JPH01194541A - Cryptographic key communication system - Google Patents
Cryptographic key communication systemInfo
- Publication number
- JPH01194541A JPH01194541A JP63018051A JP1805188A JPH01194541A JP H01194541 A JPH01194541 A JP H01194541A JP 63018051 A JP63018051 A JP 63018051A JP 1805188 A JP1805188 A JP 1805188A JP H01194541 A JPH01194541 A JP H01194541A
- Authority
- JP
- Japan
- Prior art keywords
- user
- information
- memory
- key
- secret
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Abstract
Description
〔産業上の利用分野〕
この発明は、秘密鍵暗号を用いた秘密通信において、複
数局で秘密鍵を共有して秘密通信を行う暗号鍵通信方式
に関するものである。
〔従来の技術〕
第3図は岡本栄司による従来の暗号鍵共有方式(“ID
に基づく鍵配送方式”、電子通信学会技術研究報告IT
86−53.’pp、25−28゜1986年)の装置
化したものを示す構成図であり、図において、51は秘
密情報を格納するメモリ、52は公開情報を格納するメ
モリ、53は整数eを格納するメモリ、54は乱数生成
器、55はこの乱数生成器54で生成された乱数を格納
するメモリ、56は上記秘密情報メモリ51の値Sと公
開情報メモリ52の植aと乱数格納メモリ55の値rか
らs−a’modnの演算を行う回路、57は通信文を
出力する端子、58は通信文を入力する端子、59は利
用者が相手のID情報を人力する端子、60は上記乱数
格納メモリ55の値rとメモリ53の値eと通信文人力
端子58から入力された値XとID情報入力端子59か
ら入力された情報IDより(x” / r D) ’
mod nの演算を行う回路、61は鍵を出力する端子
である。
次に動作について説明する。ネットワークまたは通信シ
ステムの運営者または構築者は、あらかじめ大きな素数
p、qを選び、
。= p 、q (15
1)を計算する。また、
e−d = 1 (mod(p−1)(q−1) (但
し、eはCp−1)(q−1)に対して互いに素”)
(152)となるe、dを選び、利用
者iのID情報(これをIDiとする)から
s i = I D i ’ mod n
(153)を求め、その利用者固有の秘密情
報メモリ51へ格納する。
(153)弐が成立すれば
s i” = I D i (mod n)
(154)となる(Rivest、R,L、、
Shamir、A、八dleman、L、: AMet
hod for Obtaining Digital
Signatures andPublic−key
Cryptosystems”、 Commun、A
CM、21+pp。
120−126.1978)ので、通信文にこの秘密情
報を掛は合わせて送れば受信者が送信者のIDを使って
確認できる。さらに、運営者あるいは構築者はCF (
pi、 G F (qlで原始元となる整数aを選び、
公開情報メモリ52へ格納する。整数eもメモリX53
に格納する。
2者間で鍵共有をするとき、たとえば利用者1と利用者
2が鍵を共有する場合、利用者1と利用者2の鍵生成手
順は同じなので、ここでは利用者1における生成手順に
ついて述べる。
まず、利用者1は乱数生成器54で乱数r、を生成させ
、メモリY55に格納する。演算回路X56において秘
密情報メモリ51と公開情報メモIJ52とメモリY5
5から
x、 = s 、 −a”mod n
(155)を計算し、通信文出力端子57から
利用者2へ送信する。利用者2も同様にx2を利用者1
へ送信する。
次に、利用者1は通信文入力端子58から利用者2より
送られてきた情報x2を受信する。利用者1はID情報
入力端子59へ相手の利用者のID情報、つまりID、
を入力し、またメモリX 。
53とメモリY55より演算回路Y60を用いてKey
= (X2 ” / I Dt ) ”mod n
(156)を求める。利用者2も同様にKeyを求
める。
このとき、鍵出力端子61から得られる値はKey=
a ””” mod n (157
)となり、利用者1と利用者2は鍵を共有できたことに
なる。
〔発明が解決しようとする課題〕
ID情報を使った従来の暗号鍵通信方式は以上のように
構成されているので、1対1の通信の場合のみしか秘密
鍵を共有することはできず、TV会議のような複数局が
同時に通信を行う場合は別の方法で秘密鍵を共有するこ
とが必要であるなどの問題点があった。
この発明は上記のような問題点を解消するためになされ
たもので、各局のID情報とシステム自体の秘密情報と
を組み合わせることにより、複数局で安全な秘密通信を
行うことができる暗号鍵通信方式を得ることを目的とす
る。
〔課題を解決するための手段〕
この発明に係る暗号鍵通信方式は、各局の利用者に固有
の情報で公開されているID情報、システム自体の秘密
情報と乱数の組合せ情報を中央の局が各子局から集めて
所定の演算を施し、この演算結果を各子局に送出するこ
とで2以上の各局に共通の暗号鍵を作り出し、この暗号
鍵を用いて通信を行うことを特徴とするものである。
〔作用〕
各子局は利用者に固有の情報として公開されているTD
情報、システム自体の秘密情報と乱数の組合せ情報を中
央の局に送出する。中央の局は各子局から集められた上
記組合せ情報に所定の演算を施して各子局に送出する。
この結果各子局に共通の暗号鍵が各子局に渡される。各
子局は中央の局との間でこの共通の暗号鍵を用いて通信
を行う。
〔発明の実施例〕
以下、この発明の一実施例について説明する。
第1図は本発明の実施例で、図において、1は秘密情報
を格納するメモリ、2は公開情報を格納するメモリ、3
は乱数生成器、4はこの乱数生成器3で生成された乱数
を格納するメモリ、5は上記秘密情報メモリ1の値Sと
公開情報メモリ2の値aと乱数格納メモリ4の値rから
s−a’modnの演算を行う回路、6は2人力1出力
のセレクタ、7は子局の一般利用者と中央の局の中央利
用者を切替える端子、8は上記セレクタ602人力のう
ちの一方のライン、9はこのライン8と他方のライン、
IDは通信文を出力する端子、11は通信文を入力する
端子、12は上記一般利用者/中央利用者切替端子7で
中央利用者を指定したときに開くゲート、13は上記一
般利用者/中央利用者切替端子7で一般利用者を指定し
たときに開くゲート、14は上記ゲート12から出るラ
イン、15は上記通信文人力端子11から入力される値
XとID情報IDからx’ / I D” ll1od
nの演算を行う回路、16は利用者が相手のID情報
を入力する端子、17はm−1個の値)’2+ y3
+ ・−・。
秘密情報メモリ1の値Sとメモリ4の値rと演算回路1
5で求められた値)’ 2 + 13 r ’−’+
’/ mと演算回路17で求められた値2=Σyi
からQ繁2
s ・(z−yz) rmod n、s ・(z・y*
) ’ mod n、−。
s ・<z−ym ) ’ mad nの演算を行う回
路、19は上記秘密情報メモリ1の値Sと公開情報メモ
リ2の値aとメモリ4の値rからs−a ”mod n
の演算を行う回路、20は上記演算回路18の演算結果
と演算回路19の演算結果を結合する結合器、21は上
記演算回路17の演算結果2とメモリ4の値rからz
”mod nの演算を行う回路、22は2人力l出力の
セレクタ、23はこのセレクタ22の2人力のうち一方
のライン、24はこのライン23と他方のライン、25
は上記ゲート13から出るライン、26は上記通信文人
力端子11から入力される結合された値を分ける分離器
、27はこの分離器26の2出力のうち一方のライン、
28はこのライン27と他方のライン、29は上記メモ
リ4の値rとID情報入力端子16から入力されたID
情1g I Dと分離器26を介して2つに分けられた
値の一方の値z1をIDと一緒に入力して演算回路15
で出力される値Wと2つに分けられた他方の値2から(
z’/ID”)/w’ mod nの演算を行う回路、
30は鍵共有の手順が終了したときに鍵が得られる端子
である。
次に動作について説明する。ネットワークまたは通信シ
ステムの運営者または構築者は、あらかじめ大きな素数
p+、pz (但し、p i =4k i−1、i=
1.2)を選び、
n=p+ pz 、(ID
1)k =2 k + ・kz k+ kz+
1 (ID2)を計算する。そして、利用者iの
ID情報(これをIDiとする)から
s i = T D i ’ mod n
