Wireless communication terminal device, authentication and key sharing method, program, and authentication and key sharing system

By adopting the encryption method of authentication enabled in the 6G mobile communication network, the authentication and key sharing process between the terminal device and the network is simplified, and the complexity of the authentication and key sharing method in the 6G network is solved, and efficient, easy-to-use and secure communication performance is achieved.

JP7674973B2Active Publication Date: 2025-05-12KDDI CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2021149641
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-14
Publication Date
2025-05-12
Estimated Expiration
2041-09-14

AI Technical Summary

Technical Problem

In 6G mobile communication networks, authentication and key sharing methods between terminal devices and networks need to be simplified to improve communication performance and security.

Method used

Using authentication-enabled encryption as the basic method, authentication and key sharing are realized by generating random numbers between the terminal device and the authentication server and performing authentication encryption processing.

Benefits of technology

Improves the efficiency and ease of use of certification processing, while maintaining a high level of security, suitable for the needs of 6G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007674973000001
    Figure 0007674973000001
  • Figure 0007674973000002
    Figure 0007674973000002
  • Figure 0007674973000003
    Figure 0007674973000003
Patent Text Reader

Abstract

To more easily execute authentication processing between a wireless terminal and a network while maintaining security.SOLUTION: A wireless communication terminal device 10 comprises: a control unit 11; and a storage unit 12 that stores a unique key. The control unit 11 comprises: an authentication request unit 111 that generates a first random number and transmits an authentication request including the first random number and identification information of the wireless communication terminal device 10 to a base station; an authenticated encryption key generation unit 112 that receives a response request including a second random number and an authenticated encryption sentence of the second random number from the base station that has acquired the second random number generated by an authentication server that has received the authentication request from the base station, authenticated encryption sentences of the first and second random numbers, an authenticated encryption sentence of the second random number, and an authenticated encryption key, and calculates an authenticated encryption key on the basis of the first and second random numbers and the unique key; and a response processing unit 113 that returns a response including the authenticated encryption sentence of the second random number generated on the basis of the calculated authenticated encryption key to the base station.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a wireless communication terminal device, an authentication and key sharing method, a program, and an authentication and key sharing system. [Background technology]

[0002] 5G networks are becoming widely used as a platform for high-speed mobile communications. In the security of the 5G network, with regard to the interconnection authentication between a wireless communication terminal device and the network, a unique secret key (K) written in a SIM card of the terminal device is shared with an authentication device on the network side, and an encryption key (CK) and an authentication key (IK) used for communication are dynamically generated from the secret key (K). Therefore, in the connection authentication between the terminal device and the network, three types of algorithms are used for key generation processing from the secret key (K), encryption processing using the generated encryption key (CK) and authentication key (IK), and authentication processing. Such a security configuration of the 5G network is disclosed in, for example, Non-Patent Document 1. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] 3GPP TS 33.102 V16.0.0(2020-07), Technical Specification, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Security architecture (Release 16) Summary of the Invention [Problem to be solved by the invention]

[0004] Currently, technical specifications for the sixth generation mobile communication system (6G), which will be faster, have lower latency, and offer excellent connectivity, are being considered. In order to improve communication performance such as high speed in the 6G network, security-related data processing must be as compact as possible. In this regard, there was an issue that the authentication and key sharing methods between terminal devices and the network also needed to be simplified compared to those for the 5G network.

