Portable device, management server, management system, decryption method, key management method, and program
By encrypting and distributing the common key across internal and external storage units, the system addresses security vulnerabilities in key management, ensuring secure decryption of confidential information.
Patent Information
- Application Number
- JP2024084962
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-24
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2044-05-24
AI Technical Summary
Existing systems face security vulnerabilities due to the transmission and storage of common keys, which can lead to unauthorized access and leakage, compromising the encryption of confidential information.
Implementing a system where the common key is encrypted with an embedded key and stored in both internal and removable external storage units, with decryption occurring using an encrypted encryption key, ensuring the key is not directly stored and distributed across multiple devices.
Enhances security by preventing unauthorized access and theft of the common key, maintaining confidentiality of encrypted information even if storage media are compromised.
Smart Images

Figure 2025177838000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a portable device, a management server, a management system, a decryption method, a key management method, and a program. [Background technology]
[0002] There is a system in which information stored on a contactless IC card is read by two devices located at different locations, thereby restricting user behavior. For example, in Patent Document 1, an access control device creates a common key and transmits it to a copier. When a user enters or leaves a facility, the access control device reads information from the contactless IC card. If the information contains entry authority information, the access control device encrypts the information with the common key to create encrypted information and overwrites it on the contactless IC card. A user with entry authority enters the room and has the copier's IC card reader / writer read the contactless IC card. The copier attempts to decrypt the read information using the common key previously obtained from the access control device. The copier then controls its usage based on the decryption results, thereby preventing unauthorized use. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-033437 Summary of the Invention [Problem to be solved by the invention]
[0004] The following analysis was performed by the inventors of the present disclosure.
[0005] According to the technology disclosed in Patent Document 1, a common key created by an access control device outside the room must be transmitted to a copy machine inside the room and stored in the copy machine. In other words, the common key must be held by both the access control device and the copy machine. Either of these methods may result in unauthorized access or theft of the device, which could lead to the leakage of the common key, making this an insufficient security measure.
[0006] The present disclosure has been made in consideration of the above circumstances, and one of its objects is to provide a technique that contributes to improving the security of a common key used to encrypt confidential information. [Means for solving the problem]
[0007] According to a first aspect of the present disclosure, an internal storage unit for storing an encrypted encryption key obtained by encrypting an encryption key with an embedded key; a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encryption encryption key; a reading unit that reads confidential information encrypted with the common key; a decryption unit that decrypts the confidential information using the common key, The decryption unit may be a portable device that decrypts the encrypted common key with the encrypted encryption key to obtain the common key used to decrypt the confidential information.
[0008] According to a second aspect of the present disclosure, an encryption key generation unit that generates an encryption key; a key encryption unit that encrypts a key used for encryption; a server storage unit that stores an embedded key; a server communication unit that transmits and receives keys to and from an external device; The key encryption unit When the encryption key is generated, the encryption key is encrypted with the embedded key to generate an encrypted encryption key, and the encrypted encryption key is transmitted to the external device via the server communication unit; A management server is provided which, upon obtaining the common key, obtains the encrypted encryption key from the external device, encrypts the common key with the encrypted encryption key to generate an encrypted common key, stores the encrypted common key in the server memory unit, and transmits the encrypted common key to the external device via the server communication unit.
[0009] According to a third aspect of the present disclosure, A management system including a management server and a portable device, The management server an encryption key generation unit that generates an encryption key; a key encryption unit that encrypts a key used for encryption; a server storage unit that stores an embedded key; a server communication unit that transmits and receives keys to and from the portable device; The key encryption unit When the encryption key is generated, the encryption key is encrypted with the embedded key to generate an encrypted encryption key, and the encrypted encryption key is transmitted to the portable device via the server communication unit; When the common key is acquired, the encrypted encryption key is acquired from the portable device, and the common key is encrypted with the encrypted encryption key to generate an encrypted common key, which is stored in the server storage unit and transmitted to the portable device via the server communication unit; The portable device comprises: an internal storage unit that stores the encryption key received from the management server; a removable external storage unit that stores the encrypted common key received from the management server; a reading unit that reads confidential information encrypted with the common key; a decryption unit that decrypts the confidential information using the common key, The decryption unit decrypts the encrypted common key with the encrypted encryption key to obtain the common key used to decrypt the confidential information.
[0010] According to a fourth aspect of the present disclosure, A decryption method for decrypting confidential information encrypted with a common key in a portable device including an internal storage unit that stores an encrypted encryption key obtained by encrypting an encryption key with an embedded key, and a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encrypted encryption key, comprising: The computer of the portable device decrypting the encrypted common key with the encrypted encryption key to obtain the common key; A decryption method is provided for decrypting the confidential information using the obtained common key.
[0011] According to a fifth aspect of the present disclosure, A decryption method for decrypting confidential information encrypted with the common key in a management server including a server storage unit that stores an embedded key and an encrypted common key obtained by encrypting a common key with an encrypted encryption key obtained by encrypting a generated encryption key with the embedded key, and a server communication unit that acquires the encrypted encryption key from an external device, the method comprising: obtaining the encryption key from the external device via the server communication unit; Decrypting the encrypted common key with the encrypted encryption key to obtain the common key; A decryption method is provided for decrypting the confidential information using the obtained common key.
[0012] According to a sixth aspect of the present disclosure, A key management method in a management system including a management server having an encryption key generation unit that generates an encryption key, and a portable device having an internal storage unit and a removable external storage unit, comprising: the management server generates an encrypted encryption key by encrypting the generated encryption key with an embedded key, and transmits the encrypted encryption key to the portable device; the portable device stores the encryption key transmitted from the management server in the built-in storage unit; the management server acquires the encrypted encryption key from the portable device, encrypts a common key using the encrypted encryption key to generate and store an encrypted common key, and transmits the encrypted common key to the portable device; The portable device stores the encrypted common key transmitted from the management server in the external storage unit.
