Method of exchanging cipher information
Abstract
[Task] Identify the communication partner with an open information communication network and exchange information while maintaining security.
Solution.At the request of the application service or the user 3, the master station 1 generates an encryption key or an encryption key and an encryption method 11, and the encryption key or the encryption key and the encryption method correspond to the user identification code 9 in the master station encryption key management data 13. Update management of method 11 and distribute it to slave station 2. The slave station 2 updates and manages the encryption key or the encryption key and the encryption method 11 distributed to the slave station encryption key management data 14 in accordance with the user identification code 9. The user 3 encrypts or decrypts the information with the encryption key or the encryption key stored in the slave station 2 and the encryption method 11, sends and receives the information, and uses the execution result of the application service.
Term
Term ended
Projected expiry passed 12 September 2017, 9 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
10 claims: 9 independent, 1 dependent
- 1【特許請求の範囲】 【請求項1】インターネット(17)、LAN(18)並びに公衆電話網(19)を含むWAN(20)を経由して、親局(1)へ加入接続した子局(2)並びに、利用者属性情報(10)を子局(2)を通じてもしくは直接親局(1)へ登録し、親局(1)が生成した利用者識別記号(9)を授けられた利用者(3)の三者で構成するアプリケーションサービスを実行する通信網において、アプリケーションサービスもしくは利用者(3)からの暗号鍵もしくは暗号鍵と暗号方式(11)の配布要求で、親局(1)は利用者(3)毎の暗号鍵もしくは暗号鍵と暗号方式(11)を生成又は選択して、利用者(3)の利用者識別記号(9)が格納されている子局(2)へ平文もしくは暗号化して配布し、親局暗号管理データ(13)に利用者(3)毎の暗号鍵もしくは暗号鍵と暗号方式(11)を更新管理し、子局(2)は子局暗号管理データ(14)に利用者(3)毎の暗号鍵もしくは暗号鍵と暗号方式(11)を更新管理し、利用者(3)は子局(2)もしくは親局(1)を通じて暗号鍵もしくは暗号鍵と暗号方式(11)を使用して情報を暗号化もしくは復号化して他の利用者(3)もしくは親局(1)との間で情報の交信を行う暗号情報交換方式。
- 2【請求項2】請求項1において、子局(2)が最初に親局(1)へ接続する時に、親局(1)は子局識別記号(12)を生成し、親局暗号鍵管理データ(13)に、子局識別記号(12)を通して利用する利用者(3)の利用者識別記号(9)を参照できるように記録、保管管理し、子局識別記号(12)もしくは暗号化した子局識別記号(12)を子局(2)へ配布し、子局(2)は配布された自局の子局識別記号(12)を子局暗号鍵管理データ(14)に格納し、更に、利用者(3)が親局(1)へ登録する時に、親局(1)から子局(2)へ配布される利用者識別記号(9)も子局暗号鍵管理データ(14)へ格納し、利用者(3)が子局(2)もしくは親局(1)を通してアプリケーションサービスへ参加する時、子局暗号鍵管理データ(14)もしくは親局暗号鍵管理データ(13)で格納されていない利用者識別記号(9)の利用者(3)はアプリケーションサービスへの参加を拒絶され、格納されている利用者識別記号(9)の利用者(3)は子局(2)もしくは親局(1)を通して、利用者識別記号(9)及び利用者属性情報(10)と子局識別記号(12)を一緒に親局(1)へ送信し、親局(1)は利用者(3)が子局(2)もしくは親局(1)を通してアプリケーションサービスに参加している事を確認して利用者(3)の認証を行う暗号情報交換方式。
- 3【請求項3】請求項1もしくは請求項2に於いて、既に利用者(3)が子局(2)もしくは親局(1)を通して親局(1)に登録している場合、同じ利用者(3)が利用者識別記号(9)を格納した別の子局(2)を通してアプリケーションサービスへ参加できる暗号情報交換方式 【請求項4】請求項3に於いて、既に親局(1)へ登録の済んだ利用者(3)は利用者識別記号(9)が格納されていない子局(2)もしくは親局(1)を通じてアプリケーションサービスを利用する手続きを行い、既に利用者識別記号(9)が格納されている子局(2)を通して、認証を親局(1)に申請し、利用者(3)を認証した親局(1)は親局暗号鍵管理データ(13)へ利用者識別記号(9)毎に子局識別記号(12)を記録、保管管理し、利用者識別記号(9)が格納されていない子局(2)へ利用者識別記号(9)を配布し、子局(2)は子局暗号鍵管理データ(14)へ利用者識別記号(9)を格納し、利用者(3)は新しい子局(2)もしくは親局(1)を通してアプリケーションサービスへ参加できる利用者(3)の認証を行う暗号情報交換方式。
- 5【請求項5】請求項3に於いて、親局(1)から子局(2)へ利用者(3)毎に一度に複数個の暗号鍵もしくは暗号鍵と暗号方式(11)を配布しておき、配布済みの複数の暗号鍵もしくは暗号鍵と暗号方式(11)を親局(1)と子局(2)の間で鍵を更新管理する情報(15)で親局(1)及び子局(2)の暗号鍵もしくは暗号鍵と暗号方式(11)を更新する暗号情報交換方式 【請求項6】請求項5において、N i 個の子局(2)を接続した親局(1)から、N k 個の子局(2)を接続した親局(1)がK個だけ存在したとして、K個の親局(1)を子局(2)として接続された親局(1)を設けた事を特徴とする、階層的な暗号情報交換方式 【請求項7】請求項6に於いて、親局(1)は子局(2)に既に配布した暗号鍵もしくは暗号鍵と暗号方式(11)で新しい暗号鍵もしくは暗号鍵と暗号方式(11)を暗号化して子局(2)に配布し、子局(2)は既に受信している暗号鍵もしくは暗号鍵と暗号方式(11)で、受信した暗号化された暗号鍵もしくは暗号鍵と暗号方式(11)を復号化し、子局(2)の子局暗号鍵管理データ(14)に格納されている暗号鍵もしくは暗号鍵と暗号方式(11)を更新格納する暗号情報交換方式。
- 8【請求項8】請求項6に於いて、親局(1)は新しい暗号鍵もしくは暗号鍵と暗号方式(11)を既に子局(2)へ配布した暗号鍵もしくは暗号鍵と暗号方式(11)を使用せず暗号化して子局(2)に配布し、子局(2)はこの暗号を復号化して子局暗号鍵管理データ(14)に格納する暗号情報交換方式。
- 9【請求項9】請求項7もしくは請求項8に於いて、送信元の利用者(3)が送信したい単数もしくは複数の利用者(3)宛の情報を暗号化して親局(1)に送信し、親局(1)は暗号を復号化して、送信先の利用者(3)の暗号鍵もしくは暗号鍵と暗号方式(11)で暗号化し、送信先の利用者識別記号(9)が格納されている子局(2)宛に送信し、送信先の利用者(3)は暗号を復号化して送信元の利用者(3)からの情報を受信し、送信元と送信先の間で親局(1)を中継して暗号情報の交信を行う暗号情報交換方式。
- 10【請求項10】請求項7もしくは請求項8に於いて、利用者(3)が交信したい単数もしくは複数の利用者(3)と直接交信を行う前に、親局(1)は受信元の利用者(3)の暗号鍵もしくは暗号鍵と暗号方式(11)を送信元の利用者識別記号(9)が格納されている子局(2)へ配布し、送信元の利用者(3)は配布された暗号鍵もしくは暗号鍵と暗号方式(11)で情報を暗号化して、送信先の利用者(3)へ直接送信し、受信した利用者(3)は暗号を復号化し情報を交信する暗号情報交換方式。
- 11【請求項11】請求項7もしくは請求項8に於いて、アプリケーションサービス、もしくは利用者(3)の要求で、親局(1)は限定された利用者(3)に共通の暗号鍵もしくは暗号鍵と暗号方式(11)もしくは暗号確認情報(23)を生成もしくは選択し、利用者(3)の利用者識別記号(9)が登録された子局(2)もしくは親局(1)へ配布し、暗号情報の交信を行う暗号情報交換方式 【請求項12】請求項7もしくは請求項8に於いて、利用者(3)と親局(1)の間で暗号化した情報の交信を行う暗号情報交換方式。
- 13【請求項13】請求項9及び請求項10及び請求項11の情報交信方式において、アプリケーションサービスに必要な複数の利用者(3)の情報が時間的にずれて親局(1)に着信する場合、アプリケーションサービスで必要な情報が親局(1)に全て着信した後、複数の利用者(3)に関わるアプリケーションサービスの処理を親局(1)が行う暗号情報交換方式。
