Encryption device, encryption method, encryption program, and encryption system

The encryption device addresses vulnerabilities in existing systems by splitting and encrypting data with multiple methods and updating standards, ensuring high confidentiality even if encryption information is compromised.

JP2025112968APending Publication Date: 2025-08-01NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024007556
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

Existing encryption systems, such as described in Patent Document 1, are vulnerable to decryption by malicious third parties due to predetermined encryption means and information, which can be compromised, leading to security breaches.

Method used

An encryption device that splits data into multiple parts, encrypts each part using different standards, and combines them, while periodically updating these standards to enhance security.

Benefits of technology

This approach significantly enhances data confidentiality by making it difficult for unauthorized parties to decrypt the data, even if encryption methods are compromised or leaked, by using diverse encryption techniques and dynamic updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025112968000001_ABST
    Figure 2025112968000001_ABST
Patent Text Reader

Abstract

To provide an encryption system that has high confidentiality.SOLUTION: An encryption device comprises: a division part which divides data into a plurality of pieces of division data based upon first norms; an encryption part which encrypts the plurality of pieces of division data respectively based upon the first norms to generate a plurality of pieces of encrypted data; and a combining part which combines the plurality of pieces of encrypted data into one piece of combined data, the first norms being updated into second norms.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an encryption device, an encryption method, an encryption program, and an encryption system.

Background Art

[0002] Patent Document 1 describes an encryption system that divides transmission data into a plurality of data and encrypts each of the divided plurality of data using a plurality of encryption keys.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the encryption system described in Patent Document 1, the means and information used in the encryption process are determined in advance, and the information is added to the transmission data. When a vulnerability is discovered in the encryption process and / or when the means and the information are leaked, there is a problem that the encrypted data is decrypted by a malicious third party.

[0005] An object of the present disclosure is to provide an encryption device that solves the above problems.

Means for Solving the Problems

[0006] According to one aspect of the present disclosure, there is provided an encryption device including a division unit that divides data into a plurality of divided data based on a first standard, an encryption unit that encrypts each of the plurality of divided data based on the first standard to generate a plurality of encrypted data, and a combination unit that combines the plurality of encrypted data into one combined data, and updating the first standard to a second standard.

[0007] According to one aspect of the present disclosure, based on a first standard, a splitting step of splitting data into a plurality of split data, an encrypting step of encrypting each of the plurality of split data based on the first standard to generate a plurality of encrypted data, and a combining step of combining the plurality of encrypted data into one combined data, and updating the first standard to a second standard, an encryption method is provided.

[0008] According to one aspect of the present disclosure, based on a first standard, a splitting step of splitting data into a plurality of split data, an encrypting step of encrypting each of the plurality of split data based on the first standard to generate a plurality of encrypted data, and a combining step of combining the plurality of encrypted data into one combined data, and updating the first standard to a second standard, an encryption program is provided.

[0009] According to one aspect of the present disclosure, an encryption system is provided that includes an encryption device and at least one decryption device, and based on a first standard, data is transmitted and received between the encryption device and the at least one decryption device, and the first standard is updated to a second standard.

Advantages of the Invention

[0010] According to the present disclosure, it becomes possible to provide an encryption system with high confidentiality.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Mode for Carrying Out the Invention

[0012] Hereinafter, an encryption device according to an embodiment of the present disclosure will be described with reference to the drawings. In all the drawings, the same or corresponding components are denoted by the same reference numerals, and common descriptions are omitted.

[0013] [First Embodiment] FIG. 1 is a schematic diagram showing an encryption system according to an embodiment of the present disclosure. The encryption system 1 includes a transmitter 2, a plurality of receivers 3, and a server 4. In the present embodiment, the transmitter 2, the plurality of receivers 3, and the server 4 are communicably connected to each other via a network 5.

[0014] The transmitter 2 is an information processing device that transmits data to the receiver 3, and can be, for example, a personal computer, a workstation, a mobile terminal, a hardware server, a software server, etc. When the transmitter 2 is a hardware server, the transmitter 2 can be, for example, a network server or a cloud server, etc. When the transmitter 2 is a software server, the transmitter 2 can be, for example, server software or a server program, etc. In the present embodiment, one transmitter 2 is shown in FIG. 1, but the number of transmitters 2 is not limited to one. The transmitter 2 encrypts data based on the specifications (hereinafter, shared specifications) managed by the encryption system 1 or the server 4, and transmits the encrypted data to a plurality of receivers 3.

[0015] The receiver 3 is an information processing device that receives data from the transmitter 2, and can be, for example, a personal computer, a workstation, a mobile terminal, a hardware server, a software server, etc. When the receiver 3 is a hardware server, the receiver 3 can be, for example, a network server or a cloud server, etc. When the receiver 3 is a software server, the receiver 3 can be, for example, server software or a server program, etc. The receiver 3 receives data from the transmitter 2 and decrypts the data encrypted by the transmitter 2 based on the shared specifications managed by the encryption system 1.

[0016] The server 4 is an information processing device and can be, for example, a hardware server, a software server, etc. When the server 4 is a hardware server, the server 4 can be, for example, a network server or a cloud server, etc. When the server 4 is a software server, the server 4 can be, for example, server software or a server program, etc. The server 4 manages the shared specifications used in the encryption system 1.

[0017] Server 4 periodically or irregularly transmits the shared specifications to the transmitter 2 and the receiver 3, and updates the shared specifications used in the encryption system 1. The transmitter 2 receives the shared specifications from the server 4, encrypts the data based on the always-updated shared specifications, and transmits the encrypted data to the receiver 3. The receiver 3 receives the shared specifications from the server 4, receives the encrypted data from the transmitter 2 based on the always-updated shared specifications, and decrypts the data.

[0018] In addition, when the server 4 does not transmit the shared specifications to the transmitter 2 and the receiver 3, and the transmitter 2 encrypts the data and transmits the data to the receiver 3, the transmitter 2 may obtain the shared specifications from the server 4. Alternatively, the transmitter 2 may obtain some of the shared specifications used for encrypting the data from among the shared specifications, and encrypt the data based on the some of the shared specifications.

[0019] Similarly, when the receiver 3 receives the encrypted data from the transmitter 2 and decrypts the data, the receiver 3 may obtain the shared specifications from the server 4. Alternatively, the receiver 3 may obtain some of the shared specifications used for decrypting the encrypted data from among the shared specifications, and decrypt the data based on the some of the shared specifications. The manner in which the transmitter 2 and the receiver 3 obtain the shared specifications is not limited to the above manner. For example, the user of the transmitter 2 and the user of the receiver 3 may transfer the shared specifications via a USB memory or the like, or may transfer the shared specifications by mail or the like via a network different from the network 5 in FIG. 1. When the transmitter 2 and the receiver 3 transfer the shared specifications to each other, it is desirable that the transmitter 2 and the receiver 3 transfer the shared specifications via a network different from the network 5 through which the encrypted data is transferred.

[0020] Figure 2 is a block diagram showing the transmitter 2 according to an embodiment of the present disclosure. The transmitter 2 includes a CPU 21, a ROM 22, a RAM 23, a storage device 24, an input / output IF (Interface) 25, and a communication IF 26. The CPU 21, the ROM 22, the RAM 23, the storage device 24, the input / output IF 25, and the communication IF 26 are communicably connected to each other via a bus 29.

[0021] The CPU 21 is a Central Processing Unit. The CPU 21 controls each part of the transmitter 2 using an application program. The ROM 22 is a Read Only Memory. The ROM 22 is composed of a non-volatile memory and stores an application program for controlling each part of the transmitter 2. The RAM 23 is a Random Access Memory. The RAM 23 provides a memory area necessary for the operation of the CPU 21. The storage device 24 is a large-capacity storage device such as a Hard Disc Drive.