(ID3)を求め、その利用者固有の秘密情
報メモリ1へ格納する。
(ID3)式が成立すれば、
s i’ =IDi” (mod n )
(ID4)となることが知られている( Lieb
erherr、 K、 :Uniform Compl
exity and Digital Signatu
re”。
1、ecture Notes in Compute
r 5cience 115+^utoma。
Language and Programming、
Eighth ColloColloquiu、 l5
rael、 pp、 530−543+ 1981)の
で、通信文にこの秘密情報を掛は合わせて送れば受信者
が送信者の[Dを使って確認できる。また、運営者ある
いは構築者はGF (p+ ) 、 GF (1)z
)で原始元となる整数aを選び、公開情報メモリ2へ
格納する。
第2図のようなm人の利用者からなるスター状のネット
ワークの場合、利用者1を通信文を集配する中央局の「
中央利用者」と呼ぶことにすると、各子局の各利用者は
中央利用者との間だけで通信文を交信する。鍵生成の手
順は中央利用者を除(すべての利用者において同じなの
で、ここでは利用者I (中央利用者)と利用者i
(2≦i≦m)における手順について述べる。
第1図において、まず、利用者iは乱数生成器3で乱数
riを生成させ、メモリ4へ格納する。
演算回路A5において秘密情報メモリ1と公開情報メモ
リ2とメモリ4から
x i = s i−a”mod n
(ID5)を計算し、セレクタA6へ送る。セレク
タ八6は一般利用者/中央利用者切替端子7につながれ
、一般利用者であればラインA8を、中央利用者であれ
ばラインB9を選択して通信文出力端子IDに出力する
。利用者iは一般利用者なので(ID5)式の値を出力
し、利用者1 (中央利用者)へ送信する。
次に、利用者1は利用者iからxiを受信する。
同様に各利用者からxZ+ x3+・・−’+ x
i−1,x tit、・−1xmを受信する。それらを
通信文人力端子11から入力する。ゲートA12は中央
利用者のときのみ開き、ゲー)B13は一般利用者のと
きのみ開(。よって、利用者1はラインC14を介して
、XZ、X3.’−−−’、xmを演算回路B15へ送
る。利用者1はID情報入力端子16から、x2のとき
はI DZ + XiのときはI D3 、’−”+
xmのときはIDmを人力し、演算回路B15を用
いて1 z=xz’/IO,2mod n= a ””
mod n2=Σ y i mod n=a’ ””r
3+G−””modnを求める。さらに、秘密情報メモ
リ1とメモリ4と(ID6)式、 (ID7)式の値
から演算回路D18を用いて
を計算する。また、演算回路E19を用いてz I=s
、−a4r’mad n (ID9
)を求め、利用者1は、利用者2へ(Z 2+ Z +
)+利用者3へ(zff+ z+)+ ’−’*利用者
mへ(zz、zυを結合器20を介して通信文出力端子
11より出力する。同時に、利用者1は演算回路F21
を用いてメモリ4と(ID7)式の値より
Key =z”’mod n
(1ID)を求める。セレクタB22は中央利用者のと
きラインE23を、一般利用者のときラインF24を出
力する。ここでは、(1ID)式の値を選び、鍵出力端
子30より出力する。
一方、利用者iは通信文人力端子11より、(zLz+
)を入力し、ゲートB13.ラインD25を介して分離
器26へ送られる。分離器26は、ziをラインG27
.2.をラインH28に分けて送る。ID情報入力端子
16より入力された相手のID、つまりID、と2.よ
り演算回路B15を用いて
w = z 、 ’/ ID、” mod n
(111)を計算し、さらに、IDI とW
と21とメモリ4の値より演算回路G29を用いて
Key =(zi’/!D+”)/ wi”mod n
(112)を求め、鍵出力端子30より得
られる。
このとき、
Key= a16rl +rz+r:+、−、、+rn
)modn(l13)が成り立つので、すべての利用者
が同一のKeyの値を得ることができる。
〔発明の効果〕
以上説明したように、この発明は、各局の利用者に固存
の情報で公開されているID情報とシステム自体の秘密
消和と乱数の組合せ情報を中央の局が各子局から集めて
所定の演算を施し、この演算結果を各子局に送出するこ
とで各局に共通の暗号鍵を作り出し、この暗号鍵を用い
て通信を行うので、2以上の複数局の秘密通信を行う場
合でも複数局で同一の秘密鍵が共有できる効果がある。[Industrial Application Field] The present invention relates to a cryptographic key communication system in which secret keys are shared by multiple stations to perform secret communications using secret key cryptography. [Prior art] Figure 3 shows Eiji Okamoto's conventional cryptographic key sharing method (“ID
“Key distribution method based on ”, Institute of Electronics and Communication Engineers Technical Research Report IT
86-53. 'pp, 25-28゜1986) is a configuration diagram showing a device version of the system. In the figure, 51 is a memory for storing secret information, 52 is a memory for storing public information, and 53 is for storing an integer e. A memory 54 is a random number generator, 55 is a memory for storing random numbers generated by the random number generator 54, and 56 is a value S of the secret information memory 51, a value S of the public information memory 52, and a value of the random number storage memory 55. A circuit that calculates s-a'modn from r, 57 is a terminal for outputting a message, 58 is a terminal for inputting a message, 59 is a terminal for a user to manually input the ID information of the other party, 60 is the random number storage mentioned above. From the value r in the memory 55, the value e in the memory 53, the value X input from the correspondence terminal 58, and the information ID input from the ID information input terminal 59, (x''/r D)'
A circuit 61 is a terminal for outputting a key. Next, the operation will be explained. The operator or builder of a network or communication system selects large prime numbers p and q in advance and calculates . = p, q (15
1) Calculate. Also, e-d = 1 (mod (p-1) (q-1) (however, e is coprime to Cp-1) (q-1)")
(152) Select e and d, and from user i's ID information (this is IDi), s i = I Di ' mod n
(153) and stores it in the secret information memory 51 unique to that user. (153) If 2 holds, s i” = ID i (mod n)
(154) (Rivest, R, L, .
