Access Management Device and Program
The access management device addresses the complexity of managing multiple access rights and their inclusion relationships by using a directed acyclic graph and one-way functions, reducing the number of keys needed and enhancing security.
Patent Information
- Application Number
- JP2023092961
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-06
- Publication Date
- 2025-06-09
- Estimated Expiration
- 2038-10-23
AI Technical Summary
Existing access control systems face challenges in managing a large number of access rights and their inclusion relationships, leading to increased complexity and difficulty in key management and distribution.
The proposed access management device and program utilize a directed acyclic graph to represent inclusion relationships between access rights, associating public and secret identification information with each node. This system grants secret authentication information to users in a way that conceals it from third parties, reducing the number of keys needed by using a one-way function with homomorphic properties.
This approach effectively reduces the number of keys required for access control, simplifies key management, and enhances security by minimizing the risk of key exposure and unauthorized access.
Smart Images

Figure 0007689755000039 
Figure 0007689755000040 
Figure 0007689755000041
Abstract
Description
Technical Field
[0001] The present invention relates to an access management device and a program.
Background Art
[0002] Privilege management is an important issue for ensuring the security of information systems. In the configuration and operation of general information systems today, there are various types of privileges granted, and the complexity of privilege management is increasing depending on the nature of the organization and operation. Also, against the backdrop of the spread of IoT (Internet of Things) devices, the number of objects to which privileges are reflected is becoming extremely large.
[0003]
[0004] For example, consider a device with multiple sensors installed in a building. As holders of privileges, there are the device manufacturer, the building administrator, the device installer, the occupants of the floor of the building, etc. For example, the device manufacturer holds the privilege to enable firmware updates built into the device regardless of the building, the building administrator holds the management privilege for the devices installed in the building, and the floor occupants hold the read privilege for specific sensors. Such complex privilege management with a large number of management targets is required.
Prior Art Documents
Patent Documents
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-194888 [Summary of the Invention] [Problems to be Solved by the Invention]
[0006] However, in the data management system as described in Patent Document 1, in a situation where complicated and numerous authority management for management targets is required, if a method of assigning keys for access control is adopted according to each device and the number of types of authorities to be granted, the number of required keys increases, and there is a problem that it becomes difficult to manage and distribute the keys.
[0007] On the other hand, since the number of required keys increases, it is difficult to perform access control in a situation where complicated and numerous authority management for management targets is required by key management. When performing complicated access control, a system for confirming access rights is separately prepared, and the access rights are controlled by the system. In a system separately prepared for confirming access rights, the system for controlling access rights becomes a single point of failure, and when the security of the system is breached, there is a problem that all authentications are broken.
[0008] In the present invention, access control that handles a plurality of access rights having an inclusion relationship with each other is handled without separately preparing a system for confirming access rights. Here, as an example of a plurality of access rights having an inclusion relationship with each other, two access rights, an upper access right and a lower access right, are considered, and it is assumed that a user who can exercise the upper access right can exercise the lower access right. That is, it is assumed that the upper access right includes the lower access right.
[0009] In the access control for managing the two access rights, a user who can exercise the upper access right is given two keys, namely, a key for exercising the upper access right and a key for exercising the lower access right, and a user who can exercise the lower access right needs to be given one key for exercising the lower access right. In this access control, due to the inclusion relationship that the upper access right includes the lower access right, in addition to the number of access rights, keys are required for the number of such inclusion relationships.
[0010] The problem to be solved by the present invention is to reduce the number of keys to be managed in an access control that deals with a plurality of access rights having an inclusion relationship with each other, with respect to the number of access rights and the number of inclusion relationships.
[0011] The present invention has been made in view of the above points, and provides an access management device and a program that can reduce the number of keys to be managed in an access control for managing a plurality of access rights having an inclusion relationship with each other, with respect to the number of access rights and the number of inclusion relationships.
Means for Solving the Problem
[0012] The present invention has been made to solve the above problems. One aspect of the present invention is that for each node of a directed acyclic graph showing the inclusion relationship between the access rights by associating an access right with each node, public identification information disclosed to a user exercising the access right, secret identification information which is information essential for exercising the access right, and secret authentication information given to the user are respectively associated with an access right management unit, an access right granting unit that grants the secret authentication information associated by the access right management unit to an access target node which is the node corresponding to the access right exercised by the user among the nodes, in a manner that the secret authentication information is concealed from a third party, access right exercise information indicating a value obtained by inputting the secret authentication information granted by the access right granting unit and the public identification information of a superior node in the directed acyclic graph of the node corresponding to the secret authentication information into a one-way function, and an access right inspection unit that inspects whether or not the secret identification information associated with the access target node satisfies a predetermined relational expression, and is an access management device including these components.
[0013] Also, one aspect of the present invention is that in the above access management device, the one-way function has homomorphic properties, and the access right exercise information is generated by executing a predetermined calculation procedure on the value obtained by inputting the secret authentication information into the one-way function and the public identification information of the superior node.
[0014] Also, one aspect of the present invention is that in the above access management device, in addition to the inclusion relationship shown by the directed acyclic graph, for a logical formula access right which is an access right shown by logical formulas of a plurality of the access rights, based on the secret identification information and the public identification information respectively associated by the access right management unit with the nodes associated with the plurality of the access rights used to represent the logical formula access right, a logical formula secret identification information generation unit that generates logical formula secret identification information which is the secret identification information for the logical formula access right is further provided.
[0015] Also, in one aspect of the present invention, in the above access management device, the target of access by the access right is data, and the data is encrypted using the secret identification information as a key, and the data is decrypted using the secret identification information calculated from the secret authentication information given to the user as a key, thereby enabling access to the data.
[0016] Also, in one aspect of the present invention, in the above access management device, the access right granting unit grants the user the secret authentication information by recording the secret authentication information in a tamper-resistant characteristic module that is a module having tamper-resistant characteristics held by the user, and at least a part of the access right exercise information is calculated within the tamper-resistant characteristic module.
[0017] Also, in one aspect of the present invention, in the above access management device, there is further provided a ticket generation unit that generates a ticket which is a value of a second one-way function using at least a part of the input of the secret authentication information of the access right to the user and user identification information for identifying the user, and the access right granting unit grants the user the ticket generated by the ticket generation unit as the secret authentication information, and the access right inspection unit inspects whether a second access right exercise information obtained by inputting the ticket granted by the access right granting unit into the one-way function and the secret identification information associated with the access target node satisfy a predetermined relational expression.
[0018] Also, in one aspect of the present invention, in the above access management device, there is further provided an unauthorized user determination unit that acquires the user identification information used to generate the ticket from the second access right exercise information generated by the user based on the ticket generated by the ticket generation unit.
[0019] Further, one aspect of the present invention is to cause a computer to associate with each node of a directed acyclic graph indicating an inclusion relationship between access rights by associating an access right with each node, public identification information publicly disclosed to a user exercising the access right, secret identification information that is information essential for exercising the access right, and secret authentication information given to the user, an access right management step; an access right granting step of granting the secret authentication information associated by the access right management step to an access target node, which is the node corresponding to the access right exercised by the user among the nodes, by a method of keeping the secret authentication information hidden from a third party; access right exercise information indicating a value obtained by inputting the secret authentication information granted by the access right granting step and the public identification information of the upper node in the directed acyclic graph of the node corresponding to the secret authentication information into a one-way function; and an access right inspection step of inspecting whether or not the secret identification information associated with the access target node satisfies a predetermined relational expression.
Advantages of the Invention
[0020] According to the present invention, the number of keys to be managed in access control for managing a plurality of access rights having an inclusion relationship with each other can be reduced with respect to the number of access rights and the number of inclusion relationships.
Brief Description of the Drawings
[0021]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Embodiments for Carrying Out the Invention
[0022] (First Embodiment) (Configuration of Access Management System) Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. FIG. 1 is a diagram showing an example of an access management system AS according to the present embodiment. The access management system AS is a system for managing access by a user UE to an access target R. The access management system AS includes a user terminal 1, an access management device 2, an access right information server 3, and an access target server 4.
[0023] The user terminal 1 is an example of the user UE. The user terminal 1 is, for example, a mobile communication terminal such as a smartphone or a personal computer. The user terminal 1 may be a dedicated terminal that a user always wears and carries when receiving services from the environment, such as a security card.
[0024] The user terminal 1 includes a plurality of user terminals 1-i (i = 1, 2, ···, N: N is the number of user terminals). Hereinafter, there are cases where the entire plurality of user terminals 1-i are referred to as the user terminal 1 and cases where one of the plurality of user terminals 1-i is representative and referred to as the user terminal 1. The user terminal 1 accesses an access target R, which is the target of access stored in the access target server 4, via the access management device 2. The access target R is, as an example, data. In the present embodiment, accessing the access target R means, for example, including reading, writing, and executing the access target R that is data, as defined in the access control of UNIX (registered trademark). In the present embodiment, as an example, the access target R includes a plurality of access targets R1 to R9.
[0025] The access management device 2 manages access by the user terminal 1 to the access target R stored in the access target server 4 based on the access right information XI stored in the access right information server 3 and the user management information UL stored in the access right information server 3. The access management device 2 is, for example, a gateway or a gatekeeper.
[0026] Here, in order to access the access targets R1 to R9 included in the access target R, the access rights V1 to V9 corresponding to each of the access targets R1 to R9 are respectively required. The access right information XI is information indicating the inclusion relationship between the access rights V1 to V9 and the information of the key required to exercise the access right V. Hereinafter, the access rights V1 to V9 are collectively referred to as the access right V.
[0027] The user management information UL is information indicating whether the access rights V1 to V9 corresponding to each of the access targets R1 to R9 can be granted to each of the plurality of user terminals 1-i. The user management information UL is, as an example, two-dimensional table-form data. The user management information UL has columns for each of the plurality of user terminals 1-i, and indicates whether the access rights V1 to V9 can be granted for each column.
[0028] The access right information server 3 stores the access right information XI and the user management information UL. The access target server 4 stores the access target R. Here, the access target R is stored encrypted.
[0029] Here, referring to FIG. 2, the access right information XI will be described. FIG. 2 is a diagram showing an example of the access right information XI according to the present embodiment. In the access right information XI, the inclusion relationship between the access rights V is shown by a directed acyclic graph (DAG) OG. In the present embodiment, as an example, the access rights V are nine access rights V1 to V9 whose inclusion relationship is defined with each other. include. The directed acyclic graph OG has nine nodes N1 to N9. The nodes N1 to N9 are respectively associated with the access rights V1 to V9.
