JPH01200846A - System for distributing cipher key in network system - Google Patents

System for distributing cipher key in network system

Info

Publication number
JPH01200846A
JPH01200846A JP63023933A JP2393388A JPH01200846A JP H01200846 A JPH01200846 A JP H01200846A JP 63023933 A JP63023933 A JP 63023933A JP 2393388 A JP2393388 A JP 2393388A JP H01200846 A JPH01200846 A JP H01200846A
Authority
JP
Japan
Prior art keywords
cipher key
key
data processing
processing system
encryption
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
JP63023933A
Other languages
Japanese (ja)
Inventor
Masahiko Watanabe
渡邉 理彦
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NEC Corp
Original Assignee
NEC Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by NEC Corp filed Critical NEC Corp
Priority to JP63023933A priority Critical patent/JPH01200846A/en
Publication of JPH01200846A publication Critical patent/JPH01200846A/en
Pending legal-status Critical Current

Links

Abstract

PURPOSE:To prevent loading a cipher key on the communication path and to reduce a hazardousness that the cipher key is plagiarized by ciphering the cipher key itself to be used for transmitting and receiving data and distributing it. CONSTITUTION:A cipher key K decided by a data processing system 10 is ciphered through a ciphering mechanism 11 by a node key N1 to a cipher key K' and sent on the communication path. When the cipher key K' is received by a data processing system 20, the cipher key K' is decoded through a decoding mechanism 22 by a node key N2 to a cipher key K'' and transmitted to the system 10. At the system 10, the cipher key K'' is decoded through a decoding mechanism 12 by the node key N1 to a cipher key K'''. In the course, the ciphering by the node key N1 is offset. At the system 20, by decoding the cipher key K''' through a ciphering mechanism 21 by the node key N2 to a cipher key K'''', the cipher key K to be decided by the system 10 first can be obtained.

Description

【発明の詳細な説明】 〔産業上の利用分野〕 本発明は、データ処理ネットワークシステムに関し、特
に1通信路上のデータを暗号化するための暗号キーの配
送方式に関する。
DETAILED DESCRIPTION OF THE INVENTION [Field of Industrial Application] The present invention relates to a data processing network system, and particularly to a method for delivering an encryption key for encrypting data on one communication path.

〔従来の技術〕[Conventional technology]

従来、この種の暗号キー配送方式は、暗号キー自身を通
信路上にのせて配送するか、あるいは。
Conventionally, this type of encryption key distribution method has either delivered the encryption key itself on a communication path, or

オフラインで、媒体等による配送を行っていた。Deliveries were made offline using media, etc.

〔発明が解決しようとする課題〕[Problem to be solved by the invention]

上述し友従来の暗号キー配送方式では9通信路上に暗号
キーがそのままのってしまうために、盗まれやすい、と
いう欠点がある。
The above-mentioned conventional encryption key distribution method has the drawback that the encryption key is left on the communication path as is, making it easy to steal.

一方1通信路を使用せずに、オフラインでフロッピィデ
ィスク等の媒体による配送でも、盗まれることが考えら
れ、しかも、暗号キーの変更が。
On the other hand, even if the data is delivered offline using a medium such as a floppy disk without using a single communication channel, it is possible that the data will be stolen, and the encryption key may need to be changed.

通信路を使用した場合に比べると、困難な念め。This is a difficult reminder compared to using a communication channel.

システムの柔軟性に欠けるという欠点がある。The disadvantage is that the system lacks flexibility.

〔課題を解決するための手段〕[Means to solve the problem]

本発明によるネットワークシステムにおける暗号キー配
送方式は、複数のデータ処理システム間でデータの授受
を行うネットワークシステムにおける通信路上のデータ
を暗号化するための暗号キーの配送方式において、前記
データ処理システムの各々は、前記暗号キーを暗号化し
、暗号化された暗号キーを前記通信路上へ送出する暗号
化機構2有することを特徴とする。
A cryptographic key distribution method in a network system according to the present invention is a cryptographic key distribution method for encrypting data on a communication path in a network system that exchanges data between a plurality of data processing systems. is characterized by having an encryption mechanism 2 that encrypts the encryption key and sends the encrypted encryption key onto the communication path.

〔実施例〕〔Example〕

次に本発明の実施例について図面を参照して説明する。 Next, embodiments of the present invention will be described with reference to the drawings.

