Encryption key synchronization system, encryption key management device, synchronization management device, and encryption key synchronization method
The synchronization management device generates a common transport key for encryption key management devices, simplifying and reducing costs in synchronizing databases by avoiding individual master key transmission, ensuring secure and efficient key management.
Patent Information
- Application Number
- JP2024098907
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-19
- Publication Date
- 2026-01-07
AI Technical Summary
Synchronizing databases between redundantly configured encryption key management devices is complicated when individual master keys are used, as it necessitates confidential transmission and increases costs.
A synchronization management device generates a common transport key for multiple encryption key management devices, allowing them to perform database synchronization without transmitting individual master keys, using a unique master key for encryption and a transport key for re-encryption during synchronization.
This approach simplifies and reduces the cost of database synchronization by eliminating the need for confidential master key transmission between devices, ensuring secure and efficient key management.
Smart Images

Figure 2026001501000001_ABST
Abstract
Description
[Technical Field]
[0001] The present application relates to a technique for synchronizing encryption keys stored in a plurality of redundantly configured encryption key management devices. [Background technology]
[0002] Encryption technology using encryption keys has become indispensable in the field of information security. To safely store and manage encryption keys, it has been proposed to use an HSM (Hardware Security Module) (for example, Patent Document 1). In order to safely store and manage encryption keys, the invention disclosed in Patent Document 1 stores encrypted encryption keys in a database.
[0003] In an encryption key management device that has a database for storing encrypted encryption keys, it is desirable to have multiple encryption key management devices in a redundant configuration to improve reliability and availability. When multiple encryption key management devices are configured redundantly, it becomes necessary to synchronize the databases between the encryption key management devices.
[0004] An HSM has the function of storing an encryption key called a master key and encrypting data using the master key (for example, Patent Document 2). If the encryption key management devices share a common master key, the risk of the master key being leaked increases, but if the encryption key management devices have individual master keys, the master keys must be sent and received confidentially between the encryption key management devices, which complicates the process of synchronizing databases. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-61267 [Patent Document 2] Japanese Patent Application Publication No. 2018-23162 Summary of the Invention [Problem to be solved by the invention]
[0006] Therefore, in this application, a cryptographic key management device equipped with a database that stores cryptographic keys encrypted using an HSM is configured redundantly, so that even if the master keys stored in the HSM are individualized in the cryptographic key management device, the process of synchronizing the database can be simplified. [Means for solving the problem]
[0007] The first invention for solving the above-mentioned problems is a system invention, which is an encryption key synchronization system including a plurality of redundantly configured encryption key management devices and a synchronization management device that manages synchronization of the encryption key management devices. In order to solve the above-mentioned problems, the encryption key management device according to the first invention is an HSM (Hardware Security Module) that stores a master key unique to each encryption key management device and performs cryptographic calculations using at least the master key. a synchronization means for receiving a transport key common to each encryption key management device from the synchronization management device, upon receiving an instruction to send updated content from the synchronization management device, acquiring the service key updated in the database from the database, causing the HSM to re-encrypt the service key acquired from the database using the master key, and transmitting the service key re-encrypted using the transport key to the synchronization management device; and for receiving, upon receiving a database update instruction from the synchronization management device, a database update instruction including the service key encrypted using the transport key, causing the HSM to re-encrypt the service key included in the database update instruction, using the master key, and updating the database using the service key re-encrypted using the master key after receiving the transport key from the synchronization management device. The synchronization management device of the first invention comprises a synchronization management means that monitors updates to the database for each of the encryption key management devices, and when an update to the database is detected, generates the transport key and transmits it to each of the encryption key management devices, then transmits the update content transmission instruction to the encryption key management device where the database has been updated, obtains the service key encrypted with the transport key from the encryption key management device that transmitted the update content transmission instruction, and transmits the database update instruction including the service key encrypted with the transport key to all of the other encryption key management devices except for the encryption key management device where the database has been updated. In addition, this application also claims patent rights to the encryption key management device that constitutes the encryption key synchronization system according to the first invention, and the synchronization management device that constitutes the encryption key synchronization system according to the first invention.