- 14【請求項14】請求項12及び請求項13において、暗号情報交換機能を使う子局用のアプリケーションソフトウエ(5)をインストールし、子局(2)に格納されている利用者識別記号(9)の利用者(3)が直接入力操作を行わずアプリケーションサービスが子局(2)に格納されている利用者識別記号(9)の利用者(3)に代わって、その他の利用者(3)との暗号情報を交信する暗号情報交換方式。
Independent claims10
116 paragraphs, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Purpose]
As communication networks, LAN, public switched telephone network exchange connection network, and the Internet are expanding worldwide as inexpensive and open communication networks. Since it is open and easy to connect to all people who participated in the WAN including the Internet and the telephone network, the contents of the information can be easily viewed by a third party. Therefore, the weakness of these communication networks is how to overcome the security of the communication networks. Security issues on the communication network include how to prevent unexpected parties from invading communication equipment and eavesdropping and vandalism of data and systems, and how to protect yourself from viruses that destroy systems and data. In addition to the above, there is a problem of how to prevent eavesdropping of such information during data communication and abuse of the nature of the communication network in which the communication partner cannot be seen.
【0002】
To prevent problems that occur during communication, there is a problem of authentication of how to confirm that the communication partner is definitely the other party, and information encryption that makes the information incomprehensible to anyone other than the parties concerned. So, we will focus on two issues: how to securely exchange encryption keys that encrypt information. The present invention relates to how to confirm that the other party with whom the communication is being made is the correct one, and how to securely exchange the encryption key or encryption method so that only the persons concerned can use it.
【0003】
[Technical field to which the invention belongs]
It relates to a cryptographic information exchange method of how to perform secure information exchange in an electronic information communication network.
【0004】
[Conventional technology]
Research has been conducted for a long time on how to exchange information safely on information and communication networks, but with the spread of the Internet in recent years, secure communication of information has become important. In order to ensure the security of the information communicated on the information and communication network, the encryption method that encrypts the information and the encryption key that encrypts the information so that it cannot be read by anyone other than the parties concerned are secured. Proposals have been made regarding a method of authenticating the person using both the public key and the private key, and encrypting and decrypting the information in order to deliver the encryption key. In addition, research is being conducted to authenticate the person by a method of generating a one-time password (16).
【0005】
[Problems to be Solved by the Invention]
The issues of information communication in a highly open information and communication network are as follows for information exchange and use in commercial transactions. 1 It takes man-hours to manage encryption key distribution 2 Free from the risk of individuals remembering encryption keys 3 Ensuring security against eavesdropping and cryptanalysis 4 Reduction of payment system risk during delivery payment 5 Ensuring personal authentication [0006]
When the encryption key is distributed to each other among N people, the management man-hours for distributing the encryption key through the route of N (N-1) / 2 are generated in (Fig. 4) a. One challenge is to reduce this cost.
【0007】
In order to decrypt the encrypted information with the encryption key, the encryption key must be stored. The encryption key is lengthened to prevent the encryption from being easily broken, and exceeds the limit that humans can remember. In that case, password management for managing the encryption key becomes necessary, and eventually management corresponding to the limit of human memory is required. Attempts such as using an IC card to separate the private key from human memory can be considered, but the security of the encryption key managed by an individual is not always strong, such as the problem of losing the card. Such encryption key management avoids the opportunity to easily use the information and communication network.
