JPS603242A - Ciphering communication system - Google Patents

Ciphering communication system

Info

Publication number
JPS603242A
JPS603242A JP58110681A JP11068183A JPS603242A JP S603242 A JPS603242 A JP S603242A JP 58110681 A JP58110681 A JP 58110681A JP 11068183 A JP11068183 A JP 11068183A JP S603242 A JPS603242 A JP S603242A
Authority
JP
Japan
Prior art keywords
frame
key
encryption
communication
extracts
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP58110681A
Other languages
Japanese (ja)
Other versions
JPH0151107B2 (en
Inventor
Katsuhiro Oki
大木 勝博
Tetsuya Mori
哲也 森
Kumiko Segawa
瀬川 久美子
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fujitsu Ltd
Original Assignee
Fujitsu Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Fujitsu Ltd filed Critical Fujitsu Ltd
Priority to JP58110681A priority Critical patent/JPS603242A/en
Publication of JPS603242A publication Critical patent/JPS603242A/en
Publication of JPH0151107B2 publication Critical patent/JPH0151107B2/ja
Granted legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04KSECRET COMMUNICATION; JAMMING OF COMMUNICATION
    • H04K1/00Secret communication

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)

Abstract

PURPOSE:To improve the degree of confidentiality of cipher and to attain ease of management of a key by preserving the number of keys for ciphering the same as the number of frames and designating a key depending on the frame number used for communication. CONSTITUTION:A communication controller 4 detects a signal burst at a communication control section 7, a synchronizing detection section 8 detects an idle frame and identifies the frame number of the idle frame. A key management section 9 extracts the key of the frame number and transmits it to a ciphering/ decoding circuit 10. A transmitted message from a terminal processor 5 is formed into a ciphered message at the ciphering/decoding circuit 10 by using the key. Further, this ciphered message is inserted in the idle frame while being added with an own station identification number, an opposite station identification number and a control code, and the result is transmitted to a communication line CC.

Description

【発明の詳細な説明】 〔発明の技術分野〕 本発明は暗号文を使用して多重化通信を行う場合におい
て、暗号文を作成するときの暗号をフレーム順−位毎に
管理することにより多数の装置との間でデータ通信を行
うときでも少数の暗号文により機密保持を行うことがで
きるようにした暗号通信方式に関するものである。
[Detailed Description of the Invention] [Technical Field of the Invention] When performing multiplex communication using ciphertext, the present invention manages multiple ciphers for each frame order when creating ciphertext. The present invention relates to an encrypted communication method that can maintain confidentiality using a small number of ciphertexts even when data is communicated with other devices.

〔従来技術と問題点〕[Conventional technology and problems]

データ通信において、その通信内容が盗用されることを
防止するため9通信文を暗号化して機密保持することが
行われている。このような暗号化方式を9例えば1つの
ホストと多数の端末との間でデータを多重通信する場合
に適用するとき、ネットワーク全体で1つの暗号を使用
する場合と。
In data communications, messages are encrypted to maintain confidentiality in order to prevent the contents of the communications from being stolen. For example, when such an encryption method is applied to multiplex communication of data between one host and a large number of terminals, one cipher is used for the entire network.

ホストと端末間の通信文を端末度に用意された暗号を使
用する方式がある。しかし前者は暗号化及び復号化のた
めのキイをネットワークとして】つだけ使用するために
解読され易く、シたがって暗号強度が低いという欠点が
あり、また後者は相手数だけキイを設定してこれを使用
しなければならないので相手端末が増加する等システム
が変更するときこれに応じてキイを作成する必要があり
システムの変更が容易ではなく、シかも相手数が多数で
あればある程その数だけキイを管理しなければならず、
したがってキイの管理が容易ではないという欠点が存在
する。
There is a method that uses a cipher prepared for each terminal in the communication between the host and the terminal. However, the former method uses only one key for encryption and decryption as a network, so it is easily decrypted and therefore has low encryption strength. Therefore, when the system changes, such as when the number of partner terminals increases, it is necessary to create keys accordingly, and it is not easy to change the system. only have to manage the keys,
Therefore, there is a drawback that key management is not easy.

