Privacy telephone set
Abstract
[Task] By encrypting a random combination of an encryption key and an encryption algorithm, a secret communication device having extremely high confidentiality is provided.
Solution.The encryption management unit 13 receives the encryption key from the encryption key generation unit 11 from the encryption algorithm selection unit 12, stores and stores the encryption key, and then stores the stored encryption key and the encryption algorithm on the receiving side via the communication line. When the response information from the secret talk device on the receiving side is received, the encryption key and encryption algorithm stored in the storage device are sent to the encryption unit 14 and the decryption / restoration unit 15, respectively. The encryption key and encryption algorithm stored in the storage device are erased when the communication is completed, and the encryption key stored in the storage device of the encryption unit and the storage device of the decryption / restoration unit. And instruct to erase the cryptographic algorithm.
Term
Term ended
Projected expiry passed 28 February 2017, 9.6 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
7 claims: 5 independent, 2 dependent
- 1【特許請求の範囲】 【請求項1】 通信回線を介して接続し通信情報を暗号化して相互通信を行う秘話装置において、 1桁以上の暗号キー情報をランダムに発生する暗号キー生成手段と、 予め登録した複数の暗号アルゴリズム情報から成る暗号アルゴリズム群の中からランダムに1つの暗号アルゴリズム情報を選択する暗号アルゴリズム選択手段と、 通信開始するたびに前記暗号キー生成手段が発生した前記暗号キー情報と前記暗号アルゴリズム選択手段が選択した前記暗号アルゴリズム情報とを発信側から通信回線を介して受信側へ通知して前記通信情報の暗号化情報を発信側と受信側間に設定する暗号化情報設定手段と、 を有することを特徴とする秘話装置。
- 2【請求項2】 通信回線を介して接続し通信情報を暗号化して相互通信を行う秘話装置において、 少なくとも1桁の暗号キー情報をランダムに発生する暗号キー生成手段と、 予め登録した複数の暗号アルゴリズム情報から成る暗号アルゴリズム群の中からランダムに1つの暗号アルゴリズム情報を選択する暗号アルゴリズム選択手段と、 通信中の前記通信情報の前記暗号化情報の設定変更を要求するための暗号化情報変更要求手段と、 通信開始するたびに前記暗号キー生成手段が発生した前記暗号キー情報と前記暗号アルゴリズム選択手段が選択した前記暗号アルゴリズム情報とを発信側から前記通信回線を介して受信側へ通知して前記通信情報の暗号化情報を発信側と受信側間に設定すると共に、前記暗号化情報変更要求手段から前記暗号化情報の変更要求があったとき通信中の前記暗号化情報を新らたな暗号化情報に変更する暗号化情報設定手段と、 を有することを特徴とする秘話装置。
- 3【請求項3】 前記暗号化情報は、前記通信回線がディジタル回線の場合には、呼設定メッセージを使用し、前記通信回線がアナログ回線の場合には、変復調装置を使用してそれぞれ送信することを特徴とする請求項1および2記載の秘話装置。
- 4【請求項4】 通信回線を介して接続し通信情報を暗号化して相互通信を行う秘話装置において、 1桁以上の暗号キー情報をランダムに発生する暗号キー生成部と、 複数の暗号アルゴリズム情報を予め登録しておく第1の記憶装置を備え、第1の記憶装置に登録されている暗号アルゴリズム群の中からランダムに1つの暗号アルゴリズム情報を選択する暗号アルゴリズム選択部と、 前記暗号キー生成部が生成した前記暗号キー情報と前記暗号アルゴリズム選択部が選択した前記暗号アルゴリズム情報とから成る暗号化情報を格納する第3の記憶装置を備え、第3の記憶装置に格納されている前記暗号化情報に基づき送信する前記通信情報を暗号化する暗号化部と、 前記暗号キー生成部が生成した前記暗号キー情報と前記暗号アルゴリズム選択部が選択した前記暗号アルゴリズム情報とから成る前記暗号化情報を格納する第4の記憶装置を備え、第4の記憶装置に格納されている前記暗号化情報に基づき受信した前記通信情報を解読,復元化する解読/復元部と、 前記暗号キー生成部が生成した前記暗号キー情報と前記暗号アルゴリズム選択部が選択した前記暗号アルゴリズム情報とから成る前記暗号化情報を格納する第2の記憶装置と、前記暗号化情報をアナログ/ディジタル変換するための変復調部とを備え、前記第2の記憶装置に格納されている前記暗号化情報を前記通信回線がデジタル回線の場合は呼設定メッセージを使用し、前記通信回線がアナログ回線の場合は前記変復調部を使用して受信側の秘話装置へそれぞれ送信し、受信側の秘話装置からの応答を応答メッセージまたは前記変復調部を介して受信したとき、前記第2の記憶装置に格納されている前記暗号化情報を前記暗号化部および前記解読/復元部へ送出し、通信が終了したとき前記第2の記憶装置に格納されている前記暗号化情報を消去すると共に、前記暗号化部の前記第3の記憶装置および前記解読/復元部の前記第4の記憶装置に格納されている前記暗号化情報の消去を指示する暗号化管理部と、 音声入出力手段とデータ入出力手段とを備えたマンマシンインタフェース部と、 を有することを特徴とする秘話装置。
- 5【請求項5】 通信回線を介して接続し通信情報を暗号化して相互通信を行う秘話装置において、 1桁以上の暗号キー情報をランダムに発生する暗号キー生成部と、 複数の暗号アルゴリズム情報を予め登録しておく第1の記憶装置を備え、第1の記憶装置に登録されている暗号アルゴリズム群の中からランダムに1つの暗号アルゴリズムを選択する暗号アルゴリズム選択部と、 通信中の前記通信情報の前記暗号化情報の設定変更を要求するための暗号化情報設定変更要求手段と、 前記暗号キー生成部が生成した前記暗号キー情報と前記暗号アルゴリズム選択部が選択した前記暗号アルゴリズム情報とから成る暗号化情報を格納する第3の記憶装置を備え、第3の記憶装置に格納されている前記暗号化情報に基づき送信する前記通信情報を暗号化する暗号化部と、 前記暗号キー生成部が生成した前記暗号キー情報と前記暗号アルゴリズム選択部が選択した前記暗号アルゴリズム情報とから成る前記暗号化情報を格納する第4の記憶装置を備え、第4の記憶装置に格納されている前記暗号化情報に基づき受信した前記通信情報を解読,復元化する解読/復元部と、 