[0022] The input / output IF 25 is an input / output interface for voice input from the user, voice output to the user, and data transmission and reception between the terminal 1 and other devices. The input / output IF 25 may include a mouse, a trackball, a keyboard, a speaker, etc. The user can operate the transmitter 2 via the input / output IF 25. The communication IF 26 performs mutual data communication between the transmitter 2, a plurality of receivers 3, and a server 4 via wired communication or / and wireless communication.

[0023] In this embodiment, since the configurations of the receiver 3 and the server 4 are the same as the configuration of the transmitter 2, the description of the configurations of the receiver 3 and the server 4 is omitted.

[0024] FIG. 3 is a block diagram showing the functions of the transmitter 2 and the receiver 3 according to an embodiment of the present disclosure. The transmitter 2 includes a control unit 201, a specification determination unit 202, an information addition unit 203, a division unit 204, an encryption unit 205, a combination unit 206, an interleaver 207, a database 208, and a shared specification 209.

[0025] The control unit 201 controls the functions of the transmitter 2. That is, the control unit 201 controls and manages the specification determination unit 202, the information addition unit 203, the division unit 204, the encryption unit 205, the combination unit 206, the interleaver 207, and the database 208. The control unit 201 can receive user input, execution instructions, transmission data and transmission data information, and the shared specification 209 from the input / output IF 25 and the communication IF 26 provided in the transmitter 2 and store them in the database 208. The control unit 201 can transmit the encrypted transmission data and the like to the receiver 3 via the input / output IF 25 and the communication IF 26. The control unit 201 can communicate with the server 4 via the input / output IF 25 and the communication IF 26 and transmit a request for transmitting the latest information about the shared specification 209, a request for transmitting a part or all of the shared specification 209, and the like.

[0026] The specification determination unit 202 selects one encryption procedure from among a plurality of encryption procedures included in the shared specification 209. For example, the specification determination unit 202 may determine the encryption procedure based on the selection of the user operating the transmitter 2, may determine the encryption procedure based on the MAC address of the transmitter 2, may determine the encryption procedure based on the MAC address of the receiver 3, or may determine the encryption procedure based on the date and time of transmitting the transmission file. The method for determining the encryption procedure is not limited to the above method. For example, the encryption procedure may be determined based on a sequence number obtained by combining the MAC address of the transmitter 2 and the MAC address of the receiver 3. The transmitter 2 encrypts the transmission data according to the encryption procedure selected by the specification determination unit 202.

[0027] The information addition unit 203 adds identification information indicating the encryption procedure selected by the specification determination unit 202 to the transmission data. For example, when the file name of the transmission data is "YYYYMMDD_transmission data.extension", identification information indicating the encryption procedure may be added to the end of the file name of the transmission data, such as "YYYYMMDD_transmission data (identification information).extension". For example, identification information indicating the encryption procedure may be added to the header information of the transmission data. In this case, it is preferable that the information addition unit 203 adds identification information indicating the encryption procedure to the header of the data combined by the combination unit 206. The information addition unit 203 may transmit the identification information indicating the encryption procedure to the receiver 3 via a network different from the network 5 separately from the encrypted transmission data. Alternatively, the encryption procedure to be used in advance may be determined between the transmitter 2 and the receiver 3.

[0028] Note that the information addition unit 203 may encrypt the identification information. For example, the encryption method may be stream encryption using the MAC address of the receiver 3, which is the transmission destination of the encrypted data. When encrypting the identification information, it is desirable that the transmitter 2 and the receiver 3 share the encryption method. By encrypting the identification information, it becomes difficult to infer the correspondence between the identification information included in the file name and the encryption procedure included in the sharing specification 209. In the present disclosure, for the sake of simplicity of explanation, the information addition unit 203 adds identification information directly indicating the procedure number of the sharing specification 209. For example, when the transmitter 2 encrypts the transmission data using the third encryption procedure, the identification information is "3".

[0029] The splitting unit 204 splits the transmission data into a plurality of data based on the encryption procedure selected by the specification determination unit 202. For example, when the data transmitted by the transmitter 2 is one file, the transmission data is split into two or more data. For example, when the data transmitted by the transmitter 2 is a real-time imaging video or the like, a part of the transmission data may be split into a certain data length.

[0030] The encryption unit 205 encrypts the plurality of data divided by the division unit 204 based on the encryption procedure selected by the specification determination unit 202. The encryption method may be, for example, Elgamal encryption, elliptic Elgamal encryption, RSA encryption, Diffie-Hellman key sharing, elliptic curve Diffie-Hellman key sharing, etc. The encryption method used in the encryption unit 205 is not limited to the above methods. The encryption method used in the encryption unit 205 may be a known encryption method that can be implemented.

[0031] The combining unit 206 combines the plurality of encrypted data to generate one piece of data. For example, when the data transmitted by the transmitter 2 is one file, all of the plurality of data encrypted by the encryption unit 205 may be combined to generate one piece of data. For example, when the data transmitted by the transmitter 2 is a real-time imaging video or the like, a part of the plurality of data encrypted by the encryption unit 205 may be combined to generate one encrypted data.

[0032] The interleaver 207 performs interleaving processing (data rearrangement) on the plurality of data divided by the division unit 204 and / or the plurality of data encrypted by the encryption unit 205 based on the encryption procedure selected by the specification determination unit 202 and a predetermined interleaving table. For example, when the interleaving table size is 4 (i.e., the number of data divisions is 4) and the elements of the table are [4, 3, 2, 1], the first, second, third, and fourth divided transmission data are rearranged, and the order of the transmission data from the beginning to the end of the data is changed to the fourth, third, second, and first. Note that the data interleaved by the interleaver 207 is not limited to the plurality of data divided by the division unit 204 and / or the plurality of data encrypted by the encryption unit 205. For example, the encrypted data combined by the combining unit 206 may be divided into a predetermined number of blocks, and the plurality of divided blocks may be interleaved.

[0033] The database 208 is a storage area that stores the sharing specifications 209. As will be described later, when the sharing specifications 209 are updated moment by moment, a plurality of sharing specifications 209 may be stored. The database 208 may store the MAC addresses of the plurality of receivers 3, authentication information, etc. when communicating between the transmitter 2 and the server 4.

[0034] The receiver 3 includes a control unit 301, a specification determination unit 302, an information extraction unit 303, a division unit 304, a decoding unit 305, a combination unit 306, a deinterleaver 307, a database 308, and a sharing specification 309.

[0035] The control unit 301 controls the functions of the receiver 3. That is, the control unit 301 controls and manages the specification determination unit 302, the information extraction unit 303, the division unit 304, the decoding unit 305, the combination unit 306, the deinterleaver 307, and the database 308. The control unit 301 can receive user input, execution instructions, and sharing specifications 309 from the input / output IF and communication IF provided in the receiver 3 and store them in the database 308. The control unit 301 can receive encrypted data, etc. from the transmitter 2 via the input / output IF and communication IF. The control unit 301 can communicate with the server 4 via the input / output IF and communication IF and transmit a request for sending the latest information about the sharing specification 309, a request for sending a part or all of the sharing specification 309, etc.

[0036] Based on the identification information added by the information addition unit 203, the specification determination unit 302 selects one encryption procedure from among the plurality of encryption procedures included in the sharing specification 309. The information extraction unit 303 extracts the identification information added by the information addition unit 203 from the encrypted data received by the receiver 3. The transmitter 2 and the receiver 3 determine in advance a method of adding identification information, etc., and based on the determined method, the information extraction unit 303 extracts the identification information from the encrypted data. When the receiver 3 receives, via a network different from the network 5, identification information indicating an encryption procedure from the transmitter 2 separately from the encrypted data, based on the received identification information, the specification determination unit 302 selects one encryption procedure from among the plurality of encryption procedures included in the sharing specification 309. The receiver 3 decrypts the encrypted data based on the encryption procedure selected by the specification determination unit 302.

