JPH02260841A - Communication equipment - Google Patents

Communication equipment

Info

Publication number
JPH02260841A
JPH02260841A JP1078542A JP7854289A JPH02260841A JP H02260841 A JPH02260841 A JP H02260841A JP 1078542 A JP1078542 A JP 1078542A JP 7854289 A JP7854289 A JP 7854289A JP H02260841 A JPH02260841 A JP H02260841A
Authority
JP
Japan
Prior art keywords
key
key generation
generation data
communication
function
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP1078542A
Other languages
Japanese (ja)
Other versions
JP2518919B2 (en
Inventor
Masahiko Iwata
雅彦 岩田
Sadami Kurihara
定見 栗原
Shoji Miyaguchi
庄司 宮口
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NTT Inc
Original Assignee
Nippon Telegraph and Telephone Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nippon Telegraph and Telephone Corp filed Critical Nippon Telegraph and Telephone Corp
Priority to JP1078542A priority Critical patent/JP2518919B2/en
Publication of JPH02260841A publication Critical patent/JPH02260841A/en
Application granted granted Critical
Publication of JP2518919B2 publication Critical patent/JP2518919B2/en
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Abstract

PURPOSE:To allow both communication equipments of communication processing units to share a key used for cryptographic communication economically by providing a control means storing the key generated by a function selection function with a key storage means and then invalidating the key generating means. CONSTITUTION:A function selection function selects a key generation data storage means 1, a key generation means 2, a key storage means 3 for a generated key and a key generating function invalidating means 6 invalidating the key generating means 3 to make them available, the key generating data stored by the key generation data storage means is inputted to the key generating means 2, from which the key is generated and the generated key is stored by the key storage means 3 and then a control means 8 invalidating the key generating means 2 is provided. Thus, a different key for communication opposite party is shared in common and it is not required for each communication equipment to store lots of keys by communication opposite parties and the system offers economy.

Description

【発明の詳細な説明】 〔産業上の利用分野〕 この発明は、ネットワークに属する任意の通信処理装置
間で暗号通信を行う際に用いる鍵を共有することができ
る通信装置に関するものである。
DETAILED DESCRIPTION OF THE INVENTION [Field of Industrial Application] The present invention relates to a communication device that can share a key used when performing encrypted communication between arbitrary communication processing devices belonging to a network.

(従来の技術) 従来における鍵共有を行う通信装置では、あらかじめ鍵
保持手段に通信相手と共有すべき鍵を投入しておき、通
信時に取り出して用いる方式が考えられる。
(Prior Art) In a conventional communication device that performs key sharing, a method can be considered in which a key to be shared with a communication partner is input into a key holding means in advance, and then taken out and used during communication.

〔発明が解決しようとする課題〕[Problem to be solved by the invention]

この方式では、不特定多数の通信処理装置と通信を行う
場合には、全ての通信装置で同じ鍵を用いる必要があり
安全上好ましくない場合がある。
In this method, when communicating with an unspecified number of communication processing devices, it is necessary to use the same key in all communication devices, which may be unfavorable from a security standpoint.

また、通信相手ごとに異なる鍵を用いようとすると、各
通信装置は多数の鍵を保持する必要があり、コストの点
で問題がある。
Furthermore, if a different key is used for each communication partner, each communication device needs to hold a large number of keys, which poses a problem in terms of cost.

この発明の目的は、ネットワークに属する任意の通信処
理装置間で、暗号通信を行う際に用いる鍵を双方の通信
処理装置の通信装置間で経済的に共有できる通信装置を
提供することにある。
An object of the present invention is to provide a communication device that can economically share a key used for encrypted communication between arbitrary communication processing devices belonging to a network.

(課題を解決するための手段) この発明にかかる通信装置は、鍵生成用データを保持す
る鍵生成用データ保持手段、&n生成用データから鍵を
生成する鍵生成手段、鍵を保持する鍵保持手段、鍵生成
用データを送信する鍵生成用データ送信手段、&l生成
用データを受信する鍵生成用データ受信手段、1i生成
用データから鍵を生成する鍵生成手段を無効にする鍵生
成機能無効手段と、各手段の内一つまたは複数を選択し
て使用可能に設定する選択手段とを備え、機能選択機能
により鍵生成用データ保持手段、鍵生成手段、生成され
た鍵の鍵保持手段および鍵生成手段を無効にする鍵生成
機能無効手段を選択させて使用可能に設定し、鍵生成用
データ保持手段により保持された鍵生成用データを鍵生
成手段に人力して鍵を生成させ、生成した鍵を鍵保持手
段で保持させ、その後に鍵生成手段を無効にさせる制御
手段を有するものである。
(Means for Solving the Problems) A communication device according to the present invention includes a key generation data holding means for holding key generation data, a key generation means for generating a key from the &n generation data, and a key holding means for holding the key. means, key generation data transmitting means for transmitting key generation data, key generation data receiving means for receiving &l generation data, key generation function disabling for disabling the key generation means for generating keys from 1i generation data and a selection means for selecting one or more of the means and setting them to be usable, and the function selection function allows the key generation data holding means, the key generation means, the key holding means for the generated key, and The key generation function disabling means for disabling the key generation means is selected and enabled, and the key generation means is manually generated using the key generation data held by the key generation data holding means to generate a key. The control means has a control means for causing the key holding means to hold the generated key, and then disabling the key generation means.

