Key distribution system
Abstract
It was not possible to determine a clone source of unauthorized receiver devices. A key distribution system (1) of the present invention comprises a communication path (10), a key issuance center (11), a server (12), and a plurality of receiver devices (13a-13n). The key issuance center (11) distributes, to the server (12), a system private variable group set (SPGS) that is information necessary for distributing a shared key (SK) to the receiver devices (13a-13n), while distributing, to the plurality of receiver devices (13a-13n), an individual information group (EMMG) necessary for receiving the shared key (SK) from the server (12). The server (12) produces the shared key (SK), also produces, based on the shared key (SK) and system private variable group set (SPGS), a common information (ECM), and then distributes the common information (ECM) to the plurality of receiver devices (13a-13n). The receiver devices (13a-13n) acquire, based on the individual information group (EMMG) and common information (ECM), the shared key (SK) and output it to the exterior.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
33 claims: 30 independent, 3 dependent
- 1請求の範囲 共有鍵を配信する鍵配信システムであって、 前記鍵配信システムは、 前記共有鍵を基に共通情報を生成し、前記共通情報を配信するサーバと、 前記共通情報及び個別中間鍵群集合を基に、前記共有鍵を取得する複数の受信 装置と、から構成され、 前記受信装置は、一以上のシステム秘密変数群に基づく一以上の個別中間鍵か らなる個別中間鍵群を複数含む前記個別中間鍵群集合を少なくとも異なる二種類以 上含む複数の前記個別中間鍵群集合の中から、 V、ずれか一つの前記個別中間鍵 群集合が予め与えられており、 前記サーバと前記受信装置のそれぞれは通信路を介して通信可能であって、 前記サーバは、 前記共有鍵を格納する共有鍵格納部と、 予め与えられた一以上の前記システム秘密変数群カゝらなるシステム秘密変数群集 合を格納するシステム秘密変数群格納部と、 前記共有鍵を基に、前記共通情報を生成する複数の共通情報生成部と、 複数の前記共通情報生成部の中から一つを選択する共通情報生成部選択部と、 前記共通情報を複数の前記受信装置に同時に、または、個別に配信する共通情 報配信部と、を備え、 前記複数の共通情報生成部は、各々、共通情報生成方法が異なり、前記共通情 報生成方法を使用して、前記システム秘密変数群集合及び前記共有鍵に基づき、 鍵更新データを作成し、前記共通情報生成方法に対応付けられた共通情報識別子 及び前記鍵更新データを含む前記共通情報を生成し、 前記受信装置は、 前記共通情報を受信する共通情報受信部と、 複数の共通情報生成方法の各々に対応する前記個別中間鍵群からなる前記個別 中間鍵群集合を格納する個別中間鍵群格納部と、 複数の前記共通情報生成部に対応する複数の共有鍵取得部と、 複数の前記共有鍵取得部の中から一つを選択する共有鍵取得部選択部と、を備 え、 前記共有鍵取得部選択部は、前記共通情報受信部で受信した前記共通情報に含 まれる前記共通情報識別子に基づき、 前記複数の共有鍵取得部の中から一つを選択し、 前記共有鍵取得部は、前記共通情報識別子に対応した共有鍵取得方法と前記個 別中間鍵群に基づき、前記共通情報を使用して、前記共有鍵を取得すること を特徴とする鍵配信システム。 複数の前記共通情報生成方法は、第一共通情報生成方法を含み、 複数の前記共有鍵取得方法は、前記第一共通情報生成方法と対となる第一共有 鍵取得方法を含み、 前記システム秘密変数群集合は、一以上の第一システム秘密変数カゝら成る第一シ ステム秘密変数群を含み、 前記個別中間鍵群集合は、前記第一システム秘密変数群及び一以上の第一個別 中間鍵生成式に基づき生成される、一以上の第一個別中間鍵から成る第一個別中 間鍵群を含み、 前記サーバには、一以上の時変変数生成式及び一以上のサーバ共通中間鍵生 成式が予め与えられており、 前記受信装置のそれぞれには、一以上の受信装置共通中間鍵生成式が予め与え られており、 前記第一共通情報生成方法は、 一以上の乱数力 なる乱数群を生成し、前記乱数群及び前記第一システム秘密変 数群及び前記時変変数生成式を基に、一以上の時変変数から成る時変変数群を生 成し、前記第一システム秘密変数群及び前記乱数群及び前記サーバ共通中間鍵生 成式を基に、共通中間鍵を生成し、 前記共通中間鍵を基に、前記共有鍵を暗号化して、暗号化共有鍵を生成し、 前記鍵更新データは、前記時変変数群及び前記暗号化共有鍵を含む、方法であ り、 前記第一共有鍵取得方法は、 前記時変変数群及び前記第一個別中間鍵群及び前記受信装置共通中間鍵生成 式を基に、前記共通中間鍵を生成し、 前記共通中間鍵を基に、前記暗号化共有鍵の復号化を行い、前記共有鍵を取得 する方法であることを特徴とする、請求項 1に記載の鍵配信システム。 前記サーバには、前記複数の個別中間鍵群集合の中から、いずれか一つの前記 個別中間鍵群集合が予め与えられており、 前記サーバは、予め与えられた前記個別中間鍵群集合を格納する個別中間鍵群 集合格納部と、を備え、 複数の前記共通情報生成方法は、第一共通情報生成方法を含み、 複数の前記共有鍵取得方法は、前記第一共通情報生成方法と対となる第一共有 鍵取得方法を含み、 前記システム秘密変数群集合は、一以上の第一システム秘密変数カゝら成る第一シ ステム秘密変数群を含み、 前記個別中間鍵群集合は、前記第一システム秘密変数群及び一以上の第一個別 中間鍵生成式に基づき生成される、一以上の第一個別中間鍵から成る第一個別中 間鍵群を含み、 前記サーバには、一以上の時変変数生成式及び一以上の受信装置共通中間鍵 生成式が予め与えられており、 前記受信装置のそれぞれには、前記受信装置共通中間鍵生成式が予め与えられ ており、 前記第一共通情報生成方法は、 一以上の乱数力 なる乱数群を生成し、前記乱数群及び前記第一システム秘密変 数群及び前記時変変数生成式を基に、一以上の時変変数から成る時変変数群を生 成し、前記第一個別中間鍵群及び前記時変変数群及び前記受信装置共通中間鍵 生成式を基に、共通中間鍵を生成し、 前記共通中間鍵を基に、前記共有鍵を暗号化して、暗号化共有鍵を生成し、 前記鍵更新データは、前記時変変数群及び前記暗号化共有鍵を含む、方法であ り、 前記第一共有鍵取得方法は、 前記時変変数群及び前記第一個別中間鍵群及び前記受信装置共通中間鍵生成 式を基に、前記共通中間鍵を生成し、 前記共通中間鍵を基に、前記暗号化共有鍵の復号化を行い、前記共有鍵を取得 する方法であることを特徴とする、請求項 1に記載の鍵配信システム。
- 2[4] 複数の前記共通情報生成方法は、第二共通情報生成方法を含み、 複数の前記共有鍵取得方法は、前記第二共通情報生成方法と対となる第二共有 鍵取得方法を含み、 前記システム秘密変数群集合は、複数の第二システム秘密鍵から成る第二システ ム秘密鍵群を含み、 前記個別中間鍵群集合は、複数の前記第二システム秘密鍵の!、ずれか一以上の 前記第二システム秘密鍵から成る第二個別中間鍵群を含み、 前記第二共通情報生成方法は、 前記第二システム秘密鍵群に含まれる一以上の前記第二システム秘密鍵のそれぞ れを基に、前記共有鍵の暗号化を行い、複数の暗号化共有鍵を生成し、 前記複数の暗号化共有鍵を結合した暗号化共有鍵群を生成し、 前記鍵更新データは、前記暗号化共有鍵群を含む、方法であり、 前記第二共有鍵取得方法は、 前記鍵更新データに含まれる前記暗号化共有鍵群の中から、前記第二個別中間 鍵群に含まれる前記第二システム秘密鍵のいずれかに対応する一つの前記暗号ィ匕 共有鍵を選定し、 前記第二システム秘密鍵を基に、選定した前記暗号化共有鍵を復号化すること〖こ より、前記共有鍵を取得する方法であることを特徴とする、請求項 1記載の鍵配信シ ステム。
- 3[5] 前記個別中間鍵群集合は、複数の前記第二システム秘密鍵の!、ずれか一つの前 記第二システム秘密鍵から成る第二個別中間鍵群を含み、 前記第二共通情報生成方法は、 前記第二システム秘密鍵群に含まれる複数の前記第二システム秘密鍵のそれぞれ を基に、前記共有鍵の暗号化を行い、複数の暗号化共有鍵を生成し、前記複数の 暗号ィ匕共有鍵を結合した暗号ィ匕共有鍵群を生成する方法であることを特徴とする、 請求項 4に記載の鍵配信システム。
- 4[6] 前記鍵配信システムは、さらに、前記通信路を介して前記受信装置のそれぞれに 接続され、個別情報群を配信する鍵発行センタと、を備え、 前記鍵発行センタは、 予め前記受信装置に与えられた一以上の個別鍵を格納する出力装置対応情報格 納部と、 前記個別情報を生成する複数の個別情報生成部と、 前記個別情報及び前記個別情報生成部に対応付けられた個別情報識別子の組 を二種類以上含む前記個別情報群を、複数の前記受信装置に同時に、または、個 別に配信する個別情報群配信部と、を備え、 前記個別情報生成部は、各々、個別情報生成方法が異なり、前記個別情報生成 方法を基に、前記個別情報識別子及び前記システム秘密変数群及び前記個別情報 を出力し、 前記受信装置は、 予め与えられた前記個別鍵を格納する個別鍵格納部と、 前記個別情報群を受信する個別情報群受信部と、 複数の前記個別情報生成部に対応する複数の個別中間鍵群取得部と、を備え、 前記個別情報受信部は、受信した前記個別情報群に含まれる前記個別情報識別 子に基づき、複数の前記個別中間鍵群取得部のそれぞれへ、前記個別情報識別子 に対応する前記個別情報を出力し、 前記個別中間鍵取得部は、前記個別情報識別子に対応した個別中間鍵取得方法 を使用して、前記個別情報及び前記個別鍵に基づき、前記個別中間鍵群を取得す ることを特徴とする、請求項 1記載の鍵配信システム。
- 5[7] 前記複数の個別情報生成部は、さらに、前記システム秘密変数群を生成し、 前記鍵発行センタは、 前記システム秘密変数群及び前記個別情報生成部に対応付けられた前記個別情 報識別子の組を二種類以上含む前記システム秘密変数群集合を前記サーバへ配 布するシステム秘密変数群集合送信部と、を備え、 前記サーバは、 配布された前記システム秘密変数群集合を前記システム秘密変数群格納部へ格 納するシステム秘密変数群集合受信部と、を備えることを特徴とする、請求項 6に記 載の鍵配信システム。
- 6[8] 前記鍵発行センタは、前記通信路を介して前記サーバに接続され、 前記システム秘密変数群集合送信部は、前記通信路を介して前記サーバへ前記 システム秘密変数群集合を配信し、前記システム秘密変数群集合受信部は、前記通 信路を介して前記鍵発行センタカゝら前記システム秘密変数群集合を受信することを 特徴とする、請求項 6記載の鍵配信システム。
- 7[9] 前記システム秘密変数群集合送信部は、可搬媒体へ前記システム秘密変数群集 合を記録し、前記システム秘密変数群集合受信部は、前記可搬媒体に記録された 前記システム秘密変数群集合を読み取ることを特徴とする、請求項 6記載の鍵配信 システム。
- 8[10] 前記鍵発行センタと前記サーバは、予めサーバ鍵を共有しているとし、前記システ ム秘密変数群集合送信部は、前記サーバ鍵を基に前記システム秘密変数群集合を 暗号化して、暗号化データを作成して、前記サーバへ配布し、前記システム秘密変 数群集合受信部は、配布された前記暗号ィ匕データを前記サーバ鍵を基に復号化し 、前記システム秘密変数群集合を取得することを特徴とする、請求項 7記載の鍵配信 システム。
- 9[11] 複数の前記個別情報生成方法は、第一個別情報生成方法を含み、 複数の前記個別中間鍵取得方法は、前記第一個別情報生成方法と対となる第一 個別中間鍵群取得方法を含み、 前記鍵発行センタは、予め与えられる期間鍵及び前記期間鍵に対応付けられた前 記第一システム秘密変数群及び前記期間鍵に対応付けられた期間識別子の組を一 種類以上格納する期間情報格納部と、を備え、 前記受信装置の前記個別鍵格納部のそれぞれは、前記期間鍵を基に、前記第一 個別中間鍵群が暗号化されることにより生成された暗号ィ匕第一個別中間鍵群及び前 記期間鍵に対応付けられた前記期間識別子の組を一種類以上格納しており、 前記第一個別情報生成方法は、 前記期間情報格納部の中から、一組の前記期間鍵及び前記第一システム秘密変 数群及び前記期間識別子を選択し、 各々の前記個別鍵を基に、前記期間鍵を暗号化し、複数の暗号化期間鍵を生成し 前記個別情報群は、前記複数の暗号化期間鍵を結合した暗号化期間鍵群及び前 記期間識別子からなる第一個別情報を含み、 前記第一個別中間鍵群取得方法は、 前記個別鍵に基づき、前記第一個別情報に含まれる前記複数の暗号化期間鍵の いずれか一つの前記暗号ィ匕期間鍵を復号ィ匕し、前記期間鍵を取得し、 前記個別鍵格納部に含まれる一以上の前記暗号化第一個別中間鍵群の中から、 前記期間識別子に対応付けられた前記暗号化第一個別中間鍵群を一つ選択し、 前記期間鍵に基づき、前記暗号化第一個別中間鍵群を復号化することによって、 前記第一個別中間鍵群を取得する方法であることを特徴とする、請求項 6記載の鍵 配信システム。 複数の前記個別情報生成方法は、第二個別情報生成方法を含み、 複数の前記個別中間鍵取得方法は、前記第二個別情報生成方法と対となる第二 個別中間鍵群取得方法を含み、 前記第二個別情報生成方法は、 各々の前記個別鍵に対して、複数の前記第二システム秘密鍵のいずれか一つを 選定し、各々の前記個別鍵に基づき、選定した前記第二システム秘密鍵を暗号化し 、複数の暗号化第二システム秘密鍵を生成し、 前記個別情報群は、前記複数の暗号化第二システム秘密鍵を結合した暗号化第 二システム秘密鍵群を含む第二個別情報を含み、 前記第二個別中間鍵群取得方法は、 前記第二個別情報に含まれる前記複数の暗号化第二システム秘密鍵の中から、 前記個別鍵に対応する前記暗号化第二システム秘密鍵を一つ選定し、前記個別鍵 に基づき、選定した前記暗号ィ匕第二システム秘密鍵を復号ィ匕することによって、前記 第二システム秘密鍵を取得し、その前記第二システム秘密鍵を前記第二個別中間 鍵群とする方法であることを特徴とする、請求項 6記載の鍵配信システム。
- 10[13] 前記個別中間鍵生成式には、少なくとも、加算演算及び乗算演算が含まれている ことを特徴とする、請求項 2記載の鍵配信システム。
- 11[14] 前記時変変数生成式には、少なくとも、加算演算及び乗算演算が含まれていること を特徴とする、請求項 2記載の鍵配信システム。
- 12[15] 前記サーバ共通中間鍵生成式には、少なくとも、加算演算及び乗算演算が含まれ て 、ることを特徴とする、請求項 2記載の鍵配信システム。
- 13[16] 前記受信装置共通中間鍵生成式には、少なくとも、加算演算及び乗算演算が含ま れて ヽることを特徴とする、請求項 2記載の鍵配信システム。
- 14[17] 前記第二システム秘密鍵群は、 10個の第二システム秘密鍵から成ることを特徴と する、請求項 4記載の鍵配信システム。
- 15[18] 共有鍵を配信するサーバと、前記共有鍵を受信する複数の受信装置と、を備える 鍵配信システムにおける受信装置であって、 前記受信装置は、 外部から共通情報を受信する共通情報受信部と、 複数の共有鍵取得方法の各々に対応する個別中間鍵群力 成る個別中間鍵群集 合を格納する個別中間鍵群格納部と、 複数の前記共有鍵取得方法に対応する複数の共有鍵取得部と、 複数の前記共有鍵取得部の中から一つを選択する共有鍵取得部選択部と、を備 え、 前記共有鍵取得部選択部は、前記共通情報受信部で受信した前記共通情報に含 まれる共通情報識別子に基づき、前記共有鍵取得部を一つ選択し、 前記共有鍵取得部は、前記共通情報識別子に対応した前記共有鍵取得方法及び 前記個別中間鍵群に基づき、前記共通情報を使用して、前記共有鍵を取得すること を特徴とする受信装置。
- 16[19] 複数の前記共有鍵取得方法は、第一共有鍵取得方法を含み、 前記個別中間鍵群集合は、一以上の第一個別中間鍵から成る第一個別中間鍵群 を含み、 前記受信装置のそれぞれには、一以上の受信装置共通中間鍵生成式が予め与え られており、 前記共通情報は、時変変数群及び暗号化共有鍵からなる第一共通情報を含み、 前記第一共有鍵取得方法は、 前記第一共通情報に含まれる前記時変変数群及び前記第一個別中間鍵群及び 前記受信装置共通中間鍵生成式を基に、前記共通中間鍵を生成し、 前記共通中間鍵を基に、前記暗号化共有鍵の復号化を行い、前記共有鍵を取得 する方法であることを特徴とする、請求項 18記載の受信装置。
- 17[20] 複数の前記共有鍵取得方法は、第二共有鍵取得方法を含み、 前記個別中間鍵群集合は、複数の第二システム秘密鍵の 、ずれか一以上の前記 第二システム秘密鍵から成る第二個別中間鍵群を含み、 前記共通情報は、前記複数の第二システム秘密鍵の!、ずれか一以上の前記第二 システム秘密鍵のそれぞれを基に、前記共有鍵を暗号化することで生成されたー以 上の暗号化共有鍵を含む暗号化共有鍵群からなる第二共通情報を含み、 前記第二共有鍵取得方法は、 前記共通第二共通情報に含まれる前記暗号化共有鍵群の中から、前記第二個別 中間鍵群に含まれる前記第二システム秘密鍵のいずれかに対応する一つの前記暗 号化共有鍵を選定し、 前記第二システム秘密鍵を基に、選定した前記暗号化共有鍵を復号化すること〖こ より、前記共有鍵を取得する方法であることを特徴とする、請求項 18記載の受信装 置。
- 18[21] 前記個別中間鍵群集合は、複数の前記第二システム秘密鍵の!、ずれか一つの前 記第二システム秘密鍵から成る第二個別中間鍵群を含むことを特徴とする、請求項 2 0記載の受信装置。
- 19[22] 前記鍵配信システムは、さらに、前記通信路を介して前記受信装置のそれぞれとサ ーバに接続され、個別情報群を配信する鍵発行センタと、を備え、 前記受信装置は、 予め与えられた個別鍵を格納する個別鍵格納部と、 外部から前記個別情報群を受信する個別情報群受信部と、 複数の個別中間鍵取得方法に対応する複数の個別中間鍵群取得部と、を備え、 前記個別情報受信部は、受信した前記個別情報群に含まれる個別情報識別子に 基づき、複数の前記個別中間鍵群取得部のそれぞれへ、前記個別情報群に含まれ 前記個別情報識別子に対応する前記個別情報を出力し、 前記個別中間鍵取得部は、前記個別情報識別子に対応した前記個別中間鍵取得 方法を使用して、前記個別情報及び前記個別鍵に基づき、前記個別中間鍵群を取 得することを特徴とする、請求項 18記載の受信装置。
- 20[23] 複数の前記個別中間鍵取得方法は、第一個別中間鍵群取得方法を含み、 前記受信装置の前記個別鍵格納部のそれぞれは、期間鍵を基に、第一個別中間 鍵群を暗号ィ匕することにより生成される暗号ィ匕第一個別中間鍵群及び前記期間鍵に 対応付けられた期間識別子の組を一種類以上格納しており、 前記個別情報群は、それぞれの前記個別鍵を基に前記期間鍵を暗号化して生成 された複数の暗号ィ匕期間鍵を含む暗号ィ匕期間鍵群及び前記期間識別子カゝらなる第 一個別情報を含み、 前記第一個別中間鍵群取得方法は、 前記個別鍵に基づき、前記第一個別情報に含まれる前記複数の暗号化期間鍵の いずれか一つの前記暗号ィ匕期間鍵を復号ィ匕し、前記期間鍵を取得し、 前記個別鍵格納部に含まれる一以上の前記暗号化第一個別中間鍵群の中から、 前記期間識別子に対応付けられた前記暗号化第一個別中間鍵群を一つ選択し、 前記期間鍵に基づき、前記暗号化第一個別中間鍵群を復号化することによって、 前記第一個別中間鍵群を取得する方法であることを特徴とする、請求項 19記載の受 信装置。
- 21[24] 複数の前記個別中間鍵取得方法は、第二個別中間鍵群取得方法を含み、 前記個別情報群は、それぞれの前記個別鍵を基に、前記第二システム秘密鍵のい ずれ力を暗号ィ匕することによって生成された複数の暗号ィ匕第二システム秘密鍵から なる暗号化第二システム秘密鍵群を含む第二個別情報を含み、 前記第二個別中間鍵群取得方法は、 前記第二個別情報に含まれる前記複数の暗号化第二システム秘密鍵の中から、 前記個別鍵に対応する前記暗号化第二システム秘密鍵を一つ選定し、前記個別鍵 に基づき、選定した前記暗号ィ匕第二システム秘密鍵を復号ィ匕することによって、前記 第二システム秘密鍵を取得し、その前記第二システム秘密鍵を前記第二個別中間 鍵群とする方法であることを特徴とする、請求項 20記載の受信装置。
- 22[25] 前記受信装置共通中間鍵生成式には、少なくとも、加算演算及び乗算演算が含ま れていることを特徴とする、請求項 19記載の受信装置。
- 23[26] 共有鍵を配信するサーバと、通信路を介して接続され、前記共有鍵を受信する処 理をコンピュータに実行させるプログラムであって、 外部力 共通情報を受信するステップと、 複数の共有鍵取得方法の各々に対応する個別中間鍵群力 成る個別中間鍵群集 合を格納するステップと、 複数の前記共有鍵取得方法に対応する複数の共有鍵取得ステップと、 前記共通情報受信部で受信した前記共通情報に含まれる共通情報識別子に基づ き、前記共有鍵取得部を一つ選択するステップと、をコンピュータに実行させ、 前記共有鍵取得ステップは、前記共通情報識別子に対応した前記共有鍵取得方 法及び前記個別中間鍵群に基づき、前記共通情報を使用して、前記共有鍵を取得 することを特徴とするプログラム。
- 24[27] 複数の前記共有鍵取得方法は、第一共有鍵取得方法を含み、 前記個別中間鍵群集合は、一以上の第一個別中間鍵から成る第一個別中間鍵群 を含み、 前記プログラムのそれぞれには、一以上の受信装置共通中間鍵生成式が予め与 えられており、 前記共通情報は、時変変数群及び共通中間鍵を基に前記共有鍵を暗号化するこ とにより生成される暗号化共有鍵からなる第一共通情報を含み、 前記第一共有鍵取得方法は、 前記第一共通情報に含まれる時変変数群、及び前記第一個別中間鍵群及び前記 受信装置共通中間鍵生成式を基に、前記共通中間鍵を生成し、 前記共通中間鍵を基に、前記暗号化共有鍵の復号化を行い、前記共有鍵を取得 する方法であることを特徴とする請求項 26記載のプログラム。
- 25[28] 複数の前記共有鍵取得方法は、第二共有鍵取得方法を含み、 前記個別中間鍵群集合は、複数の第二システム秘密鍵の 、ずれか一以上の前記 第二システム秘密鍵から成る第二個別中間鍵群を含み、 前記共通情報は、前記複数の第二システム秘密鍵の!、ずれか一以上の前記第二 システム秘密鍵を基に前記共有鍵を暗号ィ匕することにより生成される複数の暗号ィ匕 共有鍵からなる暗号化共有鍵群を含む第二共通情報を含み、 前記第二共有鍵取得方法は、 前記共通第二共通情報に含まれる前記暗号化共有鍵群の中から、前記第二個別 中間鍵群に含まれる前記第二システム秘密鍵のいずれかに対応する一つの前記暗 号化共有鍵を選定し、 前記第二システム秘密鍵を基に、選定した前記暗号化共有鍵を復号化すること〖こ より、前記共有鍵を取得する方法であることを特徴とする請求項 26記載のプログラム
- 26[29] 前記個別中間鍵群集合は、複数の第二システム秘密鍵の!、ずれか一つの前記第 二システム秘密鍵から成る第二個別中間鍵群を含むことを特徴とする請求項 28記載 のプログラム。
- 27[30] 前記受信装置共通中間鍵生成式には、少なくとも、加算演算及び乗算演算が含ま れていることを特徴とする請求項 27記載のプログラム。
- 28[31] 請求項 26記載のプログラムを記録した媒体。
- 29[32] 共有鍵を配信する鍵配信方法であって、 前記鍵配信方法は、 前記共有鍵を基に共通情報を生成し、前記共通情報を配信する鍵配信ステップと 前記共通情報及び個別中間鍵群集合を基に、前記共有鍵を取得する複数の鍵受 信ステップと、から構成され、 前記鍵受信ステップには、一以上のシステム秘密変数群に基づく一以上の個別中 間鍵からなる個別中間鍵群を複数含む前記個別中間鍵群集合を少なくとも異なる二 種類以上含む複数の前記個別中間鍵群集合の中から、 V、ずれか一つの前記個別 中間鍵群集合が予め与えられており、 前記鍵配信ステップは、 前記共有鍵を格納するステップと、 予め与えられた一以上のシステム秘密変数群カゝらなるシステム秘密変数群集合を 格納するステップと、 前記共有鍵を基に、前記共通情報を生成する複数の共通情報生成ステップと、 複数の前記共通情報生成ステップの中から一つを選択するステップと、 前記共通情報を複数の前記受信装置に同時に、または、個別に配信するステップ と、を含み、 前記複数の共通情報生成ステップは、各々、共通情報生成方法が異なり、前記共 通情報生成方法を使用して、前記システム秘密変数群集合及び前記共有鍵に基づ き、鍵更新データを作成し、前記共通情報生成方法に対応付けられた共通情報識 別子及び前記鍵更新データを含む前記共通情報を生成し、 前記鍵受信ステップは、 前記共通情報を受信するステップと、 複数の共通情報生成方法の各々に対応する前記個別中間鍵群からなる前記個別 中間鍵群集合を格納するステップと、 複数の前記共通情報生成部に対応する複数の共有鍵取得ステップと、 前記共通情報受信部で受信した前記共通情報に含まれる前記共通情報識別子に 基づき、複数の前記共有鍵取得ステップの中から一つを選択するステップと、を含み 前記共有鍵取得ステップは、前記共通情報識別子に対応した共有鍵取得方法と 前記個別中間鍵群に基づき、前記共通情報を使用して、前記共有鍵を取得すること を特徴とする鍵配信方法。
- 30[33] 複数の前記共通情報生成方法は、第一共通情報生成方法を含み、 複数の前記共有鍵取得方法は、前記第一共通情報生成方法と対となる第一共有 鍵取得方法を含み、 前記システム秘密変数群集合は、一以上の第一システム秘密変数カゝら成る第一シ ステム秘密変数群を含み、 前記個別中間鍵群集合は、前記第一システム秘密変数群及び一以上の第一個別 中間鍵生成式に基づき生成される、一以上の第一個別中間鍵から成る第一個別中 間鍵群を含み、 前記鍵配信ステップには、一以上の時変変数生成式及び一以上のサーバ共通中 間鍵生成式が予め与えられており、 前記鍵受信ステップのそれぞれには、一以上の受信装置共通中間鍵生成式が予 め与えられており、 前記第一共通情報生成方法は、 一以上の乱数力 なる乱数群を生成し、前記乱数群及び前記第一システム秘密変 数群及び前記時変変数生成式を基に、一以上の時変変数から成る時変変数群を生 成し、前記第一システム秘密変数群及び前記乱数群及び前記サーバ共通中間鍵生 成式を基に、共通中間鍵を生成し、 前記共通中間鍵を基に、前記共有鍵を暗号化して、暗号化共有鍵を生成する方 法であり、 前記鍵更新データは、前記時変変数群及び前記暗号化共有鍵を含み、 前記第一共有鍵取得方法は、 前記時変変数群及び前記第一個別中間鍵群及び前記受信装置共通中間鍵生成 式を基に、前記共通中間鍵を生成し、 前記共通中間鍵を基に、前記暗号化共有鍵の復号化を行い、前記共有鍵を取得 する方法であることを特徴とする、請求項 32記載の鍵配信方法。
- 31[34] 前記鍵配信ステップは、前記複数の前記個別中間鍵群集合の中から、 V、ずれか一 つの前記個別中間鍵群集合が予め与えられており、 前記鍵受信ステップは、予め与えられた前記個別中間鍵群集合を格納するステツ プと、を含み、 複数の前記共通情報生成方法は、第一共通情報生成方法を含み、 複数の前記共有鍵取得方法は、前記第一共通情報生成方法と対となる第一共有 鍵取得方法を含み、 前記システム秘密変数群集合は、一以上の第一システム秘密変数カゝら成る第一シ ステム秘密変数群を含み、 前記個別中間鍵群集合は、前記第一システム秘密変数群及び一以上の第一個別 中間鍵生成式に基づき生成される、一以上の第一個別中間鍵から成る第一個別中 間鍵群を含み、 前記サーバには、一以上の時変変数生成式及び一以上の共通中間鍵生成式が 予め与えられており、 前記鍵受信ステップのそれぞれには、前記共通中間鍵生成式が予め与えられてお り、 前記第一共通情報生成方法は、 一以上の乱数力 なる乱数群を生成し、前記乱数群及び前記第一システム秘密変 数群及び前記時変変数生成式を基に、一以上の時変変数から成る時変変数群を生 成し、前記第一個別中間鍵群及び前記乱数群及び前記サーバ共通中間鍵生成式 を基に、共通中間鍵を生成し、 前記共通中間鍵を基に、前記共有鍵を暗号化して、暗号化共有鍵を生成する方 法であり、 前記鍵更新データは、前記時変変数群及び前記暗号化共有鍵を含み、 前記第一共有鍵取得方法は、 前記時変変数群及び前記第一個別中間鍵群及び前記共通中間鍵生成式を基に 、前記共通中間鍵を生成し、 前記共通中間鍵を基に、前記暗号化共有鍵の復号化を行い、前記共有鍵を取得 する方法であることを特徴とする、請求項 33記載の鍵配信方法。
- 32[35] 複数の前記共通情報生成方法は、第二共通情報生成方法を含み、 複数の前記共有鍵取得方法は、前記第二共通情報生成方法と対となる第二共有 鍵取得方法を含み、 前記システム秘密変数群集合は、複数の第二システム秘密鍵から成る第二システ ム秘密鍵群を含み、 前記個別中間鍵群集合は、複数の前記第二システム秘密鍵の!、ずれか一以上の 前記第二システム秘密鍵から成る第二個別中間鍵群を含み、 前記第二共通情報生成方法は、 前記第二システム秘密鍵群に含まれる一以上の前記第二システム秘密鍵のそれぞ れを基に、前記共有鍵の暗号化を行い、複数の暗号化共有鍵を生成し、 前記複数の暗号化共有鍵を結合した暗号化共有鍵群を生成する方法であり、 前記鍵更新データは、前記暗号化共有鍵群を含み、 前記第二共有鍵取得方法は、 前記鍵更新データに含まれる前記暗号化共有鍵群の中から、前記第二個別中間 鍵群に含まれる前記第二システム秘密鍵のいずれかに対応する一つの前記暗号ィ匕 共有鍵を選定し、 前記第二システム秘密鍵を基に、選定した前記暗号化共有鍵を復号化すること により、前記共有鍵を取得する方法であることを特徴とする、請求項 32記載の鍵配 信方法。
- 33[36] 前記個別中間鍵群集合は、複数の前記第二システム秘密鍵の!、ずれか一つの前 記第二システム秘密鍵から成る第二個別中間鍵群を含むことを特徴とする、請求項 3 5記載の鍵配信方法。
Independent claims33
427 paragraphs in 1 section, as filed
0001Specification
0002Key distribution system
0003Technical field
0004[0001] The present invention is making individual information required in order to be related with the key distribution system which distributes a share key to a plurality of receiving sets and to acquire a share key especially for every receiving set, and is a receiving set. Even if the information currently assigned is revealed, it is the art which can pursue the receiving set of the disclosure origin. It is related.
0005Background art
0006[0002] following on the spread of the high-speed channels represented by ADSL, optical fiber 1, etc. -- digitization -- Service which provides contents, such as Was done music and an image, via a channel is offered briskly. To -- it became like. Cong represented by the illegal copy etc. with the spread of such services The protection-of-copyrights method which prevents a Ten illegal use is needed. Generally, it is this Co. Encoding technology is used for the protection-of-copyrights method which prevents a Tent illegal use. That is, code Y of the digital contents is carried out using a certain contents code B key, a channel is passed, and it is Arrangement. Cloth is carried out, Contents decoding B key corresponding to the contents code B key can be given, and they are and Reception. Only a device decrypts the enciphered contents and it is reproduction of the original digital contents. It can carry out.
0007[0003] By the way, contents decoding B key given to the receiving set is usually held secretly. Power to which the aggressor is given [ all the / receiving set ] by the inaccurate analysis of the device, etc. Tent decoding B key may be acquired. A certain receiving set is given and they are and To Cong Teng. When a List decryption key carries out in - Leakage, an aggressor is Cong Teng in whom pursuit of this disclosure origin is impossible. The inaccurate receiving set which performs decoding Y of digital contents using List decoding B key is created, and it is Co. There is a possibility of performing the illegal use of Tent. Means which prevents such a contents illegal use As one, it is a receiving set of a revealing agency by giving an individual key for every receiving set. The system which pursues possible can be considered. Broadcast which sends the same data as all the receiving sets In office type contents distribution, it compares as a method which prevents a contents illegal use. There is a key distribution system indicated in The following nonpatent literature 1. [0004] Drawing 53 shows the conventional key distribution system indicated in nonpatent literature 1. Figure 5 Key issue center 91 which channel 90 mentions below in 3, server 92, and a plurality of reception Device 93a -- It is the channel which has connected 93 eta and they are Network, such as the Internet and a network. It realizes by The. Key issue center 91 and a plurality of receiving sets 93a -- All of 93 eta Group, beforehand -- one individual key IKa' -- sharing - -iotakappaeta -- for example, key issue center 91 and reception device 93a -- individual key IKa, Key issue center 91 and receiving set 93b are key issue about individual key 1Kb. Center 91 and receiving set 93 eta assume that individual key IKn is shared beforehand.
0008[0005] They are all the receiving sets 93a first. -- How to share common intermediate key SMK between 93 eta is explained. Key issue center 91 creates common intermediate key SMK, and transmits the common intermediate key SMK to The - Ba 92. next, each receiving set 93a -- it has shared with 93 eta beforehand -- individual Key IKa, The common intermediate key SMK is enciphered based on 1Kb and - - - IKn, Each of that cryptogram E nc (IKa, SMK) and Enc (1Kb, SMK) - - -, It is a code about the value which combined Enc (IKn, SMK). As-izing common intermediate key group ENCSMKG=Enc (IKaゝ SMK) | | Enc (1Kb, SMK) | | - - - Enc (IKn, SMK) A plurality of receiving sets 93a -- It distributes towards 93 eta. When "| I" is a joint sign and Enc (kappa, P) carries out code Y of Plaintext P here using code B key K A cryptogram is meant. In nonpatent literature 1, they are individual information (EMM) and individual key IKa about the thing of encryption common intermediate key group ENCSM KG. -- It is [ a master key (km) and ] among common about the thing of IKn. Call between key SMK a work key (Kw), respectively! /, To. a plurality of receiving sets 93a which received encryption common intermediate key group EN CSMKG -- 93 eta extracting the cryptogram corresponding to the individual key which self has out of encryption common intermediate key group ENCSM KG, and being based on an individual key -- the -- A cryptogram is decrypted and common intermediate key SMK is acquired. carrying-out-like this * This -- all the Receiving device 93a -- Common common intermediate key SMK is sharable by 93 eta.