[0013] According to a seventh aspect of the present disclosure, A computer includes an internal storage unit that stores an encrypted encryption key obtained by encrypting an encryption key with an embedded key, and a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encrypted encryption key. a step of decrypting the encrypted common key with the encrypted encryption key to obtain the common key; A program for executing the steps of: using the obtained common key to decrypt confidential information that has been encrypted in advance with the common key; and
[0014] According to an eighth aspect of the present disclosure, A computer includes a server storage unit that stores an embedded key and an encrypted common key obtained by encrypting a common key with an encrypted encryption key obtained by encrypting a generated encryption key with the embedded key, and a server communication unit that acquires the encrypted encryption key from an external device, obtaining the encryption key from the external device via the server communication unit; a step of decrypting the encrypted common key with the encrypted encryption key to obtain the common key; A program for executing the steps of: using the obtained common key to decrypt confidential information that has been encrypted in advance with the common key; and
[0015] These programs can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present disclosure can also be embodied as a computer program product. [Effects of the Invention]
[0016] The present disclosure can contribute to improving the security of a common key used to encrypt confidential information. [Brief explanation of the drawings]
[0017] [Figure 1] 1A is an overall configuration diagram of an example of a management system of the present disclosure, and FIG. 1B is a functional block diagram of an example of a card reader of the present disclosure. [Figure 2] FIG. 1 is a diagram for explaining a storage location of a key according to the present disclosure. [Figure 3] FIG. 1A is a functional block diagram of an example of a management server according to the present disclosure, and FIG. 1B is a diagram for explaining an example of information stored in a server storage unit of the management server. [Figure 4] 1A and 1B are diagrams for explaining an example of an operation permission table and an entry management table, respectively, according to the present disclosure, and FIG. 1C and 1D are diagrams for explaining an example of an authentication table, according to the present disclosure. [Figure 5] FIG. 2 is a functional block diagram of an example of a card reader of the present disclosure. [Figure 6] 10 is a flowchart of an example of a key management process of the present disclosure. [Figure 7] 10 is a flowchart illustrating an example of an operation authentication process of the present disclosure. [Figure 8] 10 is a flowchart illustrating an example of an entry management process according to the present disclosure. [Figure 9] FIG. 2 is a functional block diagram of an example of a card reader of the present disclosure. [Figure 10] FIG. 1 is a configuration diagram illustrating an example of a hardware configuration of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0018] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that reference numerals in the drawings are assigned to each element for convenience as an example to facilitate understanding, and are not intended to limit the present disclosure to the illustrated aspects. Furthermore, connecting lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Furthermore, in the following description, "A and / or B" means A or B, or A and B.
[0019] <<First Embodiment>> An overview of this embodiment will be described. FIG. 1(a) is a diagram for explaining the overview of this embodiment. A card reader 200, which is a portable device of this embodiment, is included in a management system 100 that manages entry to each area 620, such as a room. The card reader 200 is placed in front of the door of each area 620 and manages locking and unlocking of the door. The area 620 having the door where the card reader 200 is placed is also referred to as the management area 620 of the card reader 200. In addition to the card reader 200, the management system 100 may also include a management server 300 and an electric lock 400.
[0020] Before describing the card reader 200 of this embodiment, we will briefly explain the management server 300. The management server 300 manages, for example, ID information that indicates who is permitted to enter each area 620. The management server 300 is connected to each card reader 200 via a network 610 such as a LAN, and transmits ID information that indicates who is permitted to enter each area 620 to each card reader 200.
[0021] The management server 300 of this embodiment also holds a prepared embedded key. It also generates an encryption key to be used within the management system 100. It then encrypts the generated encryption key with the embedded key to generate an encrypted encryption key, and transmits the encrypted encryption key to each card reader 200. In other words, the management server 300 does not hold either the encryption key or the encrypted encryption key within its own device.
[0022] Furthermore, when the management server 300 is given the common key, it obtains the encryption key from the card reader 200, encrypts the common key with the encryption key, and generates an encrypted common key. The management server 300 stores the generated encrypted common key in its own device and also transmits it to the card reader 200.
[0023] The card reader 200 reads encrypted confidential information (encrypted confidential information 501) from the IC card 500 carried by each user, decrypts it, extracts ID information, and manages entry into the management area 620 of the own device.
[0024] To achieve this, the card reader 200 of this embodiment includes a reading unit 210, a decoding unit 220, an interface (IF) 230, and an internal storage unit 240, as shown in FIG. 1(b).
[0025] The built-in storage unit 240 is a storage unit built into the card reader 200, and is configured with a readable and writable storage medium such as an SRAM (Static Random Access Memory). The built-in storage unit 240 stores an encrypted encryption key 712, which is an encryption key encrypted with an embedded key 711. The encrypted encryption key 712 is transmitted from the management server 300, for example, by encrypted communication or the like.
[0026] The IF 230 is an interface for accessing the external storage unit 231. The card reader 200 of this embodiment can access a removable external storage unit 231, such as an SD card, via this IF 230. The card reader 200 may be provided with, for example, a direct memory slot into which an SD card can be directly inserted, as the IF 230. The IF 230 may also be a USB (Universal Serial Bus) port.
[0027] The external storage unit 231 stores an embedded key 711 and an encrypted common key 713. The embedded key 711 is distributed in advance. The encrypted common key 713 is transmitted from the management server 300, for example, by encrypted communication.
[0028] The reading unit 210 reads the encrypted confidential information 501 recorded on the IC card 500. The encrypted confidential information 501 is confidential information encrypted with a common key prepared in advance. The confidential information includes a user ID that uniquely identifies the user who owns the IC card 500. The reading unit 210 performs short-range wireless communication with the IC chip in the IC card 500 to acquire the encrypted confidential information 501. For example, near field communication (NFC) is used as the short-range wireless communication.
[0029] The decryption unit 220 decrypts the encrypted confidential information 501 read by the reading unit 210 using a common key. The decryption unit 220 of this embodiment calculates a common key using the encrypted common key 713 stored in the external storage unit 231 and the encrypted encryption key 712 stored in the internal storage unit 240, and decrypts the encrypted confidential information 501. The decryption unit 220 obtains the common key by decrypting the encrypted common key 713 with the encrypted encryption key 712.
[0030] A list of storage locations for each type of key is shown in Fig. 2. As shown in this figure, the embedded key 711 is stored in the storage unit of the management server 300 and the external storage unit 231 of the card reader 200. Furthermore, the encrypted encryption key 712 encrypted with the embedded key 711 is stored in the built-in storage unit 240 of the card reader 200. Furthermore, the encrypted common key 713, which is a common key encrypted with the encrypted encryption key 712, is stored in the external storage unit 231 of the card reader 200 and the management server 300.
[0031] As described above, the card reader 200 of this embodiment reads and decrypts the encrypted confidential information 501 encrypted with a common key stored in the IC card 500, and extracts the user ID. At this time, an embedded key 711 and an encryption key unique to the system are prepared for encrypting the common key, and the common key is encrypted and stored using these. In other words, the common key required for decrypting the encrypted confidential information 501 is not stored directly within the card reader 200. Furthermore, the encrypted encryption key 712 and the encrypted common key 713 required to obtain the common key are stored separately in the internal storage unit 240 and the external storage unit 231.
[0032] As described above, according to this embodiment, the common key required for decrypting confidential information can be safely stored by not storing the common key as is. Furthermore, security is further enhanced by distributing the storage locations of the information required for decrypting the common key. In other words, removable storage media are generally prone to theft. However, according to this embodiment, even if the storage medium is stolen, it cannot be decrypted.