[0037] Based on the encryption procedure selected by the specification determination unit 302, the splitting unit 304 splits the encrypted data into a plurality of data. For example, if it is determined that the number of splits is 4 in the encryption procedure, the splitting unit 304 splits the encrypted data into four data. For example, if it is determined that the split data length is a predetermined split length in the encryption procedure, the splitting unit 304 splits a part of the encrypted data into the predetermined split length.

[0038] Based on the encryption procedure and the encryption key selected by the specification determination unit 302, the decryption unit 305 decrypts the plurality of data split by the splitting unit 304. The decryption method may be a method corresponding to the encryption method used in the encryption unit 205.

[0039] The combining unit 306 combines the plurality of decrypted data to generate one data. For example, when the data transmitted by the transmitter 2 is one file, all of the plurality of data decrypted by the decryption unit 305 are combined to generate one data. For example, when the data transmitted by the transmitter 2 is a real-time imaging video or the like, a part of the plurality of data decrypted by the decryption unit 305 may be combined to generate one data.

[0040] The deinterleaver 307 performs a deinterleaving process (data rearrangement) on a plurality of data divided in the dividing unit 304 and / or a plurality of data decoded in the decoding unit 305 based on the encryption procedure selected in the specification determination unit 302 and a predetermined interleaving table. For example, when the interleaving table size is 4 (i.e., the number of data divisions is 4) and the elements of the table are [4, 3, 2, 1], in the transmitter 2, the first, second, third, and fourth divided transmission data are rearranged, and the order of the transmission data from the head to the end of the data is changed to the fourth, third, second, and first. In the receiver 3, the order of the encrypted data is further rearranged, and the order of the encrypted data is changed to the first, second, third, and fourth. That is, the deinterleaving process corresponds to the reverse process of the interleaving process in the interleaver 207. Note that the data deinterleaved by the deinterleaver 307 is not limited to a plurality of data divided in the dividing unit 304 and / or a plurality of data decoded in the decoding unit 305. The deinterleaver 307 performs the reverse process of the interleaving process executed in the transmitter 2.

[0041] The database 308 is a storage area for storing the shared specification 309. As will be described later, when the shared specification 309 is updated from moment to moment, a plurality of shared specifications 309 may be stored. The database 308 may store the MAC address of the transmitter 2, authentication information, etc. when communicating between the receiver 3 and the server 4.

[0042] FIG. 4 is a diagram showing an example of a shared specification according to an embodiment of the present disclosure, and is an example of the shared specification 209 in FIG. 3. In the present disclosure, the shared specification 209 includes a procedure number 2091, a division number 2092A or a division length 2092B, an encryption method 2093, a key length 2094, a key number 2095 indicating an encryption key, a code 2096 and a table number 2097 indicating the interleaving process after division, and a code 2098 and a table number 2099 indicating the interleaving process after encryption.

[0043] Procedure number 2091 corresponds directly or indirectly to the identification information given in the information addition unit 203. As described above, for the sake of simplicity, the information addition unit 203 adds identification information directly indicating the procedure number 2091 of the sharing specification 209, so the procedure number 2091 and the identification information are the same number. For example, when the transmitter 2 encrypts the transmission data based on the "0" -th encryption procedure of the procedure number 2091, the identification information indicates the "0" -th. Based on the said identification information, the information extraction unit 303 extracts the "0" -th of the procedure number 2091.

[0044] The number of divisions 2092A and the division length 2092B are used for dividing the transmission data in the division unit 204 and dividing the encrypted data in the division unit 304. For example, when the number of divisions 2092A is "4", the transmitter 2 divides the transmission data into 4 pieces of data. For example, when the division length 2092B is "128" kilobytes (KB), the transmitter 2 divides the transmission data every 128 KB. Note that the unit of the division length 2092B is not limited to kilobytes. The division length 2092B may be a unit smaller than a kilobyte or a unit larger than a kilobyte. For example, when the capacity of the transmission data is large, the division length 2092B may be set in megabyte units. Also, the division length 2092B may have a plurality of division lengths. For example, when dividing the transmission data, one transmission data may be divided using a plurality of division lengths such as 8 - kilobyte divided data, 16 - kilobyte divided data, 24 - kilobyte divided data, 8 - kilobyte divided data, 16 - kilobyte divided data, 24 - kilobyte divided data,....

[0045] The encryption method 2093 indicates the encryption method in the encryption unit 205. The encryption method 2093 may have a plurality of encryption methods. For example, when the number of divisions 2092A is "4", for the 4 divided pieces of data, the encryption method 2093 may have 4 different encryption methods [method A, method B, method C, method D]. All of the plurality of encryption methods may be different from each other, or some of the plurality of encryption methods may be different from each other.

[0046] The key length 2094 indicates the length of the encryption key used for encryption in the encryption unit 205. The key length 2094 may have multiple encryption key lengths. For example, when the division number 2092A is "2", for the two divided data, the key length 2094 may have two different encryption key lengths [64, 32]. All of the multiple encryption key lengths may be different from each other, or some of the multiple encryption key lengths may be different from each other.

[0047] The key number 2095 indicates the encryption key used for encryption in the encryption unit 205. The key number 2095 may have multiple encryption keys. For example, when the division number 2092A is "4", for the four divided data, the key number 2095 may have four different encryption keys [2, 4, 6, 8]. All of the multiple encryption keys may be different from each other, or some of the multiple encryption keys may be different from each other.

[0048] Note that the sharing specification 209 may directly include the encryption key instead of the key number 2095. For example, the sharing specification 209 may include a sequence of numbers indicating the encryption key. For example, when the division number 2092A is "4", for the four divided data, the key number 2095 may have a sequence of numbers [sequence 1, sequence 2, sequence 3, sequence 4] indicating four different encryption keys. All of the sequences of numbers indicating the multiple encryption keys may be different from each other, or some of the sequences of numbers indicating the multiple encryption keys may be different from each other. Also, in addition to the sequence of numbers indicating the four encryption keys, the key number 2095 may have a sequence of numbers indicating the public keys corresponding to the respective encryption keys.

[0049] Symbol 2096 is a variable for switching the presence or absence of interleaving processing, and indicates whether to perform interleaving processing on the data divided by the dividing unit 204 and whether to perform de-interleaving processing on the data divided by the dividing unit 304. Table number 2097 is a number indicating an interleaving table, and selects one interleaving table from among a plurality of interleaving tables. When symbol 2096 is "none", table number 2097 does not specify a table, and the interleaver 207 does not perform interleaving processing on the divided data. When symbol 2096 is "yes", table number 2097 specifies a table, and the interleaver 207 performs interleaving processing on the divided data according to the interleaving table indicated by table number 2097. For example, when the division number 2092A is "8" and symbol 2096 is "yes", the interleaver 207 selects the table with the number indicated by table number 2097 from among a plurality of interleaving tables with an element number of 8, and performs interleaving processing on the divided data. Note that table number 2097 may directly store the interleaving table instead of the number indicating the interleaving table.

[0050] Symbol 2098 is a variable for switching the presence or absence of interleaving processing, and indicates whether to perform interleaving processing on the data encrypted by the encryption unit 205 and whether to perform de-interleaving processing on the data decrypted by the decryption unit 305. Table number 2099 is a number indicating an interleaving table, and selects one interleaving table from among a plurality of interleaving tables. When symbol 2098 is "none", table number 2099 does not specify a table, and the interleaver 207 does not perform interleaving processing on the encrypted data. When symbol 2098 is "yes", table number 2099 specifies a table, and the interleaver 207 performs interleaving processing on the encrypted data according to the interleaving table indicated by table number 2099.

