Key delivery system with signature function
Abstract
PURPOSE:To disable a person, who steals key information to try the access to a terminal but does not know secret information, to decode a cipher by combining discrimination information and secret information at the time of generating a common key. CONSTITUTION:A center 20 generates two parameters Zi and kk for a user (i) and writes them on a magnetic stripe card 19 corresponding to the user (i) and delivers this card to the user (i). Similar parameters whose subscript is changed to (k) are generated for a user (k) to deliver the card to a user (k). Users (i) and (k) read delivered magnetic stripe cards 19 from a card reader 26 and manage them as a user management file. The parameter Zk which the user (i) receives from the user (k) of the other party includes the reciprocal of an open parameter IDk and a password pwk of the terminal of the other party; and when the user (i) generates the common key, he is requested to input not only IDk of the user (k) of the other party but also a password pwi of the user (i) from a keyboard.
Term
Term ended
Projected expiry passed 1 May 2009, 17.4 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
5 claims: 1 independent, 4 dependent
- 1[Claim(s)] 【特許請求の範囲】 1) Let an encryption key and a decoding key of two terminals which communicate be a common key equal to mutual, In a common key encryptosystem-ized method which enciphers correspondence with said common key and is transmitted as a cryptogram, and decodes the received cryptogram with said common key, and it receives as correspondence between said each terminal, A key information control means (2) which holds beforehand key information (3) which contains discernment information on a self-terminal, and secret information of a self-terminal as a component to each of a plurality of terminals (1), and it transmits to it before a communication start of a cryptogram (10) at a mating terminal, An input means into which discernment information on a mating terminal (5) and secret information (6) of a self-terminal are made to input before a communication start of a cryptogram (10), It changes based on information containing discernment information (5) on said mating terminal into which said key information (3) transmitted from said mating terminal before a communication start of a cryptogram (10) was inputted from said input means (4), and secret information (6) of said self-terminal. A key distribution method with a signature function having a common key generating means (7) which generates a common key (8). 1)通信を行う2つの端末の暗号化鍵と復号鍵を相互に等しい共通鍵とし、前記各端末間で通信文を前記共通鍵により暗号化して暗号文として送信し、受信した該暗号文を前記共通鍵により復号して通信文として受信する共通鍵暗号化方式において、 複数の端末(1)の各々に、 自己端末の識別情報及び自己端末の秘密情報を構成要素として含む鍵情報(3)を予め保持し、暗号文(10)の通信開始前に相手端末に転送する鍵情報制御手段(2)と、 暗号文(10)の通信開始前に相手端末の識別情報(5)と自己端末の秘密情報(6)を入力させる入力手段と、 暗号文(10)の通信開始前に前記相手端末から転送されてくる前記鍵情報(3)を前記入力手段(4)から入力された前記相手端末の識別情報(5)及び前記自己端末の秘密情報(6)を含む情報に基づいて変換して共通鍵(8)を生成する共通鍵生成手段(7)とを有することを特徴とする署名機能を持つ鍵配送方式。
4 paragraphs, as filed
[Detailed Description of the Invention]
[Outline important point] Let the encryption key and decoding key of two terminals which communicate be a common key equal to mutual, starting the common key encryptosystem-ized method which performs encryption/decoding with a common key between correspondence and a cryptogram between each terminal -- further -- detailed The unique common key with a signature which can attest each terminal is realized among arbitrary mating terminals about a key distribution method with a signature function in case key information is exchanged, it is mutually before a communication start and each terminal generates a common key, and the generation process of a common key is easy, And it aims at enabling it to manage the secret parameter for every terminal safely and easily by the comparatively loose thing of a guard, etc. like magnetic Stripke 1 Do, The key information control means which holds beforehand the key information which contains the discernment information on a self-terminal, and the secret information of a self-terminal as a component to each of a plurality of terminals, and it transmits to it before the communication start of a cryptogram at a mating terminal, The input means into which the discernment information on a mating terminal and the secret information of a self-terminal are made to input before the communication start of a cryptogram, It constitutes so that it may have a common key generating means which changes based on the information containing the discernment information on the above-mentioned mating terminal into which the above-mentioned key information transmitted from the above-mentioned mating terminal before the communication start of a cryptogram was inputted from the above-mentioned human power means, and the secret information of the above-mentioned self-terminal, and generates a common key. [Industrial Application] The present invention uses as a common key equal to mutual the encryption key and decoding key of two terminals which communicate, The common key encryptosystem-ized method which performs encryption/decoding with a common key between correspondence and a cryptogram is started between each terminal, and it is related with a key distribution method with a signature function in case key information is exchanged, it is mutually before a communication start and each terminal generates a common key in more detail. [Description of the Prior Art] In recent years, the