.
Therefore, in FIG. 3, when issuing the content request 102, the encrypted data receiving device 111 first transmits the identifier reference request 121 to the encrypted data transmitting device 110.
When the request analysis control unit 306 receives the request for the identifier reference from the encrypted data receiving device 111, the analysis unit 311 analyzes the request contents and instructs the identifier transmission control unit 313 to control the identifier transmission. Then, according to the instruction from the identifier transmission control unit 313, the encryption key identifier 303 stored in the encryption key register 304 is transmitted to the encrypted data receiving device 111 by the encryption key identifier request processing unit 308.
Since the encryption key was updated at time 100 immediately before the identifier reference request 121, the encrypted data receiving device 111 was previously used from the identifier received by the encrypted data receiving device 111 for the identifier reference request 121. Judge that the acquired encryption key Kx has been updated. Since the encryption key Kx acquired last time has been updated, the encrypted data receiving device 111 then requests the encrypted data transmitting device 110 for authentication / key exchange.
Then, by the authentication / key exchange 101, the encrypted data receiving device 111 acquires the encryption key Kx [1], and the encrypted data 103 and 105 received in the subsequent content requests 102 and 104 are received by the received encryption key Kx. Decrypt with [1].
Then, in FIG. 3, the encrypted data receiving device 111 issues an identifier reference request 122 to the encrypted data transmitting device 110 immediately before the time 106.
Here, the identifier transmission control unit 313, which receives the reference request for the new identifier from the encrypted data receiving device 111, refers to the count value of the Kx update timer 310 and starts from the time when the last encrypted data transmission is completed. It is determined whether the time is 5 minutes immediately before the time when the predetermined time (2 hours) elapses, that is, whether 1 hour 55 minutes or more has passed from the time when the transmission of the last encrypted data is completed.
In addition, also in FIG. 3, as in FIG. 2, the predetermined time (2 hours) set for discarding / updating the encryption key when the encrypted data has not been transmitted has passed. This is an example of the first predetermined time of the invention. Further, a time set as 1 hour 55 minutes from the time when the transmission of the last encrypted data, which is shorter than the first predetermined time, is completed corresponds to an example of the second predetermined time of the present invention.
If 1 hour and 55 minutes have not passed since the last transmission of the encrypted data was completed, the identifier transmission control unit 313 does not update the encryption key, and the encryption key stored in the encryption key register 304 is stored. Instructs the encryption key identifier request processing unit 308 to return the identifier 303 to the encrypted data receiving device 111.
On the other hand, if 1 hour 55 minutes or more has passed since the last transmission of the encrypted data was completed, the identifier transmission control unit 313 updates the encryption key Kx305 and the encryption key identifier 303 to the encryption key generation unit 315. Instructs the encryption key identifier request processing unit 308 to return the new encryption key identifier 303 after the update. In this case, the identifier transmission control unit 313 causes the encryption key generation unit 315 to update the encryption key Kx305 and the encryption key identifier 303, and then causes the encryption key identifier request processing unit 308 to return the encryption key identifier 303. , Resets the count of the Kx update timer 310 and starts counting again.
In the case of FIG. 3, since the identifier reference request from the encrypted data receiving device 111 is received after 1 hour and 55 minutes have passed from the time when the transmission of the last encrypted data is completed, the identifier transmission control is performed. At the time 126 when the request is received, the unit 313 discards / updates the encryption key Kx [1] used up to that point, generates a new encryption key Kx [2], and stores the encryption key Kx [2] in the encryption key register 304. Rewrite the existing encryption key Kx305 and encryption key identifier 303. Then, the identifier transmission control unit 313 passes the identifier of the new encryption key Kx [2] to the encryption key identifier request processing unit 308, and the encryption key identifier request processing unit 308 transfers the identifier of the new encryption key Kx [2]. It is transmitted to the encrypted data receiving device 111.
Immediately after this identifier reference request 122, at time 106, which is two hours after the completion of the transmission of the last encrypted data, the identifier transmission control unit 313 receives the identifier reference request 122 and the encryption key generation unit 315. Since the count of the Kx update timer 310 is reset when the encryption key Kx305 and the encryption key identifier 303 are updated, 2 hours have passed since the last transmission of the encrypted data was completed. Therefore, at this time 106, the process of destroying / updating the encryption key Kx is not performed.