[0008] The second invention that solves the above-mentioned problem is a method invention, which is an encryption key synchronization method executed by multiple redundantly configured encryption key management devices and a synchronization management device that manages the synchronization of the encryption key management devices. The encryption key management device according to the second aspect of the present invention includes an HSM (Hardware Security Module) that stores a master key unique to each encryption key management device and performs cryptographic calculations using at least the master key, and a database that stores one or more service keys encrypted with the master key using the HSM. A cryptographic key management device synchronization method according to a second aspect of the present invention includes a step a) in which the synchronization management device monitors updates to the database for each of the cryptographic key management devices, and when an update to the database is detected, generates a transport key and transmits the generated transport key to each of the cryptographic key management devices; a step b) in which the synchronization management device transmits an update content transmission instruction to the cryptographic key management devices whose databases have been updated, and the cryptographic key management device that has received the update content transmission instruction retrieves the service key updated in the database from the database, and then causes the HSM to execute a process of re-encrypting the service key retrieved from the database with the master key by using the transport key, and and step c) in which, when the synchronization management device receives the service key encrypted with the transport key from the encryption key management device that sent the update content transmission instruction, the synchronization management device transmits a database update instruction including the service key received from the encryption key management device to each of the other encryption key management devices that do not have their databases updated, and the encryption key management device that has received the database update instruction causes the HSM to re-encrypt the service key included in the database update instruction from the transport key to the master key, and updates the database using the service key re-encrypted with the master key. [Effects of the Invention]
[0009] In this application, a synchronization management device generates a transport key that is common to multiple redundantly configured encryption key management devices, and each encryption key management device uses this transport key to perform processing related to database synchronization.This allows for a redundant configuration of encryption key management devices equipped with a database that stores encryption keys encrypted using an HSM, and simplifies processing related to database synchronization even if the master keys stored in the HSM are individualized by the encryption key management devices. [Brief explanation of the drawings]
[0010] [Figure 1]FIG. 1 is a diagram showing the configuration of an encryption key synchronization system. [Figure 2] FIG. 2 is a block diagram of an encryption key management device. [Figure 3] FIG. 4 is a diagram for explaining a synchronization start process executed by a synchronization unit of the encryption key management device. [Figure 4] FIG. 10 is a diagram for explaining an update content transmission process executed by a synchronization unit of the encryption key management device. [Figure 5] FIG. 4 is a diagram for explaining a database update process executed by a synchronization unit of the encryption key management device. [Figure 6] FIG. 2 is a block diagram of a synchronization management device. [Figure 7] FIG. 2 is a diagram for explaining a process executed by a synchronization management unit included in the synchronization management device. DETAILED DESCRIPTION OF THE INVENTION
[0011] From here, we will describe an embodiment of the invention disclosed in this application. This embodiment is intended to facilitate understanding of the invention disclosed in this application. The invention disclosed in this application is not limited to the embodiment described below. Furthermore, unless otherwise specified, the drawings are schematic diagrams drawn to facilitate understanding of the invention.
[0012] The configuration of an encryption key synchronization system 1 disclosed in the present application will be described with reference to Fig. 1. Fig. 1 is a diagram showing the configuration of an encryption key synchronization system 1 disclosed in the present application.
[0013] As shown in Fig. 1, the encryption key synchronization system 1 disclosed in the present application includes a plurality of redundantly configured encryption key management devices 10 and a synchronization management device 11 that manages synchronization of the encryption key management devices 10. The plurality of redundantly configured encryption key management devices 10 are connected to the synchronization management device 11 via a network not shown in Fig. 1. Each of the plurality of encryption key management devices 10 has the same function. In the embodiment, when each encryption key management device 10 is to be identified and described, one of the letters a to c is assigned to the reference numeral.
