JPH03162152A - Portable cipher key storage device - Google Patents

Portable cipher key storage device

Info

Publication number
JPH03162152A
JPH03162152A JP1300680A JP30068089A JPH03162152A JP H03162152 A JPH03162152 A JP H03162152A JP 1300680 A JP1300680 A JP 1300680A JP 30068089 A JP30068089 A JP 30068089A JP H03162152 A JPH03162152 A JP H03162152A
Authority
JP
Japan
Prior art keywords
public key
user
key
communication
certificate
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP1300680A
Other languages
Japanese (ja)
Other versions
JP2874916B2 (en
Inventor
Atsushi Shinpo
淳 新保
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Toshiba Corp
Original Assignee
Toshiba Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Toshiba Corp filed Critical Toshiba Corp
Priority to JP1300680A priority Critical patent/JP2874916B2/en
Publication of JPH03162152A publication Critical patent/JPH03162152A/en
Application granted granted Critical
Publication of JP2874916B2 publication Critical patent/JP2874916B2/en
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Abstract

PURPOSE:To facilitate the disclosure key management and to improve the system efficiency by holding separately only a disclosure key of the other user used frequently in each user in a small scale list in addition of storage of a secret key. CONSTITUTION:A portable cipher key storage device (IC card) 7 is provided with a storage means 10 having a disclosure key storage area 10A of a comparatively small capacity which stores a secret key of the own device, and also, can store plural disclosure keys of the other device to which a communication is executed frequently. Accordingly, when the disclosure key of only the other device to which a communication is executed frequently is stored in the disclosure key storage area 10A of this storage means 10, a cipher communication can be executed to the other user by only the own disclosure key in many cases. In such a way, the management of the disclosure key is facilitated, and the system efficiency can be improved.

Description

【発明の詳細な説明】 [発明の目的コ (産業上の利用分野) 本発明は、公開鍵暗号を取扱う情報通信システムのユー
ザ端末に接続されて使用される携帯用暗号鍵記憶装置に
関する。
DETAILED DESCRIPTION OF THE INVENTION [Purpose of the Invention (Field of Industrial Application) The present invention relates to a portable cryptographic key storage device used by being connected to a user terminal of an information communication system that handles public key cryptography.

(従来の技術) 各種情報通信システムにおいては、メッセージの作或者
が誰なのか、メッセージが通信途上において改ざんされ
ていないが、通信相手は本人に間違いないかなど各種の
事項を認証することが重要要件となっている。また、通
信回線や記憶媒体から不正にデータが読み出されること
を防止するデータ守秘も重要性を増している。
(Prior art) In various information communication systems, it is important to authenticate various things such as who wrote the message, whether the message has not been tampered with during communication, and whether the person communicating with the message is the same person. It is a requirement. Furthermore, data confidentiality, which prevents data from being read illegally from communication lines or storage media, is becoming increasingly important.

この種認証及び守秘の機能を実現する方峡として暗号技
術、特に公開鍵暗号技術が挙げられる。
Cryptographic technology, especially public key cryptographic technology, can be cited as a way to realize this type of authentication and confidentiality function.

この技術は、ある互いの逆変換を特定する情報としてあ
る特定のユーザあるいは装置だけに固有の秘密鍵及び不
特定多数のユーザあるいは装置に公開される公開鍵の二
種類の鍵を用いる暗号方式で、公開鍵を用いて作成され
た暗号文は秘密鍵を用いて解読でき、公開鍵から対応す
る秘密鍵を求めることは計算量的に困難であることが特
徴である。
This technology is an encryption method that uses two types of keys: a private key that is unique to a specific user or device, and a public key that is open to an unspecified number of users or devices. A ciphertext created using a public key can be decrypted using a private key, and finding the corresponding private key from the public key is computationally difficult.

公開鍵暗号技術の中で最も有名で、かつ有望視されてい
る方式としては、暗号通信にも認証通信にも利用できる
R S A (R1vest−Shamir−^旧em
an )方式が挙げられる。
The most famous and promising method among public key cryptographic techniques is RSA (R1vest-Shamir-^formerly em.
an ) method is mentioned.

RSA暗号方式は通信相手の公開鍵を(e,n)、秘密
鍵をd,Mを平文、Cを暗号文として、次の計算式(1
)、(2)により暗号化、復号化が行われる。
The RSA encryption method uses the following calculation formula (1) where the communication partner's public key is (e, n), the private key is d, M is plaintext, and C is ciphertext
) and (2), encryption and decryption are performed.

C − M  l!lod n           
=il)M − C dIlod n        
    =12)RSA暗号の安全性を保証するために
n,dは10進150桁(512ビット)程度の大きさ
が必要となる。eはかなり小さくてよく、1−0進10
桁(20ビット)程度で十分である。
C-Ml! lod n
=il) M − C dIlod n
=12) In order to guarantee the security of RSA encryption, n and d need to have a size of about 150 decimal digits (512 bits). e can be quite small, 1-0 base 10
A digit (20 bits) is sufficient.

上記式において(1〉が暗号化の操作,(2〉が復号化
の操作になる。逆に、平文をCとして(2)式の操作に
より暗号文(署名文)Mを作成することをディジタル署
名と呼ぶ。この場合、(1)の操作は署名の検査に相当
する。いずれの使い方においても(2)式の操作ができ
るのは秘密鍵dを知っているものに限られる。
In the above equation, (1> is the encryption operation, and (2> is the decryption operation.) Conversely, when the plaintext is C, creating the ciphertext (signature text) M by the operation of equation (2) is the digital It is called a signature. In this case, the operation in (1) corresponds to verifying the signature. In either case, only those who know the private key d can perform the operation in equation (2).

第5図〜第7図にRSA暗号を利用した情報通信システ
ムの構成例を3例示した。
FIGS. 5 to 7 show three examples of configurations of information communication systems using RSA cryptography.

第5図に示すシステムは、ネットワーク1に管理センタ
2と多数の端末3を接続し、各端末に秘密鍵記憶装置と
してのICカード4を接触または非接触で接続可能とし
、各端末3及び管理センタ2に全会員の公開鍵を記憶し
た公開鍵リスト5を設けたものである。
The system shown in FIG. 5 connects a management center 2 and a large number of terminals 3 to a network 1, and connects an IC card 4 as a private key storage device to each terminal with or without contact. A public key list 5 in which public keys of all members are stored is provided in the center 2.