spread of the communications networks in a company is expanded remarkably. However, in the communication in a company, when sending the important data of personnel information . in-company confidential information . fund management information etc. using a communications network, there are problems, such as incorrect delivery by the party concerned with communication tapping and interception / communication by the 3rd person, and importance is attached to encoding technology. In encoding technology, the encryption key and decoding key of two terminals which communicate are used as a common key equal to mutual, and there is a common key encryptosystem-ized method which performs encryption/decoding with a common key between correspondence and a cryptogram between each terminal. And there is a method which exchanges key information, is mutually before a communication start as a method which generates a common key, and generates a common key at each terminal. Although it is necessary to manage the key information (it is only hereafter called a key) for generating a common key at each terminal, the key which key management should complicate and the number of members to a communications network should manage if A few times thru/or tens of thousands and a number increase will become huge, and it will become impossible to maintain communicative safety in the above-mentioned encoding technology. As a conventional system of key management, there is a key management method using an ID number (identification number of each terminal). This is a method using the ID number of each terminal which communicates as creation information of a common key. [Problem(s) to be Solved by the Invention] In however, the common key which was generated in the case of the above-mentioned conventional example, Secret information which each individual communication between the parties manages, such as a password and a password, has not entwined, When the trouble involving transmission and reception of wording of a telegram arises in a communication between the parties after communication, a just mediator is difficult to prove the fact of wording-of-a-telegram transmission and reception, and his generation process of a common key is complicated, the guard of an IC card etc. is firm and it is necessary to manage the secret parameter which each user manages -- etc. -- it has a problem. The present invention realizes the unique common key with a signature which can attest each terminal among arbitrary mating terminals, and is simple for the generation process of a common key, And it aims at enabling it to manage the secret parameter for every terminal safely and easily by the comparatively loose thing of a guard, etc. like magnetic Stripke 1 Do. [Means for solving problem] Drawing 1 is a block diagram of the present invention. The present invention uses as a common key equal to mutual the encryption key and decoding key of two terminals which communicate, and is premised on the common key encryptosystem-ized method which enciphers correspondence with a common key, transmits as a cryptogram, decodes the received cryptogram with a common key, and it receives as correspondence between each terminal. The present invention has the following key information control means, input means, and common key generating means to a plurality of terminals 11 and each of 1k ... Key information 3i and 3h in which key information control means 2z and 2k ... contain the discernment information on a self-terminal, and the secret information of a self-terminal as a component It is a means to hold ... beforehand and to transmit to mating terminal 11 or l, for example via channel 11 before the communication start of a cryptogram. Here, the above-mentioned discernment information is for example, ID data, and the secret information of a self-terminal is password data of for example, a self-terminal. And key information 3! and 3k ... are data values acquired by carrying out Exponentiation of the predetermined integer, for example, and the paragraph of the product of the reciprocal of ■D A date of a self-terminal and the password data of a self-terminal is included in the paragraph of the Exponentiation. Or key information 31 and 3k ... are good also as a data value acquired by calculating the surplus to a predetermined composite number about the value acquired by above-mentioned carrying out Exponentiation, for example. input means 41 and 4k ... before the communication start of a cryptogram -- discernment information 5k on a mating terminal, 6 t of secret information of 5i ... and a self-terminal, and 6h It is a means to make ... input. discernment information 51 and 5k on a mating terminal ... is ID data as mentioned above, and secret information 61 of a self-terminal and 6k ... are the passwords of a self-terminal as mentioned above. Common key generating means 71 and 7k ... are mating terminals 1k before the communication start of a cryptogram, ·Il From ... to key information 3k transmitted via channel 11 3 -- direct [ ] -- discernment information 5h and 5t on the mating terminal into which ... was inputted from input means 4+ and 4k ... It is a means to change based on the information containing ..., and secret information 6I of a self-terminal and 6k ..., and to generate common key 8. The means are mating terminal 1b and It, for example. Data value 3k which is the key information sent from ..., 31 -- mating terminal 1m which carried out