[0014] In the embodiment, the encryption key management device 10 is a device that provides cryptographic services involving cryptographic processing, such as encryption / decryption and digital signature generation. The encryption key management device 10 stores a service key 104 used in the cryptographic services provided by the encryption key management device 10. The encryption key management device 10 stores a master key 103 that is unique to the encryption key management device 10, and includes a database 102 that stores a service key 104M obtained by encrypting the plaintext of the service key 104 using the master key 103. While FIG. 1 illustrates the encryption key management device 10 as if it uses only one service key 104, in reality, the encryption key management device 10 uses multiple service keys 104 that differ depending on the cryptographic service and user. Therefore, the number of service keys 104M stored in the database 102 is generally not one but multiple.
[0015] To improve the reliability and availability of the encryption key synchronization system 1, the encryption key synchronization system 1 has a redundant configuration of encryption key management devices 10 each having a database 102 that stores one or more service keys 104M. A redundant configuration of the encryption key management devices 10 means that multiple (three in FIG. 1) encryption key management devices 10 are provided with databases 102 containing the same content. This allows the other encryption key management devices 10 to continue functioning normally even if one of the encryption key management devices 10 fails, preventing the loss of the service keys 104 stored in the databases 102.
[0016] The service key 104 used in the encryption service is data that must be stored in secret. To reduce the risk of leakage of the service key 104, the encryption key management device 10 encrypts the service key 104 with a different encryption key and stores it in the database 102. Encrypting with an encryption key means encrypting using an encryption key. In this application, an encryption key that is not common to the encryption key management device 10 but is unique to the encryption key management device 10 is used to encrypt the service key 104 stored in the database 102. In this application, an encryption key that is unique to the encryption key management device 10 and that encrypts the service key 104 stored in the database 102 is called a master key 103. The reason why the master key 103 is unique to the encryption key management device 10 despite the redundant configuration of the encryption management device is to reduce the risk of leakage of the master key 103.
[0017] When a plurality of encryption key management devices 10 are configured redundantly, if a service key 104 is added / deleted or updated in one encryption key management device 10, it becomes necessary to synchronize the databases 102 between the redundantly configured encryption key management devices 10. If the master key 103 used to encrypt the service key 104 is made unique in each encryption key management device 10, the master key 103 must be transmitted and received confidentially between the encryption key management devices 10, which complicates the process for synchronizing the databases 102 and increases the cost for synchronizing the databases 102.
[0018] Therefore, in the encryption key synchronization system 1 according to the embodiment, a synchronization management device 11 that generates a transport key 111, which serves as a common encryption key for the redundantly configured encryption key management devices 10, is provided separately from the encryption key management devices 10. If the common transport key 111 is used by the multiple redundantly configured encryption key management devices 10 to perform processing related to synchronization of the databases 102, transmission and reception of the master key 103 between the encryption key management devices 10 becomes unnecessary, and processing related to synchronization of the databases 102 can be simplified. If processing related to synchronization of the databases 102 can be simplified, costs related to synchronization of the databases 102 can also be reduced.
[0019] The encryption key management device 10 will now be described in detail with reference to Fig. 2. Fig. 2 is a block diagram of the encryption key management device 10.
[0020] The encryption key management device 10 included in the encryption key synchronization system 1 is realized using a general-purpose server. The encryption key management device 10 is the central part of the encryption key management device 10 and includes a processor 105a that processes data according to program instructions, a large-capacity storage device 105b such as a hard disk or SSD (Solid State Drive) for saving data, and an HSM 101 (Hardware Security Module) that is a dedicated device for protecting encryption keys.
[0021] Naturally, the encryption key management device 10 realized using a general-purpose server includes hardware necessary for a general-purpose server, such as RAM (Random Access Memory), a network interface for connecting to a network, and a power supply unit, which are not shown in Fig. 2. The encryption key management device 10 realized using a general-purpose server also includes software necessary for a general-purpose server, such as an operating system, which is the basic software for general-purpose servers, which are not shown in Fig. 2.
