Encryption method, decryption method, information processing system, and program

The encryption method addresses the security challenges of IoT data storage by using a tamper-resistant device for key generation, ensuring secure encryption and decryption, even with devices of limited capacity, thereby enhancing the security of data stored on storage mediums.

JP2025079587APending Publication Date: 2025-05-22DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023192361
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-10
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

Existing encryption methods for IoT data face challenges in ensuring the security of data stored on storage mediums, particularly due to the need for expensive devices with matching functions on both sending and receiving sides, and the limitations of storage capacity and security in USBs and IC cards.

Method used

An encryption method involving a first information processing device that generates key generation data and transmits it to a second information processing device, which derives keys for encryption and decryption, ensuring secure storage of encrypted data on a storage medium with limited capacity.

Benefits of technology

This method enhances the security of data stored on storage mediums by utilizing a tamper-resistant device for key generation, allowing for secure encryption and decryption processes, even with devices of limited storage capacity and computing power.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025079587000001_ABST
    Figure 2025079587000001_ABST
Patent Text Reader

Abstract

To provide an encryption method, a decryption method, an information processing system, and a program for ensuring security of data stored in a storage medium.SOLUTION: An encryption processing method is executed by an information processing terminal that stores an encryption target file and an anti-tamper device that stores a first key and a second key. In the encryption processing method, the information processing terminal generates an encryption target information file and key generation data of the encryption target information file, and transmits the key generation data to the anti-tamper device; the anti-tamper device derives a third key from the key generation data and the first key, and transmits the third key to the information processing terminal; the information processing terminal encrypts the encryption target information file by the third key, and transmits first data generated from the encryption target file to the anti-tamper device; the anti-tamper device derives a fourth key from the first data and the second key, and transmits the fourth key to the information processing terminal; and the information processing terminal encrypts the encryption target file by the fourth key.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to an encryption method, a decryption method, an information processing system, and a program. [Background technology]

[0002] With the recent spread of IoT (Internet of Things), various devices are connected to networks, and data acquired from these devices is being utilized. For example, collected data can be used for entrance and exit monitoring using video information acquired by cameras, disaster monitoring using measuring instruments such as seismometers and flow meters, business continuity plan (BCP) support, smart homes, smart cities, etc. Such various IoT data can be transmitted and received via networks.

[0003] In general, communication paths on a network are encrypted using a communication method such as TLS (Transport Layer Security). At the data receiving end, the decrypted data is stored on a storage medium. Confidential data (e.g., keys, personal information, etc.) that should be stored in a secure area may be processed in the encrypted state without decrypting the received encrypted data. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2019-161521 A Summary of the Invention [Problem to be solved by the invention]

[0005] However, to achieve this, not only would an expensive device be necessary, but the same functions would be required on both the sending and receiving sides. As a measure for the receiving side only, the received data may be encrypted and stored on a USB (Universal Serial Bus) with encryption function, but the security of the encryption key may not be sufficient, and if the encryption key is leaked, all the stored data will be revealed. Also, the data may be stored on a highly secure IC (Integrated Circuit) card, but there is a problem that the capacity of the IC card is not sufficient.

[0006] In view of the above problems, an object of the present disclosure is to provide an encryption technique for ensuring the security of data stored on a storage medium. [Means for solving the problem]

[0007] One aspect of the present disclosure relates to an encryption method executed by a first information processing device that stores a file to be encrypted and a second information processing device that stores a first key and a second key, comprising: the first information processing device generating an information file to be encrypted and key generation data for the information file to be encrypted, and transmitting the key generation data to the second information processing device; the second information processing device deriving a third key from the key generation data and the first key, and transmitting the third key to the first information processing device; the first information processing device encrypting the information file to be encrypted using the third key and transmitting first data generated from the file to be encrypted to the second information processing device; the second information processing device deriving a fourth key from the first data and the second key, and transmitting the fourth key to the first information processing device; and the first information processing device encrypting the file to be encrypted using the fourth key.

