Key management system for authentication and key management method for authentication
The authentication key management system enables secure, cost-effective transfer of authentication keys between terminals using operator and security codes, eliminating the need for biometric devices and reducing administrative overhead.
Patent Information
- Application Number
- JP2024041842
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-18
- Publication Date
- 2025-10-01
AI Technical Summary
Conventional methods for copying authentication keys between terminals require dedicated equipment like biometric authentication devices, increasing costs.
An authentication key management system that uses a first and second terminal with secure storage and key management units, employing operator codes and security codes to securely transfer authentication keys between terminals without re-registration in the server.
Authentication keys can be copied between terminals with a simple configuration and low cost, reducing administrative burden and eliminating the need for dedicated security equipment.
Smart Images

Figure 2025142475000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a system and method for sharing an authentication key between terminals to be used when accessing a server. [Background technology]
[0002] In a system in which an authentication key is used to access a server, the authentication key is registered in advance in the server and the client terminal. When a client terminal is replaced in such a system, the authentication key is re-registered in the server and the new client terminal. However, re-registering the authentication key is a heavy burden for the system administrator. Therefore, a method of copying the authentication key between terminals has been proposed (for example, see Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6479723 Summary of the Invention [Problem to be solved by the invention]
[0004] As described above, methods for copying authentication keys between terminals have been proposed. However, conventional techniques can increase the cost of copying authentication keys between terminals. For example, in the system described in Patent Document 1, copying of an authentication key is permitted after user authentication such as biometric authentication is performed on both the copy source terminal and the copy destination terminal. In other words, conventional techniques require dedicated equipment such as a biometric authentication device to ensure security, which increases costs.
[0005] An object of one aspect of the present invention is to provide a method for copying an authentication key for accessing a server between terminals with a simple configuration or at low cost. [Means for solving the problem]
[0006] An authentication key management system according to one aspect of the present invention manages authentication keys used by a first terminal and a second terminal when accessing a server. The first terminal includes a first storage unit and a first key management unit. The second terminal includes a second storage unit and a second key management unit. The authentication key and a first security code are stored in the first storage unit in advance. The second storage unit is stored in advance with a second security code. When transmitting the authentication key stored in the first storage unit to the second terminal, a first operator code is written in the first storage unit, and a second operator code that is the same as the first operator code is written in the second storage unit. The second key management unit generates an encrypted operator code by encrypting the second operator code with the second security code, and transmits the encrypted operator code to the first terminal. The first key management unit compares the decrypted operator code reproduced by decrypting the encrypted operator code with the first security code with the first operator code, and when the decrypted operator code matches the first operator code, transmits the authentication key to the second terminal. [Effects of the Invention]
[0007] According to the above-described aspect, an authentication key for accessing a server can be copied between terminals with a simple configuration or at low cost. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram illustrating an example of a client-server system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of a configuration of a terminal according to an embodiment of the present invention. [Figure 3] FIG. 10 is a diagram illustrating an example of a case in which an existing terminal is replaced with a new terminal in a client-server system. [Figure 4]FIG. 10 is a sequence diagram showing an example of a procedure for copying an authentication key between terminals. [Figure 5] FIG. 10 is a sequence diagram showing another example of a procedure for copying an authentication key between terminals. DETAILED DESCRIPTION OF THE INVENTION
[0009] 1 shows an example of a client-server system according to an embodiment of the present invention. In this example, a server 1 provides services to a terminal 11 and a terminal 12. The terminals 11 and 12 are each clients of the server 1. That is, each of the terminals 11 and 12 can receive the services provided by the server 1.
[0010] Each terminal (11, 12) holds an authentication key for accessing the server 1. In this embodiment, the terminal 11 holds the authentication key K011, and the terminal 12 holds the authentication key K012. The server 1 holds authentication keys used when accepting access from each terminal (11, 12). In this embodiment, the server 1 holds the authentication key K001 used when accepting access from the terminal 11, and the authentication key K002 used when accepting access from the terminal 12. Note that the authentication key K001 and the authentication key K011 are associated with each other, and the authentication key K002 and the authentication key K012 are also associated with each other.