前記暗号キー生成部が生成した前記暗号キー情報と前記暗号アルゴリズム選択部が選択した前記暗号アルゴリズム情報とから成る前記暗号化情報を格納する第2の記憶装置と、前記暗号化情報をアナログ/ディジタル変換するための変復調部とを備え、前記第2の記憶装置に格納されている前記暗号化情報を前記通信回線がディジタル回線の場合は呼設定メッセージを使用し、前記通信回線がアナログ回線の場合は前記変復調部を使用して受信側の秘話装置へそれぞれ送信し、受信側の秘話装置からの応答を応答メッセージまたは前記変復調部を介して受信したとき、前記第2の記憶装置に格納されている前記暗号化情報を前記暗号化部および前記解読/復元部へ送出し、通信中に前記暗号化情報設定変更要求手段から暗号化情報の設定変更要求を受けたとき、前記第2,第3,第4の記憶装置に格納されている現在の前記暗号化情報を消去し、前記暗号キー生成部が発生する新らたな暗号キー情報と前記暗号アルゴリズム選択部が選択した新らたな前記暗号アルゴリズムを使用して通信開始と同様な手順で前記暗号化情報を再設定し、通信が終了したとき前記第2の記憶装置に格納されている前記暗号化情報を消去すると共に、前記暗号化部の前記第3の記憶装置および前記解読/復元部の前記第4の記憶装置に格納されている前記暗号化情報の消去を指示する暗号化管理部と、 音声入出力手段とデータ入出力手段とを備えたマンマシンインタフェース部と、 を有することを特徴とする秘話装置。
- 6【請求項6】 前記暗号化情報の設定変更要求は、発信側および受信側いずれの秘話装置からでも可能であることを特徴とする請求項2および5記載の秘話装置。
- 7【請求項7】 前記暗号化情報設定変更要求手段は、予め設定した所定の周期で自動的に前記暗号化情報の設定変更要求情報を送出することを特徴とする請求項2および5記載の秘話装置。
Independent claims7
173 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a secret voice device, and more particularly to an encryption method for two-way communication that can be encrypted by randomly combining an encryption key and an encryption algorithm and can be used for both analog and digital communication methods.
【0002】
[Conventional technology]
When communicating highly confidential information in telephone, facsimile, and data communication, a secret communication device is used to prevent communication interception by a third party.
【0003】
A secret communication device in an ISDN terminal that encrypts by combining a plurality of encryption algorithms is proposed, for example, in Japanese Patent Application Laid-Open No. 04-053326. FIG. 5 is a block diagram of a secret voice device of Japanese Patent Application Laid-Open No. 4-53326.
【0004】
The line control unit 21 of the secret communication device 20 shown in FIG. 5 terminates the line consisting of the D channel and the B channel in the integrated service digital network (hereinafter referred to as ISDN), and the telephone device 22 attaches the D channel to the line control unit 21. It is connected to the channel by the B channel.
【0005】
The cryptographic algorithm selection device 23 is connected to the D channel of the ISDN via the line control unit 21, selects a plurality of cryptographic algorithms from the cryptographic algorithm group at the time of transmission, and selects a predetermined message, for example, a call on the D channel of the ISDN. The combination information of the selected encryption algorithm is written in a predetermined information element of the setting message, for example, the incoming subaddress, and the encryption algorithm is selected based on the combination information received at the incoming subaddress of the call setting message at the time of incoming call.
【0006】
The algorithm accommodating memory 24 stores the programs of each cryptographic algorithm of the cryptographic algorithm group. The cryptographic processing device 25 is inserted into the B channel between the circuit control unit 21 and the telephone device 22, and encrypts information on the B channel of the ISDN according to the program of each cryptographic algorithm selected by the cryptographic algorithm selection device 23. Transform and decrypt.
【0007】
At the time of transmission, the cryptographic algorithm selection device 23 selects a plurality of cryptographic algorithms from the cryptographic algorithm group and determines the combination thereof. As shown in FIG. 6, the combination information of each of the selected cryptographic algorithms is written to the incoming subaddress of the call setting message in the D channel of ISDN and sent to the D channel of ISDN via the line control unit 21.