【0008】
The big issue is how to prevent eavesdropping and decryption of communications on the information and communication network even if they are encrypted. Furthermore, not only the information is stolen, but also if the stolen information is used to impersonate the person himself / herself, the damage will be increased. The central issue is how to prevent such damage.
【0009】
Compared to over-the-counter sales, one issue is how to settle products and prices on the communication network. When the product is delivered, the product is delivered in exchange for the price, the price is sent first and then the product is delivered, or the product is delivered and the price is transferred. In a commercial transaction on an information network that involves delivery of a product, if the price and the product cannot be settled relative to each other, the product or the person who paid the price bears the risk. Bilateral transactions are also desirable for transactions on information and communication networks.
【0010】
Crimes such as misrepresenting the person and stealing the person to damage the person, stealing the information of another person, or destroying the software property of another person are major problems in the information and communication network. The biggest issue is how to authenticate whether or not the communication partner is the person himself / herself.
【0011】
[Means for solving problems]
The concept of the present invention is that the master station generates a disposable encryption key [Throw Away Encryptical key] or a disposable encryption key and encryption method as needed, and distributes the encryption key or encryption to the slave station. Keys and cryptosystems change, so even if you try to eavesdrop, you have to break the cipher, and even if you succeed in breaking the cipher after a certain amount of time, a disposable cipher key or a disposable cipher Since the key and encryption method have changed, even if you try to impersonate the user, the encryption key distributed by the master station or the encryption key and encryption method are different, so the encryption of the fake who is trying to impersonate the user The master station cannot decrypt the code and does not authenticate the person.
【0012】
Install the application software (4) for the master station that uses the cryptographic information exchange function in Fig. 1 and Fig. 2, have the master station sharing function (6) for the cryptographic information exchange function, and use the Internet (17) and LAN (18). ), Consists of information devices such as personal computers or workstations that communicate encrypted information with the slave station (2) that subscribes to and connects to the master station (1) via WAN (20) including the public telephone network (19). Install the application software (5) for the slave station that uses the cryptographic information exchange function that incorporates the master station (1) to be used and the slave station sharing function (8) of the cryptographic information exchange function, and then install the master station (1). It has a slave station (2) consisting of information devices such as a personal computer, mobile information terminal, or workstation connected to the company, and a user (3) of the encrypted information exchange function (3), and has a master station (1). The user (3) registered in) or the user (2) integrated with the slave station (2) that substitutes the function of the user (3) with the application software (5) installed in the slave station (2). A cryptographic information exchange communication network consisting of 3) is constructed.
【0013】
The encryption key or the encryption key and the encryption method (11) are communicated only between the master station (1) and the slave station (2), and the encryption key or the encryption key and the encryption method (11) are exchanged between the slave stations (2). ) Is not changed directly. Therefore, since the encrypted encryption key or the encryption key and the encryption method (11) are centrally managed by the master station (1), the load related to the management of the encryption key is applied between the slave stations (2). Even if the encryption information is eavesdropped while being transmitted, a third party cannot know the encryption key or the encryption key and the encryption method (11) unless the encryption is broken, and the encryption information can be distributed safely.
【0014】
Figure 2 shows the sharing function for cryptographic information exchange between the master station (1), slave station (2), and user (3), and the sharing function (6) for the master station of the cryptographic information exchange function is. 1. Cryptographic key or cryptographic key and cryptographic method (11) issuance request from user (3), issuance request when an event occurs in the application service, or random, or at a fixed number of times or at random Or, in response to an issuance request at regular intervals, the master station (1) generates or selects one or more encryption keys or encryption keys and encryption method (11) for each user (3). To do. 2. Update the encryption key or encryption key and encryption method (11) generated or selected for each user identification code (9) to the master station encryption key management data (13). 3. Distribute the generated or selected encryption key or encryption key and encryption method (11) to the slave station (2) in which the user identification code (9) of the user (3) is stored. 4. When registering the user (3), the user identification code (9) is generated, recorded in the master station encryption key management data (13), and the user attribute is associated with the user identification code (9). Information (10) is recorded, the user identification code (9) is distributed to the slave station (2) connected to the master station (1) by the user (3) through the slave station (2), and the master station (1) Notify the user that the registration has been approved 5. At the time of subscription connection of the slave station (2), the slave station identification code (12) is generated, recorded in the master station encryption key management data (13), and distributed to the slave station (2). 6. Input reception of slave station (2) and communication control with slave station (2) 7. Ability to execute application services using the encrypted information exchange method 8. Receive the encrypted user identification code (9), user attribute information (10), and slave station identification code (12), and compare them with the master station encryption key management data (13) to match the user (3). Authenticate. 9. When communicating information with the slave station (2), the information is encrypted and decrypted.
【0014】
The corresponding function (7) of the child station sharing function of the cryptographic information exchange function is 1. Communication control with the master station (1) 2. The encryption key or encryption key and encryption method (11) for each user (3) that stores the user identification code (9) are updated and stored for each user identification code (9). 3. Stores the slave station identification code (12) distributed by the master station (1) to the slave station (2), and puts the slave station identification code (12) together with the user identification code (9) in the user attribute information ( Send 10) to the master station (1). 4. The slave station (2) confirms the single or multiple user identification symbols (9) stored in the slave station encryption key management data (14), and the user identification code (9) is not stored. Refuse the user (3) to participate in the application service. 5. The slave station (2) goes to the slave station (2) so that a part or all of the registered user attribute information (10) cannot be seen by a third party other than the user (3). It is also possible to store it and save the user (3) from manually inputting the attribute information. 6. Accepts the password (16) change request from the user (3), sends the update information to the master station (1), and stores it if the slave station (2) stores it internally. Perform data change processing. 7. When the user (3) communicates information with another slave station (2) or master station (1) through the slave station (2), the encrypted key or encryption key for each stored user (3) Information is encrypted and decrypted using encryption method (11).