[0022] The HSM 101 included in the encryption key management device 10 is a device that performs encryption calculations using this master key 103. Although not shown, the HSM 101 also includes a memory for securely storing data. The HSM 101 included in the encryption key management device 10 stores in this memory a master key 103, which is an encryption key unique to each encryption key management device 10 and is used to encrypt a service key 104 stored in a database 102.
[0023] A database 102 is constructed in the storage 105b of the encryption key management device 10 to store a plurality of service keys 104 used in the encryption services provided by the encryption key management device 10, such as encryption / decryption and digital signature generation. As described above, the database 102 stores not the plaintext of the service key 104, but the service key 104M encrypted with the master key 103 using the HSM 101. Note that the process of encrypting the service key 104 with the master key 103 is executed secretly inside the HSM 101.
[0024] When used in the cryptographic service provided by the cryptographic key management device 10, the service key 104M encrypted with the master key 103 is input to the HSM 101. The HSM 101 decrypts the service key 104M encrypted with the master key 103 with the master key 103, and then uses the plaintext of the decrypted service key 104 to perform the cryptographic processing instructed by the HSM 101 (encryption / decryption of data, generation of a digital signature, etc.).
[0025] The HSM 101 included in the encryption key management device 10 is used not only for the encryption service provided by the encryption key management device 10, but also for processing related to synchronization of the database 102. When the HSM 101 is used for synchronization of the database 102, a transport key 111 common to multiple redundantly configured encryption key management devices 10 is transmitted from the synchronization management device 11 to the encryption key management device 10. In processing related to synchronization of the database 102, the HSM 101 of the encryption key management device 10 whose database 102 has been updated performs processing to re-encrypt the service key 104 using the master key 103 with encryption using the transport key 111. In addition, the HSM 101 of the encryption key management device 10 whose database 102 has not been updated performs processing to re-encrypt the service key 104 using the transport key 111 with encryption using the master key 103.
[0026] The encryption key management device 10 includes a synchronization means 100 that executes processing related to synchronization of the databases 102 as a function utilizing the processor 105a of the encryption key management device 10. A computer program for causing the processor 105a of the encryption key management device 10 to operate as the synchronization means 100 is implemented in the storage 105b of the encryption key management device 10.
[0027] The processing executed by the synchronization means 100 of the encryption key management device 10 will be described in detail. Fig. 3 is a diagram illustrating the synchronization start processing executed by the synchronization means 100 of the encryption key management device 10. Fig. 4 is a diagram illustrating the update content transmission processing executed by the synchronization means 100 of the encryption key management device 10. Fig. 5 is a diagram illustrating the database update processing executed by the synchronization means 100 of the encryption key management device 10.
[0028] The synchronization means 100 included in the encryption key management device 10 executes processing in accordance with instructions sent from the synchronization management device 11. In the present application, the instructions sent from the synchronization management device 11 include a synchronization start instruction, an update content transmission instruction, and a database update instruction.
[0029] 3, the synchronization start processing executed by the synchronization means 100 included in the encryption key management device 10 will be described. When the synchronization means 100 included in the encryption key management device 10 receives a synchronization start instruction from the synchronization management device 11 (step S1), it requests the synchronization management device 11 to transmit the transport key 111 (step S2). When the synchronization means 100 included in the encryption key management device 10 receives the ciphertext of the encrypted transport key 111 from the synchronization management device 11 (step S3), it decrypts the ciphertext of the transport key 111 using an encryption key that is paired with the encryption key that encrypted the transport key 111, and obtains the transport key 111 to be used in synchronization of the database 102 (step S4). Then, the synchronization means 100 included in the encryption key management device 10 notifies the synchronization management device 11 of the completion of the synchronization start processing (step S5), and the procedure in FIG. 3 ends. The synchronization management device 11 encrypts the transport key 111 to be transmitted to the encryption key management device 10 in order to prevent the transport key 111 from being leaked.
