JPH10200520A - Key management method and system - Google Patents

Key management method and system

Info

Publication number
JPH10200520A
JPH10200520A JP9003644A JP364497A JPH10200520A JP H10200520 A JPH10200520 A JP H10200520A JP 9003644 A JP9003644 A JP 9003644A JP 364497 A JP364497 A JP 364497A JP H10200520 A JPH10200520 A JP H10200520A
Authority
JP
Japan
Prior art keywords
key
session
user
information
secret
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
JP9003644A
Other languages
Japanese (ja)
Inventor
Masasuki Kanda
雅透 神田
Yoichi Takashima
洋一 高嶋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NTT Inc
Original Assignee
Nippon Telegraph and Telephone Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nippon Telegraph and Telephone Corp filed Critical Nippon Telegraph and Telephone Corp
Priority to JP9003644A priority Critical patent/JPH10200520A/en
Publication of JPH10200520A publication Critical patent/JPH10200520A/en
Pending legal-status Critical Current

Links

Abstract

(57)【要約】 【課題】 執行機関5が暗号文解読を実施する場合、そ
の定めの範囲内に限定する。 【解決手段】 鍵管理機関装置3,4に、システム秘密
鍵Ss1,Ss2、ユーザ秘密情報Si1,Si2を登録し、暗
号通信時に、発信ユーザ1はマスター鍵Kabと日時情報
Dにより、Kd=gKabD(modn)を作り、メッセージ暗
号化用の鍵Ks をKd で暗号化してデータLEAFを作
り、受信側ユーザ2はユーザ1と同様の手法でKd を作
り、このKd でLEAFを復号してKs を得る。機関5
が解読する際には、機関3,4はKab、Dと乱数R1
2 を用いて鍵K1 ,K2 を作って機関5へ提供し、機
関5はK1 ,K2 から鍵K* =K1 ・K2 を生成して、
機関3,4へ送り、機関3,4でK* からそれぞれ
1 ,R2 を消去する準備をしてK1 ′,K2 ′を機関
5へ送り機関5はK1 ′,K2 ′からKd を作り、Kd
でLEAFを復号してKs を得る。
(57) [Summary] [Problem] When the enforcement agency 5 performs ciphertext decryption, it is limited to within the prescribed range. SOLUTION: System secret keys Ss 1 and Ss 2 and user secret information Si 1 and Si 2 are registered in key management institution devices 3 and 4, and at the time of encrypted communication, a transmitting user 1 uses a master key Kab and date and time information D at the time of encrypted communication. , Kd = g KabD (modn), encrypts the message encryption key Ks with Kd to create data LEAF, and the receiving user 2 creates Kd in the same manner as user 1, and uses this Kd to create LEAF. Decrypt to obtain Ks. Institution 5
When decrypting, the institutions 3 and 4 receive Kab, D and random numbers R 1 ,
Create a key K 1, K 2 by using the R 2 provides to the engine 5, engine 5 is to generate a key K * = K 1 · K 2 from K 1, K 2,
The engines 3 and 4 are sent, and the engines 3 and 4 prepare to delete R 1 and R 2 from K * , respectively, and send K 1 ′ and K 2 ′ to the engine 5, and the engine 5 sends K 1 ′ and K 2 ′. Make Kd from
Decrypts the LEAF to obtain Ks.

Description

【発明の詳細な説明】DETAILED DESCRIPTION OF THE INVENTION

【0001】[0001]

【発明の属する技術分野】この発明は、暗号通信システ
ムにおいて、法律または契約等に基づき通信中またはデ
ータベース等に蓄積された暗号文を解読する権限、もし
くは暗号文を復号するためのセッション鍵を複製する権
限を有する執行機関が、その定めの範囲内に限り確実に
暗号文を解読し、またはセッション鍵を複製できるよう
にすると同時に、その定めを逸脱して執行機関が不当に
暗号文を解読し、またはセッション鍵を複製することに
よってユーザ(利用者)のプライバシーが侵害されるこ
とがないようにするための鍵管理方法及びシステムに関
する。
BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to a cryptographic communication system, which is capable of decrypting a cipher text stored in a database or the like during communication or a session key for decrypting a cipher text, based on a law or a contract. Enforcement authority authorized to decrypt ciphertexts or duplicate session keys only to the extent of its provisions, and at the same time deviate from such provisions Or a key management method and system for preventing the privacy of a user (user) from being violated by duplicating a session key.

【0002】[0002]

【従来の技術】近年、暗号化技術は情報化社会を担う基
盤技術として広く研究され、極めて強力な暗号化技術が
開発されてきている。一方で、強力な暗号化技術が開発
されるにつれ、従来から不正行為とされてきた通信の盗
聴や改ざんは防止できるようになったものの、今度は暗
号化技術自体が反社会的行為に利用される懸念が広まっ
ている。しかし、現在の暗号化技術では、いかなるもの
も通信の盗聴が出来ないことを目的としているため、仮
に反社会的行為に利用されていたとしてもそれを認知し
たり、あるいは摘発したりすることは出来ない。
2. Description of the Related Art In recent years, encryption technology has been widely studied as a fundamental technology for the information society, and extremely strong encryption technology has been developed. On the other hand, as strong encryption technology has been developed, it has become possible to prevent eavesdropping and falsification of communications that have been conventionally regarded as fraudulent, but this time encryption technology itself is used for antisocial acts. Concerns are spreading. However, since the current encryption technology aims to prevent anyone from eavesdropping on communications, even if it is used for antisocial acts, it will not be recognized or caught Can not.

【0003】また、企業防衛の観点から社内の重要なフ
ァイルなどを暗号化して保管しておく等の対策を取って
いる企業も見受けられるようになったが、一方で事故や
災害、その他何らかの理由によって暗号化されたファイ
ルが復号できなくなる事態が発生した場合でも、現在の
暗号化技術ではそのファイルを復号する手段はもはや存
在せず、そのファイルは永遠に利用不可能なものとな
る。
[0003] Also, from the viewpoint of corporate defense, some companies have taken measures such as encrypting and storing important files in the company, but on the other hand, accidents, disasters, and other reasons have occurred. Even if a situation occurs in which an encrypted file cannot be decrypted, there is no longer any means for decrypting the file with the current encryption technology, and the file is permanently unavailable.

【0004】このため、ある一定の条件下において法律
または契約等に基づく執行機関が暗号文を解読できるよ
うにする技術が欧米を中心に検討されており、これらは
キーリカバリーまたはキーエスクローという名前で呼ば
れている。これらの技術は、一般には暗号通信を利用す
るときに使用したセッション鍵を暗号化した上でLEA
F(Law Enhancement Access Field) 等の付加データの
中に格納、暗号文に付加しておき、裁判所命令あるいは
契約等により暗号文解読の許可が発せられたとき、執行
機関は付加データからセッション鍵を復元して暗号文を
解読することができるようにするものである。なかでも
代表的なのが、アメリカ政府が提唱しているEscrowed E
ncryption Standard(Federal Information Processing
Standards Publication(FIPS)185, U.S.Dept.of Commer
ce) である。
[0004] For this reason, technologies for enabling enforcement agencies to decrypt ciphertexts under certain conditions under laws or contracts have been studied mainly in Europe and the United States. These technologies are called key recovery or key escrow. being called. These technologies generally use LEA after encrypting a session key used when using encrypted communication.
F (Law Enhancement Access Field), etc., stored in the additional data and added to the ciphertext, and when a permission to decrypt the ciphertext is issued by a court order or contract, the enforcement agency sends the session key from the additional data. It is intended to be able to recover and decrypt the ciphertext. A typical example is Escrowed E, which is proposed by the U.S. government.
ncryption Standard (Federal Information Processing
Standards Publication (FIPS) 185, USDept. Of Commer
ce).

【0005】図6はEscrowed Encryption Standardの動
作概要である。この方式によれば、ユーザは耐タンパー
なチップであるクリッパーチップを利用して暗号通信を
行うことになる。このクリッパーチップにはSKIPJ
ACKとよばれる秘密暗号アルゴリズム、LEAFの秘
密生成アルゴリズム及び検証アルゴリズム等の複数のア
ルゴリズムと、装置番号、ユニット鍵及びファミリー鍵
等の複数の装置固有またはシステム共通のデータとが封
入されている。このチップは通信傍受機能の確保を目的
とした機密保持政策によりアメリカ政府の認可を受けた
製造工場でのみ製造が許可される仕組みのため、具体的
な構成は非公開である、動作概要のみ公表されている。
FIG. 6 shows an outline of the operation of the Escrowed Encryption Standard. According to this method, a user performs cipher communication using a clipper chip that is a tamper-resistant chip. This clipper chip has SKIPJ
A plurality of algorithms such as a secret encryption algorithm called ACK, a secret generation algorithm and a verification algorithm of LEAF, and a plurality of device-specific or system-common data such as a device number, a unit key, and a family key are enclosed. Since this chip is a mechanism that is allowed to be manufactured only at manufacturing plants that have been approved by the US government due to confidentiality policies aimed at securing the communication interception function, the specific configuration is not disclosed, only the operation summary is published Have been.