Following the transmission of the identifier reference request 122 and the identifier of the encryption key Kx [2], after time 106, the encrypted data receiving device 111 issues a request for authentication / key exchange, and the authentication / key exchange is performed (authentication / key exchange). one two Three). In the authentication / key exchange 123, the encrypted data receiving device 111 acquires a new encryption key Kx [2].
Further, following the authentication / key exchange 123, the content transmission request 124 is issued from the encrypted data receiving device 111. At this time, the encrypted data transmission device 110 encrypts the content with the encryption key Kx [2] updated at time 126, and transmits the encrypted data 125.
On the other hand, the encrypted data receiving device 111 decrypts the received encrypted data 125 by using the encryption key Kx [2] acquired at the time of the authentication / key exchange 123, so that the encrypted data 125 can be decrypted correctly.
Next, when the encrypted data receiving device 111 shown in FIG. 3 refers to the unique identifier given to the encryption key, the encrypted data transmitting device 110 updates the encryption key Kx305 and the encryption key identifier 303. The algorithm will be described with reference to FIGS. 1 and 4.
FIG. 4 shows a processing flow when the requirements analysis control unit 306 of the encrypted data transmission device 110 updates the encryption key Kx305 and the encryption key identifier 303.
At the time of initialization, the encryption key generation unit 315 of the request analysis control unit 306 generates the initial value of the encryption key Kx305 and the encryption key identifier 303 corresponding to this initial value with random numbers and stores them in the encryption key register 304 (S200). ). At this time, the encryption key generation unit 315 starts counting the Kx update timer 310 (S201), and the analysis unit 311 enters the request waiting state from the encrypted data receiving device 111 (S202).
The analysis unit 311 that received some request from the encrypted data receiving device 111 notifies the encryption key generation unit 315, and the encryption key generation unit 315 that received the notification has the count value of the Kx update timer 310 exceeding 2 hours. Determine if it is (S203). Then, when the count value exceeds 2 hours, the encryption key generation unit 315 generates a new encryption key Kx305 value with a random number and reads the value of the encryption key identifier 303 from the encryption key register 304. It increments and writes back to the encryption key register 304 (S204), resets the count value of the Kx update timer 310, and starts from zero again (S205).
Next, the analysis unit 311 analyzes the request content from the encrypted data receiving device 111 (S206), and branches the processing to S210, S207, and S214 according to the received request content, respectively.
When the content of the request received from the encrypted data receiving device 111 is an authentication / key exchange request, the analysis unit 311 instructs the authentication control unit 314 to execute the authentication / key exchange request.
The authentication control unit 314 determines whether the count value of the Kx update timer 310 exceeds the time 5 minutes before the time (2 hours) when the value of the encryption key Kx305 is updated in S204, that is, 1 hour 55 minutes. However, if it is exceeded (S210), the encryption key generator 315 is instructed to update the encryption key Kx305. Upon receiving the instruction, the encryption key generator 315 generates a new encryption key Kx305 value with a random number, reads the value of the encryption key identifier 303 from the encryption key register 304, increments it, and writes it back to the encryption key register 304 again ( S211), reset the count value of the Kx update timer 310 and start from zero again (S212).
The authentication control unit 314 causes the encryption key generation unit 315 to update the encryption key Kx305, and then causes the authentication / key exchange unit 307 to perform authentication / key exchange with the encrypted data receiving device 111. Instruct. Then, when the authentication / key exchange is completed, the authentication control unit 314 reads the encryption key Kx305 and the encryption key identifier 303 from the encryption key register 304 and passes them to the authentication / key exchange unit 307 to perform the authentication / key exchange unit. It is transmitted to the encrypted data receiving device 111 by 307 (S213).
On the other hand, in S206, when the request content received from the encrypted data receiving device 111 is a reference request for the encryption key identifier, the analysis unit 311 instructs the identifier transmission control unit 313 to transmit the identifier. put out.
The identifier transmission control unit 313 determines whether or not the count value of the Kx update timer 310 exceeds the time 5 minutes before the time (2 hours) when the value of the encryption key Kx305 is updated in S204, that is, 1 hour 55 minutes. Judgment (S214), and if it exceeds, instruct the encryption key generator 315 to update the encryption key Kx305. Upon receiving the instruction, the encryption key generator 315 generates a new encryption key Kx305 value with a random number, reads the value of the encryption key identifier 303 from the encryption key register 304, increments it, and writes it back to the encryption key register 304 again ( S215), reset the count value of the Kx update timer 310 and start from zero again (S216).