0009[0006] Next, all the receiving sets 93a -- When it is 93 eta and decoding Y of the contents etc. is carried out, for example, it uses. How to share share key SK is explained. Server 92 creates share key SK and is receiving set 93a. -- It is based on common intermediate key SMK currently shared with 93 eta, It is dark about the share key SK. It item-izes, the cryptogram Enc (SMK, SK) is used as encryption share key ENCSK, and they are a plurality of Receiving. Place 93a -- It distributes towards 93 eta. A plurality of Receiving which received code Common key ENCSK Place 93a -- 93 eta is based on common intermediate key SMK, and is a line about decryption of encryption share key ENCSK. It is and acquires share key SK. carrying-out-like this * This -- all the receiving sets 93a -- Both common to 93 eta Owner key SK is sharable. in addition -- in nonpatent literature 1 -- thing of share key SK the thing of scramble key (Ks) code Common key ENCSK -- share information (ECM) -- it -- It is by Call. It is code Common key ENCSK based on share key SK with new server 92. It generates and they are a plurality of receiving sets 93a about the code Common key ENCSK. -- It distributes to 93 eta. Therefore, it can also update to new share key SK.
0010[0007] in addition, by updating common intermediate key SMK, key issue center 91 should cancel the receiving set which has a certain specific individual key, and acquires share key SK -- it also comes out and to make it like It comes. the case where the receiving set which has an individual key of receiving set 93a is cancelled here -- just -- Explanation is carried out. First, common intermediate key SMK is newly created and it is a sir about the common intermediate key SMK. It transmits to Ba 92. Then, all except individual key IKa currently beforehand shared with receiving set 93a Individual key 1Kb -- Each of IKn is used, They are line ! and each of its cryptogram Enc (1Kb, SMK) about encryption of the common intermediate key SMK, the value which combined 1 and Enc (IKn, SMK) -- encryption a connoisseur -- as intermediate key group ENCSMKG=Enc (IKb, SMK) || - -'Enc (IKn, SMK) -- double -- receiving set 93a of a number -- It distributes to 93 eta. By doing so, it is reception of those other than receiving set 93a. Device 93b -- Power in which share key SK is obtained since common intermediate key SMK is acquirable in 93 eta in receiving set 93a, since common intermediate key SMK is unacquirable, share key SK is not obtained. It becomes. By doing in this way, cancelling a receiving set key issue center 91 It can do. Receiving sets 93b other than receiving set 93a -- Also when cancelling 93 eta, it receives. Although it becomes the same operation as the case of device 93a, when carrying out code Y of the common intermediate key SMK, it uses. It differs in that an individual key changes.
0011[0008] In such a system, it is receiving set 93a by an aggressor. -- Any of 93 eta It is embedded at a receiving set. From the individual key currently embedded at the receiving set even if a To individual key is acquired unjustly and an aggressor makes the receiving set using the individual key to Leak Since the receiving set of Leak origin can be pursued, they are measures, such as cancellation of an object receiving set. It becomes possible to strike.
0012Nonpatent literature 1 : "Structure of digital broadcasting office system" Institute of Image Information and Television Engineers Editing Form publication office Nonpatent literature 2 : "Present age code theoretical" Shin-ichi Ikeno, Kenji Koyama collaboration Institute of Electronics, Information and Communication Engineers Editing Nonpatent literature 3: "THE ART OF COMPUTER PROGRAMMING Vol. 2 -- 1 -- I SBN 0-201-03822-6 written by SEMINUMERICAL ALGORITHMS DONALD E. KNUTH
0013The indication of an invention
0014Object of the Invention
0015[0009] Receiving set 93a -- It is embedded at which receiving set of 93 eta! / When a To individual key is acquired unjustly, the aggressor other than a method who stated at the point uses the individual key, and is common. Intermediate key SMK is acquired and the inaccurate receiving set which embedded the common intermediate key SMK is made. A case can be considered. With the conventional composition previously described to such an attack, common middle key SMK -- all the receiving sets 93a -- since it was a value common to 93 eta -- the inaccurate Receiving Are embedded at Place! Pursue the receiving set of a revealing agency from /Key (common intermediate key SMK). Do! /! /-- obtaining and having a subject -- I.
0016[0010] Key which can pursue the receiving set of a revealing agency even if the inaccurate receiving set which the present invention solves the above-mentioned subject and embedded the intermediate key by the aggressor is created It aims at providing a Trust system.
0017Means for solving problem
0018[0011] The invention in Claim 1 is a key distribution system which distributes a share key, and is said key distribution system, server which generates common information based on the above-mentioned share key, and distributes the above-mentioned common information When A plurality of Acceptance which acquire the above-mentioned share key based on the above-mentioned common information and an individual intermediate key group set It comprises Receiver and is the above-mentioned receiving set, It is based on one or more system secret variable groups. Above-mentioned individual intermediate key group set containing multiple individual intermediate key groups which consist of one or more individual intermediate keys From under several above-mentioned different individual intermediate key group sets at least included two or more kinds, ! /and gap One above-mentioned individual intermediate key group set is given beforehand, and they are the above-mentioned server and the above-mentioned receiving set. Via a channel, communication is possible and each is the above-mentioned server, The above-mentioned share key is stored. The share key storing part to carry out and the one or more above-mentioned system secret variable group power given beforehand Si System secret variable group storage which stores a stem secret variable group set, A plurality of common information generating parts which generate and the above-mentioned common information based on the above-mentioned share key, and a plurality of above-mentioned common information generating parts They are [ the common information generating part selecting part which chooses one from inside, and ] a plurality of above-mentioned Acceptance about the above-mentioned common information. It has a common information distribution part distributed to Receiver that it is simultaneous or individually, Respectively, common information generation methods differ and a plurality of above-mentioned common information generating parts are the above-mentioned common information generation methods. It is used, It is based on the above-mentioned system secret variable group set and the above-mentioned share key, and is renewal data of a key. It creates, The common information identifier and the above-mentioned renewal of a key which were matched with the above-mentioned common information generation method The above-mentioned common information containing data is generated, and it is the above-mentioned receiving set, The above-mentioned common information is received. Above-mentioned individual intermediate key corresponding to a common information receiving part and each of a plurality of common information generation methods Individual intermediate key group storage which stores the above-mentioned individual intermediate key group set that consists of groups, a plurality of above Inside of a plurality of share key acquisition parts corresponding to a common information generating part, and a plurality of above-mentioned share key acquisition parts from -- having a share key acquisition part selecting part which chooses one -- the above-mentioned share key acquisition part selecting part, To the above-mentioned common information identifier contained in the above-mentioned common information received in the above-mentioned common information receiving part It is based, one is chosen from a plurality of above-mentioned share key acquisition parts, and it is the above-mentioned share key acquisition part, Before being based on the share key acquisition method corresponding to the above-mentioned common information identifier, and the above-mentioned individual intermediate key group Using account common information, the above-mentioned share key is acquired.
0019The invention in Claim 2 is a key distribution system given in Claim 1, and are a plurality of above. Common information generation method, The first community information generation method is included and they are a plurality of above-mentioned methods of share key acquisition. Method, The first share key acquisition method used as the above-mentioned first community information generation method and a pair is included, and he is above-mentioned Si. Stem secret variable group set, The one or more first system Secret of the first system secret variable Power ゝTo become A dense variable group is included and it is the above-mentioned individual intermediate key group set, The above-mentioned first system secret variable group and 1 It is from an individual intermediate key for a start [ one or more ] which are generated based on an individual intermediate key generation type above for a start. An individual intermediate key group is included for a start which changes, and it is in the above-mentioned server, the time or more of one -- a strange variable generation type and 1 the above server common intermediate key generation formula is given beforehand -- each of the above-mentioned receiving set To One or more receiving set common intermediate key generation formulas are given beforehand, and are common to the first [ above-mentioned ]. Information generation method, The random number group which consists of one or more random numbers is generated, and they are the above-mentioned random number group and the above-mentioned The. Based on a strange variable generation type, it is [ above / a 1 system secret variable group and ] at the time, It is Formation from a strange variable at the time or more of one. A Time-varying variable group is generated, a common intermediate key is generated based on a Ba [ The above-mentioned first system secret variable group, the above-mentioned random number group, and the above-mentioned The - ] common intermediate key generation type, and it is a front based on the above-mentioned common intermediate key. An account share key is enciphered, An encryption share key is generated and it is the above-mentioned renewal data of a key, strange at the time of the above -- strange it is a method containing a number group and the above-mentioned encryption share key -- the above-mentioned first share key acquisition method, Before They are an individual intermediate key group and the above-mentioned receiving set common intermediate key generation type a strange variable group and for a start [ above-mentioned ] at the time of an account. The above-mentioned common intermediate key is generated to a machine, and it is Recovery of the above-mentioned encryption share key based on the above-mentioned common intermediate key. It is the method of acquiring line and the above-mentioned share key for item-ization.
0020[0013] The invention in Claim 3 is a key distribution system given in Claim 1, and is in said server, Any one above-mentioned individual intermediate key group out of a plurality of above-mentioned individual intermediate key group sets The set is given beforehand and it is the above-mentioned server, Above-mentioned individual intermediate key group set given beforehand Individual intermediate key group set storage to store, A preparation and a plurality of above-mentioned common information generation methods contain and the first community information generation method, and are a plurality of above-mentioned share key acquisition methods, the above-mentioned first -- common Sentiment including the first share key acquisition method used as a news generation method and a pair -- the above-mentioned system secret variable group set Is It describes above including the one or more first system [ of the first system secret variable Power ゝTo become ] secret variable groups. Individual intermediate key group set, It is individual middle the above-mentioned first system secret variable group and for a start [ one or more ]. It is an individual intermediate key for a start which comprises an individual intermediate key for a start [ one or more ] which are generated based on a key generation type. A group is included and it is in the above-mentioned server, They are a strange variable generation type and one or more receiving set community at the time or more of one. The intermediate key generation formula is given beforehand and it is the above-mentioned Receiving in each of the above-mentioned receiving set. The Place common intermediate key generation formula is given beforehand, and the above-mentioned first community information generation method generates the random number group which consists of a random number more than -, The above-mentioned random number group and the above-mentioned first system secret variable group It reaches and is [ above ] based on a strange variable generation type at the time, When a strange variable is comprised at the time or more of one, a strange variable group is generated, and they are a strange variable group and the above-mentioned receiving set common intermediate key generation and for a start [ above-mentioned ] at the time of an individual intermediate key group and the above. On a basis [ formula ], A common intermediate key is generated, based on the above-mentioned common intermediate key, the above-mentioned share key is enciphered, and an encryption share key are generated, and it is the above-mentioned renewal data of a key, They are a strange variable group and the above-mentioned code Y at the time of the above. It is a method containing a share key and is the above-mentioned first share key acquisition method, It is [ a strange variable group and ] a front at the time of the above. Based on an individual intermediate key group and the above-mentioned receiving set common intermediate key generation type, it is the above-mentioned common middle for a start [ account ]. A key is generated, the above-mentioned encryption share key is decrypted based on the above-mentioned common intermediate key, and the above is. It is the method of acquiring an owner key.
0021[0014] The invention in Claim 4 is a key distribution system of claim 1 statement, and are said a plurality of common information generation methods, the -- a 2 common information generation method is included -- a plurality of above-mentioned share key acquisition methods Is The second share key acquisition method used as the above-mentioned second community information generation method and a pair is included, and it is the above-mentioned System. Beam secret variable group set, The second system secret keys which comprise a plurality of second system secret keys It contains and is the above-mentioned individual intermediate key group set, either - of a plurality of above-mentioned second system secret keys -- with -- the [ which comprises the upper, above-mentioned second system secret key ] -- a 2 individual intermediate key group is included -- the [ above-mentioned ] -- 2 common Sentiment News generation method, The second one or more [ which is contained in the above-mentioned second system secret keys ] above-mentioned systems On a basis [ each / of a secret key ], The above-mentioned share key is enciphered and it is raw about a plurality of encryption share keys. It accomplishes, the encryption share keys which combined a plurality of above-mentioned encryption share keys are generated, and it is the above-mentioned renewal of a key. Data, It is a method containing the above-mentioned encryption share keys, and is the above-mentioned second share key acquisition method, the [ out of the above-mentioned encryption share keys contained in the above-mentioned renewal data of a key / above-mentioned ] -- 2 individual intermediate key selecting the one above-mentioned encryption share key corresponding to either of the above-mentioned second system secret keys contained in a group -- basis [ secret key / above-mentioned / second system ], The selected above-mentioned encryption share key is decoded. By changing, it is the method of acquiring the above-mentioned share key.
0022[0015] The invention in Claim 5 is a key distribution system given in Claim 4, and is said individual intermediate key group set, of a plurality of above-mentioned second system secret keys, a gap, or the second one above-mentioned System the [ which comprises a Beam secret key ] -- a 2 individual intermediate key group is included -- the [ above-mentioned ] -- 2 common information generation method, Above It is a basis about each of a plurality of above-mentioned second system secret keys contained in the second system secret keys. The above-mentioned share key is enciphered, a plurality of encryption share keys are generated, and they are a plurality of above-mentioned codes. It is the method of generating the code Share keys which combined the-izing share key.