第1図は本発明の方式を示したものであり、データ処理
システム10とデータ処理システム20は、それぞれ、
暗号化機構11.21と、復号化機構12.22とを有
し9通信路により接続されている。
FIG. 1 shows the system of the present invention, in which a data processing system 10 and a data processing system 20 each include:
It has an encryption mechanism 11.21 and a decryption mechanism 12.22, which are connected by nine communication paths.

第1図には、データ処理システム10で決定すれた暗号
キーKが、データ処理システム20へ配送される過程を
示しており、二重線の部分は1通信路上の流れを示して
いる。データ処理システム10で決定された暗号キーに
は、データ処理システム10が固有に持っているノード
キーN1によ通信路上に送り出される。
FIG. 1 shows the process in which the encryption key K determined by the data processing system 10 is delivered to the data processing system 20, and the double line portion shows the flow on one communication path. The encryption key determined by the data processing system 10 is sent out onto the communication path using the node key N1 that the data processing system 10 has uniquely.

K’=に@Nl                  
  ・・・(1)ここで、暗号化を[F]、復号化全[
F]と略して式に表わす。
K'= to @Nl
...(1) Here, encryption is [F], decryption is [F]
F] is abbreviated as the formula.

データ処理システム20では、第1の暗号化された暗号
キーに/ +受信すると、これを、データ処理システム
20が固有に持っているノードキーN2(Nlと異なっ
ても良い)により、復号化機構22を介して、(2)式
に示されるように第1の復号化された暗号キーK“に復
号化し、データ処理システム10へと送信する。
When the data processing system 20 receives the first encrypted encryption key /+, it is transferred to the decryption mechanism 22 using the node key N2 (which may be different from Nl) unique to the data processing system 20. is decrypted into a first decrypted encryption key K'' as shown in equation (2), and transmitted to the data processing system 10.

K//=に′[F]N2=に@NI[F]N2    
    ・・・(2)次にデータ処理システム10では
、第1の復号化された暗号キーに′′を、ノードキーN
1で復号化機構12を介して(3)式に示されるように
第2の復号化された暗号キーK”に復号化する。この過
程において、最初のノードキーN1による暗号化が相殺
される。
K//= to'[F]N2=@NI[F]N2
...(2) Next, in the data processing system 10, '' is added to the first decrypted encryption key, and node key N is added to the first decrypted encryption key.
1, it is decrypted to a second decrypted encryption key K'' via the decryption mechanism 12 as shown in equation (3). In this process, the encryption by the first node key N1 is canceled out.

K″′=につN1=K[F]N1■N2[F]N1=に
■N2    ・・(3)データ処理システム20では
、この第2の復号化された暗号キーに/#−t、暗号化
機構21を介して。
K'''=N1=K[F]N1■N2[F]N1=N2...(3) The data processing system 20 uses this second decrypted encryption key as /#-t, Via the encryption mechanism 21.

ノードキーN2で、(4)式に示されるように第2の暗
号化された暗号キーK“”に暗号化することにより。
By encrypting with the node key N2 into a second encrypted encryption key K"" as shown in equation (4).

一番最初に、データ処理システム1oで決定すれた暗号
キーKi得ることができる。
First, the cryptographic key Ki determined by the data processing system 1o can be obtained.

K” =に′′@N 2=に@N 2@N 2=K  
    ・(4)〔発明の効果〕 以上説明したように本発明は、データの授受に使用され
る暗号キー自身を、暗号化して配送することにより、暗
号キーがそのまま通信路上にのることがなくなり、暗号
キーか盗まれる危険性を少なくすることができる効果が
ある。ま几、各々のデータ処理システムが固有の(シス
テム間で取り決められていない)ノードキーを持ち、し
かも。
K” = に′′@N 2= に@N 2@N 2=K
- (4) [Effects of the invention] As explained above, the present invention encrypts and delivers the encryption key itself used for sending and receiving data, thereby preventing the encryption key from being transmitted as is on the communication path. This has the effect of reducing the risk of encryption keys being stolen. However, each data processing system has a unique node key (not negotiated between systems).

それすら相手のデータ処理システムに教える必要がなく
、安全性が高く、柔軟性のあるネットワークシステムを
構築することができる。
There is no need to tell the data processing system of the other party, and a highly secure and flexible network system can be constructed.