〔発明の目的〕[Purpose of the invention]

本発明の目的は上記欠点を解決するためにフレーム毎に
暗号化・復号化のためのキイを決定することにより、暗
号強度を高めるとともに、かつキイの管理を容易にした
暗号通信方式を提供することである。
The purpose of the present invention is to solve the above-mentioned drawbacks by determining a key for encryption/decryption for each frame, thereby increasing encryption strength and providing an encrypted communication method that facilitates key management. That's true.

〔発明の構成〕[Structure of the invention]

この目的を達成するため、本発明の暗号通信方式では、
多取化通信ネットワークシステムに適用するデータ通信
暗号装置において9通信文のフレーム順位毎に使用する
複数の暗号キイを保持しフレーム順位に応じて暗号キイ
を抽出する暗号キイ管理部と、送信に使用する空きフレ
ーム順位及び受信文が位置しているフレーム順位を検出
する同期検出部と、これらのフレーム順位により必要と
する暗号キイにより送信文を暗号化したり、受信文を復
号化する暗号・復号部を設け、送信のときは空きフレー
ムを検出してそのフレーム順位によりキイを抽出して送
信文を暗号化するとともに受信のときは受信文のフレー
ム順位によりキイを抽出して受信文を解読するようにし
たことを特徴とする。
In order to achieve this objective, the encrypted communication method of the present invention:
A data communication cryptographic device applied to a multi-transmission communication network system includes a cryptographic key management unit that holds a plurality of cryptographic keys to be used for each frame rank of nine messages and extracts cryptographic keys according to the frame rank, and a cryptographic key management unit used for transmission. a synchronization detection unit that detects the empty frame order and the frame order in which the received text is located, and an encryption/decryption unit that encrypts the transmitted text and decrypts the received text using the encryption key required according to these frame orders. is set up, and when transmitting, it detects an empty frame and extracts a key according to the frame order to encrypt the transmitted text, and when receiving, it extracts a key according to the frame order of the received text and decrypts the received text. It is characterized by the following.

〔発明の実施例〕[Embodiments of the invention]

本発明を一実施例にもとづき詳述するに先立ち。 Before describing the present invention in detail based on one embodiment.

第3図によりその概略を説明する。The outline will be explained with reference to FIG.

多重通信の場合には、第31図(イ)に示す如く、信号
バースト・ユニッ) BUは先頭に同期制御コードSY
Cが位置しそれから複数のフレームFO。
In the case of multiplex communication, as shown in Figure 31 (a), the signal burst unit (BU) has a synchronization control code SY
C is located and then multiple frames FO.

Fl・・・Fnカ位置している。本発明では、このフレ
ームFO,Fl・・・Fnにおける通信文を暗号化する
ときに使用するキイを、フレームFO−Fnの番号毎に
定めておく。したがって送信時に空きフレームを検出し
たときその空きフレームのフレーム番号により使用すべ
きキイが特定されることになる。また、第3図(ロ)に
おける自局識別番号DAを解読して自局あての通信文を
受信したとき、そのフレーム番号により暗号キイが定ま
って、いるので。
Fl...Fn are located. In the present invention, keys to be used when encrypting messages in frames FO, Fl, . . . , Fn are determined for each number of frames FO to Fn. Therefore, when an empty frame is detected during transmission, the key to be used is specified based on the frame number of the empty frame. Furthermore, when the own station identification number DA in Fig. 3(b) is decoded and a message addressed to the own station is received, the encryption key is determined by the frame number.

この暗号キイを使用して受信文を解読することができる
。このように構成することにより受信端末装置が多数の
場合でも、暗号キイの数はフレーム数により限定されて
いるので、端末装置を増設してもキイ数が増加すること
はない0 次に本発明の一実施例を第1図及び第2図にもとづき、
第3図を参照しつつ説明する。
This encryption key can be used to decrypt the received text. With this configuration, even if there are a large number of receiving terminal devices, the number of encryption keys is limited by the number of frames, so even if more terminal devices are added, the number of keys will not increase.Next, the present invention Based on an example of FIG. 1 and FIG. 2,
This will be explained with reference to FIG.