[0033] In particular, one of the pieces of information required to decrypt the common key is stored in a removable external storage unit 231 such as an SD card. For example, if the external storage unit 231 is removed from the card reader 200 during times when no one is entering the room, such as on holidays or at night, the key information will not be leaked even if the card reader 200 itself, which is a portable device that can be easily carried around, is stolen.
[0034] According to the card reader 200 of this embodiment, it is possible to improve the security of the common key used to encrypt confidential information.
[0035] <<Second embodiment>> Next, a second embodiment of the present disclosure will be described. This embodiment is an embodiment that embodies the first embodiment in more detail. In this embodiment, components with the same names as those in the first embodiment basically have the same functions as those in the first embodiment. Hereinafter, this embodiment will be described, focusing on the differences from the first embodiment.
[0036] The management system 100 of this embodiment has basically the same configuration as the first embodiment, and manages entry to each area 620 such as a room. As shown in Fig. 1(a), the management system 100 includes a management server 300, a card reader 200 placed in front of the door of each area 620, and an electric lock 400 for the door of each area 620.
[0037] The management server 300 and each card reader 200 are connected via a network 610 such as a LAN. A server-connected card reader 301 is connected to the management server 300 via a wired or wireless connection. This server-connected card reader 301 reads encrypted confidential information 501 recorded on an IC card 500. The card reader 200 and the electric lock 400 are also connected via a wired or wireless connection.
[0038] A user who is the administrator of the entire management system 100 accesses the management server 300 and registers individuals permitted to enter each area 620. Here, information (data) indicating whether or not entry is permitted is registered in association with a user ID. The registered data is distributed via LAN to the card readers 200 in each area 620. Each card reader 200 reads the encrypted confidential information 501 stored in the IC card 500 of the person wishing to enter and determines whether the user ID included in the confidential information is registered as an individual permitted to enter. If the individual is a person permitted to enter, it outputs an unlocking signal to the connected electric lock 400. The electric lock 400 receives the unlocking signal and unlocks, for example, by contact movement. This unlocks the door for entry to the area 620.
[0039] [Administration Server] The management server 300 manages users who are permitted to enter each area 620. Specifically, the management is performed by a user ID assigned to each user.
[0040] Each user is assigned a uniquely identifiable user ID in advance. The user ID is included in the confidential information. The confidential information is encrypted with a common key prepared in advance and recorded on the IC card 500 as encrypted confidential information 501. The user is authenticated using this IC card 500.
[0041] To achieve this, the management server 300 of this embodiment includes an encryption key generation unit 310, a key encryption unit 320, a server communication unit 330, a server interface (IF) 340, a server authentication unit 350, and a server storage unit 360, as shown in Figure 3(a).
[0042] The encryption key generation unit 310 generates an encryption key.
[0043] The key encryption unit 320 encrypts a key used for encryption. In this embodiment, the encryption key is encrypted using an embedded key 711 to generate an encrypted encryption key 712. The common key is also encrypted using the encrypted encryption key 712 to generate an encrypted common key 713. The common key is obtained from the common key storage medium 302 via the server IF 340.
[0044] The server communication unit 330 transmits and receives various information including keys to and from external devices. In this embodiment, keys are transmitted and received between the card reader 200 and the server communication unit 330 via encrypted communication. Specifically, an encrypted encryption key 712 and an encrypted common key 713 are transmitted to the card reader 200. In this embodiment, information related to a room entry management table 364 (described later) is also transmitted to the card reader 200. The room entry management table 364 is transmitted, for example, every time it is updated.
[0045] Furthermore, the management server 300 of this embodiment does not hold the encrypted encryption key 712. Therefore, when the encrypted encryption key 712 is needed, the management server 300 requests the encrypted encryption key 712 from the card reader 200 via the server communication unit 330. Furthermore, the management server 300 receives the encrypted encryption key 712 transmitted from the card reader 200 in response to the request via the server communication unit 330.
[0046] The server IF 340 is a connection interface for various external devices. For example, it is a USB interface. In this embodiment, the server IF 340 is connected to a server connection card reader 301, a common key storage medium 302, an input / output device 303, etc., and transmits and receives data to and from these devices. The server IF 340 may be equipped with multiple types of interfaces.
[0047] For example, the server IF 340 receives encrypted confidential information 501 recorded on an IC card 500 that has been read by the server-connected card reader 301. It also reads a common key from a common key storage medium 302. It also receives information input via an input device of the input / output device 303, and outputs information processed by the management server 300 via an output device. In this embodiment, an operation permission table 363 and an entry management table 364, which will be described later, are generated when a user inputs necessary information via an input device.
[0048] The server authentication unit 350 authenticates the user. In this embodiment, if information permitting operation is stored in an operation permission table 363 (described later) in association with the user ID, the authentication is deemed successful and operation of the management server 300 is permitted.
[0049] The server storage unit 360 stores information generated by the management server 300, information required for processing, etc. In this embodiment, as shown in Fig. 3(b), an embedded key 711, an encrypted common key 713, an operation permission table 363, and an entry management table 364 are stored. The embedded key 711 is prepared in advance for the management system 100, and is distributed to all devices belonging to the management system 100.
[0050] The embedded key 711 is input via the input / output device 303 connected to the server IF 340 and stored in the server storage unit 360, for example.
[0051] The operation permission table 363 is a table for managing users who can access the management server 300. Whether or not an operation is permitted is registered in the operation permission table 363 for each user ID. An example of the operation permission table 363 is shown in FIG. 4(a). As shown in this figure, information 363b indicating permission (in this figure, a circle) or denial is registered in association with a user ID 363a. In this embodiment, the server authentication unit 350 refers to the operation permission table 363 and determines whether or not information permitting an operation is registered in association with the acquired user ID. If permitted information is registered, authentication is performed and the operation is permitted.
[0052] As described above, the user ID is encrypted with the common key and pre-recorded in the IC card 500 as encrypted confidential information 501. The server-connected card reader 301 reads the encrypted confidential information 501 contained in the swept IC card 500. The server authentication unit 350 then acquires the encrypted confidential information 501 via the server IF 340. The server authentication unit 350 decrypts the encrypted confidential information 501 with the common key and acquires the user ID. The common key used for decryption is obtained by decrypting the encrypted common key 713 with the encrypted encryption key 712. The encrypted encryption key 712 is acquired from the card reader 200 via the server communication unit 330.
[0053] Note that the operation permission table 363 may register only the user IDs of users who are permitted to operate the management server 300. In this case, the server authentication unit 350 determines whether or not the user ID in the read encrypted confidential information 501 is registered in the operation permission table 363, and performs user authentication.
