Web conferencing system, client device, client program, server device, and server program

The web conferencing system addresses the inefficiency of multiple key sharing operations by implementing a hierarchical key management structure, where clients share keys only with their parent clients, reducing the number of key sharing operations and enhancing efficiency.

JP7685940B2Active Publication Date: 2025-05-30MITSUBISHI ELECTRIC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021196392
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-02
Publication Date
2025-05-30
Estimated Expiration
2041-12-02

AI Technical Summary

Technical Problem

In web conferencing systems, the existing methods require each participant to perform pairwise key sharing with all other participants, leading to a high number of key sharing operations, which is costly and inefficient.

Method used

The system introduces a mechanism where each client device generates and stores a communication key upon initial participation. Subsequent participations involve key sharing with the parent client, reducing the number of key sharing operations by establishing a hierarchical key management structure.

Benefits of technology

This approach allows each participant to obtain an encryption key through only two rounds of two-party key sharing, significantly reducing the number of key sharing operations and enhancing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007685940000001
    Figure 0007685940000001
  • Figure 0007685940000002
    Figure 0007685940000002
  • Figure 0007685940000003
    Figure 0007685940000003
Patent Text Reader

Abstract

To allow each participant in a web conference to obtain an encryption key for message communication through a small number of times of two-party key sharing.SOLUTION: A client device 200 generates and stores a communication key when the client device participates first, performs key sharing with a parent client when the client device participates second and later, and uses an encrypted communication key from the parent client to decrypt the communication key and store the communication key. If the key sharing with a child client is not performed, the client device 200 performs key sharing with a newly joined client device by making the same the child client, updates the stored communication key by hashing, and transmits the encrypted communication key to the child client, and transmits a participation notification to the parent client. When receiving the participation notification from the child client, the client device 200 updates the stored communication key by the hashing.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a web conferencing system.

Background Art

[0002] In a web conferencing system, messages are encrypted and sent to each participant. The encryption key for message communication is encrypted and sent to each participant. Non-Patent Document 1 describes that each participant performs pairwise key sharing with all other participants.

[0003] When n people participate in a web conference n C 2 times of key sharing are required. Since key sharing is very costly, it is necessary to reduce the number of key sharing operations as much as possible.

Prior Art Documents

Non-Patent Documents

[0004]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] An object of the present disclosure is to enable each participant in a web conference to obtain an encryption key for message communication by performing pairwise key sharing a small number of times.

Means for Solving the Problems

[0006] The web conferencing system of the present disclosure It includes a plurality of client devices participating in a web conference. Each of the plurality of client devices When participating in the web conference for the first time, generates and stores a communication key used for message communication in the web conference. When participating in the web conference for the second time and later, performs key sharing with the client device that has become the parent client during the participation in the web conference, receives the encrypted communication key from the parent client, decrypts the communication key from the encrypted communication key using the shared key with the parent client, and stores the communication key. When not performing the key sharing with the child client during the participation in the web conference, sets the newly participating client device as the child client and performs the key sharing, updates the stored communication key by hashing, encrypts the updated and stored communication key using the shared key with the child client, transmits the encrypted communication key to the child client, and transmits a participation notice to the parent client. When receiving a participation notice from the child client, updates the stored communication key by the hashing.

Advantages of the Invention

[0007] According to the present disclosure, each participant (client device) in a web conference can obtain an encryption key (communication key) for message communication through two rounds of two-party key sharing between the parent participant and the child participant.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Figure 27

Figure 28

Modes for Carrying Out the Invention

[0009] In the embodiments and the drawings, the same elements or corresponding elements are denoted by the same reference numerals. The description of the elements denoted by the same reference numerals as the described elements will be omitted or simplified as appropriate. The arrows in the figures mainly indicate the flow of data or the flow of processing.

[0010] Embodiment 1. The web conferencing system 100 will be described with reference to FIGS. 1 to 23.

[0011] ***Description of Configuration*** Based on FIG. 1, the configuration of the web conferencing system 100 will be described. The web conferencing system 100 includes a plurality of client devices 200 that participate in web conferences. The web conferencing system 100 further includes a server device 300 and a certification authority device 400. The plurality of client devices 200, the server device 300, and the certification authority device 400 communicate with each other via the network 101. A specific example of the network 101 is the Internet.

[0012] Based on FIG. 2, the configuration of the client device 200 will be described. The client device 200 is a computer equipped with hardware such as a processor 201, a memory 202, an auxiliary storage device 203, a communication device 204, and an input / output interface 205. These hardware components are connected to each other via signal lines.

[0013] The processor 201 is an IC that performs arithmetic processing and controls other hardware. For example, the processor 201 is a CPU. IC is an abbreviation for Integrated Circuit. CPU is an abbreviation for Central Processing Unit.

[0014] The memory 202 is a volatile or non-volatile storage device. The memory 202 is also called the main storage device or main memory. For example, the memory 202 is a RAM. The data stored in the memory 202 is saved in the auxiliary storage device 203 as needed. RAM is an abbreviation for Random Access Memory.

[0015] The auxiliary storage device 203 is a non-volatile storage device. For example, the auxiliary storage device 203 is a ROM, HDD, flash memory, or a combination thereof. The data stored in the auxiliary storage device 203 is loaded into the memory 202 as needed. ROM is an abbreviation for Read Only Memory. HDD is an abbreviation for Hard Disk Drive.

[0016] The communication device 204 is a receiver and a transmitter. For example, the communication device 204 is a communication chip or a NIC. The communication of the client device 200 is performed using the communication device 204. NIC is an abbreviation for Network Interface Card.

[0017] The input / output interface 205 is a port to which an input device and an output device are connected. For example, the input / output interface 205 is a USB terminal, the input devices are a keyboard, a mouse, and a microphone, and the output devices are a display and a speaker. The input / output of the client device 200 is performed using the input / output interface 205. USB is an abbreviation for Universal Serial Bus.

[0018] The client device 200 includes elements such as a preparation unit 210, a registration unit 220, a setting unit 230, a participation unit 240, a departure unit 250, and a communication unit 260. These elements are realized by software.

[0019] The auxiliary storage device 203 stores a client program for causing a computer to function as the preparation unit 210, the registration unit 220, the setting unit 230, the participation unit 240, the departure unit 250, and the communication unit 260. The client program is loaded into the memory 202 and executed by the processor 201. The auxiliary storage device 203 further stores an OS. At least a part of the OS is loaded into the memory 202 and executed by the processor 201. The processor 201 executes the client program while executing the OS. OS is an abbreviation for Operating System.

[0020] The input / output data of the client program is stored in the storage unit 290. The memory 202 functions as the storage unit 290. However, storage devices such as the auxiliary storage device 203, the registers in the processor 201, and the cache memory in the processor 201 may function as the storage unit 290 instead of, or together with, the memory 202.

[0021] The client device 200 may include a plurality of processors that replace the processor 201.

[0022] The client program can be recorded (stored) in a computer-readable manner on a non-volatile recording medium such as an optical disk or a flash memory.

[0023] Based on FIG. 3, the functional configuration of the client device 200 will be described. The preparation unit 210 includes a CA certificate acquisition unit 211. The registration unit 220 includes an identification code acquisition unit 221, a signature key generation unit 222, and a CL certificate acquisition unit 223. The setting unit 230 includes a member list generation unit 231, a conference information acquisition unit 232, and a member list correction unit 233. The participation unit 240 includes a conference participation unit 241, a communication key generation unit 242, a key sharing unit 243, a communication key update unit 244, a communication key acquisition unit 245, and a participation notification unit 246. The departure unit 250 includes a departure notification unit 251, a re-sharing unit 252, a new key generation unit 253, and a new key transmission unit 254. The communication unit 260 includes a message transmission unit 261 and a message reception unit 262. "CA" means a certification authority. "CL" means a client.

[0024] Based on FIG. 4, the configuration of the server device 300 will be described. The server device 300 is a computer including hardware such as a processor 301, a memory 302, an auxiliary storage device 303, a communication device 304, and an input / output interface 305. These hardware components are connected to each other via signal lines.

[0025] The processor 301 is an IC that performs arithmetic processing and controls other hardware. For example, the processor 301 is a CPU. The memory 302 is a volatile or non-volatile storage device. The memory 302 is also called a main storage device or a main memory. For example, the memory 302 is a RAM. The data stored in the memory 302 is saved in the auxiliary storage device 303 as needed. The auxiliary storage device 303 is a non-volatile storage device. For example, the auxiliary storage device 303 is a ROM, HDD, flash memory, or a combination thereof. The data stored in the auxiliary storage device 303 is loaded into the memory 302 as needed. The communication device 304 is a receiver and a transmitter. For example, the communication device 304 is a communication chip or a NIC. The communication of the server device 300 is performed using the communication device 304. The input / output interface 305 is a port to which an input device and an output device are connected. For example, the input / output interface 305 is a USB terminal, the input device is a keyboard and a mouse, and the output device is a display. The input / output of the server device 300 is performed using the input / output interface 305.

[0026] The server device 300 includes elements such as an identification code management unit 321, a conference information management unit 331, a participation management unit 341, a departure management unit 351, and a communication management unit 361. These elements are realized by software.