【0006】この動作概要によれば、まず製造工場11
は各々のクリッパーチップにアルゴリズム、データなど
を封入して流通させるとともに、ユニット鍵を二つのデ
ータに分割して装置番号とともに法律が指定する二つの
エスクローエージャンシー12,13に預ける。次に、
ユーザは何らかの方法によってセッション鍵をあらかじ
め共有している状況下で暗号通信を行う場合、送信者A
はセッション鍵及びメッセージをクリッパーチップ15
Aに入力する。クリッパーチップ15Aはメッセージを
セッション鍵を用いてSKIPJACKアルゴリズムに
よって暗号化部16で暗号化すると同時に、セッション
鍵を装置番号及びいくつかの非公開データとともにユニ
ット鍵及びファミリー鍵を用いて秘密生成アルゴリズム
によって暗号化部17で暗号化してLEAFを生成す
る。このようにして生成された暗号文及びLEAFが通
信相手に送信される。
According to this operation summary, first, the manufacturing factory 11
, While enclosing the algorithm and data in each clipper chip and distributing it, divides the unit key into two pieces of data and deposits them together with the device number in two escrow agencies 12 and 13 specified by law. next,
When the user performs cryptographic communication in a situation where the session key is shared in advance by any method, the sender A
Sends the session key and message to the clipper chip 15
Input to A. The clipper chip 15A encrypts the message using the session key with the encryption unit 16 using the SKIPJACK algorithm, and simultaneously encrypts the session key with the unit key and family key together with the device number and some secret data using the secret generation algorithm. The encrypting unit 17 generates the LEAF. The ciphertext and LEAF generated in this way are transmitted to the communication partner.

【0007】また、受信者Bはセッション鍵、受信した
暗号文及びLEAFをクリッパーチップ15Bに入力す
る。クリッパーチップ15BはまずLEAFの正当性を
ファミリー鍵及び非公開データを用いて検証部18で検
証し、検証にパスした場合のみ暗号文をセッション鍵を
用いてSKIPJACKアルゴリズムによって復号部1
9で復号する。万が一、検証に失敗した場合には復号を
行わない。
[0007] Further, the receiver B inputs the session key, the received ciphertext and the LEAF to the clipper chip 15B. The clipper chip 15B first verifies the validity of the LEAF by the verification unit 18 using the family key and the secret data, and only when the verification is passed, the ciphertext is decrypted by the SKIPJACK algorithm using the session key using the session key.
Decrypt at 9. If the verification fails, decryption is not performed.

【0008】さらに、裁判所から検証令状を得て法執行
機関21が通信を傍受する場合、検証令状を二つのエス
クローエージャンシー12,13に提示することによっ
て、法執行機関21はクリッパーチップ15Aの分割さ
れたユニット鍵1,2のデータをそれぞれのエスクロー
エージャンシー12,13から受け取り、クリッパーチ
ップ15Aのユニット鍵を鍵再構成部22で再構成す
る。その後に、LEAFをファミリー鍵及び再構成した
ユニット鍵を用いて復号部23で復号してセッション鍵
を獲得する。このようにして獲得したセッション鍵を用
いることによって暗号文を復号部24で解読し、メッセ
ージを傍受することが出来るようになる。
Further, when the law enforcement agency 21 obtains a verification warrant from the court and intercepts the communication, the law enforcement agency 21 presents the verification warrant to the two escrow agencies 12 and 13 so that the law enforcement agency 21 divides the clipper chip 15A. The received data of the unit keys 1 and 2 are received from the respective escrow agencies 12 and 13, and the unit key of the clipper chip 15A is reconfigured by the key reconfiguration unit 22. After that, the LEAF is decrypted by the decryption unit 23 using the family key and the reconstructed unit key to obtain a session key. By using the session key thus obtained, the ciphertext can be decrypted by the decryption unit 24 and the message can be intercepted.

【0009】しかし、この方法についてはいくつかの問
題点があることが指摘されており、なかでも、(1)構
成の基本をなす部分が通信傍受機能を確保するとの理由
でほとんど非公開とされているため、具体的な動作が不
明であること、(2)法執行機関21が一度でも裁判所
の令状を得て通信を傍受した場合、当該装置に対するユ
ニット鍵を獲得してしまうため、それ以降は裁判所が許
可した範囲内かどうかに関わらず、過去、現在、未来に
わたって無条件に当該装置が発振側となる通信を傍受で
きるようになってしまうこと、(3)当該装置が受信側
であったときには、送信側装置に対するユニット鍵を獲
得しない限り通信傍受が不可能となり、もし通信傍受を
強行しようとすれば検証令状に含まれていないユーザの
装置に対するユニット鍵が開示されてしまうことになる
等が大きな問題点となっている。すなわち、法執行機関
の利益の方により重点が置かれた方式であり、法執行機
関によるプライバシー侵害の危険性が極めて高いとの懸
念が払拭できない。また、法執行機関の不正な通信傍受
に対し、裁判所による法的なコントロールが効かなくな
る点も無視できない。
[0009] However, it has been pointed out that this method has some problems. Among them, (1) it is almost kept secret because the basic part of the configuration secures a communication interception function. (2) If the law enforcement agency 21 obtains a court's warrant and intercepts communications at least once, it will acquire a unit key for the device, and thereafter, Can unconditionally intercept the communication in which the device is the oscillating side over the past, present and future, regardless of whether it is within the range permitted by the court. In this case, it is impossible to intercept the communication unless the unit key for the transmitting device is obtained, and if an attempt is made to forcibly intercept the communication, the unit interception for the user's device not included in the verification warrant is performed. Etc. so that the bets key from being disclosed is a major problem. In other words, it is a scheme that places more emphasis on the interests of law enforcement agencies and does not dispel concerns that the risk of privacy infringement by law enforcement agencies is extremely high. In addition, it cannot be ignored that legal control by law enforcement agencies is not effective against illegal interception of communications by law enforcement agencies.

【0010】[0010]

【発明が解決しようとする課題】この発明の目的は、法
律または契約等に基づいて実施される暗号文解読または
セッション鍵複製に対し、可能な限りのユーザのプライ
バシーを保護をする観点から、(1)公開プロトコル及
び公開アルゴリズムを使用すること、(2)法律または
契約等に基づいて執行機関が暗号文解読またはセッショ
ン鍵複製を実施する場合には、その定めの範囲内に限り
確実に暗号文を解読またはセッション鍵を複製できるこ
と、(3)執行機関がその定めを逸脱して不当に暗号文
を解読またはセッション鍵を複製しようとしても、暗号
文の解読及びセッション鍵の複製が出来ないこと、
(4)法律または契約等による権限を有しない者は、い
っさい暗号文の解読及びセッション鍵の複製が出来ない
ことを実現する鍵管理方法及びシステムを提供すること
にある。
SUMMARY OF THE INVENTION An object of the present invention is to protect the user's privacy as much as possible from cipher decryption or session key duplication performed based on a law or a contract. 1) Use public protocols and algorithms. (2) If an enforcement authority performs ciphertext decryption or session key duplication based on laws or contracts, ensure that ciphertexts are used only within the specified range. (3) that the enforcement authority cannot decrypt the ciphertext and duplicate the session key, even if the enforcement authority attempts to decrypt the ciphertext or duplicate the session key illegally beyond the provisions;
(4) A person who does not have authority according to a law or a contract is to provide a key management method and a system that realizes no decryption of cipher text and no duplication of a session key.

【0011】[0011]

【課題を解決するための手段】この発明では、上記目的
を達成するための方法として、鍵管理機関または鍵生成
機関もしくはユーザが生成したシステム秘密鍵及びユー
ザ秘密情報または通信当事者を特定するマスター鍵Kab
を鍵管理機関が登録管理する過程と、暗号通信を行うと
きに発信側がマスター鍵Kabと日時情報とを含むデータ
を用いてセッション暗号化鍵Kdaとし、実際のメッセー
ジの暗号化に用いたセッション鍵KSを含むデータをセ
ッション暗号化鍵Kd によって暗号化することにより付
加データLEAFを生成する過程と、受信側が発信側と
同様の手法で生成したセッション暗号化鍵Kd を用いて
付加データLEAFを復号することによってセッション
鍵KSを獲得する過程と、及び暗号文解読またはセッシ
ョン鍵複製を行うときに鍵管理機関はマスター鍵Kabと
日時情報と乱数データR1 (R2 )とを含むデータを用
いて生成した疑似マスター鍵K1 (K2 )を執行機関に
提供し、執行機関は疑似マスター鍵K1 ,K2 を用いて
疑似セッション暗号化鍵K* を生成した後、鍵管理機関
に送付し、鍵管理機関は疑似セッション暗号化鍵K*
ら乱数データR1 (R2 )を消去してK1 ′(K2 ′)
として執行機関に返送し、執行機関はK1 ′,K2 ′か
らセッション暗号化鍵Kd を再構成した後、セッション
暗号化鍵Kd を用いて付加データLEAFを復号してセ
ッション鍵KSを獲得し、さらに必要ならばそのセッシ
ョン鍵KS を利用して暗号文を解読する過程と、を有
することを特徴とする。なお、日時情報には法律または
契約等に基づいた時間的に許可された範囲内であるかど
うかを判断するための情報が含まれていればよいので、
実際の日時情報ではなくても送信番号、メッセージ番号
等、時間的に区別される情報であればどのような情報で
あっても良い。さらにこれらの情報が複数種類含まれて
いても構わないし、その他の情報、例えば送受信者のユ
ーザ名、乱数データ等の付加データがさらに付加されて
いても構わない。
According to the present invention, as a method for achieving the above object, a system secret key and user secret information generated by a key management organization or a key generation organization or a user or a master key for specifying a communication party are provided. Kab
The key management organization registers and manages the session key, and when performing the cryptographic communication, the transmitting side uses the data including the master key Kab and the date and time information as the session encryption key Kda, and the session key used for encrypting the actual message. A process of generating additional data LEAF by encrypting data including KS with the session encryption key Kd, and decrypting the additional data LEAF using the session encryption key Kd generated by the receiving side in the same manner as the transmitting side. The key management institution obtains the session key KS by using the data including the master key Kab, date and time information, and random number data R 1 (R 2 ). pseudo-session encrypted using the provided pseudo master key K 1 (K 2) the enforcement, enforcement pseudo master key K 1, K 2 After generating the K *, and sending to the key management institutions, K 1 to erase the key management center random number data R 1 from the pseudo-session encryption key K * (R 2) '( K 2')
After reconstructing the session encryption key Kd from K 1 ′ and K 2 ′, the enforcement agency decrypts the additional data LEAF using the session encryption key Kd to obtain the session key KS. And, if necessary, decrypting the ciphertext using the session key KS. Since the date and time information only needs to include information for determining whether or not the time is within a permitted range based on a law or a contract,
Instead of the actual date and time information, any information may be used as long as the information is temporally distinguished, such as a transmission number and a message number. Furthermore, a plurality of types of such information may be included, and other information, for example, additional data such as a user name of a transmitter / receiver and random number data may be further added.