このシステムは、各ユーザが他のユーザ全員の公開鍵を
いわば電話帳のような形でリストとして保持する方式で
あり、自己の公開鍵リスト5を自由に検索できる利点は
あるものの、新規ユーザがシステムに加入するたびに、
また、あるユーザが自分の公開鍵を変更するたびに、全
員の公開鍵リストラを変更しなければならないという欠
点がある。
In this system, each user maintains a list of all other users' public keys, similar to a telephone directory, and although it has the advantage of allowing users to freely search their own public key list 5, new users Every time you join the system,
Another drawback is that every time a user changes his or her own public key, everyone's public key restructuring must be changed.

第6図に示すシステムは、公開鍵リスト5を管理センタ
2にのみ設け、管理センタ2が公開鍵リストラを集中的
に管理する方式である。このシステムでは、公開鍵リス
ト5が1ケ所で集中管理されるので、リスト変更が容易
となるが、各ユーザは通信相手の公開鍵が必要となるた
びに管理センタ2の公開鍵リストラにアクセスするので
管理センタ2に負荷集中するという欠点がある。
The system shown in FIG. 6 is a system in which the public key list 5 is provided only in the management center 2, and the management center 2 centrally manages public key restructuring. In this system, the public key list 5 is centrally managed in one place, making it easy to change the list, but each user must access the public key restructuring in the management center 2 every time they need the public key of their communication partner. Therefore, there is a drawback that the load is concentrated on the management center 2.

第7図に示したシステムは、第5図及び第6図に示した
公開鍵リストラを排除する方法で、ユーザは通信相手の
公開鍵が必要となるたびに直接、通信相手の端末3ない
しICカード4のメモリ6に記憶された公開鍵を送信し
てもらうというものである。このシステムでは、公開鍵
リストらが排除されるので、その管理が不要となる利点
があるという反面、通信相手がスタンバイ状態でないと
公開鍵が得られないという欠点がある。
The system shown in FIG. 7 is a method that eliminates the public key restructuring shown in FIGS. The public key stored in the memory 6 of the card 4 is sent to the user. This system has the advantage that the public key list is eliminated and does not need to be managed, but has the disadvantage that the public key cannot be obtained unless the communication partner is in standby mode.

以上示したシステム例において、いずれの場合にも端末
3には、秘密鍵を保持するためのICカ一ド4が利用さ
れる。秘密鍵記憶装置としてICカード4を用いる理由
は主に次のような利点があるからである。
In the system examples shown above, in any case, the terminal 3 uses an IC card 4 for holding a private key. The reason why the IC card 4 is used as a private key storage device is mainly because it has the following advantages.

■ ICカードは、パスワード検査によるアクセス制御
が可能であり、不正なユーザの使用を排除できる。
■ Access to IC cards can be controlled by password checking, and use by unauthorized users can be excluded.

■ ICカードは可搬性の点で優れており、ICカード
のリーダ・ライタを備えた計算機端末であればどれでも
利用できる。
■ IC cards are excellent in terms of portability and can be used in any computer terminal equipped with an IC card reader/writer.

■ ICカードを分解して内部に記憶されている情報を
読み出すことは困難である。
■ It is difficult to disassemble an IC card and read out the information stored inside it.

ところで、上記の如き情報通信システムにあっては、第
3者による“なりすまし”の問題がある。
By the way, in the above information communication system, there is a problem of "spoofing" by a third party.

これは、例えば第7図に示すシステムにおいて、ユーザ
AがユーザBに公開鍵(eB.ne)の要求信号を送信
した場合を仮定すると、この要求信号を傍受したユーザ
Cが、自分の公開鍵( ec +nc)をユーザBを装
ってユーザAに送り付ければ、ユーザAはユーザBの公
開鍵が送られてきたものと欺かれる。この時、ユーザA
がユーザBに対して作成した暗号文Cは、Mmodnc
となるから復号鍵dcをもつユーザCによって復号され
ることになる。
For example, in the system shown in FIG. 7, if user A sends a request signal for a public key (eB.ne) to user B, then user C, who intercepted this request signal, will receive his own public key. If (ec + nc) is sent to user A under the guise of user B, user A will be fooled into thinking that user B's public key has been sent. At this time, user A
The ciphertext C created by user B is Mmodnc
Therefore, it is decrypted by user C who has the decryption key dc.

このようななりすましの問題に対処する方法としてko
hnf’elderによって示された方法( ”A M
ethod for Certificatlon,−
HIT Lab . for Coo+puLerSc
ience,Cambridge,Mass.(197
8))がある。この方法は例えば第7図において、管理
センタ2がユーザID及びユーザ公開鍵にディジタル署
名を行い、その署名文をもって公開鍵証明書とするもの
である。相手ユーザの公開鍵とセンタ2の公開鍵証明書
を得たユーザは管理センタ2の公開鍵eo,noを使っ
て証明書を検査することにより、ユーザ公開鍵の正当性
を確認できる。
As a way to deal with this kind of spoofing problem, ko
The method shown by hnf'elder ("A M
method for Certificatlon,-
HIT Lab. for Coo+puLerSc
ience, Cambridge, Mass. (197
8)). In this method, for example, as shown in FIG. 7, the management center 2 digitally signs a user ID and a user public key, and uses the signature as a public key certificate. The user who has obtained the public key of the other user and the public key certificate of the center 2 can confirm the validity of the user public key by inspecting the certificate using the public keys eo and no of the management center 2.

RSA暗号を利用することを想定し、シャドウ型の署名
及びインプリント型の署名に・つき具体的な利用法を説
明する。管理センタ2の秘密鍵をdo、公開鍵を(eo
, no) 、ユーザiのIDを101 、公開鍵を(
 el, nl)とする。
Assuming that RSA encryption is used, specific usage of shadow type signatures and imprint type signatures will be explained. The private key of management center 2 is do, the public key is (eo
, no), the ID of user i is 101, and the public key is (
el, nl).

[シャドウ型の署名〕 まず、センタ2で作威されるユーザiの公開鍵証明書C
ertiは次式で示される。
[Shadow type signature] First, user i's public key certificate C created at center 2
erti is expressed by the following formula.

