JPH0448009B2

Encryption system key distribution method and apparatus

Abstract

This record has no abstract on file.

Term

Term ended

Expired 11 January 2003, 23.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

2 paragraphs, as filed

[Brief Description of the Drawings]

Operation and directions of these attributes of the present invention and the specific example of the present invention will be completely understood by the example of the illustration shown in relation to an attached chart. In the whole system figure and Drawing 2 which use KDC and some terminals, Drawing 1 is figures showing an initial information setup in both terminals in KDC and safe area, The flow chart the 3rd and 4 figures indicate in detail the phenomenon which occurs within each terminal to be, The flow chart which shows in detail the phenomenon to which Drawing 5 occurs within KDC, the figure in which the 6~19th figure shows the key information in each terminal and the method of forming control data, and the 21~28th figure are figures showing the key information in KDC, and the method of forming terminal data. Outline Drawing 1 shows many terminals A and B mutually connectable via a transport network (for example, public exchange network) So KDC10, and X. These terminals must be able to set up a safe channel mutually, in order to exchange safety information. In the process, these terminals must perform communication with KDC. It is connected to transmission track 13 through link 16, and transmission track 12 from terminal A starts safe A call to terminal B. If a user determines that he will start safe data exchange, each terminal will set up the transmission track to KDC like link 14 to terminal A. Exchange of the following information is performed from KDC from terminal A, and terminal B to KDC. If KDC receives these messages both, KDC will form two messages and the message will be transmitted to terminal A via link 15 at terminal B via link 14, respectively. The message of these each includes other suitable information described by session key information and the following. It generates at terminal A and terminal B, and this session key information is exchanged through KDC. Once exchange is performed between two terminals and KDC(s), link 14 which is a key distribution link between terminals A and KDC will be removed, and key distribution link 15 between KDC and terminal B will also be removed. Link 16 which is a session link of terminals A and B is re-formed. The further key information is exchanged based on former partial exchange, both terminals extract a session key independently, eventually session key information is used, and data (namely, digital data or a digital sound) is safely transmitted by data link 16. Since the further session information is taken out among terminals A and B independently of KDC, The malicious operator of KDC cannot take out key information required to decode the safe message transmitted among terminals A and B, without substituting information for a session channel positively. In order to make safe the next key distribution between a terminal and KDC so that it may understand below, note being contained in the message to which peculiar new terminal key information is transmitted between KDC and a terminal. This new information is unique independently [ former information ] therefore. DETAILED DESCRIPTION If it returns to Drawing 2, the information for which initial setting between a terminal and KDC was transported to KDC from the terminal must be performed by method which is not changed. This initial setting is performed in the place where a transfer is performed in the safe area like safe area 23. Since subsequent KDC and the communication between each terminal are dependent on former communication, at a certain time, both a terminal and KDC include the suitable information for a standup, and it is important by being ideally performed in safe area that safety is not checked. (It is based on safe area in play Maintenance shown in Drawing 2) At the time of initial system construction, a terminal is put in in safe area 23 and KDC generates a key pair peculiar to a terminal to each terminal. The function of these key pairs is described below. KDC generates a decryption key peculiar to a terminal, and the Suitableing cryptographic key to each terminal. The decryption key which this cryptographic key is added into key memory storage peculiar to the terminal to each terminal, and Suitables is memorized by the address of that terminal in key memory storage peculiar to the terminal in KDC. A random number (to terminal A, it is Ua) peculiar to each terminal is memorized in the verification information memory storage equivalent to the address of this terminal in KDC. The same random number as this must be loaded and memorized in the verification information memory storage in a terminal, and the random number is used for performing a verification check at the time of the first call setup to KDC. The 3rd and 4 figures are the flow charts showing the operation which occurs within the terminal like terminal A. A key peculiar [ how ] to a terminal is updated and the following arguments are related with the time series between the terminal and KDC explaining how a call setup and a session key are distributed. With reference to the 6~28th figure, it has this discussion. The 6~19th figure shows the device in a terminal, and a step is shown for how a call setup key and a session key are formed later on. The 20~28th figure shows Then with the device in KDC, and each figure shows a key formation process. It argues about the specific device currently used at the terminal with reference to Drawing 6. About generating of an actual number, it argues below. Device 72 is a random number generator which is the device or algorithm which generates 0 and 1 in same probability. This random number generation may use a noise diode, and can also use the algorithm which generates 0 and 1 independently statistically. A safe level becomes higher as these