[0051] It should be noted that the shared norm 309 in the receiver 3 has the same configuration as the shared norm 209 in the transmitter 2. Like the shared norm 209, the shared norm 309 also includes a procedure number 2091, a division number 2092A or a division length 2092B, an encryption method 2093, a key length 2094, a key number 2095 indicating the encryption key, a code 2096 and a table number 2097 indicating the interleaving process after division, and a code 2098 and a table number 2099 indicating the interleaving process after encryption.

[0052] FIG. 5 is a flowchart showing encryption processing in a transmitter according to an embodiment of the present disclosure. FIG. 6 is a diagram showing an example of a data structure according to an embodiment of the present disclosure. An example of encryption processing in the transmitter 2 will be described for a case where the transmission data is a single file, not continuous data such as real-time video, and the file name of the transmission data is "YYYYMMDD_transmission data.extension." It is assumed that it is predetermined between the transmitter 2 and the receiver 3 that identification information indicating the encryption procedure will be added to the end of the file name. Furthermore, an example of encryption processing in the transmitter 2 will be described using the encryption procedure indicated by "1" in procedure number 2091 as an example.

[0053] The transmitter 2 acquires the transmission data (step S101). The trigger for the transmitter 2 to acquire the transmission data is not particularly limited. For example, the user may operate the transmitter 2 to acquire the transmission data to be transmitted to the receiver 3. The receiver 3 may request the transmission data from the transmitter 2, and the transmitter 2 may acquire the transmission data. An information processing device other than the transmitter 2 may transmit the transmission data to the transmitter 2, and the transmitter 2 may acquire the transmission data. The control unit 201 executes encryption processing when it acquires the transmission data. The control unit 201 advances the encryption processing to step S103.

[0054] The specification determination unit 202 determines one encryption procedure from among a plurality of encryption procedures included in the shared specification 209 (step S103). That is, the specification determination unit 202 determines the procedure number 2091 in the shared specification 209. The method for determining the procedure number 2091 is not particularly limited. For example, the user may input the procedure number 2091. The specification determination unit 202 may determine the procedure number 2091 suitable for the transmission data based on the data capacity of the transmission data or the like. The specification determination unit 202 may determine the procedure number 2091 based on the MAC address of the transmitter 2, or may determine the procedure number 2091 by masking the MAC address with the maximum number of the procedure number 2091. In the example of FIG. 5 of the present disclosure, as described above, the specification determination unit 202 determines the procedure number 2091 as "1". When the specification determination unit 202 determines the procedure number 2091, the control unit 201 proceeds with the encryption process to step S105.

[0055] The information addition unit 203 adds identification information to the transmission data based on the procedure number 2091 (step S105). In the example of FIG. 5 of the present disclosure, as described above, the information addition unit 203 adds the identification information to the end of the file name of the transmission data. The file name of the transmission data is "YYYYMMDD_transmission data.extension", and the information addition unit 203 adds the identification information to the file name of the transmission data, so that the file name of the transmission data becomes "YYYYMMDD_transmission data (identification information).extension". Note that the identification information includes information indicating "1" of the procedure number 2091. When the information addition unit 203 adds the identification information to the header of the transmission data, the information addition unit 203 adds the identification information to the header of the data combined in the combining unit 206. When the identification information is transmitted to the receiver 3 separately from the transmission data, the information addition unit 203 may generate a dummy file or the like, store the identification information, and transmit it to the receiver 3. The control unit 201 proceeds with the encryption process to step S107.

[0056] The splitting unit 204 splits the transmission data into a plurality of data based on the procedure number 2091 determined by the specification determination unit 202 (step S107). Since the procedure number 2091 determined by the specification determination unit 202 is "1", the number of splits 2092A in the sharing specification 209 is "4". The splitting unit 204 splits the transmission data into a plurality of data according to the number of splits 2092A. As shown in FIG. 6, the transmission data is split by the splitting unit 204 into a plurality of data (data #1, data #2, data #3, data #4). Here, in the sharing specification 209 of FIG. 4, since the code 2096 indicating the presence or absence of the interleaving process after splitting is "none", the interleaving process after splitting is not executed. The control unit 201 proceeds with the encryption process to step S109.

[0057] The encryption unit 205 encrypts the plurality of split data based on the procedure number 2091 determined by the specification determination unit 202 (step S109). Since the procedure number 2091 determined by the specification determination unit 202 is "1", the encryption method 2093 in the sharing specification 209 is [method A, method B, method A, method B], the key length is [64, 32, 64, 32], and the encryption key number is [1, 3, 2, 4]. The encryption unit 205 encrypts each of the plurality of split data according to the encryption method 2093.

[0058] As shown in FIG. 6, data #1 is encrypted with encryption method A and encryption key number 1 having a key length of 64 bits. Data #2 is encrypted with encryption method B and encryption key number 3 having a key length of 32 bits. Data #3 is encrypted with encryption method A and encryption key number 2 having a key length of 64 bits. Data #4 is encrypted with encryption method B and encryption key number 4 having a key length of 32 bits. That is, the encryption unit 205 can encrypt the plurality of split data under different conditions. Here, in the sharing specification 209 of FIG. 4, since the code 2098 indicating the presence or absence of the interleaving process after encryption is "yes", the interleaving process after encryption is executed. The control unit 201 proceeds with the encryption process to step S111.

[0059] The interleaver 207 interleaves a plurality of encrypted data based on the procedure number 2091 determined by the norm determination unit 202 (step S111). Since the table number 2099 is "3", the interleaver 207 interleaves the encrypted data using the interleaving table corresponding to the third one among the plurality of interleaving tables. For example, when the third interleaving table is [3, 4, 1, 2], as shown in FIG. 6, the encrypted data #1, data #2, data #3, data #4 are rearranged in the order of data #3, data #4, data #1, data #2 according to the interleaving table. The control unit 201 proceeds with the encryption process to step S113.

[0060] The combining unit 206 combines the rearranged plurality of data (step S113). The combining unit 206 combines data #3, data #4, data #1, data #2 to generate one encrypted data. That is, the encrypted data includes transmission data that is divided into a plurality and encrypted by a plurality of encryption methods. When the combining unit 206 generates the encrypted data, the control unit 201 proceeds with the encryption process to step S115.

[0061] The transmitter 2 transmits the encrypted data to the receiver 3 (step S115). The transmitter 2 transmits the encrypted data with the file name “YYYYMMDD_transmission data (identification information).extension” determined in step S105 to the receiver 3. When there are a plurality of receivers 3 and the transmission data is encrypted by different encryption procedures, the information addition unit 203 adds different file names to the plurality of encrypted data respectively. For example, when the transmitter 2 encrypts the transmission data using an encryption procedure with the procedure number 2091 being “0”, an encryption procedure with the procedure number 2091 being “1”, and an encryption procedure with the procedure number 2091 being “2” for three receivers 3 respectively, the transmitter 2 transmits the encrypted data with the file name “YYYYMMDD_transmission data (0).extension”, the encrypted data with the file name “YYYYMMDD_transmission data (1).extension”, and the encrypted data with the file name “YYYYMMDD_transmission data (2).extension” to the receivers 3 corresponding to their respective encryption procedures.

[0062] The transmitter 2 divides the transmission data into a plurality of data, encrypts them with a plurality of encryption methods, and combines the encrypted plurality of data. The transmitter 2 transmits the combined plurality of data to the receiver 3 as one encrypted data. Even if a malicious third party intercepts the encrypted data, if the number of divisions, the plurality of encryption methods, the plurality of key lengths and encryption keys, and the interleaving table cannot be specified, the encrypted data cannot be decrypted into the transmission data. Even if a third party tries to decrypt the encrypted data by brute-force attack, it cannot be easily decrypted.

