Cryptographic key management system
The cryptographic key management system addresses secure data updates in electronic devices by using an HSM to generate and manage encryption keys, ensuring legitimate updates and preventing fraudulent installations.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- KK TOSHIBA
- Filing Date
- 2022-04-28
- Publication Date
- 2026-06-22
AI Technical Summary
The challenge of ensuring secure data updates in electronic devices after shipment, where products may download fraudulent updates from unauthorized sources, leading to potential information leakage or device hijacking.
A cryptographic key management system comprising a key management device and a product management device, which utilizes an HSM to generate and manage encryption keys, ensuring secure data updates by verifying the legitimacy of update data through digital signatures and encryption.
Ensures secure and legitimate data updates by authenticating users and devices, preventing installation of fraudulent programs, thereby protecting against information leakage and device hijacking.
Smart Images

Figure 0007877053000001 
Figure 0007877053000002 
Figure 0007877053000003
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to Cryptographic key management system .
Background Art
[0002] In recent years, products (devices) equipped with electronic devices such as LSIs including memories capable of updating stored contents have been increasing. Some of these products (devices) have a function of updating data stored in the memory after being shipped from the manufacturer. A product with a function of updating data after shipment writes the updated data downloaded from an external device into the memory. Since the product after shipment is in the possession of the end user, for example, updated data is distributed online or downloaded in response to a request from the end user.
[0003] However, since the product after shipment is in the possession of the end user, there is a possibility that a secure communication path cannot be ensured or that fake data is downloaded from a fake external device (such as a fake website). If the product downloads a fraudulent program tampered with by an attacker, the fraudulent program is installed and the normal operation cannot be performed. For example, if the product is updated using malicious fake firmware, there is a possibility of suffering damages such as information leakage or device hijacking. Therefore, it is desired that a product having a data update function performs data update after confirming that the update data is provided by a legitimate business operator (manufacturer or update data provider) himself.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
[0005] To solve the above problems, the present invention enables secure data updates in a product. Cryptographic key management system The purpose is to provide. [Means for solving the problem]
[0006] According to the embodiment, The cryptographic key management system comprises a key management device for managing key information and a product management device for managing products. The key management device comprises a first communication unit, an interface, and a first processor. The product management device comprises a second communication unit, a third communication unit, and a second processor. The first communication unit communicates with the product management device. The interface connects to an HSM that generates key information and securely stores the generated key information. The first processor requests the HSM to generate key information containing an encryption key to be written to a product when the product management device requests it; obtains the encryption key to be written to a product from the HSM when the product management device requests it; transmits the encryption key obtained from the HSM to the product management device; requests the HSM to perform calculations using key information on product update data when the product management device requests it; obtains the calculation data generated by the calculation performed by the HSM; and transmits the calculation data obtained from the HSM to the product management device. The second communication unit communicates with the key management device. The third communication unit communicates with the product. The second processor requests the key management device to generate key information, including an encryption key to be written to the product before shipment, then obtains the encryption key from the key management device. After requesting the key management device to perform calculations using the key information on the update data to be written to the product with the encryption key written on it, the processor obtains the calculation data from the key management device and distributes the calculation data obtained from the key management device to the product. [Brief explanation of the drawing]
[0007] [Figure 1] Figure 1 is a schematic diagram showing an example configuration of an encryption key management system according to an embodiment. [Figure 2] Figure 2 is a block diagram showing an example configuration of a product management server in the cryptographic key management system according to the embodiment. [Figure 3] Figure 3 is a block diagram showing an example configuration of the signature server in the signature system of the cryptographic key management system according to the embodiment. [Figure 4] Figure 4 is a block diagram showing an example of the configuration of products managed by the product management server in the cryptographic key management system according to the embodiment. [Figure 5] Figure 5 is a sequence illustrating an example of the process by which a signature server provides an encryption key to a product management server in an encryption key management system according to the embodiment. [Figure 6] Figure 6 is a sequence illustrating an example of processing update data using key information managed by the signature server in the cryptographic key management system according to the embodiment. [Modes for carrying out the invention]
[0008] The embodiments will be described below with reference to the drawings. First, the configuration of the cryptographic key management system 1 according to this embodiment will be described. Figure 1 shows an example of the configuration of the cryptographic key management system 1 according to an embodiment. In the configuration example shown in Figure 1, the cryptographic key management system 1 includes a product management system 2 and a signature system 3.
[0009] Product Management System 2 is a system for managing product (device) 8. Product 8, managed by Product Management System 2, is a device equipped with electronic equipment that has memory capable of writing data, such as an LSI. Product Management System 2 manages data such as programs or control data to be written to the memory of the electronic equipment installed in product 8.
[0010] In this embodiment, the product management system 2 has a function to manage data to be written to product 8A before it is shipped to the end user, and a function to manage data (update data) to be written to product 8B after it has been shipped.
[0011] Furthermore, the business operator (user) that manages the data to be written to product 8A before shipment and the business operator (user) that manages the update data to be written to product 8B after shipment may be the same business operator or different business operators.
