Encrypted communication system
The cryptographic communication system uses tamper-resistant devices with embedded key generation functions to enable secure and efficient key sharing between devices, addressing the trade-off in existing systems and enhancing security while simplifying key management.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-12-09
- Publication Date
- 2026-04-02
AI Technical Summary
Existing vehicle-to-roadside communication systems face a trade-off between security and data volume, making it difficult to achieve both high security and a simple encrypted communication system, and configurations where each device has the same number of keys as communication targets are impractical due to the inability to add more partners and enormous key data.
Implementing cryptographic communication devices with tamper-resistant devices storing key generation functions and individual information, allowing devices to generate and authenticate common keys independently, thereby enhancing security and simplifying key management.
This approach provides high security against impersonation and simplifies key management, making it suitable for IoT devices with limited processing power and eliminating the need for external key management servers.
Smart Images

Figure 0007839496000001 
Figure 0007839496000002 
Figure 0007839496000003
Abstract
Description
Technical Field
[0001] This disclosure relates to an encrypted communication system Mu .
Background Art
[0002] In the vehicle-to-roadside communication system described in Patent Document 1, roadside units and in-vehicle units existing in a certain area communicate using the same common key. Also, in this system, the roadside unit obtains the common keys of the area to which the roadside unit belongs and neighboring areas from a key management server and distributes them to in-vehicle units capable of communication. This system is an encrypted communication system equipped with a key management server and roadside units (see Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the system described in Patent Document 1, as a countermeasure against impersonation by a third party, security is enhanced by increasing the data volume and making the encryption complex. Here, there is a trade-off relationship between the level of security and the data volume. Therefore, as the data volume increases, the encrypted communication system becomes larger. For this reason, it has been difficult to achieve both a simple encrypted communication system and high security in some cases.
[0005] To address these problems, one possible configuration is one in which each device is equipped with individual information and the same number of keys (or key bundles) as the number of communication targets, thus providing high security and eliminating the need for external devices such as key management servers. However, a configuration in which each device is equipped with the same number of keys (or key bundles) as the number of communication targets is not practical because it would be impossible to increase the number of communication partners later, and the amount of data in the key generation function would become enormous. [Means for solving the problem]
[0006] To solve the above problem, one embodiment provides a first cryptographic communication device having a first tamper-resistant device for storing a first key generation function and a first storage unit for storing first individual information, and a second cryptographic communication device having a second tamper-resistant device for storing a second key generation function and a second storage unit for storing second individual information, further comprising: the first cryptographic communication device having a first input unit and a first communication unit, and the second cryptographic communication device having a second input unit and a second communication unit, and when the first cryptographic communication device and the second cryptographic communication device communicate with each other, the first cryptographic communication device has the second Individual information is input through the first input unit or received by the first communication unit; in the second cryptographic communication device, the first individual information is input through the second input unit or received by the second communication unit; the first cryptographic communication device generates a 12th common key using the first key generation function and the second individual information; the second cryptographic communication device generates a 21st common key using the second key generation function and the first individual information; the first tamper-resistant device stores the 12th common key; and the second tamper-resistant device stores the 21st common key. The first encrypted communication device generates a first authenticator using the 12th common key and the first individual information, transmits the generated first authenticator to the second encrypted communication device, the second encrypted communication device decrypts the first authenticator received from the first encrypted communication device using the 21st common key, and the second encrypted communication device authenticates the first encrypted communication device based on the decryption result of the first authenticator. It is an encrypted communication system. [Brief explanation of the drawing]
[0009] [Figure 1] This figure shows a schematic example of an encrypted communication system configuration. [Figure 2] This diagram shows the processing flow of encrypted communication between the first encrypted communication device and the second encrypted communication device. [Figure 3]This diagram shows the process of generating a shared key. [Figure 4] This diagram shows the process of generating an authenticator. [Figure 5] This diagram shows a shared key generated by a legitimate device. [Figure 6] This diagram shows a shared key generated by an unauthorized device. [Figure 7] This figure shows a modified example of the first encrypted communication device (1a). [Modes for carrying out the invention]
[0010] The embodiments will be described below with reference to the drawings.
[0011] Figure 1 shows a schematic example of the configuration of the encrypted communication system 1. The encrypted communication system 1 comprises a first encrypted communication device 11 and a second encrypted communication device 12.
