Security communication method
Abstract
[Task] Eliminate the overhead of authentication procedures between terminals, and prevent inconsistencies between communication channels for encrypting / decrypting communication data.
Solution.The terminal devices 20 and 30 digitally sign the digital information of the terminal identification name and the terminal public key with the private key of the certification authority 40 as information for proving that the terminal itself is correct. Hold. When the terminal devices 20 and 30 perform confidential communication, first, a communication path for mutual authentication is established, and certificates are exchanged with each other to confirm that the other party is correct. Next, a communication path for encrypting / decrypting communication data is established above the communication path established for the above authentication, and the private key of the private key encryption method is shared using the public key encryption method. ..

Term
Term ended
Projected expiry passed 4 September 2015, 11.1 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
4 claims: 1 independent, 3 dependent
- 1【特許請求の範囲】 【請求項1】 各端末装置は、端末装置自身が正しいことを証明するための情報として、端末装置の識別名と端末装置の公開鍵暗号方式におけるパブリック鍵とで構成されたディジタル情報に対して証明機関の公開鍵暗号方式のプライベート鍵によりディジタル署名された証明書を保持し、端末装置相互が秘話通信を行うとき、まず端末装置が保持する前記証明書を相互に交換して相手が正しいと認証し、次に通信データの内容の暗号化/復号に使用するための秘密鍵暗号方式における秘密鍵を公開鍵暗号方式を使用して共有し、該相互に共有した通信用の秘密鍵を使用して秘話通信を行う方法において、 端末装置Tiと端末装置Tjが秘話通信を行うとき、まず、端末装置Ti,Tjは相互に認証を行うための通信路を開設し、自分を証明する証明書Ci,Cjを互いに交換し検証することで、相手が正しいことを確認するとともに認証のために開設した通信路が正しいことを確認し、 次に、認証のために開設した通信路の上位に通信データの内容の暗号化/復号を行うための通信路を開設し、通信データの内容の暗号化/復号のための秘密鍵を共有するために、端末装置Tiは乱数Rkviを発生し、該乱数Rkviを端末装置Tjの認証時に取得した証明書Cjから取り出した端末装置Tjのパブリック鍵を使用して暗号化するとともに、該暗号化データに対して端末装置Tiのプライベート鍵で暗号化することでディジタル署名を行い、これら暗号化データとディジタル署名データのディジタル情報を端末装置Tjに送信し、 前記ディジタル情報を受信した端末装置Tjは受信したディジタル情報中の端末装置Tjのパブリック鍵により暗号化された乱数Rkviのディジタルデータを端末装置Tjのプライベート鍵により復号することにより乱数Rkviの値を得るとともに、ディジタル署名データを端末装置Tiの認証時に取得した証明書Ciから取り出した端末装置Tiのパブリック鍵を使用して復号し、該復号したディジタルデータと前記端末装置Tjのパブリック鍵により暗号化された乱数Rkviのディジタルデータを比較し、等しければ正しく端末装置Tiより送信された秘密鍵情報であると確認し、 次に、端末装置Tjは乱数Rkvjを生成し、該生成した乱数Rkvjと前記復号した乱数Rkviとの排他的論和結果を秘密鍵暗号方式で通信するための秘密鍵とその他の必要なデータとし、さらに前記乱数Rkvjを前記端末装置Tiの認証時に取得した証明書Ciから取り出した端末装置Tiのパブリック鍵を使用して暗号化するとともに、該暗号化データに対して端末装置Tjのプライベート鍵で暗号化することでディジタル署名を行い、これら暗号化データとディジタル署名データディジタル情報を端末装置Tiに送信し、 前記ディジタル情報を受信した端末装置Tiは、受信したディジタル情報中の端末装置Tiのパブリック鍵により暗号化された乱数Rkvjのディジタルデータを端末装置Tiのプライベート鍵により復号することにより乱数Rkvjの値を得るとともに、ディジタル署名データを端末装置Tjの認証時に取得した証明書Cjから取り出した端末装置Tjのパブリック鍵を使用して復号し、該復号したディジタルデータと前記端末装置Tjのパブリック鍵により暗号化された乱数Rkvjのディジタルデータを比較し、等しければ正しく端末装置Tjより送信された鍵情報であると確認し、 次に、端末装置Tiは前記生成した乱数Rkviと前記復号した乱数Rkvjとの排他的論理和結果を秘密鍵暗号方式で通信するための秘密鍵とその他の必要なデータとし、 端末装置Tiと端末装置Tjは、前記共有した秘密鍵と他のデータを使用して秘密鍵暗号方式で通信内容の暗号化ならびに復号を行うことを特徴とする秘話通信方法。
- 2【請求項2】 請求項1記載の秘話通信方法において、通信データの内容の暗号化/復号のための通信路は、認証のために開設した通信路の上位に複数本開設可能し、各通信データの内容の暗号化/復号の通信路で秘話通信を行うときは、各々の通信データの内容の暗号化/復号のための通信路で秘密鍵を共有することで、一つの認証のための通信路上で、各々異なる秘密鍵を使用して複数の通信路で秘話通信を行うことを特徴とする秘話通信方法。
- 3【請求項3】 請求項2記載の秘話通信方法において、通信データの内容の暗号化/復号のための通信路が、認証のための通信路の上位に少なくともひとつ開設してあれば、該認証ための通信路上に新しい通信データの内容の暗号化/復号のための通信路を開設するとき、秘話通信を行うために新たに必要な秘密鍵と他のデータを共有するために使用する証明書の情報は、既に開設している認証のための通信路の証明書の情報を使用することを特徴とする秘話通信方法。
- 4【請求項4】 請求項3記載の秘話通信方法において、秘話通信を終了するとき、認証のための通信路上に開設された全ての通信データの内容の暗号化/復号のための通信路が閉設されたときに、該認証のための通信路上の情報を閉設することを特徴とする秘話通信方法。
Independent claims4
