Communication method, first device, second device, and program
By adding a confirmation flag and Nonce to the classical certificate, the hybrid mode support status is safely confirmed between devices, which solves the problem that the hybrid mode cannot be effectively applied in the prior art and enhances the security of communication.
Patent Information
- Application Number
- CN202380071407.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-14
- Filing Date
- 2023-09-20
- Publication Date
- 2025-05-13
AI Technical Summary
When the prior art migrates from classical encryption methods to PQC methods, it is impossible to effectively confirm whether the device supports hybrid methods, resulting in the inability to appropriately apply hybrid methods, affecting the security of encryption.
By adding a confirmation flag indicating that the hybrid mode is supported in the classical certificate, the device returns Nonce and confirmation flags according to whether the hybrid mode is supported, and generates a signature to detect message tampering.
It realizes the secure confirmation of the hybrid mode support status between devices, thereby more appropriately applying the hybrid mode, enhancing the security of communication.
Smart Images

Figure CN119999142A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a communication method, a first device, a second device, and a program. Background Art
[0002] Patent Document 1 discloses a method of migrating (transitioning) an encryption system used by applications in an enterprise system to a hybrid method combining a so-called classical encryption method and a PQC (Post Quantum Cryptography) method.
[0003] Prior art literature
[0004] Patent Document 1: International Publication No. 2020 / 087152 Summary of the invention
[0005] Problems to be solved by the invention
[0006] The present disclosure provides a communication method and the like for more appropriately applying a hybrid approach.
[0007] Technical solutions to solve problems
[0008] One aspect of the present disclosure involves a communication method between a first device and a second device, wherein the first device sends a certificate of a first encryption method to the second device, the certificate including a confirmation flag indicating support (compatibility) for an encryption method different from the first encryption method, and when the first device receives a message including a Nonce (Number once) and the confirmation flag from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce and the confirmation flag included in the received message to the second device, and when the first device receives a message including the Nonce but not the confirmation flag from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce included in the received message to the second device.
[0009] Another aspect of the present disclosure relates to a communication method between a first device and a second device, wherein the second device receives a certificate of a first encryption method from the first device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the second device supports the different encryption method, as a response to the received certificate, the second device sends a message including a Nonce and the confirmation mark to the first device, and when the second device does not support the different encryption method, as a response to the received certificate, the second device sends a message including the Nonce and not including the confirmation mark to the first device, and the second device receives from the first device a signature generated based on the Nonce contained in the sent message, and any one of the Nonce and the confirmation mark.
[0010] Another aspect of the present disclosure relates to a communication method between a first device and a second device, wherein the first device sends a certificate of a first encryption method to the second device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the second device supports the different encryption method, as a response to the received certificate, the second device sends a message including a Nonce and the confirmation mark to the first device, and when the second device does not support the different encryption method, as a response to the received certificate, the second device sends a message including the Nonce to the first device. In the case where the first device receives a message including Nonce and the confirmation mark as a response to the sending of the certificate from the second device, the first device sends to the second device a signature generated based on the Nonce and the confirmation mark included in the received message; in the case where the first device receives a message including Nonce and not including the confirmation mark as a response to the sending of the certificate from the second device, the first device sends to the second device a signature generated based on the Nonce included in the received message.
[0011] An aspect of the present disclosure relates to a first device that is capable of communicating with a second device, and comprises: a certificate generation unit that generates a certificate for a first encryption method, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method; and a signature generation unit that, when sending the generated certificate to the second device, receives a message including a Nonce and the confirmation mark as a response from the second device, generates a signature based on the Nonce and the confirmation mark included in the received message; and, when sending the generated certificate to the second device, receives a message including the Nonce but not including the confirmation mark as a response from the second device, generates a signature based on the Nonce included in the received message.
[0012] The second device involved in one aspect of the present disclosure is a second device capable of communicating with a first device, comprising: a message generating unit, when receiving a certificate for a first encryption method from the first device including a confirmation mark indicating support for an encryption method different from the first encryption method, if the second device supports the different encryption method, the second device generates a message including a Nonce and the confirmation mark as a response to the received certificate, and if the second device does not support the different encryption method, the second device generates a message including the Nonce and not including the confirmation mark as a response to the received certificate; and a communication unit, the second device receiving from the first device a signature generated based on the Nonce contained in the message sent, and either the Nonce or the confirmation mark.
[0013] One aspect of the present disclosure relates to a program for causing a computer to execute a communication method between a first device and a second device, in which the first device sends a certificate of a first encryption method to the second device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the first device receives a message including a Nonce and the confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce and the confirmation mark included in the received message to the second device, and when the first device receives a message including the Nonce but not including the confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce included in the received message to the second device.
[0014] Another aspect of the present disclosure relates to a program for causing a computer to execute a communication method between a first device and a second device, in which the second device receives a certificate of a first encryption method from the first device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the second device supports the different encryption method, as a response to the received certificate, the second device sends a message including a Nonce and the confirmation mark to the first device, and when the second device does not support the different encryption method, as a response to the received certificate, the second device sends a message including the Nonce and not including the confirmation mark to the first device, and the second device receives from the first device a signature generated based on the Nonce contained in the sent message, and either the Nonce or the confirmation mark.
[0015] In addition, these general or specific technical solutions can be implemented by devices, integrated circuits, computer programs, or non-transitory recording media such as computer-readable CD-ROMs, or by any combination of devices, integrated circuits, computer programs, and non-transitory recording media.
[0016] Effects of the Invention
[0017] The communication method and the like in the present disclosure can more appropriately apply a hybrid approach. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 This is a diagram for explaining an overview of a communication system according to an embodiment.
[0019] Figure 2 This is a diagram for explaining an overview of a communication system according to another example of the embodiment.
[0020] Figure 3 This is a block diagram showing an example of the functional structure of a certificate issuing (signing) device according to an embodiment.
[0021] Figure 4 This is a block diagram showing an example of the functional structure of a public key (symmetric key) issuing device according to an embodiment.
[0022] Figure 5 This is a block diagram showing another example of the functional structure of the public key issuing device involved in the embodiment.
[0023] Figure 6 This is a block diagram showing an example of the functional structure of a terminal device involved in the implementation manner.
[0024] Figure 7This is a block diagram showing another example of the functional structure of the terminal device involved in the embodiment.
[0025] Figure 8 This is a block diagram showing an example of the functional structure of a terminal device involved in the implementation manner.
[0026] Fig. 9 It is a sequence diagram for explaining an example of the operation (work) of the communication system according to the embodiment.
[0027] Fig.10 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0028] Fig.11 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0029] Fig.12 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0030] Fig.13 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0031] Fig.14 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0032] Fig.15 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0033] Fig.16 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0034] Fig.17 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0035] Fig.18 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0036] Fig.19 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0037] Fig. 20 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0038] Fig.21 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0039] Fig. 22 This is a sequence diagram for explaining an example of the operation of the communication system according to the embodiment.
