JPS6231231A - Password collating system - Google Patents
Password collating systemInfo
- Publication number
- JPS6231231A JPS6231231A JP60171583A JP17158385A JPS6231231A JP S6231231 A JPS6231231 A JP S6231231A JP 60171583 A JP60171583 A JP 60171583A JP 17158385 A JP17158385 A JP 17158385A JP S6231231 A JPS6231231 A JP S6231231A
- Authority
- JP
- Japan
- Prior art keywords
- password
- circuit
- data
- terminal
- ciphered
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000000034 method Methods 0.000 claims abstract description 8
- 238000012795 verification Methods 0.000 claims description 11
- 230000005540 biological transmission Effects 0.000 abstract description 16
- 238000004891 communication Methods 0.000 abstract description 8
- 238000010586 diagram Methods 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 1
- 239000000284 extract Substances 0.000 description 1
Abstract
Description
【発明の詳細な説明】
〔産業上の利用分野〕
本発明は、ディジタルデータ通信網において、データの
機密保護のために使用されるパスワードの照合方式に関
する。DETAILED DESCRIPTION OF THE INVENTION [Field of Industrial Application] The present invention relates to a password verification method used for data security protection in a digital data communication network.
本発明は、相手端末から受信したパスワードを照合して
相手端末を確認して所要のデータを送信するともに、次
回に使用すべきパスワードを決定し、これを暗号化して
送出することにより、相手端末に通知し、使用の度毎に
パスワードを変化させるようにして、
パスワードの盗聴を防止し、データの秘密を確実に保護
することかで−きる方式を提供するものである。The present invention verifies the password received from the other party's terminal, confirms the other party's terminal, transmits the required data, determines the password to be used next time, encrypts it, and sends it to the other party's terminal. This provides a method that can prevent password eavesdropping and reliably protect the confidentiality of data by notifying the user and changing the password each time it is used.
従来のパスワード照合方式は、単にあらかじめパスワー
ドを定めておいて、同一のパスワードを暗号化せずにそ
のまま繰返し使用するだけである。Conventional password verification methods simply determine a password in advance and use the same password repeatedly without encrypting it.
したがって、万一データ通信網のパスワードが盗聴され
ると、盗聴されたパスワードによってデータが盗まれて
データの機密保護ができなくなる。Therefore, if the password of the data communication network is intercepted, data will be stolen using the intercepted password, making it impossible to protect the security of the data.
本発明は、上述の従来の欠点を解決し、パスワードを固
定しないで、通信の都度変化させることにより第三者に
パスワードが盗聴されることを防止できるパスワード照
合方式を提供する。The present invention solves the above-mentioned conventional drawbacks and provides a password verification method that prevents a third party from eavesdropping on a password by changing the password each time communication is performed without fixing the password.
本発明のパスワード照合方式は、ランダムにパスワード
を発生するパスワード発生回路と、このパスワード発生
回路の出力するパスワードを暗号化するパスワード暗号
化回路と、相手端未刈にパスワードを管理するパスワー
ド管理回路と、受信したパスワードを前記パスワード管
理回路の管理するパスワードと照合するパスワード照合
回路とを備え、相手端末から受信したパスワードが前記
パスワード管理回路の管理するパスワードと一敗したと
きは、所要のデータを送出するととも、前記パスワード
発生回路2からランダムに読出した次回に使用すべきパ
スワードを前記パスワード暗号化回路によって暗号化し
て送出することにより、相手端末に次回に使用すべきパ
スワードを通知するようにして、1通信ごとにパスワー
ドを変化させるようにしている。The password verification method of the present invention includes a password generation circuit that randomly generates passwords, a password encryption circuit that encrypts the password output from this password generation circuit, and a password management circuit that manages passwords at the other end's end. , a password verification circuit that verifies the received password with the password managed by the password management circuit, and when the password received from the other party's terminal fails the password managed by the password management circuit, the required data is transmitted. At the same time, the password to be used next time read out at random from the password generation circuit 2 is encrypted by the password encryption circuit and sent, thereby notifying the other terminal of the password to be used next time, I try to change the password for each communication.
次に、本発明の実施例について図面を参照して説明する
。Next, embodiments of the present invention will be described with reference to the drawings.