96 paragraphs, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a method of performing confidential communication between terminal devices using a digital transmission line, and in particular, a mutual authentication method suitable for transferring data information using a digital transmission line and encryption of communication contents. It concerns how to share keys and other confidential information used for conversion / recovery.
【0002】
[Conventional technology]
Confidential communication is a security measure for digital communication. In confidential communication, the sender and the receiver confirm that the other party is correct, and then perform confidential communication.
【0003】
Cryptography for secret communication is roughly divided into two types: private key cryptography and public key cryptography. In public key cryptography, the encryption key and the decryption key are the same, and the sender and the receiver share this same secret key (hereinafter referred to as the private key) to encrypt and decrypt each other (for details, refer to. Reference [1]: See "Modern Cryptography: Shinichi Ikeno, Kenji Koyama, Society of Electronics, Information and Communication Engineers, PP24-40, 1988"). On the other hand, the public key encryption method is a method in which the encryption key and the decryption key are different, and only the decryption key is kept secret (hereinafter referred to as a private key), but the encryption key is made public (hereinafter referred to as a public key). (For details, refer to Reference [1]: "Modern Cryptographic Theory: Shinichi Ikeno, Kenji Koyama, Electronic Information and Communication Society, PP77-104, 1988").
【0004】
Public-key cryptography is superior to private-key cryptography in that anyone who knows the public key can be the sender of confidential communication and that only one person who knows the private key can sign it, but the amount of calculation is large. There is a drawback that the speed of narrowing down is slow due to the huge amount of. For this reason, at present, whether the private key cryptosystem is used for both authentication between senders and receivers and encryption / decryption of the contents of communication data (for example, Reference [2]: "Yamaguchi et al., Implementation and proof of LAN encrypted communication". (Refer to "Technical Research Report of the Society of Electronics, Information and Communication Engineers, OSF93-38,1993"), or public key cryptography is used for mutual authentication between senders and receivers, and private key cryptography is used for encryption / decryption of communication data contents. A method using a method (see, eg, J.Linn.RFC1421: Privacy Enhancement for Internet Electronic Mail: Partl: Message Encryplion and Authentication Proccedures. February 1993.) is used. Here, regarding the authentication method between terminals by the private key cryptosystem and the public key cryptosystem, for example, reference [4] (Infomation). technology-Security techniques-Entity authentication-Part 2: Mechanisms using symetric encipherment algorithms ISO / IEC 9798-2: 1994) and literature [5] :( Infomation technology-Security techniques-Entity authentication-Part 2: Entity authentication using a It is described in detail in public key algorithms ISO / IEC 9798-3: 1994). In the conventional method using authentication between these terminals, when secret communication is performed after authentication, the communication path itself used for authentication is communicated. Used to encrypt / decrypt data content.