Exponentiation of ..., generated common key 8, and was inputted into the paragraph of the Exponentiation from input means 4+ and 4h, and L Password data 6I and 6k of .. and a self-terminal .. ID data 5h and 5t of ... the paragraph of a product is included. Or it may be made to generate common key 8 by calculating the surplus to the above-mentioned predetermined composite number about the value acquired by above-mentioned carrying out the Power east. The paragraph of the product of correspondence number data and the date data may be made to be included in the paragraph of the above-mentioned Exponentiation further. By using common key 8 generated as mentioned above, in each terminal 11 and 1+c, as shown in the Drawings 12t and 12m, encryption or decoding is performed between correspondence 9K, 10+, or 9k and 10v. On the other hand, it adds to each above-mentioned composition by the present invention, and they are each terminal 1+ and lm. It has composition which has center Management Department 13 which does generalization management of ... The Management Department supplies beforehand key information for this every terminal 25, and 2k ... to each terminal 1i and 1k ... with the form of for example, magnetic Stripke 1 Do. [For Work ] When a self terminal, for example, 11, receives key information 3k from a partner's terminal 2l, for example, the key information control means of 1k, the discernment information on mating terminal 1k and the secret information of mating terminal 1k are contained in the key information 3k. and the case where common key 8 is generated by common key generating means 71 of self-terminal 11 -- everything but discernment information 5k on input means 41 to a mating terminal -- secret information 61 of a self-terminal -- input To shake -- things are also required. Therefore, it is even if others are going to steal key information 31 of terminal 1 quantity, terminal 11 tends to be operated and it is going to access terminal 1k, Since they cannot generate the same common key 8 as common key 8 generated by the mating terminal 1k side if the others do not understand secret information 6 demons (password etc.) of a self-terminal, they cannot perform encryption or decoding but can realize encryption communication with very high safety. In this case, in common key generating means 7 Ying, since common key 8 is generable Exponentiation of a predetermined integer, or only by calculating a surplus further, the creation process of a common key becomes easy. Key information 3I of every terminal 11 and 1k ... and 3k ... are dashed lines 14r and 14h of center Management Department 13 to Drawing 1, for example. Although supplied like ..., In this case, since a code is undecipherable as mentioned above only by 3 l. of each key information and 3k ... being stolen, the above-mentioned supply can be performed by being a comparatively loose thing of a guard like a mag-stripe card. On the other hand, when you generate common key 8 by each common key generation 1000-step 1! and 1k, include the paragraph of the product of correspondence data and the date data in the paragraph of the above-mentioned Exponentiation, For example, when a trouble occurs behind, center Management Department 13 can prove the fact of wording-of-a-telegram (correspondence) transmission and reception easily by checking the contents of common key 8. [The example of real Application] Hereinafter, operation of the example of the present invention is explained, referring to drawings. Drawing 2 is the whole this example system configuration figure. In the figure, as for users i and k who communicate by operating each personal computer terminal 17 and 17h first, 16k Hesset does [ 16 Ns of each communication control unit ] mag-stripe cards 191 and 19b provided from center 20. Then, each user i and k inputs and does each keyboard 1B+ and the required parameter mentioned below from 18k before a communication start. And encryption communication is performed between personal computer terminal 17+ and 17 m via communication control units 16t and 16m and channel 21. In the example of Drawing 2, although only the part corresponding to 2 persons of users i and k in communication control units 161 and 16h is shown, naturally many devices are connected via channel 21. Drawings 3 are communication control unit 161 of Drawing 2, and a lineblock diagram of 16*. In the figure, communication control unit 16 corresponds to 16+ of Drawing 2, and 16b, keyboard 18 corresponds to 181 and 18k of Drawing 2, and magnetic Stripke 1 Do 19 corresponds to 191 and 19k of Drawing 2. Card reader 23 reads the contents of mag-stripe card 19 supplied from center 20 of Drawing 2, and makes the required parameter mentioned below input into power-law reminder operation machine 24. Self user ID is added with power-law reminder operation machine 24, and the contents of above-mentioned magnetic Stripke 1 Do 19 are sent to transceiving equipment 26 as it is. On the other hand, the other party communication person also has a device of the same composition, the other party also returns a partner's peculiar ID and above-mentioned data, and the data is received by transceiving equipment 26 and inputted into power-law reminder operation machine 24. Self ID and password which are entered from keyboard 18 with this input into power-law reminder operation machine 24, . to which power-law reminder operation processing mentioned below is performed, as a result the