random number generators generate 0.1 at random. The output of a random number generator is an in-series style of 0 and 1, and the correlation between 1 or the correlation between A bit groups is 0. Bidirectional asymmetrical key generator 73 takes in the random number from random number generator 72 as an input, a cryptographic key and a consistency decryption key are calculated, and a decryption key is made not to be drawn from a decryption key to a cryptographic key, and a cryptographic key. Generating of these keys is Rivest and Shamir. and the work of Adleman -- a RSA algorithm which is described on page 120~126 in "a digital sign, the method of obtaining a public key encryption system", CACM, the 21st volume, No. 2, and February, 1978 in the bottom -- therefore, it can carry out. Device 74 has realized the bidirectional asymmetrical encipherment algorithm (for example, RSA algorithm), i.e., the encryption algorithm based on two separate keys, which cannot derive a cryptographic key from a decryption key and cannot derive a decryption key from a cryptographic key conversely. Device 74 has two inputs (I and K) and one output 0. Input I is A bit which should be enciphered or decrypted. Input K is encryption or a decryption key. (A RSA algorithm performs the same function regardless of encryption and decryption.) An output is input A bit enciphered or decrypted by the supplied key. This algorithm is stated to the above-mentioned paper again. Device 75 realizes the two following functions f and g which carry out character. That is, R cannot be determined even if f (R, P) and P are given, It is g(R1, f (R2, P), P) =g (R2, f (R1, P), P), and they are functions f and g which cannot determine R1, R2, or g (R1, f (R2, P), P) even if f (R1, P), f (R2, P), and P are given. Device 75 realizes the above-mentioned function by a Diffie-Hellman's algorithm. this algorithm -- the work of Diffie and Hellman -- the bottom -- the [ "the new direction of encryption", IEEE Transactions onInformation Theory, and ] -- it is stated to page 644-665 in IP-22 volume and November, 1976. The inputs of this algorithm are base Y, modulus Q, and index EXP. An output is Divided remainder in Q about what EXP squared Y as for. Functions f and g are the same as that of what was mentioned above in this example. It is shown as registers 71, 70, and 76 that memory storage is required. One of them is semipermanent register 71 include both key information Eak peculiar to the terminal used for enciphering the message to verification information Va and KDC. Temporary register 70 of Then is good for what kind of state at first, and is used during the period which sets an interaction to KDC at the time of a setup of safe A call. The address register contains everlastingly the terminal (in this case, terminal A) address (namely, public information which identifies A uniquely to KDC). An address register contains the address of the terminal called now again during the set time of a safe session (or A call). Although the size of a register including verification information and encryption / decryption information changes depending on the specific algorithm used, it is Udah of 1000 A bit respectively in this example. The information relevant to a symmetrical session key and a random number is Udah of 100 A bit, address information is unique although it is dependent on a terminal number grant plan, and Then KDC is I know about this. For example, this address information of Then is also good at the telephone number of a specific terminal, and is good at the serial number of a terminal. [ of Then ] Next, with reference to Drawing 20, it argues about work of the module in a key distribution unit. Address register 200 of KDC achieves the same function as the address register of a terminal. Device 210 which performs the RSA function of KDC performs the same function as the RSA function of the above-mentioned terminal. Random number generator 211 performs the same function as the random number generator of the above-mentioned terminal. Encryption and decryption key generator 212 achieve the same function as the thing in the above-mentioned terminal. Device 213 is a generator of the parameter used as an input to the above-mentioned device 75. In this specific example, these parameters are the bases and moduli of a Diffie-Hellman's algorithm. The algorithm needs the output of random number generator 211 as an input. The generating method is stated to the paper of the above-mentioned Diffie. Registers 214 and 216 which are semipermanent memory storage existed in KDC, and these registers have memorized verification information Va and decryption key information Dak peculiar to the terminal between A call. It is used for semipermanent registers 215 and 217 memorizing information in the setting process of A call. These registers perform the same function as the register of the terminal mentioned above. Operation of a system Next, operation of a system is explained below using the 3rd figure. At first, the key management device in a terminal will be in a waiting state until the demand for starting safe A call is received from a terminal control processor. At this time, the cryptographic key peculiar to the terminal used for enciphering the information transmitted to KDC is memorized in the terminal like the above-mentioned. Verification information is also memorized. These two information is memorized by A call (or the first setup) K of the last formed with this terminal. This is shown in Drawing 6 as Va and Eak. Reception of the demand which starts safe A call must give the address of Caller-ed to a key management device via a control processor. A new call setup key is generated at this time. This is shown in box 32 of Drawing 7 as Eka. Generating of the partial session key used for enciphering the data on the link to terminal A from terminal B is shown in box 33. At this time, verification information is updated using the key which occurred exactly at this time. An updating function is expressed as follows. Va1'=f (Va1, E1) and Va2'=f (Va2, E2) -- meaning that ' was updated here -- Va1 It is VA2=Va. Va is the memorized verification information and E is the cryptographic key which occurred exactly. The character of f is as follows. (1) as opposed to all V, E1, and E2 -- :f(V, E1) !