【0005】
[Problems to be Solved by the Invention]
In the above-mentioned prior art, there is a drawback that the terminals that have already performed secret communication must authenticate each other again in order to generate a close logical path and perform secret communication, which has a large overhead. There is. In addition, when using a certificate for mutual authentication between terminals, when authentication and sharing of private key have already been completed between terminals and a communication path has been established to perform confidential communication, another communication is newly used. The following problems arise in establishing the path of the above and performing confidential communication. That is, when the certificates of each other were exchanged and authenticated in order to establish a communication path for the existing secret communication, the certificate of the other party had not expired yet, but the newly opened secret communication When mutual authentication is performed for the communication path for the device, the certificate of the other party has expired, and the existing communication path has expired even though the same terminals perform confidential communication. However, there is a problem of state mismatch that the newly opened communication path has expired.
【0006】
The present invention is intended to solve such a problem, and an object of the present invention is to provide a method for authenticating confidential communication and sharing a key suitable for transferring data information using a digital transmission line. Is.
【0007】
[Means for solving problems]
In the present invention, each terminal device is used by a certification authority for digital information composed of a terminal identification name and a public key in the terminal public key cryptosystem as information for proving that the terminal device itself is correct. Holds a certificate digitally signed with a private key of public key cryptography. When the terminal devices holding this certificate perform confidential communication, each terminal device first exchanges the certificates held by the terminal devices with each other to authenticate that the other party is correct, and then performs the following. In addition, the private key in the private key encryption method for use in encrypting / decrypting the contents of communication data is shared using the public key encryption method, and the secret story is used using the private key for communication shared with each other. Communicate.
【0008】
It is assumed that the terminal device Ti and the terminal device Tj perform confidential communication. First, the terminal devices Ti and Tj establish a communication path for mutual authentication, and by exchanging and verifying the certificates Ci and Cj that certify themselves, the other party is confirmed to be correct and for authentication. Confirm that the communication path opened in is correct.
【0009】
Next, a communication path for encrypting / decrypting the contents of the communication data is opened above the communication path opened for authentication, and the private key for encrypting / decrypting the contents of the communication data is shared. Therefore, the terminal device Ti generates a random number Rkvi, encrypts the random number Rkvi using the public key of the terminal device Tj extracted from the certificate Cj obtained at the time of authentication of the terminal device Tj, and encrypts the encrypted data. Alternatively, the hashed data of the encrypted data is encrypted with the private key of the terminal device Ti to perform a digital signature, and the digital information of the encrypted data and the digital signature data is transmitted to the terminal device Tj.
【0010】
The terminal device Tj that received this digital information obtains the value of the random number Rkvi by decrypting the digital data of the random number Rkvi encrypted by the public key of the terminal device Tj in the received digital information with the private key of the terminal device Tj. At the same time, the digital signature data is decrypted using the public key of the terminal device Ti taken out from the certificate Ci obtained at the time of authentication of the terminal device Ti, and encrypted by the decrypted digital data and the public key of the terminal device Tj. Compare the digital data of the randomized Rkvi, and if they are equal, confirm that the private key information is correctly transmitted from the terminal device Ti. Next, the terminal device Tj generates a random number Rkvj, takes an exclusive OR with the decrypted random number Rkvj, and communicates the result of the exclusive OR with the secret key encryption method and others. It is the necessary data (initial value) of. Further, the terminal device Tj encrypts the random number Rkvj using the public key of the terminal Ti extracted from the certificate obtained at the time of authentication of the terminal Ti, and the encrypted data or data obtained by hashing the encrypted data. The digital signature is performed by encrypting the data with the private key of the terminal device Tj, and the digital information of the encrypted data and the digital signature data is transmitted to the terminal device Ti.
【0011】
The terminal device Ti that has received this digital information obtains the value of the random number Rkvj by decrypting the digital data of the random number Rkvj encrypted by the public key of the terminal device Ti in the received digital information with the private key of the terminal device Ti. At the same time, the digital signature data is decrypted using the public key of the terminal device Tj taken out from the certificate Cj obtained at the time of authentication of the terminal device Tj, and is encrypted by the decrypted digital data and the public key of the terminal device Tj. Compare the digital data of the random number Rkvj, and if they are equal, confirm that the private key information is correctly transmitted from the terminal device Tj. Next, the terminal device Ti takes an exclusive OR with the previously generated random number Rkvi and the random number Rkvj, and requires a secret key and other necessary for communicating the exclusive OR result by the secret key encryption method. Data (initial value).