common key which were obtained and which is mentioned below are memorized to common key safekeeping device 25, and it is set to the key input of cryptogram decoders 27 via the device. Encryption N27 performs encryption or decoding between the 1000-sentence data by the side of personal computer 17, and the cryptogram by the side of channel 21. On the other hand, the other party to which it applied for communication gives the date at that time to the common key kept by common key safekeeping device 25 after the end of communication, and sends it to center 20 of Drawing 2 via cryptogram decoders 27, transceiving equipment 26, and channel 21. Hereinafter, operation of the example of the composition of Drawings 2 and 3 of the above is explained along with the explanatory view of Drawing 4 of operation. Unless reference is made in particular, Drawings 2 and 4 shall be referred to at any time. First, especially in center 20, for example, it does not illustrate, center management file 28 shown in Drawing 4 is memorized in a disk store etc. Parameter c, n=pxq (p and q are prime numbers) secret as the file, e, d however e-d=1mod (LCM (q (p-1)-1)), secret parameter (password;1) Wl that each user registered beforehand, pW3 ..., pw+++, and the open parameter (ID+, IDz, .., ID.) that is each user's identification numbers are managed. Here, LCM expresses the least common multiple. Here, LCM expresses the least common multiple. And center 20 is two parameter Zi=M"""'*9" (IDi is ID+ X IDt =l nod (it asks using the relation of LCM (q (p 1)-1)) here) first. And kk=c-e is created for user i, these are written in magnetic Stripke 1 Do 19 corresponding to user i, and it distributes to user i. In fact, although the surplus of Zi is calculated, since it is easy, the following explanation explains first as what does not calculate a surplus, and it explains the meaning and arithmetic method which calculate a surplus after it by it. It is an operation here. "*j means multiplication. Center 20 creates and rations the same parameter from which the subscript was set to k also to user k. Same operation is performed also to other users of a plurality of who do not illustrate in particular. Each user i and k reads distributed magnetic Strike card 19 from card reader 23, and manages as user management files 29 and 29k of Drawing 4. Especially this file is memorized by the memory storage in power-law reminder operation machine 24 etc. which are not illustrated temporarily, for example. When user i wants to start communication with user k, user i passes transceiving equipment 26 from power-law reminder operation machine 24, and it is Communication control device W 1 of user k. The above-mentioned parameter Z1 is transmitted to 6 k. Similarly, user k transmits parameter Zk to user's i communication control unit 161. As opposed to parameter Zk by which user i was received via transceiving equipment 26 in power-law reminder operation machine 24 from user k, User i uses parameter kk got from center 20, self password pWi, user kOIDk (k, such as user's k name, address, and telephone number public information which shows the person himself/herself) who inputted from keyboard 18 beforehand, etc., They are z and kk*IDk+bPWl as shown in Drawing 4. It calculates. The common key which becomes in M C ()P W i * P W k is obtained from a relation with 29k of Drawing 4 as a result of this operation. Although a surplus calculates also to this value in fact, this is mentioned below. The above-mentioned common key is memorized by common key safekeeping device 25. On the other hand, the operation as the above-mentioned user i also with the same user k side is performed. That is, received parameter Z1 is received in power-law reminder operation machine 24, parameter kk which user k got from center 20 and self password pwk which carried out human power from keyboard 18 beforehand, and user's i IDt (i, such as a name of i, an address, and a telephone number public information which shows the person himself/herself) etc. -- using -- Z and kk*lD1 umbrella PI+lk It calculates. The completely same common key as the user i side that becomes in M C Application P W i Application P W k is obtained as a result of this operation. This common key is memorized by common key safekeeping device 25. The common key of common key safekeeping device 25 inputs into cryptogram decoders 27 after the above operation, and it is used as a key of the cryptogram decoders which realize confidential communication. After the end of communication, user k gives the date to a common key, and notifies these pieces of information to center 20 via transceiving equipment 26 and 2 l. of channels from cryptogram decoders 27. In the above operation, common tIIMc*P"l*PWk calculated with power-law reminder operation machine 24 of each user i and k, such as parameters Z1 and Zk with which each user i and k is provided from center 20, is used by those surpluses in fact, calculating it. This will be based on the reasons of maintenance-of-secret nature, such as a password, being improved that the value of a parameter may overflow, and by taking a surplus, if Exponentiation is calculated simply. These surplus operations are realized as follows. Zi in center 20 (it is the same only by i differing from k also to Zi=) Surplus operation Zi (mod n) over composite number n, first -- M' (mod n) calculates -- next, the value -- (■Di)-' -- after squaring, nod n calculates again and, finally the