Shamir, A., 8dleman, L.: AMet
Hod for Obtaining Digital
Signatures andPublic-key
Cryptosystems”, Commun, A
CM, 21+pp. 120-126.1978), so if this confidential information is sent along with the message, the recipient can confirm it using the sender's ID. In addition, the operator or constructor is CF (
pi, G F (select the integer a that becomes the primitive element with ql,
The information is stored in the public information memory 52. Integer e also memory X53
Store in. When sharing a key between two parties, for example, when user 1 and user 2 share a key, the key generation procedure for user 1 and user 2 is the same, so here we will describe the generation procedure for user 1. . First, the user 1 causes the random number generator 54 to generate a random number r, and stores it in the memory Y55. In the arithmetic circuit X56, the secret information memory 51, the public information memo IJ52, and the memory Y5
5 to x, = s, −a”mod n
(155) is calculated and transmitted to the user 2 from the message output terminal 57. User 2 also sets x2 to user 1.
Send to. Next, user 1 receives the information x2 sent from user 2 from the message input terminal 58. User 1 inputs the ID information of the other user, that is, the ID, to the ID information input terminal 59.
and also memory X. 53 and memory Y55 using the arithmetic circuit Y60.
= (X2 ” / I Dt ) ”mod n
Find (156). User 2 similarly obtains the Key. At this time, the value obtained from the key output terminal 61 is Key=
a “”” mod n (157
), which means that user 1 and user 2 have been able to share the key. [Problem to be solved by the invention] Since the conventional cryptographic key communication method using ID information is configured as described above, the secret key can only be shared in one-to-one communication. When multiple stations communicate at the same time, such as in a TV conference, there are problems such as the need to share the secret key using another method. This invention was made to solve the above-mentioned problems, and by combining the ID information of each station and the secret information of the system itself, it is possible to carry out secure secret communication between multiple stations using cryptographic key communication. The purpose is to obtain a method. [Means for Solving the Problems] The cryptographic key communication method according to the present invention allows a central station to collect combination information of ID information that is unique to users of each station and is made public, secret information of the system itself, and random numbers. The data is collected from each slave station, subjected to a predetermined calculation, and the result of this calculation is sent to each slave station to create an encryption key common to two or more stations, and this encryption key is used to perform communication. It is something. [Operation] Each slave station uses TD, which is disclosed as information unique to the user.
The information, a combination of secret information of the system itself and random numbers, is sent to a central station. The central station performs predetermined calculations on the combination information collected from each slave station and sends the result to each slave station. As a result, an encryption key common to each slave station is passed to each slave station. Each slave station communicates with the central station using this common encryption key. [Embodiment of the Invention] An embodiment of the invention will be described below. FIG. 1 shows an embodiment of the present invention. In the figure, 1 is a memory for storing secret information, 2 is a memory for storing public information, and 3 is a memory for storing public information.
is a random number generator, 4 is a memory for storing random numbers generated by this random number generator 3, and 5 is a value S of the secret information memory 1, a value a of the public information memory 2, and a value r to s of the random number storage memory 4. -a'modn calculation circuit, 6 is a selector with two manual outputs, 7 is a terminal for switching between the general user of the slave station and the central user of the central station, and 8 is one of the selectors 602 and 1 output. Line 9 is this line 8 and the other line,
ID is a terminal for outputting a message, 11 is a terminal for inputting a message, 12 is a gate that opens when a central user is designated with the general user/central user switching terminal 7, and 13 is a gate for the general user/central user. A gate that opens when a general user is specified at the central user switching terminal 7, 14 is a line exiting from the gate 12, and 15 is a line from the value X input from the correspondence terminal 11 and the ID information ID to x'/I. D”ll1od
16 is a terminal where the user inputs the other party's ID information, 17 is m-1 values)'2+y3
+・−・. Value S of secret information memory 1, value r of memory 4, and calculation circuit 1
5)' 2 + 13 r '-'+
'/ m and the value 2 obtained by the calculation circuit 17 = Σyi
From Q 2 s ・(z-yz) rmod n, s ・(z・y*
) ' mod n, -. A circuit 19 calculates s-a ``mod n'' from the value S of the secret information memory 1, the value a of the public information memory 2, and the value r of the memory 4.
20 is a combiner that combines the calculation result of the calculation circuit 18 and the calculation result of the calculation circuit 19; 21 is the calculation result 2 of the calculation circuit 17 and the value r to z of the memory 4;
22 is a selector for 2-manpower l output, 23 is one line of the 2-manpower of this selector 22, 24 is this line 23 and the other line, 25
is a line coming out from the gate 13, 26 is a separator that separates the combined values input from the correspondence terminal 11, 27 is one line of the two outputs of this separator 26,
28 is this line 27 and the other line, 29 is the value r of the memory 4 and the ID input from the ID information input terminal 16.
One value z1 of the two divided values is inputted together with the ID via the information 1g ID and the separator 26, and then sent to the arithmetic circuit 15.
From the value W outputted in and the other value 2 divided into two, (
z'/ID")/w' mod n calculation circuit,
30 is a terminal from which a key is obtained when the key sharing procedure is completed. Next, the operation will be explained. The operator or builder of a network or communication system must determine in advance the large prime numbers p+, pz (where p i =4k i-1, i=
1.2), n=p+ pz, (ID
1) k = 2 k + ・kz k+ kz+
1 (ID2) is calculated. Then, from the ID information of user i (this is referred to as IDi), s i = T Di ' mod n
(ID3) and stores it in the secret information memory 1 unique to that user. If the formula (ID3) holds, s i' = IDi” (mod n)
(ID4) (Lieb
erherr, K, :Uniform Compl
Exity and Digital Signatu
1. Notes in Compute
r 5science 115+^utoma. Language and programming,
Eighth ColloColloquiu, l5
Rael, pp. 530-543+ 1981), so if this secret information is sent along with the message, the receiver can confirm the sender's [D]. In addition, the operator or constructor is GF (p+), GF (1)z
) is used to select an integer a as a primitive element and store it in the public information memory 2. In the case of a star-shaped network consisting of m users as shown in Figure 2, user 1 is connected to the central station that collects and delivers messages.
"Central user", each user of each slave station communicates messages only with the central user. The key generation procedure is the same for all users except for the central user (since it is the same for all users, here we will explain the steps for user I (central user) and user i).