また、制御装置として、機能選択手段により鍵生成用デ
ータ保持手段および鍵生成用データ送信手段を選択させ
て使用可能に設定し、鍵生成用データ保持手段により保
持された鍵生成用データを鍵生成用データ送信手段によ
り通信相手に送信させるようにしてもよい。
Further, the control device selects and enables the key generation data holding means and the key generation data transmission means by the function selection means, and generates a key by using the key generation data held by the key generation data holding means. Alternatively, the data may be transmitted to the other party using the data transmitting means.

さらに、制御装置として、機能選択手段により鍵生成手
段および鍵生成用データ受信手段を選択させて使用可能
に設定し、鍵生成用データ受信手段により通信相手から
受信した鍵生成用データを鍵生成手段に入力して鍵を生
成させるようにすることもできる。
Further, as a control device, the function selection means selects the key generation means and the key generation data reception means and sets them to be usable, and the key generation data received from the communication partner is transmitted to the key generation means by the key generation data reception means. You can also have it generate a key by entering it.

〔作用〕[Effect]

この発明にかかる請求項(1)に記載の発明は、鍵生成
用データを生成した後、この生成した鍵は鍵保持手段で
保持されるとともに、鍵生成手段は無効にされる。
In the invention according to claim (1), after the key generation data is generated, the generated key is held by the key holding means, and the key generation means is invalidated.

また、請求項(2)に記載の発明は、鍵生成用データは
鍵生成用データ保持手段に保持された鍵生成用データ送
信手段により通信相手に送信する。
Further, in the invention described in claim (2), the key generation data is transmitted to the communication partner by the key generation data transmitting means held in the key generation data holding means.

さらに、請求項(3)に記載の発明は、鍵生成用データ
を通信相手から受信し、鍵生成手段に人力して鍵を生成
する。
Furthermore, in the invention described in claim (3), key generation data is received from a communication partner, and the key generation means is manually generated to generate a key.

〔実施例〕〔Example〕

この発明の一実施例を図面について説明する。 An embodiment of the present invention will be described with reference to the drawings.

第1図に、同時に1つまたは複数の相手と通信を行う機
能を有する複数の通信処理装置と、それらに接続された
個々の回線に対応する通信装置および通信装置間を相互
に接続するネットワークから構成されるシステム構成を
示す。
Figure 1 shows a network that interconnects multiple communication processing devices that have the function of communicating with one or more parties at the same time, communication devices corresponding to individual lines connected to them, and communication devices. Shows the configured system configuration.

i1図kl:オイテ、100,200.300は通信処
理装置であり、400はネットワークを示す。101,
201,301は処理装置、102−1〜102−m、
202,302はそれぞれ通信装置を示す。なお、通信
装置102−1〜102−mは総称するときは単に10
2を用いる。
Figure i1 kl: 100, 200, 300 is a communication processing device, and 400 is a network. 101,
201, 301 are processing devices, 102-1 to 102-m,
202 and 302 each indicate a communication device. In addition, when the communication devices 102-1 to 102-m are collectively referred to, they are simply referred to as 10.
2 is used.

第2図に通信処理装置100,200,300の構成要
素となる通信装置102,202.302の構成を、通
信装置102を例にとって示す。
FIG. 2 shows the configuration of the communication devices 102, 202, and 302, which are the constituent elements of the communication processing devices 100, 200, and 300, taking the communication device 102 as an example.

通信装置102は鍵生成用データ保持手段1.鍵生成手
段2.鍵保持手段3.tl生成用データ送信手段4.鍵
生成用データ受信手段5.前記鍵生成手段2を無効にす
る鍵生成機能無効手段61機能選択手段7.制御手段8
.暗号手段9.データ送受信手段10から構成される。
The communication device 102 includes key generation data holding means 1. Key generation means 2. Key holding means 3. tl generation data transmission means 4. Key generation data receiving means 5. Key generation function disabling means 61 for disabling the key generation means 2 Function selection means 7. Control means 8
.. Encryption means 9. It is composed of data transmitting/receiving means 10.

通信処理装置100の通信装置102が相手通信処理装
置200゜300の通信装置202,302と鍵を共有
する方法を以下に述べる。
A method for the communication device 102 of the communication processing device 100 to share a key with the communication devices 202, 302 of the partner communication processing device 200, 300 will be described below.

(通信装置の初期設定) ネットワーク管理者は通信装置102に対してあらかじ
め選択手段7により鍵生成用データ保持手段1.1!生
成手段2.&!保持手段3.1を生成用データ送信手段
4.11生成用デ一タ受信手段5゜鍵生成機能無効手段
6の内必要な手段を選択して使用可能に設定し、通信装
置102の機能を初期設定する。
(Initial Settings of Communication Device) The network administrator selects in advance the selection means 7 for the communication device 102 by key generation data holding means 1.1! Generation means 2. &! Select and enable the holding means 3.1 from among the generation data transmission means 4.11 the generation data reception means 5 and the key generation function disabling means 6, and enable the functions of the communication device 102. Initialize.