[0030] For example, a public key cryptosystem can be used to encrypt the transport key 111. In this case, the encryption key management device 10 stores its own private key, and the synchronization management device 11 stores the public key of the encryption key management device 10 for each encryption key management device 10. The synchronization management device 11 encrypts the transport key 111 using the public key of the encryption key management device 10, and the synchronization means 100 of the encryption key management device 10 decrypts the transport key 111 encrypted with the public key using the private key.
[0031] 4, an explanation will be given of the update content transmission process executed by the synchronization means 100 included in the encryption key management device 10. The update content transmission process is a process executed by the encryption key management device 10 when the database 102 is updated in the device itself.
[0032] When the synchronization means 100 provided in the encryption key management device 10 receives the instruction to send updated content from the synchronization management device 11, it starts an updated content sending process to transfer the service key 104 that has been updated in the database 102 (step S10). The updated service key 104 may be a part or all of the service keys 104 stored in the database 102 of the encryption key management device 10.
[0033] The synchronization means 100 included in the encryption key management device 10 obtains the service key 104M corresponding to the updated service key 104 from the database 102 (step S11). As described above, the service key 104M stored in the database 102 becomes the service key 104 encrypted with the master key 103. The synchronization means 100 included in the encryption key management device 10 requests the HSM 101 to re-encrypt the service key 104M obtained in step S11 using the master key 103 with the transport key 111 (step S12). When requesting re-encryption using the transport key 111, the synchronization means 100 included in the encryption key management device 10 inputs the service key 104M encrypted with the master key 103 and the transport key 111 to the HSM 101.
[0034] The HSM 101 uses the master key 103 stored in the HSM 101 to decrypt the service key 104M encrypted with the master key 103 to obtain the plaintext of the service key 104, and re-encrypts it with the transport key 111 input to the HSM 101 (step S13), and outputs the service key 104D re-encrypted with the transport key 111 to the synchronization means 100 (step S14). The encryption key management device 10 transmits the service key 104D re-encrypted with the transport key 111 to the synchronization management device 11 (step S15), and the procedure in Fig. 4 ends.
[0035] In this embodiment, the encryption key management device 10 whose database 102 has been updated is the encryption key management device 10a. In this case, the synchronization management device 11 transmits an instruction to transmit updated contents to the encryption key management device 10a, and the encryption key management device 10a executes the updated contents transmission process shown in Fig. 4. In step S15 of Fig. 4, the synchronization means 100 of the encryption key management device 10a re-encrypts the service key 104M updated in its own database 102a using the master key 103a with the transport key 111, and transmits the re-encrypted service key 104M to the synchronization management device 11.
[0036] 5, the database update process executed by the synchronization means 100 included in the encryption key management device 10 will be described. The database update process is a process executed by the encryption key management device 10 when the database 102 is updated in another encryption key management device 10.
[0037] When the synchronization means 100 included in the encryption key management device 10 receives the database update instruction from the synchronization management device 11, it starts a database update process for updating the database 102 included in the encryption key management device 10 (step S20). The database update instruction received from the synchronization management device 11 includes a service key 104 used to update the database 102, and this service key 104 is encrypted with a transport key 111.
[0038] The synchronization means 100 included in the encryption key management device 10 requests the HSM 101 to re-encrypt the service key 104D received from the synchronization management device 11 using the transport key 111 with the master key 103 (step S21). When requesting re-encryption using the transport key 111, the synchronization means 100 included in the encryption key management device 10 inputs the service key 104D encrypted with the transport key 111 and the transport key 111 into the HSM 101.