[0030] Nodes N1 to N9 are connected by directed edges L with directions (in the example shown in FIG. 2, directed edges L12, L13, L24, L25, L35, L36, L47, L57, L58, L68, L79, and L89). For example, node N1 and node N2 are connected by directed edge L12 in the direction from node N1 to node N2.
[0031] Here, when there is a directed edge from one node Ni to another node Nj, the access right Vi corresponding to node Ni includes the access right Vj corresponding to node Nj. That the access right Vi includes the access right Vj means that by exercising the access right Vi, it is possible to access the access target Rj corresponding to the access right Vj. When the access right Vi includes the access right Vj, the access right Vi includes, in addition to the access right Vj, the access right V included by the access right Vj.
[0032] Hereinafter, when one node and another node are connected by a directed edge L in the direction from the one node to the other node, the one node may be referred to as the upper node and the other node may be referred to as the lower node, respectively. Also, when the access right Vi includes the access right Vj and the access right Vj includes the access right Vk, by applying the transitive law, it may be said that the access right Vi includes the access right Vk, or the node of the access right Vi is the upper node of the node of the access right Vk.
[0033] To each node N, public identification information PK, secret identification information SK, and secret authentication information AI are respectively associated. For example, to node N1, public identification information PK1, secret identification information SK1, and secret authentication information AI1 are associated, and to node N2, public identification information PK2, secret identification information SK2, and secret authentication information AI2 are associated. The public identification information PK, the secret identification information SK, and the secret authentication information AI are information necessary for exercising the above-described access right V.
[0034] Let the public identification information PKi of node Ni be the number xi. Let the number r be the common secret key of access right V. The secret authentication information AIi corresponding to access right Vi is determined by Equation (1).
[0035]
Number
[0036] Here, the number p is a large prime number. The numbers r and xi belong to the set shown by Equation (2), and are randomly selected so as to be relatively prime to p - 1.
[0037]
Number
[0038] When granting the access right Vi corresponding to node Ni to a certain user terminal 1 among a plurality of user terminals 1 - i (i = 1, 2, ···, N: N is the number of user terminals), the secret authentication information AIi shown by Equation (1) is granted so that only the administrator of the access management device 2 can access it, including the user terminal 1. For example, the secret authentication information AIi is transmitted to a tamper-resistant device held by the user terminal 1 using an encryption path and recorded in the device, so that those other than the administrator of the access management device 2 cannot access the secret authentication information AIi. In particular, the value of the secret authentication information AIi is also kept secret from the user to whom the access right Vi is granted. If the value of the secret authentication information AIi is known, the common secret key r will be revealed by multiplying by the reciprocal of the number xi in the modulus p. However, in the third embodiment of the present invention described later, an example is shown in which a tamper-resistant device becomes unnecessary by encoding the secret authentication information AIi so that those other than the administrator of the access management device 2 cannot understand it.
[0039] On one hand, the secret identification information SK is configured as follows. Let the group G be a cyclic group with the number p as its order, and the operation of the group G be described by multiplication. Also, let the element g be a generator of the group G. Assume that the discrete logarithm problem regarding the group G is computationally unsolvable. Therefore, assume that the function represented by Equation (3) is a one-way function with respect to the number x.
[0040]
Number
[0041] Hereinafter, the function represented by Equation (3) is referred to as the one-way function F1. The one-way function F1 is a function that has values in the group G. The one-way function F1 has homomorphism. As methods for constructing one-way functions, for example, a construction method using the discrete logarithm problem and a construction method using prime factorization such as RSA are known. In the construction method using the discrete logarithm problem, a one-way function with homomorphism can be constructed using the discrete logarithm problem over a finite field, the discrete logarithm problem on an elliptic curve, etc. The one-way function F1 of the present embodiment is, as an example, a one-way function constructed by a construction method using the discrete logarithm problem without limiting the group G. Note that as long as the one-way function F1 has homomorphism, it may be a one-way function constructed by other construction methods such as a construction method using prime factorization such as RSA.
[0042] For the node Ni corresponding to the access right Vi, let the set of indices of the nodes N for which there is a path to the node Ni following the direction of the inclusion relation indicated by the directed edge be the set Ai. Here, the index of the node N is, for example, the index i in the case of the node Ni. That is, the set Ai is the set of indices of the upper nodes Nj of the node Ni. In the example shown in FIG. 2, for example, the set A4 for the node N4 is the set consisting of the index 2 of the node N2 and the index 1 of the node N1. In another example, the set A8 for the node N8 is the set consisting of the index 5 of the node N5, the index 2 of the node N2, the index 1 of the node N1, the index 6 of the node N6, and the index 3 of the node N3.
[0043] The secret identification information SKi of node Ni is defined as an element of the group G shown by Equation (4).
[0044]
Number
[0045] In the access target Ri corresponding to node Ni, for example, access control is performed by using the secret identification information SKi as follows. That is, access control is performed in the following manner.
[0046] The access management device 2 that performs access control on the access target Ri performs Diffie-Hellman-Merkle authentication with the user terminal 1. Only when the user terminal 1 can generate the value of the one-way function F1 shown by Equation (5) for the random number λ generated each time authentication is performed, the access to the access target Ri is permitted. Here, the value of the one-way function F1 generated by the user terminal 1 is referred to as access right exercise information GK.
[0047]
Number
[0048] As an example of the access control method, a method can be considered in which the access management device 2 transmits the value of the λ-th power of the generator g shown by Equation (6) to the user terminal 1, and permits access to the access target Ri when the value of Equation (5) or its cryptographic hash value (for example, a value generated using SHA-1, etc.) is received from the user terminal 1. As another example of the access control method, a method can be considered in which the access management device 2 encrypts the access target Ri using the value of Equation (5) as a key, transmits the value of Equation (6) to the user terminal 1, and can decrypt the cipher only when the user terminal 1 can calculate the value of Equation (5).
[0049]
Number
[0050] For any index j included in the set Ai, assume that the user terminal 1 is granted the access right Vj. Therefore, it is assumed that the user terminal 1 can execute the calculation of the one-way function F1 represented by Equation (3) with the secret authentication information AIj represented by Equation (7) as part of the input.
[0051]
Number
[0052] Assume that the user terminal 1 cannot access the secret authentication information AIj. For example, the secret authentication information AIj is recorded in a tamper-resistant device held by the user terminal 1, the tamper-resistant device incorporates a microcomputer, and calculates the value of the one-way function F1 represented by Equation (8) in a secure calculation area within the tamper-resistant device and outputs only the result.
[0053]
Number
[0054] Here, in the exercise of the access right Vi included by the access right Vj, first, the value of the one-way function F1 represented by Equation (8) is calculated.
[0055] Next, the exercise of the access right Vi is executed by calculating the secret identification information SKi for the access right Vi according to Equation (10) using the set of public identification information PK represented by Equation (9) which is a set of public identification information PK, and the number xi which is the public identification information PKi of the node Ni.
[0056]
Number
[0057]
Number
[0058] As described above, the user terminal 1 to which the upper access right Vj is granted can exercise any lower access right Vi.
[0059] Next, referring to FIG. 3, the configurations of the user terminal 1 and the access management device 2 will be described in detail. FIG. 3 is a diagram showing an example of the configurations of the user terminal 1 and the access management device 2 according to the present embodiment. Since the functions of the plurality of user terminals 1-i (i = 1, 2, ···, N: N is the number of user terminals) shown in FIG. 1 are equivalent to each other, in FIG. 3, one of the plurality of user terminals 1-i (i = 1, 2, ···, N: N is the number of user terminals) shown in FIG. 1 is represented as the user terminal 1 and illustrated.
[0060] The user terminal 1 includes a communication unit 10, a public information acquisition unit 11, a public information storage unit 12, an access request unit 13, a tamper-resistant characteristic module 14, and an access execution unit 15.
[0061] The communication unit 10 is a communication module and transmits and receives various information to and from the access management device 2. The public information acquisition unit 11 acquires the public information PI supplied by the access management device 2. The public information PI includes public identification information PK and group information GI. The group information GI is information indicating the group G and includes a generator of the group G and a number p that is the order of the group G. Note that the group information GI may include, for example, the defining equation of the group G when the group G is an elliptic curve. The public information storage unit 12 stores the public information PI acquired by the public information acquisition unit 11.
[0062] The access request unit 13 supplies access request information AR to the access management device 2. The access request information AR is information indicating the access target node AN. Here, the access target node AN is a node Ni corresponding to the access target Ri accessed by the user terminal 1 among the nodes N of the directed acyclic graph OG.
[0063] The tamper-resistant characteristic module 14 is a module having tamper-resistant characteristics. That is, the tamper-resistant characteristic module 14 has the property that data, programs held inside the device itself, and calculation processes executed inside the device itself cannot be observed or interfered with from the outside. The tamper-resistant characteristic module 14 includes a secret authentication information acquisition unit 140, a secret authentication information storage unit 141, and an access right exercise information generation unit 142.
[0064] The secret authentication information acquisition unit 140 acquires the secret authentication information AI supplied from the access management device 2. The secret authentication information storage unit 141 stores the secret authentication information AI acquired by the secret authentication information acquisition unit 140. The access right exercise information generation unit 142 generates access right exercise information GK based on the public information PI stored in the public information storage unit 12 and the secret authentication information AI stored in the secret authentication information storage unit 141. To generate the access right exercise information GK, the access right exercise information generation unit 142 has a function of executing a one-way function F1.
[0065] When access to the access target R is permitted by the access management device 2, the access execution unit 15 executes access to the access target R.
[0066] The access management device 2 includes a communication unit 20, a user management unit 21, an access right management unit 22, an access request acquisition unit 23, an access right granting unit 24, a random number generation unit 25, an access right inspection unit 26, and an access permission unit 27.
[0067] The communication unit 20 is a communication module that transmits and receives various types of information to and from the user terminal 1. The user management unit 21 determines whether to grant the user terminal 1 the access right V to the access target R based on the user management information UL stored in the access right information server 3. The access right management unit 22 manages the access right information XI stored in the access right information server 3. Here, the access right management unit 22 associates the public identification information PK, the secret identification information SK, and the secret authentication information AI with each node N of the directed acyclic graph OG, respectively.