【0012】
As a result, the terminal device Ti and the terminal device Tj share the private key and other data (initial value) used for encrypting the contents of communication data equal to each other, and use these shared private keys and other data. Then, the communication content is encrypted and decrypted by the private key encryption method.
【0013】
Further, in the present invention, a plurality of communication channels for encrypting / decrypting the contents of communication data can be opened above the communication channels established for authentication, and communication channels for encrypting / decrypting the contents of each communication data can be established. When performing secret communication with, by sharing the private key on the communication path for encrypting / decrypting the contents of each communication data, different private keys are used on the communication path for one authentication. Confidential communication is possible through multiple communication channels.
【0014】
Further, in the present invention, if at least one communication path for encrypting / decrypting the content of the communication data is opened above the communication path for authentication, the new communication data is placed on the communication path for authentication. When opening a communication channel for encrypting / decrypting the contents, the information of the certificate used to share the new private key required for confidential communication and other data has already been opened. Use the information in the channel certificate.
【0015】
Further, in the present invention, when the confidential communication is terminated, the authentication is performed when the communication path for encrypting / decrypting the contents of all communication data established on the communication path for authentication is closed. Close the information on the communication path for.
【0016】
[Example]
Hereinafter, an embodiment of the present invention will be described with reference to the drawings. In the description of this embodiment, ISDN is used as the digital transmission line, but of course, it can be applied to digital transmission lines other than ISDN.
【0017】
FIG. 1 is a block diagram showing an embodiment of a communication system to which the secret communication method of the present invention is applied. In FIG. 1, the switching device 10 accommodates a plurality of ISDN basic interface subscriber lines. The terminal devices 20 and 30 are connected to the ISDN basic interface subscriber line. Each terminal device has a terminal control unit 110 that performs layer 1 to layer 3 control of ISDN subscriber lines and network control of upper layers above layer 4, and an encryption processing unit 120 that performs authentication processing and key sharing processing between terminals. It is composed of a communication data processing unit 130 that performs secret communication using a shared private key. The terminal devices 20 and 30 are also connected to the certification authority 40, and receive a certificate digitally signed by the private key of the certification authority 40 for the digital information composed of the identification name of the terminal and the public key of the terminal. When the user directly goes to the certification authority 40 to issue a certificate, the connection between the terminal devices 20 and 30 and the certification authority 40 can be omitted. In the following, the terminal device 20 will be referred to as Ti, and the terminal device 30 will be referred to as Tj.
【0018】
FIG. 2 shows an example of symbols used in the description of this embodiment. Regarding the terminal Tj, "i" in the symbol in FIG. 2 may be replaced with "j".
【0019】
FIG. 3 is an example of a certificate created by the certification authority 40. This shows an example of the certificate Ci of the terminal Ti, and the length CDL of the certificate, the identification name Ti of the terminal device, the public key Pki in the public key cryptosystem of the terminal Ti, and the Ti and Pki are used. The combined information is hashed with the unidirectional data compression function H, and the value is encrypted with the private key Sca of the public key cryptosystem of the certification authority 40. Cryptography E [Sca] (H (TiThePki) )), That is, it is composed of digitally signed data. Here, as a typical public key cryptosystem, there is an RSA cryptosystem (for details, refer to Reference [6]: "PKCS # 1 RSA Encryption Standard, Version1.5, RSA DataSecurity Inc. 1993"). As a private key cryptosystem, there is a DES method (for details, refer to Reference [7]: "FIPS Publication 46-1: Data Encryption Standard, National Bureau of Standards. 1988"). Also, as a hash function, MD2 (For details, refer to Reference [8]: "RFC1319: The MD2". (See Message-Digest Algorithm., B.Kaliski., 1992) and MDS5 (see Ref. [9]: "RFC1321: The MD5 Message-Digest Algorithm., B.Kaliski., 1992" for details). Needless to say, the present invention can be applied to other public key cryptosystems, private key cryptosystems, and hash functions.
【0020】
When the terminal is installed, the terminal device 20 (terminal Ti) generates the public key Pki and the private key Ski of the terminal, and sends the identification name Ti and the public key Pki of the terminal to the certification authority 40 to issue the certificate Ci. The private key Ski of the terminal, the certificate Ci shown in FIG. 2, and the public key Pca of the certification authority 40 are set in the encryption processing unit 120. Similarly, in the terminal device 30 (terminal Tj), the private key Skj of the terminal, the certificate Cj, and the public key Pca of the certification authority 40 are set in the encryption processing unit 120.