図は、本発明の一実施例を示すブロック図である。すな
わち、ランダムにパスワードを発生するパスワード発生
回路2と、パスワード発生回路2の出力するパスワード
を暗号化するパスワード暗号化回路3と、相手端末から
データ送受信回路1が受信したパスワードをパスワード
管理回路4が管理するパスワードと照合するパスワード
照合回路6と、パスワード発生回路2がランダムに発生
したパスワードを相手端未刈にその端末識別符号に対応
させて管理するパスワード管理回路4と、パスワード管
理回路4の管理に使用されるメモリ5と、これらを制御
する中央制御回路7とから構成されている。そして、各
相手端末は、それぞれデータ送受信回路8、暗号化パス
ワード解読回路9、パスワード管理回路10<メモリ1
1およびこれらを制御する中央制御回路12とを備えて
いて、データ送受信回路1から所定のデータとともに送
出され暗号化されたパスワードを、暗号化パスワード解
読回路9によって元のパスワードに復元し、このパスワ
ードをパスワード管理回路10によって管理し、次回の
データ送信許可要求信号を送出する際には、パスワード
管理回路10の管理するパスワードを送出する。The figure is a block diagram showing one embodiment of the present invention. That is, a password generation circuit 2 that randomly generates a password, a password encryption circuit 3 that encrypts the password output from the password generation circuit 2, and a password management circuit 4 that encodes the password received by the data transmission/reception circuit 1 from the other party's terminal. A password verification circuit 6 that matches the password to be managed; a password management circuit 4 that manages the password randomly generated by the password generation circuit 2 in correspondence with the terminal identification code of the other end; and management of the password management circuit 4. It consists of a memory 5 used for this purpose, and a central control circuit 7 that controls these. Each partner terminal has a data transmitting/receiving circuit 8, an encrypted password decoding circuit 9, a password management circuit 10<memory 1
1 and a central control circuit 12 for controlling these, the encrypted password sent from the data transmitting/receiving circuit 1 along with predetermined data is restored to the original password by the encrypted password decoding circuit 9, and the password is is managed by the password management circuit 10, and when sending out the next data transmission permission request signal, the password managed by the password management circuit 10 is sent.
次に本実施例の動作について説明する。まず、相手端末
からのデータ送信要求信号がデータ送受信回路1に入力
されると、中央制御回路7は自己の端末識別符号IDを
データ送受信回路1から相手端末に送出する。相手端末
は、上記端末識別符号IDを受信すると、中央制御回路
12が上記端末識別符号IDに対応してパスワード管理
回路10が管理するパスワードを選択し、このパスワー
ドと自端末の端末識別符号IDとを載せたデータ送信許
可要求信号をデータ送受信回路8を介して送出する。こ
のデータ送信許可要求信号がデータ送受信回路1で受信
されると、パスワード照合回路6がパスワード管理回路
4の管理する端末識別符号ID対応のパスワードを抽出
して、受信したパスワードと照合する。不一致であれば
、通信網を復旧し、一致したときは相手端末に対してデ
ータ送信許可信号を送出して所要のデータ送信を開始す
る。上記データ送信許可信号には、以下に説明するよう
にして、次回に使用すべきパスワードを暗号化したデー
タが含まれている。すなわち、パスワード発生回路2が
ランダムに発生したパスワードをパスワード暗号化回路
3により特定の暗号化方式によって暗号化し、上記デー
タ送信許可信号中に含ませる。同時に−、パスワード発
生回路2の出力する暗号化前のパスワードは、当該相手
端末の端末識別符号IDに対応させてパスワード管理回
路4で管理される。すなわち、メモリ5の当該相手端末
の端末識別符号IDに対応する番地の内容をパスワード
発生回路2の出力したパスワードによって更新する。こ
れは次回のパスワード照合に使用される。Next, the operation of this embodiment will be explained. First, when a data transmission request signal from a partner terminal is input to the data transmitting/receiving circuit 1, the central control circuit 7 sends its own terminal identification code ID from the data transmitting/receiving circuit 1 to the partner terminal. When the other terminal receives the terminal identification code ID, the central control circuit 12 selects a password managed by the password management circuit 10 corresponding to the terminal identification code ID, and combines this password with the terminal identification code ID of the own terminal. A data transmission permission request signal carrying the data is sent out via the data transmission/reception circuit 8. When this data transmission permission request signal is received by the data transmission/reception circuit 1, the password verification circuit 6 extracts the password corresponding to the terminal identification code ID managed by the password management circuit 4, and collates it with the received password. If they do not match, the communication network is restored, and if they match, a data transmission permission signal is sent to the other party's terminal to start transmitting the required data. The data transmission permission signal includes data in which a password to be used next time is encrypted as described below. That is, the password generated randomly by the password generation circuit 2 is encrypted by the password encryption circuit 3 using a specific encryption method, and is included in the data transmission permission signal. At the same time, the unencrypted password output by the password generation circuit 2 is managed by the password management circuit 4 in correspondence with the terminal identification code ID of the other party's terminal. That is, the contents of the address corresponding to the terminal identification code ID of the partner terminal in the memory 5 are updated with the password output from the password generation circuit 2. This will be used for the next password verification.