【0015】
Finally, the user sharing function (8) of the cryptographic information exchange function is 1. Enter and send the attribute information (10) as the user (3) requested by the application service through the slave station (2) or the master station (1), perform the procedure requested by the application service, and perform the user ( Register with the master station (1) as 3). 2. Execute the application service through the slave station (2) or the master station (1) for convenience. 3. The user (3) inputs part or all of the user attribute information (10) through the slave station (2), but stores part or all of the attribute information in the slave station (2). You can easily operate it. 4. Depending on the application service, the application software (5) for the slave station that uses the encrypted information exchange function is installed in the slave station (2), and all or most of the input / output functions are performed on behalf of the user (3). On behalf of the user, the slave station (2) can execute the application service without the input / output operation of the user (3). Generally, the user (3) who provides the application service is integrated with the slave station (2), so the application software (5) for the slave station that uses the encrypted information exchange function performs the function of the user (3). Almost everything is done on your behalf. 5. Change the password (16) managed in the memory of the user (3) at any time.
【0016】
As user attribute information (10) sent and received between the slave station (2) and the master station (1) in order for the user (3) to register with the master station (1) and obtain authentication of identity. It is organized into the following three categories. 1 Information generated and managed by the master station (1) a User identification code (9) b Slave station identification code (12) 2 Information managed in the memory of user (3) a password (16) 3 Social information of user (3) a name b address c Subscriber phone number d Email address e Driver's license, health insurance card, family register extract, seal certificate, etc. g Work place The information generated and managed by the master station (1) is the information generated and managed by the master station (1) when the slave station (2) and the user (3) subscribe to the master station (1) or register. Since the identification symbol (12) of is used by the master station (1) to identify the slave station (2), a unique symbol is assigned to each slave station (2). Only the master station (1) manages the slave station identification symbol (12) and distributes it to the slave station (2), and the child station encryption key management data (13) and the slave station encryption key management data (14) are used as children. The station identification code (12) is stored. The user identification code (9) is notified to the user (3), stored and managed by the master station (1) and the slave station (2), and used in place of the name. There is a password (16) as information to be managed in the memory of the user (3). As a general rule, this information is manually input by the user (3) through the slave station (2) prior to the use of the application service, and is used by the master station (1) as information for authentication of the user (3). .. As a general rule, the password (16) is retained only by the memory of the user (3), but in order to improve usability, it is possible to store it in the slave station (2) so that a third party cannot see it. Is. In order to prevent the password (16) from being leaked to a third party, the password (2) is changed at any time by the slave station (2), and the user (3) managed by the master station (1) or the slave station (2). ) Change the password (16) for each. The social information of the user (3) includes the name and address. This information is the information that the user (3) registers for the confirmation of the user (3) when first registering with the master station (1), and this information is used one by one for each use. ) Is troublesome to input manually, so some or all of this information can be registered and used in the slave station (2). However, since it is not information that is actively disclosed to a third party, it is stored so that it cannot be accessed by anyone other than the user (3).
【0017】
Generation, distribution, and management of cryptographic keys or cryptographic keys and cryptographic methods (11) When the master station (1) generates or selects and distributes the encryption key or the encryption key and the encryption method (11) and when to update it depends on the application service. Basically, information commands related to key generation, distribution, and update are communicated between the master station (1) and the slave station (2), and the master station (1) and the slave station (2) match each other. The encrypted key or encryption key and encryption method (11) are recorded and stored. There are the following commands as information commands for managing keys. 1. Key generation and distribution request 2. Key receipt report 3. Key update request 4. Key renewal notice 5. Key update report The key generation and distribution request is issued by the application service of the user (3) or the master station (1) when necessary. For the convenience of management and the need for management, the key update notification is to distribute multiple encryption keys or encryption keys and encryption method (11) to the slave station (2) at once in Fig. 3 for specific use. Information (15) that manages the key, which is a common recognition between the master station (1) and the slave station (2), such as the number of times, a specific time interval, a specific time, or after executing a specific application service. The slave station (2) reports the result of changing the encryption key or the encryption key and the encryption method (11). In this case, if the master station (1) and the slave station (2) can always grasp the common situation, the master station (1) changes the key information in the same way as the slave station (2) changes the key. Can be updated. However, if the master station (1) cannot grasp the situation until the notification of the slave station (2) is received, the slave station (2) must suspend the use until the update is completed. For example, when the slave station (2) disposes of the currently used encryption key or encryption key and encryption method (11) every set number of uses, and updates to the next encryption key or encryption key and encryption method (11), Even if a common concept regarding the number of times of use is confirmed between the master station (1) and the slave station (2), the situation cannot be grasped unless the slave station (2) has used the slave station (2) how many times. In this case, the slave station (2) determines and updates the encryption key or the encryption key and the encryption method (11), and issues a key update notification to the master station (1).
【0018】
As the encryption method and the encryption key used in the present invention, one of the common key type encryption methods already studied in the world is adopted. The type of encryption method to be selected is selected according to the characteristics or business feasibility of the application service.
【0019】
In the present invention, the distribution path of the encryption key or the encryption key and the encryption method (11) is as follows in the information communication network with N participants (Fig. 4 (a)) by the slave station (2). The distribution route when distributing keys to each other is N * (N-1) / 2, but the key distribution route only between the master station (1) and the slave station (2) is (Fig. 4 (b)). It becomes N, and the distribution route of the encryption key can be reduced by (N-1) / 2 times compared to distributing it to any other party. Furthermore, in (Fig. 4 (c)), K master stations (1) are regarded as slave stations (2), a new master station (1) is provided, and the existing master station (1) is replaced with the slave station (2). ), The management span is reduced to N and K, and the distribution route and distribution management man-hours for the encryption key or encryption key and encryption method (11) are greatly simplified. Be transformed.