[0005] One object of the present invention is to provide a wireless communication terminal device, an authentication and key sharing method, a program, and an authentication and key sharing system that can make the protocol more efficient and more simply execute authentication processing between a wireless communication terminal device and a network in a mobile communication network while maintaining a required security level by using authenticated encryption as a primitive. [Means for solving the problem]

[0006] A wireless communication terminal device according to one aspect of the present invention includes a control unit, a memory unit that stores a unique key shared with an authentication server, and a communication unit. The control unit includes an authentication request unit that generates a first random number and transmits an authentication request including the first random number and identification information of the wireless communication terminal device to a base station via the communication unit. The control unit includes: an authentication request unit that receives a second random number generated by the authentication server that has received the authentication request from the base station, an authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number, an authenticated ciphertext obtained by authenticating and encrypting the second random number, and an authenticated encryption key. The control unit includes:

[0007] The authentication request unit may transmit an authentication request, which is generated by encrypting the first random number and identification information of the wireless communication terminal device using a public key of the wireless communication terminal device, to a base station via the communication unit.

[0008] The authenticated encryption key generation unit may generate an authentication key and an encryption key based on the first random number, the second random number, and the unique key using two different key generation functions.

[0009] The authenticated encryption key generation unit may generate the authenticated encryption key based on the first random number, the second random number, and the unique key using one key generation function.

[0010] The authenticated encryption key generation unit may determine the validity of the calculated authenticated encryption key based on an authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number included in the response request received from the base station.

[0011] Another aspect of the present invention is an authentication and key sharing method, which is performed by a wireless communication terminal device including a control unit, a storage unit that stores a unique key shared with an authentication server, and a communication unit, and which includes the following steps: an authentication request step of generating a first random number and transmitting an authentication request including the first random number and identification information of the wireless communication terminal device to a base station via the communication unit; an authentication encryption key generation step of receiving a second random number generated by the authentication server that has received the authentication request from the base station, an authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number, an authenticated ciphertext obtained by authenticating and encrypting the second random number, and an authenticated encryption key, from the base station which has acquired the second random number and the authenticated ciphertext, and calculating an authenticated encryption key based on the first random number, the second random number, and the unique key; and a response processing step of authenticating and encrypting the second random number with the authenticated encryption key calculated in the authenticated encryption key generation step, and returning a response including the authenticated ciphertext to the base station via the communication unit.

[0012] Yet another aspect of the present invention is a program for causing a computer to function as the wireless communication terminal device.

[0013] Yet another aspect of the present invention is an authentication and key sharing system including a wireless communication terminal device, a base station, and an authentication server, the wireless communication terminal device including a control unit, a storage unit for storing a unique key shared with the authentication server, and a communication unit, the control unit including an authentication request unit for generating a first random number and transmitting an authentication request including the first random number and identification information of the wireless communication terminal device to a base station via the communication unit, a second random number generated by the authentication server receiving the authentication request from the base station, and an authentication key obtained by authenticating and encrypting the first random number and the second random number. an authenticated encryption key generation unit that receives a response request including the second random number and the authenticated ciphertext from the base station that has acquired the authenticated ciphertext, the authenticated ciphertext obtained by authenticating and encrypting the second random number, and the authenticated encryption key, and calculates an authenticated encryption key based on the first random number, the second random number, and the unique key; and a response processing unit that authenticates and encrypts the second random number using the authenticated encryption key calculated by the authenticated encryption key generation unit, and returns a response including the authenticated ciphertext to the base station via the communication unit, The base station includes a control unit and a communication unit, and the control unit receives an authentication request including the first random number and identification information of the wireless communication terminal device from the wireless communication terminal device via the communication unit and transmits the received authentication request to the authentication server, and receives from the authentication server via the communication unit an authentication vector including the second random number generated by the authentication server, an authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number, an authenticated ciphertext obtained by authenticating and encrypting the second random number, and an authenticated encryption key. an authentication vector receiving unit for receiving an authentication vector from the base station via the communication unit, the authentication vector receiving unit receiving a response request including the second random number and identification information of the wireless communication terminal device via the communication unit, the authentication server including a control unit and a communication unit, the control unit receiving an authentication request including the first random number and identification information of the wireless communication terminal device via the communication unit from the base station, the control unit generating the second random number, and calculating an authenticated encryption key based on the first random number, the second random number, and the unique key,an authentication vector generation unit that calculates an authenticated ciphertext by authenticating and encrypting the first random number and the second random number, and that calculates an authenticated ciphertext by authenticating and encrypting the second random number to generate the authentication vector and transmits the authentication vector to the base station via the communication unit.