[0012] The first encrypted communication device 11 includes a first tamper-resistant device 111, a first memory 131, a first input unit 132, a first output unit 133, a first communication unit 134, and a first control unit 135. The first tamper-resistant device 111 stores the first key generation function 311. The first tamper-resistant device 111 may have the first key generation function 311 embedded in it during manufacturing. The first tamper-resistant device 111 may also be an IoT (Internet of Things) device. The first memory 131 stores the first individual information 331. The first memory 131 is an example of the first storage unit.
[0013] The second encrypted communication device 12 includes a second tamper-resistant device 211, a second memory 231, a second input unit 232, a second output unit 233, a second communication unit 234, and a second control unit 235. The second tamper-resistant device 211 stores a second key generation function 312. The second key generation function 312 may be embedded in the second tamper-resistant device 211 during manufacturing. The second tamper-resistant device 211 may be an IoT device. The second memory 231 stores second individual information 332. The second memory 231 is an example of a second storage unit.
[0014] The first cryptographic communication device 11 will be described. The first tamper-resistant device 111 has a function of calculating a common key using the first key generation function 311. The first tamper-resistant device 111 may be detachable from the first cryptographic communication device 11, or may be integrated with the first cryptographic communication device 11. For example, the main body of the first cryptographic communication device 11 is configured using a computer, the first tamper-resistant device 111 is configured as a chip, and the first cryptographic communication device 11 may be configured by inserting the chip into the board of the computer. The first tamper-resistant device 111 is protected so that the first key generation function 311 stored in the first tamper-resistant device 111 cannot be improperly obtained from the outside.
[0015] The first memory 131 may also store information other than the first individual information 331. The first input unit 132 has an operation unit operated by the first user of the first cryptographic communication device 11, and inputs information according to the operation content of the operation unit. The first output unit 133 outputs information by screen display, voice, or the like.
[0016] The first communication unit 134 is a communication interface for communicating with the second cryptographic communication device 12. This communication may be wired communication or wireless communication. As wireless communication, short-range wireless communication (NFC: Near Field Communication), which is a type of RFID (Radio Frequency Identification) technology, may be used. In this embodiment, a case where the first cryptographic communication device 11 and the second cryptographic communication device 12 communicate directly is shown. However, the first cryptographic communication device 11 and the second cryptographic communication device 12 may communicate indirectly via another device. The communication path through which the first communication unit 134 communicates with the second cryptographic communication device 12 is a communication path that can be wiretapped and intercepted. Therefore, cryptographic communication becomes effective.
[0017] The first control unit 135 controls various processes. The first control unit 135 may include a processor such as a CPU (Central Processing Unit), and may execute a control program stored in the first memory 131 to control various processes.
[0018] In this embodiment, the first tamper-resistant device 111 has a function of performing operations for encryption and decryption using the first key generation function 311, and the first control unit 135 controls the input and output of the first tamper-resistant device 111 to execute operations by the first tamper-resistant device 111. As another configuration example, the first control unit 135 may execute a part of the operations for the encryption and the decryption, and the encryption and the decryption may be realized in combination with the operations by the first tamper-resistant device 111.
[0019] As the first key generation function 311, various key generation functions may be used. The first key generation function 311 may be a function that generates an ID-based key, or may be a function that generates a KPS key. As the first key generation function 311, in order to reduce the amount of computation, a function that does not perform a pairing operation is preferably used, particularly when the computing power of the first tamper-resistant device 111 is low. As the first key generation function 311, a function that performs matrix operations may be used. However, a function that performs a pairing operation may be used as the first key generation function 311.
[0020] The first individual information 331 is information that can uniquely identify the first encrypted communication device 11 in the encrypted communication system 1, and is information specific to the first encrypted communication device 11 in the encrypted communication system 1. The first individual information 331 is made public. The first individual information 331 may be various types of information, such as the serial number of the first encrypted communication device 11, the MAC address of the first encrypted communication device 11, the email address of the first user configured in the first encrypted communication device 11, the name of the first user configured in the first encrypted communication device 11, or the My Number of the first user configured in the first encrypted communication device 11.
[0021] The second encrypted communication device 12 will now be described. The configuration and operation of the second encrypted communication device 12 are the same as those of the first encrypted communication device 11. Specifically, the configuration and operation of the second tamper-resistant device 211, second memory 231, second input unit 232, second output unit 233, second communication unit 234, and second control unit 235 in the second encrypted communication device 12 are the same as those of the first tamper-resistant device 111, first memory 131, first input unit 132, first output unit 133, first communication unit 134, and first control unit 135 in the first encrypted communication device 11.
[0022] The second key generation function 312 is different from the first key generation function 311. The second individual information 332 is information specific to the second encrypted communication device 12 in the encrypted communication system 1. The second encrypted communication device 12 is operated by the second user. The second user may be different from the first user, or they may be the same person as the first user.
