An
authentication key exchange system according to one embodiment is an
authentication key exchange system including a
key generation device and a plurality of equipment. The
key generation device includes a parameter generation unit configured to receive a
security parameter 1λ and a total number N of the equipment as inputs, and output a master private key MSK, a master public key MPK, and an initial revoked user
list RL; a static private
key generation unit configured to receive the master private key MSK, the master public key MPK, and an identifier ID of the equipment as inputs, and output a static private key sskID corresponding to the identifier ID; a revoked user
list update unit configured to receive the master public key MPK and a new revoked user
list RL as inputs, increment a
current time T, and update a revoked user list RLT at the
current time T to the revoked user list RL; and a key update information generation unit configured to receive the master private key MSK, the master public key MPK, the
current time T, and the revoked user list RL as inputs, and output key update information kuT at the current time T by using a KUNode
algorithm. The equipment includes a latest private key generation unit configured to receive the master public key MPK, the static private key sskID corresponding to its own identifier ID, and the key update information kuT at the current time T as inputs, and output a latest private key cskID,T at the current time T without using
pairing calculation; a temporary key generation unit configured to receive the master public key MPK and the latest private key cskID,T corresponding to its own identifier ID at the current time T as inputs, and output a temporary private key eskID and a temporary public key epkID; and a
session key generation unit configured to receive the master public key MPK, its own identifier ID, an identifier ID′ of a communication partner, the latest private key cskID,T corresponding to its own identifier ID at the current time T, the temporary private key eskID corresponding to its own identifier ID, and a temporary public key epkID′ corresponding to the identifier ID′ of the communication partner as inputs, and output a
session key SK shared with the communication partner.