[0040] Fig.23 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0041] Fig.24 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0042] Fig.25 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0043] Fig.26 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0044] Fig. 27 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0045] Fig.28 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0046] Fig.29 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0047] Fig.30 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0048] Fig.31 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0049] Fig.32 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0050] Fig.33 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0051] Fig.34 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0052] Fig.35 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0053] Fig.36 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0054] Fig.37This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0055] Fig.38 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0056] Fig.39 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0057] Fig.40 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0058] Fig.41 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0059] Fig.42 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0060] Fig.43 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0061] Fig.44 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0062] Fig.45 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0063] Fig.46 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0064] Fig.47 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0065] Fig.48 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0066] Fig.49 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0067] Fig.50 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0068] Fig.51 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0069] Fig.52 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0070] Fig.53 This is a sequence diagram for explaining an example of the operation of the communication system according to the modification of the embodiment.
[0071] Fig.54 This is a sequence diagram for explaining an example of the operation of the communication system according to the modification of the embodiment.
[0072] Fig.55 This is a sequence diagram for explaining an example of the operation of the communication system according to the modification of the embodiment.
[0073] Fig.56 This is a sequence diagram for explaining an example of the operation of the communication system according to the modification of the embodiment. DETAILED DESCRIPTION
[0074] (Insights that form the basis of this disclosure)
[0075] In recent years, the development of quantum computers has been prevalent. On the other hand, it is well known that due to the large-scale development of quantum computers, the currently used encryption method (hereinafter referred to as the classical encryption method, or simply the classical method) will theoretically lose security guarantees. In view of this situation, a new encryption method (hereinafter referred to as the PQC (Post Quantum Cryptography) method) that can withstand the computing performance of large-scale quantum computers has been proposed, and preparations are being made for migration from the classical method. However, the history of the PQC method is still very short, and it cannot be said that a full evaluation of security has been conducted. In other words, when the PQC method is used directly, the security of encryption cannot be guaranteed. Therefore, it is believed that it is best to use a method that uses both the classical method and the PQC method (hereinafter referred to as a hybrid method) during the transition period before the security evaluation is fully completed. As a classical method, RSA or EC-DSA (Elliptic Curve-Digital Signature Algorithm) can be used.
[0076] However, although the hybrid method is effective for maintaining security in the long term, it needs to be dealt with on the communication device side. In other words, this method cannot be used in communications with existing devices that do not support the hybrid method (no backward compatibility). Therefore, it is necessary to confirm whether the device on the other side supports the hybrid method during communication.
[0077] This disclosure describes a communication method for more appropriately applying the hybrid method, taking communication in which one device (second device) authenticates the other device (first device) and exchanges keys as an example. The overview of this communication method is as follows.
[0078] First, a non-critical extension area for confirming the hybrid support status of the second device side is added as a confirmation mark to the classical certificate sent by the first device. If the second device side supports the hybrid method, the mark is read and the confirmation mark is returned together with the Nonce. Then, the first device side uses both the received Nonce and the confirmation mark to generate a signature. In this way, for example, even if the communication is eavesdropped when the confirmation mark is returned from the second device side together with the Nonce and only the tampered Nonce is sent to the first device side, because the confirmation mark is not included in the signature further sent from the first device, the second device side can detect tampering based on the mismatch (inconsistency) with the Nonce and the confirmation mark used for sending. That is to say, from the point of view of being able to safely confirm the hybrid support status, the hybrid method can be more appropriately applied.
[0079] (Overview of the present disclosure)
[0080] A summary of the present disclosure is as follows.
[0081] The communication method involved in the first aspect of the present disclosure is a communication method between a first device and a second device, the first device sends a certificate of a first encryption method to the second device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the first device receives a message including a Nonce and a confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce and the confirmation mark included in the received message to the second device, and when the first device receives a message including a Nonce but not including a confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce included in the received message to the second device.
[0082] According to such a communication method, it is possible to detect whether the message has been tampered with using the message sent as a response from the second device and the signature received from the first device thereafter. In other words, the second device can obtain information for detecting whether the message has been tampered with. Thus, from the perspective of being able to safely confirm the hybrid support state, the hybrid method can be more appropriately applied.
[0083] In addition, the communication method involved in the second aspect of the present disclosure is based on the communication method described in the first aspect. When the first device receives a detection flag generated by the second device indicating that there is tampering with the message, the communication session between the first device and the second device is continued in a different encryption method. The detection flag is generated based on the mismatch between the message sent by the second device in response to the sending of the certificate and the signature sent from the first device to the second device in response to the reception of the message.
[0084] According to this, based on the reception of the detection flag indicating that there has been tampering with the message, it is possible to continue the communication session between the first device and the second device using a different encryption method.
[0085] In addition, the communication method involved in the third aspect of the present disclosure is based on the communication method described in the first aspect, and ends the communication session between the first device and the second device when the first device receives a detection flag generated by the second device indicating that there is tampering with the message, and the detection flag is generated based on the mismatch between the message sent by the second device in response to the sending of the certificate and the signature sent from the first device to the second device in response to the reception of the message.
[0086] According to this, the communication session between the first device and the second device can be terminated based on the reception of the detection flag indicating that there has been tampering with the message.
[0087] In addition, a communication method according to a fourth aspect of the present disclosure is based on the communication method described in any one of the first to third aspects, wherein the first encryption method is an RSA method or an EC-DSA method, and the different encryption method is a PQC method.
[0088] Based on this, a hybrid method that uses the RSA method or the EC-DSA method and the PQC method can be more appropriately applied.
[0089] In addition, the communication method involved in the fifth aspect of the present disclosure is a communication method between a first device and a second device, the second device receives a certificate of a first encryption method from the first device, the certificate includes a confirmation mark indicating support for an encryption method different from the first encryption method, when the second device supports different encryption methods, as a response to the received certificate, the second device sends a message including a Nonce and a confirmation mark to the first device, when the second device does not support different encryption methods, as a response to the received certificate, the second device sends a message including a Nonce and not including a confirmation mark to the first device, and the second device receives from the first device a signature generated based on the Nonce contained in the sent message, and either the Nonce and the confirmation mark.
[0090] According to this, using the message sent as a response from the second device and the signature received from the first device thereafter, it is possible to detect whether the message has been tampered with. In other words, the second device can obtain information for detecting whether the message has been tampered with. Therefore, from the perspective of being able to safely confirm the hybrid support state, the hybrid method can be more appropriately applied.
[0091] In addition, the communication method involved in the sixth aspect of the present disclosure is a communication method between a first device and a second device, the first device sends a certificate of a first encryption method to the second device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the second device supports different encryption methods, as a response to the received certificate, the second device sends a message including Nonce and a confirmation mark to the first device, and when the second device does not support different encryption methods, as a response to the received certificate, the second device sends a message including Nonce and not including a confirmation mark to the first device, and when the first device receives a message including Nonce and a confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce and the confirmation mark included in the received message to the second device, and when the first device receives a message including Nonce and not including a confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce included in the received message to the second device.