【0008】
The terminal identification code 31 in the format of the incoming subaddress of the call setting message shown in FIG. 6 is a terminal identification code for identifying the possibility of encrypted communication. A method of combining encryption algorithms is specified in the encryption algorithm selection key unit 32, and an encryption key for each algorithm is specified in the encryption key unit 33.
【0009】
Further, the cryptographic algorithm selection device 23 sets the corresponding program in the algorithm accommodating memory 24 inside the cryptographic processing device 25 based on the cryptographic algorithm selection key unit 32 and the encryption key unit 33 specified in the incoming subaddress of the call setting message. Load into memory (not shown).
【0010】
In this algorithm accommodating memory 24, for each encryption algorithm A, B, ......, a program for encryption Ac, Bc ...... and a program for decryption Ad, Bd. ..... are stored in pairs, and each is loaded in pairs in the internal memory (not shown) of the encryption processing device 25.
【0011】
The call setting message sent to the D channel of ISDN is received by the line control unit 21 of the ISDN terminal device on the receiving side, and its incoming subaddress is also transferred to the cryptographic algorithm selection device 23. The cryptographic algorithm selection device 23 first refers to the terminal identification code 31 in the incoming subaddress to identify whether or not cryptographic communication is possible. As a result, if the encryption communication is impossible, the encryption processing device 25 is instructed not to perform the encryption processing in the B channel, and the line control unit 21 is notified of the completion of the reception preparation.
【0012】
If cryptographic communication is possible as a result of identification, the cryptographic algorithm selection key unit 32 in the incoming subaddress is analyzed, the selection algorithm to be used is selected, and each selected cryptographic algorithm is executed according to the processing order. Load from the accommodation memory 24 to the internal memory of the encryption processing device 25.
【0013】
At that time, the setting of the encryption key based on the analysis of the encryption key unit 33 in the incoming subaddress is executed on the encryption algorithm selection device 23, and then the line control unit 21 is notified of the completion of reception preparation.
【0014】
Upon receiving the notification of the completion of reception preparation, the line control unit 21 sends a response message to the calling terminal to ISDN, and thereafter communication with the calling terminal becomes possible.
【0015】
[Problems to be Solved by the Invention]
As described above, the conventional secret communication device includes a line control unit 21, a telephone device 22, a cryptographic algorithm selection device 23, a cryptographic algorithm storage memory 24, and a cryptographic processing device 25, and a plurality of ciphers selected from the cryptographic algorithm group. The combination of algorithms is notified to the other terminal that writes to the incoming subaddress of the call setting message on the D channel of ISDN, and the transmission information is encrypted / decrypted according to the combination of multiple encryption algorithms. Cryptographic algorithms A, B, ... in which the encryption programs Ac, Bc ...... and the decryption programs Ad, Bd ...... are stored as a pair. Since ... is selected and used, there are few types of cryptographic algorithms (finite), and since it is a relatively simple combination, there is a risk of communication interception by a third party, which is not always sufficient for security.
【0016】
Also, it cannot support both analog and digital lines. Therefore, when used for an analog line, a separate secret voice device for the analog line is required.
【0017】
An object of the present invention is to provide a secret communication device having extremely high confidentiality and capable of supporting both analog and digital lines by encrypting with a random combination of an encryption key and an encryption algorithm.
【0018】
[Means for solving problems]
The secret communication device of the present invention is a secret communication device that connects via a communication line and encrypts communication information to perform mutual communication, and is an encryption key generation means that randomly generates encryption key information of one digit or more, and a plurality of registered in advance. A cryptographic algorithm selection means that randomly selects one cryptographic algorithm information from a group of cryptographic algorithms consisting of the above cryptographic algorithm information, and the cryptographic key information and the cryptographic algorithm selection that the cryptographic key generation means generates each time communication is started. It has an encryption information setting means for notifying the receiving side of the encryption algorithm information selected by the means from the transmitting side via a communication line and setting the encrypted information of the communication information between the transmitting side and the receiving side. It is characterized by that.
【0019】
In addition, in a secret communication device that connects via a communication line and encrypts communication information to perform mutual communication, an encryption key generation means that randomly generates at least one digit encryption key information and a plurality of encryption algorithm information registered in advance are used. A cryptographic algorithm selection means for randomly selecting one cryptographic algorithm information from a group of cryptographic algorithms, and a cryptographic information change requesting means for requesting a change in the setting of the encryption information of the communication information during communication. Each time communication is started, the encryption key information generated by the encryption key generation means and the encryption algorithm information selected by the encryption algorithm selection means are notified from the transmitting side to the receiving side via the communication line, and the communication information. The encryption information of is set between the transmitting side and the receiving side, and when the encryption information change requesting means requests the change of the encryption information, the encryption information being communicated is newly encrypted information. It is characterized by having an encrypted information setting means for changing to.
【0020】
Further, the encrypted information is characterized in that when the communication line is a digital line, a call setting message is used, and when the communication line is an analog line, a modulation / demodulation device is used to transmit the encrypted information. To do.