【0021】
When the terminal device 20 (Ti) and the terminal device 30 (Tj) perform confidential communication, first, the certificates Ci and Cj held by each terminal are exchanged with each other to authenticate that the other party is correct, and then the communication is performed. The private key in the secret key encryption method used for encrypting / decrypting the data contents is shared using the public key encryption method, and the secret communication is performed using the secret key shared by each other.
【0022】
First, the authentication procedure between terminals will be described with reference to FIG. At this stage, the terminal Ti already holds the private key Ski of the terminal, the certificate Ci, and the public key Pca of the certification authority, and the terminal Tj also holds the Skj, Cj of the terminal and the Pca of the certification authority.
【0023】
The terminal Ti generates a random number Ri and sends CiTheRi to the terminal Tj. The terminal Tj inspects the received certificate Ci as follows to confirm that it is correct. Calculate H (TiThePki) from Ti and Pkj in the received Ci. b. Calculate E [Pca] (E [Sca] H (TiThePki)) from the received digital signature data in Ci to obtain H (TiThePki). c. Check if the calculated values of a and b above are equal, and if they are, confirm that the received certificate Ci is correct. Then, if confirmed to be correct, retain the received certificate Ci.
【0024】
The terminal Tj generates a random number Rj and sends CjTheRj to the terminal Ti. The terminal Ti inspects the received certificate Cj as follows to confirm that it is correct. a. Calculate H (TjThePkj) from Tj and Pkj in the received Cj. b. Calculate E [Pca] (E [Sca] H (TjThePkj)) from the received digital signature data in Cj to obtain H (TjThePkj). c. Check if the calculated values of a and b above are equal, and if they are, confirm that the received certificate Cj is correct. Then, when it is confirmed that it is correct, it retains the received certificate Cj.
【0025】
The terminal Tj transmits RjTheRiTheTiTheE [Skj] (RjTheRiTheTi) in which the plaintext data of Rj, Ri, Ti and the encrypted data thereof are combined to the terminal Ti. The terminal Ti inspects the received information as follows to confirm that the terminal Tj is correct. Calculate E [Pkj] (E [Skj] (RjTheRiTheTi) from the received encrypted data to obtain RjTheRiTheTi). b. Compare the received plaintext data RjTheRiTheTi with the RjTheRiTheTi obtained in a above. If they are equal, confirm that the terminal Tj is correct.
【0026】
The terminal Ti transmits RiTheRjTheTjTheE [Ski] (RiTheRjTheTj), which is a combination of the plaintext data of Ri, Rj, and Tj and its encrypted data, to the terminal Tj. The terminal Tj inspects the received information as follows to confirm that the terminal Ti is correct. Calculate E [Pki] (E [Ski] (RiTheRjTheTj) from the received encrypted data to obtain RiTheRjTheTj. b. Compare RiTheRjTheTj in the received plaintext data with RiTheRjTheTj obtained in a above. If they are equal, confirm that the terminal Ti is correct.
【0027】
Next, the procedure for sharing the private key and other necessary data (initial value) used for encrypting / decrypting the contents of the communication data will be described with reference to FIG. At this stage, the terminal Ti holds the certificate Cj of the other terminal Tj in addition to the certificate Ci of the terminal, and similarly, the terminal Tj holds the Cj of the other terminal Ti in addition to the Cj of the terminal.
【0028】
The terminal Ti generates a random number Rkvi, and E [Pkj] (Rkvi) The E [Ski] (H (E [Pkj] (Rkvi))) that combines the encrypted data of Rkvi and its digital signature data with the terminal Tj. Send. The terminal Tj inspects the received information as follows, confirms that the information is correct, and generates a data encryption key and initial values. Calculate E [Pki] (E [Ski] (H (E [Pkj] (Rkvi)))) from the received digital signature data to obtain H (E [Pkj] (Rkvi))). b. Calculate H (E [Pkj] (Rkvi)) from the received encrypted data and compare it with H (E [Pkj] (Rkvi)) obtained in a above, and if they are equal, the message has not been tampered with. To confirm. Calculate cE [Skj] (E [Pkj] (Rkvi)) to get Rkvi. d. Generate a random number Rkvj. Then, an exclusive OR is taken with the random number Rkvi decrypted in the above c and the generated random number Rkvj, and the data encryption / decryption key DEKs and the initial value IVs are generated as follows. DEKs: Top 8 bytes of Rkvi and Rkvj exclusive OR data IVs : Lower 8 bytes of exclusive OR data of Rkvi and Rkvj e. Set DEKs and IVs to the communication data processing unit 130.