The procedure for (2≦i≦m) will be described. In FIG. 1, user i first generates a random number ri using random number generator 3 and stores it in memory 4. In the arithmetic circuit A5, from the secret information memory 1, the public information memory 2, and the memory 4, x i = s i-a” mod n
(ID5) is calculated and sent to selector A6. The selector 86 is connected to the general user/central user switching terminal 7, and selects line A8 for the general user and line B9 for the central user, and outputs the selected line to the message output terminal ID. Since user i is a general user, it outputs the value of formula (ID5) and sends it to user 1 (central user). Next, user 1 receives xi from user i. Similarly, each user receives xZ+ x3+...-'+ x
Receive i-1, x tit, -1xm. These are inputted from the correspondence human power terminal 11. Gate A12 is open only when the central user is present, and gate B13 is open only when the user is a general user. Send to B15. User 1 inputs from the ID information input terminal 16, if x2, IDZ + if Xi, ID3, '-"+
When xm, input IDm manually and use arithmetic circuit B15 to calculate 1 z=xz'/IO, 2mod n= a ""
mod n2=Σ y i mod n=a' ””r
Find 3+G-""modn. Furthermore, the arithmetic circuit D18 is used to calculate from the values of the secret information memory 1, memory 4, equations (ID6), and equations (ID7). Furthermore, using the arithmetic circuit E19, z I=s
, -a4r'mad n (ID9
), and user 1 sends (Z 2+ Z +
) + To user 3 (zff + z +) + '-' * To user m (zz, zυ are output from the message output terminal 11 via the coupler 20. At the same time, the user 1
Using memory 4 and the value of formula (ID7), Key = z”'mod n
Find (1 ID). Selector B22 outputs line E23 when the user is a central user, and outputs line F24 when the user is a general user. Here, the value of equation (1ID) is selected and output from the key output terminal 30. On the other hand, user i receives (zLz+
) and enter gate B13. It is sent to the separator 26 via line D25. Separator 26 connects zi to line G27
.. 2. are divided and sent to line H28. 2. ID of the other party inputted from the ID information input terminal 16, that is, ID; Using the arithmetic circuit B15, w = z, '/ ID, " mod n
(111), and furthermore, IDI and W
21 and the value of memory 4, use the arithmetic circuit G29 to calculate Key = (zi'/!D+")/wi"mod n
(112) is obtained from the key output terminal 30. At this time, Key=a16rl +rz+r:+,-,,+rn
) modn(l13) holds, all users can obtain the same Key value. [Effects of the Invention] As explained above, the present invention allows a central station to transmit to each user a combination of ID information, private information, and random numbers, which is unique to the users of each station, and random numbers. A common encryption key is created for each station by collecting data from the station, performing a predetermined calculation, and sending the results of this calculation to each slave station.This encryption key is used for communication, so secret communication between two or more stations is possible. This has the effect of allowing multiple stations to share the same secret key even when doing so.
第1図はこの発明の一実施例による暗号鍵通信方式を示
す構成図、第2図はこの発明が適用されるスター状ネッ
トワークの構成図、第3図は従来の暗号鍵通信方式を示
す構成図である。
1は秘密情報メモリ、2は公開情報メモリ、3は乱数生
成器、4はメモリ、5は演算回路A、6はセレクタA、
7は一般利用者/中央利用者切替端子、8はラインA、
9はラインB、IDは通信文出力端子、11は通信文人
力端子、12はゲートA、13はゲートB、14はライ
ンC115は演算回路B、16はID情報入力端子、1
7は演算回路C,18は演算回路D、19は演算回路E
、20は結合器、21は演算回路F、22はセレクタB
123はラインE、24はラインF、25はラインD1
26は分離器、27はラインG128はラインH129
は演算回路G130は鍵出力端子、51は秘密情報メモ
リ、52は公開情報メモリ、53はメモリx154は乱
数生成器、55はメモリY156は演算回路×157は
通信文出力端子、58は通信文人力端子、60は演算回
路Y、59はID情報入力端子、61は鍵出力端子であ
る。
代理人 大 岩 増 雄(ばか2名)拓1+”
U
第2図
集3圓
59;TDJtiu77GJ、67 、”gL’7j’
Ph”r手続補正書(自発)
1、事件の表示 特願昭63−018051号2、
発明の名称
暗号鍵通信方式
3、補正をする者
代表者 志 岐 守 哉
4、代理人
5 補正の対象
明細書全文。
a 補正の内容
明細書全文を別紙のとおり補正する。
以上
明 細 書 (全文補正)
1、発明の名称
暗号鍵通信方式
2特許請求の範囲
中央の局と複数の子局とがスター状に接続されているネ
ットワークのシステムを構築している通信路上で、各局
が互いに共通の暗号鍵を用いて秘密の通信を行う場合、
システム自体の秘密情報と上記各局の公開された利用者
名等のID情報と乱数とを演算して各局に共通の上記暗
号鍵を作り出し、この共通の暗号鍵を用いて通信を行う
暗号鍵通信方式であって、各局に公開されているID情
報と上記秘密情報と上記乱数の組合せからなる組合せ情
報を中央の局が各子局から集めて所定の演算を施して各
子局に送出することにより2以上の局に共通の暗号鍵を
作り出し、この暗号鍵を用いて秘密の通信を行うことを
特徴とする暗号鍵通信方式。
a発明の詳細な説明
[産業上の利用分野]
この発明は、秘密鍵暗号を用いた秘密通信において、複
数局で秘密鍵を共有して秘密通信を行う暗号鍵通信方式
に関するものである。
[従来の技術]
第3図は岡本栄司による従来の暗号鍵共有方式(“ID
に基づく鍵配送方式″、電子通信学会技術研究報告IT
86−53.pp、25−28゜1986年)の装置化
したものを示す構成図であり、図において、51は秘密
情報を格納するメモリ、52は公開情報を格納するメモ
リ、53は整数eを格納するメモリ、54は乱数生成器
、55はこの乱数生成器54で生成された乱数を格納す
るメモリ、56は上記秘密情報メモリ51の値Sと公開
情報メモリ52の値aと乱数格納メモリ55の値rから
s−a’modnの演算を行う回路、57は通信文を出
力する端子、58は通信文を入力する端子、59は利用
者が相手のID情報を入力する端子、60は上記乱数格
納メモリ55の値rとメモリ53の値eと通信文人力端
子58から入力された値XとID情報入力端子59から
入力された情報IDより(x@/ I D) ’ mo
d nの演算を行う回路、61は鍵を出力する端子であ
る。
次に動作について説明する。ネットワークまたは通信シ
ステムの運営者または構築者は、あらかじめ大きな素数
P+ qを選び、
n=P”I (151)
を計算する。また、
e−dミ1 (mod(p−1)(q−1) (但し、
eは(p−1)(q−1)に対して互いに素)
(152)となるe、dを選び、利用者iの
’ID情報(これをID、とする)から
St ==ID、 dmod n
(153)を求め、その利用者固有の秘密情報メモリ5
1へ格納する。
(153)式が成立すれば
s t e=I D t (mod n)
(154)となる(
Rivest、R,L、、Shamir、A、、Adl
eman、L、: AMethod for Obta
ining Digital Signatures
andPublic−key Cryptosyste
ms″、 Commun、ACM、21.pp。
120−126.1978)ので、通信文にこの秘密情
報を掛け合わせて送れば受信者が送信者のIDを使って
確認できる。さらに、運営者あるいは構築者はG F(
Pl、 G Ff(11で原始光となる整数aを選び、
公開情報メモリ52へ格納する。整数eもメモリX53
に格納する。
2者間で鍵共有をするとき、たとえば利用者1と利用者
2が鍵を共有する場合、利用者1と利用者2の鍵生成手