[0012] In the configuration example shown in Figure 1, the product management system 2 comprises a product management server (product management device) 4 and a data storage 5. The product management server 4 is a computer that manages the data to be written to the products 8 (8A, 8B). The data storage 5 stores the data managed by the product management server 4.
[0013] The product management server 4 shall have the function of supplying data to be written to product 8A before shipment and the function of distributing data to be written (update data) to product 8B after shipment. The product management server 4 may consist of one server device or multiple server devices. For example, if the company that supplies data to product 8A before shipment and the company that distributes update data to product 8B after shipment are different companies, the product management server 4 that supplies data to product 8A before shipment and the product management server 4 that distributes update data to product 8B after shipment may be different devices (hardware).
[0014] In the product management system 2, the product management server 4 manages the data to be written to product 8A before it is shipped to the end user (for example, during the manufacturing process) and ensures that the data is written to product 8A before shipment. For example, the product management server 4 supplies data such as programs (firmware or drivers, etc.) and control data to product 8A (or a device that writes data to product 8A) during the manufacturing process. Product 8A before shipment writes the data supplied by the product management server 4 to its own memory.
[0015] Furthermore, the product management server 4 obtains an encryption key (public key or symmetric key) from the signature system 3 to write to the product 8A before shipment in order to verify the legitimacy of the data to be distributed to the product after shipment. The product management server 4 supplies the encryption key obtained from the signature system 3 to the product 8A before shipment. As a result, the product 8A before shipment writes the data supplied by the product management server 4 to its own memory.
[0016] Furthermore, in the product management system 2, the product management server 4 manages the data (update data) to be written to the product 8B after shipment. For example, the product management system 2 manages the data (update data) to update programs, control data, etc., written to the product 8B after shipment. The product management server 4 obtains data (distribution data to the product) that has been processed (digitally signed or encrypted) by the signature system 3 using key information for the update data to be written to each product 8B after shipment.
[0017] The product management server 4 distributes the distribution data obtained by the signature system 3 performing arithmetic processing on the update data using the key information to each product 8B after shipment. For example, the product management server 4 may distribute the distribution data obtained by performing arithmetic processing on the update data to each product 8B that is online-connected after shipment. Also, the product management server 4 may notify the user (end user) who holds the product 8B after shipment of the data update, and provide the distribution data obtained by performing arithmetic processing on the update data in response to a request from the end user. Also, the product management server 4 may publish the distribution data on the WEB server so that the end user can download the distribution data obtained by performing arithmetic processing on the update data from the WEB server.
[0018] Before shipment, the product 8B acquires the distribution data obtained by performing arithmetic processing on the update data using the key information from the product management server 4. The product 8B decrypts the distribution data using the encryption key written in itself to confirm the validity of the update data included in the distribution data, and writes the update data with confirmed validity into its own memory. For example, when acquiring the update data electronically signed as the distribution data, the product 8B writes the update data into its own memory after confirming the validity of the electronic signature using the public key written in itself. Also, when acquiring the update data encrypted with a common key as the distribution data, the product 8B decrypts the encrypted update data using the common key written in itself and then writes the update data into its own memory.
[0019] The signature system 3 includes a signature server (key management device) 6 and an HSM (Hardware Security Module) 7. The signature server 6 is a key management device that manages the key information including the encryption key written in the product 8 managed by the product management system 2. As functions realized by the signature server 6 cooperating with the HSM, it has functions such as a key generation function, a key acquisition function, and a signature generation function.
[0020] HSM7 is a tamper-resistant hardware device (security device) that securely generates, protects, and manages key information. HSM7 generates key information, including encryption keys, and securely stores the generated key information. Furthermore, HSM7 performs computational processing, including encryption processes, using the stored key information. For example, HSM7 performs computational processing such as data encryption and decryption, digital signatures, and the creation of digital certificates using the stored key information.
[0021] As a key management device, the signature server 6 provides the product management server 4, as a product management device, with cryptographic keys generated by the HSM7 in response to a request from the product management server 4. For example, as a key generation function, the signature server 6 generates key information using the HSM7 in response to a request from the product management server 4. For example, the signature server 6 generates key information including a public key and a private key pair using the HSM7 in response to a request from the product management server 4.
[0022] As a key acquisition function, the signature server 6 provides the product management server 4 with an encryption key to be written to the product 8 in response to a request from the product management server 4. For example, the signature server 6 provides the product management server 4 with the public key generated by the HSM7 as the encryption key to be written to the product 8 in response to a request from the product management server 4. Furthermore, instead of providing the public key itself to the product management server 4, the signature server 6 may provide (distribute) a public key certificate that has been self-signed and conforms to a predetermined format (for example, a format specified by a standard such as X.509).