【0012】また、上記目的を達成するためのシステム
として、ユーザ装置にはセッション鍵生成手段、マスタ
ー鍵生成手段、日時管理手段、セッション暗号化鍵生成
手段、付加データ生成手段、セッション鍵獲得手段及び
暗号手段を有し、鍵管理機関装置にはシステム秘密鍵管
理データベース、ユーザ秘密情報管理データベース、乱
数データ生成手段、疑似マスター鍵生成手段及び乱数デ
ータ消去手段を有し、執行機関装置には蓄積手段、疑似
セッション暗号化鍵生成手段、セッション暗号化鍵再構
成手段及び解析手段を有することを必須とし、さらにシ
ステム公開鍵及びシステム秘密鍵を生成する情報生成手
段を鍵管理機関装置または鍵生成機関装置に備え、ユー
ザ公開情報及びユーザ秘密情報またはマスター鍵を生成
するユーザ情報生成手段をユーザ装置または鍵生成機関
装置もしくは鍵管理機関装置に備えることを特徴とす
る。また、必要ならば暗号文を解読するための暗号手段
を執行機関装置に備えても良い。
Further, as a system for achieving the above object, a user apparatus includes a session key generation unit, a master key generation unit, a date and time management unit, a session encryption key generation unit, an additional data generation unit, a session key acquisition unit, The key management institution device has a system secret key management database, a user secret information management database, a random number data generation unit, a pseudo master key generation unit, and a random number data erasure unit. , A pseudo session encryption key generation means, a session encryption key reconstructing means, and an analysis means, and an information generation means for generating a system public key and a system secret key is provided by a key management institution device or a key generation institution device. User information to generate user public information and user secret information or master key Characterized in that it comprises means to the user device or key generation engine apparatus or the key management center apparatus. If necessary, the enforcement apparatus may be provided with an encryption means for decrypting the encrypted text.

【0013】[0013]

【作用】この発明によれば、セッション鍵KSを獲得し
暗号文を解読するためにはセッション暗号化鍵Kd を入
手することが必要であり、またそのセッション暗号化鍵
Kd はマスター鍵Kabと日時情報とを含むデータを用い
て得られることから、任意のセッション暗号化鍵Kd を
生成するためにはマスター鍵Kabを入手することが必要
となる。
According to the present invention, it is necessary to obtain the session encryption key Kd in order to obtain the session key KS and decrypt the ciphertext, and the session encryption key Kd is obtained by combining the master key Kab with the date and time. Since it is obtained by using data including information, it is necessary to obtain the master key Kab in order to generate an arbitrary session encryption key Kd.

【0014】しかし、このセッション暗号化鍵Kd から
マスター鍵Kabと日時情報とを含むデータを取り出すた
めには数学的に解法が極めて困難とされる離散対数問題
を解く必要があり、これは公開鍵暗号方法を解読するの
と同程度の困難性を有していると考えられている。した
がって、たとえセッション暗号化鍵Kd が得られたとし
ても執行機関及び権限を有しないものがセッション暗号
化鍵Kd を解読してマスター鍵Kabを取り出すことは出
来ない。
However, in order to extract the data including the master key Kab and the date and time information from the session encryption key Kd, it is necessary to solve a discrete logarithm problem that is extremely difficult to solve mathematically, and this requires a public key. It is believed to have as much difficulty as decrypting the cryptographic method. Therefore, even if the session encryption key Kd is obtained, it is impossible for an unauthorized party or an unauthorized party to decrypt the session encryption key Kd and extract the master key Kab.

【0015】一方、暗号文解読またはセッション鍵複製
を行うとき、執行機関が鍵管理機関から入手できるのは
疑似マスター鍵K1 ,K2 であり、これらから疑似セッ
ション暗号化鍵K* を求めることが出来る。しかし、疑
似セッション暗号化鍵K* からセッション暗号化鍵Kd
またはマスター鍵Kabを求めるには鍵管理機関が管理し
ている乱数データを消去する必要があり、その乱数デー
タを消去できるのは鍵管理機関だけである。ゆえに、鍵
管理機関はマスター鍵自体を執行機関に開かすことな
く、疑似セッション暗号化鍵K* から乱数データを消去
することによってセッション暗号化鍵Kd だけを執行機
関に渡すことが出来る。さらに、鍵管理機関が提供する
疑似マスター鍵K1 (K2 )は発信側、受信側を問わず
一方のユーザのユーザ秘密情報または通信当事者を特定
するマスター鍵のみしか使用しないで生成できるため、
範囲対象外のユーザのユーザ秘密情報またはマスター鍵
が使用されることはない。また、ユーザはセッション鍵
KSの送付を付加データLEAFを用いて行うため、も
し不当な付加データであればユーザ同士自身でもセッシ
ョン鍵の共有が出来ないことになるため、暗号通信が可
能である以上は正当な付加データが用いられていること
になる。したがって、法律または契約等に基づいて暗号
文解読またはセッション鍵複製が行われる場合、鍵管理
機関がその定めの範囲内であるかどうかを確認し、範囲
内であると認めた場合にのみセッション暗号化鍵Kd を
執行機関に渡すことになり、かつセッション暗号化鍵K
d が得られた場合には付加データが正当なものであるこ
とから必ずセッション鍵KSを求められ、ひいては暗号
文を解読することが出来る。
On the other hand, when performing ciphertext decryption or session key duplication, the enforcement authority can obtain the pseudo master keys K 1 and K 2 from the key management authority, and obtain the pseudo session encryption key K * therefrom. Can be done. However, from the pseudo session encryption key K * to the session encryption key Kd
Alternatively, to obtain the master key Kab, it is necessary to delete the random number data managed by the key management organization, and only the key management organization can delete the random number data. Therefore, the key management authority can pass only the session encryption key Kd to the enforcement authority by deleting the random number data from the pseudo session encryption key K * without opening the master key itself to the enforcement authority. Further, since the pseudo master key K 1 (K 2 ) provided by the key management organization can be generated using only the user secret information of one user or the master key specifying the communication party regardless of the originator or the recipient,
No user secrets or master keys of unscoped users are used. In addition, since the user sends the session key KS using the additional data LEAF, if the additional data is invalid, the users themselves cannot share the session key with each other. Means that valid additional data is used. Therefore, when ciphertext decryption or session key duplication is performed based on laws or contracts, the key management authority checks whether it is within the prescribed range, and only if it is determined to be within the range, the session encryption is performed. Will pass the encryption key Kd to the enforcement authority and the session encryption key K
When d is obtained, since the additional data is valid, the session key KS is always obtained, and the ciphertext can be decrypted.

【0016】また、日時情報は通信ごとまたはセッショ
ン鍵KS更新ごとに異なるため、セッション暗号化鍵K
d も通信ごとまたはセッション鍵更新ごとに異なる。し
たがって、執行機関が入手できたセッション暗号化鍵K
d もそれに対応する場合のセッション鍵KSの複製また
は暗号文の解読についてのみ有効なのであって、それ以
外の場合には役に立たない。
Further, since the date and time information differs for each communication or each time the session key KS is updated, the session encryption key K
d also differs for each communication or each session key update. Therefore, the session encryption key K obtained by the executive
d is also effective only for the duplication of the session key KS or the decryption of the ciphertext in the case of corresponding to it, and is useless in other cases.

【0017】ゆえに、権限を有しないものはもとより執
行機関でさえいかなる状況下にあってもマスター鍵自体
Kabを獲得することは出来ないので、任意のセッション
暗号化鍵Kdaが不正に生成されることはあり得ず、結果
として執行機関がその範囲を逸脱して不当に暗号文を解
読し、またはセッション鍵を複製することは出来ない。
[0017] Therefore, even if the authority does not have authority, even the enforcement authority cannot acquire the master key Kab under any circumstances, so that any session encryption key Kda is illegally generated. As a result, it is not possible for an enforcement authority to deviate from its scope and unfairly decrypt the ciphertext or duplicate the session key.

【0018】なお、この発明においてはアルゴリズムが
公開されている公開鍵暗号方式及び共通鍵暗号方式を用
いてシステムを構成することが出来る。
In the present invention, a system can be configured using a public key cryptosystem and a common key cryptosystem in which algorithms are disclosed.