[0068] The access request acquisition unit 23 acquires the access request information AR supplied from the user terminal 1. The random number generation unit 25 generates a random number λ and supplies it to the access right granting unit 24.
[0069] The access right inspection unit 26 supplies the secret authentication information AI to the user terminal 1. Also, the access right granting unit 24 calculates the value of the λ-th power of the generator g represented by Equation (6) based on the random number λ generated by the random number generation unit 25 according to the access request information AR acquired by the access request acquisition unit 23, and supplies the calculated value to the user terminal 1 to perform Diffie-Hellman-Merkle authentication.
[0070] As a result, the access right inspection unit 26 inspects whether the value of the λ-th power of the access right exercise information GK supplied from the user terminal 1 matches the value of the λ-th power of the secret identification information SK associated with the access target node AN indicated by the access request information AR. That is, the access right inspection unit 26 inspects whether the access right exercise information GK and the secret identification information SK match.
[0071] Here, since the group G is configured such that it is computationally difficult to solve the discrete logarithm problem, it is impossible to know the random number λ from the value of the random number λ-th power of the generator g supplied to the user terminal 1. Since the access right exercise information GK, which is expected to match the secret identification information SK, is masked by the random number λ, even if the communication between the user terminal 1 and the access management device 2 is intercepted, the secret identification information SK does not leak from the intercepted communication content. This authentication method is known as the Diffie-Hellman-Merkle authentication method. The access permission unit 27 permits or prohibits access to the access target R of the user terminal 1 according to the determination result of the access right inspection unit 26.
[0072] (Processing in the access management system) With reference to FIG. 4, the access management process, which is the process of the access management device 2 before access by the user terminal 1, will be described. FIG. 4 is a diagram showing an example of the access management process of the access management device 2 according to the present embodiment. The process shown in FIG. 4 starts when the operation of the access management system AS is started.
[0073] Step S100: The access right management unit 22 associates the public identification information PK, the secret identification information SK, and the secret authentication information AI with each node N of the directed acyclic graph OG included in the access right information XI stored in the access right information server 3 via the communication unit 20.
[0074] For example, here the access right management unit 22 can encrypt the access target R by associating the secret identification information SK with the node N corresponding to the access target R. In order to avoid all the access targets R associated with the node N being encrypted with the same key, a random number λ is generated for each access target R, the value of the random number λ-th power of the secret identification information SK is used as the encryption key, and the value of the random number λ-th power of the generator g shown in formula (5) shown in formula (6) is attached to the encrypted access target R, thereby combining Diffie-Hellman-Merkle authentication and data confidentiality by encryption. This encryption method is known as the ElGamal encryption method.
[0075] As described above, the directed acyclic graph OG shows the inclusion relationship between the access rights V by associating each node with an access right V. The public identification information PK is information that is publicly disclosed to the user UE exercising the access right V. The secret identification information SK is information essential for exercising the access right V. The secret authentication information AI is information given to the user UE.
[0076] Therefore, the access right management unit 22 associates the public identification information PK publicly disclosed to the user UE exercising the access right V, the secret identification information SK that is essential information for exercising the access right V, and the secret authentication information AI given to the user UE with each node N of the directed acyclic graph OG that shows the inclusion relationship between the access rights V by associating each node with an access right V.
[0077] Also, the target of access by the access right V (in this example, the access target R) is data, and the data is encrypted using the secret identification information SK or the value of the random number λ-th power of the secret identification information SK as the key. Here, access to the data becomes possible by decrypting the data using the value of the random number λ-th power of the secret identification information SK calculated from the secret authentication information AI given to the user UE as the key.
[0078] Here, the secret identification information SKi associated with the lower-level node Ni associated with the access right Vi included in the access right Vj associated with a certain upper-level node Nj by the method shown in Equation (10) is calculated via the one-way function F1 from the value obtained by inputting the λ-th power of the random number of the generator g and the secret authentication information AIj associated with the node Nj into the one-way function F1, and the public identification information PK and the public identification information PKi associated with the node N indicated by the set Ai among the public identification information PK.
[0079] That is, for the lower-level node N associated with the access right V included in the access right V associated with a certain upper-level node among the nodes N, the secret identification information SK associated with it by the access right management unit 22 is obtained by using the one-way function F1 from the secret authentication information AI associated with the upper-level node by the access right management unit 22, a predetermined public identification information PK among the public identification information PK, and the λ-th power of the random number of the generator g.
[0080] Step S110: The access right management unit 22 supplies the public identification information PK to each of the plurality of user terminals 1-i (i = 1, 2, ···, N: N is the number of user terminals) via the communication unit 20.
[0081] Step S120: The user management unit 21 determines the user terminal 1 to which the access right V is to be granted based on the user management information UL stored in the access right information server 3. The user management unit 21 supplies the determination result to the access right granting unit 24.
[0082] Step S130: The access right granting unit 24 grants the access right V to the user terminal 1. Here, the access right granting unit 24 supplies the secret authentication information AI to the user terminal 1 via the communication unit 20, thereby granting the access right V to the user terminal 1. The secret authentication information AI that the access right granting unit 24 grants to the user terminal 1 is the secret authentication information AI associated with the access target node AN indicated by the access request information AR acquired by the access request acquisition unit 23.
[0083] Next, referring to FIG. 5, the processing of the user terminal 1 before access is described. FIG. 5 is a diagram showing an example of the acquisition process of the public information and the secret authentication information of the user terminal 1 according to the present embodiment. Step S200: The public information acquisition unit 11 acquires the public identification information PK supplied from the access management device 2 via the communication unit 10. The public information acquisition unit 11 stores the acquired public identification information PK in the public information storage unit 12.
[0084] Step S210: The secret authentication information acquisition unit 140 acquires the secret authentication information AI supplied from the access management device 2 via the communication unit 10. The secret authentication information acquisition unit 140 stores the acquired secret authentication information AI in the secret authentication information storage unit 141.
[0085] Here, since the secret authentication information acquisition unit 140 and the secret authentication information storage unit 141 are provided in the tamper-resistant characteristic module 14, the secret authentication information AI stored in the secret authentication information storage unit 141 cannot be referred to by other functional units of the user terminal 1 provided outside the tamper-resistant characteristic module 14.
[0086] Next, referring to FIG. 6, the processing when the user terminal 1 accesses the access target R is described. FIG. 6 is a diagram showing an example of the access execution process of the user terminal 1 according to the present embodiment. Step S300: The access request unit 13 requests access to the access target R from the access management device 2. Here, the access request unit 13 requests access by supplying access request information AR to the access management device 2 via the communication unit 10.
[0087] Step S310: The secret authentication information acquisition unit 140 acquires the random number λ power of the generator g of the group G represented by the formula (6) supplied from the access management device 2, and supplies it to the access right exercise information generation unit 142.
[0088] Step S320: The access right exercise information generation unit 142 generates the random number λ power value of the access right exercise information GK from the secret authentication information AI stored in the secret authentication information storage unit 141, the predetermined public identification information PK included in the public information PI stored in the public information storage unit 12, and the value of the random number λ power of the generator g supplied from the secret authentication information acquisition unit 140. Here, the access right exercise information GK is represented by the above-described formula (5). That is, the access right exercise information GK is generated by executing a predetermined calculation procedure on the value obtained by inputting the secret authentication information AI into the one-way function F1 and the public identification information PK of the upper node.
[0089] The access right exercise information generation unit 142 is provided in the tamper-resistant characteristic module 14. That is, the access right exercise information GK is calculated within the tamper-resistant characteristic module 14. Since the access right exercise information GK is calculated within the tamper-resistant characteristic module 14, the calculation process of the access right exercise information GK is not referenced from other functional units of the user terminal 1 provided outside the tamper-resistant characteristic module 14.
[0090] Note that since the one-way function F1 of the present embodiment satisfies homomorphic properties, the access right exercise information generation unit 142 may calculate the part of the access right exercise information GK that requires the secret authentication information AI, and cause an external device to calculate the remaining part of the access right exercise information GK that uses the public identification information PK. That is, at least a part of the access right exercise information GK is calculated within the anti-tampering characteristic module 14.
[0091] In this embodiment, since the value of the random number λ power of the access right exercise information GK is generated from the secret authentication information AI, the predetermined public identification information PK, and the value of the random number λ power of the generator g in the law p, the secret authentication information AI will not be decoded by a third party other than the administrator of the access management device 2. The reason why the secret authentication information AI will not be decoded by a third party other than the administrator of the access management device 2 is based on the DDH (Decisional Diffie Hellman) hypothesis.
[0092] Step S330: The access right exercise information generation unit 142 supplies the generated access right exercise information GK to the access management device 2 via the communication unit 10.
[0093] Step S340: The access request unit 13 determines whether the access to the access target R is permitted by the access management device 2. Here, when the access request unit 13 acquires the access permission information AP supplied from the access management device 2, it determines that the access to the access target R is permitted. When the access request unit 13 acquires the access prohibition information AD supplied from the access management device 2, it determines that the access to the access target R is not permitted.
[0094] When the access request unit 13 determines that the access to the access target R is permitted (Step S340; YES), the access execution unit 15 executes the process of Step S350. On the other hand, when the access request unit 13 determines that the access to the access target R is not permitted (Step S340; NO), the process ends.
[0095] Step S350: The access execution unit 15 executes the access to the access target R via the communication unit 10.
[0096] Next, referring to FIG. 7, the process by which the access management device 2 verifies access to the access target R of the user terminal 1 will be described. FIG. 7 is a diagram showing an example of the access verification process of the access management device 2 according to the present embodiment.
[0097] Step S400: The access request acquisition unit 23 acquires the access request information AR supplied from the user terminal 1 via the communication unit 20. The access request acquisition unit 23 supplies the acquired access request information AR to the access right inspection unit 26.
[0098] Step S410: The access right inspection unit 26 supplies the value of the random number λ power of the generator g of the group G to the user terminal 1 via the communication unit 20. Here, the random number generation unit 25 generates a random number λ each time the access request acquisition unit 23 acquires the access request information AR in step S400.