=f (V, E2) -- here -- E1!=E2. (2) as opposed to all V21 and V2, and E -- :f(V1, E) !=f (V2, E) -- here -- V1!=V2. (3) When V and V'=f (V, E) is given, it is difficult to determine E. (4) When E is an asymmetrical-ized item-ized key, D cannot be determined from E. In this example, it is Va'=Va1'|Va2'. However, it is Va=Va1|Va2, and Va1' is equal to Va1 enciphered by Eka, and Va2' is equal to Va2 enciphered by Eba. This updating process is shown in Drawing 9. It is read from memory storage the first half of verification information Va1, and is provided as an input to a RSA algorithm. The key used for enciphering this information is call setup key Eka which occurred exactly. This becomes Va1', and as shown in Drawing 10, it rewrites Va1. Next, the second half of verification information Va2 is enciphered using Eba which occurred exactly. Va2' obtained as the result replaces Va2 in a memory register. This is shown all over box 34 of Drawing 3. Or [ that verification information Va'' updated when summarized is memorized by former A call ], Or it is the verification information given to the terminal from KDC at the time of initial setting, and a half is enciphered using the encryption portion of the partial session key which occurred in this A call, and other halves are enciphered using the call setup key to that A call. As shown in box 36 of Drawing 3, and Drawing 11 at this time, the format of the message to KDC is prepared. The contents of this message are the encryption portions of two keys which occurred exactly. Partial session key Eba and new call setup key Eka which are formed among terminals A and B are enciphered using cryptographic key Eak peculiar to the terminal which was memorized from former A call from KDC to a terminal, or was given to the terminal at the time of initial setting. The information which may be destroyed with a terminal at this time is call setup cryptographic key Eka and partial session key Eba which were generated by cryptographic key Eak and a terminal peculiar to the terminal memorized by former A call at the terminal. Next, the enciphered message is added to address A of a dispatch terminal, and address B of A call terminal-ed continues after that. This message is transmitted to KDC at this time. Thereby, a terminal goes into the waiting state which stands by the information which should be received from KDC. This is shown in box 37 of Drawing 3. As shown in Drawing 5, KDC is in a waiting state until a message is received from terminal A. This is shown in box 50 of Drawing 5. If a message is received, KDC will read the address information in a message into an address register, and the register will give the decryption index which is used for decoding a message, and is not if it is The. KDC has a decryption key peculiar to the consistency verification information over each terminal taken out from former A call in the memory storage, and the terminal to each terminal. This is shown in box 214 of Drawing 20, and 216. The message from terminal A is decoded using decryption key Dak peculiar to the terminal which Suitables to the terminal. (It should be distributed to terminal B) As new call setup key Eka and partial session key Eba show in Drawing 21, it memorizes in a KDC memory temporarily. At this time, as shown in Drawing 22, KDC can update that verification information by the completely same method as a terminal. This is performed by enciphering each half of the memorized verification information for call setup key information Eka which was received as shown in Drawing 23 and which it session-key-information-Eba(ed) and was received. Thereby, updating verification information Va'' is generated. As shown in Drawing 24, distribution center KDC generates bidirectional asymmetrical encipherment / decryption key pair Eak', and Dak' at this time. Here, the updated information is expressed. Eak' is distributed to terminal A in order to use it by setup of the next A call to key distribution center KDC. Decryption key Dak' adds decryption key Dak memorized from former A call. Other two information is generated again at this time. These are parameters used for generating a symmetrical session key with a terminal. In this case, these are the parameters of a Diffie-Hellman's algorithm. Like the above-mentioned, one side is base Y and another side is modulus Q. The quantity of the information by which occurs in KDC and safety is carried out to each terminal changes depending on an algorithm. This information is memorized in a temporary memory and used as a part of message returned to terminal A and terminal B. This generating process is shown in Drawing 25, and is connected with box 55 of the flow chart of Drawing 5. As shown in Drawing 26 at this time, although KDC completes A call to terminal A, the message must be received from terminal B. If it has not received, it must wait for operation of KDC to terminal A until terminal B reaches this point. This gives partial session key information Eab that KDC was generated in terminal B to terminal A, and it is because partial session key Eba which occurred at terminal A must be able to be given to terminal B. The same parameter that occurred by one operation needs to make the conjoint action during the operation which rewrites the parameter which occurred by operation of another side perform. Since this generates a symmetrical session key, it is guaranteed that the parameter transmitted to the terminal is the same. In order to adjust the information in key distribution center KDC, when internal exchange is performed between A register and B register, the format of the message to a terminal will be ready. This is shown in Drawing 27. The message to terminal A grows into the new terminal used