[0092] According to this, using the message sent as a response from the second device and the signature received from the first device thereafter, it is possible to detect whether the message has been tampered with. In other words, the second device can obtain information for detecting whether the message has been tampered with. Therefore, from the perspective of being able to safely confirm the hybrid support state, the hybrid method can be more appropriately applied.
[0093] In addition, the first device involved in the seventh aspect of the present disclosure is a first device capable of communicating with a second device, and comprises: a certificate generation unit, which generates a certificate for a first encryption method, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method; and a signature generation unit, which, when sending the generated certificate to the second device, receives a message including a Nonce and a confirmation mark as a response from the second device, generates a signature based on the Nonce and the confirmation mark included in the received message; and, when sending the generated certificate to the second device, receives a message including a Nonce and not including a confirmation mark as a response from the second device, generates a signature based on the Nonce included in the received message.
[0094] This achieves the same effect as the above-mentioned communication method.
[0095] In addition, the second device involved in the eighth aspect of the present disclosure is a second device capable of communicating with the first device, and comprises: a message generating unit, which, when receiving a certificate of the first encryption method from the first device including a confirmation mark indicating support for an encryption method different from the first encryption method, generates a message including a Nonce and a confirmation mark as a response to the received certificate if the second device supports different encryption methods, and generates a message including a Nonce and no confirmation mark as a response to the received certificate if the second device does not support different encryption methods; and a communication unit, which receives from the first device a signature generated based on the Nonce contained in the sent message, and either the Nonce and the confirmation mark.
[0096] This achieves the same effect as the above-mentioned communication method.
[0097] In addition, the program involved in the 9th aspect of the present disclosure is a program for causing a computer to execute a communication method between a first device and a second device, in which the first device sends a certificate of a first encryption method to a second device, the certificate including a confirmation mark indicating support for an encryption method different from the first encryption method, and when the first device receives a message including a Nonce and a confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce and the confirmation mark included in the received message to the second device, and when the first device receives a message including a Nonce and not including a confirmation mark from the second device as a response to the sending of the certificate, the first device sends a signature generated based on the Nonce included in the received message to the second device.
[0098] According to this, by using a computer, the same effect as the above-mentioned communication method can be achieved.
[0099] In addition, the program involved in the 10th aspect of the present disclosure is a program for causing a computer to execute a communication method between a first device and a second device. In the communication method, the second device receives a certificate of a first encryption method from the first device, and the certificate includes a confirmation mark indicating support for an encryption method different from the first encryption method. When the second device supports a different encryption method, as a response to the received certificate, the second device sends a message including a Nonce and a confirmation mark to the first device. When the second device does not support a different encryption method, as a response to the received certificate, the second device sends a message including a Nonce and not including a confirmation mark to the first device. The second device receives from the first device a signature generated based on the Nonce contained in the sent message, and either the Nonce and the confirmation mark.
[0100] According to this, by using a computer, the same effect as the above-mentioned communication method can be achieved.
[0101] In addition, these general or specific technical solutions can be implemented by devices, integrated circuits, computer programs, or non-transitory recording media such as computer-readable CD-ROMs, or by any combination of devices, integrated circuits, computer programs, and non-transitory recording media.
[0102] Hereinafter, the embodiments will be described in detail with reference to the accompanying drawings as appropriate. However, unnecessary detailed descriptions may be omitted. For example, detailed descriptions of well-known matters and repeated descriptions of substantially the same structures may be omitted. This is to avoid the following description from becoming unnecessarily lengthy and to make it easy for those skilled in the art to understand.
[0103] In addition, the inventor provides the drawings and the following description in order to enable those skilled in the art to fully understand the present disclosure, and does not intend to limit the subject matter described in the claims by these.
[0104] (Implementation Method)
[0105] [constitute]
[0106] Figure 1 FIG. 1 is a diagram for explaining an overview of a communication system according to an embodiment of the present invention. Figure 1 , as devices involved in communication, a terminal device 300 corresponding to a first device and a terminal device 400 corresponding to a second device are shown.
[0107] The certificate issuing device 100 generates an electronic signature certificate used by the user, and transmits the certificate to the terminal devices 300 and 400. The certificate issuing device 100 is implemented by, for example, a server device belonging to a certificate issuing organization.
[0108] The public key issuing device 200 generates different public keys for each terminal device 300 and 400 used by the user, and embeds the public keys into the terminal devices 300 and 400. The public key issuing device 200 is operated by, for example, a terminal device manufacturing company that manufactures the terminal devices 300 and 400. In addition to the above, the public key issuing device 200 may also generate a common test message and flag for each terminal device 300 and 400 used by the user, and embed the test message and flag into the terminal devices 300 and 400.
[0109] The terminal device 300 performs communication between terminal devices (with the terminal device 400), random number generation processing, signature generation processing, session key generation processing, etc. In addition to the above, the terminal device 300 can also perform key generation.
[0110] The terminal device 400 performs communication between terminal devices (with the terminal device 300 ), random number generation processing, signature verification processing, session key generation processing, and the like.
[0111] also, Figure 2 This is a diagram for explaining an overview of a communication system according to another example of the embodiment. In this example, the public key issuing device 200 is managed and operated by respective users so as to be connectable to the terminal devices 300 and 400 .
[0112] Figure 3 1 is a block diagram showing an example of the functional structure of the certificate issuing device involved in the embodiment. The certificate issuing device 100 is implemented by a processor, a memory, and a predetermined program stored in the memory. The certificate issuing device 100 generates an electronic signature certificate used by the user and sends the certificate to the terminal devices 300 and 400. The certificate issuing device 100 has a random number generation unit 101, a flag generation unit 102, a key generation unit 103, a signature generation unit 104, a certificate generation unit 105, and a communication unit 106 as a functional structure.
[0113] The random number generation unit 101 performs random number generation processing, notifies the key generation unit 103 of the generated random number A, and notifies the signature generation unit 104 of the generated random number B. However, the random number A and the random number B may be different. The random number may not be a uniform random number.
[0114] The flag generation unit 102 generates a flag indicating that the certificate supports (corresponds to) multiple algorithms (the so-called algorithm means encryption method), and notifies the signature generation unit 104 and the certificate generation unit 105. However, the flag may be in binary, integer value, or other forms. The flag may be a specified flag or other flag. There may be multiple flags depending on the type and number of algorithms supported by the certificate.
[0115] The key generation unit 103 performs generation processing of a private key A, a public key B, a private key C, and a public key D, notifies the private key A and the public key D to the signature generation unit 104, notifies the public key D to the certificate generation unit 105, and notifies the public key B and the private key C to the communication unit 106. The public key B is notified to the terminal device 400, and the private key C is notified to the terminal device 300. However, the key generation unit 103 may create a plurality of private keys and public keys, or may create a common key.