0023[0016] The invention in Claim 6 is a key distribution system of claim 1 statement, and is said key distribution system, It is connected to each of the above-mentioned receiving set via the above-mentioned channel, and individual It has a key issue center which distributes an information group, and is the above-mentioned key issue center, It is the above-mentioned Receiving beforehand. Information storing part corresponding to the output unit which stores one or more individual keys given to Place, being the above-mentioned -- individual A plurality of individual information generation parts which generate information, and the above-mentioned individual information and the above-mentioned individual information generation The above-mentioned individual information group containing two or more kinds of groups of the individual information identifier matched with the part, double -- equipping the above-mentioned receiving set of a number with the individual information group distribution part distributed that it is simultaneous or individually -- and above-mentioned individual information generation part, Respectively, individual information generation methods differ and it is the above-mentioned individual information generation. Based on a method, they are the above-mentioned individual information identifier, the above-mentioned system secret variable group, and the above-mentioned individual information. It outputs and is the above-mentioned receiving set, The individual key storing part which stores the above-mentioned individual key given beforehand, and and the individual information group receiving part which receives the above-mentioned individual information group, To a plurality of above-mentioned individual information generation parts It had a plurality of corresponding individual intermediate key group acquisition parts, and received the above-mentioned individual information receiving part. It is based on the above-mentioned individual information identifier contained in the above-mentioned individual information group, a plurality of above-mentioned individual intermediate key group acquisition parts pass, respectively, and it outputs the above-mentioned individual information corresponding to the above-mentioned individual information identifier -- the above-mentioned individual intermediate key acquisition part, Individual intermediate key acquisition method corresponding to the above-mentioned individual information identifier It is used, is based on the above-mentioned individual information and the above-mentioned individual key, and is To acquire about the above-mentioned individual intermediate key group. It is characterized by To.
0024[0017] The invention in Claim 7 is a key distribution system given in Claim 6, and are said a plurality of individual information generation parts, generating To * This and the above-mentioned system secret variable group -- the above-mentioned key issue center Is it was matched with the above-mentioned system secret variable group and the above-mentioned individual information generation part -- being the above-mentioned -- individual the above-mentioned system secret variable group set containing two or more kinds of groups of an information identifier -- the above-mentioned server System secret variable group set transmission section to distribute, Before the preparation and the above-mentioned server were distributed System which stores an account system secret variable group set in the above-mentioned system secret variable group storage It has a secret variable group set receiving part.
0025[0018] The invention in Claim 8 is a key distribution system of claim 6 statement, and is said key issue center, It is connected to the above-mentioned server via the above-mentioned channel, and is the above-mentioned system secret variable group set. Transmission section, passing the above-mentioned channel -- it is distribution about the above-mentioned system secret variable group set to the above-mentioned server carry out and the above-mentioned system secret variable group set receiving part passes the above-mentioned channel -- the above-mentioned key issue center from -- the above-mentioned system secret variable group set is received
0026[0019] The invention in Claim 9 is a key distribution system of claim 6 statement, and is said system secret variable group set transmission section, Before recording the above-mentioned system secret variable group set on a portable medium The above-mentioned system Secret by which the account system secret variable group set receiving part was recorded on the above-mentioned portable medium A dense variable group set is read.
0027[0020] The invention in Claim 10, It is a key distribution system of claim 7 statement, and they are said key issue center and said server, It assumes that the key server is shared beforehand and is the above-mentioned system secret variable group. Set transmission section, the above-mentioned system secret variable group set is enciphered based on the above-mentioned key server -- creating encryption data and distributing to the above-mentioned server -- the above-mentioned system secret variable group set reception Part, It is [ decoding-Í-A-] the above-mentioned system based on the above-mentioned key server about the distributed above-mentioned code Y data. A secret variable group set is acquired. [0021] The invention in Claim 11, It is a key distribution system of claim 6 statement, and they are a plurality of above. Individual information generation method, The first individual information generation method is included and they are a plurality of above-mentioned individual Intermediate key picker. How to acquire, the first used as the above-mentioned first individual information generation method and a pair -- an individual intermediate key group acquisition method -- Including seeing -- the above-mentioned key issue center, It is a group of an identifier during the period matched with the key during the above-mentioned first system secret variable group matched with the key during a key and the above-mentioned period during the period given beforehand, and the above-mentioned period. It is an information storing part during the period stored one or more kinds, Above-mentioned individual key storing of a preparation and the above-mentioned receiving set Each of a part, Based on a key, an individual intermediate key group is enciphered for a start [ above-mentioned ] during the above-mentioned period. The above-mentioned term matched with the key during an individual intermediate key group and the above-mentioned period for a start [ encryption ] generated One or more kinds of groups of a between identifier are stored, the above-mentioned first individual information generation method -- the above-mentioned term a set out of a between information storing part of above-mentioned periods -- a key and the above-mentioned first system secret variable group -- and -- Choose an identifier during the above-mentioned period. enciphering a key during the above-mentioned period based on each of the above-mentioned individual key -- double -- generating a key during the encryption of a number -- the above-mentioned individual information group is combination about a key during [ a plurality of ] the above-mentioned encryption Include the first individual information that consists of identifiers during keys and the above-mentioned period during [ which was carried out ] the encryption. The above-mentioned first Before an individual intermediate key group acquisition method is included in the first above-mentioned individual information based on the above-mentioned individual key Decoding Y of any one above-mentioned code Time period key of the code Time period key of account plurality is carried out, It is an individual intermediate key for a start [ one or more / above-mentioned / encryption ] which acquire a key during the above-mentioned period and are contained in the above-mentioned individual key storing part. From the inside of a group, It is 1 about an individual intermediate key group for a start [ above-mentioned / encryption ] which was matched with the identifier during the above-mentioned period. Select one is made and an individual intermediate key group is decrypted for a start [ above-mentioned / encryption ] based on a key during the above-mentioned period. Therefore, it is the method of acquiring an individual intermediate key group for a start [ above-mentioned ].
0028[0022] The invention in Claim 12, It is a key distribution system of claim 6 statement, and they are said a plurality of individual information generation methods, The second individual information generation method is included and they are a plurality of above-mentioned individual Intermediate key picker. How to acquire, the [ used as the above-mentioned second individual information generation method and a pair ] -- a 2 individual intermediate key group acquisition method -- Including seeing -- the above-mentioned second individual information generation method, It is [ each of the above-mentioned individual key / ] a plurality of second [ above-mentioned / the ]. Any one of the system secret keys is selected, Before [ each of the above-mentioned individual key ] selecting Before enciphering the second system secret key of an account and generating a plurality of second system secret keys of encryption Account individual information group, the second Si of encryption who combined a plurality of above-mentioned second system secret keys of encryption including the second individual information containing stem secret keys -- the [ above-mentioned ] -- 2 individual intermediate key group acquisition method, From the inside of a plurality of above-mentioned second system secret keys of encryption contained in the second above-mentioned individual information, Before The one above-mentioned second system secret key of encryption corresponding to an account individual key is selected, and it is in the above-mentioned individual lock. It is based and the selected above-mentioned second system secret key of encryption is decrypted, above-mentioned The acquiring a 2 system secret key -- the above-mentioned second system secret key -- the [ above-mentioned ] -- it is the method of making it into a 2 individual intermediate key group
0029[0023] The inventions in Claim 13 are the feature and To about being a key distribution system of claim 2 statement, and the addition operation and the multiplication operation being included in said individual intermediate key generation type at least. To.
0030[0024] The invention in Claim 14 is a key distribution system of claim 2 statement, and the addition operation and the multiplication operation are included [ above ] in the strange variable generation type at least at the time.
0031[0025] The invention in Claim 15 is a key distribution system of claim 2 statement, and the addition operation and the multiplication operation are included in said server common intermediate key generation type at least. It is considered as the feature.
0032[0026] The invention in Claim 16 is a key distribution system of claim 2 statement, and the addition operation and the multiplication operation are included in said receiving set common intermediate key generation type at least. It is considered as the feature.
0033[0027] The invention in Claim 17 is a key distribution system of claim 4 statement, and comprises said second system secret keys and the ten second system secret keys.
0034[0028] The invention in Claim 18, It is a receiving set in a key distribution system provided with the server which distributes a share key, and a plurality of receiving sets which receive the above-mentioned share key, and is the above-mentioned Receiving. Place, A common information receiving part which receives common information from the exterior, and a plurality of share key acquisition methods Individual intermediate key group which stores the individual intermediate key group Power ゝTo become individual intermediate key group set corresponding to each Storage, A plurality of share key acquisition parts corresponding to a plurality of above-mentioned share key acquisition methods, and plurality The share key acquisition part selecting part which chooses one from the above-mentioned share key acquisition parts is had and described above. Share key acquisition part selecting part, It is contained in the above-mentioned common information received in the above-mentioned common information receiving part. It is based on a common information identifier, In the above-mentioned share key acquisition method corresponding to [ choose the one above-mentioned share key acquisition part, and ] and the above-mentioned common information identifier in the above-mentioned share key acquisition part, and the above-mentioned individual intermediate key group It is based, the above-mentioned common information is used, and the above-mentioned share key is acquired. [0029] The invention in Claim 19, It is a receiving set given in Claim 18, and they are said a plurality of shares. Key acquisition method, The first share key acquisition method is included and it is the above-mentioned individual intermediate key group set, For a start which comprises an individual intermediate key for a start [ one or more ], including an individual intermediate key group, and one or more receiving set common intermediate key generation formulas are beforehand given to each of the above-mentioned receiving set, and it is the above-mentioned common information, a time -- strange -- the [ which consists of a variable group and an encryption share key ] -- including 1 common information -- the above-mentioned first share key acquisition Method, the [ above-mentioned ] -- the time of the above included in 1 common information -- a strange variable group and the above-mentioned first -- individual intermediate key generating the above-mentioned common intermediate key based on a group and the above-mentioned receiving set common intermediate key generation type -- the above a connoisseur -- the method of decrypting the above-mentioned encryption share key and acquiring the above-mentioned share key based on an intermediate key it is -- it is characterized by things.
0035[0030] The invention in Claim 20, It is a receiving set of claim 18 statement, and they are said a plurality of share key acquisition methods, The second share key acquisition method is included and it is the above-mentioned individual intermediate key group set, a plurality of The the second which comprises any one or more above-mentioned second system secret keys of a 2 system secret key -- individual an intermediate key group is included -- above-mentioned common information, Any 1 of a plurality of above-mentioned second system secret keys On a basis [ each / of the above above-mentioned second system secret key ], Code Y of the above-mentioned share key is carried out. The second community information which consists of encryption share keys containing one or more generated encryption share keys It contains and is the above-mentioned second share key acquisition method, the [ above-mentioned / community ] -- the above-mentioned encryption included in 2 common information the [ out of share keys / above-mentioned ] -- V of the above-mentioned second system secret key contained in a 2 individual intermediate key group, The one above-mentioned encryption share key corresponding for whether being a gap is selected, and it is the above-mentioned second system secret key. The above-mentioned share key is acquired by carrying out decoding Y of the above-mentioned code Common key selected on the basis. It is a method.
0036[0031] the invention in Claim 21 is a receiving set of claim 20 statement -- said individual intermediate key group set -- of said a plurality of second system secret keys, a gap, or said one second system Secret the [ which comprises Close key ] -- a 2 individual intermediate key group is included
0037[0032] The invention in Claim 22, It is a receiving set of claim 18 statement, and is said key distribution system, It is connected to each and the server of the above-mentioned receiving set via the above-mentioned channel, has a key issue center which distributes an individual information group, and is the above-mentioned receiving set, It was given beforehand. The individual key storing part which stores an individual key, and individual information which receives the above-mentioned individual information group from the exterior Group receiving part, A plurality of individual intermediate key group acquisition parts corresponding to a plurality of individual intermediate key acquisition methods It has and is the above-mentioned individual information receiving part, Personal information contained in the received above-mentioned individual information group Based on another child, a plurality of above-mentioned individual intermediate key group acquisition parts pass, respectively, In the above-mentioned individual information group It is contained, the above-mentioned individual information corresponding to the above-mentioned individual information identifier is outputted, and it is the above-mentioned individual Intermediate key picker. Before a profitable part uses the above-mentioned individual intermediate key acquisition method corresponding to the above-mentioned individual information identifier Based on account individual information and the above-mentioned individual key, it is the feature about acquiring the above-mentioned individual intermediate key group. It carries out.
0038[0033] The invention in Claim 23, It is a receiving set of claim 19 statement, and they are said a plurality of individual intermediate key acquisition methods, An individual intermediate key group acquisition method is included for a start, and it is the above-mentioned Pieces of the above-mentioned receiving set. Each of another key storing part, carrying out code Y of the individual intermediate key group for a start based on a key during the period the [ by which Generation is carried out / code Y ] -- the period matched with the key during a 1 individual intermediate key group and the above-mentioned period -- discernment Store one or more kinds of a child's groups. The above-mentioned individual information group is each above-mentioned individual key. It is a key during [ which contains a key during / which were generated by the machine by carrying out code Hie of the key during the above-mentioned period / a plurality of / the code Hie ] the code Hie. The first individual information that consists of identifiers during a group and the above-mentioned period is included, It is individual intermediate key group acquisition for a start [ above-mentioned ]. A plurality of above-mentioned encryption term by which a method is included in the first above-mentioned individual information based on the above-mentioned individual key Decoding Y of any one above-mentioned code Time period key of the between key is carried out, acquiring a key during the above-mentioned period -- the above the [ which is contained in an individual key storing part / one or more above-mentioned / code Y ] -- from the inside of a 1 individual intermediate key group The above-mentioned term One individual intermediate key group is chosen for a start [ above-mentioned / encryption ] which was matched with the between identifier, and it is the above-mentioned period. Based on a key, it is the first above-mentioned piece by decrypting an individual intermediate key group for a start [ above-mentioned / encryption ]. It is the method of acquiring another intermediate key group.
0039[0034] The invention in Claim 24, It is a receiving set of claim 20 statement, and they are said a plurality of individual intermediate key acquisition methods, the -- including a 2 individual intermediate key group acquisition method -- the above-mentioned individual information group, It Enciphering-based on above-mentioned individual key of But-whether they are ! [ of the above-mentioned second system secret key ], and gap * This The second system Secret of code Y which consists of a plurality of second system secret keys of code Y therefore generated The second individual information containing dense keys is included, the [ above-mentioned ] -- a 2 individual intermediate key group acquisition method -- above-mentioned The From the inside of a plurality of above-mentioned second system secret keys of encryption contained in 2 individual information being the above-mentioned -- individual the one above-mentioned second system secret key of encryption corresponding to a key is selected, and it is based on the above-mentioned individual key -- decrypting the selected above-mentioned second system secret key of encryption, the second above-mentioned Sis acquiring the Tem secret key -- the above-mentioned second system secret key -- the [ above-mentioned ] -- it is considered as a 2 individual intermediate key group It is a method.
0040[0035] The invention in Claim 25 is Special about being a receiving set of claim 19 statement and the addition operation and the multiplication operation being included in said receiving set common intermediate key generation type at least. It is considered as the mark.
0041[0036] The invention in Claim 26, they are a server which distributes a share key, and a program which makes a computer perform processing which is connected via a channel and receives the above-mentioned share key -- the exterior from -- step which receives common information, it corresponds to each of a plurality of share key acquisition methods -- individual Step which stores the individual intermediate key group set which comprises an intermediate key group, A plurality of above-mentioned share key acquisition A plurality of share key acquisition steps corresponding to a method, Before receiving in the above-mentioned common information receiving part It is based on the common information identifier contained in account common information, and is one To select about the above-mentioned share key acquisition part. To step, performing a computer -- the above-mentioned share key acquisition step -- above-mentioned common information being based on the above-mentioned share key acquisition method corresponding to an identifier, and the above-mentioned individual intermediate key group -- the above a connoisseur -- using information, the above-mentioned share key is acquired
0042[0037] The invention in Claim 27, It is a program of claim 26 statement and they are said a plurality of share key acquisition methods, The first share key acquisition method is included and it is the above-mentioned individual intermediate key group set, one or more The above-mentioned program is alike including an individual intermediate key group, respectively for a start comprise an individual intermediate key for a start. Is One or more receiving set common intermediate key generation formulas are given beforehand, and it is the above-mentioned common information. a time -- strange -- it is generated by carrying out code Y of the above-mentioned share key based on a variable group and a common intermediate key the [ which consists of an encryption share key ] -- including 1 common information -- the above-mentioned first share key acquisition method, Above-mentioned The When contained in 1 common information, they are [ a strange variable group and ] an individual intermediate key group and the above-mentioned Receiving for a start [ above-mentioned ]. Based on a Place common intermediate key generation type, it is the feature about it being the method of generating the above-mentioned common intermediate key and acquiring line and the above-mentioned share key for decoding Y of the above-mentioned code Common key based on the above-mentioned common intermediate key. It carries out.
0043[0038] The invention in Claim 28, It is a program of claim 26 statement and they are said a plurality of share key acquisition methods, The second share key acquisition method is included and it is the above-mentioned individual intermediate key group set, a plurality of The the second which comprises any one or more above-mentioned second system secret keys of a 2 system secret key -- individual an intermediate key group is included -- above-mentioned common information, Any 1 of a plurality of above-mentioned second system secret keys It is generated by enciphering the above-mentioned share key based on the above above-mentioned second system secret key. The second community information containing the encryption share keys which consist of an encryption share key of Multiple is included, Above The above-mentioned encryption share keys with which the second share key acquisition method is included in the above-mentioned second community information of community From inside, the [ above-mentioned ] -- either of the above-mentioned second system secret keys contained in a 2 individual intermediate key group selecting the one corresponding above-mentioned code Common key -- a basis [ secret key / above-mentioned / second system ] -- Selection the method of acquiring the above-mentioned share key by decrypting the constant above-mentioned encryption share key carried out -- Ah It is characterized by To.
0044[0039] the invention in Claim 29 is a program of claim 28 statement -- said individual intermediate key group set -- of a plurality of second system secret keys, a gap, or said one second system secret key the [ Power ゝTo become ] -- a 2 individual intermediate key group is included
0045[0040] The invention in Claim 30 is Special about being a program of claim 27 statement and the addition operation and the multiplication operation being included in said receiving set common intermediate key generation type at least. It is considered as the mark.
0046[0041] The invention in Claim 31 is the medium which recorded the program of the claim 26 statement.
0047[0042] The invention in Claim 32, It is a key distribution method which distributes a share key, and is the above-mentioned key distribution method, Key distribution A which generates common information based on the above-mentioned share key, and distributes the above-mentioned common information Step, the above-mentioned share key is acquired based on the above-mentioned common information and an individual intermediate key group set -- double -- comprising a key receiving step of a number -- the above-mentioned key receiving step One or more systems Above-mentioned Pieces containing multiple individual intermediate key groups which consist of one or more individual intermediate keys based on a secret variable group Several above-mentioned individual intermediate key group sets that are different at least in another intermediate key group set and that are included two or more kinds From inside, Any one above-mentioned individual intermediate key group set is given beforehand, and it is the above-mentioned Key. Trust step, the step which stores the above-mentioned share key, and one or more systems given beforehand secret variable group Power ゝ and others -- step which stores a system secret variable group set, The above-mentioned share key A plurality of common information generation steps which generate the above-mentioned common information to a machine, A plurality of above-mentioned common Sentiment They are [ the step which chooses one from news generation steps, and ] a plurality of above-mentioned Acceptance about the above-mentioned common information. The step distributed to Receiver that it is simultaneous or individually is included, and they are a plurality of above-mentioned common information. A generation step differs in a common information generation method respectively, The above-mentioned common information generation method is used. It carries out and is based on the above-mentioned system secret variable group set and the above-mentioned share key, The common information identifier and the above-mentioned renewal day of a key which created the renewal data of a key and were matched with the above-mentioned common information generation method The above-mentioned common information containing Tha is generated, and it is the above-mentioned key receiving step, The above-mentioned common information is received. Above-mentioned individual intermediate key group power corresponding to a step and each of a plurality of common information generation methods Step which stores the above-mentioned individual intermediate key group set, It corresponds to a plurality of above-mentioned common information generating parts. A plurality of share key acquisition steps to carry out, above-mentioned common information received in the above-mentioned common information receiving part being based on the above-mentioned common information identifier contained -- inside of a plurality of above-mentioned share key acquisition steps , -- step which chooses one, An implication and the above-mentioned share key acquisition step are the above-mentioned common Knowledge. It is based on the share key acquisition method corresponding to another child, and the above-mentioned individual intermediate key group, and is Use about the above-mentioned common information. for is carried out and the above-mentioned share key is acquired.
0048[0043] The invention in Claim 33, It is a key distribution method given in Claim 32, and they are said a plurality of common information generation methods, The first community information generation method is included and they are a plurality of above-mentioned methods of share key acquisition. Method, The first share key acquisition method used as the above-mentioned first community information generation method and a pair is included, and he is above-mentioned Si. Stem secret variable group set, The one or more first system Secret of the first system secret variable Power ゝTo become A dense variable group is included and it is the above-mentioned individual intermediate key group set, The above-mentioned first system secret variable group and 1 It is from an individual intermediate key for a start [ one or more ] which are generated based on an individual intermediate key generation type above for a start. An individual intermediate key group is included for a start which changes, and it is in the above-mentioned key distribution step, the time or more of one -- strange variable generation a formula and one or more server common intermediate key generation formulas are given beforehand -- the above-mentioned key receiving Step -- respectively -- being alike one or more receiving set common intermediate key generation formulas are given beforehand -- the [ above-mentioned ] -- a 1 common information generation method, The random number group which consists of one or more random numbers is generated, and it is the above-mentioned random number. Based on a strange variable generation type, it is [ above / a group, the above-mentioned first system secret variable group, and ] at the time, At the time or more of one When a strange variable is comprised, a strange variable group is generated, a common intermediate key is generated based on the above-mentioned first system secret variable group, the above-mentioned random number group, and the above-mentioned server common intermediate key generation type, and it is the above-mentioned common middle. On a basis [ key ], It is the method of enciphering the above-mentioned share key and generating an encryption share key, and is the above-mentioned key. Updating data, A strange variable group and the above-mentioned encryption share key are included [ above ] at the time, and it is the above-mentioned first share Kotori. How to acquire, Inside [ common / a strange variable group and for a start / above-mentioned / to an individual intermediate key group and the above-mentioned receiving set at the time of the above ] Based on a between key generation type, the above-mentioned common intermediate key is generated and it is the above-mentioned code based on the above-mentioned common intermediate key. It is the method of acquiring line and the above-mentioned share key for decryption of a-izing share key.
0049[0044] The invention in Claim 34, It is a key distribution method given in Claim 33, and is said key distribution step, Any one above-mentioned Pieces out of a plurality of above-mentioned above-mentioned individual intermediate key group sets Another intermediate key group set is given beforehand, and it is the above-mentioned key receiving step, it was given beforehand -- front -- the step which stores an account individual intermediate key group set is included -- a plurality of above-mentioned common information generation methods Is The first community information generation method is included and they are a plurality of above-mentioned share key acquisition methods, Common to the first [ above-mentioned ] The first share key acquisition method used as an information generation method and a pair is included, and it is the above-mentioned system secret variable crowd. Synthesis, Before the one or more first system [ of the first system secret variable Power ゝTo become ] secret variable groups are included Account individual intermediate key group set, Inside [ individual the above-mentioned first system secret variable group and for a start / one or more ] It is individual middle for a start which comprises an individual intermediate key for a start [ one or more ] which are generated based on a between key generation type. Keys are included and it is in the above-mentioned server, They are a strange variable generation type and one or more common intermediate keys at the time or more of one. The generation formula is given beforehand and it is the above-mentioned common middle in each of the above-mentioned key receiving step. The key generation formula is given beforehand and the above-mentioned first community information generation method generates the random number group which consists of one or more random numbers, At the time of the above-mentioned random number group, the above-mentioned first system secret variable group, and the above On a basis [ type / strange variable generation ], When a strange variable is comprised at the time or more of one, a strange variable group is generated, and it is the above-mentioned first. Inside [ common based on an individual intermediate key group, the above-mentioned random number group, and the above-mentioned server common intermediate key generation type ] A between key is generated and the above-mentioned share key is enciphered based on the above-mentioned common intermediate key, Encryption share key It is the method of generating and is the above-mentioned renewal data of a key, They are a strange variable group and the above-mentioned encryption share at the time of the above. A key is included and it is the above-mentioned first share key acquisition method, It is individual middle a strange variable group and for a start [ above-mentioned ] at the time of the above. Based on keys and the above-mentioned common intermediate key generation type, the above-mentioned common intermediate key is generated and it is the above-mentioned common middle. This which is the method of decrypting the above-mentioned encryption share key and acquiring the above-mentioned share key based on a key It is considered as the feature.
