Communication method, communication system, server, and communication device

By using pre-stored random number seeds to generate keys in communication devices and servers, the problem of communication devices being unable to update electronic certificates in a quantum computing environment is solved. This enables the creation or updating of electronic certificates without sending private keys, ensuring communication security and the flexibility of encryption methods.

CN122162342APending Publication Date: 2026-06-05PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
Filing Date
2024-07-23
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

In a quantum computing environment, existing technologies cannot create or update electronic certificates without sending private keys, and the vulnerabilities of existing encryption methods mean that communication security cannot be guaranteed.

Method used

By pre-storing the same random number seed in the communication device and the server, a key containing a private key and a public key is generated, and a digital certificate is created using this key. This avoids directly sending the private key and ensures that the communication device can generate the same key as the server and receive the digital certificate.

Benefits of technology

It enables the creation or renewal of electronic certificates without sending private keys, ensuring communication security, adapting to changes in encryption methods in quantum computing environments, and avoiding the risk of private key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122162342A_ABST
    Figure CN122162342A_ABST
Patent Text Reader

Abstract

In the communication method, a key (first key) including a private key and a public key is generated using a random number seed stored in advance (S202), an electronic certificate regarding the key is created using the generated key (S203), and the created electronic certificate is transmitted to a communication device (200) in which the same random number seed as the above-described random number seed is stored in advance and the same key (second key) as the above-described key is generated using the random number seed (S204).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to communication methods, communication systems, servers, and communication devices. Background Technology

[0002] Patent document 1 discloses an information processing device or signature generation device for implementing a public key authentication method or an electronic signature (signature) method for multi-element simultaneous equations of unknown efficiency (trapdoor).

[0003] Existing technical documents

[0004] Patent documents

[0005] Patent Document 1: Japanese Patent Application Publication No. 2013-48350 Summary of the Invention

[0006] The problem that the invention aims to solve

[0007] This disclosure provides communication methods, etc., for creating (producing) or updating digital certificates without sending a private key.

[0008] Technical solutions for solving the problem

[0009] In one aspect of the communication method disclosed herein, a key containing a private key and a public key is generated using a pre-stored random number seed, an electronic certificate about the key is created using the generated key, and the created electronic certificate is sent to a communication device, the communication device having a pre-stored random number seed identical to the random number seed, and using the random number seed to generate a key identical to the key.

[0010] Additionally, one aspect of this disclosure relates to a communication system comprising a server and a communication device communicating with the server. The server comprises a key generation unit, a certificate creation unit, and a communication unit. The key generation unit generates a key containing a private key and a public key using a pre-stored random number seed. The certificate creation unit creates an electronic certificate about the key using the key generated by the key generation unit. The communication unit sends the electronic certificate created by the certificate creation unit to the communication device. The communication device comprises a communication unit and a key generation unit. The communication unit receives the electronic certificate sent from the server. The key generation unit generates a key identical to the key using a pre-stored random number seed identical to the random number seed.

[0011] In addition, one embodiment of this disclosure involves a server comprising a key generation unit, a certificate creation unit, and a communication unit. The key generation unit generates a key containing a private key and a public key using a pre-stored random number seed. The certificate creation unit uses the key generated by the key generation unit to create an electronic certificate for that key. The communication unit sends the electronic certificate created by the certificate creation unit to a communication device, wherein the communication device pre-stores the same random number seed as the key generation unit and uses that random number seed to generate a key identical to the key.

[0012] Additionally, one aspect of this disclosure relates to a communication device that communicates with a server, comprising a key generation unit and a communication unit. The key generation unit uses a pre-stored random number seed, identical to the random number seed used on the server, to generate a key identical to the key containing a private key and a public key generated on the server. The communication unit receives an electronic certificate from the server, created using the key on the server, relating to that key.

[0013] Invention Effects

[0014] According to this disclosure, it has the advantage of being able to create or update digital certificates without sending a private key. Attached Figure Description

[0015] Figure 1 This is a block diagram illustrating an example of the overall configuration of a communication system encompassing the implementation method.

[0016] Figure 2 This is a block diagram illustrating an example of the functional structure of a server involved in an implementation method.

[0017] Figure 3 This is a diagram representing an example of a random number seed.

[0018] Figure 4 This is a diagram representing an example of a private key.

[0019] Figure 5 This is a diagram illustrating an example of an electronic certificate.

[0020] Figure 6 This is a block diagram illustrating an example of the functional structure of a communication device involved in an implementation.

[0021] Figure 7 This is a timing diagram illustrating the first operational example of the communication system involved in the implementation method.

[0022] Figure 8 This is a timing diagram illustrating a second operational example of the communication system involved in the implementation method.

[0023] Figure 9This is a timing diagram illustrating an example of the operation of a communication system according to a first variation of the implementation.

[0024] Figure 10 This is a block diagram illustrating an example of the functional structure of a server involved in a second variation of the implementation method.

[0025] Figure 11 This is a diagram illustrating an example of encryption method information.

[0026] Figure 12 This is a timing diagram illustrating an operational example of a communication system involved in a second variation of the implementation.

[0027] Figure 13 This is a diagram representing an example of a random number seed for each device ID.

[0028] Figure 14 This is a timing diagram illustrating an operational example of the communication system involved in the third variation of the implementation method.

[0029] Figure 15 This is a timing diagram illustrating an operational example of the communication system involved in the fourth variation of the implementation method.

[0030] Figure 16 This is a timing diagram illustrating an operational example of the communication system involved in the fifth variation of the implementation method.

[0031] Figure 17 This is a graph representing an example of how many times the random number seed for each device ID has been used.

[0032] Figure 18 This is a schematic diagram of the operation of the communication system according to the sixth variation of the implementation method.

