JP5637401B2

Encryption key update method, encryption key update device, and encryption key update program

Abstract

This record has no abstract on file.

Term

Projected expiry 26 November 2032.

  1. Priority and filed
  2. Granted
  3. Today
  4. Projected expiry

9 claims: 3 independent, 6 dependent

  1. 1
    In a network consisting of a server and a large number of nodes, if a node has d types of attributes, it is considered that the nodes belong to d groups at the same time, and a group key is associated with each group defined in this way. Regarding the method in which the server shares the group key only with the nodes belonging to the group and performs encrypted communication for each group, the server updates the group key when there is a change in the group members. A method of correctly distributing the updated group key, and controlling group key distribution so that when a node is forcibly excluded from the group, the excluded node does not continue to own a valid group key. And When the node to be excluded is a group head node, the server exchanges roles between the group head node which is the node to be excluded and another node in the minimum group to which the group head belongs. The node to be excluded is a node that is not a group head node, and the updated group key is sent to a node other than the node to be excluded in the corresponding group via the group head node. The minimum group is a product set of a plurality of groups obtained as a result of extracting one group having an arbitrary attribute value for each attribute, and is a non-empty minimum. The group head node is a node that belongs to a group that includes exactly one node in a product set with an arbitrary minimum group. A method of updating an encryption key. サーバと多数のノードから構成されるネットワークにおいて、ノードに属性がd種類存在する場合、ノードはd個のグループに同時に属すると考え、このように定義される各グループに対してグループ鍵を対応付け、サーバがグループ鍵をそのグループに属するノードとだけ共有して、各グループを対象とする暗号通信を実施する方法に関し、グループ構成員の変化があった場合に、サーバがグループ鍵を更新し、更新後のグループ鍵を正しく配信する方法であって、あるノードを強制的にグループから排除する場合に、排除されるノードが有効なグループ鍵を所有し続けることのないよう、グループ鍵配信の制御を行い、 前記サーバが、排除するべきノードがグループヘッドノードである場合には、排除するべきノードであるグループヘッドノードとそのグループヘッドが属する極小グループ内の他のノードとで役割を交換することにより、前記排除するべきノードをグループヘッドノードでないノードにした上で、更新後のグループ鍵を、その対応するグループにおいて排除するべきノード以外のノードにグループヘッドノードを介して送ることで、前記排除するべきノードを排除するグループヘッドノード排除ステップを有し、 前記極小グループは、属性毎に任意の属性値を持つグループを1つずつ抽出した結果得た複数のグループの積集合であり、かつ、空でない極小の集合であるグループであり、前記グループヘッドノードは、任意の極小グループとの積集合にちょうど一個のノードを含むようなグループに属するノードである、 ことを特徴とする暗号鍵更新方法。
  2. 3
    In a network consisting of a server and a large number of nodes, if a node has d types of attributes, it is considered that the nodes belong to d groups at the same time, and a group key is associated with each group defined in this way. Regarding the method in which the server shares the group key only with the nodes belonging to the group and performs encrypted communication for each group, the server updates the group key when there is a change in the group members. Control of group key distribution so that when a node is forcibly excluded from the group, it is a method of correctly distributing the updated key so that the excluded node