[0014] In the authentication and key sharing system, the authentication request unit may transmit an authentication request, in which the first random number and identification information of the wireless communication terminal device are encrypted using a public key of the wireless communication terminal device, to a base station via the communication unit, the authentication request forwarding unit transmits the authentication request to the authentication server, and the authentication request receiving unit may receive the authentication request via the communication unit and decrypt it using a private key to obtain the first random number and the identification information of the wireless communication terminal device. Effect of the Invention

[0015] According to the present invention, by using authenticated encryption as a primitive, it is possible to make the protocol more efficient and to execute authentication processing between a wireless communication terminal device and a network in a mobile communication network more simply while maintaining a required security level. [Brief description of the drawings]

[0016] [Figure 1] 1 is a diagram showing an example of the configuration of a mobile communication network having an authentication and key sharing system in one embodiment of the present invention. [Diagram 2] 1 is a block diagram showing an example of a configuration of a wireless communication terminal device according to an embodiment; [Diagram 3] FIG. 2 is a block diagram showing a configuration example of a base station according to an embodiment. [Figure 4] FIG. 2 is a block diagram illustrating a configuration example of an authentication server according to an embodiment. [Diagram 5] FIG. 2 is a diagram illustrating a flow of a key generation process implemented in an authentication and key sharing system in an embodiment. [Figure 6]2 is a sequence diagram illustrating the flow of data processing executed by the authentication and key sharing system according to one embodiment of the present invention; FIG. [Figure 7] FIG. 11 is a sequence diagram illustrating the flow of data processing executed by an authentication and key sharing system in a modified embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0017] Hereinafter, the present invention will be described based on an embodiment with reference to the accompanying drawings. FIG. 1 shows a schematic diagram of an example of the overall configuration of a mobile communication system 1 to which an authentication and key sharing system according to an embodiment of the present invention is applied. In the mobile communication system 1 shown in FIG. 1, a wireless communication terminal device 10 (hereinafter, abbreviated as "terminal device 10" unless otherwise required), a base station 20, and an authentication server 30 are communicably connected to a network 40. The network 40 is a network for mobile communication including wireless and wired communication networks. The terminal device 10 is a wireless communication terminal device such as a smartphone or a tablet terminal, and can communicate with other terminal devices 10 via wireless communication with the base station 20. The base station 20 mediates communication between the terminal devices 10, and performs authentication processing of the terminal device 10 when communicating with the terminal device 10 through information exchange with the authentication server 30. The authentication server 30 performs various key generation processing and the like required for authentication processing of the terminal device 10 based on shared information such as identification information of the terminal device 10 received from the base station 20. In the authentication and key sharing system according to the present embodiment applied to the mobile communication system 1, authenticated encryption processing is used as an encryption primitive used in the authentication processing between the terminal device and the base station, and the algorithms used when executing the key generation processing, encryption processing, and authentication processing required therefor are unified to reduce data processing associated with the authentication processing and reduce hardware resources. Although not particularly limited, the authentication and key sharing system according to the present embodiment is suitably applied to a sixth generation mobile communication system, so-called 6G.

[0018] Next, a description will be given of the wireless communication terminal device 10, the base station 20, and the authentication server 30. Fig. 2 shows an example of the functional configuration of the wireless communication terminal device 10 in this embodiment. The terminal device 10 is an information processing device (computer) with a communication function, such as a smartphone or a tablet terminal, and includes a control unit 11, a storage unit 12, a communication unit 13, as well as various data input / output devices.

[0019] The control unit 11 is a part that controls the entire terminal device 10, and realizes each function of the terminal device 10 in this embodiment by appropriately reading and executing various programs stored in the storage unit 20. The control unit 10 may be a processor such as a CPU.

