JPS6182546A - secret communication method - Google Patents
secret communication methodInfo
- Publication number
- JPS6182546A JPS6182546A JP59205059A JP20505984A JPS6182546A JP S6182546 A JPS6182546 A JP S6182546A JP 59205059 A JP59205059 A JP 59205059A JP 20505984 A JP20505984 A JP 20505984A JP S6182546 A JPS6182546 A JP S6182546A
- Authority
- JP
- Japan
- Prior art keywords
- key
- encryption
- information processing
- information
- information processor
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
Abstract
Description
【発明の詳細な説明】
〔発明の利用分野〕
本発明は秘密通信方式に係り、詳し・くけ、この種秘密
通信方式に用いられる暗号鍵の管理法に関する。DETAILED DESCRIPTION OF THE INVENTION [Field of Application of the Invention] The present invention relates to a secret communication system, and more particularly, to a method for managing cryptographic keys used in this type of secret communication system.
コンピュータシステムを通信網を介し、て結ぶコンピュ
ータ・ネットワーク・システムの進展により、ネットワ
ーク上での情報の機密保護の必要性が増大している。情
報の機密保護手段としては暗号化方式が有効であり、従
来1通信文の暗号化を複雑にする暗号アルゴリズムに関
し、では種々提案されている(例えば特公昭54−35
441号。With the development of computer network systems that connect computer systems via communication networks, the need to protect the confidentiality of information on networks has increased. Encryption methods are effective as a means of protecting the confidentiality of information, and various cryptographic algorithms have been proposed to complicate the encryption of one message (for example, Japanese Patent Publication No. 54-35
No. 441.
特公昭5/l−30602号参照)。し、かり7、暗号
化を#L雑にすると暗号化に要するオーバヘッドが増大
し、現実問題としてハードウェア、ソフトウェアの仕掛
けも大きくなり、コストも多大となる。(See Special Publication No. 5/1-30602). However, if the encryption is #L coarse, the overhead required for encryption will increase, and as a practical matter, the hardware and software devices will also become larger, and the cost will also increase.
従って、暗号化アルゴリズムは適度な複雑さにとどめ、
しかも情報の8!密保護が保証される秘密通信方式の実
現が望まれている。Therefore, the encryption algorithm should be kept to a moderate level of complexity.
And 8 pieces of information! It is desired to realize a secret communication method that guarantees confidentiality.
本発明の目的は、暗号化アルゴリズムをあまり複雑にし
なくとも情報の機密保護が達成される実現性の高い秘密
通信方式を提供することにある。SUMMARY OF THE INVENTION An object of the present invention is to provide a highly practical secret communication method that can achieve information security without making the encryption algorithm too complicated.
暗号化の有効性は、暗号化された情報が第3者に解読き
狛ろまでに、正当な利用者が所期の目的を達成する二と
にある。これを実現するには二つの方式があり、第1は
暗号化アルゴリズムを複雑にすることであり、第2は暗
号鍵を頻繁に変更することである。本発明は第2の方式
に着目し、暗号鍵を鍵管理センタで総括的に管理して、
ホストシステムに対する暗号鍵の送達頻度、鍵変更等の
バリエーションを容易に実現するものである。The effectiveness of encryption lies in the fact that a legitimate user can achieve the intended purpose before the encrypted information can be decoded by a third party. There are two ways to achieve this: the first is to make the encryption algorithm more complex, and the second is to frequently change the encryption key. The present invention focuses on the second method, and comprehensively manages encryption keys at a key management center.
This makes it easy to realize variations in the frequency of sending encryption keys to the host system, key changes, etc.
以下1図面を参照して本発明の一実施例を詳細に説明す
る−
第1図は本発明の一実施例の全体構成を示す。An embodiment of the present invention will be described in detail below with reference to one drawing. FIG. 1 shows the overall configuration of an embodiment of the present invention.