[0063] In this embodiment, the transmitter 2 divides the transmission data into a plurality of data and encrypts the divided plurality of data with different encryption methods. Further, the transmitter 2 combines the encrypted plurality of data into one data and transmits it to the receiver 3. By dividing the transmission data into a plurality of data and encrypting the plurality of data with different encryption methods, the encryption system can generate encrypted data with high confidentiality compared to the case where all of the transmission data is encrypted with the same encryption method.

[0064] FIG. 7 is a flowchart showing the decoding process in a receiver according to an embodiment of the present disclosure. Taking the case where the transmitter 2 generates encrypted data and transmits the encrypted data to the receiver 3 according to steps S101 - S115 in FIG. 5 as an example, an example of the decoding process in the receiver 3 will be described.

[0065] The receiver 3 acquires the encrypted data (step S201). The receiver 3 acquires the encrypted data encrypted by steps S101 - S115 from the transmitter 2. When the control unit 301 acquires the encrypted data, the control unit 301 starts to execute the decoding process. The control unit 301 proceeds with the decoding process to step S203.

[0066] The information extraction unit 303 extracts the identification information from the file name "YYYYMMDD_transmission data (identification information).extension" of the encrypted data (step S203). In step S105, the information extraction unit 303 extracts the identification information added by the information addition unit 203. The information extraction unit 303 extracts the identification information indicating "1" of the procedure number 2091. In step S105, when the information addition unit 203 adds the identification information to the header of the encrypted data, the information extraction unit 303 extracts the identification information from the header of the encrypted data. The control unit 301 proceeds with the decoding process to step S205.

[0067] The specification determination unit 302 determines one encryption procedure from among a plurality of encryption procedures included in the shared specification 309 based on the identification information (step S205). That is, the specification determination unit 302 determines the procedure number 2091 in the shared specification 309 based on the identification information. In response to the information extraction unit 303 extracting the identification information indicating "1" of the procedure number 2091, the specification determination unit 302 determines the encryption procedure as "1" of the procedure number 2091. When the specification determination unit 302 determines the procedure number 2091, the control unit 301 proceeds with the decoding process to step S304.

[0068] The splitting unit 304 splits the encrypted data into a plurality of data based on the procedure number 2091 determined by the specification determination unit 302 (step S207). Since the procedure number 2091 determined by the specification determination unit 302 is "1", the splitting number 2092A in the sharing specification 309 is "4". The splitting unit 304 splits the encrypted data into a plurality of data according to the splitting number 2092A. The encrypted data is split by the splitting unit 304 into a plurality of data (data #1, data #2, data #3, data #4). Here, since the code 2098 indicating the presence or absence of the interleaving process after encryption is "yes", the de-interleaving process before decryption is executed. The control unit 301 proceeds with the decryption process to step S209.

[0069] The deinterleaver 307 performs deinterleaving processing on the plurality of divided data based on the procedure number 2091 determined by the specification determination unit 302 (step S209). Since the table number 2099 is "3", the deinterleaver 307 performs deinterleaving processing on the divided data using the deinterleaving table corresponding to the third one among the plurality of deinterleaving tables. For example, when the third deinterleaving table is [3, 4, 1, 2], the divided data #1, data #2, data #3, and data #4 are rearranged in the order of data #3, data #4, data #1, and data #2 according to the deinterleaving table. Here, in the process of step S111 in FIG. 5, the divided and encrypted data #1, data #2, data #3, and data #4 are rearranged in the order of data #3, data #4, data #1, and data #2. In the receiver 3, the order of the plurality of data included in the encrypted data is data #3, data #4, data #1, and data #2. When the plurality of data included in the encrypted data are rearranged according to the deinterleaving table, the plurality of data included in the encrypted data are rearranged in the order of data #3 (the first data in the transmission data), data #4 (the second data in the transmission data), data #1 (the third data in the transmission data), and data #2 (the fourth data in the transmission data). That is, the deinterleaver 307 rearranges the divided data so that the plurality of data included in the encrypted data are in the order of the data before being rearranged in step S111 in the transmitter 2. The control unit 301 proceeds with the decryption process to step S211.

[0070] The decoder 305 decrypts the plurality of divided data based on the procedure number 2091 determined by the specification determination unit 302 (step S211). Since the procedure number 2091 determined by the specification determination unit 302 is "1", the encryption method 2093 in the shared specification 309 is [method A, method B, method A, method B], the key length is [64, 32, 64, 32], and the encryption key number is [1, 3, 2, 4]. The decoder 305 decrypts each of the plurality of divided data according to the encryption method 2093.

[0071] In step S109 of FIG. 5, data #1 is encrypted with encryption method A and encryption key No. 1 having a key length of 64 bits. The decryption unit 305 executes the decryption process of data #1 according to encryption method A and encryption key No. 1 having a key length of 64 bits. In step S109 of FIG. 5, data #2 is encrypted with encryption method B and encryption key No. 3 having a key length of 32 bits. The decryption unit 305 executes the decryption process of data #2 according to encryption method B and encryption key No. 3 having a key length of 32 bits. In step S109 of FIG. 5, data #3 is encrypted with encryption method A and encryption key No. 2 having a key length of 64 bits. The decryption unit 305 executes the decryption process of data #3 according to encryption method A and encryption key No. 2 having a key length of 64 bits. In step S109 of FIG. 5, data #4 is encrypted with encryption method B and encryption key No. 4 having a key length of 32 bits. The decryption unit 305 executes the decryption process of data #4 according to encryption method B and encryption key No. 4 having a key length of 32 bits. Here, since the code 2096 indicating the presence or absence of the interleaving process after division is "none", the deinterleaving process before combination is not executed. The control unit 301 advances the decryption process to step S213.

[0072] The combining unit 306 combines a plurality of data (step S213). The combining unit 206 combines data #3, data #4, data #1, and data #2 to generate one received data. When the combining unit 306 generates the received data, the control unit 201 advances the decryption process to step S215.

[0073] The receiver 3 stores the received data in the storage device (step S215). The received data is the decrypted transmitted data and is the encrypted data decrypted based on the procedure number 2091.

[0074] In this embodiment, the transmitter 2 divides the transmission data into a plurality of data, and encrypts the divided plurality of data with different encryption methods, different encryption keys, and different key lengths. Further, the transmitter 2 combines the encrypted plurality of data into one data and transmits it to the receiver 3. By dividing the transmission data into a plurality of data and encrypting the plurality of data with different encryption methods, different encryption keys, and different key lengths, encrypted data with high confidentiality can be generated as compared with the case where all of the transmission data is encrypted with the same encryption method.

[0075] [Second Embodiment] In the first embodiment, the transmitter 2 includes a shared specification 209 in the database 208, and the plurality of receivers 3 include a shared specification 309 in the database 308. In this embodiment, the server 4 includes the shared specification 209 and the shared specification 309, and the transmitter 2 and the plurality of receivers 3 acquire all or part of the shared specification 209 from the server 4. Since the shared specification 209 and the shared specification 309 have the same configuration, the shared specification 209 is described in this embodiment. Note that, for the components of the encryption system in this embodiment and the components of the encryption system in the first embodiment that are the same components, the same reference numerals are given and the description is omitted.

[0076] FIG. 8 is a diagram showing an example of a method for acquiring an encryption procedure in an encryption system according to an embodiment of the present disclosure. In FIG. 8, the encryption process (steps S101-S115) by the transmitter 2 is the same as the encryption process in FIG. 5, and the decryption process (steps S203-S215) by the receiver 3 is the same as the decryption process in FIG. 7. Therefore, the description of the encryption process and the decryption process is omitted.