[0033] Figure 19 This is a timing diagram illustrating an operational example of the communication system involved in the sixth variation of the implementation method.

[0034] Figure 20 This is a diagram illustrating an example of how many times a random number seed is used for each device ID and the encryption method.

[0035] Figure 21 This is a diagram illustrating an example of the bit size of the random number for each device ID. Detailed Implementation

[0036] (The insights that form the basis of this disclosure)

[0037] In recent years, the development of quantum computers has been booming due to their emergence. On the other hand, it is known that the current encryption methods (hereinafter referred to as "classical encryption methods") are theoretically becoming "critical" due to the large-scale deployment of quantum computers. In view of this situation, a new encryption method capable of withstanding the computational power of large-scale quantum computers, namely quantum-resistant encryption, has been proposed.

[0038] However, although it is a quantum-resistant encryption method, its security assessment is not complete. Even after adopting quantum-resistant encryption in communication devices, vulnerabilities may still be discovered within it. Moreover, if vulnerabilities are found in the encryption method used by the communication device, in order to ensure communication security, it is necessary to immediately switch to another encryption method and update the electronic certificate being used.

[0039] In this context, when a communication device entrusts a server to create or update an electronic certificate, the communication device needs to send a Certificate Signing Request (CSR) to the server (Certification Authority). A CSR is a message requesting the server to issue (publish) a digital certificate for the key pair (private and public keys) generated in the communication device. This message is electronically signed with the sender's private key and sent to the server.

[0040] However, if a vulnerability is found in the encryption method used, the security of communication cannot be guaranteed, and there is a problem such as being unable to send the private key to the server over the network.

[0041] Furthermore, even if no vulnerabilities are found in the encryption method used, such as when the private key is stored in a secure element within the communication device, it is still impossible to retrieve the private key outside the communication device. Therefore, in this case, there is also the problem of being unable to send the private key to the server over the network.

[0042] In view of the above, the purpose of this disclosure is to provide a communication method, etc., that enables the creation or renewal of electronic certificates without sending a private key by using a pre-stored random number seed to create electronic certificates.

[0043] More specifically, in the communication method disclosed in the first aspect, a key containing a private key and a public key is generated using a pre-stored random number seed, an electronic certificate about the key is created using the generated key, and the created electronic certificate is sent to a communication device, which pre-stores the same random number seed as the above-mentioned random number seed and uses the random number seed to generate a key that is the same as the above-mentioned key.

[0044] Therefore, using the same random number seed as that used in the communication device, a key identical to the key generated in the communication device is generated, and an electronic certificate for that key is created and sent to the communication device. Thus, the communication device can obtain an electronic certificate essentially containing the key generated by the communication device. Therefore, this provides the advantage of being able to create or update electronic certificates without sending a private key.

[0045] Additionally, for example, in the communication method involved in the second aspect of this disclosure, in the first aspect, the key is generated based on the encryption method that the communication device can use during the key generation process.

[0046] Therefore, it generates keys based on the encryption methods that the communication device can use, and then creates electronic certificates, thus having the advantage of being able to create or update electronic certificates corresponding to the encryption methods that can be used in the communication device.

[0047] Additionally, for example, in the communication method disclosed in the third aspect, in the second aspect, the encryption method is a quantum-resistant encryption method.

[0048] Therefore, compared to encrypted communication using classical encryption methods, the key is difficult to decrypt, thus having the advantage of easily ensuring the confidentiality of data sent and received using the key.

[0049] Additionally, for example, in the communication method involved in the fourth aspect of this disclosure, in the second or third aspect, it is determined whether the encryption method is secure or vulnerable, and in the key generation process, the key is generated if the encryption method is determined to be secure.

[0050] Therefore, a key is generated under secure encryption, and then a digital certificate is created, thus having the advantage of not having to create a digital certificate for encryption methods that have been found to be vulnerable.

[0051] Additionally, for example, in the communication method according to the fifth aspect of this disclosure, in any of the first to fourth aspects, an identifier of the communication device is also obtained, and in the key generation process, a random number seed corresponding to the obtained identifier is used to generate the key.

[0052] Therefore, by using a random number seed corresponding to the identifier of the communication device to generate a key, and then creating an electronic certificate, it has the advantage of being able to create electronic certificates inherent in each of multiple communication devices.

[0053] Additionally, for example, in the communication method involved in the sixth aspect of this disclosure, in any of the first to fifth aspects, it is determined whether the electronic certificate needs to be updated, and in the key generation process, a key is generated if it is determined that the electronic certificate needs to be updated.

[0054] Therefore, it determines whether an electronic certificate needs to be updated, generates a key if an update is needed, and then creates the electronic certificate. This has the advantage of not needing to delegate the electronic certificate update from the communication device.

[0055] Additionally, for example, in the communication method disclosed in the seventh aspect, in any of the first to sixth aspects, the number of times the random number seed in the communication device is used is obtained, such that the number of times the random number seed is used is consistent with the number of times the random number seed in the communication device is obtained.

[0056] This ensures that the random number seed is used the same number of times as the random number seed in the communication device, resulting in the same random numbers generated using the random number seed as those generated in the communication device. Consequently, the generated key and the key generated in the communication device are always the same, thus providing the advantage of a digital certificate that is difficult to invalidate.

[0057] Additionally, for example, the communication system according to the eighth aspect of this disclosure includes a server and a communication device communicating with the server. The server includes a key generation unit, a certificate creation unit, and a communication unit. The key generation unit generates a key containing a private key and a public key using a pre-stored random number seed. The certificate creation unit uses the key generated by the key generation unit to create an electronic certificate for that key. The communication unit sends the electronic certificate created by the certificate creation unit to the communication device. The communication device includes a communication unit and a key generation unit. The communication unit receives the electronic certificate sent from the server. The key generation unit generates a key identical to the aforementioned key using a pre-stored random number seed identical to the aforementioned random number seed.