初期設定された通信装置102 (202,302)の
具体例を第3図(a)および第3図(b)に示す。第3
図(a)の通信装置202 (302)は鍵生成用デー
タ保持手段1.*生成用データ送信手段4.鍵生成手段
2.&1保持手段3.鍵生成機能無効手段6を選択され
た装置で、鍵生成用データと鍵生成手段2により生成し
た鍵を鍵保持手段3で保持した後に鍵生成機能そのもの
は無効化されている。第3図(b)の通信装置102−
1〜102−mは鍵生成用データ受信手段5と鍵生成手
段2が選択された装置である。
Specific examples of the initialized communication device 102 (202, 302) are shown in FIGS. 3(a) and 3(b). Third
The communication device 202 (302) in Figure (a) is the key generation data holding means 1. *Generation data transmission means 4. Key generation means 2. &1 Holding means 3. In a device in which the key generation function disabling means 6 is selected, after the key generation data and the key generated by the key generation means 2 are held in the key holding means 3, the key generation function itself is disabled. Communication device 102- in FIG. 3(b)
1 to 102-m are devices in which the key generation data receiving means 5 and the key generation means 2 are selected.

(通信時の鍵共有方法) 第4図は、第3図(a)の機能を有する通信装置202
 (302)と第3図(b)の機能を有する通信装置1
02−1〜102−m間の鍵共有と暗号通信の手順を示
すものである。通信装置202 、、302は暗号通信
を行う前に鍵生成用データ送信手段4によりあらかじめ
保持している鍵生成用データを送信する。通信装置10
2−1〜102−mは鍵生成用データ受信手段5により
通信装置202,302から受信した鍵生成用データと
鍵生成手段2により鍵を生成する。以後は通信装置20
2,302側ではあらかじめ保持している鍵を、通信装
置102−1〜102−m側では鍵生成用データから生
成した鍵を用いて■■■−■■、■@−00の手順で暗
号通信を実現する。
(Key sharing method during communication) FIG. 4 shows a communication device 202 having the functions shown in FIG. 3(a).
(302) and a communication device 1 having the functions shown in FIG. 3(b)
It shows the procedure of key sharing and encrypted communication between 02-1 to 102-m. Before the communication devices 202, 302 perform encrypted communication, the key generation data transmitting means 4 transmits the key generation data held in advance. Communication device 10
2-1 to 102-m generate keys using the key generation data received from the communication devices 202 and 302 by the key generation data receiving means 5 and the key generation means 2. From now on, the communication device 20
The 2,302 side uses the key held in advance, and the communication devices 102-1 to 102-m use the key generated from the key generation data to encrypt in the steps of ■■■-■■, ■@-00. Realize communication.

この方法は、従来技術と比較して、通信相手ごとに異な
る鍵を経済的に共有できることが特徴である。すわなち
、通信を行う2つの通信装置202.302側と102
−1〜102−m側の少なくとも一方は通信時に鍵を生
成するので、通信相手ごとの多数の鍵を常時保持する必
要がない。通信装置202.302側の鍵は装置を利用
者に弓き渡す前に実施する初期設定のときに設定され、
この鍵生成機能はすでに無効化されているため通信装置
202.302の利用者は鍵生成機能を知ることができ
ないようになっている。
Compared to conventional techniques, this method is characterized in that different keys can be shared economically for each communication partner. In other words, the two communication devices 202, 302 and 102 that communicate
Since at least one of the parties -1 to 102-m generates a key during communication, there is no need to always hold a large number of keys for each communication partner. The key on the communication device 202, 302 side is set during the initial settings performed before handing over the device to the user.
Since this key generation function has already been disabled, the user of the communication device 202, 302 cannot know the key generation function.

すなわち、鍵生成はセンタ等の信頼できる通信処理装置
側の通信装置102−1〜102−mのみが行うものと
し、端末等の一般通信処理装置側の通信装置202.3
02では鍵生成機能を使用できないように設定しておく
等の方式をとれば、センタ以外は他の端末の鍵を知るこ
とができないことからセンタ一端末間で安全な暗号通信
が可能となる。
That is, key generation is performed only by the communication devices 102-1 to 102-m on the reliable communication processing device side such as a center, and the key generation is performed by the communication devices 202.3 on the general communication processing device side such as a terminal.
In 02, if a method such as setting the key generation function so that it cannot be used is adopted, since no one other than the center can know the keys of other terminals, safe encrypted communication between the center and the terminal becomes possible.

次に、上記ノ通信装置102,202.302を用いた
各種の通信態様について説明する。
Next, various communication modes using the above communication devices 102, 202, and 302 will be explained.