【0021】
In addition, in a secret communication device that connects via a communication line and encrypts communication information to perform mutual communication, an encryption key generator that randomly generates encryption key information of one digit or more and a plurality of encryption algorithm information are registered in advance. A cryptographic algorithm selection unit that includes a first storage device to be stored and randomly selects one cryptographic algorithm information from a group of cryptographic algorithms registered in the first storage device, and a cryptographic key generation unit are generated. A third storage device for storing encryption information including the encryption key information and the encryption algorithm information selected by the encryption algorithm selection unit is provided, and based on the encryption information stored in the third storage device. A second unit that stores the encryption information including an encryption unit that encrypts the communication information to be transmitted, the encryption key information generated by the encryption key generation unit, and the encryption algorithm information selected by the encryption algorithm selection unit. It is equipped with 4 storage devices, and decrypts the communication information received based on the encrypted information stored in the 4th storage device.A second storage device that stores the encryption information including the decryption / restoration unit to be restored, the encryption key information generated by the encryption key generation unit, and the encryption algorithm information selected by the encryption algorithm selection unit. , A modulation / demodulation unit for analog / digital conversion of the encrypted information is provided, and a call setting message is used for the encrypted information stored in the second storage device when the communication line is a digital line. When the communication line is an analog line, the modulation / demodulation unit is used to transmit to the secret talk device on the receiving side, respectively, and when the response from the secret talk device on the receiving side is received via the response message or the modulation / demodulation unit, the above-mentioned The encryption information stored in the second storage device is sent to the encryption unit and the decryption / restoration unit, and when communication is completed, the encryption information stored in the second storage device is transmitted. Along with erasing, an encryption management unit that instructs the erasure of the encrypted information stored in the third storage device of the encryption unit and the fourth storage device of the decryption / restoration unit, and a voice input It is characterized by having a man-machine interface unit including an output means and a data input / output means.
【0022】
In addition, in a secret communication device that connects via a communication line and encrypts communication information to perform mutual communication, an encryption key generator that randomly generates encryption key information of one digit or more and a plurality of encryption algorithm information are registered in advance. A cryptographic algorithm selection unit that includes a first storage device and randomly selects one cryptographic algorithm from a group of cryptographic algorithms registered in the first storage device, and the cipher of the communication information during communication. Encryption information consisting of an encryption information setting change requesting means for requesting a setting change of encryption information, the encryption key information generated by the encryption key generation unit, and the encryption algorithm information selected by the encryption algorithm selection unit. A third storage device for storing the above, an encryption unit that encrypts the communication information transmitted based on the encryption information stored in the third storage device, and the encryption key generation unit generated. A fourth storage device for storing the encryption information including the encryption key information and the encryption algorithm information selected by the encryption algorithm selection unit is provided, and based on the encryption information stored in the fourth storage device. The encryption information including the decryption / restoration unit that decrypts and restores the received communication information, the encryption key information generated by the encryption key generation unit, and the encryption algorithm information selected by the encryption algorithm selection unit. A second storage device for storing the encryption information and a modulation / demodulation unit for analog / digital conversion of the encryption information are provided, and the encryption information stored in the second storage device can be stored in the communication line on a digital line. In this case, a call setting message is used, and if the communication line is an analog line, the modulation / demodulation unit is used to transmit to the secret talk device on the receiving side, and the response from the secret talk device on the receiving side is sent to the response message or the modulation / demodulation unit. When received via, the encryption information stored in the second storage device is sent to the encryption unit and the decryption / restoration unit, and encrypted from the encryption information setting change requesting means during communication. When receiving a request to change the setting of encryption information, the above 2nd, 3rd,The current encryption information stored in the fourth storage device is erased, and the new encryption key information generated by the encryption key generation unit and the new encryption selected by the encryption algorithm selection unit are used. The encryption information is reset by using an algorithm in the same procedure as the communication start, and when the communication is completed, the encryption information stored in the second storage device is erased and the encryption unit is deleted. The encryption management unit for instructing the erasure of the encrypted information stored in the third storage device and the fourth storage device of the decryption / restoration unit, and the voice input / output means and the data input / output means. It is characterized by having a man-machine interface unit provided with the above.
【0023】
Further, the request for changing the setting of the encrypted information can be made from either the transmitting side or the receiving side secret voice device.
【0024】
Further, the encryption information setting change request means is characterized in that the setting change request information of the encryption information is automatically transmitted at a predetermined cycle set in advance.
【0025】
BEST MODE FOR CARRYING OUT THE INVENTION
Embodiments of the present invention will be described in detail with reference to the drawings. FIG. 1 is a block diagram showing a main configuration of a secret voice device according to the first embodiment of the present invention.
【0026】
First, the configuration of the first embodiment will be described. The secret communication device 10 of the first embodiment shown in FIG. 1 has a encryption key generation unit 11 that generates an encryption key composed of a random number of one digit or more, and an encryption algorithm stored in advance in the encryption algorithm storage unit 17. A storage device that stores a cryptographic algorithm selection unit 12 that randomly selects one cryptographic algorithm from the group, a cryptographic key generated by the cryptographic key generation unit 11, and a cryptographic algorithm selected by the cryptographic algorithm selection unit 12 ( (Not shown) and an encryption management unit 13 that includes a modulation / demodulation unit 18 for analog / digital conversion of encryption information consisting of an encryption key and an encryption algorithm, and an encryption management unit 13 that manages a combination of the encryption key and the encryption algorithm, and encryption. Encryption unit 14, which encrypts transmission communication information such as voice signals, facsimile image signals, and data signals according to the encryption key and encryption algorithm specified by the encryption management unit 13, decrypts / restores the contents of the encrypted received communication information. It is composed of a decryption / restoration unit 15, a man-machine interface unit 16 including an input / output device such as a keyboard and a display, and a handset.