does not continue to own a valid group key. Do, If the attribute is a division of all node sets N, (condition 1) GiN, (condition 2) i j, then GiGj is an empty set, (condition 3) G1G2. .. .. Family of sets {G1, G2, which satisfy the three conditions of Gm = N. .. .. , Gm} is called an attribute, and d attributes A1,. .. .. , Ad, Ai = {Gi, 1,. .. .. , Gi, mi} (mi is the number of elements of Ai), and if Gi, j is a set of nodes having the jth attribute value for the attribute i, k integers 1 i1,. .. .. , Ik, d and k groups Gi1, j1,. .. .. , Gik, jk (however, for 1 a k, Gia, ja Aia) exists, and G = Gi1, j1. .. .. When the node set G such as Gik and jk is a group of order k, d attributes constituting group C (minimum group) of order d, which is a minimum set in the inclusion relationship between structured groups. In addition to (Condition 4), CG0,1 includes exactly one node (group head) for any minimum group C, and (Condition 5) A group other than G0,1 in any minimum group C, A0. A special attribute A0 = {G0,1,. That is configured so that CG0, j contains at most one node (group member) with respect to G0, j. .. .. , G0, m0} (where m0> 0) is introduced, and d + 1 attribute sets A0, A1,. .. .. , Update and manage the group key in the d-dimensional group structure composed of Ad, Since the nodes belong to exactly one minimal group and A0 is a division of the node set N, d + 1 integer set j0, j1,. For any node n. .. .. , Jd exists, and G0, j0G1, j1. .. .. It can be expressed as Gd, jd = {n}, and the d + 1 character set (j0, j1, ..., jd) is treated as the identifier (ID) of the node n. A0, A1,. .. .. Considering the case where Ad defines a d-dimensional group structure, at this time, the server is a node belonging to a group Gi, j (0 i d, 1 j mi) of order 1 and a group key ki, j ( (Called an element key) is shared in advance, and the group G = Gi1, j1. .. .. Gik, jk (i1 <... <ik), h (ki1, j1 || ... || kik, jk) (h is a hash function, || is a key concatenation) on the server and node The information that can be calculated is the group key k (G) of G. Only the node belonging to G knows the group key k (G) of the group G of the rank k. At this time, the server or the node belonging to G encrypts the data to be transmitted to G by k (G). Multicast the obtained ciphertext to the G node and distribute it. Assuming that the ID of the node n is (j0, j1, ..., jd), n is d + 1 element keys k0, j0 ,. .. .. , Kd, jd, and by using these d + 1 keys, n can calculate kn = h (k0, j0 || ... || kd, jd), and this value kn is n. And since only the server is a calculable value, the server uses kn as the key shared between n and the server (node key), and the server encrypts the data for each node with its own node key. Safely send in a unicast manner In order to enable a secure one-to-one message exchange between the group head and each group member of the smallest group to which the group head belongs, the server has each of the group head and each group member. A unique key (member key) common to the node key is encrypted and sent in a unicast manner. When the server wants to add