[0058] Therefore, it has the advantage of being able to achieve the same effect as the communication methods described above.

[0059] Additionally, for example, the server involved in the ninth method of this disclosure includes a key generation unit, a certificate creation unit, and a communication unit. The key generation unit generates a key containing a private key and a public key using a pre-stored random number seed. The certificate creation unit uses the key generated by the key generation unit to create an electronic certificate for that key. The communication unit sends the electronic certificate created by the certificate creation unit to a communication device that has pre-stored the same random number seed as described above and uses that random number seed to generate a key identical to the key described above.

[0060] Therefore, it has the advantage of being able to achieve the same effect as the communication methods described above.

[0061] Additionally, for example, the tenth method of this disclosure relates to a communication device that communicates with a server, comprising a key generation unit and a communication unit. The key generation unit uses a pre-stored random number seed, the same as the random number seed used on the server, to generate a key identical to the key containing a private key and a public key generated on the server. The communication unit receives an electronic certificate from the server, created using the key on the server, concerning that key.

[0062] Therefore, it has the advantage of being able to achieve the same effect as the communication methods described above.

[0063] Furthermore, these general or specific methods can be implemented through systems, devices, methods, integrated circuits, computer programs, or non-transient recording media such as computer-readable CD-ROMs, or through any combination of systems, devices, methods, integrated circuits, computer programs, and recording media.

[0064] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Furthermore, the embodiments described below are general or specific examples. The numerical values, shapes, materials, constituent elements, arrangement positions of constituent elements, connection methods, steps, or order of steps shown in the following embodiments are examples and are not intended to limit this disclosure. Additionally, constituent elements in the following embodiments not described in the independent claims are described as arbitrary constituent elements. Furthermore, the figures are schematic diagrams and are not necessarily strictly illustrative. Also, in the figures, substantially identical structures are labeled with the same reference numerals, and sometimes repeated descriptions are omitted or simplified.

[0065] (Implementation Method)

[0066] [1. Summary]

[0067] First, use Figure 1 An overview of the communication method involved in the implementation method is provided. Figure 1 This is a block diagram illustrating an example of the functional structure of the overall configuration of the communication system 10 included in the implementation method. For example... Figure 1 As shown, the communication system 10 includes a server 100 and a communication device 200. The communication device 200 is a device that conducts encrypted communication with other communication devices 300 via a network such as the Internet. Furthermore, in this embodiment, the communication system 10 includes one communication device 200, but it may also include multiple communication devices 200.

[0068] Server 100, acting as a certification authority, upon receiving a message from communication device 200 requesting the creation or renewal of an electronic certificate (hereinafter also referred to as a "request message"), creates an electronic certificate (a signed certificate) according to the received request message and sends the created electronic certificate to the communication device 200, the source of the request message. Additionally, server 100 sends a random number seed to communication device 200. In this embodiment, server 100 sends a random number seed to one communication device 200, but if there are multiple communication devices 200, it can send different random number seeds to each of the multiple communication devices 200.

[0069] Here, server 100 sends a random number seed to communication device 200, for example, before sending a new electronic certificate to communication device 200, or before sending an updated electronic certificate to communication device 200. Therefore, communication device 200 is assigned a random number seed before obtaining a new electronic certificate or before obtaining an updated electronic certificate. Consequently, the same random number seed is stored in both server 100 and communication device 200. Figure 1 In the example shown, the server 100 and the communication device 200 respectively store the random number seed "0x12345...".

[0070] Here, for example, if a vulnerability is found in the algorithm (encryption method) used, rendering it unusable, the communication device 200 sends a request message to the server 100. Upon receiving the request message, the server 100 generates a key pair (private key and public key) based on a pre-stored random number seed. Then, the server 100 creates an electronic certificate that is electronically signed using the private key contained in the generated key pair and sends the created electronic certificate to the communication device 200.

[0071] On the other hand, the communication device 200 generates a key pair based on a pre-stored random number seed. This key pair is generated based on the same random number seed shared by both the server 100 and the communication device 200, and is therefore identical to the key pair generated in the server 100. In other words, by obtaining the electronic certificate sent from the server 100, the communication device 200 can obtain an electronic certificate about the private key from the server 100 without sending the private key used in the future. As described above, the communication system 10 (communication method) according to the embodiment has the advantage of being able to create or update electronic certificates without sending the private key.

[0072] [2. Composition]

[0073] Next, the overall configuration of the communication system 10 according to the embodiments will be described. As described above, in the embodiments, the communication system 10 is described as including a server 100 and a communication device 200. The communication device 200 is implemented, for example, through an information terminal such as a personal computer, smartphone, or tablet terminal. In addition, the communication device 200 is configured to communicate with the server 100 via a network such as the Internet.

[0074] Figure 2 This is a block diagram illustrating an example of the functional structure of a server 100 according to an embodiment. The server 100 includes a processor and a memory, and its functions are implemented by executing a program stored in the memory via the processor. For example... Figure 2 As shown, the management server 100 includes a random number seed generation unit 101, a random number seed storage unit 102, a key generation unit 103, a certificate creation unit 104, and a communication unit 105.

[0075] The random number seed generation unit 101 generates random number seeds that are pre-stored by the server 100 and the communication device 200 respectively. Figure 3 This is a diagram representing an example of a random number seed. (For example...) Figure 3 As shown, the random number seed generation unit 101 generates, for example, a 16-bit random number seed. The random number seed generation unit 101 generates the random number seed by executing an appropriate generation algorithm, for example.