[0020] The storage unit 12 is a storage area for various programs and various data for making the hardware group function as the terminal device 10, and may be a ROM, a RAM, a flash memory, or a semiconductor (SSD). Specifically, the storage unit 20 stores a program for making the control unit 10 execute each function of the present embodiment, various parameters, data input from a base station 20 or the like described later, and data such as various keys generated by each functional unit described later. The storage unit 20 includes a storage medium in which identification information unique to the terminal device 10 is stored, such as a SIM card in which identification information of a subscriber in mobile communication is stored. Note that data stored in the SIM card may be stored in the storage unit 12 according to the eSIM standard. The SIM card, which is a part of the storage unit 12, or the data stored through the eSIM standard includes master secret data (unique key) that is input data for a key generation function for generating an authenticated encryption key described later. The storage unit 12 also stores a key generation function for generating the authenticated encryption key. The master secret data and the key generation function are used to generate authenticated ciphertext used in authentication processing between the terminal device 10 and the base station 20, as will be described later. FIG. 5 shows a schematic diagram of a process for generating an authentication key (AK) and an encryption key (EK) for authenticated encryption processing using a predetermined key derivation function (KDF). This key generation function is a function that receives multiple parameters including at least one secret parameter as input and outputs a key suitable for a predetermined algorithm or application (see, for example, ISO / IEC11770-6:2016). In this embodiment, the authentication key (AK) and encryption key (EK) for the authenticated encryption process used as a cryptographic primitive are configured to be generated using a key generation function called Rocca. Rocca is described, for example, in Kosei Sakamoto, Fukang Liu, Yuto Nakano, Shinsaku Kiyomoto, Takanori Isobe, “Rocca: An Efficient AES-based Encryption Scheme for Beyond 5G”, Transactions on Symmetric Cryptology ISSN 2519-173X, Vol. 2021, No. 2, pp. 1-30.

[0021] Specifically, as shown in Fig. 5, as a key generation function KDF, a master secret data, which is a unique key shared between the terminal device 10 and the authentication server 30 via the identification information of the terminal device 10, is input, and a calculation is performed by a key generation function using different combinations of a random number R1 generated by the terminal device 10 and a random number R2 generated by the authentication server 30 (in the example of Fig. 5, a parameter created by concatenating the random number R1 and the random number R2, and a parameter created by concatenating the random number R2 and the random number R1) as keys, and two different outputs are used as an authentication key (AK) and an encryption key (EK) for authenticated encryption processing, respectively. Using the obtained authentication key (AK) and encryption key (EK), an authenticated ciphertext can be used as an encryption primitive that enables secure communication between the terminal device 10 and the base station 20. The method of authenticated encryption may be any of Encrypt-then-MAC (EtM), Encrypt-and-MAC (E&M), and MAC-then-Encrypt (MtE). In this embodiment, two different keys, an authentication key (AK) and an encryption key (EK), are generated. However, only one type of parameter may be used as the key for the key generation function, and authenticated encryption processing may be performed with a single key. In addition, in this embodiment, two different keys are generated by reversing the order in which the two random numbers R1 and R2 are concatenated for the key used by the key generation function. However, it is also possible to leave the order in which the random numbers are concatenated unchanged and add other different numerical values ​​to appropriate positions (for example, it is also possible to concatenate the random number R1 with the random number R2 and add a different number (e.g., 0 or 1) to the beginning of the numbers).

[0022] The communication unit 13 is a communication module for digital wireless communication configured as an integrated circuit component including, for example, various passive devices for processing high frequencies and a processor for amplifying and processing signals, and performs data processing for wireless communication with the base station 20.