第1図は本発明の暗号通信方式を使用したシステム構成
図、第2図はその通信制御装置及び暗号装置の詳細図で
ある。
FIG. 1 is a system configuration diagram using the cryptographic communication system of the present invention, and FIG. 2 is a detailed diagram of the communication control device and cryptographic device.

図中、1はホスト処理装・置、2は通信制御装置。In the figure, 1 is a host processing device/device, and 2 is a communication control device.

3は暗号装置、4.4−0・・・4−Nは通信制御装置
3 is an encryption device, and 4.4-0...4-N is a communication control device.

5.5−0・・・5−Nは端末処理装置、6.6−0・
・・6−Nは暗号装置、7は通信制御部、8は同期検出
部。
5.5-0...5-N is a terminal processing device, 6.6-0...
... 6-N is an encryption device, 7 is a communication control unit, and 8 is a synchronization detection unit.

9はキイ管理部、10は暗号・復号回路である。9 is a key management section, and 10 is an encryption/decryption circuit.

まず1本発明における特徴的構成を有する通信制御装置
及び暗号装置は親局Mおよび端末局S。
First, a communication control device and an encryption device having a characteristic configuration according to the present invention are a master station M and a terminal station S.

・・・SNにおいていずれも同一構成であるので、第2
図により説明する。
...Since they all have the same configuration in SN, the second
This will be explained using figures.

通信制御装置4には通信制御部7.同期検出部8が設け
られている。通信制御部7は親局Mもしくは子局SO〜
8Nより通信回線に対してデータを送出したり、あるい
は通信回線よりデータを受信するための各種制御を行う
ものであり、マルチフレームの信号パース)BUが伝達
されたときこれを受信して同期検出部8に送出するもの
である。
The communication control device 4 includes a communication control section 7. A synchronization detection section 8 is provided. The communication control unit 7 is connected to the master station M or the slave station SO~
It performs various controls for sending data from the 8N to the communication line or receiving data from the communication line, and synchronization is detected by receiving the multi-frame signal parse (BU) when it is transmitted. This is what is sent to section 8.

同期検出部8はこの信号パース)BUが伝達すれたとき
、その先頭の同期制御コード5YCr二より同期をとり
、それからこれを構成しているフレームを読取りそのフ
レーム番号を認識するものである。
When this signal parse) BU is transmitted, the synchronization detecting section 8 synchronizes from the synchronization control code 5YCr2 at the head thereof, and then reads the frames constituting this and recognizes the frame number.

暗号装置6は暗号の作成および解読のために必要なキイ
を少くともそのフレーム数保持するとともにこのキイに
より送信文を暗号化したり受信文を復号するものであり
、そのために暗号用のフレーム番号毎のキイを保持する
キイ管理部9や暗号文を作成したり復号する暗号・復号
回路10を有するものである。
The encryption device 6 stores keys necessary for creating and decoding codes for at least the same number of frames, and uses these keys to encrypt transmitted texts and decrypt received texts. It has a key management unit 9 that holds keys, and an encryption/decryption circuit 10 that creates and decrypts ciphertext.

以下本発明の動作について説明する。The operation of the present invention will be explained below.

(1)暗号文を送信するとき 例えば子局SOからSNに対してデータを送信するとき
、子局SOの通信制御装置4−0は、親局Mより各子局
8O−8Nに送出された信号バーストをその通信制御部
7で検出し、同期検出部8にてその空きフレーム、例え
ばフレームF1を検出する。これにより空きフレームの
フレーム番号が1であることを識別して、キイ管理部9
はそのフレーム番号1のキイを取出し、これを暗号・復
号回路10に送出する。そして端末処理装置5−0から
伝達された送出文をこのキイにより暗号・復号回路JO
において暗号−文に作成する。そしてこの暗号文を、第
3図(ロ)に示す如く、自局識別番号DAと、送信先で
ある相手局識別番号SA及び制御コードCを付加してフ
レームを完成した上で。
(1) When transmitting ciphertext For example, when transmitting data from slave station SO to SN, communication control device 4-0 of slave station SO transmits data from master station M to each slave station 8O-8N. The communication control section 7 detects the signal burst, and the synchronization detection section 8 detects the empty frame, for example, frame F1. As a result, the frame number of the empty frame is identified as 1, and the key management unit 9
extracts the key of frame number 1 and sends it to the encryption/decryption circuit 10. Then, using this key, the transmission text transmitted from the terminal processing device 5-0 is sent to the encryption/decryption circuit JO.
Create a ciphertext at Then, as shown in FIG. 3 (b), this ciphertext is added with the own station identification number DA, the destination station identification number SA, and the control code C to complete the frame.