the node n to the group Gi, j of the order 1, if the code statement obtained by encrypting the data x with the key k is written as Ek (x), the node addition means provided in the server is , C = Eh (ki, j) (ki'i, j) is calculated for the nodes that have belonged to Gi, j for a long time, and c is multicast-distributed to the nodes belonging to Gi, j, and for n. By encrypting the new key k'i, j in a unicast manner with the node key shared only by the server and its node and transmitting it from the server, the new key k'i, j is transmitted while ensuring backward security. In the new group Gi, j, When the server excludes the node n from the group Gi, j of rank 1, if the set obtained by removing n from Gi, j is written as G'i, j, G'i, j will remain in the group even after the exclusion of n. All nodes belonging to G'i, j must be able to obtain new keys k'i, j, and the node n to be excluded is excluded in order to ensure forward security. Since it is necessary not to know k'i and j, the main node exclusion means provided in the server cooperates with the sub-node exclusion means provided in the group head that always exists in the minimum group, and the node exclusion means. Perform the processing of When the server excludes the node n from the group Gi, j of rank 1, if the exclusion node n is not the group head and i 0 for the element groups Gi, j excluding n, the main node exclusion means of the server. First, when ki and j are the element keys of Gi and j and k'i and j are the element keys of the new Gi and j, k = h (k0,1 || ki, j) is calculated and x. = Ek (k'i, j) is obtained, and a 4-character set (i, j, IDn, x) is multicast-transmitted to a node (group head) belonging to Gi, jG0,1 (IDn is excluded). The ID of the node n), and then the sub-node exclusion means of the node (group head) belonging to Gi, jG0,1 decodes x to obtain the new keys k'i, j of Gi, j, and finally. In addition, when the sub-node exclusion means of the node (group head) belonging to Gi, jG0,1 does not include the exclusion node n in the minimum group C to which the own node belongs, k (C) (the minimum group C to which the own node belongs). K'i, j is encrypted using the group key of), and Ek (C) (k'i, j) is multicast-distributed to the group members of C, while the exclusion node is distributed to the minimum group C to which the group head belongs. When n is included, the subnode exclusion means of the group head unicastly encrypts k'i and j using the member key and transmits them to the group members of C other than n. When the server excludes the node n from the group Gi, j of rank 1, if the exclusion node n is not the group head and i = 0 and j 1 for the element groups Gi, j excluding n, the server The main node exclusion means calculates x1 = Eh (k0, j) (k'0, j) and x2 = Eh (k0,1) (x1), and obtains a 4-character set (0, j, IDn, x2). Multicast distribution is performed to the set G0,1 of the group heads, and the subnode exclusion means of each group head decodes x2 to obtain x1 (since the group head does not know k0, j, x1 cannot be decoded). , G0, j and the minimum group C