The identifier transmission control unit 313 causes the encryption key generation unit 315 to update the encryption key Kx305, and then gives the encryption key identifier 303 to the encryption key identifier request processing unit 308, and gives the encryption key identifier 303 to the encryption data receiving device 111. Instruct to send. Upon receiving this instruction, the encryption key identifier request processing unit 308 returns the requested encryption key identifier 303 to the encrypted data receiving device 111.
On the other hand, in S206, when the request content received from the encrypted data receiving device 111 is a content transmission request, the analysis unit 311 instructs the data transmission control unit 312 to transmit the encrypted content data. put out.
The data transmission control unit 312 gives an instruction to read the plaintext content data to the hard disk 300 and an instruction to encrypt the plaintext content data to the data encryption transmission unit 301. Upon receiving this instruction, the data encryption transmitter 301 reads the encryption key Kx305 stored in the encryption key register 304, encrypts the plain text content data using the encryption key Kx305 (S207), and interfaces the encrypted content data. It is sent back to the encrypted data receiving device 111 via unit 302 (S208). Further, the data transmission control unit 312 resets the count value of the Kx update timer 310 after the transmission of the encrypted data is completed, and starts from zero again (S209).
The request analysis control unit 306 updates the encryption key Kx305 and the encryption key identifier 303 with S211 or S215 according to the algorithm described above, so that the encryption data transmission device 110 performs an authentication / key exchange request or an encryption key identifier information request. If the count value of the Kx update timer 310 exceeds 1 hour 55 minutes at the time of receiving the above, each request is executed after the encryption key Kx305 and the encryption key identifier 303 are updated. As a result, the encryption key Kx305 is updated immediately after the encryption data receiving device 111 acquires the encryption key Kx305 by authentication / key exchange, and the encryption data receiving device 111 also acquires the encryption key identifier 303. Since there is no possibility that the encryption key Kx305 will be updated immediately afterwards, it is possible to provide an encryption data transmission device and an encryption key update method that can reliably decrypt the encrypted content data received by the encryption data reception device 111. It will be possible.
Further, by equipping the electronic device for transmitting the encrypted data with the encrypted data transmission device 110 of the first embodiment, it is possible to provide an electronic device capable of reliably decrypting the received encrypted content data. For example, it can be applied to electronic devices that transmit encrypted content data, such as AV devices connected to a LAN, personal computers, and STBs.
In the first embodiment, the time for updating the encryption key Kx is set to be 2 hours and 1 hour 55 minutes after the completion of the transmission of the last encrypted data. Even if the time is set to any other predetermined value, the same effect can be obtained if the time updated by S211 and S215 in FIG. 4 is earlier than the time updated by S204. Needless to say.
Further, in the first embodiment, the plaintext content data is encrypted with the encryption key Kx, but the content data is not directly encrypted with the encryption key Kx, but the content is indirectly derived from the encryption key Kx. It goes without saying that the same effect can be obtained by encrypting the data.
Further, in the first embodiment, the configuration in which only one encrypted data receiving device 111 is connected to the encrypted data transmitting device 110 has been described, but a plurality of encrypted data receiving devices are encrypted by one unit. It may be connected so as to receive the encrypted content data from the encrypted data transmission device.
Further, in the first embodiment, the encrypted data transmitting device 110 and the encrypted data receiving device 111 are connected by Ethernet 309, but if the connection method is such that the encrypted data can be transmitted and received, wired or wireless. Regardless of, it may be connected in any way.
As described above, the configuration of the present invention may be realized by software or hardware.
As described above, the encrypted data transmission device of the present invention.<u style="single">Place</u>, In the encrypted data transmission device, the second is slightly smaller than the original encryption key destruction / update time (the time when two hours have passed from the time when the transmission of the last encrypted data in the present embodiment is completed). A key update time (in the present embodiment, a time point after 1 hour 55 minutes has passed from the time when the transmission of the last encrypted data is completed) is provided, and the encrypted data receiving device transmits the encrypted data for the authentication / key exchange request. If the timing of transmission to the device is after this second key update time has elapsed, the encryption key is updated earlier than the original key update timing, and the encrypted data receiving device is notified. , Sends a new updated encryption key.