[0023] Furthermore, if the signature server 6 is operating in a manner that manages key information for a symmetric-key cryptography system, it may generate key information including the symmetric key using the HSM7 in response to a request from the product management server 4, and provide the generated symmetric key to the product management server 4 as the encryption key to write to the product 8. In addition, the signature server 6 may encrypt the public key using the shared encryption key and provide it to the product management server 4. Furthermore, the signature server 6 may encrypt the public key certificate using the shared encryption key and provide it to the product management server 4.
[0024] The signature server 6, as a signature generation function, digitally signs update data from the product management server 4 using the HSM7. For example, the signature server 6 receives a request from the product management server 4 to digitally sign update data for product 8 on which the public key included in the key information generated by the HSM7 has been written. The signature server 6 digitally signs the update data for which the product management server 4 has requested a digital signature, using the private key corresponding to the public key written to product 8, which is stored in the HSM7. The signature server 6 sends the update data (signature file), digitally signed with the private key corresponding to the public key written to product 8 by the HSM7, to the product management server 4. Note that if a symmetric key encryption system is supported, the signature server 6 may also generate a MAC as a signature generation function.
[0025] Furthermore, the signature server 6 may also have a function to save log data indicating the processing details. For example, the signature server 6 may generate log data indicating the processing details when it performs a process such as digital signature using a private key stored by the HSM7, and save the generated log data, which has been digitally signed by the HSM7 (signed log data), to a storage device.
[0026] Furthermore, the signature server 6 has a user management function that manages businesses that manage products (businesses that manufacture products, or businesses that provide services to products after shipment) as users of the cryptographic key management system 1. For example, the signature server 6 has user management functions such as user authentication, management of user information, management of user permissions, registration, modification and deletion of user information, user group management, access restrictions for groups, and notifications to users via email, etc.
[0027] Furthermore, as a user registration function, in order to prevent registration by non-designated businesses, the number of users who can register may be limited by a whitelist check. For example, by including an email address in the user information to be registered and performing a whitelist check on the domain of the email address, it may be possible to allow users with email addresses belonging to a specific domain to register.
[0028] Next, the configuration of the product management server 4 of the product management system 2 in the cryptographic key management system 1 according to the embodiment will be described. Figure 2 is a block diagram showing an example configuration of a product management server 4 as a product management device in the cryptographic key management system 1 according to this embodiment. As shown in Figure 2, the product management server 4, which functions as a product management device, includes a processor 41, ROM 42, RAM 43, data memory 44, interface (I / F) 45, communication interface (I / F) 46, and communication interface (I / F) 47.
[0029] The processor 41 performs various processes by executing programs. The processor 41 is, for example, a CPU (Central Processing Unit). The processor 41 is connected to various parts within the server 4 via a system bus and sends and receives data to and from these parts. The processor 41 works in cooperation with the ROM 42 and RAM 43 to perform operations such as control and data processing in the product management server 4, which functions as a product management device.
[0030] ROM (Read Only Memory) 42 is a non-volatile memory that stores programs and control data necessary to realize the basic operation of the product management server 4. RAM (Random Access Memory) 43 is volatile memory that temporarily stores data. RAM 43 functions as working memory when the processor 41 executes a program.
[0031] The data memory 44 is a storage unit that stores various types of data. The data memory 44 is composed of non-volatile memory that allows data to be rewritten. For example, the data memory 44 stores OS programs, application programs, operation setting information, and so on.
[0032] Interface 45 is an interface for accessing the data storage 5. If the data storage 5 is a storage device as an external device, interface 45 only needs to be compatible with the interface standard of the storage device as the data storage 5. If the data storage 5 is a data server or the like, interface 45 should be configured as a communication interface for communicating with the data server as the data storage 5.
[0033] The communication interface 46 is an interface (second communication unit) for communicating with the signature server 6 of the signature system 3. The communication interface 46 may communicate with the signature server 6 wirelessly or via a wired connection. For example, the communication interface 46 may connect to the signature server 6 via a wide-area network such as the Internet.
[0034] The communication interface 47 is an interface for communicating with the product (device) 8 (8A, 8B). The communication interface 47 may supply data to the product 8 wirelessly or via a wired connection. The communication interface 47 includes an interface for supplying data to the product 8 before shipment and an interface for supplying distribution data, including update data, to the product 8B after shipment.
[0035] Furthermore, communication interfaces 46 and 47 may be implemented using a single communication interface. Similarly, interface 45 may be configured as a common interface with either communication interface 46 or communication interface 47.
[0036] Next, the configuration of the signature server 6 of the signature system 3 in the cryptographic key management system 1 according to the embodiment will be described. Figure 3 is a block diagram showing an example configuration of a signature server 6 as a key management device in the cryptographic key management system 1 according to this embodiment. As shown in Figure 3, the signature server 6, acting as a key management device, includes a processor 61, ROM 62, RAM 63, data memory 64, interface 65, and communication interface 66.
[0037] The processor 61 performs various processes by executing programs. The processor 61 is, for example, a CPU (Central Processing Unit). The processor 61 is connected to various parts of the server 6 via a system bus and sends and receives data to and from these parts. The processor 61 works in cooperation with the ROM 62 and RAM 63 to perform operations such as control and data processing in the signature server 6.