[0076] The random number seed storage unit 102 stores the random number seed generated by the random number seed generation unit 101.

[0077] When the key generation unit 103 receives a request message from the communication device 200, that is, when it receives a message from the communication device 200 requesting the creation or renewal of an electronic certificate, it generates a key using a random number seed stored in the random number seed storage unit 102. In this embodiment, the key generated by the key generation unit 103 is a key pair containing a private key and a public key. In other words, the key generation unit 103 uses a pre-stored random number seed to generate a key containing a private key and a public key. Hereinafter, the key generated by the key generation unit 103 of the server 100 will also be referred to as the "first key".

[0078] Figure 4 This is a diagram representing an example of a private key. (Example:) Figure 4As shown, the key generation unit 103 generates, for example, a private key with a bit string of 16 bits or more. Additionally, the key generation unit 103 generates, for example, a public key with a bit string of 16 bits or more. The key generation unit 103 generates a key (first key) by executing an appropriate encryption key generation algorithm. Furthermore, the key generation unit 103 can also generate a key (first key) corresponding to the encryption method used if information related to the encryption method is obtained from the communication device 200.

[0079] The certificate creation unit 104 uses the key (first key) generated by the key generation unit 103 to create an electronic certificate for that key. Figure 5 This is a diagram illustrating an example of an electronic certificate. (For example...) Figure 5 As shown, the certificate creation unit 104, for example, creates an electronic certificate containing the issuer, the encryption method used, the public key, and the signature. Figure 5 In the example shown, the issuer is server 100, the encryption method used is "Dilithium2" as a quantum-resistant encryption method, the public key is a public key generated by key generation unit 103, and the signature is a signature generated using the private key generated by key generation unit 103. Figure 5 As shown, the certificate creation unit 104 generates, for example, a signature with a bit string of 16 bits or more. The certificate creation unit 104 creates an electronic certificate, for example, by executing an appropriate certificate creation algorithm.

[0080] The communication unit 105 receives a request message sent from the communication device 200. Additionally, the communication unit 105 sends the random number seed generated by the random number seed generation unit 101 to the communication device 200, the source of the request message. The sending of the random number seed to the communication device 200 is performed primarily only when the communication device 200 is first used. Furthermore, the communication unit 105 sends the electronic certificate created by the certificate creation unit 104 to the communication device 200, the source of the request message.

[0081] Figure 6 This is a block diagram illustrating an example of the functional structure of the communication device 200 according to an embodiment. The communication device 200 includes a processor and a memory, and its functions are implemented by executing a program stored in the memory through the processor. Figure 6 As shown, the communication device 200 includes a random number seed storage unit 201, a key generation unit 202, a key storage unit 203, a certificate update unit 204, a certificate storage unit 205, and a communication unit 206.

[0082] The random number seed storage unit 201 stores the random number seed received from the server 100 by the communication unit 206.

[0083] When the key generation unit 202 sends a request message to the server 100, that is, when creating or updating an electronic certificate, it generates a key using a random number seed stored in the random number seed storage unit 201. In this embodiment, the key generated by the key generation unit 202 is a key pair containing a private key and a public key. The key generation unit 202 generates the key, for example, by executing an appropriate encryption key generation algorithm. Hereinafter, the key generated by the key generation unit 202 of the communication device 200 will also be referred to as the "second key".

[0084] Here, the key generation unit 202 generates a key (second key) by using the same random number seed as used in the server 100 and executing the same encryption key generation algorithm as used by the key generation unit 103 of the server 100. Therefore, the key generated by the key generation unit 202 (second key) is the same as the key generated by the key generation unit 103 of the server 100 (first key). In other words, the key generation unit 202 uses a pre-stored random number seed, the same as used in the server 100, to generate a key (second key) that is identical to the key (first key) containing the private and public keys generated in the server 100.

[0085] The key storage unit 203 stores the key (second key) generated by the key generation unit 202. For example, if no key is stored, the key storage unit 203 stores the key generated by the key generation unit 202 as a new key. Alternatively, if a key is already stored, the key storage unit 203 updates and stores the key by overwriting it with the key generated by the key generation unit 202.

[0086] The certificate renewal department 204 sends a request message to the server 100 when an electronic certificate needs to be renewed. Situations requiring renewal include, for example, the electronic certificate expiring or a vulnerability being discovered in the encryption method being used.

[0087] The certificate storage unit 205 stores the electronic certificates received by the communication unit 206. For example, if no electronic certificate is stored, the certificate storage unit 205 stores the electronic certificate received by the communication unit 206 as a new electronic certificate. Alternatively, if an electronic certificate is already stored, the certificate storage unit 205 updates and stores the electronic certificate by overwriting it with the electronic certificate received by the communication unit 206.

[0088] Communication unit 206 sends a request message to server 100. Additionally, communication unit 206 receives an electronic certificate sent from server 100. In other words, communication unit 206 receives an electronic certificate sent from server 100, created on server 100 using a key (first key) related to that key.

[0089] [3. Action]

[0090] Hereinafter, an example of the operation of the communication system 10 according to the embodiment will be described.

[0091] [3-1. Example of the first action]

[0092] Figure 7 This is a timing diagram illustrating a first operational example of the communication system 10 according to the implementation method. The first operational example is executed, for example, when the communication device 200 is first used.

[0093] First, server 100 generates a random number seed (S101). Then, server 100 sends the generated random number seed to communication device 200 (S102). In addition, server 100 stores the generated random number seed in random number seed storage unit 102 (S103).

[0094] When the communication device 200 receives a random number seed, it stores the received random number seed in the random number seed storage unit 201 (S104). Furthermore, the execution order of steps S103 and S104 can be reversed, or they can be executed in parallel. In this way, the same random number seed is stored in both the server 100 and the communication device 200.

