Encrypted communication method

By transferring the common key through a high-speed separate communication path, the system achieves low-latency communication and maintains security in common-key cryptosystems, addressing the challenges of frequent encryption and decryption processes.

WO2025115204A1PCT designated stage expired Publication Date: 2025-06-05NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/043050
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-01
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing common-key cryptosystems face challenges in achieving low-latency communication while maintaining security, as they require frequent encryption and decryption processes that increase the risk of eavesdropping and tampering during key exchange.

Method used

The proposed solution involves transferring the common key through a separate communication path with higher speed than the main data path, allowing for periodic key generation and exchange without significantly increasing communication time. This method reduces the need for public-key cryptosystems, which are computationally intensive.

Benefits of technology

This approach enables low-latency communication by minimizing the time required for key exchange and encryption processing, while maintaining a high security level by frequently changing the common key and reducing the risk of interception and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023043050_05062025_PF_FP_ABST
    Figure JP2023043050_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The purpose of the present invention is to provide a communication system and the like of a common key cryptosystem capable of performing low-latency communication while maintaining a security level. A communication system 301 transfers data from a transmission device 10 to a reception device 20 via a main communication path 50 by a common key system. The transmission device 10 includes: a key generation unit 11 that periodically generates a common key; a key exchange transmission unit 12 that, for each generation of the common key, transmits the common key to the reception device 20 by another communication path 51 having a communication speed faster than that of the main communication path 50; an encryption unit 13 that encrypts data with the common key; and a main signal transmission unit 14 that transmits the encrypted data to the reception device 20 by the main communication path 50. The reception device 20 includes: a key exchange reception unit 21 that receives the common key from the other communication path 51; a main signal reception unit 22 that receives the encrypted data from the main communication path 50; and a decryption unit 23 that decrypts the received data with the common key.
Need to check novelty before this filing date? Find Prior Art

Description

Encrypted communication method

[0001] The present disclosure relates to a cryptographic key sharing scheme.

[0002] Data communication can be subject to eavesdropping and tampering. For this reason, encrypted communication is used for highly confidential data. Two methods are used for encrypted communication. The most representative common key method is AES (Advanced Encryption Standard), and the most representative public key method is RSA (Reliable RSA Algorithm).

[0003] Withdrawn NIST Technical Series Publication (https: / / tex2e.github.io / rfc-translater / html / rfc8017.html), retrieved November 6, 2023. The Advanced Encryption Standard (AES) Cipher Algorithm in the SNMP User-based Security Model (https: / / www.nist.gov / publications / advanced-encryption-standard-aes), retrieved November 6, 2023.

[0004] Because encryption and decryption require computational processing, it is difficult to transmit encrypted data in the same communication time as unencrypted communication. In particular, the public key method requires a larger amount of computational processing than the common key method, and the encryption processing takes time, resulting in a long end-to-end communication time. Normally, as shown in Figure 1, the common key of a common key method is sent using public key encryption to prevent eavesdropping and tampering of the common key exchange and maintain a level of security. However, as mentioned above, encryption processing time is required each time a key is exchanged, which lengthens communication time. In Figure 1, the steps are as follows: P01: Determining a public key P02: Determining a common key P03: Sending a public key P04: Encrypting the common key using the public key P05: Sending the encrypted common key P06: Encrypting data using the common key P07: Decrypting the public key using the private key P08: Sending the encrypted data P09: Decrypting data using the common key

[0005] Here, by continuing communication without changing the common key after exchanging it once using public key cryptography, the frequency of the encryption process can be reduced and the overall communication time can be shortened. However, if the common key is intercepted, the amount of information leaked increases, making it difficult to maintain a high level of security.

[0006] As described above, the common key cryptography has a problem in that it is difficult to simultaneously reduce the risk of eavesdropping or tampering in the intermediate path during key exchange and realize low-latency communication. Therefore, in order to solve the above problem, the present invention aims to provide a common key cryptography communication system, an encrypted communication method, a transmitting device, a receiving device, and a program that enable low-latency communication while maintaining a security level.

[0007] In order to achieve the above object, the communication system according to the present invention transfers a common key via a separate communication path that has a higher communication speed than a main communication path for transferring data.