[0039] The HSM 101 uses the transport key 111 input to the HSM 101 to decrypt the service key 104D that has been encrypted using the transport key 111 to obtain the plaintext of the service key 104, and then re-encrypts it using the master key 103 stored in the HSM 101 (step S22), and outputs the service key 104M that has been re-encrypted using the master key 103 to the synchronization means 100 (step S23).
[0040] The synchronization means 100 provided in the encryption key management device 10 updates the database 102 provided in the device itself using the service key 104M that has been re-encrypted using the master key 103 (step S24), and when the update of the database 102 provided in the device itself is completed, it notifies the synchronization management device 11 of the completion of the update of the database 102 (step S25), and the procedure in Figure 5 is terminated.
[0041] If the service key 104 to be updated is registered in the database 102 included in the encryption key management device 10, the synchronization means 100 included in the encryption key management device 10 deletes the service key 104 registered in the database 102 included in the device and adds the service key 104M output by the HSM 101 to the database 102. If the service key 104 to be updated is not registered in the database 102 included in the device, the synchronization means 100 adds the service key 104 output by the HSM 101 to the database 102 as a new key.
[0042] In the embodiment, the synchronization management device 11 transmits a database update instruction to the encryption key management devices 10b and 10c whose databases 102 have not been updated, and the encryption key management devices 10b and 10c execute the database update process shown in Fig. 5. In step S22 of Fig. 5, the HSM 101 of the encryption key management device 10b decrypts the service key 104D encrypted with the transport key 111 to obtain the plaintext of the service key 104, and then re-encrypts it with the master key 103b stored in the HSM 101, and the synchronization means 100 of the encryption key management device 10b updates the database 102b using the service key 104M re-encrypted with the master key 103b. Also, in step S22 of FIG. 5, the HSM 101 of the encryption key management device 10c decrypts the service key 104D encrypted using the transport key 111 to obtain the plaintext of the service key 104, and then re-encrypts it using the master key 103c stored in the HSM 101. The synchronization means 100 of the encryption key management device 10c updates the database 102c using the service key 104M that has been re-encrypted using the master key 103c.
[0043] The synchronization management device 11 will now be described in detail with reference to Fig. 6. Fig. 6 is a block diagram of the synchronization management device 11.
[0044] The synchronization management device 11 included in the encryption key synchronization system 1 is realized using a general-purpose server, similar to the encryption key management device 10. The synchronization management device 11 is the central part of the synchronization management device 11, and includes a processor 111a that processes data according to program instructions, and a large-capacity storage 111b.
[0045] Naturally, the synchronization management device 11 realized using a general-purpose server includes hardware necessary for a general-purpose server, such as RAM (Random Access Memory), a network interface for connecting to a network, and a power supply unit, which are not shown in Fig. 6. In addition, the synchronization management device 11 realized using a general-purpose server includes software necessary for a general-purpose server, such as an operating system, which is the basic software for the general-purpose server, which are not shown in Fig. 6.
[0046] The synchronization management device 11 includes a synchronization management means 110 that monitors the database 102 of each of the redundantly configured multiple encryption key management devices 10, and when a change occurs in at least one of the databases 102, generates a common transport key 111 in the redundantly configured encryption key management devices 10 and executes processing related to the synchronization of the databases 102, as a function that utilizes the processor 111a of the synchronization management device 11. A computer program for causing the processor 111a of the synchronization management device 11 to function as the synchronization management means 110 is stored in the storage 111b of the synchronization management device 11.
[0047] One possible method for monitoring the database 102 of each of the multiple redundantly configured encryption key management devices 10 is to store metadata (such as the name of the service key 104 and the update date) of the database 102 of each of the multiple redundantly configured encryption key management devices 10 in the storage 111b of the synchronization management device 11, and periodically check for updates to the database 102 using the metadata. Another possible method is to install a computer program in the encryption key management device 10 that monitors updates to the database 102, and receive update notifications for the database 102 from this computer program in real time.