[0099] Here, as described in step S210 of FIG. 5, the secret authentication information AI given to the user terminal 1 is stored in the secret authentication information storage unit 141 of the tamper-resistant characteristic module 14 held by the user terminal 1. That is, the access right granting unit 24 grants the secret authentication information AI to the user UE by recording the secret authentication information AI in the tamper-resistant characteristic module 14, which is a module having a tamper-resistant characteristic held by the user UE.
[0100] The access right granting unit 24 grants the secret authentication information AI to the user terminal 1, which is the user UE, by recording the secret authentication information AI in the tamper-resistant characteristic module 14, so the secret authentication information AI is concealed from a third party. Here, the third party includes a user outside the access management system AS, a user terminal 1 other than the user terminal 1 that supplied the access request information AR to the access management device 2, and the user terminal 1 that supplied the access request information AR to the access management device 2. The secret authentication information AI is referred to from the access management device 2.
[0101] That is, the access right granting unit 24 grants the user UE, by a method that conceals the secret authentication information AI from a third party, the secret authentication information AI associated by the access right management unit 22 with the access target node AN which is the node N corresponding to the access right V exercised by the user UE among the nodes N.
[0102] Step S420: The access right inspection unit 26 acquires, via the communication unit 20, the access right exercise information GK supplied from the user terminal 1.
[0103] Step S430: The access right inspection unit 26 determines whether or not the access right exercise information GK acquired in step S420 matches the random number λ power of the secret identification information SK associated with the access target node AN indicated by the access request information AR. That is, the fact that the access right exercise information GK matches the random number λ power of the secret identification information SK means that the access right exercise information GK matches the value including the random number λ represented by the above-described formula (5). Note that the fact that the access right exercise information GK matches the random number λ power of the secret identification information SK is an example of the access right exercise information GK and the secret identification information SK satisfying a predetermined relational expression.
[0104] The access right inspection unit 26 inspects whether or not the access right exercise information GK obtained by using the secret authentication information AI granted by the access right granting unit 24, the public identification information PK of the node N corresponding to the secret authentication information AI, the public identification information PK of the upper node in the directed acyclic graph OG of the node N, and the one-way function F1, and the secret identification information SK associated with the access target node AN satisfy a predetermined relational expression.
[0105] When the access right inspection unit 26 determines that the access right exercise information GK and the secret identification information SK satisfy the above-described predetermined relational expression (step S430; YES), it supplies a determination result indicating that the access right has been confirmed to the access permission unit 27. Thereafter, the access permission unit 27 executes the process of step S440. On the other hand, when the access right inspection unit 26 determines that the access right exercise information GK and the secret identification information SK do not satisfy the above-described predetermined relational expression (step S430; NO), it supplies a determination result indicating that the access right is not confirmed to the access permission unit 27. Thereafter, the access permission unit 27 executes the process of step S450.
[0106] Step S440: The access permission unit 27 permits access to the access target R of the user terminal 1. The access permission unit 27 supplies the access permission information AP to the user terminal 1 via the communication unit 20.
[0107] Step S450: The access permission unit 27 prohibits access to the access target R of the user terminal 1. The access permission unit 27 supplies the access prohibition information AD to the user terminal 1 via the communication unit 20.
[0108] In this embodiment, the case where the access right exercise information GK is generated using the random number λ and the access right inspection unit 26 determines whether the access right exercise information GK matches the value including the random number λ represented by the formula (5), that is, whether the relational expression that the access right exercise information GK matches the random number λ power of the secret identification information SK holds has been described. However, the present invention is not limited to this. The random number λ may not be used for the generation of the access right exercise information GK, and the access right exercise information GK may be generated as the value represented by the formula (4). When the access right exercise information GK is generated as the value represented by the formula (4), in step S440, the access right inspection unit 26 determines whether the access right exercise information GK matches the secret identification information SK represented by the formula (4).
[0109] Note that when the random number λ is not used for the generation of the access right exercise information GK and the access right exercise information GK is generated as the value represented by the formula (4), the access management device 2 may not include the random number generation unit 25. Also in this case, the processes of step S310 in FIG. 6 and step S410 in FIG. 7 are omitted.
[0110] In addition, in this embodiment, the secret authentication information AI has been described for the case where it is given from the access management device 2 to the user terminal 1 in step S130 of FIG. 4, but it is not limited to this. After acquiring the access request information AR supplied from the user terminal 1 in step S400 of FIG. 7, the secret authentication information AI may be given from the access management device 2 to the user terminal 1. For example, in step S410 of FIG. 7, the secret authentication information AI may be given from the access management device 2 to the user terminal 1 together with the value of the random number λ power of the generator g of the group G.
[0111] As described above, the access management device 2 according to this embodiment includes an access right management unit 22, an access right granting unit 24, and an access right inspection unit 26. The access right management unit 22 associates, with each node N of the directed acyclic graph OG showing the inclusion relationship between the access rights V by associating the access right V with each node, the public identification information PK publicly disclosed to the user UE exercising the access right V, the secret identification information SK which is essential information for exercising the access right V, and the secret authentication information AI given to the user UE. The access right granting unit 24 grants the secret authentication information AI associated by the access right management unit 22 to the access target node AN which is the node N corresponding to the access right V exercised by the user UE among the nodes N, by a method in which the secret authentication information AI is concealed from a third party, to the user UE. The access right inspection unit 26 inspects whether or not the access right exercise information GK indicating the value obtained by inputting the secret authentication information AI granted by the access right granting unit 24 and the public identification information PK of the upper node in the directed acyclic graph OG of the node N corresponding to the secret authentication information AI, and the secret identification information SK associated with the access target node AN satisfy a predetermined relational expression.
[0112] With this configuration, in the access management device 2 according to this embodiment, it is associated with the lower node Since the secret identification information SK is obtained by inputting the secret authentication information AI associated with the upper node and a predetermined public identification information PK among the public identification information PK into the one-way function F1, the number of keys to be managed in access control for managing a plurality of access rights having an inclusion relationship with each other can be reduced with respect to the number of access rights and the number of inclusion relationships. In the access management device 2 according to the present embodiment, it is possible to realize access control for complex and large-scale targets while keeping the number of keys to be managed small.
[0113] Further, in the access management device 2 according to the present embodiment, the one-way function F1 has homomorphic properties, and the access right exercise information GK is generated by executing a predetermined calculation procedure on the value obtained by inputting the secret authentication information AI into the one-way function F1 and the public identification information PK of the upper node in the directed acyclic graph OG of the node N. With this configuration, the input of the one-way function F1 calculated within the tamper-resistant characteristic module 14 is only the secret authentication information AI, and outside the tamper-resistant characteristic module 14, by executing a predetermined calculation procedure on the output of the one-way function F1 and the public identification information PK of the upper node, it becomes possible to generate the necessary access right exercise information GK, and it becomes possible to reduce the data input / output to the tamper-resistant characteristic module 14 and the calculation amount within the tamper-resistant characteristic module 14 with limited computing power.
[0114] Also, in the access management device 2 according to the present embodiment, the target of access by the access right V (in this example, the access target R) is data, and the data is encrypted using the secret identification information SK as a key, and access to the data becomes possible by decrypting the data using the secret identification information SK calculated from the secret authentication information AI given to the user UE as a key. With this configuration, in the access management device 2 according to the present embodiment, among the secret identification information SK which is a key for encrypting data, the secret identification information SK associated with the lower nodes is obtained by inputting the secret authentication information AI associated with the upper nodes and a predetermined public identification information PK among the public identification information PK into the one-way function F1. Therefore, when managing the access rights to data, the number of keys to be managed can be reduced with respect to the number of access rights and the number of inclusion relationships.
[0115] Also, in the access management device 2 according to the present embodiment, the access right granting unit 24 grants the secret authentication information AI to the user UE by recording the secret authentication information AI in the tamper-resistant characteristic module 14 which is a module having tamper-resistant characteristics held by the user UE. Also, at least a part of the access right exercise information GK is calculated within the tamper-resistant characteristic module 14. With this configuration, in the access management device 2 according to the present embodiment, the secret authentication information AI can be granted to the user by a method that is concealed from a third party, and the access right exercise information GK can be calculated by a method that is concealed from a third party. Therefore, the access rights can be managed more securely than in the case where the tamper-resistant characteristic module 14 is not used. In the access management device 2 according to the present embodiment, when the one-way function F1 satisfies homomorphic properties, the part of the access right exercise information GK that requires the secret authentication information AI is calculated within the tamper-resistant characteristic module 14, and the remaining part of the access right exercise information GK that uses the public identification information PK is calculated by an external device. By doing so, the calculation efficiency can be improved.
[0116] (Second Embodiment) Hereinafter, a second embodiment of the present invention will be described in detail with reference to the drawings. In access control that deals with a plurality of access rights having an inclusion relationship with each other, it is common for a new access right to be defined using the logical relationship (logical formula) of existing access rights. For example, the first table and the second of a relational database When independent access rights are set for the first table and the second table respectively, in order to access the join of the first table and the second table, it is necessary to have the access rights for both the first table and the second table. That is, the access right represented by the logical product of the access rights for both the first table and the second table is required.
[0117] Conversely, in order to access the projection to the columns commonly included in the first table and the second table, it is sufficient to have the access right for either the first table or the second table. The said access right is represented by the logical sum of the access rights for both the first table and the second table.
[0118] In the above first embodiment, the case where the access management device handles access rights whose inclusion relationship is shown by a directed acyclic graph has been described. In this embodiment, the case where the access management device newly sets an access right represented by an arbitrary logical formula among the already defined two or more access right groups will be described.
[0119] For example, for simplicity, assume that the public identification information of the root authority is 1, the secret identification information is the value shown by formula (11), and the secret authentication information is the number r.
[0120]
Equation
[0121] Hereinafter, for simplicity of explanation, consider the access rights V1 and V2 directly under the root authority, but this assumption is not essential. The public identification information of the access right Vi is the value shown by formula (12), the secret identification information SKi is the value shown by formula (13), and the secret authentication information is the value shown by formula (14). When the access right Vi is not directly under the root authority, similar to the case of the above first embodiment, for example, the secret identification information may be determined by formula (4). In fact, formula (13) is nothing but the value of formula (4) when Ai = {1} and xi = 1.