[0077] When the transmitter 2 obtains the transmission data in step S101, it obtains the encryption procedure from the server 4 (step S302). For example, the transmitter 2 transmits the information of the transmission data, the MAC address of the transmitter 2, and the MAC address of the receiver 3 to the server 4. The server 4 selects an encryption procedure using the MAC address of the transmitter 2 and the MAC address of the receiver 3. The server 4 may select an encryption procedure based on the MAC address of the transmitter 2 and the MAC address of the receiver 3 from among the appropriate encryption procedures for the transmission data. In this embodiment, it is assumed that the server 4 selects the "0" -th encryption procedure with the procedure number 2091. It is desirable that the network used when the transmitter 2 obtains the encryption procedure from the server 4 is a different network from the network 5 through which the transmitter 2 transmits the encrypted data to the receiver 3.

[0078] The server 4 transmits to the transmitter 2 the division number 2092A for the "0" -th of the procedure number 2091, the encryption method 2093, the key length 2094, the key number 2095, the code 2096 for switching the presence or absence of interleaving processing after division, the table number 2097, the code 2098 for switching the presence or absence of interleaving processing after encryption, the table number 2099 (step S303). Note that the server 4 may transmit the interleaving table corresponding to the table number to the transmitter 2 instead of the table number 2097 and / or the table number 2099.

[0079] When the transmitter 2 obtains the encryption procedure from the server 4, it executes the encryption process in steps S105 - S115 according to the encryption procedure. As described above, the encryption process in steps S105 - S115 is the same as the encryption process in FIG. 5.

[0080] When the receiver 3 acquires the encrypted data from the transmitter 2 in step S115 (corresponding to step S201 in FIG. 7), in step S203, it extracts the identification information from the file name of the encrypted data. Further, the receiver 3 acquires the encryption procedure from the server 4 (step S304). For example, the receiver 3 transmits the extracted identification information to the server 4. It is desirable that the network used when the receiver 3 acquires the encryption procedure from the server 4 is different from the network 5 through which the receiver 3 receives the encrypted data from the transmitter 2.

[0081] The server 4 selects an encryption procedure using the identification information received from the receiver 3. In the present embodiment, since the procedure number 2091 corresponding to the identification information is "0", the server 4 determines the number of divisions 2092A for "0" of the procedure number 2091, the encryption method 2093, the key length 2094, the key number 2095, the code 2096 for switching the presence or absence of interleaving processing after division, the table number 2097, the code 2098 for switching the presence or absence of interleaving processing after encryption, the table number 2099, and transmits them to the receiver 3 (step S305). Note that the server 4 may transmit an interleaving table corresponding to the table number to the receiver 3 instead of the table number 2097 and / or the table number 2099.

[0082] When the receiver 3 acquires the encryption procedure from the server 4, it executes the decryption process in steps S207 - S215 according to the encryption procedure. As described above, the decryption process in steps S207 - S215 is the same as the decryption process in FIG. 7.

[0083] In the configuration of FIG. 8, the transmitter 2 may transmit the information of the transmission data, the MAC address of the transmitter 2, and the MAC address of the receiver 3 to the server 4, and the receiver 3 may transmit the identification information, the MAC address of the transmitter 2, and the MAC address of the receiver 3 to the server 4. The server 4 may select an encryption procedure based on the information of the transmission data received from the transmitter 2, the MAC address of the transmitter 2, and the MAC address of the receiver 3. Further, the server 4 may compare the MAC address of the transmitter 2 and the MAC address of the receiver 3 received from the transmitter 2 with the MAC address of the transmitter 2 and the MAC address of the receiver 3 received from the receiver 3. When the MAC address of the transmitter 2 and the MAC address of the receiver 3 received from the transmitter 2 match the MAC address of the transmitter 2 and the MAC address of the receiver 3 received from the receiver 3, the server 4 may select an encryption procedure based on the identification information received from the receiver 3 and transmit the encryption procedure to the receiver 3. Also, the server 4 may select an encryption procedure based on the MAC address of the transmitter 2 and the MAC address of the receiver 3 from among appropriate encryption procedures for the transmission data.

[0084] Alternatively, authentication regarding data transmission and reception may be performed among the transmitter 2, the receiver 3, and the server 4. For example, a configuration may be adopted in which when the transmitter 2 and the receiver 3 transmit authentication information to the server 4 and the server 4 authenticates the transmitter 2 and the receiver 3, the transmitter 2 and the receiver 3 can obtain an encryption procedure from the server 4.

[0085] In this embodiment, the transmitter 2 divides the transmission data into a plurality of data, and encrypts the divided plurality of data with different encryption methods, different encryption keys, and different key lengths. Further, the transmitter 2 combines the encrypted plurality of data into one data and transmits it to the receiver 3. By dividing the transmission data into a plurality of data and encrypting the plurality of data with different encryption methods, different encryption keys, and different key lengths, encrypted data with high confidentiality can be generated as compared with the case where all of the transmission data is encrypted with the same encryption method. Further, by the transmitter 2 and the receiver 3 obtaining the common specifications 209 and 309 from the server 4, the transmitter 2 and the receiver 3 can maintain the confidentiality of the encryption procedure and the confidentiality of the encrypted data in the encryption system even when exposed to the risk of information leakage.

[0086] [Third Embodiment] In the second embodiment, the server 4 has the common specification 209, and the transmitter 2 and the plurality of receivers 3 obtain all or part of the common specification 209 from the server 4. In this embodiment, the server 4 periodically or irregularly updates the encryption procedure included in the common specification 209. In this embodiment, a configuration in which the server 4 updates the common specification 209 when a part of the encryption procedure included in the common specification 209 is leaked to a third party will be described. Note that components of the encryption system in this embodiment that are the same as those of the encryption systems in the first and second embodiments are denoted by the same reference numerals, and the description thereof is omitted.

[0087] FIG. 9 is a diagram showing an example of a method for updating a sharing specification in an encryption system according to an embodiment of the present disclosure. FIG. 10 is a diagram showing an example of a method for updating a sharing specification in an encryption system according to an embodiment of the present disclosure. In FIG. 9, the encryption processing (steps S101, S302, S303, S105 - S115) by the transmitter 2 is the same as the encryption processing in FIGS. 5 and 8. Similarly, the decryption processing (steps S203, S304, S305, S207 - S215) by the receiver 3 is the same as the decryption processing in FIGS. 7 and 8. Therefore, the description of the encryption processing and the decryption processing will be omitted.

[0088] When the transmitter 2 acquires the transmission data in step S101, it acquires the encryption procedure from the server 4 (step S302). The server 4 transmits to the transmitter 2 the number of divisions 2092A for the "0"th of the procedure number 2091, the encryption method 2093, the key length 2094, the key number 2095, the code 2096 for switching the presence or absence of the interleaving process after division, the table number 2097, the code 2098 for switching the presence or absence of the interleaving process after encryption, and the table number 2099 (step S303).

[0089] When the server 4 detects that some or all of the encryption procedures included in the common specification 209 have been leaked to a third party (step S401), the server 4 notifies the transmitter 2 to change the encryption procedures transmitted in step S303 (step S403). The opportunity for the server 4 to notify the transmitter 2 to change the encryption procedures and update the common specification 209 is not limited to the case where the encryption procedures are leaked to a third party. For example, the server 4 may update the common specification 209 when a vulnerability is discovered in a part of the encryption method included in the common specification 209. Alternatively, the server 4 may update the common specification 209 periodically. For example, the server 4 may update the common specification 209 once every three days or once a week. Note that the server 4 may detect that a vulnerability has been discovered in some or all of the encryption procedures included in the common specification 209 and that some or all of the encryption procedures included in the common specification 209 have been leaked to a third party via a service that distributes security information, news, technical reports, a Social Networking Service (SNS), etc.