(実施例1) (センタ一端末間での鍵共有)第5図に
よりセンタ一端末間での鍵共有の実施例を説明する。セ
ンタCは同時に複数の相手と通信でき、複数の通信装置
c−j、 j=x、・・・・・・mを有し、端末Tiは
通信装置Miを有し、センタCの任意の通信装置C−j
を介してセンタCと通信するネットワークである。例え
ば住民票等の個人情報を暗号通信を用いてファクシミリ
端末に送信するネットワークを考える。センタCは市役
所等の行政機関、端末Tiは一般家庭のファクシミリ端
末であり、通信装置Miは端末Tiに内蔵されたモデム
等の回線終端装置である。端末TtからセンタCにアク
セスし、暗号通信を用いて情報を送信してもらう場合に
、端末Tiの通信装置MiとセンタCの任意の通信装置
C−jとの間で端末鍵Kiを共有する例により説明する
(Embodiment 1) (Key sharing between a center and a terminal) An embodiment of key sharing between a center and a terminal will be described with reference to FIG. Center C can communicate with multiple parties at the same time and has multiple communication devices c-j, j=x, m, terminal Ti has communication device Mi, and any communication of center C Device C-j
This is a network that communicates with center C via. For example, consider a network that transmits personal information such as a residence card to a facsimile terminal using encrypted communication. The center C is a government agency such as a city hall, the terminal Ti is a facsimile terminal in a general household, and the communication device Mi is a line termination device such as a modem built into the terminal Ti. When a terminal Tt accesses the center C and sends information using encrypted communication, a terminal key Ki is shared between the communication device Mi of the terminal Ti and any communication device C-j of the center C. Let's explain by example.

ここでは鍵生成機能をFで表し、鍵生成用データとして 端末Tiの電話番号IDi。Here, the key generation function is represented by F, and the key generation data is Telephone number IDi of terminal Ti.

端末Tiの鍵乱数化コードGi。Key randomization code Gi of terminal Ti.

センタCが有する端末側に秘密の鍵生成パラメータP を用い端末11Kiは次式により生成するものとする。Secret key generation parameter P on the terminal side owned by center C It is assumed that the terminal 11Ki is generated using the following equation.

Ki=F(PeGi、  ID1) (センタ側通信装置の初期設定) センタCは通信装置C−jに対して、あらかじめ選択手
段7により鍵生成用データ保持手段1゜鍵生成手段2.
&!生成用データ受信手段5を選択して使用可能に設定
し、鍵生成用データ保持手段1には鍵生成パラメータP
を書き込んでおく。
Ki=F(PeGi, ID1) (Initial setting of center side communication device) The center C selects in advance the key generation data holding means 1, the key generation means 2, and the selection means 7 for the communication device C-j.
&! The generation data receiving means 5 is selected and enabled, and the key generation parameter P is set in the key generation data holding means 1.
Write it down.

(端末側通信装置の初期設定) センタCは端末Tiの通信装置MLに対して、あらかじ
め選択手段7により鍵生成用データ保持手段1.鍵保持
手段3.1!生成用デ一タ送信手段4を選択して使用可
能に設定する。さらに、センタCは端末Tiに電話番号
IDiと鍵乱数化コードGiを付与し、これらを鍵生成
用データ保持手段1に書き込むとともに、次式により端
末鍵Kiを決め鍵保持装置に設定する。
(Initial Setting of Terminal Side Communication Device) The center C selects the key generation data holding means 1. Key holding means 3.1! The generation data transmission means 4 is selected and set to be usable. Furthermore, the center C assigns a telephone number IDi and a key randomization code Gi to the terminal Ti, writes these into the key generation data holding means 1, and sets the terminal key Ki in the key holding device according to the following equation.

Ki=F (PeGi、ID1) なお、端末側の通信装置Miに対しては鍵生成手段2を
使用可能に設定せず、また、鍵生成パラメータPは鍵生
成用データ保持手段1に投入しない方が第三者の端末T
iが端末11Kiを知ることができないので安全性が高
い。
Ki=F (PeGi, ID1) Note that the key generation means 2 is not set to be usable for the communication device Mi on the terminal side, and the key generation parameter P is not input to the key generation data holding means 1. is a third party's terminal T
The security is high because i cannot know the terminal 11Ki.

(通信時の鍵共有方法) 住民票請求者が端末TiからセンタCの代表電話番号に
電話をかけ、ネットワーク400を経由してセンタCの
任意の通信装置C−jと接続したとする。端末側の通信
装置Miは鍵生成用データ保持手段1に保持された電話
番号IDiと鍵乱数化コードGiを鍵生成用データ送信
手段4によりセンタCに送信するとともに、鍵保持手段
3から端末11Kiを取り出す。一方、センタ側の通信
装置c−jは鍵生成用データ受信手段5により端末Ti
の電話番号IDiと鍵乱数化コードGiを受信し、鍵生
成用データ保持手段1から鍵生成パラメータPを取り出
し、これらを鍵生成手段2に入力することによって端末
Tiの端末鍵 Ki=F(PeGi、ID1) を得る。
(Key sharing method during communication) It is assumed that a residence card requester calls the representative telephone number of the center C from the terminal Ti and connects to an arbitrary communication device C-j of the center C via the network 400. The communication device Mi on the terminal side transmits the telephone number IDi and the key randomization code Gi held in the key generation data holding means 1 to the center C by the key generation data sending means 4, and also transmits the telephone number IDi and the key randomization code Gi held in the key generation data holding means 1 to the center C from the key holding means 3 to the terminal 11Ki. Take out. On the other hand, the communication device c-j on the center side receives the terminal Ti using the key generation data receiving means 5.
The terminal key Ki=F(PeGi , ID1).