[0048] The following describes in detail the processing executed by the synchronization management means 110 included in the synchronization management device 11. Fig. 7 is a diagram illustrating the processing executed by the synchronization management means 110 included in the synchronization management device 11. The description of the processing executed by the synchronization management means 110 included in the synchronization management device 11 also serves as a description of the encryption key synchronization method, which is a method invention of the present application.
[0049] The synchronization management means 110 included in the synchronization management device 11 monitors the database 102 of each of the multiple redundantly configured encryption key management devices 10 (step S30), and upon detecting an update to at least one of the databases 102, generates a transport key 111 (step S31) and then transmits a synchronization start instruction to all of the multiple redundantly configured encryption key management devices 10 (step S32). The synchronization means 100 of the encryption key management device 10 that has received the synchronization start instruction executes the synchronization start processing described with reference to FIG. 3 (step S33), and upon completion of the synchronization start processing, transmits a notification of the completion of the synchronization start processing to the synchronization management device 11 (step S34). In the embodiment, the synchronization start instruction is transmitted to all of the multiple redundantly configured encryption key management devices 10a to 10c.
[0050] When the completion of the synchronization start process is notified from all of the multiple redundantly configured encryption key management devices 10, the synchronization management means 110 included in the synchronization management device 11 sends an update content transmission instruction to the encryption key management device 10 whose database 102 has been updated (step S35). The synchronization means 100 of the encryption key management device 10 that has received the update content transmission instruction executes the update content transmission process described with reference to FIG. 4 (step S36) and transmits the service key 104D that has been re-encrypted using the transport key 111 to the synchronization management device 11 (step S37). In this embodiment, the encryption key management device 10 whose database 102 has been updated is the encryption key management device 10a. Therefore, in step S35, the synchronization management means 110 included in the synchronization management device 11 sends an update content transmission instruction to the encryption key management device 10a, and in step S36, the synchronization means 100 of the encryption key management device 10a executes the update content transmission process.
[0051] Next, the synchronization management means 110 of the synchronization management device 11 transmits a database update instruction including the service key 104 that has been re-encrypted using the transport key 111 to all of the encryption key management devices 10 except for the encryption key management device 10 whose database 102 has been changed (step S38). The synchronization means 100 of the encryption key management device 10 that received the database update instruction executes the database update process described with reference to FIG. 5 (step S39) and transmits a notification of completion of updating the database 102 to the synchronization management device 11 (step S40). When all of the encryption key management devices 10 that transmitted the database update instruction notify the synchronization management device 11 of the completion of updating the database 102, this procedure ends. In this embodiment, the encryption key management device 10 whose database 102 has been updated is the encryption key management device 10a. Therefore, in step S38, the synchronization management means 110 provided in the synchronization management device 11 sends a database update instruction to each of the encryption key management device 10b and the encryption key management device 10c, and in step S39, the synchronization means 100 of the encryption key management device 10b and the synchronization means 100 of the encryption key management device 10c each executes a database update process.
[0052] In this way, the encryption key synchronization system 1 according to the embodiment is configured such that the synchronization management device 11 generates a common transport key 111 among the redundantly configured encryption key management devices 10, and an encryption key management device 10 that has had an update to its database 102 uses the synchronization management device 11 to distribute the updated contents of the database 102 (which becomes the service key 104D encrypted with the transport key 111) to the other encryption key management devices 10. In the encryption key synchronization system 1 according to the embodiment, the master key 103 unique to each encryption key management device 10 is not sent or received, which simplifies the processing related to the synchronization of the databases 102, and as a result, the cost related to the synchronization of the databases 102 is also reduced.