[0011] When terminal 11 accesses server 1, terminal 11 transmits a message generated based on authentication key K011, for example, to server 1, and server 1 authenticates the received message using authentication key K001. If this authentication is successful, server 1 permits access by terminal 11. The same procedure is followed when terminal 12 accesses server 1.
[0012] In the client-server system configured as described above, it is assumed that the terminal 12 is replaced with a new terminal 12B. In this case, a new authentication key pair may be generated and registered in the server 1 and the terminal 12B, but this procedure places a heavy burden on the administrator of the client-server system. Therefore, in the authentication key management method according to an embodiment of the present invention, the authentication key K012 is copied from the existing terminal 12 to the new terminal 12B. Thereafter, the terminal 12B accesses the server 1 using the authentication key K012 received from the terminal 12. In the following description, the terminal that transmits the authentication key (terminal 12 in FIG. 1) may be referred to as the "copy source terminal." Furthermore, the terminal that receives the authentication key (terminal 12B in FIG. 1) may be referred to as the "copy destination terminal."
[0013] 2 shows an example of the configuration of a terminal according to an embodiment of the present invention. Terminal 20 according to the embodiment of the present invention has a normal area and a secure area. Terminal 20 shown in FIG. 2 corresponds to terminal 11, 12, or 12B shown in FIG. 1.
[0014] The normal area is equipped with normal storage and processor resources. The normal storage stores an operating system and various application programs. The processor resources then execute the various application programs on the operating system, thereby controlling the operation of the terminal 20.
[0015] The secure area includes a secure storage 21. An authentication key and a security code are stored in the secure storage 21. Here, the security code is written to the secure storage 21 by, for example, the manufacturer of the terminal 20 before the terminal 20 is shipped. The authentication key is written to the secure storage 21 by, for example, an administrator of the client-server system.
[0016] The security code is, for example, a bit pattern of a predetermined length. The security code is generated for each terminal. The manufacturer of the terminal 20 manages the security codes assigned to the terminals that it manufactures. That is, the manufacturer of the terminal 20 manages the values of the security codes assigned to each terminal. Note that the security code written in the secure storage 21 of each terminal 20 is basically known only to the manufacturer of the terminal 20. That is, even the user of the terminal 20 or the administrator of the client-server system cannot read the security code stored in the secure storage 21.
[0017] The authentication key is an encryption key used by the terminal 20 when accessing the server 1. In addition, an authentication key is generated for each terminal. Here, the authentication key registered in the server 1 and the authentication key stored in the secure storage 21 of the terminal 20 constitute an authentication key pair. In the example shown in FIG. 1, the authentication key K001 registered in the server 1 and the authentication key K011 held by the terminal 11 constitute an authentication key pair, and the authentication key K002 registered in the server 1 and the authentication key K012 held by the terminal 12 constitute an authentication key pair.
[0018] The secure area is equipped with a key management unit 22. The key management unit 22 is realized by using processor resources to execute an application program for copying authentication keys between terminals. The key management unit 22 can also access information stored in the secure storage 21. For example, the key management unit 22 can access security codes stored in the secure storage 21 in the procedure for copying authentication keys between terminals.
[0019] When the terminal 20 accesses the server 1, it uses the authentication key stored in the secure storage 21. At this time, the application program accessing the server 1 may obtain the authentication key via the key management unit 22.
[0020] 3 shows an example of a case where an existing terminal is replaced with a new terminal in a client-server system. In this case, the existing terminal 20A is replaced with a new terminal 20B. The configurations and functions of terminal 20A and terminal 20B are substantially the same as those of terminal 20 shown in FIG. 2. Therefore, terminal 20A and / or terminal 20B may be collectively referred to as "terminal 20."
[0021] A security code P1 and an authentication key K020 are written in the secure storage 21A of the terminal 20A. The security code P1 is written by the manufacturer of the terminal 20. The authentication key K020 is written, for example, by an administrator of the client-server system. In the following description, the administrator of the client-server system may be referred to as an "operator."
[0022] A security code P2 is written in the secure storage 21B of the terminal 20B. The security code P2 is also written by the manufacturer of the terminal 20. Here, it is assumed that the manufacturer of the terminal 20 is aware that the terminal 20A will be replaced with the terminal 20B. That is, the manufacturer of the terminal 20 is aware that the terminal 20B is a replacement for the terminal 20A. In this case, the manufacturer of the terminal 20 writes the same security code as the security code held by the terminal 20A into the secure storage 21B of the terminal 20B. That is, the value of the security code P2 stored in the secure storage 21B of the terminal 20B is the same as the security code P1 stored in the secure storage 21B of the terminal 20A. At this point, an authentication key has not yet been stored in the secure storage 21B of the terminal 20B.