【0027】
The encryption key generation unit 11 has a function of randomly generating a plurality of digits of numerical information as an encryption key from the numerical information registered in advance and sending it to the encryption management unit 13. Since the encryption key generation unit 11 newly generates an encryption key each time communication is started (called), a storage device such as a random access memory (RAM) or a flash memory (FMEM) is not required. ..
【0028】
The cryptographic algorithm selection unit 12 randomly selects one cryptographic algorithm from the cryptographic algorithm accommodating unit 17 that stores a plurality of cryptographic algorithms in advance and the cryptographic algorithm group stored in the cryptographic algorithm accommodating unit 17. It has a selection circuit to be used.
【0029】
The cryptographic algorithm accommodating unit 17 can be configured by, for example, FMEM or ROM, and a plurality of cryptographic algorithms applicable to each case of analog / digital communication are stored in advance, and the selection circuit is stored from this algorithm accommodating unit 17. A cryptographic algorithm is randomly selected each time communication is started, and this is sent to the cryptographic management unit 13.
【0030】
The encryption management unit 13 has a storage device (not shown), a function of requesting an encryption key and an encryption algorithm each time communication is started, and an encryption key and encryption received from the encryption key generation unit 11 and the encryption algorithm selection unit 12. After storing the algorithm in the storage device, it is received from the encryption key generation unit 11 and the encryption algorithm selection unit 12 via the communication line immediately after the communication line with the secret communication device on the receiving side is connected (before transmission of communication information). A function to transmit the encrypted key and encryption algorithm to the secret device on the receiving side, and a crypto key stored in the storage device when a predetermined response signal (ready signal) is received from the secret device on the receiving side via a communication line. It has a function of sending the encryption key and the encryption algorithm received from the generation unit 11 and the encryption algorithm selection unit 12 to the encryption unit 14 and the decryption / restoration unit 15.
【0031】
When the communication line is a digital line such as ISDN, this information is put on the B channel of ISDN and transmitted to the secret communication device on the receiving side as in the case of the conventional secret communication device. In the case of a certain analog line, the same function is realized by transmitting via the modulation / demodulation unit 18.
【0032】
Further, when the communication ends (line disconnection), the encryption management unit 13 erases the encryption key and the encryption algorithm stored in the storage device, prepares for the next communication start, and then generates a communication start request again. Then, the encryption key and the encryption algorithm are newly generated, and the new encryption information is set in the transmitting side and the receiving side secret communication device by the same procedure as described above.
【0033】
The encryption unit 14 and the decryption / restoration unit 15 each have a storage device (not shown), receive an encryption key and an encryption algorithm from the encryption key management unit 13, store them in the storage device, and use the stored encryption key and encryption algorithm. The communication information to be transmitted is encrypted, the encrypted received communication information is decrypted / restored, and the communication information is transmitted and received by the man-machine interface unit 16.
【0034】
The encryption unit 14 and the decryption / restoration unit 15 have a function of being able to handle all combinations of the encryption key and the encryption algorithm generated / selected from the encryption key generation unit 11 and the encryption algorithm selection unit 12.
【0035】
Next, the operation will be described with reference to Fig. 2 and Fig. 1. FIG. 2 is a flowchart showing the operation of the first embodiment.
【0036】
When the man-machine interface unit 16 of the secret voice device 10 is called by a predetermined method and it is detected that a communication line is connected to the secret talk device on the receiving side (step S101 in FIG. 2), the calling side is immediately called. The encryption key generation unit 11 of the secret communication device 10 generates a random encryption key (for example, a value of 1111) (S102) and notifies the encryption management unit 3.
【0037】
At the same time, the cryptographic algorithm selection unit 12 randomly selects one cryptographic algorithm from the cryptographic algorithm group (for example, A, B, ......, Z) registered in advance in the cryptographic algorithm storage unit (for example, ROM) 17. Select (for example, C) and notify (S103) the encryption management unit 13.
【0038】
The encryption management unit 13 stores the encryption key 1111 received from the encryption key generation unit 11 and the encryption algorithm C received from the encryption algorithm selection unit 12 in the RAM (not shown), and before transmitting the communication information. In order to confirm that the receiving side secret talk device 10 can realize the secret talk communication using the encryption according to the present invention, first, the encryption key 1111 and the encryption algorithm C are applied to the receiving side secret talk device 10 (encryption key). The combination information of 1111 and cryptographic algorithm C) is notified via the connected communication line (S104).
【0039】
When the communication line is a digital line, the D channel call setting message is used for the notification to the receiving side secret voice device 10, and when the communication line is an analog line, the modulation / demodulation unit 18 of the encryption management unit 13 is used. And send it out.