value raises to the power of pW4. Thereby, they are Z and = Md* (surplus mod n lDil rate pwi? receiving calculates.). zkkk*IDk*PW1 in user i First, in Zkkk (modn), operation Sale, the following D, and after Sono value mosquito IDk's squaring, mod n calculates again surplus operation z and kk*IDk*PWI (H■d 1) to composite number n, and in PWs, the value squares them. Thereby, surplus mad n of zkkk*lDk*PW1 calculates. As were shown above, and shown in Drawing 4 29k, the reciprocal and password PWh of open parameter ID. of the mating terminal are contained in parameter Zk which user i receives from a partner's user k. and the case where user i generates a common key -- keyboard 1B to partner's user's k ID, of, etc. -- user's i password PW -- {-- to input is demanded. Therefore, it is even if others are going to steal user's i mag-stripe card 19, for example and it is going to access user k, Since they cannot generate the same common key as common key Mc*PW1*PWk generated by a partner's user k side if the others do not understand user's i password PWi, they cannot decode a code. Therefore, encryption communication with very high safety is realizable. Only by the contents, such as the amount of Z and Zk, being stolen as mentioned above, since a code is undecipherable, the loose medium means of a guard like mag-stripe card 19 may be sufficient as the supply of the above-mentioned parameter to each user from center 20. When a trouble occurs behind, for example, center 20 can prove easily the fact among which users communication was performed, by analyzing the contents of the common key notified after the end of communication from each user. Next, Drawings 5 are Drawing 2 and an explanatory view of other examples of the present invention based on the composition of Drawing 3 of operation. When user i generates a common key from parameter Z sent by the partner, a different point from Drawing 4 is a point which has entwined the information on document number N which communicates, and date T in the paragraph of Exponentiation, as shown as Zkkk"IDkiit'W1*N*T of the figure. By doing in this way, a trouble occurs behind, for example, and when center 20 analyzes the common key notified after the end of communication from each user, it becomes possible to analyze to the information on the accessed document or its date. [Effect of the Invention] According to the present invention, since it can avoid decoding a code even if others are going to steal key information and it is going to access a certain terminal by having twined discernment information and secret information when generating a common key if secret information is not known, encryption communication with very high safety is realizable. In this case, since a common key is generable Exponentiation of a predetermined integer, or only by calculating a surplus further, for example, the creation process of a common key becomes easy. the case where key information is supplied to each terminal -- Above -- since a code is undecipherable only by key information being stolen like, the supply can be performed by being a comparatively loose thing of a guard like a mag-stripe card, and it becomes possible to make supply cost very cheap. In addition, the thing for which the paragraph of the product of correspondence data and the date data is included in the paragraph of Exponentiation when generating a common key by each common key generating means, For example, when a trouble occurs behind, the center Management Department becomes possible [ proving the fact of wording-of-a-telegram (correspondence) transmission and reception easily ] by checking the contents of the common key.
[Brief Description of the Drawings]
The explanatory view of this example of operation and Drawing 5 of the lineblock diagram [ according / Drawing 1 / to the block diagram of the present invention ] of the communication control unit according [ Drawing 3 ] to this example according [ Drawing 2 ] to the whole this example system configuration figure and Drawing 4 are explanatory views of other examples of operation. 1 1K ... Terminal, 2 2K ... Key Information Control Means, 3 3K ... Key Information, 4 4 and ... Input Means, 5 5K ... Discernment Information on Mating Terminal, 6 Ying, and 6K ... Secret Information of Self-Terminal, and 7I and 7K ... Common Key Generating Means and 8 -- 91 , 1 0 - 1 L - 1 3 - a common key and ... correspondence, - cryptogram, - channel, and - center Management Department.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2013138435A | Cited by | Japan | Examiner |
| JP2002519939A | Cited by | Japan | Examiner |
| JPH04247737A | Cited by | Japan | Search report |
| WO2005074185A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP4750274B2 | Cited by | Japan | Search report |
| JP2008124847A | Cited by | Japan | Examiner |
| JP2002099856A | Cited by | Japan | Search report |
3 priority claims, no other members on record
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 10916989 | Japan | A | |
| 1109169 | – | – | – |
| JP19890109169 | – | – | – |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS |
Numbers
- Publication
- 2-291740
- Publication, DOCDB
- H02291740
- Publication, EPODOC
- JPH02291740
- Application
- 1109169
- Application, DOCDB
- 10916989
- Application, EPODOC
- JP19890109169
Titles2
- English
- KEY DELIVERY SYSTEM WITH SIGNATURE FUNCTION
- Japanese
- 【発明の名称】署名機能を持つ鍵配送方式
Classification
- IPC, 3
- H04L9 08
- G09C1 00
- H04L9 32