[0116] The signature generation unit 104 performs signature processing based on the private key A on the plain text including the public key D and the flag notified from the flag generation unit 102, and notifies the generated signature to the certificate generation unit 105. However, several signatures may be generated, and the number of plain texts and the number of private keys used to generate signatures are not limited. The plain text may also include the public key or public key notified from the terminal device 300.
[0117] The certificate generation unit 105 creates a certificate including the flag notified from the flag generation unit 102 , the signature notified from the signature generation unit 104 , and the public key D notified from the key generation unit 103 , and notifies the communication unit 106 and the terminal device 300 .
[0118] Figure 4 1 is a block diagram showing an example of the functional structure of the public key issuing device involved in the embodiment. The public key issuing device 200 is implemented by a processor, a memory, and a predetermined program stored in the memory. The public key issuing device 200 generates different public keys according to the terminal devices 300 and 400 used by the user, and embeds the public keys into each terminal device 300 and 400. The public key issuing device 200 has a random number generation unit 201, a public key generation unit 202, and a communication unit 203 as a functional structure.
[0119] The random number generation unit 201 performs random number generation processing and notifies the generated random number to the common key generation unit 202. However, a plurality of random numbers may be generated, and the random numbers may not be uniform random numbers.
[0120] The public key generation unit 202 performs the public key generation process and notifies the communication unit 203 of the generated public key. However, multiple public keys may be generated. Figure 2 As shown, in another example of the embodiment, the public key issuing device 200 may be attached to the terminal devices 300 and 400 of each user.
[0121] Figure 5 200a can also generate a common test message and a flag for the terminal devices 300 and 400 used by the user, and embed the test message and the flag into the terminal devices 300 and 400, which is suitable for example Figure 1 The public key issuing device 200a in this example has a random number generating unit 201a, a flag generating unit 202a, a test message generating unit 203a, a public key generating unit 204a, and a communication unit 205a as a functional structure.
[0122] The random number generation unit 201a performs random number generation processing, notifies the generated random number A to the flag generation unit 202a, notifies the generated random number B to the test message generation unit 203a, and notifies the generated random number C to the public key generation unit 204a. However, the random number A, the random number B, and the random number C may be different. The random number may not be a uniform random number.
[0123] The flag generation unit 202a generates a flag indicating that the certificate supports multiple algorithms and notifies the communication unit 205a. However, the flag may be in binary or integer form. The flag may be specified or not. There may be multiple flags depending on the type and number of algorithms supported by the certificate.
[0124] The test message generation unit 203a performs the test message generation process and sends the test message to the communication unit 205a. However, the flag may be in binary or integer form. The test message may be specified or not. There may be multiple test messages depending on the purpose.
[0125] The common key generation unit 204a performs common key generation processing and notifies the communication unit 205a of the generated common key. However, a plurality of common keys may be generated.
[0126] Figure 6 1 is a block diagram showing an example of the functional structure of a terminal device involved in the embodiment. The terminal device 300 is implemented by a processor, a memory, and a predetermined program stored in the memory. The terminal device 300 performs communication between terminal devices, random number generation processing, signature generation processing, session key generation processing, etc. The terminal device 300 has a random number generation unit 301, a signature generation unit 302, a session key generation unit 303, a session key confirmation unit 304, a certificate storage unit 305, and a communication unit 306 as a functional structure.
[0127] The random number generation unit 301 performs signature generation processing and notifies the generated random number to the signature generation unit 302. However, a plurality of random numbers may be generated, and the random numbers may not be uniform random numbers.
[0128] The signature generation unit 302 performs a signature process based on the private key C notified from the key generation unit 103 on the plain text including the flag and the Nonce, and notifies the communication unit 306 of the generated signature, and notifies the terminal device 400. However, a plurality of signatures may be generated, and there is no particular limitation on how many plain texts and how many private keys are used to generate signatures. The plain text may not include the flag and the Nonce, and may not be a signature based on the private key C notified from the key generation unit 103.
[0129] Session key generation unit 303 performs session key generation processing for key exchange, and notifies communication unit 306 and terminal device 400. However, a plurality of session keys may be generated, and an encrypted test message may be notified together with the session key.
[0130] Session key confirmation unit 304 performs confirmation processing on the session key notified from session key generation unit 303, and notifies the confirmation result to communication unit 306. However, a plurality of session keys may be confirmed, and a session key other than the session key notified from session key generation unit 303 may be confirmed.
[0131] The certificate storage unit 305 stores the certificate notified from the certificate generation unit 105. In addition, the certificate is notified to the communication unit 306 and the certificate is notified to the terminal device 400 as necessary.
[0132] Figure 7 1 is a block diagram showing another example of the functional structure of the terminal device involved in the embodiment. The terminal device 300a can also perform key generation. The terminal device 300a in this example has a random number generation unit 301a, a signature generation unit 302a, a session key generation unit 303a, a session key confirmation unit 304a, a certificate storage unit 305a, a key generation unit 306a and a communication unit 307a as a functional structure. The functions of the random number generation unit 301a, the signature generation unit 302a, the session key generation unit 303a, the session key confirmation unit 304a, the certificate storage unit 305a and the communication unit 307a are respectively the same as the random number generation unit 301, the signature generation unit 302, the session key generation unit 303, the session key confirmation unit 304, the certificate storage unit 305 and the communication unit 306, so the description is omitted.
[0133] The key generation unit 306a generates a private key C and a public key D, notifies the communication unit 307a, and notifies the certificate issuing device 100. However, the key generation unit 306a may generate a plurality of private keys and public keys, or may generate a common key.
[0134] Figure 8 1 is a block diagram showing an example of the functional structure of a terminal device involved in the embodiment. The terminal device 400 is implemented by a processor, a memory, and a predetermined program stored in the memory. The terminal device 400 performs communication between terminal devices, random number generation processing, signature verification processing, session key generation processing, etc. The terminal device 400 has a random number generation unit 401, a Nonce flag generation unit 402, a session key generation unit 403, a signature verification unit 404, a certificate verification unit 405, a certificate reading unit 406, and a communication unit 407 as a functional structure.
[0135] The random number generation unit 401 performs random number generation processing, notifies the Nonce flag generation unit 402 of the generated random number A, and notifies the session key generation unit 403 of the generated random number B. However, the random number A and the random number B may be different. The random number may not be a uniform random number.
[0136] The Nonce flag generation unit 402 performs the generation process of the Nonce for signature and the flag for attack detection notification. The Nonce is notified to the communication unit 407 and notified to the terminal device 300. The flag is notified to the session key generation unit 403. However, the Nonce flag generation unit 402 does not necessarily need to generate both the Nonce and the flag, and may generate only one side. In addition, the generated Nonce and flag may be of multiple types, and multiple Nonce and flags may be generated.
[0137] The signature verification unit 404 performs verification processing on the signature notified from the certificate verification unit 405, and notifies the verification result to the certificate verification unit 405. However, the signature verification unit 404 may verify a plurality of signatures.