[0122]
Number
[0123]
Number
[0124]
Number
[0125] Here, the access right represented by a logical formula of two or more access rights is referred to as a logical formula access right LV. Also, the secret authentication information associated with the logical formula access right LV is referred to as a logical formula secret identification information LSK. The secret authentication information associated with the logical formula access right LV is referred to as a logical formula secret authentication information LAI. The public identification information associated with the logical formula access right LV is referred to as a logical formula public identification information LPK.
[0126] Let the logical formula access right LV described by the logical product (AND) of the access right V1 and the access right V2 be the logical formula access right V1∧2 . Let the logical formula public identification information LPK of the logical formula access right V1∧2 be the value shown by the formula (15). In particular, when the logical formula access right V1∧2 is not explicitly given to the user and access is permitted only to the user who has been given both the access right V1 and the access right V2, the value of the logical formula public identification information LPK may be 1.
[0127]
Number
[0128] Let the logical formula secret identification information LSK of the logical formula access right V1∧2 be the value shown by the formula (16), and let the logical formula secret authentication information LAI of the logical formula access right V1∧2 be the value shown by the formula (17).
[0129]
Number
[0130]
Number
[0131] Here, a user to whom both the secret authentication information AI1 and the secret authentication information AI2 are given can calculate the logical formula secret identification information LSK of the logical formula access right V1∧2 by the operation of formula (18).
[0132]
Number
[0133] It can be seen that there are two types of users who can exercise the logical formula access right V1∧2 by the operation of formula (18). The first type of user is a user to whom the access right V1 and the access right V2 are respectively given, and thus can calculate both the value represented by formula (19) and the value represented by formula (20).
[0134]
Number
[0135]
Number
[0136] The second type of user is a user to whom the logical formula access right V1∧2 is given, and thus can calculate the value represented by formula (21).
[0137]
Number
[0138] Only the first user or the second user can exercise the logical formula access right. The first user simultaneously has any access right included in access right V1 and any access right included in access right V2. On the other hand, the second user has only the logical formula access right V1∧2 . V1∧2
[0139] Here, the access right described by the logical sum (OR) of access right V1 and access right V2 is defined as the logical formula access right V1∨2 . If the logical formula secret identification information LSK of the logical formula access right V1∨2 is determined by the value shown in formula (22), and the logical formula secret authentication information LAI of the logical formula access right V1∨2 is determined by the value shown in formula (23), then the logical formula access right V1∨2 can be constructed in the same manner as in the above-described logical product case.
[0140]
Number
[0141]
Number
[0142] By recursively combining the above configurations, it becomes possible to construct an access right described by an arbitrary logical formula with existing access rights as arguments using public identification information, secret identification information, and secret authentication information.
[0143] (Configuration of Access Management System) The access management system according to this embodiment is referred to as access management system ASa. Also, the user terminal according to this embodiment is referred to as user terminal 1a, the access management device is referred to as access management device 2a, and the access right information server is referred to as access right information server 3a.
[0144] FIG. 8 is a diagram showing the configurations of the user terminal 1a and the access management device 2a according to the present embodiment. When comparing the user terminal 1a (FIG. 8) according to the present embodiment with the user terminal 1 (FIG. 3) according to the first embodiment, the public information acquisition unit 11a, the public information storage unit 12a, the access request unit 13a, and the anti-tampering characteristic module 14a are different. Here, the functions of the other components (communication unit 1 0 and the access execution unit 15) are the same as those in the first embodiment. Also, when comparing the access management device 2a (FIG. 8) according to the present embodiment with the access management device 2 (FIG. 3) according to the first embodiment, the user management unit 21a, the access right management unit 22a, the access request acquisition unit 23a, the access right granting unit 24a, the access right inspection unit 26a, the access permission unit 27a, and the logical formula secret identification information generation unit 28a are different. Here, the functions of the other components (communication unit 20 and the random number generation unit 25) are the same as those in the first embodiment. Also, when comparing the access right information server 3a (FIG. 8) according to the present embodiment with the access right information server 3 (FIG. 3) according to the first embodiment, the stored access right information XIa is different. Here, the information indicated by the user management information UL is the same as that in the first embodiment. The configuration of the access target server 4 (FIG. 8) according to the present embodiment is the same as the configuration of the access target server 4 (FIG. 3). The description of the same functions as those in the first embodiment is omitted, and in the second embodiment, the description will focus on the parts different from the first embodiment.
[0145] The user terminal 1a includes a communication unit 10, a public information acquisition unit 11a, a public information storage unit 12a, an access request unit 13a, an anti-tampering characteristic module 14a, and an access execution unit 15.
[0146] The public information acquisition unit 11a acquires the public information PIa supplied by the access management device 2. The public information PIa includes public identification information PK, group information GI, and logical formula public identification information LPK. The public information storage unit 12a stores the public information PIa acquired by the public information acquisition unit 11a.
[0147] The access request unit 13a supplies logical formula access request information LAR to the access management device 2a. Here, the logical formula access request information LAR is information indicating one or more access targets R indicated by a logical formula. The logical formula access request information LAR indicates, for example, the combination of the access target R1 and the access target R2. Also, in another example, the logical formula access request information LAR indicates the common part of the access target R1 and the access target R2.
[0148] The anti-tamper characteristic module 14a includes a secret authentication information acquisition unit 140a, a secret authentication information storage unit 141a, and an access right exercise information generation unit 142a. The secret authentication information acquisition unit 140a acquires secret authentication information AI and logical formula secret authentication information LAI supplied from the access management device 2a. The secret authentication information storage unit 141a stores the secret authentication information AI and the logical formula secret authentication information LAI acquired by the secret authentication information acquisition unit 140a.
[0149] The access right exercise information generation unit 142a generates logical formula access right exercise information LGK based on the public information PIa stored in the public information storage unit 12, the secret authentication information AI stored in the secret authentication information storage unit 141, and the logical formula secret authentication information LAI stored in the secret authentication information storage unit 141. Here, for example, the value of the one-way function F1 generated by the user terminal 1a according to the above-described formula (18) is referred to as the logical formula access right exercise information LGK.
[0150] The access management device 2a includes a communication unit 20, a user management unit 21a, an access right management unit 22a, an access request acquisition unit 23a, an access right granting unit 24a, a random number generation unit 25, an access right inspection unit 26a, an access permission unit 27a, and a logical formula secret identification information generation unit 28a.
[0151] The user management unit 21a determines whether it is possible to grant a logical formula access right LV to the user terminal 1a based on the user management information UL stored in the access right information server 3a. The access right management unit 22a associates public identification information PK, secret identification information SK, and secret authentication information AI with each node N of the directed acyclic graph OG, respectively. Further, the access right management unit 22a associates logical formula public identification information LPK, logical formula secret identification information LSK, and logical formula secret authentication information LAI with the logical formula access right V1∧2 For the logical formula access right, it associates logical formula public identification information LPK, logical formula secret identification information LSK, and logical formula secret authentication information LAI.
[0152] The access request acquisition unit 23a acquires logical formula access request information LAR supplied from the user terminal 1a. When explicitly granting the logical formula access right LV, the access right granting unit 24a supplies the logical formula secret authentication information LAI to the user terminal 1. The logical formula secret identification information generation unit 28a generates the logical formula secret identification information LSK.
[0153] Based on the logical formula access request information LAR acquired by the access request acquisition unit 23, the access right inspection unit 26a supplies the user terminal 1a with the λ-th power of the generator g of the group G by the formula (6) from the random number λ generated by the random number generation unit 25, and checks whether the logical formula access right exercise information LGK supplied from the user terminal 1a matches the λ-th power of the logical formula secret identification information LSK associated with the access target R represented by the logical formula indicated by the logical formula access request information LAR. Based on the determination result of the access right inspection unit 26a, the access permission unit 27a permits or prohibits access to the access target R represented by the logical formula of the user terminal 1.
[0154] The access right information server 3a stores access right information XIa and user management information UL. Here, the access right information XIa is information indicating the inclusion relationship among the access rights V1 to V9, the key required to exercise the access right V, and the information of the key required to exercise the logical formula access right LV.
[0155] (Processing in the access management system) FIG. 9 is a diagram showing an example of the access management process of the access management apparatus 2a according to the present embodiment. The process shown in FIG. 9 starts when the operation of the access management system ASa is started.
[0156] Step S500: The access right management unit 22a associates, via the communication unit 20, the public identification information PK, the secret identification information SK, and the secret authentication information AI with each node N of the directed acyclic graph OG included in the access right information XIa stored in the access right information server 3a. Further, the access right management unit 22a associates, via the communication unit 20, the logical formula public identification information LPK, the logical formula secret identification information LSK, and the logical formula secret authentication information LAI with the logical formula access right LV included in the access right information XIa stored in the access right information server 3a.
[0157] Step S510: The logical formula secret identification information generation unit 28a generates the logical formula secret identification information LSK. Here, the logical formula secret identification information LSK is, in addition to the inclusion relationship between the access rights V indicated by the directed acyclic graph OG, for the logical formula access right LX which is an access right represented by the logical formulas of a plurality of access rights V, the secret identification information SK associated by the access right management unit 22a with the node N associated with the plurality of access rights V used to represent the logical formula access right LX, and based on the public identification information PK, generates the logical formula secret identification information LSK which is the secret identification information SK for the logical formula access right LX.
[0158] Step S520: The access right management unit 22a supplies, via the communication unit 20, the public identification information PK to each of the plurality of user terminals 1-i (i = 1, 2, ···, M: M is the number of user terminals). Further, the access right management unit 22a supplies, via the communication unit 2 0, the logical formula public identification information LPK to each of the plurality of user terminals 1-i (i = 1, 2, ···, M: M is the number of user terminals).
[0159] Step S530: The user management unit 21a determines whether to grant the access right V and the logical formula access right LV to the user terminal 1a based on the user management information UL stored in the access right information server 3a. The user management unit 21a supplies the determination result to the access right granting unit 24.
[0160] For example, when the user management unit 21a determines whether to grant the logical formula access right V1∧2 , based on the user management information UL, it determines whether to permit the user terminal 1a to access the combination of the access target R1 and the access target R2.
[0161] Also, for example, when the user management unit 21a determines whether to grant the logical formula access right V1∨2 , based on the user management information UL, it determines whether to permit the user terminal 1a to access the common part of the access target R1 and the access target R2.