[0027] The auxiliary storage device 303 stores a server program for causing a computer to function as the identification code management unit 321, the conference information management unit 331, the participation management unit 341, the departure management unit 351, and the communication management unit 361. The server program is loaded into the memory 302 and executed by the processor 301. The auxiliary storage device 303 further stores an OS. At least a part of the OS is loaded into the memory 302 and executed by the processor 301. The processor 301 executes the server program while executing the OS.

[0028] The input / output data of the server program is stored in the storage unit 390. The memory 302 functions as the storage unit 390. However, storage devices such as the auxiliary storage device 303, the registers in the processor 301, and the cache memory in the processor 301 may function as the storage unit 390 instead of, or together with, the memory 302.

[0029] The server device 300 may include a plurality of processors that replace the processor 301.

[0030] The server program can be recorded (stored) in a non-volatile recording medium such as an optical disk or a flash memory in a computer-readable manner.

[0031] Based on FIG. 5, the configuration of the certification authority device 400 will be described. The certification authority device 400 is a computer including hardware such as a processor 401, a memory 402, an auxiliary storage device 403, a communication device 404, and an input / output interface 405. These hardware components are connected to each other via signal lines.

[0032] The processor 401 is an IC that performs arithmetic processing and controls other hardware. For example, the processor 401 is a CPU. The memory 402 is a volatile or non-volatile storage device. The memory 402 is also called a main storage device or a main memory. For example, the memory 402 is a RAM. The data stored in the memory 402 is saved in the auxiliary storage device 403 as needed. The auxiliary storage device 403 is a non-volatile storage device. For example, the auxiliary storage device 403 is a ROM, an HDD, a flash memory, or a combination thereof. The data stored in the auxiliary storage device 403 is loaded into the memory 402 as needed. The communication device 404 is a receiver and a transmitter. For example, the communication device 404 is a communication chip or a NIC. The communication of the certification authority device 400 is performed using the communication device 404. The input / output interface 405 is a port to which an input device and an output device are connected. For example, the input / output interface 405 is a USB terminal, the input device is a keyboard and a mouse, and the output device is a display. The input / output of the certification authority device 400 is performed using the input / output interface 405.

[0033] The certification authority device 400 includes elements such as a CA certificate issuing unit 411 and a CL certificate issuing unit 421. These elements are realized by software.

[0034] In the auxiliary storage device 403, there is stored a certification authority program for causing a computer to function as the CA certificate issuing unit 411 and the CL certificate issuing unit 421. The certification authority program is loaded into the memory 402 and executed by the processor 401. The auxiliary storage device 403 further stores an OS. At least a part of the OS is loaded into the memory 402 and executed by the processor 401. The processor 401 executes the certification authority program while executing the OS.

[0035] The input / output data of the certification authority program is stored in the storage unit 490. The memory 402 functions as the storage unit 490. However, storage devices such as the auxiliary storage device 403, the registers in the processor 401, and the cache memory in the processor 401 may function as the storage unit 490 instead of, or together with, the memory 402.

[0036] The certification authority device 400 may include a plurality of processors that replace the processor 401.

[0037] The certification authority program can be recorded (stored) in a computer-readable manner on a non-volatile recording medium such as an optical disk or a flash memory.

[0038] ***Explanation of the operation*** The procedure of the operation of the web conference system 100 corresponds to the web conference method. The procedure of the operation of the web conference system 100 corresponds to the procedure of the processing by the web conference program. The web conference program includes a client program, a server program, and a certification authority program.

[0039] The web conferencing method includes a preparation process, a registration process, a setting process, a participation process, a leaving process, and a communication process.

[0040] Based on FIG. 6, the outlines of the preparation process and the registration process will be described. The preparation process is a process in which each client device 200 acquires a CA certificate. The registration process is a process in which each member of the web conference acquires an identification code and a CL certificate. The CA certificate is an electronic certificate of the certification authority device 400. The identification code identifies a member or the client device 200 for the member. The CL certificate is an electronic certificate of the client device 200.

[0041] "Client" represents the client device 200. "Server" represents the server device 300. "Certification authority" represents the certification authority device 400.

[0042] First, the client device 200 acquires a CA certificate from the certification authority device 400.

[0043] Next, the client device 200 transmits user information to the server device 300. The user information is data indicating information about the user of the client device 200. For example, the user information indicates a name, an email address, etc. The server device 300 transmits an identity verification request to the client device 200. The identity verification request is data for requesting verification from the user himself / herself. The client device 200 transmits an identity verification response to the server device 300. The identity verification response is a response to the identity verification request. The server device 300 transmits an identification code to the client device 200. Then, the client device 200 receives the identification code.

[0044] Next, the client device 200 generates a certificate signing request (CSR). The CSR is data for requesting a CL certificate. The CSR contains an identification code. The client device 200 transmits the CSR to the certification authority device 400. The certification authority device 400 transmits an inquiry request to the server device 300. The inquiry request is data for requesting an inquiry of the identification code. The inquiry request contains the same identification code as the identification code included in the CSR. The server device 300 transmits an inquiry response to the certification authority device 400. The inquiry response is a response to the inquiry request. The inquiry response indicates whether the identification code included in the inquiry request is the identification code (correct identification code) transmitted to the client device 200. Assume that the identification code included in the inquiry request is the correct identification code and continue the explanation.

[0045] Next, the certification authority device 400 generates a CL certificate and transmits the CL certificate to the server device 300. Then, the server device 300 receives and stores the CL certificate.

[0046] Based on FIG. 7, a specific example of the preparation process will be described. The "acquisition unit" of the client represents the CA certificate acquisition unit 211. The "issuing unit" of the certification authority represents the CA certificate issuing unit 411. The "storage unit" of the certification authority represents the storage unit 490.

[0047] In step S101, the CA certificate issuing unit 411 generates a CA key pair. The CA key pair is the key pair of the certification authority device 400. The key pair is a pair of a private key and a public key.

[0048] Next, the CA certificate issuing unit 411 generates a CA certificate using the CA key pair. The CA certificate includes the CA public key and a signature. This signature is generated using the CA private key.

[0049] Then, the CA certificate issuing unit 411 stores the CA private key and the CA certificate in the storage unit 490. Thereby, in the certification authority apparatus 400, the CA private key and the CA certificate are stored.

[0050] In step S102, the CA certificate acquisition unit 211 acquires the CA certificate. For example, the CA certificate acquisition unit 211 requests the CA certificate from the certification authority apparatus 400, the CA certificate issuing unit 411 transmits the CA certificate to the client apparatus 200, and the CA certificate acquisition unit 211 receives the CA certificate. For the communication of the CA certificate, means such as via the web or email are used. Note that the CA certificate needs to reach the client apparatus 200 without being tampered with.

[0051] Then, the CA certificate acquisition unit 211 stores the CA certificate in the storage unit 290. Thereby, in the client apparatus 200, the CA certificate is stored.

[0052] Based on FIGS. 8 and 9, a specific example of the registration process will be described. The "acquisition unit" of the client represents the identification code acquisition unit 221 or the CL certificate acquisition unit 223. The "generation unit" of the client represents the signature key generation unit 222. The "storage unit" of the client represents the storage unit 290. The "management unit" of the server represents the identification code management unit 321. The "storage unit" of the server represents the storage unit 390. The "issuing unit" of the certification authority represents the CL certificate issuing unit 421. The "storage unit" of the certification authority represents the storage unit 490.

[0053] In step S201, the user of the client apparatus 200 inputs user information into the client apparatus 200. The identification code acquisition unit 221 receives the input user information.

[0054] In step S202, the identification code acquisition unit 221 transmits the user information to the server device 300. The identification code management unit 321 receives the user information.

[0055] Next, the identification code management unit 321 transmits an authentication request to the client device 200. The identification code acquisition unit 221 receives the authentication request. The authentication request indicates the address of a confirmation website (registration website). The address of the website can be indicated by a URL. A URL is an abbreviation for Uniform Resource Locator.

[0056] Next, the identification code acquisition unit 221 displays the address of the registration website on the display. The user of the client device 200 operates a mouse or the like to specify the address of the registration website.

[0057] Then, the identification code acquisition unit 221 accesses the registration website and transmits an authentication response to the server device 300. The identification code management unit 321 receives the authentication response.

[0058] In step S203, the identification code management unit 321 generates an identification code for the user of the client device 200.

[0059] The identification code management unit 321 associates the user information with the identification code and stores them in the storage unit 390. Thereby, in the server device 300, the user information and the identification code are stored.

[0060] The identification code management unit 321 transmits the identification code to the client device 200. The identification code acquisition unit 221 receives the identification code.

[0061] The identification code acquisition unit 221 stores the identification code in the storage unit 290. As a result, the identification code is stored in the server device 300.

[0062] In step S211, the signature key generation unit 222 generates a signature key pair. The signature key pair is the key pair of the client device 200. The signature key pair is used for various signatures.

[0063] The signature key generation unit 222 stores the signature key pair in the storage unit 290. As a result, the signature key pair is stored in the client device 200.

[0064] In step S212, the CL certificate acquisition unit 223 generates a CSR. The CSR includes the identification code and the signature public key.