Certl−(101,el.n1)do mod n
o     =−<3>メッセージ( lDl,el.
n1)はランダム・データに近いためこのメッセージを
適当にフォーマッティングして冗長性を加えたデータに
対してディジタル署名をする。なお、このようにフォー
マッティングされるデータのサイズが法noのサイズを
越える場合には、2ブロックに分割してそれぞれのブロ
ックに対してディジタル署名を施す。
Certl-(101,el.n1)do mod n
o = −<3> message ( ldl, el.
Since n1) is close to random data, this message is appropriately formatted, redundancy is added, and a digital signature is attached to the data. Note that if the size of the data formatted in this manner exceeds the size of the modulus number, it is divided into two blocks and a digital signature is applied to each block.

ユーザに対して送信された証明書Certiの検査は次
式で行われる。
The certificate Certi sent to the user is checked using the following formula.

Datal= (lDi ,  e i ,  n i
 )− CertImod no       − (
4)よって、証明書Cert iの形式がフォーマット
に合っていること、IDiが相手ユーザの10に一致し
ていることを確認し、Datalから相手公開鍵(ei
,n1)を得ることができる。
Data= (lDi, ei, ni
) − CertImod no − (
4) Therefore, confirm that the format of the certificate Cert i matches the format and that IDi matches the number 10 of the other user, and send the other party's public key (ei
, n1) can be obtained.

この方式の場合、証明書Certiだけあれば相手公開
鍵を得ることができる。しかし、通常、メッセージ(l
Di ,ei,nl)に約1.5倍の冗長度が付けられ
るので、証明書Certlのサイズはユーザ公開鍵情報
(IDi ,el,ni)に対して約1、5〜2倍にな
る。
In this method, the other party's public key can be obtained using only the certificate Certi. However, usually the message (l
Di, ei, nl) is given approximately 1.5 times the redundancy, so the size of the certificate Certl is approximately 1.5 to 2 times the user public key information (IDi, el, ni).

[インプリント型の署名] 本方式では、コリージョン・フリーな一方向性関数fを
用いてlDi ,ei,nlを連結したメッセージ(l
Di .ei,nl)をハッシング(圧縮)する。ノ)
ツシュ結果に対してディジタル署名したものをユザiの
公開証明書Certiとし、この証明書Gertiと公
開鍵情報( 10 i ,el,n[)とをユーザのi
の公開鍵を必要とするユーザに対して送信する。
[Imprint-type signature] In this method, a collision-free one-way function f is used to create a message (l
Di. ei, nl) is hashed (compressed). of)
The digitally signed certificate for the tush result is set as user i's public certificate Certi, and this certificate Gerti and the public key information (10 i , el, n[) are set as user i's public certificate Certi.
Send the public key to users who need it.

dO CertI −『(lD1.ei.nl )   ff
lod no   =・(5)証明書Certi及び公
開鍵情報( 101,el.n1)を受信したユーザは
、この公開鍵情報をハツシングした結果f(IDi,e
l,nl )と証明書Certlを次式(6〉ニより復
号した結果が一致することを確認し、ユーザiの公開鍵
ei,nlを得る。
dO CertI - '(lD1.ei.nl) ff
lod no =・(5) The user who received the certificate Certi and the public key information (101, el.n1) hashed this public key information and hashed the result f(IDi, e
l,nl) and the certificate Certl using the following equation (6>d), and confirm that they match, and obtain the public key ei,nl of user i.

r(101,el,ni ) −Certi   a+
od no   −(6)この方法では証明書cert
Iのサイズはセンタ2の公開鍵noのサイズに一致し、
通常ユーザの公開鍵情報(IDi .el,n1)のサ
イズの方がセンタ3の公開鍵のサイズよりも大きいので
、証明書certt自身のサイズはユーザiの公開鍵情
報(lDi,ei,nl)のサイズより小さくなる。し
かし、証明書の検査に当たっては、証明書以外に公開鍵
情報(I[)i ,el,nl)が必要になるので実質
的には証明書のサイズは1.5倍程度になる。インプリ
ント型署名を利用する場合に管理センタ2が所有する公
開鍵リスI−5Aの概念図を第8図に示す。図示のよう
に、このリストラAには、ID情報、公開鍵データ、公
開鍵証明書の3つが記録されている。
r(101,el,ni) -Certi a+
od no - (6) In this method the certificate cert
The size of I matches the size of public key no of center 2,
Normally, the size of user's public key information (IDi.el, n1) is larger than the size of center 3's public key, so the size of the certificate certt itself is user i's public key information (lDi, ei, nl). will be smaller than the size of. However, when inspecting a certificate, public key information (I[)i, el, nl) is required in addition to the certificate, so the size of the certificate is actually about 1.5 times larger. FIG. 8 shows a conceptual diagram of the public key list I-5A owned by the management center 2 when an imprint type signature is used. As shown in the figure, three items are recorded in this restructuring A: ID information, public key data, and public key certificate.

以上説明してきたようにKohnfelderの方法に
より第三者のなりすましは防止できるが、公開鍵証明書
のサイズはもとのユーザ公開鍵のサイズに比べて1.5
〜2倍程度に大きくなる。したがって、この証明書をリ
ストとして管理する場合にはリストのサイズが増加し、
また通信のたびに相手から送ってもらうことにすると通
信量が増加するという問題点がある。さらに、相手公開
鍵が必要となるたびに証明書を検査しなければならない
のでユーザ側の処理量が増加することも問題点に挙げら
れる。
As explained above, Kohnfelder's method can prevent impersonation by a third party, but the size of the public key certificate is 1.5 times larger than the size of the original user public key.
It becomes about twice as large. Therefore, if you manage this certificate as a list, the size of the list will increase and
There is also the problem that the amount of communication increases if the other party sends a message each time the communication is made. Another problem is that the amount of processing on the user side increases because the certificate must be verified every time the other party's public key is needed.