0050the invention in Claim 35 is a key distribution method of claim 32 statement -- a plurality of above a connoisseur -- information generation method, the -- a 2 common information generation method is included -- a plurality of above-mentioned share key acquisition methods Is The second share key acquisition method used as the above-mentioned second community information generation method and a pair is included, and it is the above-mentioned System. Beam secret variable group set, The second system secret keys which comprise a plurality of second system secret keys It contains and is the above-mentioned individual intermediate key group set, either - of a plurality of above-mentioned second system secret keys -- with -- the [ which comprises the upper, above-mentioned second system secret key ] -- a 2 individual intermediate key group is included -- the [ above-mentioned ] -- 2 common Sentiment News generation method, The second one or more [ which is contained in the above-mentioned second system secret keys ] above-mentioned systems On a basis [ each / of a secret key ], enciphering the above-mentioned share key -- a plurality of encryption share keys -- raw -- it is the method of generating the encryption share keys which accomplished and combined a plurality of above-mentioned encryption share keys -- the above-mentioned renewal data of a key, The above-mentioned encryption share keys are included and it is the above-mentioned second share key acquisition method, the [ out of the above-mentioned encryption share keys contained in the above-mentioned renewal data of a key / above-mentioned ] -- one above-mentioned encryption corresponding to either of the above-mentioned second system secret keys contained in a 2 individual intermediate key group It is decoding about the above-mentioned encryption share key which selected the owner key and was selected based on the above-mentioned second system secret key. Change, It is the method of acquiring the above-mentioned share key.
0051[0046] the invention in Claim 36 is a key distribution method of claim 35 statement -- said individual intermediate key group set -- of said a plurality of second system secret keys, a gap, or said second one system the [ which comprises a secret key ] -- a 2 individual intermediate key group is included
EFFECT OF THE INVENTION
0053[0047] According to the key distribution system of the present invention, he is an aggressor, Inaccurate Acceptance which embedded the intermediate key which fraudulent procurement is carried out in the individual key currently embedded at the receiving set, and is obtained based on the individual key Even if Receiver is created, it is in the intermediate key, It is shown from which individual key it was generated. For a and To reason, it is embedded at an inaccurate receiving set including information! /and Intermediate key are investigated. It becomes possible to pursue the receiving set of a revealing agency.
0054[0048] The intermediate key is since it was made to comprise a plurality of individual intermediate keys, Even if the individual information of one of individual intermediate keys is forged, for a Noodle reason, in traceability, increase and safety so that the receiving set of business , The , and disclosure origin can specify the remaining individual intermediate keys It improves.
0055[0049] While referring to drawings, describe the embodiment of the key distribution system applied to the present invention below.
0056Brief explanation of the drawings
0057[0050] [Drawing 1] Outline figure of key distribution system 1 in embodiment of the invention 1
0058[figure 2] The figure showing the example of composition of key issue center 11 in embodiment of the invention 1
0059[figure 3] The figure showing the example of composition of the first individual information generation part 112 in embodiment of the invention 1
0060[figure 4] The figure showing the example of composition of information storing part 1122 during the period in embodiment of the invention 1
0061[figure 5] The first system secret variable group SPGI in embodiment of the invention 1 -- an example of one -- To indicate figure * 6] -- figure * 7] which shows an example of the first individual information EMMI in embodiment of the invention 1 -- information storing part corresponding to the receiving set in embodiment of the invention 1 It is Show about the example of composition of 113. To figure
0062* 8] -- figure * 9] which shows the example of composition of the second individual information generation part 114 in embodiment of the invention 1 -- an example of the second system secret variable group SPGII in embodiment of the invention 1 is shown Figure
0063* 10] -- the [ in embodiment of the invention 1 ] -- figure * 11] which shows an example of 2 individual intermediate key group MKIIGa -- the second individual information in embodiment of the invention 1 Figure showing an example of epsilonmumupi
0064[figure 12] It is Show about an example of system secret variable group set SPGS in embodiment of the invention 1. To figure
0065[figure 13] The figure showing an example of individual information group EMMG in embodiment of the invention 1
0066[figure 14] Flow of the processing at the time of key information distribution of key issue center 11 in embodiment of the invention 1 Re figure
0067[figure 15] The first system secret variable group S PGI of key issue center 11 in embodiment of the invention 1, and the flow chart of the processing at the time of first individual information EMMI generation
0068[figure 16] The second system secret variable group S of key issue center 11 in embodiment of the invention 1
0069PGII and the second individual information Flow chart of the processing at the time of epsilonmumupi generation
0070* 17] Figure showing the example of composition of server 12 in embodiment of the invention 1
0071[figure 18] Example of composition of system secret variable group storage 122 in embodiment of the invention 1 Shown figure
0072* 19] -- the [ in embodiment of the invention 1 ] -- figure * 20] which shows the example of composition of 1 common information generating part 125 -- the figure showing an example of strange variable group PRG at the time in embodiment of the invention 1
0073* 21] -- the [ in embodiment of the invention 1 ] -- figure * 22] which shows an example of 1 common information ECMI -- the [ in embodiment of the invention 1 ] -- figure * 23] which shows the example of composition of 2 common information generating part 126 -- an example of code Share keys ENCSKG in embodiment of the invention 1 Shown figure * 24] Figure showing an example of the second community information ECMII in embodiment of the invention 1
0074[figure 25] Flow chart of processing when system secret variable group set SPGS of server 12 in embodiment of the invention 1 is received [Drawing 26] Flow of the processing at the time of the renewal of share key SK of server 12 in embodiment of the invention 1 Figure
0075* 27] Figure showing the example of composition of receiving set 13a in embodiment of the invention 1
0076[figure 28] figure * 29] which shows the example of composition of individual key storing part 1304a in embodiment of the invention 1 -- the [ in embodiment of the invention 1 / code Y ] -- the figure showing an example of 1 individual intermediate key group set ENCMKIGS a
0077* 30] It is an individual intermediate key group for a start in embodiment of the invention 1. figure * 31] which shows an example of MKIGa -- figure * 32] which shows the example of composition of individual intermediate key storage 1305a in embodiment of the invention 1 -- individual Sentiment from key issue center 11 of receiving set 13a in embodiment of the invention 1 Flow chart of processing when news group EMMG is received
0078[figure 33] The flow chart of processing when common information ECM is received from server 12 of receiving set 13a in embodiment of the invention 1
0079[figure 34] The outline figure of key distribution system 2 in embodiment of the invention 2
0080* 35] -- figure * 36] which shows the example of composition of key issue center 21 in embodiment of the invention 2 -- the figure showing the example of composition of the third individual information generation part 212 in embodiment of the invention 2
0081[figure 37] One of the third system secret variable group set SPGIIIS in embodiment of the invention 2 Figure showing an example
0082* 38] The third individual information in embodiment of the invention 2 Figure showing an example of epsilonmumupiiota
0083[figure 39] Flow of the processing at the time of key information distribution of key issue center 21 in embodiment of the invention 2 Re figure
0084[figure 40] The third system secret variable group of key issue center 21 in embodiment of the invention 2 Set SPGIIIS and the third individual information Flow chart of the processing at the time of epsilonmumupiiota generation
0085* 41] Figure showing the example of composition of server 22 in embodiment of the invention 2
0086[figure 42] Example of composition of system secret variable group storage 222 in embodiment of the invention 2 Shown figure
0087* 43] -- the [ in embodiment of the invention 2 ] -- figure * 44] which shows an example of 3 common information ECMIII -- third system secret variable group set SP of server 22 in embodiment of the invention 2
0088Flow chart of processing when GIIIS is received [Drawing 45] Flow of the processing at the time of the renewal of share key SK of server 22 in embodiment of the invention 2 Figure
0089[figure 46] The figure showing the example of composition of receiving set 23a in embodiment of the invention 2
0090[figure 47] The individual key storing part in embodiment of the invention 2 The example of composition of 2304a shown Drawing [-- figure 48] -- Drawing [showing the example of composition of individual intermediate key storage 2305a in embodiment of the invention 2 -- figure 49] -- the third piece from key issue center 21 of receiving set 23a in embodiment of the invention 2 Another information group Flow chart of processing when epsilonmumupiiota is received
0091[figure 50] The flow chart of processing when the third community information ECMIII is received from server 22 of receiving set 23a in embodiment of the invention 2
0092[figure 51] The modification of key distribution system 1 in embodiment of the invention 1
0093[figure 52] The modification of the first community information generating part 125 in embodiment of the invention 1
0094[figure 53] The outline figure of the conventional key distribution system
0095Explanations of letters or numerals
009610 Channel
009711 and 21 Key issue center
009812 and 22 Server
009913a -- 13 n, 23a -- 23 eta Receiving set
0100111 and 211 The first control part
0101112 First Individual Information Generation Part
0102212 Third Individual Information Generation Part
01031121 Period Selecting Part
01042121 Third System Secret Variable Group Generation Part
01051122 Period Information Storing Part
01062122 First Intermediate Key Group Generation Part
01071123 Period Key Encryption Section
0108113 Information Storing Part corresponding to Receiving Set
0109114 Second Individual Information Generation Part
01101141 Second System Secret Key Generation Part 1142 -- the Second -- Individual -- Intermediate Key Group Encryption Section 115 System -- Secret -- Variable Group Set Transmission Section 215 Third System Secret Variable Group Set Transmission Section 116 Individual-Information Group Distribution Part
0111216 Third Individual Information Distribution Part
0112121 and 221 System secret variable group set receiving part
0113122 and 222 System secret variable group storage 123 Share key generation part
0114124 Common Information Generating Part Selecting Part
0115125 First Community Information Generating Part
0116225 Third Community Information Generating Part
01171251 the Time -- Strange Variable Group Generation Part
01181252 Common Intermediate Key Acquisition Part
01191253 First Shared Key Encryptosystem-ized Part
01201254 Second Control Part
0121126 Second Community Information Generating Part
01221261 Second Shared Key Encryptosystem-ized Part
01231262 Third Control Part
0124127 and 227 Common information distribution part
01251301 and 2301 Individual information group receiving part
0126It is an individual intermediate key group acquisition part for a start [ 1302a ].
0127the [ 2302a ] -- a 3 individual intermediate key group acquisition part
0128the [ 1303a ] -- a 2 individual intermediate key group acquisition part
01291304a, a 2304a individual key storing part
01301305a, a 2305a individual intermediate key group storage
01311306 and 2306a common information receiving part
01321307a share key acquisition part selecting part
0133The 1308a first share key acquisition part The 2308a third share key acquisition part
0134The 1309a second share key acquisition part
01351310 Outputting Part
0136The best form for inventing
0137[0052] (Embodiment 1)
0138key distribution system 1 as one embodiment concerning the present invention -- One [ ] -- it Explanation. the maximum -- The outline of this embodiment is explained the first using Drawing 1.
0139[0053] a figure -- key issue center 11 and server 12 which mention channel 10 below in 1, and a plurality of receiving sets 13a -- It is the channel to which 13 n is connected, and realizes in networks, such as the Internet and a network. Key issue center 11 distributes share key SK to a receiving set. To server 12, share key SK is acquired for system secret variable group set SPGS which is required information. They are a plurality of receiving sets 13a about individual information group EMMG required in order to carry out. -- It distributes to 13 n. The Community by which - Ba 12 was generated based on share key SK and system secret variable group set SPGS They are a plurality of receiving sets 13a about information ECM. -- It distributes to 13 n. A plurality of receiving sets 13a -- Based on , individual information group EMMG, and common information ECM, 13 n acquires common key SK and outputs the common key SK to the exterior. here -- key issue center 11 and receiving set 13a -- All the groups of 13 eta Is It assumes that one individual key which each class has shared beforehand is given, for example, is key issue S. The 11 and receiving set 13a are individual keys IKa, Key issue center 11 and receiving set 13b are individual keys I Kb, -- -, and key issue center 11 and receiving set 13 eta assume that individual key IKn is shared beforehand.
0140[0054] Here, explain operation of each component to details to a slight degree. first, each receiving set 13a -- the first which is respectively different to 13 n -- Individual intermediate key group MKIGa -- the [ MKGIn and ] -- inside of 2 individual Between keys MKIIGa -- how to distribute MKIIGn is explained. Introduction, key issue Seng Tha 11 generates system secret variable group set SPGS, turns the system secret variable group set S PGS to server 12, and transmits. the first -- Individual intermediate key group MKIGa -- MKIGn And 2 individual intermediate key group MKIIGa -- MKIIGn and individual key IKa -- the [ Facial expression ] -- basis [ IKn ], receiving set the first -- the [ an individual intermediate key group and ] -- generating individual information group EMMG required in order to acquire a 2 individual intermediate key group -- a plurality of receiving sets 13a -- It distributes to 13 eta. individual information group EMMG the first matched with receiving set 13a using individual key IKa with which received receiving set 13a is given beforehand -- the [ individual intermediate key group MKIGa and ] -- 2 individual intermediate key group MKIIGa is acquired. Receiving sets 13b other than receiving set 13a -- In 13 eta, each receiving set similarly They are an individual intermediate key group and the second piece for a start which was matched with each receiving set using the individual key which it has. Another intermediate key group is acquired. thus, each receiving set 13a -- The first from which 13 eta differs respectively Individual intermediate key group MKIGa -- the [ MKIGn and ] -- 2 individual intermediate key group MKIIGa -- MKIIGn -- Keep It can have.
0141[0055] Next, explain operation in case server 12 updates share key SK. First, server 12 follows the conditions given beforehand and is based on system secret variable group set SPGS, It is generated whether they are of the first community information ECMI or the second community information ECMII, and a gap, The first Common Sentiment which identifies whether they are common information ECMI or the second community information ECMII, and its either A plurality of receiving sets 13a as common information ECM containing a news identifier -- distributed towards 13 n. A plurality of receiving sets 13a -- 13 eta receives common information ECM and is Including to the common information ECM. Based on a rare To common information identifier, being contained in common information ECM is the first community information. epsilon CMI or the second community information ECMII is judged. It is The when it is the first community information ECMI. Share key SK is acquired using a 1 individual intermediate key group and the first community information ECMI. on the other hand -- The the case of 2 common information ECMII -- the -- the [ a 2 individual intermediate key group and ] -- using 2 common information ECMII -- Both Owner key SK is acquired. Thus, receiving set 13a -- Share key SK of 13 eta is updated.
0142[0056] in addition, cancel the receiving set which has a specific individual key with key issue center 11 in key distribution system 1 which is this embodiment, and acquire share key SK -- it also becomes possible and to make it like. setting this in the key issue center 11 -- system secret variable group set SPGS and the first piece the [ another intermediate key group and ] -- the time of updating a 2 individual intermediate key group, as opposed to and the receiving set which were cancelled The -- the first -- the [ an individual intermediate key group and ] -- a 2 individual intermediate key group be acquirable -- use , V cancelled like, and the individual key which a receiving set holds -- it is realizable by and making it like.
0143[0057] The above is an outline of this embodiment. Below, the details of key distribution system 1 which is one embodiment of the key distribution system of the present invention are explained. Full about these components It explains to Fine.
0144[0058] <composition of key distribution system 1> key distribution system 1 -- a figure -- it is shown in 1 -- as -- channel 10, key issue center 11, server 12, and a plurality of receiving sets 13a -- It comprises 13 eta.
0145[0059] Key issue center 11 is receiving set 13a about share key SK. -- To server 12, it is about system secret variable group set SPGS which is information required to distribute to 13 n, Share key SK is received from server 12. They are a plurality of receiving sets 13a about individual information group EMMG required to carry out. -- It distributes to 13 n. Sir A 12 generates share key SK, generates common information ECM based on the share key SK and system secret variable group set SPGS, and are a plurality of receiving sets 13a about the common information ECM. -- 13 eta It distributes. Receiving set 13a -- 13 eta is a basis about individual information group EMMG and common information ECM. Share key SK is acquired and it outputs to the exterior.
0146[0060] Below, explain these components in detail. First, they are OneV, Stated, Continuing, The key issue center 11, server 12, and receiving set 13a to the composition of channel 10. -- Composition of 13 n One and a The figure are used and explained to operation.
0147[0061] <Composition of channel 10>
0148Channels are networks, such as the Internet, a telephone line, a dedicated line, and a network, for example.
0149[0062] Composition > of Key issue center 11
0150key issue center 11 -- a figure -- it is shown in 2 -- as -- the first control part 111 and the first individual information generation part 11 2, information storing part 113 corresponding to a receiving set, the second individual information generation part 114, and system secret variable group It comprises set transmission section 115 and individual information group distribution part 116.
0151[0063] The (1) first control part 111
0152the case where the first control part 111 fulfills the renewal conditions of individual information given beforehand -- or the case where key issue center 13 carries out a start of operation -- the first individual information generation demand REQEMMI -- the first outputting to individual information generation part 112 -- the second individual information generation demand REQEMMII -- the -- 2 individual Sentiment It outputs to news generation part 114. for example, the renewal conditions of individual information -- " -- every fixed time (example: one day, one year) of a certain -- "and" -- external power [ ] -- there are case "where a certain signal is received etc. When the renewal conditions of individual information are "every A certain period of time (example: one day, and one year)", the first control part 111 is provided with a counter etc. being realizable -- renewal condition power of individual information' external power the case where a certain signal is received -- " a case -- the first -- being realizable by control part 111 being provided with the receiving part which receives an external signal etc. It is.
0153[0064] The (2) first individual information generation part 112
0154the first individual information generation part 112 -- a figure -- it is shown in 3 -- as -- a period -- selecting part 1121 and a period -- information rank It comprises key code Y part 1123 during Payment part 1122 and the period.
0155[0065] (2 -- 1) Period selecting part 1121
0156Selecting part 1121 is the first control part 111 to the first individual information generation demand REQEMMI during the period. When it receives, An intact flag (FLAG [ -- k ] -- 1 -- FLAG) as shown in Drawing 4, Period another child (PID [ -- PID ] -- 1 --) k) and a period key and (PK [ -- k ] -- 1 -- PK) the first system secret -- strange k group of a number group (SPGI -- 1 -- SPGI--k) -- {(FLAG [ -- 1, SPGI / -- 1 ] -- 1, PID -- 1, PK) Information storing part 1122 is accessed during the period which stores (FLAG -- 2, PID_2, and PK -- 2 and SPGI -- 2), -- - (FLAG -- k, PID -- k, PK_k, S PGI_k)}. And the k group 1 set is chosen from inside for the thing of intact flag power 1". And intact Off of the selected group A lug is set as "0." As the method of choosing 1 set from the things of intact flag power 1" For example, there are the method of choosing 1 set at random using a random number, etc. It is Generate about a random number. About How to do, nonpatent literature 3 is detailed. Henceforth, group selected during the period by selecting part 1121 About each value, it is [ -- i The / 1 system secret variable group SPGI -- It is referred to as i. ] intact flag FLAG. -- It is identifier PID during i and the period. -- It is key PK during i and the period. Here, it is intact flag FLAG. -- i is an intact hula. A FLAG -- 1 -- FLAG -- ! of k, It is in a gap and is identifier PID during the period. -- i is identifier PID during the period. -- 11PID -- ! of k, It is in a gap and is key PK during the period. -- i is key PK during the period. -- 1 [ It is and is the first system secret variable group SPGI. -- i is the first system secret variable group SPGI -- Suppose that it is either of 1 1 SPGI_k. ] -- PK -- ! of k, gap Next, the selected first system secret variable group SP GI -- i is outputted to system secret variable group set transmission section 115 as the first system secret variable group SPGI. And it is identifier PID during the selected period at the end. -- It is a term about key PK--i during i and the period. It outputs to between key encryption section 1123.
0157[0066] (2 -- 2) Period information storing part 1122
0158period information storing part 1122 -- a figure -- as shown in 4, it is given beforehand an intact flag and term k group of the between identifier, period key, and first system secret variable group -- {(FLAG_1, PID_1, PK 1, SPGI 1) (FLAG 2, PID 2, PK 2, and SPGI 2), -- - (FLAG k, PID_k, PK_k, SPGI -- k)} is stored. for example, a figure -- in 4 period identifier PID -- Correspond to 1. Period key PK -- 1 and the first system secret variable group S PGI -- 1 and intact flag FLAG -- 1 is held and it is identifier PID during the period. -- It corresponds to 2, Term Between key PK -- 2 and the first system secret variable group SPGI -- 2 and intact flag FLAG -- 2 is held and it is identifier PID during the period. -- It corresponds to k, Period key PK--k and the first system secret variable Group SPGI -- k and intact flag FLAG -- k is held, and State are expressed and they are and To. Here, it is the first system secret variable group SPGI. -- 1, a figure -- five like 5 -- being first system secret variable Power (s [ -- 1, V / -- 1, c--1 ] -- 1, t -- 1, u) ゝ constituted other first system secrets -- strange number group SPGI -- 2 -- SPGI -- k also comprises five first system secret variables (s [ -- s_k, t_k, u_k, v_k, c_k ] -- 2, t -- 2, u_2, v_2, c_2), respectively. The first system secret variable is first system secret variable generation type "s beforehand. -- 1 *t -- l =u -- 1 *v -- 1 mod N, s -- 2 * t -- 2=u -- 2 *v -- 2 mod N, - .., s [ -- k *v / -- It shall be given so that k mod N" may be filled. ] -- k * t -- k= u For example, five The A 1 system secret variable and modulus N For example, it is a 128-bit natural number and is here. Value of modulus N, When mentioning below, it is the same as modulus N beforehand given to strange variable group generation part 1251, common intermediate key acquisition part 1252, and the first share key acquisition part 1308a as a common value. It is a value, for example, is 2". It is {128} etc. "mod N" is a surplus operation, and is Should be power, for example, is 2". {4} means 16 and uses it in the same meaning henceforth. As the preparation method of the first system secret variable group (example: SPGI -- 1), The first four System A Beam secret variable (example: s [ -- 1, c--1 ] -- 1, t -- 1, u) is generated as a random number, before long -- the three first system secret variables (example: s [ -- 1 ] -- 1, t -- 1, u) -- the first system secret variable generation type -- substituting for "s -- 1 * t -- l =u -- l *v -- 1 mod N", There are a method of asking for the one remaining first system secret variables (example: v -- one), etc. Intact flag FLAG -- 1 -- FLAG -- It comprises each of k, "0", or "1", for example, is a natural number etc. in addition -- the time of key issue center 11 carrying out a start of operation -- intact flag FLAG -- 1 -- FLAG -- k -- all -- The"-- suppose that it is 1." Receiving set identifier AIDa -- AIDn is each receiving set 1. 3a -- Nature which is the unique identifier matched with every 13eta, for example, is different, respectively It is a number. It is key PK during To * This and the period. -- One -- Each of PK--k is a key of a DES code method given in nonpatent literature 2, etc., and is created using a random number etc., for example. Period another child PID -- 1 -- PID -- a natural number which k takes a different value, respectively, for example, is different, respectively etc. -- it is .
0159[0067] (2 -- 3) Period key encryption section 1123
0160Key encryption section 1123 is identifier PID during the period from the first system secret variable group selection part during the period. -- i and period key PK -- When i is received, information storing part 114 corresponding to a receiving set is accessed, Receiving set identifier AIDa -- AIDn and individual key IKa -- All IKn(s) are acquired. And first It corresponds to receiving set identifier AIDa! It is Based to /To go individual key IKa. Period key PK -- i is enciphered, the cryptogram is set to key ENCPKa = Enc (IKa, PK -- i) during the encryption -- it matches with receiving set identifier AIDa. And other receiving set identifiers AIDb -- It is the appearance also to AIDn, Based on a corresponding individual key, code Y of a key is performed during the period, and it is the dark. Statement Enc (1Kb, PK_i), - Set - - and Enc (IKn, PK_i) to key ENCPKb, - - -, and ENCPKn during the encryption, and it is each receiving set identifier AIDb. -- It matches with AIDn. As [ show / and / Drawing 6 ] Period identifier PID--i and a unit identifier AIDa -- AIDn and code Y term Between key ENCPKa -- First individual information EMMI = PID which comprises ENCPKn -- i | | {A.I. Artificial Intelligence Da and ENCPKa} | | {AIDb and ENCPKb} - - - | | {AIDn and ENCPKn}} are created, The first individual information EMMI is outputted to individual information group distribution part 116. The code Y algorithm which uses a key for carrying out code Y during the period here, For example, receiving set 13a which is a DE S code method of a statement, etc. and it mentions below to nonpatent literature 2 -- It is individual intermediate key group acquisition part 1 for a start [ of 13 n ]. It is business about the same method as the decoding Y algorithm used when carrying out decoding Y of the code Time period key by 302a. It is.
0161[0068] Information storing part 113 corresponding to (3) receiving sets
0162information storing part 113 corresponding to a receiving set -- a figure -- 7 shows -- as -- a plurality of receiving sets 13a -- 13 eta Receiving set identifier AIDa to identify -- AIDn and each of its receiving set 13a -- 13 eta -- beforehand -- To Individual key IKa obtained -- iotakappaeta is stored. for example, a figure -- in 7 -- Acceptance Receiving set 13a matched with Communication device identifier AIDa holds individual key IKa. Acceptance Receiving set 13b matched with Communication device identifier AIDb holds individual key 1Kb, and is Acceptance. Receiving set 13 eta matched with Communication device identifier AIDn holds individual key IKn. State is expressed. information storing part 113 corresponding to a receiving set -- the first individual information generation part 11 the [ in period key encryption section 1123 in two, and the second individual information generation part 114 ] -- 2 individual intermediate key group It is accessible from encryption section 1142.