[0065] The CL certificate acquisition unit 223 transmits the CSR to the certification authority device 400. The CL certificate issuance unit 421 receives the CSR.

[0066] In step S213, the CL certificate issuance unit 421 transmits an inquiry request to the server device 300. The identification code management unit 321 receives the inquiry request. The inquiry request includes the same identification code as the identification code included in the CSR.

[0067] The identification code management unit 321 inquires about the identification code included in the inquiry request with the stored identification codes. The identification code included in the inquiry request is referred to as the "target code". If the target code matches any of the stored identification codes, the target code is the correct identification code.

[0068] The identification code management unit 321 transmits an inquiry response to the certification authority device 400. The CL certificate issuance unit 421 receives the inquiry response. The inquiry response includes the inquiry result. The inquiry result indicates whether the target code is the correct identification code.

[0069] In step S214, the CL certificate issuing unit 421 refers to the inquiry result included in the inquiry response and determines whether the identification code included in the CSR is the correct identification code. If the identification code included in the CSR is the correct identification code, the CL certificate issuing unit 421 generates a CL certificate using the CA private key. The CL certificate includes a signature public key and a signature. This signature is generated using the CA private key.

[0070] If the identification code included in the CSR is not the correct identification code, the CL certificate is not generated. In this case, the CL certificate acquisition unit 223 cannot acquire the CL certificate.

[0071] Continue the explanation for the case where the identification code included in the CSR is the correct identification code. The CL certificate issuing unit 421 transmits the CL certificate to the client device 200. The CL certificate acquisition unit 223 receives the CL certificate.

[0072] The CL certificate acquisition unit 223 stores the CL certificate in the storage unit 290. Thereby, the CL certificate is stored in the client device 200.

[0073] Describe the features of the registration process. The server device 300 generates the identification code of each of the plurality of client devices 200 and transmits the identification code to each of the plurality of client devices 200. Each of the plurality of client devices 200 receives the identification code. Also, each client device 200 generates a signature key pair. Then, each client device 200 transmits a certificate request indicating the signature public key and the identification code to the certification authority device 400. The certification authority device 400 receives the certificate request and transmits an inquiry request indicating the identification code shown in the certificate request to the server device 300. The server device 300 receives an inquiry request and collates the identification code indicated in the inquiry request with the respective identification codes of a plurality of client devices 200. Then, the server device 300 transmits an inquiry response indicating the collation result to the certification authority device 400. The certification authority device 400 receives the inquiry response. And when the identification code indicated in the inquiry request is any one of the identification codes of the plurality of client devices 200, the certification authority device 400 issues an electronic certificate including the signature public key indicated in the certificate request for the client device 200 that is the sender of the certificate request.

[0074] Based on FIG. 10, the outline of the setting process will be described. The setting process is a process for setting a member list of a web conference. The member list is data indicating the identification codes of the respective members participating in the web conference.

[0075] First, the client (A) generates a member list. The client (A) generates a signature for the member list. The client (A) transmits the signed member list to the server device 300. The server device 300 verifies the signature of the member list. If the signature is correct, the server device 300 stores the member list.

[0076] Then, the server device 300 transmits conference information to each member indicated in the member list. When the client (A) and the client (B) are indicated in the member list, the server device 300 transmits conference information to each of the client (A) and the client (B). The conference information is data indicating the information of the web conference.

[0077] The description will continue with the case where the client (B) modifies the member list. The client (B) requests the server device 300 for the member list. The server device 300 transmits the member list to the client (B). The client (B) modifies the member list. The client (B) transmits the signed member list to the server device 300. The server device 300 verifies the signature of the member list. If the signature is correct, the server device 300 updates the member list.

[0078] Based on FIGS. 11 and 12, a specific example of the setting process will be described. The "generation unit" of the client represents the member list generation unit 231. The "acquisition unit" of the client represents the conference information acquisition unit 232. The "modification unit" of the client represents the member list modification unit 233. The "storage unit" of the client represents the storage unit 290. The "management unit" of the server represents the conference information management unit 331. The "storage unit" of the server represents the storage unit 390.

[0079] In step S301, the user (A) inputs the identification code of each member participating in the web conference into the client (A). It is assumed that the user has been informed of the identification code from each member. The member list generation unit 231 receives each input identification code.

[0080] The member list generation unit 231 generates a member list. The member list indicates each received identification code.

[0081] In step S302, the member list generation unit 231 uses the signature private key to generate a signature for the member list.

[0082] Then, the member list generation unit 231 generates a signed member list. The signed member list is data that includes a member list, a signature, and a CL certificate.

[0083] Figure 13 shows a signed member list 111. The signed member list 111 is an example of a signed member list generated by a client (A). The signed member list 111 includes an identification code and attributes for each member. "Joining" means that a user identified by the identification code joins as a member of the web conference. The signed member list 111 includes a member list, a signature (A), and a CL certificate (A). The signature (A) is a signature generated using the signature private key of the client (A). The CL certificate (A) is the CL certificate of the client (A).

[0084] Returning to Figure 11, the explanation continues from step S303. In step S303, the member list generation unit 231 sends a conference setting request to the server device 300. The conference information management unit 331 receives the conference setting request. The conference setting request is data for requesting the setting of a web conference. The conference setting request includes a signed member list.

[0085] The conference information management unit 331 verifies the signed member list included in the conference setting request. Specifically, the conference information management unit 331 verifies the signature in the signed member list using the signature public key included in the CL certificate in the signed member list. If the signature is correct, the signed member list is correct.

[0086] If the signed member list is correct, the conference information management unit 331 generates conference information. Then, the conference information management unit 331 stores the signed member list and the conference information in the storage unit 390 in association with each other. As a result, in the server device 300, the signed member list and the conference information are stored. The conference information includes a conference URL and a member list URL. The conference URL is the address of a website accessed when participating in a web conference. The member list URL is the address of a website for accessing the member list.

[0087] If the signed member list is incorrect, the web conference is not set up and the member list is not registered.

[0088] Continue the explanation for the case where the signed member list is correct. In step S304, the conference information management unit 331 transmits the conference information to the users identified by each identification code shown in the member list based on the user information being stored. For example, the conference information management unit 331 transmits the conference information using the email address of each user.

[0089] In each user's client device 200, the conference information acquisition unit 232 receives the conference information. Then, the conference information acquisition unit 232 stores the conference information in the storage unit 290. As a result, in the client device 200, the conference information is stored.

[0090] Each user may transmit the conference information to other members as needed.

[0091] In step S311, the member list modification unit 233 accesses the member list using the member list URL according to the instruction of user (B). Then, the member list modification unit 233 downloads the member list. At this time, the conference information management unit 331 transmits the member list to client (B), and the member list modification unit 233 receives the member list.

[0092] In step S312, the member list modification unit 233 modifies the member list according to the instruction of the user (B). Specifically, the member list modification unit 233 adds the modification data to the signed member list. The modification data indicates the content of the modification to the member list.

[0093] In step S313, the member list modification unit 233 generates a signature for the modification data using the signature private key.

[0094] Then, the member list modification unit 233 generates a modified member list. The modified member list includes the signed member list, the modification data, the signature, and the CL certificate.

[0095] FIG. 14 shows the modified member list 112. The modified member list 112 is an example of the signed member list 111 (see FIG. 11) modified by the client (B). The modified member list 112 includes the signed member list 111, the modification data, the signature (B), and the CL certificate (B). "Excluded" means that the user identified by the identification code is excluded from the members of the web conference. The modification data indicates that member (D) joins the members of the web conference and member (C) is excluded from the members of the web conference. The signature (B) is a signature generated using the signature private key of the client (B). The CL certificate (B) is the CL certificate of the client (B).

[0096] Returning to FIG. 12, the description continues from step S314. In step S314, the member list modification unit 233 transmits the modified member list to the server device 300. The conference information management unit 331 receives the modified member list.

[0097] The conference information management department 331 verifies the modified member list. Specifically, the conference information management department 331 verifies the signature in the modified member list by using the signature public key included in the CL certificate in the modified member list.

[0098] The conference information management department 331 verifies the modified data in the modified member list. For example, the conference information management department 331 determines whether the exclusion of non - participating members is not included in the modification content.

[0099] If the signature and the modified data are correct, the conference information management department 331 updates the signed member list in storage with the modified member list.

[0100] If at least one of the signature and the modified data is incorrect, the modified member list is discarded and the signed member list in storage is not updated.

[0101] Describe the features of the setting process. Any one of the plurality of client devices 200 generates a member list and transmits the signed member list to the server device 300. The server device 300 receives the signed member list and verifies the signature of the signed member list. And if the signature of the signed member list is correct, the server device 300 stores the member list. Each of the plurality of client devices 200 receives the member list from the server device 300. And each client device 200 modifies the member list and transmits the signed modified list to the server device 300. The modified list is the modified member list. The server device 300 receives the signed modified list and verifies the signature of the signed modified list. And if the signature of the signed modified list is correct, the server device 300 updates the member list in storage with the modified list.