【0040】
Whether or not the receiving side secret communication device 10 is a secret communication device capable of being encrypted according to the present invention is determined by receiving a ready signal from the encryption management unit 13 of the receiving side secret communication device 10 (S105).
【0041】
If the ready signal is not returned from the receiving side secret communication device 10 in step S105, it is determined that the receiving side secret communication device cannot perform encrypted communication, and normal communication other than secret communication is performed.
【0042】
When the ready signal is detected in step S105, the receiving side secret communication device 10 determines that the encrypted communication according to the present invention is possible, and proceeds to the preparation for performing the encrypted communication in the subsequent steps.
【0043】
When the encryption management unit 13 detects the ready signal in step S105, the encryption management unit 13 notifies the encryption unit 14 and the decryption / restoration unit 15 of the encryption key 1111 and the encryption algorithm C previously stored in the RAM (S106), and encrypts the encryption. The unit 14 and the decryption / restoration unit 15 store the encryption key 1111 and the encryption algorithm C received from the encryption management unit 13 in their own storage devices (RAM), respectively.
【0044】
As a result, the encryption key and the encryption algorithm are set for both the encryption unit 14 and the decryption / restoration unit 15 of the calling side secret voice device 10 and the encryption unit 14 and the decryption / restoration unit 15 of the reception side secret voice device 10. Then, the preparation for encrypted communication is completed (S107).
【0045】
After that, encrypted communication information is transmitted and received between the transmitting side secret communication device and the receiving side secret communication device via an analog communication line or a digital communication line (S108).
【0046】
When this communication is completed, the encryption management unit 13 erases the encryption key and encryption algorithm used for this communication, which are stored in the RAM, and is stored in the RAM of the encryption unit 14 and the decryption / restoration unit 15. Instructs to erase the encryption key and encryption algorithm.
【0047】
In this way, every time the encrypted communication ends, the encryption key and encryption algorithm used for the encrypted communication are discarded, and when a new communication is started, that is, for each communication (at the time of call connection), it occurs randomly. Since one encryption algorithm is randomly selected from the encryption key and the encryption algorithm group and set between the transmitting side secret communication device and the receiving side secret communication device to perform secret communication, the number of combinations of the encryption key and the encryption algorithm is conventional. The number of secret talk devices is dramatically increased, which enables more confidential secret talk communication.
【0048】
The handset, keyboard, display, etc. that make up the man-machine interface unit 16 may be those that are generally used in the past, and when using a digital communication line, the encryption key and encryption algorithm are used in the same way as in the past, ISDN. The call setting message on the D channel of the above, and in the case of an analog line, the modulation / demodulation unit notifies the receiving side, respectively, and the communication information is encrypted and decrypted / restored by the combination of the encryption key and the encryption algorithm. It can be applied to all communication terminal devices such as / fax / data communication, and it can also support both digital and analog lines, making it possible to realize a highly confidential confidential communication function.
【0049】
Next, the configuration of the second embodiment will be described. FIG. 3 is a block diagram showing a main configuration of a secret voice device showing a second embodiment of the present invention.
【0050】
The secret communication device 10 of the second embodiment shown in FIG. 3 has an encryption key generation unit 11 that generates an encryption key composed of a random number of one digit or more, and an encryption algorithm stored in advance in the encryption algorithm storage unit 17. A storage device that stores a cryptographic algorithm selection unit 12 that randomly selects one cryptographic algorithm from the group, a cryptographic key generated by the cryptographic key generation unit 11, and a cryptographic algorithm selected by the cryptographic algorithm selection unit 12 ( (Not shown) and an encryption management unit 13 that includes a modulation / demodulation unit 18 for analog / digital conversion of encryption information consisting of an encryption key and an encryption algorithm, and an encryption management unit 13 that manages a combination of the encryption key and the encryption algorithm, and encryption. Encryption unit 14, which encrypts transmission communication information such as voice signals, facsimile image signals, and data signals according to the encryption key and encryption algorithm specified by the encryption management unit 13, decrypts / restores the contents of the encrypted received communication information. Decryption / restoration unit 15, a man-machine interface unit 16 consisting of input / output devices such as keyboards and displays, and a handset, and a reset unit 19 for changing the encryption key and encryption algorithm of communication information during communication. Consists of.
【0051】
Since the configuration is the same as that of the first embodiment shown in FIG. 1 except for the reset unit 19, the description of each configuration will be omitted here.
【0052】
The reset unit 19 operates by pressing a button, key pressing information, command input, or the like, and realizes that the encryption key and encryption algorithm currently used for communication can be changed to another encryption key and encryption algorithm on the way. It will be necessary for.
【0053】
Further, in the first embodiment, the selection of the encryption key and the encryption algorithm is led by the sender, whereas the change of the encryption key and the encryption algorithm by the reset unit 19 is performed not only by the sender but also by the receiver. It is also possible with a secret talk device.
【0054】
Further, by expanding the second embodiment and adding a function of automatically resetting the reset unit 19 at regular intervals, the encryption key and encryption algorithm of the communication information during communication are automatically changed. This improves confidentiality, and eliminates the need for a change request operation for encrypted information, improving operability.
【0055】
Next, the operation of the second embodiment will be described with reference to FIG. 4 and FIG. FIG. 4 is a flowchart showing the operation of the second embodiment.