0163[0069] The (4) second individual information generation part 114
0164the second individual information generation part 114 -- a figure -- it is shown in 8 -- as -- the [ the second system secret key generation part 1141 and ] -- it comprises 2 individual intermediate key group code Y part 1142.
0165[0070] (4 1) The second system secret key generation part 1141
0166The second system secret key generation part 1141 generates the six second system secret keys kl, k2, k3, k4, and k5 and k6 the case where the second individual information generation demand REQEMMII is received from the first control part 111. How to generate the six second system secret keys kl, k2, k3, k4, k5, and k6 There are the method of generating at random, for example, if it carries out, etc., and, specifically, it is business, for example about a random number. It is realizable by being. with nonpatent literature 3 detailed about the method of generating a random number. and a figure -- as [ show / 9 ] -- the six second system secret keys kl, k2, k3, k4, k5, and k6 power creating the second system secret variable group SPGII which changes -- the [ system secret variable group set transmission section 115 and ] -- it outputs to 2 individual intermediate key group code Y part 1142.
0167[0071] (4-2) the -- 2 individual intermediate key group code Y part 1142
0168the -- 2 individual intermediate key group code Y part 1142 -- the second from the second system secret key generation part 1141 the case where system secret variable group SPGII is received -- information storing part 113 corresponding to a receiving set -- Acax Carry out A. Receiving set identifier AIDa -- AIDn and individual key IKa -- All IKn(s) are acquired. That(ing) The -- being first contained in the second system secret variable group SPGII to receiving set identifier AIDa the inside power of the second system secret key kl of six To, k2, k3, k4, k5, and k6 -- the second one key of a secret It chooses. The selection method of this one second system secret key is To select at random, for example. There are How to do etc. and it can realize this by using a random number. if the key chosen [ as opposed to / as an example / receiving set identifier AIDa ] is here used as the second system secret key kl -- a figure -- 1 0 shows -- as -- the -- 2 individual intermediate key group MKIIGa serves as the second system secret key kl. and -- -- corresponding -- and To individual key IKa -- the [ Based and / The ] -- code Y of 2 individual intermediate key group MKIIGa -- line and its cryptogram -- the [ encryption ] -- it is referred to as 2 individual intermediate key group ENCMKIIGa = Enc (IKa, MKIIGa) -- it matches with receiving set identifier AIDa. And other receiving set identifiers AIDb -- AIDn It also receives and is the appearance, The six second system secrets in the second system secret variable group SPGII The one second system secret key is chosen from keys, the second system secret key -- the second piece considering it as another intermediate key group, and corresponding -- To go individual key -- the [ Based on ] -- encryption of a 2 individual intermediate key group -- line V, It is the second piece of encryption about the cryptograms Enc (1Kb, MKIIGb), ---, Enc (IKn, MKIIGn). It is referred to as another intermediate key group ENCMKIIGb, - - -, and ENCMKIIGn, and is each receiving set identifier A IDb. -- It matches with AIDn. and a figure -- as [ show / 11 ] Receiving set identifier AIDa -- the [ AIDn and / encryption ] -- 2 individual intermediate key group ENCMKIIGa -- ENCMKIIGn power The constituted 2 individual information EMMII= {AIDa and ENCMKIIGa} | | {AIDb, ENCMKIIGb - - - | I {AIDn and ENCMKIIGn}} are created and it is the second individual information. About epsilonmumupi, it is individual information group Arrangement. It outputs to Trust part 116.} here -- the -- code Time which uses a 2 individual intermediate key group for carrying out code Language, for example, Acceptance which is a DES code method of a statement, etc. and it mentions below to nonpatent literature 2 Receiver 13a -- the [ of 13 n ] -- 2 individual intermediate key group acquisition part 1303a -- the [ code Y ] -- 2 individual intermediate key group the method same when decrypting as business and a Decryption algorithm -- business and To.
0169(5) System secret variable group set transmission section 115
0170System secret variable group set transmission section 115 is the first system of the first individual information generation part 112. The first system secret variable group SPGI is received from secret variable group selection part 1121, The second piece The second system secret-from second system secret key generation part 1141 of another information generating part 114 variable When group SPGII is received, Figure System secret variable group SPGI reaches for a start [ as shown by 12 ]. System secret variable group identifier SPGIDI corresponding to the first system secret variable group SPGI It corresponds to the second system secret variable group SPGII and its second system secret variable group SPGII. System secret variable crowd which comprises system secret variable group identifier SPGIDII to carry out Synthesis SPGS is generated. And it is to server 12 about the system secret variable group set SPGS. It turns and transmits. Here, they are system secret variable group identifier SPGIDI and a system secret variable group. Identifier SPGIDII is a natural number different, respectively, for example. a system secret -- strange number group identifier SPGIDI and system secret variable group identifier SPGIDII -- respectively -- the first System Although it uses in order to distinguish Beam secret variable group SPGI and the second system secret variable group SPGII the information on the bit position of the first system secret variable group SPGI in [ in / beforehand / key issue center 11 and server 12 ] transmitted and received data, and the second system secret variable group SPGII, etc. -- a share -- Have been, In a To case, and The system secret variable group identifier SPGIDI and system secret variable group identifier SPGIDII may not be in system secret variable group set SPGS.
0171[0073] (Six) individual information group distribution part 116
0172individual information group distribution part 116 -- period key encryption section 1123 of the first individual information generation part 112 , -- the first -- receiving individual information EMMI -- and the [ of the second individual information generation part 114 ] -- inside of 2 individual The second individual information from between keys code Y part 1142 Case where epsilonmumupi is received, a figure -- 13 shows -- as -- being What The first individual information EMMI and individual information discernment corresponding to the first individual information EMMI Child EMMIDI and the second individual information epsilonmumupi and its second individual information Pieces corresponding to epsilonmumupi Individual information group EMMG which comprises another information identifier EMMIDII is generated. And That It is receiving set 13a about individual information group EMMG. -- It distributes towards 13 eta. Here, it is individual Sentiment. Nature from which news identifier EMMIDI and individual information identifier EMMIDII differ, respectively, for example It is a number. Shave individual information identifier EMMIDI and individual information identifier EMMIDII. The first individual information EMMI of Re, and the second individual information Although it uses in order to distinguish epsilonmumupi, They are key issue center 11 and receiving set 13a beforehand. -- In 13 eta, It is individual Sentiment for a start in transmitted and received data. News EMMI and the second individual information The information on the bit position of epsilonmumupi, etc. is shared and a and To case is Pieces. In another information group EMMG, individual information identifier EMMIDI and individual information identifier EMMIDII may not be.
0173[0074] Operation > of Key issue center 11
0174Power which explained the composition of key issue center 11 above Here, it is key issue center 1. Operation of 1 is explained. fulfilling here the renewal conditions of individual information given beforehand the case where it is -- or When key issue center 11 carries out a start of operation, they are distribution and Acceptance about a share key. They are server 12 and a plurality of receiving sets 13a about key information required to carry out Trust. -- If it distributes to 13 n Operation of Can is explained using the flow chart shown in Drawing 14. the first -- individual Sentiment news generation part 112 -- the first system secret variable group SPGI and the first individual information EMMI -- Generate the details of the operation at the time of To -- a figure -- it explains using the flow chart shown in 15. the last -- the second individual information generation part 114 -- the second system secret variable group SPGII and the second individual information the details of operation when generating EM mupi -- a figure -- using the flow chart shown in 16 -- explanation It carries out. Operation at the time of the key information distribution by << key issue center 11>>
0175The first control part 111 outputs the first individual information generation demand REQE MMI to the first individual information generation part 112, and is the second individual information generation demand REQEMMII to the second individual information generation part 114. It outputs. (S1101)
0176the first individual information generation part 112 -- a figure -- following a flow chart (details are explained below) as shown by 15 The first system secret variable group SPGI and the first individual information EMMI are generated, and it is The. 1 system secret variable group SPGI is outputted to system secret variable group set transmission section 115, and it is the first. Individual information EMMI is outputted to individual information group distribution part 116. (S1102)
0177the second individual information generation part 114 -- a figure -- following a flow chart (details are explained below) as shown by 16 The second system secret variable group SPGII and the second individual information epsilonmumupi is generated and it is The. 2 system secret variable group SPGII is outputted to system secret variable group set transmission section 115, and it is the second. Individual information epsilonmumupi is outputted to individual information group distribution part 116. (S1103)
0178Si who received the first system secret variable group SPGI and the second system secret variable group SPGII Stem secret variable group set transmission section 115, The first system secret variable group SPGI and the second Sis System secret variable group set SPGS which consists of Tem secret variable group SPGII is generated, and he is the Sis. Tem secret variable group set SPGS is transmitted to server 12. (S 1104)
0179The first individual information EMMI and the second individual information Individual information group distribution part 11 which received epsilonmumupi 6 is the first individual information EMMI and the second individual information. Individual information group EMMG which consists of epsilonmumupi is generated, and it is receiving set 13a about the individual information group EMMG. -- It distributes to 13 eta and ends. (S1 105)
0180It is operation >> at the time of generation (detailed explanation of Step S 1102) about the << first system secret variable group SPGI and the first individual information EMMI.
0181The first system secret variable group selection part 1 which received the first individual information generation demand REQEMMI 121, accessing information storing part 1122 during the period -- intact flag power it is -- a set of terms A key (example: PK -- i) and the first system secret variable group (example: SPGI -- i) are acquired during a between identifier (example: PID -- i) and the period. And the intact flag (example: FLA G -- i) stored in selecting part 1121 during the period is set as "0." (S 11021)
0182The first system secret variable group selection part 1121 appears in system secret variable group set transmission section 115 by making the first system secret variable group (example: SPGI -- i) into the first system secret variable group SPGI. Power is carried out. (S11022)
0183The first system secret variable group selection part 1121 outputs a key (example: PK_i) to key code Y part 1123 during the period during an identifier (example: PID -- i) and the period during the period. (S11023)
0184During the period which received the key (example: PK_i) during an identifier (example: PID -- i) and the period during the period, it accesses to information storing part 114 corresponding to a receiving set, and key encryption section 1123 is receiving set identifier AIDa. -- AIDn as well as individual key IKa -- All the groups of IKn are acquired. (S11024)
0185Key encryption section 1123 is each individual key IKa during the period. -- It is based on iotakappaeta, A key (example: rho kappa--i) is enciphered during the period, and a key (example: ENCPKa = Enc (IKa, PK -- i), -- - and EN CPKn=Enc (IKn, IKn)) is generated during the encryption. (S 11025)
0186Each code Time period key ENCPKa -- In the individual key used for ENCPKn at the time of code Y Corresponding receiving set identifier AIDa -- It matches with AIDn, a period -- an identifier (example: PI D -- i) -- in addition, the first individual information EMMI (example: =PID -- i I I {AIDa and ENCPKa} | | {AIDb and ENCPKb} ゝ - .. ゝ {AIDnゝ ENCPKn}) is generated. (SI 1026) Key encryption section 1123 outputs the first individual information EMMI to individual information group distribution part 116 during the period. It ends by carrying out. (S11027)
0187The << second system secret variable group SPGII and the second individual information It is operation >> at the time of generation (Step S 1103 details) about epsilonmumupi.
0188The second system secret key generation part 1141 which received the second individual information generation demand REQEMMII, the six second system secret keys kl, k2, k3, k4, k5, and k6 are generated. (SI 1031) the -- the second system secret variable group SPGII which comprises the 2 second system secret key generation part 1141, the six second system secret keys kl, k2, k3, k4, k5, and k6 is generated. (S11032) the second system secret key generation part 1141 -- the second system secret variable group SPGII -- system Secret the [ dense variable group set transmission section 115 and ] -- it outputs to 2 individual intermediate key group code Y part 1142. (S 1 1033)
0189the [ which received the second system secret variable group SPGII ] -- accessing 2 individual intermediate key group code Y part 1142 and information storing part 113 corresponding to a receiving set -- Receiving set identifier AIDa -- AIDn -- and -- All individual key IKa--IKn is acquired. (S 11034) the -- 2 individual intermediate key group code Y part 1142, Receiving set identifier AIDa -- As for AIDn, Selection carries out, respectively (example: MKIIGa=kl). It receives and is Selection about the one second system secret key out of the second system secret variable group SPGII. MKIIGb=k2 and - - the [ -, MKIIGn=k6, and ] -- 2 individual intermediate key group MKIIGa -- it is referred to as MKIIGn. (S11035)
0190the -- 2 individual intermediate key group code Y part 1142 -- individual key IKa -- Based The second piece of Respectively Another intermediate key group MKIIGa -- It is code Y of MKIIGn, Line the cryptogram -- the [ encryption ] -- inside of 2 individual (1Kb, MKIIG b) between keys ENCMKIIGa = Enc (IKa, MKIIGa) and ENCMKIIGb = Enc ゝ - - it is considered as - and ENCMKIIGn=Enc (IKn, MKIIGn). (S11036)
0191the -- 2 individual intermediate key group code Y part 1142, Receiving set identifier AIDa -- AIDn and encryption the -- 2 individual intermediate key group ENCMKIIGa -- Second individual information E MMII= which comprises ENCMKIIGn {AIDa and ENCMKIIGa} | | {AIDb and ENCMKIIGb} - - - | | {AIDn and EN CMKIIGn}} are created. (S 11037).
0192[0076] the -- 2 individual intermediate key group encryption section 1142 -- the second individual information epsilonmumupi is outputted to individual information group distribution part 116. (S11038)
0193It is power above. It is the composition and operation of key issue center 11 which are the components of key distribution system 1. Then, the composition and operation of server 12 are explained.
0194[0077] <Composition of server 12>
0195server 12 -- a figure -- it is shown in 17 -- as system secret variable group set receiving part 121 and system Secret variable group storage 122, share key generation part 123, common information generating part selecting part 124, and the first a connoisseur -- the [ information generating part 125 and ] -- from 2 common information generating part 126 and common information distribution part 127 -- composition -- To be.
0196[0078] (1) system secret variable group set receiving part 121
0197System secret variable group set receiving part 121 is a system secret variable group from key issue center 11. When set SPGS is received, Si contained in received system secret variable group set SPGS It is based on SPGIDI and SPGIDII which are stem secret variable group identifiers, the first system secret -- strange extracting number group SPGI and the second system secret variable group SPGII -- a figure -- System as shown by 18 storing in Beam secret variable group storing 122 -- share key generation part 123 -- share key generation demand REQSK It outputs. [0079] (2) system secret variable group storage 122
0198system secret variable group storage 122 -- a figure -- as shown in 18, the first system secret variable group S PGI and the second system secret variable group SPGII are stored. System secret variable To group storage 122, They are strange variable group generation part 1251, common intermediate key acquisition part 1252, and the second community information student at the time in system secret variable group set receiving part 121 and the first community information generating part 125. It is accessible from the second shared key encryptosystem Y part 1261 in Formation part 126.
0199[0080] (3) share key generation part 123
0200Place which fulfills the renewal conditions of common information given beforehand when common key generation 123 receives share key generation demand RE QSK from system secret variable group set receiving part 121 Synthesis and share key SK are generated. As a method of generating share key SK, it is business about a random number, for example. There are the method of being and generating at random, etc. About the method of generating a random number, it is un-patenting. Literature 3 is detailed. And the share key SK is outputted to common information generating part selecting part 124. For example, the renewal conditions of common information are "every second" and cases, such as "every hour", Share key generation part 12 Receiving part in which it can realize by 3 being provided with a counter etc., and share key generation part 123 receives [ in the renewal conditions of common information ] an external signal in "at the time of receiving an external power specific signal" etc. It is realizable by having etc.
0201[0081] (4) common information generating part selecting part 124
0202When common information generating part selecting part 124 receives share key SK from share key generation part 123 Either the first community information generating part 125 or the second community information generating part 126 is chosen, the -- the [ selected ] -- the time of 1 common information generating part 125 -- strange variable group generation part 1251 and the first shared key encryptosystem Y the [ part 1253 or ] -- the second shared key encryptosystem-ized part 1261 of 2 common information generating part 126 -- share Key SK is outputted. Here, they are the first community information generating part 125 or the second community information generating part 126. As how to choose either, it is external power, for example. Schedule data given There is it being based and choosing at random using how to choose and a random number etc.
0203(5) The first community information generating part 125
0204the -- 1 common information generating part 125 -- a figure -- it is shown in 19 -- as -- the time -- strange variable group generation part 1251 and Both a connoisseur -- from intermediate key acquisition part 1152, the first shared key encryptosystem-ized part 1253, and the second control part 1254 It is constituted. [0082] (5 -- 1) the time -- strange variable group generation part 1251
0205a time -- strange -- variable group generation part 1251 receives share key SK from common information generating part selecting part 124 A It was case generates four random numbers z, w, and m and n. How to generate random number z, w, and m and n here If it carries out, there are the method of generating at random using a random number, etc., for example. Random number z, w, and m and n are 128-bit natural numbers, respectively, for example. System secret variable group Storage 122 is accessed, the first system secret variable group SPGI is acquired, and it is the first from the inside. System secret variable s, t, and u and v are extracted. And it is a strange variable at the time of four given beforehand. A generation type and rl = s*z+v*m mod N, Strange variable rl, r2, r3, and r4 are generated based on -r2=t*w+u*n N, -r3=u*z+t*m mod N", and "r4=v*w+s*n N" at the time of four. It carries out. then, the time of generating -- strange variable rl, r2, r3, and the figure r4 Power ゝ constituted -- as [ show / 20 ] the time -- strange -- variable group PRG is generated and strange variable group PRG is then outputted to the second control part 1254. Finally, random number z, w, and m and n are outputted towards common intermediate key acquisition part 1252.
0206[0083] (5 -- 2) Common intermediate key acquisition part 1252
0207common intermediate key acquisition part 1252 -- the time -- random number z from strange variable group generation part 1251 receiving w, m, and n accessing system secret variable group storing 122 first, when it takes -- the first system secret -- strange Number group SPGI is acquired and the first system secret variable s, t, and u, v, and c are extracted from the inside. That server common intermediate key generation type "which can give common intermediate key SMK beforehand in the back -- (z+w+c+n*m) SMK= 2* s*t*+2* (u*s*n*z+t*v*m*w) -- alike [ mod N and ] Carry out About generation. It is Output to the first shared key encryptosystem-ized part 1253 about the generated common intermediate key SMK. To.
0208[0084] (5--3) The first shared key encryptosystem Y part 1253
0209The first shared key encryptosystem Y part 1253 receives share key SK from the second control part 124, and further, when common intermediate key SMK is received from common intermediate key acquisition part 1252, it enciphers received share key SK based on the common intermediate key S MK. It is code Y of share key SK here. Code Y algorithm to be used, for example, reception which is a DES code method etc. and it mentions below device 13a -- every of 13 n -- the first share key acquisition part 1308a -- !/and Encryption share key ENCSK The same method as the decoding Y algorithm used for carrying out decoding Y is used. Then, encryption share Key ENCSK is outputted to the second control part 1254. [0085] (5 -- 4) The second control part 1254
0210the second control part 1254 -- the time -- strange -- receiving strange variable group PRG from variable group generation part 1251 at the time -- Up the case where code Common key ENCSK is received from It was and the first shared key encryptosystem Y part 1253 -- a figure -- 21 it is shown -- as At common information identifier ECMIDI which shows that it is the first community information ECMI, and the time It is Generate about the first community information ECMI which consists of strange variable group PRG and code Common key ENCSK. To. And it outputs to common information distribution part 127 by making the first community information ECMI into common information ECM. Here, common information identifier ECMIDI is a natural number, for example. Common Although information identifier ECMIDI is used when it is contained in common information ECM and To go data distinguishes the first community information EC MI and the second community information ECMII, They are server 12 and receiving set 1 beforehand. 3a -- Thailand Min who sends out the first community information ECMI and the second community information ECMII in 13 eta A is shared! In the /To go case It is the first community information identifier ECMIDI and the second to common information ECM. There may not be common information identifier ECMIDII. For example, server 12 and receiving set 13a -- In 13 n, it is a case where transmit the first community information ECMI at a certain decided time, and the second community information ECMII is then transmitted other than this etc.
0211[0086] The (6) second community information generating part 126
0212the -- 2 common information generating part 126 and a figure -- it is shown in 22 -- as -- the second shared key encryptosystem-ized part 1261 and The It comprises 3 control parts 1262.
0213[0087] (6--1) The second shared key encryptosystem Y part 1261
0214When the second shared key encryptosystem Y part 1261 receives share key SK from the second control part 124, Up Access To and system secret variable group storing 122, and it is Take about the second system secret variable group SPGII. It gains and the inside power also extracts the six second system secret keys kl, k2, k3, k4, k5, and k6. That Carry out and code-Í-A-generate encryption share key EN CSKl =Enc (kl, SK) for share key SK based on the second system secret key kl first. And to other second system secret keys k2, k3, k4, k5, and k6, similarly, share key SK is enciphered and it is encryption share key ENCSK2=Enc (k2, SK), -- - and ENCSK6=Enc (k6, SK) are generated. the last -- a figure -- 23 shows -- as -- being Come out of what connected encryption share key ENCSK1, ENCSK2, ENCSK3, ENCSK4, ENCSK5, and EN CSK6 to the third control part 1262 as code Share keys ENCSKG. Power is carried out. The code Y algorithm used for code Y of share key SK here, for example, -- receiving set 13a which is a DES code method etc. and it mentions below -- every of 13 n -- the second share key acquisition part 13 The same method as business V and a Decryption algorithm is used for decrypting one cryptogram of encryption share keys ENCSKG in 09a.
0215[0088] (6 -- 2) The third control part 1262
0216the third control part 1262 -- the second shared key encryptosystem-ized part 1261 to code Common key ENCSKG the case where it receives -- a figure -- 24 shows -- as Common information which shows that it is the second community information ECMII The second community information ECMII which identifier ECMIDII and code Share keys ENCSKG power also become It generates. And the second community information ECMII is made into common information ECM, and it is common Information distribution. It outputs to Trust part 127. Here, common information identifier ECMIDII is common information discernment, for example. It is a different natural number from child ECMIDI. The data in which common information identifier ECMIDII is contained in common information E CM distinguishes the first community information ECMI and the second community information ECMII. Although it uses when carrying out, They are server 12 and receiving set 13a beforehand. -- In 13 eta, it is the first community information. The timing which sends out epsilon CMI and the second community information ECMII is shared. Even if there are not the first community information identifier ECMIDI and the second community information identifier ECMIDII in common information EC M in a To case It is good. for example, server 12 and receiving set 13a -- in 13 eta -- a certain decided time the -- transmitting 1 common information ECMI -- other than this -- coming out -- the -- case where 2 common information ECMII is transmitted etc. -- it is .
0217[0089] (Seven) common information distribution part 127
0218common information distribution 127 -- the -- the second control part 1254 of 1 common information generating part 125, or The or [ of third control part 1262, of 2 common information generating part 126, and a gap ] -- from -- it is reception about common information ECM the case where it carries out -- receiving set 13a -- The common information ECM is distributed to 13 n.
0219[0090] <Operation of server 12>
0220power which explained the composition of server 12 above here -- operation of server 12 -- just -- Explanation is carried out. first, system Secret used when distributing share key SK from key issue center 11 the operation at the time of receiving dense variable group set SPGS -- a figure -- the flow chart shown in 25 -- business Are and it explains. next, the case where share key generation demand RE QSK is received from system secret variable group set receiving part 121 -- or When the renewal conditions of a share key given beforehand are fulfilled, The - Ba 12 is receiving set 13a. -- Stickiness of operation, the The figure at the time of distributing new share key SK to 13 n It explains using the flow chart shown in 26.