第1図において、情報処理装置10は通信回線20を通
して端末装置あるいは別の情報処理袋@30(以下、端
末¥!置とする)と結ばれている。情報処理装置10に
は暗号復号化部11があり、端末装置30にも暗号復号
化部31がある。情報処理装置10は、さらに通信回線
40により@管理センタ50と結ばれている。ここで、
鍵管理センタ50か本発明の中心をなし、@テーブル格
納部51、鍵決定部52.鍵送達部53よりなる。In FIG. 1, an information processing device 10 is connected to a terminal device or another information processing bag @30 (hereinafter referred to as a terminal) through a communication line 20. The information processing device 10 includes an encryption/decryption unit 11, and the terminal device 30 also includes an encryption/decryption unit 31. The information processing device 10 is further connected to an @management center 50 via a communication line 40. here,
The key management center 50 is the center of the present invention, and includes @table storage section 51, key determination section 52. It consists of a key delivery unit 53.
簡管理センタ50の健テーブル格納部51には鍵テーブ
ルが格納されており、そのうちの任意の鍵が鍵決定部5
2で決定され、鍵送達部53によって情報処理装置lO
に送達される。鍵送達部53は1例えば情報処理装置1
0に対して通信文1甲1位又は複数単位毎に鍵を送達す
る。情報処理装置10では、鍵管理センタ50から送達
された鍵を暗号復号15部11に保持すると共に、端末
装置30との暗号化同期をとるため通信回線20を介し
て当該鍵を端末装置30に送達する。端末装置30は、
該送達された鍵を暗号復号化部31に保持するにれによ
り、情報処理装置lOと端末装置30の間での暗号化の
プロトコルが確立される、第1図では、この鍵の送達経
路を破線で示している。A key table is stored in the health table storage unit 51 of the simple management center 50, and any key among them is stored in the key determination unit 5.
2, and the key delivery unit 53 sends the information processing device lO
delivered to. The key delivery unit 53 is 1, for example, information processing device 1
Deliver the key to 0 for each message 1A 1st place or multiple units. In the information processing device 10, the key delivered from the key management center 50 is held in the encryption/decryption unit 11, and the key is transferred to the terminal device 30 via the communication line 20 in order to synchronize the encryption with the terminal device 30. Deliver. The terminal device 30 is
By retaining the delivered key in the encryption/decryption unit 31, an encryption protocol is established between the information processing device IO and the terminal device 30. In FIG. 1, the delivery route of this key is shown. Indicated by a broken line.
ここで、鍵管理センタ50では、鍵テーブル格納部51
に鍵のバリエーション、鍵決定部52に鍵選択のバ11
ニージョン、鍵送達部53で鍵送達頻度などの変更バリ
エーションを持たせることに辷り コンピュータ・ネッ
トワーク・システム全体の総合的、総括的な鍵送達虞令
を行うことができる
次に、鍵管理センタ50の動作を具体例で説明すし
第2図は情報処理装置10と端末装置3oの間で相互に
送受fコさする通信文を示す。通信文M、。Here, in the key management center 50, the key table storage section 51
The key variations are displayed in the key selection section 52, and the key selection bar 11 is displayed in the key determination section 52.
The key management center 50 is able to issue comprehensive and comprehensive key delivery instructions for the entire computer network system. The operation will be explained using a specific example, and FIG. 2 shows communications sent and received between the information processing device 10 and the terminal device 3o. Correspondence M.
け任意の複数文字列からなる。第2図では、A〜F (
1’+ 5文字からなるどしている。文字の先頭はそI
Iぞt17トレス(=Iけ(第2図ではa −e )さ
れている7第3図は鍵番号とそれに対応する姉内容がt
′If)、ろ鍵テーブルK。を示し、でいる。第3図に
おいて、例えば鍵番号1(K、)はアドレスbの文字を
通信文の先頭にすることを示している。consists of any number of character strings. In Figure 2, A to F (
It consists of 1' + 5 characters. The first character is I
In Figure 3, the key number and its corresponding sister content are t.
′If), the key table K. It shows and is. In FIG. 3, for example, key number 1 (K,) indicates that the character at address b is to be placed at the beginning of the message.