【0020】
Registration of slave station (2) and registration of user (3) When the master station (1) accepts the registration of the user (3), it is extremely important to confirm that the user (3) is the person himself / herself. Here, it is shown what kind of information is exchanged between the master station (1), the slave station (2), and the user (3), and in what order the information is recorded. Shown in (5). 1. First, the master station (1) accepts the application program download request from the slave station (2). The master station (1) can record the reception date and time, the management number of the program to be downloaded, the encryption key or the encryption key and the encryption method (11), and the IP address of the slave station (2) as confirmation information. The IP Address of the Internet generally does not have a one-to-one correspondence with the slave station (2), but in the hope that it will show a certain bandwidth value, constantly move, have a fixed value, or show some characteristics. Record. 2. Install the downloaded program (5) in the slave station (2), and set the program-specific management number, encryption key or encryption key and encryption method (11) in the slave station (2). 3. The user (3) inputs the user attribute information (10) specified by the master station through the slave station (2) and sends it to the master station (1) together with the control number of the slave station (2). 4. The master station (1) confirms the encryption key or encryption key and encryption method (11) with the management number, records the date and time of new registration, user attribute information (10), and the slave station identification code (12). Also, generate and record the user identification code (9) and initial password (16). 5. Encrypt the slave station identification code (12), user identification code (9), and initial password (16) and send them to the slave station (2). 6. The slave station (2) decrypts the encrypted slave station identification code (12), the user identification code (9), and the initial password (16), and updates and stores it in the slave station (2). .. 7. The user (3) confirms the user identification code (9) and the initial password (16). 8. The user (3) performs the password (16) change procedure through the slave station (2), and the master station (1) accepts the change and updates the record. 9. The user (3) inputs the user attribute information (10) including the user identification symbol (9) and password (16) through the slave station (2), and the slave station (2) is the identification note of the slave station. Send to the master station (1) together with (12). 10. The master station (1) records the user attribute information (10) including the password (16) corresponding to the user identification code (9) and the slave station identification code (12). 11. It is difficult to confirm the identity of the person only by the information via the communication network, and the document specified by the application such as a driver's license, health insurance card, family register extract, etc., which shows the social information of the user, or a copy thereof Request to send, confirm with the information already sent, and keep the documents. The user (3) is now registered in the master station (1) via the slave station (2). 12. The master station (1) issues a card that clearly indicates the user identification code (9) and the address, telephone number, URL, logo mark, etc. that indicate the characteristics of the master station (1). This card also serves as a means of contacting the user (3) in case of trouble, preventing the case of falsely acting on the master station (1), and promoting the master station (1).
【0021】
The downloaded program is not always used by only one slave station (2), but is likely to be copied and used by multiple slave stations (2), but multiple slave stations (2). Even if it is used in, the encryption key or the encryption key and the encryption method (11) are changed at the time of registration of the user (3), and there is no problem. Even if multiple users (3) are registered in one slave station (2), the encryption key or encryption key and encryption method corresponding to the multiple user identification symbols (9) and the user identification symbols (9) (11) is set as the master station (1) and the slave station (2). Therefore, a plurality of users (3) can use the service of the application through one slave station (2).
【0022】
When the user (3) uses the service via multiple slave stations (2). When the user (3) wants to use the service not only through one slave station (2) but also through the mobile slave station (2) or another slave station (2). Whether or not the registered user (3) is the person There is also a method of receiving the submission of social information certifying the person as in the case of the first registration, but it is troublesome for the user (3). Figure 6 shows the registration act on the communication network that eliminates this inconvenience. The user (3) a who has already registered in the master station (1) through the slave station (2) A enters the user identification code (9) and password (16) via the slave station (2) B. Enter the attribute information (10) of user a requested by the application service including, and perform multiple registration application procedures to the master station (1). The master station (1) accepts this procedure, and the information that the slave station identification number (12) has come via the slave station (2) B and that the user (3) a has requested registration has already been registered. Check and record. User (3) a performs the authentication procedure via the already registered slave station (2) A. The master station (1) authenticates the user by confirming the authentication request received from the slave station (2) A by the user (3) a. The master station (1) distributes the newly generated encryption key or encryption key of user (3) a and the encryption method (11) to the slave station (2) B, and updates the master station encryption management data (13). .. The slave station (2) B creates a record corresponding to the user (3) a user identification code (9) using the distributed encryption key or encryption key and the encryption method (11). After completing this procedure, user (3) a can use the application services via slave station (2) A or slave station (2) B. Here, it is explained that the slave station (2) B is already connected as a slave station, but if the slave station (2) B is not yet subscribed and connected, the subscription connection procedure of the slave station (2) is performed. If so, it will be treated the same as when already connected.
【0023】
How to re-register if the system is destroyed The system of the slave station (2) may be broken. In this case, re-registration can be done by receiving the user identification code (9), password (16), and user attribute information (10) by the master station (1) and assuming that the person is the person himself / herself. If all user attribute information (10) including the person identification code (9) and password (16) is stolen, join the master station (1) through another slave station (2) and impersonate the person. You can do it. Therefore, social information will be sent to the master station (1) in writing, etc., and the identity will be confirmed again. If the system is partially destroyed while the application service is being executed, either cancel the execution of the application service, take measures by other means such as documents, or restore the system and re-register from the beginning to apply the application. The service will be executed.
【0024】
Even if the master station (1) manages the user's encryption key or encryption key and encryption method (11), the user's encryption key or encryption key and encryption method (11) recorded in the slave station (2) ) And the user's encryption key recorded in the master station (1) or the relationship between the encryption key and the encryption method (11) must be clarified.
【0025】
Tasuki distribution Figure 7 shows the user's encryption key or encryption key and encryption method (11) recorded at the master station (1) and the encryption key or encryption key and encryption method (11) recorded at the slave station (2). Show the dependencies between. The encryption key or encryption key of the user (3) already stored in the slave station (2) and the encryption method (11) are used as the encryption key.<sub>k-1</sub>, Cryptography<sub>k-1</sub>Then, the encryption key or the encryption key and the encryption method (11) newly distributed by the master station (1) to the slave station (2) are the encryption keys already stored in the slave station (2).<sub>k-1</sub>, Cryptography<sub>k-1</sub>It is encrypted with and sent to the slave station (2), and the slave station (2) decrypts it and sends it to the encryption key.<sub>k</sub>, Cryptography<sub>k</sub>Update to. After that, until the new key is distributed, the information sent and received through the slave station (2) is the encryption key.<sub>k</sub>, Cryptography<sub>k</sub>It is encrypted and compounded with. If the encryption information is received at the same time as the encryption key or the encryption key and the encryption method (11), the encryption is the already registered encryption key.<sub>k-1</sub>, Cryptography<sub>k-1</sub>Decrypt with. In this way, since encryption and decryption are performed using the already transmitted encryption key or encryption key and encryption method (11), the usage pattern is that of the encryption key or encryption key and encryption method (11). .. The relationship between the master station (1) and the slave station (2) that can be used to hang the encryption key or the encryption key and the encryption method (11) causes a time lag between the distribution of the key and the communication of the encryption information. It works to your advantage in ensuring security.