[0038] ROM (Read Only Memory) 62 is a non-volatile memory that stores programs and control data necessary to realize the basic operation of the signature server 6. RAM (Random Access Memory) 63 is volatile memory that temporarily stores data. RAM 63 functions as working memory when the processor 61 executes a program.
[0039] The data memory 64 is a storage device that stores various types of data. The data memory 64 is composed of non-volatile memory that allows data to be rewritten. For example, the data memory 64 stores OS programs, application programs, operation setting information, etc. The data memory 64 may also store user information, etc. The data memory 64 may also store log data indicating processing details.
[0040] Interface 65 is an interface for accessing the HSM7. Interface 65 only needs to be compatible with the interface standards provided by the HSM7. The communication interface 66 includes a communication interface for communicating with the product management server 4, which is a product management device. The communication interface 66 may communicate wirelessly or via a wired connection. Furthermore, the communication interface 66 may communicate with the product management server 4 in the product management system 2 via a wide-area network such as the Internet.
[0041] Next, the configuration of the product (device) 8 managed by the product management system 2 in the cryptographic key management system 1 according to this embodiment will be described. Figure 4 is a block diagram showing an example of the configuration of product 8 managed by the product management system 2 according to this embodiment. Product 8 incorporates electronic components such as LSIs that include a processor, memory, and interfaces. Product 8 is not limited to a specific device and is acceptable as long as it allows for data updates after shipment.
[0042] In the configuration example shown in Figure 4, product 8 includes a processor 81, ROM 82, RAM 83, data memory 84, and a communication interface 85. The processor 81 includes circuits that perform various processes. The processor 81 is, for example, a CPU (Central Processing Unit). The processor 81 realizes various processing functions by executing programs stored in the ROM 82 or data memory 84.
[0043] ROM82 is a non-volatile memory that functions as program memory. ROM82 stores pre-programmed control programs and control data. RAM83 is a volatile memory that functions as working memory. RAM83 also functions as a buffer for temporarily storing data being processed by the processor 81. For example, RAM83 functions as a communication buffer for temporarily storing data transmitted to and from external devices via the communication interface 85.
[0044] The data memory 84 is a non-volatile memory that allows data to be written to and rewritten. The data memory 84 is composed of, for example, EEPROM (Electrically Erasable Programmable Read Only Memory). Program files or data files are defined in the data memory 84, and control programs and various data are written to these files. For example, the data memory 84 or ROM 82 stores a program for writing data supplied from the product management server 4 to the data memory 84. The data memory 84 or ROM 82 also stores a program for verifying the legitimacy of distribution data distributed from the product management server 4.
[0045] Furthermore, data supplied from the product management server 4, which acts as a product management device, is written to the data memory 84 before the product is shipped. For example, the product 8 is supplied with an encryption key (public key or symmetric key) generated by the signature system 3 from the product management server 4 to the signature server 6, which acts as a key management device, and the encryption key supplied from the product management server 4 is written to the data memory 84. In addition, update data included in the distribution data distributed from the product management server 4, which acts as a product management device, after the product has been shipped is written to the data memory 84.
[0046] The communication interface 85 is an interface for communicating with the product management server 4. The communication interface 85 only needs to be capable of receiving data supplied from the product management server 4.
[0047] Next, we will describe data processing using key information managed by the cryptographic key management system 1 according to this embodiment. Figure 5 is a sequence illustrating an example of the operation of the process in which the encryption key to be written to product 8A is provided to the product management system 2 in the encryption key management system 1 according to this embodiment. The product management server 4 of the product management system 2 and the signature server 6 of the signature system 3 perform user authentication (ST11) for users (businesses) using the product management server 4 to log in to the signature system 3.
[0048] For example, the processor 41 of the product management server 4 communicates with the signature server 6 via the communication interface 46 and sends authentication information along with a user authentication (login) request to the signature server 6. The signature server 6 receives the user authentication request from the product management server 4 via the communication interface 66. The processor 61 of the signature server 6 performs user authentication based on the authentication information received from the product management server 4 and the user information stored in the data memory 64 or the like.
[0049] If user authentication is successful (i.e., the processor 61 of the signature server 6 confirms that the user is a legitimate user), it puts the user into a logged-in state. The processor 61 of the signature server 6 accepts processing requests (requests) from the product management server 4 based on the permissions set for the logged-in user.
[0050] When the processor 41 of the product management server 4 successfully logs in to the signature server 6, it requests the signature server 6 to generate keys, including key information such as the encryption key to be written to the product 8A before shipment (ST12). At this point, the processor 41 of the product management server 4 may also specify the encryption algorithm and security parameters along with the key generation request.
[0051] The signature server 6 receives a key generation request from the product management server 4 via the communication interface 66, submitted by a logged-in user. At this point, the processor 61 of the signature server 6 verifies that the logged-in user has the authority to request key generation. If the processor 61 confirms that the logged-in user has the authority to request key generation, it accepts the key generation request from the product management server 4.