by A call of the succession to KDC from unique key information Eka'. The message comprises partial session key information Eab received from terminal B again. The message comprises again the thing it was by carrying out, some decreases of fixed A bit, in verification information Va''. The message comprises base Y and modulus Q of a Diffie-Hellman's algorithm again. These five information is enciphered using call setup key Eka received in the message from terminal A. KDC destroys Eka, Eba, Eka', Y, and Q which Suitable to terminal A, and destroys Eka, Eab, Ebk', Y, and Q which Suitable to terminal B. Next, KDC returns this output message to terminal A. The enciphered similar message is sent to terminal B from KDC. At this time, KDC ends that processing. Drawing 28 shows the situation of KDC after A call to terminal A was sent. KDC has updated verification information Va'' which is used by A call of succession between terminals A and KDC, and decryption key information Dak' peculiar to the updated terminal. If it returns to Drawing 3 of the flow chart to terminal A again, as for the key management device of the terminal, in KDC, ON intermediary To have will function on the waiting state. Drawing 12 shows the key information memorized by the terminal during [ this ] the waiting state. This is decryption keys Dka and Dba which Suitable in the cryptographic key which occurred updated verification information Va'' and before. the information for which Drawing 13 was received from KDC -- box 38 of Drawing 3 -- therefore, it is shown how it is used. It is used for call setup decryption key Dka decrypting the message received from KDC. Five (it argued before) values transmitted from KDC are used by the following methods now. The 1st information is new distribution key Eak' memorized in semipermanent register 71, and is used by A call of the succession formed from this terminal to KDC. This is a cryptographic key peculiar to the updated terminal. The 2nd information is partial session key Eab which occurs in B and is transmitted to terminal A through KDC. The 3rd information is updated verification information Va'' which is compared with the verification information memorized by terminal A. The 4th and 5th information is base Y and modulus Q which are the parameters of a Diffie-Hellman's algorithm, and these are memorized by the temporary memory of terminal A. If box 40 of Drawing 4 is referred to, a terminal compares the verification information received from KDC, the verification information memorized now, or this verification information with the known thing decrease of the number of bits carried out at this time. (Drawing 14) These consistency will continue operation as it is. An alarm is given to a terminal control processor when these do not consistent. when it assumes that it is that in which comparison of verification succeeded, a terminal removes the channel to KDC and is at last -- when not formed, the channel to terminal B is formed. At this time, terminal A and terminal B can communicate data safely using asymmetrical session keys Eab and Eba. The following steps will be performed if a symmetrical session key is necessary. Calculation of the message transmitted to terminal B is shown in Drawing 15. Base Y and modulus Q of a Diffie-Hellman's algorithm are first used with random number Ra generated by random number generator 72. These inputs are given to Diffie-Hellman's algorithm 75, and an output turns into an input of RSA device 73. Random number Ra is memorized in the temporary memory again. Eab is used as a key of RSA device 73. Even if destroyed, Yo of session key information Eab and the number Y of bases which were received from terminal B at this time is good. The output of a RSA algorithm is sent to terminal B. The key management device of terminal A goes into a waiting state, as shown in box 44 of Drawing 4, and a message waits for that of Come back from terminal B. The idle state is shown in Drawing 16 and random number Ra generated by modulus Q and terminal A of the Diffie-Hellman's algorithm which occurred by decryption session key DabKDC which terminal A generated exists in memory storage. If a message is received from terminal B as shown in Drawing 17, terminal A will decrypt a message using the decryption key Dba memorized at the time of the early development of a partial session key. Thereby, Dba may be destroyed. This output is applied into a Diffie-Hellman's algorithm as a base. An index is random number Ra which occurred before, and modulus Q is inputted into an algorithm again. The output of a Diffie-Hellman's algorithm is symmetrical session key information equal to the session key information which terminal B calculated. Q and Ra may be destroyed at this time. Here, terminals A and B form mutually the symmetrical session key information which cannot be taken out by KDC. This key information is used in a symmetrical key algorithm like a Data Encryption Standard (DEC), in order to encipher data. It is key Eak' peculiar to the terminal received from KDC used for enciphering the following message to terminal information Va'' and KDC which were updated which is memorized in a terminal until the next demand to a safe session (namely, A call) arises, as shown in Drawing 18. the flow chart which generating of a terminal and the data of the request in KDC is performed under control of a computer processor in fact, and is shown in the 3~5th figure -- therefore, it is programmed and the illustrated data transfer series is performed. Although illustration is not carried out, this processor operates in relation to the terminal of illustration, and a KDC device, for example, its Then is also good at any of the microprocessor of the common knowledge like Intel8086 microprocessor. Note that an encryption algorithm which is different in order to obtain the result which Then is here, without deviating from the soul and the range of the present invention, and was told to the person skilled in the art, and different devices can be used.