[0138] The certificate verification unit 405 extracts the signature portion of the certificate required for verification based on the certificate and the verification method notified from the certificate reading unit 406, and notifies the signature verification unit 404. However, the certificate verification unit 405 may verify a plurality of certificates.
[0139] The certificate reading unit 406 analyzes the certificate notified from the certificate storage unit 305, and reads the presence or absence of a flag, the number and type of signatures, the number and type of public keys, etc. Furthermore, based on the read information, a method for verifying the certificate (e.g., the order of signatures to be verified, etc.) is determined, and the determined method and certificate are notified to the certificate verification unit.
[0140] [action]
[0141] Next, the operation of the communication system according to the embodiment will be described. Figure 9 to Figure 22 is a timing diagram illustrating an example of the operation of the communication system involved in the embodiment. Figure 23 to Figure 52 This is a diagram showing an example of screen display during operation of the communication system according to the embodiment.
[0142] When the operation of the communication system starts, first, the certificate issuing device 100 creates a first algorithm public key and a private key for the certificate issuing authority (S101). Specifically, the key generation unit 103 creates these public keys and private keys. In addition, the certificate issuing device 100 creates a second algorithm public key and a private key for the certificate issuing authority (S102). Specifically, the key generation unit 103 creates these public keys and private keys.
[0143] Here, the terminal device 400 sends a request for the public key of the certificate issuing authority to the certificate issuing device 100. For example, in the terminal device 400, Fig.23 The key generation setting screen shown in the figure is as follows. Fig.24 Select "Public Key" as shown, and send a request for the public key to the certificate issuing authority. In the certificate issuing device 100, it is determined whether the terminal device 400 supports the hybrid method (S103). For example, in the terminal device 400, it is displayed Fig.26 Whether mixed input screen is supported, such as Fig. 27 Select "Support" as shown. Then, switch to Fig.28 The screen for selecting whether to issue a hybrid certificate is shown. Fig.29 Selecting "Yes" as shown will input the fact that the hybrid mode is supported into the communication system.
[0144] When it is determined that the terminal device 400 supports the hybrid method ( S103 : “Supported”), the certificate issuing device 100 transmits the certificate issuing authority first algorithm public key and the certificate issuing authority second algorithm public key to the terminal device 400 .
[0145] exist Fig.28 In the screen shown, Fig.29 After selecting "Yes" as shown, for example, Fig.30 As shown, the screen for selecting the first algorithm from several options is switched to. First, as the first algorithm, for example, Fig.31 As shown in the figure, "Algorithm A" is selected from several options. Then, Fig.32 As shown, the screen switches to the second algorithm selection screen from several options. Fig.33 As shown in the figure, when "Algorithm E" is selected from several options, the certificate issuing authority of "Algorithm A" uses the first algorithm public key and the certificate issuing authority of "Algorithm E" uses the second algorithm public key, and displays Fig.34 The screen shown.
[0146] On the other hand, when it is determined that the terminal device 400 does not support the hybrid method ( S103 : “Not supported”), the certificate issuing device 100 transmits only the certificate issuing authority's first algorithm public key to the terminal device 400 .
[0147] For example, in Fig.28 In the screen shown, Fig.35 After selecting "No" as shown in Fig.36 As shown in FIG. 1 , the screen for selecting the first algorithm from several options is switched to. As the first algorithm, for example, Fig.37 When "Algorithm A" is selected from several options as shown, the certificate issuing authority that creates "Algorithm A" uses the first algorithm public key and displays Fig.34The screen shown.
[0148] In addition, for example, Fig.26 In the screen shown, Fig.38 If you select "Not Supported" as shown, the Fig.36 The screen shown in the figure switches to Fig.37 The screen shown in the figure switches to Fig.34 The screen shown.
[0149] Enter Fig.10 At N1, the terminal device 300 sends a request for a certificate and a private key to the certificate issuing device 100. For example, in the terminal device 300, Fig.23 The key generation setting screen shown in the figure is as follows. Fig.25 Select "Certificate and Private Key" as shown, and send a request for a certificate and a private key. In the certificate issuing device 100, it is determined whether the terminal device 300 supports the hybrid method (S201). For example, in the terminal device 300, it is displayed Fig.26 Whether mixed input screen is supported, such as Fig. 27 Select "Support" as shown. Then, switch to Fig.28 The screen for selecting whether to issue a hybrid certificate is shown. Fig.29 Select "Yes" as shown, and input the fact that the hybrid mode is supported to the communication system. Figure 30 to Figure 38 Therefore, the description is omitted.
[0150] When it is determined that the terminal device 300 supports the hybrid method (S201: "Support"), the certificate issuing device 100 creates a first algorithm public key and a private key for the certificate (S202). In addition, the certificate issuing device 100 creates a second algorithm public key and a private key for the certificate (S203). In addition, the certificate issuing device 100 creates a first algorithm certificate (S204). In addition, the certificate issuing device 100 creates a second algorithm certificate (S205). Moreover, the certificate issuing device 100 sends the first algorithm certificate and the corresponding private key and the second algorithm certificate and the corresponding private key to the terminal device 300. On the other hand, when it is determined that the terminal device 300 does not support the hybrid method (S201: "Support"), enter Fig.13 N2. Fig.13 Provide explanation.
[0151] Here, Fig.11 as well as Fig.12 Another example of the above-mentioned operation is shown. More specifically, the public key issuing device 200 performs a part of the above-mentioned processing. In addition, in the operation involved in this other example, the terminal device 400 and the terminal device 300 may also perform the operation. Figure 23 to Figure 38The screen display shown and the acceptance of operations on the screen. For example, Fig.11 Relative to Fig. 9 , the public key issuing device 200 sends a request for the public key for the certificate issuing agency to the certificate issuing device 100. In addition, step S301 and step S302 are respectively the same as step S101 and step S102, and therefore the description is omitted. Then, the certificate issuing device 100 determines whether the terminal device 400 supports the hybrid mode (S303) in the same way as step S103. When it is determined that the terminal device 400 supports the hybrid mode (S303: "Support"), the certificate issuing device 100 sends the first algorithm public key for the certificate issuing agency and the second algorithm public key for the certificate issuing agency to the terminal device 400 via the public key issuing device 200. On the other hand, when it is determined that the terminal device 400 does not support the hybrid mode (S303: "Not Support"), the certificate issuing device 100 sends only the first algorithm public key for the certificate issuing agency to the terminal device 400 via the public key issuing device 200.
[0152] Enter Fig.12 N3, here, the public key issuing device 200 sends a request for a certificate and a private key to the certificate issuing device 100. The certificate issuing device 100 determines whether the terminal device 300 supports the hybrid method in the same way as step S201 (S401). Steps S402 to S405 are respectively the same as steps S202 to S205, so the description is omitted. When it is determined that the terminal device 300 supports the hybrid method (S401: "Support"), the certificate issuing device 100 executes steps S402 to S405, and then sends the first algorithm certificate and the corresponding private key and the second algorithm certificate and the corresponding private key to the terminal device 300 via the public key issuing device 200. When it is determined that the terminal device 300 does not support the hybrid method (S401: "Not Supported"), enter Fig.13 N2.