【0019】[0019]

【発明の実施の形態】以下、この発明の一実施例を図面
を用いて説明する。図1はこの発明の一実施例を示す鍵
管理システムの機能構成図である。図1において、発信
側ユーザ装置1は、ユーザ公開情報及びユーザ秘密情報
を生成するユーザ情報生成手段10、ユーザの操作によ
りセッション鍵KSを設定するセッション鍵生成手段1
1、通信当事者を特定するためのマスター鍵を生成する
マスター鍵生成手段12、通信日時等を示す情報を管理
する日時管理手段13、セッション鍵を暗号化するため
のセッション暗号化鍵を生成するセッション暗号化鍵生
成手段14、付加データを生成する付加データ生成手段
15、暗号通信を行うための共通鍵暗号手段16を備え
ている。受信側ユーザ装置2は、ユーザ公開情報及びユ
ーザ秘密情報を生成するユーザ情報生成手段20、付加
データが正当なデータであるかを検証する検証手段2
1、通信当事者を特定するためのマスター鍵を生成する
マスター鍵生成手段22、セッション鍵を暗号化するた
めのセッション暗号化鍵を生成するセッション暗号化鍵
生成手段23、付加データからセッション鍵を取り出す
セッション鍵獲得手段24、暗号通信を行うための共通
鍵暗号手段25を備えている。
DESCRIPTION OF THE PREFERRED EMBODIMENTS One embodiment of the present invention will be described below with reference to the drawings. FIG. 1 is a functional configuration diagram of a key management system according to an embodiment of the present invention. In FIG. 1, an originating user device 1 includes a user information generating unit 10 for generating user public information and user secret information, and a session key generating unit 1 for setting a session key KS by a user operation.
1. Master key generation means 12 for generating a master key for specifying a communication party, date and time management means 13 for managing information indicating communication date and time, a session for generating a session encryption key for encrypting a session key The system includes an encryption key generation unit 14, an additional data generation unit 15 for generating additional data, and a common key encryption unit 16 for performing encrypted communication. The receiving-side user device 2 includes a user information generating unit 20 that generates user public information and user secret information, and a verifying unit 2 that verifies whether the additional data is valid data.
1. Master key generation means 22 for generating a master key for specifying a communication party, session encryption key generation means 23 for generating a session encryption key for encrypting a session key, and extracting a session key from additional data A session key acquiring unit 24 and a common key encrypting unit 25 for performing encrypted communication are provided.

【0020】鍵管理機関装置3は、システム公開鍵及び
システム秘密鍵を生成する情報生成手段30、鍵管理機
関装置3,4はそれぞれ、システム秘密鍵を蓄積管理し
ておくシステム秘密鍵管理データベース31,41ユー
ザ秘密情報を蓄積管理しておくユーザ秘密情報管理デー
タベース33,43、乱数データを生成する乱数データ
生成手段34,44、疑似マスター鍵の生成する疑似マ
スター鍵生成手段35,45、疑似セッション暗号化鍵
から乱数データを消去する乱数データ消去手段36,4
6を備えている。執行機関装置5は傍受した暗号文及び
付加データを蓄積しておく蓄積手段50、疑似セッショ
ン暗号化鍵を生成する疑似セッション暗号化鍵生成手段
51、セッション暗号化鍵を再構成するセッション暗号
化鍵再構成手段52、セッション鍵を獲得する解析手段
53、暗号通信を解読するための共通鍵暗号手段54を
備えている。発信側ユーザ装置1と受信側ユーザ装置2
は通信回線6で互いに接続される。
The key management institution device 3 has an information generating means 30 for generating a system public key and a system secret key, and the key management institution devices 3 and 4 have a system secret key management database 31 for storing and managing system secret keys. User secret information management databases 33 and 43 for storing and managing user secret information; random number data generating means 34 and 44 for generating random number data; pseudo master key generating means 35 and 45 for generating a pseudo master key; Random number data erasing means 36, 4 for erasing random number data from the encryption key
6 is provided. The enforcement agency device 5 includes a storage unit 50 for storing the intercepted ciphertext and additional data, a pseudo session encryption key generation unit 51 for generating a pseudo session encryption key, and a session encryption key for reconstructing the session encryption key. It comprises a reconstructing means 52, an analyzing means 53 for acquiring a session key, and a common key encrypting means 54 for decrypting encrypted communication. Originating user device 1 and receiving user device 2
Are connected to each other by a communication line 6.

【0021】次に上記実施例の動作方法について図面を
用いて説明する。なお、ここでは公開鍵暗号方式として
RSA暗号(R. L. Rivest, A. Shamir,L. Adleman,
“A method for obtaining digital signature and pub
lic-key cryptosystem, ”Communication of ACM, vol.
21, No.2, 1978.2) を用いる。始めにシステム構築時に
おける動作方法を図2に示す。
Next, the operation method of the above embodiment will be described with reference to the drawings. Here, the RSA encryption (RL Rivest, A. Shamir, L. Adleman,
“A method for obtaining digital signature and pub
lic-key cryptosystem, ”Communication of ACM, vol.
21, No.2, 1978.2). First, an operation method at the time of system construction is shown in FIG.

【0022】ステップA1:鍵管理機関装置3は情報生
成手段30において以下の情報を用意する。(1)二つ
の大きな素数p,q、(2)n=pq、(3)g、
(4)Rs 、(5)Ps ,Ss 、但し、任意のMについ
てMPsSs=M(mod n)を満たす。 ステップA2:鍵管理機関装置3はn,g,Ps ,g
1/Rsをシステム公開鍵として全ての加入ユーザに公開す
る。
Step A1: The key management organization device 3 prepares the following information in the information generating means 30. (1) two large prime numbers p, q, (2) n = pq, (3) g,
(4) Rs, (5) Ps, Ss, where M PsSs = M (mod n) for any M. Step A2: The key management institution device 3 has n, g, Ps, g
Publish 1 / Rs to all subscribers as a system public key.

【0023】ステップA3:Ss をSs1,Ss2の二つに
分割し、Ps ,Ss1,p,q,Rsを鍵管理機関装置3
のシステム秘密鍵管理データベース31において、また
Ps,Ss2,p,q,Rs を鍵管理機関装置4のシステ
ム秘密鍵管理データベース41において厳重に保管す
る。ここでSs =Ss1+Ss2を満たす。なお、p,q,
Rs ,Ss ,Ss1,Ss2はシステム上極めて重要なシス
テム秘密鍵であり、いかなる場合でも外部に流出するこ
とがないよう厳重に保管しなければならない。
[0023] Step A3: Ss to Ss 1, Ss 2 of divided into two, Ps, Ss 1, p, q, the key to Rs management center apparatus 3
, And Ps, Ss 2 , p, q, and Rs are strictly stored in the system secret key management database 41 of the key management organization device 4. Here satisfy Ss = Ss 1 + Ss 2. Note that p, q,
Rs, Ss, Ss 1, Ss 2 is a very important system secret key on the system, it must be kept in strict so that it does not flow out to the outside in any case.

【0024】ここでは鍵管理機関装置3が単独でシステ
ム公開鍵及びシステム秘密鍵を生成するものとして説明
したが、この発明はこれに限定されるわけではなく、鍵
管理機関装置4が単独で、あるいは鍵管理機関装置3と
鍵管理機関装置4が協力して生成したり、もしくは信頼
できる鍵生成機関が生成し、鍵管理機関装置3及び鍵管
理機関装置4にシステム秘密鍵を配布する場合を排除す
るものではない。
Although the description has been given here assuming that the key management institution device 3 independently generates the system public key and the system secret key, the present invention is not limited to this. Alternatively, the key management institution device 3 and the key management institution device 4 may cooperate to generate the key secret institution, or a reliable key generation institution may generate and distribute the system secret key to the key management institution devices 3 and 4. It is not excluded.

【0025】次に、ユーザがシステムに加入する場合の
動作手順を図3に示す。 ステップB1:ユーザiはユーザ情報生成手段10(2
0)において自分の秘密情報Si 及び公開情報Pi =g
Si modnを設定する。 ステップB2:秘密情報Si をSi1,Si2の二つに分割
し、安全かつ秘密裏に鍵管理機関装置3に対してPi ,
Si1を、また鍵管理機関装置4に対してPi ,Si2を送
付する。ここでSi =Si1+Si2を満たす。
Next, an operation procedure when a user joins the system is shown in FIG. Step B1: The user i enters the user information generating means 10 (2
0), own secret information Si and public information Pi = g
Set Si modn. Step B2: Pi secret information Si is divided into two Si 1, Si 2, with respect to the key management center apparatus 3 safely and secretly,
It sends Si 1 and Pi and Si 2 to the key management organization device 4. Here, Si = Si 1 + Si 2 is satisfied.

【0026】ステップB3:鍵管理機関装置3(鍵管理
機関装置4)はユーザから送付された情報をユーザ秘密
情報管理データベース33(43)において厳重に保管
する。ここではユーザ自身がユーザ公開情報及びユーザ
秘密情報を生成するものとして説明したが、この発明は
これに限定されるものではなく、ユーザに代わって、鍵
管理機関装置3(4)または信頼できる鍵生成機関が生
成し、ユーザ、鍵管理機関装置3、鍵管理機関装置4に
対して必要な情報を安全かつ秘密裏に送付する場合を排
除するものではない。
Step B3: The key management institution 3 (key management institution 4) strictly stores the information sent from the user in the user secret information management database 33 (43). Here, the description has been made assuming that the user himself generates the user public information and the user secret information. However, the present invention is not limited to this, and instead of the user, the key management institution apparatus 3 (4) or the trusted key may be used. This does not preclude the case where the information is generated by the generating institution and the necessary information is securely and secretly transmitted to the user, the key management institution device 3, and the key management institution device 4.