[0023] The control unit 11 includes an authentication request unit 111 , an authenticated encryption key generation unit 112 , and a response processing unit 113 . The authentication request unit 111 generates a first random number R1 and transmits it to the base station 20 together with its own identification information as an authentication request. The authenticated encryption key generation unit 112 receives from the base station 20 a response request including the second random number R2 generated by the authentication server 30 and an authenticated ciphertext obtained by authenticating and encrypting the first random number R1 and the second random number R2, and calculates an authenticated encryption key based on the first random number R1, the second random number R2, and master secret data held by the unit 112. The response processing unit 113 authenticates and encrypts the second random number R2 using the authenticated encryption key calculated by the authenticated encryption key generation unit 112, and returns a response including the authenticated ciphertext to the base station 20.

[0024] Next, a description will be given of the base station 20 in this embodiment. Fig. 3 shows an example of the functional configuration of the base station 20 in this embodiment. The base station 20 is an information processing device (computer) such as a server with a communication function or a personal computer, and includes a control unit 21, a storage unit 22, a communication unit 23, as well as input / output devices for various data.

[0025] The control unit 21 is a part that controls the entire base station 20, and realizes each function of the base station 20 in this embodiment by appropriately reading and executing various programs stored in the storage unit 22. The control unit 21 may be a processor such as a CPU.

[0026] The storage unit 22 is a storage area for various programs and various data for making the hardware group function as the base station 20, and may be a ROM, a RAM, a flash memory, a solid-state drive (SSD), a hard disk drive (HDD), etc. Specifically, the storage unit 22 stores programs for making the control unit 21 execute each function of this embodiment, various parameters, data input from the terminal device 10 and an authentication server 30 (described later), etc., various data generated by each functional unit (described later), etc.

[0027] The communication unit 23 is a communication module for digital wireless communication configured as an integrated circuit component including, for example, various passive devices for processing high frequencies and a processor for amplifying and processing signals, and performs data processing for wireless or wired communication between the control unit 21 and the network 40.

[0028] The control unit 21 includes an authentication request transfer unit 211 , an authentication vector receiving unit 212 , and a response request transmitting unit 213 . The authentication request transfer unit 211 receives an authentication request including a first random number R1 and identification information of the terminal device 10 from the terminal device 10, and transmits the request to the authentication server 30. The authentication vector receiving unit 212 receives an authentication vector including a second random number R2 generated by the authentication server 30, an authenticated ciphertext obtained by authenticating and encrypting the first random number R1 and the second random number R2, an authenticated ciphertext obtained by authenticating and encrypting the second random number R2, and an authenticated encryption key from the authentication server 30. The response request transmitting unit 213 transmits a response request including the second random number R2 and the authenticated ciphertext obtained by authenticating and encrypting the first random number R1 and the second random number R2 to the terminal device 10.

[0029] Next, a description will be given of the authentication server 30 in this embodiment. Fig. 4 shows an example of the functional configuration of the authentication server 30 in this embodiment. The authentication server 30 is a server with a communication function or an information processing device (computer) such as a personal computer, and includes a control unit 31, a storage unit 32, a communication unit 33, as well as various data input / output devices.

[0030] The control unit 31 is a part that controls the entire authentication server 30, and realizes each function of the authentication server 30 in this embodiment by appropriately reading and executing various programs stored in the storage unit 32. The control unit 31 may be a processor such as a CPU.

[0031] The storage unit 32 is a storage area for various programs and various data for making the hardware group function as the authentication server 30, and may be a ROM, a RAM, a flash memory, a solid-state drive (SSD), a hard disk drive (HDD), or the like. Specifically, the storage unit 32 stores programs for making the control unit 31 execute each function of this embodiment, various parameters, data input from the base station 20, etc., various data generated by each functional unit described later, and the like. The storage unit 32 also stores master secret data, which is input data for a key generation function for generating an authenticated encryption key, in association with unique identification information of the terminal device 10, and is shared with each terminal device 10.