以上の手続きにより端末Tiの通信装置MiとセンタC
の任意の通信装置C−jとの間で端末鍵Kiを共有でき
る。
By the above procedure, communication device Mi of terminal Ti and center C
The terminal key Ki can be shared with any communication device C-j.

〔実施例2〕 (センタ一端末間での鍵共有)実施例1
において、鍵乱1数化コードGiを省略して端末Tiの
端末鍵を Ki=(F、ID1) により生成する方法である。他は実施例1と同様である
[Example 2] (Key sharing between center and terminal) Example 1
In this method, the key randomization code Gi is omitted and the terminal key of the terminal Ti is generated by Ki=(F, ID1). The rest is the same as in Example 1.

〔実施例3〕 (任意端末間での鍵共有)第6図により
任意端末間での鍵共有の実施例を説明する。端末Tiは
通信装置Miを有し、任意の端末T」の通信装置Mjを
介して通信するネットワークである。
[Embodiment 3] (Key sharing between arbitrary terminals) An embodiment of key sharing between arbitrary terminals will be explained with reference to FIG. The terminal Ti has a communication device Mi, and is a network that communicates via the communication device Mj of an arbitrary terminal T.

例えば端末としてファクシミリ端末を考える。For example, consider a facsimile terminal as a terminal.

通信装置は端末に内蔵されたモデム等の回線終端装置で
ある。送信側の端末Tiからネットワーク400を介し
て受信側の端末Tjにアクセスし、暗号通信を用いて情
報を送信する場合に、端末Tiの通信装置Miと端末T
jの通信装置Mjとの間で端末Tjの端末ff1Kjを
共有する例により説明する。
The communication device is a line termination device such as a modem built into the terminal. When a transmitting terminal Ti accesses a receiving terminal Tj via the network 400 and transmits information using encrypted communication, the communication device Mi of the terminal Ti and the terminal T
An example will be explained in which the terminal Tj shares the terminal ff1Kj with the communication device Mj of the terminal Tj.

ここでは鍵生成手段をFで表し鍵生成用データとして 端末Tiの電話番号IDi、端末Tiの鍵乱数化コード
Gi。
Here, the key generation means is represented by F, and the key generation data includes the telephone number IDi of the terminal Ti and the key randomization code Gi of the terminal Ti.

鍵生成パラメータP を用い、端末11Kiは次式により生成するものとする
It is assumed that the terminal 11Ki generates the key using the following equation using the key generation parameter P.

Ki=F  (PeGi、  ID1)(通信装置の初
期設定) ネットワーク管理者は、通信装置Miに対して、あらか
じめ選択手段7により鍵生成用データ保持手段1.tl
生成手段2.鍵保持手段3.1!生成用デ一タ送信手段
4.lI生成用データ受信手段5を選択して使用可能に
設定する。さらに、端末Tiに電話番号IDiと鍵乱数
化コードGiを付与し、鍵乱数化コードGiと鍵生成パ
ラメータPを鍵生成用データ保持手段1に書き込み、端
末鍵Ki=F (P(:E)Gi、ID1)を決め鍵保
持手段3に設定する。他の端末Tjの通信装置Mjにつ
いても電話番号IDjと鍵乱数化コードGjを付与し、
同様に初期設定しておく。
Ki=F (PeGi, ID1) (Initial setting of communication device) The network administrator selects the key generation data holding unit 1. tl
Generation means 2. Key holding means 3.1! Generation data transmission means 4. The II generation data receiving means 5 is selected and set to be usable. Furthermore, a telephone number IDi and a key randomization code Gi are given to the terminal Ti, a key randomization code Gi and a key generation parameter P are written in the key generation data holding means 1, and the terminal key Ki=F (P(:E) Gi, ID1) is set in the determined key holding means 3. A telephone number IDj and a key randomization code Gj are also assigned to the communication device Mj of the other terminal Tj,
Make initial settings in the same way.

(通信時の鍵共有方法) 送信側の端末Tiは受信側の端末Tjに鍵乱数化コード
Gjの送信を要求し、端末Tjは鍵生成用データ保持手
段1に保持された鍵乱数化コードGjを鍵生成用データ
送信手段4により端末Tiに送信する。端末Tiは鍵生
成用データ受信手段5により端末Tjの鍵乱数化コード
Gjを受信し、鍵生成用データ保持手段1に保持された
鍵生成パラメータPおよび端末Tjの電話番号IDjと
ともに鍵生成手段2に入力することによって端末鍵 Kj=F (PΦGj、IDj) を生成する。
(Key sharing method during communication) The transmitting terminal Ti requests the receiving terminal Tj to transmit the key randomization code Gj, and the terminal Tj transmits the key randomization code Gj held in the key generation data holding means 1. is transmitted to the terminal Ti by the key generation data transmitting means 4. The terminal Ti receives the key randomization code Gj of the terminal Tj by the key generation data receiving means 5, and sends it to the key generation means 2 together with the key generation parameter P held in the key generation data holding means 1 and the telephone number IDj of the terminal Tj. A terminal key Kj=F (PΦGj, IDj) is generated by inputting the following.