空きフレームに挿入し、これを通信回線CCに送出する
It is inserted into an empty frame and sent to the communication line CC.

(2) この信号は一度親局Mでキャッチされた上で親
局Mよりマルチフレームの信号パース)BUがまとめら
れて各子局に送出されることになる。このとき子局8N
は各フレームの相手局識別番号SAを同期検出部8でサ
ーチして、これに子局SNが記入されていたとき、その
フレーム番号を検出し、これによりキイ管理部9よりキ
イを抽出し、これにもとづき暗号・復号回路1oにおい
て送信文を解読して復号し、これにもとづき自己の端末
処理装置5−Nでデータ処理を行うことになる0 〔発明の効果〕 本発明では、暗号装置が暗号化あるいは復号化のための
キイをフレーム数と同数保有し9通信に使用するフレー
ム番号でキイを決定するようにしたので9個別通信つま
りフレーム毎にそれぞれ別のキイを使用して安全に暗号
化して通信を行うことができるとともに、相手別にはキ
イの管理を行わないので、システムの変更、つまり端末
装置の追加・減少やキイの変更等にも容易に対処するこ
とができる。
(2) This signal is once caught by the master station M, and then the master station M parses the multi-frame signal (BU) and sends it out to each slave station. At this time, slave station 8N
searches the partner station identification number SA of each frame in the synchronization detection section 8, and when the slave station SN is written therein, detects the frame number, and extracts the key from the key management section 9 based on this, Based on this, the transmitted text is deciphered and decrypted in the encryption/decryption circuit 1o, and data processing is performed on the own terminal processing device 5-N based on this. [Effects of the Invention] In the present invention, the encryption device We have the same number of keys for encryption or decryption as the number of frames, and the key is determined by the frame number used for 9 communications, so a different key is used for each 9 individual communications, that is, each frame, to ensure secure encryption. In addition, since keys are not managed for each party, it is possible to easily deal with changes in the system, such as the addition or reduction of terminal devices or changes in keys.

【図面の簡単な説明】[Brief explanation of the drawing]

第1図は本発明の暗号通信方式を使用したシテム溝成図
、第2図はその通信制御装置及び暗装置の詳細図、第3
図は通信文の構成を示す。 図中、1はホスト処理装置、2は通信制御部3は暗号装
置、4.4−0・・・4−Nは通信制御部5.5−0・
・・5−Nは端末処理装置、6.6−0・・・6−Nは
暗号装置、7は通信制御部、8は同期山部、9はキイ管
理部、10は暗号・復号回路ある。 特許出願人 富−士通株式会社 代理人弁理士 山 谷 晧 榮 第1[21
Fig. 1 is a system diagram using the encrypted communication method of the present invention, Fig. 2 is a detailed diagram of the communication control device and dark device, and Fig. 3
The figure shows the structure of the message. In the figure, 1 is a host processing device, 2 is a communication control unit 3 is an encryption device, and 4.4-0...4-N are communication control units 5.5-0.
...5-N is a terminal processing device, 6.6-0...6-N is an encryption device, 7 is a communication control section, 8 is a synchronization section, 9 is a key management section, and 10 is an encryption/decryption circuit. . Patent applicant Fujitsu Ltd. Representative Patent Attorney Akira Yamatani Eiichi [21

Claims (1)