[0153] like Fig.13 As shown, when Fig.10 S201 is judged as "not supported" or Fig.12 If it is determined as "not supported" in S401, the certificate issuing device 100 creates a first algorithm public key and a private key for the certificate (S501). Furthermore, the certificate issuing device 100 creates a first algorithm certificate (S502) and sends the first algorithm certificate and the corresponding private key to the terminal device 300. After that, the process ends.
[0154] In addition, Figure 4 In the case of the structure shown, Fig.14 As shown, the public key issuing device 200 creates a public key (S601) and transmits it to the terminal device 400. Thereafter, the process ends.
[0155] In addition, Figure 5 In the case of the structure shown, Fig.15 As shown, the public key issuing device 200 creates a token (S701), creates a test message (S702), and creates a public key (S703). Then, the public key issuing device 200 sends the token to the terminal devices 300 and 400. In addition, the public key issuing device 200 sends the test message to the terminal devices 300 and 400. Furthermore, the public key issuing device 200 sends the public key to the terminal device 400. After that, the process ends.
[0156] Then, if Fig.16 As shown, a preliminary communication is performed between the terminal device 300 and the terminal device 400 to confirm whether communication in a hybrid mode is possible. First, the terminal device 300 sends a first algorithm certificate to the terminal device 400. At this time, in the first algorithm certificate, a confirmation mark is included in the non-critical extension area, and the confirmation mark indicates that hybrid communication is supported, that is, an encryption method that combines the classical method (first encryption method) and the PQC method (second encryption method). More specifically, in this communication method, when issuing the first algorithm certificate, the first algorithm certificate including the confirmation mark in the non-critical extension area is issued.
[0157] In the terminal device 400, when the first algorithm certificate is received, a Nonce is created (S801). Here, if the terminal device 400 supports the hybrid mode, the terminal device 400 generates a Nonce and a confirmation flag. If the terminal device 400 does not support the hybrid mode, the terminal device 400 only generates a Nonce. Therefore, when it is determined that there is no flag (S802: "None") in the determination of whether there is a flag (confirmation flag) (S802), the terminal device 400 does not support the hybrid mode. In this case, enter Fig.19 N4. Fig.19 For example, when the terminal device 400 displays Fig.40 The mark confirmation screen shown in the figure can confirm that there is no mark. Then, switch to Fig.43 The screen shown is displayed and ends.
[0158] On the other hand, if it is determined that the flag is present (S802: "Yes"), the terminal device 400 supports the hybrid mode. Fig.39 The mark confirmation screen shown in the figure can confirm the mark. Fig.43 As a response to the certificate, the terminal device 400 sends a Nonce and a confirmation flag, or only a Nonce, to the terminal device 300. The Nonce is, for example, a 128-bit random number.
[0159] The terminal device 300 determines whether there is a flag (S803). If it is determined that there is no flag (S803: "None"), the terminal device 400 does not support the hybrid mode. In this case, enter Fig. 20 N5. Fig. 20 For example, when the terminal device 300 displays Fig.42 The mark confirmation screen shown in the figure can confirm that there is no mark. Then, switch to Fig.43 The screen shown is displayed and ends.
[0160] On the other hand, if it is determined that the flag is present (S803: "Yes"), the terminal device 400 supports the hybrid mode. Fig.41 The mark confirmation screen shown in the figure can confirm the mark. Fig.43 The terminal device 300 creates a first algorithm signature (S804). Specifically, the terminal device 300 generates the first algorithm signature by signing a value obtained by combining the Nonce, the confirmation flag, and the session key using a conventional encryption method such as the EC-DSA method.
[0161] The terminal device 300 sends the generated first algorithm signature to the terminal device 400. The terminal device 400 verifies the first algorithm certificate (S805). At this time, the public key corresponding to the private key is extracted. Next, the terminal device 400 verifies the first algorithm signature (S806). The extracted public key is used in the verification.
[0162] Enter Fig.17 At N6, the terminal device 400 creates a session key (S901). Specifically, the terminal device 400 generates a 128-bit shared key based on the public key received from the terminal device 300 and the private key generated by the terminal device 400. The terminal device 400 uses the session key to encrypt the public key and the test message used for communication between the terminal devices 300 and 400 (S902). Specifically, the terminal device 400 encrypts the public key and the test message in AES mode using the generated 128-bit key and sends them.
[0163] The terminal device 400 sends the encrypted test message to the terminal device 300. The terminal device 300 creates a session key (S903). Specifically, the terminal device 300 further uses the session key to decrypt the public key and the test message (S904). Afterwards, the terminal device 300 decrypts the received encrypted public key to verify the test message.
[0164] Then, the terminal device 300 sends the second algorithm certificate to the terminal device 400. In the terminal device 400, a Nonce is created (S905), and the created Nonce is sent to the terminal device 300. In the terminal device 300, a second algorithm signature is created (S906), and the created second algorithm signature is sent to the terminal device 400.
[0165] Enter Fig.18 At N7, the terminal device 400 verifies the second algorithm certificate (S1001). In addition, the terminal device 400 verifies the second algorithm signature (S1002). After that, the terminal device 400 creates a session key (S1003), and encrypts the public key using the created session key (S1004). The terminal device 400 sends the encrypted public key to the terminal device 300. In the terminal device 300, a session key is created (S1005), and the encrypted public key is decrypted using the session key (S1006). In this way, communication under the hybrid method is established (ending the prior communication processing that supports confirmation).
[0166] Here, it is explained Fig.19 After the judgment of "None" in S802, the terminal device 400 sends the Nonce to the terminal device 300. Since the terminal device 400 does not support the hybrid mode, the terminal device 300 acts in a manner of communicating according to the first algorithm. First, the terminal device 300 creates a first algorithm signature (S1101). The terminal device 300 sends the created first algorithm signature to the terminal device 400.
[0167] Then, in the terminal device 400, the first algorithm certificate is verified (S1102), the first algorithm signature is verified (S1103), and a session key is created (S1104). Furthermore, the terminal device 400 encrypts the public key using the created session key (S1105). The terminal device 400 sends the encrypted public key to the terminal device 300. In the terminal device 300, a session key is created (S1106), and the encrypted public key is decrypted using the session key (S1107). In this way, communication according to the first algorithm (i.e., the classical method) is established (the prior communication processing supporting confirmation is terminated).
[0168] In addition, the description Fig. 20 After the judgment in S803 is "None", the terminal device 300 creates a first algorithm signature (S1201). The terminal device 300 sends the created first algorithm signature to the terminal device 400. In the terminal device 400, the first algorithm certificate is verified (S1202), and the first algorithm signature is verified (S1203). For example, the display Fig.44The verification screen of the first algorithm signature shown in FIG. At this time, if the verification fails (NG) (S1203: "Verification failed"), enter Fig.21 N8. I will talk to you later. Fig.21 Provide explanation.