[0095] [3-2. Example of the second action]

[0096] Figure 8 This is a timing diagram illustrating a second operation example of the communication system 10 according to the implementation method. The second operation example is executed, for example, when the communication device 200 has not yet requested the server 100 to issue an electronic certificate. Alternatively, the second operation example is executed when a vulnerability is found in the encryption method used, requiring an update of the electronic certificate.

[0097] First, the communication device 200 sends a request message to the server 100 (S201).

[0098] Upon receiving a request message, server 100 generates a new key (first key) using a random number seed stored in random number seed storage unit 102 (S202). Next, server 100 uses the generated key to create an electronic certificate for that key (S203). Then, server 100 sends the created electronic certificate to the communication device 200, the source of the request message (S204). Steps S202 to S204 are all processes of the communication method according to the embodiment.

[0099] The communication device 200 uses the random number seed stored in the random number seed storage unit 201 to generate a new key (second key) (S205). As described above, the key (second key) generated in step S205 is based on the same random number seed shared by both the server 100 and the communication device 200, and is therefore the same as the key (first key) generated in the server 100. In other words, the communication device 200 pre-stores the same random number seed as the one used in the server 100, and uses this random number seed to generate a key (second key) that is the same as the key (first key) generated in the server 100.

[0100] Then, when the communication device 200 receives the electronic certificate, it stores the received electronic certificate in the certificate storage unit 205 and stores the generated key (second key) in the key storage unit 203, thereby updating the electronic certificate and key (S206). Furthermore, if the communication device 200 is receiving the electronic certificate for the first time, step S206 can be replaced with "storing the electronic certificate and key".

[0101] [4. Advantages]

[0102] The advantages of the communication system 10 (communication method) according to the embodiments will be described below. As described above, in the communication system 10 (communication method) according to the embodiments, the server 100 generates a key (first key) containing a private key and a public key based on a pre-stored random number seed. Then, the server 100 creates an electronic certificate for the generated key and sends the created electronic certificate to the communication device 200. On the other hand, the communication device 200 generates a key (second key) based on a pre-stored random number seed. This key (second key) is generated based on the same random number seed shared by both the server 100 and the communication device 200, and is therefore the same as the key (first key) generated in the server 100. Therefore, by obtaining the electronic certificate sent from the server 100, the communication device 200 can obtain an electronic certificate about the private key from the server 100 without sending the private key used in the future to the server 100.

[0103] As described above, in the communication system 10 (communication method) according to the embodiment, a key identical to the one generated in the communication device 200 is generated using the same random number seed as used in the communication device 200, and an electronic certificate for that key is created and sent to the communication device 200. Therefore, the communication device 200 can obtain an electronic certificate substantially related to the key generated by the communication device 200. Thus, the communication system 10 (communication method) according to the embodiment has the advantage of being able to create or update electronic certificates without sending a private key.

[0104] Therefore, the communication system 10 (communication method) according to the implementation method has the following advantages: for example, even if a vulnerability is found in the encryption method used and the security of communication cannot be guaranteed, or if the private key is stored in a secure element in the communication device 200 and cannot be taken out of the communication device 200, electronic certificates can still be created or updated.

[0105] (Other implementation methods)

[0106] The embodiments have been described above, but this disclosure is not limited to the embodiments described above. Hereinafter, variations of the embodiments are listed. The variations listed below can also be appropriately combined.

[0107] <First Variation>

[0108] In the first variation, when the communication device 200 sends a request message to the server 100, it also sends information indicating the encryption methods that the communication device 200 can use. Then, the key generation unit 103 of the server 100 generates a key (first key) that can be used among the acquired encryption methods. That is to say, in the communication system 10 (communication method) of the first variation, the key (first key) is generated based on the encryption methods that the communication device 200 can use during the key generation process. This will be explained in detail below.

[0109] Figure 9 This is a timing diagram illustrating an operational example of the communication system 10 according to a first variation of the implementation. First, the communication device 200 sends a request message and information indicating the available encryption methods to the server 100 (S207).

[0110] When server 100 receives a request message and information indicating the available encryption methods, it generates a new key (first key) using a random number seed stored in random number seed storage unit 102 (S202). Here, server 100 also generates a new key (first key) based on the acquired available encryption methods. Subsequent steps S203-S206 are the same as in the second operational example of the embodiment, and therefore are omitted here. Furthermore, in step S205, communication device 200 generates a new key (second key) based on the available encryption methods.

[0111] As described above, in the first variation, the server 100 also generates a key (first key) based on the encryption method that the communication device 200 can use, and then creates an electronic certificate, thus having the advantage of being able to create or update electronic certificates corresponding to the encryption methods that can be used in the communication device 200.

[0112] In this first variation, the encryption method can also be quantum-resistant encryption. In this case, compared to encrypted communication using classical encryption, the key is difficult to decrypt, thus offering the advantage of easily ensuring the confidentiality of data sent and received using the key.

[0113] <Second Variation>

[0114] Figure 10 This is a block diagram illustrating an example of the functional structure of server 100' according to a second variation of the implementation method. For example... Figure 10 As shown, the server 100' in the second variation differs from the server 100 in the embodiment in that it also has an encrypted information storage unit 106.

[0115] The encryption method information storage unit 106 stores encryption method information. Encryption method information is information indicating the security of the encryption method. Figure 11 This is a diagram illustrating an example of encryption method information. In Figure 11 In the example shown, "Dilithium," a quantum-resistant encryption method, is secure, while "SIKE," another quantum-resistant encryption method, has been found to be vulnerable.

[0116] In the second variation, the difference from the first variation is that server 100' determines whether the obtained encryption method is secure or weak. If the encryption method is determined to be secure, a key (first key) is generated, and then an electronic certificate is created. This will be explained in detail below.