[0008] Specifically, the communication system of the present invention is a communication system that transfers data from a transmitting device to a receiving device via a main communication path using a common key method, wherein the transmitting device comprises: a key generation unit that periodically generates a common key; a key exchange transmission unit that transmits the common key to the receiving device via a separate communication path having a faster communication speed than the main communication path each time the common key is generated; an encryption unit that encrypts the data with the common key; and a main signal transmission unit that transmits the encrypted data to the receiving device via the main communication path; and the receiving device comprises: a key exchange reception unit that receives the common key from the separate communication path; a main signal reception unit that receives the encrypted data from the main communication path; and a decryption unit that decrypts the received data using the common key.

[0009] Among these, the transmitting device of the present invention is a transmitting device that transfers data to a receiving device via a main communication path using a common key system, and is characterized by comprising: a key generation unit that periodically generates a common key; a key exchange transmission unit that transmits the common key to the receiving device via a separate communication path that has a faster communication speed than the main communication path each time the common key is generated; an encryption unit that encrypts the data using the common key; and a main signal transmission unit that transmits the encrypted data to the receiving device via the main communication path.

[0010] The receiving device of the present invention is a receiving device to which data is transferred from a transmitting device via a main communication path using a common key system, and is characterized by comprising: a key exchange receiving unit that receives a common key periodically generated by the transmitting device from another communication path having a faster communication speed than the main communication path; a main signal receiving unit that receives the data encrypted with the common key from the main communication path; and a decoding unit that decrypts the received data with the common key.

[0011] Furthermore, the cryptographic communication method of the present invention is a cryptographic communication method for transferring data from a transmitting device to a receiving device via a main communication path using a common key system, characterized in that the transmitting device: periodically generates a common key; each time the common key is generated, transmits the common key to the receiving device via a separate communication path having a faster communication speed than the main communication path; encrypts the data with the common key; and transmits the encrypted data to the receiving device via the main communication path; and the receiving device: receives the common key from the separate communication path; receives the encrypted data from the main communication path; and decrypts the received data with the common key.

[0012] Because this cryptographic communication method does not employ a public encryption method that requires a large amount of computational processing, data transfer is possible in the sum of the data transmission time over the main communication path, the encryption processing time at the sending device, and the decryption processing time at the receiving device (saving the time required for public key encryption and decryption). Here, because the common key is transferred over a separate communication path with a high communication speed, the receiving device can obtain the common key before data arrives from the main communication path, enabling decryption processing immediately after data arrival. Therefore, communication delays can be reduced even if the cycle for common key exchange is shortened.

[0013] In this way, the present cryptographic communication method can reduce the risk of eavesdropping or tampering of the common key by transferring the common key via a separate path and by changing the common key frequently, without adopting a public cryptographic method. Therefore, the present invention can provide a communication system, cryptographic communication method, transmitting device, and receiving device that use a common key cryptography method and enable low-latency communication while maintaining a high level of security.

[0014] In addition, the key generation unit of the communication system of the present invention is characterized in that it encrypts the common key with another encryption key, and the decryption unit decrypts the common key encrypted with the encryption key before decrypting the received data with the common key.

[0015] In this cryptographic communication method, the common key is transferred via a separate, faster communication path, so there is a time lag between the arrival of the common key and the arrival of the data at the receiving device, and even if the common key is encrypted, this time lag can be used to decrypt the common key, thereby avoiding communication delays. Encrypting the common key can further increase the security level.

[0016] The communication system according to the present invention is characterized by further comprising a delay adjustment unit that grasps the difference in communication speed between the main communication path and the alternative communication path and adjusts the timing of application of the common key.

[0017] In this cryptographic communication method, the common key is transferred via a separate communication path with a high communication speed, so when the common key is changed, there is a possibility that the new common key will arrive at the receiving device before the data encrypted with the previous common key arrives at the receiving device, which is called "overtaking." Even if such "overtaking" occurs, the delay adjustment unit adjusts the timing of applying the common key, thereby reducing the number of failures in the data decryption process.

[0018] The present invention also provides a program for causing a computer to function as the transmitting device or the receiving device. The transmitting device and receiving device of the present invention can also be realized by a computer and a program, and the program can be recorded on a recording medium or provided over a network.

[0019] The above inventions can be combined as much as possible.

[0020] The present invention can provide a communication system, a cryptographic communication method, a transmitting device, a receiving device, and a program that use a common key cryptosystem and enable low-latency communication while maintaining a security level.