[0023] Here, the cryptographic communication system 1 may include other cryptographic communication devices in addition to the first cryptographic communication device 11 and the second cryptographic communication device 12. The configuration and operation of such other cryptographic communication devices are the same as those of the first cryptographic communication device 11, except for, for example, the key generation function and individual information.
[0024] Figure 2 shows the processing flow of encrypted communication between the first encrypted communication device 11 and the second encrypted communication device 12. The processes T1 to T5 performed in the first encrypted communication device 11, the processes T11 to T15 performed in the second encrypted communication device 12, and the processes T21 to T23 performed by communication between the first encrypted communication device 11 and the second encrypted communication device 12 will be explained.
[0025] In process T1, the first cryptographic communication device 11 incorporates the first key generation function 311. This process is performed when the first tamper-resistant device 111 is detachable from the first cryptographic communication device 11, and the first user or the like attaches the first tamper-resistant device 111 to the first cryptographic communication device 11. Therefore, if the first tamper-resistant device 111 is already attached to the first cryptographic communication device 11, or if the first tamper-resistant device 111 is integrated into the first cryptographic communication device 11, process T1 is omitted.
[0026] In process T2, the first encrypted communication device 11 acquires the second individual information 332. In this example, the first user operates the operation unit of the first input unit 132, and the first input unit 132 inputs the second individual information 332 corresponding to that operation, thereby the first encrypted communication device 11 acquires the second individual information 332. As another example, the second encrypted communication device 12 may transmit the second individual information 332 to the first encrypted communication device 11 via the second communication unit 234, and the first encrypted communication device 11 may receive the second individual information 332 via the first communication unit 134, thereby obtaining the second individual information 332.
[0027] In process T3, the first cryptographic communication device 11 uses the first tamper-resistant device 111 to generate a common key using the first key generation function 311 and the input second individual information 332. This common key will be referred to as the 12th common key. In this example, the 12th common key is stored in the first memory 131 of the first cryptographic communication device 11.
[0028] In process T11, the second cryptographic communication device 12 incorporates the second key generation function 312. This process is the same as process T1 in the first cryptographic communication device 11. In process T12, the second encrypted communication device 12 acquires the first individual information 331. This process is the same as process T2 in the first encrypted communication device 11. In process T13, the second cryptographic communication device 12 uses the second tamper-resistant device 211 to generate a common key using the second key generation function 312 and the input first individual information 331. This common key will be referred to as the 21st common key. In this example, the 21st common key is stored in the second memory 231 of the second cryptographic communication device 12. The 12th and 21st common keys are the same common key.
[0029] In process T4, the first cryptographic communication device 11 generates an authenticator using the 12th common key and the first individual information 331 via the first tamper-resistant device 111. This authenticator will be referred to as the first authenticator and described accordingly. In process T14, the second cryptographic communication device 12 generates an authenticator using the 21st common key and the second individual information 332 via the second tamper-resistant device 211. This authenticator will be referred to as the second authenticator and explained accordingly. The authenticator may be the MAC, which is ID information, or other information. This other information may be data that communicates time information, for example.
[0030] In process T21, the first encrypted communication device 11 transmits the first authenticator to the second encrypted communication device 12 via the first communication unit 134. The second encrypted communication device 12 receives the first authenticator via the second communication unit 234.
[0031] In process T15, the second cryptographic communication device 12 uses the second tamper-resistant device 211 to decrypt the first authenticator received using the 21st common key, and performs authentication based on the decryption result. In this example, we assume that the second encrypted communication device 12 determines, through this authentication, that the first encrypted communication device 11 is a legitimate device. In this case, the following process T22 is performed. On the other hand, if the second encrypted communication device 12 determines that the first encrypted communication device 11 is not a legitimate device, it executes predetermined processing, such as notifying the device of an anomaly. In this case, the following processing T22 does not need to be performed.
[0032] In process T22, the second encrypted communication device 12 transmits the second authenticator to the first encrypted communication device 11 via the second communication unit 234. The first encrypted communication device 11 receives the second authenticator via the first communication unit 134.
[0033] In process T5, the first cryptographic communication device 11 uses the first tamper-resistant device 111 to decrypt the second authenticator received using the 12th common key, and performs authentication based on the decryption result. In this example, we assume that the first encrypted communication device 11 determines, through this authentication, that the second encrypted communication device 12 is a legitimate device. In this case, the following process T23 is performed. On the other hand, if the first encrypted communication device 11 determines that the second encrypted communication device 12 is not a legitimate device, it executes predetermined processing, such as notifying the device of an anomaly. In this case, the following processing T23 does not need to be performed.
[0034] In process T23, the first encrypted communication device 11 and the second encrypted communication device 12 communicate with each other to complete mutual authentication.
[0035] Here, the series of processes T1-T3 in the first encrypted communication device 11 and the series of processes T11-T13 in the second encrypted communication device 12 may be performed independently of the subsequent processes T4-T5, T14-T15, and T21-T23. Furthermore, the series of processes T1 to T3 in the first encrypted communication device 11 and the series of processes T11 to T13 in the second encrypted communication device 12 may be performed independently or in parallel in time.
[0036] Furthermore, the processing T4 in the first encrypted communication device 11 and the processing T14 in the second encrypted communication device 12 may be performed independently or in parallel in time. Furthermore, the authentication performed by processes T21 and T15 and the authentication performed by processes T22 and T5 may be performed in parallel in time. That is, the order of processes T21, T22, T15, and T5 may be used, or the order of processes T21, T22, T5, and T15 may be used, and processes 5 and T15 may be performed in parallel in time.
[0037] Figure 3 shows the process of generating a shared key. In the first cryptographic communication device 11, the first tamper-resistant device 111 generates the 12th common key, Kab, using the first key generation function 311 and the input second individual information 332, which is IDb. Here, IDb represents the second individual information 332, and Kab represents the 12th common key. In the second cryptographic communication device 12, the second tamper-resistant device 211 generates the 21st common key, Kba, using the second key generation function 312 and the input first individual information 331, IDa. Here, IDa represents the first individual information 331, and Kba represents the 21st common key.
[0038] Figure 4 shows the process of generating an authenticator. In the first cryptographic communication device 11, the first tamper-resistant device 111 generates an authenticator 1, which is the first authenticator, using the 12th common key Kab and the first individual information 331 IDa. Here, authenticator 1 represents the first authenticator. In the second cryptographic communication device 12, the second tamper-resistant device 211 generates a second authenticator, authenticator 2, using the 21st common key, Kba, and the second individual information 332, IDb. Here, authenticator 2 represents the second authenticator.
[0039] Figure 5 shows a symmetric key generated by a legitimate device. In the encrypted communication system 1, the first encrypted communication device 11 and the second encrypted communication device 12 are legitimate devices. The first device information 411 is information held by the first cryptographic communication device 11 and includes the first key generation function 311, Sa, and the first individual information 331, IDa. Here, Sa represents the first key generation function 311. As shown in Figure 5, the 12th common key, Kab, is Sa(IDb), which is the result of applying the first key generation function 311, Sa, to the second individual information 332, IDb. The second device information 421 is information held by the second cryptographic communication device 12 and includes the second key generation function 312, Sb, and the second individual information 332, IDb. Here, Sb represents the second key generation function 312. As shown in Figure 5, the 21st common key, Kba, is Sb(IDa), which is the result of applying the second key generation function 312, Sb, to the first individual information 331, IDa. In the example shown in Figure 5, the first encrypted communication device 11 and the second encrypted communication device 12 are legitimate devices and are mutually authenticated.
[0040] Figure 6 shows a symmetric key generated by an unauthorized device. The third encrypted communication device, which is not shown, is assumed to be an unauthorized device in the encrypted communication system 1. Furthermore, the third encrypted communication device has illegally acquired and stored the first individual information 331. This section describes a case where an unauthorized third encrypted communication device attempts to authenticate with a legitimate second encrypted communication device 12.
[0041] The third device information 431 is information held by the third cryptographic communication device and includes the third key generation function Sc and the first individual information 331 IDa. Here, Sc represents the third key generation function. In the third cryptographic communication device, a common key Kcb is generated using the third key generation function Sc and the input second individual information 332, IDb. This common key will be referred to as the 32nd common key and explained accordingly. Here, Kcb represents the 32nd common key. As shown in Figure 6, the 32nd common key Kcb is Sc(IDb), which is the result of applying the third key generation function Sc to the second individual information 332, IDb.
[0042] The second device information 421 is information held by the second cryptographic communication device 12 and includes the second key generation function 312, Sb, and the second individual information 332, IDb. The second cryptographic communication device 12 is notified of the first individual information 331 from the third cryptographic communication device. As a result, the second cryptographic communication device 12 generates a 21st common key. As shown in Figure 6, the 21st common key, Kba, is Sb(IDa), which is the result of applying the second key generation function 312, Sb, to the first individual information 331, IDa.
[0043] In this case, the 32nd common key generated by the third cryptographic communication device and the 21st common key generated by the second cryptographic communication device 12 are different common keys. Therefore, the second cryptographic communication device 12 determines that the third cryptographic communication device is not a legitimate device. Thus, in the example shown in Figure 6, the third encrypted communication device is a fraudulent device, and mutual authentication cannot be established between the third encrypted communication device and the second encrypted communication device 12.
[0044] Here, we have shown a case where the first individual information is illegally stored in the third encrypted communication device, but the same applies when an unauthorized third user operating the third encrypted communication device causes the first individual information to be input into the second encrypted communication device 12.
[0045] Thus, in the encrypted communication system 1, even if the first individual information 331 of the first encrypted communication device 11 and the second individual information 332 of the second encrypted communication device 12 are known to a third party, so-called impersonation can be prevented. In the encrypted communication system 1, the first key generation function 311 is stored in the first tamper-resistant device 111 of the first encrypted communication device 11 before encrypted communication takes place, and the second key generation function 312 is stored in the second tamper-resistant device 211 of the second encrypted communication device 12 before encrypted communication takes place, thereby providing resistance to attacks by impersonation.
[0046] Figure 7 shows a modified example of the first encrypted communication device 11a. The first encrypted communication device 11a is a modified example of the first encrypted communication device 11 shown in Figure 1. Components similar to those in Figure 1 are given the same reference numerals, and detailed explanations are omitted. In general terms, the function of the firsta tamper-resistant device 111a, which is a modified version of the first tamper-resistant device 111, differs from that of the first cryptographic communication device 11 shown in Figure 1. In the firsta encrypted communication device 11a, the firsta tamper-resistant device 111a stores the generated 12th common key 412. This prevents the 12th common key 412 from being read from the outside in the firsta encrypted communication device 11a. As a result, the firsta encrypted communication device 11a can further enhance the security of encrypted communication. Furthermore, as another variation, the first tamper-resistant device 111a may include a control unit having a similar function to the first control unit 135 as a control unit for generating the 12th common key 412. This allows the 12th common key 412 to be generated within the first tamper-resistant device 111a. Therefore, the first cryptographic communication device 11a can further enhance the security of encrypted communications. In this configuration, the first cryptographic communication device 11a does not need to include the first control unit 135, but it may also include any control unit separate from the control unit of the first tamper-resistant device 111a. Here, we have described the first encrypted communication device 11a related to the above modifications, but similar modifications may be made to the second encrypted communication device 12 shown in Figure 1.
[0047] In the first encrypted communication device 11 according to this embodiment, a first input unit 132 and a first output unit 133 are provided. However, in other configuration examples, if one or both functions of the first input unit 132 and the first output unit 133 are not used, then one or both of the unused first input unit 132 and the first output unit 133 may be omitted. Here, we have described the first encrypted communication device 11, but the same applies to the second encrypted communication device 12.
[0048] In this embodiment, the first encrypted communication device 11 and the second encrypted communication device 12 performed mutual authentication using a first authenticator and a second authenticator, but other general authentication methods may be used. For example, the first encrypted communication device 11 and the second encrypted communication device 12 may authenticate each other using an authentication method such as a challenge-and-response method.
[0049] In this embodiment, the first encrypted communication device 11 and the second encrypted communication device 12 performed mutual authentication using a first authenticator and a second authenticator, but the first encrypted communication device 11 and the second encrypted communication device 12 do not need to perform mutual authentication. In this case, the first cryptographic communication device 11 decrypts the ciphertext transmitted from the second cryptographic communication device 12 using the 12th common key generated based on the first key generation function 311 and the second individual information 332. As a result, the first cryptographic communication device 11 can decrypt the ciphertext transmitted from the second cryptographic communication device 12. Therefore, the first cryptographic communication device 11 can indirectly recognize that the communication partner is the second cryptographic communication device 12. On the other hand, if the communication partner of the first encrypted communication device 11 is an encrypted communication device that is impersonating the second encrypted communication device 12, the first encrypted communication device 11 cannot decrypt the ciphertext sent from the impersonating encrypted communication device. Therefore, the first encrypted communication device 11 can maintain confidentiality in encrypted communication without authenticating the second encrypted communication device 12. Here, we have described the first encrypted communication device 11, but the same applies to the second encrypted communication device 12.
[0050] As described above, in the encrypted communication system 1 according to this embodiment, the first encrypted communication device 11 has first individual information 331 and a first key generation function 311 protected by a first tamper-resistant device 111. Similarly, the second encrypted communication device 12 has second individual information 332 and a second key generation function 312 protected by a second tamper-resistant device 211. The first cryptographic communication device 11 generates a 12th common key from the first key generation function 311 and the second individual information 332 of the other second cryptographic communication device 12. Similarly, the second cryptographic communication device 12 generates a 21st common key from the second key generation function 312 and the first individual information 331 of the other first cryptographic communication device 11. In this way, the first cryptographic communication device 11 and the second cryptographic communication device 12 generate common keys separately.
[0051] With this configuration, the first encrypted communication device 11 and the second encrypted communication device 12 generate a common key using their respective key generation functions and the individual information of the other party. Therefore, even if any of the individual information is leaked to a third party and used by the third encrypted communication device, the common key generated by the third encrypted communication device will be a different common key from the legitimate common key. Thus, the encrypted communication system 1 allows for a simple encrypted communication system while reducing the risk of impersonation even if the individual information of any of the encrypted communication devices is leaked to a third party.
[0052] Since the first cryptographic communication device 11 and the second cryptographic communication device 12 generate a shared key using the individual information of the other party, the need for a dedicated computing device, which was required when generating a shared key using a public key, is eliminated, thereby simplifying the cryptographic communication device. In the encrypted communication system 1, mutual authentication procedures can be performed directly and simply between the first encrypted communication device 11 and the second encrypted communication device 12 using a key sharing method that does not require preliminary communication. In the encrypted communication system 1, when the first encrypted communication device 11 and the second encrypted communication device 12 communicate encrypted directly, a network environment can be eliminated during authentication.
[0053] Thus, in the encrypted communication system 1 according to this embodiment, by utilizing ID-based encryption, which is one of the lightweight encryption technologies that requires almost no processing power, it becomes possible to enable highly secure authenticated key sharing while preventing a decrease in processing time efficiency, regardless of the processing power of the device.
[0054] Here, we will describe specific examples of the effects of the encrypted communication system 1 according to this embodiment, while highlighting the challenges of conventional technologies. Traditionally, key sharing systems have been known that generate shared keys for encrypted communication between devices using authenticated key sharing protocols. In such key sharing systems, in order to generate highly secure shared keys while preventing a decrease in processing time efficiency regardless of the processing performance of the devices, pairing operations are mainly used, and each device entrusts the processing of the secret key to a dedicated computing device, thereby realizing key generation, key sharing, and authentication through encrypted communication.
[0055] For example, traditionally, ID-based methods, used in email systems and the like, have been known as a way to solve the problems of managing and distributing private keys. For instance, in the fourth-generation key sharing scheme that divides IDs, the BigBrother problem can be solved by setting up multiple key issuance centers, and furthermore, parameters can be flexibly set while taking into account factors such as speed, required memory, and collusion thresholds according to the system environment.
[0056] However, conventional mutual authentication methods between IoT devices require a unique master key, and since the authentication partner is predetermined, it is a unique authentication method and could not authenticate between individual IoT devices. In contrast, the encrypted communication system 1 according to this embodiment enables authentication between the first encrypted communication device 11 and the second encrypted communication device 12. This makes it possible, for example, to authenticate between IoT devices.
[0057] Traditionally, public-key cryptography using pairing operations has a high computational load and requires high-performance devices, making it unsuitable for IoT devices with limited processing power. Such technologies, for example, required the provision of a dedicated computing device with a certain level of processing power on the internet. In contrast, the encrypted communication system 1 according to this embodiment employs a key generation function that does not use pairing operations, making it suitable for IoT devices with limited processing power and easier to ensure real-time performance. Furthermore, the encrypted communication system 1 according to this embodiment eliminates the need for a key issuance center or a dedicated computing device. In addition, the encrypted communication system 1 according to this embodiment may use a key generation function that employs pairing operations.
[0058] Traditional ID-based or KPS encryption technologies had a collusion problem, which sometimes meant they weren't sufficiently secure. The collusion problem is that if the same number of users as the number of elements in the public key collude and reveal their private keys to each other, the master key, which is the private key of the PKG, will be exposed. In contrast, the encrypted communication system 1 according to this embodiment can enhance resistance to collusion problems and improve security.
[0059] Traditionally, a configuration where every device has the same number of keys as the number of communication targets was impractical due to the inability to add more communication partners later on, and the enormous amount of key data. This made key management difficult. In contrast, in the encrypted communication system 1 according to this embodiment, the first encrypted communication device 11 and the second encrypted communication device 12 each hold their own key generation functions and generate a common key using the individual information of the other party, making key management easier. In the encrypted communication system 1 according to this embodiment, the first encrypted communication device 11 and the second encrypted communication device 12 can share different keys for each other without having to store different keys for each other. Furthermore, in the encrypted communication system 1 according to this embodiment, it is not necessary to provide a server device or a high-performance device such as a commissioned computing device.
[0060] An example of an application of the encrypted communication system 1 according to this embodiment will be described. In the encrypted communication system 1, after key sharing and mutual authentication between the first encrypted communication device 11 and the second encrypted communication device 12, the application can be any application. In other words, the encrypted communication system 1, including the first encrypted communication device 11 and the second encrypted communication device 12, can be applied to any system that utilizes encrypted communication.
[0061] For example, the encrypted communication system 1 may be applied to a system that verifies the validity of time information between IoT devices. Specifically, the first encrypted communication device 11 holds internal time information for verifying the validity of certificates in encrypted communication, and when external time information obtained from an external source is subjected to an attack such as tampering, it determines that the time information is invalid and thus deals with the attack.
[0062] For example, the encrypted communication system 1 may be applied to a system for vehicle-to-vehicle communication. Specifically, the first encrypted communication device 11 of the first vehicle can directly communicate with the second encrypted communication device 12 of the second vehicle through mutual authentication. Furthermore, the first encrypted communication device 11 of the first vehicle and the second encrypted communication device 12 of the second vehicle can communicate encrypted messages in real time by obtaining the other party's individual information in advance.
[0063] An example configuration according to the embodiment is shown. As an example configuration, the cryptographic communication system 1 includes a first cryptographic communication device 11 having a first tamper-resistant device 111 that stores a first key generation function 311 and a first storage unit that stores first individual information 331, and a second cryptographic communication device 12 having a second tamper-resistant device 211 that stores a second key generation function 312 and a second storage unit that stores second individual information 332. The first cryptographic communication device 11 generates a 12th common key 412 using the first key generation function 311 and the second individual information 332. The second cryptographic communication device 12 generates a 21st common key 422 using the second key generation function 312 and the first individual information 331.
[0064] As an example configuration, in the encrypted communication system 1, the 12th common key 412 is stored in the first tamper-resistant device 111, and the 21st common key 422 is stored in the second tamper-resistant device 211.
[0065] As one example configuration, the first cryptographic communication device 11 generates a first authenticator using the 12th common key 412 and the first individual information 331, and transmits the generated first authenticator to the second cryptographic communication device 12. The second cryptographic communication device 12 decrypts the first authenticator received from the first cryptographic communication device 11 using the 21st common key 422. The second cryptographic communication device 12 authenticates the first cryptographic communication device 11 based on the decryption result of the first authenticator.
[0066] As one example configuration, the second cryptographic communication device 12 generates a second authenticator using the 21st common key 422 and the second individual information 332, and transmits the generated second authenticator to the first cryptographic communication device 11. The first cryptographic communication device 11 decrypts the second authenticator received from the second cryptographic communication device 12 using the 12th common key 412. The first cryptographic communication device 11 authenticates the second cryptographic communication device 12 based on the decryption result of the second authenticator.
[0067] Encrypted communication methods may be used. As an example configuration, in the encrypted communication method, a first encrypted communication device 11 having a first tamper-resistant device 111 that stores a first key generation function 311 and a first storage unit that stores first individual information 331 generates a 12th common key 412 using the first key generation function 311 and the second individual information 332 of the second encrypted communication device 12. The second cryptographic communication device 12, which includes a second tamper-resistant device 211 that stores a second key generation function 312 and a second storage unit that stores second individual information 332, generates a 21st common key 422 using the second key generation function 312 and the first individual information 331.
[0068] Encryption devices may be implemented. As an example configuration, the cryptographic communication device includes a first tamper-resistant device 111 that stores a first key generation function 311 and a first storage unit that stores first individual information 331. The second cryptographic communication device acquires the second individual information 332 from a second cryptographic communication device 12 that includes a second tamper-resistant device 211 that stores a second key generation function 312 and a second storage unit that stores second individual information 332, and generates a 12th common key 412 using the acquired second individual information 332 and the first key generation function 311. Here, an example of the encrypted communication device is the first encrypted communication device 11 according to the embodiment.