[0117] Figure 12This is a timing diagram illustrating an operational example of the communication system 10 according to a second variation of the implementation. First, similar to the first variation, the communication device 200 sends a request message and information indicating the available encryption methods to the server 100' (S207).

[0118] When server 100' receives a request message and information indicating the available encryption method, it determines whether the obtained encryption method is secure by referring to the encryption method information stored in the encryption method information storage unit 106 (S208). If the encryption method is determined to be weak (S208: No), server 100' does not execute steps S202 to S204, and therefore does not create an electronic certificate. In this case, server 100' may also send a message to communication device 200 indicating that no electronic certificate will be created due to the weakness of the encryption method.

[0119] On the other hand, if the encryption method is deemed secure (S208: Yes), server 100' executes steps S202-S206 to create an electronic certificate. Subsequent steps S202-S206 are the same as in the implementation method and the first variation, and therefore are omitted here.

[0120] As described above, in the second variation, when the encryption method is secure, server 100' generates a key (first key) and then creates an electronic certificate, thus having the advantage of not creating an electronic certificate regarding the encryption method that has been found to be vulnerable.

[0121] <Third Variation>

[0122] In the third variation, when the communication device 200 sends a request message to the server 100, it also sends a device ID (Identifier) ​​as an identifier for the communication device 200. Then, the key generation unit 103 of the server 100 uses a random number seed corresponding to the acquired device ID to generate a key (first key). This will be explained in detail below.

[0123] Figure 13 This is a diagram representing an example of a random number seed for each device ID. For example... Figure 13 As shown, the random number seed storage unit 102 of server 100 stores multiple (in this case, two) random number seeds. Figure 13 In the example shown, when the device ID obtained is "ID001", server 100 generates a key (first key) using a random number seed of "0x4EBFE...". Alternatively, when the device ID obtained is "ID002", server 100 generates a key (first key) using a random number seed of "0x41DEC...".

[0124] Figure 14 This is a timing diagram illustrating an operational example of the communication system 10 according to a third variation of the implementation. First, the communication device 200 sends a request message and device ID to the server 100 (S209).

[0125] When server 100 receives a request message and a device ID, it reads the random number seed corresponding to the device ID from the random number seed storage unit 102 (S210). Then, server 100 uses the read random number seed to generate a new key (first key) (S202). Subsequent steps S203 to S206 are the same as in the second operation example of the embodiment, so they are omitted here. In addition, in step S205, communication device 200 uses the same random number seed as the one read by server 100 corresponding to the device ID to generate a new key (second key).

[0126] As described above, in the third variation, a key (first key) is generated using a random number seed corresponding to the identifier of the communication device 200, and an electronic certificate is created therefrom. Therefore, it has the advantage of being able to create electronic certificates inherent in each of the multiple communication devices 200.

[0127] <Fourth Variation>

[0128] In the fourth variation, server 100 determines whether the electronic certificate needs to be updated. Furthermore, if the server 100's key generation unit 103 determines that the electronic certificate needs to be updated, it generates a key (first key). This will be explained in detail below.

[0129] Server 100 determines whether an electronic certificate needs to be renewed, for example, by referring to the expiration date of the electronic certificate. Specifically, if the electronic certificate expires, server 100 determines that the electronic certificate needs to be renewed.

[0130] Additionally, server 100 determines whether an electronic certificate needs to be updated, for example, by referring to the security of the encryption method used. Specifically, server 100 determines that an electronic certificate needs to be updated if a vulnerability is found in the encryption method used.

[0131] For example, server 100 can also search for descriptions of the security of encryption methods by obtaining one or more documents describing encryption methods and performing appropriate natural language processing on the obtained documents. Furthermore, server 100 can determine that an electronic certificate needs to be updated if it finds descriptions indicating vulnerabilities in the encryption method in one or more documents.

[0132] Alternatively, for example, server 100 can also determine whether an electronic certificate needs to be updated by obtaining a judgment result regarding the security of the encryption method used, sent from a third party outside of communication system 100. This third party can be a device outside of communication system 100 or a person. Furthermore, server 100 can also obtain the aforementioned judgment result by periodically querying the third party.

[0133] Figure 15 This is a timing diagram illustrating the operation of the communication system 10 according to the fourth variation of the embodiment. First, the server 100 extracts the device ID of the communication device 200 whose electronic certificate needs updating (S211). In step S211, the server 100 determines whether each of the plurality of communication devices 200 needs an electronic certificate update and extracts the device ID of the communication device 200 determined to need an electronic certificate update. Then, the server 100 generates a new key (first key) using a random number seed (S202). In step S202, the server 100 reads the random number seed corresponding to the extracted device ID from the random number seed storage unit 102 and uses the read random number seed to generate a new key (first key). Subsequent steps S203 to S206 are the same as in the second embodiment, and therefore are omitted here.

[0134] As described above, in the fourth variation, it is determined whether the electronic certificate needs to be updated. If the electronic certificate needs to be updated, a key is generated, and then the electronic certificate is created. Therefore, it has the advantage of not having to delegate the electronic certificate update from the communication device 200 to the server 100.

[0135] However, in the fourth variation, server 100 determines whether the electronic certificate needs to be updated, but is not limited to this. For example, communication device 200 can also determine whether the electronic certificate needs to be updated. In this case, communication device 200 can send a request message to server 100 if it determines that the electronic certificate needs to be updated.

[0136] <Fifth Variation>

[0137] In the communication device 200 of the fifth variation, the timing of generating the key (second key) using a pre-stored random number seed differs from that of the communication device 200 in the implementation. This will be explained in detail below.