[0162] Step S540: The access right granting unit 24a grants the access right V and the logical formula access right LV to the user terminal 1a. Here, the access right granting unit 24a grants the access right V to the user terminal 1a by supplying the secret authentication information AI and the logical formula secret authentication information LAI to the user terminal 1a via the communication unit 20.
[0163] Next, referring to FIG. 10, the processing of the user terminal 1 before access is described. FIG. 10 is a diagram showing an example of the process of acquiring the public information and the secret authentication information of the user terminal 1 according to the present embodiment. Step S600: The public information acquisition unit 11 acquires the public identification information PK and the logical formula public identification information LPK supplied from the access management device 2 via the communication unit 10. The public information acquisition unit 11 stores the acquired public identification information PK and the logical formula public identification information LPK in the public information storage unit 12.
[0164] Step S610: If the access right that satisfies the logical formula is not granted, for example, if either access right V1 or access right V2 is not granted to the logical formula access right V1∧2 the secret authentication information acquisition unit 140a acquires the logical formula secret authentication information LAI supplied from the access management device 2a via the communication unit 10. The secret authentication information acquisition unit 140a stores the acquired logical formula secret authentication information LAI in the secret authentication information storage unit 141a.
[0165] Next, referring to FIG. 11, the processing when the user terminal 1a accesses the access target R indicated by the logical formula will be described. FIG. 11 is a diagram showing an example of the access execution process of the user terminal 1a according to the present embodiment. Since the processes of step S710, step S740, and step S750 are the same as the processes of step S310, step S340, and step S350 in FIG. 6, the description thereof will be omitted.
[0166] Step S700: The access request unit 13a requests the access management device 2a to access the access target R represented by the logical formula. Here, the access request unit 13a requests the access by supplying the logical formula access request information LAR to the access management device 2a via the communication unit 10.
[0167] Step S720: The access right exercise information generation unit 142a generates the logical formula access right exercise information LGK based on the public information PIa stored in the public information storage unit 12a and the logical formula secret authentication information LAI stored in the secret authentication information storage unit 141a.
[0168] Here, if necessary, the access right exercise information generation unit 142a inputs the given secret authentication information including the logical formula secret authentication information LAI, the logical formula public identification information LPK included in the public information PIa, and the predetermined public identification information PK, along with the random number λ-th power of the generator g of the group G supplied from the secret authentication information acquisition unit 140a, into the one-way function F1 represented by the above-described formula (3) to generate the logical formula access right exercise information LGK. Here, for example, the logical formula access right V1∧2 For the case where the value of the random number λ is 1, the logical formula access right exercise information LGK is represented by the above-described formula (18).
[0169] Even when the logical formula secret authentication information LAI is not supplied from the access management device 2a, if the secret authentication information acquisition unit 140a has acquired a plurality of secret authentication information AIs (for example, the secret authentication information AI1 for the access target R1 and the secret authentication information AI2 for the access target R2) corresponding to a plurality of access targets R (for example, the access target R1 and the access target R2), the access right exercise information generation unit 142a uses the plurality of secret authentication information AIs, the public identification information PK, and the logical formula public identification information LPK to, for example, the logical formula access right V1∧2 In this case, the logical formula access right exercise information LGK can be generated according to formula (18).
[0170] Step S730: The access right exercise information generation unit 142a supplies the generated logical formula access right exercise information LGK to the access management device 2 via the communication unit 10.
[0171] Next, referring to FIG. 12, the process of the access management device 2a verifying access to the access target R represented by the logical formula of the user terminal 1a will be described. FIG. 12 is a diagram showing an example of the access verification process of the access management device 2 according to the present embodiment. Since the processes of step S810 and step S850 are the same as the processes of step S410 and step S450 in FIG. 7, the description thereof will be omitted.
[0172] Step S800: The access request acquisition unit 23a acquires the logical formula access request information LAR supplied from the user terminal 1a via the communication unit 20. The access request acquisition unit 23 supplies the acquired access request information AR to the access right granting unit 24.
[0173] Step S820: The access right inspection unit 26a acquires the logical formula access right exercise information LGK supplied from the user terminal 1a via the communication unit 20.
[0174] Step S830: The access right inspection unit 26a determines whether or not the logical formula access right exercise information LGK acquired in Step S830 matches the value of the random number λ power of the logical formula secret identification information LSK associated with the access target R represented by the logical formula indicated by the logical formula access request information LAR.
[0175] When the access right inspection unit 26a determines that the logical formula access right exercise information LGK matches the value of the random number λ power of the logical formula secret identification information LSK (Step S830; YES), it supplies the determination result to the access permission unit 27a. Thereafter, the access permission unit 27a executes the process of Step S840. On the other hand, when it is determined that the logical formula access right exercise information LGK does not match the value of the random number λ power of the logical formula secret identification information LSK (Step S830; NO), it supplies the determination result to the access permission unit 27a. Thereafter, the access permission unit 27a executes the process of Step S850.
[0176] Step S840: The access permission unit 27a permits the user terminal 1a to access the access target R represented by the logical formula indicated by the logical formula access request information LAR. For example, if the logical formula access request information LAR is the conjunction of the access target R1 and the access target R2 When indicating the access right to the union, the access permission unit 27a permits the user terminal 1a to access the access target R1 and the access target R2. Further, for example, when the logical formula access request information LAR indicates the access right to the common part of the access target R1 and the access target R2, the access permission unit 27a permits the user terminal 1a to access the common part of the access target R1 and the access target R2.
[0177] As described above, the access management device 2a according to the present embodiment includes a logical formula secret identification information generation unit 28a. The logical formula secret identification information generation unit 28a, in addition to the inclusion relationship indicated by the directed acyclic graph OG, for the logical formula access right LX which is an access right represented by the logical formula of a plurality of access rights V, based on the secret identification information SK associated by the access right management unit 22 with the node N associated with the plurality of access rights V used to represent the logical formula access right LX, and the public identification information PK, generates the logical formula secret identification information LSK which is the secret identification information SK for the logical formula access right LX.
[0178] With this configuration, in the access management device 2a according to the present embodiment, since the logical formula secret identification information LSK can be generated based on the secret identification information SK associated with the plurality of access rights V used to represent the logical formula access right LX and the public identification information PK, in access control that deals with a plurality of access rights having an inclusion relationship with each other, and access control that deals with access rights dynamically defined by the logical formula of access rights, and access control having both of these functions, the number of keys to be managed can be reduced with respect to the number of access rights, the number of inclusion relationships, and the number of logical formulas targeted.
[0179] In the access management device 2a according to the present embodiment, for a user terminal that already has secret authentication information for an access right that satisfies a logical formula, it is not necessary to newly issue the corresponding logical formula secret authentication information LAI to the user terminal, which can reduce the labor of issuing the secret authentication information and also reduce the number of secret authentication information managed in the user terminal. Since the number of logical formula access rights increases combinatorially with respect to the number of existing access rights, the improvement effect by the access management device 2a according to the present embodiment is extremely large. Also, when the logical formula public identification information is set to 1, the information managed in the access management device 2a does not increase at all.
[0180] (Third Embodiment) Hereinafter, a third embodiment of the present invention will be described in detail with reference to the drawings. In the above first and second embodiments, as a method of concealing secret authentication information from a third party, the case where secret authentication information is recorded in a tamper-resistant module for a user has been described. In this embodiment, a method of permitting the exercise of an access right without informing a user of either the secret authentication information or the secret identification information for a user specified by an identifier is shown. In this embodiment, different from the first and second embodiments, instead of recording secret authentication information in a tamper-resistant device that a user cannot access, the access management device converts the secret authentication information into a data format called a ticket and then issues the ticket to the user. Since the ticket is data in which the secret authentication information is masked by a random number, it is safe even when transmitted, received, and recorded without encryption or the like. Furthermore, in this embodiment, when a ticket is illegally circulated due to, for example, being diverted, the access management device can restore the identifier of the user who should originally receive the ticket.
[0181] First, assume that the order of the group G in the first and second embodiments is the product pr of two secret prime numbers. Here, the group G is a cyclic group. Let the element represented by Equation (24) be the generator of the group G.
[0182]
Number
[0183] Here, the element g of order p is defined as in Equation (25).
[0184]
Number
[0185] Let the public identification information of the access right Vi be the value indicated by the above-mentioned Equation (12), and the secret identification information be the value indicated by Equation (4). Define the ticket t issued to the user whose identifier is the value u by Equation (26).
[0186]
Number
[0187] In Equation (26), PRF(·,·) is a keyed pseudorandom function, for example, the HMAC-SHA1 function. Here, assume that the header data h is header data that can uniquely identify the ticket t. For example, when generating the ticket t, uniquely determine its identifier and include the determined identifier in the header data h. The public identification information of the access right Vi is an element of the multiplicative group of the prime field of characteristic p as shown by Equation (27).
[0188]
Number
[0189] The value u of the identifier is selected as shown by Equation (29) for an appropriate natural number U evaluated from above by a polynomial of the bit length shown by Equation (28) of the prime number p (referred to as a security parameter). Evaluated from above by a polynomial of ||p|| means that for an appropriate natural number k, U ≤ ||p|| k holds.
[0190]
Number
[0191]
Number
[0192] In this embodiment, as an example, an access management device, which is a resource gateway, performs access right authentication by Diffie-Hellman-Merkle authentication. The authentication procedure is described below.
[0193] First, the user requests access to the resource to the resource gateway that is the target of the access right Vi. Next, the gateway generates a random number that satisfies Equation (30) and supplies the value indicated by Equation (31) to the user. Hereinafter, the value generated using the random number indicated by Equation (31) is represented as value c.
[0194]
Number
[0195]
Number
[0196] Subsequently, the user calculates the value indicated by Equation (32) and supplies it to the gateway.
[0197]
Number
[0198] Finally, the gateway checks whether Equation (33) holds based on the value supplied from the user, and permits the user's access only when the check equation holds.
[0199]
Number
[0200] Since the two prime numbers p and r are secret information, PRF(p, h) is a random number that is computationally infeasible for those who do not know p. Therefore, since the ticket t is also a computationally infeasible random number, it can be seen that it is impossible to forge the ticket.
[0201] On the other hand, when the ticket t is used illegally, for the value R in the illegally presented formula (32), first, the calculation shown by formula (34) is executed.