一方、上記データ送信許可信号中に含ませてデータ送受
信回路1から送信され暗号化されたパスワードは、相手
端末のデータ送受信回路8で受信され、暗号化パスワー
ド解読回路9で解読されて元のパスワードに復元される
。これは次回に使用すべきパスワードであり、パスワー
ド管理回路10がメモ1月1を使用して端末識別符号I
D対応に管理する。On the other hand, the encrypted password included in the data transmission permission signal and transmitted from the data transmitting/receiving circuit 1 is received by the data transmitting/receiving circuit 8 of the other party's terminal, is decoded by the encrypted password decoding circuit 9, and becomes the original password. will be restored. This is the password to be used next time, and the password management circuit 10 uses the memo January 1 to input the terminal identification code I.
Manage according to D.
したがって、次回のデータ送信許可要求信号時には、パ
スワード管理回路10によって管理されているパスワー
ドを使用する。このパスワードは、上述の動作によって
1通信ごとに変化されるから、仮にパスワードが盗聴さ
れてもデータの秘密を保護することが可能である。さら
に、上記パスワードは、暗号化して送出されたデータを
解読したものであるから、第三者が暗号化されたデータ
を盗聴しても元のパスワードを解読することは困難であ
り、より一層の機密保護が保証される。Therefore, the password managed by the password management circuit 10 is used at the time of the next data transmission permission request signal. Since this password is changed for each communication by the above-described operation, it is possible to protect the confidentiality of data even if the password is intercepted. Furthermore, since the above password is a decryption of encrypted data, even if a third party were to eavesdrop on the encrypted data, it would be difficult to decipher the original password. Confidentiality is guaranteed.
以上のように、本発明においては、相手端末機側に、1
iffl信ごとにパスワードを変化させ、かつ暗号化し
て通知するように構成したから、第三者がパスワードを
盗聴することを防止し、仮に盗聴された場合においても
データの機密を保護できるという効果がある。As described above, in the present invention, one
Since the password is changed for each iffl message and the password is encrypted, it is configured to prevent a third party from eavesdropping on the password, and even if the password is eavesdropped, the confidentiality of the data can be protected. be.
図は本発明の一実施例を示すブロック図。
l・・・データ送受信回路、2・・・パスワード発生回
路、3・・・パスワード暗号化回路、4・・・パスワー
ド管理回路、5・・・メモリ、6・・・パスワード照合
回路、7・・・中央制御回路、8・・・データ送受信回
路、9・・・暗号化パスワード解読回路、10・・・パ
スワード管理回路、11・・・メモリ、12・・・中央
制御回路。The figure is a block diagram showing one embodiment of the present invention. l...Data transmission/reception circuit, 2...Password generation circuit, 3...Password encryption circuit, 4...Password management circuit, 5...Memory, 6...Password verification circuit, 7... - Central control circuit, 8... Data transmission/reception circuit, 9... Encrypted password decoding circuit, 10... Password management circuit, 11... Memory, 12... Central control circuit.
Claims (1)
回路と、 このパスワード発生回路の出力するパスワードを暗号化
するパスワード暗号化回路と、 相手端末別にパスワードを管理するパスワード管理回路
と、 受信したパスワードを前記パスワード管理回路の管理す
るパスワードと照合するパスワード照合回路と を備え、 相手端末から受信したパスワードが前記パスワード管理
回路の管理するパスワードと一致したときは、所要のデ
ータを送出するととも、前記パスワード発生回路からラ
ンダムに読出した次回に使用すべきパスワードを前記パ
スワード暗号化回路によって暗号化して送出することに
より、相手端末に次回に使用すべきパスワードを通知す
る制御手段を備えたこと を特徴とするパスワード照合方式。(1) A password generation circuit that randomly generates a password; a password encryption circuit that encrypts the password output from this password generation circuit; a password management circuit that manages passwords for each partner terminal; A password verification circuit is provided to verify the password with the password managed by the management circuit, and when the password received from the other terminal matches the password managed by the password management circuit, the required data is transmitted and the password is transmitted from the password generation circuit. A password verification method characterized by comprising a control means for notifying the other terminal of the password to be used next time by encrypting the randomly read password to be used next time by the password encryption circuit and sending it. .