(発明か解決しようとする課題) 以上述べてきたように、従来よりの各種の公開鍵の管理
方式では、公開鍵リストの更新が容易にはできなかった
り、公開鍵管理センタに負荷が集中したり、相手端末が
スタンバイ状、態でないと公開鍵が得られなかったり、
公開鍵証明書による公開鍵リストのサイズが増大し、相
手公開鍵が必要となるたびに公開鍵証明書の検査が必要
となるなど、公開鍵の管理が大変で、システム効率が悪
いという問題点があった。
(Problem to be solved by the invention) As mentioned above, with the various conventional public key management methods, it is not easy to update the public key list, and the load is concentrated on the public key management center. or the public key cannot be obtained unless the other party's terminal is in standby mode,
The problem is that the size of the public key list due to public key certificates increases, and the public key certificate must be inspected every time the other party's public key is needed, making public key management difficult and system efficiency low. was there.

そこで、本発明は、公開鍵の管理が容易で、システム効
率を向上させることができる携帯用暗号鍵記憶装置を提
供することを目的とする。
SUMMARY OF THE INVENTION Therefore, an object of the present invention is to provide a portable cryptographic key storage device that can easily manage public keys and improve system efficiency.

[発明の構成コ (課題を解決するための手段) 上記課題を解決する本発明の携帯用暗号鍵記憶装置は、
公開鍵暗号を取扱う情報通信システムのユーザ端末に接
続されて使用される携帯用暗号鍵記憶装置7において、
ユーザの正当性を確認するユーザ確認手段8と、他の装
置と通信を行うための通信手段9と、自己の装置7に固
有の秘密鍵を記憶すると共に頻繁に通信することとなる
相手装置の公開鍵を複数記憶可能の公開鍵記憶領域10
Aを有する記憶手段10と、該記憶手段10に記憶され
た通信相手の公開鍵を用いて適宜暗号化処理を行うと共
に通信相手の公開鍵及びその正当性証明情報が前記通信
手段9を介して入力されf.7とき前記正当性証明情報
の正当性を検査する演算手段11と、制御手順は変更不
能に構成され前記演算手段11で前記正当性証明書の正
当性が判断されたとき当該通信相手の公開鍵を前記記憶
手段]0の公開鍵記憶領域10Aに書き込み可能とする
制御手段12を備えて或ることを特徴とする。
[Configuration of the Invention (Means for Solving the Problems) The portable encryption key storage device of the present invention that solves the above problems includes:
In a portable cryptographic key storage device 7 used by being connected to a user terminal of an information communication system that handles public key cryptography,
A user confirmation means 8 for confirming the validity of the user, a communication means 9 for communicating with other devices, and a device 7 for storing a private key unique to the own device 7 and communicating frequently with the other device. Public key storage area 10 that can store multiple public keys
A and the communication partner's public key stored in the storage means 10 are used to perform appropriate encryption processing, and the communication partner's public key and its validity proof information are transmitted via the communication means 9. input f. When the validity of the validity certificate is determined by the calculation means 11, the control procedure is configured to be unchangeable, and when the validity of the validity certificate is determined by the calculation means 11, the public key of the communication partner is The present invention is characterized in that it includes a control means 12 that enables writing of the public key storage area 10A of the storage means]0.

(作用) 本発明の携帯用暗号鍵記憶装置では、自己の装置の秘密
鍵を記憶すると共に頻繁に通信することとなる相手装置
の公開鍵を複数i+:!憶可能の比較的小さな容量の公
開鍵記憶領域10Aを有する記憶手段10を備えている
。したがって、この記憶手段10の公開鍵記憶領域10
Aに頻繁に通信する相手装置に限ってその公開鍵を記憶
をしておけば、多くの場合に自己が有する公開鍵のみで
他のユーザと暗号通信できる。
(Function) The portable cryptographic key storage device of the present invention stores the private key of its own device and also stores the public keys of the other device with which it communicates frequently. A storage means 10 having a relatively small capacity public key storage area 10A is provided. Therefore, the public key storage area 10 of this storage means 10
If the public key is stored only in the partner device that frequently communicates with A, in many cases it is possible to perform encrypted communication with other users using only the public key that A has.

また、本発明では、他のユーザないし管理センタから送
信されてきた公開鍵及びその正当性証明情報を人力し、
その正当性を判断した上でその公開鍵を前記記憶手段1
0の公開鍵記憶領域10Aに書込み可能とする演算手段
11及び制御手段12を備えており、制御手段12の制
御手順はその内容を変更不可能に構戊されている。した
がって、自装置7内に記憶されていない相手公開鍵が今
後頻繁に必要となると考えられるときのみ前記記憶手段
10の公開鍵記憶領域10Aに記憶可能の範囲で他のユ
ーザの公開鍵を記録してゆくことができる。また、この
とき、本発明ではその書込み手順は限定されないので、
公開鍵記憶領域10Aの記憶容量が満杯となったとき複
数記憶された公開鍵のうち使用頻度の一番低いものを次
の新たな公開鍵で更新するなど各種の応用ができるもの
である。
In addition, in the present invention, the public key and its validity proof information sent from other users or the management center are manually collected,
After determining its validity, the public key is stored in the storage means 1.
It is equipped with arithmetic means 11 and a control means 12 that are capable of writing into the public key storage area 10A of 0, and the control procedure of the control means 12 is configured such that its contents cannot be changed. Therefore, only when it is thought that the other user's public key that is not stored in the own device 7 will be needed frequently in the future, the other user's public key is recorded to the extent that it can be stored in the public key storage area 10A of the storage means 10. You can go there. Moreover, at this time, the writing procedure is not limited in the present invention, so
When the storage capacity of the public key storage area 10A becomes full, various applications can be made, such as updating the least frequently used public key among the plurality of stored public keys with the next new public key.

(実施例) 以下、本発明の実施例を説明する。(Example) Examples of the present invention will be described below.

第1図は本発明の一実施例に係る携帯用暗号鍵記憶装置
のブロック図、第2図は公開鍵記憶領域の記憶内容を示
す説明図、第3図は応用システムの構或例を示す説明図
である。
Fig. 1 is a block diagram of a portable encryption key storage device according to an embodiment of the present invention, Fig. 2 is an explanatory diagram showing the storage contents of a public key storage area, and Fig. 3 shows an example of the structure of an application system. It is an explanatory diagram.