[0008] Another aspect of the present disclosure relates to a decryption method executed by a first information processing device that stores an encrypted file and a second information processing device that stores a first key and a second key, comprising: the first information processing device transmitting key generation data of an information file to be encrypted of the encrypted file to the second information processing device; the second information processing device deriving a third key from the key generation data and the first key and transmitting the third key to the first information processing device; the first information processing device decrypting the information file to be encrypted using the third key and transmitting first data generated from the key generation information file to the second information processing device; the second information processing device deriving a fourth key from the first data and the second key and transmitting the fourth key to the first information processing device; and the first information processing device decrypting the encrypted file using the fourth key. Effect of the Invention

[0009] According to the present disclosure, it is possible to provide an encryption technique for ensuring the security of data stored on a storage medium. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 is a schematic diagram illustrating an information processing system according to an embodiment of the present disclosure. [Diagram 2] FIG. 2 is a schematic diagram illustrating an encryption process in an information processing system according to an embodiment of the present disclosure. [Diagram 3] FIG. 3 is a block diagram illustrating a hardware configuration of an information processing terminal according to an embodiment of the present disclosure. [Figure 4] FIG. 4 is a block diagram illustrating a hardware configuration of a tamper-resistant device according to an embodiment of the present disclosure. [Diagram 5] FIG. 5 is a sequence diagram illustrating an encryption process according to an embodiment of the present disclosure. [Figure 6] 6A to 6D are schematic diagrams showing various data used in encryption processing according to an embodiment of the present disclosure. [Figure 7] FIG. 7 is a sequence diagram illustrating a decryption process according to an embodiment of the present disclosure. [Figure 8] 8A to 8D are schematic diagrams showing various data used in the decoding process according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0012] In the following embodiment, an information processing system that encrypts and stores encryption target data is disclosed.

[0013] [Information Processing System] First, an information processing system according to an embodiment of the present disclosure will be described. Fig. 1 is a schematic diagram showing an information processing system 10 according to an embodiment of the present disclosure.

[0014] 1, the information processing system 10 includes an information processing terminal 100 and a tamper-resistant device 200, and the information processing terminal 100 and the tamper-resistant device 200 are communicatively connected to each other. Typically, the information processing terminal 100 and the tamper-resistant device 200 can be connected to each other via wiring, a cable, or the like.

[0015] The information processing terminal 100 may be any type of information processing device, such as a smartphone, a tablet, a personal computer, a server, or a processing circuit.

[0016] The tamper-resistant device 200 may be any type of information processing device, such as an IC circuit or an IC card, that has tamper resistance for storing confidential data.

[0017] In the illustrated embodiment, the information processing terminal 100 and the tamper-resistant device 200 are physically separated, but the present disclosure is not limited to this. For example, the tamper-resistant device 200 may be built into the information processing terminal 100.

[0018] FIG. 2 is a schematic diagram showing an encryption process in the information processing system 10 according to an embodiment of the present disclosure. As shown in FIG. 2, in the information processing terminal 100, in the encryption process, as will be described in detail hereinafter, using the key generated by the tamper-resistant device 200, the file to be encrypted stored therein is encrypted to generate an encrypted file. On the other hand, in the decryption process, the information processing terminal 100 requests the key from the tamper-resistant device 200, and decrypts the encrypted file using the key generated by the tamper-resistant device 200.

[0019] As described above, in the information processing system 10 according to the present embodiment, the tamper-resistant device 200 only generates keys for encryption and decryption, and the file to be encrypted is encrypted by the information processing terminal 100 having a relatively large storage capacity and computing power and stored as an encrypted file. Thereby, using the tamper-resistant device 200 with limited storage capacity and computing power, the files stored in the portable information terminal 100 can be encrypted.

[0020] Here, the information processing terminal 100 may have a hardware configuration as shown in FIG. 3, for example. That is, the information processing terminal 100 includes an interface device 101, a storage device 102, a memory device 103, a processor 104, a user interface (UI) device 105, and a communication device 106 that are interconnected via a bus B.

[0021] Programs and / or data for realizing various functions and processes in the information processing terminal 100 are downloaded from an external device and / or network to the storage device 102 or the memory device 103 via the interface device 101.

[0022] The storage device 102 is realized by a non-volatile memory or the like and stores installed or downloaded programs or data (for example, files, etc.).

[0023] The memory device 103 is realized by a random access memory, a static memory, or the like, and when a program or an instruction is activated, reads and stores the program or instruction, data, or the like from the storage device 102. The storage device 102, the memory device 103, and the removable storage medium may be collectively referred to as a non-transitory storage medium.

[0024] The processor 104 may be realized by one or more CPUs (Central Processing Units), GPUs (Graphics Processing Units), processing circuitry, etc., which may be composed of one or more processor cores, and executes various functions and processes of the information processing terminal 100 in accordance with programs, instructions, data such as parameters necessary to execute the programs or instructions, etc. stored in the memory device 103.