[0090] When the transmitter 2 receives a notification from the server 4 to change the encryption procedures, the transmitter 2 interrupts the encryption process of the transmission data (step S404). The transmitter 2 interrupts the encryption process of the transmission data until it receives encryption procedures different from those received from the server 4 in step S303.

[0091] Server 4 updates part or all of the sharing specification 209 (step S405). For example, in the sharing specification 209A of FIG. 10, if any of the encryption procedures of "1" - "4" and "6" in the procedure number 2091 may have been leaked to a third party, as shown in the sharing specification 209B of FIG. 10, Server 4 may update the encryption procedure that may have been leaked to a third party. For example, in "1" of the procedure number 2091, Server 4 updates the encryption method 2093, the key length 2094, and the key number 2095. In "2" of the procedure number 2091, Server 4 updates the key length 2094 and the table number 2097. In "3" of the procedure number 2091, Server 4 updates the table number 2097. In "4" of the procedure number 2091, Server 4 updates the encryption method 2093. In "6" of the procedure number 2091, Server 4 updates the encryption method 2093. When updating the sharing specification 209, Server 4 may not only change the configuration of the encryption procedure but also delete the encryption procedure.

[0092] Server 4 updates the sharing specification 209 and transmits the encryption procedure included in the updated sharing specification 209 to the transmitter 2 (step S407). When the transmitter 2 receives the encryption procedure from Server 4, the transmitter 2 resumes the encryption process of the transmission data (steps S105 - S115). As described above, the encryption process in steps S105 - S115 is the same as the encryption process in FIG. 5.

[0093] When the receiver 3 obtains the encrypted data from the transmitter 2 in step S115, in step S203, the receiver 3 extracts the identification information from the file name of the encrypted data. Further, in step S304, the receiver 3 obtains the encryption procedure from Server 4. In step S305, Server 4 selects the encryption procedure using the identification information received from the receiver 3, and transmits the number of divisions 2092A, the encryption method 2093, the key length 2094, the key number 2095, the code 2096 for switching the presence or absence of the interleaving process after division, the table number 2097, the code 2098 for switching the presence or absence of the interleaving process after encryption, and the table number 2099 included in the encryption procedure to the receiver 3.

[0094] In step S305 of this embodiment, the encryption procedure that the server 4 sends to the receiver 3 is the encryption procedure included in the shared specification 209 updated in step S405. Using an encryption procedure different from the encryption procedure detected to have been leaked to a third party in step S401, the transmitter 2 and the receiver 3 can respectively execute an encryption process and a decryption process.

[0095] When the receiver 3 obtains the encryption procedure from the server 4, it executes the decryption process in steps S207 - S215 according to the encryption procedure. As described above, the decryption process in steps S207 - S215 is the same as the decryption process in FIG. 7.

[0096] In this embodiment, the transmitter 2 divides the transmission data into a plurality of data based on the encryption procedure obtained from the server 4, and encrypts the divided plurality of data with different encryption methods, different encryption keys, and different key lengths. Further, the transmitter 2 combines the encrypted plurality of data into one data and transmits it to the receiver 3. By dividing the transmission data into a plurality of data and encrypting the plurality of data with different encryption methods, different encryption keys, and different key lengths, encrypted data with high confidentiality can be generated as compared with the case where all of the transmission data is encrypted with the same encryption method. Further, when the server 4 updates the shared specification 209 regularly or irregularly, even when a vulnerability is found in the encryption procedure included in the shared specification 209 or the encryption procedure is leaked to a third party, the encryption system can generate encrypted data with high confidentiality.

[0097] When encrypting transmission data using an encryption key of a certain key length without applying the configuration of the present invention, and when applying the configuration of the present invention and encrypting transmission data using a plurality of encryption keys and a plurality of encryption methods, the encryption method in the case of applying the configuration of the present invention can generate encrypted data with higher confidentiality. Furthermore, in the configuration of the present application, it is possible to enhance confidentiality by using different encryption keys and a plurality of encryption methods, so it is also possible to shorten the key lengths of the plurality of encryption keys and reduce the time required for the encryption process and the decryption process.

[0098] [Other Embodiments] FIG. 11 is a block diagram showing the configuration of an encryption system according to another embodiment disclosed in the present application. The encryption system 100 includes a splitting unit 101, an encryption unit 102, a combining unit 103, and a first specification 104. The splitting unit 101 splits data based on the first specification 104. The encryption unit 102 encrypts the data split into a plurality based on the first specification 104. The combining unit 103 combines the plurality of encrypted data based on the first specification 104.

[0099] Also, a program that operates the configuration of the above-described embodiments to realize the functions of the above-described embodiments is recorded on a recording medium, the program recorded on the recording medium is read as code, and a processing method executed by a computer is also included in the scope of each embodiment. That is, a computer-readable recording medium is also included in the scope of each embodiment. In addition, not only the recording medium on which the above-described computer program is recorded, but also the computer program itself is included in each embodiment.

[0100] As the recording medium, for example, a floppy (registered trademark) disk, a hard disk, an optical disk, a magneto-optical disk, a CD-ROM (Compact Disc-Read Only Memory), a magnetic tape, a non-volatile memory card, or a ROM can be used. Further, not limited to those that execute processing with only the program recorded on the recording medium, those that operate on an OS (Operating System) and execute processing in cooperation with other software and the functions of expansion boards are also included in the scope of each embodiment.

[0101] As described above, the present disclosure has been described with reference to the embodiments, but the present disclosure is not limited to the above-described embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and detailed description of the present disclosure. Further, each embodiment can be combined with other embodiments as appropriate.

[0102] Some or all of the above embodiments can be described as follows in the appended claims, but are not limited thereto.

[0103] (Appended Claim 1) A splitting unit that splits data into a plurality of split data based on a first specification, An encryption unit that encrypts each of the plurality of split data based on the first specification to generate a plurality of encrypted data, A combining unit that combines the plurality of encrypted data into one combined data, and An encryption device that updates the first specification to a second specification.

[0104] (Appended Claim 2) The first specification and the second specification include a plurality of encryption procedures, The first specification is updated to the second specification according to a predetermined condition, The predetermined condition is at least one encryption procedure in the first specification has been leaked to a third party, and a vulnerability has been discovered in at least one encryption procedure in the first specification, and The encryption device according to Appendix 1, comprising that a certain period of time has elapsed since the update date and time of at least one encryption procedure among the first specifications.

[0105] (Appendix 3) The encryption device according to Appendix 1 or 2, wherein at least two of the plurality of divided data are encrypted using different encryption keys.

[0106] (Appendix 4) The encryption device according to Appendix 1 to 3, wherein at least two of the plurality of divided data are encrypted using different encryption methods.

[0107] (Appendix 5) The encryption device according to Appendix 1 to 4, further comprising an interleaver for rearranging the order of at least one of the plurality of divided data and the plurality of encrypted data based on the first specification or the second specification.

[0108] (Appendix 6) The encryption device according to Appendix 1 to 5, further comprising an information addition unit for adding information indicating the first specification or the second specification to the combined data based on the first specification or the second specification.

[0109] (Appendix 7) The first specification includes the number of data divisions, the divided data length, the encryption method, the public key, the private key, and the interleaving table. The encryption device according to Appendix 1 to 6.

[0110] (Appendix 8) A splitting step of splitting data into a plurality of divided data based on the first specification; An encryption step of encrypting each of the plurality of divided data based on the first specification to generate a plurality of encrypted data; A combining step of combining the plurality of encrypted data into one combined data. The encryption method further comprises updating the first specification to a second specification. An encryption method for updating the first specification to a second specification.