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP60171583A JPS6231231A (en) | 1985-08-02 | 1985-08-02 | Password collating system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP60171583A JPS6231231A (en) | 1985-08-02 | 1985-08-02 | Password collating system |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JPS6231231A true JPS6231231A (en) | 1987-02-10 |
Family
ID=15925842
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP60171583A Pending JPS6231231A (en) | 1985-08-02 | 1985-08-02 | Password collating system |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPS6231231A (en) |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH0213035A (en) * | 1988-04-04 | 1990-01-17 | Motorola Inc | Method and apparatus for control access to communication system |
| US6496937B1 (en) | 1998-01-13 | 2002-12-17 | Nec Corp. | Password updating apparatus and recording medium used therefor |
| JP2006505993A (en) * | 2002-11-06 | 2006-02-16 | インターナショナル・ビジネス・マシーンズ・コーポレーション | Providing access code sets to user devices |
| JP2013078066A (en) * | 2011-09-30 | 2013-04-25 | Toshiba Corp | Information processing device, start control method, and program |
| JP2025150021A (en) * | 2024-03-27 | 2025-10-09 | 三菱電機インフォメーションシステムズ株式会社 | Access management device, communication device, access management system, access management method, access management program, communication method, and communication program |
-
1985
- 1985-08-02 JP JP60171583A patent/JPS6231231A/en active Pending
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH0213035A (en) * | 1988-04-04 | 1990-01-17 | Motorola Inc | Method and apparatus for control access to communication system |
| US6496937B1 (en) | 1998-01-13 | 2002-12-17 | Nec Corp. | Password updating apparatus and recording medium used therefor |
| JP2006505993A (en) * | 2002-11-06 | 2006-02-16 | インターナショナル・ビジネス・マシーンズ・コーポレーション | Providing access code sets to user devices |
| JP2013078066A (en) * | 2011-09-30 | 2013-04-25 | Toshiba Corp | Information processing device, start control method, and program |
| JP2025150021A (en) * | 2024-03-27 | 2025-10-09 | 三菱電機インフォメーションシステムズ株式会社 | Access management device, communication device, access management system, access management method, access management program, communication method, and communication program |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US6826686B1 (en) | Method and apparatus for secure password transmission and password changes | |
| US7688975B2 (en) | Method and apparatus for dynamic generation of symmetric encryption keys and exchange of dynamic symmetric key infrastructure | |
| US5995624A (en) | Bilateral authentication and information encryption token system and method | |
| JPH09167098A (en) | Communication system for portable device | |
| CN101464932B (en) | Cooperation method and system for hardware security units, and its application apparatus | |
| JPH1013401A (en) | Method for establishing secured communication and related ciphering/decoding system | |
| JPH10171717A (en) | IC card and cryptographic communication system using the same | |
| EP0018129B1 (en) | Method of providing security of data on a communication path | |
| JPH04247737A (en) | Enciphering device | |
| JPS6231231A (en) | Password collating system | |
| AU753951B2 (en) | Voice and data encryption method using a cryptographic key split combiner | |
| JPH063905B2 (en) | Authentication method between the center and the user | |
| JPS63161745A (en) | Terminal equipment for cryptographic communication | |
| JP2001285286A (en) | Authentication method, recording medium, authentication system, terminal device, and recording medium creating device for authentication | |
| JPH07336328A (en) | Cipher device | |
| JP3327368B2 (en) | User password authentication method | |
| JPH0373633A (en) | Cryptographic communication system | |
| JP2541308B2 (en) | Confidential database communication method | |
| CN113612599A (en) | Lightweight power Internet of things communication encryption method based on preset key book | |
| JPH02195377A (en) | Ic card provided with key sharing function | |
| JPH06276188A (en) | Electronic communication equipment | |
| KR100763464B1 (en) | Secret key exchange method for encrypted communication | |
| JP2850391B2 (en) | Confidential communication relay system | |
| JP3230726B2 (en) | Encrypted communication method | |
| JP2893775B2 (en) | Key management method for cryptographic communication system for mobile communication |