[0025] The user interface (UI) device 105 may be composed of input devices such as a keyboard, a mouse, a camera, a microphone, etc., output devices such as a display, a speaker, a headset, a printer, etc., and input / output devices such as a touch panel, and realizes an interface between a user and the information processing terminal 100. For example, a user may operate the information processing terminal 100 by operating a GUI (Graphical User Interface) displayed on a display or a touch panel using a keyboard, a mouse, etc.

[0026] The communication device 106 is realized by various communication circuits that execute wired and / or wireless communication processing with an external device, the Internet, a LAN (Local Area Network), a cellular network, or other communication network.

[0027] However, the above-described hardware configuration is merely an example, and the information processing terminal 100 according to the present disclosure may be realized by any other appropriate hardware configuration.

[0028] On the other hand, the tamper-resistant device 200 may have a hardware configuration as shown in Fig. 4. That is, the tamper-resistant device 200 has a storage device 201, a memory device 202, a processor 203, and a communication device 204.

[0029] The storage device 201 is realized by a non-volatile memory or the like, and stores installed or downloaded programs or instructions, as well as files, data, and the like used in executing the programs or instructions.

[0030] The memory device 202 is realized by a random access memory, a static memory, etc., and reads and stores programs, data, etc. The memory device 202 can operate as a working memory for the processor 203.

[0031] The processor 203 may be realized by a CPU, a processing circuit, etc., and executes various functions and processes of the tamper-resistant device 200 in accordance with programs stored in the memory device 202 and data such as parameters required to execute the programs.

[0032] The communication device 204 is realized by various communication circuits that execute communication processes with external devices, communication networks, and the like.

[0033] However, the above-described hardware configuration is merely an example, and the tamper-resistant device 200 according to the present disclosure may be realized by any other suitable hardware configuration.

[0034] [Encryption process] Next, an encryption process in the information processing system 10 according to an embodiment of the present disclosure will be described. Fig. 5 is a sequence diagram showing the encryption process in the information processing system 10 according to an embodiment of the present disclosure. As shown in Fig. 5, the encryption process is realized by an information processing terminal 100 that stores an encryption target file B, and a tamper-resistant device 200 that generates a key used in the encryption process by the information processing terminal 100.

[0035] In step S101, the information processing terminal 100 generates an encryption target information file C from an encryption target file B, and generates key generation data D from the encryption target information file C. That is, in order to encrypt the encryption target file B shown in FIG. 6A, the information processing terminal 100 first generates an encryption target information file C including data generated from the encryption target file B, such as a checksum or signature of the encryption target file B, a message authentication code (MAC) value, a hash value, or a part of data of the file B, and user data, as shown in FIG. 6B. Next, the information processing terminal 100 generates key generation data D including user data, as shown in FIG. 6C. Here, the user data may be composed of, for example, a user ID and password of the user of the information processing terminal 100, a terminal number of the information processing terminal 100, an update date of the encryption target information file, and the like. The user data of the encryption target information file C and the user data of the key generation data D may be different.

[0036] In step S 102 , the information processing terminal 100 transmits the key generation data D to the tamper-resistant device 200 .

[0037] In step S103, the tamper-resistant device 200 derives key 1-1 from the key generation data D and key 1. Specifically, the tamper-resistant device 200 may store key 1 in advance and generate key 1-1 from the key generation data D and key 1 using any appropriate key derivation method such as a GenerateKey command or a key derivation function (KDF).

[0038] In step S 104 , the tamper-resistant device 200 transmits the key 1 - 1 to the information processing terminal 100 .

[0039] In step S105, the information processing terminal 100 encrypts the encryption target information file C with the key 1-1.

[0040] In step S106, the information processing terminal 100 transmits data E generated from the encryption target file B to the tamper-resistant device 200. For example, the data E may be generated from plaintext data of the encryption target information file C generated from the encryption target file B, as shown in FIG. 6D.

[0041] In step S107, the tamper-resistant device 200 derives a key 2-1 from the data E and the key 2. Specifically, the tamper-resistant device 200 may store the key 2 in advance and generate the key 2-1 from the data E and the key 2 by using any appropriate key derivation method such as a GenerateKey command or a key derivation function (KDF). The data E may be set to a MAC value or a hash value of the data E depending on the input data length obtained by the key derivation function. Note that the key 2 may be different from the key 1, or may be the same as the key 1. The keys 1 and 2 from which the keys 1-1 and 2-1 are derived may be held as confidential data in the tamper-resistant device 200.