【0029】
The terminal Tj transmits E [Pki] (Rkvj) The E [Skj] (H (E [Pki] (Rkvj))), which is a combination of the encrypted data of Rkvj and its digital signature data, to the terminal Ti. The terminal Ti inspects the received information as follows, confirms that the information is correct, and generates a data encryption key and an initial value. Calculate E [Pkj] (E [Skj] (H (E [Pki] (Rkvj)))) from the received digital signature data to obtain H (E [Pki] (Rkvj)). b. Calculate H (E [Pki] (Rkvj)) from the received encrypted data and compare it with H (E [Pki] (Rkvj)) decrypted in a above. To confirm. Calculate cE [Ski] (E [Pki] (Rkvj)) to get Rkvj. d. Exclusively OR the random number Rkvj decrypted in c above and the previously generated random number Rkvi, and generate the data encryption / decryption key DEKs and the initial value IVs as follows. DEKs: Top 8 bytes of Rkvi and Rkvj exclusive OR data IVs: Lower 8 bytes of exclusive OR data of Rkvi and Rkvj e. Set DEKs and IVs to the communication data processing unit 130.
【0030】
After that, the terminal Ti and the terminal Tj encrypt / decrypt the communication data using the shared private key DEKs for encryption / decryption and its initial value IVs. For example, when the terminal Ti is the transmitting side and the terminal Tj is the receiving side, the terminal Ti encrypts the plaintext (communication data) p with the key DEKs and the initial value IVs by the private key encryption method e [DEKs, IVs] ( p) is generated and transmitted, and the terminal Tj calculates d [DEKs, IVs] (e (DEKs, IVs] (p)) with the same DEKs, IVs for the received ciphers by the private key encryption method. Decrypt plaintext p.
【0031】
Next, when the communication path for authentication in FIG. 4 and the communication path in FIG. 5 have already been established and the contents of the communication data are encrypted / decrypted between the terminal Ti and the terminal Tj, the same terminals are used. The operation when a new secret communication request is generated will be described with reference to FIG. The terminals Ti and Tj are the certificate Cj or Ci (hereinafter collectively referred to as C) of the other terminal that has authenticated each other, as well as the counter flag Flgj or Flgj indicating which terminal the communication path for authentication is established with. It holds Figi (hereinafter collectively referred to as Flg). In the initial state, both the counter flag Flg and certificate C are zero. In FIG. 6, only one Flg and one C are shown, but of course it is possible to have a plurality of counter flags Flg and certificate C in order to perform confidential communication at the same time as a plurality of terminals.
【0032】
When a secret communication request occurs, the terminal determines the operation of the terminal by inspecting the certificate C containing information indicating whether the counter flag Flg is zero or more and which terminal it is. That is, when a new secret communication request occurs, Flg is inspected to see if it is zero or more. If none of the Flg is zero or more, or if Flg is zero or more but the certificate C you have is inspected and you do not have the certificate C of the other party with whom you want to communicate, the secret story with the new terminal As a communication request, the keys for authenticating each other and encrypting / decrypting the contents of communication data are shared by executing the procedures of FIGS. 4 and 5 described above, and secret communication is performed. FIG. 6A shows this, and for convenience, only the authentication procedure between terminals is shown here. At this time, the contents of Flg are added by 1, and the acquired certificate C of the corresponding terminal is set in the holding mechanism.
【0033】
On the other hand, when a new request for confidential communication occurs, if the inspected Flg is zero or more and the certificate C of the other party to perform confidential communication is already held, the content of the corresponding Flg is added by 1 and the content of the corresponding Flg is added. Immediately execute the key sharing procedure shown in Fig. 5 on the communication path for authentication established in Fig. 3, establish a communication path for encrypting / decrypting new communication data, and perform confidential communication on this communication path. Share the key to do. At this time, the certificate C of the other terminal uses the certificate already held, and the exchange of new certificates between the terminals is not executed. Figure 6 (b) shows this.
【0034】
By doing so, even when multiple logical paths are opened on one physical channel between terminals to perform confidential communication, the authentication between terminals is completed at the first time and for each logical path. Communication data can be encrypted / decrypted with different keys.
