摘要:
The present invention has an object to overcome problems of a key recovery system using a conventional KRF system and to achieve efficient operation of the overall key recovery system. A key recovery system of the present invention includes check units 12a, 12b for checking whether a user has a recovery authorization for a common key KS, on the basis of a recovery condition RC specified by a recovery condition index RCI which is added to an encrypted message (encrypted message obtained by encrypting the common key KS with a public key KRCpub) supplied from a terminal (10a to 10d) of the user concerned, and a key recovery control unit 14 which is provided separately from the check units 12a, 12b and decrypts the encrypted message with a private key KRCpri paired with the public key KRCpub to recover the common key. The check unit 12a, 12b supplies the common key KS recovered in the key recovery control unit 14 to the user concerned only when the user has the recovery authorization.
摘要:
A key recovery condition encryption apparatus includes a hashing unit, a first concatenating unit, and a condition information encryption unit. The hashing unit calculates a hash value on the basis of a hash function using a key recovery information text serving as information necessary for performing key recovery. The first concatenating unit concatenates the hash value from the hashing unit to the key recovery condition. The condition information encrytion unit encrypts a concatenating result from the first concatenating unit by using a first encryption key. Also is disclosed a key recovery condition decryption apparatus for decrypting the encrypted data from the above encryption apparatus.
摘要:
A key recovery condition encryption apparatus includes a hashing unit, a first concatenating unit, and a condition information encryption unit. The hashing unit calculates a hash value on the basis of a hash function using a key recovery information text serving as information necessary for performing key recovery. The first concatenating unit concatenates the hash value from the hashing unit to the key recovery condition. The condition information encrytion unit encrypts a concatenating result from the first concatenating unit by using a first encryption key. Also is disclosed a key recovery condition decryption apparatus for decrypting the encrypted data from the above encryption apparatus.
摘要:
The present invention has an object to overcome problems of a key recovery system using a conventional KRF system and to achieve efficient operation of the overall key recovery system. A key recovery system of the present invention includes check units 12a, 12b for checking whether a user has a recovery authorization for a common key KS, on the basis of a recovery condition RC specified by a recovery condition index RCI which is added to an encrypted message (encrypted message obtained by encrypting the common key KS with a public key KRCpub) supplied from a terminal (10a to 10d) of the user concerned, and a key recovery control unit 14 which is provided separately from the check units 12a, 12b and decrypts the encrypted message with a private key KRCpri paired with the public key KRCpub to recover the common key. The check unit 12a, 12b supplies the common key KS recovered in the key recovery control unit 14 to the user concerned only when the user has the recovery authorization.
摘要:
A storage apparatus includes a key management unit (12) for managing an individual key unique to the apparatus and a common key shared with other storage apparatuses, and an encryption unit (13) for performing an encrypting process or verifying data for performing the encrypting process on electronic data stored in the apparatus to which the unit belongs using the individual key, and performing the encrypting process or verifying the data on the electronic data transmitted to or received from another apparatus using the common key. Thus, the apparatus communicates data using an applicable common key in a local environment and a global environment, appropriately manages a key in each environment, and guarantees the security of the electronic data.
摘要:
A management device for ensuring the authenticity of electronic documents. The management device generates a series of instances of corresponding original data information depending on a change in a time series of the electronic information, and manages the series of the instances as one original data sequence. The assignment device assigns original data sequence identification information to the original data sequence. The issue device issues registration certificate information which contains the original data sequence identification information, and is used for access to an instance in a series of instances.
摘要:
An information storage device (10,30) in which a plurality of storage media (12,18a,18b,41a,41b) having different accessibility is provided with a unit (3-1,3-2,3-3) for controlling the retrieval of a portable storage medium (e.g. 18a) which can be retrieved from the information storage device (10,30) by selecting, at a request to retrieve the portable storage medium, the storage medium either storing the body of a file and the data for use in accessing the file or storing only the body of the file. The information storage device (10,30) stores in and moves to a storage medium at an appropriate level the data for use in accessing a file depending on the situation.
摘要:
An information storage device (10,30) in which a plurality of storage media (12,18a,18b,41a,41b) having different accessibility is provided with a unit (3-1,3-2,3-3) for controlling the retrieval of a portable storage medium (e.g. 18a) which can be retrieved from the information storage device (10,30) by selecting, at a request to retrieve the portable storage medium, the storage medium either storing the body of a file and the data for use in accessing the file or storing only the body of the file. The information storage device (10,30) stores in and moves to a storage medium at an appropriate level the data for use in accessing a file depending on the situation.
摘要:
A management device for ensuring the authenticity of electronic documents. The management device generates a series of instances of corresponding original data information depending on a change in a time series of the electronic information, and manages the series of the instances as one original data sequence. The assignment device assigns original data sequence identification information to the original data sequence. The issue device issues registration certificate information which contains the original data sequence identification information, and is used for access to an instance in a series of instances.