惟テーブルl(1,は鍵管理センタ5oの鍵テーブル(
各柄部51に格納されており、鍵番号及びそれに対、j
、:する清内容は任意に選択して変更することか可(1
ヒである一世テーブルK。は鍵決定部52に1ηI゛・
fl こ:て乱数による方法や利用者による指定へ゛
」パに上り任膚:の鍵番号が決定される。鍵決定部52
で決定された鍵番号は鍵内容と共に鍵送達部53に送ら
れる。鍵送達部53では、′@番号と鍵内容を情報処理
装置10の暗号復号化部11、及び該暗号復号化部11
、通信回線2oを介して端末装置1!730の暗号復号
化部21に送達するが。The table l (1, is the key table of the key management center 5o (
It is stored in each handle part 51, and the key number and its counterpart, j
,: You can arbitrarily select and change the content to be used (1
Issei Table K who is Hi. is given to the key determination unit 52 as 1ηI゛・
The key number for fl is determined by a method using random numbers or by a method specified by the user. Key determination unit 52
The key number determined in is sent to the key delivery unit 53 together with the key contents. The key delivery unit 53 sends the '@ number and the key content to the encryption/decryption unit 11 of the information processing device 10 and the encryption/decryption unit 11.
, is delivered to the encryption/decryption unit 21 of the terminal device 1!730 via the communication line 2o.
、二の時、暗号復号部1、31の間での暗号同期をとる
ため、鍵番号に同期符号を付加して送達する。同期符号
には1例えば通信文の通番や時刻を用いる。, 2, in order to achieve cryptographic synchronization between the encryption/decryption units 1 and 31, a synchronization code is added to the key number and delivered. For example, the serial number or time of the message is used as the synchronization code.
情報処理装置10から端末装置3oに通信文M、を送る
とした場合、暗号化復号化部11では鍵送遠部53から
B番号に、鍵内容すが送達さ、lすると 情報処理装置
10で処理された第2図のj、]信文M、を第4図のM
、に変換し、て端末装置30に送る。一方、端末装置3
oの暗号復号化部31では、送られてきたM、を元のM
l、に変換する、な、む、第3図に示す俳テーブルは甲
なる一例にすぎず1種々のバリエーションが考えられる
ことけ云うまでもない。又、鍵テーブルを予め情報処理
装置10や端末装置30の暗号復号化部11゜3Iに与
えておくようにすると5鍵管理センタ50は鍵番号と同
期符号を送達するだけでよく、鍵内容の送達が省略でき
る。When a message M is sent from the information processing device 10 to the terminal device 3o, the encryption/decryption section 11 sends the key contents from the key sending section 53 to the B number. The processed message j in Figure 2, ] message M, is converted to M in Figure 4.
, and sends it to the terminal device 30. On the other hand, terminal device 3
The decryption unit 31 of o converts the sent M to the original M.
The haiku table shown in FIG. 3 is only one example, and it goes without saying that various variations can be considered. Furthermore, if the key table is given in advance to the encryption/decryption unit 11゜3I of the information processing device 10 or the terminal device 30, the 5-key management center 50 only needs to send the key number and the synchronization code, and the key contents can be Delivery can be omitted.
本発明によれば、暗号鍵を鍵管理センタで集中的に管理
するため、鍵の送達頻度、鍵変更等の任意のバリニーシ
コンが容易であり、暗号化アルゴリズムを複雑化するこ
となく、情報の機密保護が達成される。According to the present invention, since encryption keys are centrally managed in a key management center, arbitrary changes such as key delivery frequency and key changes can be easily made, and information can be kept confidential without complicating the encryption algorithm. Protection is achieved.