第1図において、本例の暗号鍵記憶装置7は、ICカー
ドを用いて携帯用に構成され、ユーザの正当性を確認す
るユーザ確認手段8と、他の装置と通信を行うための通
信手段9と、自己の装置7に固有の秘密鍵を記憶すると
共に頻繁に通信する相手装置の公開鍵を複数記憶可能の
公開鍵記憶領域1−OAを有する記憶手段1oと、記憶
手段1oに記憶された通信相手の公開鍵を用いて通信相
手の公開鍵及びその正当性証明情報が前記通信手段9を
介して人力されたとき前記正当性証明情報の正当性を検
査する演算手段11と、制御手順は変更不能に構戊され
前記演算手段1〕で前記正当性証明書の正当性が判別さ
れたとき当該通信相手の公開鍵を前記記憶手段10の公
開鍵記憶領域10Aに書き込み可能とする制御手段12
を備えて成る。
In FIG. 1, the encryption key storage device 7 of this example is configured to be portable using an IC card, and includes user confirmation means 8 for confirming user authenticity, and communication means for communicating with other devices. 9, a storage means 1o having a public key storage area 1-OA capable of storing a private key unique to the own device 7 and a plurality of public keys of the other device with which communication is frequently performed; a calculation means 11 for checking the validity of the validity proof information when the public key of the communication party and its validity proof information are input manually via the communication means 9 using the public key of the communication party; and a control procedure; is configured to be unchangeable, and when the validity certificate is determined by the calculation means 1, the public key of the communication partner can be written into the public key storage area 10A of the storage means 10. 12
It consists of:

上記において、ユーザ確認手段8は、/くスワド照合や
指紋照合などにより、ユーザの正当性を確認するもので
ある。
In the above, the user verification means 8 verifies the authenticity of the user by swath verification, fingerprint verification, or the like.

通信手段9は、ICカード・リーダ・ライタを介して外
部計算機と通信するものである。
The communication means 9 is for communicating with an external computer via an IC card reader/writer.

記憶手段10は不揮発性メモリとしてのE2PROMで
構成され、ここに公開鍵記憶領域1. O Aを記憶さ
せる。たたし、前記制御手段12の制御プログラムは読
み出し専用で書換不能のROMに5己憶させるものとす
る。
The storage means 10 is composed of an E2PROM as a non-volatile memory, and has a public key storage area 1. OA is memorized. However, the control program for the control means 12 is stored in a read-only, non-rewritable ROM.

第2図に示すように、公開鍵記憶領域10Aには、限ら
れた記憶容量内で頻繁に使用する公開鍵がIDと共{こ
l己憶されるようになっている。
As shown in FIG. 2, in the public key storage area 10A, frequently used public keys are stored together with IDs within a limited storage capacity.

演算手段11は、RSA暗号処理に必要な多倍長計算を
実行でき、デイジタル署名や相手公開鍵を用いた暗号化
などの処理を実行する。
The calculation means 11 can perform multiple precision calculations required for RSA cryptographic processing, and performs processing such as digital signatures and encryption using the other party's public key.

次に、第3図に示すシステムは第6図に示したシステム
に対応するもので、ネットワーク1に管理センタ13及
び多数の端末3が接続されている。
Next, the system shown in FIG. 3 corresponds to the system shown in FIG. 6, in which a management center 13 and a large number of terminals 3 are connected to a network 1.

各端末3には前記の暗号鍵記憶装置7が接続可能とされ
、管理センタ13にはシステムの全加入者の公開鍵情報
及び公開鍵証明書を登録した公開鍵リスト14が接続さ
れている。
The aforementioned encryption key storage device 7 can be connected to each terminal 3, and a public key list 14 in which public key information and public key certificates of all subscribers of the system are registered is connected to the management center 13.

管理センタ13は、各ユーザの秘密鍵、及び該ユーザが
頻繁に使用するとして指定したユーザについての公開鍵
を暗号鍵記憶装置7に書き込んで発行する作業と、各ユ
ーザの公開鍵に対して公開鍵証明書を作成して公開鍵リ
スト14に登録し公開鍵リスト14を管理する作業と、
ユーザからの公開鍵送信要求を受け、対応する公開鍵情
報および公開鍵証明書を送信する作業を遂行するもつで
ある。
The management center 13 performs the tasks of writing and issuing each user's private key and the public key of a user designated as frequently used by the user into the encryption key storage device 7, and publishing the public key of each user. Creating a key certificate, registering it in the public key list 14, and managing the public key list 14;
It is responsible for receiving a public key transmission request from a user and transmitting the corresponding public key information and public key certificate.

相手公開鍵の登録方式を第4図にフローチャートで示し
た。本処理は通信すべき相手の公開鍵が公開鍵記憶領域
10Aに記憶されていない場合の要求に基いて開始され
る。
The method for registering the other party's public key is shown in a flowchart in FIG. This process is started based on a request when the public key of the other party to communicate with is not stored in the public key storage area 10A.

まず、ステップ401で相手公開鍵の送信要求を出力し
、ステップ402で管理センタ13から公開鍵と証明書
を受信し、ステップ403で従来技術で示したと同様の
検査方式にてその検査を行う。
First, in step 401, a request for transmission of the other party's public key is output, in step 402, the public key and certificate are received from the management center 13, and in step 403, they are inspected using the same inspection method as shown in the prior art.

ステップ404て険査結果を判別し、証明書のiE当性
が判別されたらステップ405で公開鍵記憶頭域に空き
が有るか否かを判別し、空きか有ればステップ406で
登録する。
The inspection result is determined in step 404, and if the iE validity of the certificate is determined, it is determined in step 405 whether or not there is space in the public key storage area, and if there is space, it is registered in step 406.

一方、ステップ404で証明書の正当性か認められなか
った場合には、ステップ407へ移行してその公開鍵は
登録しない。
On the other hand, if the validity of the certificate is not recognized in step 404, the process moves to step 407 and the public key is not registered.

また、ステップ404  405で証明書の正当性は認
められるものの公開鍵記憶領域10Aに空き領域が無い
と判断される場合には、ステップ408で公開鍵登録命
令が人力されているか否かを↑11別する。
In addition, if it is determined in steps 404 to 405 that the certificate is valid but there is no free space in the public key storage area 10A, in step 408 it is determined whether or not the public key registration command has been manually entered. Separate.