一方、受信側の端末Tjは鍵保持手段3から端末鍵Kj
を取り出す。
On the other hand, the terminal Tj on the receiving side receives the terminal key Kj from the key holding means 3.
Take out.

以上の手続きにより端末Tiの通信装置Miと端末Tj
の通信装置Mjとの間で端末&lKjを共有できる。
Through the above procedure, communication device Mi of terminal Ti and terminal Tj
The terminal &lKj can be shared with the communication device Mj of the terminal &lKj.

(実施例4)(任意端末間での鍵共有)実施例3におい
て、鍵乱数化コードGjを省略して端末Tiの端末鍵を Ki=F (P、ID1) により生成する方式である。各通信装置に関しては鍵生
成用データ送信手段4,1を生成用データ受信手段5を
使用可能に設定する必要なない。他は実施例3と同様で
ある。
(Embodiment 4) (Key sharing between arbitrary terminals) In Embodiment 3, the key randomization code Gj is omitted and the terminal key of terminal Ti is generated using Ki=F (P, ID1). Regarding each communication device, it is not necessary to set the key generation data transmission means 4, 1 to enable the generation data reception means 5. The rest is the same as in Example 3.

〔実施例5)(グループ内での鍵共有)実施例3におい
て、鍵生成パラメータPを任意の複数端末からなるグル
ープごとに異なる値に設定することにより、あらかじめ
決められたグループに属する任意の端末の通信装置間で
通信相手ごとに異なる鍵を共有することができる。
[Example 5] (Key sharing within a group) In Example 3, by setting the key generation parameter P to a different value for each group of multiple arbitrary terminals, any terminal belonging to a predetermined group A different key can be shared between communication devices for each communication partner.

〔実施例6〕 (グループ内での鍵共有)実施例5にお
いて、鍵乱数化コードGiを省略して端末Tiの端末鍵
を Ki=F (P、ID1) により生成する方法である。他は実施例5と同様である
[Embodiment 6] (Key sharing within a group) In Embodiment 5, the key randomization code Gi is omitted and the terminal key of the terminal Ti is generated by Ki=F (P, ID1). The rest is the same as in Example 5.

(発明の効果) この発明による通信装置は、鍵生成用データを保持する
鍵生成用データ保持手段、&l生成用データから鍵を生
成する鍵生成手段、fflを保持する鍵保持手段、鍵生
成用データを送信する鍵生成用データ送信手段、&l生
成用データを受信する鍵生成用データ受信手段、鍵生成
用データから鍵を生成する鍵生成手段を無効にする鍵生
成機能無効手段と、各手段の内1つまたは複数を選択し
て使用可能に設定する選択手段とを備えたので、ネット
ワーク管理者があらかじめそのネットワークにおける鍵
共有に必要な手段を選択して使用可能に設定し、特定の
機能を有する通信装置として初期設定されるので、その
機能の種類によりセンタ一端末系、端末一端末系等の様
々なシステムに対応できる。この通信装置を用いれば通
信相手ごとに異なる鍵を共有でき、しかも個々の通信装
置が通信相手刈の多数の鍵を保持する必要がなく経済的
である。さらに、初期設定の仕方によっては安全性の高
い鍵共有も可能である等の利点がある。
(Effects of the Invention) The communication device according to the present invention includes a key generation data holding means for holding key generation data, a key generation means for generating a key from &l generation data, a key holding means for holding ffl, and a key generation data holding means for holding key generation data. A key generation data transmitting means for transmitting data, a key generation data receiving means for receiving &l generation data, a key generation function disabling means for disabling the key generation means for generating a key from the key generation data, and each means The network administrator can select and enable one or more of the methods necessary for key sharing in the network, enable the network administrator, and select one or more of the methods to enable the use of a specific function. Since the communication device is initially set as a communication device having a function, it can be used in various systems such as a center-to-terminal system and a terminal-to-terminal system, depending on the type of function. By using this communication device, different keys can be shared for each communication partner, and each communication device does not need to hold a large number of keys for each communication partner, which is economical. Furthermore, depending on how the initial settings are made, highly secure key sharing is also possible.

【図面の簡単な説明】[Brief explanation of drawings]