to which it belongs include one node n', and if n n', the subnode exclusion means of the group head is uni-node to n'with a member key. Encrypt x1 as a cast and send it When the server excludes the node n from the group Gi, j of rank 1, when i = 0 and j = 1, that is, the exclusion node n is the group head, the main node exclusion means provided in the server excludes n. Performs the process of exchanging the roles of the group heads n of the groups Gi and j and the nodes n'in the minimum group to which the group heads belong, and performs the node exclusion process when the exclusion node is not the group head after the role exchange process is completed. An encryption key renewal method characterized by enforcement. サーバと多数のノードから構成されるネットワークにおいて、ノードに属性がd種類存在する場合、ノードはd個のグループに同時に属すると考え、このように定義される各グループに対してグループ鍵を対応付け、サーバがグループ鍵をそのグループに属するノードとだけ共有して、各グループを対象とする暗号通信を実施する方法に関し、グループ構成員の変化があった場合に、サーバがグループ鍵を更新し、更新後の鍵を正しく配信する方法であって、あるノードを強制的にグループから排除する場合に、排除されるノードが有効なグループ鍵を所有し続けることのないよう、グループ鍵配信の制御を行い、 属性を全ノード集合Nの分割であるとし、(条件1)Gi⊂N、(条件2)i≠jならばGi∩Gjは空集合である、(条件3)G1∪G2∪...Gm=N、の3つの条件を満たす集合族{G1,G2,...,Gm}を属性と呼ぶとき、d個の属性A1,...,Adを考え、Ai={Gi,1,...,Gi,mi}とし(miはAiの要素数)、Gi,jは、属性iについてj番目の属性値を持つノードの集合であるとしたとき、k個の整数1≦i1,...,ik,≦dおよびk個のグループGi1,j1,...,Gik,jk(ただし、1≦a≦kに対してGia,ja∈Aiaとする)が存在し、G=Gi1,j1∩...∩Gik,jkとなるノード集合Gを位数kのグループであるというとき、構造化グループ間の包含関係において極小の集合である位数dのグループC(極小グループ)を構成するd個の属性に加え、(条件4)任意の極小グループCに対し、C∩G0,1がちょうど一個のノード(グループヘッド)を含む、(条件5)任意の極小グループC,A0におけるG0,1以外のグループG0,jに対し、C∩G0,jが高々一個のノード(グループメンバ)を含む、の2つを満たすように構成した特殊な属性A0={G0,1,...,G0,m0}(ただしm0>0)を導入して、d+1個の属性組A0,A1,...,Adで構成するd次元グループ構造でグループ鍵を更新管理し、 ノードはちょうど一個の極小グループに属すること、A0はノード集合Nの分割になっていることより、任意のノードnに対してd+1個の整数組j0,j1,...,jdが存在し、G0,j0∩G1,j1∩...∩Gd,jd={n}とあらわすことができ、d+1字組(j0,j1,...,jd)をノードnの識別子(ID)として取り扱い、 A0,A1,...,Adがd次元グループ構造を定義する場合を考え、この時サーバは、位数1のグループGi,j(0≦i≦d,1≦j≦mi)に属するノードとグループ鍵ki,j(要素鍵と呼ぶ)をあらかじめ共有し、位数kのグループG=Gi1,j1∩...∩Gik,jk(i1<...<ik)に対し、h(ki1,j1||...||kik,jk)(hはハッシュ関数、||は鍵の連接)としてサーバおよびノードで計算できる情報をGのグループ鍵k(G)とし、 位数kのグループGのグループ鍵k(G)を知るのはGに属するノードのみであり、この時、サーバあるいはGに属するノードは、Gに送信したいデータをk(G)により暗号化し、得られた暗号文をGのノードに対してマルチキャスト配信し、 ノードnのIDを(j0,j1,...,jd)とすると、nはd+1個の要素鍵k0,j0,...,kd,jdを所有し、これらd+1個の鍵を用いることにより、nはkn=h(k0,j0||...||kd,jd)を計算することができ、この値knはnおよびサーバだけが計算可能な値であるため、サーバはknをnとサーバとの間で共有された鍵(ノード鍵)として、サーバは、各ノードに対してそれぞれのノード鍵でデータを暗号化してユニキャスト的に安全に送信し、 グループヘッドとそのグループヘッドの属する極小グループの各グループメンバとの間で安全に一対一のメッセージの交換を行うことを可能とするため、サーバは、グループヘッドと各グループメンバに対して、それぞれのノード鍵で共通のユニークな鍵(メンバ鍵)を暗号化してユニキャスト的に送信し、 サーバがノードnを位数1のグループGi,jに追加したいとき、データxを鍵kにより暗号化して得られる暗号文をEk(x)と書くこととすると、サーバに備えさせるノード追加手段は、Gi,jに以前から所属するノードには、c=Eh(ki,j)(k’i,j)を計算し、cをGi,jに属するノードに対してマルチキャスト配信し、nに対してはユニキャスト的に新しい鍵k’i,jをサーバとそのノードだけで共有するノード鍵で暗号化してサーバから伝達することで、後方安全性を確保しつつ、新しい鍵k’i,jを新しいグループGi,jで共有し、 サーバがノードnを位数1のグループGi,jから排除するとき、Gi,jからnを除いた集合をG’i,jと書くと、G’i,jは、nの排除後もグループにとどまるノード集合であり、G’i,jに属するすべてのノードは、新しい鍵k’i,jを入手できなければならず、かつ、前方安全性を確保するため、排除されるノードnがk’i,jを知ることがないようにしなければならないため、サーバに備えさせる主ノード排除手段は、極小グループに必ず一個存在するグループヘッドに備えさせる副ノード排除手段と連携して、ノード排除の処理を実施し、 