【0027】次に、ユーザAとユーザBが暗号通信を行
う場合の動作手順を図4に示す。なお、発信側をA、受
信側をBとし、以下のステップC1〜C5はユーザAの
装置1が、ステップC6〜C9はユーザBの装置2が行
うものとする。 ステップC1:セッション鍵生成手段11を用いて、セ
ッション鍵KSを自由に設定する。
FIG. 4 shows an operation procedure in the case where the user A and the user B perform encrypted communication. It is assumed that the transmitting side is A and the receiving side is B, and the following steps C1 to C5 are performed by the device A of the user A, and steps C6 to C9 are performed by the device 2 of the user B. Step C1: The session key KS is freely set using the session key generation means 11.

【0028】ステップC2:マスター鍵生成手段12を
用いてユーザAのユーザ秘密情報Sa とユーザBのユー
ザ公開情報Pb とからユーザAとユーザBのマスター鍵
Kab=Pb Sa=gSaSb (mod n)を求める。 ステップC3:マスター鍵Kabと日時管理手段13から
得られた日時情報Dとを用いてセッション暗号化鍵生成
手段14において、セッション暗号化鍵Kd =gKabD(m
odn)を求める。つまりKabとDでgを暗号化してKd
を求める。
Step C2: Using the master key generation means 12, the master keys Kab = Pb Sa = g SaSb (mod n) of the users A and B from the user secret information Sa of the user A and the user public information Pb of the user B. Ask for. Step C3: Using the master key Kab and the date / time information D obtained from the date / time management unit 13, the session encryption key generation unit 14 generates a session encryption key Kd = g KabD (m
odn). In other words, g is encrypted with Kab and D and Kd
Ask for.

【0029】ステップC4:付加データ生成手段15に
おいてセッション暗号化鍵Kd を用いてセッション鍵K
Sに関する付加データLEAF={f(KS ,Kd )
|D|checksum}を生成する。ここで、f(M,K)は
任意の共通鍵暗号方式fであり、かつMを鍵Kで暗号化
することを表す。また、|は連結を表し、checksumは付
加データLEAFの正当性を示すチェックサムデータで
ある。
Step C4: The additional data generation means 15 uses the session encryption key Kd to
Additional data LEAF for S = Δf (KS, Kd)
| D | checksum} is generated. Here, f (M, K) is an arbitrary common key cryptosystem f, and represents that M is encrypted with the key K. Also, | indicates concatenation, and checksum is checksum data indicating the validity of the additional data LEAF.

【0030】ステップC5:付加データLEAFをユー
ザBの装置2へ通信回線6を通じて送付する。 ステップC6:検証手段21においてchecksumを用いて
付加データLEAFの正当性を検証する。検証に失敗し
た場合には通信を切断する。 ステップC7:マスター鍵生成手段22を用いてユーザ
Bのユーザ秘密情報Sb とユーザAのユーザ公開情報P
a とからユーザAとユーザBのマスター鍵Kab=Pa Sb
=gSaSb(modn)を求める。
Step C5: The additional data LEAF is sent to the device 2 of the user B via the communication line 6. Step C6: The verification unit 21 verifies the validity of the additional data LEAF using the checksum. If the verification fails, disconnect the communication. Step C7: Using the master key generation means 22, the user secret information Sb of the user B and the user public information P of the user A
From a, the master keys Kab = Pa Sb of users A and B
= G SaSb (modn).

【0031】ステップC8:付加データLEAFから日
時情報Dを取り出し、マスター鍵Kabと日時情報Dを用
いてセッション暗号化鍵生成手段23においてセッショ
ン暗号化鍵 Kd =gKabD(modn)を求める。 ステップC9:セッション鍵獲得手段24においてセッ
ション暗号化鍵Kd を用いて付加データLEAFからセ
ッション鍵KS=f-1(f(KS ,Kd ),Kd )を
求める。ここで、f-1(C,K)は共通鍵暗号方式fで
あり、かつCを鍵Kで復号することを表す。
Step C8: The date and time information D is extracted from the additional data LEAF, and the session encryption key generation means 23 obtains a session encryption key Kd = g KabD (modn) using the master key Kab and the date and time information D. Step C9: The session key obtaining means 24 obtains a session key KS = f -1 (f (KS, Kd), Kd) from the additional data LEAF using the session encryption key Kd. Here, f −1 (C, K) is the common key cryptosystem f, and represents that C is decrypted with the key K.

【0032】ステップC10:ユーザAの装置1とユー
ザBの装置2はセッション鍵KSを用いてそれぞれ共通
鍵暗号手段16,25を利用して通信回線6を通じて暗
号通信を行う。 ステップC11:ユーザAまたはユーザBの一方がセッ
ション鍵KS を変更したいと考えたときには、セッシ
ョン鍵KS ヲ変更しようとしたユーザを発信側として
ステップC1からの動作を繰り返す。
Step C10: The device 1 of the user A and the device 2 of the user B perform encrypted communication through the communication line 6 using the common key encryption means 16 and 25 using the session key KS. Step C11: When one of the user A and the user B wants to change the session key KS, the operation from step C1 is repeated with the session key KS {the user who tried to change the call originating side}.

【0033】最後に、法律または契約等に基づいて執行
機関が暗号文解読またはセッション鍵複製を実行する場
合の動作手順を図5に示す。ここで、執行機関は暗号文
解読またはセッション鍵複製を実行するに当たって必要
な許可証(例えば、裁判所の通信傍受検証令状、実施伺
い書等)を入手しているものとし、さらに通信回線6を
通じて行われた通信データが蓄積手段50に蓄積されて
いるものとする。また、許可証の対象となっているユー
ザがAであるとし、このときの通信相手がBであるとす
る。
Finally, FIG. 5 shows an operation procedure in the case where an enforcement agency executes ciphertext decryption or session key duplication based on a law or a contract. Here, it is assumed that the enforcement agency has obtained a permit (for example, a communication interception verification warrant, an inquiry letter, etc.) necessary to execute ciphertext decryption or session key duplication. It is assumed that the received communication data is stored in the storage unit 50. It is also assumed that the user who is the target of the permit is A, and the communication partner at this time is B.

【0034】ステップD1:執行機関装置5は鍵管理機
関装置3及び鍵管理機関装置4に対し、暗号文解読また
はセッション鍵複製を適正に実行する旨を記した許可証
及び付加データLEAFから獲得した日時情報Dを提示
する。なお、鍵管理機関装置3,4と執行機関装置5と
の間のデータのやりとりには通信回線を利用しても良い
し、通信回線以外を利用しても良い。
Step D1: The enforcement authority device 5 obtains the key management authority device 3 and the key management authority device 4 from the permit and the additional data LEAF indicating that the ciphertext decryption or the session key duplication is properly executed. The date and time information D is presented. The exchange of data between the key management institution devices 3 and 4 and the enforcement institution device 5 may use a communication line, or may use a communication line other than the communication line.

【0035】ステップD2:鍵管理機関装置3(鍵管理
機関装置4)は許可証が正当なものであるかどうかを確
認し、かつ執行機関が暗号文解読またはセッション鍵複
製を実施しようとしている対象が許可証または法律、契
約等に記された範囲内であるかどうかを確認する。範囲
外であると判断した場合には請求を棄却する。 ステップD3:鍵管理機関装置3(鍵管理機関装置4)
が適正な範囲内であると認定した場合、乱数データ生成
手段34(44)を用いて乱数データR1 (R 2 )を生
成する。
Step D2: Key management organization device 3 (key management
The institution 4) checks whether the permit is valid.
Authorized and the enforcement authority decrypts the ciphertext or duplicates the session key.
If you are trying to implement
Check if it is within the range described in about etc. range
If it is determined to be outside, reject the request. Step D3: Key management institution device 3 (key management institution device 4)
If it is determined that is within the appropriate range, random number data generation
Random number data R using the means 34 (44)1(R Two) Raw
To achieve.

【0036】ステップD4:鍵管理機関装置3(鍵管理
機関装置4)は分割されたシステム秘密鍵Ss1(Ss2)
、分割されたユーザAのユーザ秘密情報Sa1(S
a2)、ユーザBのユーザ公開情報Pb 及び乱数データR
1 (R2 )を用いて、疑似マスター鍵生成手段35(4
5)において疑似マスター鍵 K1 =Pb Sa1 ・R1 Ps(modn),(K2 =Pb Sa2
2 Ps(modn))を計算する。
Step D4: The key management organization device 3 (key management organization device 4) splits the system secret key Ss 1 (Ss 2 )
, The user secret information Sa 1 (S
a 2 ), user public information Pb of user B and random number data R
1 (R 2 ), the pseudo master key generation means 35 (4
In 5), the pseudo master key K 1 = Pb Sa1 · R 1 Ps (modn), (K 2 = Pb Sa2 ·
R 2 Ps (modn)) is calculated.