0221<<Operation when system secret variable group set SPGS is received from key issue center 11>> system secret variable group set receiving part 121, System secret variable group identifier SPGIDI contained in received system secret variable group set SPGS -- Based on SPGIDII, it is the first System. Beam secret variable group SPGI and the second system secret variable group SPGII are extracted. (S1201) System secret variable group set receiving parts 121 are the first system secret variable group SPGI and the second. System secret variable group SPGII is stored in system secret variable group storage 122, and it ends. (S1202)
0222<<server 12 is receiving set 13a. -- When distributing new share key SK to 13 n, share key generation part 123 of operation>> generates share key SK, and it is Output to common information generating part selecting part 124. To. (S1251)
0223Common information generating part selecting part 124 is the first community information generating part 125 or the second community information generation. One of parts 126 is chosen and share key SK is outputted to the selected one. Here, common to the first When information generating part 125 is chosen, it progresses to Step S1254. On the contrary, he is the second community information student. When Formation part 126 is chosen, it progresses to step S 1260. (S1252)
0224the [ which received share key SK from share key information selecting part 124 ] -- 1 common information generating part 125 -- random -- Several z, w, m, and n are generated. Then, system secret variable group storing 122 is accessed, and it is the first. System secret variable group SPGI is acquired and the inside power is also the first system secret variable s, t, and u and v. It extracts. and the time of four given beforehand -- strange variable generation type "-- rl = s * z+v* m mo d N, Strange variable rl, r2, r3, and r4 are generated at the time of four based on r2=t *w+u * n N, r3 =u* z+t * m mod N, and r4=v *w+s * n N." strange at the time of four generated -- when variable r 1, r2, r3, and r4 power are also constituted, strange variable group PRG is generated. (S1253)
0225Strange variable group PRG is then outputted to the second control part 1254. (S 1254)
0226Random number z, w, and m and n are outputted towards common intermediate key acquisition part 1252. (S1255) Common intermediate key acquisition part 1252, a time -- strange -- receiving random number z, w, and m and n from variable group generation part 1251 accessing system secret variable group storing 122 first, when it takes -- the first system secret -- strange Number group SPGI is acquired and the first system secret variable s, t and u, and V and c are extracted from the inside. And server common intermediate key generation type [ SMK= 2 * s * t * (z+w+c+n *m)+2 * (u* s * n* z+t *v* m*w) ] "mod N" [This base which can give common intermediate key SMK beforehand! /Get caught is carried out. (SI 256)
0227Generated common intermediate key SMK is outputted to the first shared key encryptosystem-ized part 1253. (S 1257) The first shared key encryptosystem Y part 1253, When share key SK was received from the second control part 124 and common intermediate key SMK is further received from common intermediate key acquisition part 1252, Received share key SK is enciphered based on the common intermediate key S MK, and it is encryption share key ENCSK. It generates and outputs the code Common key ENCSK to the second control part 1254. (S1258) the second control part 1254 -- the time -- strange -- receiving strange variable group PRG from variable group generation part 1251 at the time Up When code Common key ENCSK is received from It was and the first shared key encryptosystem Y part 1253, the first a connoisseur -- common information identifier ECMIDI which shows that it is information ECMI, and the time -- strange variable group PRG And It consists of Encryption key shared key ENCSK. The first community information ECMI is generated and it is common Sentiment in the first. It outputs to common information distribution part 127 by making news ECMI into common information ECM. Step S126 It progresses to 4. (S1259)
0228When the second shared key encryptosystem Y part 1261 receives share key SK from the second control part 124, Up Access To and system secret variable group storing 122, and it is Take about the second system secret variable group SPGII. It gains and the inside power also extracts the six second system secret keys kl, k2, k3, k4, k5, and k6. (1260)
0229The second shared key encryptosystem Y part 1261 is each second system secret key kl, B No. of notes of the share key SK is carried out based on k2, k3, k4 and k5, and k6, B No. A shared key ENCSKl =Enc (kl, SK) and ENCSK2=Enc (k2, SK), - Generate - - and ENCSK6=Enc (k6, SK), and encryption is. Owner key ENCSK1 -- ENCSK6 is connected and encryption share keys ENCSKG are generated. (S1261)
0230The second shared key encryptosystem Y part 1261 outputs encryption share keys ENCSKG to the third control part 1262. (S1262)
0231When the third control part 1262 receives code Share keys ENCSKG from the second shared key encryptosystem-ized part 1261, The second community information ECMII which consists of common information identifier ECMIDII which shows that it is the second community information ECMII, and encryption share keys ENCSKG is generated, and it is the second [ the ]. It outputs to common information distribution part 127 by making common information ECMII into common information ECM. (S126 3)
0232Common information distribution part 127 which received common information ECM is receiving set 13a. -- It is common Sentiment to 13 n. News ECM is distributed and it ends. (S1264)
0233The above is the composition and operation of server 12 which are the components of key distribution system 1. Then, , receiving set 13a -- The composition and operation of 13 eta are explained. First, style of receiving set 13a Operation is explained to be Formation, next they are receiving set 13a and other receiving sets 13b. -- 13 eta Difference is described.
0234[0092] <Composition of receiving set 13a>
0235receiving set 13a -- a figure -- it is shown in 27 -- as -- individual information receiving part 1301 and the first -- individual intermediate key group Acquisition part 1302a, the -- 2 individual intermediate key group acquisition part 1303a, individual key storing part 1304a, and inside of individual Between key storing part 1305a, common information receiving part 1306, the second selecting part 1307a, and the first share key acquisition It comprises part 1308a, second share key acquisition part 1309a, and outputting part 1310. Here, it is The. It is individual intermediate key group acquisition part 1303a 1 individual intermediate key group acquisition part 1302a and for a start, Individual key storing part 1304a, individual intermediate key storage 1305a, the second selecting part 1307a, It is first share key acquisition part 1308 a, the second share key acquisition part 1309a, and a component peculiar to Is a receiver 13a, and is Individual information reception. Trust part 1301, common information receiving part 1306, outputting part 1310, Is a receiver 13a -- In 13 eta It is a common component.
0236[0093] (1) individual-information receiving part 1301
0237When individual information receiving part 1301 receives individual information group EMMG from server 12, Individual information identifier EMMIDI contained in received individual information group EMMG being based on EMMID II -- the first individual information EMMI and the second individual information extracting epsilonmumupi -- the first -- individual Sentiment news EMMI -- the first -- individual intermediate key group acquisition part 1302a -- the second individual information epsilonmumupi -- the second -- individual It outputs to intermediate key group acquisition part 1303a.
0238[0094] It is individual intermediate key group acquisition part 1302a for a start [ (2) ].
0239When individual intermediate key group acquisition part 1302a receives the first individual information E MMI from individual information receiving part 1301 for a start, first -- a figure -- Receiver identification from individual key storing part 1304a as shown in 28 another child AIDa, individual key IKa, and the encryption first -- individual intermediate key group set ENCMKIGSa -- Take It gains. And it is an identifier (for example, PID [ -- 1 / -- PID / -- Either of the k ] -- i: PI D -- i is PID) during the period from the first received individual information EMMI, And it is stored in individual key storing part 1304a. Code Time period key ENCPKa corresponding to receiving set identifier AIDa which was is acquired. Based on individual key IKa stored in after that and individual key storing part 1304, decoding Y of key ENCP Ka is performed during the encryption, and it is identifier PID during the period. -- It is key PK during the period corresponding to i. -- i is acquired. the -- after and a figure -- the [ as shown by 29 / code Y ] -- from [ under 1 individual intermediate key group set ENCMKIGSa ] The period identifier in The 1 individual information EMMI (example: PID -- i) PID -- i is PID. -- 1 -- PID -- An individual intermediate key group (for example, ENCMKIGa [ -- i ] -- i: ENCM KIGa ENCMKIGa [ -- ENCMKIGa / -- k ] -- 1 someday power) is acquired for a start [ encryption ] corresponding to a k Of gap, Period key PK -- being based on i -- the [ the / code Y ] -- performing decoding Y of a 1 individual intermediate key group -- a figure -- individual intermediate key group MKIGa is acquired for a start [ as shown by 30 ]. Then, individual intermediate key group M KIGa is stored in individual intermediate key storage 1305a for a start [ the ] which was decrypted.
0240[0095] the [ (3) ] -- 2 individual intermediate key group acquisition part 1303a
0241the -- 2 individual intermediate key group acquisition part 1303a -- the second individual information from individual information receiving part 1301 the case where E mumupi is received -- first -- a figure -- Receiver identification from individual key storing part 1304a as shown in 28 Another child AIDa and individual key IKa are acquired. And the second received individual information from epsilonmumupi, code Second corresponding to receiving set identifier AIDa stored in individual key storing part 1304 2 individual intermediate key group ENCMKIIGa is acquired. then -- being based on individual key IKa -- the code the [-izing ] -- decoding Y of 2 individual intermediate key group ENCMKIIGa -- the [ line and ] -- 2 individual intermediate key group MKIIGa is acquired. the [ then, / the / which was acquired ] -- 2 individual intermediate key group MKIIGa -- individual intermediate key storing It stores in part 1305a.
0242[0096] (4) individual key storing part 1304a
0243individual key storing part 1304a -- a figure -- as shown in 28, individual intermediate key group set ENCMKIGSa is held receiving set identifier AIDa, individual key I Ka, and for a start [ encryption ]. this -- individual key storing part 1304a -- the first -- the [ individual intermediate key group acquisition part 1302a and ] -- 2 individual intermediate key It is accessible from group acquisition part 1303a. receiving set identifier AIDa -- for example, -- self--- it is the number of Natural -- Receiving set identifier AIDb -- taking a different value from each of AIDn -- individual key IK a For example, it is a key of a DES code method given in nonpatent literature 2, and is business about a random number etc. beforehand. What was generated by being is embedded and it is individual key 1Kb. -- A different value from IKn is taken. [0097] What was stored by this individual key storing part 1304a, and was beforehand created in addition by key issue center 11 by the following methods for a start [ Encryption ] individual intermediate key group set ENCMKIGSa It is embedded.
0244[0098] Period identifier PID -- It corresponds to 1 and is the first system [ of To go ] secret variable s. -- 1 and t -- 1 and u -- 1 and V -- 1 and c -- As opposed to 1, Individualization variable generation type" x * y=c given beforehand -- Two individualization variables x and y which fill 1m od N" are generated. As the method of generating two individualization variables x and y here, using a random number -- one individualization variable (example: X) -- raw -- if there are a method of asking for another individualization variable (example: y) by accomplishing and assigning the value to an individualization variable generation type, etc. and one random individualization variable X is chosen -- certainly -- individualization Variable y exists. Individualization variables x and y are 128-bit natural numbers, and are Up, for example. which It was" *" is a multiplication operation, for example, 2*5 means 10, and it uses in the same meaning henceforth. Then, it is an individual intermediate key for a start [ four ] which are given beforehand using the individualization variables X and y. Generation type" mkll= s -- l * x mod N, mkI2=t -- 1 * y mod N, mkI3= [ -- v / -- Based on l * y mod N", individual intermediate key mkll, mkI2, mkI3, and mkI4 are generated for a start / four /. ] -- u -- l * x modN", "mkI4= and the four first -- individual intermediate key mkll, mkI2, mkI3, and mkI4 power the figure constituted -- the first as shown by 30 -- individual intermediate key group MKIGa It generates. And it is identifier PID during the period about individual intermediate key group MKIGa for a start [ this ]. -- It is with correspondence to 1. It is key PK during the period which Keep it. and key issue center 11 hold. -- Code Y is performed based on one, and it is the encryption first. Individual intermediate key group ENCMKIGa is generated. Other first system secret variables s -- 2 -- s--k And the second system [ of Facial expression ] secret variable t -- 2 -- t--k and the third system secret variable u -- 2 -- u--k -- and -- the fourth system secret variable V -- 2 -- v--k and the fifth system secret variable c -- 2 -- as opposed to c--k The -- the same Individualization variables X and y are generated and it is based on an individual intermediate key generation type for a start, First Individual intermediate key mkll -- 2 [ 2 / 2 / 2 -- mkI4 -- k is generated. / -- mkI3 -- k, mkI4 -- / -- mkI2 -- k, mkI3 -- ] -- mkll -- k, mkI2 -- And it is a style from each of an individual intermediate key for a start [ the ]. It is individual intermediate key group MKIGa for a start to accomplish. -- 2 (=mkll -- 2 | | mkI2_2 | | mkI3_2 I ImkI4_2), MKIa -- 3, - - -, and MKIa_k are generated. And each period Match with identifier PID_2' ..PID_k, code Y is Performed based on key rhokappa_2 and . -rho kappa_eta during the period, and it is Generate about individual intermediate key group ENCMKIGa 2 and - -'ENCMKIGa k for a start [ encryption ]. To. the last -- a figure -- the [ as shown by 29 / code Y ] -- value {(ENCMKIGa -- 1, PID -- 1) | | (ENCMKIGa -- 2, PID_2) I I and -- I I (ENCMKIGa_k) with which the group of identifier was made to connect during the period matched with the 1 individual intermediate key group PID_k} -- the [ code Y ] -- 1 individual intermediate key crowd It is beforehand embedded as Synthesis ENCMKIGSa. Individual for a start [ each / encryption ] An intermediate key group set (ENCMKIGSa -- ENCMKIGSn) is receiving set 13a. -- It is different to every 13eta. It is made to become a To value. This is each receiving set 13a, for example. -- Every 13eta, Period Another child PID -- 1 [ Realization can be carried out. ] -- PID -- It rubs so that an individualization variable (x, y) which is different by every k may be generated and used.
0245[0099] (5) individual intermediate key storage 1305a
0246individual intermediate key storage 1305a -- a figure -- 31 shows -- as -- the first -- individual intermediate key group MKIGa And the [ Facial expression ] -- 2 individual intermediate key group MKIIGa is held. this individual intermediate key storage 1305 a -- the first -- the [ individual intermediate key group acquisition part 1302a and ] -- from 2 individual intermediate key group acquisition part 1303a It is accessible.
0247[0100] (Six) common information receiving part 1306
0248When common information receiving part 1306 receives common information ECM from server 12, it receives. It was common information ECM is outputted to the second selecting part 1307a.
0249[0101] The (7) second selecting part 1307a
0250When the second selecting part 1307a receives common information ECM from common information receiving part 1306 Based on the common information identifier (ECMIDI or ECMIDII) contained in the common information ECM, the common information ECM is a seal about the first community information ECMI and the second community information ECMII. Disconnect is carried out. When the common information ECM is the first individual information ECMI, it is individual intermediate key storing. Individual intermediate key group MKIGa is acquired from part 1305a for a start, and they are the first community information ECMI and the first piece. Another intermediate key group MKIGa is outputted to the first share key acquisition part 1308a. opposite -- the common Sentiment the case where news ECM is the second individual information ECMII -- the [ from individual intermediate key storage 1305a ] -- inside of 2 individual acquiring between keys MKIIGa -- the -- the [ 2 common information ECMII and ] -- 2 individual intermediate key group MKIIGa -- The It outputs to 2 share key acquisition part 1309a.
0251[0102] The (8) first share key acquisition part 1308a
0252the first share key acquisition part 1308a -- the first from the second selecting part 1307a -- individual intermediate key group MKIGa the [ and ] -- the case where 1 common information ECMI is received -- first -- the -- strange [ at the time ], from 1 common information ECMI -- strange several -- PRG is extracted. Then, it is about strange variable rl, r2, r3, and r4 then at the time from strange variable group PRG. It extracts and extracts individual intermediate key mkl 1, mkI2, mkl 3, and mkI4 from individual intermediate key group MKIGa for a start. then, receiving set common intermediate key generation formula "given beforehand -- a basis [" / SMK= (rl+mkll) * (rl+mkI2)+(rl+mkI3) * (rl+mkI4) mod N] -- Both a connoisseur -- intermediate key SMK is generated. And encryption share key ENCS K is extracted from the first community information ECMI, and the code Common key ENCSK is decoded based on generated common intermediate key SMK. It turns and acquires share key SK. And the share key SK is outputted to outputting part 1310.
0253[0103] The (9) second share key acquisition part 1309a
0254the second share key acquisition part 1309a -- the [ from the second selecting part 1307a ] -- the [ 2 individual intermediate key group MKIIGa and ] -- the case where 2 common information ECMII is received, First, second encryption share keys ENCSKG power and second encryption share key ENCSK1, ENCSK2, ENCSK3, ENCSK4, ENCSK 5, and ENDSK6 are extracted. the [ and ] -- the second contained in 2 individual intermediate key group MKIIGa a system secret key -- Based Code Y of the share key SK was carried out with The and its second system secret key. Cryptogram, One cryptogram of second encryption share key ENCSK1, ENCSK2, ENCSK3, ENCSK4, EN CSK5, and ENDSK6 which chose one from power someday and was chosen is decrypted, and and share key SK are acquired. Then, the share key SK is outputted to outputting part 1310. As the method of choosing one from second encryption share key ENCSK1, ENCSK2, ENCSK3, ENCSK4, ENCSK5, or E NDSK6, To the second community information generating part 126 It sets and is in the second code Share keys ENCSKG, The which uses a share key for carrying out a code It is each second code Y about the second system secret key identifier which identifies a 2 system secret key. It is made to make a share key correspond. the -- being contained like 2 individual intermediate key group MKIIGa Make it include the second system secret key identifier corresponding to the second system secret key of To. Based on the second system secret key identifier, it is second code Common keyENCSK1. -- Inside power of ENDSK6 There are the method of choosing one, etc.
0255[0104] (10) outputting part 1310
0256outputting part 1310 -- or [ ! of the first share key acquisition part 1308a or the second share key acquisition part 1309a, and a gap ] -- from -- when share key SK is received, received share key SK is outputted to the exterior. [0105] <Operation of receiving set 13a>
0257Although the composition of receiving set 13a was explained above, it is Motion of receiving set 13a here. Work is explained. first, the time of receiving individual information group EMMG -- the first -- individual intermediate key the [ group MKIGa and ] -- the operation at the time of acquiring 2 individual intermediate key group MKIIGa -- a figure -- 32 -- Show It explains using a To flow chart. next, the time of receiving common information ECM -- the first piece the [ another intermediate key group MKIGa or ] -- using 2 individual intermediate key group MKIIGa -- it is acquisition about share key SK the operation at the time of carrying out -- a figure -- it explains using the flow chart shown in 33.
0258[0106] <<Operation when individual information group EMMG is received from key issue center 11>>
0259Individual information receiving part 1301 which received individual information group EMMG from key issue center 11 is Acceptance. The first individual information EMMI out of individual information group EMMG which carried out Trust, and the second individual information EM mupi is extracted. (S1301)
0260individual information receiving part 1301 -- the first individual information EMMI -- the first -- individual intermediate key group acquisition part 130 outputting to 2a -- the second individual information epsilonmumupi -- the -- outputted to 2 individual intermediate key group acquisition part 1303a. (S1302)
0261Individual intermediate key group acquisition part 1302a is individual key storing for a start which received the first individual information EMMI. It is an individual intermediate key group receiving set identifier AIDa, individual key IKa, and for a start [ encryption ] from part 1304a. Set ENCMKIGSa is acquired. (S1303)
0262From the first individual information EMMI that individual intermediate key group acquisition part 1302a received for a start to Period Another child PID -- To i and receiving set identifier AIDa stored in individual key storing part 1304 Key ENCPKa is acquired during the corresponding encryption. (S 1304)
0263individual intermediate key group acquisition part 1302a is stored in individual key storing part 1304 for a start -- and It was -- individual decrypting key ENCPKa during the encryption based on key IKa -- a period -- Key PK -- i -- get. (S1305)
0264Individual intermediate key group acquisition part 1302a is out of individual intermediate key group set ENCMKIG Sa for a start [ encryption ] for a start, Encryption No. corresponding to period identifier PID--i in the first individual information EMMI A 1 individual intermediate key group is acquired and it is key PK during the period. -- It is based on i and is an individual intermediate key group for a start [ the / encryption ]. Decoding Y is performed and individual intermediate key group MKIGa is acquired for a start. (S1306)
0265Individual intermediate key group acquisition part 1302a is Pieces about individual intermediate key group MKIGa for a start which was decrypted for a start. It stores in another intermediate key storage 1305a. (S 1307)
0266the second individual information from individual information receiving part 1301 the [ which received epsilonmumupi ] -- 2 individual intermediate key group Take profitable part 1303a -- individual key storing part 1304a to receiving set identifier AIDa and individual key IKa It acquires. (S1308)
0267the -- the second individual information that 2 individual intermediate key group acquisition part 1303a received Individual key from epsilonmumupi code Y second corresponding to receiving set identifier AIDa stored in storage 1304 -- individual Intermediate key group ENCMKIIGa is acquired. (S1309)
0268the -- 2 individual intermediate key group acquisition part 1303a is based on individual key IKa -- the encryption second -- individual Intermediate key group ENCMKIIGa is decrypted. (S 1310)
0269the -- the [ which 2 individual intermediate key group acquisition part 1303a decrypted ] -- 2 individual intermediate key group MKIIGa -- Pieces It stores in another intermediate key storage 1305a. (S 1311)
0270<<Operation [ when common information ECM is received from server 12 ] >>
0271Community which common information receiving part 1306 which received common information ECM from server 12 received Information ECM is outputted to the second selecting part 1307a. (S1351)
0272The second selecting part 1307a that received common information ECM from common information receiving part 1306, the -- the case where the common information identifier contained in common information ECM is acquired, and the common information identifier is ECMIDI -- the common information ECM -- the -- considering it as 1 common information ECMI Individual intermediate key rank Individual intermediate key group MKIGa is acquired from Payment part 1305a for a start, individual intermediate key group MKI Ga and the first community information ECMI are outputted to the first share key acquisition part 1308a for a start [ the ], and it is step S 135. It progresses to 2. When the common information identifier is ECMIDII, it is The about the common information ECM. It is considered as 2 common information ECMII, the [ from individual intermediate key storage 1305a ] -- acquiring 2 individual intermediate key group MKIIGa -- the [ the ] -- the [ 2 individual intermediate key group MKIIGa and ] -- 2 common information ECMII -- The It outputs to 2 share key acquisition part 1309a, and progresses to Step S1356. (S1352)
0273The first share key acquisition which received individual intermediate key group MKIGa and the first community information ECMI for a start Part 1308a extracts strange variable PRG from the first community information ECMI at the time, and is then strange after that. Strange variable rl, r2, r3, and r4 are extracted from variable group PRG at the time. And individual intermediate key mkll, mkI2, mkI3, and mkI4 are extracted from individual intermediate key group MKIa for a start. And it is To beforehand. Common intermediate key SMK is calculated based on receiving set community intermediate key generation type" SMK= (rl+mkll) * (r2+mkI2)+(r3+ mkI3) * (r4+mkI4) mod N" obtained. (S1353) The first share key acquisition part 1308a is the first community information ECMI to encryption share key ENCSK. Decoding Y of the code Common key ENCSK is carried out based on common intermediate key SMK extracted and generated.
0274Share key SK is acquired. (S1354)
0275The first share key acquisition part 1308a outputs the share key SK to outputting part 1310, and is Step S.
0276It progresses to 1358. (S1355)
0277the -- the [ 2 individual intermediate key group MKIIGa and ] -- the second share Kotori which received 2 common information ECMII profitable part 1309a -- second encryption share key ENCSK1 from encryption share keys ENCSKG, and E
0278NCSK2, ENCSK3, ENCSK4, ENCSK5, and ENCSK6 are extracted. And the second It is based on individual intermediate key group MKIIGa, and they are the six second encryption share key ENCSK1 and EN.
0279One [ corresponding / either ] of CSK2, ENCSK3, ENCSK4, ENCSK5, and the ENCSK6 A cryptogram is decrypted and share key SK is acquired. (S1356)
0280The second share key acquisition part 1309a outputs share key SK to outputting part 1310. (S1357) Outputting part 1310 outputs received share key SK to the exterior, when share key SK is received from either the first share key acquisition part 1308a or the second share key acquisition part 1309a. (S
02811358)
0282The above is the composition and operation of receiving set 13a which are the components of key distribution system 1. What Receiving set 13b of receiving set 13a and others -- The difference with 13 eta is as follows.
0283[0107] For a start [ (i) ], in order to acquire an individual intermediate key group for a start by individual intermediate key group acquisition part 1302a, it is Pieces. It is individual middle the receiving set identifier obtained from another key storing part 1304a, an individual key, and for a start [ encryption ]. A keys set is each receiving set 13a. -- It differs by 13 eta.
0284(ii) the -- 2 individual intermediate key group acquisition part 1303a -- the -- in order to acquire a 2 individual intermediate key group -- Pieces the receiving set identifier and individual key which are obtained from another key storing part 1304a -- each receiving set 1 3a -- It differs by 13 eta.
0285[0108] (iii) -- being stored by individual key storing part 1304a -- , a Reception unit identifier, and (AIDa -- AIDn) an individual key, and (iKa-IKn) the encryption first -- an individual intermediate key group set -- each receiving set 1 3a -- It differs by 13 eta.
0286[0109] being stored by (iv) individual intermediate key storage 1305a -- the [ and / To ] -- a 1 individual intermediate key group and the second -- individual
0287An intermediate key group is each receiving set 13a. -- It differs by 13 n.
0288[0110] the first acquired from individual intermediate key storage 1305a by the second selecting part 1307a of (V) -- inside of individual the [ between keys and ] -- a 2 individual intermediate key group -- each receiving set 13a -- It differs by 13 n.
0289[0111] It is individual middle for a start which is used by the first share key acquisition part 1308a of (vi) when acquiring share key SK. Keys are each receiving set 13a. -- It differs by 13 n.
0290[0112] It is the second share key acquisition part 1309a of (vii),
0291the [ which is used by the second share key acquisition part 1309a when acquiring share key SK ] -- 2 individual intermediate key a group -- each receiving set 13a -- It differs by 13 n.