[0102] Based on FIGS. 15 and 16, the outlines of the participation process and the departure process will be described. The participation process is a process for each member to participate in a web conference. The departure process is a process for a member who has already participated in a web conference to leave the web conference.

[0103] In FIG. 15, the solid white circles indicate members who are participating in the web conference. The dashed white circles indicate members who have not participated in the web conference. The black circles indicate members who have left the web conference. When member (A) participates in the web conference first, the eligibility for member (A) to participate is determined by the server device 300 using the member list. When each member participates in the web conference after the first time, the eligibility for each member to participate is determined by one of the members who are already participating. For example, the eligibility for member (B) to participate is determined by member (A). Also, the eligibility for member (C) to participate is determined by member (B). The member who determines the eligibility for participation is referred to as the "parent member". Also, the member whose eligibility for participation is determined is referred to as the "child member". The parent member and the child member perform key sharing. For example, member (A) performs key sharing with member (B). Also, member (B) performs key sharing with each of member (A) and member (B). When a member who is participating in the web conference leaves the web conference, the parent member with respect to the departing member and the child member with respect to the departing member perform key sharing. For example, when member (C) leaves, member (B) and member (D) perform key sharing.

[0104] In FIG. 16, "Join" means participation in the web conference. "Auth" means determination (authentication) of the eligibility for participation in the web conference. "Ratchet" means hashing. "Leave" means leaving the web conference. "Gen" means generation of a communication key. The communication key is a common key used for message communication in the web conference. The communication key is also referred to as a group key. Also, "k" X,Y represents the shared key between member (X) and member (Y). "k" X,G represents the updated communication key.

[0105] When a new member joins a web conference, the parent member (the corresponding member) for the new member hashes and updates the stored communication key and distributes the updated communication key to the new member. Furthermore, if there is a parent member for the corresponding member, the corresponding member notifies the parent member of the new member's participation. Then, the parent member hashes and updates the stored communication key. If there is a parent member for the parent member (the upper member), the parent member notifies the upper member of the new member's participation. The upper member operates in the same manner as the parent member. For example, when member (C) joins a web conference, member (B) hashes and updates the communication key k' A,G to obtain the updated communication key k'' A,G and distributes it to member (B). Furthermore, member (B) notifies member (A) of member (C)'s participation. Then, member (A) hashes the communication key k' A,G to update it to the communication key k'' A,G

[0106] When a participating member leaves a web conference, the parent member (the corresponding member) for the leaving member generates a new communication key and distributes the new communication key to each of the parent member and the child members of the leaving member. If there is a parent member for the parent member (the upper member), the upper member distributes the new communication key to the parent member. Then, the parent member for the upper member operates in the same manner as the upper member. If there is a child member for the child member (the lower member), the child member distributes the new communication key to the lower member. Then, the lower member operates in the same manner as the child member. For example, when member (C) leaves a web conference, member (B) generates a new communication key k B,G ​Generate new communication keys k for each of member (A) and member (D). B,G Distribute them.

[0107] Based on FIGS. 17 to 20, a specific example of the participation process will be described. "Client (A)" represents the client device 200 that participates in the web conference first. "Client (B)" represents the client device 200 that participates in the web conference second. "Client (C)" represents the client device 200 that participates in the web conference third. "Client (D)" represents the client device 200 that participates in the web conference fourth. The "participation section" of the client represents the conference participation section 241. The "generation section" of the client represents the communication key generation section 242. The "sharing section" of the client represents the key sharing section 243. The "update section" of the client represents the communication key update section 244. The "acquisition section" of the client represents the communication key acquisition section 245. The "notification section" of the client represents the participation notification section 246. The "memory section" of the client represents the memory section 290. The "management section" of the server represents the participation management section 341. The "memory section" of the server represents the memory section 390.

[0108] In step S401, the conference participation section 241 of client (A) sends a participation request to the server device 300. The participation management section 341 receives the participation request. The participation request is data for participating in the web conference. The participation request includes an identification code.

[0109] The participation management section 341 determines whether there is a client device 200 participating in the web conference. At this time, there is no client device 200 participating in the web conference. In this case, the participation management unit 341 determines whether the member list in storage contains the same identification code as the one included in the participation request. The identification code that is the same as the one included in the participation request is referred to as the "target code". If the target code is included in the member list in storage, the participation management unit 341 permits the client (A) to participate in the web conference. Then, the participation management unit 341 transmits a participation response indicating permission to participate in the web conference to the client (A). Note that the participation management unit 341 manages the identification codes of the respective members participating in the web conference. If the target code is not included in the member list in storage, the participation management unit 341 transmits a participation response indicating non - permission to participate in the web conference to the client (A). The conference participation unit 241 receives the participation response. The participation response is a response corresponding to the participation request.

[0110] The case where there is a client device 200 participating in the web conference will be described later.

[0111] In step S402, the conference participation unit 241 generates a communication key. The communication key is, for example, a random number. Then, the conference participation unit 241 stores the communication key in the storage unit 290. As a result, the communication key is stored in the client (A).

[0112] In step S411, the conference participation unit 241 of the client (B) transmits a participation request to the server device 300. The participation management unit 341 receives the participation request.

[0113] The participation management unit 341 determines whether there is a client device 200 participating in the web conference. At this time, the client (A) is participating in the web conference. In this case, the participation management unit 341 transmits a participation response indicating that there is a participating client device 200 to the client (B). The participation management unit 341 of the client (B) receives the participation response.

[0114] In step S412, the key sharing unit 243 of the client (B) generates an exchange key pair. The exchange key pair is a key pair for key sharing with other client devices 200. Specific examples of the exchange key are an ECDH key or a DH key. ECDH is an abbreviation for Elliptic curve Diffie-Hellman. DH is an abbreviation for Diffie-Hellman.

[0115] The key sharing unit 243 of the client (B) generates a signature for the exchange public key using the signature private key.

[0116] The key sharing unit 243 of the client (B) generates exchange data and transmits the exchange data to the server device 300. The exchange data is data for performing key exchange with other client devices 200. The exchange data includes the exchange public key, the signature, and the CL certificate.

[0117] The exchange data of the client (B) is referred to as exchange data (B). The exchange public key included in the exchange data (B) is referred to as exchange public key (B). The signature included in the exchange data (B) is referred to as signature (B). The CL certificate included in the exchange data (B) is referred to as CL certificate (B).

[0118] The participation management unit 341 receives the exchange data (B) and stores the exchange data (B) in the storage unit 390.

[0119] In step S413, the participation management unit 341 transmits an authentication request to all client devices participating in the web conference. The key sharing unit 243 of the client (A) receives the authentication request. The authentication request is data for notifying a new participation in the web conference.

[0120] The key sharing unit 243 of the client (A) determines whether key sharing is being performed with the child client. At this time, the client (A) is not performing key sharing with the child client. In this case, the key sharing unit 243 of the client (A) generates an exchange key pair. Also, the key sharing unit 243 generates a signature for the exchange public key using the signature private key. Then, the key sharing unit 243 generates exchange data and transmits the exchange data to the server device 300.

[0121] The exchange data of the client (A) is referred to as exchange data (A). The exchange public key included in the exchange data (A) is referred to as exchange public key (A). The signature included in the exchange data (A) is referred to as signature (A). The CL certificate included in the exchange data (A) is referred to as CL certificate (A).

[0122] The participation management unit 341 receives the exchange data (A) and stores the exchange data (A) in the storage unit 390.

[0123] In step S414, the participation management unit 341 transmits the exchange data (A) to the client (B) and transmits the exchange data (B) to the client (A). The key sharing unit 243 of the client (B) receives the exchange data (A). The key sharing unit 243 of the client (A) receives the exchange data (B).

[0124] In step S415, the key sharing unit 243 of the client (B) verifies the exchange data (A). Specifically, the key sharing unit 243 verifies the signature in the CL certificate (A) using the CA public key in the CA certificate. If the signature in the CL certificate (A) is correct, the key sharing unit 243 verifies the signature (A) using the signature public key in the CL certificate (A). If the signature (A) is correct, the exchange data (A) is correct. And the client (A) is authenticated.

[0125] If the exchange data (A) is correct, the key sharing unit 243 executes a process for key sharing using the exchange public key (A). As a result, a shared key (AB) is generated. Then, the key sharing unit 243 stores the shared key (AB) in the storage unit 290. Thereby, the shared key (AB) is stored in the client (A). The shared key (AB) is a common key shared between the client (A) and the client (B).

[0126] If the exchange data (A) is incorrect, the shared key (AB) is not generated in the client (B). That is, key sharing is not performed.

[0127] In step S416, the key sharing unit 243 of the client (A) verifies the exchange data (B). Specifically, the key sharing unit 243 verifies the signature in the CL certificate (B) using the CA public key in the CA certificate. If the signature in the CL certificate (B) is correct, the key sharing unit 243 verifies the signature (B) using the signature public key in the CL certificate (B). If the signature (B) is correct, the exchange data (B) is correct. And the client (B) is authenticated. Thereby, the participation of the client (B) in the web conference is permitted.

[0128] If the exchange data (B) is correct, the key sharing unit 243 executes a process for key sharing using the exchange public key (B). As a result, a shared key (AB) is generated. Then, the key sharing unit 243 stores the shared key (AB) in the storage unit 290. Thereby, the shared key (AB) is stored in the client (B).