[0111] (Appendix 9) The first specification and the second specification include a plurality of encryption procedures, The first specification is updated to the second specification according to a predetermined condition, The predetermined condition is at least one encryption procedure in the first specification has been leaked to a third party, and a vulnerability has been discovered in at least one encryption procedure in the first specification, and a certain period of time has elapsed since the update date and time of at least one encryption procedure in the first specification, including the encryption method described in Appendix 8.

[0112] (Appendix 10) At least two of the plurality of divided data are encrypted using different encryption keys, the encryption method described in Appendix 8 or 9.

[0113] (Appendix 11) At least two of the plurality of divided data are encrypted using different encryption methods, the encryption method described in Appendix 8 to 10.

[0114] (Appendix 12) Based on the first specification or the second specification, the encryption method described in Appendix 8 to 11 further includes an interleaving step of rearranging the order of at least one of the plurality of divided data and the plurality of encrypted data.

[0115] (Appendix 13) Based on the first specification or the second specification, the encryption method described in Appendix 8 to 12 further includes an information addition step of adding information indicating the first specification or the second specification to the combined data.

[0116] (Appendix 14) The first specification is the encryption method described in Appendices 8 to 13, including the number of data divisions, the divided data length, the encryption method, the public key, the private key, and the interleaving table.

[0117] (Appendix 15) A dividing step of dividing data into a plurality of divided data based on the first specification, An encryption step of encrypting each of the plurality of divided data based on the first specification to generate a plurality of encrypted data, A combining step of combining the plurality of encrypted data into one combined data, and An encryption program for updating the first specification to a second specification.

[0118] (Appendix 16) The first specification and the second specification include a plurality of encryption procedures, The first specification is updated to the second specification according to a predetermined condition, The predetermined condition is At least one encryption procedure in the first specification has been leaked to a third party, Vulnerabilities have been discovered in at least one encryption procedure in the first specification, A certain period of time has elapsed since the update date and time of at least one encryption procedure in the first specification, and includes the encryption program described in Appendix 15.

[0119] (Appendix 17) At least two of the plurality of divided data are encrypted using different encryption keys, and the encryption program described in Appendix 15 or 16.

[0120] (Appendix 18) At least two of the plurality of divided data are encrypted using different encryption methods, and the encryption program described in Appendices 15 to 17.

[0121] (Appendix 19) The encryption program according to Appendices 15 to 18, further comprising an interleaving step of rearranging the order of at least one of the plurality of divided data and the plurality of encrypted data based on the first specification or the second specification.

[0122] (Appendix 20) The encryption program according to Appendices 15 to 19, further comprising an information addition step of adding information indicating the first specification or the second specification to the combined data based on the first specification or the second specification.

[0123] (Appendix 21) The first specification includes the number of data divisions, the divided data length, the encryption method, the public key, the private key, and the interleaving table. The encryption program according to Appendices 15 to 20.

[0124] (Appendix 22) An encryption system and At least one decryption system, and Based on the first specification, data is transmitted and received between the encryption system and the at least one decryption system. An encryption system that updates the first specification to a second specification.

[0125] (Appendix 23) The first specification and the second specification include a plurality of encryption procedures. The first specification is updated to the second specification according to a predetermined condition. The predetermined condition is At least one encryption procedure in the first specification has been leaked to a third party, Vulnerability has been discovered in at least one encryption procedure in the first specification, A certain amount of time has elapsed since the update date and time of at least one encryption procedure in the first specification. The encryption system according to Appendix 22.

[0126] (Appendix 24) Among the plurality of divided data, at least two pieces of divided data are encrypted using different encryption keys, the encryption system according to Appendix 22 or 23.

[0127] (Appendix 25) Among the plurality of divided data, at least two pieces of divided data are encrypted using different encryption methods, the encryption system according to Appendix 22 to 24.

[0128] (Appendix 26) Based on the first specification or the second specification, further comprising an interleaver for rearranging the order of at least one of the plurality of divided data and the plurality of encrypted data, the encryption system according to Appendix 22 to 25.

[0129] (Appendix 27) Based on the first specification or the second specification, further comprising an information addition unit for adding information indicating the first specification or the second specification to the combined data, the encryption system according to Appendix 22 to 26.

[0130] (Appendix 28) The first specification includes the number of data divisions, the divided data length, the encryption method, the public key, the secret key, and the interleaving table, the encryption system according to Appendix 22 to 27.

Explanation of Signs

[0131] 1: Encryption system 100: Encryption system 101: Division unit 102: Encryption unit 103: Combination unit 2: Transmitter 201: Control unit 202: Specification determination unit 203: Information addition unit 204: Division unit 205: Encryption unit 206: Combination unit 207: Interleaver 208: Database 209: Common Specification 3: Receiver 301: Control Unit 302: Specification Determination Unit 303: Information Extraction Unit 304: Division Unit 305: Decryption Unit 306: Combination Unit 307: Deinterleaver 308: Database 309: Common Specification 4: Server 5: Network

Claims

1. A splitting unit that splits data into a plurality of split data based on a first specification; An encryption unit that encrypts each of the plurality of split data based on the first specification to generate a plurality of encrypted data; A combining unit that combines the plurality of encrypted data into one combined data, and an encryption device that updates the first specification to a second specification. The encryption device according to claim 1, wherein the first specification and the second specification include a plurality of encryption procedures, and the first specification is updated to the second specification according to a predetermined condition.

2. The first specification and the second specification include a plurality of encryption procedures, and the first specification is updated to the second specification according to a predetermined condition. The predetermined condition includes that at least one encryption procedure in the first specification has been leaked to a third party, that a vulnerability has been discovered in at least one encryption procedure in the first specification, and that a certain period of time has elapsed since the update date and time of at least one encryption procedure in the first specification.

3. The encryption device according to claim 1, wherein at least two of the plurality of split data are encrypted using different encryption keys.

4. The encryption device according to claim 1, wherein at least two of the plurality of split data are encrypted using different encryption methods.

5. The encryption device according to claim 1, further comprising an interleaver that rearranges the order of at least one of the plurality of data of the plurality of split data and the plurality of encrypted data based on the first specification or the second specification.

6. The encryption device according to claim 1, further comprising an information addition unit that adds information indicating the first specification or the second specification to the combined data based on the first specification or the second specification.

7. The encryption device according to claim 1, wherein the first specification includes the number of data splits, the split data length, the encryption method, the public key, the private key, and the interleaving table.

8. An encryption method that includes a splitting step of splitting data into a plurality of split data based on a first specification, an encryption step of encrypting each of the plurality of split data based on the first specification to generate a plurality of encrypted data, and a combining step of combining the plurality of encrypted data into one combined data, and updating the first specification to a second specification.

9. A splitting step of splitting data into a plurality of split data based on a first specification.

10. An encryption step of encrypting each of the plurality of split data based on the first specification to generate a plurality of encrypted data.

11. A combining step of combining the plurality of encrypted data into one combined data.

12. The encryption method according to claim 8, further comprising an interleaving step of interleaving at least one of the plurality of data of the plurality of split data and the plurality of encrypted data based on the first specification or the second specification.

13. The encryption method according to claim 8, further comprising an information addition step of adding information indicating the first specification or the second specification to the combined data based on the first specification or the second specification. An encryption step of encrypting each of the plurality of divided data based on the first specification to generate a plurality of encrypted data; A combining step of combining the plurality of encrypted data into one combined data; and An encryption program that updates the first specification to a second specification.

10. An encryption device; and At least one decryption device, comprising: Based on the first specification, data is transmitted and received between the encryption device and the at least one decryption device; An encryption system that updates the first specification to a second specification.

Citation Information

Patent Citations

  • Enciphering processing system

    JP2000059355A