[0054] The entry management table 364 manages the user IDs that are permitted to enter each area 620. An example of the entry management table 364 is shown in Fig. 4(b). As shown in this figure, for each area 620 (area ID 364b) managed by the management server 300, information 364c indicating whether each user ID 364a is permitted to enter is registered.
[0055] Every time the entry management table 364 is created / updated, data related to each area 620 is sent to the card reader 200 that manages that area 620. That is, information about area A in the entry management table 364 is sent to the card reader 200 that manages area A, and information about area B in the entry management table 364 is sent to the card reader 200 that manages area B. Note that every time the information about each area 620 is updated, the entry management table 364 is sent to the card reader 200 that manages that area 620.
[0056] Similarly to the operation permission table 363, the entry management table 364 may also register only the user IDs of users who are permitted to enter the room. All entry management tables 364 may also be transmitted to each card reader 200.
[0057] [Card reader] As in the first embodiment, the card reader 200 reads the encrypted confidential information 501 from the IC card 500 carried by each user, decrypts it, and extracts the user ID. Then, based on the extracted user ID, the card reader 200 manages entry into the management area 620 of the own device.
[0058] 5, the card reader 200 of this embodiment includes, like the first embodiment, a reading unit 210, a decryption unit 220, an IF 230, and an internal storage unit 240. The card reader 200 of this embodiment further includes a communication unit 250, an authentication unit 260, and an output unit 270.
[0059] The components with the same names as those in the first embodiment basically have the same functions as those in the first embodiment. Therefore, a description thereof will be omitted here. However, in this embodiment, an authentication table 242 is stored in addition to the encrypted encryption key 712 in the built-in storage unit 240.
[0060] The authentication table 242 is information related to the management area 620 of the entry management table 364, which is transmitted from the management server 300. An example of the authentication table 242 is shown in Figures 4(c) and 4(d). As shown in the figure, the authentication table 242 registers information 242b indicating whether or not entry to the management area 620 is permitted (in this figure, O) in association with a user ID 242a.
[0061] The communication unit 250 transmits and receives information to and from external devices. In this embodiment, the communication unit 250 receives the encrypted encryption key 712 and the encrypted common key 713 from the management server 300 via encrypted communication. The communication unit 250 also receives the authentication table 242. The authentication table 242 is received, for example, every time the relevant section of the entry management table 364 is updated. Furthermore, upon receiving a request for the encrypted encryption key 712 from the management server 300, the communication unit 250 transmits the encrypted encryption key 712 to the requesting management server 300 in response to the request.
[0062] The authentication unit 260 performs authentication using the confidential information decrypted by the decryption unit 220. As described above, the authentication unit 260 extracts a user ID from the decrypted confidential information and performs authentication by referring to the authentication table 242. In this embodiment, for example, if permission information 242b is registered in the authentication table 242 in association with the extracted user ID 242a, the authentication unit 260 notifies the output unit 270 of successful authentication as the authentication result.
[0063] The output unit 270 outputs a signal according to the authentication result. In this embodiment, if the authentication unit 260 is successful in the authentication, it outputs an unlock signal to the connected electric lock 400.
[0064] When the electric lock 400 receives the unlock signal, it unlocks and allows the user holding the IC card 500 to enter the management area 620.
[0065] [Key management process] The flow of key management processing in the management system 100 of this embodiment will be described. In this embodiment, an encryption key is generated by the management server 300. The management server 300 also obtains a common key from the common key storage medium 302. These are then encrypted to generate an encrypted encryption key 712 and an encrypted common key 713, which are then distributed to each card reader 200. Here, the processing for one card reader 200 will be described as an example. If there are multiple card readers 200, the management server 300 will execute this processing for each card reader 200.
[0066] 6 shows a processing flow of key management processing by the management system 100 of this embodiment. This processing is started, for example, in response to an instruction from a user who manages the management system 100.
[0067] First, the encryption key generating unit 310 of the management server 300 generates an encryption key (step S1101).
[0068] Next, the key encryption unit 320 encrypts the generated encryption key with the embedded key 711 to generate an encrypted encryption key 712 (step S1102), and then transmits the encrypted encryption key 712 to the card reader 200 via the server communication unit 330 (step S1103).
[0069] On the card reader 200 side, when the communication unit 250 receives the encrypted encryption key 712 from the management server 300, the communication unit 250 stores the encrypted encryption key 712 in the internal storage unit 240 (step S1201). After that, the management server 300 deletes the encrypted encryption key 712 (step S1104).
[0070] First, the encrypted encryption key 712 is generated through the above process and stored in the built-in storage unit 240 of the card reader 200.
[0071] Thereafter, at a predetermined timing, the management server 300 reads the common key from the common key storage medium 302 via the server IF 340, thereby acquiring the common key (step S1105).
[0072] Then, the management server 300 requests the encrypted encryption key 712 from the card reader 200 that transmitted the encrypted encryption key 712 via the server communication unit 330 (step S1106).
[0073] Upon receiving the request, the communication unit 250 of the card reader 200 transmits the encrypted encryption key 712 stored in the internal storage unit 240 to the management server 300 (step S1202).
[0074] Upon receiving the encrypted encryption key 712, the management server 300 uses it to encrypt the acquired common key and generate the encrypted common key 713 (step S1107).
[0075] The management server 300 then transmits the generated encrypted common key 713 to the card reader 200 that transmitted the encrypted encryption key 712 (step S1108). The management server 300 also stores the encrypted common key 713 in the server storage unit 360, which is a storage unit of the management server 300, and deletes the encrypted encryption key 712 (step S1109).
[0076] Upon receiving the encrypted common key 713, the card reader 200 stores the encrypted common key 713 in the external storage unit 231 via the IF 230 (step S1203).
[0077] As a result, as shown in Figure 2, the encrypted common key 713 is stored in the server memory unit 360 of the management server 300, the encrypted encryption key 712 is stored in the internal memory unit 240 of the card reader 200, and the encrypted common key 713 is stored in the external memory unit 231.
[0078] [Operation authentication process] Next, the operation authentication process in the management server 300 will be described. This process is a process for restricting users who are allowed to operate the management server 300. Fig. 7 shows the process flow of the operation authentication process of this embodiment. This process is started when the server-connected card reader 301, which is connected via the server IF 340, reads the encrypted confidential information 501 from the IC card 500. The initial state of the management server 300 is an operation-disallowed state in which no operations from the user are accepted.
[0079] The server authentication unit 350 acquires the encrypted confidential information 501 from the server-connected card reader 301 (step S1301). The encrypted confidential information 501 is acquired via the server IF340.