[0169] If the verification of the first algorithm signature is successful (OK) (S1203: "Verification successful"), the session key creation process is performed (S1204). Fig.45 The screen showing the verification result is "OK" is displayed, and the Fig.46 The screen indicating the end of verification is shown. Then, the terminal device 400 encrypts the public key using the created session key (S1205). The terminal device 400 sends the encrypted public key to the terminal device 300. In the terminal device 300, a session key is created (S1206), and the encrypted public key is decrypted using the session key (S1207). In this way, communication according to the first algorithm (i.e., the classical method) is established (the prior communication processing supporting confirmation is completed).
[0170] Next, explain Fig.21 If the verification of the first algorithm signature fails (S1203: "Verification failed"), the terminal device 400 determines whether to continue communication or terminate communication (S1301). For example, display Fig.47 The screen showing the verification result is "NG" is displayed, and the Fig.48 The screen for selecting whether to continue or end the communication is shown. When the terminal device 400 determines that the communication is to be ended (S1301: "communication is ended"), the communication is ended and all processing is ended. Fig.51 When you select "End" as shown, the Fig.52 On the other hand, when the terminal device 400 determines that the communication is to be continued (S1301: "Communication continues"), the terminal device 400 creates a session key (S1302). Fig.49 When you select "Continue Communication" as shown, the Fig.50 The screen indicating the continuation of communication is shown. Then, the terminal device 400 encrypts the detection flag using the created session key (S1303). The detection flag is a flag indicating that there is tampering with the message. In other words, since it is possible that the attacker has changed the communication to the classical mode, if the communication is to be continued, it is preferably continued in the PQC mode. Therefore, afterwards, it will be switched to the communication according to the second algorithm equivalent to the PQC mode.
[0171] The terminal device 400 sends the encrypted detection flag to the terminal device 300. Then, the terminal device 400 creates a session key (S1304) and decrypts the encrypted detection flag using the session key (S1305). In this way, in the terminal device 300, tampering is detected by receiving the detection flag. After that, the terminal device 300 sends the second algorithm certificate to the terminal device 400. The terminal device 400 creates a Nonce (S1306) and sends the created Nonce to the terminal device 300.
[0172] Enter Fig. 22 At N9, the terminal device 300 creates a second algorithm signature (S1401) and sends the created second algorithm signature to the terminal device 400. The terminal device 400 verifies the second algorithm certificate (S1402). In addition, the terminal device 400 verifies the second algorithm signature (S1403). After that, the terminal device 400 creates a session key (S1404) and encrypts the public key using the created session key (S1405). The terminal device 400 sends the encrypted public key to the terminal device 300. In the terminal device 300, a session key is created (S1406), and the encrypted public key is decrypted using the session key (S1407). In this way, communication under the PQC method is established (ending the prior communication processing that supports confirmation).
[0173] [Modifications]
[0174] In the modified example described below, Fig.16 , Fig.17 , Fig.19 as well as Fig. 20 Corresponding Figure 53 to Figure 56 In the description, the differences from the above-mentioned embodiment are mainly described, and the description of the same points as the above-mentioned embodiment is omitted. Figure 53 to Figure 56 This is a sequence diagram for explaining an example of the operation of the communication system according to the modification of the embodiment.
[0175] In the above embodiment, if Figure 30 to Figure 33 , Figure 36-37 As shown in FIG. 1 , it is explained that the first algorithm and the second algorithm are selected from several options and used. It is necessary to check which algorithm is selected between the terminal device 300 and the terminal device 400. However, in this case, a function of confirming whether the selected algorithms are the same may be added to the communication system. Therefore, in the communication system involved in the modified example, in addition to Figures 16 to 20 In addition to the actions described in , steps (S800, S900, S1100 and S1200) are added to confirm whether the algorithms are the same.
[0176] Fig.53 and Fig.16 Corresponding, except Fig.16 In addition to the operation of the communication system shown in the figure, a step of confirming whether the algorithms are the same is added (S800). Here, after the terminal device 300 sends the generated first algorithm signature to the terminal device 400, the terminal device 400 confirms whether the first algorithm is the same (S800). In addition, the terminal device 300 may confirm whether the algorithm to be used as the first algorithm is the same as the algorithm selected as the first algorithm in the terminal device 400.
[0177] Fig.54 and Fig.17 Corresponding, except Fig.17 In addition to the operation of the communication system shown in the figure, a step of confirming whether the algorithms are the same is added (S900). Here, after the terminal device 300 sends the generated second algorithm signature to the terminal device 400, the terminal device 400 confirms whether the second algorithm is the same (S900). In addition, the terminal device 300 may confirm whether the algorithm to be used as the second algorithm is the same as the algorithm selected as the second algorithm in the terminal device 400.
[0178] Fig.55 and Fig.19 Corresponding, except Fig.19 In addition to the operation of the communication system shown in FIG. 1 , a step of confirming whether the algorithms are the same is added (S1100). Here, after the terminal device 300 sends the generated first algorithm signature to the terminal device 400, the terminal device 400 confirms whether the first algorithm is the same (S1100). Alternatively, the terminal device 300 may confirm whether the algorithm to be used as the first algorithm is the same as the algorithm selected as the first algorithm in the terminal device 400.
[0179] Fig.56 and Fig. 20 Corresponding, except Fig. 20 In addition to the operation of the communication system shown in FIG. 1 , a step of confirming whether the algorithms are the same is added (S1200). Here, after the terminal device 300 sends the generated first algorithm signature to the terminal device 400, the terminal device 400 confirms whether the first algorithm is the same (S1200). Alternatively, the terminal device 300 may confirm whether the algorithm to be used as the first algorithm is the same as the algorithm selected as the first algorithm in the terminal device 400.
[0180] (Other embodiments)
[0181] In the above embodiment, when it is determined as "yes" in step S802, both the terminal device 300 and the terminal device 400 support the second algorithm. For example, after the security of the PQC method is fully evaluated, even if the PQC method is used alone, it is not harmful. When it is known that the terminal device 300 and the terminal device 400 support the second algorithm (step S802: "yes"), the processing for communication based on the first algorithm is not performed, and only the processing for communication based on the second algorithm is performed (processing from the sending of the second algorithm certificate after step S904).
[0182] In addition, in the above-mentioned embodiments, each component may be formed by dedicated hardware, or implemented by executing a software program suitable for each component. Each component may also be implemented by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory.
[0183] In addition, each component may also be a circuit (or integrated circuit). These circuits may constitute one circuit as a whole, or they may be different circuits. In addition, these circuits may be general circuits or dedicated circuits.
[0184] In addition, the general or specific technical solutions of the present disclosure may also be implemented by a system, device, method, integrated circuit, computer program, or non-transient recording medium such as a computer-readable CD-ROM. In addition, it may also be implemented by any combination of a system, device, method, integrated circuit, computer program, and non-transient recording medium such as a computer-readable CD-ROM.