[0023] When exchanging the terminal 20A for the terminal 20B, the operator stores the operator code in the secure storage 21A of the terminal 20A and the secure storage 21B of the terminal 20B. At this time, the same operator code value is stored in the secure storage 21A and the secure storage 21B. In the embodiment shown in Fig. 3, the operator code Q1 is stored in the secure storage 21A and the secure storage 21B.
[0024] Fig. 4 is a sequence diagram showing an example of a procedure for copying an authentication key between terminals. In this example, the authentication key K020 is copied from terminal 20A shown in Fig. 3 to terminal 20B. That is, the authentication key K020 and a security code P1 are stored in the secure storage 21A of terminal 20A, and the security code P2 is stored in the secure storage 21B of terminal 20B. The security code P1 and the security code P2 are the same.
[0025] In S1, the operator saves the operator code Q1 in the secure storage 21A of the terminal 20A and the secure storage 21B of the terminal 20B. That is, the same operator code Q1 is given to the terminal 20A and the terminal 20B. The operator may give the operator code Q1 to the terminal 20A and the terminal 20B simultaneously, or may give the operator code Q1 to the terminal 20A and the terminal 20B at different times.
[0026] In S2, the terminal 20B encrypts the operator code Q1 with the security code P2. As a result, an encrypted operator code (encrypted operator code) is generated. The process of S2 is executed by the key management unit 22B.
[0027] In S3, the terminal 20B transmits the operator code encrypted with the security code P2 to the terminal 20A. It is assumed that the terminals 20A and 20B are capable of communicating with each other via, for example, a local area network.
[0028] In S4, the terminal 20A decrypts the data received from the terminal 20B using the security code P1. That is, the operator code encrypted in the terminal 20B using the security code P2 is decrypted using the security code P1. Here, the security code P1 held by the terminal 20A and the security code P2 held by the terminal 20B are the same. Therefore, the operator code Q1 is reproduced by this decryption process.
[0029] In S5, the terminal 20A compares the operator code stored in its own secure storage 21A with the operator code reproduced by the decryption process. In this embodiment, the operator code Q1 is stored in the secure storage 21A, and the operator code Q1 is reproduced by the decryption process. That is, the operator code stored in the secure storage 21A and the operator code reproduced by the decryption process match each other. In this case, the terminal 20A determines that the same security code is written in the terminal 20A and the terminal 20B. Therefore, the terminal 20A determines that the terminal 20B is a valid destination to copy the authentication key.
[0030] Then, in S6, terminal 20A encrypts authentication key K020 stored in its own secure storage 21A with operator code Q1 and security code P1. As a result, an encrypted authentication key (encrypted authentication key) is generated. Note that the processes of S4 to S6 are executed by key management unit 22A. Then, in S7, terminal 20A transmits the encrypted authentication key to terminal 20B.
[0031] In S8, the terminal 20B decrypts the data received from the terminal 20A using the operator code Q1 and the security code P2. That is, the authentication key encrypted in the terminal 20A using the operator code Q1 and the security code P1 is decrypted using the operator code Q1 and the security code P2. Here, as described above, the security code P1 and the security code P2 are the same. Therefore, the authentication key K020 is reproduced by this decryption process. Then, in S9, the terminal 20B stores the authentication key K020 in the secure storage 21B of the terminal 20B. Note that the processes of S8 to S9 are executed by the key management unit 22B. Thereafter, in S10, the terminal 20B transmits a receipt notification indicating that the authentication key has been received to the terminal 20A.
[0032] In S11, the terminal 20B discards the operator code Q1 provided by the operator in response to storing the authentication key K020 in the secure storage 21B. Also, in S12, the terminal 20A discards the operator code Q1 provided by the operator in response to receiving the acknowledgment. Furthermore, it is preferable that the terminal 20A discards the authentication key K020 stored in the secure storage 21A in response to receiving the acknowledgment.