[0129] If the exchange data (B) is incorrect, the shared key (AB) is not generated in the client (A). That is, key sharing is not performed.

[0130] In step S421, the communication key update unit 244 of the client (A) hashes and updates the stored communication key. That is, the communication key update unit 244 hashes the stored communication key and updates the stored communication key with the obtained hash value.

[0131] In step S422, the communication key update unit 244 of the client (A) encrypts the updated stored communication key using the shared key (AB). As a result, an encrypted communication key is obtained.

[0132] The communication key update unit 244 of the client (A) transmits the encrypted communication key to the server device 300. The participation management unit 341 receives the encrypted communication key and stores the encrypted communication key in the storage unit 390.

[0133] In step S423, the communication key acquisition unit 245 of the client (B) transmits a communication key request to the server device 300. The participation management unit 341 receives the communication key request. The communication key request is data for requesting a communication key.

[0134] The participation management unit 341 transmits the encrypted communication key to the client (B). The communication key acquisition unit 245 of the client (B) receives the encrypted communication key.

[0135] In step S424, the communication key acquisition unit 245 of the client (B) decrypts the communication key from the encrypted communication key using the shared key (AB).

[0136] The communication key acquisition unit 245 of the client (B) stores the communication key in the storage unit 290. As a result, in the client (B), the same communication key as the communication key stored in the client (A) is stored.

[0137] In step S425, the participation notification unit 246 of the client (A) determines whether there is a parent client for the client (A). At this time, there is no parent client for the client (A). In this case, the process ends.

[0138] In step S431, the client (C) becomes a child client and the client (B) becomes a parent client. Then, key sharing is performed between the client (B) and the client (C). The key sharing procedure is the same as the key sharing procedure (S411~S416) performed between the client (A) and the client (B). As a result, a shared key (BC) is stored in each of the client (B) and the client (C). The shared key (BC) is a common key shared between the client (B) and the client (C).

[0139] Furthermore, key update is performed between the client (B) and the client (C). The key update procedure is the same as the key update procedure (S421~S424) performed between the client (A) and the client (B). As a result, a communication key is stored in each of the client (B) and the client (C). Since this communication key is hashed by the client (B), it is different from the communication key stored in the client (A).

[0140] Then, the participation notification unit 246 of the client (B) determines whether there is a parent client for the client (B) (the same as step S425). The client (A) is the parent client for the client (B). In this case, the process proceeds to step S432.

[0141] In step S432, the participation notification unit 246 of the client (B) generates a participation notification. The participation notice is data for notifying the parent client of a new participation in the web conference. Furthermore, the participation notice unit 246 generates a message authentication code (MAC) using the shared key (AB). Then, the participation notice unit 246 transmits the participation notice including the MAC to the server device 300. The participation management unit 341 receives the participation notice.

[0142] Information for identifying the participation notice (such as a timestamp or a sequence number) may be included in the participation notice. This information can be used to prevent the retransmission of the participation notice.

[0143] The participation management unit 341 transmits the participation notice to the client (A). The communication key update unit 244 of the client (A) receives the participation notice.

[0144] In step S434, the communication key update unit 244 of the client (A) verifies the MAC included in the participation notice using the shared key (AB).

[0145] If the MAC is correct, the communication key update unit 244 hashes and updates the stored communication key. As a result, in the client (A), the same communication key as the communication key stored in the client (B) is stored.

[0146] The hashing method is common among the plurality of client devices 200, and the hashing results are the same among the plurality of client devices 200. For example, the plurality of client devices 200 use the same hash function for hashing.

[0147] In step S435, the participation notice unit 246 of the client (A) determines whether there is a parent client for the client (A). Since there is no parent client for the client (A), the process ends.

[0148] If there is a parent client for client (A), client (A) sends a participation notice to the parent client, similar to client (B). Then, the parent client updates the communication key in storage (step S434), similar to client (A), and sends a participation notice as necessary (step S435). This process continues until the client device 200 without a parent client updates the communication key in storage.

[0149] Describe the features of the participation process. When the client device 200 participates in the web conference for the first time, it generates and stores a communication key. When the client device 200 participates in the web conference for the second time or later, it performs key sharing with the client device that has become the parent client while participating in the web conference. Then, the client device 200 receives the encrypted communication key from the parent client, decrypts the communication key from the encrypted communication key using the shared key with the parent client, and stores the communication key. When not performing key sharing with a child client while participating in the web conference, the client device 200 sets the newly participating client device as a child client and performs key sharing. Also, the client device 200 updates the stored communication key by hashing. Then, the client device 200 encrypts the updated and stored communication key using the shared key with the child client, and sends the encrypted communication key to the child client. Furthermore, the client device 200 sends a participation notice to the parent client. When receiving a participation notice from a child client, the client device 200 updates the stored communication key by hashing.

[0150] Each of the multiple client devices 200 becomes a participating request client when participating in the web conference. Then, each client device 200 sends a participation request indicating an identification code to the server device 300. When the server device 300 receives a participation request from the first participating client for the web conference, the server device 300 collates the identification code indicated in the received participation request with the member list of the web conference. The server device 300 determines whether the participating client can participate based on the collation result. Then, the server device 300 transmits a participation response indicating the determination result to the participating client. When the server device 300 receives a participation request from a participating client that participates in the web conference after the second time, the server device 300 transmits an authentication request for the participating client to all the client devices 200 participating in the web conference. Each client device 200 participating in the web conference operates as follows. When not performing key sharing with a child client when receiving an authentication request, the client device 200 receives a signed exchange key transmitted from the participating client and verifies the signature of the signed exchange key. And when the exchange key of the signed exchange key is correct, the client device 200 uses the participating client as a child client and performs key sharing using the exchange key.

[0151] Based on FIGS. 21 and 22, a specific example of the leaving process will be described. "Client (A)" represents the client device 200 that participated in the web conference first. "Client (B)" represents the client device 200 that participated in the web conference second. "Client (C)" represents the client device 200 that participated in the web conference third. "Client (D)" represents the client device 200 that participated in the web conference fourth. The "notification unit" of the client represents the leaving notification unit 251. The "sharing unit" of the client represents the re-sharing unit 252. The "generation unit" of the client represents the new key generation unit 253. The "transmission unit" of the client represents the new key transmission unit 254. The "storage unit" of the client represents the storage unit 290. The "management section" of the server represents the disconnection management section 351. The "memory section" of the server represents the memory section 390.

[0152] In step S501, the disconnection notification section 251 of the client (B) sends a disconnection notification to the server device 300. The disconnection management section 351 receives the disconnection notification. The disconnection notification is data for disconnecting from the web conference. The disconnection notification includes the identification code of the disconnected client. The disconnected client is the client device 200 that has disconnected from the web conference.

[0153] The disconnection management section 351 sends the disconnection notification to all client devices 200 participating in the web conference. In each participating client device 200, the re-sharing section 252 receives the disconnection notification.

[0154] In each participating client device 200, the re-sharing section 252 refers to the identification code included in the disconnection notification. Then, the re-sharing section 252 determines whether the client device 200 is the parent client of the disconnected client or the child client of the disconnected client.

[0155] Client (A) is the parent client of client (B). In this case, the process in client (A) proceeds to step S502. Client (C) is the child client of client (B). In this case, the process in client (C) proceeds to step S502. Client (D) is not the parent client of client (B). Also, client (D) is not the child client of client (B). In this case, in client (D), no processing is performed for the disconnection notification.

[0156] In step S502, the re-sharing unit 252 of the client (A) generates the exchange data (A') and transmits the exchange data (A') to the server device 300. Also, the re-sharing unit 252 of the client (C) generates the exchange data (C') and transmits the exchange data (C') to the server device 300. The method for generating the exchange data is the same as the method in the participation process (see FIG. 18).

[0157] The departure management unit 351 receives the exchange data (A') and the exchange data (C'), transmits the exchange data (C') to the client (A), and transmits the exchange data (A') to the client (C).

[0158] In step S503, the re-sharing unit 252 of the client (A) verifies the exchange data (C'), generates a shared key (AC) by key sharing, and stores the shared key (AC). Also, the re-sharing unit 252 of the client (C) verifies the exchange data (A'), generates a shared key (AC) by key sharing, and stores the shared key (AC). The methods for verification and key sharing are the same as the methods in the participation process (see FIG. 18).

[0159] In step S511, the new key generation unit 253 of the client (A) generates a new communication key. The new key generation unit 253 updates the stored communication key with the new communication key. As a result, a new communication key is stored in the client (A).

[0160] In step S512, the new key transmission unit 254 of the client (A) encrypts the new communication key using the shared key (AC). As a result, an encrypted communication key is obtained.

[0161] The new key transmission unit 254 transmits the encrypted communication key to the server device 300. The departure management unit 351 receives the encrypted communication key and stores the encrypted communication key in the storage unit 390.

[0162] The disconnection management unit 351 transmits the encrypted communication key to the client (C). The new key transmission unit 254 of the client (C) receives the encrypted communication key.