[0185] For example, the present disclosure may be implemented as a communication method executed by various devices (computers or DSPs) involved in communication, or may be implemented as a program for causing a computer or DSP to execute the communication method.
[0186] In the above-described embodiments, the processing performed by a specific processing unit may be performed by another processing unit. In addition, the order of multiple processing in the operation of the communication system described in the above-described embodiments may be changed, and multiple processing may be performed in parallel.
[0187] In addition, various modifications that can be conceived by those skilled in the art to the embodiments, or embodiments achieved by arbitrarily combining components and functions in the embodiments within the scope not departing from the gist of the present disclosure are also included in the present disclosure.
[0188] Industrial Applicability
[0189] The present disclosure is useful as a communication method when a hybrid method is applied.
[0190] Description of Reference Numerals
[0191] 100: Certificate issuing device
[0192] 101, 201, 201a, 301, 301a, 401: Random number generation unit
[0193] 102, 202a: Logo generation unit
[0194] 103, 306a: Key generation unit
[0195] 104, 302, 302a: Signature generation unit
[0196] 105: Certificate Generation Department
[0197] 106, 203, 205a, 306, 307a, 407: Department of Communications
[0198] 200, 200a: Public key issuing device
[0199] 202, 204a: Public key generation unit
[0200] 203a: Test message generation unit
[0201] 300, 300a, 400: terminal device
[0202] 303, 303a: Session key generation unit
[0203] 304, 304a: Session key confirmation unit
[0204] 305, 305a: Certificate storage unit
[0205] 402: Nonce flag generation unit
[0206] 403: Session key generation unit
[0207] 404: Signature Verification Department
[0208] 405: Certificate Verification Department
[0209] 406: Certificate Reading Section
Claims
1. A communication method, comprising: a communication method between a first device and a second device; The first device sends a certificate for a first encryption method to the second device, the certificate including a confirmation flag indicating support for an encryption method different from the first encryption method. When the first device receives a message including the Nonce and the confirmation flag as a response from the second device to the transmission of the certificate, the first device transmits to the second device a signature generated based on the Nonce and the confirmation flag included in the received message, When the first device receives a message including the Nonce and not including the confirmation flag as a response from the second device to the transmission of the certificate, the first device transmits a signature generated based on the Nonce included in the received message to the second device.
2. The communication method according to claim 1, The communication session between the first device and the second device is continued in the different encryption method when the first device receives a detection flag generated by the second device indicating that tampering of the message exists, the detection flag being generated based on the mismatch between the message sent by the second device in response to the sending of the certificate and the signature sent from the first device to the second device in response to the reception of the message.
3. The communication method according to claim 1, The communication session between the first device and the second device is terminated when the first device receives a detection flag generated by the second device indicating that tampering of the message exists, wherein the detection flag is generated based on the mismatch between the message sent by the second device in response to the sending of the certificate and the signature sent from the first device to the second device in response to the reception of the message.
4. The communication method according to any one of claims 1 to 3, The first encryption method is RSA method or EC-DSA method, The different encryption method is the PQC method, i.e., the post-quantum cryptography method.
5. A communication method, comprising: a communication method between a first device and a second device; The second device receives a certificate for a first encryption method from the first device, the certificate including a confirmation flag indicating support for an encryption method different from the first encryption method, When the second device supports the different encryption method, the second device sends a message including the Nonce and the confirmation flag to the first device in response to the received certificate. In the case where the second device does not support the different encryption method, the second device sends a message including the Nonce and excluding the confirmation flag to the first device as a response to the received certificate, The second device receives from the first device a signature generated based on the Nonce included in the transmitted message, and on any one of the Nonce and the confirmation flag.
6. A communication method, comprising: a communication method between a first device and a second device; The first device sends a certificate for a first encryption method to the second device, the certificate including a confirmation flag indicating support for an encryption method different from the first encryption method. When the second device supports the different encryption method, the second device sends a message including the Nonce and the confirmation flag to the first device in response to the received certificate. In the case where the second device does not support the different encryption method, the second device sends a message including the Nonce and excluding the confirmation flag to the first device as a response to the received certificate, When the first device receives a message including the Nonce and the confirmation flag as a response from the second device to the transmission of the certificate, the first device transmits to the second device a signature generated based on the Nonce and the confirmation flag included in the received message, When the first device receives a message including the Nonce and not including the confirmation flag as a response from the second device to the transmission of the certificate, the first device transmits a signature generated based on the Nonce included in the received message to the second device.
7. A first device capable of communicating with a second device, comprising: a certificate generating unit that generates a certificate for a first encryption method, the certificate including a confirmation flag indicating support for an encryption method different from the first encryption method; and Signature generation unit, The signature generating unit, When the generated certificate is sent to the second device, if a message including Nonce and the confirmation flag is received as a response from the second device, a signature is generated based on the Nonce and the confirmation flag included in the received message, When the generated certificate is sent to the second device, if a message including the Nonce and not including the confirmation flag is received as a response from the second device, a signature is generated based on the Nonce included in the received message.
8. A second device capable of communicating with a first device, comprising: The message generating unit, upon receiving a certificate of a first encryption method from the first device including a confirmation flag indicating support for an encryption method different from the first encryption method, If the second device supports the different encryption method, a message including Nonce and the confirmation flag is generated as a response to the received certificate, If the second device does not support the different encryption method, generating a message including the Nonce and not including the confirmation flag as a response to the received certificate; and The communication unit is configured to receive, from the first device, a signature generated based on the Nonce contained in the transmitted message and on any one of the Nonce and the confirmation flag.
9. A program for causing a computer to execute a communication method between a first device and a second device, In the communication method, The first device sends a certificate for a first encryption method to the second device, the certificate including a confirmation flag indicating support for an encryption method different from the first encryption method. When the first device receives a message including the Nonce and the confirmation flag as a response from the second device to the transmission of the certificate, the first device transmits to the second device a signature generated based on the Nonce and the confirmation flag included in the received message, When the first device receives a message including the Nonce and not including the confirmation flag as a response from the second device to the transmission of the certificate, the first device transmits a signature generated based on the Nonce included in the received message to the second device.
10. A program for causing a computer to execute a communication method between a first device and a second device, In the communication method, The second device receives a certificate for a first encryption method from the first device, the certificate including a confirmation flag indicating support for an encryption method different from the first encryption method, When the second device supports the different encryption method, the second device sends a message including the Nonce and the confirmation flag to the first device in response to the received certificate. In the case where the second device does not support the different encryption method, the second device sends a message including the Nonce and excluding the confirmation flag to the first device as a response to the received certificate, The second device receives from the first device a signature generated based on the Nonce included in the transmitted message, and on any one of the Nonce and the confirmation flag.
Citation Information
Patent Citations
Extensions for using a digital certificate with multiple cryptosystems
WO2020087152A1