[0032] The communication unit 33 is a communication module for digital wireless communication configured as an integrated circuit component including, for example, various passive devices for processing high frequencies and a processor for amplifying and processing signals, and performs data processing for wireless or wired communication between the control unit 31 and the network 40.

[0033] The control unit 31 includes an authentication request receiving unit 311 and an authentication vector generating unit 312 . The authentication request receiving unit 311 receives an authentication request for the terminal device 10 from the base station 20. The authentication vector generating unit 312 generates a second random number R2, calculates an authenticated encryption key based on the first random number R1, the second random number R2, and master secret data associated with the identification information received from the authentication request of the terminal device 10, calculates an authenticated ciphertext obtained by authenticating and encrypting the first random number R1 and the second random number R2, and an authenticated ciphertext obtained by authenticating and encrypting the second random number R2 using the authenticated encryption key, generates an authentication vector, and transmits the authentication vector to the base station 20.

[0034] Next, the authentication process between the terminal device 10 and the base station 20 in the authentication and key sharing system of the present embodiment described above will be described. Fig. 6 is a sequence diagram showing data processing between the terminal device 10, the base station 20, and the authentication server 30 in the mobile communication system for the authentication and key sharing process in the authentication and key sharing system of the present embodiment. In the following description, the same symbols as in Fig. 6 are used for various data transmitted and received between the terminal device 10, the base station 20, and the authentication server 30. When the terminal device 10 starts wireless communication with the base station 20, in step S1, the authentication request unit 111 of the terminal device 10 generates a first random number (R1) and reads its own identification information (ID_A) from the memory unit 12, and generates an authentication request including the first random number (R1) and the identification information (ID_A). In step S2, the authentication request unit 111 transmits the generated authentication request (ID_A, R1) to the base station 20 via the communication unit 13.

[0035] In step S3, the authentication request transfer unit 211 of the base station 20 receives the authentication request (ID_A, R1) from the terminal device 10 via the communication unit . In step S4, the authentication request transfer unit 211 of the base station 20 transmits the received authentication request (ID_A, R1) to the authentication server 30.

[0036] In step S5, the authentication request receiving unit 311 of the authentication server 30 receives an authentication request (ID_A, R1) including a first random number (R1) and identification information (ID_A) of the terminal device 10 from the base station 20 via the communication unit 33. Then, the authentication vector generating unit 312 of the authentication server 30 generates a second random number (R2) and calculates an authenticated encryption key (AK, EK) based on the master secret data associated with the first random number (R1), the second random number (R2), and the identification information (ID_A). Then, the authentication vector creation unit 312 uses the generated authenticated encryption key (AK, EK) to calculate an authenticated ciphertext (AE(R1,R2)) obtained by authenticating and encrypting the first random number (R1) and the second random number (R2), and an authenticated ciphertext (AE(R2)) obtained by authenticating and encrypting the second random number (R2), thereby generating an authentication vector (R2,AE(R1,R2),AE(R2),AK,EK) including the second random number (R2), the authenticated ciphertext (AE(R1,R2)), (AE(R2), and the authenticated encryption key (AK,EK). In step S6, the authentication vector generation unit 312 of the authentication server 30 transmits the generated authentication vector (R2, AE(R1, R2), AE(R2), AK, EK) to the base station 20 via the communication unit 33.

[0037] In step S7, the authentication vector receiving unit 212 of the base station 20 receives the authentication vector transmitted by the authentication server 30 via the communication unit . In step S8, the response request sending unit 213 of the base station 20 sends a response request (R2, AE(R1, R2)) including the second random number (R2) contained in the received authentication vector (R2, AE(R1, R2), AE(R2), AK, EK) and the authenticated ciphertext (AE(R1, R2)) to the terminal device 10 via the communication unit 23.