[0042] In step S108, the tamper-resistant device 200 transmits the key 2-1 to the information processing terminal 100.

[0043] In step S109, the information processing terminal 100 encrypts the encryption target file B with the key 2-1, and stores the generated encrypted file B.

[0044] In this manner, in the information processing system 10 according to this embodiment, the information processing terminal 100 uses the key acquired from the tamper-resistant device 200 to encrypt the encryption target file B, and stores the generated encrypted file B. This allows the information processing terminal 100, which has a relatively large storage capacity and computing power, to encrypt the encryption target file B, and safely store the generated encrypted file B, using the key from the tamper-resistant device 200, which has a limited storage capacity and computing power.

[0045] [Decryption process] Next, a decryption process in the information processing system 10 according to an embodiment of the present disclosure will be described. Fig. 7 is a sequence diagram showing the decryption process in the information processing system 10 according to an embodiment of the present disclosure. As shown in Fig. 7, the decryption process is realized by the information processing terminal 100 that stores the encrypted file B generated by the above-mentioned encryption process, and the tamper-resistant device 200 that generates a key used in the decryption process by the information processing terminal 100.

[0046] In step S201, the information processing terminal 100 transmits key generation data D of an information file C to be encrypted to the tamper-resistant device 200. The key generation data D is the same as that generated in the encryption process of the file B to be encrypted, and the encrypted file B can be decrypted only by a user who knows the key generation data D. To decrypt the encrypted file B shown in Fig. 8A, the information processing terminal 100 first generates key generation data D including user data, as shown in Figs. 8B and 8C. Here, the user data may be composed of, for example, a user ID and password of the user of the information processing terminal 100, the terminal number of the information processing terminal 100, etc.

[0047] In step S202, the tamper-resistant device 200 derives key 1-1 from the key generation data D and key 1. Specifically, the tamper-resistant device 200 may store key 1 in advance and generate key 1-1 from the key generation data D and key 1 using any appropriate key derivation method such as a GenerateKey command or a key derivation function (KDF).

[0048] In step S 203 , the tamper-resistant device 200 transmits the key 1 - 1 to the information processing terminal 100 .

[0049] In step S204, the information processing terminal 100 decrypts the encryption target information file C with the key 1-1. That is, the information processing terminal 100 decrypts the encryption target information file C encrypted with the key 1-1 in the encryption process described above with the same key 1-1.

[0050] In step S205, the information processing terminal 100 extracts data E of the encryption target information file B from the decrypted encryption target information file C. Specifically, the information processing terminal 100 generates data E as shown in Fig. 8D from the plaintext data of the encryption target information file C shown in Fig. 8B. For example, the data E may be generated from a part of the plaintext data of the encryption target information file C, or from data other than the encryption target information file C.

[0051] In step S206, the information processing terminal 100 transmits the data E to the tamper-resistant device 200.

[0052] In step S207, the tamper-resistant device 200 derives a key 2-1 from the data E and the key 2. Specifically, the tamper-resistant device 200 may store the key 2 in advance and generate the key 2-1 from the data E and the key 2 by using any appropriate key derivation method such as a GenerateKey command or a key derivation function (KDF). Note that the key 2 may be different from the key 1, or may be the same as the key 1. Furthermore, the keys 1 and 2 may be the same as those used in the encryption process described above. The keys 1 and 2 from which the keys 1-1 and 2-1 are derived are held as confidential data in the tamper-resistant device 200.

[0053] In step S208, the tamper-resistant device 200 transmits the key 2-1 to the information processing terminal 100.

[0054] In step S209, the information processing terminal 100 decrypts the encrypted file B with the key 2-1. It is also possible to verify the validity of the series of processes by regenerating the encryption target information file C using the decrypted file and comparing and verifying it with the file C decrypted in step S205. The comparison and verification target may be only the value generated from the file B.

[0055] In this manner, in the information processing system 10 according to this embodiment, the information processing terminal 100 uses the key acquired from the tamper-resistant device 200 to decrypt the encrypted file B and restore file B. As a result, the information processing terminal 100 having a relatively large storage capacity and computing power can decrypt the encrypted file B and restore file B using the key from the tamper-resistant device 200 having a limited storage capacity and computing power.