【特許請求の範囲】[Claims] 多重化通信ネットワークシステムに適用するデータ通信
暗号装置において9通信文のフレーム順位毎(二使用す
る複数の暗号キイを保持しフレーム順位(二応じて暗号
キイを抽出する暗号キイ管理部と、送信に使用する空き
フレーム順位及び受信文が位置しているフレーム順位を
検出する同期検出部と、これらのフレーム順位により必
要とする暗号キイにより送信文を暗号化したり受信文を
復号化する暗号・復号部を設け、−送信のときは空きフ
レームを検出してそのフレーム順位によりキイを抽出し
て送信文を暗号化するとともに受信のときは受信文のフ
レーム順位によりキイを抽出して受信文を解読するよう
にしたことを特徴とする暗号通信方式。
In a data communication cryptographic device applied to a multiplex communication network system, there is a cryptographic key management unit that holds multiple cryptographic keys to be used and extracts cryptographic keys according to the frame rank (2) for each frame order of nine messages, and a cryptographic key management unit that extracts cryptographic keys according to the frame rank (2). A synchronization detection unit that detects the empty frame order to be used and the frame order in which the received text is located, and an encryption/decryption unit that encrypts the transmitted text and decrypts the received text using the encryption key required according to these frame orders. - When transmitting, it detects an empty frame and extracts a key according to the frame order to encrypt the transmitted text, and when receiving, it extracts a key according to the frame order of the received text and decrypts the received text. An encrypted communication method characterized by:
JP58110681A 1983-06-20 1983-06-20 Ciphering communication system Granted JPS603242A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP58110681A JPS603242A (en) 1983-06-20 1983-06-20 Ciphering communication system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP58110681A JPS603242A (en) 1983-06-20 1983-06-20 Ciphering communication system

Publications (2)

Publication Number Publication Date
JPS603242A true JPS603242A (en) 1985-01-09
JPH0151107B2 JPH0151107B2 (en) 1989-11-01

Family

ID=14541750

Family Applications (1)

Application Number Title Priority Date Filing Date
JP58110681A Granted JPS603242A (en) 1983-06-20 1983-06-20 Ciphering communication system

Country Status (1)

Country Link
JP (1) JPS603242A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH02241152A (en) * 1989-03-14 1990-09-25 Kokusai Denshin Denwa Co Ltd <Kdd> Privacy call system

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH02241152A (en) * 1989-03-14 1990-09-25 Kokusai Denshin Denwa Co Ltd <Kdd> Privacy call system

Also Published As

Publication number Publication date
JPH0151107B2 (en) 1989-11-01

Similar Documents

Publication Publication Date Title
US5751813A (en) Use of an encryption server for encrypting messages
US5475757A (en) Secure data transmission method
US4172213A (en) Byte stream selective encryption/decryption device
JP4094216B2 (en) Automatic resynchronization of cryptographic synchronization information
US7284123B2 (en) Secure communication system and method for integrated mobile communication terminals comprising a short-distance communication module
JPH09502845A (en) Key distribution device in encryption system
JPH1022994A (en) Encryption device and decryption device, encryption method and decryption method, and communication system using them
CN105959281A (en) File encrypted transmission method and device
JPH04297157A (en) Data ciphering device
JPH0637750A (en) Information transfer system
CA2226831A1 (en) Decryption of retransmitted data in an encrypted communication system
JPH11136234A (en) User authentication system and user authentication method
JPH10107832A (en) Cipher multi-address mail system
CN101242453B (en) A transmission method and system for dual-audio multi-frequency signal
JP2000059352A (en) Encryption communication system
JPS603242A (en) Ciphering communication system
CN104243291A (en) Instant messaging method and system thereof capable of guaranteeing safety of user communication content
JPH0777933A (en) Network data encryption device
JPS63151136A (en) Privacy communication system
JPH0373633A (en) Cryptographic communication system
JPS6181043A (en) Cipher processing system of packet communication
JPH0646052A (en) Encipherment system in high speed transport mechanism
JPH0993242A (en) Data transmitter-receiver
JPS60102038A (en) Cipher communication system
JPS6182546A (en) secret communication method