第1図はこの発明の通信装置を用いた通信処理装置とネ
ットワークの関係を示す図、第2図は通信装置の構成を
示す図、第3図(a)、(b)は第2図の通信装置の動
作状態をそれぞれ示す図、第4図は鍵共有と暗号通信の
実施手順の例を示す図、第5図、第6図はこの発明によ
る通信装置を用いた通信態様を説明するためのブロック
図である。 図中、1は鍵生成用データ保持手段、2は鍵生成手段、
3は鍵保持手段、4は鍵生成用データ送信手段、5は鍵
生成用データ受信手段、6は鍵生成機能無効手段、7は
選択手段、8は制御手段、9は暗号手段、10はデータ
送受信手段、100.200,300は通信処理装置、
101゜201.301は処理装置、102,202゜
302は通信装置、400はネットワークである。
FIG. 1 is a diagram showing the relationship between a communication processing device using the communication device of the present invention and a network, FIG. 2 is a diagram showing the configuration of the communication device, and FIGS. 3(a) and (b) are the same as those in FIG. FIG. 4 is a diagram showing an example of the implementation procedure of key sharing and encrypted communication, and FIGS. 5 and 6 are for explaining communication modes using the communication device according to the present invention. FIG. In the figure, 1 is a key generation data holding means, 2 is a key generation means,
3 is a key holding means, 4 is a key generation data transmitting means, 5 is a key generation data receiving means, 6 is a key generation function disabling means, 7 is a selection means, 8 is a control means, 9 is an encryption means, and 10 is data Transmitting/receiving means, 100, 200, 300 is a communication processing device,
101°201.301 is a processing device, 102, 202°302 is a communication device, and 400 is a network.

Claims (3)

【特許請求の範囲】[Claims] (1)同時に1つまたは複数の相手と通信を行う機能を
有する複数の通信処理装置と、前記通信処理装置に接続
された個々の回線に対応する通信装置および前記通信装
置間を相互に接続するネットワークから構成されるシス
テムにおいて、鍵生成用データを保持する鍵生成用デー
タ保持手段、前記鍵生成用データから鍵を生成する鍵生
成手段、前記鍵を保持する鍵保持手段、前記鍵生成用デ
ータを送信する鍵生成用データ送信手段、前記鍵生成用
データを受信する鍵生成用データ受信手段、鍵生成用デ
ータから鍵を生成する鍵生成手段を無効にする鍵生成機
能無効手段と、前記各手段の内1つまたは複数を選択し
て使用可能に設定する選択手段とを備え、前記機能選択
機能により前記鍵生成用データ保持手段、鍵生成手段、
生成された鍵の鍵保持手段および鍵生成手段を無効にす
る鍵生成機能無効手段を選択させて使用可能に設定し、
鍵生成用データ保持手段により保持された鍵生成用デー
タを鍵生成手段に入力して鍵を生成させ、生成した鍵を
鍵保持手段で保持させ、その後に鍵生成手段を無効にさ
せる制御手段を有することを特徴とする通信装置。
(1) Mutually connecting a plurality of communication processing devices having the function of communicating with one or more parties at the same time, communication devices corresponding to individual lines connected to the communication processing devices, and the communication devices. In a system comprising a network, a key generation data holding means holds key generation data, a key generation means generates a key from the key generation data, a key holding means holds the key, and the key generation data key generation data transmitting means for transmitting the key generation data, key generation data receiving means for receiving the key generation data, key generation function disabling means for disabling the key generation means for generating the key from the key generation data; a selection means for selecting one or more of the means and setting it usable; the function selection function allows the key generation data holding means, the key generation means,
Select and enable a key generation function disabling means for disabling the key holding means and key generation means of the generated key,
A control means for inputting key generation data held by the key generation data holding means into the key generation means to generate a key, holding the generated key in the key holding means, and then disabling the key generation means. A communication device comprising:
(2)同時に1つまたは複数の相手と通信を行う機能を
有する複数の通信処理装置と、前記通信処理装置に接続
された個々の回線に対応する通信装置および前記通信装
置間を相互に接続するネットワークから構成されるシス
テムにおいて、鍵生成用データを保持する鍵生成用デー
タ保持手段、前記鍵生成用データから鍵を生成する鍵生
成手段、前記鍵を保持する鍵保持手段、前記鍵生成用デ
ータを送信する鍵生成用データ送信手段、前記鍵生成用
データを受信する鍵生成用データ受信手段、鍵生成用デ
ータから鍵を生成する鍵生成手段を無効にする鍵生成機
能無効手段と、前記各手段の内一つまたは複数を選択し
て使用可能に設定する選択手段とを備え、前記機能選択
手段により前記鍵生成用データ保持手段および鍵生成用
データ送信手段を選択させて使用可能に設定し、鍵生成
用データ保持手段により保持された鍵生成用データを鍵
生成用データ送信手段により通信相手に送信させる制御
手段を有することを特徴とする通信装置。
(2) Mutually connecting a plurality of communication processing devices having the function of communicating with one or more parties at the same time, communication devices corresponding to individual lines connected to the communication processing devices, and the communication devices. In a system comprising a network, a key generation data holding means holds key generation data, a key generation means generates a key from the key generation data, a key holding means holds the key, and the key generation data key generation data transmitting means for transmitting the key generation data, key generation data receiving means for receiving the key generation data, key generation function disabling means for disabling the key generation means for generating the key from the key generation data; a selection means for selecting one or more of the means and setting it usable, the function selection means selecting the key generation data holding means and the key generation data transmission means and setting them usable. 1. A communication device comprising: control means for causing key generation data transmitting means to transmit key generation data held by key generation data holding means to a communication partner.
(3)同時に1つまたは複数の相手と通信を行う機能を
有する複数の通信処理装置と、前記通信処理装置に接続
された個々の回線に対応する通信装置および前記通信装
置間を相互に接続するネットワークから構成されるシス
テムにおいて、鍵生成用データを保持する鍵生成用デー
タ保持手段、前記鍵生成用データから鍵を生成する鍵生
成手段、前記鍵を保持する鍵保持手段、前記鍵生成用デ
ータを送信する鍵生成用データ送信手段、前記鍵生成用
データを受信する鍵生成用データ受信手段、鍵生成用デ
ータから鍵を生成する鍵生成手段を無効にする鍵生成機
能無効手段と、前記各手段の内一つまたは複数を選択し
て使用可能に設定する選択手段とを備え、前記機能選択
手段により前記鍵生成手段および鍵生成用データ受信手
段を選択させて使用可能に設定し、鍵生成用データ受信
手段により通信相手から受信した鍵生成用データを鍵生
成手段に入力して鍵を生成させる制御手段を有すること
を特徴とする通信装置。
(3) Mutually connecting a plurality of communication processing devices having the function of communicating with one or more parties at the same time, communication devices corresponding to individual lines connected to the communication processing devices, and the communication devices. In a system comprising a network, a key generation data holding means holds key generation data, a key generation means generates a key from the key generation data, a key holding means holds the key, and the key generation data key generation data transmitting means for transmitting the key generation data, key generation data receiving means for receiving the key generation data, key generation function disabling means for disabling the key generation means for generating the key from the key generation data; a selection means for selecting and enabling one or more of the means; the function selection means selects and enables the key generation means and the key generation data receiving means; 1. A communication device comprising a control means for inputting key generation data received from a communication partner by a communication data receiving means to the key generation means to generate a key.
JP1078542A 1989-03-31 1989-03-31 Communication device Expired - Fee Related JP2518919B2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP1078542A JP2518919B2 (en) 1989-03-31 1989-03-31 Communication device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP1078542A JP2518919B2 (en) 1989-03-31 1989-03-31 Communication device