0292[0113] <Verification of Embodiment 1 of operation>
0293in this Embodiment 1 -- each receiving set 13a -- The first which takes a different value to 13 eta Individual intermediate key group MKIGa -- the [ MKIGn and ] -- 2 individual intermediate key group MKIIGa -- MKIIGn -- rate Irrespective of It is assigned all the receiving sets 13a -- in 13 eta -- the same share key SK the reason which can be derived -- One [ ] -- it Explanation.
0294[0114] It is individual intermediate key group MKIGa the first community information ECMI and for a start first. -- Place using MKIGn Synthesis is explained. It is individual intermediate key group MKIGa for a start. -- As for MKIGn, each is To beforehand. They are individual intermediate key mkl 1, mkI2, and mkl for a start which fills an individual intermediate key generation type for a start [ four ] which are obtained.
0295It comprises 3 and mkI4. the time -- strange variable group PRG and the time of four -- strange variable generation type It is generated so that it may fill. By doing in this way, it is a receiving set common intermediate key generation type. It can change as follows.
0296[0115] SMK= (rl+mkll) * (r2+mkI2) + (r3+mkI3) * (r4+mkI4)
0297= {s* +x) +v*m} * * (w+y) +u*n} + lu* (z-- x) +t*m} * {v*
0298(w -- y) +s water n}
0299= {s* (z + x) *t* (w+y) +u* (z-- x) *v* (w-- y)} + {u*n*s* (z + x) +v*m*t* (w+y) + s*n*u* (z-- x) +t*m*v* (w-- y)} +u* v*m* n+s water t water m water n
0300It becomes. It is using the conditions of "x*y=c" here,
0301* - = 2*s*t* (z*w+c*n*m)+ 2* (u*s*n*z+t*v*m*w) Becoming, this is all the receiving sets 13a. -- Only a parameter common to 13 n is power. It changes (it is got blocked and individualization variables X and y are not included). Therefore, all the receiving sets 13a -- In 13 eta, common intermediate key SMK derives a common value. This is server common intermediate key generation. A formula and SMK="2 * s * t * z *w+c * n * m+ 2 * (u* s * n* z+t *v* m*w) and , It is in agreement.
0302[0116] the [ next, ] -- the [ 2 common information ECMII and ] -- 2 individual intermediate key group MKIIGa -- case of MKIIGn It attaches and explains. the -- 2 individual intermediate key group MKIIGa -- MKIIGn is given beforehand, respectively Any second one system of the second system secret key (in the case of Example 1 six pieces) of Multiple It comprises a secret key. The second share information ECMII is a plurality of The about share key SK. The cryptogram of share key SK which carried out code Y using each of a 2 system secret key is included, and they are and To . Therefore, one second system secret key of a plurality of second system secret keys is held. The , All receiving set 13a -- The and common share key SK can be derived now to 13 eta. It is.
0303[0117] <Effect of Embodiment 1>
0304in Embodiment 1 of the present invention, share key SK common to all the receiving sets is peculiar to a receiving set the first -- the [ an individual intermediate key group and ] -- it was made to be generated from a 2 individual intermediate key group doing so should -- the first -- the [ an individual intermediate key group or ] -- one individual information of the 2 individual intermediate key groups Even if forged, the receiving set of a revealing agency is specific using another individual intermediate key. It comes to be able to do and can realize improvement in safety.
0305[0118] (Embodiment 2)
0306Key distribution system 2 as one embodiment concerning the present invention is explained. Fruit With key distribution system 1 in applied configuration 1, Each output unit 13a -- 13 eta is common information ECM. When it receives, Two share key acquisition methods! One [ /, of a gap, a gap, or ] method is chosen. Power which acquired Shared key Contents distribution system 2 in Embodiment 2, When ECM is received, the point which acquires a share key using two share key acquisition methods both differs from and Embodiment 1 greatly.
0307[0119] Below, explain the details of contents distribution system 2 which is one embodiment of the contents distribution system of the present invention. [0120] <Composition of contents Rooster S Trust system 2>
0308key distribution system 2 -- a figure -- it is shown in 34 -- as -- the same channel 10 as Embodiment 1, and operation Key issue center 21 which differs in form 1, server 22 which differs in Embodiment 1, and plurality receiving set 22a which is different in Embodiment 1 -- It comprises 22 eta. Role of each component Key issue center 11 and the sir in key distribution system 1 whose One and The are Embodiments 1 comparatively A 12 and output unit 13a -- It is the same as 13 eta respectively.
0309[0121] Below, explain the details of key distribution system 2 which is one embodiment of the key distribution system of the present invention.
0310[0122] Explain the component of these in detail. First, key issue center 21, server 22, and receiving set 23a -- The composition and operation of 23 eta are explained using figures.
0311[0123] Composition > of Key issue center 21
0312key issue center 21 -- a figure -- it is shown in 35 -- as -- the fourth control part 211 and the third individual information generation part 2 12, information storing part 113 corresponding to a receiving set, system secret variable group set transmission section 215, and individual Sentiment News group distribution part 216 and power It is constituted. information storing part 113 corresponding to the receiving set in key distribution system [ in / about information storing part 113 corresponding to a receiving set / and Embodiment 1 ] 2 -- the same -- it is -- since -- explanation is omitted.
0313[0124] The (1) first control part 211
0314Key when the first control part 211 fulfills the renewal conditions of individual information given beforehand When issue center 23 carries out a start of operation, it is the third about the third individual information generation demand REQEMMIII. It outputs to individual information generation part 212. For example, the renewal conditions of individual information are the cases "during [ every ] a certain specified term (example: every day by day [ 1 ] and year)", The first control part 211 is provided with a counter etc. It can realize and is renewal condition power of individual information' external power. " when a certain signal is received In which case, realization by the first control part 211 being provided with the receiving part which receives an external signal etc. is possible. It is ability.
0315[0125] The (2) third individual information generation part 212
0316the third individual information generation part 212 -- a figure -- as shown in 36, it comprises third system secret variable group generation part 2121 and first intermediate key group generation part 2122.
0317[0126] (2 -- 1) The third system secret variable group generation part 2121 The third system secret variable group generation part 2121, From the first control part 211 to the third individual information generation Six each of first system secret variable group identifier SPGIID 11SPGIID6 is received the case where demand REQEMMIII is received, The first system secret variable group {SPGI1, SPGI2, S PGI3, SPGI4, SPGI5, and SPGI6} is generated. About each composition of the first system secret variable group SPG Ii (SPGIl -- SPGI6), key distribution System of Embodiment 1 Beam 1 -- the same -- a figure -- as [ show / 5 ] -- five -- it is first system secret variable (second--i, t--i, u [ -- i, c / -- i:i ] -- i, v 11 6) Power ゝ constituted. Each first system secret variable SPGI11SPGI6 is [ -- i mod N / :i is generated so that 116" may be filled. ] first system secret variable generation type" s beforehand. -- i * t -- i=u -- i *v For example, the five first system secret variables and Modus N is a 128-bit natural number, for example. It is considered as a value beforehand common to the value of modulus N here, the third community information generating part 225 mentioned below, and the third share key generation part 2308a. It is the same value as Is given modulus N, for example, is 2". It is {128} etc. Here, "is Should power, for example, is 2". {4} means 16 and uses it in the same meaning henceforth. First system secret variable group identifier SPGID1 -- SPGIID6 -- each first system Secret variable group SPGI1 -- it is the identifier matched with SPGI6 -- for example, -- respectively -- different -- It is a natural number. For example, six first system secret variable group identifier SPGIID1 -- SP GIID6 -- 11 of a natural number -- it may be 6 -- it may carry out and a random number may be sufficient. To how to generate a random number It attaches and nonpatent literature 3 is detailed. and a figure -- 37 shows -- as 6 sets of first systems Group {SPGIID1, SPGIl HSPGII D2, and SPGI2} of a secret variable group identifier and the first system secret variable group - - - The third system secret variable group SPGIII which consists of {SPGIID6 and SPGI6} It generates, The third system secret variable group set transmission section 215 and the first intermediate key group generation part 221 It outputs to 2.
0318(2 -- 2) The first intermediate key group generation part 2122
0319The first intermediate key group generation part 2122 is the third Si from the third system secret variable group generation part 2121. When stem secret variable group SPGIII is received, it is Acax to information storing part 113 corresponding to a receiving set. A is carried out and it is receiving set identifier AIDa. -- AIDn is acquired. And six first system secret keys first contained in the third system secret variable group SPGIII to receiving set identifier A.I. Artificial Intelligence Da Group SPGI1 -- The inside of SPGI6 to the one first system secret keys are chosen. this one the selection method of the first system secret keys has the method of choosing at random, for example, etc. -- this is realizable by using a random number. The key here chosen to receiving set identifier A IDa as an example, the -- considering it as 1 secret variable SPGIi (SPGIi SPGI1 -- of SPGI6 either) -- the -- 1 secret variable SPGIi -- six first system secret variable s_i and t_i as well asu -- i and V -- i and c -- it is assumed that it is ゝ constituted. and the first six System -- secret -- a variable -- s -- i -- t -- i -- u -- i -- v--i -- c -- i -- a basis -- beforehand -- giving -- having -- individualization -- a variable -- generation -- a formula -- " -- x -- * -- y=c -- i mod N -- " -- filling -- as -- two -- a One -- individualization -- a variable -- x -- y -- generating . Here, as a method of generating two individualization variables x and y, a random number is used and it is raw at random, for example. There are the method of carrying out Formation, etc. For example, it is a 128-bit natural number, and and "*" are multiplication operations, for example, 2*5 means 10, and individualization variables x and y are business at the same meaning henceforth. It is. random [, for example / in individualization variable X ] as how to ask for these individualization variables x and y -- ready -- x*y=c -- generating as a numerical value -- individualization variable generation type "-- substituting that individualization variable x for i mod N", there are a method of asking for the remaining individualization variables y, etc., and random -- individual If one-izing variable X is chosen, individualization variable y certainly exists. Then, the individualization variables X and y are used, the four firsts given beforehand -- individual intermediate key generation type "-- mkll = s [ -- It is based on il *y mod N" and is individual intermediate key mkll for a start / four /, ] -- i * x mod N, ,ゝ, mkI2=t- i *y mod N, ,ゝ, mkI3= -- u- i* x mod N, ,ゝ, mkI4= -- v It is raw about mkI2, mkI3, and mkI4. Formation is carried out. and the four first -- from individual intermediate key mkll, mkI2, mkI3, and mkI4 -- composition -- Individual intermediate key group MKIGa is generated for a start [ as shown by To be figure 30 ]. Then, based on the individual key I Ka, code Y of individual intermediate key group MKIGa is performed for a start, The cryptogram is set to individual intermediate key group ENCMKIGa = Enc (IKa, MKIGa) for a start [ encryption ], Receiving set identifier AIDa and the first system secret variable group identifier SPGIIDi to the first secret variable SPGIi (SPG IIDi is matched with any power of 11SPGIID6.) And other receiving set identifiers AID b -- It is made the same also to AIDn, the encryption first -- Individual intermediate key group ENCMKIGb -- being referred to as - and E NCMKIGn -- Each receiving set identifier AIDb -- AIDn and the first system secret -- strange It matches with number group identifier SPGIIDi. And receiving set identifier A.I. Artificial Intelligence Da as shown in Drawing 38 -- It is individual intermediate key group ENCMKIGa AIDn and for a start [ encryption ]. -- ENCMKIGn and the first The third individual information that comprises a system secret variable group identifier epsilonmumuiotapi is created, The The 3 individual information EMMIII is outputted to individual information group distribution part 216. It is an individual intermediate key for a start here. Code Y algorithm which uses a group for carrying out code Y, it is a statement to nonpatent literature 2 receiving set 23a which is a DES code method etc. and it mentions below -- the [ of 23 eta ] -- 3 individual intermediate key group Take the time of decrypting an individual intermediate key group for a start [ encryption ] in profitable part 1303a -- business -- the same method as !Recovery A Í rhythm is used.
0320[0128] (3) system secret variable group set transmission section 215
0321system secret variable group set transmission section 215 -- the third system of the third individual information generation part 212 the case where the third system secret variable group SPGIII is received from secret variable group selection part 2121 -- the -- The third system secret variable group set SPGIII is turned to server 22, and it transmits.
0322[0129] (Four) individual information group distribution part 216
0323Individual information group distribution part 216 is the first intermediate key group generation part 212 of the third individual information generation part 212. When the 2 to third individual information EMMIII is received, the third individual information EMMIII is received. Device 23a -- It distributes towards 23 eta.
0324[0130] Operation > of Key issue center 21
0325Power which explained the composition of key issue center 21 above Here, it is key issue center 2. Operation of 1 is explained. fulfilling here the renewal conditions of individual information given beforehand the case where it is -- or When key issue center 21 carries out a start of operation, they are distribution and Acceptance about a share key. They are server 22 and a plurality of receiving sets 23a about key information required to carry out Trust. -- If it distributes to 23 eta Operation of Can is explained using the flow chart shown in Drawing 39. the -- 3 individual Sentiment News generation part 212 is generation about the third system secret variable group SPGIII and the third individual information EMMIII. The details of operation when carrying out are explained using the flow chart shown in Drawing 40.
0326[0131] <<Operation at the time of the key information distribution by key issue center 21>>
0327The first control part 211 is the third individual information generation demand to the third individual information generation part 212. REQE mumupiiota is outputted. (S2101)
0328the third individual information generation part 212 -- a figure -- following a flow chart (details are explained below) as shown by 40 the third system secret variable group SPGIII and the third individual information EMMIII are generated -- the third system secret variable group SPGIII -- the third system secret variable group set transmission section 215 -- output It carries out and outputs the third individual information EMMIII to the third individual information distribution part 216. (S2102) The third system secret variable group set transmission section 2 which received the third system secret variable group SPGIII 15 transmits the third system secret variable group SPGIII to server 22. (S2103) the third individual information the third individual information distribution part 216 which received epsilonmumupiiota -- the [ the ] -- 3 individual Sentiment news epsilonmumupiiota -- receiving set 23a -- It distributes to 23 eta and ends. (S2104)
0329The << third system secret variable group SPGIIIS and the third individual information It is operation >> at the time of generation (detailed explanation of Step S2102) about epsilonmumupiiota.
0330The third system secret variable group generation part 2121 which received the third individual information generation demand REQEMMIII, They are the five first system secret variables (second--i, t -- i, u -- i), respectively. v -- i and c -- i:i -- one -- 1 -- generating the first system secret variable group {SPGI1, SPGI2, SPGI3, SPGI4, SPGI 5, SPGI6} which consists of 6 First system secret variable group identifier SPGIID1 -- That of SPGIID6 It matches to Each. (S21021)
0331The third system secret variable group generation part 2121, 6 sets of first system secret variable group identifiers And group {SPGIID1 and SPGI1} of the first system secret variable group {SPGIID2 and SPGI2} - - - The third system secret variable group SPGIII which consists of {SPGIID6, SPGI6} is generated, The third Sis It outputs to Tem secret variable group set transmission section 215 and the first intermediate key group generation part 2212. (S2 1022)
0332The first intermediate key group generation part 2122 which received the third system secret variable group SPGIII is Receiving. Correspondence information storing part 113 is accessed and it is receiving set identifier AIDa. -- AIDn is acquired. (S21023)
0333The first intermediate key group generation part 2122 which received the third system secret variable group SPGIII, The third Si Six first system secret keys SPGI1 contained in stem secret variable group SPGIII -- From the inside of SPGI6, the one first system secret keys SPGIi (i 11 6) are chosen -- the first five Sis Tem secret variable s -- i and t -- i and u -- i and V -- i and c -- i is extracted. (S 21024) The first intermediate key group generation part 2122, five -- a piece -- the -- one -- a system -- secret -- a variable -- s--i -- t -- i -- u -- i -- v -- _ -- i -- c -- i -- a basis -- beforehand -- giving -- having -- individualization -- a variable -- generation -- a formula -- " -- x*y=c -- i mod N -- " -- filling -- Two individualization variables [ like ] x and y are generated. (S21025)
0334The individualization variables X and y are used for the first intermediate key group generation part 2122, the four firsts given beforehand -- individual intermediate key generation type "-- mkll = s i* x mod N", " -- mkI2=t i *y mo d N and mkI3= -- u- i* x mod N and mkI4= -- v -- il *y mod N -- it is alike, and it is based and individual intermediate key mkll, mkI2, mkI3, and mkI4 are generated for a start [ of 4 Pieces ]. and the four The 1 individual intermediate key mkll, mkI2, mkI3, and mkI4 power the figure constituted -- the first piece as shown by 30 Another intermediate key group MKIGa is generated. (S21026)
0335The first intermediate key group generation part 2122 is based on an individual key, and is encryption of an individual intermediate key group for a start. It carries out, the cryptogram is made into an individual intermediate key group for a start [ encryption ], and it is still an individual intermediate key group for a start [ encryption ]. It assigns to the receiving set identifier which is not assigned. (S21027)
0336the first intermediate key group generation part 2122 -- All the receiving set identifiers AIDa -- as opposed to AIDn -- dark the [ item Y ] -- if a 1 individual intermediate key group is assigned, it will progress to Step S21029. if -- all -- Receiving set identifier AIDa -- the individual intermediate key group was assigned for a start [ encryption ] to AIDn. , -- it returns to Step 21024. (S21028)
0337The first intermediate key group generation part 2122 is receiving set identifier AIDa. -- AIDn and the first piece of encryption Another intermediate key group ENCMKIGa -- From ENCMKIGn and the first system secret variable group identifier The third individual information epsilonmumupiiota constituted is created, The third individual information About epsilonmumupiiota, it is individual Sentiment. It outputs to news group distribution part 216. It ends. (S21029)
0338It is power above. It is the composition and operation of key issue center 21 which are the components of key distribution system 2. The composition, Stickiness of operation, and Explanation of Continuing, The, and server 22 are performed.
0339[0132] <Composition of server 22>
0340server 22 -- a figure -- it is shown in 41 -- as -- system secret variable group set receiving part 221 and system the [ secret variable group storage 222, share key generation part 123, and ] -- 3 common information generating part 225 and common information It comprises distribution part 227. About share key generation part 123, since it is the same as share key generation part 123 in key distribution system 1 of Embodiment 1, explanation is omitted.
0341[0133] (1) system secret variable group set receiving part 221
0342system secret variable group set receiving part 221 -- the third system secret from key issue center 21 -- strange Case where number group set SPGIIIS is received, the received third system secret variable group set SPGIIIS -- a figure -- storing in system secret variable group storing 222 as shown by 42 -- share key generation part 123 Share key generation demand REQSK is outputted.
0343[0134] (2) system secret variable group storage 222 system secret variable group storage 222 -- a figure -- 42 shows -- as -- the third system secret variable crowd Synthesis SPGIIIS is stored.
0344(3) The third community information generating part 225
0345The third community information generating part 225 receives share key SK from common information generating part selecting part 124. In the It was case First, system secret variable group storage 222 is accessed, and it is the third system secret variable. Group SPGIII is acquired and the inside power is also 6 sets of first system secret variable identifiers, and the first system. A secret variable group is extracted. and the set of first system secret variable identifier SPGIID1 and first system secret variable group SPGI1 are received -- six first system secret variable s--l, t_1, and u -- 1 and v -- 1 and c -- 1 is extracted. Then, four random numbers z, w, and m and n are generated. Here It generates at random, using a random number for example as a method of generating random number z, w, and m and n. There are the method of carrying out, etc. Random number z, w, and m and n are 128-bit nature, respectively, for example. It is a number. and the time of four given beforehand -- strange variable generation type "-- rl = s -- l*z+v -- l*m mod N, r2=t- 1 *w+u- l*n N, r3=u- l*z+t- l*m mod N", "r4=v -- 1 *w+s -- Based on 1 *n N", it is Generate about strange variable rl, r2, r3, and r4 at the time of four. To. and the figure where strange variable rl, r2 and r3, and r4 power are also constituted when it generates -- strange, when 20 shows generating variable group PRG (this -- the time -- strange -- referred to as variable PRG1) -- that time -- strange variable group PRG -- the first It matches with system secret variable identifier SPGIID1. Then, common intermediate key SMK Prediction 1 * Because -- common to a Given server -- intermediate key generation type" -- SMK=2*s -- 1 *t -- (z+w+c -- 1+n*mj+2* (u- l*s- l*n*z+t- l*v- l*m*w) -- Generation based on is mod N and carried out.) Dark of share key SK finally received based on the common intermediate key SMK It is item-ization, Line code Purchase shared key ENCSK is generated (this is set to share intermediate key ENCSK1) -- strange [ at first system secret variable identifier SPGIID1 and the time ] in the code Common key ENCSK It matches with variable group PRG. And first system secret variable identifier SPGIID 2 of other groups -- SPGIID6 and first system secret variable group SPGI2 -- As opposed to SPGI6, SPGIID1 -- all -- To -- the same -- the time -- Strange variable group PRG2 -- PRG6 and code Purchase shared keyENCSK2 -- ENCSK6 -- Creation is carried out. And first system secret variable identifier SPGIID1 -- It is [ SPGIID6 and ] strange variable group PRG1 at the time. -- PRG6 and code Purchase shared keyENCSK1 -- It consists of ENCSK6, a figure -- the [ as shown by 43, and ] -- 3 common information ECMIII is created, and it is alike to a common information distribution part, and outputs to it. The code Y algorithm used for code Y of share key SK here, For example, receiving set 13a which is a DES code method etc. and it mentions below -- The same method as the decoding Y algorithm used for decrypting code Common key E NCSK in each third share key acquisition part 2308a of 13 eta is used.
0346[0136] (Four) common information distribution part 227
0347Common information distribution 227 receives the third community information ECMIII from the third community information generating part 225. When it carries out, it is receiving set 23a. -- The third community information ECMIII is distributed to 23 eta.
0348[0137] <Operation of server 22>
0349power which explained the composition of server 22 above here -- operation of server 22 -- just -- Explanation is carried out. first, the third System used when distributing share key SK from key issue center 21 the operation at the time of receiving Beam secret variable group set SPGIIIS -- a figure -- Frochia 1 shown in 44 It explains using A. next, share key generation important point from system secret variable group set receiving part 221 the case where Request REQSK is received -- or Place which fulfilled the renewal conditions of a share key given beforehand Synthesis and server 22 are receiving sets 23a. -- It explains to the operation at the time of distributing new share key SK to 23 eta using the flow chart shown in One VGo figure 45.
0350<<[0138] Operation when the third system secret variable group set SPGIIIS is received from key issue center 21
0351>
0352System secret variable group set receiving part 221 stores the received third system secret variable group set S PGIIIS in system secret variable group storage 222, and is completed. (S2202)
0353<<server 22 is receiving set 23a. -- which share key generation part 123 of operation>> generates share key SK when distributing new share key SK to 23 eta, and is outputted to the third community information generating part 225. (S2251)
0354The third community information generating part 225 accesses system secret variable group storage 222, and is the third. System secret variable group SPGIII is acquired and they are 6 sets of first system secret variable discernment from the inside. The first system secret variable group is extracted with a child. (S2252)
0355the -- 3 common information generating part 225 -- yet -- the time -- strange -- generating a variable group and an encryption share key! / -- as opposed to V, a set of first system secret variable identifiers, and the first system secret variable group Six pieces The first system secret variable [ -- i, v / -- i, c / -- i is extracted and four random numbers z, w, and m and n are generated after that. ] s -- i, t -- i, u (S2253) The third community information generating part 225, the time of four given beforehand -- strange variable generation type "-- rl = s -- i*z+v- i*m mod N, r2=t- i*w+u- i*n N, r3=u- i*z+t- i*m mod N", "r4=v -- i*w+s -- It is about strange variable rl, r2 and r3, and r4 based on i*n N" at the time of four. It generates. (S2254)
0356The third community information generating part 225 generates strange variable group PRG, when it generates and strange variable rl, r2, r3, and r4 power are also constituted. (S2255)
0357The third community information generating part 225 is common intermediate key SMK, Inside of server [ which is given beforehand ] common It is key generation type" SMK=2*s in between. -- i*t -- It generates based on i*+(z+w+c -- i+n*m)2* (u -- i*s -- i* n*z+t_i*v_i*m*w) mod N." (S2256)
0358The third community information generating part 225 enciphers received share key S K based on common intermediate key SMK, generates code Purchase shared key ENCSK, and is the encryption share key ENCSK. It matches with strange variable group PRG at first system secret variable identifier SPGIID1 and the time. (S22 57)
0359the -- 3 common information generating part 225 -- first system secret variable identifier SPGIID1 of all the groups -- as opposed to 1SPGIID6 -- the time -- Strange variable group PRG1 -- PRG6 and encryption share key ENCSK1 -- if EN CSK6 is generated, it will progress to Step S2259. the first system secret Variable identification of all the groups Strange variable group PRG1 -- PRG6 and encryption share key ENCSK1 -- Another child SPGIID1 -- as opposed to SPGIID6 -- the time -- if ENCSK6 is not generated, it will return to Step S2252. (S2258) The third community information generating part 225, First system secret variable identifier SPGIID1 -- It is [ SPGIID 6 and ] strange variable group PRG 1 at the time. -- PRG6 and encryption share key ENCSK1 -- The third community information ECMIII which ENCSK6 power also becomes is created, and it outputs to passing common information distribution part 227. (S2 259)
0360Common information distribution 227 is receiving set 23a. -- The third community information ECMIII is distributed to 23 eta. It ends. (S2260)
0361The above is the composition and operation of server 22 which are the components of key distribution system 2. Then, , receiving set 23a -- The composition and operation of 23 eta are explained. First, style of receiving set 23a Operation is explained to be Formation, next they are receiving set 23a and other receiving sets 23b. -- 23 eta Difference is described. [0139] Composition > of Receiver 23a
0362receiving set 23a -- a figure -- it is shown in 46 -- as -- the [ individual information receiving part 2301 and ] -- 3 individual intermediate key group Acquisition part 2302a, Individual key storing part 2304a, individual intermediate key storage 2305a, common information reception It comprises part 2306a, third share key acquisition part 2308a, and outputting part 1310. Here, it is The. 3 individual intermediate key group acquisition part 2302a, individual key storing part 2304a, Individual intermediate key storage 2305a, common information receiving part 2306a, the third share key acquisition part 2308a, composition peculiar to Is a receiver 23a It is an element and they are individual information receiving part 2301, outputting part 1310, and Is a receiver 23a. -- In 23 eta It is a common component.