順は同じなので、ここでは利用者lにおける生成手順に
ついて述べる。
まず、利用者1は乱数生成器54で乱数r1を生成させ
、メモリY55に格納する。演算回路X56において秘
密情報メモリ51と公開情報メモリ52とメモリY55
から
xt =s、 参a”mod n
(155)を計算し、通信文出力端子57から利用者2
へ送信する。利用者2も同様にx2を利用者1へ送信す
る。
次に、利用者1は通信文人力端子58から利用者2より
送られてきた情報X、を受信する。利用者1はID情報
入力端子59へ相手の利用者のID情報、つまりID2
を入力し、またメモリX53とメモリY55より演算回
路Y60を用いてKey== (x2 e/ I D2
) ” mod n (158)を求める。利用
者2も同様にKeyを求める。
このとき、鍵出力端子61から得られる値はKey=
a ’ ”r2nod n (15
7)となり、利用者1と利用者2は鍵を共有できたこと
になる。
[発明が解決しようとする課題]
ID情報を使った従来の暗号鍵通信方式は以上のように
構成されているので、1対1の通信の場合のみしか秘密
鍵を共有することはできず、TV会議のような複数局が
同時に通信を行う場合は別の方法で秘密鍵を共有するこ
とが必要であるなどの問題点があった。
この発明は上記のような問題点を解消するためになされ
たもので、各局のID情報とシステム自体の秘密情報と
を組み合わせることにより、複数局で安全な秘密通信を
行うことができる暗号鍵通信方式を得ることを目的とす
る。
[課題を解決するための手段]
この発明に係る暗号鍵通信方式は、各局の利用者に固有
の情報で公開されているID情報、システム自体の秘密
情報と乱数の組合せ情報を中央の局が各子局から集めて
所定の演算を施し、この演算結果を各子局に送出するこ
とで2以上の各局に共通の暗号鍵を作り出し、この暗号
鍵を用いて通信を行うことを特徴とするものである。
[作用コ
各子局は利用者に固有の情報として公開されているID
情報、システム自体の秘密情報と乱数の組合せ情報を中
央の局に送出する。中央の局は各子局から集められた上
記組合せ情報に所定の演算を施して各子局に送出する。
この結果各子局に共通の暗号鍵が各子局に渡される。各
子局は中央の局との間でこの共通の暗号鍵を用いて通信
を行う。
[発明の実施例]
以下、この発明の一実施例について説明する。
第1図は本発明の実施例で、図において、1は秘密情報
を格納するメモリ、2は公開情報を格納するメモリ、3
は乱数生成器、4はこの乱数生成器3で生成された乱数
を格納するメモリ、5は上記秘密情報メモリ1の値Sと
公開情報メモリ2の値aと乱数格納メモリ4の値rがら
s−a’modnの演算を行う回路、6は2人力1出カ
のセレクタ、7は子局の一般利用者と中央の局の中央利
用者を切替える端子、8は上記セレクタ6の2人力のう
ちの一方のライン、9はこのライン8と他方のライン、
IDは通信文を出方する端子、11は通信文を入力する
端子、12は上記一般利用者/中央利用者切替端子7で
中央利用者を指定したときに開くゲート、13は上記一
般利用者/中央利用者切替端子7で一般利用者を指定し
たときに開くゲート、14は上記ゲート12がら出るラ
イン、15は上記通信文人力端子11がら入力される値
XとID情報IDからx’ / I D2mod nの
演算を行う回路、16は利用者が相手のID情報を入力
する端子、17はm−1個の値3/2 + ’/s t
・・・。
y、からeyzの演算を行う回路、18は上記秘密情報
メモリ1の値Sとメモリ4の値rと演算回路15で求め
られた値’j21 y3 t・・・、y、、と演算回路
17で求められた値z = XZ yt から7=2
s′(z+y2) ’ mod n、s′(z″y、
) ’ mod n、−。
s (z ”/m ) ’ mad nの演算を行う回
路、19は上記秘密情報メモリ1の値Sと公開情報メモ
リ2の値aとメモリ4の値rからs−a ”mod n
の演算を行う回路、20は上記演算回路18の演算結果
と演算回路19の演算結果を結合する結合器、21は上
記演算回路17の演算結果Zとメモリ4の値rからz
”mod nの演算を行う回路、22は2人力1出力の
セレクタ、23はこのセレクタ22の2人力のうち一方
のライン、24はこのライン23と他方のライン、25
は上記ゲート13から出るライン、26は上記通信文人
力端子11から入力される結合された値を分ける分離器
、27はこの分離器26の2出力のうち一方のライン、
28はこのライン27と他方のライン、29は上記メモ
リ4の値rとID情報入力端子16から入力されたID
情報IDと分離器26を介して2つに分けられた値の一
方の値2.をIDと一緒に入力して演算回路15で出力
される値Wと2つに分けられた他方の値2から(Z’
/ID2)/w’ mod nの演算を行う回路、30
は鍵共有の手順が終了したときに鍵が得られる端子であ
る。
次に動作について説明する。ネットワークまたは通信シ
ステムの運営者または構築者は、あらかじめ大きな素数
p1.P2 (但し、pt=4kt −1、i=1.
2)を選び、
n=p、 ・P 2 (I
D1)k=2に、 ・kz −kl−に2+1
(ID2)を計算する。そして、利用者iのID情報
(これをID+とする)とから
s、 =IDt ’ mod n
(ID3)を求め、その利用者固有の秘密情報メモリ1
へ格納する。
(ID3)式が成立すれば、
81 ’ E”ID+ 2(mad n )
(ID4)となることが知られている( Lieb
erherr、 K、 :Uniform Compl
exity and Digital Signatu
re”。
Lecture Notes in Computer
5cience 115.Automa。
Language and Programming、
Eighth ColloColloquiu、 l5
rael、 pp、 530−543.1981)ので
、通信文にこの秘密情報を掛は合わせて送れば受信者が
送信者のIDを使って確認できる。また、運営者あるい
は構築者はGF(p 1) t G F (p 2 )
で原始光となる整数aを選び、公開情報メモリ2へ格納
する。
第2図のようなm人の利用者からなるスター状のネット
ワークの場合、利用者1を通信文を集配する中央局の「
中央利用者」と呼ぶことにすると、各子局の各利用者は
中央利用者との間だけで通信文を交信する。鍵生成の手
順は中央利用者を除くすべての利用者において同じなの
で、ここでは利用者1(中央利用者)と利用者i (2
≦i≦m)における手順について述べる。
第1図において、まず、利用者iは乱数生成器3で乱数
riを生成させ、メモリ4へ格納する。
演算回路A5において秘密情報メモリ1と公開情報メモ
リ2とメモリ4から
x(= s 1 ′a”mod n
(ID5)を計算し、セレクタ八6へ送る。セレクタ
A6は一般利用者/中央利用者切替端子7につながれ、
一般利用者であればラインA8を、中央利用者であれば
ラインB9を選択して通信文出力端子IDに出力する。
利用者iは一般利用者なので(ID5)式の値を出力し
、利用者1(中央利用者)へ送信する。
次に、利用者1は利用者iからXえを受信する。
同様に各利用者からX2 + X3 +・・・yXt−
1tXi−1v・・・、X、を受信する。それらを通信
文人力端子11から入力する。ゲートA12は中央利用
者のときのみ開き、ゲートB13は一般利用者のときの
み開く。よって、利用者1はラインC14を介して、X
2 v X3 r・・・、Xoを演算回路B15へ送る
。利用者1はID情報入力端子16から、x2のときは
ID2.x3のときはより3、・・・、X、のときはI
D、を入力し、演算回路B15を用いて
z=誉yt mod n=a ” r2” ’←−−
−−” ” ’ mod n1=2
を求める。さらに、秘密情報メモリ1とメモリ4と (
ID6)式、 (ID7)式の値から演算回路D18
を用いて
を計算する。また、演算回路E19を用いてz、 =s
、 6a ””mod n (ID9
)を求め、利用者1は、利用者2へ(Zl 、zl L
利用者3へ(Zl 、ZI L”’ r利用者mへ(Z
m +21 )を結合器20を介して通信文出力端子1
1より出力する。同時に、利用者1は演算回路F21を
用いてメモリ4と (ID7)式の値より
に、ey = z 4”nod n
(1ID)を求める。セレクタB22は中央利用者
のときラインE23を、一般利用者のときラインF24
を出力する。ここでは、 (1ID)式の値を選び、対
出力端子3oより出力する。
一方、利用者iは通信文人力端子11より、(ZttZ
i)を入力し、ゲートB13.ラインD25を介して分
離器26へ送られる。分離器26は、Zt をラインG
27.z、をラインH28に分けて送る。ID情報入力
端子16より入力された相手のID、つまりID、とZ
lより演算回路B15を用いて
w= z 1 ’ / IDt 2mod n
(111)を計算し、さらに、ID、とWとz
lとメモリ4の値より演算回路G29を用いて
Key=(z、 ’/ID、 ’ )/w、 ” ma
d n (112)を求め、対出力端子3oより得
られる。
このとき、
Tl、8y= 816 rs (r2− rs
−−−−−−−r、+ l ff1od n
(l13)が成り立つので、すべての利用
者が同一のKeyの値を得ることができる。
[発明の効果コ
以上説明したように、この発明は、各局の利用者に固有
の情報で公開されているID情報とシステム自体の秘密
情報と乱数の組合せ情報を中央の局が各子局から集めて
所定の演算を施し、この演算結果を各子局に送出するこ
とで各局に共通の暗号鍵を作り出し、この暗号鍵を用い
て通信を行うので、2以上の複数局の秘密通信を行う場
合でも複数局で同一の秘密鍵が共有できる効果がある。FIG. 1 is a configuration diagram showing an encryption key communication method according to an embodiment of the present invention, FIG. 2 is a configuration diagram of a star network to which this invention is applied, and FIG. 3 is a configuration diagram showing a conventional encryption key communication method. It is a diagram. 1 is a secret information memory, 2 is a public information memory, 3 is a random number generator, 4 is a memory, 5 is an arithmetic circuit A, 6 is a selector A,
7 is general user/central user switching terminal, 8 is line A,
9 is a line B, ID is a message output terminal, 11 is a communication human power terminal, 12 is a gate A, 13 is a gate B, 14 is a line C115 is an arithmetic circuit B, 16 is an ID information input terminal, 1
7 is an arithmetic circuit C, 18 is an arithmetic circuit D, and 19 is an arithmetic circuit E.
, 20 is a coupler, 21 is an arithmetic circuit F, and 22 is a selector B.