[0021] FIG. 1 is a diagram illustrating a method for transmitting a common key of a common key system by a public key cryptosystem. FIG. 1 is a diagram illustrating the configuration of a communication system according to the present invention. FIG. 2 is a flowchart illustrating a cryptographic communication method according to the present invention. FIG. 3 is a sequence diagram illustrating a cryptographic communication method according to the present invention. FIG. 4 is a diagram illustrating the configuration of a communication system according to the present invention. FIG. 5 is a flowchart illustrating a cryptographic communication method according to the present invention. FIG. 6 is a sequence diagram illustrating a cryptographic communication method according to the present invention. FIG. 7 is a diagram illustrating the configuration of a communication system according to the present invention. FIG. 8 is a flowchart illustrating a cryptographic communication method according to the present invention. FIG. 9 is a sequence diagram illustrating a cryptographic communication method according to the present invention. FIG. 10 is a diagram illustrating a specific example of a communication system according to the present invention. FIG. 11 is a diagram illustrating a transmitting device and a receiving device according to the present invention.

[0022] The following description of the preferred embodiments of the present invention will be given with reference to the accompanying drawings. The preferred embodiments described below are examples of the present invention, and the present invention is not limited to the preferred embodiments. In this specification and the drawings, components having the same reference numerals are intended to represent the same components.

[0023] (Embodiment 1) Fig. 2 is a diagram illustrating the configuration of a communication system 301 according to this embodiment. The communication system 301 is a communication system that transfers data from a transmitting device 10 to a receiving device 20 via a main communication path 50 using a common key system. The transmitting device 10 includes a key generation unit 11 that periodically generates a common key, a key exchange transmission unit 12 that transmits the common key to the receiving device 20 via an alternative communication path 51 that has a faster communication speed than the main communication path 50 each time the common key is generated, an encryption unit 13 that encrypts the data using the common key, and a main signal transmission unit 14 that transmits the encrypted data to the receiving device 20 via the main communication path 50. The receiving device 20 includes a key exchange reception unit 21 that receives the common key from the alternative communication path 51, a main signal reception unit 22 that receives the encrypted data from the main communication path 50, and a decryption unit 23 that decrypts the received data using the common key.

[0024] Fig. 3 is a flowchart illustrating an encrypted communication method of the communication system 301. Fig. 4 is a sequence diagram illustrating the encrypted communication method of the communication system 301. This encrypted communication method transfers data from a transmitting device 10 to a receiving device 20 via a main communication path 50 using a common key system, and includes the following steps: the transmitting device 10 periodically generates a common key (step S11); each time the common key is generated, the transmitting device 10 transmits the common key to the receiving device 20 via an alternative communication path 51 having a faster communication speed than the main communication path 50 (step S12); the transmitting device 10 encrypts the data using the common key (step S13); and the receiving device 20 transmits the encrypted data via the main communication path 50 to the receiving device 20 (step S14); and the receiving device 20 receives the common key from the alternative communication path 51 (step S21); receives the encrypted data from the main communication path (step S22); and decrypts the received data using the common key (step S23).

[0025] In Fig. 4, the steps are as follows: P11: Determining a common key A P12: Transmitting common key A P13: Encrypting data using common key A P14: Transmitting encrypted data P15: Decrypting data using common key A P21: Determining a common key B P22: Transmitting common key B P23: Encrypting data using common key B P24: Transmitting encrypted data P25: Decrypting data using common key B

[0026] The communication system 301 transfers data via a main communication path 50 and exchanges common keys via an alternative communication path 51. The receiving device 20 performs decryption processing using the common key transferred via the alternative communication path 51. The alternative communication path 51 has a faster communication speed than the main communication path 50. The main communication path 50 is wired communication such as optical fiber, and the alternative communication path 51 is space communication via a satellite. Conversely, the main communication path 50 may be wireless communication via multiple wireless relay stations, and the alternative communication path 51 may be wired communication such as optical fiber. For example, the main communication path 50 may be a transmission path that is "wideband but has a long transmission distance and a large delay" such as a traffic channel / U-plane, and the alternative communication path 51 may be a transmission path that is "narrowband but has a short transmission distance and a short delay" such as a control channel / C-plane.

[0027] Furthermore, since the communication system 301 does not transfer the common key using a public key system, the risk of eavesdropping or tampering is reduced by frequently switching the common key. For example, the communication system 301 switches the common key once per minute.