【0037】ステップD5:鍵管理機関装置3(鍵管理
機関装置4)は疑似マスター鍵K1(K2 )を執行機関
装置5に送付する。 ステップD6:執行機関装置5は疑似セッション暗号化
鍵生成手段51を用いて疑似マスター鍵K1 (K2 )か
ら疑似セッション暗号化鍵 K* =K1 ・K2 =Pb Sa1+Sa2 ・R1 Ps・R2 Ps=P
b Sa・R1 Ps・R2 Ps=Kab・R1 Ps・R2 Ps(modn)
を計算する。
Step D5: The key management institution device 3 (key management institution device 4) sends the pseudo master key K 1 (K 2 ) to the executive institution device 5. Step D6: The enforcement agency device 5 uses the pseudo session encryption key generation means 51 to convert the pseudo session encryption key K * = K 1 · K 2 = Pb Sa1 + Sa2 · R 1 from the pseudo master key K 1 (K 2 ). Ps · R 2 Ps = P
b Sa · R 1 Ps · R 2 Ps = Kab · R 1 Ps · R 2 Ps (modn)
Is calculated.

【0038】ステップD7:執行機関装置5は疑似セッ
ション暗号化鍵K* を鍵管理機関装置3及び鍵管理機関
装置4に送付する。 ステップD8:鍵管理機関装置3(鍵管理機関装置4)
は疑似セッション暗号化鍵K* から乱数データR1 (R
2 )を消去するために乱数データ消去手段36(46)
を用いてシステム秘密鍵Rs ,Ss1(Ss2)と乱数デー
タR1 (R2 )と日時情報Dとから K1 ′=(K* ・Rs ・D)Ss1 /R1 =(Kab・Rs ・D)Ss1 ・(R1 PsSs1 /R1 )・R2 PsSs1 (modn) [K2 ′=(K* ・Rs ・D)Ss2 /R2 =(Kab・Rs ・D)Ss2 ・R1 PsSs2 ・(R2 PsSs2 /R2 )(modn)] を計算する。乱数データ消去の準備を行う。
Step D7: The enforcement institution 5 sends the pseudo session encryption key K * to the key management institution 3 and the key management institution 4. Step D8: Key Management Institution 3 (Key Management Institution 4)
Random number data R 1 from the pseudo-session encryption key K * is (R
2 ) Random number data erasing means 36 (46) for erasing
System secret key Rs using, Ss 1 K 1 from (Ss 2) and the random number data R 1 and (R 2) and the date and time information D '= (K * · Rs · D) Ss1 / R 1 = (Kab · Rs · D) Ss1 · (R 1 PsSs1 / R 1) · R 2 PsSs1 (modn) [K 2 '= (K * · Rs · D) Ss2 / R 2 = (Kab · Rs · D) Ss2 · R 1 PsSs2 · (R 2 PsSs2 / R 2 ) calculating a (modn)]. Prepare for random number data erasure.

【0039】ステップD9:鍵管理機関装置3(鍵管理
機関装置4)はK1 ′(K2 ′)を執行機関装置5に送
付する。 ステップD10:執行機関装置5はセッション暗号化鍵
再構成手段52を用いてK1 ′(K2 ′)とシステム公
開鍵Ps ,g1/Rsからセッション暗号化鍵Kdを再構成
する。 Kd ′=K1 ′・K2 ′=(Kab・Rs ・D)Ss1+Ss2 ・(R1 Ps(Ss1+Ss2) /R1 )・(R2 Ps(Ss1+Ss2) /R2 ) =(Kab・Rs ・D)Ss・(R1 PsSs/R1 )・(R2 PsSs/R2 ) =(Kab・Rs ・D)Ss(modn) Kd =((g1/RsKd' ) Ps=(g1/RsKabRsD=gKabD (mod n) ステップD11:執行機関装置5は解析手段53におい
てセッション暗号鍵Kd を用いて付加データLEAFか
らセッション鍵KS =f-1(f(KS ,Kd ),K
d )を求める。
Step D9: The key management institution device 3 (key management institution device 4) sends K 1 ′ (K 2 ′) to the enforcement institution device 5. Step D10: The enforcement agency device 5 uses the session encryption key reconstructing means 52 to reconstruct the session encryption key Kd from K 1 ′ (K 2 ′) and the system public keys Ps, g 1 / Rs . Kd '= K 1' · K 2 '= (Kab · Rs · D) Ss1 + Ss2 · (R 1 Ps (Ss1 + Ss2) / R 1) · (R 2 Ps (Ss1 + Ss2) / R 2) = (Kab · Rs · D) Ss · (R 1 PsSs / R 1 ) · (R 2 PsSs / R 2 ) = (Kab · Rs · D) Ss (modn) Kd = ((g 1 / Rs ) Kd ′ ) Ps = (g 1 / Rs ) KabRsD = g KabD (mod n) Step D11: The enforcement authority apparatus 5 uses the session encryption key Kd in the analysis means 53 to extract the session key KS = f −1 (f (KS) from the additional data LEAF using the session encryption key Kd. , Kd), K
d).

【0040】ステップD12:執行機関は共通鍵暗号手
段54においてセッション鍵KSを用いて、蓄積手段5
0に蓄積されているデータA・B間の暗号文を解読す
る。ちなみに、許可証の対象となっているユーザがBで
あるとし、このときの通信相手がAである場合には、ス
テップD4が以下のように代わるだけである。 ステップD4* :鍵管理機関装置3(鍵管理機関装置
4)はシステム公開鍵Ps 、分割されたユーザBのユー
ザ秘密情報Sb1(Sb2)、ユーザAのユーザ公開情報P
a 及び乱数データR1 (R2 )を用いて、疑似マスター
鍵生成手段35(45)において疑似マスター鍵 K1 =Pa Sb1 ・R1 Ps(modn),(K2 =Pa Sb2
2 Ps(modn))を計算する。
Step D12: The enforcement authority uses the session key KS in the common key encryption means 54 to store
Decrypt the ciphertext between data A and B stored in 0. Incidentally, if the user who is the target of the permit is B and the communication partner at this time is A, step D4 is simply replaced as follows. Step D4 * : The key management institution device 3 (key management institution device 4) sends the system public key Ps, the divided user secret information Sb 1 (Sb 2 ) of the user B, and the user public information P of the user A
a and the random number data R 1 (R 2 ), the pseudo master key generation means 35 (45) uses the pseudo master key K 1 = Pa Sb1 · R 1 Ps (modn), (K 2 = Pa Sb2 ·
R 2 Ps (modn)) is calculated.

【0041】このような処理はKab=Pb Sa=Pa Sb
SaSb (mod n)が常に成立することから可能となる。
したがって、許可証の対象となっているユーザが発信
側、受信側のどちらであるかを問わずに同じ方法で処理
することが出来ることを示しており、さらに鍵管理機関
装置3,4が利用しているユーザ秘密情報は許可証の対
象になっているユーザのものであり、通信相手のユーザ
についてはユーザ公開情報しか利用しない。したがっ
て、許可証の対象外のユーザのユーザ秘密情報が利用さ
れることはない。
Such a process is performed as follows: Kab = Pb Sa = Pa Sb =
This is possible because g SaSb (mod n) always holds.
Therefore, it indicates that the same method can be used regardless of whether the user who is the target of the permit is the sender or the receiver, and the key management institution devices 3 and 4 use The user secret information is that of the user who is the target of the permit, and only the user public information is used for the communication partner user. Therefore, the user secret information of the user who is not the target of the permit is not used.

【0042】以上の説明では、この方法を鍵管理機関が
二つ存在するものとして説明したが、ユーザ秘密情報及
びシステム秘密鍵の分割数を変えることによって、単独
または二つ以上の鍵管理機関装置が存在するシステムと
して構築することが可能である。例えば、単独であれば
鍵管理機関装置はユーザ秘密情報及びシステム秘密鍵は
全て所有することになり、この場合にはステップD3〜
D7までを省略でき、直接執行機関装置に対してKd ′
=(Kab・Rs ・D)Ssを提供することが出来る。ま
た、鍵管理機関がk(k2)個あるならばSs =Σ
j=1 k Ssj,Si =Σj=1 k Sijを満たすようにシステ
ム秘密鍵とユーザ秘密情報を分割して所有させればよ
い。この場合には、ステップD6でK* =Πj=1 k j
(modn)、ステップD10でKd ′=Πj=1 k j ′(m
odn)となる以外は全く同様の処理で実現できる。
In the above description, this method has been described on the assumption that there are two key management institutions. However, by changing the number of divisions of the user secret information and the system secret key, one or more key management units can be used. Can be constructed as a system in which For example, if alone, the key management institution apparatus owns all of the user secret information and the system secret key.
Up to D7 can be omitted, and Kd '
= (Kab · Rs · D) Ss . If there are k (k > 2) key management institutions, Ss = Σ
The system secret key and the user secret information may be divided and owned so as to satisfy j = 1 k Ssj, Si = Σ j = 1 k Sij. In this case, at step D6, K * = Π j = 1 k K j
(modn), in step D10 Kd '= 1 = Π j k K j' (m
odn) can be realized by exactly the same processing.