[0202]
Number
[0203] Next, for example, using an algorithm such as Baby-Step-Giant-Step, a value u that satisfies formula (35) is searched for.
[0204]
Number
[0205] It is known that the search for the value u that satisfies formula (35) can be executed with a computational complexity of the order shown by formula (36). Hereinafter, formula (35) is referred to as the user determination formula.
[0206]
Number
[0207] Since the upper limit value of the natural number U is bounded by a polynomial of the parameters shown by formula (28), it is possible to search for the value u within a practical time.
[0208] As described above, in the present embodiment, by issuing the ticket t and the header data h based on the formula (26), it is impossible for the user to know the secret authentication information or the secret identification information. Further, in the present embodiment, when the ticket t is illegally used, it becomes possible to identify the user who issued the ticket t first.
[0209] (Configuration of Access Management System) The access management system according to the present embodiment is referred to as an access management system ASb. Further, the user terminal according to the present embodiment is referred to as a user terminal 1b, and the access management device is referred to as an access management device 2b.
[0210] FIG. 13 is a diagram showing the configurations of the user terminal 1b and the access management device 2b according to the present embodiment. When comparing the user terminal 1b (FIG. 13) according to the present embodiment with the user terminal 1 (FIG. 3) according to the first embodiment, the module 14b is different. Here, the functions of the other components (communication unit 10, public information acquisition unit 11, public information storage unit 12, access request unit 13, and access execution unit 15) are the same as those in the first embodiment. Further, when comparing the access management device 2b (FIG. 13) according to the present embodiment with the access management device 2 (FIG. 3) according to the first embodiment, the ticket granting unit 24b, the ticket inspection unit 26b, the ticket generation unit 29b, and the illegal user determination unit 30b are different. Here, the functions of the other components (communication unit 20, user management unit 21, access right management unit 22, access request acquisition unit 23, random number generation unit 25, and access permission unit 27) are the same as those in the first embodiment. Further, the configuration of the access right information server 3 (FIG. 8) according to the present embodiment is the same as the configuration of the access right information server 3 (FIG. 3) according to the first embodiment. The configuration of the access target server 4 (FIG. 8) according to the present embodiment is the same as the configuration of the access target server 4 (FIG. 3) according to the first embodiment. The description of the same functions as in the first embodiment is omitted, and in the third embodiment, the description will be centered on the parts different from the first embodiment.
[0211] The user terminal 1b includes a communication unit 10, a public information acquisition unit 11, a public information storage unit 12, an access request unit 13, a module 14b, and an access execution unit 15.
[0212] The module 14b includes a ticket acquisition unit 140b, a ticket storage unit 141b, and a ticket exercise information generation unit 142b. In this embodiment, the case where the module 14b does not have tamper resistance characteristics will be described, but the module 14b may have tamper resistance characteristics.
[0213] The ticket acquisition unit 140b acquires a ticket t supplied from the access management device 2b. The ticket storage unit 141b stores the ticket t acquired by the ticket acquisition unit 140b. The ticket exercise information generation unit 142b generates ticket exercise information TK based on the public information PI stored in the public information storage unit 12 and the ticket t stored in the ticket storage unit 141b. Here, the ticket exercise information TK is the value of the one-way function F1 generated by the user terminal 1b and is represented by the above-described formula (32).
[0214] The access management device 2b includes a communication unit 20, a user management unit 21, an access right management unit 22, an access request acquisition unit 23, a ticket granting unit 24b, a random number generation unit 25, a ticket inspection unit 26b, an access permission unit 27, a ticket generation unit 29b, and an unauthorized user determination unit 30b.
[0215] The ticket granting unit 24b supplies the ticket t to the user terminal 1b.
[0216] The ticket inspection unit 26b supplies the value represented by the above-described formula (31) to the user terminal 1b according to the access request information AR acquired by the access request acquisition unit 23. Further, the ticket inspection unit 26b inspects whether or not the relational expression represented by the formula (33) holds between the ticket exercise information TK supplied from the user terminal 1b and the secret identification information SK associated with the access target node AN indicated by the access request information AR.
[0217] The ticket generation unit 29b generates a ticket t based on the above-described formula (26). The unauthorized user determination unit 30b acquires the user identification information UI used to generate the ticket t from the ticket exercise information TK generated by the user UE using the ticket t generated by the ticket generation unit 29b based on the formula (35). The unauthorized user determination unit 30b determines an unauthorized user based on the acquired user identification information UI. Here, the user identification information UI is information indicating the identifier of the user terminal 1b.
[0218] (Processing in the access management system) With reference to FIG. 14, the access management process, which is the process of the access management device 2b before the access by the user terminal 1b, will be described. FIG. 14 is a diagram showing an example of the access management process of the access management device 2b according to the present embodiment. The process shown in FIG. 14 starts when the operation of the access management system ASb is started. Note that the processes of step S900, step S910, and step S920 are the same as the processes of step S100, step S110, and step S120 in FIG. 4, and thus the description thereof will be omitted.
[0219] Step S930: The ticket generation unit 29b generates a ticket t based on the formula (26). The ticket generation unit 29b supplies the generated ticket t to the ticket granting unit 24b. Here, Equation (26) includes operations on the numbers xi, that is, operations on the secret authentication information AI. Further, Equation (26) includes operations on the value u including the secret prime number p, that is, operations on the user identification information UI including factors not disclosed to the user UE.
[0220] It is difficult to calculate the prime number p, the numbers xi, and the value u on the right side from the ticket t on the left side by inverse operation within a practical time. That is, Equation (26) represents a one-way function. This one-way function is called one-way function F2.
[0221] Therefore, the ticket t is a value of the one-way function F2 that takes at least part of the input as the secret authentication information AI of the access right V to the user UE and the user identification information UI that identifies the user UE. That is, the ticket generation unit 29b generates a ticket t that is a value of the one-way function F2 that takes at least part of the input as the secret authentication information AI of the access right V to the user UE and the user identification information UI that identifies the user UE.
[0222] Note that a one-way function represented by an equation other than Equation (26) may be used as the one-way function F2 such that it is difficult to calculate the prime number p, the numbers xi, and the value u on the right side from the ticket t on the left side by inverse operation within a practical time.
[0223] Step S940: The ticket granting unit 24b grants the ticket t generated by the ticket generation unit 29b to the user terminal 1b indicated by the value u that is the user identification information UI used for generating the ticket t. Here, the ticket granting unit 24b grants the ticket t by supplying the ticket t to the user terminal 1b via the communication unit 20.
[0224] The ticket t is information obtained by converting the secret authentication information AI based on Equation (26). That is, the ticket granting unit 24b grants the ticket t generated by the ticket generation unit 29b to the user UE as the secret authentication information AI.
[0225] Next, referring to FIG. 15, the processing of the user terminal 1b before access is described. FIG. 15 is a diagram showing an example of the ticket acquisition process of the user terminal 1b according to the present embodiment. Note that since the process of step S1000 is the same as the process of step S200 in FIG. 5, the description thereof is omitted.
[0226] Step S1010: The ticket acquisition unit 140b acquires the ticket t supplied from the access management device 2b via the communication unit 10. The ticket acquisition unit 140b stores the acquired ticket t in the ticket storage unit 141b.
[0227] Next, referring to FIG. 16, the processing when the user terminal 1b accesses the access target R is described. FIG. 16 is a diagram showing an example of the access execution process of the user terminal 1b according to the present embodiment. Note that since the processes of step S1100, step S1140, and step S1150 are the same as the processes of step S300, step S340, and step S350 in FIG. 5, the descriptions thereof are omitted.
[0228] Step S1110: The ticket exercise information generation unit 142b acquires the value c generated using a random number, which is supplied from the access management device 2b, via the communication unit 10.
[0229] Step S1120: The ticket exercise information generation unit 142b generates ticket exercise information TK based on the value c supplied from the access management device 2b and the ticket t stored in the ticket storage unit 141b. Here, the ticket exercise information generation unit 142b generates the ticket exercise information TK based on the ticket t and the value c supplied from the ticket acquisition unit 140b according to the above-described formula (32).
[0230] Step S1130: The ticket exercise information generation unit 142b supplies the generated ticket exercise information TK to the access management device 2b via the communication unit 10.
[0231] Next, referring to FIG. 17, a process in which the access management device 2b verifies access to the access target R of the user terminal 1b will be described. FIG. 17 is a diagram showing an example of the access verification process of the access management device 2b according to the present embodiment. In the access verification process shown in FIG. 17, a case where access is performed by the user terminal 1b indicated by the value u which is the user identification information UI used for generating the ticket t will be described. Note that since the processes of step S1200, step S1240, and step S1250 are the same as the processes of step S400, step S440, and step S450 in FIG. 7, the description thereof will be omitted.
[0232] Step S1210: The ticket granting unit 24b supplies the value c generated using a random number to the user terminal 1 via the communication unit 20. Here, the ticket granting unit 24b generates the value c based on the random number λ generated by the random number generation unit 25 and the formula (31). Here, the ticket granting unit 24b generates the value c every time the access request acquisition unit 23 acquires the access request information AR in step S1200.
[0233] Step S1220: The ticket inspection unit 26b acquires the ticket exercise information TK supplied from the user terminal 1b via the communication unit 20.
[0234] Step S1230: The ticket inspection unit 26b determines whether or not the ticket exercise information TK acquired in step S1220 matches the secret identification information SK associated with the access target node AN indicated by the access request information AR. Note that in the present embodiment, the ticket exercise information TK and the secret identification information SK are considered to match when the ticket exercise information TK and the secret identification information SK satisfy the above-described formula (33).
[0235] Here, the value R in Expression (33) is a value obtained by inputting the ticket t into the one-way function F1. That is, the ticket inspection unit 26b inspects whether the ticket exercise information TK obtained by inputting the ticket t given by the ticket granting unit 24b into the one-way function F1 and the secret identification information SK associated with the access target node AN satisfy a predetermined relational expression.
[0236] When the ticket inspection unit 26b determines that the ticket exercise information TK and the secret identification information SK match (step S1230; YES), the ticket inspection unit 26b supplies a determination result indicating that the ticket exercise information TK and the secret identification information SK match to the access permission unit 27. Thereafter, the access permission unit 27 executes the process of step S1240. On the other hand, when the ticket inspection unit 26b determines that the ticket exercise information TK and the secret identification information SK do not match (step S1230; NO), the ticket inspection unit 26b supplies a determination result indicating that the ticket exercise information TK and the secret identification information SK do not match to the access permission unit 27. Thereafter, the access permission unit 27 executes the process of step S1250.