[0052] When the processor 61 of the signature server 6 receives a key generation request from the product management server 4, it requests the HSM7 connected to interface 65 to generate key information (ST13). The HSM7 generates key information, including the encryption key to be written to product 8A, in response to the request from the processor 61 (ST14). Once the HSM7 has generated key information, including the encryption key, in response to the key information generation request from the signature server 6, it securely stores the generated key information in association with the key ID (ST15).
[0053] For example, if the key information managed by the cryptographic key management system 1 is a public-key cryptosystem, the HSM7 generates a public key and its corresponding private key as key information. Once the HSM7 generates the key pair of public and private keys, it associates the generated key pair with a key ID and stores it within the HSM7. In this case, the HSM7 securely stores the private key generated as part of the key pair without outputting it externally. The HSM7 then uses the private key, specified by the key ID, to perform calculations such as digital signatures.
[0054] Furthermore, if the key information managed by the encryption key management system 1 is a symmetric-key encryption system, the HSM7 generates key information that includes the symmetric key. Once the HSM7 generates key information that includes the symmetric key, it associates the symmetric key with a key ID and stores it within the HSM7. The HSM7 then uses the symmetric key, which is the key information specified by the key ID, to perform calculations such as data encryption.
[0055] In the signature system 3, the HSM7 stores the generated key information in association with a key ID, and then outputs the key ID indicating the stored (generated) key information to the signature server 6. When the processor 61 of the signature server 6 receives the key ID indicating the generated key information from the HSM7, it notifies the product management server 4, which requested the key generation, of the key ID. Here, the processor 61 of the signature server 6 may also store the key ID indicating the generated key information in association with information indicating the logged-in user (such as a user ID) in a data memory 64 or the like.
[0056] The product management server 4, which requested key generation, receives a key ID indicating the generated key information from the signature server 6 via the communication interface 46. The processor 41 of the product management server 4 stores the key ID notified by the signature server 6 in the data storage 5 or data memory 44. This allows the product management server 4 to specify the key information generated by the signature system 3 in response to the key generation request.
[0057] Furthermore, the processor 41 of the product management server 4 requests the signature server 6, which acts as a key management device, to generate key information, and then requests the signature server 6 to provide an encryption key to be written to the product 8A before shipment (requesting the acquisition of an encryption key) (ST16). For example, after receiving a key ID from the signature server 6 indicating the key information generated by the HSM7, the processor 41 of the product management server 4 requests the signature server 6 to provide an encryption key to be written to the product 8A before shipment, specifying the key ID.
[0058] The signature server 6 receives a request for an encryption key to be written to product 8A (a request to obtain an encryption key) via the communication interface 66. At this point, the processor 61 of the signature server 6 verifies that the logged-in user has the authority to obtain the encryption key. If the processor 61 confirms that the logged-in user has the authority to obtain the encryption key, it accepts the request for the encryption key from the product management server 4.
[0059] When the processor 61 of the signature server 6 receives a request for an encryption key from the product management server 4, it requests the encryption key included in the key information generated in response to the request of the logged-in user from the HSM7 (ST17). The HSM7 outputs the encryption key included in the key information to the signature server 6 in response to the request from the signature server 6 (ST18).
[0060] For example, the processor 61 of the signature server 6 requests the encryption key contained in the key information corresponding to the key ID specified by the product management server 4 from the HSM7. In response to the request from the signature server 6, the HSM7 outputs the encryption key contained in the key information corresponding to the key ID specified by the product management server 4 to the signature server 6.
[0061] Furthermore, if the key information managed by the encryption key management system 1 is a public-key cryptosystem, the HSM7 outputs the public key included in the key information (key pair) corresponding to the key ID specified by the product management server 4 to the signature server 6. If the key information managed by the encryption key management system 1 is a symmetric-key cryptosystem, the HSM7 outputs the symmetric key included in the key information corresponding to the key ID specified by the product management server 4 to the signature server 6.
[0062] When the signature server 6's processor 61 obtains the encryption key output by the HSM7, it sends the encryption key (public key or symmetric key) obtained from the HSM7 to the product management server 4, which is the source of the encryption key request, via the communication interface 66 (ST19).
[0063] The product management server 4 requests an encryption key to be written to product 8A before shipment, and then receives the encryption key from the signature server 6 via the communication interface 46. When the processor 41 of the product management server 4 receives the encryption key to be written to product 8A from the signature server 6, it supplies the received encryption key to product 8A as the encryption key to be written before shipment (ST20).
[0064] Before shipment, product 8A receives an encryption key supplied from product management server 4 via communication interface 85. When product 8A's processor 81 receives the encryption key to be written to it from product management server 4, it executes the process of writing the received encryption key to itself (ST21). Once product 8A's processor 81 has finished writing the encryption key, it notifies product management server 4 that the writing of the encryption key is complete.