この公開鍵登録命令は、ユーザ指定によるもので、例え
ば今後頻繁に使用することが予定されるユーザに対し、
登録すべきであることを指定するものである。
This public key registration command is specified by the user.For example, for a user who is expected to use the public key frequently in the future,
This specifies that the information should be registered.

そこで、ステップ408で登録命令が人力されている場
合には、ステップ401へ移行してその公開鍵を登録す
る。ただし、このとき、公開鍵登録領域10Aには空き
が無いので、使用頻度の低い、または長期に亘って不使
用の公開鍵を一つだけ抹消する。
Therefore, if the registration command is manually issued in step 408, the process moves to step 401 and the public key is registered. However, at this time, since there is no free space in the public key registration area 10A, only one public key that is used infrequently or that has not been used for a long time is deleted.

ステップ408で特に登録命令が入力されていない場合
は、本公開鍵は今回限り使用するものとして、公開鍵記
憶領域10Aには登録しない。
If no particular registration command is input in step 408, the public key is assumed to be used only this time and is not registered in the public key storage area 10A.

第4図に示す手順は、例えばプログラムとして設定し専
用のROMに書いているので列えばコンピュータ・ウィ
ルスなどによっても侵されることがない。
The procedure shown in FIG. 4 is set as a program and written in a dedicated ROM, so that it will not be attacked by computer viruses.

よって、暗号鍵記憶装置7内に書き込まれた公開鍵は、
再び同しユーザIDに対する公開鍵情報と公開鍵証明書
が受信され、その公開鍵証明書の検査結果が正常である
場合以外は書き替えが不可能となるように制御される。
Therefore, the public key written in the encryption key storage device 7 is
The public key information and public key certificate for the same user ID are received again, and the control is performed so that rewriting is not possible unless the inspection result of the public key certificate is normal.

公開鍵の変更時には、例えば、新しい公開鍵データに対
応する公開鍵証明書を管理センタ13に発行してもらい
、その公開鍵データと公開鍵証明書を頻繁に通信する相
手ユーザに送信し、制御手段12に更新指令を与えるよ
うにすればよい。
When changing the public key, for example, the management center 13 issues a public key certificate corresponding to the new public key data, and sends the public key data and public key certificate to the user with whom the user frequently communicates, and controls the data. An update command may be given to the means 12.

暗号鍵記憶領域10A内に記録された相手ユーザの公開
鍵を使った暗号化およびデイジタル署名の検査は自装置
7内の演算手段11を利用して行う。暗号鍵記憶装置7
内で行う暗号処理を高速化するために、例えば演算手段
11として暗号鍵記憶装置7内に暗号処理ノ\−ドウエ
アを組み込む方法が挙げられるが、秘密鍵等の秘密情報
を外部端末に示すことなく暗号化処理の処理時間を短縮
する方法としての“依頼計算”を用い、外部端末の計算
能力を借りることもできる。暗号処理としてRSA暗号
を利用する場合に用いることができる依頼計算の手順は
例えば次の3つの文献に示されている。
Encryption using the other user's public key recorded in the encryption key storage area 10A and checking of the digital signature are performed using the calculation means 11 within the own device 7. Encryption key storage device 7
In order to speed up the cryptographic processing carried out internally, for example, there is a method of incorporating cryptographic processing hardware into the cryptographic key storage device 7 as the calculation means 11, but it is also possible to show secret information such as a private key to an external terminal. It is also possible to borrow the computing power of external terminals by using "request calculation" as a method to shorten the processing time of encryption processing. Request calculation procedures that can be used when using RSA encryption as cryptographic processing are shown in the following three documents, for example.

[文献1コ 加藤光幾,松本勉,今井秀樹,“安全な計算依頼法につ
いて”, 1988年暗号と情報セキュリティシンポジ
ウム資料。
[Reference 1 Mitsunori Kato, Tsutomu Matsumoto, Hideki Imai, “On a secure calculation request method”, 1988 Cryptography and Information Security Symposium Materials.

[文献2] 松本勉,今井秀樹“秘密を漏らさずにサービスを依頼す
る方法について”, l!389年暗号と情報セキュリ
ティシンポジウム資料。
[Reference 2] Tsutomu Matsumoto, Hideki Imai “How to request services without revealing secrets”, l! 389 Cryptography and Information Security Symposium Materials.

[文献3] 川村信一,新保淳.“依頼計算によるRSA暗号の秘密
変換”, 1989年暗号と情報セキュリティシンポジ
ウム資料。
[Reference 3] Shinichi Kawamura, Jun Shinbo. “Secret conversion of RSA encryption by request calculation”, 1989 Cryptography and Information Security Symposium Materials.

以上により、本例の携帯用暗号鍵記憶装置7によれば、
ICカードの特性を十分活用できることは勿論のこと、
頻繁に通信する複数のユーザの公開鍵のみをリストとし
て持つ構戊となっているので、ユーザのリストサイズを
大幅に削減することができる。
As described above, according to the portable encryption key storage device 7 of this example,
Of course, it is possible to fully utilize the characteristics of IC cards,
Since the list contains only the public keys of multiple users who frequently communicate with each other, the size of the user list can be significantly reduced.

また、暗号鍵記憶装置7の中に幾つか相手ユーザの公開
鍵が記憶されているので、暗号鍵記憶装置7に必要な公
開鍵が登録されていない場合にのみセンタ・リストもし
くは相手端末にアクセスすればよく、通信回線の利用効
率が大幅に向上する。
In addition, since several public keys of other users are stored in the encryption key storage device 7, access to the center list or the other party terminal is only made when the necessary public key is not registered in the encryption key storage device 7. This will greatly improve the efficiency of communication line usage.

また、例えばフロッピーディスク等のアクセス制御能力
のない媒体では、ディスク内の情報を容易に書き替える
ことができるため、公開鍵証明書を一緒に書き込んてお
かなけれけばならないのに対し、本例の如<ICカード
等のアクセス制御能力のある媒体に記録する場合には情
報の書き替えは困難である。したがって、公開鍵証明書
は最初の公開鍵情報の書き込み時の検査に利用すればそ
の後の処理には不必要になる。よって、公開鍵証明書を
記録する必要はなく、公開鍵証明書のデータ量だけ記憶
領域は削減できる。
Also, for media without access control capabilities, such as floppy disks, the information on the disk can be easily rewritten, so the public key certificate must be written along with it. When recording on a medium with access control capability, such as an IC card, it is difficult to rewrite the information. Therefore, if the public key certificate is used for checking when writing public key information for the first time, it becomes unnecessary for subsequent processing. Therefore, there is no need to record the public key certificate, and the storage area can be reduced by the amount of data of the public key certificate.