The encrypted data transmission device of the present invention<u style="single">Place</u>By using this, when the encrypted data transmitter receives the authentication / key exchange request, if the second encryption key update time, which is shorter than the original encryption key update time, has already passed, the encryption key By sending the encryption key Kx to the encrypted data receiving device after updating the encryption key, the encryption key can be updated between the time when the authentication / key exchange is performed and the time when the content data is requested. It is possible to avoid the problem that the encrypted data that occurs and is received by the encrypted data receiving device is not decrypted correctly.
Further, the encrypted data transmission device of the present invention<u style="single">Place</u>When the encrypted data receiving device requests the identifier given to the encryption key in the encrypted data transmitting device, the original encryption key is destroyed / updated in the encrypted data transmitting device (the last in the present embodiment). The second key update time (1 hour 55 from the time when the last encrypted data transmission in the present embodiment) is slightly smaller than the time when 2 hours have passed from the time when the transmission of the encrypted data of If the time when the encrypted data receiving device requests the encryption key identifier from the encrypted data transmitting device is after the second key update time has elapsed. , The encryption key is updated earlier than the original key update timing, and the updated new encryption key identifier is transmitted to the encrypted data receiving device.
The encrypted data transmission device of the present invention<u style="single">Place</u>By using this, when the encrypted data receiving device requests the encrypted data transmitting device for the encryption key identifier, the second encryption key update time, which is shorter than the original encryption key update time, has already passed. In that case, the encrypted data transmission device transmits the encryption key identifier after the encryption key is updated, so that the encryption is performed between the inquiry of the identifier and the request for the content data. It is possible to avoid the problem that the encrypted data received by the encrypted data receiving device is not correctly decrypted due to the update of the key.
Encrypted data transmission device according to the present invention<u style="single">Place</u>It has the effect that the receiving device can reliably decrypt the received encrypted data, and is useful for an encrypted data transmission device, an encryption key update method, an electronic device, and the like used when performing encrypted data transmission.
<figref num="1">Block diagram of the encrypted data transmission / reception system according to the first embodiment of the present invention</figref><figref num="2">The figure which shows the method of updating the encryption key in the encrypted data transmission apparatus of Embodiment 1 of this invention.</figref><figref num="3">The figure which shows the method of updating the encryption key in the encryption data transmission device when the encryption data receiving device refers to the identifier of the encryption key in Embodiment 1 of this invention.</figref><figref num="4">The figure which shows the processing flow when the encrypted data transmission apparatus of Embodiment 1 of this invention updates an encryption key and an encryption key identifier.</figref><figref num="5">Block diagram of a conventional encrypted data transmission / reception system</figref><figref num="6">The figure which shows the update method of the encryption key in the conventional conventional encrypted data transmission device.</figref><figref num="7">The figure which shows the method of updating the encryption key in the conventional encrypted data transmission device when the authentication and the key exchange occur immediately before the time when the encryption key is updated.</figref>
Code description
110 Encrypted data transmitter 111 Encrypted data receiver 100, 106, 120, 126 time 101, 107, 123 Authentication / key exchange 102, 104, 108, 124 Content request 103, 105, 109, 125 encrypted data 121 122 Identifier reference request 300 hard disk 301 Data encryption transmitter 302 Interface section 303 Cryptographic key identifier 304 Cryptographic key register 305 Encryption key Kx 306 Requirements Analysis Control Unit 307 Authentication / Key Exchange Department 308 Cryptographic key identifier request processing unit 309 Ethernet 310 Kx update timer 311 Analysis Department 312 Data transmission control unit 313 Identifier transmission control unit 314 Authentication control unit
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2003244131A | Cites | Japan |
| JP2001230769A | Cites | Japan |
| JP2004229114A | Cites | Japan |
| JP2002217896A | Cites | Japan |
| JP2005136870A | Cites | Japan |
| JP2001345798A | Cites | Japan |
| JP2004302846A | Cites | Japan |
| JP11289326A | Cites | Japan |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2005292805 | Japan | A | |
| JP20050292805 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2007104430A | Japan | A | |
| JP4907944B2This record | Japan | B2 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: A7422RD02 | RD02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4907944
- Publication, DOCDB
- 4907944
- Publication, EPODOC
- JP4907944B
- Application
- 292805
- Application, DOCDB
- 2005292805
- Application, EPODOC
- JP20050292805
Titles2
- Japanese
- 暗号化データ送信装置
- English
- Encrypted data transmitter
Classification
- IPC, 1
- H04L9 14