[0056] Although the examples of the present disclosure have been described in detail above, the present disclosure is not limited to the specific embodiments described above, and various modifications and variations are possible within the scope of the gist of the present disclosure described in the claims. [Explanation of symbols]

[0057] 10. Information Processing Systems 100 Information processing terminal 200 Anti-tamper Device

Claims

1. An encryption method executed by a first information processing device that stores a file to be encrypted and a second information processing device that stores a first key and a second key, comprising: the first information processing device generates an encryption target information file and key generation data for the encryption target information file, and transmits the key generation data to the second information processing device; the second information processing device deriving a third key from the key generation data and the first key, and transmitting the third key to the first information processing device; the first information processing device encrypts the encryption target information file with the third key, and transmits first data generated from the encryption target file to the second information processing device; the second information processing device deriving a fourth key from the first data and the second key, and transmitting the fourth key to the first information processing device; the first information processing device encrypts the encryption target file with the fourth key; 1. An encryption method comprising:

2. 2. The encryption method according to claim 1, wherein the encryption target information file includes a value generated from the encryption target file and user data.

3. 2. The encryption method according to claim 1, wherein the first data includes plaintext data of the encryption target information file.

4. a first information processing device that stores a file to be encrypted; a second information processing device that stores a first key and a second key; An information processing system having: the first information processing device generates an encryption target information file and key generation data for the encryption target information file, and transmits the key generation data to the second information processing device; the second information processing device derives a third key from the key generation data and the first key, and transmits the third key to the first information processing device; the first information processing device encrypts the encryption target information file with the third key, and transmits first data generated from the encryption target file to the second information processing device; the second information processing device derives a fourth key from the first data and the second key, and transmits the fourth key to the first information processing device; The first information processing device encrypts the encryption target file with the fourth key.

5. A program to be executed by a first information processing device that stores a file to be encrypted and a second information processing device that stores a first key and a second key, causing the first information processing device to generate an encryption target information file and key generation data for the encryption target information file, and to transmit the key generation data to the second information processing device; causing the second information processing device to derive a third key from the key generation data and the first key, and to transmit the third key to the first information processing device; causing the first information processing device to encrypt the encryption target information file with the third key and transmit first data generated from the encryption target file to the second information processing device; causing the second information processing device to derive a fourth key from the first data and the second key, and to transmit the fourth key to the first information processing device; A program that causes the first information processing device to encrypt the encryption target file with the fourth key.

6. A decryption method executed by a first information processing device that stores an encrypted file and a second information processing device that stores a first key and a second key, comprising: The first information processing device transmits key generation data for an encryption target information file of the encrypted file to the second information processing device; the second information processing device deriving a third key from the key generation data and the first key, and transmitting the third key to the first information processing device; the first information processing device decrypts the encryption target information file with the third key, and transmits first data generated from the encryption target information file to the second information processing device; the second information processing device deriving a fourth key from the first data and the second key, and transmitting the fourth key to the first information processing device; the first information processing device decrypting the encrypted file with the fourth key; The decoding method according to claim 1,

7. 7. The decryption method according to claim 6, wherein the encryption target information file includes a value generated from the encryption target file and user data.

8. 7. The decryption method according to claim 6, wherein the first data includes plaintext data of the encryption target information file.

9. a first information processing device that stores an encrypted file; a second information processing device that stores a first key and a second key; An information processing system having: the first information processing device transmits key generation data for an encryption target information file of the encrypted file to the second information processing device; the second information processing device derives a third key from the key generation data and the first key, and transmits the third key to the first information processing device; the first information processing device decrypts the encryption target information file with the third key, and transmits first data generated from the encryption target information file to the second information processing device; the second information processing device derives a fourth key from the first data and the second key, and transmits the fourth key to the first information processing device; The first information processing device decrypts the encrypted file with the fourth key.

10. A program to be executed by a first information processing device that stores an encrypted file and a second information processing device that stores a first key and a second key, causing the first information processing device to transmit key generation data for an information file to be encrypted of the encrypted file to the second information processing device; causing the second information processing device to derive a third key from the key generation data and the first key, and to transmit the third key to the first information processing device; causing the first information processing device to decrypt the encryption target information file with the third key and transmit first data generated from the encryption target information file to the second information processing device; causing the second information processing device to derive a fourth key from the first data and the second key, and to transmit the fourth key to the first information processing device; A program that causes the first information processing device to decrypt the encrypted file with the fourth key.

Citation Information

Patent Citations

  • Vehicle key distribution system and general-purpose scanning tool

    JP2019161521A