[0028] In this way, communication system 301 achieves low latency by not using the public key method, enables frequent key exchanges by transferring the common key via a separate, high-speed communication path different from the main communication path, and increases the security level by increasing the frequency of common key exchanges.

[0029] (Embodiment 2) Fig. 5 is a diagram illustrating the configuration of a communication system 302 according to this embodiment. The configuration of the communication system 302 is the same as the configuration of the communication system 301 in Fig. 2. However, the communication system 302 is characterized in that the key generation unit 11 encrypts the common key with another encryption key, and the decryption unit 23 decrypts the common key encrypted with the encryption key before decrypting the received data with the common key.

[0030] 6 is a flowchart illustrating the cryptographic communication method of the communication system 302. This cryptographic communication method adds a step P11a for encrypting a common key and a step P12a for decrypting the common key to the cryptographic communication method of the communication system 301 in FIG. 3. A public key or the previously used common key may be used to encrypt / decrypt the common key.

[0031] 7 is a sequence diagram for encrypting / decrypting a common key using a public key. This cryptographic communication method encrypts a public key that is periodically generated using a public key α transmitted from the receiving device 20. In FIG. 7, the steps are as follows: P01: Determining public key α; P03: Transmitting public key α; P11: Determining common key A; P11a: Encrypting common key A using public key α; P12: Transmitting encrypted common key A; P12a: Decrypting common key A using public key α; P13: Encrypting data using common key A; P14: Transmitting encrypted data; P15: Decrypting data using common key A; P21: Determining common key B; P21a: Encrypting common key B using public key α; P22: Transmitting encrypted common key B; P22a: Decrypting common key B using public key α; P23: Encrypting data using common key B; P24: Transmitting encrypted data; P25: Decrypting data using common key B. The process is repeated.

[0032] In this cryptographic communication method, the common key is encrypted using a public key system, which takes time to decrypt, but the public key is transferred over a separate communication path 51, which has a faster communication speed than the main communication path 50, so that the receiving device 20 can receive the public key before the data. In other words, the receiving device 20 has time to decrypt the public key before receiving the data, and data communication delays can be avoided even when the common key is encrypted using the public key system.

[0033] Figure 8 is also a sequence diagram for encrypting / decrypting a common key using a public key. In this cryptographic communication method, public key A1 is encrypted with public key α transmitted from receiving device 20 only the first time, and thereafter public key An is encrypted with public key An-1 generated immediately before. In Figure 8, the steps are as follows: P01: Determine public key α P03: Transmit public key α P11: Determine common key A1 P11a: Encrypt common key A1 using public key α P12: Transmit encrypted common key A1 P12a: Decrypt common key A1 using public key α P13: Encrypt data using common key A1 P14: Transmit encrypted data P15: Decrypt data using common key A1 P21: Determine common key A2 P21a: Encrypt common key A2 using common key A1 P22: Transmit encrypted common key A2 P22a: Decrypt common key A2 using common key A1 P23: Encrypt data using common key A2 P24: Transmit encrypted data P25: Decrypt data using common key A2 The process repeats.

[0034] In this cryptographic communication method, the common key is encrypted using a public key system, which takes time to decrypt, but the public key is transferred over a separate communication path 51, which has a faster communication speed than the main communication path 50, so that the receiving device 20 can receive the public key before the data. In other words, the receiving device 20 has time to decrypt the public key before receiving the data, so that data communication delays can be avoided even if the common key is encrypted using the public key system. Furthermore, in the case of this cryptographic communication method, the common key from the second time onwards is encrypted using the previous common key instead of the public key, so the decryption time can be shortened and the method can be implemented even if the distance between the transmitting device 10 and the receiving device 20 is short (even if there is not enough time to decrypt the public key).

[0035] (Embodiment 3) Fig. 9 is a diagram illustrating the configuration of a communication system 303 according to this embodiment. The configuration of the communication system 303 is the same as the configuration of the communication system 301 in Fig. 2. However, the communication system 303 differs from the communication system 301 in Fig. 2 in that it performs communication while changing the common key very frequently (for example, every 10 msec).

[0036] Fig. 10 is a flowchart illustrating the cryptographic communication method of the communication system 303. This cryptographic communication method differs from the cryptographic communication method of the communication system 301 in Fig. 3 in that generation of the next symmetric key (step S11) is started before transmitting the one created symmetric key to the receiving device 20 (step S12).