[0080] The server authentication unit 350 requests the encrypted encryption key 712 from the card reader 200 (step S1302). The request is sent to the card reader 200 via the server communication unit 330.
[0081] In response to the request, the server authentication unit 350 acquires the encrypted encryption key 712 (step S1303), and decrypts the encrypted common key 713 with the encrypted encryption key 712 (step S1304). As described above, the encrypted common key 713 is stored in the server storage unit 360. After decryption, the server authentication unit 350 deletes the encrypted encryption key 712.
[0082] The server authentication unit 350 decrypts the encrypted confidential information 501 with the common key obtained by decryption (step S1305), and then acquires the user ID included in the decrypted confidential information (step S1306).
[0083] The server authentication unit 350 refers to the operation permission table 363 and performs authentication processing for the acquired user ID (step S1307). If the acquired user ID is registered as being permitted to operate in the operation permission table 363, the authentication is deemed successful. Otherwise, the authentication is deemed unsuccessful.
[0084] If the authentication is successful (S1307; Yes), the server authentication unit 350 sets the management server 300 to an operation-permitted state (step S1308). Here, for example, the management server 300 is set to a state in which it can accept input from an input device. Also, various data stored in the server storage unit 360 can be updated with the input data.
[0085] Server authentication unit 350 maintains the above state until an end instruction is received (step S1309). On the other hand, if an end instruction is received, server authentication unit 350 returns to the operation-disallowed state (step S1310) and ends the process.
[0086] On the other hand, if the authentication is unsuccessful in step S1307 (S1307; No), server authentication unit 350 ends the process.
[0087] [Entry control processing] Next, the flow of the entry management process in the card reader 200 of this embodiment will be described. In this embodiment, the card reader 200 reads the encrypted confidential information 501 from the IC card 500 held by the user, and controls the operation of the electric lock 400 attached to the door of the management area 620. FIG. 8 shows the processing flow of the entry management process of this embodiment. It is assumed here that the latest authentication table 242 has been sent in advance from the management server 300. This process starts when the user holds the IC card 500 over the card.
[0088] First, the reading unit 210 acquires the encrypted confidential information 501 from the IC card 500 (step S1401).
[0089] The decryption unit 220 then decrypts the encrypted common key 713 with the encrypted encryption key 712 (step S1402) to obtain the common key. The encrypted encryption key 712 is obtained from the internal storage unit 240, and the encrypted common key 713 is obtained from the external storage unit 231.
[0090] The decryption unit 220 decrypts the encrypted confidential information 501 with the common key (step S1403), and obtains the user ID included in the confidential information (step S1404).
[0091] The authentication unit 260 refers to the authentication table 242 and authenticates the user ID (step S1405). That is, if information indicating permission to enter the room is registered in association with the user ID in the authentication table 242, the authentication is deemed successful; otherwise, the authentication is deemed unsuccessful.
[0092] If the authentication is successful (S1405; Yes), the authentication unit 260 notifies the output unit 270 to that effect. The output unit 270 outputs an unlock signal to the electric lock 400 (step S1406), and the process ends. Upon receiving the unlock signal, the electric lock 400 unlocks the door and opens it.
[0093] On the other hand, if the authentication is unsuccessful (S1405; No), the process ends.
[0094] As described above, according to this embodiment, the card reader 200 has the same configuration as in the first embodiment, and therefore, the same effects as in the first embodiment can be obtained.
[0095] Furthermore, according to this embodiment, the management server 300 does not hold the encrypted encryption key 712. Therefore, even if the management server 300 is accessed illegally, the common key cannot be decrypted and the common key cannot be obtained.
[0096] Thus, according to this embodiment, the information necessary to decrypt the common key is stored in a distributed manner in both the card reader 200 and the management server 300 that make up the management system 100, thereby increasing the difficulty of decrypting the common key.
[0097] Therefore, according to this embodiment, it is possible to improve the security of the common key used to encrypt confidential information in the management system 100. This is particularly useful when encrypting information such as a user ID recorded on an IC card with a common key and using the encrypted information for authentication in an organization that requires high confidentiality.
[0098] <<Third Embodiment>> Next, a third embodiment will be described. The card reader 200 of this embodiment further has a function of deleting the encrypted encryption key 712 stored in the internal storage unit 240 in the event of unauthorized interference, etc. This further improves security.
[0099] The overall configuration of the management system 100 of this embodiment is the same as that of any of the above-described embodiments. The configuration of the management server 300 is also the same as that of any of the above-described embodiments. Therefore, a description thereof will be omitted.
[0100] To achieve the above functions, the card reader 200 of this embodiment further includes a tamper detection unit 280 and a deletion unit 290 in addition to the configuration of any of the above embodiments, as shown in Fig. 9. Note that here, an example is shown in which these functions are provided in the configuration of the card reader 200 of the second embodiment.
[0101] Tamper detection unit 280 detects unauthorized interference with card reader 200. Note that tampering refers to unauthorized interference, analysis, or alteration. At the hardware level, this includes physically disassembling the device or bypassing the encryption circuit. At the software level, this includes decompiling a program or rewriting data.
[0102] The deleting unit 290 deletes predetermined data when the tamper detecting unit 280 detects tampering. In this embodiment, the encrypted encryption key 712 stored in the internal storage unit 240 is deleted.
[0103] The tamper detection unit 280 and the deletion unit 290 may be realized, for example, by an existing tamper-resistant device. A tamper-resistant device is a device that automatically erases internal confidential data if an attempt is made to disassemble or analyze the device in an unauthorized manner. Specifically, it detects unnatural changes in temperature, humidity, voltage, location, etc., damage to the casing, or missing screws as attacks, and activates a data erasure program.
[0104] Other functions of the card reader 200 are the same as those of any of the above embodiments, and therefore will not be described here.
[0105] As described above, this embodiment has the same configuration as the above-described embodiments, and therefore provides the same effects as those embodiments.
[0106] Furthermore, according to this embodiment, if the card reader 200 is forced open, the encrypted encryption key 712 stored in the internal storage unit 240 is deleted. This makes it impossible to decrypt the common key, further increasing security.
[0107] Therefore, according to this embodiment, it is possible to improve the security of the common key used to encrypt confidential information.
[0108] <Variation 1> In the above embodiment, the embedded key 711 is distributed in advance to all devices in the management system 100. However, this is not limiting. For example, the embedded key 711 may be held only by the management server 300.
[0109] <Variation 2> In the above embodiment, in the card reader 200, the encrypted encryption key 712 is stored in the internal storage unit 240, and the encrypted common key 713 is stored in the external storage unit 231. However, this may be reversed. In this case, if the card reader 200 has a tamper function, the deletion unit 290 is set to delete the encrypted encryption key 712 stored in the external storage unit 231 when tampering is detected.