【図面の簡単な説明】[Brief explanation of the drawing]

第1図は本発明の一実施例によるネットワークシステム
における暗号キー配送方式の構成を示すブロック図であ
る。 lO・・・データ処理システム、11・・・暗号化機構
。 12・・・復号化機構、20・・・データ処理システム
。 21・・・暗号化機構、22・・・復号化機構。
FIG. 1 is a block diagram showing the configuration of a cryptographic key distribution method in a network system according to an embodiment of the present invention. lO...Data processing system, 11...Encryption mechanism. 12...Decoding mechanism, 20...Data processing system. 21... Encryption mechanism, 22... Decryption mechanism.

Claims (1)

【特許請求の範囲】[Claims] 1、複数のデータ処理システム間でデータの授受を行う
ネットワークシステムにおける通信路上のデータを暗号
化するための暗号キーの配送方式において、前記データ
処理システムの各々は、前記暗号キーを暗号化し、暗号
化された暗号キーを前記通信路上へ送出する暗号化機構
を有することを特徴とするネットワークシステムにおけ
る暗号キー配送方式。
1. In a cryptographic key delivery method for encrypting data on a communication path in a network system that exchanges data between multiple data processing systems, each of the data processing systems encrypts the cryptographic key and performs encryption. 1. An encryption key distribution method in a network system, comprising an encryption mechanism that sends an encoded encryption key onto the communication path.
JP63023933A 1988-02-05 1988-02-05 System for distributing cipher key in network system Pending JPH01200846A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP63023933A JPH01200846A (en) 1988-02-05 1988-02-05 System for distributing cipher key in network system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP63023933A JPH01200846A (en) 1988-02-05 1988-02-05 System for distributing cipher key in network system

Publications (1)

Publication Number Publication Date
JPH01200846A true JPH01200846A (en) 1989-08-14

Family

ID=12124330

Family Applications (1)

Application Number Title Priority Date Filing Date
JP63023933A Pending JPH01200846A (en) 1988-02-05 1988-02-05 System for distributing cipher key in network system

Country Status (1)

Country Link
JP (1) JPH01200846A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH0369220A (en) * 1989-06-16 1991-03-25 Ferranti Creditphone Ltd Method of transferring identity from portable transmitter and receiver to base station
JPH0486135A (en) * 1990-07-30 1992-03-18 Sharp Corp Privacy call device

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH0369220A (en) * 1989-06-16 1991-03-25 Ferranti Creditphone Ltd Method of transferring identity from portable transmitter and receiver to base station
JPH0486135A (en) * 1990-07-30 1992-03-18 Sharp Corp Privacy call device

Similar Documents

Publication Publication Date Title
US6636968B1 (en) Multi-node encryption and key delivery
CA2808369C (en) System for protecting an encrypted information unit
CN111371790B (en) Data encryption sending method based on alliance chain, related method, device and system
JPH08234658A (en) Method for generation of encoding key
EP1236303A4 (en) PUBLIC KEY HIERARCHY WITH SEVERAL STEPS TO INCREASE EFFICIENCY AND SAFETY
KR20030011672A (en) Method of transmitting confidential data
US12200099B2 (en) Multi-party cryptographic systems and methods
JP2002510164A (en) Method and apparatus for communicating a secret message to selected members
JP2862141B2 (en) Identification number-based key management device using conventional encryption
JP2022548185A5 (en)
JPH04297157A (en) Data ciphering device
JPH10107832A (en) Cipher multi-address mail system
JPH01225251A (en) Secret key delivering system
JPH01200846A (en) System for distributing cipher key in network system
JPH07336328A (en) Cipher device
JP2001285278A (en) Encryption communication method and encryption communication system
JP2003309544A (en) Cipher key delivery apparatus
JPH02184882A (en) Public key management method for public key cryptography
JPH0897813A (en) Method and equipment for communication
JPH01284890A (en) Sharing method for key
JPH0618367B2 (en) Key delivery method
JPH03235442A (en) Ciphered communication system
JPS6172437A (en) Qualifying system using open key distribution system
CN113343281A (en) OTP encryption as a service cloud computing method and system oriented to data transaction
JPS63160444A (en) Cryptographic communication equipment