Publications (2)

Publication Number Publication Date
JPH02260841A true JPH02260841A (en) 1990-10-23
JP2518919B2 JP2518919B2 (en) 1996-07-31

Family

ID=13664803

Family Applications (1)

Application Number Title Priority Date Filing Date
JP1078542A Expired - Fee Related JP2518919B2 (en) 1989-03-31 1989-03-31 Communication device

Country Status (1)

Country Link
JP (1) JP2518919B2 (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007174658A (en) * 2006-12-19 2007-07-05 Toshiba Corp Mobile phone
JP2009060384A (en) * 2007-08-31 2009-03-19 Sharp Corp Image communication system and image communication apparatus
US7685071B2 (en) 2005-04-18 2010-03-23 Kabushiki Kaisha Toshiba Mobile communication terminal
US8064603B2 (en) 2005-11-29 2011-11-22 Kabushiki Kaisha Toshiba Information terminal

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7685071B2 (en) 2005-04-18 2010-03-23 Kabushiki Kaisha Toshiba Mobile communication terminal
US8064603B2 (en) 2005-11-29 2011-11-22 Kabushiki Kaisha Toshiba Information terminal
JP2007174658A (en) * 2006-12-19 2007-07-05 Toshiba Corp Mobile phone
JP2009060384A (en) * 2007-08-31 2009-03-19 Sharp Corp Image communication system and image communication apparatus

Also Published As

Publication number Publication date
JP2518919B2 (en) 1996-07-31

Similar Documents

Publication Publication Date Title
US7817802B2 (en) Cryptographic key management in a communication network
US6018583A (en) Secure computer network
CN106452739A (en) Quantum network service station and quantum communication network
CN111192050B (en) Digital asset private key storage and extraction method and device
CN104917807A (en) Resource transfer method, apparatus and system
CN119276494B (en) Session key generation method and related device
CN110276000A (en) Acquisition methods and device, the storage medium and electronic device of media resource
CA3102933C (en) Encryption device, a communication system and method of exchanging encrypted data in a communication network
CN107493281A (en) encryption communication method and device
US20080189297A1 (en) Securely Storing and Accessing Data
JPH02260841A (en) Communication equipment
KR20180005095A (en) Apparatus and method for sharing information
CN104794408B (en) File encrypting method and terminal system
JP2005209118A (en) Information distributed storage system, and overall authentication server device, authentication server device, distributed storage server device, and information distributed storage method used in this system
JP2001344214A (en) Terminal authentication method and cryptographic communication system
CN107426175A (en) The real-time encrypted transmission method of data
JP2005223773A (en) Method and apparatus for generating and sharing a common key within a group
JPH05347616A (en) Group encryption communication method and group encryption communication system
JPH09149023A (en) Information communication processing apparatus and information communication processing method
JPH07336328A (en) Cipher device
JPH01233851A (en) Cryptographic device
KR20050048936A (en) Method for protecting local wireless communication in wireless communication terminal
JPH0373633A (en) Cryptographic communication system
RU2838046C1 (en) Method of generating and distributing keys in multi-segment network with quantum key distribution
CN114785497B (en) A method and device for determining shared data for protecting data privacy

Legal Events

Date Code Title Description
LAPS Cancellation because of no payment of annual fees