[0110] The encrypted encryption key 712 and the encrypted common key 713 may be stored in separate storage areas, i.e., they may be stored in physically different storage areas accessible by the CPU of the card reader 200, whether built-in or external.
[0111] <Variation 3> In the above embodiment, the generation of the encryption key and the acquisition of the common key are temporally unrelated in the management server 300, but this is not limiting. For example, the encryption key may be generated when the common key is read from the common key storage medium 302.
[0112] In this case, the management server 300 first encrypts the encryption key with the embedded key 711 to generate an encrypted encryption key 712. Then, the generated encrypted encryption key 712 is transmitted to the card reader 200. Furthermore, before deleting the generated encrypted encryption key 712, the management server 300 encrypts the common key with the encrypted encryption key 712 to generate an encrypted common key 713. Then, the generated encrypted common key 713 is transmitted to the card reader 200. Thereafter, the encrypted encryption key 712 is deleted.
[0113] This eliminates the need to obtain the encrypted encryption key 712 from the card reader 200 when encrypting the common key, and makes it possible to reduce the number of times encrypted communications are performed with the card reader 200.
[0114] <Variation 4> In each of the above embodiments, even when the management system 100 has multiple card readers 200, one encryption key is used. However, this is not limiting. For example, a different encryption key may be generated for each set of one or multiple card readers 200.
[0115] Here, as an example, this modified example will be described taking as an example a case where different encryption keys are generated for each of two card readers 200 (first card reader, second card reader).
[0116] The management system 100 generates a first card reader encryption key (first encryption key) for the first card reader 200. Then, the management system 100 encrypts the generated first encryption key with the embedded key 711 to generate an encrypted first encryption key as an encrypted encryption key 712 of the first encryption key. The management system 100 transmits the encrypted first encryption key to the first card reader 200. The management system 100 also encrypts the common key with the encrypted first encryption key to generate a first encrypted common key as an encrypted common key 713 encrypted with the encrypted first encryption key. The management system 100 transmits the generated first encrypted common key to the first card reader 200 and stores it in the server storage unit 360 in association with information (card reader ID) that identifies the first card reader 200.
[0117] Similarly, a second card reader encryption key (second encryption key) is generated for the second card reader 200. The generated second encryption key is then encrypted with the embedded key 711 to generate an encrypted second encryption key as the encrypted encryption key 712 of the second encryption key. The encrypted second encryption key is transmitted to the second card reader 200. The common key is also encrypted with the encrypted second encryption key to generate a second encrypted common key as the encrypted common key 713. The generated second encrypted common key is transmitted to the second card reader 200 and is stored in the server storage unit 360 in association with the card reader ID of the second card reader 200.
[0118] In this case, any card reader 200 may request the encrypted encryption key 712 when the server-connected card reader 301 decrypts the encrypted confidential information 501 that it has read. However, the encrypted encryption key 712 is received along with the card reader ID. The encrypted common key 713 registered in association with the card reader ID is then decrypted using the received encrypted encryption key 712 to obtain the common key.
[0119] By generating an encryption key for each card reader 200, even if the encrypted encryption key 712 is leaked from one card reader 200, the encrypted encryption key 712 cannot be used in other card readers 200. Therefore, it is only necessary to delete the encrypted encryption key 712 from the leaked card reader 200. This further improves the security of the common key in the entire management system 100.
[0120] <Variation 5> The encryption key may also be configured to be regenerated at predetermined time intervals or upon the occurrence of a predetermined event.
[0121] For example, every time a new encryption key is generated, the management server 300 encrypts the encryption key with the embedded key 711 to generate an encrypted encryption key 712. The management server 300 then transmits the generated encrypted encryption key 712 to each card reader 200. Every time the card reader 200 receives a new encrypted encryption key 712, it updates the encrypted encryption key 712 in the built-in storage unit 240.
[0122] Furthermore, the management server 300 reads the common key and encrypts it every time it generates an encrypted encryption key 712, thereby generating an encrypted common key 713. The management server 300 then transmits the generated encrypted common key 713 to each card reader 200. On the card reader 200 side, the encrypted common key 713 in the external storage unit 231 is updated every time a new encrypted common key 713 is received.
[0123] This allows the encryption key 712 to be updated at a predetermined timing, thereby increasing the security of the common key in the management system 100.
[0124] <Variation 6> In the second embodiment, the card reader 200 manages / restricts entry into the managed area 620, but the objects of management / restriction are not limited to this. For example, the use of a device to which the card reader 200 is connected may be managed / restricted.
[0125] [Hardware configuration] The management server 300 and the card reader 200 of each of the above embodiments may be realized by, for example, a general-purpose information processing device. The general-purpose information processing device includes, for example, a CPU (Central Processing Unit) 191, a main storage device (memory) 192, an auxiliary storage device 193, a communication I / F 194, and an expansion I / F 195, which are interconnected by an internal bus, as shown in FIG.
[0126] The CPU 191 realizes the above functions and controls the entire device by, for example, loading a program stored in the auxiliary storage device 193 into the main storage device 192 and executing it. Note that the CPU 191 may be replaced by one or more processors such as an MPU (Micro Processing Unit).
[0127] The main storage device 192 is a memory such as a RAM (Random Access Memory), etc. The main storage device 192 is a work area when the CPU 191 processes programs executed by the installed devices.
[0128] The auxiliary storage device 193 is, for example, a read-only memory (ROM), a hard disk drive (HDD), or a solid state drive (SSD). The auxiliary storage device 193 stores various programs executed by the installed device. In each of the above embodiments and / or modifications, the server storage unit 360 and the internal storage unit 240 are each constructed in the auxiliary storage device 193.
[0129] The auxiliary storage device 193 may include a storage medium such as a flexible disk, a hard disk, an optical disk, a CD-ROM, a CD-R, a magnetic tape, a nonvolatile memory card, a DVD, etc. These media may be used as the external storage unit 231 in the card reader 200 instead of an SD card.
[0130] The programs stored in the auxiliary storage device 193 can be provided as program products recorded on a non-transitory computer-readable recording medium. The auxiliary storage device 193 can be used to store various programs recorded on a non-transitory computer-readable recording medium for the medium to long term.
[0131] The communication I / F 194 is an interface for inputting and outputting signals and data via wired or wireless connections. For example, in each of the above-described embodiments and / or modifications, the communication I / F 194 is connected to a LAN, and data is transmitted and received between the management server 300 and the card reader 200. The communication I / F 194 may also include an antenna, a modem, etc.
[0132] The expansion I / F 195 is, for example, a USB interface or a memory slot, and is connected to an external storage unit, an input device, an output device, etc. The expansion I / F 195 may be provided with a plurality of different types of interfaces.