[0163] In step S513, the new key transmission unit 254 of the client (C) decrypts a new communication key from the encrypted communication key using the shared key (AC). The new key transmission unit 254 updates the stored communication key with the new communication key. As a result, a new communication key is stored in the client (C).

[0164] In step S514, the new key transmission unit 254 of the client (C) determines whether there is a child client for the client (C). The client (D) is a child client for the client (C). In this case, the new key transmission unit 254 of the client (C) encrypts the new communication key using the shared key (CD) and transmits the encrypted communication key to the server device 300. The disconnection management unit 351 receives the encrypted communication key and transmits the encrypted communication key to the client (D). The new key transmission unit 254 of the client (D) receives the encrypted communication key.

[0165] In step S515, the new key transmission unit 254 of the client (D) decrypts a new communication key from the encrypted communication key using the shared key (CD) and updates the stored communication key with the new communication key. As a result, a new communication key is stored in the client (D).

[0166] The new key transmission unit 254 of the client (D) determines whether there is a child client for the client (D). There is no child client for the client (D). In this case, the process ends.

[0167] If there is a child client for the client (D), the client (D) transmits an encrypted communication key to the child client in the same manner as the client (C). Then, similar to the client (D), the child client updates the communication key being stored (step S515) and transmits an encrypted communication key as necessary. This process continues until the client device 200 without a child client updates the communication key being stored.

[0168] Describe the features of the disconnection process. When disconnecting from the web conference, the client device 200 transmits a disconnection notice to each of the parent client and the child client. When receiving the disconnection notice of the parent client, the client device 200 performs key sharing with a new parent client. The parent client for the parent client becomes the new parent client. The client device 200 receives an encrypted communication key from the new parent client and decrypts the new communication key from the encrypted communication key using the shared key with the new parent client. Then, the client device 200 stores the new communication key instead of the communication key being stored. Furthermore, the client device 200 encrypts the new communication key using the shared key with the child client and transmits the encrypted communication key to the child client. When receiving the encrypted communication key from the parent client, the client device 200 decrypts the new communication key from the encrypted communication key using the shared key with the parent client and stores the new communication key instead of the communication key being stored. When receiving the disconnection notice of the child client, the client device 200 performs key sharing with a new child client. The child client for the child client becomes the new child client. Also, the client device 200 generates a new communication key and stores it instead of the communication key being stored. Then, the client device 200 encrypts the new communication key using the shared key with the new child client and transmits the encrypted communication key to the new child client.

[0169] Each of the plurality of client devices 200 does not perform key sharing with other client devices unless either the parent client or the child client disconnects from the web conference.

[0170] Based on FIG. 23, communication processing will be described. The communication processing is processing in which the client device 200 participating in the web conference communicates a message.

[0171] The "transmission unit" of the client represents the message transmission unit 261. The "reception unit" of the client represents the message reception unit 262. The "storage unit" of the client represents the storage unit 290. The "storage unit" of the server represents the storage unit 390.

[0172] In step S601, the user of the client (A) inputs a message into the client (A). The message transmission unit 261 receives the message. The form of the message is, for example, a character string, voice, or video.

[0173] The message transmission unit 261 encodes the message. That is, the message transmission unit 261 converts the message into data in a prescribed format. Thereby, an encoded message is obtained.

[0174] The message transmission unit 261 encrypts the encoded message using a communication key. Thereby, an encrypted message is obtained.

[0175] The message transmission unit 261 transmits the encrypted message to the server device 300. The communication management unit 361 receives the encrypted message and stores it in the storage unit 390.

[0176] The communication management unit 361 transmits the encrypted message to each client device 200 participating in the web conference. The message reception unit 262 of the client (B) receives the encrypted message.

[0177] In step S603, the message receiving unit 262 of the client (B) decrypts the encoded message from the encrypted message using the communication key in storage.

[0178] The message receiving unit 262 decrypts the message from the encoded message.

[0179] The message receiving unit 262 outputs the message. For example, the message receiving unit 262 displays the message on a display.

[0180] ***Effect of Embodiment 1*** For two-party key sharing, it is necessary to securely pass the initial key (exchange key) of each user to the other party. Conventionally, the initial key was registered in the server together with the phone number. Therefore, if the server administrator has malicious intent, impersonation by replacing the initial key becomes possible. In Embodiment 1, the initial key is distributed using an electronic certificate. Thereby, forgery of the initial key in the server can be prevented.

[0181] In Embodiment 1, a list of participating members is generated when opening a web conference. Thereby, entry (participation in the web conference) of an uninvited third party can be prevented.

[0182] Conventionally, for n members n C 2 times of key sharing were required. According to Embodiment 1, the number of times of key sharing can be reduced to (n - 1 + α) times. "α" means the number of departure times.

[0183] In Embodiment 1, an updated communication key by hashing is passed to a new participating client. Thereby, the new participating client cannot decrypt the messages before participation.

[0184] In Embodiment 1, when a client participating in a web conference leaves the web conference, a new communication key is generated. As a result, the leaving client cannot decrypt messages after leaving.

[0185] Embodiment 2. A form of dealing with leaving a web conference without notice will be mainly described based on FIGS. 24 to 28, which are different from Embodiment 1.

[0186] ***Description of Configuration*** Based on FIG. 24, the configuration of the client device 200 will be described. The client device 200 further includes an element called a detection unit 270. The detection unit 270 is implemented by software. The client program further causes a computer to function as the detection unit 270.

[0187] Based on FIG. 25, the configuration of the detection unit 270 will be described. The detection unit 270 includes a confirmation request unit 271, a confirmation response unit 272, and a proxy notification unit 273.

[0188] Based on FIG. 26, the configuration of the server device 300 will be described. The server device 300 further includes a detection management unit 371. The detection management unit 371 is implemented by software. The server program further causes a computer to function as the detection management unit 371.

[0189] ***Description of Operation*** The web conference method includes a detection process. The detection process is a process of detecting a client device 200 that has left the web conference without sending a leaving notification.

[0190] Based on FIG. 27, the outline of the detection process will be described. “Join” means participation in a web conference. 「Gen nonce」 means generating a nonce. A nonce is a random value. 「Sign」 means signing. 「Verify」 means verifying a signature. 「Auth」 means authenticating a child client. 「Gen k B,G 」 means generating a communication key.

[0191] During a web conference, client (A) sends a nonce to each client participating in the web conference. Each client participating in the web conference generates a signature for the nonce and sends the signature to client (A). Client (A) verifies each signature. After that, client (C) left the web conference without sending a disconnection notice. After that, client (E) sent a nonce to each client participating in the web conference. However, it could not receive a signature from client (C). In this case, client (E) notifies each client that client (C) has left the web conference. After that, client (B), which was the parent client of client (C), generated a new communication key k B,G and the new communication key k B,G is transmitted to each client.

[0192] Based on Figure 28, a specific example of the detection process will be described. The "request part" of the client represents the confirmation request part 271. The "response part" of the client represents the confirmation response part 272. The "memory part" of the client represents the memory part 290. The "management part" of the server represents the detection management part 371. The "memory part" of the server represents the memory part 390.

[0193] In step S701, the confirmation request unit 271 of each participating client device 200 determines whether it is the confirmation timing. The confirmation timing is a predetermined timing for disconnection confirmation. For example, each time that visits at regular intervals after the transmission of the participation notice is the confirmation timing.

[0194] In client (A), the confirmation timing is detected. In this case, the confirmation request unit 271 of client (A) transmits a disconnection confirmation request to the server device 300. The detection management unit 371 receives the disconnection confirmation request. The disconnection confirmation request is data for confirming the client device 200 that has disconnected from the web conference. The disconnection confirmation request includes a confirmation message. The confirmation message is an arbitrary message and includes a nonce to prevent the retransmission of the confirmation message.

[0195] The detection management unit 371 transmits the disconnection confirmation request to all client devices 200 managed as participating client devices 200. The confirmation response unit 272 of client (B) receives the disconnection confirmation request. The confirmation response unit 272 of client (C) receives the disconnection confirmation request.

[0196] In step S702, the confirmation response unit 272 of client (B) generates a signature for the confirmation message using the signature private key. The confirmation response unit 272 generates a disconnection confirmation response and transmits the disconnection confirmation response to the server device 300. The detection management unit 371 receives the disconnection confirmation response. The disconnection confirmation response is a response to the disconnection confirmation request. The disconnection confirmation response includes a signature for the confirmation message, a CL certificate, and an identification code.

[0197] Similar to client (B), the confirmation response unit 272 of client (C) transmits the disconnection confirmation response to the server device 300. The detection management unit 371 receives the disconnection confirmation response.

[0198] In step S703, the detection management unit 371 generates management data. The management data includes each disconnection confirmation response and the participating client list. The participating client list is a list of identification codes of the client devices 200 that are managed as the participating client devices 200.

[0199] The detection management unit 371 transmits the management data to the client (A). The proxy notification unit 273 of the client (A) receives the management data.

[0200] In step S704, the proxy notification unit 273 of the client (A) verifies each disconnection confirmation response included in the management data. Specifically, the proxy notification unit 273 uses the CA public key in the CA certificate to verify the signature in the CL certificate. If the signature in the CL certificate is correct, the proxy notification unit 273 uses the signature public key in the CL certificate to verify the signature for the confirmation message. If the signature for the confirmation message is correct, the disconnection confirmation response is correct.