[0037] Fig. 11 is a sequence diagram illustrating the encrypted communication method of the communication system 303. In Fig. 11, the steps are as follows: P11: Determining a common key A P12: Transmitting common key A P13: Encrypting data using common key A P14: Transmitting encrypted data P15: Decrypting data using common key A P16: Immediately after determining common key A, starting generation of the next common key B P21: Determining common key B P22: Transmitting common key B P23: Encrypting data using common key B P24: Transmitting encrypted data P25: Decrypting data using common key B P26: Immediately after determining common key B, starting generation of the next common key C

[0038] The communication system 303 starts generating the next common key immediately after determining one common key, thereby increasing the frequency of common key exchange. In other words, the communication system 303 achieves a higher security level by increasing the frequency of common key exchange.

[0039] (Embodiment 4) When the frequency of exchanging common keys is increased as in embodiment 3, the common keys are transferred over a separate high-speed communication path, which can cause a problem such as that shown in Fig. 12. That is, the next common key overtakes the data encrypted with the previous common key, resulting in a period M during which data cannot be decrypted.

[0040] In this embodiment, a communication system will be described that has a function to prevent the occurrence of such a time period M. The communication system further includes a delay adjustment unit 15 in the transmitting device 10 that grasps the difference in communication speed between the main communication path 50 and the alternative communication path 51 and adjusts the timing of application of the common key.

[0041] FIG. 13 is a diagram illustrating a communication system 304 in which the transmitting device 10 includes a delay adjustment unit 15. FIG. 14 is a flowchart illustrating an encrypted communication method of the communication system 304. The key exchange receiving unit 21 of the receiving device 20 determines a communication delay when it receives a common key (step S21). For example, the key exchange receiving unit 21 can determine the communication delay by comparing the transmission time included in the common key packet with the current time. The key exchange receiving unit 21 then notifies the transmitting device 10 of the communication delay (step S21b). The notification of the communication delay may be made via the main communication path 50 or the alternative communication path 51. The main signal receiving unit 22 of the receiving device 20 also determines the communication delay when it receives a main signal (step S22). For example, the main signal receiving unit 22 can determine the communication delay by comparing the transmission time included in the main signal packet with the current time. The main signal receiving unit 22 then notifies the transmitting device 10 of the communication delay (step S22b). The notification of the communication delay may be made via the main communication path 50 or the alternative communication path 51 .

[0042] The delay adjustment unit 15 of the transmitting device 10 calculates the delay difference between the communication delay of the other communication path 51 notified by the receiving device 20 in step S15 and the communication delay of the main communication path 50 (step S16), and performs a transmission delay to delay the transmission time of the common key so that the aforementioned time M does not occur (step S12b).

[0043] Fig. 15 is a sequence diagram illustrating the encrypted communication method of the communication system 304. In Fig. 15, the steps are as follows: P11: Determining a common key A P12: Transmitting the common key A P12x: Transmitting delay information P13: Encrypting data using the common key A P14: Transmitting the encrypted data P15: Decrypting data using the common key A P16: Starting generation of the next common key B immediately after determining the common key A P21: Determining a common key B P21b: Waiting for transmission of the common key B (adding a transmission delay based on the delay information) P22: Transmitting the common key B P23: Encrypting data using the common key B P24: Transmitting the encrypted data P25: Decrypting data using the common key B

[0044] As described in the third embodiment, the communication system 304 starts generating the next common key immediately after determining one common key, thereby increasing the frequency of common key exchange. Furthermore, in the communication system 304, the receiving device 20 grasps the delay amount of the previous common key A and notifies the transmitting device 10 of this delay information. The transmitting device 10 waits for transmission of common key B based on the delay difference between the delay information (the delay amount of common key A) and the delay amount of data encrypted with that key (step P21b). Step P21b prevents common key B from overtaking data encrypted with common key A. In other words, the communication system 304 realizes a higher security level by increasing the frequency of common key exchange, and can avoid data that cannot be decrypted because the common key overtakes the data.

[0045] Fifth Embodiment In this embodiment, a communication system having a function of preventing the occurrence of the time M described in Fig. 12 will be described. This communication system further includes a delay adjustment unit 25 in the receiving device 20 that grasps the difference in communication speed between the main communication path 50 and the alternative communication path 51 and adjusts the timing of application of the common key.

[0046] FIG. 16 is a diagram illustrating a communication system 305 in which the receiving device 20 includes a delay adjustment unit 25. FIG. 17 is a flowchart illustrating an encrypted communication method of the communication system 305. The key exchange receiving unit 21 of the receiving device 20 determines a communication delay (step S21b) when it receives a common key (step S21). For example, the key exchange receiving unit 21 can determine the communication delay by comparing the transmission time included in the common key packet with the current time. Furthermore, the main signal receiving unit 22 of the receiving device 20 determines the communication delay (step S22b) when it receives a main signal (step S22). For example, the main signal receiving unit 22 can determine the communication delay by comparing the transmission time included in the main signal packet with the current time.

[0047] The delay adjustment unit 15 of the receiving device 20 calculates the delay difference between the communication delay of the other communication path 51 and the communication delay of the main communication path 50 (step S26), and performs an application delay to delay the time at which the common key is applied to the data so that the aforementioned time M does not occur (step S27).

[0048] Fig. 18 is a sequence diagram illustrating the encrypted communication method of the communication system 305. In Fig. 18, the steps are as follows: P11: Determining a common key A P12: Transmitting common key A P13: Encrypting data using common key A P14: Transmitting encrypted data P15: Decrypting data using common key A P16: Starting generation of the next common key B immediately after determining common key A P21: Determining common key B P22: Transmitting common key B P22b: Waiting for the time to apply common key B (application delay) P23: Encrypting data using common key B P24: Transmitting encrypted data P25: Decrypting data using common key B

[0049] As described in the third embodiment, the communication system 305 starts generating the next common key immediately after determining one common key, thereby increasing the frequency of common key exchange. Furthermore, the communication system 305 causes the receiving device 20 to wait for the timing to use common key B for decryption based on the delay difference between the previous common key A and the data encrypted with that key (step P22b). Step P21b prevents data encrypted with common key A from being decrypted with common key B, even if common key B overtakes data encrypted with common key A. In other words, the communication system 305 increases the security level by increasing the frequency of common key exchange, and can avoid the occurrence of data that cannot be decrypted even if the common key overtakes the data.

[0050] Sixth Embodiment In this embodiment, a communication system having a function of preventing the occurrence of the time M described in Fig. 12 will be described. This communication system is characterized in that the transmitting device 10 further includes a tagging unit 16 that attaches a key tag to data indicating which common key was used to encrypt the data, and the decryption unit 23 of the receiving device 20 decrypts the data with the common key corresponding to the key tag attached to the data.

[0051] FIG. 19 illustrates a communication system 306 in which the transmitting device 10 includes a tagging unit 16 and the receiving device 20 includes a tag allocating unit 26 that identifies a key tag attached to data. FIG. 20 is a flowchart illustrating an encrypted communication method of the communication system 306. The tag allocating unit 16 of the transmitting device 10 determines which common key was used when the encryption unit 13 encrypts data (step S13) and assigns a key tag identifying the common key to the encrypted data (step S13c). The main signal transmitting unit 14 transmits the key-tagged data (step S14). The tag allocating unit 26 of the receiving device 20 selects a common key to be applied to the data from among the received common keys based on the key tag of the received data and passes it to the decryption unit 23 (step S22c).

[0052] Fig. 21 is a sequence diagram illustrating the encrypted communication method of the communication system 306. In Fig. 21, the steps are as follows: P11: Determining common key A P12: Transmitting common key A P13: Encrypting data using common key A (a tag 31a indicating that encryption has been performed using common key A is attached) P14: Transmitting encrypted data P15: Decrypting data using common key A based on tag 31a P16: Immediately after determining common key A, starting generation of next common key B P21: Determining common key B P22: Transmitting common key B P23: Encrypting data using common key B (a tag 31b indicating that encryption has been performed using common key B is attached) P24: Transmitting encrypted data P25: Decrypting data using common key B based on tag 31b

[0053] As described in the third embodiment, the communication system 306 starts generating the next common key immediately after determining one common key, thereby increasing the frequency of common key exchange. Furthermore, in the communication system 306, the transmitting device 10 assigns a key tag to encrypted data before transmitting it, and the receiving device 20 decrypts it with a common key corresponding to the key tag, thereby preventing data encrypted with common key A from being decrypted with common key B even if common key B overtakes data encrypted with common key A. In other words, the communication system 306 increases the security level by increasing the frequency of common key exchange, and can avoid the occurrence of data that cannot be decrypted even if the common key overtakes the data.