[0138] Figure 16 This is a timing diagram illustrating an operational example of the communication system 10 according to the fifth modification of the implementation method. For example... Figure 16As shown, in the fifth variation, the communication device 200 generates a new key (second key) from the random number seed before sending a request message to the server 100 (S205). Alternatively, the communication device 200 may also generate the new key (second key) from the random number seed during the period from sending the request message to receiving the electronic certificate sent from the server 100.

[0139] <Sixth Variation>

[0140] The server 100 in the sixth variation differs from the server 100 in the implementation method in that it obtains the number of times the random number seed in the communication device 200 has been used, and performs an adjustment process to make the number of times the random number seed in the server 100 has been used consistent with the obtained number of times the random number seed in the communication device 200 has been used. This will be explained in detail below.

[0141] Essentially, the random number seed in server 100 is used the same number of times as the random number seed in communication device 200. Therefore, the key generated using the random number seed in server 100 (the first key) and the key generated using the random number seed in communication device 200 (the second key) are based on the same random number generation and are thus identical. Therefore, the electronic certificate created in server 100 for the generated key (the first key) is essentially an electronic certificate for the key (the second key).

[0142] However, for various reasons, there may be instances where the number of times the random number seed in server 100 is used differs from the number of times the random number seed in communication device 200 is used. In this case, the random numbers generated using the random number seed in server 100 are different from those generated using the random number seed in communication device 200, making it impossible to generate the same key in both server 100 and communication device 200. Furthermore, in this situation, the electronic certificate created in server 100 for the generated key (first key) will not become an electronic certificate for the key (second key), potentially leading to the problem of the created electronic certificate becoming invalid.

[0143] Therefore, in the sixth variation, the aforementioned problem is eliminated by performing an adjustment process that makes the number of times the random number seed in server 100 is used consistent with the number of times the random number seed in communication device 200 is used. Specifically, server 100 obtains, for example, the device ID and the number of times the random number seed is used from communication device 200 and stores them in memory. Figure 17 This is a graph representing an example of how many times the random number seed for each device ID has been used.

[0144] Then, before generating a new key (first key) using the random number seed, the server 100 reads the number of times the random number seed corresponding to the device ID of the communication device 200, which is the object of the creation of the electronic certificate, is used, and performs an adjustment process to make the number of times the random number seed is used consistent with the number of times the random number seed is used in the server 100.

[0145] Specifically, if the number of times the random number seed in server 100 is used is less than the number of times the random number seed in communication device 200 is used, random numbers are generated using the random number seed in a manner that makes the number of times the random number seed in server 100 is used the same as the number of times the random number seed in communication device 200 is used, and the generated random numbers are discarded. On the other hand, if the number of times the random number seed in server 100 is used is more than the number of times the random number seed in communication device 200 is used, data representing the difference in the number of times the random number seed is used is sent to communication device 200, instructing it to adjust the number of times the random number seed is used. Then, communication device 200 generates random numbers using the random number seed according to the instruction, based on the difference in the number of times the random number seed is used, and discards the generated random numbers.

[0146] Figure 18 This is a schematic diagram of the operation of the communication system 10 according to the sixth variation of the implementation. Figure 18 (a) indicates the number of times the random number seed of each of the server 100 and the communication device 200 was used before the adjustment process was executed. Figure 18 (b) indicates the number of times the random number seed is used by both server 100 and communication device 200 after the adjustment process is executed. Figure 18 In the example shown in (a), the random number seed in server 100 is used 5 times, while the random number seed in communication device 200 is used 3 times. Therefore, server 100 sends data representing the difference in the number of uses (in this case, 2 times) to communication device 200, instructing it to adjust the number of times the random number seed is used. Then, communication device 200, following this instruction, generates random numbers using the random number seed according to the difference in the number of uses and discards the generated random numbers. Thus, the number of times the random number seed in server 100 is used and the number of times the random number seed in communication device 200 is used both become the same (5 times).

[0147] Figure 19 This is a timing diagram illustrating an operational example of the communication system 10 according to the sixth modification of the implementation method. Figure 19 In the example shown, it is assumed that server 100 has received a request message and device ID from communication device 200. First, communication device 200 sends data to server 100 indicating the number of times the random number seed has been used (S301).

[0148] When server 100 receives data indicating the number of times the random number seed has been used, it determines whether the number of times the random number seed in server 100 has been used is the same as the number of times the random number seed in communication device 200 has been used (S302). If the number of times the random number seed in server 100 has been used is the same as the number of times the random number seed in communication device 200 has been used (S302: Yes), server 100 does not execute steps S303 to S306 as described below.

[0149] On the other hand, if the number of times the random number seed in server 100 is used is different from the number of times the random number seed in communication device 200 is used (S302: No), server 100 then determines whether server 100 has fewer uses of the random number seed (S303). If server 100 has fewer uses of the random number seed (S303: Yes), server 100 generates random numbers using the random number seed in a way that makes the number of uses of the random number seed in server 100 the same as the number of uses of the random number seed in communication device 200, and then discards the generated random numbers (S305).

[0150] On the other hand, if the communication device 200 has used the random number seed less times (S303: No), the server 100 sends data representing the difference in the number of uses to the communication device 200, instructing it to adjust the number of times the random number seed is used (S304).

[0151] When the communication device 200 receives the above data, it generates a random number using a random number seed according to the above instructions based on the difference in the number of times it has been used, and then discards the generated random number (S306).

[0152] As described above, in the sixth variation, the number of times the random number seed in server 100 is used is the same as the number of times the random number seed in communication device 200 is used. Therefore, the random numbers generated using the random number seed in server 100 are the same as the random numbers generated using the random number seed in communication device 200. Thus, in the sixth variation, the same key can always be generated in both server 100 and communication device 200, thus providing the advantage that electronic certificates created on server 100 are difficult to invalidate.