[0065] When the processor 41 of the product management server 4 receives notification from product 8A that the writing of the encryption key is complete, it stores information identifying product 8A (e.g., product ID) and the key ID corresponding to the written encryption key in the data storage 5 or data memory 44.
[0066] Once product 8A has finished writing the encryption key obtained from the signature server 6 to the product management server 4, it becomes ready for shipment and is delivered to end users.
[0067] Furthermore, the signature server 6 may also save a log showing the processing details and notify the user. In the processing example shown in Figure 5, when the processor 61 of the signature server 6 sends an encryption key to the product management server 4, it generates log data showing the processing details (ST24). When the processor 61 of the signature server 6 generates the log data, if it is a public key cryptography system, it requests the HSM7 to digitally sign the log data (ST25). Here, the signature server 6 requests the digital signature of the log data by specifying the key ID corresponding to the encryption key.
[0068] In response to a request from the signing server 6, HSM7 digitally signs the log data using a private key paired with a public key corresponding to a specified key ID (ST26). HSM7 outputs the generated signed log data to the signing server 6 (ST27). The processor 61 of the signing server 6 saves the signed log data generated by HSM7 to a storage device such as data memory 64 (ST28). As a result, the signing system 3, including the signing server 6, can save log data indicating processing details with a signature, and can view log data whose authenticity is guaranteed.
[0069] Furthermore, when the processor 61 of the signature server 6 sends an encryption key to be written to product 8A in response to a request from the product management server 4, it notifies the user to whom the encryption key was sent of the processing details (ST29). For example, the processor 61 of the signature server 6 sends an email indicating the processing details to the email address included in the user information of the user who requested the encryption key to be written to product 8A. This allows the user (business operator) to understand the processing details performed using the signature system 3.
[0070] Next, we will describe the data processing using key information in the cryptographic key management system 1 according to this embodiment. Figure 6 is a sequence illustrating an example of the operation of a data update process for a product 8B after shipment using key information in the cryptographic key management system 1 according to this embodiment. When providing update data to product 8B after shipment, the cryptographic key management system 1 supplies the update data to product 8B, which has been processed in a way that makes it valid using the cryptographic key written to product 8B.
[0071] For example, if the key information managed by the cryptographic key management system 1 is a public-key cryptosystem, the signature system 3 supplies updated data to product 8B with a digital signature attached using the private key corresponding to the public key written to product 8B. This allows product 8B to verify the validity of the updated data using the public key written to it and then write the updated data to itself.
[0072] Furthermore, if the key information managed by the encryption key management system 1 is a symmetric-key cryptosystem, the signature system 3 supplies the product 8B with updated data encrypted using the symmetric key written to the product 8B. This allows the product 8B to write updated data back to itself that can be decrypted using the symmetric key written to it.
[0073] In the following explanation of the processing example shown in Figure 6, we assume that the cryptographic key management system 1 manages the key information of the public key cryptography system. First, the product management server 4 in the product management system 2 obtains the update data to be written to the shipped product 8B (which has already had the encryption key written to it) (ST30). When the processor 41 of the product management server 4 obtains the update data for product 8B, it performs a login process to the signature server 6 in order to request the signature system 3 to process the update data so that product 8B itself can verify its legitimacy (ST31).
[0074] For example, the processor 41 of the product management server 4 establishes a communication connection with the signature server 6 via the communication interface 46 and sends authentication information to the signature server 6 along with a user authentication (login) request. The processor 61 of the signature server 6 performs user authentication based on the authentication information of the logged-in user received from the product management server 4 and the user information stored in the data memory 64 or the like. If user authentication is successful (if the processor 61 confirms that the user is a legitimate user), it sets the user in a logged-in state and accepts processing requests from that user.
[0075] When the processor 41 of the product management server 4 successfully logs in to the signature server 6, it requests the signature server 6 to digitally sign the update data to be written to the product 8B after shipment (ST32). Here, the processor 41 of the product management server 4 requests the digital signature of the update data by specifying the key ID that indicates the public key written to the product 8B. The processor 41 may also specify the signature algorithm and security parameters along with the signature request.
[0076] The signature server 6 receives a signature request for update data from the product management server 4 via the communication interface 66. At this point, the processor 61 of the signature server 6 verifies that the logged-in user has the authority to obtain an electronic signature. If the processor 61 confirms that the logged-in user has the authority to obtain an electronic signature, it accepts the signature request from the product management server 4.
[0077] When the processor 61 of the signature server 6 receives a signature request from the product management server 4, it requests the HSM7 connected to interface 65 to generate an electronic signature for the update data (ST33). Here, the processor 61 supplies the update data and a key ID indicating the key information to be used for signing, along with the signature request, to the HSM7 via interface 65. The HSM7 generates an electronic signature for the update data in response to the signature request from the signature server 6 (ST34). The HSM7 identifies the private key corresponding to the key ID specified by the signature server 6 and generates a signature file (signed update data) by attaching an electronic signature to the update data using the identified private key. The HSM7 outputs the generated signature file to the signature server 6 (ST35).