123 is line E, 24 is line F, 25 is line D1
26 is a separator, 27 is line G128 is line H129
51 is a secret information memory, 52 is a public information memory, 53 is a memory x 154 is a random number generator, 55 is a memory Y 156 is an arithmetic circuit x 157 is a message output terminal, 58 is a message output terminal, and 58 is a message output terminal. Terminals 60 are an arithmetic circuit Y, 59 is an ID information input terminal, and 61 is a key output terminal. Agent Masuo Oiwa (2 idiots) Taku 1+”
U Figure 2 Collection 3 59; TDJtiu77GJ, 67, "gL'7j"
Ph”r procedural amendment (spontaneous) 1. Indication of the case Patent Application No. 1983-018051 2.
Name of the invention Encryption key communication method 3, Person making the amendment Representative Moriya Shiki 4, Agent 5 Full text of the specification to be amended. a. Contents of the amendment The entire text of the specification shall be amended as shown in the attached sheet. Above description (full text amended) 1. Title of the invention Encryption key communication method 2. Claims On a communication path that constructs a network system in which a central station and a plurality of slave stations are connected in a star shape. , when each station performs secret communication using a common encryption key,
Encryption key communication in which the encryption key common to each station is created by calculating the secret information of the system itself, the public ID information such as the user name of each station, and a random number, and communication is performed using this common encryption key. A method in which a central station collects combination information consisting of a combination of ID information disclosed to each station, the above-mentioned secret information, and the above-mentioned random number from each slave station, performs a predetermined calculation, and sends it to each slave station. A cryptographic key communication system characterized by creating a common cryptographic key for two or more stations and performing secret communication using this cryptographic key. Detailed Description of the Invention [Field of Industrial Application] The present invention relates to a cryptographic key communication system in which a secret key is shared by a plurality of stations for secret communication using secret key cryptography. [Prior art] Figure 3 shows the conventional cryptographic key sharing method (“ID
``key distribution method based on ``, Institute of Electronics and Communication Engineers Technical Research Report IT
86-53. pp. 25-28゜1986). In the figure, 51 is a memory for storing secret information, 52 is a memory for storing public information, and 53 is a memory for storing an integer e. , 54 is a random number generator, 55 is a memory for storing random numbers generated by the random number generator 54, and 56 is a value S of the secret information memory 51, a value a of the public information memory 52, and a value r of the random number storage memory 55. 57 is a terminal for outputting the message, 58 is a terminal for inputting the message, 59 is a terminal for the user to input ID information of the other party, 60 is the random number storage memory mentioned above. From the value r of 55, the value e of memory 53, the value X input from the correspondence terminal 58, and the information ID input from the ID information input terminal 59, (x@/ID) 'mo
A circuit for calculating dn, 61 is a terminal for outputting a key. Next, the operation will be explained. The operator or builder of a network or communication system selects a large prime number P+ q in advance and calculates n=P”I (151)
Calculate. Also, e-d mi 1 (mod (p-1) (q-1) (however,
e is relatively prime to (p-1)(q-1))
(152) Select e and d, and from user i's ID information (this is assumed to be ID), St == ID, dmod n
(153), and the user's unique secret information memory 5
Store to 1. If the formula (153) holds, s t e = ID t (mod n)
(154) becomes (
Rivest, R.L., Shamir, A., Adl.
Eman, L.: AMethod for Obta
ining Digital Signatures
andPublic-key Cryptosystem
ms'', Common, ACM, 21.pp. 120-126.1978), so if the message is multiplied with this secret information and sent, the receiver can confirm it using the sender's ID. The person is GF (
Pl, G Ff (Choose the integer a that becomes the primordial light in 11,
The information is stored in the public information memory 52. Integer e also memory X53
Store in. When sharing a key between two parties, for example, when user 1 and user 2 share a key, the key generation procedure for user 1 and user 2 is the same, so here we will describe the generation procedure for user l. . First, the user 1 causes the random number generator 54 to generate a random number r1 and stores it in the memory Y55. In the arithmetic circuit X56, the secret information memory 51, the public information memory 52, and the memory Y55
From xt = s, see a”mod n
(155) and sends the message output terminal 57 to user 2.
Send to. User 2 similarly sends x2 to user 1. Next, the user 1 receives the information X sent from the user 2 from the correspondence terminal 58. User 1 inputs the ID information of the other user, that is, ID2, to the ID information input terminal 59.