【0056】
When the man-machine interface unit 16 of the secret voice device 10 is called by a predetermined method and it is detected that a communication line is connected to the secret talk device on the receiving side (step S201 in FIG. 4), the calling side is immediately called. The encryption key generation unit 11 of the secret communication device 10 generates a random encryption key (for example, a value of 1111) (S202) and notifies the encryption management unit 13.
【0057】
At the same time, the cryptographic algorithm selection unit 12 randomly selects one cryptographic algorithm from the cryptographic algorithm group (for example, A, B, ......, Z) registered in advance in the cryptographic algorithm storage unit (for example, ROM) 17. Select (for example, C) (S203) and notify the encryption management unit 13.
【0058】
The encryption management unit 13 stores the encryption key 1111 received from the encryption key generation unit 11 and the encryption algorithm C received from the encryption algorithm selection unit 12 in the RAM (not shown), and before transmitting the communication information. In order to confirm that the receiving side secret talk device 10 can realize the secret talk communication using the encryption according to the present invention, first, the encryption key 1111 and the encryption algorithm C are applied to the receiving side secret talk device 10 (encryption key). The combination information of 1111 and cryptographic algorithm C) is notified via the connected communication line (S204).
【0059】
This notification to the receiving side secret device uses the D channel call setting message when the communication line is a digital line, and uses the modulation / demodulation unit 18 of the encryption management unit 13 when the communication line is an analog line. And send it out.
【0060】
Whether or not the receiving side secret voice device 10 is a secret talk device capable of being encrypted according to the present invention is determined by receiving a ready signal from the encryption management unit 13 of the receiving side secret talk device 10 (S205).
【0061】
If the ready signal is not returned from the receiving side secret communication device 10 in step S105, it is determined that the receiving side secret communication device cannot perform encrypted communication, and normal communication other than secret communication is performed.
【0062】
When the ready signal is detected in step S205, the receiving side secret communication device 10 determines that the encrypted communication according to the present invention is possible, and proceeds to the preparation for performing the encrypted communication in the subsequent steps.
【0063】
When the encryption management unit 13 detects the ready signal in step S205, the encryption management unit 13 notifies the encryption unit 14 and the decryption / restoration unit 15 of the encryption key 1111 and the encryption algorithm C previously stored in the RAM (S206), and encrypts the encryption. The unit 14 and the decryption / restoration unit 15 store the encryption key 1111 and the encryption algorithm C received from the encryption management unit 13 in their own storage devices (RAM), respectively.
【0064】
As a result, the encryption key and the encryption algorithm are set for both the encryption unit 14 and the decryption / restoration unit 15 of the calling side secret voice device 10 and the encryption unit 14 and the decryption / restoration unit 15 of the reception side secret voice device 10. Then, the preparation for encrypted communication is completed (S207).
【0065】
After that, encrypted communication information is transmitted and received between the transmitting side secret communication device and the receiving side secret communication device via an analog communication line or a digital communication line (S208).
【0066】
The encryption management unit 13 monitors the completion of communication (S209), and when this communication is completed (S211), erases the encryption key and encryption algorithm used for this communication stored in the RAM, and also deletes the encryption unit 14 Instructs to erase the encryption key and encryption algorithm stored in the RAM of the decryption / recovery unit 15.
【0067】
When the encryption management unit 13 monitors the encryption information setting change request based on the switch press information or command information sent from the reset unit 19 during communication (S209) (S210) and identifies the encryption information setting change request information. , Cryptographic key 1111 currently in use and cryptographic algorithm C are different from the cryptographic key and cryptographic algorithm C. While erasing C, the process proceeds to step S202 by instructing the erasure of the encryption key and the encryption algorithm stored in the RAMs of the encryption unit 14 and the decryption / restoration unit 15.
【0068】
After that, the operations of steps S202 to S207 are repeated, and an encryption key (for example, 2222) and an encryption algorithm (for example, Z) different from the encryption key 1111 and the encryption algorithm C used up to now are used for the sender secret talk device and the receiver secret talk device. Reset between and continue encrypted communication.
【0069】
In addition, although it was explained that the encryption key and the encryption algorithm during communication are arbitrarily changed by the reset operation on the sending side or the receiving side, the encryption key and the encryption algorithm are automatically changed at a predetermined cycle at a predetermined cycle. You can also.
【0070】
In this way, since the encryption key and the encryption algorithm can be reset during communication, the confidentiality of the encrypted communication is further increased.
【0071】
[Effect of the invention]
As described above, the first embodiment of the present invention is an encryption key that randomly generates a plurality of digits of encryption key information in a secret communication device that connects via a communication line and encrypts communication information to perform mutual communication. A generation means, a cryptographic algorithm selection means for randomly selecting one cryptographic algorithm information from a group of cryptographic algorithms consisting of a plurality of cryptographic algorithm information registered in advance, and a cryptographic key for which a cryptographic key generation means is generated each time communication is started. Information and encryption algorithm information selected by the encryption algorithm selection means are notified from the sender side to the receiver side via a communication line, and the encryption information of the communication information is set every time communication is performed between the sender side and the receiver side. It is composed of information setting means, and every time the encrypted communication is completed, the encryption key and encryption algorithm used for the encrypted communication are discarded, and when the communication is newly started, that is, for each communication (at the time of call connection). , Since one encryption algorithm is randomly selected from the randomly generated encryption key and encryption algorithm group and set between the sender side secret talk device and the receiver side secret talk device to perform confidential communication, the encryption key and the cryptographic algorithm The number of combinations is dramatically increased as compared with the conventional secret talk device, which enables more confidential secret talk communication.