[0133] For example, the external storage unit 231 of the card reader 200 is connected via the expansion I / F 195. The electric lock 400 may also be connected via the expansion I / F 195.
[0134] The server connection card reader 301, shared key storage medium 302, and input / output device 303 of the management server 300 are connected via an expansion I / F 195. The input device is a device that accepts user operations, such as a keyboard or mouse. The output device is a display device such as a monitor. The liquid crystal monitor may have a touch panel function that accepts instructions by touch operation by the user.
[0135] The above-mentioned functions of each device are realized by the CPU 191 loading a program stored in the auxiliary storage device 193 into the main storage device 192 and executing it.
[0136] The hardware configuration of each device is not limited to this. Each function (server) of each device may be implemented using, for example, an integrated circuit (IC) dedicated to each process, an application specific integrated circuit (ASIC), a system on a chip (SOC), a field programmable gate array (FPGA), or the like.
[0137] In addition, a program for realizing each of the above functions of each device can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present disclosure can also be embodied as a computer program product.
[0138] In the process flow used in the above explanation, multiple steps (processes) are described in order, but the order in which each step is performed is not limited to the order described. For example, the order of the steps shown in the figure can be changed to the extent that the content is not affected, such as performing each process in parallel.
[0139] Although the embodiments and modifications of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments and can be modified in various ways that would be understandable to a person skilled in the art. Each embodiment and modification can be combined with other embodiments as appropriate. Furthermore, for example, the network configurations and element configurations shown in the drawings are examples intended to aid in understanding the present disclosure and are not limited to the configurations shown in these drawings.
[0140] Finally, preferred embodiments of the present disclosure will be summarized. Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes. (Appendix 1) The portable device is an internal storage unit for storing an encrypted encryption key obtained by encrypting an encryption key with an embedded key; a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encryption encryption key; a reading unit that reads confidential information encrypted with the common key; and a decryption unit that decrypts the confidential information using the common key. The decryption unit decrypts the encrypted common key with the encrypted encryption key to obtain the common key used when decrypting the confidential information. (Appendix 2) 2. The portable device of claim 1, a tamper detection unit that detects unauthorized interference with the portable device; It is desirable to further comprise a deletion unit that deletes the encryption key stored in the built-in storage unit when the tamper detection unit detects the interference. (Appendix 3) 3. The portable device of claim 1, an authentication unit that performs authentication using the decrypted confidential information; It is preferable that the device further comprises an output unit that outputs a signal according to the result of the authentication. (Appendix 4) The management server is an encryption key generation unit that generates an encryption key; a key encryption unit that encrypts a key used for encryption; a server storage unit that stores an embedded key; and a server communication unit that transmits and receives keys to and from an external device. The key encryption unit When the encryption key is generated, the encryption key is encrypted with the embedded key to generate an encrypted encryption key, and the encrypted encryption key is transmitted to the external device via the server communication unit; When the common key is obtained, the encrypted encryption key is obtained from the external device, the common key is encrypted with the encrypted encryption key to generate an encrypted common key, which is stored in the server memory unit and transmitted to the external device via the server communication unit. (Appendix 5) The management system is The system includes a management server and a portable device. The management server an encryption key generation unit that generates an encryption key; a key encryption unit that encrypts a key used for encryption; a server storage unit that stores an embedded key; and a server communication unit that transmits and receives keys to and from the portable device. The key encryption unit When the encryption key is generated, the encryption key is encrypted with the embedded key to generate an encrypted encryption key, and the encrypted encryption key is transmitted to the portable device via the server communication unit; When the common key is obtained, the encrypted encryption key is obtained from the portable device, the common key is encrypted with the encrypted encryption key to generate an encrypted common key, which is stored in the server memory unit and transmitted to the portable device via the server communication unit. The portable device comprises: an internal storage unit that stores the encryption key received from the management server; a removable external storage unit that stores the encrypted common key received from the management server; a reading unit that reads confidential information encrypted with the common key; and a decryption unit that decrypts the confidential information using the common key. The decryption unit decrypts the encrypted common key with the encrypted encryption key to obtain the common key used when decrypting the confidential information. (Appendix 6) In a portable device including an internal storage unit that stores an encrypted encryption key obtained by encrypting an encryption key with an embedded key, and a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encrypted encryption key, a decryption method for decrypting confidential information encrypted with the common key comprises: The computer of the portable device decrypting the encrypted common key with the encrypted encryption key to obtain the common key; The confidential information is decrypted using the obtained common key. (Appendix 7) A decryption method for decrypting confidential information encrypted with the common key in a management server including a server storage unit that stores an embedded key and an encrypted common key obtained by encrypting a common key with an encrypted encryption key obtained by encrypting a generated encryption key with the embedded key, and a server communication unit that acquires the encrypted encryption key from an external device, comprises: obtaining the encryption key from the external device via the server communication unit; Decrypting the encrypted common key with the encrypted encryption key to obtain the common key; The confidential information is decrypted using the obtained common key. (Appendix 8) A key management method in a management system including a management server having an encryption key generation unit that generates an encryption key, and a portable device having an internal storage unit and a removable external storage unit, comprising: the management server generates an encrypted encryption key by encrypting the generated encryption key with an embedded key, and transmits the encrypted encryption key to the portable device; the portable device stores the encryption key transmitted from the management server in the built-in storage unit; the management server acquires the encrypted encryption key from the portable device, encrypts a common key using the encrypted encryption key to generate and store an encrypted common key, and transmits the encrypted common key to the portable device; The portable device stores the encrypted common key transmitted from the management server in the external storage unit. (Appendix 9) A computer includes an internal storage unit that stores an encrypted encryption key obtained by encrypting an encryption key with an embedded key, and a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encrypted encryption key, a step of decrypting the encrypted common key with the encrypted encryption key to obtain the common key; and a program for executing a procedure for decrypting confidential information that has been encrypted in advance with the common key, using the obtained common key. (Appendix 10) A computer includes a server storage unit that stores an embedded key and an encrypted common key obtained by encrypting a common key with an encrypted encryption key obtained by encrypting a generated encryption key with the embedded key, and a server communication unit that acquires the encrypted encryption key from an external device, obtaining the encryption key from the external device via the server communication unit; a step of decrypting the encrypted common key with the encrypted encryption key to obtain the common key; and a program for executing a procedure for decrypting confidential information that has been encrypted in advance with the common key, using the obtained common key. (Appendix 11) 9. The key management method according to claim 8, The key management method further comprises deleting the encrypted encryption key stored in the internal storage unit when unauthorized tampering with the portable device is detected. Note that, like Supplementary Note 1, the form of Supplementary Note 5 can be expanded into the form of Supplementary Note 2-3.