[0153] In addition, the server 100 may also store the encryption method used by the communication device 200 in the memory, etc., when storing the number of times the random number seed is used in the memory according to each device ID. Figure 20 This is a diagram illustrating an example of how many times a random number seed is used and the encryption method for each device ID.

[0154] Alternatively, server 100 may not record the number of times the random number seed is used, but instead store the total bit size of the random numbers generated using the random number seed in memory according to each device ID. Figure 21 This is a diagram illustrating an example of the bit size of a random number for each device ID. In this case, server 100 performs an adjustment process such that the total bit size of the random number generated in server 100 is consistent with the total bit size of the random number generated in communication device 200.

[0155] In addition, the server 100 can perform the above-mentioned adjustment process periodically, or it can perform it whenever it receives a request message from the communication device 200.

[0156] <Other variations>

[0157] In the above-described embodiments, the communication device 200 stores a random number seed by obtaining a random number seed generated by the server 100 from the server 100, but is not limited thereto. For example, the communication device 200 may also obtain a random number seed from an external storage medium such as USB (Universal Serial Bus) or a device different from the server 100, and store the same random number seed used in the server 100. Alternatively, for example, the communication device 200 may also store the same random number seed used in the server 100 by writing the random number seed during the manufacturing process of the communication device 200, such as in a factory.

[0158] Furthermore, in the above embodiments, the processing performed by a specific processing unit can also be performed by other processing units. Additionally, the order of multiple processes can be changed, or multiple processes can be executed in parallel.

[0159] Furthermore, in the above embodiments, each component can also be implemented by executing a software program suitable for each component. Each component can also be implemented by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0160] Furthermore, the constituent elements can also be implemented using hardware. For example, the constituent elements can also be circuits (or integrated circuits). These circuits can be used as a whole to form a single circuit, or they can be separate circuits. In addition, these circuits can be general-purpose circuits or special-purpose circuits.

[0161] Furthermore, the present disclosure, in its entirety or in specific form, can also be implemented by means of apparatus, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM. Additionally, the present disclosure, in its entirety or in specific form, can also be implemented by any combination of apparatus, method, integrated circuit, computer program, and recording medium.

[0162] For example, this disclosure can be implemented as a communication method executed by a computer, or as a program for causing a computer to execute the communication method. This disclosure can also be implemented as a computer-readable, non-transitory recording medium containing such a program.

[0163] Furthermore, this disclosure also includes various modifications to the embodiments that can be conceived by those skilled in the art, or any combination of the constituent elements and functions of the embodiments within the scope of this disclosure without departing from the spirit of this disclosure.

[0164] Industrial availability

[0165] This disclosure is useful when creating or updating electronic certificates.

[0166] Explanation of reference numerals in the attached figures

[0167] 10 Communication system; 100, 100' Server; 101 Random number seed generation unit; 102 Random number seed storage unit; 103 Key generation unit; 104 Certificate creation unit; 105 Communication unit; 106 Encryption method information storage unit; 200 Communication equipment; 201 Random number seed storage unit; 202 Key generation unit; 203 Key storage unit; 204 Certificate update unit; 205 Certificate storage unit; 206 Communication unit; 300 Other communication equipment.

Claims

1. A communication method, comprising: Generate a key containing a private key and a public key using a pre-stored random number seed. Use the generated key to create an electronic certificate for that key. The created electronic certificate is sent to a communication device, which has a pre-stored random number seed identical to the random number seed, and uses the random number seed to generate a key identical to the key.

2. The communication method according to claim 1, In the process of generating the key, the key is also generated based on the encryption methods that the communication device can use.

3. The communication method according to claim 2, The encryption method is a quantum-resistant encryption method.

4. The communication method according to claim 2, To determine whether the encryption method is secure or vulnerable, In the process of generating the key, the key is generated if the encryption method is determined to be secure.

5. The communication method according to any one of claims 1 to 4, It also obtains the identifier of the communication device. In the process of generating the key, the key is generated using the random number seed corresponding to the obtained identifier.

6. The communication method according to any one of claims 1 to 4, Determine whether the electronic certificate needs to be updated. In the process of generating the key, the key is generated if it is determined that the electronic certificate needs to be updated.

7. The communication method according to any one of claims 1 to 4, The number of times the random number seed in the communication device has been used is obtained. The number of times the random number seed is used is consistent with the number of times the random number seed in the obtained communication device is used.

8. A communication system, It includes a server and communication equipment for communicating with the server. The server has the following features: The key generation unit uses a pre-stored random number seed to generate a key containing a private key and a public key; The certificate creation department creates an electronic certificate for the key using the key generated by the key generation department; and The communications department sends the electronic certificate created by the certificate creation department to the communications equipment. The communication device includes: The communications department receives the electronic certificate sent from the server; and The key generation unit generates a key that is the same as the key using a pre-stored random number seed that is the same as the random number seed.

9. A server, having: The key generation unit uses a pre-stored random number seed to generate a key containing a private key and a public key; The certificate creation department creates an electronic certificate for the key using the key generated by the key generation department; and The communication unit sends the electronic certificate created by the certificate creation unit to the communication device, which has a random number seed that is the same as the random number seed stored in advance, and uses the random number seed to generate a key that is the same as the key.

10. A communication device for communicating with a server, comprising: A key generation unit, using a pre-stored random number seed identical to the one used on the server, generates a key identical to the one generated on the server, containing a private key and a public key; and The communications department receives an electronic certificate about the key, created on the server using the key, sent from the server.

Citation Information

Patent Citations

  • Information processing device, signature generation device, information processing method, signature generation method, and program

    JP2013048350A