, and using the arithmetic circuit Y60 from memory X53 and memory Y55, Key== (x2 e/ I D2
) ” mod n (158) is obtained. User 2 similarly obtains the Key. At this time, the value obtained from the key output terminal 61 is Key=
a' ”r2nod n (15
7), which means that user 1 and user 2 were able to share the key. [Problems to be Solved by the Invention] Since the conventional cryptographic key communication method using ID information is configured as described above, the secret key can only be shared in one-to-one communication. When multiple stations communicate at the same time, such as in a TV conference, there are problems such as the need to share the secret key using another method. This invention was made to solve the above-mentioned problems, and by combining the ID information of each station and the secret information of the system itself, it is possible to carry out secure secret communication between multiple stations using cryptographic key communication. The purpose is to obtain a method. [Means for Solving the Problems] The cryptographic key communication system according to the present invention allows a central station to collect combination information of ID information that is unique to users of each station and is made public, secret information of the system itself, and random numbers. The data is collected from each slave station, subjected to a predetermined calculation, and the result of this calculation is sent to each slave station to create an encryption key common to two or more stations, and this encryption key is used to perform communication. It is something. [Each slave station has an ID that is published as information unique to the user.]
The information, a combination of secret information of the system itself and random numbers, is sent to a central station. The central station performs predetermined calculations on the combination information collected from each slave station and sends the result to each slave station. As a result, an encryption key common to each slave station is passed to each slave station. Each slave station communicates with the central station using this common encryption key. [Embodiment of the Invention] An embodiment of the present invention will be described below. FIG. 1 shows an embodiment of the present invention. In the figure, 1 is a memory for storing secret information, 2 is a memory for storing public information, and 3 is a memory for storing public information.
is a random number generator, 4 is a memory for storing the random numbers generated by this random number generator 3, and 5 is a value s from the value S of the secret information memory 1, the value a of the public information memory 2, and the value r of the random number storage memory 4. -a'modn calculation circuit, 6 is a 2-man power, 1 output selector, 7 is a terminal for switching between the general user of the slave station and the central user of the central station, 8 is the 2-man power of the selector 6. One line, 9 is this line 8 and the other line,
ID is a terminal for outputting a message, 11 is a terminal for inputting a message, 12 is a gate that opens when a central user is designated with the general user/central user switching terminal 7, and 13 is a gate for the general user. /A gate that opens when a general user is specified at the central user switching terminal 7, 14 is a line exiting from the gate 12, 15 is a value x input from the correspondence terminal 11 and the ID information x' / A circuit for calculating ID2mod n, 16 is a terminal for the user to input the other party's ID information, 17 is m-1 values 3/2 + '/s t
.... A circuit 18 calculates eyz from y, and a calculation circuit 17 calculates the value S of the secret information memory 1, the value r of the memory 4, the value 'j21 y3 t..., y, found in the calculation circuit 15, and the calculation circuit 17. From the value z = XZ yt, 7=2 s'(z+y2)' mod n, s'(z″y,
) ' mod n, -. A circuit 19 calculates s-a ``mod n'' from the value S of the secret information memory 1, the value a of the public information memory 2, and the value r of the memory 4.
20 is a combiner that combines the calculation result of the calculation circuit 18 and the calculation result of the calculation circuit 19; 21 is a combiner that combines the calculation result Z of the calculation circuit 17 and the value r of the memory 4 to z;
22 is a selector with 2 human power and 1 output, 23 is one line of the 2 human power of this selector 22, 24 is this line 23 and the other line, 25
is a line coming out from the gate 13, 26 is a separator that separates the combined values input from the correspondence terminal 11, 27 is one line of the two outputs of this separator 26,
28 is this line 27 and the other line, 29 is the value r of the memory 4 and the ID input from the ID information input terminal 16.
One value 2 of the two values divided through the information ID and the separator 26. is input together with the ID, and from the value W outputted by the arithmetic circuit 15 and the other value 2 divided into two, (Z'
/ID2)/w' mod n calculation circuit, 30
is the terminal from which the key is obtained when the key sharing procedure is completed. Next, the operation will be explained. The operator or builder of a network or communication system determines in advance a large prime number p1. P2 (However, pt=4kt −1, i=1.
2), n=p, ・P 2 (I
D1) k=2, ・kz −kl− 2+1
(ID2) is calculated. Then, from the ID information of user i (this is referred to as ID+), s, = IDt ' mod n
(ID3), and secret information memory 1 unique to that user.
Store it in (ID3) If the formula holds, 81 'E”ID+ 2(mad n)
(ID4) (Lieb
erherr, K, :Uniform Compl
Exity and Digital Signatu
re”. Lecture Notes in Computer
5science 115. Automa. Language and programming,
Eighth ColloColloquiu, l5
Rael, pp. 530-543.1981), so if this confidential information is sent along with the message, the recipient can confirm it using the sender's ID. In addition, the operator or constructor is GF (p 1) t GF (p 2)
The integer a that becomes the primitive light is selected and stored in the public information memory 2. In the case of a star-shaped network consisting of m users as shown in Figure 2, user 1 is connected to the central station that collects and delivers messages.
"Central user", each user of each slave station communicates messages only with the central user. The key generation procedure is the same for all users except the central user, so here we use user 1 (central user) and user i (2
≦i≦m) will be described. In FIG. 1, user i first generates a random number ri using random number generator 3 and stores it in memory 4. In the arithmetic circuit A5, the secret information memory 1, the public information memory 2, and the memory 4 are
(ID5) and sends it to selector 86. Selector A6 is connected to general user/central user switching terminal 7,
A general user selects line A8, and a central user selects line B9 and outputs it to the message output terminal ID. Since user i is a general user, it outputs the value of formula (ID5) and sends it to user 1 (central user). Next, user 1 receives X from user i. Similarly, from each user, X2 + X3 +...yXt-
1tXi-1v...,X is received. These are inputted from the correspondence human power terminal 11. Gate A12 opens only for central users, and gate B13 opens only for general users. Therefore, user 1 receives X via line C14.
2 v X3 r..., sends Xo to the arithmetic circuit B15. User 1 inputs ID2.x from the ID information input terminal 16. If x3, then 3,...,X, then I
D, and using the arithmetic circuit B15, z=yt mod n=a ” r2” '←--
--” ” ' Find mod n1=2. Furthermore, secret information memory 1 and memory 4 (
From the values of formulas ID6) and (ID7), calculation circuit D18
Calculate using . Also, using the arithmetic circuit E19, z, =s
, 6a ""mod n (ID9
), and user 1 sends (Zl , zl L
To user 3 (Zl, ZI L”' rTo user m (Z
m +21) through the coupler 20 to the message output terminal 1.
Output from 1. At the same time, user 1 uses arithmetic circuit F21 to calculate ey = z 4''nod n from memory 4 and the value of formula (ID7).
Find (1 ID). Selector B22 selects line E23 when the user is a central user, and selects line F24 when the user is a general user.
Output. Here, the value of equation (1ID) is selected and output from the pair output terminal 3o. On the other hand, user i sends (ZttZ
i) and enter gate B13. It is sent to the separator 26 via line D25. Separator 26 connects Zt to line G
27. z, is divided and sent to line H28. ID of the other party input from the ID information input terminal 16, that is, ID, and Z
From l, using the arithmetic circuit B15, w = z 1 ' / IDt 2mod n
(111), and further, ID, W and z
Using the arithmetic circuit G29 from l and the value of memory 4, Key=(z, '/ID, ')/w, " ma
d n (112) is obtained from the pair output terminal 3o. At this time, Tl, 8y= 816 rs (r2- rs
−−−−−−r, + l ff1od n
Since (l13) holds true, all users can obtain the same Key value. [Effects of the Invention] As explained above, the present invention allows a central station to collect combination information of ID information, which is information unique to users of each station and made public, secret information of the system itself, and random numbers, from each slave station. They are collected, subjected to a predetermined calculation, and the results of this calculation are sent to each slave station to create a common encryption key for each station.This encryption key is used for communication, allowing secret communication between two or more stations. This has the effect of allowing multiple stations to share the same secret key even in the case of multiple stations.