0363[0140] (1) individual-information receiving part 2301
0364individual information receiving part 2301 -- the third individual information group from server 22 Place which received epsilonmumupiiota Synthesis and the third received individual information epsilonmumupiiota -- the -- it outputs to 3 individual intermediate key group acquisition part 2302a
0365[0141] the [ (2) ] -- 3 individual intermediate key group acquisition part 2302a
0366the -- 3 individual intermediate key group acquisition part 2302a -- the third individual information from individual information receiving part 2301 the case where E mumupiiota is received -- first -- a figure -- receiving set from individual key storing part 2304a as shown in 47 Identifier AIDa and individual key IKa are acquired. and the third received individual information epsilonmumupiiota from -- dark corresponding to [ it is stored in individual key storing part 2304a, and ] and Reception unit identifier AIDa The first intermediate key group ENCMKIGa of item Y is acquired. Then, it is Encryption No. based on individual key IKa. They are a line, the first intermediate key group MKIGa, and the first System about decoding Y of 1 intermediate key group ENCMKIGa. Beam secret variable group identifier SPGIIDi is acquired. the last -- the first intermediate key group MKIGa And the first system [ of Facial expression ] secret variable group identifier SPGIIDi -- a figure -- individual intermediate key storing as shown by 48 It is alike to part 2305a, and stores in it.
0367[0142] (3) individual key storing part 2304a
0368individual key storing part 2304a -- a figure -- as shown in 47, receiving set identifier AIDa and individual key I Ka are held.
0369[0143] (4) individual intermediate key storage 2305a
0370individual intermediate key storage 2305a -- a figure -- 48 shows -- as -- the first -- individual intermediate key group MKIGa And The first system [ of Facial expression ] secret variable group identifier SPGIIDi is held. [0144] (Five) common information receiving part 2306a
0371The case where common information receiving part 2306a receives the third community information ECMIII from server 22, individual intermediate key storage 2305a is accessed, and they are individual intermediate key group MKIGa and the first System for a start. Beam secret variable group identifier SPGIIDi is acquired. And when in agreement with the and first system secret variable group identifier SPGIIDi out of the third community information ECMIII, they are strange variable group PRGi and a code. -izing share key ENCSKi is extracted. Then, it is [ individual intermediate key group MKIGa and ] a strange variable for a start at the time. Group PRGi and code Common key ENCSKi are outputted to the third share key acquisition part 2308a.
0372[0145] The (6) third share key acquisition part 2308a
0373Then strange, when the third share key acquisition part 2308a receives strange variable group PRGi and code Common key ENCSKi for a start from common information receiving part 2306a at individual intermediate key group MK IGa and the time Strange variable rl, r2, r3, and r4 are extracted from variable group PRGi at the time. And individual intermediate key mkll, mkI2, mkI3, and mkI4 are extracted from individual intermediate key group MKIGa for a start. Then, beforehand Common intermediate key SMK is generated based on receiving set community intermediate key generation type" SMK= (rl+mkll) * (rl+mkI2)+(rl+mkI3) * (rl+mkI4) mod N" given. And based on generated common intermediate key SMK, encryption share key ENCSKi is decrypted and share key SK is acquired. And the share key SK is outputted to outputting part 1310.
0374[0146] <Operation of receiving set 23a>
0375Although the composition of receiving set 23a was explained above, it is Motion of receiving set 23a here. Work is explained. first, the third individual information group Individual for a start, when epsilonmumupiiota is received the operation at the time of acquiring intermediate key group MKIGa -- a figure -- using the flow chart shown in 49 It explains. Next, it is business about the flow chart shown in of operation Stickiness[ at the time of using individual intermediate key group MKI Ga for a start, and acquiring share key SK, when the third community information ECMIII is received ] , and The figure 50. Are and it explains.
0376<<[0147] From key issue center 21 to the third individual information Operation when epsilonmumupiiota is received>>
0377the third individual information group from key issue center 21 individual information receiving part 2301 which received epsilonmumupiiota -- and the third individual information epsilonmumupiiota -- the -- it outputs to 3 individual intermediate key group acquisition part 2302a. (S2301) the third individual information the [ which received epsilonmumupiiota ] -- 3 individual intermediate key group acquisition part 2302a -- individual Key case Receiving set identifier AIDa and individual key IKa are acquired from Payment part 2304a. (S2302) the -- 3 individual intermediate key group acquisition part 2302a, The third received individual information From epsilonmumupiiota to an individual key The first middle of code Y corresponding to receiving set identifier AIDa stored in storage 2304 Key ENCMKIa and the first system secret variable group identifier SPGIIDa are acquired. (S2303)
0378the -- 3 individual intermediate key group acquisition part 2302a was stored in individual key storing part 2304 -- individual Based on key IKa, the first intermediate key ENCMKIa of encryption is decrypted, and the first intermediate key MKI a is acquired. (S2304)
0379the -- 3 individual intermediate key group acquisition part 2302a -- the first -- individual intermediate key group MKIGa and the first System secret variable group identifier SPGIIDa is stored in individual intermediate key storage 2305a. It ends. (S2304)
0380<<Operation when the third community information ECMIII is received from server 22>>
0381Common information receiving part 2306a which received the third community information ECMIII from server 22 is individual. They are individual intermediate key group MKIGa and the first system secret variable group for a start from intermediate key storage 2305a. Identifier SPGIIDa is acquired. (S2351)
0382common information receiving part 2306a -- the -- the first system secret out of 3 common information ECMIII -- strange The first system secret variable group identifier SPGIIDa corresponding to number group identifier SPGIIDa, and coincidence When carrying out, strange variable group PRGi and encryption share key ENCSKi are extracted. (S2352)
0383Common information receiving part 2306a is [ individual intermediate key group MKIGa and ] strange variable group PRGi And for a start at the time. Encryption key shared key ENCSKi is outputted to the third share key acquisition part 2308a. (S2353) the third share key acquisition part 2308a -- the time -- strange variable groups PRG and the time -- strange variable rl, r2, r3, and r4 It extracts. (S2354)
0384The third share key acquisition part 2308a extracts individual intermediate key mk II, mkI2, mkI3, and mkI4 from individual intermediate key group MKIGa for a start. (S2355)
0385receiving set common intermediate key generation type "to which the third share key acquisition part 2308a is given beforehand -- common intermediate key SMK is generated based on SMK = (rl+mkll) * (rl+mkI2)+(rl+mkI3) * (rl+mkI4) mod N." (S2356)
0386The third share key acquisition part 2308a decoding-Í-A-acquires share key SK for encryption share key E NCSKi based on generated common intermediate key SMK. (S2357) The third share key acquisition part 2308a outputs the share key SK to outputting part 1310. (S235 8)
0387Outputting part 1310 is Output to the exterior about share key SK received when share key SK was received. To. (S2359)
0388The above is the composition and operation of receiving set 23a which are the components of key distribution system 2. What Receiving set 23b of receiving set 23a and others -- The difference with 23 eta is as follows.
0389[0148] the [ (i) ] -- 3 individual intermediate key group acquisition part 2302a -- the -- in order to acquire a 3 individual intermediate key group -- Pieces the receiving set identifier and individual key which are obtained from another key storing part 2304a -- each receiving set 2 3a -- It differs by 23 eta.
0390[0149] It is stored by (ii) individual key storing part 2304a, and is Receipt unit identifier (AIDa -- AID).
0391n) And an individual key (IKa -- IKn) is each receiving set 23a. -- It differs by 23 eta.
0392[0150] being stored by (iii) individual intermediate key storage 2305a -- the [ and / To ] -- a 1 individual intermediate key group and the first system secret variable group identifier -- each receiving set 23a -- It differs by 23 eta.
0393[0151] The first piece acquired from individual intermediate key storage 2305a in (iv) common information receiving part 2306a Another intermediate key group and the first system secret variable group identifier are each receiving set 23a. -- 23 eta It differs.
0394[0152] It is individual middle for a start which is used by the third share key acquisition part 2308a of (V) when acquiring share key SK. Keys are each receiving set 13a. -- It differs by 13 n.
0395[0153] <Verification of Embodiment 2 of operation>
0396In this Embodiment 2, it is each receiving set 23a. -- The first which takes a different value to 23 eta Individual intermediate key group MKIGa -- MKIGn is assigned and it is in spite of To go, all the receiving sets 23a -- the reason which can derive the same share key SK in 23 eta -- Embodiment 1 -- said -- him -- it is a reason.
0397[0154] <Effect of Embodiment 2>
0398in Embodiment 2 of the present invention, share key SK common to all the receiving sets is peculiar to a receiving set the -- it was made to be generated from a 3 individual intermediate key doing so -- the -- a 3 individual intermediate key -- Fill -- Crowded -- it is -- the receiving set of a revealing agency can be specified now also to an inaccurate receiving set [0155] <Modification>
0399the embodiment described above is an example of operation of the present invention -- the present invention -- this operation deviate from that dropping off in what is limited to a form in any way -- , range Well , and The -- the main modes It can carry out. It is contained in the present invention also when as follows.
0400[0156] (1) channels 10 may be networks, such as a terrestrial wave or a satellite.
0401(2) in Embodiment 1 -- a figure -- 34 shows -- as -- key issue center 11 -- inside of portable medium 15 Record system secret variable group set SPGS. System Secret by which server 12 which distributed the portable medium 15 to server 12, and received and portable medium 15 is recorded in portable medium 15 By reading dense variable group set SPGS, it is Take about system secret variable group set SPGS. It may be made to gain. Here, portable media 15 are a flexible disk, CD-ROM, and DVD, for example. -- They are portable recording media, such as RAM. By this, it is with key issue center 11. It becomes unnecessary to connect server 12 via the channel. Embodiment 2 -- Even if it is, it is realizable similarly.
0402[0157] In (3) embodiment 1, key issue center 11 generates an individual intermediate key group for a start in one more excess, add to server 12 at system secret variable group SPG, and it is an individual intermediate key group for a start [ the ]. It is made to distribute, System secret variable group storage 122 of server 12, the first piece storing another intermediate key group -- a figure -- 35 shows -- as -- the time of server 12 -- strange variable group generation Part 1251, common intermediate key acquisition part 1252 -- instead of [ of random number z, w, and m and n ] -- the time -- strange -- making it output variable group PR G -- common intermediate key acquisition part 1252 of server 12, a time -- strange variable group generation Case where strange variable group PRG is received from part 1251 at the time, First, system secret variable group storage 122 is accessed, and an individual intermediate key group is acquired for a start, strange at the time out of strange variable group PRG, when individual intermediate key mkll, mkI2, mkI3, and mkI4 are acquired from the inside for a start and it receives -- extracting variable r 1, r2, r3, and r4 -- after that and common intermediate key SMK Common to the receiving set given beforehand It may be made to generate based on intermediate key generation type" SMK= (rl+mkll) * (rl+mkI2)+(rl+mkI3) * (rl+mkI4) mod N." Inside [ individual / for a start / of server 12 / by this ] This which pursues that key disclosure took place from server 12 also when between keys are revealed It comes to be able to do. In Embodiment 2, it is realizable similarly.
0403[0158] Strange [ at an individual intermediate key generation type and the time ] (4) system secret variable generation type, an individualization variable generation type, and for a start A variable generation type, a server common intermediate key generation type, and a receiving set common intermediate key generation type are carried-out types. It does not restrict only to a formula given in voice 1 and Embodiment 2. Receiving set common intermediate key generation To a formula, it is [ an individual intermediate key generation type and ] a strange variable generation type an individualization variable generation type and for a start at the time, cost a formula when ON is carried out -- the -- in agreement with a 1 common intermediate key -- the first -- an individual intermediate key generation type -- Pieces another-ized variables x and y are included -- further -- the time -- a strange variable generation type, a server common intermediate key generation type, and Receiving If the Place common intermediate key generation type does not contain individualization variables x and y, it is good.
0404[0159] (5) System secret variable group SPG is generated using one system secret variable generation type, and V and It was, Two or more kinds of system secret variable generation types are used, and it is system secret variable group SPG. Even if it generates, right may be carried out, and system secret variable county SPG may be generated, without using a system secret variable generation type. For example, system secret variable group SPG may be a random number.
0405[0160] (6) Although the individualization variable was generated using one individualization variable generation type, business and a Individualization variable may be generated for two or more kinds of individualization variable generation types, and it is an individualization variable generation type. An individualization variable may be generated, without using it. Even if for example, an individualization variable is a random number It is good.
0406[0161] (7) Five or more kinds of power which was generating the intermediate key using the individual intermediate key generation type for a start [ four ] the first -- an individual intermediate key generation type -- the [ business and / The ] -- even if it generates a 1 individual intermediate key -- right -- -- it carries out -- three kinds -- with -- the lower first -- an individual intermediate key generation type -- the [ business and / The ] -- even if it generates a 1 individual intermediate key -- good !.
0407[0162] (8) using a strange variable generation type at the time of four -- the time -- strange -- five kinds of power which was generating variable group PRG -- with -- the upper time -- a strange variable generation type -- business -- Time change variable group PRG may be generated -- carrying out three or less kinds the time -- strange -- using a variable generation type -- the time -- strange -- variable group PRG may be generated -- carrying out -- further -- the time -- strange variable Strange variable group PRG may be generated at the time, without using a generation type. for example, the time -- strange -- variable group PRG may be a random number.
0408[0163] (9) although common intermediate key SMK was calculated using one server common intermediate key generation type, even if it calculates business V and The common intermediate key SMK for and two or more kinds of server common intermediate key generation types -- right -- it is -- .
0409[0164] (10) Common intermediate key SMK is calculated using one receiving set common intermediate key generation type. It was generates business and The common intermediate key SMK for two or more kinds of receiving set common intermediate key generation types. The is also good. [0165] (11) receiving-set common intermediate key generation types are all the receiving sets 13a. -- 13 n or receiving set 23a It is not necessary to use a receiving set common intermediate key generation type common to 23 eta. --
0410[0166] In (12) embodiment 1, it is individual intermediate key group MKIGa for a start [ each ]. -- MKIGn, four The The first of five or more power in which 1 individual intermediate key mkll, mkI2, mkI3, and mkI4 power were also constituted comprising an individual intermediate key -- and The -- right -- -- it carries out -- comprising an individual intermediate key for a start [ three or less ] Me me is also good.
0411[0167] It is strange variable power at the time of strange variable group PRG and five power or more in which strange variable rl, r2, r3, and r4 power were also constituted at the time of four, at the time of (13). It may be constituted and comprises a strange variable at the time or less of three. Me me is also good.
0412[0168] (14) -- some -- the same individual key as a plurality of receiving sets, and the first -- the [ an individual intermediate key group or ] -- inside of 2 individual Between keys may be assigned.
0413[0169] At (15) embodiment 1, the second system secret key generation part 1141 is, The six second system secret keys kl, k2, k3, k4, k5, and k6 are generated. The second system of seven or more Secret power secret key may be generated and the five or less second system secret keys may be generated. For example, The Even if 2 system secret key generation part 1141 generates the ten second system secret keys kl, k2, k3, k4, k5, k6 and k7, k8, k9, and klO /.! Under the present circumstances, the number of the second system secret keys of second system Necessities variable group SPGII[Including this rare To will differ. For example, the second system secret key It is generation part 1141 and they are the ten second system secret keys kl, When k2, k3, k4, k5, k6, k7, k8, k9, and klO are generated, the second system secret variable group SPGII will contain the ten second system secret keys kl, k2, k3, k4, k5, k6, k7, k8, k9, and klO.
0414[0170] Although the receiving set was outputting share key SK to the exterior in (16) embodiment 1 and Embodiment 2, External power also inputs contents, is based on share key SK, and servers are contents. It is a receiving set, as code Y is carried out and the encryption contents are also distributed to a receiving set, Code Y contents are received, decoding Y is performed based on share key SK, and it is Take about contents. It is good !, even if it gains and makes it output the contents outside.
0415[0171] With server 12 of (17) embodiment 1, Either the first community information generating part 125 or the second community information generating part 126 is chosen, The first community information ECMI or the second community information Only any Tsutomu of EC mupi is generating and it is Power. Server 12, Each time and first community information generation The first community information ECMI is generated in part 125, the -- 2 common information generating part 126 -- the -- generating 2 common information ECMII -- after generation -- the -- the [ 1 common information ECMI or ] -- 2 common information ECMII is choosing whether it is a gap -- receiving set 13a -- It may be made to distribute to 13 eta.
0416[0172] the time of key issue center 11 distributing individual information group EMMG in (18) embodiment 1 receiving set 13a -- it may distribute to 13 eta simultaneously -- carrying out -- each receiving set 13a -- 13 eta -- individual -- It may distribute. When server 12 distributes common information ECM, it receives similarly. Device 13a -- It may distribute to 13 n simultaneously and is each receiving set 13a. -- It distributes individually 13 n. It is good.
0417[0173] Although the third system secret keys set SPGIIIS contained the six first system secret keys in (19) embodiment 2, even if seven or more pieces may be included and five or less pieces are included It is good.
0418[0174] in (20) embodiment 2 -- key issue center 21 -- the third individual information group the time of distributing epsilonmumupiiota -- receiving set 23a -- it may distribute to 23 eta simultaneously -- carrying out -- each receiving set 23a -- 23 eta -- it may distribute individually. Also when server 22 distributes the third community information ECMIII It is receiving set 23a similarly. -- It may distribute to 23 eta simultaneously and is each receiving set 23a. -- 23eta Pieces It may distribute independently.
0419[0175] At (21) embodiment 1, server 12 is receiving set 13a. -- Common information ECM is transmitted to 13 eta, and ! and It was, Server 12 and receiving set 13a -- Common information ECM that 13 n is common beforehand, and common information Multiple groups of an identifier are held and server 12 is Receiving about one of common information identifiers. Place 13a -- It distributes to 13 n, Receiving set 13a -- It is a basis about the common information identifier received in 13 n. Even if it acquires corresponding common information ECM, it is right .
0420[0176] Key issue center 11 is in (22) embodiment 1, the first assigned to the receiving set corresponding to a receiving set identifier and its receiving set identifier -- the [ an individual intermediate key group and ] -- 2 individual intermediate key Hold the correspondence information on a group. They are an individual intermediate key group or the second certain piece for a start [ a certain ]. It may enable it to specify the receiving set currently assigned based on another intermediate key group. That the time of a certain inaccurate receiving set being discovered by making it like -- the inaccurate receiving set -- Fill -- Included -- rare -- the ing first -- the [ an individual intermediate key group or / certain ] -- revealing based on a 2 individual intermediate key group Receiving device can be specified now. correspondence information -- except for key issue center 11 -- Keep it may have -- carrying out -- correspondence information -- the first -- the [ an individual intermediate key group or ] -- 2 individual intermediate key group only the group of a receiving set identifier is included with whether they are ! and a gap -- and The -- right , Embodiment 2 -- even if it is -- key issue center 21 -- or except key issue center 21 -- power a receiving set identifier -- the -- the first assigned to the receiving set corresponding to a receiving set identifier -- an individual intermediate key group and the first System The same thing is realizable even if it holds the correspondence information on a Beam secret variable group identifier. Correspondence information is an individual intermediate key group or the first system secret variable group identifier for a start. Only the group of a receiving set identifier is included with whether they are ! and a gap, and and The are also right .
0421[0177] In the first individual information generation part and the second individual information generation part, in (23) embodiment 1, Oh in key issue center 11, the third individual information generation part, the fourth individual information generation part, and more than it even if there is an individual information generation part -- Well receiving set 13a -- 13 eta -- the first -- individual intermediate key group acquisition the [ a part and ] -- a 2 individual intermediate key group acquisition part -- Oh, the -- a 3 individual intermediate key group acquisition part and the fourth piece There may be an another intermediate key group acquisition part and an individual intermediate key group acquisition part beyond it. Key issue center 11 and receiving set 13a -- In 13 eta, an individual intermediate key group acquisition part is the same as an individual information generation part. Only a number exists and an individual information identifier should carry out even that only the same kind.
0422[0178] in (24) embodiment 1 -- server 12 -- the -- the [ a 1 common information generating part and ] -- 2 common Sentiment a news generation part -- Oh, the -- the [ a 3 common information generating part or ] -- Both beyond a 4 common information generating part and it a connoisseur -- even if there is an information generating part -- Well receiving set 13a -- 13 eta -- the first share key acquisition part and The a 2 share key acquisition part -- Oh -- the third share key acquisition part, the fourth share key acquisition part, and more than it There may be a share key acquisition part. Server 12 and receiving set 13a -- In 13 eta, it is common information. In a generation part and a share key acquisition part, only the same number exists and a common information identifier only the same kind Even that may be carried out.
0423[0179] In (25) embodiment 1, it is a key during the period. rhokappa -- 1 [ Power which was a key common to VGo to 13 eta For every receiving set, even if it is an individual key, it is right . ] -- PK -- k is all the receiving sets 13a. --
0424[0180] Though (26) present invention is methods shown above, it is good. Though it is a computer program which realizes these methods by Comb - Tha, it is good, and it is the above-mentioned Computer. It is good though it is a digital signal which log rum power also becomes. The above-mentioned computer program or the recording medium which can computer read the above-mentioned digital signal, for example, a removable disc, a hard disk, CD, MO, DVD, an SD memory card, semiconductor memory of the present invention, etc. are good also as what the account of * This recorded. It is good though it is the above-mentioned computer program or the above-mentioned digital signal currently recorded on these recording media. Present invention
0425the above-mentioned computer program or the above-mentioned digital signal -- electric telecommunication lines and radio -- or -- an owner -- As what transmits a line communication line and the Internet via the network etc. which are made into representation It is good. With the computer systems with which the present invention was provided with the microprocessor and the memory It is, the above-mentioned memory has memorized the above-mentioned computer program, and it is above-mentioned microphone Lopro. Though the Sessa operates according to the above-mentioned computer program, it is good. The above-mentioned pro Recording a gram or the above-mentioned digital signal on the above-mentioned recording medium, and transporting it, or before An account program or the above-mentioned digital signal is transported via the above-mentioned network etc. Also noting that it carries out with other independent computer systems /!
0426[0181] Also noting that the (27) above-mentioned embodiment and the above-mentioned modification are combined, respectively /.!
0427Industrial applicability
0428[0182] They are power or a The key distribution system to the present invention, Even if an aggressor acquires the individual key of a certain receiving set unjustly and an inaccurate receiving set is created using the individual key, the -- un--- having the effect that the clone origin of a right receiving set can be pursued -- communication of the Internet etc. I would like to distribute contents safely using networks, such as a way, terrestrial broadcasting, and satellite broadcasting. It is useful to a case.
51 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| WO2008043289A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| JPH02291740A | Cites | Japan | Y | International search |
| JPH03239033A | Cites | Japan | Y | International search |
| JPH11313055A | Cites | Japan | Y | International search |
7 members in 7 offices
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004025386 | Japan | A |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| JP2005218023A | Japan | A | |
| WO2005074185A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| TW200534656A | Taiwan Province of China | A | |
| EP1713196A1 | European Patent Office (EPO) | A1 | |
| CN1860722A | China | A | |
| KR20060121160A | Republic of Korea | A | |
| US2009238368A1 | United States of America | A1 |
11 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: withdrawn in national officeWithdrawnWWW | WWW | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: withdrawn in national officeWithdrawnWWW | WWW | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO |
Numbers
- Publication
- 2005/074185
- Application
- 1359
Titles2
- English
- KEY DISTRIBUTION SYSTEM
- French
- SYSTEME DE DISTRIBUTION DE CLES
Classification
- CPC, 5
- H04L9/0833
- H04L9/08
- H04L9/0891
- H04L2209/60
- H04L9/32
- IPC, 1
- H04L9 08
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo