Communication device and program to be executed by a computer

The adaptive cipher suite selection in communication devices addresses security and communication quality issues for IoT devices by dynamically matching encryption methods to the capabilities of communicating parties, enhancing security and efficiency.

JP7825277B2Active Publication Date: 2026-03-06ATR ADVANCED TELECOMM RES INST INT
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-03-24
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

Existing encryption methods, particularly for IoT devices, face challenges in ensuring security and communication quality due to low computing power and narrow communication channels, which are exacerbated by the potential vulnerabilities of quantum computers.

Method used

A communication device and program that adaptively select a cipher suite based on cryptographic processing and communication quality, using a cipher selection unit to determine the most suitable encryption method and key length for secure and efficient data transmission.

Benefits of technology

Enhances encryption security and communication quality by dynamically selecting cipher suites that match the performance capabilities of communicating parties, ensuring effective data transmission even in low-performance IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007825277000004
    Figure 0007825277000004
  • Figure 0007825277000005
    Figure 0007825277000005
  • Figure 0007825277000006
    Figure 0007825277000006
Patent Text Reader

Abstract

To provide a communication apparatus capable of adoptively selecting a cipher sweet on the basis of a cipher processing of an operator and a communication quality.SOLUTION: A quality monitoring part 13 monitors a transmission speed TRS1 of a data to a cipher / decoding part 12 from an application 11. A cipher selection part 14 selects a cipher sweet corresponded to a selection rule at the time of satisfying the selection rule of a cipher selection rule table by the transmission speed TRS1 on the basis of the transmission speed TRS1 received from the quality monitoring part 13, the cipher selection rule table to which a plurality of cipher sweets and a plurality of selection rules for selecting each of the plurality of cipher sweets are corresponded each other, and a cipher processing quality table indicating a processing quality by each cipher sweet. Then, the cipher selection part 14 changes or does not change the cipher sweet used in the cipher / decoding part 12 by the cipher sweet selected.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a communication device and a program to be executed by a computer. [Background technology]

[0002] It is currently believed that when quantum computers are put into practical use, existing encryption methods may not be able to guarantee security.

[0003] For example, Shor's algorithm has been proposed, which can solve factorization and discrete logarithm problems in polynomial time on a quantum computer, and conventional encryption methods based on it may be broken when quantum computers are put into practical use.

[0004] Therefore, efforts are underway to develop and standardize post-quantum cryptography (PQC), an encryption method that is difficult to decrypt using a quantum computer (Non-Patent Document 1). [Prior art documents] [Non-patent literature]

[0005] [Non-Patent Document 1] Noboru Kunihiro, "Quantum Computers and Cryptography: Transition to Quantum-Resistant Cryptography," Journal of the Japan Society for Security Management, Vol. 35, No. 3, 2022, pp. 18-24. Summary of the Invention [Problem to be solved by the invention]

[0006] However, in order to withstand conventional cryptanalysis and quantum computer cryptanalysis, PQC tends to require longer encryption / decryption processing times, longer key lengths, and longer cipher lengths. For example, the security and processing time of encryption generally differ depending on the encryption method, and even with the same encryption method, a more secure encryption method can be achieved by increasing the key length.

[0007] In addition, IoT (Internet of Things) devices, which are often inexpensive and required in large quantities, tend to have low computing power and the communication capacity of the communication channels they use is narrow.

[0008] Therefore, when a low-performance IoT device needs to encrypt and transmit a large amount of data, the encryption may not be able to achieve the required communication quality.

[0009] Therefore, according to an embodiment of the present invention, a communication device is provided that can adaptively select a cipher suite based on the encryption processing and communication quality of the communicating parties.

[0010] Furthermore, according to an embodiment of the present invention, there is provided a program for causing a computer to execute adaptive cipher suite selection based on the cryptographic processing and communication quality of the communicating parties. [Means for solving the problem]

[0011] (Configuration 1) According to an embodiment of the present invention, a communication device is a communication device that encrypts data and transmits the encrypted data to at least a destination communication device, and includes a cipher selection unit and an encryption / decryption unit. The cipher selection unit selects a cipher suite including a cryptographic algorithm and a key length, and is configured with information sufficient to establish an encrypted communication path. The encryption / decryption unit executes a transmission process that encrypts data received from an application using the cipher suite selected by the cipher selection unit and transmits the encrypted data to the destination communication device. The cipher selection unit then selects a first cipher suite from the multiple cipher suites whose selection communication quality satisfies the selection rules in the cipher selection rule table based on a cipher selection rule table that associates multiple cipher suites with multiple selection rules for selecting each of the multiple cipher suites, a cipher processing quality table that indicates the processing quality using the cipher suites, and a selection communication quality that is the communication quality in at least one of the destination communication device and the destination communication device when encrypted data is transmitted to the destination communication device and that is the communication quality used for selecting a cipher suite, determines whether the selected first cipher suite is different from a second cipher suite used in the encryption / decryption unit, and if it determines that the first cipher suite is different from the second cipher suite, changes the second cipher suite to the first cipher suite in the encryption / decryption unit, and if it determines that the first cipher suite is the same as the second cipher suite, performs a cipher suite selection process in which the encryption / decryption unit does not change the second cipher suite to the first cipher suite. The encryption / decryption unit executes the transmission process using the first cipher suite when the cipher selection unit changes the second cipher suite to the first cipher suite, and executes the transmission process using the second cipher suite when the cipher selection unit does not change the second cipher suite to the first cipher suite.

[0012] (Configuration 2) In the first configuration, the communications device further includes a quality monitor. The quality monitor monitors first communication quality, including a first transmission rate, which is a data transmission rate when an application transmits data to the encryption / decryption unit; a second transmission rate, which is a transmission rate at a first communications interface when the encryption / decryption unit transmits encrypted data, which is a communications interface of the communications device, to a destination communications device via the first communications interface; a first reception rate, which is a reception rate at a first communications interface when the encryption / decryption unit receives encrypted data from the destination communications device via the first communications interface; and a second reception rate, which is a reception rate at which the application receives data decrypted by the encryption / decryption unit from the encryption / decryption unit. The cipher selector receives the first communication quality from the quality monitor and performs a cipher suite selection process based on the cipher selection rule table, the encryption processing quality table, and the first communication quality as a selection communication quality.

[0013] (Configuration 3) In configuration 2, the communication device further includes a quality prediction unit. The quality prediction unit receives a first communication quality from the quality monitoring unit and predicts a first future communication quality, which is the future communication quality of the communication device, based on the received first communication quality. The cipher selection unit receives the first future communication quality from the quality prediction unit and performs a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first future communication quality as the selection communication quality.

[0014] (Configuration 4) In configuration 2, the quality monitoring unit receives from the destination communications device a second communication quality including a first transmission rate, a second transmission rate, a first receiving rate, and a second receiving rate monitored in the destination communications device. The cipher selection unit receives the first and second communication qualities from the quality monitoring unit and executes a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second communication qualities as the selection communication qualities.

[0015] (Configuration 5) In configuration 2, the communications device further includes a quality prediction unit. The quality prediction unit receives from the quality monitoring unit a first communication quality and a second communication quality including a first transmission rate, a second transmission rate, a first reception rate, and a second reception rate monitored in the communications device at the destination, and predicts a first future communication quality that is the future communication quality in the communications device based on the first communication quality, and predicts a second future communication quality that is the future communication quality in the communications device at the destination, based on the second communication quality. The cipher selection unit receives the first and second future communication qualities from the quality prediction unit, and performs a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second future communication qualities as the selection communication qualities.

[0016] (Configuration 6) In configuration 2, the cipher selection unit sets a cipher change prohibition period during which a change of the cipher suite is prohibited, and after the cipher change prohibition period ends, executes a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the communication quality for selection.

[0017] (Configuration 7) In configuration 2, the encryption / decryption unit includes S encryption / decryption units that perform transmission processing of S (S is an integer equal to or greater than 2) pieces of data using S streams, respectively. The quality monitoring unit monitors the S first communication qualities by monitoring the first communication quality of the sth (s is any one of 1 to S) stream as the sth first communication quality for all of the S streams. The cipher selection unit receives the S first communication qualities from the quality monitoring unit and, based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities as the selection communication qualities, performs cipher suite selection processing on the sth encryption / decryption unit using the sth first communication quality for all of the S encryption / decryption units. Each of the S encryption / decryption units performs transmission processing using the first cipher suite or the second cipher suite for the stream that it uses to transmit encrypted data to a destination communication device.

[0018] (Configuration 8) In configuration 2, the communication device further includes a quality prediction unit. The quality prediction unit predicts S first future communication qualities, which are S future communication qualities for the S streams, based on S first communication qualities for the S streams for transmitting S (S is an integer equal to or greater than 2) pieces of data to a destination communication device, respectively. The encryption / decryption unit includes S encryption / decryption units that perform transmission processing for the S data using the S streams, respectively. The quality monitoring unit monitors the S first communication qualities by monitoring the s-th first communication quality for the s-th (s is any one of 1 to S) stream for all of the S streams. The quality prediction unit receives the S first communication qualities from the quality monitoring unit, and predicts the s-th first future communication quality, which is the future communication quality for the s-th stream among the S streams, based on the s-th (s is any one of 1 to S) first communication quality included in the received S first communication qualities, for all of the S streams, to predict the S first future communication qualities. The cipher selection unit receives the S first future communication qualities from the quality prediction unit, and executes a cipher suite selection process for the s-th encryption / decryption unit using the s-th first future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities as selection communication qualities for all S encryption / decryption units. Each of the S encryption / decryption units executes a transmission process using the first cipher suite or the second cipher suite in a stream used for transmitting encrypted data between itself and a destination communication device.

[0019] (Configuration 9) In configuration 2, the S second communication qualities of the S (S is an integer equal to or greater than 2) streams monitored in the destination communications device include a first transmission rate, a second transmission rate, a first receiving rate, and a second receiving rate for the sth (s is any one of 1 to S) stream of the destination communications device for the S streams. The encryption / decryption unit includes S encryption / decryption units that perform transmission processing using the S streams for transmitting each of the S data to the destination communications device. The quality monitoring unit monitors the first communication quality of the sth (s is any one of 1 to S) stream of the communications device for all of the S streams to monitor the S first communication qualities, and receives the S second communication qualities from the destination communications device. The cipher selection unit receives the S first communication qualities and S second communication qualities from the quality monitoring unit, and executes a cipher suite selection process in the s-th encryption / decryption unit using the s-th first communication quality and the s-th second communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities and S second communication qualities as selection communication qualities for all S encryption / decryption units. Each of the S encryption / decryption units executes a transmission process using the first cipher suite or the second cipher suite in a stream used for transmitting encrypted data between itself and a destination communication device.

[0020] (Configuration 10) In configuration 2, the communication device further includes a quality prediction unit. The quality prediction unit predicts S first future communication qualities that are S future communication qualities for the S streams based on S first communication qualities monitored by the communication device for S streams for transmitting S (S is an integer greater than or equal to 2) pieces of data to a destination communication device, and predicts S second future communication qualities that are S future communication qualities for the S streams based on S second communication qualities that are communication qualities transmitted from the destination communication device for the S streams, the second communication qualities including a first transmission rate, a second transmission rate, a first receiving rate, and a second receiving rate monitored by the destination communication device. The encryption / decryption unit includes S encryption / decryption units that perform transmission processing for the S data using the S streams, respectively. The quality monitoring unit monitors a first communication quality in the sth (s is any one of 1 to S) stream for all of the S streams to monitor the S first communication qualities, and receives the second communication qualities from the destination communication device. The quality prediction unit receives the S first communication qualities and the second communication qualities from the quality monitoring unit, and, based on the S first communication qualities, predicts a first future communication quality that is the future communication quality of the sth stream among the S streams using an sth first communication quality included in the S first communication qualities for all of the S streams to predict the S first future communication qualities, and predicts a second future communication quality that is the future communication quality of the sth stream among the S streams using an sth second communication quality included in the S second communication qualities for all of the S streams to predict the S second future communication qualities.The cipher selection unit receives the S first future communication qualities and S second future communication qualities from the quality prediction unit, and executes a cipher suite selection process in the s-th encryption / decryption unit using the s-th first future communication quality and the s-th second future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities and S second future communication qualities as selection communication qualities for all S encryption / decryption units. Each of the S encryption / decryption units executes a transmission process using the first cipher suite or the second cipher suite in a stream used for transmitting encrypted data between itself and a destination communication device.

[0021] (Configuration 11) In any of configurations 7 to 10, the cipher selection unit sets a cipher change prohibition period, which is a period during which a change of the cipher suite is prohibited for the s-th stream, and after the cipher change prohibition period ends, performs cipher suite selection processing for all S encryption / decryption units based on the cipher selection rule table, the encryption processing quality table, and S first communication qualities as communication qualities for selection, or S first communication qualities and S second communication qualities as communication qualities for selection, or S first future communication qualities as communication qualities for selection, or S first future communication qualities and S second future communication qualities as communication qualities for selection.

[0022] (Configuration 12) In any of configurations 2 to 10, the cipher selection rule table has a configuration in which multiple priorities indicating the priorities of multiple selection rules are associated with multiple cipher suites and multiple selection rules. The cipher selection unit evaluates, in descending order of priority, whether a first communication quality as a selection communication quality, or a first future communication quality as a selection communication quality, or first and second communication qualities as selection communication qualities, or first and second future communication qualities as selection communication qualities, or S first communication qualities as selection communication qualities, or S first future communication qualities as selection communication qualities, or S first future communication qualities and S second future communication qualities as selection communication qualities satisfy a selection rule, and selects a cipher suite associated with the selection rule that is first satisfied.

[0023] (Configuration 13) In any of configurations 2 to 10, the cipher selection rule table is changed at a desired timing.

[0024] (Configuration 14) According to an embodiment of the present invention, a program is provided for causing a computer to execute a process of transmitting encrypted data, which is generated by a source communication device, to at least a destination communication device, the encrypted data, between the source communication device and the destination communication device, the program comprising: a first step in which a cipher suite selection unit selects a cipher suite including a cryptographic algorithm and a key length, and including sufficient information to establish an encrypted communication path; a second step of executing a transmission process in which the encryption / decryption unit encrypts data received from the application using the cipher suite selected by the cipher selection unit and transmits the encrypted data to a destination communication device; the cipher selection unit, in a first step, selects from the plurality of cipher suites a first cipher suite whose selection communication quality satisfies a selection rule in the cipher selection rule table based on a cipher selection rule table that associates a plurality of cipher suites with a plurality of selection rules for selecting each of the plurality of cipher suites, a cipher processing quality table that indicates processing quality using the cipher suites, and a selection communication quality that is a communication quality in at least the destination communication device and the destination communication device when encrypted data is transmitted to the destination communication device and that is used for selecting a cipher suite; determines whether the selected first cipher suite is different from a second cipher suite used in the encryption / decryption unit; and, if it is determined that the first cipher suite is different from the second cipher suite, changes the second cipher suite to the first cipher suite in the encryption / decryption unit; and, if it is determined that the first cipher suite is the same as the second cipher suite, does not change the second cipher suite to the first cipher suite in the encryption / decryption unit; In the second step, when the cipher selection unit changes the second cipher suite to the first cipher suite, the encryption / decryption unit performs the transmission process using the first cipher suite, and when the cipher selection unit does not change the second cipher suite to the first cipher suite, the encryption / decryption unit performs the transmission process using the second cipher suite.

[0025] (Configuration 15) In configuration 14, the quality monitoring unit causes the computer to further execute a third step of monitoring a first communication quality including a first transmission rate, which is a data transmission rate when the application transmits data to the encryption / decryption unit; a second transmission rate, which is a transmission rate at the first communication interface when the encryption / decryption unit transmits encrypted data, which is the data encrypted by the encryption / decryption unit, to a destination communication device via the first communication interface, which is a communication interface of the communication device; a first reception rate, which is a reception rate at the first communication interface when the encryption / decryption unit receives the encrypted data from the destination communication device via the first communication interface; and a second reception rate, which is a reception rate when the application receives data decrypted by the encryption / decryption unit from the encryption / decryption unit; In a first step, the cipher selection unit receives a first communication quality from the quality monitoring unit, and executes a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the communication quality for selection.

[0026] (Configuration 16) In configuration 15, the method further causes the computer to execute a fourth step in which the quality prediction unit receives the first communication quality from the quality monitoring unit, and predicts a first future communication quality, which is a future communication quality in the communication device, based on the received first communication quality; In a first step, the cipher selection unit receives a first future communication quality from the quality prediction unit, and performs a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first future communication quality as the communication quality for selection.

[0027] (Configuration 17) In configuration 15, the method further causes the computer to execute a third step in which the quality monitoring unit receives, from the destination communication device, second communication quality including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored in the destination communication device; In the first step, the cipher selection unit receives the first communication quality and the second communication quality from the quality monitoring unit, and performs a cipher suite selection process based on a cipher selection rule table, a cipher processing quality table, and the first and second communication qualities as communication qualities for selection. (Configuration 18) In configuration 15, the quality prediction unit receives the first communication quality and the second communication quality including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored in the destination communication device from the quality monitoring unit, predicts a first future communication quality that is the future communication quality in the communication device based on the first communication quality, and predicts a second future communication quality that is the future communication quality in the destination communication device based on the second communication quality, In a first step, the cipher selection unit receives the first and second future communication qualities from the quality prediction unit, and performs a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second future communication qualities as communication qualities for selection.

[0028] (Configuration 19) In configuration 15, in a first step, the cipher selection unit sets a cipher change prohibition period during which changing of the cipher suite is prohibited, and after the cipher change prohibition period ends, executes a cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the communication quality for selection.

[0029] (Configuration 20) In configuration 15, the encryption / decryption unit includes S encryption / decryption units that perform transmission processing on S (S is an integer equal to or greater than 2) pieces of data using S streams, respectively; In a third step, the quality monitoring unit monitors the first communication quality of the s-th stream (s is any one of 1 to S) as the s-th first communication quality for all S streams, thereby monitoring the S first communication qualities; the cipher selection unit receives the S first communication qualities from the quality monitoring unit in a first step, and executes a cipher suite selection process for the s-th encryption / decryption unit using the s-th first communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities as the selection communication qualities, for all of the S encryption / decryption units; In the second step, each of the S encryption / decryption units performs transmission processing using the first cipher suite or the second cipher suite in the stream that it uses to transmit encrypted data between itself and the destination communication device.

[0030] (Configuration 21) In configuration 15, the encryption / decryption unit includes S encryption / decryption units that perform transmission processing on S (S is an integer equal to or greater than 2) pieces of data using the preceding streams, respectively; a fourth step in which the quality prediction unit predicts S first future communication qualities, which are S future communication qualities for the S streams, based on the S first communication qualities for the S streams for transmitting the S data to the destination communication device, In a third step, the quality monitoring unit monitors the s-th first communication quality in the s-th stream (s is any one of 1 to S) for all S streams, thereby monitoring the S first communication qualities; In a fourth step, the quality prediction unit receives the S first communication qualities from the quality monitoring unit, and predicts an s-th first future communication quality, which is a future communication quality for the s-th stream among the S streams, based on an s-th (s is any one of 1 to S) first communication quality included in the received S first communication qualities, for all S streams, thereby predicting the S first future communication qualities; In a first step, the cipher selection unit receives the S first future communication qualities from the quality prediction unit, and executes a cipher suite selection process for the s-th encryption / decryption unit using the s-th first future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities as selection communication qualities, for all of the S encryption / decryption units; In the second step, each of the S encryption / decryption units performs transmission processing using the first cipher suite or the second cipher suite in the stream that it uses to transmit encrypted data between itself and the destination communication device.

[0031] (Configuration 21) In configuration 14, the encryption / decryption unit includes S encryption / decryption units that perform transmission processing on S (S is an integer equal to or greater than 2) pieces of data using S streams, respectively; the quality prediction unit predicts S first future communication qualities, which are S future communication qualities for the S streams, based on S first communication qualities monitored by the communication device for the S streams for transmitting the S data to the destination communication device, and predicts S second future communication qualities, which are S future communication qualities for the S streams, based on S second communication qualities, which are communication qualities transmitted from the destination communication device for the S streams, including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored by the destination communication device; In a third step, the quality monitoring unit monitors the first communication quality of the s-th stream (s is any one of 1 to S) for all S streams to monitor the S first communication qualities, and receives the second communication quality from the destination communication device; In a fourth step, the quality prediction unit receives the S first communication qualities and the S second communication qualities from the quality monitoring unit, and, based on the S first communication qualities, predicts a first future communication quality that is a future communication quality for the s-th stream among the S streams using an s-th first communication quality included in the S first communication qualities, by executing this for all of the S streams, and predicts a second future communication quality that is a future communication quality for the s-th stream among the S streams, by executing this for all of the S streams, based on the S second communication qualities, using an s-th second communication quality included in the S second communication qualities, by executing this for all of the S streams, In a first step, the cipher selection unit receives S first future communication qualities and S second future communication qualities from the quality prediction unit, and performs a cipher suite selection process in an s-th encryption / decryption unit using the s-th first future communication quality and the s-th second future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities and the S second future communication qualities as selection communication qualities, for all of the S encryption / decryption units; In the second step, each of the S encryption / decryption units performs transmission processing using the first cipher suite or the second cipher suite in the stream that it uses to transmit encrypted data between itself and the destination communication device.

[0032] (Configuration 22) In configuration 15, the S second communication qualities for S (S is an integer greater than or equal to 2) streams monitored in the destination communication device include the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate for the sth (s is any one of 1 to S) stream of the destination communication device for the S streams.

[0033] The encryption / decryption unit is made up of S encryption / decryption units that perform transmission processing using S streams for transmitting S pieces of data to respective destination communication devices.

[0034] In a third step, the quality monitoring unit monitors the first communication quality of the s-th stream (s is any one of 1 to S) of the communication device for all S streams to monitor the S first communication qualities, and receives the S second communication qualities from the destination communication device; In a first step, the cipher selection unit receives S first communication qualities and S second communication qualities from the quality monitoring unit, and performs a cipher suite selection process in an s-th encryption / decryption unit using the s-th first communication quality and the s-th second communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities and the S second communication qualities as selection communication qualities, for all of the S encryption / decryption units; In the second step, each of the S encryption / decryption units performs transmission processing using the first cipher suite or the second cipher suite in the stream that it uses to transmit encrypted data between itself and the destination communication device.

[0035] (Configuration 23) In configuration 15, the encryption / decryption unit is made up of S encryption / decryption units that execute transmission processing for S (S is an integer equal to or greater than 2) pieces of data using S streams, respectively.

[0036] the quality prediction unit predicts S first future communication qualities, which are S future communication qualities for the S streams, based on the S first communication qualities monitored by the communication device for the S streams for transmitting the S data to the destination communication device, and predicts S second future communication qualities, which are S future communication qualities for the S streams, based on S second communication qualities, which are communication qualities transmitted from the destination communication device for the S streams, including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored by the destination communication device; In a third step, the quality monitoring unit monitors the first communication quality of the s-th stream (s is any one of 1 to S) for all S streams to monitor the S first communication qualities, and receives the second communication quality from the destination communication device; In a fourth step, the quality prediction unit receives the S first communication qualities and the second communication qualities from the quality monitoring unit, and predicts a first future communication quality, which is a future communication quality for the s-th stream among the S streams, based on the S first communication qualities, using an s-th first communication quality included in the S first communication qualities, for all of the S streams to predict the S first future communication qualities; and predicts a second future communication quality, which is a future communication quality for the s-th stream among the S streams, based on the S second communication qualities, using an s-th second communication quality included in the S second communication qualities, for all of the S streams to predict the S second future communication qualities; In a first step, the cipher selection unit receives S first future communication qualities and S second future communication qualities from the quality prediction unit, and performs a cipher suite selection process in an s-th encryption / decryption unit using the s-th first future communication quality and the s-th second future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities and the S second future communication qualities as selection communication qualities, for all of the S encryption / decryption units; In the second step, each of the S encryption / decryption units performs transmission processing using the first cipher suite or the second cipher suite in the stream that it uses to transmit encrypted data between itself and the destination communication device.

[0037] (Configuration 24) In any of configurations 20 to 23, in a first step, the cipher selection unit sets a cipher change prohibition period, which is a period during which cipher suite changes are prohibited for the s-th stream, and after the cipher change prohibition period ends, performs cipher suite selection processing for all S encryption / decryption units based on the cipher selection rule table, the encryption processing quality table, and S first communication qualities as selection communication qualities, or S first communication qualities and S second communication qualities as selection communication qualities, or S first future communication qualities as selection communication qualities, or S first future communication qualities and S second future communication qualities as selection communication qualities.

[0038] (Configuration 25) In any one of configurations 15 to 23, the cipher suite selection rule table has a configuration in which a plurality of priorities indicating priorities of a plurality of selection rules are associated with a plurality of cipher suites and a plurality of selection rules; In a first step, the cipher selection unit evaluates, in order of priority, whether a first communication quality as a communication quality to be selected, or a first future communication quality as a communication quality to be selected, or a first and second communication qualities as communication qualities to be selected, or a first and second future communication qualities as communication qualities to be selected, or S first communication qualities as communication qualities to be selected, or S first future communication qualities as communication qualities to be selected, or S first future communication qualities and S second future communication qualities as communication qualities to be selected satisfy a selection rule, and selects the cipher suite associated with the selection rule that is first satisfied.

[0039] (Configuration 26) In any of configurations 15 to 23, the encryption selection rule table in the source communication device is changed at a desired timing. [Effects of the Invention]

[0040] The cipher suite can be adaptively selected based on the cryptographic processing and communication quality of the communicating parties. [Brief explanation of the drawings]

[0041] [Figure 1] 1 is a diagram for explaining a communication mode of a communication device according to an embodiment of the present invention; [Figure 2] 1 is a schematic diagram of a communication system according to an embodiment of the invention; [Figure 3] FIG. 3 is a schematic diagram of a communication device 10 shown in FIG. 2 according to a first embodiment. [Figure 4] FIG. 3 is a schematic diagram of a communication device 20 shown in FIG. 2 according to a first embodiment. [Figure 5] 10 is a schematic diagram showing a first communication quality monitored by a quality monitor 13. FIG. [Figure 6] FIG. 4 is a schematic diagram of the encryption selection rule table 15 shown in FIG. [Figure 7] FIG. 10 is a schematic diagram of a cryptographic processing quality table. [Figure 8] 10A and 10B are schematic diagrams illustrating examples of a cryptography selection rule table and a cryptography processing quality table. [Figure 9] FIG. 10 is a schematic diagram showing another example of the encryption selection rule table 15. [Figure 10] FIG. 10 is a schematic diagram of a generalized encryption selection rule table in the case where only data transmission is performed from the communication device 10A to the communication device 20A. [Figure 11] FIG. 10 is a schematic diagram showing an example of an encryption selection rule table 15 when a receiving rate TRS3 is used. [Figure 12] FIG. 10 is a schematic diagram showing an example of the encryption selection rule table 15 when the reception rates TRS3 and TRS4 are used. [Figure 13] FIG. 10 is a schematic diagram showing an example of the encryption selection rule table 15 when a transmission rate TRS1 and a reception rate TRS3 are used. [Figure 14] 10 is a schematic diagram showing an example of an encryption selection rule table 15 when a transmission rate TRS1, a transmission rate TRS2, and a reception rate TRS3 are used. FIG. [Figure 15] 10 is a schematic diagram showing an example of the encryption selection rule table 15 when a transmission rate TRS1, a reception rate TRS3, and a reception rate TRS4 are used. FIG. [Figure 16] 10 is a schematic diagram showing an example of an encryption selection rule table 15 when a transmission rate TRS1, a transmission rate TRS2, a reception rate TRS3, and a reception rate TRS4 are used. FIG. [Figure 17] 10 is a flowchart illustrating the operation of the communication device 10A. [Figure 18] FIG. 10 is a schematic diagram showing the process of establishing an encrypted communication path. [Figure 19] 18 is a flowchart for explaining detailed operations of step S8 shown in FIG. 17. [Figure 20] FIG. 18 is a schematic diagram of an encryption key selection rule table used in the flowchart shown in FIG. [Figure 21] FIG. 3 is a schematic diagram of a second embodiment of the communication device 10 shown in FIG. [Figure 22] 10 is a flowchart illustrating a method for predicting future communication quality. [Figure 23] 23 is a flowchart for explaining detailed operations of step S_PRS1 shown in FIG. 22. [Figure 24] FIG. 1 is a first schematic diagram used to explain a method for predicting future communication quality. [Figure 25] FIG. 2 is a second schematic diagram used to explain a method for predicting future communication quality. [Figure 26] FIG. 23 is a conceptual diagram showing the operation of identifying correct data in step S_PRS5 shown in FIG. 22. [Figure 27] 10 is a flowchart illustrating the operation of the communication device 10B. [Figure 28] 28 is a flowchart for explaining detailed operations of step S8B shown in FIG. 27. [Figure 29] FIG. 29 is a schematic diagram of an encryption code selection rule table 15B used in the flowchart shown in FIG. 28. [Figure 30] FIG. 3 is a schematic diagram of a communication device 10 shown in FIG. 2 according to a third embodiment. [Figure 31] FIG. 3 is a schematic diagram of a communication device 20 shown in FIG. 2 according to a third embodiment. [Figure 32] FIG. 31 is a schematic diagram of an encryption code selection rule table 15C shown in FIG. [Figure 33] 10 is a flowchart illustrating the operation of the communication device 10C. [Figure 34] 34 is a flowchart for explaining the detailed operation of step S24 in FIG. 33. [Figure 35] FIG. 3 is a schematic diagram of a fourth embodiment of the communication device 10 shown in FIG. [Figure 36] FIG. 10 is a schematic diagram of a communication device 20 shown in FIG. 2 according to a fourth embodiment. [Figure 37] FIG. 36 is a first schematic diagram of the encryption code selection rule table 15D shown in FIG. [Figure 38] FIG. 36 is a second schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 39] FIG. 36 is a third schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 40] FIG. 36 is a fourth schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 41] FIG. 36 is a fifth schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 42] FIG. 36 is a sixth schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 43] FIG. 36 is a seventh schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 44] FIG. 36 is an eighth schematic diagram of the encryption key selection rule table 15D shown in FIG. [Figure 45] FIG. 10 is a schematic diagram of another encryption processing quality table. [Figure 46] 10 is a flowchart illustrating the operation of the communication device 10D. [Figure 47] 47 is a flowchart for explaining the detailed operation of step S8C shown in FIG. 46. [Figure 48] FIG. 10 is a schematic diagram of a fifth embodiment of the communication device 10 shown in FIG. [Figure 49]FIG. 49 is a schematic diagram of an encryption code selection rule table 15E shown in FIG. [Figure 50] 10 is a first flowchart illustrating the operation of the communication device 10E. [Figure 51] 10 is a second flowchart illustrating the operation of the communication device 10E. [Figure 52] 52 is a flowchart for explaining the detailed operation of step S8E in FIG. 51. [Figure 53] FIG. 10 is a schematic diagram of a sixth embodiment of the communication device 10 shown in FIG. [Figure 54] FIG. 54 is a first schematic diagram of the encryption key selection rule table 15F shown in FIG. 53. [Figure 55] FIG. 54 is a second schematic diagram of the encryption key selection rule table 15F shown in FIG. 53. [Figure 56] FIG. 54 is a third schematic diagram of the encryption key selection rule table 15F shown in FIG. [Figure 57] FIG. 54 is a fourth schematic diagram of the encryption key selection rule table 15F shown in FIG. [Figure 58] FIG. 54 is a fifth schematic diagram of the encryption key selection rule table 15F shown in FIG. [Figure 59] FIG. 54 is a sixth schematic diagram of the encryption key selection rule table 15F shown in FIG. [Figure 60] FIG. 54 is a seventh schematic diagram of the encryption key selection rule table 15F shown in FIG. [Figure 61] FIG. 54 is an eighth schematic diagram of the encryption key selection rule table 15F shown in FIG. [Figure 62] 10 is a flowchart for explaining the operation of the communication device 10F. [Figure 63] 63 is a flowchart for explaining the detailed operation of step S8G shown in FIG. 62. [Figure 64] FIG. 10 is a schematic diagram of a seventh embodiment of the communication device 10 shown in FIG. [Figure 65] FIG. 10 is a schematic diagram of a seventh embodiment of the communication device 20 shown in FIG. [Figure 66] FIG. 65 is a schematic diagram of an encryption code selection rule table 15G shown in FIG. 64. [Figure 67] FIG. 67 is a schematic diagram of rule tables R_1 to R_S shown in FIG. 66. [Figure 68] 10 is a first flowchart illustrating the operation of a communication device 10G. [Figure 69] 10 is a second flowchart illustrating the operation of the communication device 10G. [Figure 70] 70 is a flowchart for explaining the detailed operation of step S8H shown in FIG. 69. [Figure 71] FIG. 10 is a schematic diagram of the communication device 10 shown in FIG. 2 according to an eighth embodiment. [Figure 72] FIG. 72 is a schematic diagram of the encryption code selection rule table 10H shown in FIG. [Figure 73] 10 is a first flowchart illustrating the operation of the communication device 10H. [Figure 74] 10 is a second flowchart illustrating the operation of the communication device 10H. [Figure 75] 75 is a flowchart for explaining detailed operations of step S8J shown in FIG. 74. DETAILED DESCRIPTION OF THE INVENTION

[0042] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of the present invention will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals and description thereof will not be repeated.

[0043] FIG. 1 is a diagram for explaining a communication mode of a communication device according to an embodiment of the present invention.

[0044] Referring to (a) of Figure 1, in an embodiment of the present invention, a communication device performs at least a transmission process of encrypting data and transmitting the encrypted data to another communication device (not shown) via a base station, a core network (e.g., a fifth generation mobile communication system 5GC), the Internet (not shown), another core network (e.g., a fifth generation mobile communication system 5GC, not shown), and another base station (not shown).

[0045] In this case, the communication device transmits encrypted data at least between itself and the base station via wireless communication. The base station also transmits encrypted data between itself and the core network (5GC) via wired communication. Furthermore, in the section of the core network (5GC) - Internet - other core network - other base station, the encrypted data is transmitted via wired communication. Furthermore, the other communication device receives encrypted data between itself and the other base station via wireless communication.

[0046] Since the AMF (Access and Mobility Management Function), SMF (Session Management Function) and UPF (User Plane Function) in the core network (5GC) are well known, explanations of the AMF, SMF and UPF will be omitted.

[0047] Referring to FIG. 1(b), communication device A executes at least a transmission process of transmitting encrypted data to communication device B by wireless communication via a base station.

[0048] In an embodiment of the present invention, the source communication device may transmit data to the destination communication device using either wireless communication or wired communication, or may transmit data to the destination communication device using both wireless communication and wired communication.

[0049] 2 is a schematic diagram of a communication system according to an embodiment of the present invention. Referring to FIG. 2, a communication system 100 according to the embodiment of the present invention includes a communication device 10 and a communication device 20.

[0050] In FIG. 1, it has been explained that communication between a communication device and another communication device may be wireless communication, wired communication, or a mixture of wireless communication and wired communication. Therefore, in communication system 100, communication device 10 may transmit data to communication device 20 by wireless communication, wired communication, or a mixture of wireless communication and wired communication.

[0051] Therefore, in Figure 2, communication device 10 at least performs a transmission process to transmit data to communication device 20, and no intermediaries such as base stations and core networks (5GC) are shown between communication device 10 and communication device 20.

[0052] In the embodiment of the present invention, the cipher suite for encrypting and decrypting data includes an encryption algorithm and a key length, and is made up of information sufficient to establish an encrypted communication path.

[0053] [Embodiment 1] Fig. 3 is a schematic diagram of the first embodiment of the communication device 10 shown in Fig. 2. Referring to Fig. 3, the communication device 10A includes an application 11, an encryption / decryption unit 12, a quality monitoring unit 13, an encryption selection unit 14, and an encryption selection rule table 15.

[0054] The application 11 sets the "rules for selecting an encryption cipher" included in the encryption cipher selection rule table 15. The application 11 is also a part that generates any communication traffic between the communication device 10A and the communication device 20A (= the communication device in the first embodiment of the communication device 20 shown in FIG. 2). The communication traffic may be any kind of traffic, such as video. The application 11 then outputs the data to the encryption / decryption unit 2.

[0055] When the encryption / decryption unit 12 changes the cipher suite that it uses for encrypting and decrypting data by the cipher suite selection unit 14, the encryption / decryption unit 12 establishes an encrypted communication path with the communication device 20A (= the communication device in the first embodiment of the communication device 20 shown in FIG. 2) by the method described below. The process of establishing the encrypted communication path includes information exchange, key exchange, and authentication.

[0056] After the communication device 10A is started, the cipher suite that the encryption / decryption unit 12 uses to encrypt / decrypt data initially is set in the encryption / decryption unit 12 by the operator of the communication device 10A. In this case, the encryption / decryption unit 12 at least executes the information exchange in the process of establishing an encrypted communication path.

[0057] When communication device 10A only executes a transmission process to transmit data to communication device 20A (= the communication device in embodiment 1 of communication device 20 shown in Figure 2), encryption / decryption unit 12 receives data from application 11, encrypts the received data using a cipher suite (= the cipher suite set by the operator of communication device 10A or the cipher suite changed by cipher selection unit 14), and transmits the encrypted data to communication device 20A via the communication interface of communication device 10A (hereinafter, the communication interface of communication device 10A will be referred to as "communication IF1").

[0058] Furthermore, when communication device 10A transmits and receives data to and from communication device 20A (= the communication device in embodiment 1 of communication device 20 shown in FIG. 2), encryption / decryption unit 12 receives data from application 11, encrypts the received data using a cipher suite (= the cipher suite set by the operator of communication device 10A or the cipher suite changed by cipher selection unit 14), and transmits the encrypted data to communication device 20A via communication IF1 of communication device 10A, and also receives encrypted data from communication device 20A via communication IF1 of communication device 10A, decrypts the received encrypted data, and outputs the data to application 11.

[0059] The communication IF1 is an interface for transmitting encrypted data in the communication device 10A or an interface for receiving encrypted data from the communication device 20A.

[0060] When the communication device 10A executes only a transmission process of transmitting data to the communication device 20A (= the communication device in the first embodiment of the communication device 20 shown in FIG. 2), the quality monitoring unit 13 monitors a first communication quality CMQ1_1 including a transmission rate TRS1 which is the transmission rate when data is transmitted from the application 11 to the encryption / decryption unit 12, and a transmission rate TRS2 which is the transmission rate at the communication IF1 when the encryption / decryption unit 12 transmits encrypted data to the communication device 20A (= the communication device in the first embodiment of the communication device 20 shown in FIG. 2) via the communication IF1. Then, the quality monitoring unit 13 holds the monitored first communication quality CMQ1_1.

[0061] Furthermore, when the communication device 10A transmits and receives data to and from the communication device 20A (=the communication device in the first embodiment of the communication device 20 shown in FIG. 2), the quality monitoring unit 13 monitors a first communication quality CMQ1_2 that includes, in addition to the transmission rates TRS1 and TRS2, a reception rate TRS3 when the encryption / decryption unit 12 receives encrypted data from the communication device 20A via the communication IF 1 of the communication device 10A, and a reception rate TRS4 when the application 11 receives data decrypted by the encryption / decryption unit 12. Then, the quality monitoring unit 13 holds the monitored first communication quality CMQ1_2.

[0062] When communication device 10A performs only a transmission process to transmit data to communication device 20A (= a communication device in embodiment 1 of communication device 20 shown in Figure 2), the cipher selection unit 14 inquires about the communication quality from the quality monitoring unit 13, and selects a cipher suite using a method described below based on the first communication quality CMQ1_1 obtained from the quality monitoring unit 13, the cipher selection rule table 15, and the encryption processing quality table, determines whether the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, and if it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, it changes the cipher suite used in the encryption / decryption unit 12 to the selected cipher suite.If it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12 (i.e., if it determines that they are the same), it performs a cipher suite selection process that does not change the cipher suite used in the encryption / decryption unit 12.

[0063] Furthermore, when communication device 10A transmits and receives data to communication device 20A (=communication device in embodiment 1 of communication device 20 shown in Figure 2), the cipher selection unit 14 inquires about the communication quality from the quality monitoring unit 13, and performs cipher suite selection processing based on the first communication quality CMQ1_2 obtained from the quality monitoring unit 13, the cipher selection rule table 15, and the cipher processing quality table using a method described below.

[0064] The cipher selection rule table 15 stores rules for selecting a cipher suite by the cipher selection unit 14. The cipher selection rule table 15 is set or rewritten by the operator or application 11 of the communication device 10A.

[0065] Fig. 4 is a schematic diagram of the first embodiment of the communication device 20 shown in Fig. 2. Referring to Fig. 4, the communication device 20A includes an encryption / decryption unit 21 and an application 22.

[0066] The encryption / decryption unit 21 at least exchanges information with the encryption / decryption unit 12 of the communication device 10A in the process of establishing an encrypted communication path.

[0067] When communication device 10A only performs a transmission process to transmit data to communication device 20A, encryption / decryption unit 21 of communication device 20A receives encrypted data from communication device 10A via a communication interface (hereinafter, the communication interface of communication device 20A will be referred to as "communication IF2"), decrypts the received encrypted data using the encryption suite, and outputs the decrypted data to application 22.

[0068] Furthermore, when communication device 10A transmits and receives data to communication device 20A, encryption / decryption unit 21 receives encrypted data via communication IF2, decrypts the received encrypted data using the encryption suite, and outputs the decrypted data to application 22, and also receives data from application 22, encrypts the received data using the encryption suite, and transmits the encrypted data to communication device 10A via communication IF2.

[0069] When the communication device 10A executes only a transmission process for transmitting data to the communication device 20A, the application 22 receives the data from the encryption / decryption unit .

[0070] Furthermore, when the communication device 10A transmits and receives data to and from the communication device 20A, the application 22 outputs the data to the encryption / decryption unit 21.

[0071] In this way, the communication device 20A receives encrypted data from the communication device 10A, and transmits and receives encrypted data to and from the communication device 10A.

[0072] In the first embodiment, when encrypted data is only transmitted from the communication device 10A to the communication device 20A, the communication device 10A is, for example, a sensor, and the communication device 20A is, for example, a server. When encrypted data is transmitted and received between the communication device 10A and the communication device 20A, the communication device 10A and the communication device 20A are, for example, a mobile phone and a tablet, respectively.

[0073] Fig. 5 is a schematic diagram showing the first communication quality monitored by the quality monitor 13. Fig. 5(a) shows the first communication quality when the communication device 10A only transmits data to the communication device 20A, and Fig. 5(b) shows the first communication quality when the communication device 10A transmits and receives data to and from the communication device 20A.

[0074] Referring to (a) of Figure 5, in communication from communication device 10A to communication device 20A, the transmission speed when application 11 of communication device 10A transmits data to encryption / decryption unit 12 of communication device 10A is transmission speed TRS1, and the transmission speed at communication IF1 when encryption / decryption unit 12 transmits encrypted data via communication IF1 is transmission speed TRS2.

[0075] As a result, the first communication quality CMQ1_1 is made up of the transmission rates TRS1 and TRS2.

[0076] Then, the quality monitor 13 monitors the first communication quality CMQ1_1 (=transmission rates TRS1, TRS2).

[0077] Referring to (b) of Figure 5, in two-way communication between communication device 10A and communication device 20A, the transmission speed when application 11 of communication device 10A transmits data to encryption / decryption unit 12 of communication device 10A is transmission speed TRS1, the transmission speed at communication IF1 when encryption / decryption unit 12 transmits encrypted data via communication IF1 is transmission speed TRS2, the reception speed at communication IF1 when encrypted data is received from communication device 20A via communication IF1 is reception speed TRS3, and the reception speed when application 11 receives data from encryption / decryption unit 12 is reception speed TRS4.

[0078] As a result, the first communication quality CMQ1_2 is made up of the sending rate TRS1, the sending rate TRS2, the receiving rate TRS3, and the receiving rate TRS4.

[0079] Fig. 6 is a schematic diagram of the cipher selection rule table 15 shown in Fig. 3. Referring to Fig. 6, the cipher selection rule table 15 includes priorities, cipher suites, and conditions. The priorities, cipher suites, and conditions are associated with one another.

[0080] The priorities are made up of Priority 1 to Priority N (N is an integer equal to or greater than 2). Priority 1 is the highest priority, Priority 2 is the second highest priority, and Priority N is the lowest priority.

[0081] The cipher suites consist of Cipher Suite 1 to Cipher Suite N. Cipher Suite 1 to Cipher Suite N are associated with Priority 1 to Priority N, respectively. Cipher Suite 1 has the slowest encryption and decryption speeds, Cipher Suite 2 has the second slowest encryption and decryption speeds, and so on until Cipher Suite N has the fastest encryption and decryption speeds.

[0082] The conditions consist of rule 1 to rule N. Rule 1 to rule N correspond to priority 1 to priority N and cipher suite 1 to cipher suite N, respectively. Rule 1 to rule N are rules for selecting cipher suite 1 to cipher suite N, respectively.

[0083] 7 is a schematic diagram of an encryption processing quality table. Referring to FIG. 7, the encryption processing quality table 30 includes cipher suites 1 to N and encryption speeds C1 to C6. N and the decoding speed E1 to E N The cryptographic processing quality table 30 indicates the processing quality (= encryption speed and decryption speed) of a cipher suite. Therefore, in the embodiment of the present invention, as described above, a cipher suite includes a cryptographic algorithm and a key length, and is made up of information sufficient to establish an encrypted communication path, so that the processing quality of a cipher suite is indicated by the cryptographic processing quality table 30.

[0084] Encryption speed C1~C N are associated with cipher suites 1 to N, respectively, and have decryption speeds E1 to E N are associated with cipher suites 1 to N, respectively.

[0085] Encryption speed C1~C N is C1 <C2,C2<C3,···,C n-1 <C n and the decoding speeds E1 to E N is E1 <E2,E2<E3,···,E n-1 <E n have the following relationship.

[0086] The cipher selection unit 14 performs a test to measure the processing time of cipher suites 1 to N, and selects the encryption speed C of one cipher suite n (n is one of 1 to N). n and the decoding speed E n The encryption speeds C1 to C2 are calculated by measuring the encryption speeds C1 to C2 for all N cipher suites 1 to N. N and decoding speeds E1 to E N Get.

[0087] The encryption selector 14 then selects encryption rates C1 to C2. Nare stored in the encryption processing quality table 30 in association with the cipher suites 1 to N, respectively, and the decryption speeds E1 to E N are stored in the cryptographic processing quality table 30 in association with cipher suites 1 to N, respectively, to initialize the cryptographic processing quality table 30. The cipher selection unit 14 holds the initialized cryptographic processing quality table 30.

[0088] 8A and 8B are schematic diagrams showing examples of the encryption selection rule table 15 and the encryption processing quality table 30. (a) of Fig. 8 is an example of the encryption selection rule table 15, and (b) of Fig. 8 is an example of the encryption processing quality table 30.

[0089] The cipher selection rule table 15-1 shown in FIG. 8(a) is an cipher selection rule table when a slower cipher is used without limiting the rate of communication in the sending direction of the communication device 10A by encryption processing.

[0090] Referring to (a) of FIG. 8, the cipher suite Kyber1024 is associated with priority 1, the cipher suite Kyber768 is associated with priority 2, and the cipher suite Kyber512 is associated with priority 3.

[0091] Rule 1 associated with priority 1 is "the transmission rate TRS1, which is the data transmission rate from the application 11 to the encryption / decryption unit 12, is slower than the encryption rate of the cipher suite Kyber1024." Rule 2 associated with priority 2 is "the transmission rate TRS1, which is the data transmission rate from the application 11 to the encryption / decryption unit 12, is slower than the encryption rate of the cipher suite Kyber768." And rule 3 associated with priority 3 has no specific rule set.

[0092] Referring to (b) of FIG. 8, the cipher suite Kyber1024 has an encryption speed of 59,907 [bps] and a decryption speed of 64,592 [bps].

[0093] The Kyber768 cipher suite has an encryption speed of 91,045 bps and a decryption speed of 99,386 bps.

[0094] Furthermore, the Kyber512 cipher suite has an encryption speed of 148,198 [bps] and a decryption speed of 163,097 [bps].

[0095] The encryption speed and decryption speed figures in Cryptographic Processing Quality Table 30-1 are calculated as follows: the encryption clock cycles for Kyber512 cipher suite are 539,817, the decryption clock cycles for Kyber512 cipher suite are 490,506, the encryption clock cycles for Kyber768 cipher suite are 878,689, the decryption clock cycles for Kyber768 cipher suite are 804,940, the encryption clock cycles for Kyber1024 cipher suite are 1,335,403, and the decryption clock cycles for Kyber1024 cipher suite are 1,238,542; the operating frequency is 20 MHz; and data is encrypted every 500 bytes. 6 / clock cycles.

[0096] [Cipher suite selection method] (I) When only data transmission is performed from the communication device 10A to the communication device 20A With reference to the encryption selection rule table 15-1 shown in (a) of Figure 8 and the encryption processing quality table 30-1 shown in (b) of Figure 8, we will explain how to select an encryption suite when only transmitting data from communication device 10A to communication device 20A.

[0097] If the transmission rate TRS1 is 100,000 [bps], the cipher selection unit 14 evaluates whether the transmission rate TRS1 (= 100,000 [bps]) satisfies rule 1 in the cipher selection rule table 15-1 (= the transmission rate TRS1, which is the transmission rate of data arriving from the application 11 to the encryption / decryption unit 12, is smaller than the encryption rate of the cipher suite Kyber1024).

[0098] In this case, the encryption speed of the Kyber1024 cipher suite is 59,907 [bps] (see (b) of Figure 8), so the transmission speed TRS1 (= 100,000 [bps]) is not smaller than the encryption speed of the Kyber1024 cipher suite (= 59,907 [bps]).

[0099] Therefore, the cipher selection unit 14 evaluates that the transmission rate TRS1 (= 100,000 [bps]) does not satisfy rule 1 in the cipher selection rule table 15-1 (= the transmission rate TRS1, which is the transmission rate of data when it arrives from the application 11 to the encryption / decryption unit 12, is smaller than the encryption rate of the cipher suite Kyber1024).

[0100] Since the transmission rate TRS1 (=100,000 [bps]) does not satisfy rule 1, the encryption selection unit 14 next evaluates whether the transmission rate TRS1 (=100,000 [bps]) satisfies rule 2 or not.

[0101] In this case, the encryption speed of the Kyber768 cipher suite is 91,045 [bps] (see (b) of Figure 8), so the transmission speed TRS1 (= 100,000 [bps]) is not smaller than the encryption speed of the Kyber768 cipher suite (= 91,045 [bps]).

[0102] Therefore, the cipher selection unit 14 evaluates that the transmission rate TRS1 (= 100,000 [bps]) does not satisfy rule 2 in the cipher selection rule table 15-1 (= the transmission rate TRS1, which is the transmission rate of data when it arrives from the application 11 to the encryption / decryption unit 12, is smaller than the encryption rate of the cipher suite Kyber768).

[0103] Since the transmission rate TRS1 (=100,000 [bps]) does not satisfy rule 2, the encryption selection unit 14 next evaluates whether the transmission rate TRS1 (=100,000 [bps]) satisfies rule 3 or not.

[0104] Since no specific rule is defined for rule 3, the cipher suite selection unit 14 evaluates that the transmission rate TRS1 (=100,000 [bps]) satisfies rule 3, and selects the cipher suite 512 associated with rule 3.

[0105] In this way, the cipher suite selection unit 14 uses the transmission rate TRS1 to evaluate the rules in the cipher suite selection rule table 15-1 starting from the rule with the highest priority (rule 1 associated with priority 1), and selects the cipher suite corresponding to the first rule that is satisfied.

[0106] The reason why rule 1 in the encryption selection rule table 15-1 is that "the transmission rate TRS1, which is the rate at which data arrives from the application 11 to the encryption / decryption unit 12, is smaller than the encryption rate of the Kyber1024 encryption suite" is as follows.

[0107] If the transmission rate TRS1 is equal to or greater than the encryption rate of the Kyber1024 cipher suite, selecting the Kyber1024 cipher suite will cause the transmission rate TRS1 when transmitting data from the communication device 10A to the communication device 20A to be determined by the encryption rate of the Kyber1024 cipher suite, so this is to prevent the transmission rate TRS1 from being determined by the encryption processing of the encryption 12 / decryption unit.

[0108] The reason why rule 2 in the encryption selection rule table 15-1 is that "the transmission rate TRS1, which is the rate at which data is transmitted from the application 11 to the encryption / decryption unit 12, is smaller than the encryption rate of the encryption suite Kyber768" is the same as above.

[0109] Fig. 9 is a schematic diagram showing another example of the cipher selection rule table 15. The cipher selection rule table 15-2 shown in Fig. 9 is a cipher selection rule table for dealing with the rate limitation of the communication path in the transmission direction of the communication device 10A, without being rate-limiting due to the encryption process.

[0110] Referring to FIG. 9, encryption cipher selection rule table 15-2 is the same as encryption cipher selection rule table 15-1 except that rules 1 and 2 of encryption cipher selection rule table 15-1 are changed.

[0111] In the encryption selection rule table 15-2, rule 1 is that when transmission from communication device 10A to communication device 20A is rate-limited by transmission rate TRS2, the transmission rate TRS2 from encryption / decryption unit 12 to communication IF1 is smaller than the encryption rate of cipher suite Kyber1024, and when transmission from communication device 10A to communication device 20A is not rate-limited by transmission rate TRS2, the transmission rate TRS1 from application 11 to encryption / decryption unit 12 is smaller than the encryption rate of cipher suite Kyber1024.

[0112] Furthermore, in the encryption selection rule table 15-2, rule 2 states that when transmission from communication device 10A to communication device 20A is rate-limited by transmission rate TRS2, the transmission rate TRS2 from the encryption / decryption unit 12 to communication IF1 is smaller than the encryption rate of the cipher suite Kyber768, and when transmission from communication device 10A to communication device 20A is not rate-limited by transmission rate TRS2, the transmission rate TRS1 from application 11 to encryption / decryption unit 12 is smaller than the encryption rate of the cipher suite Kyber768.

[0113] When the transmission rate TRS1, the current encryption rate of the encryption / decryption unit 12 of the communication device 10A, and the transmission rate TRS2 are [transmission rate TRS1 < (current encryption rate of the encryption / decryption unit 12) and transmission rate TRS1 > transmission rate TRS2], the transmission from the communication device 10A to the communication device 20A is rate-limited by the transmission rate TRS2.

[0114] The encryption / decoration unit 14 refers to the encryption / decoration selection rule table 15-2 shown in FIG. 9 and the encryption / decoration processing quality table 30-1 shown in FIG. 8(b) to evaluate whether rule 1 is satisfied.

[0115] If the cipher suite selection unit 14 evaluates that the rule 1 is satisfied, it selects the cipher suite Kyber1024 associated with the rule 1.

[0116] On the other hand, when the encryption selector 14 determines that the rule 1 is not satisfied, it determines whether the rule 2 is satisfied.

[0117] Then, when the encryption key selection unit 14 evaluates that the rule 2 is satisfied, it selects Kyber768, which is associated with the rule 2.

[0118] On the other hand, if the cipher suite selection unit 14 determines that rule 2 is not satisfied, it evaluates whether rule 3 is satisfied. In this case, since rule 3 does not specify a specific rule, the cipher suite selection unit 14 determines that rule 3 is satisfied and selects the Kyber512 cipher suite associated with rule 3.

[0119] The cipher selection rule table 15-2 is obtained by adding a condition regarding the presence or absence of a communication path rate limitation to the cipher selection rule table 15-1 shown in FIG. 8(a).

[0120] FIG. 10 is a schematic diagram of a generalized encryption selection rule table in the case where only data transmission is performed from the communication device 10A to the communication device 20A.

[0121] Referring to Figure 10, (a) of Figure 10 shows encryption selection rule table 15-G1, which is a generalization of encryption selection rule table 15-1 shown in Figure 8, and (b) of Figure 10 shows encryption selection rule table 15-G2, which is a generalization of encryption selection rule table 15-2 shown in Figure 9.

[0122] Therefore, the cipher selection unit 14 evaluates whether rule 1 is satisfied based on the cipher processing quality table 30 (see Figure 5) and the cipher selection rule table 15-G1, and if it evaluates that rule 1 is satisfied, it selects cipher suite 1 associated with rule 1, and if it evaluates that rule 1 is not satisfied, it evaluates whether rule 2 is satisfied.

[0123] If the cipher suite selection unit 14 determines that rule 2 is satisfied, it selects cipher suite 2 associated with rule 2, and if it determines that rule 2 is not satisfied, it determines whether rule 3 is satisfied.

[0124] Similarly, when the encryption code selection unit 14 determines that the rule N-2 is not satisfied, it then determines whether the rule N-1 is satisfied.

[0125] If the cipher suite selection unit 14 evaluates that the rule N-1 is satisfied, it selects the cipher suite N-1 associated with the rule N-1, and if it evaluates that the rule N-1 is not satisfied, it evaluates whether the rule N is satisfied.

[0126] Since the specific content of rule N is not specified, the cipher suite selection unit 14 selects cipher suite N associated with rule N when it evaluates that rule N-1 is not satisfied.

[0127] The cipher suite selection unit 14 similarly selects a cipher suite based on the cryptographic processing quality table 30 (see FIG. 5) and the cipher suite selection rule table 15-G2. (II) When data is transmitted and received between the communication device 10A and the communication device 20A When transmitting and receiving data between communication device 10A and communication device 20A, there are cases where transmission rate TRS1 is used, cases where transmission rates TRS1 and TRS2 are used, cases where reception rate TRS3 is used, cases where reception rates TRS3 and TRS4 are used, cases where transmission rate TRS1 and reception rate TRS3 are used, cases where transmission rate TRS1, transmission rate TRS2 and reception rate TRS3 are used, cases where transmission rate TRS1 and reception rate TRS4 are used, and cases where transmission rate TRS1, transmission rate TRS2, reception rate TRS3 and reception rate TRS4 are used.

[0128] The case where the transmission rate TRS1 is used and the case where the transmission rates TRS1 and TRS2 are used have been described in FIG. 8(a) and FIG. 9, and therefore a description thereof will be omitted here. (II-1) When using receiving speed TRS3 Fig. 11 is a schematic diagram showing an example of the cipher selection rule table 15 when using a reception rate of TRS3. The cipher selection rule table 15-3 shown in Fig. 11 is an cipher selection rule table when using a slower cipher without limiting the rate of communication in the reception direction of the communication device 10A by the decryption process.

[0129] Referring to FIG. 11, cipher selection rule table 15-3 is the same as cipher selection rule table 15-1 except that rules 1 to 3 of cipher selection rule table 15-1 are changed.

[0130] In the cipher suite selection rule table 15-3, rule 1 is that the reception speed TRS3 at the communication IF1 of the communication device 10A is smaller than the decryption speed of the cipher suite Kyber1024.

[0131] Furthermore, rule 2 is that the reception speed TRS3 at the communication IF1 of the communication device 10A is smaller than the decryption speed of the encryption suite Kyber768.

[0132] And Rule 3 does not specify any specific content.

[0133] The cipher suite selection unit 14 evaluates whether rule 1 is satisfied based on the cipher suite selection rule table 15-3, and if it evaluates that rule 1 is satisfied, selects the cipher suite Kyber1024 associated with rule 1, and if it evaluates that rule 1 is not satisfied, it evaluates whether rule 2 is satisfied.

[0134] If the cipher suite selection unit 14 determines that rule 2 is satisfied, it selects the cipher suite Kyber768 associated with rule 2, and if it determines that rule 2 is not satisfied, it evaluates whether rule 3 is satisfied.

[0135] Since the specific content of rule 3 is not specified, the cipher suite selection unit 14 evaluates that rule 3 is satisfied and selects the cipher suite Kyber512 associated with rule 3.

[0136] The cipher selection rule table 15-3 includes rules that are symmetric to the rules in the cipher selection rule table 15-1 shown in Fig. 8(a) because the cipher selection rule table 15-1 evaluates whether each rule is satisfied using the transmission rate TRS1, while the cipher selection rule table 15-3 evaluates whether each rule is satisfied using the reception rate TRS3, which is the rate in the opposite direction to the transmission rate TRS1. (II-2) When using the receiving speed TRS3 and the receiving speed TRS4 FIG. 12 is a schematic diagram showing an example of the encryption selection rule table 15 when the receiving rates TRS3 and TRS4 are used.

[0137] Referring to FIG. 12, encryption cipher selection rule table 15-4 is the same as encryption cipher selection rule table 15-1 except that rules 1 to 3 of encryption cipher selection rule table 15-1 are changed.

[0138] The cipher selection rule table 15-4 is an cipher selection rule table for dealing with the rate limitation of the communication path in the receiving direction of the communication device 10A without imposing rate limitation on the decryption process.

[0139] In the encryption selection rule table 15-4, rule 1 states that if the reception rate TRS4 in the application 11 of the communication device 10A is rate-limiting, the reception rate TRS4 is smaller than the decryption rate of the encryption suite Kyber1024, and if the reception rate TRS4 is not rate-limiting, the reception rate TRS3 is smaller than the decryption rate of the encryption suite Kyber1024.

[0140] Furthermore, rule 2 states that if the receiving rate TRS4 is rate-limiting, then the receiving rate TRS4 is smaller than the decryption rate of the encryption suite Kyber768, and if the receiving rate TRSTRS4 is not rate-limiting, then the receiving rate TRS3 is smaller than the decryption rate of the encryption suite Kyber768.

[0141] And Rule 3 does not specify any specific content.

[0142] The cipher suite selection unit 14 evaluates whether rule 1 is satisfied based on the cipher suite selection rule table 15-4, and if it evaluates that rule 1 is satisfied, selects the cipher suite Kyber1024 associated with rule 1, and if it evaluates that rule 1 is not satisfied, it evaluates whether rule 2 is satisfied.

[0143] If the cipher suite selection unit 14 determines that rule 2 is satisfied, it selects the cipher suite Kyber768 associated with rule 2, and if it determines that rule 2 is not satisfied, it evaluates whether rule 3 is satisfied.

[0144] Since the specific content of rule 3 is not specified, the cipher suite selection unit 14 evaluates that rule 3 is satisfied and selects the cipher suite Kyber512 associated with rule 3.

[0145] When the reception rate TRS3 is lower than the decryption rate of the current cipher suite of the communication device 10A and is higher than the reception rate TRS4, ​​it is determined that the reception rate TRS4 is rate-limiting.

[0146] Therefore, when the reception rate TRS3 is equal to or greater than the decryption rate of the current cipher suite of the communication device 10A, or when the reception rate TRS3 is equal to or less than the reception rate TRS4, ​​or when the reception rate TRS3 is equal to or greater than the decryption rate of the current cipher suite of the communication device 10A and the reception rate TRS3 is equal to or less than the reception rate TRS4, ​​it is determined that the reception rate TRS4 is not rate-limiting. (II-3) When using a sending rate of TRS1 and a receiving rate of TRS3 FIG. 13 is a schematic diagram showing an example of the encryption selection rule table 15 when a transmission rate TRS1 and a reception rate TRS3 are used.

[0147] The cipher selection rule table 15-5 shown in FIG. 13 is an cipher selection rule table when slower ciphers are used without limiting the rate of communication in the sending and receiving directions of the communication device 10A by encryption processing.

[0148] Referring to FIG. 13, cipher selection rule table 15-5 is the same as cipher selection rule table 15-1 except that rules 1 to 3 of cipher selection rule table 15-1 are changed.

[0149] The cipher selection rule table 15-5 is an cipher selection rule table for using slower ciphers without limiting the speed of communication in the sending and receiving directions by encryption processing.

[0150] In the cipher selection rule table 15-5, rule 1 is that the transmission rate TRS1 is smaller than the encryption rate of the cipher suite Kyber1024, and the reception rate TRS3 is smaller than the decryption rate of the cipher suite Kyber1024.

[0151] Furthermore, rule 2 is that the sending rate TRS1 is smaller than the encryption rate of the encryption suite Kyber768, and the receiving rate TRS3 is smaller than the decryption rate of the encryption suite Kyber768.

[0152] And Rule 3 does not specify any specific content.

[0153] The cipher selection unit 14 evaluates whether rule 1 is satisfied based on the cipher selection rule table 15-5, and if it evaluates that rule 1 is satisfied, it selects the cipher suite Kyber1024 associated with rule 1. If it evaluates that rule 1 is not satisfied (i.e., if at least one of "the transmission rate TRS1 is smaller than the encryption rate of the cipher suite Kyber1024" and "the reception rate TRS3 is smaller than the decryption rate of the cipher suite Kyber1024" is not satisfied), it evaluates whether rule 2 is satisfied.

[0154] If the encryption selection unit 14 evaluates that rule 2 is satisfied, it selects the encryption suite Kyber768 associated with rule 2, and if it evaluates that rule 2 is not satisfied (i.e., when at least one of "the transmission rate TRS1 is smaller than the encryption rate of the encryption suite Kyber768" and "the reception rate TRS3 is smaller than the decryption rate of the encryption suite Kyber768" is not satisfied), it evaluates whether rule 3 is satisfied.

[0155] Since the specific content of rule 3 is not specified, the cipher suite selection unit 14 evaluates that rule 3 is satisfied and selects the cipher suite Kyber512 associated with rule 3. (II-4) When using transmission speed TRS1, transmission speed TRS2 and reception speed TRS3 FIG. 14 is a schematic diagram showing an example of the encryption selection rule table 15 when the transmission rates TRS1, TRS2, and the reception rate TRS3 are used.

[0156] Referring to FIG. 14, cipher selection rule table 15-6 is the same as cipher selection rule table 15-1 except that rules 1 to 3 of cipher selection rule table 15-1 are changed.

[0157] The cipher selection rule table 15-6 is an cipher selection rule table that corresponds to the rate limit of the communication path in the transmission direction and prevents the rate of transmission and reception from being limited by encryption.

[0158] In the encryption selection rule table 15-6, rule 1 states that if the transmission rate TRS2 of the communication device 10A is rate-limited, the transmission rate TRS2 is smaller than the encryption rate of the encryption suite Kyber1024, and if the transmission rate TRS2 is not rate-limited, the transmission rate TRS1 is smaller than the encryption rate of the encryption suite Kyber1024 and the reception rate TRS3 is smaller than the decryption rate of the encryption suite Kyber1024.

[0159] Furthermore, rule 2 states that if the transmission rate TRS2 is rate-limited, the transmission rate TRS2 is smaller than the encryption rate of the Kyber768 encryption suite, and if the transmission rate TRS2 is not rate-limited, the transmission rate TRS1 is smaller than the encryption rate of the Kyber768 encryption suite and the reception rate TRS3 is smaller than the decryption rate of the Kyber768 encryption suite.

[0160] And Rule 3 does not specify any specific content.

[0161] The cipher suite selection unit 14 evaluates whether rule 1 is satisfied based on the cipher suite selection rule table 15-6, and if it evaluates that rule 1 is satisfied, selects the cipher suite Kyber1024 associated with rule 1, and if it evaluates that rule 1 is not satisfied, it evaluates whether rule 2 is satisfied.

[0162] Here, when communication in the transmission direction of communication device 10A is rate-limited by the transmission rate TRS2, if the transmission rate TRS2 is evaluated to be equal to or greater than the encryption rate of encryption suite Kyber1024, it is evaluated as not satisfying rule 1. Also, when communication in the transmission direction of communication device 10A is not rate-limited by the transmission rate TRS2, if at least one of "the transmission rate TRS1 is equal to or greater than the encryption rate of encryption suite Kyber1024" and "the reception rate TRS3 is equal to or greater than the decryption rate of encryption suite Kyber1024" is satisfied, it is evaluated as not satisfying rule 1.

[0163] When evaluating whether rule 2 is satisfied, the cipher suite selection unit 14 selects the Kyber768 cipher suite associated with rule 2 if it evaluates that rule 2 is satisfied, and evaluates whether rule 3 is satisfied if it evaluates that rule 2 is not satisfied.

[0164] Here, to evaluate that rule 2 is not satisfied, simply read "encryption suite Kyber1024" as "encryption suite Kyber768" in the explanation of the evaluation that rule 1 is not satisfied above.

[0165] In evaluating whether rule 3 is satisfied or not, since no specific rule is specified for rule 3, the cipher suite selection unit 14 evaluates that rule 3 is satisfied and selects the cipher suite Kyber512 associated with rule 3. (II-5) When using transmission speed TRS1, reception speed TRS3, and reception speed TRS4 FIG. 15 is a schematic diagram showing an example of the encryption selection rule table 15 when a transmission rate TRS1, a reception rate TRS3, and a reception rate TRS4 are used.

[0166] The cipher selection rule table 15-7 shown in FIG. 15 is an cipher selection rule table when the transmission and reception speed is not limited by the cryptographic processing (encryption processing and decryption processing) in response to the rate limit of the communication path in the receiving direction of the communication device 10A.

[0167] Referring to FIG. 15, encryption cipher selection rule table 15-7 is the same as encryption cipher selection rule table 15-1 except that rules 1 to 3 of encryption cipher selection rule table 15-1 are changed.

[0168] In the encryption selection rule table 15-7, rule 1 states that if the communication device 10A is rate-constrained by the receiving rate TRS4, ​​the receiving rate TRS4 is smaller than the decryption rate of the encryption suite Kyber1024, and if the communication device 10A is not rate-constrained by the receiving rate TRS2, the sending rate TRS1 is smaller than the encryption rate of the encryption suite Kyber1024 and the receiving rate TRS3 is smaller than the decryption rate of the encryption suite Kyber1024.

[0169] Furthermore, rule 2 states that if the receiving rate TRS4 is rate-limiting, the receiving rate TRS4 is smaller than the decryption rate of the encryption suite Kyber768, and if the receiving rate TRS4 is not rate-limiting, the sending rate TRS1 is smaller than the encryption rate of the encryption suite Kyber768 and the receiving rate TRS3 is smaller than the decryption rate of the encryption suite Kyber768.

[0170] And Rule 3 does not specify any specific content.

[0171] The cipher suite selection unit 14 evaluates whether rule 1 is satisfied based on the cipher suite selection rule table 15-7, and if it evaluates that rule 1 is satisfied, selects the Kyber1024 cipher suite associated with rule 1, and if it evaluates that rule 1 is not satisfied, it evaluates whether rule 2 is satisfied.

[0172] Here, when the rate is limited by the receiving rate TRS4, ​​if the receiving rate TRS4 is evaluated to be equal to or greater than the decryption rate of the Kyber1024 encryption suite, it is evaluated as not satisfying rule 1. Also, when the rate is not limited by the receiving rate TRS4, ​​if at least one of the following is satisfied: "the sending rate TRS1 is equal to or greater than the encryption rate of the Kyber1024 encryption suite" and "the receiving rate TRS3 is equal to or greater than the decryption rate of the Kyber1024 encryption suite," it is evaluated as not satisfying rule 1.

[0173] When evaluating whether rule 2 is satisfied, the cipher suite selection unit 14 selects the Kyber768 cipher suite associated with rule 2 if it evaluates that rule 2 is satisfied, and evaluates whether rule 3 is satisfied if it evaluates that rule 2 is not satisfied.

[0174] Here, to evaluate that rule 2 is not satisfied, simply read "encryption suite Kyber1024" as "encryption suite Kyber768" in the explanation of the evaluation that rule 1 is not satisfied above.

[0175] In evaluating whether rule 3 is satisfied or not, since no specific rule is specified for rule 3, the cipher suite selection unit 14 evaluates that rule 3 is satisfied and selects the cipher suite Kyber512 associated with rule 3. (II-6) When using transmission speed TRS1, transmission speed TRS2, reception speed TRS3 and reception speed TRS4 FIG. 16 is a schematic diagram showing an example of the encryption selection rule table 15 when the transmission rates TRS1, TRS2, reception rates TRS3, and TRS4 are used.

[0176] The cipher suite selection rule table 15-8 shown in FIG. 16 is an cipher suite selection rule table for dealing with the rate limitation of the communication path without being rate-limiting due to the cipher suite process (encryption process and decryption process) in the transmission and reception direction of the communication device 10A.

[0177] Referring to FIG. 16, cipher selection rule table 15-8 is the same as cipher selection rule table 15-1 except that rules 1 to 3 of cipher selection rule table 15-1 are changed.

[0178] In the cipher selection rule table 15-8, rule 1 is that if the communication device 10A is rate-limited by its transmission rate TRS2, then the transmission rate TRS2 is smaller than the encryption rate of the Kyber1024 encryption suite; if the communication device 10A is not rate-limited by the transmission rate TRS2 but is rate-limited by its reception rate TRS4, ​​then the reception rate TRS4 is smaller than the decryption rate of the Kyber1024 encryption suite; if the communication device 10A is not rate-limited by either the transmission rate TRS2 or the reception rate TRS4, ​​then the transmission rate TRS1 is smaller than the encryption rate of the Kyber1024 encryption suite and the reception rate TRS3 is smaller than the decryption rate of the Kyber1024 encryption suite.

[0179] Furthermore, rule 2 states that if the rate is limited by the transmission rate TRS2, then the transmission rate TRS2 is smaller than the encryption rate of the Kyber768 encryption suite; if the rate is not limited by the transmission rate TRS2 but is limited by the reception rate TRS4, ​​then the reception rate TRS4 is smaller than the decryption rate of the Kyber768 encryption suite; if the rate is not limited by either the transmission rate TRS2 or the reception rate TRS4, ​​then the transmission rate TRS1 is smaller than the encryption rate of the Kyber768 encryption suite and the reception rate TRS3 is smaller than the decryption rate of the Kyber768 encryption suite.

[0180] And Rule 3 does not specify any specific content.

[0181] The cipher suite selection unit 14 evaluates whether rule 1 is satisfied based on the cipher suite selection rule table 15-8, and if it evaluates that rule 1 is satisfied, selects the cipher suite Kyber1024 associated with rule 1, and if it evaluates that rule 1 is not satisfied, it evaluates whether rule 2 is satisfied.

[0182] Here, when the rate is limited by the transmission rate TRS2, if the transmission rate TRS2 is evaluated to be equal to or greater than the encryption rate of the Kyber1024 encryption suite, it is evaluated as not satisfying rule 1. Also, when the rate is not limited by the transmission rate TRS2 but is limited by the reception rate TRS4, ​​it is evaluated as not satisfying rule 1 if the reception rate TRS4 is evaluated to be equal to or greater than the decryption rate of the Kyber1024 encryption suite. Furthermore, when the rate is not limited by either the transmission rate TRS2 or the reception rate TRS4, ​​it is evaluated as not satisfying rule 1 if at least one of "the transmission rate TRS1 is equal to or greater than the encryption rate of the Kyber1024 encryption suite" and "the reception rate TRS3 is equal to or greater than the decryption rate of the Kyber1024 encryption suite" is satisfied.

[0183] When evaluating whether rule 2 is satisfied, the cipher suite selection unit 14 selects the Kyber768 cipher suite associated with rule 2 if it evaluates that rule 2 is satisfied, and evaluates whether rule 3 is satisfied if it evaluates that rule 2 is not satisfied.

[0184] Here, to evaluate that rule 2 is not satisfied, simply read "encryption suite Kyber1024" as "encryption suite Kyber768" in the explanation of the evaluation that rule 1 is not satisfied above.

[0185] In evaluating whether rule 3 is satisfied or not, since rule 3 does not prescribe any specific content, the cipher suite selection unit 14 evaluates that rule 3 is satisfied and selects the cipher suite Kyber512 associated with rule 3.

[0186] In the encryption selection rule table 15-8, when the transmission rate TRS1 is evaluated to be smaller than the [current encryption rate of the encryption / decryption unit 12 of the communication device 10A] and larger than the transmission rate TRS2, it is determined that the rate is limited by the transmission rate TRS2.

[0187] Furthermore, in the encryption selection rule table 15-8, when it is evaluated that the reception rate TRS3 is smaller than the [current decryption rate of the encryption / decryption unit 12 of the communication device 10A] and the reception rate TRS3 is larger than the reception rate TRS4, ​​it is determined that the rate is limited by the reception rate TRS4.

[0188] 17 is a flowchart for explaining the operation of communication device 10A. Referring to Fig. 17, when operation of communication device 10A starts, rules are set in cipher selection rule table 15 (step S1). In this case, the operator of communication device 10A or application 11 of communication device 10A sets the rules in cipher selection rule table 15.

[0189] After step S1, the cipher suite selection unit 14 performs a test to measure the processing time of each cipher suite, and initializes the cipher suite processing quality table 30 (step S2).

[0190] Then, the encryptor / decryptor 12 executes the process of establishing an encrypted communication path based on the cipher suite initially set by the operator (step S3).

[0191] Thereafter, the cipher suite selection unit 14 sets a cipher suite change prohibition period PHB, which is a period during which a change of the cipher suite is prohibited (step S4).

[0192] Subsequently, the communication device 10A communicates with the communication device 20A using the application (step S5).

[0193] In this case, when communication device 10A executes only the transmission process of transmitting data to communication device 20A, application 11 of communication device 10A outputs the data to encryption / decryption unit 12, and encryption / decryption unit 12 receives the data from application 11, encrypts the received data with a cipher suite to generate encrypted data, and transmits the generated encrypted data to communication device 20A via communication IF1.

[0194] Furthermore, when communication device 10A transmits and receives data to communication device 20A, application 11 of communication device 10A outputs the data to encryption / decryption unit 12, and encryption / decryption unit 12 receives the data from application 11, encrypts the received data with a cipher suite to generate encrypted data, and transmits the generated encrypted data to communication device 20A via communication IF 1. Thereafter, encryption / decryption unit 12 of communication device 10A receives the encrypted data from communication device 20A via communication IF 1, decrypts the received encrypted data, and outputs the data to application 11.

[0195] After step S5, the cipher suite selection unit 14 determines whether the cipher suite change prohibition period PHB has ended (step S6).

[0196] Then, when the cipher change prohibition period PHB ends (see "YES" in step S6), the cipher selector 14 outputs to the quality monitor 13 the information that the cipher change prohibition period PHB has ended.

[0197] When the quality monitoring unit 13 receives a notification from the cipher selection unit 14 that the cipher change prohibition period PHB has ended, the quality monitoring unit 13 monitors the processing and communication quality (step S7). More specifically, the quality monitoring unit 13 monitors the data encryption process performed by the encryption / decryption unit 12, as well as the transmission rates TRS1 and TRS2 and the reception rates TRS3 and TRS4.

[0198] After step S7, the cipher selection unit 14 inquires about the communication quality from the quality monitoring unit 13, and selects a cipher suite based on the first communication quality (= transmission rates TRS1, TRS2 and reception rates TRS3, TRS4) obtained from the quality monitoring unit 13, the cipher selection rule table 15, and the cryptographic processing quality table 30 (step S8).

[0199] Then, the cipher suite selection unit 14 determines whether or not the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, thereby determining whether or not a different cipher suite has been selected (step S9).

[0200] In this case, when the cipher selection unit 14 determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, it determines that a different cipher suite has been selected, and when the selected cipher suite is the same as the cipher suite used in the encryption / decryption unit 12, it determines that a different cipher suite has not been selected (i.e., the same cipher suite has been selected).

[0201] If it is determined in step S9 that a different cipher suite has not been selected, the operation of the communication device 10A proceeds to step S7.

[0202] On the other hand, if it is determined in step S9 that a different cipher suite has been selected, the cipher selection unit 14 notifies the encryption / decryption unit 12 of the selected cipher suite and changes the cipher suite in the encryption / decryption unit 12 (step S10). As a result, the encryption process in the encryption / decryption unit 12 is changed.

[0203] After step S10, the cipher selector 14 sets the cipher change prohibition period PHB (step S11).

[0204] Then, the communication device 10A communicates with the communication device 20A using the changed cipher suite (step S12). In this case, "only the transmission process in which the communication device 10A transmits data to the communication device 20A" or "transmission and reception of data between the communication device 10A and the communication device 20A" described in step S5 is executed.

[0205] Thereafter, the operation of the communication device 10A proceeds to step S6. Then, while the communication device 10A is operating, the above-described steps S6 to S12 are repeatedly executed.

[0206] In the flowchart shown in FIG. 17, the cipher selection unit 14 determines in step S9 whether the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12. When it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12 (see "YES" in step S9), it executes step S10. When it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12 (see "NO" in step S9), the operation of the communication device 10A proceeds to step S7. This corresponds to executing a "cipher suite selection process in which the cipher suite used in the encryption / decryption unit 12 is determined to be different from the cipher suite used in the encryption / decryption unit 12, and if it is determined that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, the cipher suite used in the encryption / decryption unit 12 is changed to the selected cipher suite, and if it is determined that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12 (i.e., the selected cipher suite is the same as the cipher suite used in the encryption / decryption unit 12), the cipher suite used in the encryption / decryption unit 12 is not changed to the selected cipher suite."

[0207] In this case, the cipher suite selected by the cipher selector 14 constitutes the "first cipher suite," and the cipher suite used in the encryption / decryption unit 12 constitutes the "second cipher suite."

[0208] Also, in the flowchart shown in Figure 17, when step S8 is executed, when communication device 10A executes only the transmission process of transmitting data to communication device 20A, cipher selection unit 14 selects a cipher suite using cipher selection rule table 15-1 (see (a) of Figure 8) or cipher selection rule table 15-1 (see Figure 9), and communicates the selected cipher suite to encryption / decryption 12.

[0209] On the other hand, when communication device 10A transmits and receives data to and from communication device 20A, cipher suite selection unit 14 selects a cipher suite using one of cipher suite selection rule tables 15-1, 15-3 to 15-8 (see Figure 8(a) and Figures 11 to 16) and communicates the selected cipher suite to encryption / decryption unit 12.

[0210] The reason why the cipher change prohibition period PHB is set in step S11 is to prevent the cipher suite used in the encryption / decryption unit 12 from being changed to another cipher suite within a short period of time (see step S10). Also, when the cipher suite is changed, communication by the application 11 is stopped during the process of establishing an encrypted communication path, so the cipher change prohibition period PHB is set to prevent the communication by the application 11 from being stopped due to the process of establishing an encrypted communication path.

[0211] Furthermore, after step S12, the operation of the communication device 10A proceeds to step S6 in order to ensure that the period until the cipher change prohibition period PHB set in step S11 ends is secured so that the quality monitoring unit 13 can monitor the processing and communication quality using the changed cipher suite.

[0212] 18 is a schematic diagram showing the process of establishing an encrypted communication path. Referring to FIG. 18, when a cipher suite is initially set in the encryption / decryption unit 12 or when a cipher suite in the encryption / decryption unit 12 is changed, information exchange, key exchange, and authentication are performed between the encryption / decryption unit 12 and the encryption / decryption unit 21 of the communication device 20A.

[0213] Information exchange involves exchanging information necessary to establish an encrypted communication path, such as the encryption algorithm, key length, key exchange method, whether authentication is required, the authentication method, and the message verification method, between the encryption / decryption unit 12 of communication device 10A and the encryption / decryption unit 21 of communication device 20A.

[0214] Key exchange is a process in which the encryption / decryption unit 12 of the communication device 10A and the encryption / decryption unit 21 of the communication device 20A obtain key information necessary for encrypted communication. For example, key data may be exchanged directly, or a token for calculating a key may be exchanged. Furthermore, exchange may also take place using a public key certificate.

[0215] Furthermore, authentication is performed if required by the cipher suite, and there are methods using public key certificates and password authentication methods.

[0216] In step S3 of Figure 17, the process of establishing an encrypted communication path shown in Figure 18 is executed, but if the encryption key is set in the encryption / decryption unit 12 by the operator of the communication device 10A or the application 11, the key exchange in Figure 18 can be omitted.

[0217] Also in step S10 of FIG. 17, the process of establishing an encrypted communication path shown in FIG. 18 is executed.

[0218] As shown in FIG. 18, after information exchange, key exchange, and authentication are completed between the encryption / decryption unit 12 of the communication device 10A and the encryption / decryption unit 21 of the communication device 20A, data is transmitted or received between the application 11 of the communication device 10A and the application 22 of the communication device 20A using the established encrypted communication path.

[0219] Fig. 19 is a flowchart for explaining the detailed operation of step S8 shown in Fig. 17. Fig. 20 is a schematic diagram of an encryption selection rule table used in the flowchart shown in Fig. 17. The encryption selection rule table 15A shown in Fig. 20 is a table in which rules 1 to N of the encryption selection rule table 15 shown in Fig. 6 are calculated based on the transmission rate TRS1 from the application 11 to the encryption / decryption unit 12 and the encryption rates C1 to C2 of the encryption processing quality table shown in Fig. 7. N-1 The encryption cipher selection rule table 15A is a generalized encryption cipher selection rule table of the encryption cipher selection rule table 15-1 shown in FIG.

[0220] Referring to FIG. 19, after step S7 in FIG. 17, the encryption key selection unit 14 of the communication device 10A sets n=1 (step S81) and selects the rule n associated with the priority n in the encryption key selection rule table 15A (step S82).

[0221] Then, the cipher selection unit 14 determines whether the transmission rate TRS1 from the application 11 to the encryption / decryption unit 12 satisfies the rule n (step S83). In this case, the cipher selection unit 14 determines whether the transmission rate TRS1 satisfies the encryption rate C of the cipher suite n. n Determine whether the transmission rate TRS1 is smaller than the encryption rate C of cipher suite n. n If it is determined that the transmission rate TRS1 is smaller than the encryption rate C of cipher suite n, it is determined that the transmission rate TRS1 satisfies rule n. n If it is determined that the transmission rate TRS1 is equal to or greater than this, it is determined that the transmission rate TRS1 does not satisfy the rule n.

[0222] If it is determined in step S83 that the transmission rate TRS1 does not satisfy the rule n, the encryption selection unit 14 sets n=n+1 (step S84). Thereafter, the detailed operation of step S8 proceeds to step S82, and steps S82 to S84 are repeatedly executed until it is determined in step S83 that the transmission rate TRS1 satisfies the rule n.

[0223] If it is determined in step S83 that the transmission rate TRS1 satisfies the rule n, the cipher suite selection unit 14 refers to the cipher suite selection rule table 15A and selects the cipher suite n associated with the rule n when it is determined that the transmission rate TRS1 satisfies the rule n (step S85). Then, the process proceeds to step S9 in FIG. 17.

[0224] In the flowchart shown in Figure 19, when the encryption selection rule table 15A shown in Figure 20 is used, when step S82 is executed after step S81, the encryption selection unit 14 selects rule 1 associated with priority 1 in the encryption selection rule table 15A in step S82, and determines whether the transmission rate TRS1 satisfies rule 1 in step S83.

[0225] If it is determined in step S83 that the transmission rate TRS1 satisfies rule 1, the cipher suite selection unit 14 selects cipher suite 1 associated with rule 1 with reference to the cipher suite selection rule table 15A in step S85.

[0226] On the other hand, if the cipher selection unit 14 determines in step S83 that the transmission rate TRS1 does not satisfy rule 1, then in step S84 it sets n=1+1=2. Thereafter, in step S82, the cipher selection unit 14 selects rule 2 associated with priority 2 in the cipher selection rule table 15A, and in step S83 determines whether the transmission rate TRS1 satisfies rule 2.

[0227] If it is determined in step S83 that the transmission rate TRS1 satisfies rule 2, the cipher suite selection unit 14 selects cipher suite 2 associated with rule 2 with reference to the cipher suite selection rule table 15A in step S85.

[0228] On the other hand, if the encryption selector 14 determines in step S83 that the transmission rate TRS1 does not satisfy rule 2, then in step S84 it sets n=2+1=3. Thereafter, the above-described operations are repeatedly executed.

[0229] Then, in step S84, the encryption selection unit 14 sets n=n+1=N-1, and then in step S82, selects rule N-1 associated with priority N-1 in the encryption selection rule table 15A, and in step S83, determines whether the transmission rate TRS1 satisfies rule N-1.

[0230] If it is determined in step S83 that the transmission rate TRS1 satisfies the rule N-1, the cipher suite selection unit 14 selects the cipher suite N-1 associated with the rule N-1 by referring to the cipher suite selection rule table 15A in step S85.

[0231] On the other hand, when the encryption selector 14 determines in step S83 that the transmission rate TRS1 does not satisfy the rule N-1, it sets n=N-1+1=N in step S84.

[0232] Thereafter, in step S82, the cipher suite selection unit 14 selects rule N associated with priority N in the cipher suite selection rule table 15A, and in step S83 determines whether the transmission rate TRS1 satisfies rule N. In this case, since no specific rule is set for rule N, the cipher suite selection unit 14 determines in step S83 that the transmission rate TRS1 satisfies rule N.

[0233] Then, the cipher suite selection unit 14 selects the cipher suite N associated with the rule N in step S85.

[0234] In this way, by executing the flowchart shown in FIG. 19, the cipher suite selection unit 14 uses the communication quality (transmission rate TRS1) to evaluate whether the communication quality (transmission rate TRS1) satisfies the rule from the highest priority rule (rule 1 associated with priority 1) in the cipher suite selection rule table 15A, and selects the cipher suite corresponding to the rule when it is first determined that the communication quality (transmission rate TRS1) satisfies the rule.

[0235] In the cipher selection rule table 15A, rules 1 to N-1 respectively indicate that the transmission rate TRS1 is the encryption rate C1 to C2 of the cipher suites 1 to N-1. N-1 The reason for the "smaller than" is the same as that explained in the above-mentioned cipher selection rule table 15-1.

[0236] In the flowchart shown in FIG. 19, one of the encryption cipher selection rule tables 15-2 to 15-8 is used instead of the encryption cipher selection rule table 15-1.

[0237] In this case, like the encryption selection rule table 15A obtained by generalizing the encryption selection rule table 15-1, any one of the encryption selection rule tables 15-2 to 15-8 is generalized, and the generalized encryption selection rule table is used in step S83 in FIG.

[0238] According to the flowchart shown in FIG. 17 (including the flowchart shown in FIG. 19), the cipher suite selection unit 14 selects a cipher suite so that the communication quality (transmission rate TRS1) satisfies the rule (=any one of rules 1 to N) in the cipher suite selection rule table 15A (see step S8 in FIG. 17 (=the flowchart shown in FIG. 19)), and therefore can select a cipher suite that does not impair the communication quality (transmission rate TRS1).

[0239] As a result, the cipher suite in the encryption / decryption unit 12 is changed to the cipher suite selected by the cipher selection unit 14 (see step S10 in FIG. 17), and the encryption / decryption unit 12 of the communication device 10A communicates with the communication device 20A using a cipher suite that does not impair the communication quality (transmission rate TRS1) (see step S12 in FIG. 17). Therefore, data can be encrypted without impairing the communication quality (transmission rate TRS1) of the communication device 10A.

[0240] In the first embodiment, the operation of the communication device 10A may be realized by software. In this case, the communication device 10A includes a CPU (Central Processing Unit), a ROM (Read Only Memory), and a RAM (Random Access Memory). The ROM stores a program Prog_A consisting of the steps of the flowchart shown in FIG. 17 (including the flowchart shown in FIG. 19).

[0241] The CPU reads the program Prog_A from the ROM, executes the read program Prog_A, monitors the communication quality (transmission rate TRS1), and selects a cipher suite based on the monitored communication quality (transmission rate TRS1). The RAM temporarily stores the communication quality (transmission rate TRS1).

[0242] The program Prog_A may also be distributed in the form of being recorded on a recording medium such as a CD or DVD. When the recording medium on which the program Prog_A is recorded is inserted into a computer, the computer reads and executes the program Prog_A from the recording medium, monitors the communication quality (transmission rate TRS1), and selects a cipher suite based on the monitored communication quality (transmission rate TRS1).

[0243] Therefore, the recording medium on which the program Prog_A is recorded is a computer-readable recording medium.

[0244] In addition, when the operation of communication device 10A is realized by the CPU executing program Prog_A, the communication quality is not limited to the transmission rate TRS1, but the communication quality described in any of cipher selection rule table 15-2 (see Figure 9), cipher selection rule table 15-3 (see Figure 11), cipher selection rule table 15-4 (see Figure 12), cipher selection rule table 15-5 (see Figure 13), cipher selection rule table 15-6 (see Figure 14), cipher selection rule table 15-7 (see Figure 15), and cipher selection rule table 15-8 (see Figure 16) is used.

[0245] In the above description, it has been explained that a "cipher change prohibition period PHB" is set, but the present invention is not limited to this and does not require the "cipher change prohibition period PHB" to be set. This is because the cipher selector 14 can select a cipher suite that satisfies a rule (any of rules 1 to N) in the cipher selection rule table 15 based on the communication quality (transmission rate TRS1, etc.) without setting a "cipher change prohibition period PHB."

[0246] [Embodiment 2] Fig. 21 is a schematic diagram of a second embodiment of the communication device 10 shown in Fig. 2. Referring to Fig. 21, the communication device 10B in the second embodiment is the same as the communication device 10A, except that a quality prediction unit 16 is added to the communication device 10A shown in Fig. 3, the encryption cipher selection unit 14 of the communication device 10A is replaced with an encryption cipher selection unit 14A, and the encryption cipher selection rule table 15A of the communication device 10A is replaced with an encryption cipher selection rule table 15B.

[0247] In the second embodiment, the communication device 20 shown in FIG. 2 has the same configuration as the communication device 20A shown in FIG. 4, but is referred to as "communication device 20B" to distinguish it from the communication device 20A in the first embodiment.

[0248] In the second embodiment, the quality monitoring unit 13 monitors the transmission rates TRS1, TRS2 and the receiving rates TRS3, TRS4 over time, and generates time series data TRS1(t) of the transmission rate TRS1, time series data TRS2(t) of the transmission rate TRS2, time series data TRS3(t) of the receiving rate TRS3, and time series data TRS4(t) of the receiving rate TRS4 based on the transmission rates TRS1, TRS2 and the receiving rates TRS3, TRS4, ​​respectively.

[0249] The quality prediction unit 16 inquires about the communication quality from the quality monitoring unit 13, and predicts future communication quality based on the first communication quality (=time series data TRS1(t) to TRS4(t)) obtained from the quality monitoring unit 13 using a method described below.

[0250] In this case, the quality prediction unit 16 predicts future communication quality based on the time series data TRS1(t) to TRS4(t) generated by the quality monitoring unit 13, for example, by machine learning using a probabilistic neural network (PNN).

[0251] The future communication quality includes a future transmission rate TRS1_F, which is a future transmission rate predicted based on the time series data TRS1(t) of the transmission rate TRS1, a future transmission rate TRS2_F, which is a future transmission rate predicted based on the time series data TRS1(t) of the transmission rate TRS2, a future receiving rate TRS3_F, which is a future receiving rate predicted based on the time series data TRS3(t) of the receiving rate TRS3, and a future receiving rate TRS4_F, which is a future receiving rate predicted based on the time series data TRS4(t) of the receiving rate TRS4.

[0252] The cipher suite selection unit 14A queries the quality prediction unit 16 about the communication quality, and executes the above-mentioned cipher suite selection process based on the future communication quality obtained from the quality prediction unit 16, the cipher suite selection rule table 15, and the cipher suite quality table 30 (see FIG. 7). [Method for predicting future communication quality] This paper explains a method for predicting future communication quality through machine learning using a probabilistic neural network (PNN).

[0253] Fig. 22 is a flowchart for explaining a method for predicting future communication quality. Fig. 23 is a flowchart for explaining detailed operations of step S_PRS1 shown in Fig. 22. Fig. 24 and Fig. 25 are first and second schematic diagrams, respectively, used to explain a method for predicting future communication quality.

[0254] Referring to FIG. 22, when the operation of predicting future communication quality is started, the quality prediction unit 16 performs a learning process for executing a pattern matching-based prediction process using a PNN on the time series data TRS1(t) of the transmission rate TRS1 to obtain the learned data D_trained (step S_PRS1).

[0255] Then, the quality prediction unit 16 acquires a future value prediction dataset Dset1, a norm calculation dataset Dset2, and a label (correct answer data) dataset Dset_Label from the acquired trained data D_trained (step S_PRS2). The future value prediction dataset Dset1, the norm calculation dataset Dset2, and the label (correct answer data) dataset Dset_Label are respectively expressed by equations (1) to (3). The future value prediction dataset Dset1 includes the norm calculation dataset Dset2 and the label (correct answer data) dataset Dset_Label (see FIG. 24). In equation (1), n1 is a natural number.

[0256]

number

[0257]

number

[0258]

number

[0259] In the matrix of the above norm calculation data set Dset2, each row vector corresponds to a learning vector at time i.

[0260] After step S_PRS2, the quality prediction unit 16 uses the above data set (Equations (1) to (3)) to perform a learning process using, for example, a PNN, and acquires a learned model (for example, a learned model using a PNN) (step S_PRS3).

[0261] Here, the data of the transmission speed TRS1 at time i is D i If we write it as follows, the data D1s (= time series data TRS1(t)) is, for example, three consecutive time series data D1s={D i ,D i+1 ,Di+2}.

[0262] For convenience of explanation, the observation value series (time series data) of the transmission rate TRS1 after time t1 is set to c0, c1, c2, as shown in Fig. 25. In this case, the data D1s = {c0, c1, c2}.

[0263] After step S_PRS3, the quality prediction unit 16 calculates the norm (for example, Euclidean distance) D_norm={d0, d1, . . . , d n1-1} is calculated (step S_PRS4).

[0264] Then, the quality prediction unit 16 determines whether the calculated norm (for example, Euclidean distance) D_norm is equal to or smaller than the minimum value d min A row vector satisfying the following formula is detected, and a label (correct data) corresponding to the detected row vector is identified using the data set Dset_Label (step S_PRS5).

[0265] Subsequently, the quality prediction unit 16 calculates the minimum value d min The label (correct data) corresponding to the row vector having the following value is obtained as the predicted data value D_predict for the future time (step S_PRS6), and the predicted data value D_predict for the future time obtained is set as the future transmission rate TRS1_F, which is the future transmission rate of the transmission rate TRS1 (step S_PRS7).

[0266] Specifically, for example, in the case shown in FIG. 25, the norm d2 of the time series data D1s (={c0, c1, c2}) of the transmission rate TRS1 and the vector ({a2, a3, a4}) in the third row of the norm calculation data set Dset2 is the minimum value d minAssuming that the above equation is true, the quality prediction unit 16 identifies the label value a6 (the data in the third row of the label (correct data) dataset Dset_Label) corresponding to the vector ({a2, a3, a4}) in the third row of the norm calculation dataset Dset2 as the predicted data value D_predict for a future time (future time i+4 if the current time is i).

[0267] After step S_PRS7, the method for predicting a future transmission rate TRS1_F ends.

[0268] Next, a detailed operation of step S_PRS1 in Fig. 22 will be described. Referring to Fig. 23, the quality prediction unit 16 acquires k1 observation value series of the transmission rate TRS1 from time i (corresponding to time t0 in Fig. 24) and acquires a learning vector (step S_PRS1-1).

[0269] Then, the quality predicting unit 16 sets the future value data (correct answer data) corresponding to the learning vector as the observed value at time i+k2 in the label associated with the learning vector (step S_PRS1-2).

[0270] For example, in the case of FIG. 24, i=0, k1=3, and the time series data D1s of the transmission rate TRS1 is expressed as follows: D1s={D i ,D i+1 ,D i+2} ={a i ,a i+1 ,a i+2}={a0,a1,a2} The above data D1s is used as a learning vector.

[0271] In the case of FIG. 24, since k2=4, the label to be associated with the learning vector is set to the observed value (=value of transmission rate TRS1) a i+4 Let's say.

[0272] The target data for the above processing in the case of FIG. 24 is data included in the section of window Win1 in FIG. 24 (the section from time t0 to tw).

[0273] After step S_PRS1-2, the quality prediction unit 16 then advances the time (time step) by 1. That is, the quality prediction unit 16 shifts the section of window Win1 in Fig. 24 by one time step (= the time corresponding to one data sampling) toward the time axis direction Dir1, and sets the shifted section of window Win1 as the data to be processed (step S_PRS1-3).

[0274] Then, similar to process (1) (consisting of steps S_PRS1-1 and S_PRS1-2), the quality prediction unit 16 acquires k1 time series observation value series (time series data of transmission speed TRS1) from time i+1 and acquires a learning vector (step S_PRS1-4).

[0275] Thereafter, the quality prediction unit 16 sets the future value data (correct answer data) corresponding to the learning vector as the observed value (transfer rate TRS2_1) at time i+k2+1 in the label associated with the learning vector (step S_PRS1-5).

[0276] For example, in the case of FIG. 24, i=0, k1=3, and the time series data D1s of the transmission rate TRS1 is expressed as follows: D1s={D i+1 ,D i+2 ,D i+3} ={a i+1 ,a i+2 ,a i+3}={a1,a2,a3} The quality prediction unit 16 uses the above data D1s as a learning vector.

[0277] In the case of FIG. 24, since k2=4, the label to be associated with the learning vector is the observed value (transfer rate TRS2_1)a at time i+k2+1 (=i+4). i+5 Let's say.

[0278] After step S_PRS1-5, at time i+n1-1 (n1: natural number), the quality prediction unit 16 acquires k1 time series observation value series (time series data of transmission speed TRS1) from time i+n1-1, as in process (1) (=step S_PRS1-1 and step S_PRS1-2), and acquires a learning vector.

[0279] Furthermore, the future value data (correct data) corresponding to the learning vector is set as the observed value (value of transmission rate TRS1) at time i+n1-1+k2 in the label associated with the learning vector (step S_PRS1-6).

[0280] For example, in the case of FIG. 15, i=0, k1=3, and the time series data D1s of the transmission rate TRS1 is expressed as follows: D1s={D i+n1-1 ,D i+n1 ,D i+n1+1} ={a i+n1-1 ,a i+n1 ,a i+n1+1}={a n1-1 ,a n1 ,a n1+1} The quality prediction unit 16 uses the above data D1s as a learning vector.

[0281] In the case of FIG. 24, since k2=4, the quality prediction unit 16 sets the label to be associated with the learning vector as the observed value (value of transmission rate TRS1) a at time i+n1-1+k2 (=i+n1+3). n1+3 Let's say.

[0282] Then, when step S_PRS1-6 is completed, the detailed operation of step S_PRS1 in FIG. 23 is completed.

[0283] 24 and 25, the first step consists of steps S_PRS1 to S_PRS3 in FIG. 22, and the second step consists of steps S_PRS4 to S_PRS7 in FIG.

[0284] 24, the quality prediction unit 16 repeatedly acquires learning vectors from the time series data TRS1(t) of the transmission speed TRS1 and sets future values ​​corresponding to the acquired learning vectors as observed values ​​at future times in the labels corresponding to the learning vectors (see step S_PRS1 (= the flowchart shown in FIG. 23)). As a result, the labels of the data set Dset_Label shown in FIG. 24 are assigned future values ​​a4, a5, a6,...a corresponding to the learning vectors acquired from the time series data TRS1(t) of the transmission speed TRS1. n1+3 is stored.

[0285] Then, in the second step shown in Figure 25, the quality prediction unit 16 calculates the norm D_norm = {d0, d1, d2} between each row vector of the norm calculation dataset Dset2 obtained from the learned data D_trained and the data D1s (= {c0, c1, c2}).

[0286] Thereafter, the quality prediction unit 16 determines whether the calculated norm D_norm={d0, d1, d2} is the minimum value d min The row vector is detected, and the label (correct data) corresponding to the detected row vector is identified using the data set Dset_Label. The minimum value d of the norm D_norm is min The label (correct data) corresponding to the row vector is obtained as the predicted data value D_predict (=future transmission speed TRS1_F) at a future time.

[0287] For example, in FIG. 25, the quality prediction unit 16 determines whether the calculated norm D_norm={d0, d1, d2} is equal to or smaller than the minimum value d min When the row vector {a2, a3, a4} is detected as a row vector such that: a2, a3, a4}, the label a6 corresponding to the row vector {a2, a3, a4} is acquired as the predicted data value D_predict (=future transmission rate TRS1_F) at a future time.

[0288] Here, the calculated norm D_norm={d0,d1,d2} is the minimum value d minThe row vector {a2, a3, a4} given by the following equation is detected from the time series data TRS1(t) of the transmission rate TRS1 in the first step shown in FIG.

[0289] Then, the norm {d0,d1,d2} (=Euclidean distance) between the row vector {a2,a3,a4} and the data D1s (={c0,c1,c2}) is the minimum value d min Therefore, the row vector {a2, a3, a4} has the smallest Euclidean distance with the data D1s (= {c0, c1, c2}). That is, the row vectors {a0, a1, a2}, {a1, a2, a3}, {a2, a3, a4}, , {a n1-1 ,a n1 ,a n1+1}, the row vector {a2, a3, a4} is most similar to the data D1s (= {c0, c1, c2}).

[0290] Therefore, the execution of steps S_PRS4 and S_PRS5 shown in FIG. 22 by the quality prediction unit 16 corresponds to detecting, from among the multiple row vectors acquired by the quality prediction unit 16 from the norm calculation dataset Dset2, the row vector {a2, a3, a4} (= a row vector consisting of time series data earlier than the time series data D1s (= {c0, c1, c2})) that is most similar to the time series data D1s of the transmission rate TRS1 monitored by the quality monitoring unit 13, and specifying, using the dataset Dset_Label, the label (correct data) = a6 (= a transmission rate TRS1 later than the row vector {a2, a3, a4}) corresponding to the detected row vector {a2, a3, a4}.

[0291] After the quality prediction unit 16 identifies the label (correct data) = a6 in step S_PRS5, executing steps S_PRS6 and S_PRS7 corresponds to applying the correspondence between the row vector {a2, a3, a4} and the label (correct data) = a6 to the data D1s (= {c0, c1, c2}) to predict the future transmission speed TRS1_F at a time later than the data D1s (= {c0, c1, c2}).

[0292] Fig. 26 is a conceptual diagram showing the operation of identifying correct data in step S_PRS5 shown in Fig. 22. Referring to Fig. 26, in step S_PRS5 shown in Fig. 22, the quality prediction unit 16 sequentially executes (a), (b), and (c) in Fig. 26 to identify the label (correct data) = a6 corresponding to the row vector {a2, a3, a4}.

[0293] If multiple norms are the smallest, any one of the multiple norms is set as the smallest norm.

[0294] The quality prediction unit 16 predicts a future transmission rate TRS1_F, which is the future transfer rate of the transmission rate TRS1, by repeatedly executing the flowchart shown in Fig. 22 (including the flowchart shown in Fig. 23) while shifting the window Win1 toward the time axis direction Dir1 during the section t1 to t2 shown in Fig. 25. As a result, the predicted future transmission rate TRS1_F (time series data of the future transmission rate) is obtained as shown in Fig. 25 (see the dotted line in Fig. 25).

[0295] When the quality prediction unit 16 finishes predicting the future transmission rate TRS1_F of the transmission rate TRS1 by repeatedly executing the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23), it repeatedly executes the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23) to predict the future transmission rate TRS2_F, which is the future transmission rate of the transmission rate TRS2, it repeatedly executes the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23) to predict the future receiving rate TRS3_F, which is the future receiving rate of the receiving rate TRS3, and it repeatedly executes the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23) to predict the future receiving rate TRS4_F, which is the future receiving rate of the receiving rate TRS4.

[0296] Then, the quality predictor 16 holds the predicted future transmission rate TRS1_F, future transmission rate TRS2_F, future receiving rate TRS3_F, and future receiving rate TRS4_F.

[0297] Thereafter, when the quality predictor 16 receives an inquiry about communication quality from the encryption selector 14A, it notifies the encryption selector 14A of the future transmission rate TRS1_F, the future transmission rate TRS2_F, the future reception rate TRS3_F, and the future reception rate TRS4_F.

[0298] Each of the future transmission rate TRS1_F, the future transmission rate TRS2_F, the future receiving rate TRS3_F, and the future receiving rate TRS4_F is time-series data, since it is made up of a curve in which the future transmission rate or receiving rate changes over time.

[0299] Fig. 27 is a flowchart for explaining the operation of the communication device 10 B. The flowchart shown in Fig. 27 is the same as the flowchart shown in Fig. 17, except that step S8 of the flowchart shown in Fig. 17 is replaced with steps S8A and S8B.

[0300] FIG. 28 is a flowchart for explaining the detailed operation of step S8B shown in FIG.

[0301] 29 is a schematic diagram of the encryption selection rule table 15B used in the flowchart shown in Fig. 28. The encryption selection rule table 15B shown in Fig. 29 is a table in which rules 1 to N of the encryption selection rule table 15 shown in Fig. 6 are combined with a future transmission rate TRS1_F from the application 11 to the encryption / decryption unit 12 and encryption rates C1 to C2 of the encryption processing quality table shown in Fig. 7. N-1 That is, the cipher selection rule table 15B shown in Fig. 29 is an cipher selection rule table in which the "transmission rate TRS1" in the cipher selection rule table 15A (see Fig. 20), which is a generalization of the cipher selection rule table 15-1 shown in Fig. 8(a), is changed to a "future transmission rate TRS1_F."

[0302] 27, when the operation of communication device 10B starts, the above-mentioned steps S1 to S5, "YES" in step S6, and step S7 are executed sequentially. In this case, in step S5, communication device 10B executes communication with communication device 20B using application 11. That is, communication device 10B executes only a transmission process of transmitting data to communication device 20B, or transmits and receives data to and from communication device 20B.

[0303] Then, after step S7, the quality prediction unit 16 acquires the communication quality (= transmission rate TRS1) from the quality monitoring unit 13, and predicts the future communication quality based on the acquired communication quality (= transmission rate TRS1) using the above-mentioned "method for predicting future communication quality" (= flowchart shown in Figure 22 (including the flowchart shown in Figure 23)) (step S8A).

[0304] Thereafter, the cipher selection unit 14A inquires about the communication quality from the quality prediction unit 16, and selects a cipher suite based on the future communication quality obtained from the quality prediction unit 16, the cipher selection rule table 15B (see FIG. 29), and the cryptographic processing quality table 30 (see FIG. 7) (step S8B).

[0305] After step S8B, the above-described steps S9 to S12 are executed in sequence, and after step S12, the operation of communication device 10B proceeds to step S6. Then, while communication device 10B is operating, the above-described steps S6, S7, S8A, S8B, S9 to S12 are repeatedly executed.

[0306] In the flowchart shown in Figure 27, when the cipher suite of the encryption / decryption unit 12 is changed in step S10, the encryption / decryption unit 12 encrypts data using the changed cipher suite in step S12, and transmits the encrypted data to communication device 20B via communication IF1, or transmits and receives the encrypted data to and from communication device 20B.

[0307] The cipher suite in the encryption / decryption unit 12 is the cipher suite selected based on the future communication quality (=future transmission rate TRS1_F).

[0308] Therefore, the cipher suite in the encryption / decryption unit 12 can be changed to an appropriate cipher suite before the communication quality deteriorates.

[0309] The rest of the description of the flowchart shown in FIG. 27 is the same as the description of the flowchart shown in FIG.

[0310] The flowchart shown in Fig. 28 will be described. The flowchart shown in Fig. 28 is the same as the flowchart shown in Fig. 19, except that step S83 in the flowchart shown in Fig. 19 is replaced with step S83A.

[0311] Referring to Fig. 28, after step S8A in Fig. 27, steps S81 and S82 described above are executed in sequence. In this case, in step S82, the encryption key selection unit 14A selects rule n from the encryption key selection rule table 15B (see Fig. 29).

[0312] After step S82, the cipher selection unit 14A determines whether the future transmission rate TRS1_F satisfies the rule n (step S83A). In this case, the cipher selection unit 14A determines whether the future transmission rate TRS1_F satisfies the encryption rate C of the cipher suite n. n Determine whether the future transmission rate TRS1_F is smaller than the encryption rate C of cipher suite n. n If it is determined that the future sending rate TRS1_F satisfies rule n, it is determined that the future sending rate TRS1_F satisfies the encryption rate C of cipher suite n. n If it is determined that the future transmission rate TRS1_F is equal to or greater than this, it is determined that the future transmission rate TRS1_F does not satisfy the rule n.

[0313] In step S83A, when it is determined that the future transmission rate TRS1_F does not satisfy rule n, the above-mentioned step S84 is executed, and after step S84, the detailed operation of step S8B proceeds to step S82, and steps S82, S83A, and S84 are repeatedly executed until it is determined in step S83A that the future transmission rate TRS1_F satisfies rule n.

[0314] If it is determined in step S83A that the future transmission rate TRS1_F satisfies the rule n, the cipher suite selection unit 14A refers to the cipher suite selection rule table 15B and selects the cipher suite n associated with the rule n that was used when it was determined that the future transmission rate TRS1_F satisfies the rule n (step S85). After that, the operation of the communication device 10B proceeds to step S9 in FIG. 27.

[0315] In the flowchart shown in Figure 28, when the encryption selection rule table 15B shown in Figure 29 is used, when step S82 is executed after step S81, the encryption selection unit 14A selects rule 1 associated with priority 1 in the encryption selection rule table 15B in step S82, and determines whether the future transmission rate TRS1_F satisfies rule 1 in step S83A.

[0316] When it is determined in step S83A that the future transmission rate TRS1_F satisfies rule 1, the cipher suite selection unit 14A selects cipher suite 1 associated with rule 1 with reference to the cipher suite selection rule table 15B in step S85.

[0317] On the other hand, when the cipher selection unit 14A determines in step S83A that the future transmission rate TRS1_F does not satisfy rule 1, the cipher selection unit 14A sets n=1+1=2 in step S84. Thereafter, in step S82, the cipher selection unit 14A selects rule 2 associated with priority 2 in the cipher selection rule table 15B, and determines in step S83A whether the future transmission rate TRS1_F satisfies rule 2.

[0318] When it is determined in step S83A that the future transmission rate TRS1_F satisfies rule 2, the cipher suite selection unit 14A selects cipher suite 2 associated with rule 2 with reference to the cipher suite selection rule table 15B in step S85.

[0319] On the other hand, when the encryption selection unit 14A determines in step S83A that the future transmission rate TRS1_F does not satisfy rule 2, it sets n=2+1=3 in step S84. After that, the above-mentioned operations are repeatedly executed.

[0320] Then, when the encryption selection unit 14A determines in step S83A that the future transmission rate TRS1_F does not satisfy rule N-2, it sets n=N-2+1=N-1 in step S84, and then selects rule N-1 associated with priority N-1 in the encryption selection rule table 15B in step S82, and determines in step S83A whether the future transmission rate TRS1_F satisfies rule N-1.

[0321] When the cipher suite selection unit 14A determines in step S83A that the future transmission rate TRS1_F satisfies the rule N-1, in step S85, it refers to the cipher suite selection rule table 15B and selects the cipher suite N-1 associated with the rule N-1.

[0322] On the other hand, when the cipher selection unit 14A determines in step S83A that the future transmission rate TRS1_F does not satisfy the rule N-1, the cipher selection unit 14A sets n=N-1+1=N in step S84.

[0323] Thereafter, in step S82, the cipher selection unit 14A selects rule N associated with priority N in the cipher selection rule table 15B, and in step S83A determines whether the future transmission rate TRS1_F satisfies rule N. In this case, since no specific rule is set in rule N, the cipher selection unit 14A determines in step S83A that the future transmission rate TRS1_F satisfies rule N.

[0324] Then, the cipher suite selection unit 14A selects the cipher suite N associated with the rule N in step S85.

[0325] In this way, by executing the flowchart shown in Figure 28, the cipher selection unit 14A uses the future communication quality (future transmission rate TRS1_F) to evaluate whether or not the future communication quality (future transmission rate TRS1_F) satisfies the rule from the highest priority rule (rule 1 associated with priority 1) in the cipher selection rule table 15B, and selects the cipher suite corresponding to the rule when it is first determined that the future communication quality (future transmission rate TRS1_F) satisfies the rule.

[0326] In the cipher selection rule table 15B, rules 1 to N-1 respectively indicate that the future transfer rate TRS1_F is equal to the encryption rates C1 to C2 of the cipher suites 1 to N-1. N-1 The reason for the "smaller than" is the same as that explained in the above-mentioned cipher selection rule table 15-1.

[0327] In addition, in the flowchart shown in Figure 28, instead of cipher selection rule table 15B, an "cipher selection rule table similar to cipher selection rule table 15B" is used, in which any of cipher selection rule tables 15-2 to 15-8 is generalized as "cipher selection rule table 15A" and the "transmission rates TRS1, TRS2 and reception rates TRS3, TRS4" in the generalized cipher selection rule table are changed to "future transmission rates TRS1_F, TRS2_F and future reception rates TRS3_F, TRS4_F."

[0328] Therefore, when communication device 10B only performs a transmission process to transmit data to communication device 20B, and when data is transmitted and received between communication device 10B and communication device 20B, the cipher selection unit 14A can select a cipher suite based on the future communication quality predicted by the quality prediction unit 16 (future transmission rates TRS1_F, TRS2_F and future reception rates TRS3_F, TRS4_F).

[0329] According to the flowchart shown in FIG. 27 (including the flowchart shown in FIG. 28), the cipher suite selection unit 14A selects a cipher suite so that the future communication quality (future transfer rate TRS1_F) satisfies the rules in the cipher suite selection rule table 15B (step S8B in FIG. 27 (= flowchart shown in FIG. 28)), and therefore can select a cipher suite so as not to impair the future communication quality (future transfer rate TRS1_F).

[0330] As a result, the cipher suite can be changed to an appropriate one before the communication quality (transmission speeds TRS1 and TRS2 and reception speeds TRS3 and TRS4) deteriorates.

[0331] In the second embodiment, the operation of the communication device 10B may be realized by software. In this case, the communication device 10B includes a CPU, a ROM, and a RAM. The ROM stores a program Prog_B consisting of the steps of the flowchart shown in FIG. 27 (including the flowchart shown in FIG. 28).

[0332] The CPU reads the program Prog_B from the ROM, executes the read program Prog_B, predicts the future communication quality (= future transmission rate TRS1_F) from the monitored communication quality (= transmission rate TRS1), and selects a cipher suite based on the predicted future communication quality (future transmission rate TRS1_F). The RAM temporarily stores the communication quality (transmission rate TRS1) and the future communication quality (future transmission rate TRS1_F).

[0333] Furthermore, the program Prog_B may be distributed by being recorded on a recording medium such as a CD or DVD. When the recording medium on which the program Prog_B is recorded is attached to a computer, the computer reads and executes the program Prog_B from the recording medium, predicts future communication quality (= future transmission rate TRS1_F) from the monitored communication quality (= transmission rate TRS1), and selects a cipher suite based on the predicted future communication quality (= future transmission rate TRS1_F).

[0334] Therefore, the recording medium on which the program Prog_B is recorded is a computer-readable recording medium.

[0335] In addition, when the operation of communication device 10B is realized by the CPU executing program Prog_B, the communication quality is determined by generalizing any one of cipher selection rule tables 15-2 to 15-8 into "cipher selection rule table 15A" and changing the "transmission rates TRS1, TRS2 and reception rates TRS3, TRS4" of the generalized cipher selection rule table to "future transmission rates TRS1_F, TRS2_F and future reception rates TRS3_F, TRS4_F" stored in an "encryption selection rule table similar to cipher selection rule table 15B."

[0336] The rest of the description in the second embodiment is the same as the description in the first embodiment.

[0337] [Embodiment 3] Fig. 30 is a schematic diagram of a third embodiment of communication device 10 shown in Fig. 2. Referring to Fig. 30, communication device 10C in the third embodiment is the same as communication device 10A shown in Fig. 3 except that application 11 of communication device 10A shown in Fig. 3 is changed to application 11A, encryption / decryption unit 12 of communication device 10A shown in Fig. 3 is changed to S (S is an integer equal to or greater than 2) encryption / decryption units 12-1 to 12-S, quality monitoring unit 13 of communication device 10A shown in Fig. 3 is changed to quality monitoring unit 13A, encryption selection unit 14 of communication device 10A shown in Fig. 3 is changed to encryption selection unit 14B, and encryption selection rule table 15 of communication device 10A shown in Fig. 3 is changed to encryption selection rule table 15C.

[0338] In the communication device 10C, there are S streams #1 to #S. The application 11A outputs S pieces of data 1 to S to S encryption / decryption units 12-1 to 12-S via the S streams #1 to #S, respectively.

[0339] Note that S represents the total number of data, the total number of streams, the total number of encryption / decryption units, the total number of communication IFs 1, the transmission rates TRS1 and TRS2, and the reception rates TRS3 and TRS4, ​​and is an integer equal to or greater than 2. The S pieces of data are, for example, video and sensor information.

[0340] When communication device 10C executes only a transmission process for transmitting data to communication device 20C, encryption / decryption unit 12-1 receives data 1 from application 11A via stream #1, encrypts the received data 1 using cipher suite CRY_1 selected by cipher selection unit 14B, and generates encrypted data CRY_D_1. Then, encryption / decryption unit 12-1 transmits the encrypted data CRY_D_1 to communication device 20C via communication IF1_1.

[0341] Furthermore, when the communication device 10C executes only a transmission process for transmitting data to the communication device 20C, the encryption / decryption unit 12-2 receives data 2 from the application 11A via stream #2, encrypts the received data 2 using the cipher suite CRY_2 selected by the cipher selection unit 14B, and generates encrypted data CRY_D_2. Then, the encryption / decryption unit 12-2 transmits the encrypted data CRY_D_2 to the communication device 20C via communication IF1_2.

[0342] Similarly, the encryption / decryption unit 12-S receives data S from the application 11A via stream #S, encrypts the received data S using the cipher suite CRY_S selected by the cipher selection unit 14B, and generates encrypted data CRY_D_S. The encryption / decryption unit 12-S then transmits the encrypted data CRY_D_S to the communication device 20C via the communication IF1_S.

[0343] Furthermore, when the communication device 10C transmits and receives data to and from the communication device 20C, the encryption / decryption unit 12-1 receives data 1 from the application 11A via stream #1, encrypts the received data 1 using the cipher suite CRY_1 selected by the cipher selection unit 14B to generate encrypted data CRY_D_1, and transmits the generated encrypted data CRY_D_1 to the communication device 20C via communication IF1_1. Thereafter, the encryption / decryption unit 12-1 receives the encrypted data CRY_D_1 from the communication device 20C via communication IF1_1, decrypts the received encrypted data CRY_D_1 using the cipher suite CRY_1, and outputs data 1 to the application 11A via stream #1.

[0344] When the communication device 10C transmits and receives data to and from the communication device 20C, the encryption / decryption unit 12-2 receives data 2 from the application 11A via stream #2, encrypts the received data 2 using the cipher suite CRY_2 selected by the cipher selection unit 14B to generate encrypted data CRY_D_2, and transmits the generated encrypted data CRY_D_2 to the communication device 20C via communication IF1_2. Thereafter, the encryption / decryption unit 12-2 receives the encrypted data CRY_D_2 from the communication device 20C via communication IF1_2, decrypts the received encrypted data CRY_D_2 using the cipher suite CRY_2, and outputs data 2 to the application 11A via stream #2.

[0345] Similarly, when communication device 10C transmits and receives data to and from communication device 20C, encryption / decryption unit 12-S receives data S from application 11A via stream #S, encrypts the received data S using the cipher suite CRY_S selected by the cipher selection unit 14B to generate encrypted data CRY_D_S, and transmits the generated encrypted data CRY_D_S to communication device 20C via communication IF1_S. Thereafter, encryption / decryption unit 12-S receives encrypted data CRY_D_S from communication device 20C via communication IF1_S, decrypts the received encrypted data CRY_D_S using the cipher suite CRY_S, and outputs data S to application 11A via stream #S.

[0346] The quality monitoring unit 13A monitors S transmission rates TRS1_1 to TRS1_S of data 1 to S from the application 11A to the encryption / decryption units 12-1 to 12-S, respectively; S transmission rates TRS2_1 to TRS2_S of encrypted data CRY_D_1 to CRY_D_S from the encryption / decryption units 12-1 to 12-S to the communication IF1_1 to communication IF1_S, respectively; S reception rates TRS3_1 to TRS3_S when the encryption / decryption units 12-1 to 12-S receive encrypted data CRY_D_1 to CRY_D_S from the communication IF1_1 to communication IF1_S, respectively; and S reception rates TRS4_1 to TRS4_S when the application 11A receives data 1 to data S from the encryption / decryption units 12-1 to 12-S, respectively.

[0347] The cipher selection unit 14B inquires about the communication quality from the quality monitoring unit 13A, and selects S cipher suites CRY_1 to CRY_S based on the S communication qualities (= S transmission rates TRS1_1 to TRS1_S, S transmission rates TRS2_1 to TRS2_S, S reception rates TRS3_1 to TRS3_S, and S reception rates TRS4_1 to TRS4_S) obtained from the quality monitoring unit 13A, the cipher selection rule table 15C, and the cryptographic processing quality table (= see Figure 7).

[0348] Then, the cipher suite selection unit 14B transmits the selected S cipher suites CRY_1 to CRY_S to the S encryption / decryption units 12-1 to 12-S, respectively.

[0349] Fig. 31 is a schematic diagram of a third embodiment of communication device 20 shown in Fig. 2. Referring to Fig. 31, communication device 20C according to the third embodiment includes S encryption / decryption units 21-1 to 21-S, and application 22A.

[0350] In the communication device 20C, there are S streams #1 to #S. Cipher suites are set in the S encryption / decryption units 21-1 to 21-S by the process of establishing the encrypted communication path described above (see FIG. 18).

[0351] When the communication device 10C executes only a transmission process to transmit data to the communication device 20C, the encryption / decryption unit 21-1 receives encrypted data from the communication device 10C via the communication IF2_1, decrypts the received encrypted data using the encryption suite CRY_1, and outputs the decrypted data 1 to the application 22A via the stream #1.

[0352] In addition, when the communication device 10C executes only a transmission process to transmit data to the communication device 20C, the encryption / decryption unit 21-2 receives encrypted data from the communication device 10C via the communication IF2_2, decrypts the received encrypted data using the encryption suite CRY_2, and outputs the decrypted data 2 to the application 22A via the stream #2.

[0353] Similarly, when communication device 10C executes only the transmission process of transmitting data to communication device 20C, encryption / decryption unit 21-S receives encrypted data from communication device 10C via communication IF2_S, decrypts the received encrypted data using cryptographic suite CRY_S, and outputs the decrypted data S to application 22A via stream #S.

[0354] In addition, when the communication device 10C transmits and receives data to and from the communication device 20C, the encryption / decryption unit 21-1 receives encrypted data from the communication device 10C via the communication IF2_1, decrypts the received encrypted data using the cipher suite CRY_1 to output data 1 to the application 22A via stream #1, and also encrypts the data 1 received from the application 22A using the cipher suite CRY_1 to the communication device 10C via the communication IF2_1.

[0355] When the communication device 10C transmits and receives data to and from the communication device 20C, the encryption / decryption unit 21-2 receives encrypted data from the communication device 10C via the communication IF2_2, decrypts the received encrypted data using the cipher suite CRY_2 to output data 2 to the application 22A via stream #2, and also encrypts the data 2 received from the application 22A using the cipher suite CRY_2 to the communication device 10C via the communication IF2_2.

[0356] Similarly, when communication device 10C transmits and receives data to and from communication device 20C, encryption / decryption unit 21-S receives encrypted data from communication device 10C via communication IF2_S, decrypts the received encrypted data using cryptographic suite CRY_S to output data S to application 22A via stream #S, and also encrypts data S received from application 22A using cryptographic suite CRY_S to communication device 10C via communication IF2_S.

[0357] When the communication device 10C executes only the transmission process of transmitting data to the communication device 20C, the application 22A receives the data 1 to data S from the encryption / decryption units 21-1 to 21-S via the streams #1 to #S, respectively.

[0358] Furthermore, when communication device 10C transmits and receives data to and from communication device 20C, application 22A receives data 1 to data S from encryption / decryption units 21-1 to 21-S, respectively, and outputs data 1 to data S to encryption / decryption units 21-1 to 21-S, respectively.

[0359] Fig. 32 is a schematic diagram of the encryption key selection rule table 15C shown in Fig. 30. Referring to Fig. 32, the encryption key selection rule table 15C includes streams #1 to #S and element tables C_1 to C_S. The element tables C_1 to C_S are associated with the streams #1 to #S, respectively.

[0360] Each of the factor tables C_1 to C_S has the same configuration as the encryption code selection rule table 15A shown in FIG.

[0361] The operation of the cipher suite selection unit 14B to select S cipher suites CRY_1 to CRY_S will be specifically described.

[0362] When selecting cipher suite CRY_1 in the encryption / decryption unit 12-1, the cipher selection unit 14B selects the factor table C_1 (see FIG. 32) of the cipher selection rule table 15C. Then, based on the transmission rate TRS1_1, the factor table C_1 (see FIG. 32), and the encryption processing quality table (= the encryption processing quality table shown in FIG. 7), the cipher selection unit 14B determines whether the transmission rate TRS1_1 satisfies rule 1 associated with priority 1 in the factor table C_1. More specifically, when the transmission rate TRS1_1 is smaller than the encryption rate C1 of cipher suite 1, the cipher selection unit 14B determines that the transmission rate TRS1_1 satisfies rule 1 in the factor table C_1, and when the transmission rate TRS1_1 is equal to or greater than the encryption rate C1 of cipher suite 1, the cipher selection unit 14B determines that the transmission rate TRS1_1 does not satisfy rule 1 in the factor table C_1.

[0363] Then, when the cipher suite selection unit 14B determines that the transmission rate TRS1_1 satisfies rule 1 of the factor table C_1, it selects cipher suite 1 associated with rule 1 as cipher suite CRY_1.

[0364] On the other hand, when the cipher selection unit 14B determines that the transmission rate TRS1_1 does not satisfy rule 1 of the factor table C_1, the cipher selection unit 14B determines whether or not the transmission rate TRS1_1 satisfies rule 2 associated with priority 2 of the factor table C_1, based on the transmission rate TRS1_1, the factor table C_1 (see FIG. 32), and the encryption processing quality table (= the encryption processing quality table shown in FIG. 7). More specifically, when the transmission rate TRS1_1 is smaller than the encryption rate C2 of the cipher suite 2, the cipher selection unit 14B determines that the transmission rate TRS1_1 satisfies rule 2 of the factor table C_1, and when the transmission rate TRS1_1 is equal to or greater than the encryption rate C2 of the cipher suite 2, the cipher selection unit 14B determines that the transmission rate TRS1_1 does not satisfy rule 2 of the factor table C_1.

[0365] Then, when the cipher suite selection unit 14B determines that the transmission rate TRS1_1 satisfies rule 2 of the factor table C_1, it selects cipher suite 2 associated with rule 2 as cipher suite CRY_1.

[0366] On the other hand, when the encryption selection unit 14B determines that the transmission rate TRS1_1 does not satisfy rule 2 of the element table C_1, it similarly determines, based on the transmission rate TRS1_1, the element table C_1 (see Figure 32), and the encryption processing quality table (= the encryption processing quality table shown in Figure 7), whether the transmission rate TRS1_1 satisfies rules 3 to N-2, respectively, associated with priorities 3 to N-2 in the element table C_1.

[0367] Then, when the encryption selection unit 14B determines that the transmission rate TRS1_1 does not satisfy rule 3 to rule N-2 associated with priority 3 to priority N-2 in the element table C_1, it determines whether the transmission rate TRS1_1 satisfies rule N-1 associated with priority N-1 in the element table C_1 based on the transmission rate TRS1_1, the element table C_1 (see Figure 32), and the encryption processing quality table (= the encryption processing quality table shown in Figure 7).

[0368] Then, when the cipher suite selection unit 14B determines that the transmission rate TRS1_1 satisfies the rule N-1 of the element table C_1 (i.e., the transmission rate TRS1_1 satisfies the encryption rate C of the cipher suite N-1), N-1 is smaller than the rule N-1), the cipher suite N-1 associated with the rule N-1 is selected as the cipher suite CRY_1.

[0369] On the other hand, when the encryption selection unit 14B determines that the transmission rate TRS1_1 does not satisfy the rule N-1 in the element table C_1, it determines whether the transmission rate TRS1_1 satisfies the rule N associated with the priority N in the element table C_1 based on the transmission rate TRS1_1, the element table C_1 (see Figure 32), and the encryption processing quality table (= the encryption processing quality table shown in Figure 7).

[0370] In this case, since no specific rule is set for rule N, the cipher suite selection unit 14B determines that the transmission rate TRS1_1 satisfies rule N in the element table C_1, and selects the cipher suite N associated with rule N as the cipher suite CRY_1.

[0371] When selecting cipher suite CRY_2 in encryption / decryption unit 12-2 to cipher suite CRY_S in encryption / decryption unit 12-S, cipher selection unit 14B refers to element tables C_2 to C_S, respectively, and performs the same operation as the operation of selecting cipher suite CRY_1 in encryption / decryption unit 12-1 described above, thereby selecting cipher suite CRY_2 in encryption / decryption unit 12-2 to cipher suite CRY_S in encryption / decryption unit 12-S.

[0372] When the encryption selection unit 14B selects the encryption suite CRY_1 to CRY_S using the above-mentioned method, it determines whether the encryption suite CRY_s (where s is 1 to S) is the same as the encryption suite used in the encryption / decryption unit 12-s, and if the encryption suite CRY_s is different from the encryption suite used in the encryption / decryption unit 12-s, it changes the encryption suite used in the encryption / decryption unit 12-s to the encryption suite CRY_s, and if the encryption suite CRY_s is the same as the encryption suite used in the encryption / decryption unit 12-s, it performs an encryption suite selection process for all of the encryption / decryption units 12-1 to 12-S without changing the encryption suite used in the encryption / decryption unit 12-s.

[0373] Fig. 33 is a flowchart for explaining the operation of the communication device 10C. The flowchart shown in Fig. 33 is the same as the flowchart shown in Fig. 17, except that steps S6 to S12 of the flowchart shown in Fig. 17 are replaced with steps S21 to S30.

[0374] In addition, the S encryption / decryption units 12-1 to 12-S of the communication device 10C are set by the operator of the communication device 10C with S cipher suites that the S encryption / decryption units 12-1 to 12-S will use initially.

[0375] Referring to FIG. 33, when the operation of the communication device 10C starts, the above-described steps S1 to S5 are sequentially executed.

[0376] In this case, in step S1, rules 1 to N are set by the operator of the communication device 10C or the application 11A in each of the S element tables C_1 to C_S of the cipher selection rule table 15C.

[0377] In step S3, an encrypted communication path is established.

[0378] Furthermore, in step S4, the cipher selector 14B sets cipher change prohibition periods PHB_1 to PHB_S for the S streams, respectively.

[0379] Furthermore, in step S5, the communication device 10C uses the application 11A to communicate with the communication device 20C (only a transmission process for transmitting data from the communication device 10A to the communication device 20C, or transmission and reception of data between the communication device 10C and the communication device 20C).

[0380] After step S5, the encryption selection unit 14B sets s=1 (step S21), where s is an argument indicating each stream.

[0381] After step S21, the cipher selection unit 14B determines whether the cipher change prohibition period PHB_s of the target stream s has ended (step S22).

[0382] Then, in step S22, when it is determined that the cipher change prohibition period PHB_s for the target stream s has ended, the cipher selection unit 14B outputs an end signal SG_end_s indicating that the cipher change prohibition period PHB_s for the target stream s has ended to the quality monitoring unit 13A.

[0383] When the quality monitor 13A receives the end signal SG_end_s from the encryption selector 14B, it monitors the processing and communication quality of the target stream s in response to the end signal SG_end_s (step S23).

[0384] Then, the cipher selection unit 14B inquires of the quality monitoring unit 13A about the communication quality of the target stream s, and selects a cipher suite based on the communication quality (= transmission rates TRS1_s, TRS2_s and reception rates TRS3_s, TRS4_s) obtained from the quality monitoring unit 13A, the cipher selection rule table 15C (see Figure 32), and the encryption processing quality table (see Figure 7) (step S24).

[0385] Thereafter, the cipher suite selection unit 14B determines whether the cipher suite used by the cipher / selection unit 12-s for the target stream s is different from the selected cipher suite (step S25).

[0386] If it is determined in step S25 that the cipher suite used by the encryption / selection unit 12-s for the target stream s is not different from (i.e., the same as) the selected cipher suite, the operation of the communication device 10C proceeds to step S23.

[0387] On the other hand, if it is determined in step S25 that the cipher suite used by the encryptor / selector 12-s of the target stream s is different from the selected cipher suite, the cipher selector 14B notifies the encryptor / decryptor 12-s of the target stream s of the selected cipher suite and changes the cipher suite of the encryptor / decryptor 12-s (step S26). In this case, the encryptor / decryptor 12-s executes the process of establishing an encrypted communication path shown in FIG. 18 with the encryptor / decryptor 21-s of the communication device 20C.

[0388] Then, the cipher selection unit 14B sets the cipher change prohibition period PHB_s for the target stream s (step S27).

[0389] Thereafter, the communication device 10C communicates with the communication device 20C using the changed cipher suite and the target stream s (step S28).

[0390] After step S28, the encryption selecting unit 14B determines whether s=S (step S29), where S is the total number of target streams s.

[0391] If it is determined in step S29 that s is not equal to S, the encryption selecting unit 14B sets s to s+1 (step S30). Thereafter, the operation of the communication device 10C proceeds to step S22, and steps S22 to S30 are repeatedly executed until it is determined in step S29 that s is equal to S.

[0392] If it is determined in step S29 that s=S, the operation of the communication device 10C proceeds to step S21. Thereafter, while the communication device 10C is operating, the above-described steps S21 to S30 are repeatedly executed.

[0393] In the flowchart shown in Figure 33, the cipher suite selection unit 14B determines in step S25 whether the cipher suite used by the encryption / decryption unit 12-s for the target stream s is different from the selected cipher suite, and if it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12-s (see "YES" in step S25), it executes step S26.If it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12-s (see "NO" in step S25), the operation of the communication device 10C transitions to step S23, which corresponds to executing the above-mentioned "cipher suite selection process."

[0394] In this case, the cipher suite selected by the cipher selection unit 14B constitutes the "first cipher suite," and the cipher suite used in the encryption / decryption unit 12-s constitutes the "second cipher suite."

[0395] According to the flowchart shown in FIG. 33, when the communication device 10C performs only the transmission process of transmitting data to the communication device 20C, it selects a cipher suite for each target stream s (see step S24), and if the cipher suite selected in step S24 is different from the cipher suite used in the encryption / decryption unit 12-s of the target stream s (see "YES" in step S25), it encrypts the data s using the cipher suite selected in step S24 and transmits the encrypted data to the communication device 20C (see steps S26 and S28).

[0396] Also, according to the flowchart shown in FIG. 33, when communication device 10C transmits and receives data to and from communication device 20C, it selects a cipher suite for each target stream s (see step S24), and if the cipher suite selected in step S24 is different from the cipher suite used in encryption / decryption unit 12-s of target stream s (see "YES" in step S25), it encrypts data s using the cipher suite selected in step S24 and transmits the encrypted data to communication device 20C, and also receives and decrypts the encrypted data from communication device 20C and outputs the decrypted data to application 11A (see steps S26 and S28).

[0397] Therefore, the cipher suite can be changed depending on the communication quality (= transmission speed TRS1_s) to send encrypted data to communication device 20C, or the cipher suite can be changed depending on the communication quality (= transmission speed TRS1_s) to send and receive encrypted data to and from communication device 20C.

[0398] The rest of the description of the flowchart shown in FIG. 33 is the same as the description of the flowchart shown in FIG.

[0399] FIG. 34 is a flowchart for explaining the detailed operation of step S24 in FIG.

[0400] The flowchart shown in FIG. 34 is the same as the flowchart shown in FIG. 19, except that step S82 in the flowchart shown in FIG. 19 is changed to step S82A and step S83 is changed to step S83B.

[0401] Referring to FIG. 34, after step S23 in FIG. 33, the encryption selection unit 14B executes the above-mentioned step S81, and then refers to the element table C_s of the encryption selection rule table 15C to select the rule n associated with the priority n (step S82A).

[0402] Then, the cipher selection unit 14B determines whether the transmission rate TRS1_s of the stream s satisfies the rule n (step S83B).

[0403] If it is determined in step S83B that the transmission rate TRS1_s does not satisfy the rule n, the above-mentioned step S84 is executed, and then the detailed operation of step S24 proceeds to step S82A.

[0404] Thereafter, the operations of step S82A, step S83B, and step S84 are repeatedly executed until it is determined in step S83B that the transmission rate TRS1_s satisfies the rule n.

[0405] Then, if it is determined in step S83B that the transmission rate TRS1_s satisfies the rule n, the above-mentioned step S85 is executed, and then the process proceeds to step S25 in FIG.

[0406] In the flowchart shown in Figure 34, when s = 1, after step S81, in step S82A, the encryption selection unit 14B refers to the element table C_1 of the encryption selection rule table 15C and selects rule 1 associated with priority 1 in the element table C_1, and in step S83B, the encryption selection unit 14B determines whether the transmission rate TRS1_1 satisfies rule 1.

[0407] Then, when it is determined in step S83B that the transmission rate TRS1_1 does not satisfy rule 1, the cipher selection unit 14B sets n=1+1=2 in step S84.

[0408] Then, in step S82A, the encryption selection unit 14B refers to the element table C_1 and selects rule 2 associated with priority 2 in the element table C_1, and in step S83B, the encryption selection unit 14B determines whether the transmission rate TRS1_1 satisfies rule 2.

[0409] Then, when it is determined in step S83B that the transmission rate TRS1_1 does not satisfy rule 2, the cipher selection unit 14B sets n=2+1=3 in step S84.

[0410] Thereafter, for "n=3" to "n=N-2", if it is determined in step S83B that the transmission rate TRS1_1 does not satisfy rule 3 to rule N-2, the cipher selection unit 14B sets n=N-2+1=N-1 in step S84.

[0411] Then, in step S82A, the encryption selection unit 14B refers to the element table C_1 and selects the rule N-1 associated with the priority N-1 in the element table C_1, and in step S83B, the encryption selection unit 14B determines whether the transmission rate TRS1_1 satisfies the rule N-1.

[0412] If it is determined in step S83B that the transmission rate TRS1_1 satisfies the rule N-1, then in step S85 the cipher suite selection unit 14B refers to the element table C_1 and selects the cipher suite N-1 associated with the rule N-1.

[0413] On the other hand, when it is determined in step S83B that the transmission rate TRS1_1 does not satisfy the rule N-1, the cipher selection unit 14B sets n=N-1+1=N in step S84.

[0414] Then, in step S82A, the encryption selecting unit 14B refers to the element table C_1, selects the rule N associated with the priority N, and in step S83B, determines whether the transmission rate TRS1_1 satisfies the rule N.

[0415] In this case, since no specific rule is set for rule N in element table C_1 (see FIG. 32), the cipher suite selection unit 14B determines in step S83B that the transmission rate TRS1_1 satisfies rule N, and selects cipher suite N associated with rule N in step S85.

[0416] Also, when one of the factor tables C_2 to C_S of the cipher suite selection rule table 15C is used, the cipher suite selection unit 14B refers to one of the factor tables C_2 to C_S and performs the same operation as described above to select a cipher suite.

[0417] In this way, the cipher suite selection unit 14B executes the flowchart shown in FIG. 34 for one encryption / decryption unit 12-s to evaluate whether the transmission rate TRS1_s satisfies the rule from the highest priority condition (rule 1 associated with priority 1) in the cipher suite selection rule table 15C, and selects the cipher suite corresponding to the rule that first satisfies the condition.

[0418] In the element table C_s (s=1 to S) of the cipher selection rule table 15C, rules 1 to N-1 respectively indicate that the transmission rate TRS1_s is the encryption rate C1 to C2 of the cipher suites 1 to N-1. N-1 The reason for the "smaller than" is the same as that explained in the above-mentioned cipher selection rule table 15-1.

[0419] Furthermore, in the flowchart shown in FIG. 33 (including the flowchart shown in FIG. 34), when the communication device 10C performs only the transmission process of transmitting data to the communication device 20C, an “encryption selection rule table generalized from the encryption selection rule table 15-2 (see FIG. 9)” similar to the encryption selection rule table 15C generalized from the encryption selection rule table 15-1 (see FIG. 8(a)) may be used.

[0420] In addition, in the flowchart shown in FIG. 33 (including the flowchart shown in FIG. 34), when communication device 10C transmits and receives data to and from communication device 20C, an “encryption selection rule table similar to encryption selection rule table 15C” is used, which is a generalized version of any of encryption selection rule table 15-1 (see FIG. 8(a)), encryption selection rule table 15-2 (see FIG. 9), encryption selection rule table 15-3 (see FIG. 11), encryption selection rule table 15-4 (see FIG. 12), encryption selection rule table 15-5 (see FIG. 13), encryption selection rule table 15-6 (see FIG. 14), encryption selection rule table 15-7 (see FIG. 15), and encryption selection rule table 15-8 (see FIG. 16).

[0421] In the third embodiment, the operation of the communication device 10C may be realized by software. In this case, the communication device 10C includes a CPU, a ROM, and a RAM. The ROM stores a program Prog_C consisting of the steps of the flowchart shown in FIG. 33 (including the flowchart shown in FIG. 34).

[0422] The CPU reads the program Prog_C from the ROM and executes the read program Prog_C to monitor the communication quality (transmission rate TRS1_s) for each stream s and select a cipher suite based on the monitored communication quality (transmission rate TRS1_s) for all S encryption / decryption units 12-1 to 12-S. The RAM temporarily stores the communication quality (transmission rate TRS1_s).

[0423] Furthermore, the program Prog_C may be distributed by being recorded on a recording medium such as a CD or a DVD. When the recording medium on which the program Prog_C is recorded is attached to a computer, the computer reads and executes the program Prog_C from the recording medium, monitors the communication quality (transmission rate TRS1_s) for each stream s, and selects a cipher suite based on the monitored communication quality (transmission rate TRS1_s) for all S encryption / decryption units 12-1 to 12-S.

[0424] Therefore, the recording medium on which the program Prog_C is recorded is a computer-readable recording medium.

[0425] In addition, when the operation of communication device 10C is realized by the CPU executing program Prog_C, the communication quality is not limited to the transmission rate TRS1, but the communication quality described in any of cipher selection rule table 15-2 (see Figure 9), cipher selection rule table 15-3 (see Figure 11), cipher selection rule table 15-4 (see Figure 12), cipher selection rule table 15-5 (see Figure 13), cipher selection rule table 15-6 (see Figure 14), cipher selection rule table 15-7 (see Figure 15), and cipher selection rule table 15-8 (see Figure 16) is used.

[0426] The rest of the description in the third embodiment is the same as the description in the first embodiment.

[0427] [Embodiment 4] Fig. 35 is a schematic diagram of a fourth embodiment of the communication device 10 shown in Fig. 2. Referring to Fig. 35, a communication device 10D according to the fourth embodiment is the same as the communication device 10A shown in Fig. 3, except that the quality monitoring unit 13 of the communication device 10A shown in Fig. 3 is replaced with a quality monitoring unit 13B, the encryption cipher selection unit 14 of the communication device 10A is replaced with an encryption cipher selection unit 14C, and the encryption cipher selection rule table 15 of the communication device 10A is replaced with an encryption cipher selection rule table 15D.

[0428] The quality monitor 13B monitors the above-mentioned transmission rates TRS1 and TRS2 and reception rates TRS3 and TRS4.

[0429] Then, the quality monitor 13B sets the monitored sending rates TRS1 and TRS2 and receiving rates TRS3 and TRS4 as the communication quality CM_QLT1.

[0430] In addition, the quality monitoring unit 13B receives quality information QLT_IF2=[#C1 / CM_QLT2] associated with tag #C1 from the communication device 20D via a communication path to which tag #C1 is assigned, and retains the communication quality CM_QLT2 included in the received quality information QLT_IF2=[#C1 / CM_QLT2].

[0431] The communication quality CM_QLT2 includes sending rates TRS1' and TRS2' and receiving rates TRS3' and TRS4', which will be described later.

[0432] Therefore, the quality monitor 13B monitors the transmission rates TRS1 and TRS2 and the reception rates TRS3 and TRS4 in the communication device 10D, and the transmission rates TRS1' and TRS2' and the reception rates TRS3' and TRS4' in the communication device 20D.

[0433] Then, when the quality monitor 13B receives an inquiry about the communication quality from the encryption selection unit 14C, it notifies the encryption selection unit 14C of the communication quality CM_QLT1 and the communication quality CM_QLT2 in the communication device 20D.

[0434] The encryption selection unit 14C inquires about the communication quality from the quality monitoring unit 13B, and obtains the communication qualities CM_QLT1 and CM_QLT2 from the quality monitoring unit 13B.

[0435] Then, the encryption selection unit 14C selects a cipher suite based on the communication qualities CM_QLT1, CM_QLT2, the encryption selection rule table 15D (see Figure 37), and the encryption processing quality table (see Figure 45 described later), and communicates the selected cipher suite CRY_SLCT to the encryption / decryption unit 12.

[0436] The encryption / decryption unit 12 executes a process for establishing an encrypted communication path with the encryption / decryption unit 21 of the communication device 20D, and uses the established encrypted communication path to transmit the cipher suite CRY_SLCT received from the cipher selection unit 14C to the encryption / decryption unit 21 of the communication device 20D.

[0437] Fig. 36 is a schematic diagram of a fourth embodiment of communication device 20 shown in Fig. 2. Referring to Fig. 36, communication device 20D according to the fourth embodiment is the same as communication device 20A, except that quality monitoring unit 23 is added to communication device 20A shown in Fig. 4 and application 22 of communication device 20A is changed to application 22A.

[0438] The application 22A outputs data to the encryption / decryption unit 21 and receives data from the encryption / decryption unit 21.

[0439] The quality monitoring unit 23 monitors a transmission rate TRS1', which is the transmission rate when the application 22A transmits data to the encryption / decryption unit 21; a transmission rate TRS2', which is the transmission rate when the encryption / decryption unit 21 transmits encrypted data via the communication IF2; a reception rate TRS3', which is the reception rate when the encryption / decryption unit 21 receives encrypted data from the communication device 10D via the communication IF2; and a reception rate TRS4', which is the reception rate when the application 22A receives data from the encryption / decryption unit 21.

[0440] Then, the quality monitoring unit 23 generates a communication quality CM_QLT2 including the monitored transmission rates TRS1', TRS2' and reception rates TRS3', TRS4', and associates the generated communication quality CM_QLT2 with tag #C1 to generate quality information QLT_IF2=[#C1 / CM_QLT2].

[0441] Then, the quality monitor 23 transmits the quality information QLT_IF2 to the communication device 10D (=quality monitor 13B) via the communication path to which the tag #C1 has been added.

[0442] In embodiment 4, the encryption / decryption unit 21 receives encrypted data from the communication device 10D via the communication IF2, decrypts the received encrypted data using the encryption suite, and outputs the decrypted data to the application 22A.

[0443] Furthermore, when the encryption / decryption unit 21 receives data from the application 22A, it encrypts the received data using the encryption suite and transmits the encrypted data to the communication device 10D via the communication IF2.

[0444] 37 to 44 are first to eighth schematic diagrams of the encryption selection rule table 15D shown in FIG. 35, respectively.

[0445] The cipher selection rule table 15D-1 shown in FIG. 37 is an cipher selection rule table when slower ciphers are used without limiting the speed of communication in the sending direction to encryption processing.

[0446] The cipher selection rule table 15D-2 shown in FIG. 38 is an cipher selection rule table for dealing with the rate limitation of the communication path in the transmission direction, without imposing rate limitation on the cipher processing.

[0447] In the encryption selection rule table 15D-2, being rate-limited by the receiving rate TRS3' is determined when the sending rate TRS1 is lower than the current encryption rate of the communication device 10D and the sending rate TRS1 is higher than the receiving rate TRS3'.

[0448] Furthermore, in the encryption selection rule table 15D-2, the limitation to the receiving rate TRS4' is determined by the fact that the transmitting rate TRS1 is smaller than [the current encryption rate of the communication device 10D and the current decryption rate of the communication device 20D] and the transmitting rate TRS1 is greater than the receiving rate TRS4' of the communication device 20D.

[0449] This determination is made to determine whether the receiving rate TRS4' is lower than the sending rate TRS1 when the rate is not limited by the encryption process.

[0450] Furthermore, the cipher selection rule table 15D-3 shown in FIG. 39 is an cipher selection rule table when the rate of communication in the receiving direction is not limited by the encryption process and a slower cipher is used.

[0451] Furthermore, the cipher selection rule table 15D-4 shown in FIG. 40 is an cipher selection rule table for dealing with the rate limitation of the communication path in the receiving direction, without imposing rate limitation on the cipher processing.

[0452] In the encryption selection rule table 15D-4, the limiting effect on the receiving rate TRS3 is determined by the fact that the transmission rate TRS1' of the communication device 20D is smaller than the current encryption rate of the communication device 20D and the transmission rate TRS1' is greater than the receiving rate TRS3 of the communication device 10D.

[0453] Furthermore, in the encryption selection rule table 15D-4, the limitation to the receiving rate TRS4 is determined by the fact that the sending rate TRS1' is smaller than [the current encryption rate of the communication device 20D and the current decryption rate of the communication device 10D] and the sending rate TRS1' is greater than the receiving rate TRS4.

[0454] Furthermore, the cipher selection rule table 15D-5 shown in FIG. 41 is an cipher selection rule table when the speed of communication in the sending and receiving directions is not limited by the encryption process and a slower cipher is used.

[0455] Furthermore, the cipher selection rule table 15D-6 shown in FIG. 42 is an cipher selection rule table when the speed of transmission and reception is not limited by encryption, in response to the rate limit of the communication path in the transmission direction.

[0456] In the encryption selection rule table 15D-6, the limiting effect on the receiving rate TRS3' is determined by the fact that the sending rate TRS1 is lower than the current encryption rate of the communication device 10D and the sending rate TRS1 is higher than the receiving rate TRS3' of the communication device 20D.

[0457] Furthermore, in the encryption selection rule table 15D-6, the limiting effect of the receiving rate TRS4' is determined by the fact that the transmitting rate TRS1 is smaller than [the current encryption rate of the communication device 10D and the current decryption rate of the communication device 20D] and the transmitting rate TRS1 is greater than the receiving rate TRS4'.

[0458] Furthermore, the cipher selection rule table 15D-7 shown in FIG. 43 is an cipher selection rule table when the transmission and reception speed is not limited by encryption, in response to the rate limit of the communication path in the receiving direction.

[0459] In the encryption selection rule table 15D-7, being rate-limited by the receiving rate TRS3 is determined when the sending rate TRS1' is lower than the current encryption rate of the communication device 20D and the sending rate TRS1' is higher than the receiving rate TRS3.

[0460] Furthermore, in the encryption selection rule table 15D-7, the limitation to the receiving rate TRS4 is determined by the fact that the sending rate TRS1' is smaller than [the current encryption rate of the communication device 20D and the current decryption rate of the communication device 10D] and the sending rate TRS1' is greater than the receiving rate TRS4.

[0461] This determination is made to determine whether the receiving rate TRS4 is lower than the sending rate TRS1 when the rate is not limited by the encryption process.

[0462] Furthermore, the cipher selection rule table 15D-8 shown in FIG. 44 is an cipher selection rule table when the rate is not determined by the encryption process in the transmission and reception directions, but is adapted to the rate limit of the communication path.

[0463] In the encryption selection rule table 15D-8, the limiting effect on the receiving rate TRS3' is determined when the sending rate TRS1 is lower than the current encryption rate of the communication device 10D and the sending rate TRS1 is higher than the receiving rate TRD3'.

[0464] Furthermore, in the encryption selection rule table 15D-8, the limiting effect of the receiving rate TRS4' is determined by the fact that the transmitting rate TRS1 is smaller than [the current encryption rate of the communication device 10D and the current decryption rate of the communication device 20D] and the transmitting rate TRS1 is greater than the receiving rate TRS4'.

[0465] Furthermore, in the encryption selection rule table 15D-8, the limiting effect on the receiving rate TRS3 is determined when the sending rate TRS1' is lower than the current encryption rate of the communication device 20D and the sending rate TRS1' is higher than the receiving rate TRS3.

[0466] Furthermore, in the encryption selection rule table 15D-8, the limiting effect on the receiving rate TRS4' is determined by the fact that the sending rate TRS1' is smaller than [the current encryption rate of the communication device 20D and the current decryption rate of the communication device 10D] and the sending rate TRS1' is greater than the receiving rate TRS4.

[0467] FIG. 37 shows an encryption code selection rule table 15D-1, which is a first schematic diagram of the encryption code selection rule table 15D shown in FIG.

[0468] Referring to Figure 37, rule 1 associated with priority 1 is that the transmission rate TRS1 of communication device 10D is smaller than the encryption rate C1 of cipher suite 1 of communication device 10D and smaller than the decryption rate E1 of cipher suite 1 of communication device 20D.

[0469] Furthermore, rule 2 associated with priority 2 specifies that the transmission rate TRS1 of the communication device 10D is lower than the encryption rate C2 of cipher suite 2 of the communication device 10D and is also lower than the decryption rate E2 of cipher suite 2 of the communication device 20D.

[0470] Similarly, the rule N-1 associated with the priority N-1 is set to a value that indicates that the transmission rate TRS1 of the communication device 10D is equal to or greater than the encryption rate C N-1 and the decryption speed E of the cipher suite N-1 of the communication device 20D is smaller than N-1 It is smaller than that.

[0471] Further, for the rule N associated with the priority N, no specific rule is set.

[0472] The cipher selection rule table 15D-2 shown in Fig. 38 will be described. Referring to Fig. 38, rule 1 states that if the encryption process is rate-limited by the reception rate TRS3' of the communication device 20D, the reception rate TRS3' is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 10D] and the [decryption rate E1 of cipher suite 1 of the communication device 20D], if the encryption process is not rate-limited by the reception rate TRS3' of the communication device 20D but is rate-limited by the reception rate TRS4' of the communication device 20D, the reception rate TRS4' is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 10D] and the [decryption rate E1 of cipher suite 1 of the communication device 20D], and if the encryption process is not rate-limited by the reception rate TRS3' and the reception rate TRS4', the transmission rate TRS1 is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 10D and the decryption rate E1 of cipher suite 1 of the communication device 20D].

[0473] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0474] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0475] And, for rule N, no specific rule is set.

[0476] The cipher selection rule table 15D-3 shown in Fig. 39 will be described. Referring to Fig. 39, rule 1 states that the transmission rate TRS1' of the communication device 20D is smaller than {[encryption rate C1 of cipher suite 1 of the communication device 20D] and [decryption rate E1 of cipher suite 1 of the communication device 10D]}.

[0477] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0478] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0479] And, for rule N, no specific rule is set.

[0480] The cipher selection rule table 15D-4 shown in Fig. 40 will be described. Referring to Fig. 40, rule 1 states that if the encryption process is rate-limited by the reception rate TRS3 of the communication device 10D, the reception rate TRS3 is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20D] and the [decryption rate E1 of cipher suite 1 of the communication device 10D], if the encryption process is not rate-limited by the reception rate TRS3 of the communication device 10D but is rate-limited by the reception rate TRS4 of the communication device 10D, the reception rate TRS4 is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20D] and the [decryption rate E1 of cipher suite 1 of the communication device 10D], and if the encryption process is not rate-limited by the reception rate TRS3 and the reception rate TRS4, ​​the transmission rate TRS1' of the communication device 20D is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20D and the decryption rate E1 of cipher suite 1 of the communication device 10D].

[0481] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0482] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0483] And, for rule N, no specific rule is set.

[0484] The cipher selection rule table 15D-5 shown in Fig. 41 will be described. Referring to Fig. 41, rule 1 states that the transmission rate TRS1 of communication device 10D is smaller than {[encryption rate C1 of cipher suite 1 of communication device 10D] and [decryption rate E1 of cipher suite 1 of communication device 20D]}, and the transmission rate TRS1' of communication device 20D is smaller than {[encryption rate C1 of cipher suite 1 of communication device 20D] and [decryption rate E1 of cipher suite 1 of communication device 10D]}.

[0485] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0486] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0487] And, for rule N, no specific rule is set.

[0488] The cipher selection rule table 15D-6 shown in Fig. 42 will be described. Referring to Fig. 42, rule 1 states that if the encryption process is rate-determined by the reception rate TRS3' of the communication device 20D, the reception rate TRS3' is smaller than the [encryption rate C1 of the cipher suite 1 of the communication device 10D] and the [decryption rate E1 of the cipher suite 1 of the communication device 20D], and if the encryption process is not rate-determined by the reception rate TRS3' of the communication device 20D and rate-determined by the reception rate TRS4' of the communication device 20D, the reception rate TRS4' is smaller than the [encryption rate C1 of the cipher suite 1 of the communication device 10D] and the [decryption rate E1 of the cipher suite 1 of the communication device 20D]. If the transmission rate TRS1 of communication device 10D is smaller than [encryption rate C1 of encryption suite 1 of communication device 10D and decryption rate E1 of encryption suite 1 of communication device 20D] and is not limited by the reception rate TRS3' and reception rate TRS4', then the transmission rate TRS1 of communication device 10D is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 10D] and the transmission rate TRS1' of communication device 20D is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 10D].

[0489] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0490] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0491] And, for rule N, no specific rule is set.

[0492] The cipher selection rule table 15D-7 shown in Fig. 43 will be described. Referring to Fig. 43, rule 1 states that if the encryption process is rate-determined by the reception rate TRS3 of the communication device 10D, the reception rate TRS3 is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20D] and the [decryption rate E1 of cipher suite 1 of the communication device 10D], and if the encryption process is not rate-determined by the reception rate TRS3 of the communication device 10D and rate-determined by the reception rate TRS4 of the communication device 10D, the reception rate TRS4 is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20D] and the [decryption rate E1 of the cipher suite 1 of the communication device 10D]. If the transmission rate TRS1 of communication device 10D is smaller than [encryption rate C1 of encryption suite 1 of communication device 10D and decryption rate E1 of encryption suite 1 of communication device 20D] and is not limited by the reception rate TRS3 and reception rate TRS4, ​​then the transmission rate TRS1 of communication device 10D is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 20D], and the transmission rate TRS1' of communication device 20D is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 20D].

[0493] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0494] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0495] And, for rule N, no specific rule is set.

[0496] The cipher selection rule table 15D-8 shown in Fig. 44 will be described. Referring to Fig. 44, rule 1 states that if the encryption process is rate-limited by the reception rate TRS3' of the communication device 20D, the reception rate TRS3' is smaller than [encryption rate C1 of cipher suite 1 of communication device 10D] and [decryption rate E1 of cipher suite 1 of communication device 20D], and if the encryption process is not rate-limited by the reception rate TRS3' of the communication device 20D, and if the encryption process is rate-limited by the reception rate TRS4' of the communication device 20D, the reception rate TRS4' is smaller than [encryption rate C1 of cipher suite 1 of communication device 10D] and [decryption rate E1 of cipher suite 1 of communication device 20D] and is not rate-limited by the reception rates TRS3' and TRS4', and if the encryption process is rate-limited by the reception rate TRS3 of the communication device 10D, the reception rate TRS3 of the communication device 10D is smaller than [encryption rate C1 of cipher suite 1 of communication device 20D and decryption rate E1 of cipher suite 1 of communication device 20D]. If the reception rate TRS4 is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 10D] and is not limited by the reception rates TRS3', TRS4', TRS3, and is limited by the reception rate TRS4 of communication device 10D, then if the reception rate TRS4 is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 10D] and is not limited by the reception rates TRS3', TRS4', TRS3, and TRS4, ​​then the transmission rate TRS1 of communication device 10D is smaller than [encryption rate C1 of encryption suite 1 of communication device 10D and decryption rate E1 of encryption suite 1 of communication device 20D] and the transmission rate TRS1' of communication device 20D is smaller than [encryption rate C1 of encryption suite 1 of communication device 20D and decryption rate E1 of encryption suite 1 of communication device 10D].

[0497] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0498] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1" and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0499] And, for rule N, no specific rule is set.

[0500] 45 is a schematic diagram of another encryption processing quality table. Referring to FIG. 45, the encryption processing quality table 30A includes the cipher suites and encryption speeds C1 to C2 in the encryption processing quality table shown in FIG. N and decoding speed E1~E N The communication device 10D and the communication device 20D each have a corresponding relationship with each other.

[0501] Fig. 46 is a flowchart for explaining the operation of communication device 10 D. The flowchart shown in Fig. 46 is the same as the flowchart shown in Fig. 17, except that step S31 is added between step S7 and step S8 of the flowchart shown in Fig. 17 and step S8 is changed to step S8C.

[0502] 46, when the operation of the communication device 10D starts, the above-described steps S1 to S7 are executed sequentially. In this case, in step S3, the encryption / decryption unit 12 of the communication device 10D executes the process of establishing an encrypted communication path shown in FIG. 18 with the encryption / decryption unit 21 of the communication device 20D, and in step S5, the communication device 10D executes communication with the communication device 20D using the application 11.

[0503] After step S7, the quality monitoring unit 13B of the communication device 10D receives the quality information QLT_IF2=[#C1 / CM_QLT2] from the communication device 20D, thereby receiving the communication quality CM_QLT2 (=transmission rates TRS1', TRS2' and reception rates TRS3', TRS4') monitored by the communication device 20D (step S31). As a result, the quality monitoring unit 13B of the communication device 10D monitors the transmission rates TRS1, TRS2, TRS1', TRS2' and reception rates TRS3, TRS4, ​​TRS3', TRS4'.

[0504] After step S31, the cipher selection unit 14C inquires about the communication quality from the quality monitoring unit 13, and selects a cipher suite based on the communication qualities CM_QLT1, CM_QLT2 obtained from the quality monitoring unit 13B, one of the cipher selection rule tables 15D-1 to 15D-8 (see Figures 37 to 44), and the cryptographic processing quality table (see Figure 45) (step S8C).

[0505] Thereafter, the above-described steps S9 and S10 are sequentially executed. In this case, in step S10, the encryption / decryption unit 12 of the communication device 10D executes the process of establishing an encrypted communication path shown in Fig. 18 between the encryption / decryption unit 21 of the communication device 20D and the encryption / decryption unit 21 of the communication device 20D, thereby establishing an encrypted communication path.

[0506] After step S10, the above-described steps S11 and S12 are executed in sequence, and after step S12, the operation of communication device 10D proceeds to step S6. Thereafter, while communication device 10D is operating, the above-described steps S6, S7, S31, S8C, S9, S10, S11, and S12 are repeatedly executed.

[0507] In the flowchart shown in Figure 46, the cipher selection unit 14C determines in step S9 whether the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, and if it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12 (see "YES" in step S9), it executes step S10, and if it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12 (see "NO" in step S9), the operation of the communication device 10D transitions to step S7, which corresponds to executing the above-mentioned "cipher suite selection process."

[0508] In this case, the cipher suite selected by the cipher selection unit 14C constitutes the "first cipher suite," and the cipher suite used in the encryption / decryption unit 12 constitutes the "second cipher suite."

[0509] According to the flowchart shown in FIG. 46, the cipher suite selection unit 14C of the communication device 10D selects a cipher suite based on the communication quality CM_QLT1 (= transmission rates TRS1, TRS2 and reception rates TRS3, TRS4) in the communication device 10D and the communication quality CM_QLT2 (= transmission rates TRS1', TRS2' and reception rates TRS3', TRS4') in the communication device 20D (see step S8C).

[0510] Therefore, a cipher suite can be selected adaptively to the communication quality of both the communication device 10D and the communication device 20D.

[0511] The rest of the description of the flowchart shown in FIG. 46 is the same as the description of the flowchart shown in FIG.

[0512] FIG. 47 is a flowchart for explaining the detailed operation of step S8C shown in FIG.

[0513] The flowchart shown in FIG. 47 is the same as the flowchart shown in FIG. 19, except that step S83 of the flowchart shown in FIG. 19 is replaced with step S83C.

[0514] In FIG. 47, the operation of step S8C will be described in detail using the encryption selection rule table 15D-1 shown in FIG.

[0515] Referring to FIG. 47, when the detailed operation of step S8C is started, the above-described steps S81 and S82 are executed in sequence.

[0516] After step S82, the cipher suite selection unit 14C determines whether the transmission rate TRS1 of the communication device 10D satisfies the rule n in the cipher suite selection rule table 15D-1 (step S83C).

[0517] If it is determined in step S83C that the transmission rate TRS1 does not satisfy the rule n, then step S84 described above is executed.

[0518] Thereafter, the detailed operation of step S8C proceeds to step S82.

[0519] On the other hand, if it is determined in step S83C that the transmission rate TRS1 satisfies the rule n, the above-mentioned step S85 is executed, and after step S85, the process proceeds to step S9 in FIG.

[0520] In the flowchart shown in Figure 47, after step S81, in step S82, the encryption selection unit 14C selects rule 1 associated with priority 1 in the encryption selection rule table 15D-1, and in step S83C, the encryption selection unit 14C determines whether the transmission rate TRS1 satisfies rule 1.

[0521] Then, when it is determined in step S83C that the transmission rate TRS1 does not satisfy rule 1, the cipher selection unit 14C sets n=1+1=2 in step S84.

[0522] Thereafter, in step S82, the cipher suite selection unit 14C selects rule 2 associated with priority 2 in the cipher suite selection rule table 15D-1, and in step S83C, the cipher suite selection unit 14C determines whether the transmission rate TRS1 satisfies rule 2.

[0523] Then, when it is determined in step S83C that the transmission rate TRS1 does not satisfy rule 2, the cipher selection unit 14C sets n=2+1=3 in step S84.

[0524] Thereafter, for "n=3" to "n=N-2", if it is determined in step S83C that the transmission rate TRS1 does not satisfy rule 3 to rule N-2, the cipher selection unit 14C sets n=N-2+1=N-1 in step S84.

[0525] Then, in step S82, the cipher suite selection unit 14C selects rule N-1 associated with priority N-1 in the cipher suite selection rule table 15D-1, and in step S83C, the cipher suite selection unit 14C determines whether the transmission rate TRS1 satisfies rule N-1.

[0526] If it is determined in step S83C that the transmission rate TRS1 satisfies the rule N-1, the cipher suite selection unit 14C selects the cipher suite N-1 associated with the rule N-1 in the cipher suite selection rule table 15D-1 in step S85.

[0527] On the other hand, when it is determined in step S83C that the transmission rate TRS1 does not satisfy the rule N-1, the cipher selection unit 14C sets n=N-1+1=N in step S84.

[0528] Then, in step S82, the cipher suite selection unit 14C selects rule N associated with priority N in the cipher suite selection rule table 15D-1, and in step S83C, determines whether the transmission rate TRS1 satisfies rule N.

[0529] In this case, since no specific rule is set for rule N in the cipher suite selection rule table 15D (see FIG. 37), the cipher suite selection unit 14C determines in step S83C that the transmission rate TRS1 satisfies rule N, and selects cipher suite N associated with rule N in step S85.

[0530] In this way, by executing the flowchart shown in Figure 47, the cipher suite selection unit 14C evaluates whether the transmission rate TRS1 satisfies the rule from the highest priority condition (rule 1 associated with priority 1) in the cipher suite selection rule table 15D-1, and selects the cipher suite corresponding to the rule that first satisfied the condition.

[0531] Even when one of the cipher suite selection rule tables 15D-2 to 15D-8 is used instead of the cipher suite selection rule table 15D-1, the cipher suite selection unit 14C selects a cipher suite by the above-described operation.

[0532] In this case, in step S83C of FIG. 47, the cipher suite selection unit 14C sequentially determines whether rules 1 to N in the cipher suite selection rule tables 15D-2 to 15D-8 are satisfied, starting from rule 1, and selects the cipher suite associated with the rule that is determined to be satisfied.

[0533] In the fourth embodiment, the operation of the communication device 10D may be realized by software. In this case, the communication device 10D includes a CPU, a ROM, and a RAM. The ROM stores a program Prog_D consisting of the steps of the flowchart shown in FIG. 46 (including the flowchart shown in FIG. 47).

[0534] The CPU reads the program Prog_D from the ROM and executes the read program Prog_C to select a cipher suite based on the communication quality CM_QLT1 of the communication device 10D and the communication quality CM_QLT2 of the communication device 20D. The RAM temporarily stores the communication qualities CM_QLT1 and CM_QLT2.

[0535] Furthermore, the program Prog_D may be distributed by being recorded on a recording medium such as a CD or a DVD. When the recording medium on which the program Prog_D is recorded is attached to a computer, the computer reads and executes the program Prog_D from the recording medium and selects a cipher suite based on the communication quality CM_QLT1 of the communication device 10D and the communication quality CM_QLT2 of the communication device 20D.

[0536] Therefore, the recording medium on which the program Prog_D is recorded is a computer-readable recording medium.

[0537] In addition, when the operation of the communication device 10D is realized by the CPU executing the program Prog_D, the communication quality is not limited to the transmission rate TRS1, but the communication quality described in any of the cipher selection rule table 15D-2 (see Figure 38), the cipher selection rule table 15D-3 (see Figure 39), the cipher selection rule table 15D-4 (see Figure 40), the cipher selection rule table 15D-5 (see Figure 41), the cipher selection rule table 15D-6 (see Figure 42), the cipher selection rule table 15D-7 (see Figure 43), and the cipher selection rule table 15D-8 (see Figure 44) is used.

[0538] The rest of the description in the fourth embodiment is the same as the description in the first embodiment.

[0539] [Embodiment 5] Fig. 48 is a schematic diagram of a fifth embodiment of the communication device 10 shown in Fig. 2. Referring to Fig. 48, the communication device 10E according to the fifth embodiment is the same as the communication device 10C shown in Fig. 30, except that a quality prediction unit 16A is added to the communication device 10C shown in Fig. 30, the encryption cipher selection unit 14B of the communication device 10C is replaced with an encryption cipher selection unit 14D, and the encryption cipher selection rule table 15C of the communication device 10C is replaced with an encryption cipher selection rule table 15E.

[0540] In addition, in the fifth embodiment, the communication device 20 shown in FIG. 2 has the same configuration as the communication device 20C shown in FIG. 31, but is referred to as "communication device 20E" to distinguish it from the communication device 20C in the third embodiment.

[0541] In embodiment 5, the quality monitoring unit 13A monitors S transmission rates TRS1_1 to TRS1_S of S pieces of data 1 to S from the application 11A to S encryption / decryption units 12-1 to 12-S respectively over time, and generates S pieces of time series data D(t)1_1 to 1_S of the S transmission rates TRS1_1 to TRS1_S.

[0542] In addition, the quality monitoring unit 13A monitors S transmission rates TRS2_1 to TRS2_S over time when the S encryption / decryption units 12-1 to 12-S respectively transmit S encrypted data to S communication IF1_1 to communication IF1_S, and generates S time series data D(t)2_1 to 2_S of the S transmission rates TRS2_1 to TRS2_S.

[0543] Furthermore, the quality monitoring unit 13A monitors the S receiving rates TRS3_1 to TRS3_S over time when the S encryption / decryption units 12-1 to 12-S each receive S encrypted data from the communication device 20E, and generates S time series data D(t)3_1 to 3_S of the S transmitting rates TRS3_1 to TRS3_S.

[0544] Furthermore, the quality monitoring unit 13A monitors S receiving rates TRS4_1 to TRS4_S over time when the application 11A receives data from S encryption / decryption units 12-1 to 12-S, and generates S time series data D(t)4_1 to 4_S of the S transmitting rates TRS4_1 to TRS4_S.

[0545] The quality monitoring unit 13A holds S pieces of time series data D(t)1_1 to 1_S, S pieces of time series data D(t)2_1 to 2_S, S pieces of time series data D(t)3_1 to 3_S, and S pieces of time series data D(t)4_1 to 4_S.

[0546] The quality prediction unit 16A inquires about the communication quality from the quality monitoring unit 13A, and predicts the future communication quality CM_QLT_F based on the communication quality obtained from the quality monitoring unit 13A using the above-mentioned [Method for predicting future communication quality] (= the flowchart shown in Figure 22 (including the flowchart shown in Figure 23)).

[0547] In this case, the quality prediction unit 16A predicts the future transmission rate TRS1_s_F, which is the future transmission rate, based on the time series data D(t)1_s (s = any one of 1 to S) using the above-mentioned [method for predicting future communication quality] (= flowchart shown in Figure 22 (including the flowchart shown in Figure 23)) for all S pieces of time series data D(t)1_1 to 1_S, thereby predicting the S pieces of future transmission rates TRS1_1_F to TRS1_S_F.

[0548] The quality predictor 16A then holds S future transmission rates TRS1_1_F to TRS1_S_F.

[0549] Furthermore, the quality prediction unit 16A predicts the future transmission rate TRS2_s_F, which is the future transmission rate, based on the time series data D(t)2_s (s = 1 to S) using the above-mentioned [method for predicting future communication quality] (= the flowchart shown in Figure 22 (including the flowchart shown in Figure 23)) for all S pieces of time series data D(t)2_1 to 2_S, thereby predicting the S pieces of future transmission rates TRS2_1_F to TRS2_S_F.

[0550] The quality predictor 16A then holds S future transmission rates TRS2_1_F to TRS2_S_F.

[0551] Furthermore, the quality prediction unit 16A predicts the future receiving speed TRS3_s_F, which is the future receiving speed, based on the time series data D(t)3_s (s = any one of 1 to S) using the above-mentioned [method for predicting future communication quality] (= flowchart shown in Figure 22 (including the flowchart shown in Figure 23)) for all S time series data D(t)3_1 to 3_S, thereby predicting S future receiving speeds TRS3_1_F to TRS3_S_F.

[0552] The quality predictor 16A then holds S future receiving rates TRS3_1_F to TRS3_S_F.

[0553] Furthermore, the quality prediction unit 16A predicts the future receiving speed TRS4_s_F, which is the future receiving speed, based on the time series data D(t)4_s (s = any one of 1 to S) using the above-mentioned [method for predicting future communication quality] (= flowchart shown in Figure 22 (including the flowchart shown in Figure 23)) for all S time series data D(t)4_1 to 4_S, thereby predicting S future receiving speeds TRS4_1_F to TRS4_S_F.

[0554] The quality predictor 16A then holds S future receiving rates TRS4_1_F to TRS4_S_F.

[0555] S future transmission rates TRS1_1_F to TRS1_S_F, S future transmission rates TRS2_1_F to TRS2_S_F, S future reception rates TRS3_1_F to TRS3_S_F, and S future reception rates TRS4_1_F to TRS4_S_F configure future communication quality CM_QLT_F.

[0556] The cipher selection unit 14D inquires about the communication quality from the quality prediction unit 16A, and selects a cipher suite for each of the S encryption / decryption units 12-1 to 12-S based on the future communication quality CM_QLT_F obtained from the quality prediction unit 16A, the cipher selection rule table 15E, and the encryption processing quality table (see FIG. 7).

[0557] Then, the cipher suite selection unit 14D transmits the selected S cipher suites to the S encryption / decryption units 12-1 to 12-S, respectively.

[0558] Fig. 49 is a schematic diagram of the encryption code selection rule table 15E shown in Fig. 48. Referring to Fig. 49, the encryption code selection rule table 15E includes element tables E_1 to E_S.

[0559] The element tables E_1 to E_S are associated with the encryption / decryption units 12-1 to 12-S, respectively.

[0560] The element table E_1 is obtained by changing the transmission rate TRS1 in the cipher selection rule table 15-G1 shown in FIG. 10 to a future transmission rate TRS1_1_F.

[0561] Also, element table E_2 is obtained by changing the future transmission rate TRS1_1_F of element table E_1 to a future transmission rate TRS1_2_F.

[0562] Similarly, element table E_S is obtained by changing the future transmission rate TRS1_1_F of element table E_1 to a future transmission rate TRS1_S_F.

[0563] 50 and 51 are first and second flowcharts, respectively, for explaining the operation of the communication device 10E.

[0564] The flowcharts shown in FIGS. 50 and 51 are the same as the flowchart shown in FIG. 33, except that step S24 of the flowchart shown in FIG. 33 is replaced with steps S8D and S8E.

[0565] Referring to FIG. 50, when the operation of the communication device 10E is started, the above-described steps S1 to S5 are sequentially executed.

[0566] In this case, in step S3, the process of establishing an encrypted communication path is executed as shown in Fig. 18. Also, in step S5, the communication device 10E executes communication with the communication device 20E using the application 11A.

[0567] Referring to FIG. 51, after step S5, steps S21 to S23 described above are executed in sequence.

[0568] After step S23, the quality predicting unit 16A acquires the communication quality of the target stream s from the quality monitoring unit 13A, and predicts the future communication quality of the target stream s based on the acquired communication quality of the target stream s (step S8D).

[0569] In this case, the quality prediction unit 16A predicts the future transmission rate TRS1_s_F by the above-mentioned "method for predicting future communication quality" (= the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23)) based on the time series data D(t)1_s of the transmission rate TRS1_s of the target stream s, and predicts the future transmission rate TRS2_s by the above-mentioned "method for predicting future communication quality" (= the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23)) based on the time series data D(t)2_s of the transmission rate TRS2_s of the target stream s. _F is predicted, and based on the time series data D(t)3_s of the receiving speed TRS3_s of the target stream s, the future receiving speed TRS3_s_F is predicted by the above-mentioned "method for predicting future communication quality" (= the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23)) and based on the time series data D(t)4_s of the receiving speed TRS4_s of the target stream s, the future receiving speed TRS4_s_F is predicted by the above-mentioned "method for predicting future communication quality" (= the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23)).

[0570] Then, after step S8D, the cipher selection unit 14D inquires of the quality prediction unit 16A about the communication quality of the target stream s, and selects a cipher suite based on the future communication quality of the target stream s (= future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F) obtained from the quality prediction unit 16A, the cipher selection rule table 15E (see Figure 49), and the encryption processing quality table (see Figure 7) (step S8E).

[0571] Thereafter, the above-described steps S25 to S29 are sequentially executed. If it is determined in step S29 that s is not equal to S, step S30 is executed, and then the operation of communication device 10E proceeds to step S22. Then, steps S22, S23, S8D, S8E, and steps S25 to S30 are repeatedly executed until it is determined in step S29 that s is equal to S.

[0572] Then, if it is determined in step S29 that s=S, the operation of communication device 10E proceeds to step S21, and steps S21 to S23, steps S8D, S8E, and steps S25 to S30 are repeatedly executed while communication device 10E is operating.

[0573] In the flowcharts shown in Figures 50 and 51, when it is determined in step S22 that the cipher change prohibition period PHB_s for the target stream s has ended, the communication quality of the target stream s is monitored (see step S23), and based on the monitored communication quality of the target stream s, the future communication quality of the target stream s (= future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F) is predicted (see step S8D).

[0574] Then, a cipher suite is selected based on the future communication quality of the target stream s predicted in step S8D, the cipher selection rule table, and the cipher processing quality table (see step S8E).

[0575] Thereafter, when it is determined that the cipher suite used by the encryption / decryption unit 12-s of the target stream s is different from the cipher suite selected in step S8E (see "YES" in step S25), the cipher suite selected in step S8E is transmitted to the encryption / decryption unit 12-s of the target stream s, and the cipher suite used by the encryption / decryption unit 12-s of the target stream s is changed to the cipher suite selected in step S8E (see step S26). In this case, the encryption / decryption unit 12-s of the communication device 10E executes the process of establishing an encrypted communication path shown in FIG. 18 with the encryption / decryption unit 21-s of the communication device 20E.

[0576] Then, the cipher change prohibition period PHB_s for the target stream s is set (see step S27), and communication is performed between the communication device 10E and the communication device 20E using the changed cipher suite (see step S28). In this case, when the communication device 10E executes only a transmission process of transmitting data to the communication device 20E, the encryption / decryption unit 12-s of the communication device 10E transmits encrypted data to the communication device 20E via the communication IF1_s, and when the communication device 10E executes data transmission and reception with the communication device 20E, the encryption / decryption unit 12-s transmits encrypted data to the communication device 20E via the communication IF1_s and receives encrypted data from the communication device 20E via the communication IF1_s.

[0577] Therefore, in the path of "YES" in step S22 → step S23 → step S8D → step S8E → "YES" in step S25 → step S26 → step S27 → step S28, the communication quality of the target stream s is monitored, the future communication quality of the target stream s is predicted based on the monitored communication quality of the target stream s, a cipher suite is selected based on the predicted future communication quality of the target stream s, the cipher suite used by the encryption / decryption unit 12-s of the target stream s is changed based on the selected cipher suite, and communication is carried out between communication device 10E and communication device 20E using the changed cipher suite.

[0578] Then, "YES" in step S22 → step S23 → step S8D → step S8E → "YES" in step S25 → step S26 → step S27 → step S28 is executed for all streams 1 to S as long as it is determined in step S25 that the cipher suite used by the encryption / decryption unit 12-s of the target stream s is different from the selected cipher suite.

[0579] As a result, for each of streams 1 to S, communication is performed between the communication device 10E and the communication device 20E using the cipher suite selected based on the predicted future communication quality.

[0580] Also, in the flowcharts shown in Figures 50 and 51, the cipher selection unit 14D determines in step S25 whether the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12-s, and if it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12-s (see "YES" in step S25), it executes step S26.If it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12-s (see "NO" in step S25), the operation of the communication device 10E transitions to step S23, which corresponds to executing the above-mentioned "cipher suite selection process."

[0581] In this case, the cipher suite selected by the cipher selection unit 14D constitutes the "first cipher suite," and the cipher suite used in the encryption / decryption unit 12-s (s=1 to S) constitutes the "second cipher suite."

[0582] Figure 52 is a flowchart for explaining the detailed operation of step S8E in Figure 51. The flowchart shown in Figure 52 is the same as the flowchart shown in Figure 19, except that step S82 in the flowchart shown in Figure 19 is changed to step S82B and step S83 in the flowchart shown in Figure 19 is changed to step S83D.

[0583] Referring to Figure 52, after step S8D in Figure 51, the encryption selection unit 14D executes the above-mentioned step S81, and then refers to the element table E_s of the encryption selection rule table 15E to select the rule n associated with the priority n (step S82B).

[0584] Then, the cipher selection unit 14D determines whether the future transmission rate TRS1_s_F of the stream s satisfies the rule n (step S83D).

[0585] If it is determined in step S83D that the future transmission rate TRS1_s_F does not satisfy the rule n, then step S84 described above is executed, and thereafter the detailed operation of step S8E proceeds to step S82B.

[0586] Then, the operations of step S82B, step S83D, and step S84 are repeatedly executed until it is determined in step S83D that the future transmission rate TRS1_s_F satisfies the rule n.

[0587] Then, if it is determined in step S83D that the future transmission rate TRS1_s_F satisfies the rule n, the above-mentioned step S85 is executed, and then the process proceeds to step S25 in FIG.

[0588] In the flowchart shown in Figure 52, when s = 1, after step S81, in step S82B, the encryption selection unit 14D refers to element table E_1 of the encryption selection rule table 15E and selects rule 1 associated with priority 1 in element table E_1, and in step S83D, the encryption selection unit 14D determines whether the future transmission rate TRS1_s_F satisfies rule 1.

[0589] Then, when it is determined in step S83D that the future transmission rate TRS1_s_F does not satisfy rule 1, the cipher selection unit 14D sets n=1+1=2 in step S84.

[0590] Then, in step S82B, the encryption selection unit 14D refers to the element table E_1 and selects rule 2 associated with priority 2 in the element table E_1, and in step S83D, the encryption selection unit 14D determines whether the future transmission rate TRS1_s_F satisfies rule 2.

[0591] Then, when it is determined in step S83D that the future transmission rate TRS1_s_F does not satisfy rule 2, the cipher selection unit 14D sets n=2+1=3 in step S84.

[0592] Thereafter, for "n=3" to "n=N-2", if it is determined in step S83D that the future transmission rate TRS1_s_F does not satisfy rule 3 to rule N-2, the cipher selection unit 14D sets n=N-2+1=N-1 in step S84.

[0593] Then, in step S82B, the encryption selection unit 14D refers to the element table E_1 and selects the rule N-1 associated with the priority N-1 in the element table E_1, and in step S83D, the encryption selection unit 14D determines whether the future transmission rate TRS1_s_F satisfies the rule N-1.

[0594] If it is determined in step S83D that the future transmission rate TRS1_s_F satisfies the rule N-1, then in step S85 the cipher suite selection unit 14D refers to the element table E_1 and selects the cipher suite N-1 associated with the rule N-1.

[0595] On the other hand, when the cipher selection unit 14D determines in step S83D that the future transmission rate TRS1_s_F does not satisfy the rule N-1, the cipher selection unit 14D sets n=N-1+1=N in step S84.

[0596] Then, in step S82B, the encryption selecting unit 14D refers to the element table E_1, selects the rule N associated with the priority N, and in step S83D determines whether the future transmission rate TRS1_s_F satisfies the rule N.

[0597] In this case, since no specific rule is set for rule N in element table E_1 (see Figure 49), the cipher suite selection unit 14D determines in step S83D that the future transmission rate TRS1_s_F satisfies rule N, and selects cipher suite N associated with rule N in step S85.

[0598] Also, when any of the element tables E_2 to E_S of the cipher suite selection rule table 15E is used, the cipher suite selection unit 14D refers to one of the element tables E_2 to E_S and performs the same operation as described above to select a cipher suite.

[0599] In this way, by executing the flowchart shown in Figure 52, the cipher suite selection unit 14D evaluates whether the future transmission rate TRS1_s_F satisfies the rule from the highest priority condition (rule 1 associated with priority 1) in any of the element tables E_1 to E_S of the cipher suite selection rule table 15E, and selects the cipher suite corresponding to the rule that first satisfied the condition.

[0600] When the communication device 10E only performs a transmission process to transmit data to the communication device 20E, the cipher suite selection unit 14C selects a cipher suite by the above-described operation using a cipher suite selection rule table that is a generalized version of the cipher suite selection rule table 15-2 (see FIG. 9) instead of the cipher suite selection rule table 15E.

[0601] Furthermore, when the communication device 10E transmits and receives data to and from the communication device 20E, the cipher suite is selected by the above-described operation using, instead of the cipher suite selection rule table 15E, a cipher suite that is a generalized version of one of the cipher suite selection rule tables 15-1 to 15-8 (see (a) of Figure 8, Figure 9, Figures 11 to 16) as the cipher suite selection rule table 15E.

[0602] In this case, in step S83D of FIG. 52, the cipher suite selection unit 14C sequentially determines whether rules 1 to N of the cipher suite selection rule table 15E, which is a generalized version of any of the cipher suite selection rule tables 15-2 to 15-8 (see FIGS. 9, 11 to 16), are satisfied, starting from rule 1, and selects the cipher suite associated with the rule that is determined to be satisfied.

[0603] Furthermore, in the element table E_s (s=1 to S) of the cipher selection rule table 15E, rules 1 to N-1 respectively indicate that "future transmission rate TRS1_s_F is equal to encryption rates C1 to C2 of cipher suites 1 to N-1." N-1 The reason for the "smaller than" is the same as that explained in the above-mentioned cipher selection rule table 15-1.

[0604] In the fifth embodiment, the operation of the communication device 10E may be realized by software. In this case, the communication device 10E includes a CPU, a ROM, and a RAM. The ROM stores a program Prog_E consisting of the steps of the flowcharts shown in FIGS. 50 and 51 (including the flowchart shown in FIG. 52).

[0605] The CPU reads the program Prog_E from the ROM and executes the read program Prog_E to predict the communication quality (future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F) for each stream s, and selects a cipher suite based on the predicted communication quality (future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F) for all S encryption / decryption units 12-1 to 12-S. The RAM temporarily stores the communication quality (future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F).

[0606] Furthermore, the program Prog_E may be distributed by being recorded on a recording medium such as a CD or a DVD. When the recording medium on which the program Prog_E is recorded is attached to a computer, the computer reads and executes the program Prog_E from the recording medium to predict the communication quality (future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F) for each stream s, and selects a cipher suite based on the predicted communication quality (future transmission rates TRS1_s_F, TRS2_s_F and future reception rates TRS3_s_F, TRS4_s_F) for all S encryption / decryption units 12-1 through 12-S.

[0607] Therefore, the recording medium on which the program Prog_E is recorded is a computer-readable recording medium.

[0608] The rest of the description in the fifth embodiment is the same as the description in the first to third embodiments.

[0609] [Embodiment 6] Fig. 53 is a schematic diagram of a sixth embodiment of the communication device 10 shown in Fig. 2. The communication device 10E shown in Fig. 53 is the same as the communication device 10D shown in Fig. 35, except that a quality prediction unit 16B is added to the communication device 10D shown in Fig. 35, the encryption cipher selection unit 14C of the communication device 10D shown in Fig. 35 is replaced with an encryption cipher selection unit 14E, and the encryption cipher selection rule table 15D of the communication device 10D shown in Fig. 35 is replaced with an encryption cipher selection rule table 15F.

[0610] In addition, in embodiment 6, the communication device 20 shown in Figure 2 has the same configuration as the communication device 20D shown in Figure 36, but in order to distinguish it from the communication device 20D, the communication device 20 in embodiment 6 will be referred to as "communication device 20F."

[0611] Referring to FIG. 53, the quality monitor 13B acquires the above-mentioned time series data TRS1(t), time series data TRS2(t), time series data TRS3(t), and time series data TRS4(t).

[0612] In addition, the quality monitoring unit 13B receives, via communication IF1, time series data TRS1'(t) of the transmission rate TRS1', time series data TRS2'(t) of the transmission rate TRS2', time series data TRS3'(t) of the receiving rate TRS3', and time series data TRS4'(t) of the receiving rate TRS4' from the communication device 20E.

[0613] The quality prediction unit 16B inquires about the communication quality from the quality monitoring unit 13B and receives time series data TRS1(t), TRS2(t), TRS3(t), TRS4(t), TRS1'(t), TRS2'(t), TRS3'(t), and TRS4'(t) from the quality monitoring unit 13B.

[0614] Then, the quality prediction unit 16B predicts future transmission rates TRS1_F, TRS2_F, TRS1'_F, and TRS2'_F based on the time series data TRS1(t), TRS2(t), TRS1'(t), and TRS2'(t), respectively, using the above-mentioned "method for predicting future communication quality" (= the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23)).

[0615] Furthermore, the quality prediction unit 16B predicts future receiving speeds TRS3_F, TRS4_F, TRS3'_F, and TRS4'_F based on the time series data TRS3(t), TRS4(t), TRS3',(t), and TRS4',(t), respectively, using the above-mentioned "method for predicting future communication quality" (= the flowchart shown in FIG. 22 (including the flowchart shown in FIG. 23)).

[0616] The cipher selection unit 14E inquires of the quality prediction unit 16B about future communication quality, and obtains future transmission rates TRS1_F, TRS2_F, TRS1'_F, TRS2'_F, TRS3_F, TRS4_F, TRS3'_F, and TRS4'_F from the quality prediction unit 16B.

[0617] Then, the cipher suite selection unit 14E selects a cipher suite based on the future transmission rates TRS1_F, TRS2_F, TRS1'_F, TRS2'_F, TRS3_F, TRS4_F, TRS3'_F, and TRS4'_F, the cipher selection rule table 15F, and the cryptographic processing quality table 30A (see FIG. 45).

[0618] Then, the cipher suite selection unit 14E notifies the encryption / decryption unit 12 of the cipher suite and changes the cipher suite.

[0619] 54 to 61 are first to eighth schematic diagrams of the encryption code selection rule table 15F shown in FIG. 53, respectively.

[0620] The cipher selection rule table 15F-1 shown in Figure 54 is the same as the cipher selection rule table 15D-1 shown in Figure 37, except that the "transmission rate TRS1" is changed to "future transmission rate TRS1_F."

[0621] The cipher selection rule table 15F-2 shown in Figure 55 is the same as the cipher selection rule table 15D-2 shown in Figure 38, except that the "reception rate TRS3'" is changed to the "future reception rate TRS3'_F", the "reception rate TRS4'" is changed to the "future reception rate TRS4'_F", and the "transmission rate TRS1" is changed to the "future transmission rate TRS1_F".

[0622] The cipher selection rule table 15F-3 shown in Figure 56 is the same as the cipher selection rule table 15D-2 shown in Figure 39, except that the "transmission rate TRS1'" in the cipher selection rule table 15D-3 shown in Figure 39 is changed to "future transmission rate TRS1'_F."

[0623] The encryption selection rule table 15F-4 shown in Figure 57 is the same as the encryption selection rule table 15D-2 shown in Figure 40, except that the "reception rate TRS3" in the encryption selection rule table 15D-4 shown in Figure 40 is changed to "future reception rate TRS3_F," the "reception rate TRS4" is changed to "future reception rate TRS4_F," and the "transmission rate TRS1'" is changed to "future transmission rate TRS1'_F."

[0624] The cipher selection rule table 15F-5 shown in Figure 58 is the same as the cipher selection rule table 15D-4 shown in Figure 41, except that the "transmission rate TRS1" in the cipher selection rule table 15D-5 shown in Figure 41 is changed to "future transmission rate TRS1_F" and the "transmission rate TRS1'" is changed to "future transmission rate TRS1'_F."

[0625] The cipher selection rule table 15F-6 shown in Figure 59 is the same as the cipher selection rule table 15D-6 shown in Figure 42, except that the "reception rate TRS3'" is changed to the "future reception rate TRS3'_F", the "reception rate TRS4'" is changed to the "future reception rate TRS4'_F", the "transmission rate TRS1" is changed to the "future transmission rate TRS1_F", and the "transmission rate TRS1'" is changed to the "future transmission rate TRS1'_F".

[0626] The encryption selection rule table 15F-7 shown in Figure 60 is the same as the encryption selection rule table 15D-7 shown in Figure 43, except that the "reception rate TRS3" is changed to the "future reception rate TRS3_F", the "reception rate TRS4" is changed to the "future reception rate TRS4_F", the "transmission rate TRS1" is changed to the "future transmission rate TRS1_F", and the "transmission rate TRS1'" is changed to the "future transmission rate TRS1'_F".

[0627] The encryption selection rule table 15F-8 shown in Figure 61 is the same as the encryption selection rule table 15D-8 shown in Figure 44, except that ``reception rate TRS3''' is changed to ``future reception rate TRS3'_F,'' ``reception rate TRS4''' is changed to ``future reception rate TRS4'_F,'' ``reception rate TRS3'' is changed to ``future reception rate TRS3_F,'' ``reception rate TRS4'' is changed to ``future reception rate TRS4_F,'' ``transmission rate TRS1'' is changed to ``future transmission rate TRS1_F,'' and ``transmission rate TRS1''' is changed to ``future transmission rate TRS1'_F.''

[0628] The cipher selection rule table 15F-1 shown in Fig. 54 will be described. Referring to Fig. 54, rule 1 states that the future transmission rate TRS1_F of the communication device 10F is smaller than the encryption rate C1 of cipher suite 1 of the communication device 10F, and the future transmission rate TRS1_F of the communication device 10F is smaller than the decryption rate E1 of cipher suite 1 of the communication device 20F.

[0629] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0630] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”.N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0631] And, for rule N, no specific rule is set.

[0632] The encryption selection rule table 15F-2 shown in FIG. 55 will be described. Referring to Figure 55, rule 1 is that if the future reception rate TRS3'_F of communication device 20F is rate-limited, the future reception rate TRS3'_F is smaller than {[encryption rate C1 of cipher suite 1 of communication device 10F] and [decryption rate E1 of cipher suite 1 of communication device 20F]}, if the future reception rate TRS3'_F is not rate-limited but is rate-limited by the future reception rate TRS4'_F of communication device 20F, the future reception rate TRS4'_F is smaller than {[encryption rate C1 of cipher suite 1 of communication device 10F] and [decryption rate E1 of cipher suite 1 of communication device 20F]}, and if the future reception rate TRS3'_F, TRS4'_F is not rate-limited, the future transmission rate TRS1_F is smaller than {[encryption rate C1 of cipher suite 1 of communication device 10F] and [decryption rate E1 of cipher suite 1 of communication device 20F]}.

[0633] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0634] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0635] And, for rule N, no specific rule is set.

[0636] In the encryption selection rule table 15F-2, the future reception rate TRS3'_F is determined to be rate-limiting when the future transmission rate TRS1_F is smaller than the current encryption rate of the communication device 10F and the future transmission rate TRS1_F is greater than the future reception rate TRS3'_F.

[0637] Furthermore, in the encryption selection rule table 15F-2, the future reception rate TRS4'_F is determined to be rate-limiting when the future transmission rate TRS1_F is smaller than [the current encryption rate of communication device 10F and the current decryption rate of communication device 20F] and the future transmission rate TRS1_F is greater than the future reception rate TRS4'_F of communication device 20F.

[0638] This determination is made to determine whether the future receiving rate TRS4'_F is lower than the future sending rate TRS1_F when the rate is not limited by the encryption process.

[0639] The cipher selection rule table 15F-3 shown in Fig. 56 will be described. Referring to Fig. 56, rule 1 states that the future transmission rate TRS1'_F is smaller than the encryption rate C1 of cipher suite 1 of the communication device 20F, and the future transmission rate TRS1'_F is smaller than the decryption rate E1 of cipher suite 1 of the communication device 10F.

[0640] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0641] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0642] And, for rule N, no specific rule is set.

[0643] The encryption selection rule table 15F-4 shown in FIG. 57 will be described. Referring to Figure 57, rule 1 is that if the cryptographic processing is rate-limited by the future reception rate TRS3_F of the communication device 10F, the future reception rate TRS3_F is smaller than [the encryption rate C1 of the cipher suite 1 of the communication device 20F] and [the decryption rate E1 of the cipher suite 1 of the communication device 10F]; if the cryptographic processing is not rate-limited by the future reception rate TRS3_F of the communication device 20F but is rate-limited by the future reception rate TRS4_F of the communication device 10F, the future reception rate TRS4_F is smaller than [the encryption rate C1 of the cipher suite 1 of the communication device 20F] and [the decryption rate E1 of the cipher suite 1 of the communication device 10F]; and if the cryptographic processing is not rate-limited by the future reception rates TRS3_F and TRS4_F, the future transmission rate TRS1'_F of the communication device 20F is smaller than [the encryption rate C1 of the cipher suite 1 of the communication device 20F and the decryption rate E1 of the cipher suite 1 of the communication device 10F].

[0644] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0645] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0646] And, for rule N, no specific rule is set.

[0647] In the encryption selection rule table 15F-4, the limiting effect on the future reception rate TRS3_F is determined by the fact that the future transmission rate TRS1'_F of the communication device 20F is smaller than the current encryption rate of the communication device 20F and the future transmission rate TRS1'_F is greater than the future reception rate TRS3_F of the communication device 10F.

[0648] Furthermore, in the encryption selection rule table 15F-4, the future reception rate TRS4_F is determined to be rate-limiting when the future transmission rate TRS1'_F is smaller than [the current encryption rate of the communication device 20F and the current decryption rate of the communication device 10F] and the future transmission rate TRS1'_F is greater than the future reception rate TRS4_F.

[0649] The cipher selection rule table 15F-5 shown in Fig. 58 will be described. Referring to Fig. 58, rule 1 states that the future transmission rate TRS1_F is smaller than the encryption rate C1 of cipher suite 1 of communication device 10F and the decryption rate E1 of cipher suite 1 of communication device 20F, and the future transmission rate TRS1'_F is smaller than the encryption rate C1 of cipher suite 1 of communication device 20F and the decryption rate E1 of cipher suite 1 of communication device 10F.

[0650] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0651] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0652] And, for rule N, no specific rule is set.

[0653] The cipher selection rule table 15F-6 shown in Fig. 59 will be described. Referring to Fig. 59, rule 1 states that if the encryption process is rate-determined by the future reception rate TRS3'_F of the communication device 20F, the future reception rate TRS3'_F is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 10F] and the [decryption rate E1 of cipher suite 1 of the communication device 20F], and the encryption process is not rate-determined by the future reception rate TRS3'_F of the communication device 20F, but if the encryption process is rate-determined by the future reception rate TRS4'_F of the communication device 20F, the future reception rate TRS4'_F is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 10F] and the [decryption rate E1 of cipher suite 1 of the communication device 20F]. If the future transmission rate TRS1_F is smaller than [encryption rate C1 of encryption suite 1 of communication device 20F and decryption rate E1 of encryption suite 1 of communication device 20F] and is not rate-limited by the future reception rates TRS3'_F and TRS4'_F, then the future transmission rate TRS1_F is smaller than [encryption rate C1 of encryption suite 1 of communication device 20F and decryption rate E1 of encryption suite 1 of communication device 20F] and the future transmission rate TRS1'_F is smaller than [encryption rate C1 of encryption suite 1 of communication device 20F and decryption rate E1 of encryption suite 1 of communication device 10F].

[0654] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0655] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0656] And, for rule N, no specific rule is set.

[0657] In the encryption selection rule table 15F-6, the future reception rate TRS3'_F is determined to be rate-limiting when the future transmission rate TRS1_F is smaller than the current encryption rate of the communication device 10F and the future transmission rate TRS1_F is smaller than the future reception rate TRS3'_F of the communication device 20F.

[0658] Furthermore, in the encryption selection rule table 15F-6, the future reception rate TRS4'_F is determined to be rate-limiting when the future transmission rate TRS1_F is smaller than [the current encryption rate of the communication device 10F and the current decryption rate of the communication device 20F] and the future transmission rate TRS1_F is greater than the future reception rate TRS4'_F.

[0659] The cipher selection rule table 15F-7 shown in Fig. 60 will be described. Referring to Fig. 60, rule 1 states that if the encryption process is limited by the future reception rate TRS3_F of the communication device 10F, the future reception rate TRS3_F is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20F] and the [decryption rate E1 of cipher suite 1 of the communication device 10F], and the encryption process is not limited by the future reception rate TRS3_F, and if the encryption process is limited by the future reception rate TRS4_F of the communication device 10F, the future reception rate TRS4_F is smaller than the [encryption rate C1 of cipher suite 1 of the communication device 20F] and the [decryption rate E1 of cipher suite 1 of the communication device 20F]. If the future transmission rate TRS1_F is smaller than [encryption rate C1 of encryption suite 1 of communication device 10F and decryption rate E1 of encryption suite 1 of communication device 20F] and is not limited by the future reception rates TRS3_F and TRS4_F, then the future transmission rate TRS1_F is smaller than [encryption rate C1 of encryption suite 1 of communication device 20F and decryption rate E1 of encryption suite 1 of communication device 10F] and the future transmission rate TRS1'_F is smaller than [encryption rate C1 of encryption suite 1 of communication device 20F and decryption rate E1 of encryption suite 1 of communication device 10F].

[0660] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0661] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0662] And, for rule N, no specific rule is set.

[0663] In the encryption selection rule table 15F-7, the future reception rate TRS3_F is determined to be rate-limiting when the future transmission rate TRS1'_F is smaller than the current encryption rate of the communication device 20F and the future transmission rate TRS1'_F is greater than the future reception rate TRS3_F.

[0664] Furthermore, in the encryption selection rule table 15F-7, the future reception rate TRS4_F is determined to be rate-limiting when the future transmission rate TRS1'_F is smaller than [the current encryption rate of the communication device 20F and the current decryption rate of the communication device 10F] and the future transmission rate TRS1'_F is greater than the future reception rate TRS4_F.

[0665] This determination is made to determine whether the future receiving rate TRS4_F is lower than the future sending rate TRS1_F when the rate is not limited by the encryption process.

[0666] The encryption selection rule table 15F-8 shown in FIG. 61 will be described. Referring to FIG. 61, rule 1 states that if the encryption process is rate-determined by the future reception rate TRS3'_F of the communication device 20F, the future reception rate TRS3'_F is smaller than [encryption rate C1 of cipher suite 1 of the communication device 10F] and [decryption rate E1 of cipher suite 1 of the communication device 20F], and the encryption process is not rate-determined by the future reception rate TRS3'_F; if the encryption process is rate-determined by the future reception rate TRS4'_F of the communication device 20F, the future reception rate TRS4'_F is smaller than [encryption rate C1 of cipher suite 1 of the communication device 10F] and [decryption rate E1 of cipher suite 1 of the communication device 20F], and the encryption process is not rate-determined by the future reception rate TRS3'_F of the communication device 20F, and the future reception rate TRS3_F of the communication device 10F is smaller than [encryption rate C1 of cipher suite 1 of the communication device 2 ... If the future reception rate TRS4_F is smaller than {[encryption rate C1 of encryption suite 1 of communication device 20F] and [decryption rate E1 of encryption suite 1 of communication device 10F]} and is not rate-limited by the future reception rates TRS3'_F, TRS4'_F, TRS3_F but is rate-limited by the future reception rate TRS4_F of communication device 10F, then if the future reception rate TRS4_F is smaller than {[encryption rate C1 of encryption suite 1 of communication device 10F] and [decryption rate E1 of encryption suite 1 of communication device 20F]} and is not rate-limited by the future reception rates TRS3'_F, TRS4'_F, TRS3_F, TRS4_F, then the future transmission rate TRS1_F is smaller than {[encryption rate C1 of encryption suite 1 of communication device 10F] and [decryption rate E1 of encryption suite 1 of communication device 20F]} and the future transmission rate TRS1'_F is smaller than {[encryption rate C1 of encryption suite 1 of communication device 20F] and [decryption rate E1 of encryption suite 1 of communication device 10F]}.

[0667] Rule 2 is the same as Rule 1, except that "Cipher Suite 1," "Encryption Speed ​​C1," and "Decryption Speed ​​E1" in the explanation of Rule 1 are replaced with "Cipher Suite 2," "Encryption Speed ​​C2," and "Decryption Speed ​​E2," respectively.

[0668] Similarly, for rule N-1, the “Cipher Suite 1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1” in the explanation of rule 1 are respectively changed to “Cipher Suite N-1”, “Encryption Speed ​​C1”, and “Decryption Speed ​​E1”. N-1 " and "Decoding speed E N-1 ", and the rest is the same as Rule 1.

[0669] And, for rule N, no specific rule is set.

[0670] In the encryption selection rule table 15F-8, the future reception rate TRS3'_F is determined to be rate-limiting when the future transmission rate TRS1_F is smaller than the current encryption rate of the communication device 10F and the future transmission rate TRS1_F is greater than the future reception rate TRD3'_F.

[0671] Furthermore, in the encryption selection rule table 15F-8, the future reception rate TRS4'_F is determined to be rate-limiting when the future transmission rate TRS1_F is smaller than [the current encryption rate of the communication device 10F and the current decryption rate of the communication device 20F] and the future transmission rate TRS1_F is greater than the future reception rate TRS4'_F.

[0672] Furthermore, in the encryption selection rule table 15F-8, the limiting effect on the future reception rate TRS3_F is determined by the fact that the future transmission rate TRS1'_F is smaller than the current encryption rate of the communication device 20F and the future transmission rate TRS1'_F is greater than the future reception rate TRS3_F.

[0673] Furthermore, in the encryption selection rule table 15F-8, the future reception rate TRS4'_F is determined to be rate-limiting when the future transmission rate TRS1'_F is smaller than [the current encryption rate of the communication device 20F and the current decryption rate of the communication device 10F] and the future transmission rate TRS1'_F is greater than the future reception rate TRS4'_F.

[0674] Fig. 62 is a flowchart for explaining the operation of the communication device 10F. The flowchart shown in Fig. 62 is the same as the flowchart shown in Fig. 46, except that step S8C of the flowchart shown in Fig. 46 is replaced with steps S8F and S8G.

[0675] Referring to FIG. 62, when the operation of the communication device 10F starts, the above-described steps S1 to S7 and step S31 are executed in sequence.

[0676] In this case, in step S5, the communication device 10F communicates with the communication device 20F using the application 11. Also, in step S31, the quality monitor 13B receives the communication quality CM_QLT2 (= time series data TRS1'(t), time series data TRS2'(t), time series data TRS3'(t), and time series data TRS4'(t)) from the communication device 20F.

[0677] After step S31, the quality prediction unit 16B predicts future transmission rates TRS1'_F, TRS2'_F and future receiving rates TRS3'_F, TRS4'_F based on the time series data TRS1'(t), time series data TRS2'(t), time series data TRS3'(t), and time series data TRS4'(t) monitored by the communication device 10F, respectively, using the above-mentioned "method for predicting future communication quality" (= the flowchart shown in Figure 22 (including the flowchart shown in Figure 23)) (step S8F).

[0678] Then, the cipher selection unit 14E inquires about the communication quality from the quality prediction unit 16B, and selects a cipher suite based on the future communication quality obtained from the quality prediction unit 16B, the cipher selection rule table 15F (= any one of the cipher selection rule tables 15F-1 to 15F-8), and the cryptographic processing quality table (see Figure 45) (step S8G).

[0679] After step S8G, the above-described steps S9, S10, S11, and S12 are sequentially executed, and after step S12, the operation of communication device 10F proceeds to step S6. Thereafter, while communication device 10F is operating, the above-described steps S6, S7, S31, S8F, S8G, S9, S10, S11, and S12 are repeatedly executed.

[0680] In the flowchart shown in Figure 62, the cipher selection unit 14E determines in step S9 whether the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12, and if it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12 (see "YES" in step S9), it executes step S10, and if it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12 (see "NO" in step S9), the operation of the communication device 10F transitions to step S7, which corresponds to executing the above-mentioned "cipher suite selection process."

[0681] In this case, the cipher suite selected by the cipher selection unit 14E constitutes the "first cipher suite," and the cipher suite used in the encryption / decryption unit 12 constitutes the "second cipher suite."

[0682] According to the flowchart shown in Figure 62, the cipher selection unit 14E of the communication device 10F selects a cipher suite based on the future transmission rates TRS1_F, TRS2_F and future reception rates TRS3_F, TRS4_F of the transmission rates TRS1, TRS2 and reception rates TRS3, TRS4 monitored in the communication device 10F, and the future transmission rates TRS1'_F, TRS2'_F and future reception rates TRS3'_F, TRS4'_F of the transmission rates TRS1', TRS2' and reception rates TRS3', TRS4' monitored in the communication device 20F (see step S8G).

[0683] Therefore, a cipher suite can be selected adaptively to the future communication quality of both the communication device 10F and the communication device 20F.

[0684] As a result, in both the communication device 10F and the communication device 20F, the cipher suite can be changed before the communication quality deteriorates.

[0685] The rest of the description of the flowchart shown in FIG. 62 is the same as the description of the flowchart shown in FIG.

[0686] FIG. 63 is a flowchart for explaining the detailed operation of step S8G shown in FIG.

[0687] The flowchart shown in FIG. 63 is the same as the flowchart shown in FIG. 47, except that step S83C of the flowchart shown in FIG. 47 is replaced with step S83E.

[0688] Referring to FIG. 63, when the detailed operation of step S8G is started, after step S8F shown in FIG. 62, steps S81 and S82 described above are executed in sequence.

[0689] After step S82, the cipher suite selection unit 14E determines whether the future transmission rate TRS1_F of the communication device 10F satisfies the rule n in the cipher suite selection rule table 15F-1 (see FIG. 54) (step S83E).

[0690] If it is determined in step S83E that the future transmission rate TRS1_F does not satisfy the rule n, then step S84 described above is executed.

[0691] Thereafter, the detailed operation of step S8G proceeds to step S82.

[0692] On the other hand, if it is determined in step S83E that the future transmission rate TRS1_F satisfies the rule n, the above-mentioned step S85 is executed, and after step S85, the process proceeds to step S9 in FIG.

[0693] In the flowchart shown in Figure 63, after step S81, in step S82, the encryption selection unit 14E selects rule 1 associated with priority 1 in the encryption selection rule table 15F-1, and in step S83E, the encryption selection unit 14E determines whether the future transmission rate TRS1_F satisfies rule 1.

[0694] Then, when it is determined in step S83E that the future transmission rate TRS1_F does not satisfy rule 1, the cipher selection unit 14E sets n=1+1=2 in step S84.

[0695] Thereafter, in step S82, the cipher suite selection unit 14E selects rule 2 associated with priority 2 in the cipher suite selection rule table 15F, and in step S83E, the cipher suite selection unit 14E determines whether the future transmission rate TRS1_F satisfies rule 2.

[0696] Then, when it is determined in step S83E that the future transmission rate TRS1_F does not satisfy rule 2, the cipher selection unit 14E sets n=2+1=3 in step S84.

[0697] Thereafter, for "n=3" to "n=N-2", if it is determined in step S83E that the future transmission rate TRS1_F does not satisfy rule 3 to rule N-2, the cipher selection unit 14E sets n=N-2+1=N-1 in step S84.

[0698] Then, in step S82, the encryption selection unit 14E selects rule N-1 associated with priority N-1 in the encryption selection rule table 15F, and in step S83E, the encryption selection unit 14E determines whether the future transmission rate TRS1_F satisfies rule N-1.

[0699] If it is determined in step S83E that the future transmission rate TRS1_F satisfies the rule N-1, the cipher suite selection unit 14E selects the cipher suite N-1 associated with the rule N-1 in the cipher suite selection rule table 15F in step S85.

[0700] On the other hand, when the cipher selection unit 14E determines in step S83E that the future transmission rate TRS1_F does not satisfy the rule N-1, the cipher selection unit 14E sets n=N-1+1=N in step S84.

[0701] Then, in step S82, the encryption key selection unit 14E selects rule N associated with priority N in the encryption key selection rule table 15F-1, and determines whether the future transmission rate TRS1_F satisfies rule N or not in step S83E.

[0702] In this case, since no specific rule is set for rule N in the cipher selection rule table 15F-1 (see Figure 54), the cipher selection unit 14E determines in step S83E that the future transmission rate TRS1_F satisfies rule N, and selects cipher suite N associated with rule N in step S85.

[0703] In this way, by executing the flowchart shown in Figure 63, the cipher suite selection unit 14E evaluates whether the future transmission rate TRS1_F satisfies the rule from the highest priority condition (rule 1 associated with priority 1) in the cipher suite selection rule table 15F, and selects the cipher suite corresponding to the rule that first satisfied the condition.

[0704] The cipher suite selection unit 14E uses one of the cipher suite selection rule tables 15F-2 to 15F-8 (see FIGS. 54 to 61) instead of the cipher suite selection rule table 15F-1, and selects a cipher suite through the above-described operation.

[0705] In this case, in step S83E of FIG. 63, the cipher suite selection unit 14E sequentially determines whether rules 1 to N in any one of the cipher suite selection rule tables 15F-2 to 15F-8 are satisfied, starting from rule 1, and selects the cipher suite associated with the rule that is determined to be satisfied.

[0706] In addition, in the cipher selection rule table 15F-1, rules 1 to N-1 respectively indicate that "future transmission rate TRS1_F is equal to encryption rates C1 to C2 of cipher suites 1 to N-1." N-1 The reason for the "smaller than" is the same as that explained in the above-mentioned cipher selection rule table 15-1.

[0707] In the sixth embodiment, the operation of the communication device 10F may be realized by software. In this case, the communication device 10F includes a CPU, a ROM, and a RAM. The ROM stores a program Prog_F consisting of the steps of the flowchart shown in FIG. 62 (including the flowchart shown in FIG. 63).

[0708] The CPU reads the program Prog_F from the ROM and executes the read program Prog_F to select a cipher suite based on both the future transmission rate TRS1_F of the communication device 10F and the future transmission rate TRS1'_F of the communication device 20F. The RAM temporarily stores the future transmission rate TRS1_F and the future transmission rate TRS1'_F.

[0709] The program Prog_F may also be distributed by being recorded on a recording medium such as a CD or DVD. When the recording medium on which the program Prog_F is recorded is attached to a computer, the computer reads and executes the program Prog_F from the recording medium, and selects a cipher suite based on both the future transmission rate TRS1_F of the communication device 10F and the future transmission rate TRS1'_F of the communication device 20F.

[0710] Therefore, the recording medium on which the program Prog_F is recorded is a computer-readable recording medium.

[0711] In addition, when the operation of the communication device 10F is realized by the CPU executing the program Prog_F, the communication quality is not limited to the future transmission rate TRS1_F and the future transmission rate TRS1'_F, but the communication quality described in any of the cipher selection rule table 15F-2 (see Figure 55), the cipher selection rule table 15F-3 (see Figure 56), the cipher selection rule table 15F-4 (see Figure 57), the cipher selection rule table 15F-5 (see Figure 58), the cipher selection rule table 15F-6 (see Figure 59), the cipher selection rule table 15F-7 (see Figure 60), and the cipher selection rule table 15F-8 (see Figure 61) is used.

[0712] Other aspects of the sixth embodiment are the same as those of the first, second and fourth embodiments.

[0713] [Embodiment 7] Fig. 64 is a schematic diagram of the seventh embodiment of the communication device 10 shown in Fig. 2. The communication device 10G shown in Fig. 64 is the same as the communication device 10C shown in Fig. 30, except that the quality monitoring unit 13A of the communication device 10C shown in Fig. 30 is replaced with a quality monitoring unit 13C, the encryption cipher selection unit 14B of the communication device 10C shown in Fig. 30 is replaced with an encryption cipher selection rule table 14F, and the encryption cipher selection rule table 15C of the communication device 10C shown in Fig. 30 is replaced with an encryption cipher selection rule table 15G.

[0714] In the seventh embodiment, the communication device 20 shown in FIG. 2 is referred to as a "communication device 20G."

[0715] Referring to Figure 64, the quality monitoring unit 13C monitors S transmission rates TRS1_1 to TRS1_S which are the transmission rates when the application 11A transmits data to S encryption / decryption units 12-1 to 12-S, respectively; S transmission rates TRS2_1 to TRS2_S which are the transmission rates at communication IF1_1 to communication IF1_S when the S encryption / decryption units 12-1 to 12-S transmit encrypted data via communication IF1_1 to communication IF1_S, respectively; S reception rates TRS3_1 to TRS3_S which are the reception rates when the S encryption / decryption units 12-1 to 12-S receive encrypted data via communication IF1_1 to communication IF1_S, respectively; and S reception rates TRS4_1 to TRS4_S which are the reception rates when the application 11A receives data from the S encryption / decryption units 12-1 to 12-S, respectively.

[0716] Here, S transmission rates TRS1_1 to TRS1_S, S transmission rates TRS2_1 to TRS2_S, S reception rates TRS3_1 to TRS3_S, and S reception rates TRS4_1 to TRS4_S configure communication quality CM_QLT3.

[0717] In addition, the quality monitoring unit 13C receives the transmission rates TRS1'_1 to TRS1'_S, TRS2'_1 to TRS2'_S and receiving rates TRS3'_1 to TRS3'_S, TRS4'_1 to TRS4'_S in the communication device 20G from the communication device 20G via a communication path assigned tag #C1, and holds the received transmission rates TRS1'_1 to TRS1'_S, TRS2'_1 to TRS2'_S and receiving rates TRS3'_1 to TRS3'_S, TRS4'_1 to TRS4'_S.

[0718] When the quality monitoring unit 13C receives an inquiry about communication quality from the encryption selection unit 14F, it notifies the encryption selection unit 14F of the transmission rates TRS1_1 to TRS1_S, TRS2_1 to TRS2_S, TRS1'_1 to TRS1'_S, TRS2'_1 to TRS2'_S and the reception rates TRS3_1 to TRS3_S, TRS4_1 to TRS4_S, TRS3'_1 to TRS3'_S, TRS4'_1 to TRS4'_S.

[0719] The encryption selection unit 14F inquires about communication quality from the quality monitoring unit 13C and obtains transmission rates TRS1_1 to TRS1_S, TRS2_1 to TRS2_S, TRS1'_1 to TRS1'_S, TRS2'_1 to TRS2'_S and reception rates TRS3_1 to TRS3_S, TRS4_1 to TRS4_S, TRS3'_1 to TRS3'_S, TRS4'_1 to TRS4'_S from the quality monitoring unit 13C.

[0720] Then, the cipher selection unit 14F selects S cipher suites CRY_1_SLCT to CRY_S_SLCT based on the transmission rates TRS1_1 to TRS1_S, TRS2_1 to TRS2_S, TRS1'_1 to TRS1'_S, TRS2'_1 to TRS2'_S and the reception rates TRS3_1 to TRS3_S, TRS4_1 to TRS4_S, TRS3'_1 to TRS3'_S, TRS4'_1 to TRS4'_S, the cipher selection rule table 15G and the cryptographic processing quality table (see Figure 45), and transmits the selected S cipher suites CRY_1_SLCT to CRY_S_SLCT to the S encryption / decryption units 12-1 to 12-S, respectively.

[0721] Fig. 65 is a schematic diagram of the seventh embodiment of the communication device 20 shown in Fig. 2. Referring to Fig. 65, the communication device 20G according to the seventh embodiment includes S encryption / decryption units 21-1 to 21-S, an application 22B, and a quality monitoring unit 23A.

[0722] The encryption / decryption unit 21-1 receives encrypted data from the communication device 10G via the communication IF2_1. Then, the encryption / decryption unit 21-1 decrypts the encrypted data using the cipher suite and outputs the decrypted data to the application 22B via the stream #1.

[0723] Furthermore, the encryption / decryption unit 21-1 receives data from the application 22B via stream #1, encrypts the received data using the cipher suite, and transmits the encrypted data to the communication device 10G via the communication IF2_1.

[0724] The encryption / decryption unit 21-2 receives encrypted data from the communication device 10G via the communication IF2_2. Then, the encryption / decryption unit 21-2 decrypts the encrypted data using the cipher suite and outputs the decrypted data to the application 22B via the stream #2.

[0725] Furthermore, the encryption / decryption unit 21-2 receives data from the application 22B via stream #2, encrypts the received data using the cipher suite, and transmits the encrypted data to the communication device 10G via communication IF2_2.

[0726] Similarly, the encryption / decryption unit 21-S receives encrypted data from the communication device 10G via the communication IF2_S. Then, the encryption / decryption unit 21-S decrypts the encrypted data using the cipher suite and outputs the decrypted data to the application 22B via the stream #S.

[0727] The encryption / decryption unit 21-S also receives data from the application 22B via stream #S, encrypts the received data using the cipher suite, and transmits the encrypted data to the communication device 10G via the communication IF2_S.

[0728] The application 22B outputs data 1 to S to the encryption / decryption units 21-1 to 21-S via streams #1 to #S, respectively. The application 22B also receives data 1 to S from the encryption / decryption unit 21-S via streams #1 to #S, respectively.

[0729] The quality monitoring unit 23A monitors S transmission rates TRS1'_1 to TRS1'_S, which are transmission rates at which the application 22B transmits the data 1 to S to the encryption / decryption units 21-1 to 21-S, respectively.

[0730] In addition, the quality monitoring unit 23A monitors S transmission rates TRS2'_1 to TRS2'_S, which are the transmission rates in communication IF2_1 to communication IF2_S when the encryption / decryption units 21-1 to 21_S transmit S encrypted data to the communication device 10G via communication IF2_1 to communication IF2_S, respectively.

[0731] Furthermore, the quality monitoring unit 23A monitors S receiving rates TRS3'_1 to TRS3'_S, which are the receiving rates at communication IF2_1 to communication IF2_S when the encryption / decryption units 21-1 to 21_S receive S encrypted data from the communication device 10G via communication IF2_1 to communication IF2_S, respectively.

[0732] Furthermore, the quality monitor 23A monitors S receiving rates TRS4'_1 to TRS4'_S, which are the receiving rates at which the application 22B receives S pieces of data from the encryption / decryption units 21-1 to 21_S via stream #1 to stream #S, respectively.

[0733] As a result, the quality monitor 23A monitors S transmission rates TRS1'_1 to TRS1'_S, S transmission rates TRS2'_1 to TRS2'_S, S receiving rates TRS3'_1 to TRS3'_S, and S receiving rates TRS4'_1 to TRS4'_S.

[0734] Then, the quality monitor 23A generates communication quality CM_QLT4 including S transmission rates TRS1'_1 to TRS1'_S, S transmission rates TRS2'_1 to TRS2'_S, S receiving rates TRS3'_1 to TRS3'_S, and S receiving rates TRS4'_1 to TRS4'_S.

[0735] Then, the quality monitoring unit 23A generates quality information QLT_IF4=[#C1 / CM_QLT4] that associates the communication quality CM_QLT4 with tag #C1, and transmits the generated quality information QLT_IF4=[#C1 / CM_QLT4] to the communication device 10G via the communication path to which tag #C1 is assigned.

[0736] Fig. 66 is a schematic diagram of the encryption key selection rule table 15G shown in Fig. 64. Referring to Fig. 66, the encryption key selection rule table 15G includes element tables G_1 to G_S.

[0737] The element tables G_1 to G_S correspond to the streams #1 to #S, respectively. The element tables G_1 to G_S include the rule tables R_1 to R_S, respectively. The rule tables R_1 to R_S correspond to the priorities 1 to N, respectively.

[0738] Fig. 67 is a schematic diagram of rule tables R_1 to R_S shown in Fig. 66. Referring to Fig. 67, rule table R_1 includes rules 1 to N associated with priorities 1 to N, respectively.

[0739] Rule 1 is that the transmission rate TRS1_1 of the communication device 10G is smaller than the encryption rate C1 of the cipher suite 1 of the communication device 10G and the decryption rate E1 of the cipher suite 1 of the communication device 20G.

[0740] Rule 2 is that the transmission rate TRS1_1 of the communication device 10G is smaller than the encryption rate C2 of the cipher suite 2 of the communication device 10G and the decryption rate E2 of the cipher suite 2 of the communication device 20G.

[0741] Similarly, the rule N-1 specifies that the transmission rate TRS1_1 of the communication device 10G is equal to the encryption rate C N-1 and the decryption speed E of the cipher suite N-1 of the communication device 20G N-1 It is smaller than that.

[0742] And, for rule N, no specific rule is set.

[0743] Rules 1 to N in the rule table R_1 are the same as rules 1 to N in the encryption code selection rule table 15D-1 shown in FIG.

[0744] Moreover, each of the rule tables R_2 to R_G has the same configuration as the rule table R_1.

[0745] Therefore, the encryption / decryption rule table 15G shown in FIG. 66 is configured by associating the encryption / decryption rule table 15D-1 shown in FIG. 37 with the S encryption / decryption units 12-1 to 12-S in the S streams #1 to #S.

[0746] 66 may be configured by associating cipher selection rule table 15D-2 shown in FIG. 38 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-3 shown in FIG. 39 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-4 shown in FIG. 40 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-5 shown in FIG. 41 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-6 shown in FIG. 42 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-7 shown in FIG. 43 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-8 shown in FIG. 44 with S encryption / decryption units 12-1 to 12-S in S streams #1 to #S, or by associating cipher selection rule table 15D-9 shown in FIG. 42 may be configured to correspond to the S encryption / decryption units 12-1 to 12-S for the S streams #1 to #S, or the encryption selection rule table 15D-6 shown in FIG. 42 may be configured to correspond to the S encryption / decryption units 12-1 to 12-S for the S streams #1 to #S, or the encryption selection rule table 15D-7 shown in FIG. 43 may be configured to correspond to the S encryption / decryption units 12-1 to 12-S for the S streams #1 to #S, or the encryption selection rule table 15D-8 shown in FIG. 44 may be configured to correspond to the S encryption / decryption units 12-1 to 12-S for the S streams #1 to #S.

[0747] Figures 68 and 69 are first and second flowcharts, respectively, for explaining the operation of communication device 10G. The flowcharts shown in Figures 68 and 69 are the same as the flowchart shown in Figure 33, except that step S24 of the flowchart shown in Figure 33 is replaced with step S31A and step S8H.

[0748] 68, when the operation of communication device 10G starts, the above-described steps S1 to S5 are executed in order. In this case, in step S5, communication device 10G executes communication with communication device 20G using application 11A.

[0749] Referring to FIG. 69, after step S5 in FIG. 68, steps S21 to S23 described above are executed in sequence.

[0750] After step S23, the quality monitor 13C of the communication device 10G receives the communication quality CM_QLT4 from the communication device 20G via the communication path assigned #C1 (step S31A).

[0751] Thereafter, the cipher selection unit 14F of the communication device 10G inquires about the communication quality from the quality monitoring unit 13C, and selects a cipher suite based on the communication qualities CM_QLT3, CM_QLT4 obtained from the quality monitoring unit 13C, the cipher selection rule table 15G, and the cryptographic processing quality table (see Figure 45) (step S8H).

[0752] Then, after step S8H, the above-mentioned steps S25 to S28 are executed sequentially, and then, if it is determined in step S29 that s is not equal to S, step S30 is executed, and then the operation of communication device 10G proceeds to step S22.

[0753] Then, steps S22, S23, S31A, S8H, S25, S26, S27, and S28 are repeatedly executed until it is determined in step S29 that s=S.

[0754] If it is determined in step S29 that s=S, the operation of communication device 10G proceeds to step S21. Thereafter, while communication device 10G is operating, steps S21, S22, S23, S31A, S8H, and S25 to S30 are repeatedly executed.

[0755] In the flowcharts shown in Figures 68 and 69, the cipher suite selection unit 14F determines in step S25 whether the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12-s, and if it determines that the selected cipher suite is different from the cipher suite used in the encryption / decryption unit 12-s (see "YES" in step S25), it executes step S26, and if it determines that the selected cipher suite is not different from the cipher suite used in the encryption / decryption unit 12-s (see "NO" in step S25), the operation of the communication device 10G transitions to step S23, which corresponds to executing the above-mentioned "cipher suite selection process."

[0756] In this case, the cipher suite selected by the cipher selection unit 14F constitutes the "first cipher suite," and the cipher suite used in the encryption / decryption unit 12-s constitutes the "second cipher suite."

[0757] In the flowcharts shown in FIGS. 68 and 69, step S25 is executed for all of streams 1 to S, so the cipher suite selection unit 14F executes the above-described "cipher suite selection process" S times.

[0758] According to the flowcharts shown in Figures 68 and 69, the cipher selection unit 14F of the communication device 10G selects a cipher suite (see step S8H) for all streams 1 to S using the transmission rates TRS1_s, TRS2_s and reception rates TRS3_s, TRS4_s monitored in the communication device 10G and the transmission rates TRS1'_s, TRS2'_s and reception rates TRS3'_s, TRS4'_s monitored in the communication device 20G.

[0759] Therefore, for all of streams 1 to S, a cipher suite can be selected adaptively to the communication quality of both the communication device 10G and the communication device 20G.

[0760] The rest of the explanation of the flowcharts shown in FIGS. 68 and 69 is the same as the explanation of the flowchart shown in FIG.

[0761] Figure 70 is a flowchart for explaining the detailed operation of step S8H shown in Figure 69. The flowchart shown in Figure 70 is the same as the flowchart shown in Figure 52, except that step S82B of the flowchart shown in Figure 52 is changed to step S82C and step S83D of the flowchart shown in Figure 52 is changed to step S83F.

[0762] Referring to Figure 70, the encryption selection unit 14F of the communication device 10G executes the above-mentioned step S81 after step S31A of Figure 69, and then refers to the rule table R_s of the element table G_s of the encryption selection rule table 15G to select the rule n associated with the priority n (step S82C).

[0763] Then, the cipher selection unit 14F determines whether the transmission rate TRS1_s of the stream s satisfies the rule n (step S83F).

[0764] If it is determined in step S83F that the transmission rate TRS1_s does not satisfy the rule n, the above-described step S84 is executed, and then the detailed operation of step S8H proceeds to step S82C.

[0765] Thereafter, the operations of step S82C, step S83F, and step S84 are repeatedly executed until it is determined in step S83F that the transmission rate TRS1_s satisfies the rule n.

[0766] Then, if it is determined in step S83F that the transmission rate TRS1_s satisfies the rule n, the above-mentioned step S85 is executed, and then the process proceeds to step S25 in FIG.

[0767] In the flowchart shown in Figure 70, when s = 1, after step S81, in step S82C, the encryption selection unit 14F refers to the rule table R_1 of the element table G_1 of the encryption selection rule table 15G and selects rule 1 associated with priority 1 in the element table G_1, and in step S83F, the encryption selection unit 14F determines whether the transmission speed TRS1_s satisfies rule 1.

[0768] Then, when it is determined in step S83F that the transmission rate TRS1_s does not satisfy rule 1, the cipher selection unit 14F sets n=1+1=2 in step S84.

[0769] Then, in step S82C, the encryption selection unit 14F refers to the rule table R_1 and selects rule 2 associated with priority 2 in the element table G_1, and in step S83F, the encryption selection unit 14F determines whether the transmission rate TRS1_s satisfies rule 2.

[0770] Then, when it is determined in step S83F that the transmission rate TRS1_s does not satisfy rule 2, the cipher selection unit 14F sets n=2+1=3...

Claims

1. A communication device that encrypts data and transmits the encrypted data to at least a destination communication device, Applications and a cipher suite selection unit that selects a cipher suite including a cryptographic algorithm and a key length, and that is sufficient information for establishing an encrypted communication path; an encryption / decryption unit that encrypts data received from the application using the cipher suite selected by the cipher selection unit and executes a transmission process to transmit the encrypted data to the destination communication device, the cipher selection unit selects a first cipher suite from the plurality of cipher suites, the first cipher suite having the selection rule of the cipher selection rule table, based on a cipher selection rule table that associates the plurality of cipher suites with a plurality of selection rules for selecting each of the plurality of cipher suites, a cipher processing quality table that indicates processing qualities (= encryption speed and decryption speed) of the cipher suites, and a selection communication quality that is a communication quality in at least the destination communication device and the destination communication device when the encrypted data is transmitted to the destination communication device and that is used for selecting the cipher suite; determines whether the selected first cipher suite is different from a second cipher suite used in the encryption / decryption unit; and, when it is determined that the first cipher suite is different from the second cipher suite, changes the second cipher suite to the first cipher suite in the encryption / decryption unit; and, when it is determined that the first cipher suite is the same as the second cipher suite, does not change the second cipher suite to the first cipher suite in the encryption / decryption unit; a communication device, wherein the encryption / decryption unit executes the transmission process using the first cipher suite when the cipher selection unit changes the second cipher suite to the first cipher suite, and executes the transmission process using the second cipher suite when the cipher selection unit does not change the second cipher suite to the first cipher suite.

2. a quality monitoring unit that monitors first communication quality including a first transmission rate that is a transmission rate of the data when the application transmits the data to the encryption / decryption unit; a second transmission rate that is a transmission rate at a first communication interface that is a communication interface of the communication device when the encryption / decryption unit transmits encrypted data obtained by encrypting the data to the destination communication device via the first communication interface; a first reception rate that is a reception rate at the first communication interface when the encryption / decryption unit receives the encrypted data from the destination communication device via the first communication interface; and a second reception rate that is a reception rate at which the application receives data decrypted by the encryption / decryption unit from the encryption / decryption unit, 2. The communication device according to claim 1, wherein the cipher selection unit receives the first communication quality from the quality monitoring unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the selection communication quality.

3. a quality prediction unit that receives the first communication quality from the quality monitoring unit and predicts a first future communication quality, which is a future communication quality in the communication device, based on the received first communication quality; 3. The communication device according to claim 2, wherein the cipher selection unit receives the first future communication quality from the quality prediction unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first future communication quality as the selection communication quality.

4. the quality monitoring unit receives, from the destination communication device, second communication quality including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored in the destination communication device; 3. The communication device according to claim 2, wherein the cipher selection unit receives the first and second communication qualities from the quality monitoring unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second communication qualities as the selection communication qualities.

5. a quality prediction unit that receives from the quality monitoring unit the first communication quality and a second communication quality including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored in the destination communication device, predicts a first future communication quality that is a future communication quality in the communication device based on the first communication quality, and predicts a second future communication quality that is a future communication quality in the destination communication device based on the second communication quality, 3. The communication device according to claim 2, wherein the cipher selection unit receives the first and second future communication qualities from the quality prediction unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second future communication qualities as the selection communication qualities.

6. 3. The communication device according to claim 2, wherein the cipher selection unit sets a cipher change prohibition period during which a change of the cipher suite is prohibited, and after the cipher change prohibition period ends, executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the selection communication quality.

7. the encryption / decryption unit includes S encryption / decryption units that perform the transmission process on S pieces of data (S is an integer equal to or greater than 2) using S streams, respectively; the quality monitoring unit monitors the first communication quality in an s-th stream (s is any one of 1 to S) as the s-th first communication quality for all of the S streams, thereby monitoring the S first communication qualities; the cipher selection unit receives the S first communication qualities from the quality monitoring unit, and executes the cipher suite selection process for the s-th encryption / decryption unit using the s-th first communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 3. The communication device according to claim 2, wherein each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream used by the encryption / decryption unit to transmit the encrypted data between itself and the destination communication device.

8. a quality prediction unit configured to predict S first future communication qualities, which are S future communication qualities for the S streams, based on the S first communication qualities for the S streams for transmitting S (S is an integer equal to or greater than 2) pieces of data to the destination communication device, the encryption / decryption unit includes S encryption / decryption units that perform the transmission process on the S data items using the S streams, respectively; the quality monitoring unit monitors the s-th first communication quality in the s-th (s is any one of 1 to S) stream for all of the S streams, thereby monitoring the S first communication qualities; the quality prediction unit receives the S first communication qualities from the quality monitoring unit, and predicts the s-th first future communication quality, which is a future communication quality of the s-th stream among the S streams, based on the s-th (s is any one of 1 to S) first communication quality included in the received S first communication qualities, for all of the S streams, thereby predicting the S first future communication qualities; the cipher selection unit receives the S first future communication qualities from the quality prediction unit, and executes the cipher suite selection process for the s-th encryption / decryption unit using the s-th first future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 3. The communication device according to claim 2, wherein each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream used by the encryption / decryption unit to transmit the encrypted data between itself and the destination communication device.

9. the S second communication qualities of the S (S is an integer of 2 or more) streams monitored in the destination communication device include the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate in the s-th (s is any one of 1 to S) stream of the destination communication device for the S streams; the encryption / decryption unit comprises S encryption / decryption units that perform the transmission process using S streams for transmitting the S data items to the destination communication device, respectively; the quality monitoring unit monitors the first communication qualities of the S streams by monitoring the first communication qualities of the s-th stream (s is any one of 1 to S) of the communication device for all of the S streams, and receives the S second communication qualities from the destination communication device; the cipher selection unit receives the S first communication qualities and the S second communication qualities from the quality monitoring unit, and executes the cipher suite selection process in an s-th encryption / decryption unit using the s-th first communication quality and the s-th second communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities and the S second communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 3. The communication device according to claim 2, wherein each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream used by the encryption / decryption unit to transmit the encrypted data between itself and the destination communication device.

10. a quality prediction unit that predicts S first future communication qualities, which are S future communication qualities for the S streams, based on the S first communication qualities monitored by the communication device for S streams for transmitting S (S is an integer of 2 or more) pieces of data to the destination communication device, and that predicts S second future communication qualities, which are S future communication qualities for the S streams, based on S second communication qualities, which are communication qualities transmitted from the destination communication device for the S streams, including the first transmission rate, the second transmission rate, the first receiving rate, and the second receiving rate monitored by the destination communication device; the encryption / decryption unit includes S encryption / decryption units that perform the transmission process on the S data items using the S streams, respectively; the quality monitoring unit monitors the first communication qualities of the s-th stream (s is any one of 1 to S) for all of the S streams, and receives the second communication qualities from the destination communication device; the quality prediction unit receives the S first communication qualities and the second communication qualities from the quality monitoring unit, and, based on the S first communication qualities, predicts a first future communication quality that is a future communication quality for an s-th stream among the S streams using an s-th first communication quality included in the S first communication qualities, by executing this for all of the S streams, and predicts a second future communication quality that is a future communication quality for an s-th stream among the S streams, based on the S second communication qualities, by executing this for all of the S streams, and predicts the S second future communication qualities; the cipher selection unit receives the S first future communication qualities and the S second future communication qualities from the quality prediction unit, and executes the cipher suite selection process in an s-th encryption / decryption unit using the s-th first future communication quality and the s-th second future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities and the S second future communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 3. The communication device according to claim 2, wherein each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream used by the encryption / decryption unit to transmit the encrypted data between itself and the destination communication device.

11. 11. The communication device according to claim 10, wherein the cipher selection unit sets a cipher change prohibition period during which a change of the cipher suite is prohibited for the s-th stream, and after the cipher change prohibition period ends, executes the cipher suite selection process for all of the S encryption / decryption units based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities as the selection communication qualities, or the S first communication qualities and the S second communication qualities as the selection communication qualities, or the S first future communication qualities as the selection communication qualities, or the S first future communication qualities and the S second future communication qualities as the selection communication qualities.

12. the cipher suite selection rule table has a configuration in which a plurality of priorities indicating priorities of the plurality of selection rules are associated with the plurality of cipher suites and the plurality of selection rules, 3. The communication device according to claim 2, wherein the cipher selector evaluates, in descending order of priority, whether the first communication quality as the selection target communication quality, or the first future communication quality as the selection target communication quality, or the first communication quality and second communication quality as the selection target communication quality (second communication quality including the first transmission rate, the second transmission rate, the first receiving rate, and the second receiving rate monitored in the destination communication device), or the first and second future communication qualities as the selection target communication quality, or the S first communication qualities as the selection target communication quality, or S (S is an integer greater than or equal to 2) first future communication qualities as the selection target communication quality, which are S first future communication qualities in S streams for transmitting S pieces of data to the destination communication device, or the S first future communication qualities and S second future communication qualities which are the S future communication qualities in the S streams as the selection target communication quality, satisfy the selection rule, and selects the cipher suite associated with the selection rule that is first satisfied.

13. The communication device according to claim 2 , wherein the encryption key selection rule table is changed at a desired timing.

14. A program for causing a computer to execute a process of transmitting encrypted data, which is generated by a source communication device, to at least the destination communication device, between the source communication device and the destination communication device, the program comprising: a first step in which a cipher suite selection unit selects a cipher suite including a cryptographic algorithm and a key length, and including information sufficient to establish an encrypted communication path; a second step of executing a transmission process in which an encryption / decryption unit encrypts data received from an application of the source communication device using the cipher suite selected by the cipher selection unit and transmits the encrypted data to the destination communication device; the cipher selection unit, in the first step, performs a cipher suite selection process in which a first cipher suite whose selection communication quality satisfies the selection rule of the cipher selection rule table is selected from the plurality of cipher suites based on a cipher selection rule table that associates a plurality of cipher suites with a plurality of selection rules for selecting each of the plurality of cipher suites, a cipher processing quality table that indicates processing quality (= encryption speed and decryption speed) of the cipher suites, and a selection communication quality that is a communication quality in at least the destination communication device and the destination communication device when the encrypted data is transmitted to the destination communication device and that is used for selecting the cipher suite; the cipher selection unit determines whether the selected first cipher suite is different from a second cipher suite used in the encryption / decryption unit; and, when it is determined that the first cipher suite is different from the second cipher suite, changes the second cipher suite to the first cipher suite in the encryption / decryption unit; and, when it is determined that the first cipher suite is the same as the second cipher suite, does not change the second cipher suite to the first cipher suite in the encryption / decryption unit; A program to be executed by a computer, wherein in the second step, the encryption / decryption unit executes the transmission process using the first cipher suite when the cipher selection unit changes the second cipher suite to the first cipher suite, and executes the transmission process using the second cipher suite when the cipher selection unit does not change the second cipher suite to the first cipher suite.

15. the quality monitoring unit monitors a first communication quality including a first transmission rate, which is a transmission rate of the data when the application transmits the data to the encryption / decryption unit; a second transmission rate, which is a transmission rate at a first communication interface when the encryption / decryption unit transmits the encrypted data, obtained by encrypting the data, to the destination communication device via the first communication interface, which is a communication interface of the communication device; a first reception rate, which is a reception rate at the first communication interface when the encryption / decryption unit receives the encrypted data from the destination communication device via the first communication interface; and a second reception rate, which is a reception rate at which the application receives data decrypted by the encryption / decryption unit from the encryption / decryption unit; 15. The program for causing a computer to execute the program according to claim 14, wherein in the first step, the cipher selection unit receives the first communication quality from the quality monitoring unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the selection communication quality.

16. a fourth step in which a quality prediction unit receives the first communication quality from the quality monitoring unit and predicts a first future communication quality, which is a future communication quality in the communication device, based on the received first communication quality; 16. The program for causing a computer to execute the program according to claim 15, wherein in the first step, the cipher selection unit receives the first future communication quality from the quality prediction unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first future communication quality as the selection communication quality.

17. a third step in which a quality monitoring unit receives, from the destination communication device, second communication quality including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored in the destination communication device; 16. The program for causing a computer to execute the program according to claim 15, wherein in the first step, the cipher selection unit receives the first communication quality and the second communication quality from the quality monitoring unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second communication qualities as the selection communication qualities.

18. a fourth step in which a quality prediction unit receives from the quality monitoring unit the first communication quality and a second communication quality including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored in the destination communication device, predicts a first future communication quality that is a future communication quality in the communication device based on the first communication quality, and predicts a second future communication quality that is a future communication quality in the destination communication device based on the second communication quality; 16. The program for causing a computer to execute the program according to claim 15, wherein in the first step, the cipher selection unit receives the first and second future communication qualities from the quality prediction unit, and executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first and second future communication qualities as the selection communication qualities.

19. 16. The program for causing a computer to execute the program according to claim 15, wherein the cipher selection unit sets a cipher change prohibition period during which a change of the cipher suite is prohibited in the first step, and after the cipher change prohibition period ends, executes the cipher suite selection process based on the cipher selection rule table, the cipher processing quality table, and the first communication quality as the selection communication quality.

20. the encryption / decryption unit includes S encryption / decryption units that perform the transmission process on S pieces of data (S is an integer equal to or greater than 2) using S streams, respectively; the quality monitoring unit, in the third step, monitors the first communication quality in an s-th stream (s is any one of 1 to S) as the s-th first communication quality for all of the S streams, thereby monitoring the S first communication qualities; the cipher selection unit receives the S first communication qualities from the quality monitoring unit in the first step, and executes the cipher suite selection process for the s-th encryption / decryption unit using the s-th first communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 16. The program for causing a computer to execute the program described in claim 15, wherein, in the second step, each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream that the S encryption / decryption units use to transmit the encrypted data between the S encryption / decryption units and the destination communication device.

21. the encryption / decryption unit includes S encryption / decryption units that perform the transmission process on S (S is an integer equal to or greater than 2) pieces of data using the S streams, respectively; a fourth step in which a quality prediction unit predicts S first future communication qualities, which are S future communication qualities for the S streams, based on the S first communication qualities for the S streams for transmitting the S data to the destination communication device, in the third step, the quality monitoring unit monitors the S first communication qualities by monitoring the s-th first communication quality in the s-th (s is any one of 1 to S) stream for all of the S streams; In the fourth step, the quality prediction unit receives the S first communication qualities from the quality monitoring unit, and predicts the s-th first future communication quality, which is a future communication quality of the s-th stream among the S streams, based on the s-th (s is any one of 1 to S) first communication quality included in the received S first communication qualities, by executing this for all of the S streams, thereby predicting the S first future communication qualities; the cipher selection unit, in the first step, receives the S first future communication qualities from the quality prediction unit, and executes the cipher suite selection process for the s-th encryption / decryption unit using the s-th first future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 16. The program for causing a computer to execute the program described in claim 15, wherein, in the second step, each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream that the S encryption / decryption units use to transmit the encrypted data between the S encryption / decryption units and the destination communication device.

22. the S second communication qualities of the S (S is an integer of 2 or more) streams monitored in the destination communication device include the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate in the s-th (s is any one of 1 to S) stream of the destination communication device for the S streams; the encryption / decryption unit comprises S encryption / decryption units that perform the transmission process using S streams for transmitting the S data items to the destination communication device, respectively; In the third step, the quality monitoring unit monitors the first communication quality of the s-th stream (s is any one of 1 to S) of the communication device for all of the S streams to monitor the S first communication qualities, and receives the S second communication qualities from the destination communication device; in the first step, the cipher selection unit receives the S first communication qualities and the S second communication qualities from the quality monitoring unit, and executes the cipher suite selection process in an s-th encryption / decryption unit using the s-th first communication quality and the s-th second communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities and the S second communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 16. The program for causing a computer to execute the program described in claim 15, wherein, in the second step, each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream that the S encryption / decryption units use to transmit the encrypted data between the S encryption / decryption units and the destination communication device.

23. the encryption / decryption unit includes S encryption / decryption units that perform the transmission process on S (S is an integer equal to or greater than 2) pieces of data using the S streams, respectively; the quality prediction unit predicts S first future communication qualities, which are S future communication qualities for the S streams, based on the S first communication qualities monitored by the communication device for the S streams for transmitting the S data items to the destination communication device, and predicts S second future communication qualities, which are S future communication qualities for the S streams, based on S second communication qualities, which are communication qualities transmitted from the destination communication device for the S streams, including the first transmission rate, the second transmission rate, the first reception rate, and the second reception rate monitored by the destination communication device; in the third step, the quality monitoring unit monitors the first communication quality of an s-th stream (s is any one of 1 to S) for all of the S streams to monitor the S first communication qualities, and receives the second communication quality from the destination communication device; In the fourth step, the quality prediction unit receives the S first communication qualities and the second communication qualities from the quality monitoring unit, and, based on the S first communication qualities, predicts a first future communication quality that is a future communication quality for an s-th stream among the S streams using an s-th first communication quality included in the S first communication qualities, by executing this for all of the S streams, and predicts a second future communication quality that is a future communication quality for an s-th stream among the S streams using an s-th second communication quality included in the S second communication qualities, by executing this for all of the S streams, and predicts the S second future communication qualities; in the first step, the cipher selection unit receives the S first future communication qualities and the S second future communication qualities from the quality prediction unit, and executes the cipher suite selection process in an s-th encryption / decryption unit using the s-th first future communication quality and the s-th second future communication quality based on the cipher selection rule table, the encryption processing quality table, and the S first future communication qualities and the S second future communication qualities as the selection communication qualities, for all of the S encryption / decryption units; 16. The program for causing a computer to execute the program described in claim 15, wherein, in the second step, each of the S encryption / decryption units performs the transmission process using the first cipher suite or the second cipher suite in a stream that the S encryption / decryption units use to transmit the encrypted data between the S encryption / decryption units and the destination communication device.

24. 24. The program for causing a computer to execute the program according to claim 23, wherein the cipher selection unit, in the first step, sets a cipher change prohibition period during which a change of the cipher suite is prohibited for the s-th stream, and after the cipher change prohibition period has expired, executes the cipher suite selection process for all of the S encryption / decryption units based on the cipher selection rule table, the encryption processing quality table, and the S first communication qualities as the selection communication qualities, or the S first communication qualities and the S second communication qualities as the selection communication qualities, or the S first future communication qualities as the selection communication qualities, or the S first future communication qualities and the S second future communication qualities as the selection communication qualities.

25. the cipher suite selection rule table has a configuration in which a plurality of priorities indicating priorities of the plurality of selection rules are associated with the plurality of cipher suites and the plurality of selection rules, 16. The program for causing a computer to execute the program according to claim 15, wherein, in the first step, the cipher selection unit evaluates, in descending order of priority, whether or not the first communication quality as the selection communication quality, or the first future communication quality as the selection communication quality, or the first communication quality and a second communication quality as the selection communication quality and the second communication quality including the first transmission rate, the second transmission rate, the first receiving rate, and the second receiving rate monitored in the destination communication device, or the first and second future communication qualities as the selection communication qualities, or the S first communication qualities as the selection communication qualities, or S first future communication qualities which are S future communication qualities for S (S is an integer of 2 or more) streams as the selection communication qualities, or the S first future communication qualities and S second future communication qualities which are the S future communication qualities for the S streams as the selection communication qualities satisfy the selection rule, and selects a cipher suite associated with the selection rule which is first satisfied.

26. 24. The program for causing a computer to execute the program according to claim 15, wherein the encryption selection rule table in the source communication device is changed at a desired timing.

Citation Information

Patent Citations

  • Communication equipment

    JP2004064652A

  • Apparatus and program for selecting encryption module

    JP2009089045A

  • Information processing device, program, and recording medium

    JP2013258566A

  • Dynamic cryptography change system

    JP2014045237A