[0141] The disclosures of the above-mentioned patent documents, etc. are incorporated herein by reference. Modifications and adjustments of the embodiments and variations are possible within the scope of the entire disclosure of the present invention (including the claims), and further based on the basic technical concept thereof. Furthermore, various combinations and selections of the various disclosed elements (including each element of each claim, each element of each embodiment or variation, each element of each drawing, etc.) are possible within the scope of this disclosure. In other words, this disclosure naturally includes various modifications and alterations that would be possible by a person skilled in the art in accordance with the entire disclosure, including the claims, and the technical concept thereof. In particular, with regard to the numerical ranges set forth herein, any numerical value or subrange included within the range should be construed as being specifically set forth, even if not otherwise specified. [Explanation of symbols]
[0142] 100: management system, 191: CPU, 192: main memory device, 193: auxiliary memory device, 194: communication I / F, 195: expansion I / F, 200: card reader, 210: reading unit, 220: decryption unit, 230: IF, 231: external storage unit, 240: internal storage unit, 242: authentication table, 242a: user ID, 242b: permission / denial information, 250: communication unit, 260: authentication unit, 270: output unit, 280: tamper detection unit, 290: deletion unit, 300: Management server, 301: Server connection card reader, 302: Common key storage medium, 303: Input / output device, 310: Encryption key generation unit, 320: Key encryption unit, 330: Server communication unit, 340: Server IF, 350: Server authentication unit, 360: Server storage unit, 363: Operation permission table, 363a: User ID, 363b: Permission / denial information, 364: Entry management table, 364a: User ID, 364b: Area ID, 364c: Permission / denial information, 400: Electric lock, 500: IC card, 501: Encrypted confidential information, 610: Network, 620: Area, 711: Embedded key, 712: Encryption encryption key, 713: Encryption common key
Claims
1. an internal storage unit for storing an encrypted encryption key obtained by encrypting an encryption key with an embedded key; a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encryption encryption key; a reading unit that reads confidential information encrypted with the common key; a decryption unit that decrypts the confidential information using the common key, The decryption unit decrypts the encrypted common key with the encrypted encryption key to obtain the common key used to decrypt the confidential information.
2. 2. The portable device of claim 1, a tamper detection unit that detects unauthorized interference with the portable device; a deletion unit that deletes the encryption key stored in the built-in storage unit when the tamper detection unit detects the interference.
3. 2. The portable device of claim 1, an authentication unit that performs authentication using the decrypted confidential information; The portable device further comprises an output unit that outputs a signal according to a result of the authentication.
4. an encryption key generation unit that generates an encryption key; a key encryption unit that encrypts a key used for encryption; a server storage unit that stores an embedded key; a server communication unit that transmits and receives keys to and from an external device; The key encryption unit When the encryption key is generated, the encryption key is encrypted with the embedded key to generate an encrypted encryption key, and the encrypted encryption key is transmitted to the external device via the server communication unit; When the management server obtains the common key, it obtains the encrypted encryption key from the external device, encrypts the common key with the encrypted encryption key to generate an encrypted common key, stores the encrypted common key in the server memory unit, and transmits the encrypted common key to the external device via the server communication unit.
5. A management system including a management server and a portable device, The management server an encryption key generation unit that generates an encryption key; a key encryption unit that encrypts a key used for encryption; a server storage unit that stores an embedded key; a server communication unit that transmits and receives keys to and from the portable device; The key encryption unit When the encryption key is generated, the encryption key is encrypted with the embedded key to generate an encrypted encryption key, and the encrypted encryption key is transmitted to the portable device via the server communication unit; When the common key is acquired, the encrypted encryption key is acquired from the portable device, and the common key is encrypted with the encrypted encryption key to generate an encrypted common key, which is stored in the server storage unit and transmitted to the portable device via the server communication unit; The portable device comprises: an internal storage unit that stores the encryption key received from the management server; a removable external storage unit that stores the encrypted common key received from the management server; a reading unit that reads confidential information encrypted with the common key; a decryption unit that decrypts the confidential information using the common key, The decryption unit decrypts the encrypted common key with the encrypted encryption key to obtain the common key used to decrypt the confidential information.
6. A decryption method for decrypting confidential information encrypted with a common key in a portable device including an internal storage unit that stores an encrypted encryption key obtained by encrypting an encryption key with an embedded key, and a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encrypted encryption key, comprising: The computer of the portable device decrypting the encrypted common key with the encrypted encryption key to obtain the common key; a decryption method for decrypting the confidential information using the obtained common key.
7. A decryption method for decrypting confidential information encrypted with the common key in a management server including a server storage unit that stores an embedded key and an encrypted common key obtained by encrypting a common key with an encrypted encryption key obtained by encrypting a generated encryption key with the embedded key, and a server communication unit that acquires the encrypted encryption key from an external device, the method comprising: obtaining the encryption key from the external device via the server communication unit; Decrypting the encrypted common key with the encrypted encryption key to obtain the common key; a decryption method for decrypting the confidential information using the obtained common key.
8. A key management method in a management system including a management server having an encryption key generation unit that generates an encryption key, and a portable device having an internal storage unit and a removable external storage unit, comprising: the management server generates an encrypted encryption key by encrypting the generated encryption key with an embedded key, and transmits the encrypted encryption key to the portable device; the portable device stores the encryption key transmitted from the management server in the built-in storage unit; the management server acquires the encrypted encryption key from the portable device, encrypts a common key using the encrypted encryption key to generate and store an encrypted common key, and transmits the encrypted common key to the portable device; The portable device stores the encrypted common key transmitted from the management server in the external storage unit.
9. A computer includes an internal storage unit that stores an encrypted encryption key obtained by encrypting an encryption key with an embedded key, and a removable external storage unit that stores an encrypted common key obtained by encrypting a common key with the encrypted encryption key, a step of decrypting the encrypted common key with the encrypted encryption key to obtain the common key; and a program for executing a procedure for decrypting confidential information that has been encrypted in advance with the common key, using the obtained common key.
10. A computer includes a server storage unit that stores an embedded key and an encrypted common key obtained by encrypting a common key with an encrypted encryption key obtained by encrypting a generated encryption key with the embedded key, and a server communication unit that acquires the encrypted encryption key from an external device, obtaining the encryption key from the external device via the server communication unit; a step of decrypting the encrypted common key with the encrypted encryption key to obtain the common key; and a program for executing a procedure for decrypting confidential information that has been encrypted in advance with the common key, using the obtained common key.
Citation Information
Patent Citations
Communication equipment and its method
JP1997261217A
Communication apparatus and method
JP2006094435A
Entrance / exit management apparatus, management target device and management system
JP2008033437A