本発明は、上記実施例に限定されるものではなくその要
旨を逸脱しない範囲で適宜変形して実施できる。
The present invention is not limited to the above-mentioned embodiments, and can be implemented with appropriate modifications without departing from the gist thereof.

[発明の効果] 以上の通り、本発明は、秘密鍵の記憶に加えて各ユーザ
において頻繁に使用することとなる相手ユーザの公開鍵
のみを小規模リストで個別に保持されるようにした携帯
用暗号鍵記憶装置であるので、従来のいずれの情報通信
システムに対しても公開鍵の管理が容易で、システム効
率を向上させることができる。
[Effects of the Invention] As described above, the present invention provides a mobile phone in which, in addition to storing private keys, only public keys of other users that are frequently used by each user are individually held in a small list. Since it is a cryptographic key storage device for use in any conventional information communication system, public keys can be easily managed and system efficiency can be improved.

【図面の簡単な説明】[Brief explanation of the drawing]

第1図は本発明による携帯用暗号鍵記憶装置のー実施例
を示すブロック図、第2図は上記暗号鍵記憶装置が有す
る公開鍵記憶領域の記憶内容を示す説明図、第3図は上
記暗号鍵記憶装置を利用した情報通信ネットワークの構
成例を示す説明図、第4図は上記暗号鍵記憶装置に相手
公開鍵を登録する手順を示すフローチャート、第5図は
公開鍵暗号を利用した従来の情報通信ネットワークの一
構成図、第6図は公開鍵暗号を利用した従来の情報通信
ネットワークの別な一構成図、第7図は公開鍵暗号を利
用した従来の情報通信ネットワークのさらに別な一構成
図、第8図は従来の公開鍵リストの概念図である。 7・・・携帯用暗号鍵記憶装置(ICカード)8・・・
ユーザ確認手段 9・・・通信手段 0・・記憶手段 OA・・・公開鍵記憶領域 1・・・演算手段 2・・・制御手段
FIG. 1 is a block diagram showing an embodiment of the portable encryption key storage device according to the present invention, FIG. 2 is an explanatory diagram showing the storage contents of the public key storage area of the encryption key storage device, and FIG. 3 is the above An explanatory diagram showing an example of the configuration of an information communication network using an encryption key storage device, FIG. 4 is a flowchart showing the procedure for registering the other party's public key in the encryption key storage device, and FIG. 5 is a conventional method using public key cryptography. Figure 6 is a diagram showing another configuration of a conventional information communications network using public key cryptography, and Figure 7 is a diagram showing yet another configuration of a conventional information communications network using public key cryptography. One configuration diagram, FIG. 8, is a conceptual diagram of a conventional public key list. 7... Portable encryption key storage device (IC card) 8...
User confirmation means 9... Communication means 0... Storage means OA... Public key storage area 1... Calculation means 2... Control means

Claims (1)

【特許請求の範囲】[Claims] 公開鍵暗号を取扱う情報通信システムのユーザ端末に接
続されて使用される携帯用暗号鍵記憶装置において、ユ
ーザの正当性を確認するユーザ確認手段と、他の装置と
通信を行うための通信手段と、自己の装置に固有の秘密
鍵を記憶すると共に頻繁に通信することとなる相手装置
の公開鍵を複数記憶可能の公開鍵記憶領域を有する記憶
手段と、該記憶手段に記憶された通信相手の公開鍵を用
いて適宜暗号化処理を行うと共に通信相手の公開鍵及び
その正当性証明情報が前記通信手段を介して入力された
とき前記正当性証明情報の正当性を検査する演算手段と
、制御手順は変更不能に構成され前記演算手段で前記正
当性証明書の正当性が判断されたとき当該通信相手の公
開鍵を前記記憶手段の公開鍵記憶領域に書き込み可能と
する制御手段を備えたことを特徴とする携帯用暗号鍵記
憶装置。
In a portable cryptographic key storage device used by being connected to a user terminal of an information communication system that handles public key cryptography, a user confirmation means for confirming user authenticity, a communication means for communicating with other devices, and , a storage means having a public key storage area capable of storing a private key unique to the own device and a plurality of public keys of the other device with which communication is frequently performed; a calculation means that performs an appropriate encryption process using a public key and checks the validity of the validity proof information when the communication partner's public key and its validity proof information are input via the communication means; and a control unit. The procedure is configured to be unchangeable, and the control means is configured to enable writing of the public key of the communicating party into the public key storage area of the storage means when the validity of the validity certificate is determined by the calculation means. A portable encryption key storage device characterized by:
JP1300680A 1989-11-21 1989-11-21 Portable encryption key storage device Expired - Fee Related JP2874916B2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP1300680A JP2874916B2 (en) 1989-11-21 1989-11-21 Portable encryption key storage device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP1300680A JP2874916B2 (en) 1989-11-21 1989-11-21 Portable encryption key storage device

Publications (2)

Publication Number Publication Date
JPH03162152A true JPH03162152A (en) 1991-07-12
JP2874916B2 JP2874916B2 (en) 1999-03-24

Family

ID=17887784

Family Applications (1)

Application Number Title Priority Date Filing Date
JP1300680A Expired - Fee Related JP2874916B2 (en) 1989-11-21 1989-11-21 Portable encryption key storage device

Country Status (1)

Country Link
JP (1) JP2874916B2 (en)