[0078] When the processor 61 of the signature server 6 obtains the signature file generated by the HSM7, it sends the signature file to the product management server 4, which is the source of the signature request, via the communication interface 66 (ST36).
[0079] After requesting a signature for the update data to be written to product 8A after shipment, the product management server 4 receives a signature file as signed update data from the signature server 6 via the communication interface 46. The processor 41 of the product management server 4 converts the signature file (signed update data) received from the signature server 6 into distribution data to be distributed to product 8B. The processor 41 distributes the signature file, which has been digitally signed by the signature system 3 as distribution data, to product 8B (ST37).
[0080] Furthermore, the method of distributing the signature file (distribution data) from the product management server 4 to product 8B is not limited to a specific method. For example, if product 8B is a device operating in an online connection mode, the product management server 4 may distribute the signature file (distribution data) to product 8B online.
[0081] Furthermore, the product management server 4 may notify users (end users) who hold the product 8B after shipment of data updates and allow them to download the signature file to the product 8B upon request from the end user. Alternatively, the product management server 4 may publish the signature file on a web server and allow end users to download the signature file to the product 8B from the web server.
[0082] After shipment, product 8B receives a signature file as distribution data distributed by product management server 4 via the communication interface 85. When product 8B's processor 81 receives the signature file distributed by product management server 4, it verifies the signature file received from product management server 4 using the public key written to it (ST38).
[0083] If the processor 81 of product 8A verifies the authenticity of the signature file using the public key, it executes the process of writing the update data contained in the signature file (ST39). Once the writing of the update data contained in the signature file is complete, the processor 81 of product 8B notifies the product management server 4 of the completion of writing the update data via the communication interface 85 (ST40).
[0084] When the processor 41 of the product management server 4 receives notification from product 8B that the writing of update data is complete, it records the completion of the writing of the update data in association with information that identifies product 8B (e.g., product ID). This allows the product management server 4 to supply product 8B with update data that has been digitally signed with a private key managed by the signature system 3. As a result, product 8B can verify the digital signature using the public key written to it and write the update data whose legitimacy has been confirmed.
[0085] Furthermore, if the key information managed by the encryption key management system 1 is a symmetric-key encryption system, the signature server 6 may receive update data for the product 8B after shipment from the product management server 4 and obtain data encrypted using the symmetric key corresponding to the symmetric key written to the product 8B by the HSM 7. In this case, the signature server 6 sends the data encrypted with the symmetric key by the HSM 7 to the product management server 4. The product management server 4 distributes the data encrypted with the symmetric key by the signature system 3 to the product 8B. The product 8B should decrypt the update data encrypted by the HSM 7 using the symmetric key and write the decrypted update data to the product 8B.
[0086] Furthermore, as shown in Figure 6, the signature server 6 may also save logs indicating the processing details and notify the user regarding the process of providing signature files to be distributed to the product 8B after shipment. In the processing example shown in Figure 6, when the processor 61 of the signature server 6 sends the signature file (distribution data) to the product management server 4, it generates log data indicating the processing details (ST41). After generating the log data, the processor 61 of the signature server 6 requests the HSM7 to digitally sign the log data (ST42).
[0087] HSM7 generates an electronic signature for the log data using the private key used to generate the signature file (ST43). HSM7 outputs the generated signed log data to the signature server 6 (ST44). The processor 61 of the signature server 6 saves the signed log data generated by HSM7 to a storage device such as the data memory 64 (ST45).
[0088] As a result, the signature system 3, including the signature server 6, can save signed log data that shows the details of the process that generated the signature file distributed to the product 8B after shipment, and it becomes possible to view log data that is guaranteed to be the original.
[0089] Furthermore, when the processor 61 of the signature server 6 receives a digitally signed signature file containing update data for the product 8B after shipment from the product management server 4, it notifies the logged-in user of the processing details (ST46). For example, the processor 61 of the signature server 6 sends an email indicating the processing details to the email address included in the user information of the logged-in user. This allows the user (business operator) to understand that the signature system 3 has sent a digitally signed signature file containing update data for the product 8B after shipment to the product management server 4.
[0090] As described above, the cryptographic key management system according to the embodiment includes a product management system and a signature system (key management system) operated by a business operator that manufactures or manages products. The signature system manages key information, including cryptographic keys generated in response to requests from the product management system, and affixes an electronic signature to update data for products on which the cryptographic keys included in the managed key information have been written. The product management system distributes the update data to products after shipment to which the signature system has affixed an electronic signature. The product obtains the electronically signed update data, verifies the validity of the obtained signature using the public key written to it, and then writes the update data to the product.
[0091] This allows businesses that manufacture or manage products using a product management system to delegate the management of encryption keys to a signature system that securely handles this task. As a result, businesses can reduce the costs associated with managing key information, including encryption keys, while ensuring the security of update data for their products. Furthermore, a signature system that includes a signature server as a key management device can provide businesses with security functions through primitive encryption processes such as signatures using encryption keys, allowing for the flexible provision of security functions that meet the diverse needs of various businesses.