[0033] Note that if terminal 20B is not an authorized replacement device, terminal 20B does not hold a security code. In this case, terminal 20B cannot transmit an encrypted operator code to terminal 20A. Alternatively, terminal 20B holds a security code that is different from the security code held by terminal 20A. In this case, when terminal 20B transmits an operator code encrypted with a security code to terminal 20A, the operator codes do not match in S5 shown in FIG. 4. In either case, terminal 20A can recognize that terminal 20B is not an authorized replacement device.
[0034] As described above, according to the authentication key management method of the embodiment of the present invention, when copying an authentication key for accessing a server between terminals, the same operator code is provided to the source terminal and the destination terminal, and the operator code is encrypted and exchanged with a security code known only to the terminal manufacturer, thereby confirming that the destination terminal is a legitimate destination terminal. Therefore, the authentication key can be securely copied from an existing terminal to a new terminal without re-registering the authentication key in the server and the new terminal. In other words, the authentication key can be securely set in a new terminal while reducing the burden on the administrator of the client-server system. In addition, the procedure according to the embodiment of the present invention does not require dedicated equipment such as a biometric authentication device when copying an authentication key between terminals.
[0035] Fig. 5 is a sequence diagram showing another example of the procedure for copying an authentication key between terminals. In this example, the authentication key K020 is also copied from terminal 20A shown in Fig. 3 to terminal 20B. That is, the authentication key K020 and a security code P1 are stored in the secure storage 21A of terminal 20A, and the security code P2 is stored in the secure storage 21B of terminal 20B. The security code P1 and the security code P2 are the same.
[0036] In the procedure shown in Fig. 4, the authentication key is encrypted with an operator code and a security code before being sent to the destination terminal. In contrast, in the procedure shown in Fig. 5, the authentication key is encrypted with a key encryption key generated in the source terminal before being sent to the destination terminal.
[0037] The processes of S1 to S5 are substantially the same in the procedure shown in Fig. 4 and the procedure shown in Fig. 5. Therefore, the copy source terminal (i.e., terminal 20A) confirms that the copy destination terminal (i.e., terminal 20B) is a legitimate copy destination terminal.
[0038] In S21, the terminal 20A generates a key encryption key. The key encryption key is not particularly limited, but may be, for example, a bit pattern of a predetermined length generated using a random number generator or the like. In S22, the terminal 20A encrypts the key encryption key generated in S21 with the security code P1. This generates an encrypted key encryption key. The processes of S21 to S22 are executed by the key management unit 22A. Then, in S23, the terminal 20A transmits the encrypted key encryption key to the terminal 20B.
[0039] In S24, terminal 20B decrypts the data received from terminal 20A using security code P2. That is, the key encryption key encrypted in terminal 20A using security code P1 is decrypted using security code P2. Here, as described above, security code P1 and security code P2 are the same. Therefore, the key encryption key is reproduced by this decryption process. That is, terminal 20B obtains the key encryption key generated by terminal 20A. Note that the process of S24 is executed by key management unit 22B. Thereafter, in S25, terminal 20B transmits a receipt notification to terminal 20A indicating that the key encryption key has been received.
[0040] Upon receiving the receipt notification in S25, the terminal 20A encrypts the authentication key K020 with the key encryption key in S26. As a result, an encrypted authentication key (encrypted authentication key) is generated. The process of S26 is executed by the key management unit 22A. Then, in S27, the terminal 20A transmits the encrypted authentication key to the terminal 20B.
[0041] In S28, terminal 20B decrypts the data received from terminal 20A using the key encryption key acquired in S24. That is, the authentication key encrypted in terminal 20A using the key encryption key is decrypted using the same key encryption key. Therefore, the authentication key K020 is reproduced by this decryption process. That is, terminal 20B acquires the authentication key stored in secure storage 21A of terminal 20A. Then, in S29, terminal 20B stores the authentication key K020 in its own secure storage 21B. Note that the processes of S28 to S29 are executed by key management unit 22B. Thereafter, in S30, terminal 20B transmits a receipt notification indicating that the authentication key has been received to terminal 20A.
[0042] In S31, the terminal 20B discards the operator code Q1 and the key encryption key provided by the operator in response to storing the authentication key K020 in the secure storage 21B. In addition, in S32, the terminal 20A discards the operator code Q1 and the key encryption key provided by the operator in response to receiving the acknowledgment.