【0043】なお、利用するアルゴリズムとして、公開
鍵暗号方法、共通鍵暗号方法とも上記に記載のアルゴリ
ズムに限定されるものではない。また、付加データLE
AFには上記記載のデータの他に発信者名、受信者名等
様々な付加情報を連結しても構わない。また上述におい
てユーザ公開情報Pi と、分割したユーザ秘密情報S
i1,Si2を鍵管理機関装置3,4にPi とSi1、Pi と
Si2と分割して登録したが、ユーザA,Bに特有のマス
ター鍵Kabを分割してKab1 ,Kab2 として鍵管理機関
装置3,4に登録してもよい。即ち、ユーザA、B間に
固有のマスター鍵Kabが設定されているとする。このと
き、Kab=Kab1 ・Kab2 を満たすようにKabを2つの
Kab1 ,Kab2 に分割し、鍵管理機関装置3(鍵管理機
関装置4)はKab1 (Kab2 )をそれぞれ補間する。ス
テップD4でK1 =Kab1 ・R1 Ps(mod n),( K2 =K
ab2 ・R2 Ps(mod n))を計算し、ステップD6で K* =K1 ・K2 =(Kab1 ・Kab2 )・R1 Ps・R2 Ps =Kab・R1 Ps・R2 Ps(mod n) を計算し、以下は同様の処理となる。また、k(k
2)個の鍵管理機関があるならば、Kab=Πj=1 k Kab
j を満たすようにマスター鍵を分割して所有させればよ
い。
The algorithm to be used is publicly disclosed.
Both the key encryption method and the common key encryption method use the algorithms described above.
It is not limited to islam. In addition, additional data LE
In the AF, in addition to the data described above, the sender name, receiver name, etc.
Various additional information may be connected. Also the smell mentioned above
Public information Pi and divided user secret information S
i1, SiTwoTo the key management institution devices 3 and 41, Pi and
SiTwoAnd registered, but the cells unique to users A and B
The key key Kab1, KabTwoAs a key management body
The information may be registered in the devices 3 and 4. That is, between users A and B
It is assumed that a unique master key Kab is set. This and
Kab = Kab1・ KabTwoKab
Kab1, KabTwoAnd the key management institution device 3 (key management machine
Seki device 4) is Kab1(KabTwo) Are interpolated. S
K at Step D41= Kab1・ R1 Ps(mod n), (KTwo= K
abTwo・ RTwo Ps(mod n)) and calculate K in step D6.*= K1・ KTwo= (Kab1・ KabTwo) ・ R1 Ps・ RTwo Ps = Kab ・ R1 Ps・ RTwo Ps(mod n) is calculated, and the following processing is the same. Also, k (k>
2) If there are key management agencies, Kab = Πj = 1 kKab
split the master key to satisfy j
No.

【0044】[0044]

【発明の効果】以上に述べたようにこの発明によれば、
以下のような効果が得られる。 (1)公開のアルゴリズムのみを用いてシステムを実現
できる。 (2)法律または契約等に基づいて暗号文解読またはセ
ッション鍵複製が実施される場合には、その定めの範囲
内に限り確実に暗号文を解読またはセッション鍵を複製
できる。 (3)その定めを逸脱して不当に暗号文を解読またはセ
ッション鍵を複製しようとしても、暗号文解読及びセッ
ション鍵複製が出来ない。 (4)法律または契約等による権限を有しない者は、い
っさい暗号文解読及びセッション鍵複製が出来ない。
As described above, according to the present invention,
The following effects can be obtained. (1) The system can be realized using only a public algorithm. (2) When decryption of a ciphertext or duplication of a session key is performed based on a law or a contract, etc., the ciphertext can be deciphered or the session key can be reliably reproduced only within a prescribed range. (3) Even if an attempt is made to decipher the ciphertext or duplicate the session key unduly, the ciphertext cannot be decrypted and the session key cannot be duplicated. (4) A person who does not have authority according to law or contract cannot decrypt ciphertexts or duplicate session keys at all.

【図面の簡単な説明】[Brief description of the drawings]

【図1】この発明の一実施例を示す鍵管理システムの機
能構成図。
FIG. 1 is a functional configuration diagram of a key management system according to an embodiment of the present invention.

【図2】この発明の実施例におけるシステム構築時の動
作手順を示すフローチャート。
FIG. 2 is a flowchart showing an operation procedure when a system is constructed in the embodiment of the present invention.

【図3】この発明の実施例におけるユーザのシステム加
入時の動作手順を示すフローチャート。
FIG. 3 is a flowchart showing an operation procedure when a user subscribes to the system according to the embodiment of the present invention.

【図4】この発明の実施例における暗号通信時の動作手
順を示すフローチャート。
FIG. 4 is a flowchart showing an operation procedure at the time of encrypted communication in the embodiment of the present invention.

【図5】この発明の実施例における暗号文解読またはセ
ッション鍵複製の実行時の動作手順を示すフローチャー
ト。
FIG. 5 is a flowchart showing an operation procedure when executing ciphertext decryption or session key duplication in the embodiment of the present invention.

【図6】クリッパーチップにおける動作概要を示す図。FIG. 6 is a diagram showing an operation outline in the clipper chip.

Claims (11)