[0038] In step S9, the authenticated encryption key generation unit 112 of the terminal device 10 receives a response request (R2, AE(R1, R2)) including the second random number (R2) and the authenticated ciphertext (AE(R1, R2)) received from the base station 20, and calculates an authenticated encryption key (AK, EK) using the first random number (R1) that it has generated and held, the received second random number (R2), and the master secret data that it has stored. Then, the response processing unit 113 of the terminal device 10 authenticates and encrypts the second random number (R2) using the authenticated encryption key (AK, EK) calculated by the authenticated encryption key generation unit 112, and generates a response (AE(R2)) including the authenticated ciphertext (AE(R2)). In step S10, the response processing unit 113 of the terminal device 10 transmits the generated authenticated ciphertext (AE(R2)) to the base station 20 via the communication unit 13. In step S11, the base station 20 compares the authenticated ciphertext (AE(R2)) received from the terminal device 10 with the authenticated ciphertext (AE(R2)) that it had already received and stored from the authentication server 30 in step S7, and if the two match, it determines that the terminal device 10 has been authenticated and continues wireless communication with the terminal device 10.

[0039] As described above, according to the authentication and key sharing system of the present embodiment, by using authenticated encryption as a primitive, it becomes possible to perform authentication, encryption, and key generation (key sharing) in one stage between the terminal device 10 and the base station 20, thereby improving security and making the protocol more efficient. In addition, it is possible to reduce the mounting area of ​​the chip that executes the protocol and simplify the application that executes the protocol. In addition, by using authenticated encryption as a cryptographic primitive, it is possible to simultaneously realize encryption and message authentication in the authentication and key sharing process.

[0040] Next, a modified example of the authentication and key sharing system in this embodiment will be described. Fig. 7 shows a sequence diagram relating to the modified example and corresponding to Fig. 6. In Fig. 7, the same reference numerals are used to denote process steps corresponding to those in Fig. 6. The authentication and key sharing process in the modified example is different in that a message transmitted from the terminal device 10 is encrypted when the terminal device 10 and the base station 20 start wireless communication. The message transmitted from the terminal device 10 to the base station 20 is encrypted by a public key cryptosystem and can be decrypted by the authentication server 30 which holds a private key for decryption in advance.

[0041] 7, in step S1A, the authentication request unit 111 of the terminal device 10 generates an authentication request (ID_A, R1) including a first random number (R1) and identification information (ID_A), and generates a ciphertext (Pub(ID_A, R1)) by encrypting the request with a public key. This ciphertext (Pub(ID_A, R1)) is received by the authentication server 30 through the processing steps of steps S2A to S5A. In the authentication server 30, the authentication request receiving unit 311 decrypts the received ciphertext (Pub(ID_A, R1)) with the private key held by the authentication server 30. Thereafter, the same processing as in the sequence diagram of FIG. 6 is performed. According to such a modified example, in addition to the effects achieved by the authentication and key sharing system in the present embodiment described above, since the message including the identification information (ID_A) sent from the terminal device 10 is encrypted, there is no risk of the identification information (ID_A) being known to a third party through eavesdropping, and the security level is further improved.

[0042] The authenticated encryption key generation unit 112 may generate an authentication key and an encryption key based on the first random number R1, the second random number R2, and the unique key using two different key generation functions. In this way, different keys are used for authentication and encryption, so that the security of communications can be further improved.

[0043] The authenticated encryption key generation unit 112 may generate the authenticated encryption key based on the first random number R1, the second random number R2, and the unique key using one key generation function. In this way, the load required for the process of generating an authenticated encryption key can be reduced.

[0044] The authenticated encryption key generation unit 112 may determine the validity of the calculated authenticated encryption key based on an authenticated ciphertext obtained by authenticating and encrypting the first random number R1 and the second random number R2 included in the response request received from the base station 20. In this way, the validity of the authenticated encryption key is guaranteed, and therefore the security of the communication between the terminal device 10 and the base station 20 is improved.