[0237] Here, referring to FIG. 18, the unauthorized user determination process of the access management device 2 when the ticket t is used illegally will be described. The illegal use of the ticket t means that, for example, access using the ticket t is performed by a user other than the user to whom the access management device 2b granted the ticket t. The user to whom the access management device 2b granted the ticket t is the user indicated by the value u that is the user identification information UI used for the generation of the ticket t.
[0238] FIG. 18 shows an example of the unauthorized user determination process of the access management device 2b according to the present embodiment. This is a diagram. The unauthorized user determination process shown in FIG. 18 is started when access using the ticket t is performed by a user other than the user to whom the access management device 2b granted the ticket t.
[0239] Step S1300: The unauthorized user determination unit 30b calculates the left side of the user determination formula of Expression (35) using the ticket exercise information TK generated by the user terminal 1b according to Expression (32) using the ticket t. Here, the unauthorized user determination unit 30b uses the header data h of the ticket t for the calculation of the left side of the user determination formula of Expression (35). Step S1310: The unauthorized user determination unit 30b determines the user to whom the ticket t is assigned. Here, the unauthorized user determination unit 30b determines the user to whom the ticket t is assigned, for example, by calculating a value u that satisfies the user determination formula of Expression (35) using an algorithm such as Baby-Step-Giant-Step.
[0240] As described above, the access management device 2b according to the present embodiment includes a ticket generation unit 29b. The ticket generation unit 29b generates a ticket t that is a value of a second one-way function (in this example, the one-way function F2) having at least a part of the input as the secret authentication information AI of the access right V to the user UE and the user identification information UI for identifying the user UE. The access right granting unit 24 (in this example, the ticket granting unit 24b) grants the ticket t generated by the ticket generation unit 29b to the user UE as the secret authentication information AI. The access right inspection unit 26 (in this example, the ticket inspection unit 26b) inspects whether or not the second access right exercise information (in this example, the ticket exercise information TK) obtained by inputting the ticket t granted by the access right granting unit 24 (in this example, the ticket granting unit 24b) into the one-way function F1 and the secret identification information SK associated with the access target node AN satisfy a predetermined relational expression.
[0241] With this configuration, in the access management device 2b according to the present embodiment, since the secret authentication information AI can be converted into the ticket t and granted to the user, a tamper-resistant characteristic module or the like is not required when the secret authentication information AI is granted to the user by a method of concealing it from a third party.
[0242] In addition, the access management device 2b according to this embodiment includes an unauthorized user determination unit 30b. The unauthorized user determination unit 30b acquires user identification information UI used to generate the ticket t from second access right exercise information (in this example, ticket exercise information TK) generated by the user UE based on the ticket t generated by the ticket generation unit 29b.
[0243] With this configuration, in the access management device 2b according to this embodiment, since it is possible to identify the user who first issued the ticket t, it is possible to prevent the ticket t from leaking illegally. If the user leaks the ticket t assigned to himself / herself, the access management device 2b according to this embodiment will identify the user.
[0244] Note that a part of the access management devices 2, 2a, and 2b in the above-described embodiment, for example, the communication unit 20, the user management units 21, 21a, the access right management units 22, 22a, the access request acquisition units 23, 23a, the access right granting units 24, 24a, the random number generation unit 25, the access right inspection units 26, 26a, the access permission units 27, 27a, the logical formula secret identification information generation unit 28a, the ticket granting unit 24b, the ticket inspection unit 26b, the ticket generation unit 29b, and the unauthorized user determination unit 30b may be realized by a computer. In that case, a program for realizing this control function is recorded on a computer-readable recording medium, and the program recorded on this recording medium is read into a computer system and executed to realize it. This is also acceptable. Here, the "computer system" refers to the computer systems built into the access management devices 2, 2a, and 2b, and includes hardware such as an OS and peripheral devices. Also, the "computer-readable recording medium" refers to portable media such as flexible disks, magneto-optical disks, ROMs, and CD-ROMs, and storage devices such as hard disks built into computer systems. Furthermore, the "computer-readable recording medium" also includes those that hold a program dynamically for a short time, such as a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, and those that hold a program for a certain period of time, such as volatile memory inside a computer system that serves as a server or client in that case. Also, the above program may be for realizing a part of the functions described above, and furthermore, it may be possible to realize the functions described above in combination with a program already recorded in the computer system. Also, a part or all of the access management devices 2, 2a, and 2b in the above-described embodiments may be realized as an integrated circuit such as an LSI (Large Scale Integration). Each functional block of the access management devices 2, 2a, and 2b may be made into a processor individually, or a part or all may be integrated and made into a processor. Also, the method of integrating into an integrated circuit is not limited to LSI, and it may be realized by a dedicated circuit or a general-purpose processor. Also, when a technology for integrating into an integrated circuit that replaces LSI appears due to the progress of semiconductor technology, an integrated circuit using such technology may be used.
[0245] As described above, one embodiment of the present invention has been described in detail with reference to the drawings. However, the specific configuration is not limited to the above, and various design changes and the like can be made without departing from the gist of the present invention.
Description of Reference Numerals
[0246] AS, ASa, ASb... Access management system, 1, 1a, 1b... User terminal, 2, 2a, 2b... Access management device, 3... Access right information server, 4... Access target server, 10, 20... Communication unit, 11... Public information acquisition unit, 12... Public information storage unit, 13... Access request unit, 14... Tamper-resistant characteristic module, 140... Secret authentication information acquisition unit, 141... Secret authentication information storage unit, 142... Access right exercise information generation unit, 15... Access execution unit, 21... User management unit, 22, 22a... Access right management unit, 23... Access request acquisition unit, 24, 24a... Access right granting unit, 25... Random number generation unit, 26, 26a... Access right inspection unit, 27, 27a... Access permission unit, 28a... Logical formula secret identification information generation unit, 14b... Module, 140b... Ticket acquisition unit, 141b... Ticket storage unit, 142b... Ticket exercise information generation unit, 11a... Public information acquisition unit, 12a... Public information storage unit, 13a... Access request unit, 14a... Tamper-resistant characteristic module, 140a... Secret authentication information acquisition unit, 141a... Secret authentication information storage unit, 142a... Access right exercise information generation unit, 15a... Access execution unit, 24b... Ticket granting unit, 26b... Ticket inspection unit, 29b... Ticket generation unit, 30b... Illegal user determination unit, OG... Directed acyclic graph, N, N1... Node, V... Access right, PI... Public information, PK... Public identification information, SK... Secret identification information, AI... Secret authentication information, F1... One-way function, F2... One-way function, AN... Access target node, UI... User identification information, LX... Logical formula access right, LSK... Logical formula secret identification information
Claims
1. A user terminal that makes an access request to an access target, and an access management device that manages the access to the access target by the user terminal, wherein the access management device includes an access right for permitting the user terminal to access the access target, an access right management means for managing the access right, an access right granting means for granting the access right, and an access right inspection means for inspecting the validity of the access right, wherein the access right management means includes a directed acyclic graph, wherein the directed acyclic graph includes a plurality of nodes respectively corresponding to a plurality of the access targets, wherein the access management device includes public identification information associated with the node and disclosed to the user terminal, secret identification information that is identification information associated with the node, and secret authentication information used for the inspection of the access right, when the public identification information is xi, the secret authentication information is represented by formula (1), 【Number 1】 the secret identification information is an element of the group shown in formula (4), [Number 4] the access right management means associates the node with the public identification information, the secret identification information, and the secret authentication information, when there is an access request from the user terminal, the access right inspection means transmits the secret authentication information to the user terminal, the user terminal generates first access right exercise information using the secret authentication information, the access right inspection means authenticates the access right when the first access right exercise information and the secret identification information satisfy a predetermined relationship, the user terminal generates the first access right exercise information, which is a value obtained by inputting the secret authentication information, the public identification information associated with the upper node of the node associated with the secret authentication information, into a one-way function, The one-way function has homomorphic properties, and an access management system characterized by this.
2. The access management device includes a logical formula access right represented by logical formulas of a plurality of the access rights, logical formula public identification information that is identification information associated with the node and disclosed to the user terminal, logical formula secret identification information that is identification information associated with the node and is the secret identification information for the logical formula access right, and logical formula secret authentication information used for the inspection of the access right. The access right management means associates the node with the logical formula public identification information, the logical formula secret identification information, and the logical formula secret authentication information. When there is an access request from the user terminal to one or more access targets indicated by a logical formula, the access right inspection means transmits the logical formula secret authentication information to the user terminal. The user terminal generates logical formula access right exercise information using the logical formula secret authentication information. When the logical formula access right exercise information and the logical formula secret identification information satisfy a predetermined relational expression, the access right inspection means authenticates the access right. The user terminal generates the logical formula access right exercise information, which is a value obtained by inputting the logical formula secret authentication information and the logical formula public identification information associated with the upper node of the node associated with the logical formula secret authentication information into the one-way function. The access management system according to claim 1, wherein the one-way function has homomorphic properties.
3. The access target is data. The access management system according to claim 1 or 2, wherein the secret identification information is an encryption key for encrypting the access target.
4. The user terminal includes ticket generation means for generating a ticket by inputting identification information of the user terminal into a second one-way function. When there is an access request based on the access right from the user terminal to the access target, the access right inspection means transmits the ticket to the user terminal as secret authentication information. The user terminal generates second access right exercise information using the ticket. The access management system according to any one of claims 1 to 3.
5. The access management device includes unauthorized user determination means for determining the legitimacy of the user terminal. The unauthorized user determination means determines the legitimacy of the user terminal using the second access right exercise information. The access management system according to claim 4.
6. An access management program that, when executed on a computer, causes the computer to function as the access management system according to any one of claims 1 to 5.
Citation Information
Patent Citations
Access right management system, portable terminal, gateway and contents server
JP2001175540A
Method and apparatus for processing key information, and program
JP2005109753A
Hierarchical Identity-Based Encryption and Signature Schemes
JP2005521323A
Information processing method, and information processing apparatus
JP2006020292A
Information encryption device and its control method, computer program and computer readable storage medium
JP2006074392A