[0069] A program for realizing the function of any component in any of the devices described above may be recorded on a computer-readable recording medium, and the program may be loaded into a computer system and executed. Here, "computer system" includes the operating system and hardware such as peripheral devices. "Computer-readable recording medium" refers to portable media such as flexible disks, magneto-optical disks, ROM (Read Only Memory), CD (Compact Disc)-ROMs, and storage devices such as hard disks built into the computer system. "Computer-readable recording medium" also includes volatile memory within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. Such volatile memory may be RAM. The recording medium may also be a non-temporary recording medium.
[0070] The above program may be transmitted from a computer system that stores this program in a memory device or the like to another computer system via a transmission medium, or by transmission waves within the transmission medium. The "transmission medium" used to transmit the program refers to a medium that has the function of transmitting information, such as a network like the Internet or a communication line like a telephone line. The above program may be intended to implement some of the functions described above. The above program may also be a so-called differential file, capable of implementing the aforementioned functions in combination with programs already recorded in the computer system. A differential file may also be called a differential program.
[0071] The functions of any component in any device described above may be implemented by a processor. Each process in the embodiment may be implemented by a processor that operates based on information such as a program, and a computer-readable recording medium that stores information such as a program. The functions of each part of the processor may be implemented by separate hardware, or the functions of each part may be implemented by integrated hardware. The processor includes hardware, and the hardware may include at least one of a circuit that processes digital signals and a circuit that processes analog signals. The processor may be configured using one or more circuit devices or one or both of one or more circuit elements mounted on a circuit board. ICs (Integrated Circuits) may be used as circuit devices, and resistors or capacitors may be used as circuit elements.
[0072] The processor may be a CPU. However, the processor is not limited to a CPU; various types of processors such as a GPU (Graphics Processing Unit) or a DSP (Digital Signal Processor) may be used. The processor may be a hardware circuit using an ASIC (Application Specific Integrated Circuit). The processor may consist of multiple CPUs, or it may consist of hardware circuits using multiple ASICs. The processor may consist of a combination of multiple CPUs and hardware circuits using multiple ASICs. The processor may include one or more amplifier circuits or filter circuits that process analog signals.
[0073] Although embodiments have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments and includes designs and the like that do not depart from the spirit of this invention. [Explanation of Symbols]
[0074] 1... Encryption communication system, 11... First encrypted communication device, 11a... First a encrypted communication device, 12... Second encrypted communication device, 111... First tamper-resistant device, 111a... First a tamper-resistant device, 131... First memory, 132... First input unit, 133... First output unit, 134... First communication unit, 135... First control unit, 211... Second tamper-resistant device, 231... 232...Second memory, 233...Second input unit, 234...Second communication unit, 235...Second control unit, 311...First key generation function, 312...Second key generation function, 331...First individual information, 332...Second individual information, 411...First device information, 412...Twelfth common key, 421...Second device information, 422...Twenty-first common key, 431...Third device information, 432...Third-second common key
Claims
1. A first cryptographic communication device having a first tamper-resistant device that stores a first key generation function, and a first storage unit that stores first individual information, A second cryptographic communication device having a second tamper-resistant device that stores a second key generation function, and a second storage unit that stores second individual information, It is equipped with, and furthermore, The first encrypted communication device comprises a first input unit and a first communication unit, The second encrypted communication device comprises a second input unit and a second communication unit, When the first encrypted communication device and the second encrypted communication device communicate with each other, In the first encrypted communication device, the second individual information is input through the first input unit or received by the first communication unit. In the second encrypted communication device, the first individual information is input through the second input unit or received by the second communication unit. The first cryptographic communication device generates a twelfth common key using the first key generation function and the second individual information, The second cryptographic communication device generates a 21st common key using the second key generation function and the first individual information, The first tamper-resistant device stores the 12th common key, The second tamper-resistant device stores the 21st common key, The first cryptographic communication device generates a first authenticator using the twelfth common key and the first individual information, and transmits the generated first authenticator to the second cryptographic communication device. The second cryptographic communication device decrypts the first authenticator received from the first cryptographic communication device using the 21st common key. The second encrypted communication device authenticates the first encrypted communication device based on the decryption result of the first authenticator. Encrypted communication system.
2. The second cryptographic communication device generates a second authenticator using the 21st common key and the second individual information, and transmits the generated second authenticator to the first cryptographic communication device. The first cryptographic communication device decrypts the second authenticator received from the second cryptographic communication device using the twelfth common key. The first encrypted communication device authenticates the second encrypted communication device based on the decryption result of the second authenticator. The encrypted communication system according to claim 1.
Citation Information
Patent Citations
Computer system
JP2012048488A
Inter-vehicle / road-to-vehicle communication system
JP2012227672A