[0045] In addition, by using authenticated encryption as a primitive according to the above-mentioned embodiment, for example, it is possible to improve the security of communication via a network and to make the protocol more efficient. In addition, it is possible to reduce the mounting area of ​​the chip that executes the protocol and to simplify the application that executes the protocol, which makes it possible to contribute to Goal 9 of the Sustainable Development Goals (SDGs) led by the United Nations, "Build resilient infrastructure, promote sustainable industrialization and foster innovation."

[0046] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Furthermore, the effects described in the above-described embodiments are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.

[0047] The authentication and key sharing method in this embodiment is realized by software. When realized by software, a program constituting this software is installed in an information processing device (computer). These programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a Web service via a network without being downloaded. [Explanation of symbols]

[0048] 10 Wireless communication terminal equipment 11 Control section 111 Authentication request section 112 Authenticated encryption key generation unit 113 Response processing unit 12 Storage section 13. Communications Department 20 base station 21 Control section 211 Authentication Request Transfer Unit 212 Authentication Vector Reception Unit 213 Response request sending part 22 Memory section 23 Communications Department 30 Authentication Server 31 Control Unit 311 Authentication request receiver 312 Authentication Vector Creation Unit 32 Storage section 33 Communications Department 40 Network

Claims

1. An authentication and key sharing system including a wireless communication terminal device, a base station, and an authentication server, The wireless communication terminal device A control unit; a storage unit that stores a unique key shared with the authentication server; A communication unit, The control unit is an authentication request unit that generates a first random number and transmits an authentication request including the first random number and identification information of the wireless communication terminal device to a base station via the communication unit; an authenticated encryption key generation unit that receives, from the base station which has acquired a second random number generated by the authentication server which has received the authentication request from the base station, an authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number, an authenticated ciphertext obtained by authenticating and encrypting the second random number, and an authenticated encryption key, the response request including the second random number and the authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number, and calculates an authenticated encryption key based on the first random number, the second random number, and the unique key; a response processing unit that performs authenticated encryption on the second random number by using the authenticated encryption key calculated by the authenticated encryption key generation unit, and returns a response including the authenticated ciphertext to the base station via the communication unit, The base station, A control unit and a communication unit are provided, The control unit is an authentication request transfer unit that receives an authentication request including the first random number and identification information of the wireless communication terminal device from the wireless communication terminal device via the communication unit and transmits the received authentication request to the authentication server; an authentication vector receiving unit that receives, via the communication unit, from the authentication server, an authentication vector including the second random number generated by the authentication server, an authenticated ciphertext obtained by authenticating and encrypting the first random number and the second random number, an authenticated ciphertext obtained by authenticating and encrypting the second random number, and an authenticated encryption key; a response request transmission unit that transmits a response request including the second random number included in the authentication vector and the authenticated ciphertext to the wireless communication terminal device via the communication unit, The authentication server, A control unit and a communication unit are provided, The control unit is an authentication request receiving unit that receives an authentication request including the first random number and identification information of the wireless communication terminal device from the base station via the communication unit; an authentication vector generation unit that generates the second random number, calculates an authenticated encryption key based on the first random number, the second random number, and the unique key, calculates an authenticated ciphertext by authenticating and encrypting the first random number and the second random number, and calculates the authenticated ciphertext by authenticating and encrypting the second random number, thereby generating the authentication vector and transmitting it to the base station via the communication unit. Authentication and key sharing system.

2. the authentication request unit transmits an authentication request, which is generated by encrypting the first random number and the identification information of the wireless communication terminal device using a public key of the authentication server, to a base station via the communication unit; The authentication request transfer unit transmits the authentication request to the authentication server, the authentication request receiving unit receives the authentication request via the communication unit, and decrypts the authentication request using a private key to obtain the first random number and identification information of the wireless communication terminal device.

2. The authentication and key sharing system of claim 1.

Citation Information

Patent Citations

  • Data communication method and data communication device

    JP2015126485A

  • Entity authentication method and apparatus based on pre-shared keys

    JP2017529807A