[0043] In this way, in the procedure shown in Fig. 5, the authentication key is encrypted with a key encryption key generated in the copy source terminal and then transmitted to the copy destination terminal, which is expected to improve security compared to the procedure shown in Fig. 4.
[0044] 4 and 5, the authenticity of the copy destination terminal is confirmed using an operator code encrypted with a security code, but the embodiment of the present invention is not limited to this method. For example, the authenticity of the copy destination terminal may be confirmed using a security code encrypted with an operator code.
[0045] Furthermore, the encryption method of the client-server system is not particularly limited. For example, the authentication key copied between terminals may be a common key in a common key encryption system. Alternatively, the authentication key copied between terminals may be a private key used in a public key encryption system. [Explanation of symbols]
[0046] 1 server 11, 12, 12B terminals 20, 20A, 20B terminals 21, 21A, 21B Secure Storage 22, 22A, 22B Key management section
Claims
1. An authentication key management system that manages authentication keys used when a first terminal and a second terminal access a server, comprising: The first terminal a first storage unit; a first key management unit; The second terminal a second storage unit; and a second key management unit; the authentication key and the first security code are stored in advance in the first storage unit; a second security code is stored in advance in the second storage unit; when transmitting the authentication key stored in the first storage unit to the second terminal, a first operator code is written in the first storage unit, and a second operator code that is the same as the first operator code is written in the second storage unit; The second key management unit generating an encrypted operator code by encrypting the second operator code with the second security code; transmitting the encrypted operator code to the first terminal; The first key management unit comparing a decrypted operator code reproduced by decrypting the encrypted operator code with the first security code with the first operator code; When the decrypted operator code matches the first operator code, the authentication key is transmitted to the second terminal. An authentication key management system characterized by:
2. The process of transmitting the authentication key to the second terminal by the first key management unit includes: generating an encrypted authentication key by encrypting the authentication key with the first operator code and the first security code; transmitting the encrypted authentication key to the second terminal; The second key management unit obtains the authentication key by decrypting the encrypted authentication key with the second operator code and the second security code.
2. The authentication key management system according to claim 1, wherein:
3. After acquiring the authentication key, the second key management unit: Discarding the second operator code stored in the second storage unit; sending a receipt notification to the first terminal indicating that the authentication key has been acquired; Upon receiving the receipt notification, the first key management unit discards the first operator code stored in the first storage unit.
3. The authentication key management system according to claim 2.
4. The first key management unit Generate a key encryption key; encrypting the key encrypting key with the first security code; transmitting the encrypted key encryption key to the second terminal; the second key management unit obtains the key encryption key by decrypting the encrypted key encryption key with the second security code; The process of transmitting the authentication key to the second terminal by the first key management unit includes: encrypting the authentication key with the key encryption key to generate an encrypted authentication key; transmitting the encrypted authentication key to the second terminal; The second key management unit obtains the authentication key by decrypting the encrypted authentication key with the key encryption key.
2. The authentication key management system according to claim 1, wherein:
5. After acquiring the authentication key, the second key management unit: discarding the second operator code and the key encryption key; sending a receipt notification to the first terminal indicating that the authentication key has been acquired; Upon receiving the acknowledgment, the first key management unit discards the first operator code and the key encryption key.
5. The authentication key management system according to claim 4.
6. An authentication key management method for managing an authentication key used when a first terminal and a second terminal access a server, comprising: a first storage unit provided in the first terminal stores the authentication key and a first security code in advance; a second storage unit provided in the second terminal stores a second security code in advance; when transmitting the authentication key stored in the first storage unit to the second terminal, a first operator code is written in the first storage unit, and a second operator code that is the same as the first operator code is written in the second storage unit; The second terminal generating an encrypted operator code by encrypting the second operator code with the second security code; transmitting the encrypted operator code to the first terminal; The first terminal comparing a decrypted operator code reproduced by decrypting the encrypted operator code with the first security code with the first operator code; When the decrypted operator code matches the first operator code, the authentication key is transmitted to the second terminal.
1. An authentication key management method comprising:
Citation Information
Patent Citations
Optical modulating device
JP1989079723A