[0201] The proxy notification unit 273 extracts from the participating client list the identification codes that do not match any of the identification codes in the correct disconnection confirmation responses. The client device 200 identified by the extracted identification code is referred to as the disconnected client. The disconnected client is the client device 200 that has left the web conference without sending a disconnection notification.

[0202] If there is a disconnected client, the proxy notification unit 273 of the client (A) sends a disconnection notification on behalf of the disconnected client. The processing for the disconnection notification (disconnection processing) is as described in the first embodiment.

[0203] Describe the features of the detection process. When receiving a confirmation request for confirming that a user has left the web conference, each client device 200 participating in the web conference transmits a confirmation response to the confirmation request. Each client device 200 participating in the web conference transmits a confirmation request at an arbitrary timing and receives a confirmation response from the client device participating in the web conference. Next, the client device 200 detects, as a left client, a client device 200 that has not left the web conference and is not the source of the confirmation response. Then, the client device 200 transmits a departure notification of the left client.

[0204] ***Effect of Embodiment 2*** According to Embodiment 2, it is possible to handle the case where a member silently leaves the web conference.

[0205] ***Summary of Embodiments*** The member who first participates in the web conference generates a communication key. The members who participate in the web conference after the second one perform authentication and key sharing with one of the members who have already participated. If a member who has left the web conference appears, the member who authenticated the leaving member performs authentication and key sharing with the member who authenticated the leaving member.

[0206] If the authentication and key sharing at the time of participation are successful, the authenticating member hashes its communication key and passes the hash value to the authenticated member as the communication key. At the same time, the authenticating member notifies the other participating members to that effect. Each member who receives the notification hashes its communication key.

[0207] If the authentication and key sharing at the time of leaving are completed, the member who authenticated the leaving member generates a communication key and distributes the communication key to the member with whom the key sharing was performed. The member who receives the communication key distributes the communication key to the member with whom the key sharing was performed.

[0208] Members who first participate in a web conference are determined for approval or disapproval using the member list.

[0209] Each member can have a maximum of two counterparts for authentication and key exchange.

[0210] The member who opens a web conference generates a list of participating members, signs it, sends the list to the server, and receives the issuance of a conference URL. Each member listed in the list operates as follows as needed. The member receives the list from the server, adds or deletes members to the list, signs it, and sends the list to the server.

[0211] At the time of initial registration of a user, the server performs identity verification and issues an identification code that uniquely identifies the verified user. The user sends a certificate signing request (CSR) containing the identification code to the CA. The CA inquires with the server about the presence or absence of the identification code and issues a certificate if the identification code is registered.

[0212] During a web conference, one member generates a nonce at an arbitrary timing and requests a signature from other members. The other members sign the nonce and reply with the signature together with their certificates to the member who requested the signature. The member who requested the signature verifies the signature and detects members who have left silently. After detection, a withdrawal process (authentication, key sharing, communication key update) is executed.

[0213] ***Supplement to the Embodiment*** The server device 300 and the certification authority device 400 may be configured as one device.

[0214] Each embodiment is an example of a preferred form and is not intended to limit the technical scope of the present disclosure. Each embodiment may be implemented partially or in combination with other forms. The procedures described using flowcharts and the like may be changed as appropriate.

[0215] Each element of the client device 200, the server device 300, and the certification authority device 400 may be implemented by any of software, hardware, firmware, or a combination thereof. The "section" which is an element of the client device 200, the server device 300, and the certification authority device 400 may be read as "process", "step", "circuit", or "circuitry".

Explanation of Signs

[0216] 100 Web conferencing system, 101 Network, 111 Signed member list, 112 Modified member list, 200 Client device, 201 Processor, 202 Memory, 203 Auxiliary storage device, 204 Communication device, 205 Input / output interface, 210 Preparation section, 211 CA certificate acquisition section, 220 Registration section, 221 Identification code acquisition section, 222 Signature key generation section, 223 CL certificate acquisition section, 230 Setting section, 231 Member list generation section, 232 Conference information acquisition section, 233 Member list modification section, 240 Participation section, 241 Conference participation section, 242 Communication key generation section, 243 Key sharing section, 244 Communication key update section, 245 Communication key acquisition section, 246 Participation notification section, 250 Departure section, 251 Departure notification section, 252 Re-sharing section, 253 New key generation section, 254 New key transmission section, 260 Communication section, 261 Message transmission section, 262 Message reception section, 270 Detection section, 271 Confirmation request section, 272 Confirmation response section, 273 Proxy notification section, 290 Storage section, 300 Server device, 301 Processor, 302 Memory, 303 Auxiliary storage device, 304 Communication device, 305 Input / output interface, 321 Identification code management section, 331 Conference information management section, 341 Participation management section, 351 Departure management section, 361 Communication management section, 371 Detection management section, 390 Storage section, 400 Certification authority device, 401 Processor, 402 Memory, 403 Auxiliary storage device, 404 Communication device, 405 Input / output interface, 411 CA certificate issuance section, 421 CL certificate issuance section, 490 Storage section.

Claims

1. A web conference system comprising a plurality of client devices participating in a web conference, wherein each of the plurality of client devices generates and stores a communication key used for message communication in the web conference when it first participates in the web conference, when it participates in the web conference after the first participation, performs key sharing with the client device that has become the parent client during the web conference, receives the encrypted communication key from the parent client, decrypts the communication key from the encrypted communication key using the shared key with the parent client, and stores the communication key, when not performing the key sharing with a child client during the web conference, makes the newly participating client device in the web conference the child client and performs the key sharing, updates the stored communication key by hashing, encrypts the updated and stored communication key using the shared key with the child client, transmits the encrypted communication key to the child client, and transmits a participation notice to the parent client, when receiving a participation notice from the child client, updates the stored communication key by the hashing A web conference system.

2. Each client device that has participated in the web conference transmits a disconnection notice to each of the parent client and the child client when it disconnects from the web conference, each client device participating in the web conference when receiving a disconnection notice of the parent client, makes a new parent client for the parent client, performs key sharing with the new parent client, receives the encrypted communication key from the new parent client, decrypts a new communication key from the encrypted communication key using the shared key with the new parent client, stores the new communication key instead of the stored communication key, encrypts the new communication key using the shared key with the child client, and transmits the encrypted communication key to the child client, when receiving the encrypted communication key from the parent client, decrypts a new communication key from the encrypted communication key using the shared key with the parent client, and stores the new communication key instead of the stored communication key When receiving the detachment notice of the child client, make the child client for the child client a new child client, perform key sharing with the new child client, generate a new communication key, store it in place of the stored communication key, encrypt the new communication key using the shared key with the new child client, and send the encrypted communication key to the new child client. The web conference system according to claim 1.

3. Each client device participating in the web conference When receiving a confirmation request for confirming that it has left the web conference, send a confirmation response to the confirmation request. When any timing arrives, send the confirmation request, receive the confirmation response from the client device participating in the web conference, detect a client device that has not left the web conference and is not the sender of the confirmation response as a detached client, and send a detachment notice of the detached client. The web conference system according to claim 2.

4. Each of the plurality of client devices does not perform key sharing with other client devices unless either the parent client or the child client leaves the web conference. The web conference system according to any one of claims 1 to 3.

5. The web conference system includes a server device. Each of the plurality of client devices, when participating in the web conference, becomes a participating request client and sends a participating request indicating an identification code to the server device. The server device When receiving the participation request of the first participating request client in the web conference, collate the identification code shown in the received participation request with the member list of the web conference, determine the participation permission of the participating request client based on the collation result, and send a participation response indicating the determination result to the participating request client. When receiving the participation request of a participating request client that participates in the web conference after the second time, send an authentication request for the participating request client to all client devices participating in the web conference. Each client device participating in the web conference When the key sharing with the child client has not been performed when the authentication request is received, receive the signed exchange key sent from the participating request client, verify the signature of the signed exchange key, and if the signature of the signed exchange key is correct, set the participating request client as the child client and perform the key sharing using the exchange key. The web conferencing system according to any one of claims 1 to 4.

6. Any one of the plurality of client devices generates the member list, and transmits the signed member list to the server device. The server device receives the signed member list, verifies the signature of the signed member list, and stores the member list if the signature of the signed member list is correct. Each of the plurality of client devices receives the member list from the server device, modifies the member list, and transmits the signed modified list to the server device. The server device receives the signed modified list, verifies the signature of the signed modified list, and updates the stored member list with the modified list if the signature of the signed modified list is correct. The web conferencing system according to claim 5.

7. The web conferencing system includes a certification authority device. The server device generates the identification code for each of the plurality of client devices, and transmits the identification code to each of the plurality of client devices. Each of the plurality of client devices receives the identification code, generates a signature key pair, and transmits a certificate request indicating the signature public key and the identification code to the certification authority device. The certification authority device receives the certificate request, and transmits an inquiry request indicating the identification code shown in the certificate request to the server device. The server device receives the inquiry request, collates the identification code shown in the inquiry request with the identification code of each of the plurality of client devices, and transmits an inquiry response indicating the collation result to the certification authority device. The certification authority device receives the inquiry response, and issues an electronic certificate including the signature public key shown in the certificate request for the client device that is the source of the certificate request when the identification code shown in the inquiry request is the identification code of any one of the plurality of client devices. The web conferencing system according to claim 5 or claim 6.