【0072】
For example, even if the encryption key is 3 digits, 999 combinations can be obtained. At this time, even if the number of encryption algorithms is the same as that of the conventional technology, the number of combinations of the encryption key and the encryption algorithm is several times that of the conventional technology. It will be dozens of times larger than that.
【0073】
In addition, when using a digital communication line, the encryption key and encryption algorithm are notified to the receiving side by a call setting message on the D channel of ISDN, and by a modulation / demodulation unit in the case of an analog line, as in the conventional case. However, since the communication information is encrypted and decrypted / restored by the combination of the encryption key and the encryption algorithm, it can be applied to all kinds of communication such as telephone / fax / data communication, and also for both digital / analog lines. I can handle it.
【0074】
In the second embodiment of the present invention, the configuration of the first embodiment is required to change the setting of the encrypted information of the communication information during communication by pressing a button, pressing a key, inputting a command, or the like. Since the encryption information change requesting means of the above is added, the encryption key and the encryption algorithm currently used for the communication can be changed to another encryption key and the encryption algorithm in the middle of the communication. Furthermore, confidential communication with high confidentiality becomes possible.
【0075】
Further, in the first embodiment, the selection of the encryption key and the encryption algorithm is led by the sender, whereas the change of the encryption key and the encryption algorithm during communication is performed by the sender by the encryption information change request means. Not only that, it is possible to use the secret communication device on the receiving side.
【0076】
Further, the second embodiment is developed to add a function of automatically resetting the encrypted information change requesting means at regular intervals, and automatically change the encryption key and encryption algorithm of the communication information during communication. By doing so, the confidentiality is improved, and the operation of requesting the change of the encrypted information becomes unnecessary, and the operability is improved.
[Simple explanation of drawings]
[Figure 1]
It is a block diagram which shows the main structure of the 1st Embodiment of this invention.
[Figure 2]
It is a flowchart which shows the operation of the 1st Embodiment of this invention.
[Fig. 3]
It is a block diagram which shows the main structure of the 2nd Embodiment of this invention.
[Fig. 4]
It is a flowchart which shows the operation of the 2nd Embodiment of this invention.
[Fig. 5]
It is a block diagram of a conventional secret talk device.
[Fig. 6]
It is a figure which shows the format of the incoming call subaddress used in the conventional secret voice apparatus.
[Explanation of symbols]
10 Confidential device 11 Encryption key generator 12 Cryptographic algorithm selection section 13 Encryption Management Department 14 Encryption section 15 Decoding / Restoring Department 16 Man-machine interface section 17 Cryptographic algorithm containment 18 Modulation / demodulation section 19 Reset section 20 Traditional esoteric device 21 Line control unit 22 Telephone equipment 23 Cryptographic algorithm selection section 24 Algorithm containment memory 25 Cryptographic processing equipment 31 Terminal identification code 32 Cryptographic algorithm selection key part 33 Encryption key part
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2003501878A | Cited by | Japan | Examiner |
| JP7358658B1 | Cited by | Japan | Search report |
| JP2011259439A | Cited by | Japan | Search report |
| JP2007194679A | Cited by | Japan | Examiner |
| JP2008259163A | Cited by | Japan | Examiner |
| US8856523B2 | Cited by | United States of America | Applicant |
| JP2014099875A | Cited by | Japan | Search report |
| JP7358659B1 | Cited by | Japan | Search report |
| US8515073B2 | Cited by | United States of America | Applicant |
| JP2007282070A | Cited by | Japan | Examiner |
| JP2009201163A | Cited by | Japan | Examiner |
| JP2009534697A | Cited by | Japan | Search report |
| US10469455B2 | Cited by | United States of America | Applicant |
| WO2023162233A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2011507318A | Cited by | Japan | Examiner |
| US7913094B2 | Cited by | United States of America | Applicant |
| JP2013214993A | Cited by | Japan | Search report |
| JP2007172653A | Cited by | Japan | Examiner |
| JP2014531175A | Cited by | Japan | Search report |
| JP2006191508A | Cited by | Japan | Search report |
| JP2013215385A | Cited by | Japan | Examiner |
| JP2009534697A | Cited by | Japan | Search report |
| JP2008236022A | Cited by | Japan | Examiner |
| JP2009201163A | Cited by | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 4578097 | Japan | A | |
| JP19970045780 | – | – | – |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Notification of change of attorneyJAPANESE INTERMEDIATE CODE: A7421RD01 | RD01 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 |
Numbers
- Publication
- 10-242956
- Publication, DOCDB
- H10242956
- Publication, EPODOC
- JPH10242956
- Application
- 9045780
- Application, DOCDB
- 4578097
- Application, EPODOC
- JP19970045780
Titles2
- Japanese
- 【発明の名称】秘話装置
- English
- [Title of Invention] Confidential device
Classification
- IPC, 3
- H04L9 14
- H04M1 68
- H04M11 00