[0054] (Embodiment 7) Figure 22 is a diagram illustrating a specific example of the present communication system. In this communication system, a transmitting device 10 and a receiving device 20 are located on different continents, and secure, low-latency, and high-capacity communication is performed over ultra-long distances between continents. A main communication path 50 is wired communication using optical fiber. An alternative communication path 51 is satellite communication, which has a shorter latency than optical fiber communication. This communication system is suitable for, for example, scalping (short-term stock trading) of foreign stocks and remote meetings between important international figures, such as government officials.

[0055] (Embodiment 8) The transmitting device 10 and the receiving device 20 can also be realized by a computer and a program, and the program can be recorded on a recording medium or provided via a network. Figure 23 shows a block diagram of a system 100. The system 100 includes a computer 105 connected to a network 135.

[0056] Network 135 is a data communications network. Network 135 may be a private or public network and may include any or all of the following: (a) a personal area network, e.g., covering a room; (b) a local area network, e.g., covering a building; (c) a campus area network, e.g., covering a campus; (d) a metropolitan area network, e.g., covering a city; (e) a wide area network, e.g., covering an area spanning city, region, or country boundaries; or (f) the Internet. Communications are conducted over network 135 by electronic and optical signals.

[0057] Computer 105 includes a processor 110 and a memory 115 connected to processor 110. Although computer 105 is depicted herein as a stand-alone device, it is not limited to such, but rather may be connected to other devices not shown in a distributed processing system.

[0058] Processor 110 is an electronic device made up of logic circuits that responds to and carries out instructions.

[0059] The memory 115 is a tangible computer-readable storage medium on which a computer program is encoded. In this regard, the memory 115 stores data and instructions, i.e., program code, that can be read and executed by the processor 110 to control its operation. The memory 115 can be implemented as a random access memory (RAM), a hard drive, a read-only memory (ROM), or a combination thereof. One component of the memory 115 is a program module 120.

[0060] The program modules 120 contain instructions for controlling the processor 110 to perform the processes described herein. Although operations are described herein as being performed by the computer 105 or a method or process or sub-process thereof, those operations are actually performed by the processor 110.

[0061] The term "module" is used herein to refer to a functional operation that may be embodied as either a stand-alone component or an integrated configuration of multiple subcomponents. Thus, program module 120 may be implemented as a single module or as multiple modules operating in cooperation with each other. Furthermore, although program module 120 is described herein as being installed in memory 115 and therefore implemented in software, it may be implemented in any of hardware (e.g., electronic circuitry), firmware, software, or a combination thereof.

[0062] While the program modules 120 are shown as already loaded into memory 115, they may also be configured to reside on storage device 140 for later loading into memory 115. Storage device 140 is a tangible, computer-readable storage medium that stores the program modules 120. Examples of storage device 140 include compact discs, magnetic tape, read-only memory, optical storage media, a memory unit consisting of a hard drive or multiple parallel hard drives, and a universal serial bus (USB) flash drive. Alternatively, storage device 140 may be random access memory or another type of electronic storage device located in a remote storage system (not shown) and connected to computer 105 via network 135.

[0063] System 100 further includes data source 150A and data source 150B, collectively referred to herein as data sources 150, that are communicatively connected to network 135. In practice, data sources 150 may include any number of data sources, i.e., one or more data sources. Data sources 150 may include unstructured data and may include social media.

[0064] The system 100 further includes a user device 130 operated by the user 101 and connected to the computer 105 via a network 135. The user device 130 includes an input device, such as a keyboard or a voice recognition subsystem, that allows the user 101 to communicate information and command selections to the processor 110. The user device 130 also includes an output device, such as a display device or a printer or a voice synthesizer. A cursor control, such as a mouse, trackball, or touch-sensitive screen, allows the user 101 to manipulate a cursor on the display device to communicate further information and command selections to the processor 110.

[0065] The processor 110 outputs the results 122 of the execution of the program modules 120 to the user device 130. Alternatively, the processor 110 can provide the output to a storage device 125, such as a database or memory, or via a network 135 to a remote device not shown.