【0026】
Parallel distribution method of encryption key In Fig. 8, the encryption key or encryption key encrypted by the master station (1) and the encryption method (11) are distributed to the slave station (2), and the distributed encryption is decrypted in the slave station (2). The encryption key or the encryption key and the encryption method (11) are stored in the slave station (2). Information is encrypted and decrypted with the previously distributed encryption key or encryption key and encryption method (11) without using the distribution encryption key or encryption key and encryption method (11).
【0027】
The information exchange method using the encrypted information exchange method consisting of the master station (1), the slave station (2), and the user (3) sets the following three formats. 1 The master station (1) relays the information of the user (3) and exchanges information. 2 Exchange information directly between users (3). 3 Information is exchanged between the master station (1) and the user (3). After confirming that the user is the user (3), the information to be updated may be the case where the plaintext is encrypted and the information is communicated, or the case where the plaintext is communicated. As information communication, information exchange that occurs in management such as information exchange in case of trouble occurs in addition to the intended information exchange in order to support the execution of the application service, but here the user (3) is the application service. Only the information exchange performed when using is explained.
【0028】
Relay information exchange: As shown in Fig. 9, the master station (1) takes information between slave stations (2) A and slave station (2) B, and then relays information between slave stations (2) A and B. Show the case. The delivery information encrypted by the user (3) a encryption key or the encryption key and the encryption method (11) and the destination user (3) are transmitted to the master station (1). The received master station (1) decrypts the encryption, and the slave station (2) B user (3) b's encryption key or encryption key and the delivery information are encrypted by the encryption method (11), and the user ( 3) Send to the slave station (2) B where b is registered. The user (3) b received at the slave station (2) B decodes the information and understands the content of the received information. Information is not directly transmitted / received between slave station (2) A and slave station (2) B, but is indirectly exchanged by relaying master station (1).
【0029】
In the case of relay information exchange, since the master station (1) performs the relay work of encrypting and decrypting the information, it takes time and effort, but there is an advantage obtained by that. 1 For indirect information transactions, the user attribute information (10) of user (3) a is only confirmed by the master station (1), and only the information related to the matter is transmitted to user (3) b. By doing so, anonymous information transmission becomes possible. 2 When the master station (1) exchanges relay information between the slave stations (2) A and B, the timing at which the master station (1) receives the information of the user (3) a in Fig. 10 and the user ( 3) If the timing of receiving the information in b does not match, the application service processing is temporarily suspended, and the application service processing is executed after both information are available.
【0030】
When communicating information directly between users (3): When you want to communicate encrypted information directly between slave stations (2) without going through the master station (1), use it through slave station (2) A in Fig. 11. Person (3) a requests direct communication with user (3) b and requests distribution of encryption key or encryption key and encryption method (11) or encryption confirmation information (23) for confirmation instead. The master station (1) generates or selects a common encryption key or encryption key and encryption method (11) or alternative encryption confirmation information (23) for user (3) a and user (3) b, and is a slave station. Distribute to (2) A and slave station (2) B. The encryption key or encryption key that is duplicated in both slave stations (2) and the encryption method (11) or the encryption confirmation information (23) that replaces it are stored, and the encryption information is sent and received between users (3) a and b. , Decrypt, check the contents, and communicate information.
【0031】
When the user (3) sends and receives encrypted information between the source and the receiver of the information, the source user (3) sends the encryption key or the encryption key to one or more destination users (3). And the distribution request of the encryption method (11) is made to the master station (1), and the master station (1) uses the encryption key of the destination user (3) or the encryption key and the encryption method (11) of the source. The user identification code (9) of the person (3) is transmitted to the slave station (2), and the user identification code (9) of the source encrypts the information and sends it to the destination. The destination user (3) decrypts the encryption and communicates information.
【0032】
Communicating information between the master station (1) and the user (3): In some cases, the user (3) communicates information directly with the master station (1) through the slave station (2). In FIG. 12, A1 of the user (3) directly communicates information with the master station (1) through the slave station (2) A.
【0033】
[Example]
Delivery transaction Figure 13 shows an example of a product sales transaction system that delivers products via a communication network. The master station (1) relays the order from the buyer to the seller and setstles the transaction when the sale is agreed. The purchaser of the slave station (2) places an order for the product to be purchased, and the seller of the slave station (2) accepts the order and ships the product directly to the shipping destination. A purchaser registered in a plurality of slave stations connected to a transaction agency / settlement institution of the master station (1) and a seller registered in a plurality of slave stations form a commercial transaction communication network. This is an example in which the master station (1) relays the information of the user (3) and exchanges information. Following the transaction procedure in Figure 13, The purchaser's transaction start request is sent to the relay agency / settlement institution together with the user identification code (9), user attribute information (10), and slave station identification code (12), and the relay agency / settlement institution sends this. Decrypt. Confirm the purchaser with the user identification code (9), user attribute information (10), and slave station identification code (12). The relay agency / settlement institution generates the transaction number and the purchaser's encryption key or the encryption key and the encryption method (11) and distributes them to the purchaser. The purchaser who received the encryption key or the encryption key and the encryption method (11) are updated at the slave station (2). The purchaser encrypts the URL (Universal Resource Locator) of the seller's slave station (2), the product information to be purchased, and the attribute information of the purchaser, and sends it to the relay agency / settlement institution. The relay agency / payment institution decrypts the code, authenticates the purchaser, and confirms the credit. The purchaser's purchase specifications are encrypted with the seller's encryption key or encryption key and encryption method (11), and sent to the seller's slave station (2). At this time, since only the information related to the transaction of the product is relayed and transmitted to the seller, the purchaser can purchase the product anonymously. The seller's encryption key or encryption key and encryption method (11) are generated, distributed, and changed by the relay agency / settlement organization of the master station (1) in an arbitrary way. For example, the set number of transactions or the set time interval may be updated. The seller confirms the specifications of the order and sends an order notification to the relay agency / settlement organization together with the estimated shipping date of the product. The relay agency / payment institution decrypts the code, confirms whether it matches the order, and performs internal payment processing. The relay agency / settlement institution sends the successful sale and the estimated shipping date to the purchaser. When the seller sends a product shipping notification to the relay agency / settlement institution, the relay agency / settlement institution setstles the transaction between the purchaser and the seller. Settlement when a transaction involving delivery of a product is carried out via a communication network is performed by relaying a relay agency / settlement institution, and after receiving information on product shipment from the seller, the settlement is made at the same timing as the bilateral transaction. It became possible to settle a bilateral transaction similar to receiving the item in kind at the store and paying the price, and sent the item associated with the transaction between the buyer and the seller, but the money could not be collected or the money was sent. However, it is possible to reduce the risk that the product will not be shipped.