【0035】
Next, a case where the secret communication is terminated will be described. When terminating the secret communication, first, the communication path for encrypting / decrypting the contents of the communication data is closed based on the request. Next, in the counter flag Flg shown in FIG. 6, the content of Flg corresponding to the closed partner terminal is subtracted by 1. If the result of the subtraction is zero or more, the communication path for authentication established in FIG. 4 is left as it is, and the request operation for terminating the secret communication is terminated. If the result of subtracting 1 from the contents of Flg is zero, the contents of the certificate C of the corresponding terminal that has been acquired are initialized (cleared), and for the authentication of the opened Fig. 4 corresponding to the other terminal. By closing the communication path of, the requested operation for terminating the secret communication is terminated.
【0036】
By doing so, when a communication path for encrypting / decrypting the contents of a plurality of communication data is established on the communication path for authentication in FIG. 4, the communication path for authentication is set. Since it can be left as it is, when the above-mentioned communication path for authentication in FIG. 4 and the communication path in FIG. 5 have already been established and the contents of the communication data are encrypted / decrypted, a new one is created between the same terminals. The operation can be executed when a secret communication request occurs.
【0037】
[Effect of the invention]
As described above, according to the authentication and key sharing method of the present invention, a new logical path is generated between terminals that have already performed secret communication, and secret communication is performed. In particular, the terminals are authenticated again. There is no overhead because it is not necessary, and there is an advantage that there is no inconsistency between the communication path paths for encrypting / decrypting the contents of the communication data of the certificate.
[Simple explanation of drawings]
[Figure 1]
It is a block diagram which shows an Example of the communication system to which the secret communication method of this invention is applied.
[Figure 2]
It is a figure which shows an example of the symbol used in the Example of this invention and its meaning.
[Fig. 3]
It is a figure which shows one of the certificates used in this invention.
[Fig. 4]
It is a figure for demonstrating the mutual authentication procedure of terminals by this invention.
[Fig. 5]
It is a figure for demonstrating the secret key sharing procedure by this invention.
[Fig. 6]
It is a figure for demonstrating the authentication / private key sharing procedure when a new secret communication request by this invention occurs.
[Explanation of symbols]
10 Replacement device 20,30 Terminal equipment 40 Certification Authority 110 Terminal control unit 120 Encryption processing unit 130 Communication data processing unit
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0062475A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7747283B2 | Cited by | United States of America | Applicant |
| JP2011146054A | Cited by | Japan | Search report |
| US7260719B1 | Cited by | United States of America | Applicant |
| US8468354B2 | Cited by | United States of America | Applicant |
| US7735126B2 | Cited by | United States of America | Applicant |
| JP2002215480A | Cited by | Japan | Examiner |
| US7881714B2 | Cited by | United States of America | Applicant |
| CN115802316A | Cited by | China | Search report |
| JP2016019280A | Cited by | Japan | Search report |
| WO02087149A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2005524262A | Cited by | Japan | Examiner |
| JP4771946B2 | Cited by | Japan | Examiner |
| US7778631B2 | Cited by | United States of America | Applicant |
| US7505584B2 | Cited by | United States of America | Applicant |
| AU2002251480B2 | Cited by | Australia | Search report |
| US7039802B1 | Cited by | United States of America | Applicant |
| WO0062475A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JPWO2002087149A1 | Cited by | Japan | Search report |
| SG118221A1 | Cited by | Singapore | Search report |
| JP2007529162A | Cited by | Japan | Examiner |
| US7962744B2 | Cited by | United States of America | Applicant |
| JP2011259476A | Cited by | Japan | Examiner |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 22626795 | Japan | A | |
| JP19950226267 | – | – | – |
21 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Written measure of declining of transfer procedureJAPANESE INTERMEDIATE CODE: R370R370 | R370 | |
| Written notification for declining of transfer of rightsJAPANESE INTERMEDIATE CODE: R360R360 | R360 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 |
Numbers
- Publication
- 9-74408
- Publication, DOCDB
- H0974408
- Publication, EPODOC
- JPH0974408
- Application
- 7226267
- Application, DOCDB
- 22626795
- Application, EPODOC
- JP19950226267
Titles2
- Japanese
- 【発明の名称】秘話通信方法
- English
- [Title of Invention] Confidential Communication Method
Classification
- IPC, 3
- H04L9 08
- G09C1 00
- H04L9 32