8. A client device used in the web conferencing system according to any one of claims 1 to 7.

9. A client program for causing a computer to function as the client device according to claim 8.

10. A server device used in the web conferencing system according to claim 6, any one of a plurality of client devices generates a member list of a web conference, transmits a signed member list to the server device, the server device receives the signed member list, verifies the signature of the signed member list, and stores the member list when the signature of the signed member list is correct, each of the plurality of client devices receives the member list from the server device, modifies the member list, and transmits a signed modified list to the server device, the server device receives the signed modified list, verifies the signature of the signed modified list, and updates the stored member list with the modified list when the signature of the signed modified list is correct, each of the plurality of client devices, when participating in the web conference, acts as a participating request client and transmits a participating request indicating an identification code to the server device, the server device, when receiving a participating request of the first participating request client to the web conference, collates the identification code indicated in the received participating request with the member list, determines the participation permission of the participating request client based on the collation result, and transmits a participation response indicating the determination result to the participating request client, when receiving a participating request of a participating request client that participates in the web conference after the second time, transmits an authentication request for the participating request client to all client devices participating in the web conference, each client device participating in the web conference, when not performing the key sharing with a child client when receiving the authentication request, receives a signed exchange key transmitted from the participating request client, verifies the signature of the signed exchange key, and when the signature of the signed exchange key is correct, sets the participating request client as the child client and performs the key sharing using the exchange key, each of the plurality of client devices When participating in the web conference for the first time, generate and store a communication key used for message communication in the web conference. When participating in the web conference for the second time or later, perform key sharing with the client device that has become the parent client during the participation in the web conference, receive the encrypted communication key from the parent client, decrypt the communication key from the encrypted communication key using the shared key with the parent client, and store the communication key. When not performing the key sharing with the child client during the participation in the web conference, set the newly participating client device as the child client and perform the key sharing, update the stored communication key by hashing, encrypt the updated and stored communication key using the shared key with the child client, send the encrypted communication key to the child client, and send a participation notice to the parent client. When receiving a participation notice from the child client, update the stored communication key by hashing.

11. A server device used in the web conference system according to claim 7, The server device generates an identification code for each of a plurality of client devices and transmits the identification code to each of the plurality of client devices. Each of the plurality of client devices receives the identification code, generates a signature key pair, and transmits a certificate request indicating the signature public key and the identification code to the certification authority device. The certification authority device receives the certificate request and transmits an inquiry request indicating the identification code shown in the certificate request to the server device. The server device receives the inquiry request, collates the identification code shown in the inquiry request with the identification codes of each of the plurality of client devices, and transmits an inquiry response indicating the collation result to the certification authority device. The certification authority device receives the inquiry response, and issues an electronic certificate including the signature public key shown in the certificate request for the client device that is the source of the certificate request when the identification code shown in the inquiry request is the identification code of any of the plurality of client devices. When each of the plurality of client devices participates in the web conference, it becomes a participating request client and transmits a participation request indicating the identification code to the server device. The server device When receiving a participation request from a participating request client that is the first to participate in the web conference, the identification code shown in the received participation request is compared with the member list of the web conference, the participation eligibility of the participating request client is determined based on the comparison result, and a participation response indicating the determination result is sent to the participating request client. When receiving a participation request from a participating request client that participates in the web conference after the second time, an authentication request for the participating request client is sent to all client devices participating in the web conference. When each client device participating in the web conference has not performed the key sharing with a child client when receiving the authentication request, it receives a signed exchange key sent from the participating request client, verifies the signature of the signed exchange key, and when the signature of the signed exchange key is correct, sets the participating request client as the child client and performs the key sharing using the exchange key. Each of the plurality of client devices When participating in the web conference for the first time, generates and stores a communication key used for message communication in the web conference. When participating in the web conference after the second time, performs key sharing with a client device that has become a parent client while participating in the web conference, receives an encrypted communication key from the parent client, decrypts the communication key from the encrypted communication key using the shared key with the parent client, and stores the communication key. When not performing the key sharing with a child client while participating in the web conference, sets a newly participating client device in the web conference as the child client and performs the key sharing, updates the stored communication key by hashing, encrypts the updated and stored communication key using the shared key with the child client, sends the encrypted communication key to the child client, and sends a participation notice to the parent client. When receiving a participation notice from the child client, updates the stored communication key by the hashing.

12. A server program for causing a computer to function as the server device according to claim 10, Any one of a plurality of client devices generates a member list of a web conference and sends a signed member list to the server device. The server device receives the signed member list, verifies the signature of the signed member list, and stores the member list when the signature of the signed member list is correct. Each of the plurality of client devices receives the member list from the server device, modifies the member list, and transmits a signed modified list to the server device. The server device receives the signed modified list, verifies the signature of the signed modified list, and updates the stored member list with the modified list when the signature of the signed modified list is correct. Each of the plurality of client devices, when participating in the web conference, acts as a participating request client and transmits a participating request indicating an identification code to the server device. The server device When receiving the participation request of the first participating request client in the web conference, it collates the identification code shown in the received participation request with the member list, determines the participation permission of the participating request client based on the collation result, and transmits a participation response indicating the determination result to the participating request client. When receiving the participation request of a participating request client that participates in the web conference after the second time, it transmits an authentication request for the participating request client to all client devices participating in the web conference. When each client device participating in the web conference receives the authentication request and has not performed the key sharing with a child client, it receives the signed exchange key transmitted from the participating request client, verifies the signature of the signed exchange key, and when the signature of the signed exchange key is correct, sets the participating request client as the child client and performs the key sharing using the exchange key. Each of the plurality of client devices When participating in the web conference for the first time, generates and stores a communication key used for message communication in the web conference. When participating in the web conference after the second time, performs key sharing with the client device that has become the parent client while participating in the web conference, receives the encrypted communication key from the parent client, decrypts the communication key from the encrypted communication key using the shared key with the parent client, and stores the communication key. When participating in the web conference and not performing the key sharing with the child client, set the client device newly participating in the web conference as the child client to perform the key sharing, update the stored communication key by hashing, encrypt the updated and stored communication key using the shared key with the child client, send the encrypted communication key to the child client, and send a participation notice to the parent client. When receiving a participation notice from the child client, update the stored communication key by hashing.

13. A server program for causing a computer to function as the server device according to claim 11, The server device generates an identification code for each of a plurality of client devices and transmits the identification code to each of the plurality of client devices. Each of the plurality of client devices receives the identification code, generates a signature key pair, and transmits a certificate request indicating the signature public key and the identification code to the certification authority device. The certification authority device receives the certificate request and transmits an inquiry request indicating the identification code shown in the certificate request to the server device. The server device receives the inquiry request, collates the identification code shown in the inquiry request with the identification code of each of the plurality of client devices, and transmits an inquiry response indicating the collation result to the certification authority device. The certification authority device receives the inquiry response and issues an electronic certificate including the signature public key shown in the certificate request for the client device that is the source of the certificate request when the identification code shown in the inquiry request is the identification code of any of the plurality of client devices. When each of the plurality of client devices participates in the web conference, it becomes a participating request client and transmits a participation request indicating the identification code to the server device. The server device When receiving the participation request of the first participating request client in the web conference, collate the identification code shown in the received participation request with the member list of the web conference, determine the participation permission of the participating request client based on the collation result, and transmit a participation response indicating the determination result to the participating request client. When receiving a participation request from a participating request client that participates in the web conference after the second time, send an authentication request for the participating request client to all client devices participating in the web conference. When each client device participating in the web conference receives the authentication request and has not performed the key sharing with the child client at that time, it receives the signed exchange key sent from the participating request client, verifies the signature of the signed exchange key, and when the signature of the signed exchange key is correct, sets the participating request client as the child client and performs the key sharing using the exchange key. Each of the plurality of client devices When participating in the web conference for the first time, generates and stores a communication key used for message communication in the web conference. When participating in the web conference after the second time, performs key sharing with the client device that has become the parent client while participating in the web conference, receives the encrypted communication key from the parent client, decrypts the communication key from the encrypted communication key using the shared key with the parent client, and stores the communication key. When not performing the key sharing with the child client while participating in the web conference, sets the newly participating client device in the web conference as the child client and performs the key sharing, updates the stored communication key by hashing, encrypts the updated and stored communication key using the shared key with the child client, sends the encrypted communication key to the child client, and sends a participation notice to the parent client. When receiving a participation notice from the child client, update the stored communication key by hashing.

Citation Information

Patent Citations

  • Electronic conference entry method and electronic conferenc system

    JP1996256145A

  • Video conference system

    JP2002290940A

  • Group communication system and control method thereof, information processor, and program

    JP2005311527A

  • Group members manage group secrets.

    JP2014530554A

  • Information processing apparatus, information processing method, and computer program

    JP2019047430A