【0034】
Information service Figure 14 shows the case where service transactions such as provision of data are performed using a communication network. The service user encrypts the URL (Universal Resource Locator) of the service provider's slave station (2) and the service user attribute information (10), and sends the service usage request to the service intermediary. The service intermediary agency decrypts the code, authenticates the service user, and confirms the credit. The service intermediary agency generates or selects an encryption key or encryption key and encryption method (11), and further generates a transaction number common to the service user service provider, and gives the service user the encryption key or encryption key of the service provider. The transaction number encrypted by the encryption method (11) and the encryption key of the service user or the encryption key and the encryption method (11) are encrypted and transmitted, and the transaction number is encrypted and transmitted to the service provider. The encrypted transaction number indicates the encryption confirmation information (23). The service user stores the transmitted transaction number and encryption key or encryption key and encryption method (11). The service user sends the transaction number to the service provider, and the service provider duplicates and confirms the encrypted transaction number. Service users receive data services directly from service providers. The service fee is billed by the service provider to the service intermediary agency, and the service intermediary agency or the settlement institution setstles the service fee. Even if the service user who consented to the withdrawal of payment and the service provider do not directly handle the payment problem related to the use of the service, it is possible to settle small expenses easily by going through the service intermediary agency. You can receive it.
【0035】
Figure 15 shows home banking using the cryptographic information exchange method. The account opener who opened a deposit account at financial institution C uses the encryption key or encryption key and encryption method (11) distributed by financial institution C through the slave station (2), and the user identification code (9) and the user. Attribute information (10), slave station identification code (12), and transfer information are encrypted and sent to the financial institution of the master station (1), decrypted by the financial institution of the master station (1), and an account is opened. Is authenticated, and the transfer is processed to another account opener of the same financial institution C or an account opener of another financial institution D.
【0036】
Delivery of letter Figure 16 shows a system for reliable delivery of a letter by an electronic information management organization. The e-mail sender / receiver sets a password (16) for each e-mail address at any time through the registered slave station (2) in the electronic information management mechanism. The set password (16) is sent to the electronic information management mechanism. The sender a encrypts and sends the destination e-mail address to the electronic information management mechanism through the slave station (2), and requests the transmission of the master letter. The electronic information management mechanism encrypts and transmits the encryption key or encryption key of the receiver b and the encryption method (11) to the sender a of the slave station (2) A. The sender a encrypts the letter and sends it to the receiver b. When the decryption of the receiver b is successful, the slave station (2) B sends the reception decryption confirmation information to the electronic information management organization, and the set encryption key or the encryption key and the number of times that the encryption method (11) can be received can be received. Reduce the counter by one. When the value of the counter reaches the set value, the encryption key or the encryption key and the encryption method (11) are updated from efg to hij in FIG. 16, and the efg is erased. The electronic information management organization makes a service contact to the sender of the slave station (2). The electronic information management mechanism distributes a plurality of encryption keys or encryption keys and an encryption method (11) for each e-mail address in advance, and when the recipient receives the master letter at the slave station (2) a set number of times, the encryption is performed. The key or encryption key and encryption method (10) are erased from the slave station (2). It is possible to confirm the delivery of the letter by notifying the fact that the encrypted letter has been delivered between the sender a and the receiver b via the electronic information management mechanism.
【0037】
Intranet Figure 17 shows an example of intranet information management within a company. Slave station connected to LAN (18) (2)<sub>11</sub> Slave station (2)<sub>1k</sub>Intranet connected via WAN (20) consisting of slave station (2) 21 ... slave station (2) 2j connected via the Internet and slave station (2) jp connected by remote access. In addition to protecting the information that accesses the server with a firewall (22), the encryption key or encryption key and encryption method (11) generated and distributed to the slave station (2) to which the server of the master station (1) is connected. By using)), it is possible to build a system that can maintain the security of all information via the server of the master station (1). Even if the security against external information is strengthened with the firewall (22), as the organization grows, how to secure the security inside the firewall is a big issue, but the throw Away Encryptical key Management method solves this problem.
【0038】
FIG. 18 shows a case where a common encryption key or an encryption key and an encryption method (11) are used. The common encryption key or encryption key distributed from the master station (1) and the encryption method (11) are shared by the slave station a, the slave station b, and the slave station c, and the information can be communicated only by the persons concerned. The encryption key or the update of the encryption key and the encryption method (11) is set by the application service, and it can flexibly respond to the change of the member. Even when the bulletin board uses a common encryption key or encryption key and encryption method (11), the authentication of the parties concerned has a higher security function than only the password (16), and it is used when discussing with limited problems. it can.
【0039】
[Effect of the invention]
Public key and private key methods are used to securely pass the encryption key to all parties with whom we communicate. However, an electronic information network is constructed between the master station and the slave station to establish the master station and the slave station. And when the purpose is achieved by exchanging encryption information only between registered users, if the master station manages all the information, it can be managed with a disposable encryption key (Throw Away Encryption key). Users are not even aware of the existence of a Throw Away Encryptical key, which makes it easier for individuals to manage security.
