Key distributing device
Abstract
PURPOSE:To increase the efficiency of a key distribution by using a secret integral number specific to a user so as to convert a random number and forming a key distribution data, thereby generating a ciphering communication key under a prescribed condition. CONSTITUTION:A secret integral number and a public integral number in common to membership are stored in the card 203 of a user A and the numbers are read in a terminal 201 via a card reader 202. A terminal equipment 201 generates a random number at the key distribution processing, the number is converted by using the secret integral number and the public integral number and sends the converted random number to a communication opposite party B as a key delivery data, receives the key delivery data generated by the similar procedure from the opposite party B and discriminates whether or not the data is a data satisfying a prescribed condition according to the predetermined algorithm. When the condition is satisfied, the key distribution data is converted depending on the random number generated by the predetermined conversion and the result of conversion is used as the ciphering communication key.
Term
Term ended
Projected expiry passed 22 August 2006, 20.1 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
1 claim: 1 independent, 0 dependent
- 1[Claim(s)] 【特許請求の範囲】 In a key delivery system which delivers a key which should be shared with a communication partner on the occasion of encryption communication, A key delivery system comprising:A data creation means for key delivery which generates a random number, and changes the random number by conversion beforehand defined depending on a secret code which was able to be defined beforehand, and a digital pattern which may not necessarily be common to the party concerned with communication, and secret, and it sends to said communication partner by using the changed random number as data for key delivery, Data for key delivery created in said communication partner under the same rule as said data creation means for key delivery is received, and the data for key delivery judges according to an algorithm which was able to define beforehand whether it was data which fulfills predetermined conditions, A key preparing means for encryption communication which will change the data for key delivery depending on a random number generated [ said ] in conversion which was able to be defined beforehand if it fills, and uses the conversion result as a key for encryption communication. 暗号通信に際し通信相手と共有すべきキーを配送するキー配送装置において、乱数を発生し、該乱数を、あらかじめ定められた秘密コードと通信当事者に共通で必ずしも秘密でなくてもよいディジタルパターンとに依存してあらかじめ定められた変換で変換し、該変換された乱数をキー配送用データとして前記通信相手に送るキー配送用データ作成手段と、前記通信相手において前記キー配送用データ作成手段と同じ規則で作成されたキー配送用データを受けとり、該キー配送用データが所定の条件をみたすデータか否かをあらかじめ定められたアルゴリズムに従って判定して、みたせば該キー配送用データを前もって定められた変換にて前記発生された乱数に依存して変換し、その変換結果を暗号通信用キーとする暗号通信用キー作成手段とからなることを特徴とするキー配送装置。
4 paragraphs, as filed
[Detailed Description of the Invention]
(Field of the Invention) The present invention relates to the key delivery system used for encryption communication. (Conventional technology) As for a public-key-encryption system or a public key distribution system, Diffie and Hermann are 22 volumes of the transactions-on information theory (IEEETransactions on Information Theory) of IEEE, and No. 6, It is the method proposed at 644 pages ~ 654 pages. That of these is a method which performs encryption of a message, and conversion of a cryptographic key using the information currently released. (Problem which an invention tends to solve) Since the above-mentioned information currently released differs for every communication partner, it becomes all the convenience To and a huge quantity, and there is a fault that it must always warn against moreover being altered. (Means for solving a problem) The key delivery system of the present invention generates a random number, and it changes the random number by the conversion beforehand defined depending on the secret code which was able to be defined beforehand, and the digital pattern which may not necessarily be common to the party concerned with communication, and secret, A data creation means for key delivery to send the changed random number to the above-mentioned communication partner as the data for key delivery, The data for key delivery created in the above-mentioned communication partner by the same means as the above-mentioned data creation means for key delivery is received, and the data for key delivery judges according to the algorithm which was able to define beforehand whether it was data which fulfills predetermined conditions, It is a key delivery system carrying out from the key preparing means for