[0053] Since the synchronization management device 11 is a device that connects to all of the redundantly configured encryption key management devices 10, it is possible to have the synchronization management device 11 not only update the service key 104 or add a new service key 104, but also update the database 102 related to the deletion of a service key 104. In this case, the synchronization management device 11 obtains information identifying the deleted service key 104 from the encryption key management device 10 from which the service key 104 was deleted, distributes this information to the other encryption key management devices 10, and deletes the service key 104 deleted from one encryption key management device 10 from all of the multiple redundantly configured encryption key management devices 10. [Explanation of symbols]
[0054] 1. Cryptographic key synchronization system 10 Encryption key management device 100 Synchronization Means 101 HSM 102 databases 103 Master Key 104 Service Key 104M Service key encrypted with master key 105D Service key encrypted with transport key 11 Synchronization management device 110 Synchronization management means 111 Transport Key
Claims
1. a plurality of redundantly configured encryption key management devices and a synchronization management device that manages synchronization of the encryption key management devices; the encryption key management device includes an HSM (Hardware Security Module) that stores a master key unique to each encryption key management device and performs cryptographic calculations using at least the master key, a database that stores one or more service keys encrypted with the master key using the HSM, and synchronization means that executes processing related to synchronization of the databases; the synchronization means of the encryption key management device in which the database has been updated receives a transport key common to each encryption key management device from the synchronization management device, and then receives an instruction to send updated contents from the synchronization management device, acquires the service key updated in the database from the database, causes the HSM to execute a process of re-encrypting the service key acquired from the database using the master key with the transport key, and transmits the service key re-encrypted using the transport key to the synchronization management device; the synchronization means of the encryption key management device in which the database has not been updated, when receiving from the synchronization management device a database update instruction including the service key encrypted with the transport key after receiving the transport key from the synchronization management device, causes the HSM to execute a process of re-encrypting the service key included in the database update instruction with the transport key using the master key, and performs a process of updating the database using the service key re-encrypted with the master key; The synchronization management device comprises a synchronization management means for monitoring update of the database for each of the encryption key management devices, and when an update of the database is detected, generating the transport key and transmitting it to each of the encryption key management devices, then transmitting the update content transmission instruction to the encryption key management device in which the database has been updated, acquiring the service key encrypted with the transport key from the encryption key management device that transmitted the update content transmission instruction, and transmitting the database update instruction including the service key encrypted with the transport key to all of the encryption key management devices other than the encryption key management device in which the database has been updated.
1. A cryptographic key synchronization system comprising:
2. 2. An encryption key management device constituting the encryption key synchronization system according to claim 1.
3. 2. A synchronization management device constituting the encryption key synchronization system according to claim 1.
4. A method executed by a plurality of redundantly configured encryption key management devices and a synchronization management device that manages synchronization of the encryption key management devices, comprising: the encryption key management device includes an HSM (Hardware Security Module) that stores a master key unique to each encryption key management device and performs cryptographic calculations using at least the master key, and a database that stores one or more service keys encrypted with the master key using the HSM; a step a) in which the synchronization management device monitors updates to the database for each of the encryption key management devices, and when an update to the database is detected, generates a transport key and transmits the transport key to each of the encryption key management devices; a step b in which the synchronization management device transmits an instruction to transmit updated contents to the encryption key management device in which the database has been updated, and the encryption key management device, upon receiving the instruction to transmit updated contents, retrieves the service key updated in the database from the database, and then causes the HSM to execute a process of re-encrypting the service key retrieved from the database using the master key with encryption using the transport key, and transmits the service key re-encrypted using the transport key to the synchronization management device; and a step c) in which, when the synchronization management device receives the service key encrypted with the transport key from the encryption key management device that sent the update content transmission instruction, the synchronization management device sends a database update instruction including the service key received from the encryption key management device to each of the other encryption key management devices that do not have their databases updated, and the encryption key management device that has received the database update instruction causes the HSM to re-encrypt the service key included in the database update instruction from the transport key to the master key, and updates the database using the service key re-encrypted with the master key.
Citation Information
Patent Citations
Key generation control device and key generation storage system
JP2015061267A
On-vehicle computer system, vehicle, management method, and computer program
JP2018023162A