【0040】
On the other hand, for criminal acts from the outside via WAN, access from the outside is restricted by a firewall to ensure security. However, as the organization grows, not only the protection against unauthorized information access from the outside but also the security of the internal information network becomes more important, but the firewall cannot protect it. One Time Pass Word is effective for personal authentication even in the internal information and communication network, but it cannot handle the confidentiality of information. The cryptographic information exchange method using a disposable encryption key (Throw Away Encryptical key) is an intranet, etc., and security can be ensured regardless of internal or external access.
【0041】
Since the Internet is originally composed of a client-server system, it is often possible to configure an information communication network usage system in relation to a master station and a slave station, and a disposable encryption key (Throw Away Encryptical key) and an encryption method are used. The cryptographic information exchange method can be expected to be used in a wide range of fields.
【0042】
A private network using a dedicated line using the encryption information exchange method of the Throw Away Encryptical key managed between the relationship between the master station (1) and the slave station (2) and the user (3). While maintaining security equal to or higher than that of the above, users can build a secure private network using the open and inexpensive Internet and public telephone network without knowing the encryption key or the contents of the encryption key and encryption method. You can.
[Simple explanation of drawings]
[Figure 1]
A system configuration that manages information with a disposable encryption key (Throw Away Encryptical key) in an information communication network consisting of users, slave stations, and master stations. [Figure 2]
Sharing of functions for exchanging encrypted information between users, slave stations, and master stations [Fig. 3]
A method of updating a plurality of prepared encryption keys or encryption keys and encryption methods with information for managing keys. [Fig. 4]
(a) Number of routes to pass the encryption key between N people (b) Number of routes that make up the relationship between the master station and the slave station and pass the encryption key between N people (c) The number of encryption key paths when the relationship between the master station and the slave station is configured, the master station is configured as the slave station, and the master station is configured on it, and the hierarchical master station and slave station are configured. [Fig. 5]
A method in which the user registers with the master station through the slave station [Fig. 6]
The user registers with the master station through multiple slave stations only by communicating information on the communication network. [Fig. 7]
Management method of disposable encryption key (Throw Away Encryptical key) generated by a cross between the master station and the slave station [Fig. 8]
A management method for a disposable encryption key (Throw Away Encryptical key) used for encryption using the encryption key or encryption key sent from the master station to the slave station and the encryption method. [Fig. 9]
Cryptographic information exchange method that relays the master station and sends and receives encrypted information between the slave stations [Fig. 10]
An application service system that waits for the master station to collect information between slave stations and processes information related to the slave stations.
[Fig. 11]
Cryptographic information exchange method in which the master station generates or selects and distributes a common encryption key or encryption key and encryption method between slave stations [Fig. 12]
A system in which a master station and a slave station directly communicate encryption information with a disposable encryption key (Throw Away Encryptical key). [Fig. 13]
A commercial transaction system on a communication network that involves the delivery of goods using a Throw Away Encryptical key. [Fig. 14]
A system that provides information services using a disposable encryption key (Throw Away Encryptical key) [Fig. 15]
A system in which account holders perform home banking with financial institutions via an open network.
[Fig. 16]
A system that delivers a letter using a Throw Away Encryptical key [Fig. 17]
A system that enables highly secure information communication inside and outside a firewall using a disposable encryption key (Throw Away Encryptical key) on an intranet via LAN or WAN. [Fig. 18]
Information exchange method using a common encryption key or encryption key and encryption method [Explanation of symbols]
1. Master station 2. Slave station 3. User 4. Application software for the master station that uses the encryption information exchange function 5. Application software for slave stations that use the cryptographic information exchange function 6. Sharing function of the master station of the cryptographic information exchange function 7. Cryptographic information exchange function slave station sharing function 8. User sharing function of cryptographic information exchange function 9. User identification code 10. User attribute information 11. Cryptographic key or cryptographic key and cryptosystem 12. Slave station identification symbol 13. Master station encryption key management data 14. Slave station encryption key management data 15. Information for updating and managing keys 16. Password 17. Internet 18.LAN (Local Area network) 19. Public switched telephone network 20.WAN (Wide Area network) 21. Information package 22. Firewall 23. Cryptographic confirmation information
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7523067B1 | Cited by | United States of America | Applicant |
| JP2002281027A | Cited by | Japan | Search report |
| JP2003505978A | Cited by | Japan | Search report |
| JPWO2005067200A1 | Cited by | Japan | Examiner |
| JP4567602B2 | Cited by | Japan | Search report |
| US7448540B2 | Cited by | United States of America | Applicant |
| JP2010219912A | Cited by | Japan | Examiner |
| JP2003323544A | Cited by | Japan | Search report |
| WO2005067200A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8452985B2 | Cited by | United States of America | Applicant |
| US7523067B1 | Cited by | United States of America | Applicant |
| JP2004094781A | Cited by | Japan | Search report |
| US7657490B1 | Cited by | United States of America | Applicant |
| US7865401B2 | Cited by | United States of America | Applicant |
| JP2007072661A | Cited by | Japan | Examiner |
| US7457782B2 | Cited by | United States of America | Applicant |
| US7571117B1 | Cited by | United States of America | Applicant |
| US7024553B1 | Cited by | United States of America | Search report |
| US7721092B2 | Cited by | United States of America | Applicant |
| US7330968B2 | Cited by | United States of America | Applicant |
| WO2006079282A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7523067B1 | Cited by | United States of America | Applicant |
| CN100385983C | Cited by | China | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 28753897 | Japan | A | |
| JP19970287538 | – | – | – |
Numbers
- Publication
- 11-85014
- Publication, DOCDB
- H1185014
- Publication, EPODOC
- JPH1185014
- Application
- 9287538
- Application, DOCDB
- 28753897
- Application, EPODOC
- JP19970287538
Titles2
- Japanese
- 【発明の名称】暗号情報交換方式
- English
- [Title of Invention] Cryptographic Information Exchange Method
Classification
- IPC, 2
- H04L9 08
- G09C1 00