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH09219701A (en) * 1995-12-13 1997-08-19 Ncr Internatl Inc Method and device for retrieving identity recognizing identification
JP2002091300A (en) * 2000-09-13 2002-03-27 Nippon Telegr & Teleph Corp <Ntt> Communication partner authentication method and authentication communication terminal device using the method
JP2004320562A (en) * 2003-04-17 2004-11-11 Toshiba Corp Anonymous authentication system, device and program
JP2005502217A (en) * 2000-12-15 2005-01-20 オラクル・インターナショナル・コーポレイション Method and apparatus for delegating a digital signature to a signature server
JP2005123996A (en) * 2003-10-17 2005-05-12 National Institute Of Information & Communication Technology Information processing method and information processing system for delegating authentication information between devices
JP2005130449A (en) * 2003-07-25 2005-05-19 Ricoh Co Ltd COMMUNICATION DEVICE, COMMUNICATION SYSTEM, ABNORMALITY DETECTION METHOD, AND PROGRAM
JP2005130451A (en) * 2003-07-25 2005-05-19 Ricoh Co Ltd Communication apparatus, communication system, certificate transmission method and program
JP2006246543A (en) * 1994-01-13 2006-09-14 Certco Inc Cryptographic system and method with key escrow function
JP2006325246A (en) * 1994-09-30 2006-11-30 Intarsia Software Llc Digital cache management system
JP2007065362A (en) * 2005-08-31 2007-03-15 Ktk Kk Information communication device and information communication method
JP2010063130A (en) * 1994-09-30 2010-03-18 Intarsia Software Llc Digital cash management system
US9245260B2 (en) 1994-10-27 2016-01-26 Xylon Llc Data copyright management
JP2018528691A (en) * 2015-08-25 2018-09-27 アリババ・グループ・ホールディング・リミテッドAlibaba Group Holding Limited Method and apparatus for multi-user cluster identity authentication
JP2025021046A (en) * 2023-07-31 2025-02-13 大日本印刷株式会社 ELECTRONIC INFORMATION STORAGE MEDIUM, IC CHIP, IC CARD, PUBLIC KEY MANAGEMENT METHOD, AND PROGRAM
CN120162833A (en) * 2025-02-27 2025-06-17 北京市大数据中心 Method, device, system, storage medium and electronic device for electronic signature application

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006246543A (en) * 1994-01-13 2006-09-14 Certco Inc Cryptographic system and method with key escrow function
JP2006325246A (en) * 1994-09-30 2006-11-30 Intarsia Software Llc Digital cache management system
JP2010063130A (en) * 1994-09-30 2010-03-18 Intarsia Software Llc Digital cash management system
US9245260B2 (en) 1994-10-27 2016-01-26 Xylon Llc Data copyright management
JPH09219701A (en) * 1995-12-13 1997-08-19 Ncr Internatl Inc Method and device for retrieving identity recognizing identification
JP2002091300A (en) * 2000-09-13 2002-03-27 Nippon Telegr & Teleph Corp <Ntt> Communication partner authentication method and authentication communication terminal device using the method
JP2005502217A (en) * 2000-12-15 2005-01-20 オラクル・インターナショナル・コーポレイション Method and apparatus for delegating a digital signature to a signature server
JP2004320562A (en) * 2003-04-17 2004-11-11 Toshiba Corp Anonymous authentication system, device and program
JP2005130451A (en) * 2003-07-25 2005-05-19 Ricoh Co Ltd Communication apparatus, communication system, certificate transmission method and program
JP2005130449A (en) * 2003-07-25 2005-05-19 Ricoh Co Ltd COMMUNICATION DEVICE, COMMUNICATION SYSTEM, ABNORMALITY DETECTION METHOD, AND PROGRAM
JP2005123996A (en) * 2003-10-17 2005-05-12 National Institute Of Information & Communication Technology Information processing method and information processing system for delegating authentication information between devices
JP2007065362A (en) * 2005-08-31 2007-03-15 Ktk Kk Information communication device and information communication method
JP2018528691A (en) * 2015-08-25 2018-09-27 アリババ・グループ・ホールディング・リミテッドAlibaba Group Holding Limited Method and apparatus for multi-user cluster identity authentication
JP2025021046A (en) * 2023-07-31 2025-02-13 大日本印刷株式会社 ELECTRONIC INFORMATION STORAGE MEDIUM, IC CHIP, IC CARD, PUBLIC KEY MANAGEMENT METHOD, AND PROGRAM
CN120162833A (en) * 2025-02-27 2025-06-17 北京市大数据中心 Method, device, system, storage medium and electronic device for electronic signature application

Also Published As

Publication number Publication date
JP2874916B2 (en) 1999-03-24

Similar Documents

Publication Publication Date Title
KR102205654B1 (en) Authentication method in a distributed circumstance
US8639940B2 (en) Methods and systems for assigning roles on a token
US20230093581A1 (en) Method for directly transferring electronic coin data sets between terminals, payment system, currency system and monitoring unit
JP4638990B2 (en) Secure distribution and protection of cryptographic key information
CN1736055B (en) System, device and method for replacing keys
US7499551B1 (en) Public key infrastructure utilizing master key encryption
JP4501197B2 (en) Information portable processing system, information portable device access device and information portable device
TW449991B (en) Method and system for securely handling information between two information processing devices
EP1388989B1 (en) Digital contents issuing system and digital contents issuing method
JP7309261B2 (en) Authentication method for biometric payment device, authentication device for biometric payment device, computer device, and computer program
US20230259899A1 (en) Method, participant unit, transaction register and payment system for managing transaction data sets
US20060085848A1 (en) Method and apparatus for securing communications between a smartcard and a terminal
EP1801721A1 (en) Computer implemented method for securely acquiring a binding key for a token device and a secured memory device and system for securely binding a token device and a secured memory device
EP0266044A2 (en) Telecommunication security system and key memory module therefor
JP2009510644A (en) Method and configuration for secure authentication
US20030228886A1 (en) Electronic value data communication method, communication system, IC card, portable terminal, and communication
CN102103651B (en) Method and system for realizing all-purpose card system and smart card
JP2874916B2 (en) Portable encryption key storage device
CN113168475B (en) Securing external data storage of secure elements integrated on a system-on-chip
US20020044655A1 (en) Information appliance and use of same in distributed productivity environments
US12380442B2 (en) Address generation method, blockchain information processing method, and related device
CN103514540B (en) A kind of excellent shield service implementation method and system
GB2270446A (en) Establishing a common cryptographic key at two cryptographic sites
JP2008259069A (en) Key management system and key management method
KR20200134187A (en) Authentication method in a distributed circumstance

Legal Events

Date Code Title Description
FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20080114

Year of fee payment: 9

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20090114

Year of fee payment: 10

LAPS Cancellation because of no payment of annual fees