第1図はこの発明の一実施例による暗号鍵通信方式を示
す構成図、第2図はこの発明が適用されるスター状ネッ
トワークの構成図、第3図は従来の暗号鍵通信方式を示
す構成図である。
1は秘密情報メモリ、2は公開情報メモリ、3は乱数生
成器、4はメモリ、5は演算回路A、 6はセレクタA
、7は一般利用者/中央利用者切替端子、8はラインA
、9はラインB、IDは通信文出力端子、11は通信文
人力端子、12はゲートA、13はゲートB、14はラ
インC115は演算回路B、16はID情報入力端子、
17は演算回路C118は演算回路D、19は演算回路
E、20は結合器、21は演算回路F、22はセレクタ
B、23はラインE、24はラインF、25はラインD
、26は分離器、27はラインG、28はラインH12
9は演算回路G、30は対出力端子、51は秘密情報メ
モリ、52は公開情報メモリ、53はメモリX、54は
乱数生成器、55はメモリY、56は演算回路X、 5
7は通信文出力端子、58は通信文人力端子、59はI
D情報入力端子、60は演算回路Y、 61は対出力端
子である。FIG. 1 is a configuration diagram showing an encryption key communication method according to an embodiment of the present invention, FIG. 2 is a configuration diagram of a star network to which this invention is applied, and FIG. 3 is a configuration diagram showing a conventional encryption key communication method. It is a diagram. 1 is a secret information memory, 2 is a public information memory, 3 is a random number generator, 4 is a memory, 5 is an arithmetic circuit A, and 6 is a selector A
, 7 is general user/central user switching terminal, 8 is line A
, 9 is a line B, ID is a message output terminal, 11 is a communication human power terminal, 12 is a gate A, 13 is a gate B, 14 is a line C115 is an arithmetic circuit B, 16 is an ID information input terminal,
17 is an arithmetic circuit C118 is an arithmetic circuit D, 19 is an arithmetic circuit E, 20 is a coupler, 21 is an arithmetic circuit F, 22 is a selector B, 23 is a line E, 24 is a line F, 25 is a line D
, 26 is a separator, 27 is line G, 28 is line H12
9 is an arithmetic circuit G, 30 is a pair output terminal, 51 is a secret information memory, 52 is a public information memory, 53 is a memory X, 54 is a random number generator, 55 is a memory Y, 56 is an arithmetic circuit X, 5
7 is a message output terminal, 58 is a message human power terminal, 59 is an I
D is an information input terminal, 60 is an arithmetic circuit Y, and 61 is a pair output terminal.
Claims (1)
ットワークのシステムを構築している通信路上で、各局
が互いに共通の暗号鍵を用いて秘密の通信を行う場合、
システム自体の秘密情報と上記各局の公開された利用者
名等のID情報と乱数とを演算して各局に共通の上記暗
号鍵を作り出し、この共通の暗号鍵を用いて通信を行う
暗号鍵通信方式であって、各局に公開されているID情
報と上記秘密情報と上記乱数の組合せからなる組合せ情
報を中央の局が各子局から集めて所定の演算を施して各
子局に送出することにより2以上の局に共通の暗号鍵を
作り出し、この暗号鍵を用いて秘密の通信を行うことを
特徴とする暗号鍵通信方式。When each station performs secret communication using a common encryption key on a communication path that constructs a network system in which a central station and multiple slave stations are connected in a star shape,
Encryption key communication in which the encryption key common to each station is created by calculating the secret information of the system itself, the public ID information such as the user name of each station, and a random number, and communication is performed using this common encryption key. A method in which a central station collects combination information consisting of a combination of ID information disclosed to each station, the above-mentioned secret information, and the above-mentioned random number from each slave station, performs a predetermined calculation, and sends it to each slave station. A cryptographic key communication system characterized by creating a common cryptographic key for two or more stations and performing secret communication using this cryptographic key.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP63018051A JPH01194541A (en) | 1988-01-28 | 1988-01-28 | Cryptographic key communication system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP63018051A JPH01194541A (en) | 1988-01-28 | 1988-01-28 | Cryptographic key communication system |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JPH01194541A true JPH01194541A (en) | 1989-08-04 |
Family
ID=11960897
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP63018051A Pending JPH01194541A (en) | 1988-01-28 | 1988-01-28 | Cryptographic key communication system |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPH01194541A (en) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH07307733A (en) * | 1994-05-11 | 1995-11-21 | Nec Corp | Scrambled communication system |
| JP2000031956A (en) * | 1998-07-15 | 2000-01-28 | Nippon Telegr & Teleph Corp <Ntt> | Method and system for sharing individual secret information |
-
1988
- 1988-01-28 JP JP63018051A patent/JPH01194541A/en active Pending
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH07307733A (en) * | 1994-05-11 | 1995-11-21 | Nec Corp | Scrambled communication system |
| JP2000031956A (en) * | 1998-07-15 | 2000-01-28 | Nippon Telegr & Teleph Corp <Ntt> | Method and system for sharing individual secret information |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US5751808A (en) | Multi-purpose high speed cryptographically secure sequence generator based on zeta-one-way functions | |
| Maurer et al. | Non-interactive public-key cryptography | |
| Tanaka | A realization scheme for the identity-based cryptosystem | |
| Pfitzmann et al. | How to break the direct RSA-implementation of mixes | |
| Koyama et al. | New public-key schemes based on elliptic curves over the ring Zn | |
| Ohkubo et al. | A length-invariant hybrid mix | |
| US6243467B1 (en) | Method of elliptic curve cryptographic digital signature generation and verification using reduced base tau expansion in non-adjacent form | |
| Frankel et al. | Parallel reliable threshold multisignature | |
| Kota et al. | Implementation of the RSA algorithm and its cryptanalysis | |
| US6301362B1 (en) | Method and apparatus for cryptographically transforming an input block into an output block | |
| Mittal et al. | Group ring based public key cryptosystems | |
| AU3180699A (en) | A method and apparatus for cryptographically secure algebraic key establishment protocols | |
| JP3658004B2 (en) | Communications system | |
| Shimbo et al. | Cryptanalysis of several conference key distribution schemes | |
| JP3123820B2 (en) | Operators in finite commutative groups | |
| Paar | Applied cryptography and data security | |
| JPH01194542A (en) | Cryptographic key communication system | |
| JPH01194543A (en) | Cryptographic key communication system | |
| Moldovyan et al. | Randomized pseudo-probabilistic encryption algorithms | |
| JPH01165241A (en) | Cryptographic key sharing device | |
| Malyutina et al. | An analogue of the ElGamal scheme based on the Markovski algorithm | |
| Harn et al. | Public-key cryptosystem based on the discrete logarithm problem | |
| Sertbaş et al. | VMAIL/An Application For A Secure E-Mail Transmission Using Encrypting Techniques | |
| Líšková et al. | Efficient Simultaneous Contract Signing | |
| Yi et al. | A New Fair Exchange of Secrets by Oblivious Transfer Protocol |