encryption communication which will change the data for key delivery depending on the random number generated [ above-mentioned ] in the conversion which was able to be defined beforehand if it fills, and uses the conversion result as the key for encryption communication. (OPERATION) In order to make it intelligible in advance of a detailed description of the invention, the portions of a principle and an operation common to each example are explained using Drawing 1. In Drawing 1, the case where a cryptographic key shall be shared between user A and user 3, and user A applies starting is assumed. User A has secret integer SA, and integer (henceforth public presentation) e, c, and alpha which may not necessarily be secret and n, and user B has secret integer SB, the above-mentioned open integer e, c, and alpha, and n. The person or organization which can trust it beforehand defines and distributes these integers. How to set is mentioned below. User A generates random number r, calculates XA = a" (mod n) and yA= SA-a" (mod n), and sends (XA13'A) to user B. a (mod b) means here the remainder which broke a by b. Acceptance takes (XA, yA), yAe/xAC (modn) codes the address of A, a name, etc., and although user B is equal to reliance A, he judges whether it is no. If not equal, key delivery processing is stopped. If equal, user B will generate random number t, will calculate xB = aet (mad n) and yB = SB-aCt (mod n), and will send (xBlyB) to user A, and it asks for data encryption key wk from wk=xAt (modn). wk is equal to aer' (modn). On the other hand, user A receives (XB, yB), if yBe/xBc (mod n) codes user's B address, a name, etc., judges whether it is equal to reliance B and is not equal, he stops key delivery processing, and if equal, he will ask for data encryption key Wk from wk= xBr (mod n). This Wk is also equal to alphaert (mod H). Although IDA is known by all the members, user B may be notified of it from user A. Now, SA, SB, e, c, alpha, and n shall be defined as follows here. the size which is a grade with factorization of n difficult for n=p-q -- a difference -- it is considered as a prime number. For example, p. It is enough if q is about 2256. e and c are made into the prime number of less than n, and alpha is taken as the right integer of less than n. Furthermore as an integer with which e-d(mod (p-1) (q-1)) =1 is filled, d is set to SA = IDAd (mod n) and SB = IDBd (mod n). It is set to SAe(mod n) = IDA and SBe(mod n) = IDB when SA, SB, e, c, alpha, and n are defined as mentioned above. Since this is the same processing as the so-called code of an amount system of R8A public key dark, and decoding indicated to 126 pages from 120 pages, magazine communication and S op the NC (Communication of the ACM), of volume [ 21st ] No. 2, it is materialized. Then, it becomes yAe/XAC=SAe and alpha erC/alpha erC=IDA by making n into law. The same may be said of yBe/xBC= IDB. However, it is since user A has SA and user B has sB. yAe/XAC[ (however, injustice shall not be person or organization committed) ] (modn) =■DA -- filling (XA, yA) -- user A can be made -- yBe/xBC(mod n) = IDB -- filling (xB, yB) -- user B can be made. [ which created SA, SB etc. ] [ which can trust it ] Since it is equivalent to breaking the above-mentioned amount system of R8A public key dark, it is difficult for f, b, and n to calculate here X which fills xf(mod n) = b. It has appeared in the literature of above-mentioned IEEE that neither xB and n to XA nor wk is calculated. C is made variable, and key delivery can be performed even if it makes it notify a partner. It was shown that key delivery can be performed by the above only by each user having only e common to his secret integer S and all the members, c, alpha, and n. (EXAMPLE) Drawing 2 is a lineblock diagram showing the 1st example of the present invention. 201 is a terminal, and it is a personal computer, for example, and is the circuit by which 202 connects 203 with a card league, it is connected with a card, and 204 is connected with the communication partner. If a card is not read by others in contents, when there is a risk of anything being read although it is good, its eye See card (IC card) is good. A user is set to A. SA, e, c, alpha, and n are memorized by card 203, and it is read by terminal 201 through card reader 202. There are a card read-out program, a generating program of random number r, a calculation program of alphare and SA-alpha rc, a transceiver program with a transmitting partner, etc. in terminal 201. The work which a terminal should make in Salary is done a flow chart, and it is shown in Drawing 3 (a) and (b). If key delivery processing shown in Drawing 3 (a) requires, random number r will be generated first, SA, e, c, alpha, and n will be read from a card, Jia and yA will be calculated, and it will send to the other party. Next, in Drawing 3 (b), if xB13'B is sent also from the other party, yBe/xBC (mod n) will be calculated, and if equal to IDH, let wk= xBr (mod n) be a data encryption key. If not equal, key delivery processing is stopped. Also when XB and yB are sent from the other party and there is no rice, key delivery processing is stopped. When it stops, a retry or alarm is taken out and it notifies also to a mating terminal. One copy or all of work in a terminal is not soft, and it may perform them by exclusive Hurd. The form included in terminal 201 is also available for card reader 202 at all. the block diagram in which Drawing 4 shows the 2nd example of the present invention - it is. In Drawing 4, it has realized as a board which connects a present invention device to terminal unit 401. The random number generator with which 404 generates random numbers r and t, the exponentiation surplus circuit where 405 calculates an exponentiation surplus, ROM and 403 406 memorizes a multiplication-and-division circuit, 407 memorizes a microprocessor, and 402 has remembered the microprocessor, the program of 407, etc. to be are RAM of workspace , of microprocessor 407. Although public information e, c, and alpha and n are memorized to R and OM 402, secret information SA is included in multiplication-and-division circuit 406, and performs the multiplication and division in yA=SA-alpha" (tnod n) in multiplication-and-division circuit 406. Microprocessor 407 controls the work shown in Drawing 3. The latter can be substituted for this microprocessor 407 when the microprocessor in terminal unit 401 can be used. d, p (as long as 1 distributes s, e, c, alpha, and n to everybody, it may become unnecessary and it may discard.) which were used in the above explanation when creating s, e, c, alpha, and n, Even if yAe/XAC (modn) is not completely in agreement with ■DA, it should be just alike. When those who do not know SA make XA+yA, yAe/XAC (modn) becomes a random number and ■DA is because Mostlys completely differ. It is [ anything which can specify user A ] good, even if it does not become settled as ID and Also - and is not address 0 name. Although S, C, e, C, and n were explained as an integer, the argument completely same also as origin of a limited object is materialized. all of these change are boiled and contained in the present invention. (EFFECT OF THE INVENTION) As explained to details above, if the present invention is used, each user will produce the effect that key delivery can be performed only by having one secret information and some public information.
[Brief Description of the Drawings]
The flow chart showing the work whose lineblock diagram for a figure for Drawing 1 to show an operation of the present invention and Drawing 2 to show the 1st example of the present invention and Drawing 3 (a) and (b) each terminal should form, and Drawing 4 are block diagrams showing the 2nd example. In a figure, 101 expresses the starting side user's processing and a 102 Ha starting side user's processing, and 201 is a cable which a terminal and 202 connect 203 to a card reader, it connects to a card, and 204 connects to an other party terminal. 401 -- as for a random number generator and 405, ROM and 403 are [ a multiplication-and-division circuit and 407 ] microprocessors an exponentiation surplus circuit and 406 RAM and 404 a terminal unit and 402. 2d-To death; Station ribs 2 figure
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JPH02130078A | Cited by | Japan | Search report |
| US11411744B2 | Cited by | United States of America | Search report |
11 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 19761086 | Japan | A | |
| 61197610 | – | – | – |
| JP19860197610 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| EP0257585A2 | European Patent Office (EPO) | A2 | |
| JPS6354037AThis record | Japan | A | |
| JPS6354038A | Japan | A | |
| EP0257585A3 | European Patent Office (EPO) | A3 | |
| US4876716A | United States of America | A | |
| CA1279709C | Canada | C | |
| JPH0456501B2 | Japan | B2 | |
| JPH0456502B2 | Japan | B2 | |
| EP0257585B1 | European Patent Office (EPO) | B1 | |
| DE3782780D1 | Germany | D1 | |
| DE3782780T2 | Germany | T2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY |
Numbers
- Publication
- 63-54037
- Publication, DOCDB
- S6354037
- Publication, EPODOC
- JPS6354037
- Application
- 61197610
- Application, DOCDB
- 19761086
- Application, EPODOC
- JP19860197610
Titles2
- English
- KEY DISTRIBUTING DEVICE
- Japanese
- 【発明の名称】キ-配送装置
Classification
- IPC, 1
- H04L9 08