サーバがノードnを位数1のグループGi,jから排除するとき、排除ノードnがグループヘッドでなく、nを排除する要素グループGi,jについてi≠0である場合、サーバの主ノード排除手段は、まず、ki,jをGi,jの要素鍵、k’i,jは新しいGi,jの要素鍵としたとき、k=h(k0,1||ki,j)を計算し、x=Ek(k’i,j)を求め、4字組(i,j,IDn,x)をGi,j∩G0,1に属するノード(グループヘッド)向けにマルチキャスト送信し(IDnは排除されるノードnのID)、その後、Gi,j∩G0,1に属するノード(グループヘッド)の副ノード排除手段は、xを復号してGi,jの新しい鍵k’i,jを入手し、最後に、Gi,j∩G0,1に属するノード(グループヘッド)の副ノード排除手段は、自ノードの属する極小グループCに排除ノードnを含まないとき、k(C)(自身の属する極小グループCのグループ鍵)を用いてk’i,jを暗号化し、Ek(C)(k’i,j)をCのグループメンバに向けてマルチキャスト配信する一方、グループヘッドの属する極小グループCに排除ノードnが含まれるとき、グループヘッドの副ノード排除手段が、n以外のCのグループメンバに対してメンバ鍵を用いてユニキャスト的にk’i,jを暗号化して送信し、 サーバがノードnを位数1のグループGi,jから排除するとき、排除ノードnがグループヘッドでなく、nを排除する要素グループGi,jについてi=0かつj≠1である場合、サーバの主ノード排除手段は、x1=Eh(k0,j)(k’0,j)およびx2=Eh(k0,1)(x1)を計算し、4字組(0,j,IDn,x2)をグループヘッドの集合G0,1にマルチキャスト配信し、各グループヘッドの副ノード排除手段はx2を復号してx1を得て(グループヘッドはk0,jを知らないため、x1を復号することはできない)、G0,jと自身の属する極小グループCとの積集合に、ノードn’が一個含まれ、かつn≠n’であれば、グループヘッドの副ノード排除手段が、n’にメンバ鍵でユニキャスト的にx1を暗号化して送信し、 サーバがノードnを位数1のグループGi,jから排除するとき、i=0かつj=1すなわち排除ノードnがグループヘッドである場合に、サーバに備える主ノード排除手段は、nを排除するグループGi,jのグループヘッドnと、そのグループヘッドが属する極小グループ内のノードn’との役割を交換する処理を実施し、役割交換処理終了後に排除ノードがグループヘッドでない場合のノード排除処理を施行することを特徴とする暗号鍵更新方法。
  3. 8
    In a network consisting of a server and a large number of nodes, if a node has d types of attributes, the nodes are considered to belong to d groups at the same time, and a group key is associated with each group defined in this way. For a system in which the server shares the group key only with the nodes belonging to that group and performs encrypted communication for each group, the server updates the group key when there is a change in the group members. A system that correctly distributes the updated group key, and controls group key distribution so that when a node is forcibly excluded from the group, the excluded node does not continue to own a valid group key. And When the node to be excluded is a group head node, the server exchanges roles between the group head node which is the node to be excluded and another node in the minimum group to which the group head belongs. The node to be excluded is set to a node other than the group head node, and the updated group key is sent to a node other than the node to be excluded in the corresponding group via the group head node. The minimum group is a product set of a plurality of groups obtained as a result of extracting one group having an arbitrary attribute value for each attribute, and is a non-empty minimum. The group head node is a node that belongs to a group that includes exactly one node in a product set with an arbitrary minimum group. An encryption key update system that features this. サーバと多数のノードから構成されるネットワークにおいて、ノードに属性がd種類存在する場合、ノードはd個のグループに同時に属すると考え、このように定義される各グループに対してグループ鍵を対応付け、サーバがグループ鍵をそのグループに属するノードとだけ共有して、各グループを対象とする暗号通信を実施するシステムに関し、グループ構成員の変化があった場合に、サーバがグループ鍵を更新し、更新後のグループ鍵を正しく配信するシステムであって、あるノードを強制的にグループから排除する場合に、排除されるノードが有効なグループ鍵を所有し続けることのないよう、グループ鍵配信の制御を行い、 前記サーバが、排除するべきノードがグループヘッドノードである場合には、排除するべきノードであるグループヘッドノードとそのグループヘッドが属する極小グループ内の他のノードとで役割を交換することにより、前記排除するべきノードをグループヘッドノードでないノードにした上で、更新後のグループ鍵を、その対応するグループにおいて排除するべきノード以外のノードにグループヘッドノードを介して送ることで、前記排除するべきノードを排除するグループヘッドノード排除手段を有し、 前記極小グループは、属性毎に任意の属性値を持つグループを1つずつ抽出した結果得た複数のグループの積集合であり、かつ、空でない極小の集合であるグループであり、前記グループヘッドノードは、任意の極小グループとの積集合にちょうど一個のノードを含むようなグループに属するノードである、 ことを特徴とする暗号鍵更新システム。