【特許請求の範囲】[Claims] 【請求項1】 暗号通信システムにおけるメッセージの
暗号通信に利用するセッション鍵を管理する鍵管理方法
において、 システム構築時には鍵管理機関装置または鍵生成機関装
置がシステム公開鍵及びシステム秘密鍵を設定し、かつ
ユーザのシステム加入時にはそのユーザの装置(以下ユ
ーザ装置と記す)または上記鍵生成機関装置もしくは上
記鍵管理機関装置がユーザ公開情報及びユーザ秘密情報
を生成し、または通信当事者を特定するマスター鍵を生
成した後、システム公開鍵及びユーザ公開情報をシステ
ム上に公開し、かつ一つまたは複数の鍵管理機関におい
てシステム秘密鍵及びユーザ秘密情報またはマスター鍵
を登録管理する過程と、 暗号通信を行うときには発信側ユーザ装置が、通信当事
者を特定するマスター鍵と日時情報等の時間的な要素を
示すデータとを含むデータを用いてセッション暗号化鍵
を生成し、セッション鍵を含むデータをセッション暗号
化鍵を用いて暗号化することにより付加データを生成し
た後、付加データを受信側ユーザ装置に送信する過程
と、 受信側ユーザ装置が、通信当事者を特定するマスター鍵
と日時情報等の時間的な要素を示すデータとを含むデー
タを用いてセッション暗号化鍵を生成し、受信した付加
データをセッション暗号化鍵を用いて復号することによ
りセッション鍵を獲得する過程とを含むことを特徴とす
る鍵管理方法。
1. A key management method for managing a session key used for encryption communication of a message in an encryption communication system, wherein a key management institution device or a key generation institution device sets a system public key and a system secret key at the time of system construction. In addition, when a user joins the system, the user's device (hereinafter referred to as a user device) or the key generation institution device or the key management institution device generates user public information and user secret information, or generates a master key for identifying a communication party. After the generation, the process of publishing the system public key and the user public information on the system and registering and managing the system secret key and the user secret information or the master key in one or a plurality of key management institutions; and The originating user equipment has a master key to identify the communicating party, date and time information, etc. A session encryption key is generated using data including data indicating a temporal element, and additional data is generated by encrypting data including the session key using the session encryption key. Transmitting to the receiving-side user device, the receiving-side user device generates a session encryption key using data including a master key specifying a communication party and data indicating a time element such as date and time information, Decrypting the received additional data using the session encryption key to obtain a session key.
【請求項2】 執行機関装置が暗号文の解読またはセッ
ション鍵の複製を実施するときには鍵管理機関装置が通
信当事者を特定するマスター鍵と日時情報等の時間的な
要素を示すデータと鍵管理機関装置が生成した乱数デー
タとを含むデータを用いて疑似マスター鍵を生成して執
行機関装置に提供し、執行機関装置が疑似マスター鍵を
用いて疑似セッション暗号化鍵を生成した後、鍵管理機
関装置に返送し、鍵管理機関装置は疑似セッション暗号
化鍵から乱数データを消去する準備をして執行機関装置
に返送し、執行機関装置がセッション暗号化鍵を再構成
した後、セッション暗号化鍵を用いて付加データを復号
してセッション鍵を獲得する過程を含むことを特徴とす
る請求項1記載の鍵管理方法。
2. When an enforcement agency device decrypts a ciphertext or duplicates a session key, the key management agency device uses a master key identifying a communication party, data indicating time elements such as date and time information, and a key management agency. A pseudo master key is generated using the data including the random number data generated by the device and provided to the enforcement agency device. After the enforcement agency device generates the pseudo session encryption key using the pseudo master key, the key management agency The key management authority device prepares to erase the random number data from the pseudo session encryption key and returns it to the enforcement authority device. After the enforcement device reconfigures the session encryption key, the key management authority device reconstructs the session encryption key. 2. The key management method according to claim 1, further comprising the step of: obtaining a session key by decrypting the additional data using the key.
【請求項3】 通信当事者を特定するマスター鍵を、通
信当事者の一方のユーザ秘密情報と0の通信相手のユー
ザ公開情報とから生成することを特徴とする請求項1又
は2に記載の鍵管理方法。
3. The key management according to claim 1, wherein a master key for identifying a communication party is generated from one user secret information of the communication party and user public information of a communication partner of 0. Method.
【請求項4】 複数の鍵管理機関装置においてシステム
秘密鍵及びユーザ秘密情報またはマスター鍵を登録管理
する過程において、それらの秘密情報を分割して各々の
鍵管理機関装置が分割された秘密情報を管理することを
特徴とする請求項1から請求項3のいずれかに記載の鍵
管理方法。
4. In the process of registering and managing a system secret key and user secret information or a master key in a plurality of key management authority devices, the secret information is divided and each key management authority device divides the divided secret information. 4. The key management method according to claim 1, wherein the key is managed.
【請求項5】 上記システム秘密鍵Ss及び上記ユーザ
秘密情報Si の分割は、それぞれSs =Σj=1 k Ssj,
Si =Σj=1 k Sijを満たすように鍵管理機関装置の数
k(kは2以上の整数)に分割し、第j鍵管理機関装置
に分割されたシステム秘密鍵Ssjと分割されたユーザ秘
密情報Sijを管理させることを特徴とする請求項4記載
の鍵管理方法。
5. The division of the system secret key Ss and the user secret information Si is performed as follows: Ss = Σ j = 1 k Ssj,
Si = Σ j = 1 k The number of key management organization devices is divided into k (k is an integer of 2 or more) so as to satisfy Sij, the system secret key Ssj divided into the j-th key management organization device, and the divided user 5. The key management method according to claim 4, wherein the secret information Sij is managed.
【請求項6】 上記システム秘密鍵Ss及び上記ユーザ
A、Bを特定するマスター鍵Kabの分割はそれぞれSs
=Σj=1 k Ssj,Kab=Πj=1 k Kabj を満たすように
鍵管理機関装置の数k(kは2以上の整数)に分割し、
第j鍵管理機関装置に分割されたシステム秘密鍵Ssjと
分割されたマスター鍵Kabj を管理させることを特徴と
する請求項4記載の鍵管理方法。
6. The division of the system secret key Ss and the master key Kab specifying the users A and B is performed by Ss
= Σ j = 1 k Ssj, Kab = Π j = 1 k Kabj so that the number of key management institution devices is divided into k (k is an integer of 2 or more),
5. The key management method according to claim 4, wherein the j-th key management institution manages the divided system secret key Ssj and the divided master key Kabj.
【請求項7】 セッション暗号化鍵を生成する際に、通
信当事者を特定するマスター鍵と日時情報等の時間的な
要素を示すデータとを含むデータでシステム公開鍵を暗
号化することによってセッション暗号化鍵を生成するこ
とを特徴とする請求項1から請求項4までのいずれかに
記載の鍵管理方法。
7. A method for generating a session encryption key by encrypting a system public key with data including a master key specifying a communication party and data indicating a time element such as date and time information. The key management method according to any one of claims 1 to 4, wherein the key management unit generates a key.
【請求項8】 付加データを生成する際に、セッション
鍵を含むデータをセッション暗号化鍵を用いて共通鍵暗
号方法で暗号化することによって付加データを生成する
こと、及びセッション鍵を獲得する際に、付加データを
セッション暗号化鍵を用いて共通鍵暗号方法で復号する
ことによってセッション鍵を獲得することを特徴とする
請求項1から請求項4、請求項7のいずれかに記載の鍵
管理方法。
8. When generating additional data, generating additional data by encrypting data including a session key by a common key encryption method using a session encryption key, and obtaining the session key. 8. The key management according to claim 1, wherein a session key is obtained by decrypting the additional data by a common key encryption method using the session encryption key. Method.
【請求項9】 送信側ユーザ装置が付加データの正当性
を示すチェックサムを付加データに付加し、受信側ユー
ザ装置が受信した付加データが正しい情報であるかをそ
のチェックサムを用いて検証することを特徴とする請求
項1から請求項6までのいずれかに記載の鍵管理方法。
9. The transmitting user equipment adds a checksum indicating the validity of the additional data to the additional data, and verifies whether the additional data received by the receiving user equipment is correct information using the checksum. The key management method according to any one of claims 1 to 6, wherein:
【請求項10】 疑似セッション暗号化鍵から乱数デー
タを消去する際に、システム秘密鍵及びシステム公開鍵
を用いて公開鍵暗号方法を利用することによって疑似セ
ッション暗号化鍵から乱数データを消去することを特徴
とする請求項1から請求項5、請求項7から請求項9の
いずれかに記載の鍵管理方法。
10. When erasing random number data from a pseudo session encryption key, erasing the random number data from the pseudo session encryption key by using a public key encryption method using a system secret key and a system public key. The key management method according to any one of claims 1 to 5, and 7 to 9.
【請求項11】 暗号通信システムにおけるメッセージ
の暗号通信に利用するセッション鍵を管理する鍵管理シ
ステムにおいて、 ユーザ装置には、 セッション鍵を設定するセッション鍵生成手段と、 通信当事者を特定するマスター鍵を生成するマスター鍵
生成手段と、 日時情報等の時間的要素を示すデータを管理する日時管
理手段と、 セッション暗号化鍵を生成するセッション暗号化鍵生成
手段と、 付加データを生成する付加データ生成手段と、 付加データからセッション鍵を獲得するセッション鍵獲
得手段と、 暗号通信を行うための暗号手段と、 を備え、 鍵管理機関装置には、 システム公開鍵及びシステム秘密鍵、ユーザ公開情報及
びユーザ秘密情報またはマスター鍵を生成する情報生成
手段と、 システム秘密鍵を登録管理するシステム秘密鍵管理デー
タベースと、 ユーザ秘密情報またはマスター鍵を登録管理するユーザ
秘密情報管理データベースと、 乱数データを生成する乱数データ生成手段と、 執行機関装置に対して提供する疑似マスター鍵を生成す
る疑似マスター鍵生成手段と、 疑似セッション暗号化鍵から乱数データを消去する乱数
データ消去手段と、を備え、 執行機関装置には、 暗号文及び付加データを蓄積しておく蓄積手段と、 疑似セッション暗号化鍵を生成する疑似セッション暗号
化鍵生成手段と、 セッション暗号化鍵を再構成するセッション暗号化鍵再
構成手段と、 セッション鍵を獲得する解析手段と、 を備えることを特徴とする鍵管理システム。
11. A key management system for managing a session key used for encrypting a message in a cryptographic communication system, wherein the user device includes: a session key generating means for setting a session key; and a master key for specifying a communication party. Master key generation means for generating, date and time management means for managing data indicating time elements such as date and time information, session encryption key generation means for generating a session encryption key, and additional data generation means for generating additional data And a session key obtaining means for obtaining a session key from the additional data; and an encryption means for performing cryptographic communication. The key management authority device includes a system public key and a system secret key, a user public information and a user secret. An information generating means for generating information or a master key, and a system for registering and managing a system secret key. Secret key management database, a user secret information management database for registering and managing user secret information or a master key, random number data generating means for generating random number data, and a pseudo master key for generating a pseudo master key to be provided to an enforcement agency device A master key generating unit; and a random number data erasing unit for erasing random number data from the pseudo session encryption key. The execution unit includes a storage unit for storing cipher text and additional data, and a pseudo session encryption. A key management system comprising: a pseudo session encryption key generation unit that generates a key; a session encryption key reconfiguration unit that reconfigures a session encryption key; and an analysis unit that obtains a session key.
JP9003644A 1997-01-13 1997-01-13 Key management method and system Pending JPH10200520A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP9003644A JPH10200520A (en) 1997-01-13 1997-01-13 Key management method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP9003644A JPH10200520A (en) 1997-01-13 1997-01-13 Key management method and system

Publications (1)

Publication Number Publication Date
JPH10200520A true JPH10200520A (en) 1998-07-31

Family

ID=11563199

Family Applications (1)

Application Number Title Priority Date Filing Date
JP9003644A Pending JPH10200520A (en) 1997-01-13 1997-01-13 Key management method and system

Country Status (1)

Country Link
JP (1) JPH10200520A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003110546A (en) * 2001-09-29 2003-04-11 Toshiba Corp Receiving data processing apparatus and method
US8660264B2 (en) 1999-01-11 2014-02-25 Certicom Corp. Method and apparatus for minimizing differential power attacks on processors
DE102023120112B3 (en) 2023-07-28 2025-01-16 Utimaco IS GmbH Transmitting payload information that includes key information

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8660264B2 (en) 1999-01-11 2014-02-25 Certicom Corp. Method and apparatus for minimizing differential power attacks on processors
US8666063B2 (en) 1999-01-11 2014-03-04 Certicom Corp. Method and apparatus for minimizing differential power attacks on processors
US8666070B2 (en) 1999-01-11 2014-03-04 Certicom Corp. Method and apparatus for minimizing differential power attacks on processors
JP2003110546A (en) * 2001-09-29 2003-04-11 Toshiba Corp Receiving data processing apparatus and method
DE102023120112B3 (en) 2023-07-28 2025-01-16 Utimaco IS GmbH Transmitting payload information that includes key information

Similar Documents

Publication Publication Date Title
CA2197915C (en) Cryptographic key recovery system
US5481613A (en) Computer network cryptographic key distribution system
US6483920B2 (en) Key recovery process used for strong encryption of messages
US9704159B2 (en) Purchase transaction system with encrypted transaction information
US5956403A (en) System and method for access field verification
CN115242555A (en) A supervised cross-chain privacy data sharing method and device
JP5944437B2 (en) Efficient technology to achieve secure transactions using tamper resistant tokens
KR20010067966A (en) System and method of software-based commercial key escrow for pki environment
Kroll et al. Secure protocols for accountable warrant execution
EP4165851A1 (en) Distributed anonymized compliant encryption management system
KR20050065978A (en) Method for sending and receiving using encryption/decryption key
US20090271627A1 (en) Secure Data Transmission
Gennaro et al. Two-phase cryptographic key recovery system
Prabhu et al. Security in computer networks and distributed systems
JPH10200520A (en) Key management method and system
CN117254906A (en) A public key encryption method that supports two-way access control and accountability
CN110474873B (en) A method and system for electronic file access control based on informed range encryption
JPH10276184A (en) Key management method
Gennaro et al. Secure key recovery
KR100377196B1 (en) System and method for key recovery using multiple agents
US12261946B2 (en) System and method of creating symmetric keys using elliptic curve cryptography
KR100337637B1 (en) Method for recovering a digital document encrypted
JPH11215116A (en) Key management method and system
EP4195590A1 (en) Secure data transmission
JPH1188315A (en) Key management method and program recording medium