[0066] For example, the program module 120 may be a program that performs the flowchart of the transmitting device 10 in Figure 3, Figure 6, Figure 10, Figure 14, Figure 17, or Figure 20. The system 100 can be operated as the transmitting device 10. Furthermore, the program module 120 may be a program that performs the flowchart of the receiving device 20 in Figure 3, Figure 6, Figure 10, Figure 14, Figure 17, or Figure 20. The system 100 can be operated as the receiving device 20.

[0067] The terms "comprising" or "comprising" should be interpreted as specifying the presence of the stated features, integers, steps or components, but not excluding the presence of one or more other features, integers, steps or components or groups thereof. The terms "a" and "an" are indefinite articles and therefore do not exclude embodiments having a plurality thereof.

[0068] (Other Embodiments) The present invention is not limited to the above-described embodiment, and various modifications can be made without departing from the spirit of the present invention. In short, the present invention is not limited to the above-described embodiment, and the components can be modified and embodied in the implementation stage without departing from the spirit of the present invention.

[0069] Furthermore, various inventions can be formed by appropriately combining the multiple components disclosed in the above embodiments. For example, some components may be omitted from all the components shown in the embodiments. Furthermore, components from different embodiments may be appropriately combined.

[0070] 10: Transmitting device 11: Key generation unit 12: Key exchange transmitting unit 13: Encryption unit 14: Main signal transmitting unit 15: Delay adjustment unit 16: Tagging unit 20: Receiving device 21: Key exchange receiving unit 22: Main signal receiving unit 23: Decryption unit 25: Delay adjustment unit 26: Tag allocating unit 31a, 31b: Tag 50: Main communication path 51: Other communication path 100: System 101: User 105: Computer 110: Processor 115: Memory 120: Program module 122: Result 125: Storage device 130: User device 135: Network 140: Storage device 150: Data source 301 to 306: Communication system

Claims

1. A communication system for transferring data from a transmitting device to a receiving device via a main communication path using a common key system, wherein the transmitting device includes: a key generation unit that periodically generates a common key; a key exchange transmission unit that transmits the common key to the receiving device via a separate communication path having a higher communication speed than the main communication path each time the common key is generated; an encryption unit that encrypts the data with the common key; and a main signal transmission unit that transmits the encrypted data to the receiving device via the main communication path, and the receiving device includes: a key exchange reception unit that receives the common key from the separate communication path; a main signal reception unit that receives the encrypted data from the main communication path; and a decryption unit that decrypts the received data with the common key.

2. The communication system according to claim 1, wherein the key generation unit encrypts the common key with another encryption key, and the decryption unit decrypts the common key encrypted with the encryption key before decrypting the received data with the common key.

3. The communication system according to claim 1, further comprising a delay adjustment unit that grasps a difference in communication speed between the main communication path and the separate communication path and adjusts an application timing of the common key.

4. An encrypted communication method for transferring data from a transmitting device to a receiving device via a main communication path using a common key system, wherein in the transmitting device, the steps of: periodically generating a common key; transmitting the common key to the receiving device via a separate communication path having a higher communication speed than the main communication path each time the common key is generated; encrypting the data with the common key; and transmitting the encrypted data to the receiving device via the main communication path are performed, and in the receiving device, the steps of: receiving the common key from the separate communication path; receiving the encrypted data from the main communication path; and decrypting the received data with the common key are performed.

5. A transmitting device that transfers data to a receiving device via a main communication path using a common key method, comprising: a key generation unit that periodically generates a common key; a key exchange transmission unit that transmits the common key to the receiving device via a separate communication path having a higher communication speed than the main communication path each time the common key is generated; an encryption unit that encrypts the data with the common key; and a main signal transmission unit that transmits the encrypted data to the receiving device via the main communication path. The transmitting device is characterized by comprising the above components.

6. A receiving device that receives data transferred from a transmitting device via a main communication path using a common key method, comprising: a key exchange reception unit that receives a common key periodically generated by the transmitting device from a separate communication path having a higher communication speed than the main communication path; a main signal reception unit that receives the data encrypted with the common key from the main communication path; and a decryption unit that decrypts the received data with the common key. The receiving device is characterized by comprising the above components.

7. A program for causing a computer to function as the transmitting device according to claim 5.

8. A program for causing a computer to function as the receiving device according to claim 6.

Citation Information

Patent Citations

  • Secret communication system

    JP1991249834A

  • Optical transmission system and optical transmission method

    WO2021250834A1