第1図は本発明の一実施例の全体構成図、第2図は通信
文の一例を示す図、第3図は鍵テーブルの一例を示す図
、第4図は暗号化された通信文の一例を示す図である。
lO・・・情報処理装置、 20・・・通信回線。
30・・・端末装置又は情報処理装置。
50・・・鍵管理センタ。
第1図
第2図 第3図
第4図 ・FIG. 1 is an overall configuration diagram of an embodiment of the present invention, FIG. 2 is a diagram showing an example of a message, FIG. 3 is a diagram showing an example of a key table, and FIG. 4 is a diagram of an encrypted message. It is a figure showing an example. IO...information processing device, 20...communication line. 30...Terminal device or information processing device. 50...Key management center. Figure 1 Figure 2 Figure 3 Figure 4 ・
Claims (1)
装置間でデータ伝送を行うコンピュータ・ネットワーク
・システムにおいて、情報の暗号化を指示する鍵(以下
、暗号鍵という)を管理する鍵管理センタを前記情報処
理装置とは別個に設置し、前記鍵管理センタより任意の
鍵を或る情報処理装置に送達し、該送達を受けた情報処
理装置は当該鍵を保持すると共に通信回線を通して相手
装置に伝送し、両処理装置間で情報暗号化のプロトルコ
を確立することを特徴とする秘密通信方式。(1) In a computer network system that connects information processing devices through communication lines and transmits data between the information processing devices, a key management center that manages keys that instruct the encryption of information (hereinafter referred to as encryption keys) It is installed separately from the information processing device, and the key management center delivers an arbitrary key to a certain information processing device, and the information processing device that receives the delivery holds the key and sends it to the other device through a communication line. A secret communication method characterized by establishing an information encryption protocol between both processing devices.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP59205059A JPS6182546A (en) | 1984-09-29 | 1984-09-29 | secret communication method |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP59205059A JPS6182546A (en) | 1984-09-29 | 1984-09-29 | secret communication method |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JPS6182546A true JPS6182546A (en) | 1986-04-26 |
Family
ID=16500752
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP59205059A Pending JPS6182546A (en) | 1984-09-29 | 1984-09-29 | secret communication method |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPS6182546A (en) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5161186A (en) * | 1991-09-06 | 1992-11-03 | International Business Machines Corporation | System for secure and private communication in a triple-connected network |
| JP2006163951A (en) * | 2004-12-08 | 2006-06-22 | Kobe Univ | Digital content management system and management method thereof |
| JP2007293443A (en) * | 2006-04-21 | 2007-11-08 | Hitachi Ltd | Electronic tag system and data processing method performed by electronic tag system |
-
1984
- 1984-09-29 JP JP59205059A patent/JPS6182546A/en active Pending
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5161186A (en) * | 1991-09-06 | 1992-11-03 | International Business Machines Corporation | System for secure and private communication in a triple-connected network |
| JP2006163951A (en) * | 2004-12-08 | 2006-06-22 | Kobe Univ | Digital content management system and management method thereof |
| JP2007293443A (en) * | 2006-04-21 | 2007-11-08 | Hitachi Ltd | Electronic tag system and data processing method performed by electronic tag system |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US6169805B1 (en) | System and method of operation for providing user's security on-demand over insecure networks | |
| US6292895B1 (en) | Public key cryptosystem with roaming user capability | |
| EP0687087B1 (en) | Secure data transmission method | |
| US20200382176A1 (en) | Secure end-to-end transport through intermediary nodes | |
| US20100195824A1 (en) | Method and Apparatus for Dynamic Generation of Symmetric Encryption Keys and Exchange of Dynamic Symmetric Key Infrastructure | |
| CN1327662A (en) | Method and device for securely distributing public/secret key pairs | |
| JPH06266670A (en) | Ciphering virtual terminal initialization device | |
| JP2725478B2 (en) | Encryption key distribution method | |
| JPH04297157A (en) | Data ciphering device | |
| JPH10171717A (en) | IC card and cryptographic communication system using the same | |
| JPH11136234A (en) | User authentication system and user authentication method | |
| US7031469B2 (en) | Optimized enveloping via key reuse | |
| JPH10107832A (en) | Cipher multi-address mail system | |
| JPH0983509A (en) | Cryptographic communication method and apparatus | |
| JP2002539489A (en) | Voice and data encryption method using encryption key split combiner | |
| KR20000072516A (en) | end-to-end data encryption/decryption method and device for mobile data communication | |
| JPS6182547A (en) | secret communication method | |
| JPH0777933A (en) | Network data encryption device | |
| JPH0373633A (en) | Cryptographic communication system | |
| JPH0993242A (en) | Data transmitter-receiver | |
| JPS6231231A (en) | Password collating system | |
| JPH02122745A (en) | System and device for managing cryptographic key | |
| JP2000231523A (en) | Electronic mail system | |
| JP2003309544A (en) | Cipher key delivery apparatus | |
| JPH09326789A (en) | Partner authentication method and system in communication between portable wireless terminals |