[0092] The functions described in each of the embodiments above can be implemented not only using hardware, but also by loading a program containing each function into a computer using software. Furthermore, each function may be configured using either software or hardware, as appropriate.
[0093] While several embodiments of the present invention have been described, these embodiments are presented as examples only and are not intended to limit the scope of the invention. These novel embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents. [Explanation of symbols]
[0094] 1... Cryptographic key management system, 2... Product management system, 3... Signature system, 4... Product management server (product management device), 5... Data storage (storage device), 6... Signature server (key management device), 7... HSM, 8 (8A, 8B)... Product, 41... Processor (second processor), 44... Data memory (storage device), 45... Interface, 46... Communication interface (second communication unit), 47... Communication interface, 61... Processor (first processor), 64... Data memory (storage device), 65... Interface, 66... Communication interface (first communication unit), 81... Processor, 84... Data memory, 85... Interface.
Claims
1. In a cryptographic key management system having a key management device for managing key information and a product management device for managing products, The aforementioned key management device is, A first communication unit that communicates with the aforementioned product management device, An interface that connects to an HSM that generates key information and securely stores the generated key information, When the product management device requests the generation of key information including an encryption key to be written to the product, the HSM is requested to generate key information including an encryption key to be written to the product. When the product management device requests an encryption key to be written to the product, the encryption key to be written to the product is obtained from the HSM, and the encryption key obtained from the HSM is transmitted to the product management device. The system includes a first processor that, when the product management device requests the HSM to perform calculation processing using key information for the update data of the product, requests the HSM to perform the calculation processing, obtains the calculation processing data generated by the calculation processing performed by the HSM, and transmits the calculation processing data obtained from the HSM to the product management device. The aforementioned product management device is A second communication unit that communicates with the aforementioned key management device, A third communication unit that communicates with the aforementioned product, After requesting the key management device to generate key information including an encryption key to be written to the product before shipment, the encryption key is obtained from the key management device. A second processor that, after requesting the key management device to perform calculation processing using key information on update data to be written to the product on which the encryption key has been written, retrieves the calculation processing data from the key management device and distributes the calculation processing data retrieved from the key management device to the product, has Cryptographic key management system.
2. The first processor of the key management device is When the product management device requests the generation of a key pair consisting of a public key and a private key as the key information, the HSM is instructed to generate the key pair. When the product management device requests an encryption key to be written to the product, the public key is obtained from the HSM as the encryption key to be written to the product, and the public key obtained from the HSM is transmitted to the product management device. When the product management device requests an electronic signature as part of the calculation process for the update data of the product, the HSM is requested to electronically sign the update data using the private key corresponding to the public key written to the product, the electronic signature data generated by the electronic signature on the update data performed by the HSM is obtained, and the electronic signature data obtained from the HSM is transmitted to the product management device. The second processor of the product management device is After requesting the key management device to electronically sign the update data to be written to the product on which the public key has been written, the electronic signature data is obtained from the key management device, and the electronic signature data obtained from the key management device is distributed to the product. The cryptographic key management system according to claim 1.
3. The first processor of the key management device is When the product management device requests the generation of a common key as key information, the HSM is instructed to generate the common key. When the product management device requests an encryption key to be written to the product, the common key is obtained from the HSM as the encryption key to be written to the product, and the common key obtained from the HSM is transmitted to the product management device. When the product management device requests encryption as part of the calculation process for the update data of the product, the HSM is requested to encrypt the update data using the common key written to the product, and the encrypted data generated by the encryption of the update data performed by the HSM is transmitted to the product management device. The second processor of the product management device is After requesting the key management device to encrypt the update data to be written to the product on which the aforementioned common key has been written, the encrypted data is obtained from the key management device, and the encrypted data obtained from the key management device is distributed to the product. The cryptographic key management system according to claim 1.
4. The first processor of the key management device is When the product management device requests an encryption key to be written to the product, the encryption key to be written to the product and the key ID of the encryption key are obtained from the HSM, and the encryption key and the key ID of the encryption key obtained from the HSM are transmitted to the product management device. When the product management device requests computational processing on the product update data using the key information, the HSM is requested to perform computational processing on the update data using the encryption key identified by the key ID received from the product management device along with the update data, the computational processing data generated by the computational processing performed by the HSM is obtained, and the computational processing data obtained from the HSM is transmitted to the product management device. The cryptographic key management system according to claim 1.
5. The first processor of the key management device is The system performs user authentication based on authentication information from the product management device, and accepts requests from the product management device according to the authority of the user whose authentication was successful. The cryptographic key management system according to claim 1.
6. The first processor of the key management device is The HSM digitally signs the log data, which shows the processing details performed in response to a request from the product management device, using the private key corresponding to the public key, and saves this data to a storage device. The cryptographic key management system according to claim 2.
7. The first processor of the key management device sends a notification indicating the processing performed in response to a request from the product management device to the notification destination of the user whose user authentication was successful. The cryptographic key management system according to claim 5.